Privacy notice: what happens to the scan, the history and the messages you send us
Privacy notice · version 1 · October 2026 · Applies to the English guide for international patients — the pages listed in the editorial policy — and to every way you contact the clinic from abroad: WhatsApp, e-mail, video consultation · Issued by Clínica Dr. Fernando Giovanella Ltda., the controller
1. Who is responsible for my data?
The clinic of Dr. Fernando Giovanella in Blumenau, Brazil — in legal terms, Clínica Dr. Fernando Giovanella Ltda., CNPJ 18.182.812/0001-60 — at Centro Clínico Santa Catarina, Rua Armando Odebrecht, 70, suites 902 and 903, Garcia, Blumenau, Santa Catarina, Brazil. E-mail: atendimento@fernandogiovanella.com. WhatsApp: +55 47 99782-2642. In the law's word, the clinic is the "controller": it decides what is done with your data, and it answers for it.
The base law is Brazil's data protection law, the LGPD.1 If you live in the European Union or the United Kingdom, the GDPR or the UK GDPR may also give you rights; the ones listed in section 9 are honored for you in the same way.3,5 If you live in a U.S. state with its own consumer health data law, such as Washington or Nevada, this notice is also our consumer health data privacy policy: we don't sell health data, and you use the same rights through the same channel. HIPAA covers health plans, clearinghouses and the health-care providers — dentists included — that send claims or other standard transactions to health plans electronically, and the companies that work for them.9 The clinic sends none: you pay it directly, not through a health plan. So you won't see this clinic claim compliance with HIPAA; the claim would mean nothing.
2. Who do I write to about my data?
The clinic is a small business and, as Brazilian rules allow, has no formally appointed data protection officer (encarregado). Your channel is the clinic's own: atendimento@fernandogiovanella.com — write "Privacy" in the subject line — or the clinic's WhatsApp, +55 47 99782-2642. Requests about your data are answered by Dr. Fernando Giovanella.2
The clinic has no establishment or representative in the European Union or the United Kingdom. If you live there, use the same channel; your request is handled the same way.8
3. What do you collect about me, and why?
Five kinds of data, each for one reason.
- Who you are and how to reach you — name, country, phone, e-mail and, if you travel, your flight: to answer you, and to have you met at the airport.
- Your CBCT scan and your medical history: to tell you whether, and how, you can be treated. That is health data, and the law treats it as sensitive.1
- The conversation — WhatsApp messages, e-mails, and my notes from a video consultation: to plan, and to keep a record of what was agreed.
- Payment — what Wise or PayPal passes on, such as your name, the amount and a transaction reference (section 13): to issue a receipt. Never card or bank details.
- The page you came from — the short code a WhatsApp button adds to your message, which you can see and delete (section 11): so the clinic knows what you were reading.
What we don't collect: anything from your social media, anything bought from a data broker, anything you didn't give us or ask your dentist to send.
4. What gives you the right to use it — and what am I agreeing to?
To read your scan and your medical history, and to treat you, the basis is the protection of your health by health professionals — the basis Brazilian law sets aside for exactly this.1 On top of that, before you send health data we ask for your consent, in writing, to one thing in particular: that it be stored with the clinic's service providers in the United States (section 7). If you live in the European Union or the United Kingdom, the same message is also your explicit consent to our processing your health data.4 The exact words are below.
You can withdraw your consent at any time, by the channel in section 2. Withdrawing doesn't undo what was done before, and it doesn't erase the clinical record Brazilian law requires us to keep (section 8).
For the rest — your contact details, the conversation, the payment — the basis is the steps you asked for before treatment, the treatment contract itself and, for the records we must keep, a legal obligation. We send no marketing: we write to you only about the case you asked us about, and anything else would need a separate yes from you.
The short form. Every WhatsApp button in this guide opens a message that already carries it, so you can read it before you send: "I've read the privacy notice. I agree to send my scan and medical history for the surgeon to read. I also agree that the clinic stores them with its service providers in the United States." If your scan reaches us another way, we send you the full form below first, and we open nothing until you reply I AGREE.
