This Policy explains, in plain language, what personal data we process, why we process it, who we share it with, how we protect it and how you can exercise your rights on Awake Health's Sinais platform.
It applies specifically to Sinais — the environment where we bring together a patient's biomarkers, including data collected from your WHOOP wearable device. Other Awake Health services may have their own privacy notices.
The controller — the party that decides how and why your personal data is processed — is:
| Legal entity | AWK Clínica de Saúde Integrativa LTDA |
|---|---|
| Brazilian tax ID (CNPJ) | 32.970.654/0001-34 |
| Trading name | Awake Health |
| Website | awakehealth.com.br |
| Privacy contact | medicina@awakehealth.com.br |
Throughout this text, “Awake Health”, “we” or “the Clinic” refer to the controller, and “you” refers to the data subject — the patient.
It applies to you if you are an Awake Health patient and you have:
If you received a WHOOP device from Awake Health as part of your programme, the device account is yours — personal and non-transferable. Awake Health does not hold your WHOOP account credentials and does not access your account on your behalf.
Once you authorise the connection, we periodically receive the following from WHOOP through its official developer API:
| Category | What it includes |
|---|---|
| Recovery | recovery score, heart rate variability (HRV), resting heart rate, blood oxygen saturation (SpO₂) and skin temperature |
| Physiological cycle | day strain, average and maximum heart rate, energy expenditure |
| Sleep | duration, start and end times, sleep performance, efficiency and consistency, time in each stage (light, slow-wave, REM, awake) and respiratory rate |
| Workouts | activity type, duration, strain, average and maximum heart rate, energy expenditure and time in effort zones |
| Profile | the name and email associated with your WHOOP account |
| Body measurements | height, weight and maximum heart rate |
We also receive the technical identifiers WHOOP assigns to each record and their creation and update timestamps, which we need to keep our records consistent.
What we do not receive: the WHOOP API does not give us access to continuous heart rate, step count, VO₂ max, your Journal entries, WHOOP Coach, or any document, lab result or medical record you keep inside the WHOOP app. We also never have access to your WHOOP password.
The connection uses OAuth 2.0, an industry-standard protocol. In practice:
From then on, the platform retrieves your data automatically at regular intervals, with no action required from you. We request only the permissions we actually use, listed in section 3.2.
We also request the technical permission called offline, which lets us renew the authorisation without
asking you to log in again every hour. It does not broaden the set of data we can access.
| Purpose | What we do |
|---|---|
| Clinical care | Enable the health team caring for you to follow your biomarkers over time and inform the decisions in your programme |
| Medical records | Incorporate the data into your electronic medical record, where applicable, as part of the documentation of your care |
| Showing you your own data | Display your values, trends and comparisons against your own historical baseline |
| Quality and security | Verify the integrity and consistency of data received, fix collection failures and audit access |
| Legal obligations | Comply with medical record retention duties and respond to authorities where legally required |
All processing requires a legal basis. Ours are:
| Legal basis | Where it applies |
|---|---|
| Consent | Connecting your WHOOP account and the ongoing collection of device data. It is specific, prominent and informed, and you may withdraw it at any time |
| Health protection | Processing carried out by health professionals and health services for your care, including the medical record |
| Performance of a contract | Delivering the services contracted under your care line |
| Legal obligation | Retaining clinical documentation for the periods required by law and by Brazilian Federal Council of Medicine rules |
| Exercise of rights | Defence in judicial, administrative or arbitration proceedings |
Withdrawing consent stops the collection of new device data, but does not invalidate processing already carried out, nor override the mandatory minimum retention of clinical documentation explained in section 10.
Your data is accessible to the health team involved in your care — physicians, clinical support professionals and anyone performing a care-navigation role in your programme. Access is granted by role, limited to what is necessary, and every access is logged. All of them are bound by professional secrecy and by contractual confidentiality obligations.
We engage suppliers that process data on our behalf and under our instructions, contractually bound to security and confidentiality standards and prohibited from using the data for their own purposes:
| Supplier | Role |
|---|---|
| WHOOP, Inc. | Device manufacturer and source of the data. Acts as an independent controller in respect of your WHOOP account, governed by its own privacy policy |
| Cloudflare, Inc. | Platform hosting, database, access control and network protection |
We may share data where there is a court order, a request from a competent authority or a legal obligation. Wherever legally permitted, we will inform you.
There is no sharing for commercial, advertising or profiling purposes. We do not sell data. We do not provide data to employers, insurers or health plan operators.
