Borrador — debe revisarlo un abogado
Draft — must be reviewed by a lawyer. Text prepared for legal review. It is not the final version and may change.
Legal documents
Opifer privacy notice
How Opifer processes the personal data of the doctors who use the platform and of the visitors to its website, and how it processes, on behalf of each doctor, the data of their patients. Prepared under the Mexican Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP), published in the Diario Oficial de la Federación on March 20, 2025.
Version 2026-10-01-borrador-3 • Last updated: October 1, 2026
English translation provided for convenience. The Spanish version prevails.
1. Identity and address of the controller
[Legal name of Opifer] ("Opifer"), with its address at [full address] and tax ID (RFC) [RFC], is the controller of the personal data it collects for itself: that of the doctors and other users of the platform and that of the visitors to the opifer.vercel.app website.
Pending: complete the legal name, address and tax ID, and appoint the person or department in charge of personal data.
2. Who this notice applies to
Opifer is a platform for doctors practicing in Mexico to run their practice: clinical records, schedule, prescriptions, online booking and a patient portal. We process personal data in two different roles:
- As controller, of the data of the doctors and other users of the platform and of the website visitors. This whole notice applies to them.
- As processor, of the data of the patients each doctor records. The controller of that data is the doctor; Opifer processes it only on the doctor’s behalf and following their instructions (see "Patient data"). Patients should read their doctor’s privacy notice. Opifer offers doctors a model notice for patients.
3. Personal data we process
Of doctors and other users of the platform:
- Identification and contact: name, email address and phone number.
- Professional data: professional license (cédula profesional), specialty and subspecialty, years of experience, biography, photo, and the address, city and phone number of the practice.
- Account data: sign-in credentials (the password is stored hashed by our authentication provider; Opifer never sees it), language, sign-up date, and the version and date on which you accepted this notice and the terms.
- Usage and technical data: log of the actions taken on the platform, IP address, browser type and the access records needed to keep the service secure.
- Billing and payment data, if you subscribe to a plan: tax details and the payment information the payment processor gives us. Opifer does not store full card numbers.
Of website visitors: the technical data of their visit (IP address and server logs) and whatever they choose to send us, for example when writing to support.
4. Sensitive personal data
Opifer does not ask doctors or website visitors for sensitive personal data.
Patients’ health data is sensitive personal data. Opifer does not process it as controller but as processor, on behalf of the doctor who records it, who must obtain the patient’s express consent. The platform asks the doctor to confirm they obtained it when recording each patient, and keeps the notice version, the date and who recorded it.
5. Purposes of the processing
Primary purposes, needed for your relationship with Opifer:
- Creating and managing your account and verifying your identity when you sign in.
- Providing the service: clinical records, schedule, prescriptions, online booking, patient portal, appointment reminders by email and WhatsApp, and electronic invoicing (CFDI).
- Publishing your public profile and booking page, if you turn them on, with the professional details you choose to show.
- Giving you technical support and handling your requests.
- Keeping the platform secure: audit logs, prevention of fraud and unauthorized access, and backups.
- Charging for the service and issuing tax receipts.
- Complying with Opifer’s legal obligations and with requests from competent authorities.
Secondary purposes, not needed for the service:
- Sending you product news, satisfaction surveys and event invitations.
- Producing usage statistics to improve the platform, with de-identified data whenever possible.
6. How to refuse the secondary purposes
You can ask at any time that we stop using your data for the secondary purposes by writing to soporte@medos.app with the subject "Secondary purposes". Refusing does not affect the service.
You can also sign up for the Public Registry to Avoid Advertising (REPEP) of the Federal Consumer Protection Agency (PROFECO).
7. Patient data: Opifer as processor
Patient data (identification, contact details, clinical records with their health data, appointments, payments and documents) is recorded by the doctor, who is its controller. Opifer acts as processor and undertakes to:
- Process it only to provide the service to the doctor and following their instructions; never for its own purposes, advertising or profiling.
- Not sell, assign or transfer it, except when ordered by a competent authority.
- Keep it confidential and require the same of its staff and sub-processors.
- Apply the security measures described in this notice.
- Tell the doctor without delay about any security breach affecting that data.
- Help the doctor answer their patients’ ARCO requests: from the platform they can export all of a patient’s data and print their clinical record.
- When the relationship with the doctor ends, keep the records for the period the law requires, then block and delete them (see "Retention, blocking and deletion").
If a patient sends Opifer a request about their data, we will forward it to their doctor and let the patient know.
8. Transfers and disclosures to processors
Opifer does not sell or rent personal data.
To operate, Opifer shares data with providers that process it on its behalf, as processors or sub-processors, under contract and without being able to use it for their own purposes. These disclosures do not require your consent:
- Supabase: database, authentication and file storage, with servers in the United States of America.
