स्वास्थ्य डेटा परिशिष्ट (Clínicas)

    प्रारंभिक संस्करण, कानूनी समीक्षा में

    संस्करण 0.9.0

    यह दस्तावेज़ अभी हिंदी में अनुवादित नहीं है। इसे अंग्रेज़ी में दिखाया गया है; अनुवाद उपलब्ध होने तक अंग्रेज़ी पाठ ही बाध्यकारी है।

    Table of contents

    1. Scope
    2. Definitions
    3. Roles
    4. Legal basis and clinic obligations
    5. Professional secrecy
    6. Face photos
    7. Patient portal and App
    8. AI features
    9. WhatsApp and messaging
    10. Payments
    11. Retention, export and deletion
    12. Patient rights
    13. United States
    14. Peru
    15. DPIA support, security and incidents
    16. SonhoLab commitments

    1. Scope

    1.1 This Addendum applies to every organization that uses Clínicas, on the web or through the Clínicas mobile App.

    1.2 It supplements the Terms of Service, the Data Processing Addendum (DPA) and the Acceptable Use Policy. For Patient Data, this Addendum prevails over them if they conflict.

    1.3 The Brazil Supplement (LGPD, CDC, Marco Civil, ECA Digital), the EEA and UK Supplement, the United States Supplement and the Latin America Supplement also apply.

    2. Definitions

    • Clinic: the health or wellness provider that contracts for Clínicas.
    • Practitioner: a physician, dentist, nurse, nutritionist or other professional working for the Clinic.
    • Patient: a person whose data the Clinic enters into Clínicas, including prospective patients.
    • Patient Data: any personal data about a Patient processed in Clínicas, including the medical record (prontuário), treatment plans, prescriptions, clinical photos, appointments, signatures and payment records.
    • Health Data: Patient Data about physical or mental health, including clinical photos. It is "sensitive personal data" under LGPD Art. 5 II and 11, "data concerning health" under GDPR Art. 9, and "consumer health data" under the US state laws in section 13.

    3. Roles

    3.1 The Clinic is the controller of Patient Data. It decides why and how Patient Data is processed.

    3.2 SonhoLab is the processor ("operador", "processor", "service provider"). It processes Patient Data only on the Clinic's documented instructions (LGPD Art. 39; GDPR Art. 28).

    3.3 SonhoLab is the controller only for the Clinic's own account and billing data, under the Privacy Policy.

    4.1 Legal basis. The Clinic must have a valid legal basis for each use of Health Data. Typical bases:

    • Brazil: protection of health by health professionals or health services (LGPD Art. 11 II f), and legal or regulatory obligation for keeping the medical record (LGPD Art. 7 II and Art. 11 II a). Uses outside care, such as marketing, need specific and highlighted consent (LGPD Art. 11 I).
    • EEA and UK: provision of health care under the responsibility of a professional bound by secrecy (GDPR Art. 9(2)(h) and 9(3)), or explicit consent (Art. 9(2)(a)) for uses outside care.
    • Peru: consent, as described in section 14.
    • United States: see section 13.

    4.2 Notice. The Clinic must tell Patients what Health Data it processes in Clínicas, why, who receives it and how to exercise their rights. This includes telling them about the AI assistant if the Clinic enables it (section 8) and about where their data is kept: Patient Data is hosted in Finland (EU), and an encrypted backup copy of the database is kept on equipment operated by SonhoLab in Brazil (section 11.7).

    4.3 Consent records. Where the Clinic relies on consent, it must collect and keep proof of it. Clínicas lets the Clinic use consent form templates that the Patient signs in the System. Each signed form keeps the template version used, the date and time of signature, the signature image and a PDF copy with its SHA-256 fingerprint, and it cannot be edited after signing (a correction is recorded as a new form linked to the original). The Patient's consent to the AI assistant is recorded with its date (section 8.3).

