Skip to content
Saúde d'Agente by MediRec
  • EN
    EnglishPortuguês (Brasil)
  • ← Back to site
Saúde d'Agente application

Privacy Policy

This Policy explains how data is processed in Saúde d'Agente, an application for Community Health Workers to follow their own health.

On this page

  1. 1. Who we are and what this application is
  2. 2. Processing roles under Brazil's General Data Protection Law
  3. 3. Data we process, purposes, and legal bases
  4. 4. How information is displayed and accessed
  5. 5. Artificial intelligence
  6. 6. Sharing and processors
  7. 7. Data subject rights
  8. 8. Information security and incidents
  9. 9. Retention and deletion
  10. 10. Access, eligibility, and suspension
  11. 11. Data Protection Officer and contact channel
  12. 12. Changes to this Policy

1. Who we are and what this application is

Saúde d'Agente is an application in the MediRec ecosystem, operated by 2BLP Futuro Ltda. (Brazilian corporate taxpayer number 57.899.732/0001-82). It is intended for Community Health Workers to follow their own health as part of a shared-care model with the health network to which they are connected.

This Policy explains which data is processed, the applicable legal basis, who has access, and how data subjects may exercise their rights. Different categories of data are governed by the different arrangements described below.

2. Processing roles under Brazil's General Data Protection Law

Application data is divided into groups with different roles:

a) Data originating from Brazil's Unified Health System (SUS)—Group A. The controllers are the public health bodies (Municipal Health Department, health facilities, and other health authorities). 2BLP acts as processor, processing data on behalf and under the instructions of those bodies, pursuant to the contractual instrument governing that relationship and under the same rules applicable to MediRec.

b) Data entered by the health worker in the Application—Group B. Information voluntarily entered by the Community Health Worker. For this group, 2BLP acts as controller, and processing is based on the data subject's consent, which may be withdrawn at any time.

c) Application operation data—Group C. Technical data required to operate, secure, and improve the Application. For this group, 2BLP acts as controller.

3. Data we process, purposes, and legal bases

Group A—public health system data

  • Identification: name, CPF, CNS number, and date of birth
  • Test results
  • Data from SISREG (access regulation), SER (regulation subsystem), and other clinical records originating in the public network

Purpose: to allow the Community Health Worker to view, through a personal interface, health information already held in the public network, supporting shared care.

Legal basis: protection of health by health services and health authorities (LGPD art. 11, II, “a”) and implementation of public policies (art. 7, VII).

Group B—data entered in the Application

  • Health information reported by the User, such as chronic conditions and allergies

Purpose: to allow the Community Health Worker to record and follow information declared only by them.

Legal basis: consent (LGPD arts. 7, I, and 11, I). Consent is specific and prominent, collected separately for each type of information when that information is entered, and is distinct from acceptance of the Terms of Use or this Policy.

Group C—operation data

  • Device identifiers, access-log data (login), IP address, diagnostic and stability information (failure logs), usage data, and notification tokens. Where the Application uses automatic collection tools, such as usage-analysis or diagnostic resources, they are limited to the purposes in this section.

Purpose: to authenticate access, ensure security, prevent fraud and failures, and improve the Application.

Legal basis: compliance with legal obligations (LGPD art. 7, II—including retention of access logs under art. 15 of the Brazilian Civil Rights Framework for the Internet) and legitimate interests in security and improvement (art. 7, IX), subject to the limits of art. 10.

4. How information is displayed and accessed

4.1. Group A data is displayed in read-only mode. The Application is not the official source; the public health bodies remain responsible for that information.

4.2. Access:

  • The User's employer has no access to the User's health data.
  • The User's health care team accesses Group A information because the User is also a patient in the public network, for the purpose of providing care.
  • Group B data is not made available to the health network in the Application's format. It remains under the User's control.
In short: public-origin data is accessible to the health network because it is part of the public system; declarations made in the Application are not.

