Last updated: 2026-08-21
FRC Consultores Associados LTDA, Brazilian company registration 22.052.463/0001-30, headquartered in Recife-PE, Brasil, acts as controller of the personal data needed to provide, protect, support, and meet legal obligations related to Entrela.
When a linked professional determines their own purposes and means for processing data in the care context under their responsibility, that professional may act as an independent controller. This does not transfer professional decisions to FRC or release the professional from legal, ethical, and transparency duties.
Privacy requests may be sent to contato@frcconsultores.com.br.
The application collects and processes the following types of data:
Health app on iOS
Integration with the Health app (HealthKit) is optional and read-only. With express authorization, Entrela reads steps, distance, active energy, heart rate, heart-rate variability, and sleep. Entrela does not add or change data in the Health app and does not use that data for advertising or model training.
Data processed by Entrela is classified as sensitive personal data under Brazil’s Lei Geral de Proteção de Dados (Law No. 13.709/2018 – LGPD).
LGPD compliance
Each processing activity uses the legal basis appropriate to its stated purpose. For health data, FRC observes the grounds under Article 11 of the LGPD, including consent where applicable and health protection within legal limits, without presuming one exclusive basis for every operation.
Access to HealthKit depends on explicit consent and may be revoked. The Disable and delete data option in Entrela ends synchronization and requests deletion of health data synced to the server. Revoking only in Health app settings prevents new reads; to delete the already synced copy, also use the option in Entrela or request account deletion.
FRC uses data to maintain accounts, organize records, present descriptive visualizations and reports to users and linked professionals, enable authorized communication, protect the platform, provide support, and meet legal obligations.
Explicit prohibition
Personal and sensitive health data are NOT used to train, retrain, or improve general-purpose artificial intelligence models.
Entrela does not use artificial intelligence for diagnosis, severity triage, treatment recommendations, or automated care decisions. Personal data, self-reports, and health data are not sent to train proprietary or third-party models.
Functional sharing occurs with the healthcare professional linked by the user and with essential technology operators contracted by FRC, limited to what is necessary to provide, protect, and maintain the service.
We use Google/Firebase for authentication, database, cloud functions, abuse protection, usage metrics, and failure observability; Apple for Sign in with Apple and, when authorized, HealthKit; and EmailJS to forward messages submitted through support. Google and Apple receive the metadata needed for authentication, but self-reports and health data are not sent as part of login. Firebase processes data stored in Entrela’s backend.
On Android, Google Play processes the professional subscription and provides FRC with technical purchase metadata needed to validate access. The Capgo library used as an on-device native bridge does not receive purchase data as an external service. Historical Stripe records may remain only for support, fraud prevention, and legal obligations. Self-reports and health data are not sent through the billing flow.
We require operators to apply security measures, confidentiality, limited retention, and protection compatible with this Policy and applicable law.
FRC applies technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls, and audit records to protect data processed in Entrela.
Personal data is kept only for the period needed for the described purposes, account maintenance, and legal obligations. Synced health data depends on active consent; deletion requests remove the account and linked data from Entrela’s operational systems, except minimal records that must be retained for legal obligation, fraud prevention, or defense of rights.
Support messages and historical billing records, when they exist, follow timelines limited by support needs and legal obligations. Anonymized data, without a reasonable possibility of association with the data subject, may be retained for security and aggregated metrics.
Under the LGPD, the user may confirm processing, request access, correction, portability, withdrawal of consent, or deletion of their data.
To delete the account and all linked data, visit ladoalado.app/account-deletion. Other requests may be made through the app’s support channels at ladoalado.app/support.