Privacy Policy
This policy describes how Precepte processes personal data of users (residents, preceptors, coordinators, and other institutional roles) in the app and on the web. Precepte is an educational and administrative management tool for medical residency programs and does not process patient clinical data.
1. Categories of data collected
- Identity and contact: name, email, phone, profile photo (optional), account identifiers.
- Academic/professional data: medical license ID (CRM), enrollment, specialty, program, unit, role (RBAC).
- Product usage: schedules, attendance/time clock (including location when the user checks in), pedagogical evaluations, messages, and technical metadata required to operate the service.
- Device and notifications: push tokens (FCM), session data, and security audit trails.
2. Purposes
- Authenticate users and enforce multi-institution isolation (multi-tenancy).
- Operate schedules, attendance, evaluations, and communications for the residency program.
- Meet institutional, security, and audit obligations.
- Improve product stability and technical support.
3. Legal basis (LGPD)
We process data to perform the contract/institutional relationship with the customer institution, to comply with legal/regulatory obligations applicable to educational management, and, where needed, based on legitimate interest in security and fraud prevention — always with minimization and role-based access controls (RBAC).
4. Sharing
- With the institution the user is linked to (coordination and authorized roles).
- With infrastructure providers (e.g. Google Firebase/Auth/Firestore/Hosting/Cloud Functions) under data-processing terms.
- We do not sell personal data. We do not share data with advertisers for third-party marketing.
5. Retention
- Active profile data: while the account remains linked to the program.
- Operational audit logs: typically 2 years.
- Critical institutional audit events (e.g. account deletion, role changes): up to 10 years, for accountability.
- Educational artifacts (schedules, evaluations, attendance) may remain with the institution under program policy, without profile PII after account deletion.
6. Account deletion
You may request deletion of your own account by emailing suporte@precepte.com.br (include the account email and institution). When self-service is available in your app version, also use Perfil → Excluir minha conta (current in-app label; product UI is Portuguese). After confirmation, access is closed, tokens are revoked, and personal profile data is anonymized/removed. Records the institution must keep by obligation remain without profile PII, for the purposes and periods described in this policy.
7. Data subject rights
You may request access, correction, portability (where applicable), information about sharing, and deletion via suporte@precepte.com.br or through the in-app deletion flow. Customer institutions may also exercise administrative rights over accounts under their governance.
8. Security
We apply Firebase authentication, institution/role access rules, backend input validation, and audit trails. No system is risk-free; we report relevant incidents as required by law.
9. Controller/operator contact
Precepte — platform precepte.com.br
Email: suporte@precepte.com.br
Support page: precepte.com.br/en/support/
10. Changes
We may update this policy. The effective date at the top indicates the current version. Material changes will be communicated in the product or by email when appropriate.