GDPR · Legal

Privacy Policy

Last updated: August 3, 2026

Your health data is our top priority

Cardiograma processes special category data (health data). Please read this policy in full to understand how your data is protected and which rights you have under GDPR.

1. Data controller and contacts

The data controller is Infratartism, Lda., Portuguese legal entity with tax number (NIF) 517284707, owner of the Cardiograma domain, brand, and application. Cardiograma is a cardiovascular follow-up platform operated under the clinical supervision of Dr. Mafalda Carrington, Clinical Director and Cardiologist, registered with the Portuguese Medical Association under professional number OM60673. In-person consultations are provided at Clínica Jardim Botânico, Porto, a healthcare unit registered with ERS under number 180108. Privacy and data protection contacts: - Privacy email (GDPR rights requests): privacidade.cardiograma@protonmail.com - General contact: geral@cardiograma.pt - Data Protection Officer (DPO): Gonçalo Santos, privacidade.cardiograma@protonmail.com - Legal postal address: Rua de Serralves 777 RC Esq, 4150-702, Porto

2. Data we collect

We collect only the data strictly necessary to provide our services: Identification data: name, date of birth, tax number (NIF), phone number, and email address. Health data: medical history, medication, diagnoses, exam results (including ECG traces manually uploaded by the user), consultation records, manual measurements (e.g., blood pressure and cholesterol), nutrition logs, and smoking-cessation follow-up data (quit/reduce goal, craving and consumption entries recorded by the user). Connected device/account data: monitoring data from devices and platforms the user chooses to connect (see Section 3), collected only with consent and in read-only mode. Usage data: technical information about your device/browser, IP address, and platform interactions, for security and service improvement. Financial data: payment-related information required for invoicing. Card data is processed by certified payment providers and is not stored by Cardiograma.

3. Connected health devices and accounts (Apple Health and Health Connect)

Cardiograma may integrate data from health devices and accounts you choose to connect. This is optional, always requires explicit consent, and is read-only; we do not write, modify, or delete data in those platforms. Currently supported data sources: - Apple Health (HealthKit), data from any devices connected to these apps on Apple smartphones (Cardiograma iOS app); - Health Connect (Android), data from any devices/apps that write to Health Connect on the Android phone (Cardiograma Android app). Data read (only what is required for clinical follow-up): heart rate, resting heart rate, HRV, blood oxygen (SpO2), sleep, activity (steps/exercise/active minutes), blood pressure where available, and basic profile data where applicable. Manually uploaded ECG PDFs/images in Cardiograma are not Apple Health "Clinical Health Records". Clinical Health Records (Apple): by default, Cardiograma does not access hospital clinical records (e.g., lab results, discharge summaries, hospital medication) through Apple Health. If enabled in the future, this will remain optional and require additional explicit consent. Clinical team access (consent). By connecting a health device/account, the user expressly consents that their responsible cardiologist and authorized clinical team may access and review this data as part of the follow-up service. This human access is essential to the clinical purpose and may be revoked at any time. How we use (and do not use) this data. Data from these integrations is used only for health management within the service. It is never used for advertising, marketing profiling, or data brokerage, and is not used to train AI models. Apple Health data is not stored in iCloud. On Android, reading is local via Health Connect (we do not use the Google Health API / health restricted OAuth scopes). Google Limited Use commitment. Cardiograma's use and transfer of information received from other Google APIs (for example Calendar, when connected) follows the Google API Services User Data Policy, including Limited Use requirements. How to revoke. You can disconnect any integration at any time in Cardiograma account settings. You can also revoke access directly in iOS Settings > Privacy & Security > Health (Apple Health) or in Android Settings > Health Connect. After revocation, we stop syncing new data from that source; previously integrated data is handled as described in Section 9.

4. Purpose of processing

Your data is processed exclusively for: - Online and in-person medical consultations and ongoing clinical follow-up; - Management of personalized cardiovascular programs (including diet and exercise plans), as well as follow-up of nutrition and smoking habits recorded by the user; - Communication about appointments, results, and clinical alerts; - Billing and invoicing; - Legal compliance (including clinical documentation obligations); - Service quality improvement using anonymized and aggregated data. Your health data is never used for commercial advertising purposes and is never shared with third parties without explicit consent.

5. Artificial intelligence and the Heartbeet (Beet) assistant

Cardiograma uses AI tools, including Heartbeet, to support follow-up (e.g., organizing information and generating suggestions) always under clinical supervision. In the Nutrition section, AI may also estimate macronutrients from meal descriptions or photos and generate progress suggestions at the user's explicit request; these features are optional and do not replace medical advice. AI is a clinical support tool and does not replace medical judgment. AI processing may involve technology subprocessors under data protection agreements, who do not use your data to train their own models. Inference calls are routed, whenever the model supports it, to data centers in the European Union. Health data, including data from connected devices/accounts, is not used to train AI models. No decisions producing legal or similarly significant effects are made solely by automated means. Any AI-generated suggestion is reviewed and validated by a healthcare professional, in line with GDPR Article 22.

