Start building a more resolutive network
Book a demo and we'll show you the impact with your network's own numbers.
Version 2.7 · In force since October 7, 2026
TERAL website, platforms, applications and integrations
| Item | Information |
|---|---|
| Controller | TERAL S.A.S., Tax ID (NIT) 901.616.741-2 |
| Address | Cra 43F #10-38, Manila, El Poblado, Medellín, Antioquia, Colombia. |
| Privacy channel | Primary: alan@teral.ai. Alternate: teralai@teralmed.co. Contact phone: +57 300 467 8602. |
| Surfaces | teral.ai/es, web platform, mobile applications, administration, support and institutional integrations |
| Version | v2.7, October 1, 2026 |
TERAL S.A.S., Tax ID (NIT) 901.616.741-2, with its principal domicile in Medellín, Antioquia, Colombia, acts as controller when it determines the purposes and essential means of processing. Address for notices: Cra 43F #10-38, Manila, El Poblado, Medellín, Antioquia, Colombia. For inquiries, complaints and the exercise of rights: Primary: alan@teral.ai. Alternate: teralai@teralmed.co. Contact phone: +57 300 467 8602. The officer responsible for handling data protection requests is David Alberto Calderón Duarte, with intake and coordination through the channels indicated.
Where TERAL processes information on behalf of a healthcare provider, insurer, clinic, hospital, health professional or other client that determines the clinical or institutional purpose, TERAL will act as processor under the terms of the applicable agreement, data transmission agreement or DPA. This classification depends on the actual flow and not on the name the parties give the document.
This Policy applies to the teral.ai/es website, forms, commercial and support channels, user accounts, web and mobile applications, administrative modules, demonstrations, pilots, integrations with information systems, artificial intelligence services, APIs and any other TERAL operation involving personal data.
For processing carried out on behalf of an institutional client, the controller's lawful and documented instructions, the DPA, the security annex and the corresponding agreement will prevail for that flow. This Policy does not replace the data subject's authorization, clinical informed consent, the client's privacy notice or the obligations of the custodian of the medical record.
TERAL will apply the principles of lawfulness, purpose, freedom, truthfulness or quality, transparency, restricted access and circulation, security and confidentiality. It will also apply criteria of minimization, necessity, proportionality, privacy by design and demonstrated accountability according to the sensitivity and risk of each flow.
Data subjects may be health professionals, institutional administrators, patients, client representatives, website visitors, commercial contacts, employees, candidates, contractors, suppliers and other persons connected with TERAL's operation.
TERAL may receive data directly from the data subject; from an authorized client or user; from permitted public sources; or through integrations activated and documented for a project. The identified methods are set out below; their inclusion does not mean that all of them are deployed for every client:
The existence of redaction, pseudonymization or visual masking does not mean that all data are anonymous. Images, documents and screenshots may contain visible or embedded identifiers, metadata or text. The client and TERAL must validate the actual flow, the fields processed, the permissions, the logs and the exact point at which each control operates.
Clinical integrations are activated per project, subject to validation of their fields, permissions, authentication, logs, retention, incidents and testing. For the text flow described, AWS Comprehend and internal rules operate before inference in Bedrock/Claude or Vertex/Gemini. This sequence does not automatically cover images: images may reach Gemini with identifiable text as long as no effective prior control exists. No anonymization or prior control of that flow is presumed.
The data subject is not required to authorize the processing of sensitive data and will be informed that doing so is optional, except where a legal exception applies. Where TERAL acts as controller and the processing requires authorization, it will obtain prior, express, informed and verifiable authorization, specific to the corresponding purposes and sensitive categories.
Where it must obtain authorization, TERAL will use physical or electronic forms or other verifiable means that evidence the data subject's will; silence does not constitute authorization. It will retain evidence of the text accepted, the identity and the date of acceptance, with restricted access, for as long as the authorized processing and the applicable legal or defense obligations subsist. The data subject may request a copy through the channels in section 1.
Where a client or professional uploads clinical information and TERAL acts as processor, the controller must evidence the authorization or the applicable legal exception, inform the data subject and document its instructions. Acceptance of this Policy or of the Terms of Service does not by itself replace express authorization to process health data or clinical informed consent.