The full form. Before you send your scan — your consent (version 1, October 2026):
- What you send: your CBCT scan, your medical history and anything else you choose to send about your health.
- What it's for: so that Dr. Fernando Giovanella can read it and tell you in writing whether, and how, you can be treated — and, if you become a patient, for your treatment.
- Where it goes: to the clinic in Brazil, and to the service providers in the United States that carry and store the clinic's messages, e-mail and records — WhatsApp (Meta), Kommo, Google, Cloudflare, Anthropic and OpenAI. In the United States your data is protected by those companies' contracts with the clinic and by U.S. law, not by Brazilian or European law.
- How long: once the surgeon has read it, it is part of a clinical record, which Brazilian law requires us to keep for at least 20 years after the last entry; if it's never read, it is deleted 12 months after your last message.
- Your rights: you can withdraw this consent at any time, at atendimento@fernandogiovanella.com or on WhatsApp. Withdrawing doesn't undo what was done before, and it doesn't erase the clinical record the law requires us to keep. Full notice: www.fernandogiovanella.com/en/privacy/
To agree, reply: I AGREE. Without it, we won't read what you send.
5. How do I send my scan, and who sees it?
By WhatsApp or by e-mail — for large DICOM files, by the download link your imaging center gives you, or one you create — and here is the honest path of a WhatsApp message, because it isn't the one the padlock icon suggests. It travels encrypted between your phone and WhatsApp's servers. From there it's delivered to the clinic's account, which is connected to our patient-communication system, Kommo, where it's stored and read — by Andreza and Araceles, who answer the clinic's WhatsApp, and by me. WhatsApp's own policy says a business may give a service provider access to its messages, to store and manage them; that is what Kommo is for us.11 So I won't tell you the conversation is encrypted from your phone to mine. It isn't. The clinic's virtual assistant also reads new conversations and may answer them, at any hour (section 10).
Your scan files are saved on computers in Blumenau — the surgeon's and the clinic's — not in a cloud storage service; the message that brought them stays in the service it came through — WhatsApp, by way of Kommo, or e-mail. We open them only after you've given the consent in section 4. If you'd rather not send health data through WhatsApp, e-mail works, and you get the same answer either way.
7. My data leaves my country. What does that mean?
It leaves because you send it. When you write to the clinic from abroad, your scan and your messages travel to Brazil at your own initiative. If you live in the European Union, they come to a country the EU recognized in January 2026 as protecting personal data adequately — and Brazil recognized the EU in return.7 From Brazil, some of it goes on to the United States, where the companies in section 6 keep data for the clinic. Brazilian law allows that with your specific consent, which we ask for before you send health data (section 4).1 What it means for you: in the United States your data is protected by those companies' contracts with the clinic and by U.S. law, not by Brazilian or European law — and U.S. authorities can, in some cases, require access to data held there.
8. How long do you keep it?
It depends on what has happened with your case.
- If I've read your scan or we've had a video consultation, that reading or consultation is a clinical act, and what it relied on — your scan, your history, my written reading, my notes, your consents — is a clinical record. Brazilian law requires clinical records to be kept for at least 20 years after the last entry, whether or not you go ahead with treatment.10
- If you become a patient, the same applies to your whole record.
- If you only wrote to us, and nothing was read or discussed clinically, your messages and anything you sent are deleted 12 months after your last message.
- The virtual assistant's working copy of a conversation is deleted 90 days after the last message.
You can ask for deletion sooner (section 9), except for the clinical record the law requires us to keep.
9. What can I ask you to do?
Any of these, at any time, free of charge:1,6
- confirm whether we hold data about you, and show it to you;
- correct it if it's wrong or incomplete;
- delete it, anonymize it or block it — within the 20-year rule for clinical records;
- send it to you, or to another provider, in a usable format;
- tell you who we've shared it with;
- withdraw a consent you gave, from that moment on;
- object to a use you don't agree with, or ask us to restrict it;
- complain to a data protection authority — in Brazil, the ANPD; in the EU or the UK, your local one.
How: write to atendimento@fernandogiovanella.com (subject "Privacy") or on the clinic's WhatsApp. We'll confirm your identity first, so that nobody else can ask for your file, and you'll have an answer within 15 days.
