Privacy Policy

Last updated on April 30, 2026

1. Introduction

This Privacy Policy describes how DOPU, a brand operated by DIEGO MURAKAMI LTDA, a Brazilian limited liability company registered under tax ID (CNPJ) 54.995.846/0001-38, hereinafter referred to as "DOPU", "we" or "our", collects, uses, stores and protects the personal data of the users of our platform.

Because DOPU is operated from Brazil, this policy is drafted in compliance with Brazilian law, in particular:

  • Brazilian General Data Protection Law (LGPD) — Law No. 13.709/2018
  • Brazilian Internet Civil Framework — Law No. 12.965/2014
  • Brazilian Consumer Defense Code — Law No. 8.078/1990

2. Data Controller

For the purposes of the LGPD, DOPU acts as:

  • Controller of the data of the professionals who are users of the platform
  • Processor of the data of patients entered by those professionals

Legal name: DIEGO MURAKAMI LTDA

Brazilian tax ID (CNPJ): 54.995.846/0001-38

Address: Av. Paulista, 1106, Sala 01, 16º andar — Bela Vista, São Paulo/SP, Brazil — Postal code 01310-914

Data Protection Officer (DPO): Dopu Security

Email: dpo@dopuapp.com

Phone/WhatsApp: +55 11 93620-7212

3. Data Collected

3.1. Professional (User) Data

We collect the following data to provide the service:

DataPurposeLegal Basis (LGPD)
Full nameIdentification and personalizationArt. 7, V (contract performance)
EmailAuthentication and communicationArt. 7, V (contract performance)
PhoneSupport and account recoveryArt. 7, V (contract performance)
Tax ID (CPF/CNPJ)Tax identification and invoicingArt. 7, II (legal obligation)
Professional license (CRP)Verification of professional registrationArt. 7, V (contract performance)
AddressInvoicing and tax documentsArt. 7, II (legal obligation)
Payment dataSubscription processingArt. 7, V (contract performance)

3.2. Patient Data

Patient data is entered and managed exclusively by the professionals using the platform. DOPU acts as processor of such data, processing it on behalf of and under the instructions of the professionals (controllers).

Patient data may include:

  • Identification data (name, tax ID, date of birth, contact)
  • Health data (medical records, clinical notes, diagnostic hypotheses)
  • Clinical documents (declarations, certificates, reports)

Important: Health data is considered sensitive personal data under art. 5, II of the LGPD and receives reinforced protection.

3.3. Browsing Data

We automatically collect:

  • IP address
  • Browser and device type
  • Pages accessed and session duration
  • Date and time of access
  • Cookies (see specific section)

4. Purposes of Processing

We use the data collected to:

  • Provide and maintain the platform
  • Process registration and authentication
  • Manage subscriptions and payments
  • Send service-related communications
  • Provide technical support
  • Comply with legal and regulatory obligations
  • Improve user experience
  • Prevent fraud and ensure security
  • Generate anonymized statistics

5. Data Sharing

We may share personal data with:

RecipientPurposeData Shared
Payment processorsSubscription billingBilling data
Infrastructure providers (AWS)Hosting and storageAll (encrypted)
Email servicesNotification deliveryEmail and name
Competent authoritiesCompliance with legal obligationsAs requested

Sharing with AWS operates under the AWS Customer Agreement and the AWS Data Processing Addendum (incorporated into the AWS Service Terms), which establish AWS's obligations as data processor.

We do not sell, rent or trade personal data.

6. Storage and Security

6.1. Storage Location

Data is stored on Amazon Web Services (AWS) servers in the us-east-1 region (Virginia, United States). This storage constitutes international data transfer under art. 33 of the Brazilian LGPD, based on standard contractual clauses entered into with AWS (AWS Data Processing Addendum), supplemented by the technical safeguards described in section 6.2 (encryption in transit and at rest, access control and continuous monitoring).