TERAL has no proprietary models and conducts internal comparative AI testing solely with synthetic or effectively anonymous data. Neither this Policy nor the processing mandate authorizes reusing clinical personal data for TERAL's own purposes. Any change will require prior legal review, information and applicable legal basis, as well as documented controls.
| Flow | Controller and source of authorization | TERAL's role and evidence |
|---|---|---|
| Website, contact, account, credentials, billing, support and TERAL's own security | TERAL is Controller because it defines these administrative and operational purposes. | It must inform, obtain the applicable acceptance, handle rights requests and document processor providers. |
| Individual sign-up and clinical data uploaded by a professional | The professional is Controller and custodian vis-à-vis the patient; obtains and retains authorization or evidences the applicable exception. | TERAL is Processor in providing the platform. Terms, adherence or DPA and logs document the instructions. |
| Institutional sign-up and administration of the client's users | The institution is Controller for patients, professionals and users brought in through its relationship; TERAL is Controller only of its own commercial data. | TERAL is Processor for the contracted operation. An agreement, DPA, profiles and a record of additions and removals are required. |
| Manual upload of cases, documents and images | The institution or professional that defines the purpose and uploads the case is Controller. | TERAL is Processor. The Controller guarantees the legal basis or authorization; TERAL maintains traceability, minimizes and applies controls. |
| Integration with an electronic health record | The institution that owns the source system and the care relationship is Controller and custodian. | TERAL is Processor. Each activation requires a DPA, technical annex, minimum fields, security, logs, testing and production acceptance. |
| Teral AI to perform the contracted service | The institution or professional determines the clinical or care purpose and acts as Controller. | TERAL is Processor; AWS and Google may act as sub-processors. The text processed by Comprehend must be kept separate from the images sent to Gemini; a de-identification guarantee for one flow must not be extended to the other. |
| RAG and retrieval of documents or historical cases | The institution or professional selects sources and purpose and acts as Controller. | TERAL is Processor; permissions, isolation, retention and deletion follow the life cycle of the source. |
| Evaluation, research, training or improvement for a purpose of TERAL's own | TERAL becomes Controller of that own purpose. | Internal comparative testing is limited to synthetic or effectively anonymous data. Reuse of personal data is not authorized; a change of purpose requires separate review. |
Allocation is made by purpose and actual flow. TERAL may be Controller of its administrative operations and, at the same time, Processor of clinical information handled on behalf of a client or professional. Where Teral Incorporated engages technology providers, this must be documented in the contractual chain, but that function does not automatically make it Controller of the clinical purpose.
TERAL will not sell personal data and will not use clinical information for behavioral advertising. Nor does it authorize its providers to train or fine-tune models with service data. Inference to provide the service and internal testing are distinct purposes; the latter are subject to the rule in section 7.
The Platform may offer classification, search, summarization, draft generation, consistency auditing, conversational assistance or information retrieval through artificial intelligence models. These functions support the operation and do not replace clinical judgment, human review or the responsibility of the professional or care entity.
TERAL may classify, organize and cross-check information using rules and criteria defined for each service, and generate observations, alerts or recommendations for human review. These functions may support the review of documentation, billing, procedures or medical prescriptions. Their outputs do not by themselves constitute a finding of fraud or a final decision on care, dispensing, coverage or payment. Recommendations are not binding. The final decision rests with the competent person, who must review the output and may accept or disregard it according to their professional judgment and the applicable rules. The scope, the authorized data, the rules and the responsibilities will be established for each project.
TERAL does not direct its services to minors. If an authorized care flow includes a minor's data, the controller must verify the legal basis, the corresponding representation and respect for the minor's best interests and prevailing rights. TERAL will apply restricted access and enhanced security measures.
TERAL may grant access to authorized personnel, clients, professionals, technology providers, advisors and authorities, solely according to purpose, role and need. Where a provider processes data on behalf of TERAL or of a client, it must be bound by obligations of confidentiality, security, instructions, deletion, audit and incidents.
As of this version, the services reported as active in production are Amazon Web Services —including Comprehend and Bedrock with Claude Haiku/Sonnet models— in United States regions; Google Cloud Vertex AI/Gemini, mainly in us-central1 or global scope; and MongoDB Atlas hosted in the United States. Direct connections with Anthropic and OpenAI are configured but not active in production. The TERAL entity that procures certain services is Teral Incorporated; this does not replace the contractual identification of the provider nor does it by itself define each participant's role.
