Legal

Privacy Policy

Current version 2026-07-21.br-pf-v1, for the Brazilian operation. The full, official document, with complete supplier identification, is presented and accepted inside the app at sign-up.

1. Who is responsible for the service

FROID's supplier is responsible for the activities inherent to sign-up, security, billing, support, and platform operation. The professional or clinic decides the clinical purposes and the composition of their patients' records — controller and processor roles depend on each operation actually performed.

2. Data processed

The service may process sign-up, authentication, scheduling, payments, access and audit logs, voice, image, facial signals, acoustic metrics, transcription, patient and professional speech context, notes, reports, and session history.

3. How processing happens

Part of the metrics are calculated in the browser. In remote sessions, audio and video are transmitted over the internet and may use a TURN server. Audio segments may be sent to the backend and to a transcription provider. Transcripts, reports, and authorized records may be stored on FROID's infrastructure. Details in Security.

4. Providers and international transfer

FROID may use hosting infrastructure in Estonia and providers for payments, transcription, artificial intelligence, email, and calendaring. This may involve international data transfer, protected by the applicable contractual and technical mechanisms.

5. Purposes and legal bases

Data is used to run the contracted service, protect accounts and sessions, process payments, meet legal obligations, support healthcare activity by a licensed professional, and fulfill specific authorizations. Research and the anonymous Data-Froid require data previously approved through the anonymization process and, when applicable, optional patient authorization.

6. Retention and deletion

Retention considers purpose, contract, security, and professional or legal obligations. Deletion requests are reviewed and may result in deletion, anonymization, blocking, or restricted, justified retention. We do not promise automatic deletion on a fixed timeline when a legitimate retention obligation exists.

Irreversibility: once permanent deletion is processed, the deleted data cannot be recovered — not by FROID, not by the professional, not by the data subject themselves.

7. Data subject rights

The patient can request confirmation, access, correction, information about sharing, portability where applicable, objection, consent revocation, and anonymization, blocking, or deletion in the legal circumstances. Requests can be made through the Patient Portal or the privacy contact listed in the app, and receive documented review.

8. Security

FROID uses per-organization segregation (multitenant isolation and RLS), access control, audit trails, encryption of clinical records, and protected, verified backups. No system eliminates risk entirely; relevant incidents are assessed and communicated as required by applicable law.