Privacy Policy

Last updated: 2026-08-21

1. Introduction to personal data processing

Convenience translation: the Portuguese version is the binding text. This Policy describes how FRC Consultores Associados LTDA processes personal data when operating Entrela, a digital wellness product. Entrela identifies the product; FRC is the legal entity responsible for the platform.

2. Controller and responsibilities

FRC Consultores Associados LTDA, Brazilian company registration 22.052.463/0001-30, headquartered in Recife-PE, Brasil, acts as controller of the personal data needed to provide, protect, support, and meet legal obligations related to Entrela.

When a linked professional determines their own purposes and means for processing data in the care context under their responsibility, that professional may act as an independent controller. This does not transfer professional decisions to FRC or release the professional from legal, ethical, and transparency duties.

Privacy requests may be sent to contato@frcconsultores.com.br.

3. Data Collection and Processing

The application collects and processes the following types of data:

  • Account data: Name, age, email, phone, city/state, and basic profile information.
  • Health and mental-health data: Self-reported information, scales, questionnaires, mood records, medication adherence, and other follow-up instruments.
  • Technical data: Access logs, session identifiers, days and times of use, needed for system stability and security.
  • Usage data and technical observability: Interaction events, app and operating-system version, device identifier for notifications, and technical stability signals such as failures and performance, used for support, security, and continuous improvement.
  • Support and submitted content: Name, email, subject, message, attachments, and other content the user chooses to share through the application.
  • Billing data: For professionals subscribing on Android: a pseudonymized account identifier, product, term, status, validity, and technical purchase token used to validate access, restore subscriptions, prevent fraud, provide support, and meet legal obligations. Google Play processes the payment method; FRC does not receive full card details. Patients do not provide billing data.
  • On-device local collection and storage: Some information may be temporarily recorded on the device itself for offline operation, continuity of form completion, and later secure synchronization with the user’s account.

Health app on iOS

Integration with the Health app (HealthKit) is optional and read-only. With express authorization, Entrela reads steps, distance, active energy, heart rate, heart-rate variability, and sleep. Entrela does not add or change data in the Health app and does not use that data for advertising or model training.

4. Sensitive Health Data

Data processed by Entrela is classified as sensitive personal data under Brazil’s Lei Geral de Proteção de Dados (Law No. 13.709/2018 – LGPD).

LGPD compliance

Each processing activity uses the legal basis appropriate to its stated purpose. For health data, FRC observes the grounds under Article 11 of the LGPD, including consent where applicable and health protection within legal limits, without presuming one exclusive basis for every operation.

Access to HealthKit depends on explicit consent and may be revoked. The Disable and delete data option in Entrela ends synchronization and requests deletion of health data synced to the server. Revoking only in Health app settings prevents new reads; to delete the already synced copy, also use the option in Entrela or request account deletion.

5. Purpose of Data Use

FRC uses data to maintain accounts, organize records, present descriptive visualizations and reports to users and linked professionals, enable authorized communication, protect the platform, provide support, and meet legal obligations.

6. Use of Artificial Intelligence

Explicit prohibition

Personal and sensitive health data are NOT used to train, retrain, or improve general-purpose artificial intelligence models.

Entrela does not use artificial intelligence for diagnosis, severity triage, treatment recommendations, or automated care decisions. Personal data, self-reports, and health data are not sent to train proprietary or third-party models.

7. Data Sharing

Functional sharing occurs with the healthcare professional linked by the user and with essential technology operators contracted by FRC, limited to what is necessary to provide, protect, and maintain the service.

We use Google/Firebase for authentication, database, cloud functions, abuse protection, usage metrics, and failure observability; Apple for Sign in with Apple and, when authorized, HealthKit; and EmailJS to forward messages submitted through support. Google and Apple receive the metadata needed for authentication, but self-reports and health data are not sent as part of login. Firebase processes data stored in Entrela’s backend.

On Android, Google Play processes the professional subscription and provides FRC with technical purchase metadata needed to validate access. The Capgo library used as an on-device native bridge does not receive purchase data as an external service. Historical Stripe records may remain only for support, fraud prevention, and legal obligations. Self-reports and health data are not sent through the billing flow.

We require operators to apply security measures, confidentiality, limited retention, and protection compatible with this Policy and applicable law.

8. Information Security

FRC applies technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls, and audit records to protect data processed in Entrela.

9. Retention, revocation, and data-subject rights

Personal data is kept only for the period needed for the described purposes, account maintenance, and legal obligations. Synced health data depends on active consent; deletion requests remove the account and linked data from Entrela’s operational systems, except minimal records that must be retained for legal obligation, fraud prevention, or defense of rights.

Support messages and historical billing records, when they exist, follow timelines limited by support needs and legal obligations. Anonymized data, without a reasonable possibility of association with the data subject, may be retained for security and aggregated metrics.

Under the LGPD, the user may confirm processing, request access, correction, portability, withdrawal of consent, or deletion of their data.

To delete the account and all linked data, visit ladoalado.app/account-deletion. Other requests may be made through the app’s support channels at ladoalado.app/support.

10. Policy Updates

FRC may update this Policy to reflect legal, operational, or technical changes. Users will be informed of relevant changes and, when necessary, will be asked to accept again.