1. Purpose of this Policy
This Privacy Policy explains, objectively and transparently, how RPBioclínica collects, uses, stores, shares and protects personal data processed through the website rpbioclinica.com.br, contact forms, initial support by iVera, institutional pages, RPBioclínica Academy materials and other digital channels connected to the brand.
By using the website or submitting information through the forms, you declare that you have read this Policy and understand the data processing conditions described here.
2. Controller and privacy channel
For the purposes of Brazil’s General Data Protection Law, RPBioclínica acts as the controller of personal data collected directly through its digital channels whenever it defines the purposes and means of processing such data.
- Brand: RPBioclínica.
- Technical professional linked to the platform: Dra. Roberta Petali, dental surgeon, CRO/SP 146.608.
- Domain: rpbioclinica.com.br.
- Privacy contact channel: contato@rpbioclinica.com.br.
Requests related to personal data should be sent to the channel above, with minimum identification that allows the request holder to be confirmed.
3. Personal data that may be processed
Depending on how you interact with RPBioclínica, the following data may be processed:
| Category | Examples |
|---|---|
| Identification | Full name, preferred form of address, profession or profile informed in the contact. |
| Contact | Email, phone, WhatsApp and other information provided for a response. |
| Request data | Message submitted, selected subject, suggested routing, triage history, protocol and observations provided by the data subject. |
| Technical data | IP address, access date and time, browser, device, security logs, cookies and information required to protect the website. |
| Sensitive-context data | Information related to oral health, complaints, exams, images, forensic documents, minors or third parties, only when voluntarily submitted and relevant to the request. |
| Commercial data | Interest in services, courses, Academy materials, payment status, protocol and history of purchased digital materials, when applicable. |
4. Processing purposes
Personal data may be used to:
- receive, organize and respond to requests submitted by the user;
- route contacts internally to the appropriate clinical, technical, educational or administrative area;
- operate iVera as an initial support and contact organization tool;
- generate service protocols, prevent duplicate submissions and maintain basic administrative records;
- enable access to digital materials, Academy content, payments or support related to purchased products;
- protect the website, prevent spam, fraud, automation, abuse and unauthorized access attempts;
- comply with legal, regulatory, ethical, contractual and professional obligations;
- exercise rights in administrative, judicial, ethical, regulatory or forensic contexts, when applicable.
RPBioclínica does not use iVera to replace professional judgment or make exclusively automated decisions with relevant clinical or legal effects.
5. Legal bases used
Personal data processing may rely on different legal bases provided by the LGPD, according to context:
- consent: when the data subject authorizes submission through the form, accepts communications or requests service;
- preliminary contractual procedures: when processing is necessary to respond to a request from the data subject;
- legal or regulatory obligation: when there is a duty to retain, record or respond to competent authorities;
- legitimate interest: for security, fraud prevention, service improvement, internal organization and platform protection;
- regular exercise of rights: in administrative, judicial, arbitration or forensic procedures, when applicable;
- health protection: when there is a care context and processing by a health professional or health entity, subject to legal restrictions.
Whenever sensitive data is processed, RPBioclínica will adopt stricter criteria, access minimization and a purpose compatible with the request submitted.
6. Use of iVera and applied intelligence
iVera is an initial contact organization and triage assistant. Its role is to structure the user’s message, suggest internal routing and facilitate a response from the RPBioclínica team.
- iVera does not perform dental diagnosis;
- does not schedule appointments automatically;
- does not analyze documents as a formal forensic expert;
- does not replace clinical, technical or professional evaluation;
- should not receive sensitive documents before guidance from the team.
Messages sent to iVera may be recorded with protocol, time, summary, routing and history necessary for continuity of service, security, abuse prevention and experience improvement.
