ANPD Standard Contractual Clauses (Brazil)

TM-BR · Draft of October 6, 2026 · revision 1 · version 1.0

Final draft for counsel's review. It is not in effect, and no clinic has accepted it. Items still to be confirmed are highlighted in the text.

Convenience translation: the Português text controls.

Read in: English · Português

SHA-256 of this text: 1485b6c12c355f9b2441f747299a9469d4401d2ec6b8d25daeee2adf4dcb2908

Brazil — TM-BR (ANPD Standard Contractual Clauses) and ANX-BR (Brazil Annex)

Document IDs: TM-BR v1.0 and ANX-BR v1.0 · Effective date: [[TO CONFIRM: publication date]] Language: Portuguese controls (pt/annex-br.md; MDPA clause 22). This English text is a convenience translation for counsel and for VstreamX. The ANPD's English version of the clauses is a convenience copy only. Applies to: Clinics established in Brazil, or whose patients' data is collected in Brazil. Part of the Master Data Processing Agreement (the "MDPA"). Terms defined in the MDPA have the same meaning here.


PART I — TM-BR: Adoption of the ANPD Standard Contractual Clauses

1. Adoption

1.1 Adoption. By accepting the MDPA, the Clinic (as exporter and controller, controlador) and VstreamX (as importer and processor, operador) adopt in full and without any alteration the Standard Contractual Clauses approved by Resolution CD/ANPD No. 19 of 23 August 2024, Annex II (the "Clauses"). They do so for the international transfer of personal data from the Clinic to VstreamX and its sub-processors, under Article 33(II)(b) of Law 13.709/2018 ("LGPD").

1.2 The text.

  • The full Portuguese text of the Clauses, as published by the ANPD in the Diário Oficial da União, is reproduced in the bundle the Clinic reads before accepting, and in the Executed Copy. [[TO CONFIRM: embed the official DOU Portuguese text of Annex II from the official source file — never retyped or edited]]
  • Only the fields of Section I and the content of Section III are completed below.
  • Section II (mandatory clauses) is not altered in any way.

1.3 Nothing may contradict the Clauses.

  • Under Resolution 19, no other clause of the MDPA, of this Annex or of the DentalX Terms of Service may exclude, modify or contradict, directly or indirectly, the provisions of the Clauses.
  • The MDPA, Part II of this Annex and the Terms form the additional clauses that Section IV of the Clauses allows. They apply only in so far as they are compatible with Sections I to III.

1.4 Signature.

  • The Parties sign the Clauses by the electronic acceptance described in MDPA clause 2.4. This acceptance is valid under Article 10, §2 of Provisional Measure 2.200-2/2001 and Article 4 of Law 14.063/2020, and records the signatory's CPF.
  • The Clinic may also choose to sign with an ICP-Brasil certificate or through gov.br. VstreamX makes that option available in the Service, and records the method used.

2. Section I — General information (completed)

Clause 1. Identification of the Parties

Exporter (Controller)Importer (Processor)
Name«Clinic legal name»VstreamX Studio Inc.
QualificationController (controlador)Processor (operador)
CNPJ / CPF / registration«CNPJ» (or, for an individual practice, «CPF»)Corporation incorporated in Manitoba, Canada, no. [[TO CONFIRM: Manitoba corporation number]]
Address«Clinic address», BrazilOffice B – 1043 Rosser Ave, Brandon, Manitoba R7A 0L5, Canada
Email«Clinic owner email»admin@vstreamx.com
Contact / Encarregado«Clinic encarregado (DPO) name and email»[[TO CONFIRM: VstreamX's encarregado for Brazil — name and email]]
Signatory«Signatory name», «Signatory role», CPF «Signatory CPF»Authorised officer of VstreamX (electronic signature on the acceptance certificate)

