Privacy Policy
Introduction
Telepatía S.A.S., with NIT 901.863.452-7, domiciled in Medellín, in compliance with Law 1581 of 2012 and its regulatory decrees, commits to guarantee the protection and adequate management of personal data collected through the Telepatía application, a platform that uses artificial intelligence (AI) to optimize the interaction between Health Professionals and Users through technological means.
By authorizing the processing of their Personal Data, the Data Subject expresses their consent for such data to be processed in accordance with the provisions of this Privacy Policy and Personal Data Protection and the Terms and Conditions applicable to Users, which form an integral part of this document. In that order of ideas, by authorizing the Processing of their Personal Data, the Data Subject declares having read and understood its content.
1. OBJECTIVE
The objective of this Privacy Policy and Personal Data Protection, (hereinafter "Privacy Policy"), is to comply with Statutory Law No. 1581 of 2012, its Regulatory Decree 1074 of 2015 (Chapter 25) and other regulations governing Personal Data Protection.
2. SCOPE
This Privacy Policy is applicable both to Telepatía S.A.S., as Data Controller and its direct and indirect employees, as well as to all those third natural or legal persons to whom it Transmits Personal Data of the Data Subjects that comprise the Interest Groups of the Data Controller, when they perform any Processing on them at their request.
Insofar as this Privacy Policy is applicable only whenever Telepatía S.A.S. acts as Data Controller, the Data Subject exempts the company from the Processing of Personal Data that Health Professionals may perform and recognizes that such operations will be covered by the particular data processing policies of health service providers.
3. IDENTIFICATION OF THE DATA CONTROLLER
COMPANY NAME: TELEPATÍA S.A.S.
DOMICILE: MEDELLÍN
ADDRESS: Calle 7 # 18 - 85
EMAIL: ayuda@telepatia.ai
PHONE: 3146566962
4. DEFINITIONS
For the purposes of this Privacy Policy, the following shall be understood as:
ADOLESCENT: Persons between 12 and 18 years of age (Code of Children and Adolescents, article 3).
AUTHORIZATION: Prior, express and informed consent of the Personal Data Subject to carry out the Processing of their personal data, which may be collected (i) in writing, (ii) orally or (iii) through unequivocal conduct that allows to reasonably conclude that they granted the authorization.
PRIVACY NOTICE: Physical or electronic document, or a document in any other format, generated by the Data Controller and made available to the Data Subject for the Processing of their personal data. The Privacy Notice informs the Data Subject about the existence of the data processing policies applicable to them, how to access them, and the characteristics of the processing intended to be given to the Personal Data.
DATABASE: Organized set of personal data, physical or electronic, subject to manual or automated Processing.
PERSONAL DATA: Any information linked or that may be associated with one or more determined or determinable natural persons. The nature of Personal Data may be public, semi-private, private or sensitive.
PRIVATE DATA: Data that by its intimate or reserved nature is only relevant to the Data Subject.
PUBLIC DATA: Data qualified as such according to the mandates of the law or the Political Constitution, and data that is not semi-private, private or sensitive. Public data includes, among others, data relating to the civil status of persons, their profession or trade, their status as a merchant or public servant, and data that can be obtained without any restriction. By their nature, public data may be contained, among others, in public registries, public documents, official gazettes and bulletins that are not subject to confidentiality.
SENSITIVE DATA: Data that affect the privacy of the Personal Data Subject or whose improper use may generate discrimination, such as data that reveal racial or ethnic origin, political orientation, religious or philosophical convictions, membership in trade unions, social or human rights organizations, or organizations that promote the interests of any political party or that guarantee the rights and guarantees of opposition political parties, as well as data relating to health, sex life and biometric data (fingerprint, iris of the eye, voice, way of walking, palm of the hand or facial features, photographs, videos, among others).
The Personal Data of Children and/or Adolescents will be subject to the same rules and procedures as Sensitive Data, and no Processing will be given that may violate or threaten their physical, mental and emotional development.
