Skip to content

Privacy Policy

Last updated: July 26, 2026 · Version: privacy-notice-en-2026-07-26 · Effective: July 26, 2026

1. Who processes data and in what role

NuvaMed SpA ("NuvaMed"), RUT 78.385.718-9, with its publicly stated location in Las Condes, Santiago, is the controller for processing it determines directly, including professional accounts, contracting and billing, support, security, abuse prevention, and authorized commercial communications. If public-site analytics is enabled later, NuvaMed will be the controller for that processing and must respect the visitor's informed preference.

For clinical records and other patient data processed to deliver healthcare, the healthcare provider —the professional or institution— determines the care purpose and retains the custody and responsibilities assigned by healthcare law. For those activities, NuvaMed provides technology as a processor acting on the provider's documented instructions, without prejudice to NuvaMed's own legal obligations.

Before clinical production processing is enabled, the provider and NuvaMed must execute the applicable data processing agreement. Publishing this policy or a contract template does not replace execution and verification of that agreement.

The responsible party and rights channel therefore depend on the purpose. Requests about a clinical record are coordinated with the provider treating the patient; NuvaMed receives or routes the request where appropriate.

Contact: contacto@nuvamed.cl

2. Legal framework

This policy describes processing in light of current Chilean law and obligations applicable to healthcare providers, including:

Ley 21.719 was published, and its principal amendments enter into force on December 1, 2026. NuvaMed is adapting its contracts, controls, and procedures for that date; this reference does not mean that a future obligation is already in force or replace an assessment of each processing activity.

3. Data we collect

3.1 Healthcare professional data

3.2 Patient data

3.3 Technical data

4. Purpose of data processing

5. Legal basis

The applicable basis depends on the actor, purpose, and type of data. Delivery of this notice provides information about processing and is not, by itself, consent for every purpose.

5.1 Express authorization for necessary account data

Under article 4 of Ley 19.628 in force through November 30, 2026, registration or re-acceptance presents a separate action with this scope: “I expressly authorize NuvaMed SpA to process the personal data strictly necessary to administer and authenticate my account, provide and protect the service, handle support, prevent and investigate fraud, abuse, and security incidents, and manage the plan, billing, tax documents, and necessary transactional communications.”

The authorization covers name, RUT, contact details, profession, professional registration, institution or practice, account and session identifiers, authentication and security events, support requests, subscribed plan, billing details, and payment metadata NuvaMed receives from its payment provider. NuvaMed does not request or store complete card details under this authorization.

These data will not be disclosed to the public. They may be disclosed only to processors and providers needed for the stated purposes, to the extent described in this notice and subject to applicable contracts and controls.

This authorization is necessary to create and operate a professional account. If it is not granted, NuvaMed cannot open or maintain that account. It does not authorize marketing, non-essential analytics, recordings, AI features, or the processing of patient clinical data; those purposes require their applicable basis and, where required, a separate optional choice or specific consent. Declining an optional purpose does not prevent use of functions that do not require it.

The authorization may be revoked in writing for future processing by emailing contacto@nuvamed.cl. Revocation is not retroactive and may require account closure or restriction where processing is indispensable to provide or protect the service, without affecting legal retention duties.

6. Third-party integrations

6.1 Zoom Video Communications

NuvaMed integrates with Zoom for telemedicine sessions. When a professional connects their Zoom account:

For more information, see Zoom's Privacy Policy.

6.2 Google — Sign-In

We offer Google Sign-In. When a user chooses this option, we access only their name, email address, and profile picture from the Google account, for the sole purpose of creating or authenticating their NuvaMed account. We do not access any other Google account data through sign-in.

6.3 Google Calendar and Google Meet (telemedicine)

If a healthcare professional chooses to connect their Google account to generate Google Meet video-call links, NuvaMed requests the https://www.googleapis.com/auth/calendar.events scope of the Google Calendar API. With this permission:

Limited Use: NuvaMed's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, data obtained through Google APIs is used exclusively to provide or improve user-facing features within NuvaMed; it is not transferred to third parties except as necessary to provide those features, for security purposes, to comply with applicable laws, or in connection with a merger or acquisition; and it is not used or sold for advertising purposes.

6.4 Google Gemini (AI)

NuvaMed uses Google Gemini or Vertex AI, depending on the active configuration, for clinical-assistance functions: summaries, analysis and pre-session briefings, and —when the professional uses AI Scribe— transcription and structuring of draft clinical notes from session audio or a transcript.

Audio or text is transmitted encrypted in transit to the AI service. Minimization and pseudonymization controls are applied before or after transmission depending on the technical route; audio necessarily contains the original conversation during transcription and cannot be considered anonymous. For large recordings, the application uses Google's Files API and attempts to delete the file immediately after processing. If deletion fails or expires, Google may retain the file until its automatic expiry, currently up to 48 hours.

To support recovery after an interruption, certain AI Scribe routes may store an encrypted audio copy in NuvaMed infrastructure for a configurable technical period from 1 to 90 days. Encrypted text segments and partial facts may also be retained for continuity and traceability, in addition to the draft or clinical note reviewed and signed by the professional. Applicable retention is described in section 8 and must match the information shown to the patient before the feature is activated.

NuvaMed does not use clinical content for advertising or to train its own models. Google's use and retention terms depend on the active service and contract. Processing may occur outside Chile where a route without regional residency is used; production configuration, contractual terms, and transfer safeguards must therefore be verified for the enabled feature.

6.5 Infrastructure, payments, communications, and monitoring

These providers receive only the categories needed for the relevant function. Their effective region may differ from the application's primary region and depends on provider and configuration.

6.6 Public-site analytics

Non-essential analytics is disabled on the public site while no preference mechanism is available to support an informed choice before loading it. Local events prepared by a page are not transmitted to Google Tag Manager. If analytics is enabled later, this notice and the provider register must identify the tags, data categories, recipients, retention, and applicable transfers; clinical-record data must never be sent to those tools.

7. Security

No security measure eliminates all risk. NuvaMed reviews its controls and handles vulnerabilities and incidents according to their severity.

8. Data retention

9. Rights and requests

Personal data subjects may exercise their rights to:

Requests may be made through the in-app privacy portal or by writing to contacto@nuvamed.cl. Where a request concerns a clinical record, the requester may be asked to identify the responsible healthcare provider so NuvaMed can route or coordinate it. NuvaMed will acknowledge and respond within the applicable legal period, including any permitted extension and reason.

10. Breach notification

When an incident affects personal data, NuvaMed assesses its scope, contains and documents the incident, informs the responsible healthcare provider where appropriate, and makes communications required by applicable law and contracts without undue delay. The recipient and timing depend on the incident's nature, risk, and the rules in force; this policy does not state a universal 72-hour deadline.

11. International transfers

Primary application infrastructure is hosted on Google Cloud Platform in Santiago, Chile. Some integrations, messaging, monitoring, and AI routes may process data outside Chile. NuvaMed must identify the active service and region, limit transfer to what is necessary, and apply the contract, authorization, or other safeguard required for the relevant processing. A non-regional AI route must not be described as processing exclusively in Chile.

12. Modifications

We may update this policy to reflect legal, operational, or provider changes. We will publish the date and version, retain history, and notify material changes before they take effect. Where a new purpose requires consent, NuvaMed will request a specific choice; continued use does not replace that consent.

13. Contact

For privacy and data protection inquiries:

NuvaMed SpA
RUT: 78.385.718-9
Publicly stated location: Las Condes, Santiago, Chile
Email: contacto@nuvamed.cl
Website: nuvamed.cl