LGPD · Version 5.2 · 2026-08-20

Privacy Policy.

This policy describes how BedSight Flow processes personal data of professionals authorized by contracting healthcare institutions. It is aligned with Brazil’s General Data Protection Law (LGPD — Law 13.709/2018).

1. Who we are

FRC Consultores Associados LTDA (FRC), CNPJ 22.052.463/0001-30, is the company responsible for BedSight Flow. FRC acts as controller for data sent directly to this website for contact and as operator for hospital data processed on behalf of contracting institutions, under LGPD Art. 5(VII). The Controller Institution (hospital, clinic, or hospital network) defines the purposes, means, and processing instructions for hospital data. See the FRC legal data for complete institutional details.

Operational stage. BedSight Flow is a B2B hospital productivity tool for operational coordination. FRC is the contracting party, owner, and licensor of the service; the institution remains responsible for permitted content in each flow and for processing performed under its instructions.

2. Scope of this policy

This policy describes the processing of personal data of authorized professionals of contracting institutions (managers, NIR, coordinators, physicians, nursing, multiprofessional teams) in the course of using BedSight Flow.

Bed references and flow fields may contain Minimized and pseudonymized Health Data that may constitute sensitive personal health data under LGPD Art. 5(II) and remain linkable to a person even when initials are used. They are not treated as anonymous and remain under the Controller Institution's responsibility.

3. Types of data collected

The runtime may process operational data, professional identification, and minimized health data needed for the flow:

The product is not intended for medical records or clinical narrative. No biometrics, continuous geolocation, or cross-app tracking is evidenced in the audited iOS target; reassess if the runtime changes.

4. Purpose of processing

Data are processed exclusively to enable operational hospital-flow coordination: bed management, shift rituals, escalation of external blockers, and operational audit. The purpose is strictly administrative and managerial, falling under the administrative-software exclusion in ANVISA RDC 657/2022 (Art. 4).

When enabled, the AI agent (FAB) receives a minimized operational message, context, and history after specific consent. The runtime removes aliases/names and refuses identifiers and clinical narrative before the provider; this boundary does not make retained data anonymous. Technical and governance safeguards are detailed in the Responsible AI document.

5. Legal basis

The Controller Institution defines the legal basis and instructions for each flow. The B2B contract organizes the service, but this policy does not assert one universal legal basis; AI consent is specific and revocable and does not replace that assessment.

6. Data sharing

We share personal data only with sub-processors essential to operations:

No ATT, IDFA, or advertising SDK is evidenced in the audited iOS target. Sharing, location, and retention depend on effective configuration and current contracts; they are not presumed absent.

7. Retention and deletion

Retention is defined by the Controller Institution, applicable duties, and sub-processor contracts. Technical defaults and evidence preservation do not replace that governance.

8. Data subject rights

Under Art. 18 LGPD, the data subject may request:

Requests must be sent through FRC's public privacy channel at contato@frcconsultores.com.br. Requests involving data under the controller institution’s responsibility will be forwarded to that institution for direct response.

Without prejudice to the channels above, the data subject may also petition the National Data Protection Authority (ANPD) at gov.br/anpd, under Art. 18 §1 and Art. 55-J LGPD.

9. Security

10. Cookies and local storage

We use localStorage for functional preferences, Firebase session state, and UI state. The audited iOS target shows no ATT, IDFA, advertising SDK, or cross-app tracking purpose. This is a conclusion about the current runtime, not a guarantee about future technical processing by providers.

11. Minors

BedSight Flow is intended exclusively for professionals aged 18+ authorized by contracting institutions. We do not target the service to minors and do not intentionally collect data of minors.

12. Non-medical purpose

BedSight Flow is not a medical device, does not store medical records, and does not perform diagnosis, clinical monitoring, triage, or treatment recommendations. It does not replace hospital electronic health record systems or clinical decision tools. Clinical decisions remain entirely with the care team and the hospital’s official systems.

13. Privacy channel

Channel
BedSight Flow Privacy
Email
contato@frcconsultores.com.br

14. Security incidents

We maintain a documented information-security incident response process. Any confirmed or reasonably suspected event that compromises the confidentiality, integrity, or availability of personal data is notified to the controller institution within a reasonable time from discovery, including the nature of the incident, affected data and subjects, containment and mitigation measures, and the Officer’s contact.

Communication to the data subject and to the National Data Protection Authority (ANPD), when required under Art. 48 LGPD, is performed by the controller institution with technical support from BedSight Flow. The operator preserves forensic evidence while the investigation is ongoing and provides, upon request, an executive summary of findings.

15. Updates to this policy

This policy may be updated periodically. The current version, with its date, will always be published on this page. Material changes will be communicated to contracting institutions through channels provided in the contract.

Current version
5.2
Effective date
August 20, 2026