Instituto Olivan

Privacy Policy

Committed to privacy and in compliance with the Brazilian General Data Protection Law (Law No. 13.709/2018 – LGPD), we present this Privacy Policy to clarify how we handle the personal data we collect.

What personal data we collect and why

Identification and Contact

Basic information like name, CPF, phone number, and email, used for service and appointment scheduling.

Medical Information

Clinical and health data used for preliminary evaluation and procedure safety.

Browsing and Cookies

Anonymous usage data collected through cookies and similar technologies.

We collect and process personal data exclusively for the purpose of providing medical services in an ethical, safe, and personalized manner. Data may be collected directly from patients, companions, legal guardians, partner hospitals, and through digital forms. The collection and use of this data occur for the following purposes:

a) Identification and Contact Information:
Name, CPF, ID, date of birth, gender, address, phone number, email, occupation, and the name and contact information of the person responsible for payment and/or companion. Used for the purposes of:

b) Medical and Health Information:
Weight, height, blood type, test results, medical and surgical history, medication use, allergies, insurance information, menstrual cycle, lifestyle habits, among others. Used for:

c) Browsing and Website Interaction Data:
Cookies, IP address, browser used, time spent on pages, and browsing behavior (when enabled). Used for:

How we store and protect your data

Security and Confidentiality

We implement technical and administrative measures to protect data against unauthorized access, data leaks, and misuse.

Storage

Data is stored in internal systems and/or platforms provided by contracted technology vendors, with restricted access.

Retention Period

Data is kept for as long as necessary to fulfill the purpose for which it was collected and as required by law.

Personal data is securely stored, with access limited to authorized personnel and protected by appropriate physical and digital safeguards. We follow procedures that comply with applicable laws and industry best practices to ensure the confidentiality, integrity, and availability of information.

Data retention complies with legal deadlines and the stated purposes. After this period, data is deleted or anonymized, unless needed to fulfill legal or regulatory obligations.

Who we share data with

Partner Hospitals and Clinics

We share data with healthcare institutions when necessary for tests, hospitalizations, and surgeries.

Healthcare Professionals

We send information to anesthesiologists, doctors, and professionals directly involved in the patient’s care.

Accounting and Billing

We share data with companies responsible for issuing invoices, managing contracts, and fulfilling legal requirements.

We may share personal data with third parties whenever there is a legal basis and a legitimate purpose related to service delivery or compliance with legal and regulatory obligations. For example, we may share:

In all cases, we ensure that data sharing is secure, based on an appropriate legal basis, and subject to confidentiality and data protection agreements.

Information Security

We implement appropriate technical and administrative measures to protect personal data against unauthorized access, loss, alteration, destruction, or any form of improper or unlawful processing. However, no system is entirely foolproof. If you identify any vulnerabilities, please contact us.

Your Rights as a Data Subject

In accordance with the Brazilian General Data Protection Law (LGPD), data subjects have the right to access, correct, and control the use of their personal data. These rights include confirming whether processing is taking place and accessing the data we hold; requesting the correction of incomplete, inaccurate, or outdated data; requesting the anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data; and requesting the portability of data to another service provider, as regulated by the National Data Protection Authority (ANPD).

You also have the right to request the deletion of personal data processed based on consent, except where retention is required by legal or regulatory obligations; to receive information about public or private entities with whom the data has been shared; and to revoke consent at any time, when processing is based on consent. Finally, you may file complaints with the ANPD if you believe your rights are not being respected.

Changes to this Privacy Policy

This Privacy Policy may be modified, updated, or improved at any time to reflect changes in our processes, data handling practices, or to comply with new legal and regulatory requirements.

We recommend reviewing this document periodically to stay informed about how your personal data is being handled. When significant changes occur — especially those that directly impact data subjects' rights or the purposes of processing — the updated version will be prominently published on this website and, when necessary, may also be communicated through our regular contact channels.

The most recent version of this Policy will always be available on this page.

Last updated: May 23, 2025

Questions?

To exercise your rights or request additional information, you may contact our team directly.

Get in touch