Part of the processing takes place on servers located outside Brazil, because both WHOOP and Cloudflare operate global infrastructure. This constitutes an international data transfer under article 33 of the LGPD.
We carry out these transfers on the basis of the necessity to perform the contract with you and your specific consent, and we require contractual guarantees from suppliers offering protection equivalent to that provided under Brazilian law.
We apply technical and administrative measures proportionate to the sensitivity of the data:
No system is absolutely impenetrable. We commit to keeping these measures current and to acting transparently if an incident occurs — see section 17.
| Category | Retention period |
|---|---|
| Wearable data not incorporated into the medical record | For the duration of your care programme and up to 5 years after it ends, unless you request deletion earlier |
| Data incorporated into the medical record | For the minimum statutory medical record retention period, even if you withdraw consent |
| Access and audit logs | At least 6 months, under the Brazilian Internet Civil Framework |
| Data needed to defend legal rights | Until the definitive conclusion of the relevant proceedings or the end of the limitation period |
Once the period ends, data is irreversibly deleted or anonymised so that it can no longer be associated with you.
Wearable data changes after it is generated: a night's sleep may be rescored, an activity may be corrected, and a measurement may arrive incomplete and be completed hours later.
For that reason, when a data point is updated we store the new version without deleting the previous one. This exists for a clinical and safety reason: it allows us to state precisely what information was available to your physician on a given date, which is essential to the traceability of any clinical decision.
This history is fully subject to the retention periods in section 10 and to your right to deletion (section 12).
The LGPD guarantees you the following, at any time and free of charge (art. 18):
| Right | What it means |
|---|---|
| Confirmation and access | To know whether we process your data and to obtain a copy of it |
| Correction | To correct incomplete, inaccurate or out-of-date data |
| Anonymisation, blocking or deletion | Of unnecessary or excessive data, or data processed unlawfully |
| Portability | To receive your data in a structured, machine-readable format, or have it transmitted to another provider |
| Information on sharing | To know with whom we share your data |
| Information on consent | To be told that you may refuse consent, and what the consequences are |
| Withdrawal of consent | To withdraw consent at any time, with immediate effect for new collection |
| Objection | To object to processing based on another legal ground, where the law has not been complied with |
| Review of automated decisions | To request human review, where applicable |
To exercise any of these, write to medicina@awakehealth.com.br. We will respond within 15 days. We may ask for additional information to confirm your identity — a safeguard against fraudulent requests made in someone else's name.
You are also entitled to access, within the Sinais platform itself, the data we have collected about you.
There are three routes, and all of them work:
Revoking the connection stops the collection of new data. If you also want the data already collected to be deleted, please say so explicitly — we will handle the request under section 12, subject to the statutory medical record retention periods described in section 10.
The Sinais platform presents and compares data: it shows your values, how they evolve and how they deviate from your own historical baseline.
It does not diagnose, prescribe or recommend clinical action, and it does not make automated decisions producing legal effects or significantly affecting your interests. All clinical interpretation is performed by a qualified health professional. The information displayed does not replace medical consultation, diagnosis or treatment.
We use the bare minimum, and none of them serve advertising:
We do not use advertising, cross-site tracking or behavioural profiling cookies.
The Sinais platform is intended for people aged 18 and over. We do not knowingly collect data from children or adolescents through it. If we identify improper collection, we will delete the data. If you are a legal guardian and believe this has happened, write to medicina@awakehealth.com.br.
If a security incident occurs that may create relevant risk or harm to you, we will notify you and the Brazilian National Data Protection Authority (ANPD) within a reasonable period, describing the nature of the data affected, the risks involved and the measures taken. We will also notify WHOOP where the incident involves data originating from the device, as required by its API terms of use.
This Policy may be updated. Every version carries a number and effective date at the top. Where a change is material — particularly if it broadens the purposes of use or the list of people who can access your data — we will notify you in advance through your contact channels and, where the legal basis is consent, we will request fresh consent.
| Privacy and data subject rights | medicina@awakehealth.com.br |
|---|---|
| Data Protection Officer | Same address, with the subject line “Encarregado — LGPD” |
| National Authority | You may petition the ANPD directly — gov.br/anpd |
This Policy is governed by Brazilian law, in particular Law 13.709/2018 (LGPD), Law 12.965/2014 (Internet Civil Framework) and, where applicable, the Consumer Protection Code and the rules of the Federal Council of Medicine on medical records and professional secrecy. The courts of the data subject's domicile are elected to settle any disputes arising from it.
This English version is provided for convenience. In the event of any discrepancy, the Portuguese version prevails.