Privacy Policy
September 7, 2026 · v2026-09.1
Duologa recognizes that information relating to health, private life and psychological or therapeutic care requires a high degree of protection.
This Policy explains how CONVERSAÇÕES INSTITUTO DE FACILITAÇÃO DE DIÁLOGOS LTDA, registered under CNPJ No. 08.867.260/0001-70, headquartered at R. Professor Alonso Ferraz, 81 — Ribeirão Preto/SP, Brazil, ZIP 14025-530, processes personal data relating to the Duologa website and platform.
This Policy should be read together with the Terms of Use, the contracts entered into with subscribers and, where applicable, the relevant data processing agreement.
1. Who this Policy applies to
This Policy applies to data of:
- professionals;
- administrators and staff of clinics or organizations;
- Clients;
- participants in remote sessions;
- guest users;
- website visitors;
- business contacts;
- people who request support;
- legal representatives;
- vendors and partners.
2. Duologa’s roles in processing
Duologa’s role varies according to the operation performed.
2.1 Duologa as controller
Duologa acts as controller when it decides the purposes and essential means relating to:
- creation and administration of accounts;
- subscription and billing;
- authentication;
- fraud prevention;
- Platform security;
- service and support;
- contractual communication;
- analysis of how the product works;
- compliance with legal obligations;
- defense in proceedings;
- Duologa’s own commercial communication.
2.2 Duologa as processor
Duologa acts predominantly as processor when it processes, on behalf of a Professional or Organization:
- Client data;
- clinical records;
- psychological or therapeutic records;
- clinical notes;
- professional documents;
- recordings;
- transcripts;
- session summaries;
- attached files;
- information used in AI Features;
- calendar data related to care.
In these situations, the Professional or the Organization is the controller and defines the purpose, the legal basis, the data entered, the professional retention periods, the authorized persons and the instructions for correction, export or deletion.
Requests relating to Clinical Data may need to be forwarded to the respective Professional or Organization.
3. Data we may process
3.1 Data of professionals and administrators
We may process:
- name;
- CPF (Brazilian tax ID) or other document;
- date of birth;
- address;
- phone number;
- e-mail;
- photograph;
- profession;
- specialty;
- professional registration number;
- the organization they are linked to;
- tax data;
- plan and subscription information;
- payment history;
- preferences and settings;
- communications with support;
- credentials and authentication data.
3.2 Client data
Depending on the information entered by the Professional, we may process:
- name and preferred name;
- date of birth;
- identification document;
- contact details;
- address;
- legal guardian details;
- calendar information;
- care history;
- professional records;
- physical or mental health data;
- complaints, symptoms and reported history;
- family, social or professional information;
- documents and files;
- prescriptions or referrals entered by the Professional;
- recordings, transcripts and summaries;
- information relating to the progress of care.
Duologa does not require the Professional to enter all of this data. The Professional must limit collection to what is necessary for their activity.
3.3 Remote session data
Where a remote session is held, we may process:
- participants’ names;
- date and duration;
- IP address;
- technical connection data;
- device identifiers;
- audio and video quality;
- messages or files sent;
- audio or video, where recording has been authorized;
- transcript, where the feature is enabled.
3.4 Technical and browsing data
We may process:
- IP address;
- date and time of access;
- pages and features accessed;
- browser;
- operating system;
- device type;
- session identifiers;
- error logs;
- security events;
- authentication logs;
- cookies and similar technologies.
3.5 Data obtained from integrations
When the user connects external services, we may receive, according to the permissions granted:
- external account identification;
- calendar events;
- available time slots;
- meeting links;
- selected contacts;
- authorization tokens;
- payment identifiers;
- WhatsApp phone number or user identifier, profile name and message delivery status (WhatsApp module);
- information necessary for the requested integration.
Duologa seeks to request only the permissions necessary for the integration to work.
4. How we obtain the data
Data may be obtained:
- directly from the data subject;
- from the Professional or the Organization;
- from the account administrator;
- from a legal guardian;
- during a session;
- through authorized integrations;
- automatically, during use;
- from payment providers;
- from public sources, where necessary for professional validation or fraud prevention;
- through support or commercial relationship communications.
5. Purposes and legal bases
Duologa processes personal data for the purposes and on the grounds usually indicated below, without prejudice to other grounds legally applicable to the specific case.
5.1 Registration, authentication and account
Purposes: create, administer and protect the account, control permissions and enable access to the Platform.
Grounds usually applicable: performance of contract, preliminary procedures, legitimate interest and compliance with a legal obligation.
