Duologa

Privacy Policy

September 7, 2026 · v2026-09.1

Duologa recognizes that information relating to health, private life and psychological or therapeutic care requires a high degree of protection.

This Policy explains how CONVERSAÇÕES INSTITUTO DE FACILITAÇÃO DE DIÁLOGOS LTDA, registered under CNPJ No. 08.867.260/0001-70, headquartered at R. Professor Alonso Ferraz, 81 — Ribeirão Preto/SP, Brazil, ZIP 14025-530, processes personal data relating to the Duologa website and platform.

This Policy should be read together with the Terms of Use, the contracts entered into with subscribers and, where applicable, the relevant data processing agreement.

1. Who this Policy applies to

This Policy applies to data of:

2. Duologa’s roles in processing

Duologa’s role varies according to the operation performed.

2.1 Duologa as controller

Duologa acts as controller when it decides the purposes and essential means relating to:

2.2 Duologa as processor

Duologa acts predominantly as processor when it processes, on behalf of a Professional or Organization:

In these situations, the Professional or the Organization is the controller and defines the purpose, the legal basis, the data entered, the professional retention periods, the authorized persons and the instructions for correction, export or deletion.

Requests relating to Clinical Data may need to be forwarded to the respective Professional or Organization.

3. Data we may process

3.1 Data of professionals and administrators

We may process:

3.2 Client data

Depending on the information entered by the Professional, we may process:

Duologa does not require the Professional to enter all of this data. The Professional must limit collection to what is necessary for their activity.

3.3 Remote session data

Where a remote session is held, we may process:

3.4 Technical and browsing data

We may process:

3.5 Data obtained from integrations

When the user connects external services, we may receive, according to the permissions granted:

Duologa seeks to request only the permissions necessary for the integration to work.

4. How we obtain the data

Data may be obtained:

5. Purposes and legal bases

Duologa processes personal data for the purposes and on the grounds usually indicated below, without prejudice to other grounds legally applicable to the specific case.

5.1 Registration, authentication and account

Purposes: create, administer and protect the account, control permissions and enable access to the Platform.

Grounds usually applicable: performance of contract, preliminary procedures, legitimate interest and compliance with a legal obligation.

5.2 Subscription, charging and billing

Purposes: process payments, issue tax documents, control non-payment and render accounts.

Grounds usually applicable: performance of contract and compliance with a legal obligation.

5.3 Service and support

Purposes: respond to requests, solve problems and record the support history.

Grounds usually applicable: performance of contract and legitimate interest.

5.4 Security and fraud prevention

Purposes: protect accounts, data subjects and infrastructure, investigate events and prevent unlawful uses.

Grounds usually applicable: legitimate interest, compliance with a legal obligation and regular exercise of rights.

5.5 Operational communications

Purposes: provide information about the account, security, billing, maintenance and contractual changes.

Grounds usually applicable: performance of contract and compliance with a legal obligation.

5.6 Commercial communications

Purposes: present Duologa’s own features and offers.

Grounds usually applicable: consent or legitimate interest, depending on the context, always with an opt-out option.

5.7 Clinical Data

Purposes: run the features requested by the controller, such as clinical records, calendar, storage, transcription, summarization and draft generation.

Ground: the instructions of the Professional or the Organization and the legal basis defined by the controller under the LGPD, including the grounds applicable to sensitive personal data.

5.8 Recording, transcription and international transfer

Purposes: record the session when requested, convert audio into text, organize records and produce auxiliary materials for professional review.

Grounds: specific consent for recording and transcription; while that mechanism is in place, specific and prominent consent for the international transfer; and other grounds legally applicable to the controller.

5.9 Application logs

Purposes: security, audit and compliance with the Brazilian Internet Civil Framework.

Grounds usually applicable: compliance with a legal obligation and legitimate interest.

5.10 Defense of rights

Purposes: produce evidence and respond to judicial, administrative or arbitral proceedings.

Ground: regular exercise of rights.

Legitimate interest will not be used as a standalone ground to exploit Clinical Data for advertising, commercial profiling or purposes incompatible with the care provided.

6. Sensitive personal data

Health-related data is classified by the LGPD as sensitive personal data.

Duologa processes such data only when:

Duologa does not sell Clinical Data and does not use health information for targeted advertising.

7. Artificial intelligence and automated processing

Duologa may provide features to:

These features do not replace human analysis. Duologa does not attribute to the generated results the value of a diagnosis, prescription, psychological assessment, clinical decision or professional document.

The Professional must review, correct and validate any result before using it.

7.1 Prohibition of training with Clinical Data

Audio, recordings, transcripts, clinical records and other Clinical Data will not be used by Duologa to train general or shared AI models.

The transcription feature will only be made available where the vendor’s account, plan, region and settings prevent the content from being used for:

Duologa will keep evidence of the applicable configuration or opt-out confirmation. Free accounts or settings that do not allow those uses to be prevented will not be used for therapeutic sessions or other clinical content.