SEMI-PRIVATE DATA: Data that is not of an intimate, reserved or public nature, and whose knowledge or disclosure may be of interest not only to its subject but also to a group of people or to society in general. Semi-private data includes, among others, information related to social security and to financial and credit behavior.
RIGHT OF HABEAS DATA: In accordance with article 15 of the Political Constitution of Colombia, the right of all persons to know, update and rectify the information collected about them in databases and in the files of public and private entities.
DATA PROCESSOR: Natural or legal person, public or private, that by itself or in association with others performs the Processing of Personal Data on behalf of the Data Controller. For the purposes of this Privacy Policy, Data Processors are understood to be those reported in the National Registry of Databases.
INTEREST GROUPS: Groups of natural persons with respect to whom the Data Controller and/or Data Processors perform any Processing of Personal Data.
CHILD: Persons between 0 and 12 years of age (Code of Children and Adolescents, article 3).
PERSONAL DATA PROTECTION OFFICER: Person or Area responsible for ensuring compliance with Personal Data Protection regulations.
PQR'S: Petitions, consultations, and complaints regarding Personal Data Protection.
DATA PROTECTION: All measures necessary to provide security to records, avoiding adulteration, loss, consultation, or unauthorized access.
DATA CONTROLLER: Natural or legal person, public or private, that by itself or in association with others decides on the Database and/or the Processing of the data.
DATA SUBJECT: For the purposes of Law 1266 of 2008, the natural or legal person to whom the information held in a database refers, holder of the right of habeas data and of the other rights and guarantees enshrined in said Law and in the rules that complement, modify, replace or repeal it. For the purposes of Law 1581 of 2012, the natural person whose personal data is subject to Processing.
TRANSFER: When a Data Controller and/or Processor located in Colombia sends information or personal data to another Data Controller within or outside the country.
TRANSMISSION: Processing of Personal Data that involves their communication within or outside the territory of the Republic of Colombia, for the purpose of Processing by the Data Processor on behalf of the Data Controller.
PROCESSING: Any operation or set of operations on personal data, such as collection, storage, updating, use, circulation, transfer, transmission or deletion.
5. GUIDING PRINCIPLES
The following are the Guiding Principles regarding Personal Data Protection, and will apply to the Processing carried out by the Data Controller, its employees, and all those third natural or legal persons to whom it Transmits or Transfers Personal Data of the Data Subjects that comprise its Interest Groups, when they perform any Processing on them:
PRINCIPLE OF LEGALITY: Processing will be carried out in accordance with the legal requirements established in Statutory Law 1581 of 2012 and its regulatory decrees.
PRINCIPLE OF PURPOSE: The Processing of Personal Data must obey a legitimate purpose in accordance with the Constitution and the Law, which must be informed to the Data Subject.
PRINCIPLE OF FREEDOM: Processing can only be carried out with the prior, express and informed consent of the Data Subject. Personal data may not be obtained or disclosed without prior authorization, or in the absence of a legal or judicial mandate that waives consent. Public Data are excepted from this principle and may be Processed without the Data Subject’s authorization, in accordance with Law 1581 of 2012 and its Regulatory Decree 1074 of 2015.
PRINCIPLE OF TRUTHFULNESS OR QUALITY: Information subject to Processing must be truthful, complete, accurate, updated, verifiable and understandable. The Processing of partial, incomplete, fragmented or misleading data is prohibited.
PRINCIPLE OF TRANSPARENCY: The Data Subject has the right to obtain information about their data at any time and without restrictions.
PRINCIPLE OF ACCESS AND RESTRICTED CIRCULATION: Personal data, except public information, may not be available on the Internet or other means of mass disclosure or communication, unless access is technically controllable to provide restricted knowledge only to Data Subjects or authorized third parties.
PRINCIPLE OF SECURITY: Information must be protected by technical, human, and administrative measures to avoid unauthorized access or alteration.
PRINCIPLE OF CONFIDENTIALITY: All persons involved in Processing must guarantee confidentiality, even after their relationship with the Processing ends.