5.2 Subscription, charging and billing
Purposes: process payments, issue tax documents, control non-payment and render accounts.
Grounds usually applicable: performance of contract and compliance with a legal obligation.
5.3 Service and support
Purposes: respond to requests, solve problems and record the support history.
Grounds usually applicable: performance of contract and legitimate interest.
5.4 Security and fraud prevention
Purposes: protect accounts, data subjects and infrastructure, investigate events and prevent unlawful uses.
Grounds usually applicable: legitimate interest, compliance with a legal obligation and regular exercise of rights.
5.5 Operational communications
Purposes: provide information about the account, security, billing, maintenance and contractual changes.
Grounds usually applicable: performance of contract and compliance with a legal obligation.
5.6 Commercial communications
Purposes: present Duologa’s own features and offers.
Grounds usually applicable: consent or legitimate interest, depending on the context, always with an opt-out option.
5.7 Clinical Data
Purposes: run the features requested by the controller, such as clinical records, calendar, storage, transcription, summarization and draft generation.
Ground: the instructions of the Professional or the Organization and the legal basis defined by the controller under the LGPD, including the grounds applicable to sensitive personal data.
5.8 Recording, transcription and international transfer
Purposes: record the session when requested, convert audio into text, organize records and produce auxiliary materials for professional review.
Grounds: specific consent for recording and transcription; while that mechanism is in place, specific and prominent consent for the international transfer; and other grounds legally applicable to the controller.
5.9 Application logs
Purposes: security, audit and compliance with the Brazilian Internet Civil Framework.
Grounds usually applicable: compliance with a legal obligation and legitimate interest.
5.10 Defense of rights
Purposes: produce evidence and respond to judicial, administrative or arbitral proceedings.
Ground: regular exercise of rights.
Legitimate interest will not be used as a standalone ground to exploit Clinical Data for advertising, commercial profiling or purposes incompatible with the care provided.
6. Sensitive personal data
Health-related data is classified by the LGPD as sensitive personal data.
Duologa processes such data only when:
- it acts under the instructions of the Professional or the Organization;
- the processing is necessary for the contracted feature;
- a valid legal ground exists;
- safeguards proportionate to the risks are in place;
- access is limited to authorized persons.
Duologa does not sell Clinical Data and does not use health information for targeted advertising.
7. Artificial intelligence and automated processing
Duologa may provide features to:
- transcribe audio;
- summarize texts;
- organize records;
- suggest structures;
- improve clarity and formatting;
- support internal searches;
- generate document drafts;
- classify or relate information.
These features do not replace human analysis. Duologa does not attribute to the generated results the value of a diagnosis, prescription, psychological assessment, clinical decision or professional document.
The Professional must review, correct and validate any result before using it.
7.1 Prohibition of training with Clinical Data
Audio, recordings, transcripts, clinical records and other Clinical Data will not be used by Duologa to train general or shared AI models.
The transcription feature will only be made available where the vendor’s account, plan, region and settings prevent the content from being used for:
- training of general or shared models;
- benchmarking;
- advertising;
- building commercial profiles;
- development of the vendor’s or third parties’ products.
Duologa will keep evidence of the applicable configuration or opt-out confirmation. Free accounts or settings that do not allow those uses to be prevented will not be used for therapeutic sessions or other clinical content.
Effectively anonymized data may only be used for security, performance evaluation and technical improvement where there is no reasonable possibility of identifying or re-identifying the people involved.
8. Recordings and transcripts
Recording and transcription of sessions are optional and remain disabled by default.
Before they are enabled, participants will receive specific information about the purpose, categories of data, automated processing, sharing with a vendor, international transfer, retention, security and withdrawal.
Acceptance of this Policy does not replace the specific authorization for recording, transcription and international transfer.
Refusal does not prevent the session from being held without recording and without transcription, except for specific modalities previously chosen and disclosed.
8.1 Data processed
Recording and transcription may involve:
- voice;
- image, where video is recorded;
- participants’ names and identification;
- date and duration of the session;
- content of what is said;
- information about physical or mental health;
- family, social, professional or financial data mentioned during the session;
- technical metadata necessary for processing.
8.2 Purposes
The data may be processed to:
- produce the requested recording;
- convert audio into text;
- distinguish participants in the conversation, where the feature is available;
- organize records;
- create drafts and summaries;
- allow review by the Professional;
- store documents where that feature is enabled;
- maintain the security and traceability of the operation.
Automated transcription may contain errors and will only become part of a professional record after review and validation by the Professional.