5. Artificial intelligence

2BLP does not use artificial intelligence on personal data processed in this Application, and User data is not used to train our own or third-party AI models. No automated decision produces legal or similarly significant effects on the User. If this changes, this Policy will be updated and specific consent will be requested where required.

6. Sharing and processors

2BLP does not sell personal data or share it for advertising. Processing may involve contracted processors acting under instruction, notably Google Cloud Platform, with storage in the southamerica-east1 (Brazil) region. Any international transfers comply with LGPD article 33. Sharing with public health bodies takes place within SUS and those bodies' legal authority.

7. Data subject rights

The arrangements applicable to each group are reflected in how rights are exercised:

7.1. Group A data (identification, tests, SISREG, SER)

Because public bodies are responsible for this data and it forms part of the medical records and registers of the public network, it cannot be deleted through a direct request by the data subject in the Application. The data subject may submit requests to the reference health facility (controller) or to 2BLP's Data Protection Officer, who will forward Group A requests to the responsible controller. Identification data (name, CPF, CNS, and date of birth) is necessary for identification and continuity of care, and health records are subject to statutory medical-record retention periods (at least 20 years under CFM Resolution 1,821/2007), which prevent deletion while the retention obligation remains in force.

7.2. Group B data (declared information)

Declared information belongs to the health worker and remains under their control: it may be accessed, edited, or deleted at any time by the User directly in the Application, including through withdrawal of consent (LGPD arts. 8, §5, and 18, VI).

7.3. Effects of withdrawal (Group B)

Withdrawal is specific to each data type (withdrawing consent for allergies does not affect chronic conditions, and vice versa) and takes immediate effect: the corresponding declaration is deleted from the Application. 2BLP retains only the record of the consent event (date, time, and version of granting and withdrawal) for evidentiary purposes—never the content of the deleted declaration. Refusing or withdrawing consent does not affect the health worker's care in the health network.

8. Information security and incidents

Data is encrypted at rest, and all transmissions use HTTPS/SSL. Infrastructure is hosted in a controlled environment (Google Cloud Platform, southamerica-east1 region), with access restricted to authorized automation and the responsible technical professional. Access to the Application requires individual authentication.

If a security incident may create material risk or harm to data subjects, 2BLP will take appropriate containment measures and notify Brazil's National Data Protection Authority (ANPD) and affected data subjects within a reasonable period, as provided by LGPD article 48.

9. Retention and deletion

  • Group A: retained in accordance with the retention rules applicable to medical records and SUS records.
  • Group B: retained while consent remains valid; deleted after deletion by the User or withdrawal. In the event of access suspension (see Section 10), Group B data remains stored for 60 (sixty) days, during which the User may request export or deletion; if eligibility is not restored by the end of that period, the data is deleted.
  • Group C: access logs are retained for at least six months (art. 15 of the Brazilian Civil Rights Framework for the Internet); other operation data is retained for as long as needed for security and improvement purposes.

10. Access, eligibility, and suspension

Access depends on the User remaining a Community Health Worker in Rio de Janeiro's municipal health network. Losing that status automatically suspends access. The User is notified, and Group B data follows the retention period in Section 9. Group A data is unaffected.

11. Data Protection Officer and contact channel

To exercise rights or ask questions, contact the Data Protection Officer of 2BLP Futuro Ltda. at privacidade@2blp.com. If the matter is not resolved, the data subject may also contact Brazil's National Data Protection Authority (ANPD).

12. Changes to this Policy

This Policy may be updated. The current version will always be available in the Application and at saude-dagente-website.vercel.app. Users may be notified of material changes.

Version 1.0 · Last updated: September 20, 2026.

Saúde d'Agente

Because those who care cannot be left out of care.

Application

CAP 2.2 initiative Features FAQ Download

MediRec

Positioning Ownership medirec.com.br

Privacy

Privacy Policy Terms of Use
© 2026 2BLP Futuro Ltda. · CNPJ 57.899.732/0001-82Made in Rio de Janeiro