Data protection
LGPD & privacy
This page gathers, publicly and accessibly, how MediRec processes personal data in compliance with Law No. 13,709/2018 (the LGPD — Brazil's General Data Protection Law).
This page consolidates, in plain language, the platform's data-protection posture. The formal, complete versions — Impact Report (RIPD/DPIA), Data Elimination Procedure and Data Processing Agreement — are maintained by the DPO and made available to partner controllers on request.
1.Controller and processor
MediRec is developed and maintained by 2BLP Futuro Ltda. (CNPJ 57.899.732/0001-82). In public health operations, the contracting public entity or institute acts as the controller of citizens' data, and 2BLP Futuro acts as the processor, processing data in the name of and per the instructions of the controller, under the contract and the LGPD.
Who's who in data processing. 2BLP is the processor — always acting on the controller's instructions.
2.Data Protection Officer (DPO)
2BLP Futuro formally appointed its Data Protection Officer through internal Resolution No. 01/2026, of January 12, 2026. Data-subject requests, questions and communications about data protection can be sent to the DPO — Data Protection Officer · 2BLP Futuro Ltda. · dpo (at) 2blp.com.
3.Data processed
In the context of clinical regulation and health management, MediRec may process, depending on each municipality's or institute's configuration:
- Citizen identification data: name, CNS/CPF, date of birth and contacts, where applicable.
- Health data (sensitive): referrals, requisitions, results and clinical follow-up information from the official systems.
- Professional and manager data: access credentials and platform usage records.
4.Purposes and legal basis
Data is processed to enable clinical regulation and management of the care network. The applicable legal bases include, as the case may be, the execution of public policies, the protection of health by health professionals and services, and compliance with a legal or regulatory obligation by the controller.
5.Where data lives
Processing occurs entirely on national territory. Infrastructure is hosted on Google Cloud Platform, in the Brazilian region (São Paulo), respecting data-residency requirements. There is no international transfer of personal data outside Brazil in the normal course of operation.
6.Artificial intelligence and human validation
MediRec uses an AI model (Google Gemini) strictly transactionally, with prompt engineering — without training models on citizens' data. The model operates under Section 17 (Training Restriction) of Google Cloud's Service Specific Terms, which prohibits using the data to train or tune models. Any cache operates only in memory, expiring in 24 hours.
As for decisions: no record advances without explicit human validation. AI supports clinical and regulatory work, but the decision is always a professional's, in line with Art. 20 of the LGPD.
7.Sharing and integrations
MediRec operates connected to official systems and to laboratories — SISREG, SER, GAL, SISCAN, SINAN Rio, eSUS, Científica Lab and Biomega — from which it receives and to which it sends information according to each one's flow. Each base remains the source of truth; MediRec neither reuses nor sells this data, and sharing occurs only for the purposes described and per the controller's instructions.
The infrastructure is operated by Google Cloud (Brazil region) as a sub-processor, bound by contract and subject to the same data-protection obligations. As detailed in section 6, the data is not used to train AI models.
8.Security measures
- Data encrypted at rest.
- Traffic protected by HTTPS/SSL.
- Server access restricted to authorized automations and designated technical staff, with segregation of duties.
- Reinforced authentication for sensitive profiles.
9.Retention and elimination
MediRec maintains a Data Elimination Procedure that provides for four situations that trigger elimination:
- Data-subject request;
- Controller request;
- Contract termination;
- Deletion by the platform itself.
Elimination is carried out across the different environments where the data resides, within a maximum of 180 days, with an auditable record. Once the period necessary for the purposes and legal obligations ends, data is eliminated or anonymized.
10.Data-subject rights
Under the LGPD, the data subject may request, among others: confirmation that processing exists; access to the data; correction of incomplete or outdated data; anonymization, blocking or elimination; portability; and information about sharing. Since 2BLP acts as processor (Art. 39 of the LGPD), the path to exercise these depends on who the data subject is.
Patients
Patients don't access the system or 2BLP directly. To exercise any right, the path is the health network itself: the patient approaches the team at the unit responsible for their care — or another instance of the Department. The network assesses the request and, once the course is defined, authorized professionals engage 2BLP, which carries out exactly the operation determined by the controller.
Professional users
The professionals who use MediRec are also data subjects — of their registration and access data and of the audit trail of their own actions. Simple registration corrections (phone, email, a typo in the name) can be requested directly from 2BLP, through the DPO (dpo (at) 2blp.com). The clinical data they generate on the platform — referrals, requisitions and the like — is not the professional's to decide: it belongs to the controller, who determines any change or elimination.
11.Impact assessment (RIPD/DPIA)
2BLP Futuro maintains a Personal Data Protection Impact Report (RIPD/DPIA) that describes the processing, assesses necessity and proportionality, maps the LGPD's principles and records the risk matrix and mitigating measures, with the DPO's technical opinion.
12.Security incidents
In the event of an incident that may pose relevant risk to data subjects, 2BLP Futuro notifies the controller so that the measures provided for in the LGPD are taken, including, where applicable, notification to the ANPD (the Brazilian data protection authority) and to affected data subjects.
13.Cookies and analytics on this site
This section concerns the site medirec.com.br — not the platform. Here, 2BLP acts as controller of visitors' browsing data. The site uses:
- Session cookies (necessary): keep the site working during the visit and expire when it ends.
- Browsing analytics (Microsoft Clarity): a Microsoft tool that helps understand how the site is used — through heatmaps and session recordings — using cookies. Data is processed by Microsoft as a third party and is not used for advertising.
Analytics cookies depend on your consent: you can accept or refuse them in the notice shown when you enter the site, and review the choice at any time. Refusing them doesn't affect how the site works, and you can also block or remove cookies in your browser settings. The site also loads fonts hosted by Google Fonts, which sends your IP address to Google at load time.
Data protection isn't an add-on to MediRec — it's part of how it was built. If you have any questions about your data, talk to our DPO: dpo (at) 2blp.com.
Last updated: to be set at publication.