AUTHENTICATED GLOBAL PROTOCOL

KODEXMED · São Paulo, Brazil

Privacy Policy

Effective date: January 1, 2026 · LGPD Art. 9 · GDPR Art. 13 · HIPAA compliant

1. Data Controller

KODEXMED AUTHENTICATED GLOBAL PROTOCOL, constituted in São Paulo, Brazil, is the data controller responsible for processing your personal and clinical data on this platform. Contact: privacy@kodexmed.com

2. Data We Collect

We collect: identity data (full name, CPF/document, date of birth); contact data (email, phone in E.164 format); clinical data (health records, exam results, prescriptions); authentication data (encrypted credentials, session tokens); and device data (IP address, browser type) for security purposes.

3. Legal Basis for Processing (LGPD Art. 7)

We process your data based on: (i) explicit consent provided during registration; (ii) performance of contract (platform services); (iii) legitimate interest in platform security; and (iv) compliance with legal obligations under LGPD, GDPR, HIPAA, and ANVISA regulations.

4. Data Security

All clinical data is protected by SHA-256 cryptographic sealing. Files are encrypted at rest and in transit (TLS 1.3). Access is logged per LGPD Art. 37 and auditable at any time via your Document Vault Access History.

5. Your Rights (LGPD Art. 18 · GDPR Art. 15-22)

You have the right to: access your data; correct inaccurate data; delete your data (where legally permissible); port your data to another service; revoke consent at any time; and lodge a complaint with the ANPD (Brazil) or relevant EU supervisory authority.

6. Data Retention

Clinical records are retained for the minimum period required by Brazilian healthcare regulations (CFM Resolution 1.821/2007: 20 years for medical records). You may request deletion of non-clinical account data at any time via the platform settings.

7. International Transfers

Your data may be processed on servers located in the United States (Supabase infrastructure). All transfers comply with LGPD Chapter V international transfer requirements and appropriate safeguards are in place.

8. Cookies

We use strictly necessary cookies for authentication (session management) and locale preference. No advertising or tracking cookies are used. You may configure cookie preferences via your browser settings.

9. Contact & DPO

Data Protection Officer: privacy@kodexmed.com · KODEXMED · São Paulo, Brazil · For LGPD requests: lgpd@kodexmed.com · Response within 15 business days per LGPD Art. 18.

© 2026 KODEXMED · All Rights Reserved · São Paulo, Brazil