Pular para o conteúdo principal

Privacy policy

Updated on 22 August 2026.

This page describes how InSales handles personal data, including health data. It is written from what the system actually does: the retention periods cited here are the same ones declared in the code, per record type.

Who is responsible for what

The practice or clinic that subscribes to InSales is the controller of its patients' data: it decides why and how that data is processed. InSales is the processor, and handles this data only to provide the contracted service, following the controller's instructions. If you are a patient and want to exercise a right over your data, the path starts with the professional or clinic that treats you.

What data is processed

Identification and contact details of professionals and patients; scheduling and appointment data; health data recorded by the professional in the clinical record (intake, session notes, measurements, prescriptions, scales, meal plans and adherence entries submitted by the patient themselves); billing and transaction data; and technical access and audit logs.

Health data is treated as sensitive data

Records, measurements, scales and plans follow the regime of article 11 of the LGPD. Access is logged, clinical content sits behind a permission level separate from scheduling, and the authorship of each clinical entry is tied to the natural person who performed it, with their professional licence validated. A wrong clinical entry is not overwritten: it is voided with a mandatory reason and replaced by a new one, preserving the historical series.

How long data is kept

The period is declared per record type, in the code itself, rather than as a generic promise:

  • Clinical records and adjacent data: 20 years, by legal obligation (Law 13.787/2018 art. 6 and CFM 1.821/2007).
  • Tax and transaction records: 5 years (CTN art. 173 and 174; CDC art. 27).
  • Audit and security logs: for as long as needed to record operations (LGPD art. 37).
  • Data processed on the basis of consent: until the data subject asks for removal.
  • Operational data (schedule, catalogue, settings): for as long as the company is a customer.

Legal bases

Performance of a contract (LGPD art. 7, V) to provide the service; compliance with a legal or regulatory obligation (art. 7, II and art. 16, I) for keeping clinical and tax records; consent (art. 7, I and art. 11, I) when asked for specifically and prominently, as in telehealth consent and contact through messaging channels; and legitimate interest (art. 7, IX) for abuse prevention and protecting sending reputation.

Consent is asked per purpose

When consent is the basis, it is asked for a specific purpose and stored with the date and version of the text accepted, rather than as a blanket agreement. Consent can be withdrawn at any time, which stops the processing that relied on it, without affecting what the law requires to be kept.

Data subject rights

Data subjects may request confirmation of processing, access, correction, anonymisation, portability and information about sharing (LGPD art. 18). One important and declared limit: data under legal retention, such as clinical records, cannot be deleted on request before the period ends, because the law itself requires it to be kept. In those cases the request is fulfilled as far as the law allows, and any refusal is justified.

How to exercise your rights

Data subject requests are received by the controller, that is, the practice or clinic that processes your data. If you are an InSales customer and need support to answer a patient request, contact support through the product's channels. Today these requests are handled through direct contact, not through an automatic export button in the app.

Changes to this policy

Material changes will be published on this page with a new update date.

InSales

We use cookies to understand how you use In-Sales and improve it. We only start tracking after you accept — you can decline with no impact on using the app.