Privacy Policy
Privacy and Data Protection Policy — Dr.Post
Hello! 👋
This Privacy Policy describes how YELLOW SPARK LTDA., registered with the CNPJ/MF under No. 53.014.787/0001-07, headquartered at R. Riachuelo, 1200, Aracaju, SE — Brazil (“Dr.Post”, “We”), collects, uses, stores, shares, and protects the data of those who use Dr.Post.
Dr.Post is unlike most services: it works through WhatsApp and is operated by artificial intelligence. This means your conversations, photos, and audio are the raw material of the service — and we want you to understand exactly what happens to them. This Policy was written to be read; if anything is unclear, ask right in the conversation or write to dpo@drpost.ai.
Three commitments before anything else:
- Your identifiable conversations and content are not used to train artificial intelligence models — neither by the providers we contract (a contractual prohibition, which is also a Meta requirement for WhatsApp data), nor by us: proprietary technology is developed only with effectively anonymized data, which ceases to be personal data (Sections 4 and 12).
- We do not perform facial recognition or identification of people in photos. Images are processed exclusively to create your marketing material.
- Your card data never passes through our servers — it stays with partner payment processors, in PCI-DSS certified environments.
TABLE OF CONTENTS
- Who we are and processing roles
- What data we collect
- How we collect it
- What we use your data for and legal bases
- Artificial intelligence and your data
- Photos, audio, and images of people
- Public social media data
- WhatsApp as a channel
- Who we share your data with
- Advertising and commercial communications
- International data transfers
- How long we keep your data
- Your rights
- How to exercise your rights
- Security
- Cookies and website
- Children and adolescents
- Changes to this Policy
- Contact and Data Protection Officer (DPO)
- Governing law and jurisdiction
1. WHO WE ARE AND PROCESSING ROLES
a) Dr.Post is a content marketing service operated by artificial intelligence, provided by Yellow Spark Ltda., which acts as the Controller of the personal data processed to provide the service.
b) Our technology vendors (Section 9) act as Processors (operadores), processing data on our behalf and under our instructions.
c) When you send third-party data: if you send Dr.Post personal data of other people (for example, photos of your team or customers, testimonials, contact lists), you are the Controller of that data for the purposes of your marketing, and we process it under your instructions to provide the service — acting as Controllers only for our own purposes (security, abuse prevention, service improvement, and compliance with legal obligations). It is your sole responsibility to ensure you have the legal basis and the necessary consents — especially for images of people (Section 6) — and you will indemnify us, as set out in Section 17 of the Terms of Service, for the consequences of the absence of such authorizations.
d) This Policy applies to users of the service, visitors to the drpost.ai website, and people who chat with our WhatsApp numbers — including before subscribing (prospecting conversations).
2. WHAT DATA WE COLLECT
2.1. Data you provide to us
| Category | Examples |
|---|---|
| Identification and contact | Name, phone number (WhatsApp — the account’s primary identifier), email, country, language, time zone. |
| Tax and billing data | CPF/CNPJ (when required for billing), billing address, and equivalent tax information required in your country. |
| Your business data | Brand name, industry, website, social media profiles, visual identity, tone of voice, products and services, content preferences, campaign context, and media investment. |
| Conversations | Text messages exchanged with the AI agents via WhatsApp — including instructions, feedback, and approvals — from the first contact, even before subscribing. |
| Media you send | Photos and images (up to 5 MB), audio and voice messages (up to 16 MB), PDF documents (up to 10 MB), text files (up to 256 KB), location and contacts shared in the conversation. |
| Payment data | Card payments are handled directly by partner payment processors — we receive only customer/subscription identifiers, payment status, and plan, never the full card number. Payments via Pix or bank transfer, where available, may be received directly, recording only the data needed for confirmation and tax obligations. |
| Team | Name, phone, email, and role of team members you invite. |
2.2. Data generated by your use of the service
| Category | Examples |
|---|---|
| Brand DNA | The brand profile built by the service (visual identity, palette, typography, tone and style guidelines). |
| Produced content | Strategies, calendars, captions, hashtags, and images generated for you, including revision and approval history. |
| Usage ledger | Credit statement: operations performed, credits consumed, dates (billing transparency). |
| Technical and telemetry records | Message logs (identifiers, timestamps), production job records, usage metrics of AI operations, social media connections (connection identifier — access tokens stay with the integration provider). |
2.3. Data collected from public sources
| Source | Data |
|---|---|
| Your website | Texts, images, colors, fonts, and logo, for identity analysis. |
| Your public profiles | Posts, captions, images, bio, and public engagement metrics from the profiles you indicate (Instagram and other networks). |
| Public reference profiles | Public data from competitors or references, for research, market analysis, and inspiration (Section 7). |
| Public market data | Trends, research, and publicly available content related to your industry. |
2.4. What we do NOT collect
- We do not collect full payment data (card) — it stays with the processor.
