Document

Cadastrio Privacy Policy

The privacy and protection of information are important to Cadastrio.

This Privacy Policy explains how personal data may be collected, used, stored, shared and protected while using the website, dashboard, Google Workspace Add-on and other services related to Cadastrio.

1. Who we are

Cadastrio is a platform for registering and organizing clients, integrated with scheduling routines and with Google Calendar.

The service is made available by:

MARQUE SAÚDE LTDA

CNPJ: 21.115.895/0001-80

E-mail for privacy matters: contato@cadastrio.com

2. Who this Policy applies to

This Policy applies to:

  • users of Cadastrio;
  • administrators and members of organizations that use the platform;
  • visitors to the website;
  • individuals whose data is entered into Cadastrio by our clients, to the extent applicable to the processing carried out by the platform.

3. What data we may process

Depending on the features used, we may process different categories of data.

3.1. User account data

This may include name, e-mail address, user identifiers, the organization or workspace to which the user belongs, role, permissions and information necessary for account authentication and security.

3.2. Data related to registered clients

Users may register information about their own clients, such as:

  • name;
  • phone number and WhatsApp;
  • e-mail;
  • notes;
  • information related to appointments;
  • custom fields defined by the user or organization itself.

Custom fields may vary according to the activity carried out by the user.

3.3. Calendar and event data

When the user authorizes integration with Google services, Cadastrio may access the data necessary to make the Google Calendar-related features available.

Depending on the permissions granted and the features used, this may include:

  • calendar identification;
  • events;
  • dates and times;
  • information necessary to link events to clients;
  • technical identifiers necessary for synchronization and integration.

Cadastrio seeks to limit access to the data necessary for the operation of the features made available.

3.4. Technical and security data

We may process technical information necessary for the operation, security and diagnostics of the service, such as access logs, date and time of operations, technical identifiers, error logs, audit information and information necessary to prevent fraud and misuse.

4. Data obtained through Google APIs

Cadastrio uses Google APIs and services exclusively to make available features related to Google Calendar and Google Workspace.

According to the permissions authorized by the user, Cadastrio may access:

  • the list of calendars the user has access to;
  • identifiers and names of the calendars;
  • Google Calendar events necessary for Cadastrio to function;
  • the title and description of events;
  • start and end dates and times;
  • event identifiers;
  • technical properties used to link an event to a client registered in Cadastrio.

This information is used to enable features such as calendar identification, linking clients to events, updating event information and managing the status and modality of the appointment.

Cadastrio accesses Google data only to the extent necessary to provide the features requested by the user.

Data obtained through Google APIs:

  • is not sold;
  • is not used for targeted advertising;
  • is not used to create advertising profiles;
  • is not shared with third parties for advertising purposes;
  • is not used for purposes incompatible with the features made available by Cadastrio.

Data may be processed by infrastructure and technology providers strictly when necessary to make the service available, protect it and operate it, subject to the applicable security and data protection obligations.

The use and transfer to other applications of information received from Google APIs will comply with the Google API Services User Data Policy, including the applicable Limited Use requirements.

The user may revoke the permissions granted to Cadastrio through their Google Account settings. Revocation may prevent the features that depend on those permissions from functioning.

5. What we use the data for

Data may be processed to:

  • create and manage accounts;
  • authenticate users;
  • provide Cadastrio;
  • register, search for and organize clients;
  • link clients to events;
  • manage calendars and professionals;
  • enable custom fields;
  • maintain authorized integrations;
  • provide support;
  • diagnose failures;
  • maintain security and audit logs;
  • prevent fraud and misuse;
  • comply with legal obligations;
  • exercise rights in administrative, arbitration or judicial proceedings;
  • improve the security, stability and operation of the service.

We will not use the data for purposes incompatible with those disclosed in this Policy without an appropriate legal basis.

6. Roles in data processing

The role played by each party depends on the processing operation carried out.

When a company, professional or organization uses Cadastrio to register and manage information about its own clients and determines the purposes and essential elements of that processing, that organization or professional will be responsible for the decisions related to the processing of such data.

When Cadastrio processes this information to provide the platform in accordance with the client's instructions, it acts pursuant to those instructions and for the purpose of providing the service.

In certain of its own activities, such as account management, security, billing, fraud prevention and compliance with legal obligations, Cadastrio may make its own decisions related to the processing necessary for those purposes.

