Awake Health

Privacy Policy

Sinais platform — biomarkers and wearable device data
Version 1 · effective 26 July 2026
Ler em português

This Policy explains, in plain language, what personal data we process, why we process it, who we share it with, how we protect it and how you can exercise your rights on Awake Health's Sinais platform.

It applies specifically to Sinais — the environment where we bring together a patient's biomarkers, including data collected from your WHOOP wearable device. Other Awake Health services may have their own privacy notices.

The short version.
Contents
  1. Who the controller is
  2. Who this Policy applies to
  3. What data we process
  4. How we obtain WHOOP data
  5. What we use it for
  6. Legal bases
  7. Who we share it with
  8. International transfers
  9. Information security
  10. How long we keep it
  11. History and no overwriting
  12. Your rights
  13. How to revoke the connection
  14. Automated decisions
  15. Cookies
  16. Children and adolescents
  17. Security incidents
  18. Changes to this Policy
  19. How to contact us
  20. Governing law

1.Who the controller of your data is

The controller — the party that decides how and why your personal data is processed — is:

Legal entityAWK Clínica de Saúde Integrativa LTDA
Brazilian tax ID (CNPJ)32.970.654/0001-34
Trading nameAwake Health
Websiteawakehealth.com.br
Privacy contactmedicina@awakehealth.com.br

Throughout this text, “Awake Health”, “we” or “the Clinic” refer to the controller, and “you” refers to the data subject — the patient.

2.Who this Policy applies to

It applies to you if you are an Awake Health patient and you have:

If you received a WHOOP device from Awake Health as part of your programme, the device account is yours — personal and non-transferable. Awake Health does not hold your WHOOP account credentials and does not access your account on your behalf.

3.What data we process

3.1 Identification and contact data

3.2 Health data from the wearable device

Once you authorise the connection, we periodically receive the following from WHOOP through its official developer API:

CategoryWhat it includes
Recoveryrecovery score, heart rate variability (HRV), resting heart rate, blood oxygen saturation (SpO₂) and skin temperature
Physiological cycleday strain, average and maximum heart rate, energy expenditure
Sleepduration, start and end times, sleep performance, efficiency and consistency, time in each stage (light, slow-wave, REM, awake) and respiratory rate
Workoutsactivity type, duration, strain, average and maximum heart rate, energy expenditure and time in effort zones
Profilethe name and email associated with your WHOOP account
Body measurementsheight, weight and maximum heart rate

We also receive the technical identifiers WHOOP assigns to each record and their creation and update timestamps, which we need to keep our records consistent.

What we do not receive: the WHOOP API does not give us access to continuous heart rate, step count, VO₂ max, your Journal entries, WHOOP Coach, or any document, lab result or medical record you keep inside the WHOOP app. We also never have access to your WHOOP password.

3.3 Other health data you provide

3.4 Technical data

Sensitive data. Data about your health is classified as sensitive personal data under article 5, II of the Brazilian General Data Protection Law (Law 13.709/2018, “LGPD”). It receives heightened protection and is processed only under the grounds set out in article 11 of that law, described in section 6.

4.How we obtain WHOOP data

The connection uses OAuth 2.0, an industry-standard protocol. In practice:

  1. You click to connect within the Sinais platform.
  2. You are taken to WHOOP's own environment, where you log in directly with them.
  3. WHOOP shows you exactly which permissions we are requesting, and you decide whether to grant them.
  4. If you grant them, WHOOP issues us a revocable authorisation — never your password.

From then on, the platform retrieves your data automatically at regular intervals, with no action required from you. We request only the permissions we actually use, listed in section 3.2.

We also request the technical permission called offline, which lets us renew the authorisation without asking you to log in again every hour. It does not broaden the set of data we can access.

5.What we use your data for

PurposeWhat we do
Clinical careEnable the health team caring for you to follow your biomarkers over time and inform the decisions in your programme
Medical recordsIncorporate the data into your electronic medical record, where applicable, as part of the documentation of your care
Showing you your own dataDisplay your values, trends and comparisons against your own historical baseline
Quality and securityVerify the integrity and consistency of data received, fix collection failures and audit access
Legal obligationsComply with medical record retention duties and respond to authorities where legally required

What we do not do

6.Legal bases for processing

All processing requires a legal basis. Ours are:

Legal basisWhere it applies
Consent
art. 7, I and art. 11, I
Connecting your WHOOP account and the ongoing collection of device data. It is specific, prominent and informed, and you may withdraw it at any time
Health protection
art. 11, II, “a” and “f”
Processing carried out by health professionals and health services for your care, including the medical record
Performance of a contract
art. 7, V
Delivering the services contracted under your care line
Legal obligation
art. 7, II and art. 11, II, “a”
Retaining clinical documentation for the periods required by law and by Brazilian Federal Council of Medicine rules
Exercise of rights
art. 7, VI and art. 11, II, “d”
Defence in judicial, administrative or arbitration proceedings

Withdrawing consent stops the collection of new device data, but does not invalidate processing already carried out, nor override the mandatory minimum retention of clinical documentation explained in section 10.

7.Who we share your data with

7.1 Clinical team

Your data is accessible to the health team involved in your care — physicians, clinical support professionals and anyone performing a care-navigation role in your programme. Access is granted by role, limited to what is necessary, and every access is logged. All of them are bound by professional secrecy and by contractual confidentiality obligations.