- We do not intentionally collect sensitive data (health, religion, sexual orientation, biometrics, etc.) — and we ask that you not send it in conversations, unless strictly necessary for your marketing.
- We do not access your WhatsApp conversations with other people — only the conversation between you and our numbers.
3. HOW WE COLLECT IT
a) In the conversation: when you talk to the AI team via WhatsApp (messages, media, instructions) — including in conversations prior to subscribing.
b) At subscription: when you sign up for a plan (checkout data: name, email, phone, CPF/CNPJ where applicable, plan).
c) From public sources: when you indicate your website and profiles for analysis, and when necessary to provide the service (market research, trends, and references).
d) Automatically, through use: technical, telemetry, and usage records generated by the operation of the service.
e) From third parties: payment confirmations (payment processors) and publishing results (connected social platforms).
4. WHAT WE USE YOUR DATA FOR AND LEGAL BASES
| Purpose | Description | Legal basis (LGPD) |
|---|---|---|
| Service delivery | Operating the conversation with the agents, analyzing your brand, generating strategy and content, delivering and publishing according to your approvals. | Performance of a contract (art. 7, V) |
| AI processing | Sending your messages, media, and brand context to the AI providers to generate responses and content (Section 5). | Performance of a contract (art. 7, V) |
| Billing and credit management | Processing subscriptions, recording usage, auditing the cost of operations, preventing payment defaults. | Performance of a contract (art. 7, V) |
| Operational communications | Content deliveries, pending-approval notices, renewal, re-engagement messages. | Performance of a contract (art. 7, V) / Legitimate interest (art. 7, IX) |
| Commercial communications | Offers, news, and content from Dr.Post, from other Yellow Spark group products, and from selected commercial partners that may be of interest to your business — always sent by us, through our channels (Section 10; you can ask to stop at any time). | Legitimate interest (art. 7, IX) / Consent (art. 7, I) |
| Advertising and acquisition | Promoting Dr.Post and group products through advertising platforms, including remarketing and conversion measurement (Section 10). | Legitimate interest (art. 7, IX) for ad display and effectiveness measurement; Consent (art. 7, I), collected in a highlighted manner, for the sharing of identifiers intended to build custom and lookalike audiences |
| Service improvement and development | Analyzing usage, quality, performance, and costs; reviewing agent conversations and outputs for quality supervision; developing and testing new features. | Legitimate interest (art. 7, IX) |
| Development of proprietary technology | Using aggregated and anonymized data to develop, train, and improve the algorithms, models, products, and services of the Yellow Spark group. | Anonymized data is not personal data (art. 12) / Legitimate interest (art. 7, IX) |
| Market intelligence | Producing statistics, studies, reports, and industry benchmarks from aggregated and anonymized data, including for commercial purposes. | Anonymized data is not personal data (art. 12) / Legitimate interest (art. 7, IX) |
| Promotional use | Featuring your brand and the content produced, approved, or published in Dr.Post promotional materials, as set out in Section 8.4 of the Terms of Service. | Legitimate interest (art. 7, IX), with the right to object at any time (Section 14) |
| Security and fraud prevention | Verification of message signatures, usage limits, abuse monitoring, prevention of multiple accounts. | Legitimate interest (art. 7, IX) |
| Legal obligations | Retention of records required by law (tax, Marco Civil da Internet). | Legal obligation (art. 7, II) |
| Defense of rights | Use of records in administrative, judicial, or arbitral proceedings. | Regular exercise of rights (art. 7, VI) |
When we process data based on legitimate interest, we carry out a prior assessment (LIA) to ensure that our interests do not override your fundamental rights and freedoms. You may object to such processing at any time (Section 14), without prejudice to your use of the service’s other features.
