MediRec app
Privacy Policy
This policy explains how data is processed in the MediRec app for iOS and Android.
This policy specifically covers the MediRec mobile app. It supplements the platform’s data-protection policy, published at medirec.com.br/en/lgpd, which is the governing document and prevails in the event of any conflict.
1. Parties responsible for processing
The MediRec app, identified in app stores by the package name com.blp.medirec, is developed and maintained by 2BLP Futuro Ltda., CNPJ 57.899.732/0001-82.
For operations performed for municipalities, health departments, institutes and other contracting entities, the contracting institution acts as the controller of personal data and defines the purposes and processing instructions. 2BLP Futuro acts as the processor, processing data on behalf of the controller under the LGPD and the applicable contract.
2. Who may use the app
The app is intended exclusively for physicians, healthcare professionals, public servants and administrative workers authorized by a contracting institution. Accounts are created and managed by administrators; there is no open account registration or access for people outside contracting institutions.
3. Data processed
Depending on the enabled modules and the user’s responsibilities, the app may process:
- Professional data: name, professional contact details, institution, facility, team, access profile and authentication credentials.
- Technical and security data: IP address, app and operating-system versions, access logs, actions performed and audit trails.
- Citizen data: name, CNS or CPF, date of birth, contact details and other identifiers required for care.
- Sensitive personal health data: requests, referrals, tests, results, diagnostic hypotheses, clinical information and follow-up records.
- Documents and images: photographs or files selected by a professional for transcription, structured extraction and human validation.
- Tasks: tasks, assignees, comments, deadlines, attachments and change history used to coordinate professionals and administrative teams.
- Notifications, when enabled: technical device identifier, platform, preferences and records needed to deliver notices.
Citizen data is not provided by patients themselves. It is received from official health systems (such as those listed in section 7) or entered by authorized professionals and public servants of the contracting institution during care. Citizens do not have an account or access to the app. Processing therefore relies on the public-health legal bases described in section 4, rather than consent given by the data subject in the app.
4. Purposes and legal bases
Data is processed to authenticate users, manage permissions, protect the service, maintain audit records, organize public-health workflows and support the contracting institution’s duties.
The app also lets professionals photograph or select documents so their content can be transcribed and organized — as described in AI-assisted document transcription — and provides the Tasks module to coordinate work among physicians and administrative personnel.
The controller determines the applicable legal bases, which may include execution of public policies, protection of health, compliance with legal or regulatory obligations, and performance of a contract under Articles 7 and 11 of the LGPD. Consent is not used as the legal basis when processing results from institutional or public-health obligations.
5. Device features and permissions
- Camera, photos and files: used only when a professional chooses to capture or select a document for transcription and organization.
- Notifications, when enabled: used for operational notices related to the user’s work. Messages should avoid displaying identifiable clinical data on the lock screen.
Refusing a permission disables only the feature that depends on it. The app does not access the camera, photos or files without a user action.
6. AI-assisted document transcription
The app provides an optional document-transcription and structured-extraction feature. When a professional photographs or selects a document, an artificial-intelligence service processes its content to generate a transcription and organize the information into structured fields.
This processing uses the Google Gemini Flash 2.5 model through a multiregional Google Cloud endpoint with Zero Data Retention enabled. The model provider does not retain content submitted for transcription after processing. The model also operates under Section 17 (Training Restriction) of Google Cloud’s Service Specific Terms, which prohibits using the data to train or tune models. The international-transfer implications are described in section 8.
A healthcare professional always reviews and validates the transcription before use. No automated decision produces legal effects or significantly affects a data subject without human intervention, in accordance with Article 20 of the LGPD.
7. Sharing and service providers
Authorized professionals of the controller may access the data, and it may be shared with official systems or providers required for the contracted workflow, including SISREG, SER, GAL, SISCAN, SINAN and eSUS, always according to user permissions and the controller’s instructions.
2BLP uses infrastructure and processing providers, particularly Google Cloud as a contractually bound subprocessor subject to equivalent confidentiality and data-protection obligations. When notifications are enabled, Apple and Google delivery services may receive technical identifiers and the minimum content required to deliver a message. Processing outside Brazil is described under International data transfers. 2BLP does not sell personal data.
The app does not use third-party analytics, crash-monitoring or advertising SDKs, nor advertising identifiers. The technical and audit records described in section 3 are generated by the platform itself for security and operational purposes and are not shared for behavioral analytics or advertising.
8. International data transfers
Platform data is stored in Google Cloud data centers located in Brazil (the São Paulo southamerica-east1 region).
Certain processing operations may occur on multiregional Google Cloud infrastructure. This includes AI-assisted transcription using Google Gemini Flash 2.5 in a multiregional environment with Zero Data Retention enabled. In addition, when notifications are enabled, Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM) may process technical identifiers and the minimum message content on infrastructure outside Brazil.
These international transfers follow Articles 33 onward of the LGPD and rely on contractual data-protection clauses with providers and confidentiality and security safeguards compatible with Brazilian law. 2BLP limits transferred data to the minimum required for each purpose.
9. Retention, account deletion and elimination
Retention
Data is kept for the period required for public-health purposes, legal and regulatory obligations, periods established by the controller, and preservation of audit trails. Certain records — particularly clinical records and audit trails — are retained due to legal or regulatory requirements or for the regular exercise of rights, even after the corresponding access account is closed.
Account and data deletion
MediRec accounts are created and managed by contracting institutions; open registration is not available. Professionals wishing to delete their access account and associated data may submit a request through either of these channels:
- the administrator of their institution; or
- 2BLP’s Data Protection Officer at dpo (at) 2blp.com.
Once a request is received, the access account and associated personal data are effectively deleted — not merely deactivated or suspended — from the applicable environments, generally within 30 days. Only data that must be retained by law, regulation or for the regular exercise of rights remains stored, as described above.
Deleting an access account does not automatically eliminate clinical records and audit trails belonging to the controller. Elimination of those records requires a determination by the controlling institution. Data subjects may submit their request through the healthcare facility, health department or institution responsible for their care.
10. Security
Technical and administrative measures proportionate to risk are adopted, including HTTPS-protected traffic, encryption at rest, role-based access controls, segregation between institutions, audit records and restricted technical access.
No system is completely immune to incidents. If an event may pose a relevant risk to data subjects, 2BLP notifies the controller so the appropriate measures can be taken, including notifications required by the LGPD.
11. Rights and requests
Data subjects may exercise the rights provided by the LGPD, including confirmation of processing, access, correction, information about sharing and, when applicable, anonymization, blocking, portability or elimination.
Patients and citizens should submit requests to the healthcare facility, health department or institution responsible for their care. Professionals may request registration corrections from their institution’s administrator or 2BLP’s DPO. Changes to or elimination of clinical data depend on the controller’s decision.
12. Children’s and adolescents’ data
The app is not intended for use by children or adolescents. Authorized professionals may nevertheless process minors’ health data when necessary to provide healthcare or execute public policies, under the controller’s responsibility and in accordance with applicable law.
13. Changes to this policy
This policy may be updated to reflect legal, contractual or functional changes. The effective version date appears at the end of this page. When a material change requires additional notice, 2BLP and the controlling institution will use the appropriate channels.
14. Contact
Questions about privacy and data protection may be sent to the Data Protection Officer of 2BLP Futuro Ltda., formally appointed through Internal Resolution No. 01/2026, dated January 12, 2026:
For requests concerning medical records, clinical data, deletion or correction of data maintained by a public institution, contact the healthcare facility, health department or controlling institution responsible.
Version 2.0 · Last updated: September 1, 2026.