PRINCIPLE OF NECESSITY: Only data strictly necessary for the informed purposes will be collected and processed.
6. PROCESSING TO WHICH PERSONAL DATA WILL BE SUBJECT AND ITS PURPOSES
For the purposes of this Privacy Policy, the Data Controller, directly or through Data Processors, may, manually or in an automated manner, collect, store, use, circulate, update, delete or perform any other type of Processing on the Personal Data of its Interest Groups, at all times in accordance with the regulations in force and for the purposes described below:
6.1. GENERAL PURPOSES FOR THE PROCESSING OF PERSONAL DATA OF ALL INTEREST GROUPS
- National and international Transmission and Transfer, and storage and custody of information and/or Personal Data in physical files or on own and/or third-party servers, located within or outside the country, in countries considered secure by the Superintendence of Industry and Commerce or in those that are not, whenever required for the development of the Controller’s own activities and those related to the different interest groups.
- Registration of incoming and outgoing documents.
- Sending of communications.
- Support in internal and/or external audit processes, consultancies and implementation of improvement plans.
- Taking out and renewal of insurance policies with national and international companies, either through intermediaries or directly with the insurers.
- Reports and attention to requirements made by competent administrative authorities, especially Health authorities, and judicial authorities.
- Preparation and filing of lawsuits and complaints before the competent authorities, as well as exercising the right of defense in any administrative and/or judicial proceeding.
- Compliance with the obligations arising from the contracts entered into between the Data Controller and the Data Subjects, or with their contracting parties or employers.
- Financial and accounting management, creation of third parties, and registration in the Data Controller’s databases.
- Attention to PQR’s filed by Data Subjects or by those who prove standing to do so.
- Compliance with regulations in force.
- Purposes indicated in the authorization granted by the Data Subject and/or in the Privacy Notices.
6.2. PURPOSES FOR THE PROCESSING OF PERSONAL DATA OF CLIENTS
- Offering and quotation of goods and/or services of the Data Controller and/or its strategic allies.
- Statistical studies of credit risk behavior.
- Negotiation, execution, modification and performance of contracts.
- Registration of information of clients’ staff.
- Verification of data and references.
- Billing and collection management.
- Portfolio recovery management through persuasive, extrajudicial and/or judicial collection.
- Client management.
- Updating of balances, reimbursement of amounts collected in the event of portfolio sale or clearance of the end client.
- Client and/or user loyalty programs, including but not limited to: promotional activities, discounts and benefits.
- Social media management.
- History of commercial relationships.
- Transmission and Transfer of contact data to Data Processors, contractors and suppliers and/or strategic allies, so that they Process the Data Subject’s Personal Data for the purposes indicated in this Privacy Policy.
- Evaluation of the quality of the goods and/or services provided by the Data Controller.
- Internal and external publications and communications.
- Sending of communications, advertising and/or alerts related to the purposes contained in this Privacy Policy and in the Terms and Conditions, the operation of the Platform, the activities of the Data Controller, any of its affiliates, parent companies or subsidiaries and/or strategic allies, through the professional, business and/or personal contact data of the Data Subjects, including but not limited to landline and/or mobile telephone, physical and/or electronic mail, sms and/or mms text messages, chats, RCS, digital platforms, electronic media and/or any other means of communication.
- Behavior analysis, profiling and market segmentation, prediction, classification, business intelligence, data mining, identification of the browser used to access the Data Controller’s platforms, logs, information on devices used to access the Data Controller’s platforms (device model, operating system, Internet Protocol (IP) address, telephone or internet operator provider, average time spent on the platform, date, country and city of access).
- Fraud control and prevention, control and prevention of asset/money laundering and terrorist financing.
- Claims management.
- Transmission and transfer of contact data to data processors, any of its affiliates, parent companies or subsidiaries, contractors and suppliers, other clients and/or strategic allies, so that they process the data subject’s personal data for the purposes indicated in this Privacy Policy.
