← Back to Bia

Bia

Privacy Policy

Version 2026-08-01

1. Identity and scope

The legal entity or legal representative identified at the end of this document, referred to below as the Operator, offers the product marketed under the Bia brand. This Policy explains how data from clinic representatives and team members, their clients and patients, and visitors to public pages is processed.

2. Roles in processing

For registration, contracting, billing, security, support, and relationships with clinics, the Operator decides the essential purposes and acts as the controller. For client and patient data entered or received by a clinic, the clinic usually decides the purpose and acts as the controller, while the Operator processes the data to provide the service as a processor. The role must be confirmed for each specific operation.

3. Data processed

  • Account and team: name, clinic, email, provided phone number, role, permissions, hashed password, sessions, and access records.
  • Clinic operations: clients, conversations, calendar, services, professionals, preferences, notifications, and enabled integrations.
  • Clinical data: form and anamnesis answers, aesthetic records, clinical photos, terms, and notes supplied by the clinic or patient.
  • Messages: text, audio, images, delivery metadata, and the history needed for WhatsApp support.
  • Billing: plan, cycle, currency, amounts, status, and provider identifiers. Full card details are collected in the Asaas or Stripe environment and are not stored by the system.
  • Security and audit: IP address, session identifiers, authentication events, administrative actions, and audit trails.
  • Visit and acquisition: random browser identifier, landing-page source, and UTM parameters. The anonymous flow does not receive a name, email, phone number, or patient content.

4. Purposes

Data is processed to create and protect accounts, perform the contract, operate the assistant and calendar, process payments, deliver transactional communications, provide support, prevent fraud, maintain audits, measure the commercial funnel, and meet applicable obligations or exercise applicable rights.

Health data requires its own legal basis. The clinic must define and document the legal basis applicable to its care and provide the notices and consents required by law.

5. Artificial intelligence and clinical content

We use contracted and paid artificial intelligence services. Clinical content recorded in the system — records, anamnesis forms, and questionnaires — is encrypted and is not sent to any external service. WhatsApp messages are processed by those services only to generate a reply, and each clinic's data is isolated: no clinic can access another clinic's data.

Recent message history may be used to generate replies, classify the conversation stage, and prepare continuity of care. Audio may be sent to Groq for transcription; images received in a conversation may be sent to OpenAI for interpretation; text is processed by DeepSeek in the technical version audited for this draft. This scope differs from clinical content persisted in records, anamnesis forms, and questionnaires.

6. Providers and sharing

Sharing is limited to what each contracted function requires:

  • WhatsApp and Evolution API, to receive and send messages;
  • DeepSeek, for text processing; Groq, for audio; OpenAI, for images;
  • Asaas, as a payment provider and subprocessor for Brazilian-real payments in the new flow; Stripe, as a payment provider and subprocessor for dollar, euro, and legacy-flow payments while that configuration remains active;
  • Resend, for transactional email;
  • Google Calendar, only when the clinic enables the integration;
  • hosting, database, queue, and monitoring infrastructure needed for operation;
  • authorities or third parties when legally required or when exercising rights.

This Policy does not claim that providers stop using data for training, because the current contracts and terms of each provider still need to be verified and recorded before making any such promise.

7. International transfers

Artificial intelligence, payment, email, or infrastructure providers may process data outside Brazil. The purpose remains limited to delivering the contracted function. The destinations and applicable legal mechanism must be identified in the contracts actually adopted by the Operator.

8. Retention and deletion

The current system does not apply one automatic deletion period to every persisted category. Data remains while needed for the account and contracted operation and may be retained after closure for security, audits, legal obligations, fraud prevention, or exercising rights. Deletion requests are assessed according to the category, the controller or processor role, and the applicable legal retention grounds.

9. Security

Verified controls include password hashing, AES-256-GCM encryption of secrets and the clinical content identified in this Policy, tenant isolation with database policies, role-based permissions, audit trails, authentication, rate limits, and rechecks before sensitive actions.

No control eliminates every risk. Suspected incidents or unauthorized access must be reported through the contact listed at the end.

10. Rights and requests

A data subject may request confirmation and access, correction, information about sharing, portability where applicable, objection, review of automated decisions, anonymization, blocking or deletion where provided by law, and withdrawal of consent when consent is the basis used.

Requests should be sent to the privacy email listed below. The Operator may request information needed to confirm identity and locate the responsible controller. When the clinic is the controller, the Operator will provide the available technical assistance for its response.

11. Cookies and local storage

The pages use cookies or local storage needed for sessions, security, language, and attribution of a visit to registration. The anonymous acquisition identifier does not contain a name, email, phone number, or patient content. Optional advertising technologies require assessment and a consent mechanism before activation.

12. Updates and contact

This Policy may be updated to reflect legal, contractual, or service changes. The version appears at the top. The Operator's contact and the channel for requests are listed below.

Privacy Policy | Bia