    4.4 Minimum necessary. The Clinic must collect only the Health Data it needs and limit Practitioner and staff access by role.

    4.5 Minors. When a Patient is a child or adolescent, the Clinic must act in the patient's best interest (LGPD Art. 14) and obtain a guardian's consent where the law requires it.

    4.6 No prohibited sharing. The Clinic must not use Clínicas to share Health Data for economic advantage where LGPD Art. 11 §4 prohibits it.

    4.7 Records rules. The Clinic is responsible for professional rules on medical records, including integrity and certified digital signatures where required (Lei 13.787/2018; CFM Res. 1.821/2007).

    5. Professional secrecy

    5.1 The Clinic and its Practitioners remain bound by their professional secrecy duties, including the Brazilian Medical Ethics Code (Código de Ética Médica, Art. 73 and following), the Dental Ethics Code and equivalent rules in other countries.

    5.2 SonhoLab supports that secrecy. SonhoLab personnel may access Patient Data only when needed to provide support the Clinic asked for, keep the service secure or comply with law. They are bound by confidentiality (LGPD Art. 47; GDPR Art. 28(3)(b)).

    5.3 SonhoLab does not read medical records for any other reason.

    6. Face photos

    6.1 Clinical photos, including before-and-after face photos, are Health Data and part of the medical record.

    6.2 Clínicas uses face photos only for clinical documentation inside the Clinic's account. It has no facial recognition or face-matching function and does not use photos to identify people. If face photos were ever processed to identify a person, they would also be biometric data and would need a separate basis.

    6.3 Using a Patient's photo for advertising, social media or case publication requires the Patient's separate, specific consent. In Brazil, the Clinic must also follow professional advertising rules (for example, CFM Res. 2.336/2023 on medical advertising).

    6.4 How photos are stored. When a photo is uploaded, Clínicas removes its embedded metadata, such as location (EXIF). Clínicas encrypts clinical photos and documents, including signed forms, with AES-256-GCM before storing them, and shows them to authorized users through short-lived signed links.

    7. Patient portal and App

    7.1 Invitation only. Patients get portal or App access only when the Clinic invites them. The invitation goes to the Patient's email address. Patients do not create accounts on their own.

    7.2 Own records only. A Patient account shows only that Patient's own records. Clínicas has no separate guardian account. For a Patient who is a minor, the Clinic decides, under the rules that apply to it, which email address receives the portal invitation.

    7.3 App status. The patient App is not yet published in app stores. Patients can use the portal on the web. The App may later be published under the Clinic's own brand and app-store developer account. In that case the Clinic is responsible for the store listing, including the privacy labels and the privacy notice link, and SonhoLab gives the Clinic accurate information about the App's data practices. Today the App includes no analytics, advertising or push-notification SDK, and it uses the device camera or photo library only when the user chooses to add a photo.

    7.4 No ads or tracking. The portal and App contain no advertising and no ad-tracking pixels.

    8. AI features

    8.1 Optional AI assistant. On paid plans, Clínicas includes an optional AI assistant with two parts:

    • (a) Staff help chat, in the web panel and the App. It explains how to use Clínicas. The System sends the AI provider only the staff member's question and a guide to the screens; it does not send patient records. Staff should not type Patient Data into it.
    • (b) Patient help chat, in the App only. It explains how to use the App and answers questions about the Patient's own upcoming appointments and active treatment plan. For that, the System sends the AI provider the Patient's question, the Patient's appointments for the next 90 days (date, time, service and status) and the items of the Patient's active treatment plan. This can include Health Data.

    The Free plan has no AI features. The assistant works only after the Clinic adds its own AI key, and the Clinic can turn it off at any time by removing the key.