- Other purposes indicated in the Terms and Conditions.
6.3. PURPOSES FOR THE PROCESSING OF PERSONAL DATA OF SHAREHOLDERS.
- Calls to shareholders’ meetings.
- Sending of information related to the Data Controller’s own activities.
- Collection and payment of obligations.
- Guaranteeing the effective exercise of shareholders’ rights.
- Verification of compliance with legal and technical requirements.
- Verification of references.
6.4. PURPOSES FOR THE PROCESSING OF PERSONAL DATA OF APPLICANTS, DIRECT AND INDIRECT EMPLOYEES, ACTIVE AND INACTIVE, AND THEIR FAMILIES
- Collection of résumés directly from the Data Subject or from third natural or legal persons who submit them, either independently or on behalf of the Data Controller.
- Development of the selection process, résumé analysis, validation of employment and/or personal references, verification of judicial and/or disciplinary records, interviews and medical, psychotechnical and competency tests as required.
- Retention of résumés and results of selection processes for future hiring processes and/or in compliance with legal regulations in force.
- Employment engagement, execution of employment contracts.
- ID card issuance process.
- Contract renewal control.
- Work scheduling and assignment of functions, roles and profiles associated with the position held.
- Registration of information of direct and indirect employees, active and inactive, retirees and their families and/or beneficiaries, for the development of activities of affiliation to and payment of social security and payroll taxes, payroll, bonuses and premiums, vacations, recognition of pension rights and settlements.
- Activities related to organizational climate and culture, psychosocial risk management and well-being of direct and indirect employees and their families and/or beneficiaries.
- Management of permits, leaves and authorizations.
- Management of sanctions, admonitions, warnings, disciplinary hearings and dismissals with or without just cause.
- Registration of the disciplinary record.
- Compliance with the Data Controller’s obligations under the legal regulations in force.
- Training and education of direct and indirect personnel.
- Competency and performance evaluations.
- Salary deductions permitted by regulations in force, and execution and registration of garnishments at the request of a competent authority.
- Issuance of employment certificates and/or references.
- Delivery of work supplies and personal protective equipment.
- Contracting with third parties for services that benefit direct and indirect employees and their families and/or beneficiaries.
- Compliance with the regulations in force on occupational health and safety (SG-SST), including but not limited to: collection and analysis of health information and socio-demographic profile of direct and indirect employees, active and inactive, investigation and indicators of absenteeism, incidents and accidents, occupational medical evaluations, road safety, reporting and investigation of work incidents and accidents, workplace inspections and studies, verification of the use of protective equipment, identification of hazards and evaluation of unsafe behavior, processes of observation of safe behavior and follow-up on commitments.
- Hotel reservations, air or land tickets, delivery of fuel and toll vouchers, travel allowances, transportation allowances and vehicle requests, among others, in the event of travel by direct and indirect employees.
- Provision of information to clients, contractors and suppliers, for the execution and performance of the contracts entered into between them and the Data Controller.
- Control of schedules and verification of hours worked.
- Creation and administration of users and passwords for access to the different applications, software, technological and computer equipment, email accounts and web pages that so require.
- Creation and control of access to and modification of documents.
- Identification and tracking of personnel arrivals and departures, payroll and promotions.
- Transfer of proof of payment of contributions to the social security system and payroll taxes, and evidence of training provided to staff, sent to the Data Controller’s Contracting Parties when required for the execution of contracts and the payment of goods and/or services provided by the latter as Contractor and/or Supplier.
6.5. PURPOSES FOR THE PROCESSING OF PERSONAL DATA OF SUPPLIERS AND CONTRACTORS AND THEIR STAFF.
- Request, collection and analysis of quotations and/or offers.
- Invitations to participate in contracting processes.
- Development of contracting.
- Request for references and certificates from third parties.
- Verification of legal, technical and financial requirements.
- Compliance with legal and contractual obligations.
- Execution of contracts.
- Payment management.
- Evaluation of Contractors and Suppliers; and processing of requests for quality guarantees of the products or services acquired.
