Privacy Policy
Last updated on April 30, 2026
1. Introduction
This Privacy Policy describes how DOPU, a brand operated by DIEGO MURAKAMI LTDA, a Brazilian limited liability company registered under tax ID (CNPJ) 54.995.846/0001-38, hereinafter referred to as "DOPU", "we" or "our", collects, uses, stores and protects the personal data of the users of our platform.
Because DOPU is operated from Brazil, this policy is drafted in compliance with Brazilian law, in particular:
- Brazilian General Data Protection Law (LGPD) — Law No. 13.709/2018
- Brazilian Internet Civil Framework — Law No. 12.965/2014
- Brazilian Consumer Defense Code — Law No. 8.078/1990
2. Data Controller
For the purposes of the LGPD, DOPU acts as:
- Controller of the data of the professionals who are users of the platform
- Processor of the data of patients entered by those professionals
Legal name: DIEGO MURAKAMI LTDA
Brazilian tax ID (CNPJ): 54.995.846/0001-38
Address: Av. Paulista, 1106, Sala 01, 16º andar — Bela Vista, São Paulo/SP, Brazil — Postal code 01310-914
Data Protection Officer (DPO): Dopu Security
Email: dpo@dopuapp.com
Phone/WhatsApp: +55 11 93620-7212
3. Data Collected
3.1. Professional (User) Data
We collect the following data to provide the service:
| Data | Purpose | Legal Basis (LGPD) |
|---|---|---|
| Full name | Identification and personalization | Art. 7, V (contract performance) |
| Authentication and communication | Art. 7, V (contract performance) | |
| Phone | Support and account recovery | Art. 7, V (contract performance) |
| Tax ID (CPF/CNPJ) | Tax identification and invoicing | Art. 7, II (legal obligation) |
| Professional license (CRP) | Verification of professional registration | Art. 7, V (contract performance) |
| Address | Invoicing and tax documents | Art. 7, II (legal obligation) |
| Payment data | Subscription processing | Art. 7, V (contract performance) |
3.2. Patient Data
Patient data is entered and managed exclusively by the professionals using the platform. DOPU acts as processor of such data, processing it on behalf of and under the instructions of the professionals (controllers).
Patient data may include:
- Identification data (name, tax ID, date of birth, contact)
- Health data (medical records, clinical notes, diagnostic hypotheses)
- Clinical documents (declarations, certificates, reports)
Important: Health data is considered sensitive personal data under art. 5, II of the LGPD and receives reinforced protection.
3.3. Browsing Data
We automatically collect:
- IP address
- Browser and device type
- Pages accessed and session duration
- Date and time of access
- Cookies (see specific section)
4. Purposes of Processing
We use the data collected to:
- Provide and maintain the platform
- Process registration and authentication
- Manage subscriptions and payments
- Send service-related communications
- Provide technical support
- Comply with legal and regulatory obligations
- Improve user experience
- Prevent fraud and ensure security
- Generate anonymized statistics
5. Data Sharing
We may share personal data with:
| Recipient | Purpose | Data Shared |
|---|---|---|
| Payment processors | Subscription billing | Billing data |
| Infrastructure providers (AWS) | Hosting and storage | All (encrypted) |
| Email services | Notification delivery | Email and name |
| Competent authorities | Compliance with legal obligations | As requested |
Sharing with AWS operates under the AWS Customer Agreement and the AWS Data Processing Addendum (incorporated into the AWS Service Terms), which establish AWS's obligations as data processor.
We do not sell, rent or trade personal data.
6. Storage and Security
6.1. Storage Location
Data is stored on Amazon Web Services (AWS) servers in the us-east-1 region (Virginia, United States). This storage constitutes international data transfer under art. 33 of the Brazilian LGPD, based on standard contractual clauses entered into with AWS (AWS Data Processing Addendum), supplemented by the technical safeguards described in section 6.2 (encryption in transit and at rest, access control and continuous monitoring).
6.2. Security Measures
We implement technical and organizational measures to protect data:
- Encryption in transit (TLS/SSL) and at rest (AES-256)
- Multi-factor authentication available
- Role-based access control (RBAC)
- Continuous security monitoring
- Automatic backups and data redundancy
- Periodic vulnerability testing
- Internal information security policies
6.3. Retention Period
| Data Type | Retention Period | Basis |
|---|---|---|
| Account data | During account life + 5 years | Brazilian Civil Code |
| Billing data | 5 years after fiscal year | Tax legislation |
| Medical records (health data) | 20 years after last appointment | Law No. 13.787/2018 (CFP minimum: 5 years) |
| Access logs | 6 months | Internet Civil Framework |
7. Data Subject Rights
Under the LGPD, you have the right to:
- Confirmation and access: know whether we process your data and obtain a copy
- Rectification: request correction of incomplete or inaccurate data
- Anonymization, blocking or deletion: of unnecessary or excessive data
- Portability: receive your data in a structured format
- Deletion: request removal of data processed under consent
- Information: know with whom we share your data
- Withdrawal of consent: at any time
- Objection: to processing in certain circumstances
To exercise your rights, contact us via email at dpo@dopuapp.com. We will respond within 15 business days.
