Privacy
Privacy Policy
Your data in registration, support and clinical work. Who uses it, why and how to contact us.
Version 4 · Updated on 24 September 2026
1. Who is responsible for the data
CapMap is operated by APILAB TECNOLOGIA LTDA, Brazilian company registration (CNPJ) 69.284.049/0001-10, with its registered office at Rua Joaquim Antunes, 470, sala 01 — Pinheiros, São Paulo–SP, CEP 05415-001 — Brazil. This policy covers the institutional website, professional registration, the Portal and the app.
APILAB determines how registration, business relationship and service security data is processed. For clinical content submitted by a clinic or professional, it acts as a processor under the instructions of the party responsible for care. The clinic or professional determines the clinical purpose and applicable legal basis, informs the patient and handles their rights with APILAB’s support.
2. When you visit the site or request access
The form collects name, professional email, professional registration authority, region and number, country, language, optional clinic or organisation and an optional message. APILAB uses this information to review professional eligibility, assess the request, prevent duplicate welcome grants and reply by email. Submitting the form does not automatically enable clinical access. Do not send health information or patient data through the institutional form.
Technical browsing and security signals are also processed, such as IP address, browser, time and anti-automation check results. Abuse and duplicate-submission controls use derived identifiers, cryptographic digests and submission states; this is not anonymisation. Accepted messages are forwarded by email and kept in the support mailbox, separate from the clinical database.
3. Professional account and clinical information
Professional access involves identity, email, clinic membership, permissions and security records. Clerk authenticates identity; CapMap determines permissions and which clinic can be accessed. Photos, 3D models, reports and medical records are not part of the authentication flow with Clerk.
In the app and Portal, clinical work may include patient identification, images, 3D reconstructions, measurements, plans, studies and reports. Synchronisation sends content to CapMap’s storage and processing services. Health information is sensitive data. An image may be biometric when used to identify a person; we do not treat every photo as authorisation for biometric recognition.
Using the service does not authorise APILAB to publish patient images, use them in advertising or train AI models on them for its own purposes. A different purpose requires a specific assessment and an appropriate legal basis.
4. Purposes and legal bases
Requests initiated by you and management of professional access rely on preliminary contractual steps and performance of a contract under Article 7(V) of Brazil’s LGPD. Security and abuse prevention involving non-sensitive data rely on legitimate interest, limited to what is necessary and respecting your rights. Legal obligations and the regular exercise of rights justify processing required by law or necessary for legal proceedings.
Clinical processing of sensitive data requires a basis under Article 11 of the LGPD, determined by the party responsible for care for the specific operation, such as health protection within the statutory limits, a legal obligation, or specific and prominent consent where applicable. Legitimate interest is not used as a basis for sensitive data. Visiting the site or requesting access does not constitute patient consent.
The clinic must distinguish information provided to the patient, consent where required, and instructions to use the service. A professional’s acceptance or a synchronisation command does not, by itself, replace the patient’s decision. Where processing relies on consent, withdrawal does not invalidate prior lawful processing; the effects on future use and mandatory retention must be explained to the individual.
5. Suppliers and sharing
The site uses Vercel for hosting; Cloudflare Turnstile for anti-automation protection; Upstash-compatible Redis storage to limit abuse and prevent duplicate submissions; and Zoho ZeptoMail to forward requests by email. Turnstile receives technical security signals, not the fields entered in the form. Clerk provides professional authentication.
Clinical operations also use hosting, storage and backup services contracted by APILAB, including Backblaze B2 for backups. Access must be restricted to necessary functions and authorised people. We may provide data to comply with legal obligations, valid orders from authorities or to protect rights. We do not sell personal data.
6. International transfers
Infrastructure, authentication, security and communication services may involve storage, processing or support access in other countries, including the United States. This may happen even when you and your clinic are in Brazil. The country of your app store account does not determine where data is processed.
Each transfer must have a valid basis under the rules applicable to its origin and destination, such as an adequacy decision, contractual clauses recognised by the competent authority or another applicable legal ground. This requirement also covers onward transfers to other providers. The lawful basis for clinical processing and the transfer mechanism are separate assessments.
Downloading the app, accepting its terms or authorising a photograph does not constitute blanket consent to any international transfer. Where consent is the applicable mechanism, it must be specific, informed and separate from other purposes. To learn about recipients, countries and safeguards relevant to your data, or request information about applicable instruments, contact info@capmap.com.br.
7. Retention, deletion and security
Contact data is kept for the time needed to complete the request and, where a contract follows, to manage the relationship. Documents and records subject to legal obligations or necessary for exercising rights may be retained for the period corresponding to that purpose. Once no longer needed, data must be deleted or anonymised, subject to lawful retention exceptions.
For form protection, counters expire after 10 minutes; processing and retry states after 15 minutes; and completed or uncertain-result submission records after 24 hours from when they are written. These are not the retention periods for the email mailbox or suppliers’ own records.
Clinical data retention takes account of instructions from the party responsible for care and legal and professional recordkeeping duties. Closing an account does not automatically delete medical records. Backups follow their retention cycle and may remain unmodifiable while protected against deletion. Deletion requests are assessed in relation to these copies as well.
We use access controls, separation of permissions, protected communications and backups. No measure removes every risk. Suspected unauthorised access should be reported through the channel below; incidents involving relevant risk or harm are handled under the notification duties of the LGPD and ANPD.
9. Your rights and how to exercise them
You may request confirmation and access, correction, information about sharing, portability under applicable regulations, and anonymisation, blocking or deletion where provided by law. You may also withdraw consent, learn the consequences of withholding it, object to unlawful processing and request review of solely automated decisions affecting your interests. ANPD and consumer protection channels remain available.
Send your request to info@capmap.com.br with the subject “Privacy”. State your relationship with CapMap and your request, without initially attaching medical records or sensitive documents. We may request identity verification proportionate to the request. Handling is free and subject to statutory deadlines. Where a clinic is responsible for the data, we will help direct the request to the appropriate party.
10. Individuals and clinics outside Brazil
CapMap aims to serve professionals in different countries. This policy describes processing by APILAB; mandatory protections under the law applicable to the individual and the operation remain in force. Availability in an app store and translation of this page do not constitute certification of compliance in every country.
Where the European General Data Protection Regulation (GDPR) applies, processing requires a basis under Article 6 and, for health data or other special categories, a relevant condition under Article 9. Subject to the legal conditions, you may exercise rights of access, rectification, erasure, restriction, objection and portability, withdraw consent and lodge a complaint with the competent data protection authority. References to Brazil’s LGPD in this policy do not limit those rights.
In the United Kingdom, Switzerland, the United States and other countries, rights and obligations depend on the laws that actually apply. You may use the same privacy contact to request information and exercise your rights. If needed to identify the applicable rules, we will request proportionate information, such as the country related to the care provided. The choice of Brazilian law in the terms does not override mandatory local rights.
11. Updates to this policy
The date at the start of this page identifies the version. Material changes to processing purposes or conditions will be communicated through service channels; a new decision from the individual will be requested where necessary. Updating this page does not, by itself, authorise an incompatible use of data already collected.