6.2. Security Measures

We implement technical and organizational measures to protect data:

  • Encryption in transit (TLS/SSL) and at rest (AES-256)
  • Multi-factor authentication available
  • Role-based access control (RBAC)
  • Continuous security monitoring
  • Automatic backups and data redundancy
  • Periodic vulnerability testing
  • Internal information security policies

6.3. Retention Period

Data TypeRetention PeriodBasis
Account dataDuring account life + 5 yearsBrazilian Civil Code
Billing data5 years after fiscal yearTax legislation
Medical records (health data)20 years after last appointmentLaw No. 13.787/2018 (CFP minimum: 5 years)
Access logs6 monthsInternet Civil Framework

7. Data Subject Rights

Under the LGPD, you have the right to:

  • Confirmation and access: know whether we process your data and obtain a copy
  • Rectification: request correction of incomplete or inaccurate data
  • Anonymization, blocking or deletion: of unnecessary or excessive data
  • Portability: receive your data in a structured format
  • Deletion: request removal of data processed under consent
  • Information: know with whom we share your data
  • Withdrawal of consent: at any time
  • Objection: to processing in certain circumstances

To exercise your rights, contact us via email at dpo@dopuapp.com. We will respond within 15 business days.

Patients: If you are a patient of a professional who uses DOPU, your rights must be exercised with the responsible professional, who is the controller of your data.

8. Cookies and Similar Technologies

8.1. What Cookies Are

Cookies are small text files stored on your device that allow us to improve your browsing experience.

8.2. Types of Cookies Used

TypePurposeDuration
EssentialBasic platform functioningSession
AuthenticationKeep you logged in30 days
PreferencesRemember your settings1 year
AnalyticsUnderstand how you use the platform2 years

8.3. Cookie Management

You can manage cookies through your browser settings. Note that disabling essential cookies may affect platform functionality.

9. International Transfer

Some of our service providers may be located outside Brazil. In such cases, we ensure international transfers occur only to countries with an adequate level of protection or under appropriate safeguards, in accordance with art. 33 of the LGPD.

10. Integration with Google Services (Optional)

DOPU offers optional integration with Google services. This functionality is not mandatory — each professional can use the platform without connecting any Google account. The provisions of this section apply only to users who choose to enable such integrations.

10.1. Available features

When the user opts to connect their Google account, the following integrations become available:

  • Google Sign-In (OAuth): authentication on the platform using a Google account, without the need for a separate password
  • Google Calendar: creation and management of appointment events directly in the professional's calendar, with the option to include patients and contacts as guests (only when enabled by the professional for each patient)

10.2. Data accessed via Google

When the integration is active, DOPU may access the following data:

DataSourcePurpose
NameGoogle OAuthIdentification on the platform
Email addressGoogle OAuthAuthentication and communication
Calendar eventsGoogle Calendar APICreation and management of appointment scheduling
Guest emailsEntered by the professionalSending appointment invites when enabled

10.3. Limited use of Google data

In compliance with the Google API Services User Data Policy, data obtained via Google APIs is used exclusively for:

  • Authenticating the user on the DOPU platform
  • Creating, updating and managing appointment events on the professional's Google Calendar

DOPU does not perform and expressly prohibits the use of Google data for:

  • Targeted, personalized, retargeting or interest-based advertising
  • Sale or transfer to data brokers or information resellers
  • Determining credit eligibility or any financial purposes
  • Training artificial intelligence models
  • Building data sets for use outside the platform
  • Any purpose not directly related to the operation of the contracted service

10.4. Revoking access

The user may revoke DOPU's access to their Google account at any time via:

After revocation, no new Google data will be accessed. Data already stored follows the retention periods defined in section 6.3.

11. Minors

The DOPU platform is intended for psychology professionals over 18 years of age. We do not intentionally collect data from minors. If a professional treats minor patients, it is the professional's responsibility to obtain consent from legal guardians.

12. Changes to this Policy

We may update this Policy periodically. Significant changes will be communicated via:

  • Email to registered users
  • Notification on the platform
  • Update of the revision date at the top of this document

We recommend reviewing this page periodically.

13. Contact and DPO

For matters related to privacy and data protection:

Data Protection Officer (DPO): Dopu Security

Email: dpo@dopuapp.com

Phone/WhatsApp: +55 11 93620-7212

Legal name: DIEGO MURAKAMI LTDA

Brazilian tax ID (CNPJ): 54.995.846/0001-38

You may also file a complaint with the Brazilian National Data Protection Authority (ANPD) at www.gov.br/anpd.

14. LGPD Glossary

  • Personal data: information relating to an identified or identifiable natural person
  • Sensitive personal data: data on racial origin, religious belief, political opinion, health, sexual life, genetic or biometric data
  • Data subject: natural person to whom the personal data refers
  • Controller: party that makes decisions about the processing of personal data
  • Processor: party that processes data on behalf of the controller
  • DPO: person appointed to act as a communication channel between the controller, data subjects and the ANPD
  • Processing: any operation performed with personal data
  • Consent: free, informed and unambiguous expression of the data subject