Fernando Giovanella
Reviewed and approved by Dr. Fernando Giovanella, CRO-SC 8237How this guide is made →
A guide for patients who live abroad

Privacy notice: what happens to the scan, the history and the messages you send us

Privacy notice · version 1 · October 2026 · Applies to the English guide for international patients — the pages listed in the editorial policy — and to every way you contact the clinic from abroad: WhatsApp, e-mail, video consultation · Issued by Clínica Dr. Fernando Giovanella Ltda., the controller

1. Who is responsible for my data?

The clinic of Dr. Fernando Giovanella in Blumenau, Brazil — in legal terms, Clínica Dr. Fernando Giovanella Ltda., CNPJ 18.182.812/0001-60 — at Centro Clínico Santa Catarina, Rua Armando Odebrecht, 70, suites 902 and 903, Garcia, Blumenau, Santa Catarina, Brazil. E-mail: atendimento@fernandogiovanella.com. WhatsApp: +55 47 99782-2642. In the law's word, the clinic is the "controller": it decides what is done with your data, and it answers for it.

The base law is Brazil's data protection law, the LGPD.1 If you live in the European Union or the United Kingdom, the GDPR or the UK GDPR may also give you rights; the ones listed in section 9 are honored for you in the same way.3,5 If you live in a U.S. state with its own consumer health data law, such as Washington or Nevada, this notice is also our consumer health data privacy policy: we don't sell health data, and you use the same rights through the same channel. HIPAA covers health plans, clearinghouses and the health-care providers — dentists included — that send claims or other standard transactions to health plans electronically, and the companies that work for them.9 The clinic sends none: you pay it directly, not through a health plan. So you won't see this clinic claim compliance with HIPAA; the claim would mean nothing.

2. Who do I write to about my data?

The clinic is a small business and, as Brazilian rules allow, has no formally appointed data protection officer (encarregado). Your channel is the clinic's own: atendimento@fernandogiovanella.com — write "Privacy" in the subject line — or the clinic's WhatsApp, +55 47 99782-2642. Requests about your data are answered by Dr. Fernando Giovanella.2

The clinic has no establishment or representative in the European Union or the United Kingdom. If you live there, use the same channel; your request is handled the same way.8

3. What do you collect about me, and why?

Five kinds of data, each for one reason.

  • Who you are and how to reach you — name, country, phone, e-mail and, if you travel, your flight: to answer you, and to have you met at the airport.
  • Your CBCT scan and your medical history: to tell you whether, and how, you can be treated. That is health data, and the law treats it as sensitive.1
  • The conversation — WhatsApp messages, e-mails, and my notes from a video consultation: to plan, and to keep a record of what was agreed.
  • Payment — what Wise or PayPal passes on, such as your name, the amount and a transaction reference (section 13): to issue a receipt. Never card or bank details.
  • The page you came from — the short code a WhatsApp button adds to your message, which you can see and delete (section 11): so the clinic knows what you were reading.

What we don't collect: anything from your social media, anything bought from a data broker, anything you didn't give us or ask your dentist to send.

5. How do I send my scan, and who sees it?

By WhatsApp or by e-mail — for large DICOM files, by the download link your imaging center gives you, or one you create — and here is the honest path of a WhatsApp message, because it isn't the one the padlock icon suggests. It travels encrypted between your phone and WhatsApp's servers. From there it's delivered to the clinic's account, which is connected to our patient-communication system, Kommo, where it's stored and read — by Andreza and Araceles, who answer the clinic's WhatsApp, and by me. WhatsApp's own policy says a business may give a service provider access to its messages, to store and manage them; that is what Kommo is for us.11 So I won't tell you the conversation is encrypted from your phone to mine. It isn't. The clinic's virtual assistant also reads new conversations and may answer them, at any hour (section 10).

Your scan files are saved on computers in Blumenau — the surgeon's and the clinic's — not in a cloud storage service; the message that brought them stays in the service it came through — WhatsApp, by way of Kommo, or e-mail. We open them only after you've given the consent in section 4. If you'd rather not send health data through WhatsApp, e-mail works, and you get the same answer either way.