10. Is there a robot on the other end?
Often, at first. The clinic's WhatsApp has a virtual assistant, built on an AI model (section 6), and new conversations may first be answered by it, at any hour: it explains how things work, asks what you need, can help you book a consultation, and passes you to Andreza when you ask for a person, when you send files, or when something can't wait. During office hours, Andreza follows its conversations and can step in at any time. It doesn't read scans, it doesn't give opinions about your own case, it doesn't decide whether you're a candidate, and it doesn't set the price of any treatment; anything clinical is answered by me. If you'd rather talk to a person, say so. And if you think the assistant got something wrong about you, ask for a human review: you'll get one.
11. What runs in my browser?
Nothing that tracks you. The pages of this guide set no tracking cookies and load no analytics or advertising tags. One thing, because almost nobody says it: when you tap a WhatsApp button, the message opens with a short code at the end — it starts with "fg:" and names the page you came from — so the clinic knows what you were reading. You can see it, and you can delete it before you send. If we add analytics later, it will wait for your yes, rejecting will be as easy as accepting, and this section will change first.13
12. What about the video consultation with the surgeon?
It's a video consultation with me — preliminary, held from Brazil on the clinic's Google Meet room — and it isn't recorded. Before it, you receive and agree to a short consent form, as the rules of Brazil's Federal Council of Dentistry require for remote consultations, and you can stop the call at any time and ask to be seen in person instead.16 The consultation has a fee, which you're told before you book. The notes I take go into your clinical record (section 8).
13. What do you see when I pay?
Never your card or bank details — only what Wise or PayPal passes on. Wise's privacy notice says a recipient receives limited information when you start a payment14 — in practice, your name, the amount and a transaction reference. PayPal's says it may pass the clinic your name and e-mail address and, for some payments, your address and phone number — and that the PayPal company for the country where you live decides how it uses your data.15 What each of them does with your data is governed by its own notice, not this one.
14. How is it protected?
By ordinary measures, named plainly — not with an adjective. Inside the clinic, your record is open to three people: Andreza, Araceles and me. Outside it, to the companies in section 6, each under its own security terms. The clinical record is backed up. No system is beyond breach. If an incident is likely to put you at real risk, we tell you directly, and we tell Brazil's data protection authority (ANPD), within the deadline Brazilian rules set: three business days from when we learn of it.17
15. Do you treat minors through this guide?
No. The guide is for adults deciding for themselves. Please don't send the scan or the medical history of anyone under 18 through it; if you're a parent or guardian, write to us first.
16. How will I know if this notice changes?
The date at the top changes, and a new line in the version history below says what changed and why. If a change affects how we use data you've already sent us, we'll tell you first, by message in the channel you used — and where your consent was the basis, you can withdraw it.
Version history. Version 1 — October 2026.
References
- Brazil — Lei nº 13.709/2018, Lei Geral de Proteção de Dados Pessoais (LGPD), updated text with later amendments, arts. 5 II, 7, 9, 11, 14, 18, 19, 33, 41 and 48 (accessed 8 October 2026). https://www2.camara.leg.br/legin/fed/lei/2018/lei-13709-14-agosto-2018-787077-normaatualizada-pl.html
- ANPD — Resolução CD/ANPD nº 2, de 27 de janeiro de 2022 (small-scale processing agents), art. 11 (accessed 8 October 2026). https://www.gov.br/anpd/pt-br/acesso-a-informacao/institucional/atos-normativos/regulamentacoes_anpd/resolucao-cd-anpd-no-2-de-27-de-janeiro-de-2022
- Regulation (EU) 2016/679 (GDPR), Article 3 — territorial scope (accessed 7 October 2026). https://gdpr-info.eu/art-3-gdpr/
- GDPR, Article 9 — processing of special categories of personal data (accessed 7 October 2026). https://gdpr-info.eu/art-9-gdpr/
