Legal
Privacy Policy
How Waterfall handles personal data in Zenda — including health data, which carries stricter rules and a legal basis of its own.
Last updated · August 14, 2026
01Who we are
Waterfall is a Brazilian technology consultancy, registered under CNPJ 42.804.319/0001-10, and the developer of Zenda — a platform for handling patient conversations over WhatsApp, used by people who run the schedule for doctors and clinics.
This policy covers waterfalltech.xyz, the product page at zenda.waterfalltech.xyz, and use of Zenda itself.
This is a translation provided for convenience. The service is operated from Brazil under Brazilian law; in case of any conflict, the Portuguese version prevails.
02Who is responsible for which data
This is the most important section here, and the one that tells you where to send a request.
The doctor or clinic is the controller of their own patients' data (LGPD art. 5, VI). They decide what the data is used for, they collect the patient's number, and they set how long it is kept.
Waterfall is a processor (art. 5, VII). We handle patient data solely to run the service, on the controller's instructions, never for our own purposes. We do not sell data, do not use it for advertising, and do not train AI models on patient message content.
The person using Zenda — the assistant or secretary — handles the data on the controller's behalf. Professional confidentiality extends to assistants (CFM Resolution 2.217/2018, art. 73).
In practice: a patient who wants to access or erase their data must contact the doctor or clinic, not Waterfall. If such a request reaches us, we forward it to the controller — we cannot decide about data that is not ours.
03What data is processed
From Zenda users: name, email, password (stored only as a hash, never in plain text), and access records.
From the account's clients: the doctor's or clinic's name, specialty, medical licence number, contact phone, and the commercial details the user records — agreed fee and billing day.
From patients: WhatsApp number, display name, the content of messages exchanged, appointment dates and times, and whatever the assistant records — procedures performed, return interval and notes.
- Message content and clinical notes are treated as sensitive health data (art. 5, II).
- We collect no patient payment data. Zenda processes no payments.
- We use no advertising cookies and no third-party trackers on the site.
05On what legal basis
For health data the basis is protection of health, in a procedure carried out by health professionals and health services (art. 11, II, “f”) — not consent. That is deliberate: consent can be withdrawn at any moment, and a record that vanishes mid-treatment is a risk to the patient.
For platform users and client account data, the basis is performance of a contract (art. 7, V).
For security and fraud prevention, the basis is legitimate interest (art. 7, IX), with a documented impact assessment.
For retaining application access logs, the basis is compliance with a legal obligation (art. 7, II): Brazil's Internet Civil Framework (Law 12.965/2014, art. 15) requires an application provider incorporated as a legal entity to keep those logs for six months, under confidentiality and in a controlled environment.
06Children and adolescents
Underage patients exist — paediatrics, orthodontics and many other specialties see children every day. That raises the standard of care, which is why this has a section of its own.
Data about children and adolescents is processed always in their best interest (LGPD art. 14). The legal basis remains protection of health (art. 11, II, “f”), exercised by the treating professional — not a blanket consent collected by us.
A minor patient's rights are exercised by a parent or legal guardian, with the doctor or clinic treating them.
Zenda is not intended for use by anyone under 18: no account may be created by a minor. Nor do we collect children's data directly — what reaches us comes from the conversation the guardian or the professional starts.
07The specific handling of health data
These are not intentions — they are verifiable properties of the system.
- Message content never reaches logs, monitoring or error reports. The telemetry filter works by allow-list — a new field is emitted only if explicitly permitted — and an automated test fails if anything leaks.
- The patient record is separated per client. The same person seen by two doctors has two independent records, and a note written for one never appears on the other's screen.
- No cross-client aggregation of health data, not even for internal statistics (art. 11, §4).
- Database-level isolation. Each account sees only its own rows, enforced by the database itself and not only by the application, with an additional per-doctor scope.
- Read access to a conversation is logged — who opened it, when, and from where. Improper read access is the typical incident in a system like this, and without a log it leaves no trace.
- Automated messages carry no specialty, procedure or diagnosis, because they travel through Meta's infrastructure. A validation blocks the send if that is attempted.
08Meta and WhatsApp
Zenda uses exclusively the official WhatsApp Business API (Cloud API) from Meta. We do not use unofficial libraries: besides breaching Meta's terms, they expose the practice's number to being banned.