6. Who else touches my data?

Only the companies and people below — and every company that keeps data for the clinic is named, with its country. We don't sell data, and we don't share it with advertisers.

  • WhatsApp (a Meta company) — the messaging service, which carries your messages under its own privacy policy: WhatsApp Ireland Limited if you live in the EU, the EEA or Switzerland; WhatsApp LLC, United States, everywhere else — the UK included.11
  • Kommo — QSOFT LLC, United States — our patient-communication system: it stores the WhatsApp conversations, as a processor on our behalf.12
  • Anthropic, PBC, United States — provides the AI model behind the virtual assistant (section 10) and some of the clinic's internal tools; it receives the text of the messages the assistant answers, and what those tools are given to work on.
  • OpenAI, United States — provides the AI that the clinic's own patient-record software uses to turn the surgeon's dictated notes into text and to read lab reports; it receives what it is given to transcribe or read.
  • Google — the clinic's e-mail (Google Workspace) and video-call room (Google Meet), working for the clinic under the clinic's contract; data may be kept in the United States.
  • Cloudflare, United States — hosts this website, the virtual assistant (which keeps a working copy of each conversation for 90 days after the last message) and the clinic's own patient-record software.
  • Controle Odonto — Aplicativo Sistemas Avançados Ltda., Brazil — the clinic's patient-record system: if you become a patient, your record is kept there too.
  • Brazil's tax authorities and the clinic's accountant — the invoice Brazilian law requires for treatment carries your name, the service and the amount.
  • Wise and PayPal — for payments; each decides, under its own privacy notice, what it does with your data (section 13).
  • If you become a patient: the anesthesiology group, Anesteclin, and — for general anesthesia — Hospital Unimed Blumenau, with the clinical information your care needs; the dental laboratory that makes your teeth, with what it needs to make them; and your own dentist at home, when you give us their contact.
  • The clinic's private driver, who picks you up at the airport and takes you back: your name, your phone number and your flight — nothing clinical. The clinic doesn't book hotels, so no hotel receives anything from us.

7. My data leaves my country. What does that mean?

It leaves because you send it. When you write to the clinic from abroad, your scan and your messages travel to Brazil at your own initiative. If you live in the European Union, they come to a country the EU recognized in January 2026 as protecting personal data adequately — and Brazil recognized the EU in return.7 From Brazil, some of it goes on to the United States, where the companies in section 6 keep data for the clinic. Brazilian law allows that with your specific consent, which we ask for before you send health data (section 4).1 What it means for you: in the United States your data is protected by those companies' contracts with the clinic and by U.S. law, not by Brazilian or European law — and U.S. authorities can, in some cases, require access to data held there.

8. How long do you keep it?

It depends on what has happened with your case.

  • If I've read your scan or we've had a video consultation, that reading or consultation is a clinical act, and what it relied on — your scan, your history, my written reading, my notes, your consents — is a clinical record. Brazilian law requires clinical records to be kept for at least 20 years after the last entry, whether or not you go ahead with treatment.10
  • If you become a patient, the same applies to your whole record.
  • If you only wrote to us, and nothing was read or discussed clinically, your messages and anything you sent are deleted 12 months after your last message.
  • The virtual assistant's working copy of a conversation is deleted 90 days after the last message.

You can ask for deletion sooner (section 9), except for the clinical record the law requires us to keep.

9. What can I ask you to do?

Any of these, at any time, free of charge:1,6

  • confirm whether we hold data about you, and show it to you;
  • correct it if it's wrong or incomplete;
  • delete it, anonymize it or block it — within the 20-year rule for clinical records;
  • send it to you, or to another provider, in a usable format;
  • tell you who we've shared it with;
  • withdraw a consent you gave, from that moment on;
  • object to a use you don't agree with, or ask us to restrict it;
  • complain to a data protection authority — in Brazil, the ANPD; in the EU or the UK, your local one.

How: write to atendimento@fernandogiovanella.com (subject "Privacy") or on the clinic's WhatsApp. We'll confirm your identity first, so that nobody else can ask for your file, and you'll have an answer within 15 days.