9. AssemblyAI as transcription vendor
To convert audio into text, Duologa currently uses AssemblyAI Inc., a company headquartered in the United States acting as a data subprocessor.
The categories of information shared may include:
- audio file or stream;
- participants’ voices;
- content of what is said;
- technical identifiers of the request;
- parameters required for transcription;
- minimum processing metadata.
AssemblyAI must process the data only in accordance with Duologa’s instructions and for the purpose of providing the transcription service.
Duologa will require, contractually and technically, that AssemblyAI and its subprocessors:
- maintain confidentiality;
- adopt adequate security measures;
- limit processing to the contracted purpose;
- do not use the content for model training;
- do not perform benchmarking with the content;
- assist in responding to data subject rights;
- report security incidents;
- delete or return the data in accordance with the instructions received.
9.1 Retention at the vendor
Files sent for transcription will be configured for the shortest retention period technically available and compatible with the plan and settings adopted.
After processing is completed and technically verified, Duologa will request or execute the deletion of temporary files, intermediate transcripts and artifacts held by the vendor, except for minimum metadata required for billing, security, fraud prevention or legal compliance.
A copy of the recording will only be retained at Duologa where that feature has been expressly enabled by the Professional and disclosed to the participants.
10. International transfer relating to transcription
The use of AssemblyAI involves an international transfer of data to the United States, including voice, the content of what is said and possible sensitive personal data relating to health.
The purpose of the transfer is to temporarily receive the audio, process the voice, generate the transcript, make the result available to Duologa, provide technical support and carry out security and deletion measures.
10.1 Mechanism currently adopted
Until another contractual mechanism is implemented and disclosed, the international transfer will be carried out on the basis of the data subject’s specific and prominent consent, presented separately from the other authorizations and containing prior information about:
- the international nature of the operation;
- the main destination country;
- the identity and role of the vendor;
- the categories of data transferred;
- the purpose of the transfer;
- the possibility of withdrawal for future operations.
Refusal of the international consent will prevent the audio from being sent to AssemblyAI and, consequently, the use of automated transcription, without preventing the session from being held without that feature.
10.2 Migration to a contractual mechanism
Duologa may incorporate into the contracts with the importer the standard contractual clauses approved by the Brazilian National Data Protection Authority, or adopt another mechanism provided for in the LGPD and applicable regulations.
When that happens, this Policy will be updated to identify the mechanism actually used. Specific consent for recording and transcription will continue to be collected where necessary, even if it ceases to be the legal mechanism for the international transfer.
10.3 Essential transfer information
- Exporter: CONVERSAÇÕES INSTITUTO DE FACILITAÇÃO DE DIÁLOGOS LTDA
- Importer or subprocessor: AssemblyAI Inc.
- Main destination country: United States
- Service: audio processing and transcript generation
- Categories of data: voice, audio, content of what is said, possible health data and technical metadata
- Data subjects: Clients, professionals and other session participants
- Purpose: produce the transcript requested by the Professional
- Current mechanism: specific and prominent consent for international transfer
- Channel for rights: contato@conversacoes.com.br
The updated list of subprocessors, countries and services used will be kept on a dedicated Duologa page or made available on request.
11. Data sharing
11.1 With the Professional or the Organization
Persons authorized by the controller may access the data according to their profiles and permissions.
11.2 With service providers
We may use vendors for:
- cloud infrastructure;
- storage and backups;
- artificial intelligence;
- transcription;
- videoconferencing;
- sending e-mails and messages;
- messaging through the WhatsApp Business Platform (Meta);
- authentication;
- security;
- technical monitoring;
- payments;
- customer service;
- electronic signature;
- performance analysis.
These vendors must be subject to confidentiality, security and purpose-limitation obligations.
11.3 With integrations chosen by the user
When the user enables an integration, data may be sent to the selected service. Processing carried out directly by the third party will be subject to that third party’s privacy policy.
11.4 With authorities
Data may be provided where necessary to comply with the law, respond to a valid order, protect rights, prevent fraud, investigate an incident, protect life or physical integrity, or cooperate with a competent authority.
Whenever legally possible, Duologa will limit disclosure to what is strictly necessary.
11.5 Corporate transactions
In the event of a merger, acquisition, investment, reorganization or transfer of assets, data may be shared under confidentiality duties and continuity of the protections set out in this Policy.
11.6 Meta Platforms (WhatsApp Business Platform) as messaging vendor
When the Organization or the Professional activates the WhatsApp module, Duologa sends and receives messages through the WhatsApp Business Platform, a service of Meta Platforms, Inc. (United States) and its affiliates, acting as a technology provider (Tech Provider) authorized by the holder of the WhatsApp Business account.