    8.2 The Clinic's own AI provider. The assistant runs only on the AI provider account the Clinic chooses (any provider with an OpenAI-compatible API, such as OpenAI). The Clinic contracts with that provider and enters the API address, the model and its own API key in the Clínicas settings; SonhoLab never supplies an AI key. That provider is the Clinic's own vendor, not a SonhoLab subprocessor. The Clinic is responsible for its terms, data processing agreement, training settings and transfer safeguards, and pays its charges directly. SonhoLab is not responsible for the provider's charges, availability, outages, outputs or policy changes. SonhoLab stores the key encrypted (AES-256-GCM) and never shows it again (only its last four characters), sends the provider only the data described in section 8.1, does not log questions or answers, deletes the key when the Clinic removes it, and does not train models on Patient Data. See Subprocessors and International Transfers, section 5.

    8.3 Patient notice and consent. Before enabling the assistant, the Clinic must:

    • tell Patients that an AI system is involved, what data it receives and where it is processed;
    • obtain the Patient's consent where its legal basis requires it (for example, in Peru, or under LGPD Art. 11 where the use is not covered by health protection by health professionals, or in the EEA where Art. 9(2)(h) does not cover the use).

    In addition, before the first question, the App shows each Patient what is sent to the Clinic's AI provider and asks for the Patient's consent. Clínicas records the date of that consent, and without it nothing is sent. The Patient can withdraw consent at any time from the chat; after that, nothing more is sent.

    8.4 Disclosure in the interface. Before the Patient's first question, the App tells the Patient that the chat uses the AI provider of the Clinic. The chat does not transfer the conversation to a person; a Patient who wants to talk to someone contacts the Clinic directly.

    8.5 No diagnosis, no clinical decisions. The assistant has no function to diagnose, prescribe, give medical advice or make clinical or treatment decisions, and it is not offered for those purposes. It works only from a guide to the screens and, for Patients, their own appointments and treatment plan. AI answers can be wrong and are not medical advice. Health questions should go to the Clinic's staff. Clinic staff remain responsible for all care and for any information the assistant gives on the Clinic's behalf.

    8.6 International transfer. AI processing takes place wherever the Clinic's chosen provider processes data, which is often outside the Clinic's country (for example, in the United States for OpenAI). The Clinic is responsible for the transfer safeguards with that provider (for example, EU Standard Contractual Clauses or the ANPD standard clauses).

    9. WhatsApp and messaging

    9.1 No WhatsApp today. Clínicas does not send or receive WhatsApp messages. Appointment reminders, invitations and other notices go by email, sent from SonhoLab's own mail server in the Clinic's name. When a staff member copies a payment link to send it through another channel, such as WhatsApp, that message is outside Clínicas; the Clinic should send only the link.

    9.2 Official channel only for Health Data. If SonhoLab adds WhatsApp messaging to Clínicas, it will use only the official WhatsApp Business Platform of Meta Platforms, and SonhoLab will update this Addendum and the subprocessor list before it goes live.

    9.3 Integrations the Clinic connects. A Clinic administrator can create API keys to connect the Clinic's own tools, such as a messaging assistant. A key of that kind can look up a Patient by phone number, list services and free time slots, and book appointments. The tool and its vendor are the Clinic's choice and responsibility, not SonhoLab subprocessors. If such a tool carries Health Data over WhatsApp, the Clinic must use the official WhatsApp Business Platform (Terms of Service, section 12.5). The Clinic can revoke a key at any time.

    9.4 Minimum content. When the Clinic messages Patients through any channel, it should send only what is needed (for example, appointment reminders) and keep clinical detail inside Clínicas.

    10. Payments

    10.1 Clinics in Peru can collect Patient payments online through Culqi (card or Yape), with their own Culqi account. Online payments are not available in other countries; payments received outside Clínicas, such as cash or bank transfer, can be recorded manually. Card and Yape details are entered in Culqi's checkout: Clínicas receives only a single-use token and the result of the charge, and never receives or stores full card numbers. Culqi processes the payment data under its own terms.