- Contact with Suppliers and Contractors or their staff, for the performance of the contracts entered into or the service and/or purchase orders issued, until their termination.
- Verification of social security payment.
- Verification of compliance with occupational health and safety regulations.
7. RIGHTS OF THE DATA SUBJECTS
The following are the rights of Personal Data Subjects:
- To know, update and rectify their personal data before the Data Controllers or Data Processors. This right may be exercised, among others, with respect to partial, inaccurate, incomplete or fragmented data, data that is misleading, or data whose Processing is expressly prohibited or has not been authorized.
- To request proof of the authorization granted to the Data Controller, except when expressly excepted as a requirement for Processing, in accordance with article 10 of Law 1581 of 2012.
- To be informed by the Data Controller or the Data Processor, upon request, regarding the use given to their personal data.
- To file complaints before the Superintendence of Industry and Commerce for infringements of the provisions of Law 1581 of 2012 and the other rules that modify, add to or complement it.
- To revoke the authorization and/or request the deletion of the data when the Processing does not respect constitutional and legal principles, rights and guarantees. The revocation and/or deletion will proceed when the Superintendence of Industry and Commerce has determined that in the Processing the Controller or Processor has engaged in conduct contrary to Law 1581 of 2012 and the Constitution.
- To access, free of charge, the personal data that have been subject to Processing: (i) at least once every calendar month, and (ii) each time there are substantial modifications to the information Processing Policies that give rise to new consultations.
The request for deletion of the information and the revocation of the authorization will not proceed when the Data Subject has a legal or contractual duty to remain in the database.
8. DUTIES OF THE DATA CONTROLLER
It is the duty of the Data Controller to:
- Guarantee to the Data Subject, at all times, the full and effective exercise of the Right of Habeas Data
- Request and keep, by any means and under the conditions provided for in Law 1581 of 2012, a copy of the respective authorization granted by the Data Subject.
- Duly inform the Data Subject about the purpose of the collection and the rights they hold by virtue of the authorization granted
- Keep the information under the security conditions necessary to prevent its adulteration, loss, consultation, use or unauthorized or fraudulent access
- Guarantee that the information provided to the Data Processor is truthful, complete, accurate, updated, verifiable and understandable
- Update the information, communicating in a timely manner to the Data Processor all developments regarding the data previously provided, and adopt the other measures necessary to keep the information provided to the Data Processor up to date
- Rectify the information when it is incorrect and communicate the relevant matters to the Data Processor
- Provide the Data Processor, as the case may be, only with data whose Processing has been previously authorized in accordance with Law 1581 of 2012
- Require the Data Processor at all times to respect the security and privacy conditions of the Data Subject’s information
- Process consultations and claims made under the terms set forth in Law 1581 of 2012
- Adopt an internal manual of policies and procedures to guarantee adequate compliance with Law 1581 and, in particular, for the handling of consultations and claims
- Inform the Data Processor when certain information is under dispute by the Data Subject, once a claim has been filed and the respective procedure has not been completed
- Inform the Data Subject, upon request, about the use given to their data
- Inform the data protection authority when there are violations of security codes and risks exist in the administration of Data Subjects’ information
- Comply with the instructions and requirements issued by the Superintendence of Industry and Commerce
Telepatía S.A.S. will implement technological, administrative and physical protocols to guarantee the security of the stored Personal Data, especially those related to sensitive information such as health data.
9. DUTIES OF DATA PROCESSORS
It is the duty of the Data Processor to:
- Comply, in the development of the contracted activities, with the Privacy and Personal Data Protection Policy, as well as with all those procedures, guides and/or directives issued by the Data Controller regarding Personal Data Protection.
- Adopt, according to the instructions of the Data Controller, all the technical, human and administrative measures necessary to provide security to the records, preventing their adulteration, loss, consultation, use or unauthorized or fraudulent access.
- Implement a Personal Data Protection Policy that complies with the rules governing the matter.
