Skip to content
Waterfall

Legal

Privacy Policy

How Waterfall handles personal data in Zenda — including health data, which carries stricter rules and a legal basis of its own.

Last updated · August 14, 2026

01Who we are

Waterfall is a Brazilian technology consultancy, registered under CNPJ 42.804.319/0001-10, and the developer of Zenda — a platform for handling patient conversations over WhatsApp, used by people who run the schedule for doctors and clinics.

This policy covers waterfalltech.xyz, the product page at zenda.waterfalltech.xyz, and use of Zenda itself.

This is a translation provided for convenience. The service is operated from Brazil under Brazilian law; in case of any conflict, the Portuguese version prevails.

02Who is responsible for which data

This is the most important section here, and the one that tells you where to send a request.

The doctor or clinic is the controller of their own patients' data (LGPD art. 5, VI). They decide what the data is used for, they collect the patient's number, and they set how long it is kept.

Waterfall is a processor (art. 5, VII). We handle patient data solely to run the service, on the controller's instructions, never for our own purposes. We do not sell data, do not use it for advertising, and do not train AI models on patient message content.

The person using Zenda — the assistant or secretary — handles the data on the controller's behalf. Professional confidentiality extends to assistants (CFM Resolution 2.217/2018, art. 73).

In practice: a patient who wants to access or erase their data must contact the doctor or clinic, not Waterfall. If such a request reaches us, we forward it to the controller — we cannot decide about data that is not ours.

03What data is processed

From Zenda users: name, email, password (stored only as a hash, never in plain text), and access records.

From the account's clients: the doctor's or clinic's name, specialty, medical licence number, contact phone, and the commercial details the user records — agreed fee and billing day.

From patients: WhatsApp number, display name, the content of messages exchanged, appointment dates and times, and whatever the assistant records — procedures performed, return interval and notes.

  • Message content and clinical notes are treated as sensitive health data (art. 5, II).
  • We collect no patient payment data. Zenda processes no payments.
  • We use no advertising cookies and no third-party trackers on the site.

04Cookies and similar technologies

The site sets one cookie, `waterfall_locale`, which remembers the language you picked in the switcher. It is strictly functional: without it, every visit would revert to the browser-detected language and ignore your choice. It does not identify you and is shared with no one.

We use no advertising cookies, tracking pixels, heatmaps or third-party behavioural analytics. That is why this site has no cookie banner — there is nothing to consent to.

Inside Zenda, your session token lives in the browser's local storage to keep you signed in. Signing out clears it.

06Children and adolescents

Underage patients exist — paediatrics, orthodontics and many other specialties see children every day. That raises the standard of care, which is why this has a section of its own.

Data about children and adolescents is processed always in their best interest (LGPD art. 14). The legal basis remains protection of health (art. 11, II, “f”), exercised by the treating professional — not a blanket consent collected by us.

A minor patient's rights are exercised by a parent or legal guardian, with the doctor or clinic treating them.

Zenda is not intended for use by anyone under 18: no account may be created by a minor. Nor do we collect children's data directly — what reaches us comes from the conversation the guardian or the professional starts.

07The specific handling of health data

These are not intentions — they are verifiable properties of the system.

  • Message content never reaches logs, monitoring or error reports. The telemetry filter works by allow-list — a new field is emitted only if explicitly permitted — and an automated test fails if anything leaks.
  • The patient record is separated per client. The same person seen by two doctors has two independent records, and a note written for one never appears on the other's screen.
  • No cross-client aggregation of health data, not even for internal statistics (art. 11, §4).
  • Database-level isolation. Each account sees only its own rows, enforced by the database itself and not only by the application, with an additional per-doctor scope.
  • Read access to a conversation is logged — who opened it, when, and from where. Improper read access is the typical incident in a system like this, and without a log it leaves no trace.
  • Automated messages carry no specialty, procedure or diagnosis, because they travel through Meta's infrastructure. A validation blocks the send if that is attempted.

08Meta and WhatsApp

Zenda uses exclusively the official WhatsApp Business API (Cloud API) from Meta. We do not use unofficial libraries: besides breaching Meta's terms, they expose the practice's number to being banned.

