See how handles personal data and protects your privacy.
This Privacy Policy aims to demonstrate the commitment of MUPI SYSTEMS LTDA, private legal entity under private law, registered with CNPJ/MF under No. 26.882.608/0001-80, headquartered at Rua Dom João Pimenta, 701, store 2, Centro, in Montes Claros-MG, with the privacy and protection of personal data collected from its users.
This policy establishes the rules regarding the collection, recording, storage, use, sharing, enrichment, and deletion of data collected within the scope of the services and functionalities of the website mupisystems.com.br and platforms developed by it, in accordance with the applicable laws.
As a condition for access and use of the functionalities, the USER declares to be over 18 (eighteen) years old and that they have fully and carefully read the rules of this document and the Terms of Use, being fully aware and thus giving their free and express agreement to the terms stipulated herein. If you do not agree with these guidelines, you should discontinue your access.
Data is collected when the USER voluntarily enters or submits information by accessing and interacting with the features available on this site, which includes:
Full name, email, date of birth, phone number, full address, used for: identifying the user, performing data portability, fulfilling service obligations, informing about news and features, promoting products and services, responding to requests, and complying with legal obligations.
IP address, interaction logs, accessed screens, device information, Session ID, Cookies, used to: comply with the Internet Civil Framework, identify the user, evaluate the use of services, develop statistical and security studies.
All technologies used will always comply with current legislation and the terms of this Privacy Policy.
The collected data will be stored on servers located in the United States, United Kingdom, Germany, or Brazil, as well as in a cloud computing environment, with secure transfer when necessary.
Through the service channel, the USER may change their consent grants for the processing of their data, grant new permissions, or withdraw their consent, being informed of the consequences that the withdrawal may cause.
Request access to your data or correction of incorrect information
Transfer your data to another service provider
Request the removal of your personal data when appropriate
Express opposition to the use of your personal data
Collected data and recorded activities may also be shared with judicial authorities when there is a legal requirement, or automatically in the case of corporate transactions.
The database formed through data collection on the MUPI website and platforms is our property and responsibility, and its use, access, and sharing, when necessary, will be done within the limits and purposes of our business and described in this Privacy Policy.
Internally, the data we collect is accessed only by properly authorized professionals, respecting the principles of proportionality, necessity, and relevance to the objectives of the MUPI website and/or platforms, in addition to the commitment to confidentiality and privacy preservation under this Privacy Policy.
This item applies specifically to the mobile app "eAgenda" available for Android devices, developed and maintained by MUPI SYSTEMS LTDA.
eAgenda is an appointment and calendar management application aimed at professionals and companies that provide services by appointment (medical consultations, counseling, general services), allowing full management of appointments, participants, and notifications.
The app allows user registration linked to organizations, creation and management of calendars, scheduling appointments, registering participants, and sending reminder notifications.
The eAgenda app collects personal data from USERS and APPOINTMENT PARTICIPANTS:
Full name, email address, password (stored encrypted), used for authentication, identification, data synchronization, and legal compliance.
Trade name, unique identifier (slug), phone number, used for linking the user and personalizing the experience.
Full name (required), email (optional), phone (optional), CPF (optional), for identification, contact, notifications, and historical record.
Date, time, calendar, services, status, description, location, search code, for appointment management and reports.
Access token, profile name and email from Google/Facebook, exclusively for simplified authentication.
Device identifier for push notifications, notification preferences.
Model, OS version, installation ID, backend URL, for technical support and aggregated statistics.
Error logs, technical events, connectivity, for diagnosis and app improvement.
Important: Collection of participant data (email, phone, CPF) is OPTIONAL, with only the name being mandatory.
Consent (art. 7, I): By creating an account, the user gives free and informed consent.
Contract execution (art. 7, V): Processing necessary for the operation of the contracted service.
Legitimate Interest (art. 7, IX): Security, fraud prevention, technical support, and improvements.
Legal obligation (art. 7, II): When the organization is legally required to keep records.
Full access to scheduling data, calendars, and participants. Responsible for the purpose and manner of processing.
Processes and stores data on behalf of the data controller organization, according to contractual instructions and LGPD.
Only tokens and basic data for Firebase (notifications) and social authentication. We do not share scheduling data.
Other organizations, advertising companies, data brokers, third parties for commercial purposes, or other unrelated users.
Confirm processing and access your data
Correct incomplete or inaccurate data
Request removal of unnecessary data
Transfer data to another provider
Delete data processed with consent
Know who we share with
Revoke consent at any time
Response time: 15 business days (Art. 18, §4 LGPD), extendable by an equal period.
User registration data: 5 years after account closure (CDC arts. 12 and 34)
Participant data: Period defined by the organization, minimum 5 years
Authentication tokens: Until logout or expiration (24h access, 30 days refresh)
Local notifications: 30 days, automatically deleted
Technical logs: 90 days, then anonymized or deleted
Data may be transferred to servers outside Brazil:
Only for scanning configuration QR Code. Does not capture photos/videos.
HTTPS communication with backend and Firebase for app operation.
Push notifications via FCM. Can be disabled without harm.
Location, Contacts, System Calendar, External storage, Microphone, Phone, SMS
Contact MUPI SYSTEMS via: contato@mupisystems.com.br
Subject: "eAgenda Mobile – Proteção de Dados LGPD"
Contact the organization where you made the appointment directly (they are the data controller).
Response time: 15 business days (Art. 18, §4 LGPD), extendable by an equal period.
Access Token: short-term credential for access to protected resources.
API: Application programming interface for app-server communication.
Backend: Servers that process and store data.
Cache: Temporary storage for quick access.
Encryption: Encoding of information for security.
FCM: Firebase Cloud Messaging for push notifications.
HTTPS/TLS: Secure encrypted communication protocol.
JWT: JSON Web Token for authentication.
OAuth: Standard authorization protocol.
Push Notification: Message from the server displayed on the device.
QR Code: 2D barcode scannable by the camera.
Refresh Token: Long-term credential to renew access tokens.
SharedPreferences: Local storage of settings.
Flutter Secure Storage: Secure encrypted storage.
Synchronization: Data synchronization between device and server.
Token: Unique code for authentication and authorization.
Last update of this section: January 2026
Version: 1.0
In case of any questions regarding the provisions of this Privacy Policy, please contact us through the following channels:
Formulário
Contact pageOur team is ready to clarify any questions about how we handle your data.
Speak with our team