Legally binding version: Portuguese (pt-BR), governed by Brazilian law. This translation is provided for convenience.
Legal
Compliance and Data Governance
Version 4.0 | Last updated: May 16, 2026
Data philosophy
At CPFHub.io, information security and privacy are treated as interdependent. The platform was built on the concept of Privacy by Design, ensuring that every technical decision respects the integrity of personal data from the start. We do not sell contact lists and we do not operate as a data broker.
Legal structure of processing
CPFHub.io acts in two distinct roles under the LGPD (Brazil's data protection law), arts. 5, 42 and 43:
CPFHub.io as Controller
For the registration, billing and platform usage data provided directly by Customers, CPFHub.io is the Controller and determines the purposes and means of processing.
CPFHub.io as Processor
For third-party personal data processed through the API, CPFHub.io acts as Processor, strictly on the Customer's instructions. In this context, the Customer is the Controller and bears primary responsibility for the lawfulness of each lookup toward data subjects (LGPD, art. 42, §1).
Legal bases applicable to API lookups
The legal basis for each lookup is determined by the Customer according to its purpose. The most common bases are:
- Legitimate Interest (art. 7, IX): fraud prevention and transaction security, when the interests of the controller or of the data subject themselves outweigh the risks to the data subject.
- Fraud prevention and security (art. 11, II, “g”): authorizes the processing of data without consent when indispensable to guarantee the security of the data subject in identification processes.
- Performance of a contract (art. 7, V): when identity verification is a necessary step in formalizing a contractual relationship with the data subject.
Necessity and minimization principle (art. 6, III)
The API returns only the biographical data strictly necessary to confirm identity, avoiding unnecessary exposure of information.
Compliance with the Felca Law (Law 15.211/2025)
Law 15.211/2025 (“ECA Digital”, Brazil's digital child protection law) establishes age verification obligations for digital platforms that offer content or services unsuitable for minors. When Customers use the CPFHub.io API to meet these obligations, the Customer remains responsible for compliance with the law and must:
- implement the control mechanisms required by the ANPD (Brazil's National Data Protection Authority),
- obtain the consent of the legal guardian when necessary (LGPD, art. 14),
- document the measures adopted for accountability purposes (accountability).
CPFHub.io provides the verification infrastructure. The decision to grant or block access to the end user rests exclusively with the Customer.
Retention and transparency
Technical logs are retained for 12 months for incident traceability, error correction and compliance audits, in line with arts. 7, V and IX of the LGPD and the Marco Civil da Internet (Law 12.965/2014, Brazil's Internet Civil Framework). After this period, the data is deleted or irreversibly anonymized.
Security measures
- Infrastructure 100% hosted in Brazil.
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Multi-factor authentication (MFA) and the principle of least privilege.
- Technical log databases isolated from production databases.
- Periodic access and compliance reviews.
DPO communication channel
Under art. 41 of the LGPD, CPFHub.io maintains a direct channel for privacy and data protection matters. The Data Protection Officer (DPO) can be contacted by email at dpo@cpfhub.io. We will reply within the legal period of 15 days.