Important: we do not sell your personal data, nor do we hand it over to partners so they can contact you directly. Commercial partner offers are selected and sent by us, through our own channels (Section 10) — your data does not leave Dr.Post for that purpose. The sharing with advertising platforms described in Section 10 occurs solely for the benefit of Dr.Post and the Yellow Spark group, to promote our services — never so that third parties can advertise to you.
5. ARTIFICIAL INTELLIGENCE AND YOUR DATA
This is the most important section of this Policy. Dr.Post is operated by third-party artificial intelligence models — market-leading providers for text, image, and audio processing, contracted under commercial/enterprise tiers. For the service to work, your messages, photos, audio, documents, and your brand context are sent to these providers, which process them on our behalf, as Processors.
What this means in practice:
a) Your conversations do not train the providers’ models. We operate under commercial contracts whose terms prohibit the use of your data to train the providers’ models. This is also a Meta requirement for WhatsApp data, which we comply with in full. We may use aggregated and anonymized data to develop and improve our proprietary technology (Section 4), subject to the anonymization standard in Section 12.
b) Transitory retention at the providers. AI providers may retain inputs and outputs for short, limited periods, defined in each provider’s terms, for security, audit, and abuse-detection purposes — periods that may be extended where necessary to investigate violations or due to a legal obligation.
c) Generated content may resemble other content. AI models can generate similar content for different customers; this is a characteristic of the technology, not a sharing of your data.
d) Human supervision. Authorized Dr.Post personnel may access conversations, media, and content in your account for quality supervision, security, abuse prevention, support, billing audit, and service improvement — always under access controls and a duty of confidentiality.
e) Automated decisions. Content production is automated, but nothing is published without your approval — you are the human control in the flow. You may also request a review of any output and clarification about the service’s logic (LGPD, art. 20).
f) Identity of the providers. The exact composition of our AI vendor architecture is strategic information, protected as a commercial and industrial secret (LGPD, art. 6, VI). The providers are identified by category in Section 9; the list of sub-processors may be requested from our Data Protection Officer (Section 19).
6. PHOTOS, AUDIO, AND IMAGES OF PEOPLE
a) What we use images for: photos you send (products, premises, team, yourself) and public images of your brand are used to understand your visual identity and produce your marketing material — including processing by the AI providers in Section 5.
b) We do not identify people. We do not perform facial recognition, identification, or biometric authentication of anyone. Images are processed as ordinary personal data, for the exclusive purpose of content creation — not as biometric/sensitive data, since they are not used to identify individuals. Should the processing of certain images be classified as sensitive personal data (for example, by revealing a health context in your industry), we will adopt the legal basis of art. 11 of the LGPD and limit the processing to what is strictly necessary — it being your responsibility, when sending such images for your marketing, to ensure the corresponding legal basis.
c) Photos of third parties are your responsibility. If a photo you send shows other identifiable people (customers, team, family members), it is your responsibility to have their consent — both for the processing described here and for the use of the image in marketing (image rights — art. 20 of the Brazilian Civil Code). We have no way of verifying this for you, and you will indemnify us for claims arising from the absence of such authorizations (Section 17 of the Terms of Service).
d) Audio (voice messages): when you send a voice message, the audio is processed — including by the AI providers of Section 5 — so that the team of agents can understand it and respond, which may include generating an automatic transcription. The audio and its transcription are stored as part of the conversation history, for the same period as other messages (Section 12), and are used for the continuity of the service and, to a limited extent, for the own purposes of Section 4 (such as security, quality supervision, and legal obligations). We do not use audio for voice identification or authentication. Audio and transcriptions are deleted together with the history — upon account deletion or upon request (Section 14) — and any copies in technical records and backups are eliminated in the ordinary purge cycles (Section 12).
e) Image storage: uploaded images and visual references are stored in your brand library (in the cloud, with signed URLs and access restricted to your account) while your account is active.