- European Data Protection Board — Guidelines 3/2018 on the territorial scope of the GDPR, version 2.1, 12 November 2019 (accessed 7 October 2026). https://gdpr-text.com/en/guidelines/territorialscope/
- GDPR, Article 13 — information to be provided where personal data are collected from the data subject, with the rights of Articles 15–22 (accessed 7 October 2026). https://gdpr-info.eu/art-13-gdpr/
- European Commission — Adequacy decisions: Brazil, adequacy decision of 26 January 2026 (accessed 8 October 2026). https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en · ANPD — Resolução CD/ANPD nº 32, de 26 de janeiro de 2026: the European Union recognized as providing adequate protection of personal data (accessed 8 October 2026). https://www.in.gov.br/web/dou/-/resolucao-n-32-de-26-de-janeiro-de-2026-683334547
- GDPR, Article 27 — representatives of controllers not established in the Union (accessed 7 October 2026). https://gdpr-info.eu/art-27-gdpr/ · UK GDPR, Article 27 (mirror of the legal text, accessed 7 October 2026). https://ukgdpr.fieldfisher.com/chapter-4/article-27-gdpr/
- U.S. Department of Health and Human Services — Covered Entities and Business Associates: providers, dentists included, are covered "only if they transmit any information in an electronic form in connection with a transaction for which HHS has adopted a standard" (accessed 8 October 2026). https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html · U.S. Centers for Disease Control and Prevention — Health Insurance Portability and Accountability Act of 1996 (HIPAA): covered entities (accessed 8 October 2026). https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html
- Brazil — Lei nº 13.787, de 27 de dezembro de 2018, art. 6 — retention of clinical records for at least 20 years after the last entry (accessed 8 October 2026). https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/L13787.htm
- WhatsApp — Privacy Policy, in force since 4 January 2021: businesses may give third-party service providers access to their communications; WhatsApp LLC provides the service outside the European Region (accessed 7 and 8 October 2026). https://www.whatsapp.com/legal/privacy-policy · WhatsApp — Privacy Policy for the European Region, in force since 2 July 2026: WhatsApp Ireland Limited (accessed 8 October 2026). https://www.whatsapp.com/legal/privacy-policy-eea · WhatsApp — Privacy Policy for the UK, in force since 2 July 2026: WhatsApp LLC (accessed 8 October 2026). https://www.whatsapp.com/legal/privacy-policy-uk
- Kommo (QSOFT LLC) — Privacy Policy, revised 3 July 2026: storage and transfer of data in the United States; processor on behalf of its clients (accessed 7 October 2026). https://www.kommo.com/privacy/
- UK Information Commissioner's Office — Guide to PECR: cookies and similar technologies (accessed 7 October 2026). https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/cookies-and-similar-technologies/
- Wise — Personal Customer Privacy Notice, version 4.1, in force since 3 August 2026 (accessed 7 October 2026). https://wise.com/gb/legal/privacy-notice-personal-en
- PayPal — Privacy Statement, last updated 28 September 2026 (accessed 8 October 2026). https://www.paypal.com/ie/legalhub/paypal/privacy-full
- Conselho Federal de Odontologia — Resolução CFO-278/2025, de 25 de novembro de 2025 (remote care in dentistry), arts. 2, 5 and 7 (read 8 October 2026). https://sistemas.cfo.org.br/visualizar/atos/RESOLU%C3%87%C3%83O/SEC/2025/278
- ANPD — Resolução CD/ANPD nº 15, de 24 de abril de 2024 (communication of security incidents), arts. 5, 6 and 9 — three business days to tell the ANPD (art. 6) and to tell you (art. 9) (accessed 8 October 2026, in the Ministry of Justice's digital library). https://bibliotecadigital.mj.gov.br/bitstream/1/12879/2/RES_ANPD_2024_15.html
About this guide
Reviewed and approved by Dr. Fernando Giovanella, CRO-SC 8237 · Updated October 2026 · Next review: April 2027
Where the facts come from. The laws and the companies' own policies listed under References, read on 7 and 8 October 2026 — and the clinic's own way of working: who answers, which systems hold what, how long a record is kept. Nothing here describes a system the clinic doesn't use.
Found a mistake? Write to atendimento@fernandogiovanella.com. You'll have a reply within five business days, and corrections are made and dated on the page.