The WhatsApp Business account, the phone number and the commercial relationship with Meta belong to the Organization or the Professional, who accepts Meta’s terms and policies when connecting the line. Duologa receives only the authorization needed to operate the line on the holder’s behalf, which may be revoked at any time, on the platform itself or with Meta.
The categories of data exchanged between Duologa and Meta may include:
- the recipient’s phone number or the user identifier assigned by Meta;
- the WhatsApp profile name of whoever sends messages to the line;
- the content of messages sent and received (confirmations, reminders and replies);
- message delivery and read status;
- technical identifiers of messages and of the account;
- quality indicators and line limits assigned by Meta.
Outbound messages — appointment confirmations and billing reminders — are only sent with the Client’s valid communication consent, recorded and revocable. Messages received on the Client’s own initiative are handled as administrative service.
The WhatsApp channel is operational and is not part of the clinical record: Duologa does not use the content of those conversations in artificial-intelligence analyses nor incorporates it into the clinical record, and advises that clinical information not be sent through this channel.
Processing carried out by Meta itself is subject to Meta’s and WhatsApp Business’s privacy policies and terms. The credential that authorizes Duologa to operate the line is stored encrypted and is never exposed to the browser or to third parties.
11.7 International transfer relating to WhatsApp
Use of the WhatsApp Business Platform involves the international transfer of data to the United States and to the other countries where Meta maintains infrastructure, covering phone number or user identifier, message content and delivery metadata.
- Exporter: CONVERSAÇÕES INSTITUTO DE FACILITAÇÃO DE DIÁLOGOS LTDA, on behalf of the Organization or the Professional holding the line
- Importer: Meta Platforms, Inc. and affiliates (WhatsApp)
- Main destination country: United States
- Service: sending and receiving messages through the WhatsApp Business Platform
- Data categories: phone number or user identifier, profile name, message content, delivery status and technical metadata
- Data subjects: Clients and other contacts who communicate with the line
- Purpose: appointment confirmations, billing reminders and administrative service through the Organization’s or the Professional’s line
- Mechanism: the Client’s communication consent, informed of the international nature of the transfer through this Policy, without prejudice to the adoption of standard contractual clauses under item 10.2
- Channel for rights requests: contato@conversacoes.com.br
Refusal or revocation of the communication consent prevents further sends through WhatsApp, without prejudice to the other contact channels and to the service itself.
12. Retention periods
Data will be retained for as long as necessary for the purpose, the performance of the contract, the controller’s instructions or compliance with legal obligations.
As a general rule:
- registration and contractual data: during the relationship and for up to five years after it ends, subject to longer applicable periods;
- tax and financial documents: for the period required by tax and accounting legislation;
- application access logs: for the minimum period required by the Brazilian Internet Civil Framework;
- security logs: for the period necessary for prevention, investigation and audit, normally up to 12 months;
- support requests: during the relationship and for up to two years after the request is closed;
- Clinical Data in an active account: according to the instructions and settings of the Professional or the Organization;
- Clinical Data after termination: available for up to 90 days for export and subsequently deleted from active environments;
- backups: deleted or overwritten in the technical cycles, normally within 90 days;
- temporary audio for transcription: for the shortest period technically necessary and according to the configuration contracted with the vendor;
- intentionally stored recordings: for the period configured by the Professional or until deletion;
- anonymized data: for as long as it remains effectively anonymous.
The Professional is responsible for exporting and keeping records subject to professional, ethical or legal retention periods.
Duologa may retain data for an additional period where there is a legal obligation, an order from an authority, an investigation, litigation, the regular exercise of rights or a demonstrated security need.
13. Account termination and deletion
The Subscriber may request the termination of the account and must export in advance the data they need to keep.
After termination:
- the account may remain in restricted mode during the export window;
- the data will be deleted from active systems after the disclosed period;
- residual copies may temporarily remain in backups;
- data required for legal compliance or the defense of rights will be segregated and subject to restricted access.
Deleting the professional account does not necessarily mean the immediate deletion of all records where there is a legal ground for preservation.
14. Data subject rights
Under the LGPD, the data subject may request, as applicable:
- confirmation that processing exists;
- access;
- correction;
- information about sharing;
- anonymization;
- blocking;
- deletion;
- portability, subject to regulation;
- information about the possibility of not providing consent;
- withdrawal of consent;
- objection to unlawful processing;
- review of decisions taken solely by automated means;
- information about the criteria used in automated decisions;
- to petition the Brazilian National Data Protection Authority.