7. Data sharing
RPBioclínica may share personal data only when necessary, proportional and compatible with the purposes of this Policy, including with:
- hosting, infrastructure, security, email, automation, technology and digital support providers;
- technical providers needed to maintain a secure digital experience, when applicable;
- payment and checkout platforms, when digital materials are purchased;
- professionals, clinics, operational or technical partners involved in the requested service, when applicable;
- public authorities, professional councils, regulators or third parties when there is a legal obligation, valid order or regular exercise of rights.
RPBioclínica does not sell personal data and does not authorize the use of data for purposes incompatible with this Policy.
9. Retention and deletion
Data will be kept for the period necessary to fulfill the stated purposes, respond to requests, preserve security, meet legal obligations, prove consent, exercise rights and maintain minimal administrative records.
Technical logs and security records may be kept for a period compatible with fraud prevention, audit, incident investigation and platform protection. Data related to contractual, tax, clinical, forensic or legal relationships may follow specific legal periods.
Once the purpose ends and there is no legal basis for retention, data will be deleted, anonymized or blocked according to applicable technical and legal criteria.
10. Data subject rights
Under the LGPD, the data subject may request, when applicable:
- confirmation that processing exists;
- access to personal data;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary, excessive or non-compliant data;
- portability, subject to applicable regulation;
- information about data sharing;
- withdrawal of consent;
- objection to processing based on legitimate interest, when applicable;
- review of exclusively automated decisions, when existing and applicable.
Requests may be sent to contato@rpbioclinica.com.br. RPBioclínica may request identity confirmation to protect the data subject and prevent improper access.
11. Security measures
RPBioclínica adopts reasonable technical and organizational measures to protect personal data against unauthorized access, loss, alteration, improper disclosure, abuse and incompatible use.
Measures may include access control, segregation of sensitive files, log records, form protection, attempt limitations, secure protocols, storage outside the public website area and good digital security practices.
No digital environment is absolutely free of risk. In the event of a relevant incident, appropriate measures will be adopted according to applicable law.
12. Enhanced processing of sensitive and health data
Information related to health, dental history, clinical complaints, intraoral images, exams, forensic documents, records, biometric data, minors, family data and any element capable of revealing a health condition is treated as higher-criticality data and, when applicable, as sensitive personal data under the LGPD.
- RPBioclínica applies the principle of minimization, processing only data necessary for the stated purpose;
- the user should avoid spontaneously submitting complete documents before express guidance from the team;
- internal access to sensitive data must be limited to authorized people and according to operational, clinical, technical, legal or security need;
- sensitive data is not used for behavioral advertising, sale of databases or purposes incompatible with the request submitted;
- iVera only organizes the initial contact and does not decide, diagnose or replace qualified human evaluation.
13. Logs, blocks, security and incidents
To preserve the security of the website, iVera, forms and data subjects, RPBioclínica may use technical records, necessary cookies, browser identifiers, IP address, date and time, submission attempts, protocols, captcha records, temporary access limitation and other proportional mechanisms to prevent abuse, fraud, spam, automation and improper use.
These mechanisms may prevent duplicate submissions, temporarily block new attempts from the same browser, device or IP address and preserve technical evidence in the event of abusive use, intrusion attempts, fraud, dispute, legal obligation, regular exercise of rights or request from a competent authority.
In the event of a relevant security incident involving personal data, RPBioclínica will assess the nature, risk, data involved, technical measures adopted and applicable communication steps, observing the law and guidance from Brazil’s National Data Protection Authority.
14. Third-party data, minors and responsibility for submitted information
The user should not submit personal data of third parties, children, adolescents, patients, family members, legal parties or professionals without authorization, legal basis, appropriate representation or legitimate justification. When contact involves a minor or third party, additional information may be requested to verify legitimacy, context and processing security.
RPBioclínica may refuse, delete, limit, anonymize or not respond to messages containing excessive data, improper sensitive documents, third-party information without legitimate context, offensive, discriminatory, fraudulent, automated or incompatible content.
15. Policy updates
This Policy may be updated to reflect legal, technical, operational, regulatory or institutional changes. The current version will always be published on this page, with the update date indicated.
Last updated: July 4, 2026.