Skip to main content

Privacy Policy

TranscriMed Developer Portal Data Protection Policy

Version 1.2 • Last updated: 2026-07-25

1. Introduction

TranscriMed Tecnologia em Saúde Ltda. ("TranscriMed", "we", "our") is committed to protecting the privacy and security of personal data processed through our Developer Portal and API services. This Privacy Policy explains how we collect, use, share, and protect information when you use our developer services.

This policy complies with the Brazilian General Data Protection Law (LGPD - Lei Geral de Proteção de Dados, Law No. 13,709/2018) and other applicable data protection regulations.

2. Data Controller Information

Company: TranscriMed Tecnologia em Saúde Ltda.

Data Protection Officer (DPO):
EDUARDO DOS SANTOS LOPES — privacidade@transcrimed.com.br

Address: São Paulo, SP, Brazil

3. Information We Collect

3.1 Developer Account Information

  • Name and email address
  • Company/organization name
  • Application name and description
  • OAuth client credentials (client ID, encrypted secrets)
  • Redirect URIs and webhook endpoints

3.2 API Usage Data

  • API request logs (endpoints, timestamps, response codes)
  • Rate limiting and quota usage
  • Error logs and debugging information
  • Performance metrics and latency data

3.3 OAuth Authorization Data

  • Authorized scopes and permissions
  • Doctor consent records
  • Access token metadata (not the tokens themselves)
  • Authorization timestamps and IP addresses

3.4 Medical Data Flow

Through our API, partners may transmit:

  • Patient identifiers and demographics (encrypted)
  • Exam and procedure information
  • Medical worklist items
  • Generated medical documents

Note: TranscriMed acts as a data processor for medical data. Healthcare providers remain the data controllers.

4. Legal Basis for Processing

We process personal data based on the following legal grounds under LGPD:

  • Contract Performance:: To provide API services and maintain developer accounts
  • Legitimate Interests:: For security, fraud prevention, and service improvement
  • Legal Compliance:: To meet regulatory requirements in healthcare
  • Consent:: For optional services and marketing communications
  • Vital Interests:: In emergency medical situations (rare cases)

5. How We Use Information

  • Provide and maintain API services
  • Authenticate and authorize API requests
  • Monitor usage and enforce rate limits
  • Detect and prevent fraud or abuse
  • Generate usage analytics and billing
  • Provide technical support
  • Comply with legal obligations
  • Improve our services and develop new features

6. Data Sharing and Disclosure

We share information only in these circumstances:

  • With authorized doctors:: Based on OAuth consent for medical data access
  • Service providers:: Cloud infrastructure, monitoring, and security services
  • Legal requirements:: When required by law or court order
  • Business transfers:: In case of merger or acquisition (with notice)
  • With consent:: When you explicitly authorize sharing

We NEVER sell personal data to third parties.

7. Data Security

We implement comprehensive security measures including:

  • Encryption in transit and at rest
  • TLS 1.2+ for all API communications
  • Regular security audits and penetration testing
  • Access controls and authentication (OAuth 2.0)
  • Audit logging and monitoring
  • Incident response procedures
  • Employee training on data protection
  • Data minimization and pseudonymization

8. Data Retention

We retain data according to these policies:

  • Developer accounts:: Active duration plus 1 year after closure
  • API logs:: 90 days for debugging, aggregated data for 2 years
  • Clinical documents:: controller instructions, contract, legal hold, and the disclosed deletion lifecycle
  • Consent records:: Duration of consent plus 5 years
  • Security logs:: 2 years

9. International Data Transfers

Data may be processed in countries outside Brazil. We ensure adequate protection through:

  • Standard contractual clauses approved by ANPD
  • Adequacy decisions for compatible jurisdictions
  • Specific consent when required
  • Technical safeguards (encryption, access controls)

10. Your Rights (LGPD)

Under LGPD, you have the right to:

  • Access:: Request a copy of your personal data
  • Correction:: Update inaccurate or incomplete data
  • Deletion:: Request erasure of unnecessary data
  • Portability:: Receive data in a structured format
  • Information:: Know how and why we process your data
  • Consent withdrawal:: Revoke consent at any time
  • Opposition:: Object to certain processing activities
  • Review:: Request human review of automated decisions

To exercise these rights, contact: privacidade@transcrimed.com.br

11. Cookies and Tracking

The Developer Portal uses:

  • Essential cookies:: For authentication and security
  • Analytics cookies:: To improve our services (with consent)
  • No third-party advertising cookies:No third-party advertising cookies

You can manage cookies through your browser settings.

12. Children's Privacy

Our services are not directed to individuals under 18. We do not knowingly collect data from minors. If you believe a minor has provided data, please contact us immediately.

13. Data Breach Notification

In case of a data breach that may cause risk to your rights:

  • As controller, we will notify ANPD and affected subjects within the applicable three-business-day period
  • As operator, we will notify the controller without unjustified delay
  • We will provide information about the incident and mitigation steps
  • We will document all breaches in our internal register

14. Changes to This Policy

We may update this policy periodically. We will notify you of significant changes via email and the Developer Portal. Continued use after changes indicates acceptance of the updated policy.

15. Contact Us

Data Protection Officer (DPO):
EDUARDO DOS SANTOS LOPES — privacidade@transcrimed.com.br

General Inquiries:
Email: developers@transcrimed.com.br

ANPD (Brazilian Data Protection Authority):
Website: www.gov.br/anpd

16. Compliance Certifications

TranscriMed maintains compliance with:

  • LGPD - Lei Geral de Proteção de Dados
  • CFM - Conselho Federal de Medicina guidelines
  • ISO 27001 - Information Security Management (in progress)
  • Contractual and legal requirements applicable to each controller