10. Is there a robot on the other end?

Often, at first. The clinic's WhatsApp has a virtual assistant, built on an AI model (section 6), and new conversations may first be answered by it, at any hour: it explains how things work, asks what you need, can help you book a consultation, and passes you to Andreza when you ask for a person, when you send files, or when something can't wait. During office hours, Andreza follows its conversations and can step in at any time. It doesn't read scans, it doesn't give opinions about your own case, it doesn't decide whether you're a candidate, and it doesn't set the price of any treatment; anything clinical is answered by me. If you'd rather talk to a person, say so. And if you think the assistant got something wrong about you, ask for a human review: you'll get one.

11. What runs in my browser?

Nothing that tracks you. The pages of this guide set no tracking cookies and load no analytics or advertising tags. One thing, because almost nobody says it: when you tap a WhatsApp button, the message opens with a short code at the end — it starts with "fg:" and names the page you came from — so the clinic knows what you were reading. You can see it, and you can delete it before you send. If we add analytics later, it will wait for your yes, rejecting will be as easy as accepting, and this section will change first.13

12. What about the video consultation with the surgeon?

It's a video consultation with me — preliminary, held from Brazil on the clinic's Google Meet room — and it isn't recorded. Before it, you receive and agree to a short consent form, as the rules of Brazil's Federal Council of Dentistry require for remote consultations, and you can stop the call at any time and ask to be seen in person instead.16 The consultation has a fee, which you're told before you book. The notes I take go into your clinical record (section 8).

13. What do you see when I pay?

Never your card or bank details — only what Wise or PayPal passes on. Wise's privacy notice says a recipient receives limited information when you start a payment14 — in practice, your name, the amount and a transaction reference. PayPal's says it may pass the clinic your name and e-mail address and, for some payments, your address and phone number — and that the PayPal company for the country where you live decides how it uses your data.15 What each of them does with your data is governed by its own notice, not this one.

14. How is it protected?

By ordinary measures, named plainly — not with an adjective. Inside the clinic, your record is open to three people: Andreza, Araceles and me. Outside it, to the companies in section 6, each under its own security terms. The clinical record is backed up. No system is beyond breach. If an incident is likely to put you at real risk, we tell you directly, and we tell Brazil's data protection authority (ANPD), within the deadline Brazilian rules set: three business days from when we learn of it.17

15. Do you treat minors through this guide?

No. The guide is for adults deciding for themselves. Please don't send the scan or the medical history of anyone under 18 through it; if you're a parent or guardian, write to us first.

16. How will I know if this notice changes?

The date at the top changes, and a new line in the version history below says what changed and why. If a change affects how we use data you've already sent us, we'll tell you first, by message in the channel you used — and where your consent was the basis, you can withdraw it.

Version history. Version 1 — October 2026.

