Trust Center
Last updated: July 1, 2026
Security, privacy, and transparency are part of the product. This page brings together, in one place, how eAgenda protects your data, keeps the service available, and complies with the law — so that your security team, your DPO, or your procurement process can find the answers without having to ask.
eAgenda is developed by Mupi Systems (CNPJ 26.882.608/0001-80, Montes Claros/MG, Brazil), which operates SaaS platforms for the healthcare, professional services, education, and public services sectors.
1. Information Security
Data protection
- All traffic between users and the platform is encrypted with TLS 1.2 or higher.
- Passwords are stored exclusively as hashes, using robust algorithms (bcrypt/Argon2) — never in plain text.
Access control
- Data is segregated by ACCOUNT, in a multi-tenant architecture with logical isolation.
- Permission profiles configurable by the customer for its authorized users.
- Internal access by the Mupi team is restricted to operational need and logged.
Infrastructure
- Hosting in ISO/IEC 27001-certified data centers, located in Brazil, the United States, and/or the European Union.
- Automatic backups with a controlled retention and purge policy (details in the Privacy Policy, section 9).
- Segregated development and production environments.
2. Service Availability
On paid PLANS, we commit to 99% monthly availability, with proportional credits on the following invoice in the event of non-compliance, under clause 13 of the Terms of Use.
Scheduled maintenance is announced at least 24 hours in advance, preferably during lower-usage windows.
3. Privacy and Data Protection (LGPD)
Documents
- Privacy Policy — v2.0
- Anti-Spam and Acceptable Use Policy for Messaging — v2.0
- Data Processing Agreement (DPA) — v1.0
Processing roles, in brief. For the registration and billing data of the customers who subscribe to eAgenda, Mupi is the controller. For the data that customers and their end users enter into the platform (appointments, records), the customer is the controller and Mupi acts as processor, processing the data solely to provide the service. The full explanation is in section 2 of the Privacy Policy.
Data Subject Channel. Requests to exercise LGPD rights (art. 18) are received at contato@mupisystems.com.br, with a protocol number and progress tracking. Response within 15 days (art. 19, LGPD).
Data Protection Officer (DPO). Mupi maintains a Data Protection Officer, reachable through the Data Subject Channel above.
Sensitive data and regulated verticals. The platform serves the healthcare and education sectors; the specific safeguards for sensitive data and for data of children and adolescents are described in section 5 of the Privacy Policy.
Sub-processors. We use the following categories of providers in data processing, all contractually bound to security and privacy obligations. The named list, with purpose and location, is in Annex III of the Data Processing Agreement.
| Category | Purpose |
|---|---|
| Cloud hosting | Platform infrastructure |
| Payment intermediation | Payment processing (PCI-DSS; Mupi does not store card numbers) |
| Transactional email delivery | Confirmations, reminders, and notices |
| Messaging (WhatsApp/Meta) | Notifications, when enabled by the customer |
| Analytics and monitoring | Audience measurement and service improvement |
International transfer. Carried out on the basis of art. 33 of the LGPD and ANPD Resolution No. 19/2024, through the ANPD’s standard contractual clauses incorporated into the contracts with providers.
4. Compliance
- LGPD (Law 13,709/2018): privacy program described in the Privacy Policy; roles contracted in the Terms of Use (clause 17) and in the DPA.
- Brazilian Internet Civil Framework (Law 12,965/2014): retention of access logs for 6 months.
- Incident notification: under art. 48 of the LGPD and ANPD Resolution No. 15/2024 — ANPD and data subjects within 3 business days when there is relevant risk; affected customers notified within 24 hours.
- Infrastructure: hosting in ISO/IEC 27001-certified data centers.
5. Responsible Vulnerability Disclosure
We value the work of the security community. If you have identified a possible vulnerability in any eAgenda or Mupi Systems system:
- Report it to contato@mupisystems.com.br, describing the problem and the steps to reproduce it.
- We will acknowledge receipt within 2 business days and keep you informed of the progress.
- We ask that you do not access, alter, or exfiltrate third-party data beyond the minimum necessary for demonstration, do not degrade the service, and give us a reasonable time to remediate before any public disclosure (we suggest 90 days).
- We will not take legal action against good-faith research conducted within these rules.
We also publish a security.txt file in accordance with RFC 9116.
6. Legal Documents and Version History
| Document | Current version | Effective date |
|---|---|---|
| Terms of Use | v2.0 | June 30, 2026 |
| Privacy Policy | v2.0 | July 1, 2026 |
| Anti-Spam and Acceptable Use Policy | v2.0 | July 1, 2026 |
| DPA — Data Processing Agreement | v1.0 | June 30, 2026 |
Material changes are communicated by email 30 days in advance, under clause 19 of the Terms of Use.
7. Contact
- Privacy and Data Subject Channel: contato@mupisystems.com.br
- Security: contato@mupisystems.com.br
- Support and general questions: contato@mupisystems.com.br or via the contact page.