Privacy Policy

Last updated: · Version 1.0

This Privacy Policy explains how Medora processes the personal data of people who visit the medora.com.pt website and of those who ask us to contact them through it, in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR"), Portuguese Law No. 58/2019 of 8 August and Portuguese Law No. 41/2004 of 18 August.

1. Data controller

The data controller is Medora, a company incorporated in Brazil, registered with the Brazilian company registry (CNPJ) under No. 67.698.210/0001-76, with its registered office at Av. das Américas, 3500, Bloco 4, Toronto 3000, Sala 513B, Barra da Tijuca, CEP 22640-102, Rio de Janeiro/RJ, Brasil.

Medora has no establishment in the European Union. Because it offers its services to practitioners and clinics in Portugal, it is subject to the GDPR under Article 3(2).

For any privacy question, including exercising your rights, contact our data protection officer at privacidade@medora.com.pt.

2. What data we process, why and on what legal basis

Contact requests ("Talk to an expert")

  • Data: name, email address, mobile/WhatsApp number and how you currently practise (solo, in a clinic or newly graduated). With the request we also record the page of the website you sent it from and the language.
  • Purpose: to respond to your request for a sales contact, present Medora to you and, if you wish, prepare a proposal.
  • Legal basis: steps taken at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR).
  • How it works: the request is sent to a function hosted on Amazon Web Services (São Paulo region, Brazil), which creates a record in Medora's internal customer relationship management (CRM) system and sends an internal alert to the sales team via Slack and Telegram.
  • Mandatory fields: the form fields are needed for us to reply; without them we cannot follow up on your request through this channel.

After you submit the form, the website opens a WhatsApp chat with the message already filled in. Sending that message and the conversation that follows happen on your initiative, in the WhatsApp app provided by Meta, which processes your account data under its own terms and privacy policy.

If we use your email address to send you other commercial communications about Medora, we will only do so in accordance with Portuguese Law No. 41/2004, and you can object to them at any time, free of charge and without giving reasons.

Usage statistics and campaign measurement (only with your consent)

  • Tools: Google Analytics, loaded through Google Tag Manager, and Microsoft Clarity (analytics); Google Ads, to measure campaign conversions (marketing).
  • Data: browsing information (pages viewed, clicks, scrolling and movements on the page, visit duration), technical data about your device and browser, and online identifiers set by cookies.
  • Purpose: to understand how the website is used so we can improve it, and to measure the results of our campaigns.
  • Legal basis: your consent (Article 6(1)(a) GDPR and Article 5 of Law No. 41/2004). These tools are only loaded after you accept them, and you can withdraw your consent at any time.

Details of each cookie are set out in the Cookie Policy.

Strictly necessary cookies

We use two first-party cookies that are essential for the website to work: medora_consent, which stores your cookie choices, and medora_lang, which stores the language you selected. They are exempt from consent (Article 5(2) of Law No. 41/2004) and rely on our legitimate interest in making the website work as you asked (Article 6(1)(f) GDPR).

Website hosting and security

The website is hosted on Amazon Web Services (Amazon CloudFront and Amazon S3). Like any web server, these services produce technical access logs, which may include your IP address, date and time, the page requested and your browser identification. We use them to keep the website secure and working properly, based on our legitimate interest (Article 6(1)(f) GDPR).

3. Patient data processed in the Medora platform

This policy only covers the medora.com.pt website. Data about patients and practitioners that clinics record in the Medora platform is not covered by this policy: for that processing, the clinic is the controller and Medora acts as processor, under the service agreement and data processing agreement entered into with the clinic (Article 28 GDPR). If you are a patient of a clinic that uses Medora, please direct your requests to that clinic.

4. Who we share data with

We use service providers that process data on our behalf and under our instructions:

  • Amazon Web Services: hosting of the website and of the function that receives the contact form.
  • Slack and Telegram: internal alerts to the sales team about new contact requests.
  • Google (Google Analytics, Google Tag Manager, Google Ads) and Microsoft (Clarity): statistics and campaign measurement, only with your consent.

If you choose to continue the conversation on WhatsApp, the data you share in that conversation is also processed by Meta as the provider of that service.

We may also disclose data to public authorities where required by law.

5. Transfers outside the European Economic Area

Medora is established in Brazil and the data from the contact form is processed in Brazil. When you submit the form, your data goes directly to Medora, which remains subject to the GDPR for that processing.

Some of the providers listed above, namely Slack, Google, Microsoft and Meta, may process data in the United States. Those transfers take place on the basis of the mechanisms provided for in Chapter V GDPR, in particular those providers’ declared participation in the EU-US Data Privacy Framework and/or standard contractual clauses approved by the European Commission.

You can ask us for information about the applicable safeguards at privacidade@medora.com.pt.

6. How long we keep data

  • Contact requests that do not lead to a business relationship: for no longer than 24 months after the last contact; after that the data is deleted or anonymised.
  • If you become a customer: the data is then processed under the contract entered into, for the periods set out in it and those required by law.
  • Cookies: for the periods stated in the Cookie Policy.
  • Technical access logs: only for as long as needed for security and troubleshooting purposes.

7. Your rights

Under Articles 15 to 22 GDPR, you have the right to:

  • access your data and information about how it is processed;
  • rectification of inaccurate or incomplete data;
  • erasure of your data, in the cases provided for by law;
  • restriction of processing;
  • portability of the data you provided to us, in a structured, commonly used format;
  • object to processing based on our legitimate interest and, in any case and without having to give reasons, to processing for direct marketing purposes;
  • withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise any of these rights, write to privacidade@medora.com.pt. We will respond within one month of receiving your request, which may be extended in the cases provided for in Article 12(3) GDPR, free of charge. If we have reasonable doubts about your identity, we may ask you for additional information to confirm it.

You can withdraw the consent you gave to analytics and marketing cookies at any time using the "Cookie settings" link in the website footer.

8. Right to lodge a complaint

If you believe the processing of your data breaches the law, you can lodge a complaint with the Portuguese data protection authority, Comissão Nacional de Proteção de Dados (CNPD), at www.cnpd.pt, or with the supervisory authority of the Member State where you live or work. Where possible, we would appreciate the chance to address your concern first.

9. Security

We apply technical and organisational measures appropriate to the risk to protect personal data against loss, unauthorised access or improper disclosure (Article 32 GDPR), including an encrypted connection (HTTPS) between your browser and the website and access to data restricted to the people who need it.

10. Changes to this policy

We may update this policy, for example when the tools used on the website change. The current version is always on this page, with the date of the last update at the top. If a change is significant, we will say so on the website.