Skip to content
Menu

Privacy Policy

Last updated: 25 September 2026 · This is a translation for reference; the Portuguese version prevails.

This policy describes how Ybyata Growth Operations Ltda (CNPJ 68.452.751/0001-82, "Ybyatã") handles personal data on the ybyata.com site and on the Ybyatã platform, in accordance with Brazil's General Data Protection Law (Law No. 13,709/2018, the LGPD).

Who decides about the data

  • A clinic's patients and contacts: the clinic that uses Ybyatã is the controller of this data; it decides what it is processed for and for how long. Ybyatã is the processor: it processes this data on the clinic's behalf, following the clinic's instructions and the contract between them.
  • Clinic teams, Ybyatã's clients and visitors to this site: here Ybyatã is the controller of platform sign-in, billing and contact data.

What data the platform processes

On behalf of each clinic, depending on what the clinic uses:

  • WhatsApp conversations with contacts and patients: phone number, profile name, messages, photos, voice notes and documents.
  • Schedule: appointments, confirmations and attendance.
  • Clinical record: patient identification, assessments and progress notes, dictations, practitioners' electronic signatures, consents and documents issued (medical certificates and statements).
  • Sales and payments: what was purchased, amounts, payment status and, when provided, the payer's e-mail.
  • Where contacts came from: which ad or page the person came from (click identifiers, page parameters, the IP address and browser of whoever fills in a clinic's form).
  • Forms and consents: what the person submitted and which text they agreed to.
  • Bank statements the clinic imports to record expenses.

Part of this data is health data, which is sensitive data (LGPD, art. 5, II). It is processed for the protection of health, by a health service (art. 11, II, f), and, for the clinical record, to comply with the legal obligation to keep it (art. 11, II, a).

As controller, Ybyatã processes the data of those who sign in to the platform (name, e-mail, clinic, role, professional registration of those who sign clinical records), the access records required by the Marco Civil da Internet (who, when, from where) and the billing data of client clinics.

Artificial intelligence

The platform uses language models (Google's Gemini, through Vertex AI) to summarize and classify conversations, transcribe voice notes and dictations, suggest replies and read statements. These models run on Google Cloud infrastructure in São Paulo. AI suggestions are reviewed by the clinic's team before anything is sent. The technical records of these calls are kept on Ybyatã's own server in São Paulo and deleted after 90 days.

Who we share with

  • Google Cloud: hosting, database, files and AI, in São Paulo.
  • Meta (WhatsApp): sending and receiving the clinic's messages.
  • Meta and Google (ads): to measure which ads bring patients, we send events such as "appointment booked" or "attended", with the click identifier. Phone and identifiers go only as hashes; conversation content and any health detail are never sent.
  • Mercado Pago: the clinic's charges and payments.
  • Clerk: sign-in for teams on the platform.
  • Cloudflare: protection against bots on forms and secure access to internal tools.

Some of these providers may process data outside Brazil, under the safeguards of LGPD art. 33. We never sell personal data.

For how long

  • Conversations, contacts, schedule and sales: while the clinic uses Ybyatã; deleted at the clinic's request or when it stops using the platform.
  • Clinical record: 20 years from the last entry (Law No. 13,787/2018, art. 6).
  • Access records: 6 months (Marco Civil da Internet, art. 15).
  • The platform's technical logs: 30 days; records of AI calls: 90 days.

How we protect it

  • Each clinic's data is isolated from the others' in the database itself.
  • Data and files stay in São Paulo, encrypted in transit and at rest; clinics' credentials are encrypted.
  • The clinical record is read only by those allowed to, and every read is recorded; signing requires a second authentication factor.
  • Ybyatã staff access to a clinic's data is read-only and recorded.
  • Security alerts and an incident response plan. If an incident may affect a clinic's data, we notify the clinic within 24 hours, so it can notify the ANPD and the data subjects within the legal deadline.

Your rights

Every data subject may ask for confirmation of processing, access, correction, anonymization, portability or deletion of their data, among the other rights in LGPD art. 18.

  • If you are a clinic's patient or contact, make your request to the clinic: it decides. If you write to us, we forward it to the clinic and do what it determines. Some data, such as the clinical record, must be kept by law.
  • For data Ybyatã controls, write to [email protected].

See also how to ask for data deletion.

Cookies and browser storage

The platform uses only what is needed to keep the session of whoever signs in. Clinics' landing pages keep in the browser where the visitor came from (ad, campaign), to attribute the contact correctly. This site does not use tracking cookies.

Data protection officer and contact

Ybyata Growth Operations Ltda · R. Pais Leme, 215, Conj. 1713, Pinheiros, São Paulo/SP, Brazil · [email protected]

Changes

This policy follows what the platform does. When it changes, the date at the top changes too; relevant changes are communicated to client clinics.