Privacy Notice
Last updated: 26 August 2026
This notice explains how we handle personal data across Elventia's products, including Atendaria. It is written to be read, not to defend us from whoever reads it.
Atendaria currently operates in Brazil: patient data is handled under the LGPD (Brazilian Law 13.709/2018), and the binding text for those data subjects is the Portuguese one — elventia.com/privacidade. This English version describes the same processing under the GDPR and serves as the international reference.
1. Who is responsible
- Controller
- Diego La Mantia — sole proprietorship registered in Italy, trading as Elventia
- VAT number
- IT02976210811
- Registered office
- Via Edmondo De Amicis 9, int. 2 — 91025 Marsala (TP), Italy
- Contact
- privacy@elventia.com
2. Two different roles, and the difference matters
Within the same service we handle two sets of data under distinct responsibilities:
- We are the controller of the account data of whoever subscribes: the professional or the practice.
- We are a processor of patient data. The practice decides the purposes and means and is the controller; we only handle that data on its instructions, within what the software does.
In practice: if you are a patient and want to know what happens to your data, or want it erased, the fastest route is to ask the practice that treats you. If they ask us, we execute. You can also write to privacy@elventia.com: we forward the request to the controller and follow it through.
3. What data we handle
Account data (we are the controller)
- Name, email, phone, practice name and professional address.
- Subscription data: plan, payment method and invoice history. Card details are handled directly by the payment provider — they never pass through us and are not stored on our servers.
- Technical access logs: date, time and IP address, kept for security and legal compliance.
Patient data (we are a processor)
- Name and WhatsApp number.
- Appointments booked, moved or cancelled, and the service booked.
- The content of messages exchanged with the assistant, needed to understand the request and reply.
4. What we deliberately do not handle
The assistant handles scheduling and logistics. By product design, not by accident:
- It never asks the reason for the appointment, nor symptoms, nor medical history.
- It never gives clinical advice. Any health topic is handed back to the professional.
- We do not use conversation content for advertising, and we do not sell or licence it to third parties for commercial purposes.
That said, simply having an appointment with a psychologist or a physiotherapist can already reveal information about health. We therefore treat that data with the safeguards Article 9 GDPR — and Article 11 LGPD — require: restricted access, short retention, and no clinical content in the system.
5. Purposes and legal bases
- Delivering the service — answering patients on WhatsApp, managing the calendar, sending confirmations and reminders. Basis: performance of a contract (Art. 6(1)(b) GDPR) for account data; for patient data the basis is determined by the practice as controller.
- Billing and tax obligations — basis: legal obligation (Art. 6(1)(c)).
- Security, fraud prevention and fault diagnosis — basis: legitimate interests (Art. 6(1)(f)), limited to what is necessary.
- Support — answering people who write to us. Basis: contract or legitimate interests, as the case may be.
We make no automated decisions producing legal effects on people. The assistant books appointments; it does not score, profile or deny anything to anyone.
6. How long we keep it
- WhatsApp messages: deleted automatically after 365 days. Not a promise on paper — a routine that runs by itself in the system.
- Calendar and patient records: for as long as the practice keeps the account active, or until it asks for erasure.
- Account data: for the duration of the contract and up to 30 days after it ends.
- Invoices and tax records: for the period required by Italian law, even after the account is closed. It is the only thing that survives deletion, and it does so by legal obligation.
7. Who we share it with
- Meta Platforms — messages travel through the official WhatsApp Business platform. Without it there is no WhatsApp.
- Payment provider — to charge the subscription and issue invoices. It receives billing data, not patient data.
- Infrastructure — the servers the service runs on.
- Error monitoring — when enabled, a technical fault-reporting service, configured not to collect personal data.
Language-model processing of messages happens on our own infrastructure, under our control: conversation content is not sent to third-party AI services.
8. Where the data is
Data is processed in Italy, therefore within the European Union. For data originating in Brazil this constitutes an international transfer under Art. 33 LGPD, governed by contractual clauses with the controllers and supported by the level of protection recognised for the EU.
9. Security
- Encrypted traffic between the browser and our servers.
- WhatsApp access tokens stored encrypted, never in clear text.
- Strict separation between accounts: no practice sees another's data, and the assistant never discloses one patient's data to another.
- Internal access restricted to what support and maintenance strictly require.
No system is infallible. In the event of a breach likely to result in significant risk, we will notify the affected controllers and the competent authority within the statutory deadlines.
10. Your rights
At any time and free of charge you may request access to your data, rectification, erasure, restriction of processing, portability, and object to processing based on legitimate interests.
Write to privacy@elventia.com: we reply within 30 days. If the request concerns patient data we need the practice's authorisation, as it is the controller — and we help them comply. See also Data deletion.
You may also lodge a complaint with your supervisory authority — in Italy the Garante per la protezione dei dati personali, in Brazil the ANPD.
11. Cookies
This corporate site uses no tracking cookies and no audience-analytics tools. The product dashboard uses strictly necessary cookies only: the ones that keep you signed in and protect the session. Without them login does not work, and for that reason they do not require consent.
12. Children
The service is subscribed to by professionals and practices, not by minors. Where a patient is a minor, the booking is made by a parent or guardian, and it is for the practice — as controller — to ensure this.
13. Changes
If this notice changes materially we tell customers by email before the change takes effect, and the date at the top is always updated.
14. Contact
Privacy: privacy@elventia.com. Anything else: info@elventia.com.