Clause 2. Object

FieldContent
Main purposes of the transferProvision of DentalX, a cloud dental-practice management service, to the exporter: patient records and charting, scheduling, treatments, imaging, consent forms, prescriptions, invoicing, reminders and patient communications by email and WhatsApp, and AI-assisted drafting. This includes hosting, storage, backup, security and the support the exporter requests (MDPA Schedule 1).
Categories of personal data transferredAs MDPA Schedule 1: identification, contact, insurance, appointments, financial, communications, consent and signing evidence, professional data of practitioners, and audit-trail entries.
Sensitive personal dataYes. Health data (LGPD Art. 5(II) and Art. 11): medical and dental history, allergies, medications, diagnoses, odontogram, clinical notes, treatment plans, radiographs and photographs, documents, prescriptions, consent forms. Data of children and adolescents (LGPD Art. 14).
Categories of data subjectsPatients (including children and adolescents), their legal guardians, emergency contacts, policyholders, the exporter's professionals and staff, and third parties who correspond with the exporter.
Storage periodWhile the exporter uses the Service, as it decides. After the end, as MDPA clause 14 and Part II §6 of this Annex provide.
Country of destinationCanada (VstreamX) and the United States (sub-processors). For some services, other countries where the sub-processors operate, as listed in Clause 3.
Other informationField encryption with AES-256-GCM of the identifying fields, medical history, insurance details, consent forms and prescriptions; no use of the data for the importer's own purposes or to train AI models.

Clause 3. Onward transfers

Option B is selected. The importer may carry out onward transfers of the personal data to the following recipients, for the following purposes, in the countries listed:

RecipientPurposeCountryData
Google LLC (Google Cloud / Firebase)Hosting, database, storage, sign-in, functions, backups, logsUnited StatesAll data
Google LLC (Vertex AI)AI features chosen by the UsersUnited States (us-central1 regional endpoint) [[BLOCKING TO CONFIRM: regional endpoint live before publication; the Clauses require each onward recipient's country to be named]]Content of each AI request
Google LLC (Google Workspace / Gmail)Sending emails at the exporter's instructionUnited States, and the other countries Google names for Workspace data [[TO CONFIRM: name them from Google's Workspace data-location and sub-processor pages]]Email address and message
Meta Platforms, Inc. / WhatsApp LLCWhatsApp messages, for clinics that use DentalX's numberUnited States and other countriesTelephone number, messages and files
Google LLC (reCAPTCHA)Verification when a second factor by SMS is set up or usedUnited States and other countriesBrowser data; no patient data

Conditions. Each onward transfer is made under the conditions of Section II, and only for the purposes listed. Before any onward transfer, the importer binds each recipient, by a written instrument, to the safeguards of these Clauses, using the ANPD Standard Contractual Clauses or another mechanism that Resolution CD/ANPD 19/2024 recognises for that recipient, as the Clauses require for onward transfers. Any new recipient requires the exporter's prior consent, given in the Service as MDPA clause 7.5 provides. Until the exporter consents, the exporter's data is not routed to the new recipient. [[BLOCKING TO CONFIRM: that the Google Cloud, Google Workspace and Meta processing terms incorporate the ANPD Standard Contractual Clauses for Brazilian data, or that another Resolution 19 mechanism binds each of them; and that every 'other countries' entry above is replaced by named countries]]

Clause 4. Responsibilities of the Parties

Option A is selected. The exporter is the Designated Party. As Designated Party, the Clinic is responsible for:

  • the transparency obligations to data subjects;
  • responding to data subject requests; and
  • communicating security incidents to the ANPD and to data subjects,

as the clauses of Section II assign them to the Designated Party [[TO CONFIRM: clause numbers of the transparency, data-subject and incident clauses in the official text]].

The importer assists the exporter in each of these obligations, as MDPA clauses 8 and 9 and Part II of this Annex provide.

3. Section II — Mandatory clauses

Adopted without alteration, as published. They include the clauses on governing law and jurisdiction, which designate Brazilian law and the Brazilian courts. [[TO CONFIRM: number of the governing-law and forum clause (expected to be Clause 24) in the official text]]

4. Section III — Security measures

The security measures adopted by the importer are those in MDPA Schedule 2, reproduced in full in this Section. They are summarised here:

  • Encryption: TLS in transit; Google encryption at rest; field encryption with AES-256-GCM of the patient's name, date of birth, telephone, address, emergency contact, medical history and insurance details, and of consent forms and prescriptions; key held in Google Secret Manager with restricted access.
  • Access: isolation of each clinic by deny-by-default rules; role-based access; multi-factor authentication; automatic sign-out after 8 hours of inactivity; expiring links and single-use consent-signing links.
  • Logging and availability: audit trail of chart openings, exports, deletions and changes, kept 7 years while the account is active and returned in the export at the end; daily backups with 7 days of retention and 7 days of point-in-time recovery.
  • Development: dependency audit before each deployment; Content-Security-Policy.
  • Personnel: confidentiality obligation equivalent to professional secrecy; incident-response procedure; breach register.