7. PUBLIC SOCIAL MEDIA DATA
a) From your profiles: when you indicate your Instagram or another profile, we collect public data from it (posts, images, bio, public metrics) through specialized vendors, to build and keep your Brand DNA up to date.
b) From reference/competitor profiles: we may collect public data from other profiles for market research, competitive analysis, and inspiration. We process only publicly available data, for the limited purpose of analysis — we do not republish third-party content or use this data to contact them. This public data — including images, which may depict people — may be processed by the AI providers in Section 5, exclusively for analysis and inspiration, never to identify people.
c) The LGPD also applies to public data: we respect the purpose and the rights of data subjects. If you are the data subject of an analyzed profile and want the derived data removed, contact dpo@drpost.ai (Section 14).
d) Public data collected may be outdated or incomplete — it depends on the source platforms.
8. WHATSAPP AS A CHANNEL
a) The service works through the WhatsApp Business Platform (Meta). Your messages travel through the infrastructure of Meta and of our Meta-approved messaging solution provider, which act as Processors in transporting the messages.
b) Your use of WhatsApp on your side is governed by the Terms and the WhatsApp Privacy Policy, which apply independently of this Policy.
c) We use conversation data to provide the service and for the other purposes described in Section 4 — in compliance with Meta’s rules for businesses, including the prohibition on using WhatsApp data to train AI systems.
d) Messages outside WhatsApp’s 24-hour window are delivered through message templates approved by Meta.
9. WHO WE SHARE YOUR DATA WITH
We do not sell your personal data. We share data with the categories of vendors necessary for operation (Processors/sub-processors), listed below:
| Category | Role | Data involved |
|---|---|---|
| Meta / WhatsApp Business Platform | Message transport | Number, messages, and media from the conversation |
| Messaging solution provider | Message routing, Meta-approved | Number, messages, and media from the conversation |
| AI model providers (text, image, and audio) | AI processing (Section 5) | Conversations, media, brand context, briefings, and prompts |
| Public-data collection vendors | Reading your website and public profiles | URLs and public identifiers you indicate |
| Publishing integration provider | OAuth connection and publishing to your networks | Authorized connections and approved content (access tokens stay with the provider) |
| Payment processors and authorized resellers (Merchant of Record) | Payment processing and billing — as processors or, when acting as sellers of record, as independent controllers under their own policies | Payment, billing, and tax data |
| Cloud infrastructure providers | Database, storage, and computing | Account data (encrypted at rest) |
| Orchestration and observability providers | Execution of production tasks and telemetry | Job metadata and technical records |
| Operational communication providers | Transactional email, link shortening, report generation | Contact data and content of reports generated for you |
| Advertising platforms | Promotion of our services (Section 10) | Hashed identifiers and conversion events |
Identity of the vendors. The individual identification of the vendors in each category is strategic information of Dr.Post, protected as a commercial and industrial secret — a case expressly reserved by the LGPD’s transparency principle (art. 6, VI). We disclose by name only the vendors whose identification is inherent to the service (Meta/WhatsApp); the identity of the payment processors is visible to you at the time of payment and on your card statement. The named, up-to-date list of sub-processors is available to any data subject upon request to our Data Protection Officer (Section 19), provided within the timeframe of Section 14 — commercial secrecy is invoked only so as not to publish it openly and permanently, never to deny you the information about with whom your data is shared (art. 18, VII).
We require from all Processors contractual data-protection commitments compatible with the LGPD. The composition of the categories may be updated at any time, without amending this Policy, provided the protection standard described here is maintained.