Effectively anonymized data may only be used for security, performance evaluation and technical improvement where there is no reasonable possibility of identifying or re-identifying the people involved.

8. Recordings and transcripts

Recording and transcription of sessions are optional and remain disabled by default.

Before they are enabled, participants will receive specific information about the purpose, categories of data, automated processing, sharing with a vendor, international transfer, retention, security and withdrawal.

Acceptance of this Policy does not replace the specific authorization for recording, transcription and international transfer.

Refusal does not prevent the session from being held without recording and without transcription, except for specific modalities previously chosen and disclosed.

8.1 Data processed

Recording and transcription may involve:

8.2 Purposes

The data may be processed to:

Automated transcription may contain errors and will only become part of a professional record after review and validation by the Professional.

9. AssemblyAI as transcription vendor

To convert audio into text, Duologa currently uses AssemblyAI Inc., a company headquartered in the United States acting as a data subprocessor.

The categories of information shared may include:

AssemblyAI must process the data only in accordance with Duologa’s instructions and for the purpose of providing the transcription service.

Duologa will require, contractually and technically, that AssemblyAI and its subprocessors:

9.1 Retention at the vendor

Files sent for transcription will be configured for the shortest retention period technically available and compatible with the plan and settings adopted.

After processing is completed and technically verified, Duologa will request or execute the deletion of temporary files, intermediate transcripts and artifacts held by the vendor, except for minimum metadata required for billing, security, fraud prevention or legal compliance.

A copy of the recording will only be retained at Duologa where that feature has been expressly enabled by the Professional and disclosed to the participants.

10. International transfer relating to transcription

The use of AssemblyAI involves an international transfer of data to the United States, including voice, the content of what is said and possible sensitive personal data relating to health.

The purpose of the transfer is to temporarily receive the audio, process the voice, generate the transcript, make the result available to Duologa, provide technical support and carry out security and deletion measures.

10.1 Mechanism currently adopted

Until another contractual mechanism is implemented and disclosed, the international transfer will be carried out on the basis of the data subject’s specific and prominent consent, presented separately from the other authorizations and containing prior information about:

Refusal of the international consent will prevent the audio from being sent to AssemblyAI and, consequently, the use of automated transcription, without preventing the session from being held without that feature.

10.2 Migration to a contractual mechanism

Duologa may incorporate into the contracts with the importer the standard contractual clauses approved by the Brazilian National Data Protection Authority, or adopt another mechanism provided for in the LGPD and applicable regulations.

When that happens, this Policy will be updated to identify the mechanism actually used. Specific consent for recording and transcription will continue to be collected where necessary, even if it ceases to be the legal mechanism for the international transfer.

10.3 Essential transfer information

The updated list of subprocessors, countries and services used will be kept on a dedicated Duologa page or made available on request.

11. Data sharing

11.1 With the Professional or the Organization

Persons authorized by the controller may access the data according to their profiles and permissions.

11.2 With service providers

We may use vendors for:

These vendors must be subject to confidentiality, security and purpose-limitation obligations.

11.3 With integrations chosen by the user

When the user enables an integration, data may be sent to the selected service. Processing carried out directly by the third party will be subject to that third party’s privacy policy.

11.4 With authorities

Data may be provided where necessary to comply with the law, respond to a valid order, protect rights, prevent fraud, investigate an incident, protect life or physical integrity, or cooperate with a competent authority.

Whenever legally possible, Duologa will limit disclosure to what is strictly necessary.

11.5 Corporate transactions

In the event of a merger, acquisition, investment, reorganization or transfer of assets, data may be shared under confidentiality duties and continuity of the protections set out in this Policy.

11.6 Meta Platforms (WhatsApp Business Platform) as messaging vendor

When the Organization or the Professional activates the WhatsApp module, Duologa sends and receives messages through the WhatsApp Business Platform, a service of Meta Platforms, Inc. (United States) and its affiliates, acting as a technology provider (Tech Provider) authorized by the holder of the WhatsApp Business account.

The WhatsApp Business account, the phone number and the commercial relationship with Meta belong to the Organization or the Professional, who accepts Meta’s terms and policies when connecting the line. Duologa receives only the authorization needed to operate the line on the holder’s behalf, which may be revoked at any time, on the platform itself or with Meta.

The categories of data exchanged between Duologa and Meta may include:

Outbound messages — appointment confirmations and billing reminders — are only sent with the Client’s valid communication consent, recorded and revocable. Messages received on the Client’s own initiative are handled as administrative service.

The WhatsApp channel is operational and is not part of the clinical record: Duologa does not use the content of those conversations in artificial-intelligence analyses nor incorporates it into the clinical record, and advises that clinical information not be sent through this channel.

Processing carried out by Meta itself is subject to Meta’s and WhatsApp Business’s privacy policies and terms. The credential that authorizes Duologa to operate the line is stored encrypted and is never exposed to the browser or to third parties.

11.7 International transfer relating to WhatsApp

Use of the WhatsApp Business Platform involves the international transfer of data to the United States and to the other countries where Meta maintains infrastructure, covering phone number or user identifier, message content and delivery metadata.

