Data protection

LGPD & privacy

This page explains publicly and accessibly how MediRec processes personal data in accordance with Law No. 13,709/2018 (LGPD).

This page summarizes the platform’s data-protection posture in accessible language. The complete formal versions — the Data Protection Impact Assessment (RIPD/DPIA), Data Elimination Procedure and Data Processing Agreement — are maintained by the DPO and made available to partner controllers on request.
Data stored in BrazilEverything encryptedRestricted accessNo AI trainingHuman decision-makingAuditable elimination

1. Controller and processor

MediRec is developed and maintained by 2BLP Futuro Ltda. (CNPJ 57.899.732/0001-82). In public-health operations, the contracting public entity or institute acts as the controller of citizens’ data, while 2BLP Futuro acts as the processor, processing data on behalf of and according to the controller’s instructions, under the applicable contract and the LGPD.

Data subjectspatients and professionals
Controllerthe health department or institution
Processor2BLP · MediRec
SubprocessorGoogle Cloud · Brazil

The parties involved in processing. 2BLP is the processor and always acts on the controller’s instructions.

2. Data Protection Officer (DPO)

2BLP Futuro formally appointed its Data Protection Officer through Internal Resolution No. 01/2026, dated January 12, 2026. Data-subject requests, questions and communications about data protection may be sent to the DPO:

Data Protection Officer (DPO) · 2BLP Futuro Ltda.dpo (at) 2blp.com

3. Data processed

In clinical regulation and healthcare management, MediRec may process the following data, depending on each municipality’s or institute’s configuration:

  • Citizen identification data: name, CNS/CPF, date of birth and contact details, when applicable.
  • Health data (sensitive): referrals, requests, results and clinical follow-up information received from official systems.
  • Professional and manager data: access credentials and platform usage records.

4. Purposes and legal basis

Data is processed to support clinical regulation and healthcare-network management. Depending on the circumstances, the applicable legal bases include the execution of public policies, protection of health by healthcare professionals and services, and compliance with the controller’s legal or regulatory obligations.

5. Where data is stored

Storage and core processing take place in Brazil. The infrastructure is hosted on Google Cloud Platform in the São Paulo region (southamerica-east1), where platform data and audit trails reside. With Zero Data Retention enabled, no personal data is stored outside Brazil.

The only operation using infrastructure outside Brazil is AI-assisted document transcription (section 6). The model call runs transactionally through a multiregional Google Cloud endpoint without retention: nothing is stored or retained after processing, and nothing is used to train models. This international transfer follows Articles 33 onward of the LGPD and is supported by contractual data-protection clauses with the provider.

6. Artificial intelligence and human validation

MediRec uses an AI model (Google Gemini) strictly transactionally, with prompt engineering and without training models on citizens’ data. The model operates under Section 17 (Training Restriction) of Google Cloud’s Service Specific Terms, which prohibits using the data to train or tune models. With Zero Data Retention enabled, submitted content is not retained after processing. The model call runs through a multiregional Google Cloud endpoint (see section 5).

Regarding decisions, no record moves forward without explicit human validation. AI supports clinical and regulation work, but a professional always makes the decision, in line with Article 20 of the LGPD.

AIreads, organizes and suggests
Human validationthe professional confirms
Record moves forwardonly then

7. Sharing and integrations

MediRec connects to official systems and laboratories — SISREG, SER, GAL, SISCAN, SINAN Rio, eSUS, Científica Lab and Biomega — receiving and sending information according to each workflow. Each database remains the source of truth. MediRec neither reuses nor commercializes this data, and sharing occurs only for the stated purposes and under the controller’s instructions.

Google Cloud operates the infrastructure in its Brazilian region as a subprocessor, bound by contract and subject to equivalent data-protection obligations. As described in section 6, data is not used to train AI models.

8. Security measures

  • Data encrypted at rest.
  • Traffic protected by HTTPS/SSL.
  • Server access restricted to authorized automations and designated technical personnel, with segregation of duties.

9. Retention and elimination

MediRec maintains a Data Elimination Procedure covering four events that trigger elimination:

  • A request from the data subject;
  • A request from the controller;
  • Termination of the contract;
  • Deletion performed through the platform itself.

Elimination is carried out across the environments where the data resides within a maximum of 30 days, with an auditable record. Once the period required for the purposes and legal obligations ends, the data is eliminated or anonymized.

10. Data-subject rights

Under the LGPD, data subjects may request, among other rights, confirmation that processing exists; access to data; correction of incomplete or outdated data; anonymization, blocking or elimination; portability; and information about sharing. Because 2BLP acts as a processor (Article 39 of the LGPD), the route for exercising these rights depends on the data subject.

Patients

Patients do not access the system or contact 2BLP directly. To exercise a right, patients should contact the healthcare network through the team at the unit responsible for their care or another office of the health department. The network assesses the request and, once it determines the appropriate action, authorized professionals instruct 2BLP, which performs exactly the operation determined by the controller.

Patientcontacts the unit or health department
Healthcare networkassesses and decides
2BLPperforms the instructed action

Professional users

Professionals who use MediRec are also data subjects regarding their registration and access data and the audit trail of their own actions. Simple registration corrections (telephone number, email address or a typo in a name) may be requested directly from 2BLP through the DPO (dpo (at) 2blp.com). Clinical data they create on the platform — referrals, requests and similar records — remains under the controller’s authority, which determines any alteration or elimination.

11. Data Protection Impact Assessment (RIPD/DPIA)

2BLP Futuro maintains a Data Protection Impact Assessment (RIPD/DPIA) describing the processing, evaluating necessity and proportionality, mapping LGPD principles, and documenting the risk matrix and mitigation measures, with a technical opinion from the DPO.

12. Security incidents

If an incident may pose a relevant risk to data subjects, 2BLP Futuro notifies the controller so the measures required by the LGPD can be taken, including notification of Brazil’s data-protection authority (ANPD) and affected data subjects when applicable.

13. Cookies on this site

This section concerns the medirec.com.br website, not the platform. Here, 2BLP acts as controller of visitors’ browsing data. The site uses necessary session cookies to keep the site working during a visit; they expire when the session ends. You may block or remove cookies in your browser settings.

The site also loads fonts hosted by Google Fonts, which sends your IP address to Google when the fonts load.

Last updated: September 1, 2026.