Legally binding version: Portuguese (pt-BR), governed by Brazilian law. This translation is provided for convenience.
Legal
Privacy Policy
Version 4.2 | Published on September 28, 2026, effective October 13, 2026
1. Introduction and scope
CPFHub.io issues this policy to reaffirm its commitment to transparency, security and the protection of personal data. It covers all processing carried out through the identity lookup API and the web platform, in compliance with the Brazilian General Data Protection Law (LGPD, Law 13.709/2018) and other applicable rules.
2. Roles in data processing
Responsibilities are defined under arts. 5, 42 and 43 of the LGPD:
- CPFHub.io as Controller: registration, billing and platform usage data provided directly by Customers. CPFHub.io determines the purposes and means of processing this data.
- CPFHub.io as Processor: personal data of third parties processed through the API on the Customer's instructions. In this role, CPFHub.io acts strictly according to the instructions received. The Customer is the Controller responsible for the lawfulness of each lookup toward data subjects (LGPD, art. 42, §1).
3. Categories of data and legal bases
3.1. Data of customers and platform users
- Data: name, business email, phone number, billing data and IP address.
- Purpose: account management, technical support, billing and transactional communications.
- Legal basis: Performance of a Contract (art. 7, V, LGPD).
3.2. Data processed through the API (third-party lookups)
-
Data: CPF (Brazil's individual taxpayer ID), full name, gender and date of birth. When the Customer contracts the optional registration status lookup at Receita Federal (Brazil's federal tax authority), once that service is available, the following may also be processed:
- registration status of the CPF,
- indication of death, when available at the source,
- control code or proof of the lookup, which only reflects what the official source displayed at that moment,
- date of birth as input data, provided by the Customer when the official source requires it to run the lookup.
The available fields depend on the official source and may change at its discretion (for example, RFB Ordinance No. 667/2026, in force from October 3, 2026, removes the year of death from the official CPF lookup annex and starts requiring the CPF and date of birth for the lookup).
-
Purpose: identity verification, fraud prevention and regulatory compliance in the Customer's systems.
-
Customer's legal basis (controller): it is up to the Customer to identify and declare the applicable legal basis (art. 7, LGPD) before running each lookup, generally legitimate interest in fraud prevention (art. 7, IX) or performance of a contract with the data subject (art. 7, V). When providing the date of birth for the lookup, the Customer declares that it was obtained lawfully.
-
Deceased persons: data of deceased persons is, as a rule, outside the scope of the LGPD, which protects natural persons. Even so, CPFHub.io handles the indication of death with the same care given to other personal data, because it is used precisely to prevent fraud against living people, for example the use of a deceased person's CPF to impersonate someone else, and because a wrong indication can harm a living person.
-
Protection of the data subject: the processing helps prevent third-party data from being used to open fraudulent accounts or for identity theft.
4. Data of children and adolescents
CPFHub.io does not intentionally collect personal data of persons under 18 as direct customers of the platform. For the purposes of art. 14 of the LGPD and Law 15.211/2025 (“Felca Law”/“ECA Digital”, Brazil's digital child protection law), when API lookups involve data of children or adolescents, the Customer, as Controller, is solely responsible for:
- obtaining the specific consent of the legal guardian, when required,
- ensuring that the processing is carried out in the best interests of the minor,
- meeting the age verification obligations set out in the Felca Law.
CPFHub.io may request evidence of compliance from the Customer and, in its absence, preventively suspend access.
5. Retention and disposal policy
We apply the necessity principle under art. 6, III, of the LGPD:
- Request logs: kept for 12 months.
- Purpose of retention: fixing errors, support for failures, security audits and compliance with the Marco Civil da Internet (Law 12.965/2014, Brazil's Internet Civil Framework).
- Disposal: after 12 months, the data is deleted or irreversibly anonymized.
6. Information security
We implement technical and organizational measures to a high standard:
- Encryption: data in transit (TLS 1.3) and at rest (AES-256).
- Access control: multi-factor authentication (MFA) and the principle of least privilege.
- Monitoring: audit logs for all processing operations.
7. Security incidents
In the event of an incident that may affect personal data, CPFHub.io will notify affected Customers and, when required, the Brazilian National Data Protection Authority (ANPD) within a maximum of 72 hours after the incident is confirmed (LGPD, art. 48). The Customer undertakes to notify CPFHub.io within the same period if it identifies an incident in its own systems that involves data obtained through the API.
8. Data subject rights
Under art. 18 of the LGPD, we guarantee data subjects the following rights:
- Confirmation of the existence of processing.
- Access to the data.
- Correction of incomplete or inaccurate data.
- Anonymization, blocking or deletion of unnecessary data.
- Data portability.
- Deletion of data processed with consent.
- Objection to processing based on legitimate interest.
To exercise your rights, contact our Data Protection Officer at dpo@cpfhub.io. We will reply within the legal period of 15 days.
9. Changes
This policy may be updated to reflect technical improvements or regulatory changes. Active Customers will be notified by email at least 15 days in advance of material changes. Continued use of the services after the new version takes effect means full acceptance of the changes.