7.2 Processors

We engage suppliers that process data on our behalf and under our instructions, contractually bound to security and confidentiality standards and prohibited from using the data for their own purposes:

SupplierRole
WHOOP, Inc.Device manufacturer and source of the data. Acts as an independent controller in respect of your WHOOP account, governed by its own privacy policy
Cloudflare, Inc.Platform hosting, database, access control and network protection

7.3 Authorities

We may share data where there is a court order, a request from a competent authority or a legal obligation. Wherever legally permitted, we will inform you.

7.4 What we never share

There is no sharing for commercial, advertising or profiling purposes. We do not sell data. We do not provide data to employers, insurers or health plan operators.

8.International data transfers

Part of the processing takes place on servers located outside Brazil, because both WHOOP and Cloudflare operate global infrastructure. This constitutes an international data transfer under article 33 of the LGPD.

We carry out these transfers on the basis of the necessity to perform the contract with you and your specific consent, and we require contractual guarantees from suppliers offering protection equivalent to that provided under Brazilian law.

9.Information security

We apply technical and administrative measures proportionate to the sensitivity of the data:

No system is absolutely impenetrable. We commit to keeping these measures current and to acting transparently if an incident occurs — see section 17.

10.How long we keep your data

CategoryRetention period
Wearable data not incorporated into the medical recordFor the duration of your care programme and up to 5 years after it ends, unless you request deletion earlier
Data incorporated into the medical recordFor the minimum statutory medical record retention period, even if you withdraw consent
Access and audit logsAt least 6 months, under the Brazilian Internet Civil Framework
Data needed to defend legal rightsUntil the definitive conclusion of the relevant proceedings or the end of the limitation period

Once the period ends, data is irreversibly deleted or anonymised so that it can no longer be associated with you.

11.History and no overwriting

Wearable data changes after it is generated: a night's sleep may be rescored, an activity may be corrected, and a measurement may arrive incomplete and be completed hours later.

For that reason, when a data point is updated we store the new version without deleting the previous one. This exists for a clinical and safety reason: it allows us to state precisely what information was available to your physician on a given date, which is essential to the traceability of any clinical decision.

This history is fully subject to the retention periods in section 10 and to your right to deletion (section 12).

12.Your rights

The LGPD guarantees you the following, at any time and free of charge (art. 18):

RightWhat it means
Confirmation and accessTo know whether we process your data and to obtain a copy of it
CorrectionTo correct incomplete, inaccurate or out-of-date data
Anonymisation, blocking or deletionOf unnecessary or excessive data, or data processed unlawfully
PortabilityTo receive your data in a structured, machine-readable format, or have it transmitted to another provider
Information on sharingTo know with whom we share your data
Information on consentTo be told that you may refuse consent, and what the consequences are
Withdrawal of consentTo withdraw consent at any time, with immediate effect for new collection
ObjectionTo object to processing based on another legal ground, where the law has not been complied with
Review of automated decisionsTo request human review, where applicable

To exercise any of these, write to medicina@awakehealth.com.br. We will respond within 15 days. We may ask for additional information to confirm your identity — a safeguard against fraudulent requests made in someone else's name.

You are also entitled to access, within the Sinais platform itself, the data we have collected about you.

13.How to revoke the WHOOP connection

There are three routes, and all of them work:

  1. In the Sinais platform — use the disconnect option. Collection stops immediately and the authorisation is revoked with WHOOP.
  2. In the WHOOP app — you can remove the Awake Health integration directly in WHOOP's own settings.
  3. In writing — email medicina@awakehealth.com.br requesting disconnection.

Revoking the connection stops the collection of new data. If you also want the data already collected to be deleted, please say so explicitly — we will handle the request under section 12, subject to the statutory medical record retention periods described in section 10.

14.Automated decisions and platform content

The Sinais platform presents and compares data: it shows your values, how they evolve and how they deviate from your own historical baseline.

It does not diagnose, prescribe or recommend clinical action, and it does not make automated decisions producing legal effects or significantly affecting your interests. All clinical interpretation is performed by a qualified health professional. The information displayed does not replace medical consultation, diagnosis or treatment.

15.Cookies and similar technologies

We use the bare minimum, and none of them serve advertising:

We do not use advertising, cross-site tracking or behavioural profiling cookies.

16.Children and adolescents

The Sinais platform is intended for people aged 18 and over. We do not knowingly collect data from children or adolescents through it. If we identify improper collection, we will delete the data. If you are a legal guardian and believe this has happened, write to medicina@awakehealth.com.br.

17.Security incidents

If a security incident occurs that may create relevant risk or harm to you, we will notify you and the Brazilian National Data Protection Authority (ANPD) within a reasonable period, describing the nature of the data affected, the risks involved and the measures taken. We will also notify WHOOP where the incident involves data originating from the device, as required by its API terms of use.

18.Changes to this Policy

This Policy may be updated. Every version carries a number and effective date at the top. Where a change is material — particularly if it broadens the purposes of use or the list of people who can access your data — we will notify you in advance through your contact channels and, where the legal basis is consent, we will request fresh consent.

19.How to contact us

Privacy and data subject rightsmedicina@awakehealth.com.br
Data Protection OfficerSame address, with the subject line “Encarregado — LGPD”
National AuthorityYou may petition the ANPD directly — gov.br/anpd

20.Governing law and jurisdiction

This Policy is governed by Brazilian law, in particular Law 13.709/2018 (LGPD), Law 12.965/2014 (Internet Civil Framework) and, where applicable, the Consumer Protection Code and the rules of the Federal Council of Medicine on medical records and professional secrecy. The courts of the data subject's domicile are elected to settle any disputes arising from it.

This English version is provided for convenience. In the event of any discrepancy, the Portuguese version prevails.