Sub-processors

Last updated on August 25, 2026

Dopu relies on third parties to deliver the service. This page lists each one, what it receives, and where the data sits. It is kept current, and material changes are announced 30 days in advance, under item 13.4 of the Terms of Service.

If you are a psychologist practising in Brazil, this page serves art. 7, II and sole paragraph of CFP Resolution 09/2024: your contract with the patient must specify the technological resources used and which of them safeguard confidentiality. You may cite or attach it.

CategoryWhat it receives and whyWhere the data sits
Cloud infrastructureApplication hosting, file and document storage, authentication, and email delivery. It also runs the transcription service, which sits on Dopu's own infrastructure.United States
Managed databaseStores the platform data: patient records, session notes, schedule, and financial data.United States
Messaging (WhatsApp)Appointment reminders and payment notices. Receives the patient's phone number and, in the message body, their first name, the appointment date and time, and the professional's first name. Never clinical content.United States
Support deskUnified inbox for conversations from people who contact Dopu on WhatsApp or Instagram. It does not receive patient data entered in the platform.United States
Error monitoringTechnical failure telemetry. A filter strips email, CPF, CRP, and other personal data before sending, and if the filter itself fails the event is dropped rather than sent.United States
Payment processingSubscription billing. Receives the professional's billing data. Dopu does not store card numbers.United States
Audience and campaign measurementIP address and pages visited, on the public site only. The tags are disabled inside the signed-in area so that a patient path is never sent.United States

Named list

This page describes the categories. The full named list — each vendor by name — is available inside the platform, under Sub-processors, so the professional can cite it or attach it to the contract with their patient. Data subjects may request it from the Data Protection Officer at dpo@dopuapp.com.

We do not publish the names on an open page as a matter of security prudence: the vendor list of a health system is reconnaissance material for anyone trying to attack it. The transparency duty under art. 9 of the LGPD is met — the information exists, is complete, and is given to those entitled to it.

View the named list in the platform →

Artificial intelligence

No external artificial intelligence provider appears on this list, and that is deliberate. Transcription and note generation run on Dopu's own infrastructure. Audio, transcripts, and clinical content are never sent to third-party AI services, and are never used to train any model.

International transfer

Every vendor above processes data outside Brazil. Each transfer rests on standard contractual clauses signed with the vendor, under art. 33 of the LGPD, together with the technical measures described in item 6.2 of the Privacy Policy — encryption in transit and at rest, access control, and continuous monitoring.

Questions

Write to the Data Protection Officer at dpo@dopuapp.com.