In addition, we may share data:
a) With Yellow Spark group companies (companies under common control), based on legitimate interest (art. 7, IX), for administrative, security, and improvement purposes — and, subject to the right to object (Section 14), for the commercial and marketing purposes in Section 4 — under this same Policy;
b) With authorities, in Brazil and abroad — in the countries where we, our providers, or our partners operate or maintain infrastructure (for example, the United States, Canada, the United Kingdom, and European Union countries) —, under a legal obligation, court order, request from a competent authority, or to protect the rights of Dr.Post, its users, or third parties, including in the investigation of unlawful conduct and abuse (Terms, Section 12). Our providers may have their own legal reporting obligations to the authorities of the countries where they operate (for example, in cases of child exploitation material), which do not depend on any decision of ours;
c) In a corporate reorganization (merger, acquisition, sale of assets), with the successor bound by this Policy;
d) On your social networks, when you connect accounts and approve publications — published content is governed by the policies of the destination platform.
10. ADVERTISING AND COMMERCIAL COMMUNICATIONS
a) Commercial communications. We may send you offers, news, and content from Dr.Post, from other Yellow Spark group products, and from selected commercial partners — products and services that may be of interest to your business (for example, complementary technology or marketing services). These offers are always selected and sent by us, through the contact channels you provided to us: your data is not handed over to the partners. You may ask to stop at any time — in the conversation, via the unsubscribe link (emails), or through the DPO — without prejudice to your account’s operational communications, which will continue to be sent.
b) Remarketing and custom audiences. To promote our own services, we may share with advertising platforms (such as Meta, Google, and TikTok) hashed identifiers (email and/or phone transformed into an irreversible cryptographic code) and conversion events, in order to: display Dr.Post ads to you (remarketing); find audiences with a profile similar to that of our customers (lookalike audiences); and measure the effectiveness of our campaigns. The sharing of identifiers to build custom and lookalike audiences occurs with your consent, collected in a highlighted manner (cookie notice and/or specific request), and you may withdraw it at any time, with effect on future sharing.
c) What “hash” means: your data is transformed into an irreversible code before being sent. The platforms do not receive your email or phone in plain text — only a code that lets them check whether you already have an account with them.
d) Opt-out. You may object to the use of your data for advertising at any time (Section 14), without prejudice to your use of the service. Where applicable law requires consent for any of these activities, it will be requested in a highlighted manner.
11. INTERNATIONAL DATA TRANSFERS
a) Our technology vendors (Section 9) operate infrastructure outside Brazil — particularly in the United States. International data transfer is therefore inherent to the Service: it cannot be provided without it. By subscribing to and using the Service, you are informed of this international character of the operation.
b) The transfer relies on the grounds of art. 33 of the LGPD — in particular the necessity of the transfer for the performance of the contract between you and Dr.Post (art. 33, IX, in conjunction with art. 7, V) — and complies with the ANPD regulations (Resolution CD/ANPD No. 19/2024).
c) In addition, we select vendors that maintain, in their public data-protection terms and addenda (DPAs), recognized contractual safeguards — data-protection clauses compatible with the LGPD and, depending on the vendor, the ANPD Standard Contractual Clauses or the European Union Standard Contractual Clauses — as well as recognized security certifications (SOC 2, ISO 27001).
d) For users subject to the GDPR (European Economic Area/United Kingdom), transfers rely on the EU Standard Contractual Clauses and equivalent mechanisms maintained by the vendors.
12. HOW LONG WE KEEP YOUR DATA
| Type of data | Retention period | Justification |
|---|---|---|
| Registration and tax data | While the account is active + 5 years | Statutory limitation periods, legal obligations, and defense in proceedings |
| Conversations and work history | While the account is active | Context necessary for the service (the agents “remember” your business) |
| Prospecting conversations (before subscribing) | For as long as the legitimate interest in commercial re-engagement and fraud prevention persists — periodically reviewed — or until you object, whichever comes first | Commercial re-engagement and fraud prevention |
| Images and brand library | While the account is active | Production of content consistent with the brand |
| Audio and transcriptions (voice messages) | While the account is active, together with the conversation history | Continuity of the service and service context (Section 6.d) |
| Credit statement and transactions | 5 years after the transaction | Tax and accounting legislation |
| Access records/technical logs | 6 months, extendable only by court order or specific legal obligation | Marco Civil da Internet (art. 15) |
| Telemetry and observability | As a rule, up to 90 days | Quality, cost audit, and security |
| Marketing and advertising data | Until you object or 2 years of inactivity | Promotion of our services |
| Retention at the AI providers | Transitory, per each provider’s terms, extendable in violation investigations or due to a legal obligation | Security and abuse detection |
| Aggregated and anonymized data | Indefinitely | No longer constitutes personal data (LGPD, art. 12) |
The periods in the table that exceed 90 days derive from legal retention requirements (tax and Marco Civil da Internet) or from our legitimate interest (commercial re-engagement and promotion), as indicated in each row; retentions based on legitimate interest cease upon your objection (Section 14). Backups may retain data for a limited additional period, with progressive deletion according to the backup cycles.
