This Privacy Policy describes how Vinicius de Castro Silva Ltda ("we," "our" or "the Practice") collects, uses, stores and protects the personal data of our patients, website visitors and all others whose data is processed in connection with our physiotherapy services in Jardim Botânico, Brasília, Distrito Federal.
As a registered limited company (Ltda) providing physiotherapy — a health service — we are committed to compliance with the LGPD (Lei nº 13.709/2018), with particular attention to Art. 11 governing sensitive health data, the professional ethical framework of the COFFITO — Conselho Federal de Fisioterapia e Terapia Ocupacional, the CDC (Lei nº 8.078/1990) and applicable tax legislation in the Distrito Federal. All physiotherapists are registered with CREFITO-DF.
Introduction and Scope
This Policy applies to all personal data processed by our physiotherapy practice — including current and former patients, prospective patients who contact us to schedule sessions, website visitors and anyone whose data is processed in connection with our clinical and administrative activities. Given the health-sensitive nature of physiotherapy, we apply the highest standards of data protection under both LGPD Art. 11 and the COFFITO professional ethical framework.
Identity of the Controller
Entity type: Sociedade Limitada (Ltda)
CNPJ: 48.278.546/0001-35
Activity (CNAE): Atividades de Fisioterapia
Professional regulation: COFFITO — Conselho Federal de Fisioterapia e Terapia Ocupacional; CREFITO-DF
Address: Setor SH Tororo / Chapéu de Pedra, Q. 13 Conjunto H, 7, Jardim Botânico, Brasília — DF, CEP 71684-460, Brasil
Email: privacidade@viniciusfisioterapia.com.br
Personal Data We Collect
- Identification and contact data: Full name, CPF, date of birth, phone and email — collected when a patient schedules their first session or completes our intake form.
- Physiotherapy assessment and clinical records (prontuário fisioterapêutico): Functional assessment findings, clinical history, treatment objectives, session notes, outcome measurements and all clinical records produced in the course of physiotherapy care. Maintained per COFFITO professional standards. Classified as sensitive health data under LGPD Art. 5º, II.
- Medical and health history: Information about diagnoses, surgeries, medications, comorbidities and relevant health history — provided by the patient or their referring physician as part of the clinical intake process. Sensitive data under Art. 5º, II, processed under Art. 11.
- Medical referrals and reports: Where patients bring medical referrals, imaging reports or specialist letters — retained in the patient's clinical file for the duration of care.
- NFS-e billing data: Name and CPF for NFS-e issuance — processed only when the patient requests an NFS-e for health insurance reimbursement, income tax deduction or employer reimbursement purposes.
- Contact and scheduling data: Name, phone and message when scheduling sessions by WhatsApp, phone or website form.
- Technical website data: IP address, browser type, pages visited and access times.
Purpose and Legal Basis
| Purpose | Legal Basis (LGPD) |
|---|---|
| Provision of physiotherapy services | Consent — Art. 11, I (health data); Performance of contract — Art. 7º, V |
| Clinical assessment and treatment planning | Consent — Art. 11, I; Health professional obligation — Art. 11, II, "f" |
| Maintenance of prontuário fisioterapêutico (COFFITO) | Legal obligation — COFFITO professional framework; Art. 7º, II; Art. 11, II, "f" |
| Communication with referring physicians (with patient consent) | Consent — Art. 11, I |
| Issuing NFS-e; Receita Federal / SEFAZ-DF compliance | Legal obligation (Art. 7º, II) |
| Health insurance reimbursement documentation (when requested) | Consent; Performance of contract |
| Emergency referral or urgent communication (when required) | Protection of life; Legal obligation — Art. 11, II, "a" |
| Website analysis and improvement | Legitimate interest; Consent (cookies) |
Data Sharing
- Referring or treating physicians (with patient consent): Where a patient consents for us to communicate with their referring doctor, specialist or multidisciplinary care team — only the information relevant to coordinated care is shared, under the patient's explicit instruction.
- Health insurance companies (when requested by patient): Where a patient requires documentation for reimbursement — sessions records or invoices — shared only at the patient's request, in the format required by their insurer.
- Receita Federal / SEFAZ-DF: Tax data for NFS-e issuance and Distrito Federal fiscal compliance. Note: the DF has no municipal ISS — only Receita Federal and SEFAZ-DF apply.
- COFFITO / CREFITO-DF: Where required by a professional ethics investigation or regulatory proceeding.
- Emergency and urgent safety (LGPD Art. 11, II, "a"): Where a patient's physical safety or the safety of a third party is at imminent serious risk — minimum necessary information is communicated to appropriate emergency services. This exception is applied only in genuine medical emergencies.
- Legal authorities: When required by a competent judicial or administrative order — minimum necessary information only.
- PROCON-DF: When required in a consumer dispute under the CDC — limited to non-clinical contractual information only.
International Transfers
Our physiotherapy practice is based in Brasília, DF. All patient clinical records are stored in Brazil. Where scheduling or communication platforms operate on international servers, we use only platforms compliant with Art. 33 of the LGPD or recognised adequacy mechanisms. Patient health data is never transmitted internationally as part of our clinical operations.