Meta Platforms is a sub-processor for message content, which necessarily passes through its infrastructure to reach the patient. For the delivery metadata Meta generates and keeps on its own account — delivery status, phone number, quality signals — Meta acts as an independent controller under its own terms.
The WhatsApp billing account belongs to the doctor or clinic. Waterfall has no access to that account's payment details.
09Who we share with
Only those necessary to run the service, and always under a data processing agreement:
- Meta Platforms — sending and receiving WhatsApp messages.
- Amazon Web Services — hosting, in the São Paulo region (sa-east-1); data at rest is encrypted.
- An error monitoring tool — receives only technical identifiers and stack traces, with message content discarded before it is sent.
- Authorities, where there is a legal obligation or court order.
10International transfers
Some of the sub-processors above operate outside Brazil. Those transfers rely on standard contractual clauses under ANPD Resolution 19/2024.
Product data is hosted in Brazil. What leaves are the messages — which must leave, because that is how WhatsApp works — and technical monitoring data.
11How long we keep it
Retention is set by the controller, within the limits of the law and professional regulation. Absent specific instruction:
- Conversations and records: for as long as the professional–patient relationship lasts. Where the controller considers a record part of the patient's medical file, the professional council's rule applies — CFM Resolution 1.821/2007 sets a minimum of 20 years from the last entry, and permanent retention for anything archived electronically.
- Application access logs: six months, as required by the Internet Civil Framework (art. 15). This period cannot be shortened on request — it is a legal requirement, not our choice.
- Audit logs (who opened which conversation, and when): five years, to support the accountability duty in LGPD art. 37.
- Platform user account data: up to 90 days after the account is closed.
- Backups: data erased from the live system may persist in backups for up to 30 further days, unused, until normal rotation.
12Data subject rights
The LGPD (art. 18) grants confirmation of processing, access, correction, anonymisation, portability, information about sharing, and erasure.
If you are a patient: contact the doctor or clinic that treats you. They are the controller of your data. If you write to us, we will forward it and tell you where it went.
If you use Zenda or are a Waterfall client: write to hello@waterfalltech.xyz. We respond within the statutory period, free of charge.
You may also petition the ANPD directly — Brazil's National Data Protection Authority — if you believe your rights have not been met (art. 18, §1). You do not have to come to us first.
13How to request deletion of your data
This has its own section because it is the most common question — and because the answer depends on who is asking. A page with the full step-by-step lives at /legal/data-deletion.
If you are a patient: the request goes to the doctor or clinic treating you, who is the controller of your data. Ask them by any means, including the WhatsApp conversation itself. They carry out the deletion inside Zenda. If you write to us by mistake, we forward it to the controller and tell you where it went.
If you use Zenda: ask from within the account, or email hello@waterfalltech.xyz from your registered address. The account and associated data are erased within 15 days.
If you are a doctor or clinic and want to leave: whoever administers the account can export everything and request erasure. We carry it out within 30 days.
In every case deletion is free of charge. What survives it is only what the law requires us to keep — access logs for the statutory period, and the minimum needed to evidence that the request was fulfilled.
14Automated decisions
Zenda makes no automated decisions affecting a patient's interests. There is no algorithmic triage, no clinical risk scoring and no automatic prioritisation of care.
What is automatic is operational and visible: the return date computed from the interval the professional set, and lists ordered by who has waited longest. Every message sent to a patient originates with a person, or with an automation the professional configured and can switch off.
If that changes, this section changes first — and the right to review under LGPD art. 20 will be exercisable with the controller.
15Security and incidents
Encryption in transit and at rest, two-factor authentication, least-privilege access, and logging of access to sensitive data.
In a security incident carrying relevant risk, we notify the controller within 24 hours of becoming aware, so they can meet their duty to notify the ANPD and the data subjects (art. 48).
16Changes
Material changes are emailed to active account holders at least 30 days in advance. The date at the top of this page is always that of the version in force.
17Contact
Waterfall — CNPJ 42.804.319/0001-10 — Rio de Janeiro, Brazil.
Data protection officer (LGPD art. 41): Marcos Nunes — hello@waterfalltech.xyz. This is the channel for questions about this policy and for rights exercised by anyone with a direct relationship with us.
Patients should contact the doctor or clinic treating them, who is the controller and appoints their own officer.
National Data Protection Authority (ANPD): gov.br/anpd