    10.2 Payment records are Patient Data and follow this Addendum.

    11. Retention, export and deletion

    11.1 The Clinic decides retention. SonhoLab keeps Patient Data as the Clinic instructs while the subscription is active.

    11.2 Legal minimums are the Clinic's responsibility. For example, in Brazil the medical record must be kept at least 20 years from the last entry (Lei 13.787/2018, Art. 6). Other countries have their own rules.

    11.3 Export. From its account, on every plan, the Clinic can download each Patient's record summary and each signed form as PDF, download photos one by one, and export the patient list as a spreadsheet or PDF. Patients can download a PDF of their own history from the portal. A complete export of the Clinic's database records in a structured format (JSON) is available on request to contacto@sonholab.com. Before ending its subscription, the Clinic must export and keep the records it is legally required to keep.

    11.4 Inactive Free accounts. A Free account in which no user signs in for 90 consecutive days is deleted with all its Patient Data, after two email notices to the account owner, 30 days and 7 days before the deletion date. Signing in before that date keeps the account. Because the Clinic may have a legal duty to keep records, it must keep its account active or export its records in time.

    11.5 After termination. After a paid plan ends and is not replaced by the Free plan, or after the account is terminated, the Clinic's data remains available for export for 30 days (Terms of Service, section 19.4). Then SonhoLab deletes the Patient Data, the Clinic's files and its activity log from active systems. Deleted data disappears from backups as they expire, within 30 days at most.

    11.6 Deletion by the Clinic. A Clinic administrator can delete all of the Clinic's patient data from the account settings, after confirming with the Clinic's name. This cannot be undone and it also deletes signed records, so the Clinic must first export what it has to keep. Deletion requests about a single Patient follow section 12.3.

    11.7 Backups. The Clínicas database is backed up daily. Copies are kept 14 days on the server in Finland and 14 days in an encrypted off-site copy on equipment operated by SonhoLab in Brazil. Clinical photos and documents are stored encrypted on the server in Finland and are not yet included in the backup copies, so the Clinic should keep its own copy of the files it must retain.

    11.8 Logs. Server access logs (IP address, date and time, resource accessed) are kept 6 months (Marco Civil Art. 15), and up to 12 months for security investigations. Clínicas also keeps an activity log of every signed-in access, including views of records and photos and denied attempts: who acted, with what role, the action, the Patient concerned, the IP address and the browser. The log cannot be changed while the Clinic exists and is deleted together with the Clinic. The System has no screen to consult it today; the Clinic can obtain it on request, as part of the complete export in section 11.3.

    12. Patient rights

    12.1 Patients exercise their rights (access, correction, deletion, portability, information on sharing, revocation of consent) with the Clinic.

    12.2 If SonhoLab receives a request from a Patient, it forwards it to the Clinic without undue delay and helps the Clinic answer within its legal deadline (for example, 15 days under LGPD Art. 19 II; one month under GDPR Art. 12).

    12.3 Deletion requests are subject to the Clinic's duty to keep medical records. The Clinic decides.

    13. United States

    13.1 Not a HIPAA business associate. SonhoLab does not sign business associate agreements (BAAs) by default, and does not claim that Clínicas is "HIPAA compliant".

    13.2 No PHI without a BAA. A US covered entity or business associate under HIPAA must not upload protected health information to Clínicas unless SonhoLab and the Clinic have signed a BAA. SonhoLab does not offer a BAA by default.

    13.3 Consumer health data laws. Where a Clinic is not covered by HIPAA, state laws may still apply, including the Washington My Health My Data Act (RCW 19.373), Nevada SB 370 and the Connecticut consumer health data provisions. Under those laws:

    • the Clinic is the regulated entity and must publish its consumer health data privacy policy and obtain the required consents to collect and to share;
    • SonhoLab acts as the Clinic's processor, processes consumer health data only on the Clinic's instructions and helps the Clinic answer consumer requests, including deletion from processors and backups;
    • SonhoLab does not sell consumer health data;
    • SonhoLab does not use geofences around health care facilities.