References

  1. Brazil — Lei nº 13.709/2018, Lei Geral de Proteção de Dados Pessoais (LGPD), updated text with later amendments, arts. 5 II, 7, 9, 11, 14, 18, 19, 33, 41 and 48 (accessed 8 October 2026). https://www2.camara.leg.br/legin/fed/lei/2018/lei-13709-14-agosto-2018-787077-normaatualizada-pl.html
  2. ANPD — Resolução CD/ANPD nº 2, de 27 de janeiro de 2022 (small-scale processing agents), art. 11 (accessed 8 October 2026). https://www.gov.br/anpd/pt-br/acesso-a-informacao/institucional/atos-normativos/regulamentacoes_anpd/resolucao-cd-anpd-no-2-de-27-de-janeiro-de-2022
  3. Regulation (EU) 2016/679 (GDPR), Article 3 — territorial scope (accessed 7 October 2026). https://gdpr-info.eu/art-3-gdpr/
  4. GDPR, Article 9 — processing of special categories of personal data (accessed 7 October 2026). https://gdpr-info.eu/art-9-gdpr/
  5. European Data Protection Board — Guidelines 3/2018 on the territorial scope of the GDPR, version 2.1, 12 November 2019 (accessed 7 October 2026). https://gdpr-text.com/en/guidelines/territorialscope/
  6. GDPR, Article 13 — information to be provided where personal data are collected from the data subject, with the rights of Articles 15–22 (accessed 7 October 2026). https://gdpr-info.eu/art-13-gdpr/
  7. European Commission — Adequacy decisions: Brazil, adequacy decision of 26 January 2026 (accessed 8 October 2026). https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en · ANPD — Resolução CD/ANPD nº 32, de 26 de janeiro de 2026: the European Union recognized as providing adequate protection of personal data (accessed 8 October 2026). https://www.in.gov.br/web/dou/-/resolucao-n-32-de-26-de-janeiro-de-2026-683334547
  8. GDPR, Article 27 — representatives of controllers not established in the Union (accessed 7 October 2026). https://gdpr-info.eu/art-27-gdpr/ · UK GDPR, Article 27 (mirror of the legal text, accessed 7 October 2026). https://ukgdpr.fieldfisher.com/chapter-4/article-27-gdpr/
  9. U.S. Department of Health and Human Services — Covered Entities and Business Associates: providers, dentists included, are covered "only if they transmit any information in an electronic form in connection with a transaction for which HHS has adopted a standard" (accessed 8 October 2026). https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html · U.S. Centers for Disease Control and Prevention — Health Insurance Portability and Accountability Act of 1996 (HIPAA): covered entities (accessed 8 October 2026). https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html
  10. Brazil — Lei nº 13.787, de 27 de dezembro de 2018, art. 6 — retention of clinical records for at least 20 years after the last entry (accessed 8 October 2026). https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/L13787.htm
  11. WhatsApp — Privacy Policy, in force since 4 January 2021: businesses may give third-party service providers access to their communications; WhatsApp LLC provides the service outside the European Region (accessed 7 and 8 October 2026). https://www.whatsapp.com/legal/privacy-policy · WhatsApp — Privacy Policy for the European Region, in force since 2 July 2026: WhatsApp Ireland Limited (accessed 8 October 2026). https://www.whatsapp.com/legal/privacy-policy-eea · WhatsApp — Privacy Policy for the UK, in force since 2 July 2026: WhatsApp LLC (accessed 8 October 2026). https://www.whatsapp.com/legal/privacy-policy-uk
  12. Kommo (QSOFT LLC) — Privacy Policy, revised 3 July 2026: storage and transfer of data in the United States; processor on behalf of its clients (accessed 7 October 2026). https://www.kommo.com/privacy/
  13. UK Information Commissioner's Office — Guide to PECR: cookies and similar technologies (accessed 7 October 2026). https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guide-to-pecr/cookies-and-similar-technologies/
  14. Wise — Personal Customer Privacy Notice, version 4.1, in force since 3 August 2026 (accessed 7 October 2026). https://wise.com/gb/legal/privacy-notice-personal-en
  15. PayPal — Privacy Statement, last updated 28 September 2026 (accessed 8 October 2026). https://www.paypal.com/ie/legalhub/paypal/privacy-full
  16. Conselho Federal de Odontologia — Resolução CFO-278/2025, de 25 de novembro de 2025 (remote care in dentistry), arts. 2, 5 and 7 (read 8 October 2026). https://sistemas.cfo.org.br/visualizar/atos/RESOLU%C3%87%C3%83O/SEC/2025/278
  17. ANPD — Resolução CD/ANPD nº 15, de 24 de abril de 2024 (communication of security incidents), arts. 5, 6 and 9 — three business days to tell the ANPD (art. 6) and to tell you (art. 9) (accessed 8 October 2026, in the Ministry of Justice's digital library). https://bibliotecadigital.mj.gov.br/bitstream/1/12879/2/RES_ANPD_2024_15.html

About this guide

Reviewed and approved by Dr. Fernando Giovanella, CRO-SC 8237 · Updated October 2026 · Next review: April 2027

Where the facts come from. The laws and the companies' own policies listed under References, read on 7 and 8 October 2026 — and the clinic's own way of working: who answers, which systems hold what, how long a record is kept. Nothing here describes a system the clinic doesn't use.

Found a mistake? Write to atendimento@fernandogiovanella.com. You'll have a reply within five business days, and corrections are made and dated on the page.

How this guide is written, checked and kept up to date