Clinvya Trust

Privacy Policy

This central policy summarizes how Clinvya processes personal, operational, and clinical data in the platform context, including complementary AI, security, DPA, and retention policies. This policy should be read together with the Terms of Use, in particular clause 22.1 (Roles under the LGPD).

Data protected under LGPD

Version 2026.07.1

Last updated: 03/07/2026

Service controller

Legal name: V1 TI TECNOLOGIA DA INFORMAÇÃO LTDA

CNPJ: 21.406.034/0001-50

Municipal registration: 5.135.344-0

Address: R CARDOSO DE ALMEIDA 00797, 1o ANDAR - PERDIZES - CEP: 05013-001 - São Paulo/SP

Municipality: São Paulo

Data collected

We collect data provided in forms, onboarding, authenticated use, support, billing, and platform operation to validate responsible users, configure clinics, operate subscriptions, provide support, and fulfill contractual, tax, and legal obligations.

Google Calendar integration

When an authenticated professional chooses to connect Google Calendar, Clinvya redirects the user to Google's OAuth consent screen and requests only the permissions needed to operate the calendar integration: basic Google account identification used to associate the connection with the authenticated professional, permission to create, read, update, delete, and synchronize events in that professional's Google Calendar, and read-only access to the list of that professional's Google calendars to identify and display the connected calendar.

Clinvya uses Google user data only to connect the professional's calendar, show the connection status, create or update calendar events related to Clinvya appointments, import external Google Calendar events as availability blocks when synchronization is enabled, process Google Calendar change notifications, and maintain synchronization reliability. For patient appointments, Clinvya minimizes what is sent to Google Calendar by using a generic title such as "Consulta Clinvya" and technical identifiers; patient names, phone numbers, clinical notes, anamnesis, transcripts, financial data, and medical record content are not sent to Google Calendar by default.

Google Calendar data is processed on Microsoft Azure infrastructure (hosting and database) and, on the frontend, Sentry may receive technical error metadata for error monitoring, as detailed in the section on sharing of data obtained via Google APIs. Clinvya does not sell Google user data and does not use Google user data for advertising, credit scoring, or training public AI models.

OAuth access tokens and refresh tokens are stored in protected form, are not exposed in API responses, logs, analytics, or support tooling, and are used only for the authorized calendar operations. Webhook validation uses technical channel identifiers and secret tokens so that Google Calendar notifications can be accepted without exposing clinical content.

The professional may disconnect Google Calendar from the settings area. When disconnected, Clinvya removes the locally stored OAuth tokens, stops active webhook registration when possible, and no longer performs new Google Calendar synchronization for that connection. Operational records and historical appointment links may be retained as needed for audit, security, legal, contractual, or support purposes, in accordance with the Data Retention and Deletion Policy. Users and customers may also request deletion through the privacy contact indicated in this Policy.

Sharing of data obtained via Google APIs

Data obtained by Clinvya through Google APIs (specifically calendar events via the https://www.googleapis.com/auth/calendar.events scope, and read-only access to the professional's Google calendar list via the https://www.googleapis.com/auth/calendar.calendarlist.readonly scope) is shared only with the following third parties, exclusively to enable the calendar synchronization feature:

  • Microsoft Azure — hosting infrastructure and database provider. Data is processed and stored on Microsoft Azure servers, subject to Microsoft's security and privacy terms.
  • Sentry — frontend error monitoring provider. It receives only technical error metadata (stack traces, error codes, anonymized session IDs). It is configured with sensitive-data scrubbing and no session recording (session replay disabled). Google Calendar event data is not processed on the frontend by application design.

Third parties Clinvya does not share Google data with

Clinvya does not share, transfer, or disclose data obtained via Google APIs to:

  • Artificial intelligence providers or machine learning services
  • Advertisers or advertising platforms
  • Data brokers
  • Third parties for marketing purposes
  • Any party not directly involved in providing the calendar synchronization service to the user

Exceptions to non-sharing

We may disclose data when required by law, to comply with a valid court order, or to protect the rights, property, or safety of Clinvya, our users, or the public.

Google API Services Limited Use

Clinvya's use of data obtained via Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements:

  • Data is used exclusively to provide the user-facing calendar synchronization feature.
  • Data is not used to train artificial intelligence models, whether our own or third parties'.
  • Data is not transferred to third parties for advertising, resale, or purposes not authorized by the user.
  • Human access to the data is restricted to: (a) explicit user consent, (b) security purposes, (c) compliance with a legal obligation, or (d) internal operations with aggregated/anonymized data.

Roles under the LGPD: Controller and Processor

For purposes of Brazilian Law No. 13,709/2018 (LGPD), in relation to the personal data of patients, professionals, staff, and other data subjects entered by the Customer or their Users into the platform, the Customer acts as Controller and Clinvya acts as Processor, processing such data strictly in accordance with the Customer's lawful instructions, the Terms of Use, this Policy, and the DPA when applicable.

As Controller, it is the Customer's duty to define purposes, legal bases, authorizations, consents, information to data subjects, handling of data subject rights, and any notification to the Brazilian National Data Protection Authority (ANPD) in the event of an incident involving their data.

In relation to Clinvya's own data — Customer registration, commercial contacts, billing data, technical logs, operational telemetry, anonymized usage metrics, marketing data with consent, and other data necessary to provide the service and operate the platform — Clinvya acts as Controller, with purposes, legal bases, and adequate measures described in this Policy.

Data subject rights

Data subjects may exercise the rights provided by the LGPD, including confirmation of the existence of processing, access, correction, anonymization, blocking, deletion, portability, information on sharing, and revocation of consent, when applicable.

Requests regarding patient data entered by the Customer should generally be directed to the Customer Controller, through the channels indicated by it. Clinvya will reasonably cooperate with the Customer to enable such requests in the operational context of the platform.

Requests regarding data Clinvya processes as Controller may be sent to [email protected]. In both cases, Clinvya may take reasonable steps to confirm the requester's identity before responding.

AI, subprocessors, and retention

AI features may support transcription, organization of clinical information, assisted summaries, and documentation. Customer data is not used to train public models, and AI use is governed by the AI Usage Policy.

Enterprise providers and subprocessors may support hosting, security, observability, AI, email, analytics with consent, and payments. Retention, deletion, export, and anonymization are described in the Data Retention and Deletion Policy and may depend on legal or contractual obligations.

Following termination of the subscription, subject to the export window provided in the Terms of Use (clause 30.2) and applicable legal and regulatory obligations, Clinvya may delete, anonymize, or block the data in accordance with the Retention Policy.

Security incidents

In the event of a security incident involving data processed on the platform, Clinvya will reasonably cooperate with the Customer in the investigation, containment, and applicable communication, subject to each party's roles under the LGPD and the procedures set out in the Terms of Use (clause 32.1).

The Customer undertakes to notify Clinvya without undue delay of incidents that may affect the security, privacy, integrity, or availability of the data, through the official channels.

Security and LGPD

We process data according to LGPD principles, with access controls, defined purposes, technical event records, permission separation, and security measures appropriate to the service. Additional details are described in the Security Policy.

Updates to this Policy

This Policy may be updated to reflect legal, regulatory, operational, product, or governance changes. The version and effective date indicated above identify the edition in force. When relevant changes are made, Clinvya may notify the Customer through the official channels.

Privacy and security contact

Questions about privacy, data protection, security, or AI governance can be sent to [email protected].

[email protected]