- Process Personal Data in accordance with the instructions expressly received from the Data Controller, refraining from using them for purposes other than those contracted.
- Refrain from providing, assigning or commercializing Personal Data to third natural or legal persons, public or private, unless the data is of a public nature not subject to confidentiality, or is required by a competent authority in the exercise of its legal functions.
- Maintain strict confidentiality regarding the personal data to which they have access in the exercise of the contracted activities, and diligently comply with the duty of care and custody over such data during the entire term of the contract and even after its termination.
- Access or consult the information or Personal Data held in the Data Controller’s Databases only when strictly necessary for the exercise of the contracted activities.
- Report to the Data Controller, immediately upon materialization or upon becoming aware of it, through the channels and means established by the latter, any incident or threat of an incident that affects or may directly or indirectly affect the protection of personal data.
- Guarantee at all times the full and effective exercise of the Right of Habeas Data of the Data Subjects, as well as due process in the event of PQR´s regarding Personal Data Protection.
- Carry out in a timely manner the updating, rectification or deletion of data under the terms of Law 1581 of 2012.
- Update the information reported by the Data Controller within five (5) business days from its receipt.
- Adopt an internal manual of policies and procedures to guarantee adequate compliance with Law 1581 of 2012 and, in particular, for the handling of consultations and claims by Data Subjects.
- Refrain from circulating information that is being disputed by the Data Subject and whose blocking has been ordered by the Superintendence of Industry and Commerce.
- Allow access to the information only to those persons who may have access to it.
- Comply with the instructions and requirements issued by the Superintendence of Industry and Commerce.
- In the event of collecting data on behalf of the Data Controller, require the authorization of the Data Subjects, in the cases in which it is required, in accordance with Law 1581 of 2012 and the other rules that complement, replace, modify or repeal it.
10. PERSON OR AREA IN CHARGE OF HANDLING PQR’s
The area responsible for handling petitions, consultations and claims, before which the Data Subject may exercise their rights to know, update, rectify and delete data and revoke the authorization, will be the Management (Gerencia), which will perform the functions of Personal Data Protection Officer.
11. PROCEDURE FOR DATA SUBJECTS TO EXERCISE THEIR RIGHTS
Data Subjects, or those persons with standing under the regulations in force, may file Petitions, Consultations and Claims through the following channels established by the Data Controller for the handling of PQR’s: ayuda@telepatia.ai
In all of the above cases, the request must contain the following information:
- Name and identification of the Personal Data Subject, and of the person filing the PQR if different from the Data Subject.
- Documents evidencing the capacity in which the person filing the PQR acts.
- A concrete and precise request for information, access, updating, rectification, cancellation, deletion, objection to processing and/or revocation of consent. In each case, the request must be reasonably substantiated so that the Data Controller and/or the Data Processors can provide a substantive response.
- Physical and/or electronic address for notifications.
- Documents supporting the request, if applicable.
- The signature of the person filing the PQR.
The following are the persons entitled to file PQR´s, in accordance with article 2.2.2.25.4.1. of Decree 1074 of 2015:
- The Data Subject, who must sufficiently prove their identity.
- The successors in interest of the Data Subject, who must prove such capacity.
- The representative and/or attorney-in-fact of the Data Subject, upon proof of the representation or power of attorney.
- By stipulation in favor of another or for another, provided that the Data Subject has accepted, of which evidence must be included in the request.
The rights of Children or Adolescents will be exercised by the persons authorized to represent them.
Consultations and claims will be resolved within the terms established in Laws 1266 of 2008 and 1581 of 2012, or those that replace, modify or repeal them. Petitions and complaints will be resolved within the term established in Law 1755 of 2015, or those that replace, modify or repeal it.
11.1. CONSULTATIONS
The Data Controller or the Data Processor will respond to the consultation within a maximum term of ten (10) business days from the date of its receipt. If it is not possible to respond within this period, the interested party will be informed of the reasons for the delay and the date of response will be indicated, which may not exceed five (5) business days following the first expiration.