Anonymization standard: data is considered anonymized when subjected to techniques that make the re-identification of the data subject impossible using reasonable means and efforts — ours or those of third parties (LGPD, arts. 5, XI, and 12). We undertake not to reverse the anonymization or re-identify data subjects, and to treat as personal data any dataset that allows re-identification; aggregation is performed in a manner that does not allow the formation of a behavioral profile of an identifiable natural person (art. 12, §1).
After account cancellation: we may keep your data for a grace period no longer than necessary for its purposes — account reactivation (preserving your Brand DNA, brand library, and work history), settlement of outstanding amounts, and fraud prevention — periodically reviewed. After that, we delete or anonymize the data, except for the minimum set of identity, tax, and billing records kept under a legal obligation or for the regular exercise of rights (Section 14.e). You may request immediate deletion at any time (Section 14).
Maximum periods, not a custody commitment: the periods in this Section are maximum retention limits for data-protection purposes — they do not constitute an obligation of custody, archiving, or backup. We may delete or anonymize data before the indicated periods, at our discretion and without prior notice, subject to mandatory legal retention. Dr.Post is not a storage service: keep your own copies of the Generated Content delivered to you and of your business’s important materials.
13. YOUR RIGHTS
You have the following rights, guaranteed by the LGPD and, where applicable, by the GDPR and equivalent laws of your country (such as the CCPA/CPRA, in California, and the UK GDPR, in the United Kingdom):
| Right | Description |
|---|---|
| Confirmation and access | Know whether we process your data and obtain a copy of it. |
| Correction | Correct incomplete, inaccurate, or outdated data. |
| Deletion | Request the deletion of your data (subject to legal retention requirements). |
| Anonymization or blocking | For data that is unnecessary, excessive, or processed in non-compliance. |
| Portability | Receive your data in a structured format and take it to another provider. |
| Information about sharing | Know with whom we share your data (Section 9). |
| Withdrawal of consent | Withdraw consents given, at any time. |
| Objection | Object to processing based on legitimate interest. |
| Review of automated decisions | Request review of decisions made solely in an automated manner (LGPD, art. 20). |
| Complaint to the authority | File a complaint with the ANPD (Brazil) or your country’s authority. |
14. HOW TO EXERCISE YOUR RIGHTS
a) In the conversation: many rights can be exercised directly on WhatsApp — for example, ask about your balance and usage, request correction of brand data, etc.
b) By email: send your request to dpo@drpost.ai, with your name, registered phone number, and a description of the request. We may require proof of identity before responding, for your security and fraud prevention.
c) Timeframe: confirmation of the existence of processing and access may be provided immediately, in simplified form; the full declaration, within 15 (fifteen) days (LGPD, art. 19, §§1 and 2). Other requests will be answered within a reasonable time; complex cases may require additional time, which we will inform you of.
d) Limits: we will respond to all data subject requests. We may decline to fulfill a request when: (i) it is not possible to confirm the identity of the requester; (ii) the request is made by a third party without the data subject’s authorization; or (iii) it constitutes an abuse of right (art. 187 of the Brazilian Civil Code) — always with reasons, informing you of your right to complain to the ANPD. Repetitive or disproportionate requests may be handled on a staggered basis, without denying the rights guaranteed by the LGPD.
e) Account deletion: upon your deletion request, we terminate the subscription and delete your content, media, conversations, and other personal data from our systems. Deletion removes your content, your media, and your communications; a minimum set of identity, tax, and billing records is retained, in identifiable form, for the period required by law (legal holds of Section 12 — for example, the transaction statement and tax data) and, once that period ends, is deleted or anonymized.
f) If your data appears in the content of one of our customers (for example, in photos they sent, or in public data analyzed for them): direct your request to that customer, who is the controller of that data (Section 1.c) — we will forward to them any requests we receive directly.