Retention Periods
- Prontuário fisioterapêutico (clinical records): Minimum 5 years from the date of the last session, per COFFITO Resolution 424/2013 on clinical documentation standards. For minors, minimum 5 years after the patient reaches the age of majority. Records may be retained longer where clinically or legally warranted.
- Medical referrals and specialist reports: Retained within the patient's file for the minimum clinical records retention period above.
- NFS-e and fiscal records: Minimum 5 years under Receita Federal and SEFAZ-DF requirements.
- Scheduling and contact data (patient did not attend): Deleted within 30 days of the scheduled date.
- Website analytics: Aggregated and anonymised after 12 months.
Security Measures
- Prontuário fisioterapêutico records accessible only to the responsible physiotherapist — no administrative access to clinical data;
- Physical clinical records stored in locked filing systems at our Jardim Botânico practice;
- Digital clinical records stored in access-controlled, encrypted systems;
- WhatsApp scheduling data processed with appropriate discretion — clinical content not exchanged via open messaging without patient consent;
- Website and digital communications encrypted in transit (HTTPS/TLS);
- PCI-DSS certified payment platforms — card data never retained;
- As a Ltda, formal internal data handling protocols maintained;
- Incident response procedures and breach notification per LGPD Art. 48.
Your Rights under the LGPD
- Confirmation and Access (Art. 18, I–II): Confirm whether we hold your data and receive a copy — including a copy of your own prontuário fisioterapêutico.
- Correction (Art. 18, III): Request correction of inaccurate identification or contact data. Note that clinical records reflect professional assessment and corrections are subject to professional ethical constraints.
- Anonymisation / Blocking / Deletion (Art. 18, IV): Request deletion — subject to the mandatory COFFITO clinical record retention period (minimum 5 years from last session) and fiscal obligations.
- Portability (Art. 18, V): Receive a copy of your clinical records in a structured format for transfer to another physiotherapist or health provider.
- Deletion of consent-based data (Art. 18, VI): Withdraw consent for consent-based processing — note this does not affect the mandatory retention of clinical records.
- Information on sharing (Art. 18, VII): Find out whether and with whom your data has been shared.
- Withdrawal of Consent (Art. 8º, §5º): Withdraw consent at any time. Note: withdrawing consent for treatment processing will effectively end the therapeutic relationship.
- Complaint to the ANPD (Art. 18, §1º): Lodge a complaint at www.gov.br/anpd.
- Complaint to COFFITO / CREFITO-DF: Ethical complaints about a physiotherapist's professional conduct can be lodged with CREFITO-DF independently of LGPD rights.
We respond within 15 business days.
Cookies and Tracking
Our website may use cookies for essential functionality and aggregated performance analysis. We do not use behavioural tracking or advertising cookies. We are mindful that people seeking physiotherapy may value discretion — we do not use any tracking that could identify or profile visitors by their interest in health services.
Protection of Minors
Where physiotherapy services are provided to minors (individuals under 18), we apply LGPD Art. 14 and applicable COFFITO guidance:
- Parental or guardian consent is required for physiotherapy of children under 16, in compliance with LGPD Art. 14 and COFFITO professional standards;
- Clinical records for minors are retained for the minimum 5 years after the patient reaches 18, per applicable guidance;
- We do not collect data from children under 12 via our website.
Health Data — LGPD Art. 11
All personal data processed in the context of physiotherapy care — including assessment findings, diagnoses, treatment plans, session notes and medical history — constitutes sensitive health data under LGPD Art. 5º, II. This data is processed exclusively under the heightened protection framework of LGPD Art. 11.
Art. 11, I — Consent: The patient's informed consent to physiotherapy care, provided at the initiation of treatment. Consent is specific to the purpose of physiotherapy and may be withdrawn at any time (see Section ix).
Art. 11, II, "f" — Health professional obligation: The maintenance of the prontuário fisioterapêutico as required by COFFITO Resolution 424/2013 — the mandatory professional obligation to maintain clinical records throughout and after the therapeutic relationship.
Art. 11, II, "a" — Legal obligation / protection of life: Applied only in genuine medical emergencies requiring urgent communication with emergency services or medical professionals.
Updates to this Policy
This Policy may be updated to reflect changes in our activities, the LGPD, ANPD guidance, COFFITO resolutions or applicable Distrito Federal tax legislation. Material changes will be communicated to active patients by WhatsApp or email and via our website.
Contact & Data Protection Officer
All privacy requests — including requests for copies of your clinical records — and ethical complaints should be directed to our Data Protection Officer (Encarregado — LGPD Art. 41):
Privacy Contact — Vinicius de Castro Silva Ltda
ANPD — Autoridade Nacional de Proteção de Dados · www.gov.br/anpd
Ethical complaints about physiotherapist conduct:
CREFITO-DF — Conselho Regional de Fisioterapia e Terapia Ocupacional · www.crefito1.org.br