BeMiVe

Consent Terms

Consent for the processing of sensitive health data • Version 1.2 • Last updated: August 7, 2026

Português|English|Español|Français

This document is your free, informed, unequivocal and specific consent to the processing of sensitive personal health data. It applies together with the regional rights described in the Privacy Policy (PIPEDA and Québec's Law 25 in Canada, the Privacy Act and Australian Privacy Principles in Australia, and U.S. consumer-health-data laws).

Consent is collected in a prominent, separate way, for specific purposes.

1. Controller identification

  • Controller: W N P DE MATOS SOLUCOES EM INFORMATICA - ME, Brazilian company registry (CNPJ) 10.234.041/0001-04
  • Data Protection Officer (DPO) / Privacy Officer: Weverly Matos (support@bemive.com)
  • Contact channels: the e-mail above or "Support > Privacy" in the app

2. Sensitive data covered by this consent

When using BeMiVe you may provide sensitive personal data concerning health. The categories of sensitive data we process include:

  • Health indicators: weight, BMI, blood pressure, blood glucose, heart rate, oxygen saturation, temperature;
  • Laboratory and imaging exams: results, photos of reports, medical prescriptions;
  • Medications: name, dosage, frequency, times, side effects, including specialized treatments such as GLP-1 (Ozempic, Wegovy and similar);
  • Vaccines: type, dose, administration date, manufacturer, batch, immunization schedule;
  • Symptoms and conditions: symptom logs, chronic conditions, allergies, intolerances;
  • Physical activity and wellness data: workouts, sleep, hydration, health goals;
  • Smartwatch and wearable data: continuous heart rate, heart-rate variability, steps, calories, sleep data;
  • Family medical history: hereditary conditions recorded in the family context;
  • Health attachments: PDFs, exam images, prescriptions, medical reports, certificates.

3. Specific purposes of processing

Your sensitive health data will be processed exclusively for the following purposes:

3.1. Health monitoring and organization

Storing, organizing and displaying your health data in a structured way, enabling indicator tracking over time, charts and reports, and progress toward personal goals.

3.2. Health reminders and alerts

Sending notifications and reminders about medications, appointments, vaccines, hydration and other care routines, by push, e-mail, Alexa or other enabled channels.

3.3. Artificial-intelligence analysis

Processing your health data with artificial-intelligence models to:

  • analyze exam and prescription photos via OCR and AI, generating simplified explanations;
  • produce personalized health summaries with a wellness score;
  • answer health queries via the integration with ChatGPT and other AI assistants;
  • identify patterns and trends in your data for preventive suggestions.

Sending to AI providers happens exclusively through our backend gateway, with no direct communication between your device and the models. Only the content strictly necessary to the request context is transmitted. Each provider's processing of your data is governed by that provider's terms and privacy policy, listed in the sharing section.

3.3.1. What you are told before using AI

Before any AI feature runs, you are clearly informed about:

  • which data may be processed;
  • which provider may process it (DeepSeek and Google Cloud Vision; and, in the optional ChatGPT integration, OpenAI);
  • the purposes of the processing;
  • the technology's limitations and the possibility of error;
  • how to withdraw consent.

Warning: AI-generated insights are informational only and do not constitute medical diagnosis, prescription or professional health guidance. Always consult a qualified professional for decisions about your health.

3.4. Smartwatch and wearable integration

Importing and storing wearable sensor data (heart rate, steps, sleep, physical activity) to enrich your health profile and provide more complete insights.

3.5. Voice and AI assistants

Allowing you to check and record health data by voice (Alexa) and by text (ChatGPT), including reading indicators, recording medications and receiving reminders.

3.6. Family and dependant management

Allowing legal guardians to manage dependants' health data (minor children, elders in their care, other authorized family members) inside the app's family context, with per-profile access control.

3.7. Pet health management

Storing and organizing pets' health data (vaccines, medications, veterinary appointments, weight, exams) linked to the owner's profile.

3.8. Backup and portability

Generating encrypted backups of health data to protect against loss, and enabling structured export for exercising the right to portability.

4. Sharing of sensitive data

Your sensitive health data may be shared with:

  • AI providers (DeepSeek and Google Cloud Vision; and, in the optional ChatGPT integration, OpenAI): data is sent encrypted and limited to the query context. Each provider's processing is governed by its own terms and privacy policy. This feature is optional and activates only when you use it.
  • Amazon Alexa: voice commands are processed by Amazon to perform actions in BeMiVe, under Amazon's own privacy policy.
  • Authorized family members: within family profiles, legal guardians can view and manage dependants' data. Sharing between adults of the same family requires each data subject's express authorization.
  • People you authorize via link: when you generate a shared-record link or the emergency card, the selected data becomes accessible to anyone holding the link during its validity period; the emergency card requires no login, by design, for urgent situations. Accesses are logged and can be revoked at any time in the app.
  • Corporate portal: only aggregated, anonymized statistics are made available to the contracting company — never individual data. Anonymization requires a minimum number of participants to prevent re-identification.
  • Infrastructure providers: Amazon Web Services (EC2, RDS PostgreSQL, S3) and Firebase (push notifications, analytics) process data under processing agreements ensuring confidentiality and equivalent security.

What is never sent to AI providers: under no circumstances do we transmit passwords, authentication tokens, national ID numbers, phone, address, payment or card data, biometric data or third-party credentials. Documents unrelated to the request are not included.