6. Legal basis

Processing is based on: - Contract performance (service delivery requested by the user); - Explicit consent (special category health data and optional device/account connections); - Legal obligation (clinical documentation and tax/accounting obligations); - Legitimate interests (platform security and fraud prevention). For health data (special category), processing also relies on GDPR Article 9(2), including explicit consent (a) and provision/management of healthcare under professional secrecy obligations (h).

7. Data sharing and clinical access

Personal and health data is never sold, rented, or shared for commercial purposes. Clinical data access is restricted to the responsible cardiologist and authorized clinical/administrative staff, strictly as necessary to provide the service. Data may be shared only: - With service providers acting as processors (e.g., cloud infrastructure, payments, AI tools), under data processing agreements; - Under legal obligation (court order or competent authority request); - In medical emergencies, with healthcare professionals directly involved in treatment, whenever possible with user awareness. Main processors and categories: - Vercel: app/API hosting and runtime; - Supabase: database, authentication, and clinical storage (primary project hosted in Ireland, EU); - Stripe: payment processing; - Google: appointment scheduling (Google Calendar) and video calls (Google Meet); - Resend: transactional emails (appointment confirmations and reminders); - Apple/Google: optional health integrations (with consent). This processor list may be updated periodically. Where applicable, we execute DPAs and use legal transfer mechanisms including Standard Contractual Clauses.

8. Storage and security

Cardiograma's primary clinical data infrastructure is located in the EU, including the primary database/authentication project in Ireland (EU), with safeguards including: - Encryption in transit (TLS/HTTPS) and at rest; - Restricted access controls and two-factor authentication for healthcare professionals; - Regular backups and disaster recovery plans; - Audit logging of clinical data access. If any processor is established outside the EEA, or performs part of the processing outside the EEA (e.g., support/security operations/subprocessors), transfers occur only under an adequacy decision or appropriate safeguards such as SCCs. Health data from connected devices/accounts is not stored in personal cloud storage services, including iCloud.

9. Retention, revocation, and deletion

Clinical data is retained for at least the minimum period required by Portuguese clinical documentation laws and regulatory guidance (including Law no. 12/2005 and ERS guidance). Some records may require longer or permanent retention by law. You can delete your account and data directly in the app (Settings › Account and data deletion, immediate), via the public page at cardiograma.pt/eliminar-dados, or by contacting geral@cardiograma.pt. Deletion removes your profile, personal data, health metrics and external-service connections. Non-clinical account data is deleted immediately or within 30 days, unless legal retention obligations apply. Clinical and tax records subject to mandatory legal retention are kept in anonymized form for the applicable period. If the user disconnects an integration or closes the account, we immediately stop collecting new data from that source. Already integrated data follows the retention rules above and may only be deleted where legally allowed. Anonymized and aggregated data used for service improvement/research is not subject to deletion deadlines as it does not identify individuals. Practical retention by category: - Non-clinical account data: up to 30 days after account closure (unless legal obligation applies); - Scheduling/billing data: according to legal accounting and tax obligations; - Clinical/follow-up data: according to applicable clinical documentation laws; - Technical/security logs: only for the period strictly necessary for security, auditing, and fraud detection.

10. Your rights

Under GDPR, you have rights including access, rectification, erasure (where legally possible), portability, objection, restriction, and consent withdrawal. Access to your clinical documentation is also ensured under Portuguese Law no. 12/2005. How to exercise rights: - Send your request to privacidade.cardiograma@protonmail.com; - Specify the right you want to exercise and, when needed, minimum information for identity verification; - We respond within the GDPR legal timeframe (normally up to 30 days, extendable where legally applicable); - You may file a complaint with CNPD if unsatisfied.

11. Minors

The platform is intended for users aged 18 or older. We do not intentionally collect data from minors without express consent from a legal representative. If you are a legal representative of a minor needing cardiology follow-up, contact us so we can assess legal and clinical safeguards.

12. Cookies and similar technologies

The platform uses strictly necessary cookies for authentication and session functionality. We do not use advertising tracking cookies. We may use anonymous analytics tools to understand usage patterns and improve the platform without individual identification.

13. Supervisory authority

If you believe your data is processed in violation of GDPR, you may complain to: Comissão Nacional de Proteção de Dados (CNPD) Rua de São Bento, 148-3.º, 1200-821 Lisboa www.cnpd.pt

14. Changes to this policy

This Privacy Policy may be updated to reflect legal or operational changes. Material changes are communicated in advance by email and/or prominent in-app notice. If we use Apple Health/Health Connect data in a materially new way, we will notify you and request renewed consent before doing so.