Privacy
How GSAÚDE processes personal and health data under Brazilian data protection law (LGPD, Law 13.709/2018). Last update: August 2026.
1. Roles
The client healthcare institution is the controller of patient and staff data. GSAÚDE acts as processor, handling data only to deliver the contracted service and following the controller's instructions.
2. Data processed
Identification and contact data, insurance data, encounter data and clinical data recorded by the institution's staff, plus system access logs.
3. Purpose
Running the institution's scheduling, records, billing, finance, inpatient care, shift rosters and reports. We never sell, rent or transfer data to third parties.
4. Legal basis
Performance of a contract, compliance with legal and regulatory obligations and, for health data, protection of health in procedures carried out by health professionals and health services.
5. Security
Data hosted in Brazil, encrypted traffic, role-based access, individual passwords, audit logs of views and changes and a daily backup routine.
6. Retention and deletion
Data is kept for the period required by medical record retention law and by contract. When the contract ends, the controller receives its data and we agree on secure deletion.
7. Data subject rights
Confirmation of processing, access, correction, portability, information about sharing and withdrawal of consent where applicable. Requests should be sent to the institution where the person is treated; we support the institution in answering.
8. Sub-processors
We use strictly necessary infrastructure, email and messaging providers, bound by equivalent confidentiality and security obligations.
9. Incidents
In case of a relevant security incident we notify the controller with the information needed to assess and report it to the authority and the data subjects.
10. Data protection officer
privacidade@gsaude.net · +55 55 9692-3065.