    13.4 SonhoLab's own data. SonhoLab does not collect consumer health data for its own purposes. The United States Supplement describes SonhoLab's own practices as a controller.

    14. Peru

    14.1 Consent. Peruvian data protection law is consent-centered. Health Data is sensitive data and generally requires the Patient's express consent, given in writing (Ley 29733 and its Reglamento, DS 016-2024-JUS).

    14.2 Data bank registration. The Clinic, as the owner of the data bank (titular del banco de datos), must register its patient data bank with the Registro Nacional de Protección de Datos Personales and appoint a data protection officer (Oficial de Datos Personales) where required.

    14.3 Cross-border flow. Patient Data is hosted in Finland (EU), with an encrypted off-site copy of the database in Brazil. If the Clinic enables the AI assistant, the data described in section 8.1 is processed wherever the Clinic's AI provider processes it. The Clinic must inform Patients of this cross-border flow and meet any communication duty to the authority that the Reglamento imposes.

    14.4 Processor contract. The DPA serves as the processor (encargado) contract between the Clinic and SonhoLab.

    14.5 Breach deadline. Peru requires notice to the authority within 48 hours. SonhoLab's notice to the Clinic (section 15.3) is designed to help. For Clinics in Peru, SonhoLab's target is to notify the Clinic within 24 hours after confirming a breach.

    15. DPIA support, security and incidents

    15.1 DPIA support. Health Data processing usually requires a data protection impact assessment (GDPR Art. 35; LGPD Art. 38 RIPD). On request, SonhoLab gives the Clinic the information it needs: a description of processing, data flows, subprocessors, transfer safeguards and security measures.

    15.2 Security. SonhoLab applies the measures in Security and Incident Response: TLS in transit; application-level encryption (AES-256-GCM) of clinical photos and documents, of the Clinic's AI key and of its payment credentials; encrypted off-site database backups; per-organization logical isolation enforced in the database (row-level security); access limited to named personnel (personal SSH keys for server access); rate limiting and sign-in lockout; the activity log in section 11.8; access logs kept 6 months; secrets outside source code; and an annual review. The database and the server disks are not encrypted at rest, and Clínicas does not offer multi-factor authentication. SonhoLab holds no security or health-software certification (no SOC 2, ISO 27001 or SBIS/CFM certification).

    15.3 Breach notice. SonhoLab notifies the Clinic of a personal data breach affecting Patient Data without undue delay, with a target of 48 hours and no later than 72 hours after confirming it. The Clinic handles notices to authorities and Patients. SonhoLab helps.

    16. SonhoLab commitments

    SonhoLab:

    16.1 processes Patient Data only to provide Clínicas to the Clinic;

    16.2 never uses Patient Data for its own purposes, including marketing, analytics products or AI training (LGPD Art. 11 §4);

    16.3 never sells Patient Data or shares it for advertising;

    16.4 uses only the subprocessors listed for Clínicas in Subprocessors and International Transfers: Hetzner Online GmbH (hosting, Finland) and Culqi (only where the Clinic uses it). Meta Platforms (WhatsApp Business Platform) is listed there for messaging, which Clínicas does not offer today. The AI provider of the assistant and the tools the Clinic connects with API keys are the Clinic's own vendors (sections 8.2 and 9.3);

    16.5 gives advance notice of new subprocessors under the DPA.


    Version 0.9.0 (preliminary) · Effective 26 September 2026 · © L. M. PEREZ MONTANA (SonhoLab), CNPJ 61.620.014/0001-00. This version is under legal review; we will notify material changes as described in these documents.

    प्रारंभिक संस्करण, कानूनी समीक्षा में

    संस्करण 0.9.0

    इस पाठ का SHA-256 फ़िंगरप्रिंट: 7e37e49da52b6a0b0f8a00dff3fe0d921eef36d6078c337c5da57a7b3b2e9bcc

    कानूनी केंद्र पर वापस जाएँ