Refusal or revocation of the communication consent prevents further sends through WhatsApp, without prejudice to the other contact channels and to the service itself.

12. Retention periods

Data will be retained for as long as necessary for the purpose, the performance of the contract, the controller’s instructions or compliance with legal obligations.

As a general rule:

The Professional is responsible for exporting and keeping records subject to professional, ethical or legal retention periods.

Duologa may retain data for an additional period where there is a legal obligation, an order from an authority, an investigation, litigation, the regular exercise of rights or a demonstrated security need.

13. Account termination and deletion

The Subscriber may request the termination of the account and must export in advance the data they need to keep.

After termination:

  1. the account may remain in restricted mode during the export window;
  2. the data will be deleted from active systems after the disclosed period;
  3. residual copies may temporarily remain in backups;
  4. data required for legal compliance or the defense of rights will be segregated and subject to restricted access.

Deleting the professional account does not necessarily mean the immediate deletion of all records where there is a legal ground for preservation.

14. Data subject rights

Under the LGPD, the data subject may request, as applicable:

The request may require confirmation of the requester’s identity.

14.1 Requests relating to Clinical Data

Where Duologa acts as processor, the request must be decided by the Professional or the controlling Organization.

Duologa may forward the request to the controller, identify who the controller is, provide technical assistance and preserve the data until valid instructions are received.

Duologa may not alter or delete clinical records on its own initiative when acting as processor.

14.2 Withdrawal of consent for recording and transfer

Withdrawal will prevent future recordings, transcriptions and transfers associated with the data subject.

Withdrawal does not invalidate processing lawfully carried out before it was expressed and does not automatically require the deletion of records that must be kept due to a legal obligation, professional rule or the regular exercise of rights.

14.3 Channel for requests

Requests may be sent to contato@conversacoes.com.br.

The request must contain enough information to locate the data and confirm that the request is legitimate.

15. Children and adolescents

Professional accounts are not intended for people under 18.

Data of children or adolescents must only be entered by a Professional, Organization or authorized guardian, observing the best interest, full protection, evolving autonomy, professional rules, the guardian’s participation where required, data minimization and reinforced access controls.

Where a child or adolescent accesses the Platform directly, Duologa and the controller must adopt adequate mechanisms for information, protection and, where necessary, age verification or representation.

Data of minors will not be used for behavioral advertising or for building commercial profiles.

16. Cookies and similar technologies

Duologa may use:

16.1 Essential cookies

Necessary for authentication, security, session maintenance, basic preferences and the operation of the Platform.

16.2 Analytics cookies

Used to measure performance and understand how the website is used. Where required, they depend on consent.

16.3 Functional cookies

Used to remember preferences and enable integrations.

16.4 Marketing cookies

Where used on the institutional website, they depend on the choices presented in the cookie manager.

The authenticated area intended for clinical records and Clinical Data must not use health information for advertising or behavioral tracking.

17. Commercial communications

Duologa may send information about its own products, subject to the applicable legal basis.

The recipient may opt out of commercial communications at any time.

Messages about security, billing, contractual changes or account operation will continue to be sent while necessary for providing the service.

Clinical Data will not be used to target commercial campaigns.

18. Security

Duologa adopts technical and administrative measures proportionate to the nature and risks of the processing, including, as applicable:

No system is absolutely invulnerable. Users must also protect their accounts, devices and environments.

Suspected incidents must be reported immediately to contato@conversacoes.com.br.

19. Security incidents

Duologa will assess incidents involving personal data and take measures to contain the event, investigate its causes, reduce harm, preserve evidence, fix vulnerabilities, inform affected controllers, cooperate with authorities and support communications to data subjects.

When acting as processor, Duologa will notify the controller without undue delay.

When acting as controller and the incident may entail relevant risk or harm, it will make the communications required by the LGPD and by the regulations of the Brazilian National Data Protection Authority within the applicable deadlines.

20. Automated decisions

AI Features intended for records, summaries or documents produce assistive content and must not generate autonomous clinical decisions.

Duologa may use automated mechanisms for security, fraud detection or account protection.

Where a decision taken solely by automated means produces a relevant effect on the data subject, they may request a review and information about the criteria used, subject to commercial and industrial secrecy.

21. Data Protection Officer and privacy contact

Up-to-date information about the Data Protection Officer will also be available on the Duologa website.

22. Changes to this Policy

This Policy may be updated to reflect legal or regulatory changes, new features, changes of vendors, security improvements or changes in processing operations.

Relevant changes will be communicated through an appropriate means.

Where a new purpose depends on consent, Duologa will request specific authorization before starting the processing.

23. Applicable law

This Policy will be interpreted under Brazilian law, in particular the General Personal Data Protection Law, the Internet Civil Framework, the Consumer Protection Code where applicable, telehealth legislation, the Child and Adolescent Statute, the rules of the respective professional councils and the regulations of the Brazilian National Data Protection Authority.

Terms of Use · Data deletion instructions