Patients: If you are a patient of a professional who uses DOPU, your rights must be exercised with the responsible professional, who is the controller of your data.
8. Cookies and Similar Technologies
8.1. What Cookies Are
Cookies are small text files stored on your device that allow us to improve your browsing experience.
8.2. Types of Cookies Used
| Type | Purpose | Duration |
|---|---|---|
| Essential | Basic platform functioning | Session |
| Authentication | Keep you logged in | 30 days |
| Preferences | Remember your settings | 1 year |
| Analytics | Understand how you use the platform | 2 years |
8.3. Cookie Management
You can manage cookies through your browser settings. Note that disabling essential cookies may affect platform functionality.
9. International Transfer
Some of our service providers may be located outside Brazil. In such cases, we ensure international transfers occur only to countries with an adequate level of protection or under appropriate safeguards, in accordance with art. 33 of the LGPD.
10. Integration with Google Services (Optional)
DOPU offers optional integration with Google services. This functionality is not mandatory — each professional can use the platform without connecting any Google account. The provisions of this section apply only to users who choose to enable such integrations.
10.1. Available features
When the user opts to connect their Google account, the following integrations become available:
- Google Sign-In (OAuth): authentication on the platform using a Google account, without the need for a separate password
- Google Calendar: creation and management of appointment events directly in the professional's calendar, with the option to include patients and contacts as guests (only when enabled by the professional for each patient)
10.2. Data accessed via Google
When the integration is active, DOPU may access the following data:
| Data | Source | Purpose |
|---|---|---|
| Name | Google OAuth | Identification on the platform |
| Email address | Google OAuth | Authentication and communication |
| Calendar events | Google Calendar API | Creation and management of appointment scheduling |
| Guest emails | Entered by the professional | Sending appointment invites when enabled |
10.3. Limited use of Google data
In compliance with the Google API Services User Data Policy, data obtained via Google APIs is used exclusively for:
- Authenticating the user on the DOPU platform
- Creating, updating and managing appointment events on the professional's Google Calendar
DOPU does not perform and expressly prohibits the use of Google data for:
- Targeted, personalized, retargeting or interest-based advertising
- Sale or transfer to data brokers or information resellers
- Determining credit eligibility or any financial purposes
- Training artificial intelligence models
- Building data sets for use outside the platform
- Any purpose not directly related to the operation of the contracted service
10.4. Revoking access
The user may revoke DOPU's access to their Google account at any time via:
- DOPU platform settings (Settings > Integrations)
- Directly at myaccount.google.com/permissions
After revocation, no new Google data will be accessed. Data already stored follows the retention periods defined in section 6.3.
11. Minors
The DOPU platform is intended for psychology professionals over 18 years of age. We do not intentionally collect data from minors. If a professional treats minor patients, it is the professional's responsibility to obtain consent from legal guardians.
12. Changes to this Policy
We may update this Policy periodically. Significant changes will be communicated via:
- Email to registered users
- Notification on the platform
- Update of the revision date at the top of this document
We recommend reviewing this page periodically.
13. Contact and DPO
For matters related to privacy and data protection:
Data Protection Officer (DPO): Dopu Security
Email: dpo@dopuapp.com
Phone/WhatsApp: +55 11 93620-7212
Legal name: DIEGO MURAKAMI LTDA
Brazilian tax ID (CNPJ): 54.995.846/0001-38
You may also file a complaint with the Brazilian National Data Protection Authority (ANPD) at www.gov.br/anpd.
14. LGPD Glossary
- Personal data: information relating to an identified or identifiable natural person
- Sensitive personal data: data on racial origin, religious belief, political opinion, health, sexual life, genetic or biometric data
- Data subject: natural person to whom the personal data refers
- Controller: party that makes decisions about the processing of personal data
- Processor: party that processes data on behalf of the controller
- DPO: person appointed to act as a communication channel between the controller, data subjects and the ANPD
- Processing: any operation performed with personal data
- Consent: free, informed and unambiguous expression of the data subject