Sub-processors
Last updated on August 25, 2026
Dopu relies on third parties to deliver the service. This page lists each one, what it receives, and where the data sits. It is kept current, and material changes are announced 30 days in advance, under item 13.4 of the Terms of Service.
If you are a psychologist practising in Brazil, this page serves art. 7, II and sole paragraph of CFP Resolution 09/2024: your contract with the patient must specify the technological resources used and which of them safeguard confidentiality. You may cite or attach it.
| Category | What it receives and why | Where the data sits |
|---|---|---|
| Cloud infrastructure | Application hosting, file and document storage, authentication, and email delivery. It also runs the transcription service, which sits on Dopu's own infrastructure. | United States |
| Managed database | Stores the platform data: patient records, session notes, schedule, and financial data. | United States |
| Messaging (WhatsApp) | Appointment reminders and payment notices. Receives the patient's phone number and, in the message body, their first name, the appointment date and time, and the professional's first name. Never clinical content. | United States |
| Support desk | Unified inbox for conversations from people who contact Dopu on WhatsApp or Instagram. It does not receive patient data entered in the platform. | United States |
| Error monitoring | Technical failure telemetry. A filter strips email, CPF, CRP, and other personal data before sending, and if the filter itself fails the event is dropped rather than sent. | United States |
| Payment processing | Subscription billing. Receives the professional's billing data. Dopu does not store card numbers. | United States |
| Audience and campaign measurement | IP address and pages visited, on the public site only. The tags are disabled inside the signed-in area so that a patient path is never sent. | United States |
Named list
This page describes the categories. The full named list — each vendor by name — is available inside the platform, under Sub-processors, so the professional can cite it or attach it to the contract with their patient. Data subjects may request it from the Data Protection Officer at dpo@dopuapp.com.
We do not publish the names on an open page as a matter of security prudence: the vendor list of a health system is reconnaissance material for anyone trying to attack it. The transparency duty under art. 9 of the LGPD is met — the information exists, is complete, and is given to those entitled to it.
View the named list in the platform →Artificial intelligence
No external artificial intelligence provider appears on this list, and that is deliberate. Transcription and note generation run on Dopu's own infrastructure. Audio, transcripts, and clinical content are never sent to third-party AI services, and are never used to train any model.
International transfer
Every vendor above processes data outside Brazil. Each transfer rests on standard contractual clauses signed with the vendor, under art. 33 of the LGPD, together with the technical measures described in item 6.2 of the Privacy Policy — encryption in transit and at rest, access control, and continuous monitoring.
Questions
Write to the Data Protection Officer at dpo@dopuapp.com.