7. Legal bases

Depending on the nature of the operation, processing may occur based on the legal bases set forth in the LGPD, including, where applicable:

  • performance of a contract or procedures related to the contract;
  • compliance with a legal or regulatory obligation;
  • regular exercise of rights;
  • legitimate interest, subject to legal requirements;
  • consent, when this is the appropriate basis;
  • other legally provided grounds.

When Cadastrio acts following the instructions of a client organization, it will be up to that organization to assess the legal basis applicable to the processing it carries out through the platform.

8. Sensitive personal data

Cadastrio is a multi-professional platform and allows the creation of custom fields.

Depending on the use made by the client, these fields may contain data classified by the LGPD as sensitive personal data.

The user must avoid entering sensitive data that is not necessary for their activity and is responsible for assessing the legal requirements applicable to the processing carried out under their responsibility.

Should specific features intended for the processing of clinical information or medical records be made available in the future, additional policies, controls and conditions may apply.

9. Who the data may be shared with

Data is not sold.

We may share information only when necessary for the operation of the service or when there is an appropriate legal basis, including:

Infrastructure and technology providers

Providers used for hosting, database, authentication, processing, monitoring, security and other technical functions necessary for the platform to function.

Google

When necessary to provide authorized features related to Google Workspace, Google Calendar or other Google services used by the user.

Support and service providers

When necessary to provide technical support, maintenance or other services contracted by Cadastrio, subject to the applicable confidentiality and data protection obligations.

Public authorities

When sharing is necessary to comply with a legal obligation, court order or valid request from a competent authority.

Corporate transactions

In the event of a reorganization, merger, acquisition, investment or transfer of assets, information may be transferred as permitted by law, with the adoption of applicable protection measures.

10. International transfer

Some infrastructure or technology providers may process or store information in other countries.

When there is an international transfer of personal data, the applicable requirements of Brazilian data protection legislation will be observed.

11. Data retention

Data will be kept for the period necessary to provide the contracted services, keep the account active, comply with legal or regulatory obligations, preserve security records, prevent fraud, regularly exercise rights or meet other legitimate purposes permitted by law.

After the need for processing ends, data may be deleted or anonymized, except in cases where retention is legally required.

12. Security

We adopt technical and administrative measures designed to protect personal data against unauthorized access and against accidental or unlawful destruction, loss, alteration, communication or improper processing.

These measures may include access controls, authentication, audit logs, segregation of permissions, protection of communications and other practices compatible with the nature of the service.

Despite the measures adopted, no service connected to the internet is completely immune to risk.

13. Access control

Organizations that use Cadastrio may have different users and permission levels.

Administrators are responsible for granting access only to persons who need to use the information to perform their duties and for removing access when it is no longer needed.

14. Data subject rights

Data subjects may exercise the rights provided for under applicable law, according to the nature and circumstances of the processing.

These rights may include, under the terms of the LGPD:

  • confirmation of the existence of processing;
  • access to the data;
  • correction of incomplete, inaccurate or outdated data;
  • anonymization, blocking or deletion where applicable;
  • portability, when applicable and regulated;
  • information about sharing;
  • revocation of consent, when processing is based on consent;
  • other rights provided for by law.

When the data has been entered into Cadastrio by a client company or professional, the request may need to be directed initially to that organization, which is responsible for the decisions related to the processing.

Cadastrio will cooperate with its clients in handling requests when applicable.

15. How to request deletion or exercise rights

Requests related to personal data may be sent to:

contato@cadastrio.com

We may request information reasonably necessary to confirm the identity of the requester and to protect the data against improper access or deletion.

16. Cookies and similar technologies

The Cadastrio website and dashboard may use cookies or similar technologies necessary for authentication, security, session maintenance, user preferences, technical operation and performance measurement, when applicable.

When non-essential technologies require consent under applicable law, appropriate mechanisms will be used to obtain and manage that consent.

17. Children and adolescents

Cadastrio is intended primarily for use by professionals, companies and organizations.

Should our clients use the platform to register information about children or adolescents, it will be up to the client to observe the legal requirements applicable to the processing of such data.

18. Changes to this Policy

This Policy may be updated to reflect changes to Cadastrio, to legislation, to providers, or to privacy and security practices.

The current version will indicate its update date.

Materially relevant changes may be communicated to users through additional means.

19. Contact regarding privacy

For questions, requests or matters related to data protection:

contato@cadastrio.com

MARQUE SAÚDE LTDA

CNPJ: 21.115.895/0001-80

20. Applicable law

This Policy will be interpreted in accordance with Brazilian law, especially Law No. 13,709/2018 — Lei Geral de Proteção de Dados (LGPD – General Personal Data Protection Law).