Meta Platforms is a sub-processor for message content, which necessarily passes through its infrastructure to reach the patient. For the delivery metadata Meta generates and keeps on its own account — delivery status, phone number, quality signals — Meta acts as an independent controller under its own terms.

The WhatsApp billing account belongs to the doctor or clinic. Waterfall has no access to that account's payment details.

09Who we share with

Only those necessary to run the service, and always under a data processing agreement:

  • Meta Platforms — sending and receiving WhatsApp messages.
  • Amazon Web Services — hosting, in the São Paulo region (sa-east-1); data at rest is encrypted.
  • An error monitoring tool — receives only technical identifiers and stack traces, with message content discarded before it is sent.
  • Authorities, where there is a legal obligation or court order.

10International transfers

Some of the sub-processors above operate outside Brazil. Those transfers rely on standard contractual clauses under ANPD Resolution 19/2024.

Product data is hosted in Brazil. What leaves are the messages — which must leave, because that is how WhatsApp works — and technical monitoring data.

11How long we keep it

Retention is set by the controller, within the limits of the law and professional regulation. Absent specific instruction:

  • Conversations and records: for as long as the professional–patient relationship lasts. Where the controller considers a record part of the patient's medical file, the professional council's rule applies — CFM Resolution 1.821/2007 sets a minimum of 20 years from the last entry, and permanent retention for anything archived electronically.
  • Application access logs: six months, as required by the Internet Civil Framework (art. 15). This period cannot be shortened on request — it is a legal requirement, not our choice.
  • Audit logs (who opened which conversation, and when): five years, to support the accountability duty in LGPD art. 37.
  • Platform user account data: up to 90 days after the account is closed.
  • Backups: data erased from the live system may persist in backups for up to 30 further days, unused, until normal rotation.

12Data subject rights

The LGPD (art. 18) grants confirmation of processing, access, correction, anonymisation, portability, information about sharing, and erasure.

If you are a patient: contact the doctor or clinic that treats you. They are the controller of your data. If you write to us, we will forward it and tell you where it went.

If you use Zenda or are a Waterfall client: write to hello@waterfalltech.xyz. We respond within the statutory period, free of charge.

You may also petition the ANPD directly — Brazil's National Data Protection Authority — if you believe your rights have not been met (art. 18, §1). You do not have to come to us first.

13How to request deletion of your data

This has its own section because it is the most common question — and because the answer depends on who is asking. A page with the full step-by-step lives at /legal/data-deletion.

If you are a patient: the request goes to the doctor or clinic treating you, who is the controller of your data. Ask them by any means, including the WhatsApp conversation itself. They carry out the deletion inside Zenda. If you write to us by mistake, we forward it to the controller and tell you where it went.

If you use Zenda: ask from within the account, or email hello@waterfalltech.xyz from your registered address. The account and associated data are erased within 15 days.

If you are a doctor or clinic and want to leave: whoever administers the account can export everything and request erasure. We carry it out within 30 days.

In every case deletion is free of charge. What survives it is only what the law requires us to keep — access logs for the statutory period, and the minimum needed to evidence that the request was fulfilled.

14Automated decisions

Zenda makes no automated decisions affecting a patient's interests. There is no algorithmic triage, no clinical risk scoring and no automatic prioritisation of care.

What is automatic is operational and visible: the return date computed from the interval the professional set, and lists ordered by who has waited longest. Every message sent to a patient originates with a person, or with an automation the professional configured and can switch off.

If that changes, this section changes first — and the right to review under LGPD art. 20 will be exercisable with the controller.

15Security and incidents

Encryption in transit and at rest, two-factor authentication, least-privilege access, and logging of access to sensitive data.

In a security incident carrying relevant risk, we notify the controller within 24 hours of becoming aware, so they can meet their duty to notify the ANPD and the data subjects (art. 48).

16Changes

Material changes are emailed to active account holders at least 30 days in advance. The date at the top of this page is always that of the version in force.

17Contact

Waterfall — CNPJ 42.804.319/0001-10 — Rio de Janeiro, Brazil.

Data protection officer (LGPD art. 41): Marcos Nunes — hello@waterfalltech.xyz. This is the channel for questions about this policy and for rights exercised by anyone with a direct relationship with us.

Patients should contact the doctor or clinic treating them, who is the controller and appoints their own officer.

National Data Protection Authority (ANPD): gov.br/anpd