11.2. CLAIMS
The Data Controller or the Data Processor will respond to the claim within fifteen (15) business days from the day following its receipt. If it is not possible to respond within this period, the Company will inform the interested party of the reasons for the delay and indicate the date of response, within eight (8) business days following the first expiration.
11.3. COMPLAINTS AND PETITIONS
The Data Controller or the Data Processor will respond to the petition or complaint within fifteen (15) business days from the day following its receipt.
12. THIRD-PARTY ARTIFICIAL INTELLIGENCE SERVICE PROVIDERS (SUBPROCESSORS)
To provide its services, Telepatía S.A.S. transmits certain data to specialized third-party artificial intelligence service providers, which act as Data Processors (subprocessors) exclusively on behalf of, and under the documented instructions of, Telepatía S.A.S. The main subprocessors currently engaged are the following:
ELEVENLABS: Provides voice processing and speech-to-text services. It receives the audio of the clinical encounter for the sole purpose of generating its transcription, and processes such data without durable storage.
GOOGLE (Google Cloud Platform and Google AI models): Provides speech-to-text, de-identification, language-model processing, and secure cloud hosting services. It receives the audio of the clinical encounter, transcriptions, and the data hosted on the platform, for the purposes of transcription, removal of personal identifiers, generation of draft clinical documentation, and storage of platform data.
OPENAI: Provides de-identification and language-model processing services. It receives transcriptions of the clinical encounter for the purposes of removing personal identifiers and generating the draft clinical documentation, and processes such data without durable storage.
Telepatía S.A.S. may engage other subprocessors for the same purposes described in this section. In all cases — both the subprocessors identified above and any others that may be engaged —, such engagement is always preceded by the execution of the same data processing agreements, which impose confidentiality, information security, and data protection obligations providing a level of protection equivalent to that established in this Privacy Policy, and the use of the data for the provider’s own purposes is prohibited.
The data sent to these providers is used exclusively to deliver the service contracted by the client health institution: to transcribe the clinical encounter, remove personal identifiers, and generate the draft clinical documentation that is returned to the Health Professional, who reviews and approves it before it is confirmed. Telepatía S.A.S. does not sell Personal Data and does not share it with third parties other than the subprocessors bound by the agreements described in this section and the client institution’s own systems.
13. EQUIVALENT PROTECTION BY SUBPROCESSORS
Each subprocessor identified in Section 12 is bound by data processing agreements, including Business Associate Agreements, that impose confidentiality, information security, and data protection obligations providing a level of protection equivalent to that established in this Privacy Policy and in applicable data protection law. Subprocessors may process the data only to perform the services described above and may not use it for their own purposes.
All transmissions of data to subprocessors are encrypted in transit using TLS 1.2 or higher, with preference for TLS 1.3, and data stored on the platform is encrypted at rest.
14. DATA RETENTION AND USE FOR MODEL IMPROVEMENT
The audio of the clinical encounter is temporary data, processed in order to generate the transcription and the draft clinical documentation. The retention and removal of data follow the policy contracted with each client institution and the settings configured by that institution in the platform.
By default, data processed through the platform is retained, and data that has been de-identified — so that it no longer identifies any natural person — may be used to improve and refine Telepatía S.A.S.’s artificial intelligence models, unless the client institution disables this in the platform’s administrative settings. Client institutions may exercise this option at any time through such settings. Identified Personal Data is not used to train artificial intelligence models.
15. VALIDITY
This Privacy Policy will be effective as of February 02, 2026.
The Databases subject to Processing by the Data Controller will remain in force as long as the purposes for which the data were collected subsist and/or for the term established by law.
The Data Controller reserves the right to modify this Privacy Policy at any time. In the event of substantial changes to its content, in relation to the identification of the Data Controller and the purpose of the Processing of Personal Data, which may affect the content of the Authorization, the Data Controller will communicate these changes to the Data Subject before, or at the latest at the time of, implementing the new policies, and will require a new authorization when the change refers to the purpose of the Processing.