Where data is transferred internationally (for example, DeepSeek in China; and Google, OpenAI and Amazon with servers in the United States and other regions), we adopt standard contractual clauses and, for jurisdictions without a recognized adequate level of protection, we carry out a transfer impact assessment (TIA) with supplementary measures.

Your sensitive health data is never sold, assigned or shared for advertising purposes.

5. Consent for children, adolescents and dependants

Processing of children's and adolescents' personal data is carried out in the minor's best interest, with the specific, prominent consent of at least one parent or legal guardian. In the United States, we comply with COPPA for children under 13; in Québec, parental consent is required for children under 14.

By registering a dependant in BeMiVe, the legal guardian declares and consents that:

  • they have legal authority to consent on the dependant's behalf;
  • the dependant's health data will be processed under the same conditions and purposes described in this document;
  • access to the dependant's data is controlled by the guardian, who can grant or revoke access for other family members;
  • upon reaching the age of majority under the law of their place of residence, the dependant may exercise their rights directly as the data subject over the existing data, including requesting access, portability or deletion;
  • at any time, the guardian may request the deletion of the dependant's data.

BeMiVe may request proof of family relationship or legal guardianship before acting on requests related to dependants.

6. Pet data

Pets' health data is not personal data under data-protection laws. We nonetheless treat it with the same care and security measures applied to the platform's other data. By registering a pet, you consent to the storage, organization and use of the animal's data for the veterinary-tracking features the app offers.

7. Withdrawing consent

You can withdraw this consent at any time, free of charge and easily, through:

  • the app settings, "Privacy and Data" section;
  • e-mail to support@bemive.com;
  • the "Support > Privacy" section in the app.

Withdrawal does not affect the lawfulness of processing carried out beforehand on the basis of consent. After withdrawal, features that depend on sensitive-data processing are disabled. Data already anonymized, or needed to meet a legal obligation, is retained as the applicable law requires.

You can withdraw specific consents without affecting others. For example, you can withdraw consent for AI analysis while keeping consent for basic health monitoring.

8. Consent granularity

BeMiVe lets you manage your consents granularly. You can choose to consent — or not — to each of the following processing categories independently:

CategoryDescriptionRequired?
Basic health dataRecording weight, blood pressure, blood glucose, medications, symptomsYes (to use the app)
AI exam analysisSending exam photos for automated analysis and explanationNo
AI health summaryGenerating a score and personalized insightsNo
ChatGPT and assistantsHealth queries through the AI gatewayNo
SmartwatchImporting wearable dataNo
AlexaChecking and recording by voice commandsNo
Family profilesSharing data between family membersNo
Automatic backupMonthly encrypted on-device backupNo

Consent for "Basic health data" is necessary to use the app's core features. The other consents are optional and can be turned on or off independently in the app settings.

9. Protection measures for sensitive data

To protect your sensitive health data, we adopt the following measures:

  • Encryption in transit (TLS 1.2+) and at rest;
  • Secure on-device storage (Flutter Secure Storage / Keychain);
  • Profile-based access control with strict separation between data subjects;
  • Authorization middleware for access to dependants' data (family-link verification);
  • Password hashing with Argon2 and rotating authentication tokens;
  • Audit logs with masking of sensitive data (ID numbers, tokens, e-mails);
  • Data sent to AI providers is transmitted encrypted, with no retention by the provider;
  • Anonymization via k-anonymity (minimum of 5 participants per group) and pseudonymization in the corporate portal;
  • Periodic security testing and an incident response plan.

10. Your rights as data subject

Beyond withdrawing consent, you have the right to:

  • access all the sensitive data we process about you;
  • correct incorrect or outdated data;
  • request erasure of data processed on the basis of consent;
  • request portability of your data in a structured format;
  • obtain information about with whom your data has been shared;
  • request a review of automated decisions based on your sensitive data;
  • be informed about the consequences of not granting consent;
  • complain to the supervisory authority of your region: ANPD (Brazil), Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information (Québec), the Office of the Australian Information Commissioner (Australia), or the FTC and your state attorney general (United States).

Exercise your rights at support@bemive.com or through "Support > Privacy" in the app. Response time: 15 days (Brazil) / 30 days (other regions).

11. Consequences of not granting or withdrawing consent

We inform you that:

  • Without consent for basic health data, the app's core features (indicator, medication and exam tracking) cannot be used;
  • Withdrawing consent for optional features (AI, smartwatch, Alexa, ChatGPT) disables only the corresponding feature, without affecting the rest of the app;
  • No feature is degraded as a penalty for not granting or for withdrawing consent for optional items;
  • Account deletion removes all personal data, subject to mandatory legal retention.

12. Duration and changes

This consent remains in force while your account is active or until you withdraw it. Substantial changes to these terms will be communicated 30 days in advance by e-mail, push or in-app, and may require a new expression of consent.

13. Declaration of consent

By checking the consent box in the app or on the website, or by using features that involve sensitive health data, you declare that you:

  • have read and fully understood these Consent Terms;
  • have been informed about the specific purposes of the processing of your sensitive data;
  • agree, freely and unequivocally, to the processing of your sensitive data for the purposes described here;
  • are aware that you can withdraw this consent at any time, at no cost or prejudice;
  • have been informed about your rights as a data subject;
  • where applicable, consent on behalf of your minor dependants, in observance of the child's best interest.

Related documents