TERAL may carry out international transmissions to infrastructure, database and artificial intelligence providers located in the United States. For each flow, the controller, TERAL S.A.S., Teral Incorporated and each provider or sub-processor must be documented, together with the instructions, DPA, region and applicable measures. If a third party determines its own purposes and receives data as a controller, the flow will be treated as a transfer and the applicable legal mechanism will be verified before sending. Agreements or model clauses do not replace the legal requirements of a transfer.
TERAL will adopt technical, human, administrative and contractual measures that are reasonable and proportionate to the risk, including identity and access management, encryption where applicable, segmentation, logging, monitoring, backup, testing and vulnerability management. No measure completely eliminates risk, and this Policy does not constitute an unconditional guarantee of security, availability or absence of incidents.
In the event of an actual or suspected incident, TERAL will activate its procedure for analysis, containment, preservation of evidence, remediation and notification. Where it acts as processor, it will inform the controller without undue delay in accordance with the agreement. Notifications to data subjects or authorities will be made by the party under the obligation, within the applicable deadlines and conditions.
TERAL will retain data for as long as necessary for the purposes reported, the controller's lawful instructions and the applicable legal or defense obligations. The term of the agreement does not justify retaining unnecessary data nor does it prevent processing a well-founded deletion request.
Requests may be submitted through the email addresses or the address for notices in section 1. They must identify the data subject or their representative, describe the request and the relevant facts, indicate a channel for a response and attach the documents the requester wishes to rely on. Inquiries will be addressed within a maximum of ten (10) business days from receipt; if this is not possible, the reason and the new date will be communicated, which will not exceed five (5) business days after expiry of the initial term.
Complaints will be addressed within a maximum of fifteen (15) business days from the day following receipt. If the complaint is incomplete, a request to cure will be issued within five (5) days of receipt; if two (2) months elapse from the date of that request without the information being provided, the complaint will be deemed withdrawn. Where it is not possible to resolve within the initial term, the reason and the new date will be communicated, which will not exceed eight (8) business days after expiry of that term.
TERAL will verify the identity and, where applicable, the representation of the requester, requiring only the information necessary to process the request. It will record the request, forward it to the competent area and respond through the channel indicated. Upon receipt of a complete complaint, it will add to the database the annotation «complaint in process» and its reason within the following two (2) business days, maintaining it until resolution. Extensions will be communicated before expiry of the initial term.
If the request concerns data processed exclusively as processor, TERAL will forward it to the competent controller and will cooperate in accordance with the DPA. Where it is not competent to resolve a complaint, it will refer it to the appropriate party within a maximum of two (2) business days and will inform the requester.
The website and the applications use or may enable functional, preference, analytics and marketing technologies. Google Analytics has been identified on public pages, and Meta Pixel and Microsoft Clarity on the application sign-in page. Non-necessary technologies require a valid choice by the user before being activated, together with mechanisms to reject or withdraw that choice. Where those controls are not in place, such technologies must remain disabled. Publication of this Policy does not by itself constitute consent to those technologies. The inventory and applicable options will be detailed in the Cookie Policy and in the website's configuration mechanisms; they may also be consulted through the channels in section 1.
TERAL will publish the version and effective date of this Policy and will retain evidence of previous versions. It will inform data subjects of substantial changes in a timely manner before applying them and will obtain a new authorization where applicable. This includes material changes in purposes, sensitive categories, providers, regions, roles or AI uses.
Evidence of acceptance or acknowledgment may include the version or hash of the text, the identity or account, the date, time and time zone, the IP address or session, the channel and the acceptance event. That evidence does not turn a general acceptance into a valid authorization for sensitive purposes that were not disclosed.
This version 2.7, dated October 1, 2026, takes effect upon its publication on TERAL's website and supersedes the previous policy, without retroactive effect. The effective date of publication will be indicated alongside the text on the website. The validity of the databases and the retention of each category are governed by the criteria in section 14 and the applicable obligations. TERAL will retain evidence of the published version.
Book a demo and we'll show you the impact with your network's own numbers.