15. SECURITY
We adopt technical and organizational measures consistent with the state of the art to protect your data:
- Encryption in transit (HTTPS/TLS) in all communications with our systems and vendors;
- Encryption at rest in the database and media storage;
- Cryptographic verification of the authenticity of messages received from the platforms;
- Access control under the principle of least privilege; data access restricted to the data subject’s account; internal human access limited to authorized personnel, under a duty of confidentiality;
- Validation of received media (size limits, verification of the file’s real type) and containment of malicious instructions embedded in files;
- Monitoring and usage limits for abuse prevention.
No system is absolutely secure. We make efforts consistent with the market and the state of the art, but we cannot guarantee absolute security against every attack or incident.
Incidents: in the event of a security incident that may cause relevant risk or harm to you, we will notify the ANPD and the affected data subjects within the timeframes and in the manner of the applicable regulation (LGPD, art. 48; Resolution CD/ANPD No. 15/2024).
Your part: keep control of your WhatsApp number and your device — the account is tied to it. You are responsible for the activities carried out from your number; notify us immediately if you lose access to it.
16. COOKIES AND WEBSITE
a) The drpost.ai website uses cookies and similar technologies, in the following categories:
| Category | Purpose | Can be disabled? |
|---|---|---|
| Essential | Basic website operation (language, security). | No |
| Analytics and performance | Understand how the website is used and improve the experience (audience analytics tools). | Yes |
| Advertising | Measure campaigns and display ads for our services on other platforms (conversion and remarketing pixels — for example, from Meta, Google, and TikTok), as set out in Section 10. | Yes |
b) Where the law requires, non-essential cookies will be activated only after you express your choice through the cookie notice. You can also manage cookies in your browser settings — blocking essential ones may impair the website’s operation.
c) The service’s conversations happen on WhatsApp — not on the website.
17. CHILDREN AND ADOLESCENTS
Dr.Post is a professional service intended for people aged 18 or older. We do not intentionally collect data from children or adolescents. If we identify an account belonging to a minor, it will be terminated and the data deleted.
18. CHANGES TO THIS POLICY
We may change this Policy at any time, to reflect changes in the service, in technology, or in legislation. Material changes (those affecting your rights or how we process your data) will be communicated via WhatsApp and/or email at least 30 (thirty) days in advance. Minor changes are published on this page, with the date updated. Continued use of the service after the effective date constitutes acceptance of the new Policy; if you do not agree, you may terminate your account before it takes effect. When a change depends on your consent (by introducing a purpose subject to it), it will be requested in a highlighted manner — continued use, in that case, does not suffice.
19. CONTACT AND DATA PROTECTION OFFICER (DPO)
The Data Protection Officer (DPO) of Yellow Spark Ltda. is available for questions about this Policy and data subject requests:
| Channel | Information |
|---|---|
| DPO / privacy email | dpo@drpost.ai |
| Support email | suporte@drpost.ai |
| Directly in the conversation with the Dr.Post team |
If you are not satisfied with our response, you may complain to the Brazilian National Data Protection Authority (ANPD) or to the data protection authority of your country.
20. GOVERNING LAW AND JURISDICTION
a) This Policy is governed by the laws of the Federative Republic of Brazil, in particular the General Data Protection Law (LGPD — Law No. 13,709/2018).
b) The courts of the Judicial District of Aracaju, Sergipe, Brazil are hereby elected, without prejudice to mandatory venue rights and the protections of public-order rules applicable to your case.
c) This Policy is written in Portuguese, with translations provided for convenience. In the event of a conflict, the Portuguese version prevails, including over this English version.
Last updated: July 18, 2026
Version: 2.0
YELLOW SPARK LTDA. — CNPJ 53.014.787/0001-07 — R. Riachuelo, 1200, Aracaju, SE — Brazil
© 2026 Dr.Post — All rights reserved.