- Hosting providers for the web application and the API: [Vercel and the API provider].
- Resend: sending emails to patients: appointment reminders, satisfaction survey invitations and, when the doctor asks for it, their prescriptions with the PDF attached, which contains the diagnosis and the medications prescribed.
- Stripe: charging doctors’ subscriptions to Opifer plans. It receives card details directly; Opifer never sees or stores them.
- Twilio and WhatsApp (Meta): sending appointment reminders by WhatsApp and receiving patients’ replies, with servers in the United States of America. They only receive the patient’s first name, WhatsApp number, the date, time and place of the appointment and the doctor’s name; never clinical data.
- Facturapi: issuing, sending and cancelling the tax invoices (CFDI) doctors issue to their patients, and stamping them with Mexico’s Tax Administration Service (SAT). It receives the patient’s tax details (RFC, name, tax regime, postal code and, if given, email) and the amount; the concept is “Consulta médica”, with no clinical data.
The data is therefore hosted outside Mexico, in the United States of America. We require these providers to apply security and confidentiality measures equivalent to those in this notice.
Opifer will only transfer data to third parties without your consent in the cases the LFPDPPP allows, for example when ordered by a competent authority or when needed to establish, exercise or defend a right in court.
Pending: confirm the list of providers, where their servers are, and the processing and sub-processing agreements.
9. ARCO rights: access, rectification, cancellation and objection
You have the right to know what data we hold about you and how we use it (access), to have it corrected if it is inaccurate or incomplete (rectification), to have it removed from our records when it is no longer needed (cancellation) and to object to its use for specific purposes (objection).
To exercise them, send your request to soporte@medos.app with:
- Your name and a way to send you the answer.
- An official ID or, if a representative acts for you, the document proving the representation.
- A clear description of the data and of the right you want to exercise.
- Any document that helps locate your data and, for a rectification, the corrections and the document supporting them.
We will answer within the periods the LFPDPPP sets: up to 20 business days to give you our answer and 15 more business days to carry it out, if it applies. The request is free of charge; only justified shipping or copying costs may apply.
If you are the patient of a doctor who uses Opifer, the controller of your health data is your doctor: send your request to them. If you write to us, we will forward it to your doctor.
Pending: confirm the periods and request requirements under the 2025 LFPDPPP and its regulations.
10. Withdrawing consent
You can withdraw at any time the consent you gave us to process your data, following the same procedure as for ARCO rights. Withdrawal does not apply retroactively.
If you withdraw consent for a primary purpose we will no longer be able to provide the service and will deactivate your account. Your patients’ records are not deleted because of it: they are kept for the period the law requires (see "Retention, blocking and deletion").
11. Retention, blocking and deletion
We keep your account data while your account is active. If you close it, we deactivate it: it stops working and your public profile disappears, but it is not deleted right away, because it holds your patients’ clinical records.
NOM-004-SSA3-2012, the Mexican standard on clinical records, requires each record to be kept for at least 5 years from the date of the last medical act. During that period records are kept even when deleted on the platform: deleting an entry only removes it from the active record, and every correction keeps the previous version.
Once the retention period ends, and if no other legal obligation requires keeping it, the data is blocked: stored without any other processing, only to deal with possible liabilities during the applicable limitation period. When the blocking period ends, it is securely deleted.
Billing and payment data is kept for the period tax rules require (generally 5 years under the Federal Tax Code).
13. Security measures
We apply administrative, technical and physical security measures to protect the data against damage, loss, alteration, destruction, or unauthorized use, access or processing, including:
- Encrypted connections (HTTPS), and encryption of the database and files by our infrastructure provider.
- Access to each record only for the doctor who created it, with controls in the application and in the database.
- An audit log of the actions taken on clinical records.
- Keeping what is deleted and the previous versions of every clinical entry.
- Regular backups.
If a security breach significantly affects your rights, we will tell you without delay what happened and what you can do. If it affects patient data, we will tell the doctor who is its controller.
Pending: confirm encryption at rest and backup frequency with each provider’s plan.
14. Consent
By ticking the acceptance box when creating your account, or by accepting a new version of this notice on the platform, you consent to the processing of your data as described here. We keep the version you accepted and the date.
15. Changes to this notice
We may change this notice because of changes in the law, the service or our practices. The current version will always be on this page, with its version and date. If the change is significant, we will tell you when you sign in and ask you to accept it when the law requires it.
16. Authority
If you believe your right to the protection of your personal data has been violated, you can turn to the authority the LFPDPPP establishes, the Secretaría Anticorrupción y Buen Gobierno.
Pending: confirm the competent authority and the current procedure.
17. Contact
For any question about this notice or your personal data, write to soporte@medos.app.