The request may require confirmation of the requester’s identity.
14.1 Requests relating to Clinical Data
Where Duologa acts as processor, the request must be decided by the Professional or the controlling Organization.
Duologa may forward the request to the controller, identify who the controller is, provide technical assistance and preserve the data until valid instructions are received.
Duologa may not alter or delete clinical records on its own initiative when acting as processor.
14.2 Withdrawal of consent for recording and transfer
Withdrawal will prevent future recordings, transcriptions and transfers associated with the data subject.
Withdrawal does not invalidate processing lawfully carried out before it was expressed and does not automatically require the deletion of records that must be kept due to a legal obligation, professional rule or the regular exercise of rights.
14.3 Channel for requests
Requests may be sent to contato@conversacoes.com.br.
The request must contain enough information to locate the data and confirm that the request is legitimate.
15. Children and adolescents
Professional accounts are not intended for people under 18.
Data of children or adolescents must only be entered by a Professional, Organization or authorized guardian, observing the best interest, full protection, evolving autonomy, professional rules, the guardian’s participation where required, data minimization and reinforced access controls.
Where a child or adolescent accesses the Platform directly, Duologa and the controller must adopt adequate mechanisms for information, protection and, where necessary, age verification or representation.
Data of minors will not be used for behavioral advertising or for building commercial profiles.
16. Cookies and similar technologies
Duologa may use:
16.1 Essential cookies
Necessary for authentication, security, session maintenance, basic preferences and the operation of the Platform.
16.2 Analytics cookies
Used to measure performance and understand how the website is used. Where required, they depend on consent.
16.3 Functional cookies
Used to remember preferences and enable integrations.
16.4 Marketing cookies
Where used on the institutional website, they depend on the choices presented in the cookie manager.
The authenticated area intended for clinical records and Clinical Data must not use health information for advertising or behavioral tracking.
17. Commercial communications
Duologa may send information about its own products, subject to the applicable legal basis.
The recipient may opt out of commercial communications at any time.
Messages about security, billing, contractual changes or account operation will continue to be sent while necessary for providing the service.
Clinical Data will not be used to target commercial campaigns.
18. Security
Duologa adopts technical and administrative measures proportionate to the nature and risks of the processing, including, as applicable:
- access control;
- environment segregation;
- authentication;
- audit logs;
- encryption in transit;
- credential protection;
- backups;
- monitoring;
- vulnerability management;
- contractual confidentiality;
- incident response procedures;
- limitation of internal access;
- training of authorized persons.
No system is absolutely invulnerable. Users must also protect their accounts, devices and environments.
Suspected incidents must be reported immediately to contato@conversacoes.com.br.
19. Security incidents
Duologa will assess incidents involving personal data and take measures to contain the event, investigate its causes, reduce harm, preserve evidence, fix vulnerabilities, inform affected controllers, cooperate with authorities and support communications to data subjects.
When acting as processor, Duologa will notify the controller without undue delay.
When acting as controller and the incident may entail relevant risk or harm, it will make the communications required by the LGPD and by the regulations of the Brazilian National Data Protection Authority within the applicable deadlines.
20. Automated decisions
AI Features intended for records, summaries or documents produce assistive content and must not generate autonomous clinical decisions.
Duologa may use automated mechanisms for security, fraud detection or account protection.
Where a decision taken solely by automated means produces a relevant effect on the data subject, they may request a review and information about the criteria used, subject to commercial and industrial secrecy.
21. Data Protection Officer and privacy contact
- Data Protection Officer or responsible area: privacy and data protection area of CONVERSAÇÕES INSTITUTO DE FACILITAÇÃO DE DIÁLOGOS LTDA
- E-mail: contato@conversacoes.com.br
- Address: R. Professor Alonso Ferraz, 81 — Ribeirão Preto/SP, Brazil, ZIP 14025-530
Up-to-date information about the Data Protection Officer will also be available on the Duologa website.
22. Changes to this Policy
This Policy may be updated to reflect legal or regulatory changes, new features, changes of vendors, security improvements or changes in processing operations.
Relevant changes will be communicated through an appropriate means.
Where a new purpose depends on consent, Duologa will request specific authorization before starting the processing.
23. Applicable law
This Policy will be interpreted under Brazilian law, in particular the General Personal Data Protection Law, the Internet Civil Framework, the Consumer Protection Code where applicable, telehealth legislation, the Child and Adolescent Statute, the rules of the respective professional councils and the regulations of the Brazilian National Data Protection Authority.