Legal

Privacy Policy

This policy explains how Mind Health collects, uses, shares and protects your personal data, in compliance with Brazil's General Data Protection Law (LGPD, Law No. 13.709/2018).

Last updated: May 29, 2026

Who the controller is

The controller of your data is Mind Health Ltda EPP ("Mind Health"), registered under CNPJ No. 19.598.905/0001-33.

For privacy matters or to exercise your rights, contact our Data Protection Officer (DPO) at [DPO@DOMAIN].

What data we collect

We collect only the data needed to respond to your contact and guide you about the therapy.

  • Data you provide: name, email, phone/WhatsApp, whether you are a patient/family or a professional/clinic, the kit or condition of interest and any message you write — when you request a quote or use the contact form.
  • Technical usage data: IP address (used temporarily to limit abuse), browser type (user agent), referring page and language. We also record the date of your consent.
  • Conversations with the virtual assistant: the messages you send to the assistant are processed to generate the reply; we do not link conversation content to your identity nor use it for other purposes.

How we use your data

  • Respond to your quote or contact request and guide you about the therapy;
  • Get in touch by email, phone or WhatsApp when you ask us to;
  • Operate and protect the site (security, abuse prevention and service improvement);
  • Comply with legal and regulatory obligations.

We do not sell your data and do not use it for third-party advertising.

Legal bases (LGPD)

We process your data based on your consent, the performance of pre-contractual procedures at your request, our legitimate interest in the security and improvement of the site, and compliance with legal obligations — under Article 7 of the LGPD.

Who we share with

We share data only with service providers (processors) that help us operate, under contract and only to the extent necessary:

  • Supabase — the database where we securely store quote and contact requests;
  • Resend — sending email notifications to our team about your contact;
  • Vercel — site hosting and cookieless usage analytics (Vercel Web Analytics and Speed Insights);
  • Google Analytics — only if you consent; configured with IP anonymization;
  • Anthropic and OpenAI — when you send a message, process the virtual-assistant messages to generate the replies, without training models on them.

International transfer

Some of these providers may process data outside Brazil. In such cases, we adopt the safeguards set out in the LGPD (Article 33) for the international transfer of data.

Cookies and usage analytics

We use Vercel Web Analytics, which does not use cookies. Google Analytics is loaded only if you accept it in the cookie banner — and runs with IP anonymization. You can decline and keep using the site normally; your choice is stored in your browser.

How long we keep data

We keep contact data for as long as needed to assist you and meet legal obligations, for at most [RETENTION PERIOD]. After that, the data is deleted or anonymized.

Your rights

The LGPD grants you the right to confirm the existence of processing, access, correct, anonymize, port or delete your data, withdraw consent and object to processing. To exercise them, contact our DPO at [DPO@DOMAIN]. You may also petition Brazil's National Data Protection Authority (ANPD).

Security

We adopt technical and organizational measures to protect your data, such as restricted access and encrypted transmission. Conversation content with the assistant and your personal data are never recorded in error logs.

Minors

The site is not intended to collect data from children and adolescents without the consent of their guardians. tDCS therapy is indicated and monitored by a healthcare professional.

Changes to this policy

We may update this policy from time to time. The date of the last update is shown at the top of this page.

Contact

Questions about privacy? Contact our DPO at [DPO@DOMAIN] or our team through the site's contact channels.