Schedule demo

Privacy Policy

Last updated April 14, 2026

LEGITIMUZ TECNOLOGIA LTDA. — CNPJ 52.178.446/0001-04

1. Controller Identification

This Privacy Policy (“Policy”) is the responsibility of LEGITIMUZ TECNOLOGIA LTDA. (“LEGITIMUZ”), registered with the CNPJ under number 52.178.446/0001-04, headquartered at Rua Florida, 1595, suite 21, Cidade Monções, São Paulo SP.

LEGITIMUZ offers identity verification, document validation, age verification, and anti-fraud solutions through its products LegitFace, LegitID, LegitDoc, LegitCheck and ECA Digital, intended for companies (“Clients”) that need to validate the identity or age of their users (“Data Subjects”).

Data Protection Officer (DPO): Thomas Hannickel, [email protected]

2. Our Products

LegitFace — LegitID

Biometric facial recognition solution with liveness detection. It captures a selfie or video of the holder, compares the image with the photo on the identity document (face match), and verifies the user's actual presence to prevent fraud through spoofing, deepfakes, and presentation attacks.

Data processed: Facial photograph, liveness video, facial biometric template.

LegitDoc

Solution for capturing and automatically extracting data from identity documents (OCR). Processes images of documents such as ID cards, driver's licenses, passports, and other official documents, extracting textual data and security elements for validation.

Data processed: image of the documetage, dont, name, CPF, RG, date of birth, parencument number, issue date, and expiration date.

LegitCheck

Intelligent document validation solution. Performs cross-checking of data extracted from documents with public and private databases, confirming the authenticity, consistency, and reliability of the information. Includes CPF verification with the Federal Revenue Service, consultations with restricted lists, PEP and sanctions.

Data processed: CPF, name, date of birth, results of searches in public and private databases, risk indicators.

ECA Digital (Age Verification)

Age verification solution designed to comply with Law No. 15.211/2025 (ECA Digital). It combines identity document capture (LegitDoc) and facial recognition with proof of life (LegitFace) to confirm whether the user is 18 years of age or older, without exposing unnecessary data to the platform client.

The result of the verification is a binary signal (over or under 18 years of age), with no transmission of raw data to the client except when expressly contracted and justified by legal obligation.

The processing is strictly instrumental: the data collected for age verification is not used for advertising, profiling, content personalization, or sharing with third parties for purposes other than verification, in accordance with Article 14-A of the ECA, as amended by Law No. 15.211/2025.

Data processed: image of the identity document, facial photograph, liveness video, date of birth extracted from the document.

After measurement, only the result (confirmed age range) is retained; the raw data is deleted immediately, unless specifically required by law.

Legal basis: art. 7º, II (legal obligation) and art. 11, II, “a” of the LGPD, based on Law nº 15.211/2025 and art. 14-A of the ECA.

3. LEGITIMUZ's Role in Data Processing

LEGITIMUZ may act in different roles in the processing of personal data, according to the specific purpose of each operation, pursuant to art. 5, VI and VII, of Law No. 13.709/2018 (LGPD).

As an operator

In the execution of identity verification, document verification, and age verification services at the Client's instruction, LEGITIMUZ acts as a data operator.

The Client is the controller, as it determines the purpose and necessity of the verification. The applicable legal basis is defined by the Client in its relationship with the Data Controller.

As an independent controller

For certain specific purposes, we act as the controller of personal data, making autonomous decisions about its processing. This occurs:

  • Fraud prevention in the identity verification ecosystem, including maintaining anti-fraud indicators that protect all platform users, based on article 11, II, "g", of the LGPD, observing the principles of necessity, proportionality, and minimization.
  • Compliance with legal and regulatory obligations, including AML and Counter-Terrorism Financing (AML/CFT), communications to COAF, and obligations arising from Law No. 14,790/2023 and Ordinance SPA/MF No. 722/2024.
  • Improvement and development of verification, liveness, and anti-fraud models, with the application of minimization techniques and, when possible, anonymization.
  • Reuse of documents, images, biometric data, metadata, and verification results already submitted in previous interactions, including in new authentication attempts, revalidation, fraud prevention, auditing, incident investigation, model updates, and ecosystem protection, provided that such reuse is necessary, proportionate, and compatible with the context of the relationship, respecting applicable retention periods and relevant legal and regulatory requirements.
  • Provision of the technical mechanism for age verification at the instruction of the platform Client, subject to the obligations of Law No. 15.211/2025. In this case, we act as a data operator, with the Client being the controller responsible for compliance with the law. When LEGITIMUZ contracts directly with the data subject for age verification purposes, without client intermediation, it acts as an independent controller, based on Article 7, II, of the LGPD and Article 11, II, "a", when biometric data processing is involved. In both cases, the processing is strictly instrumental: the data collected for age verification are not used for secondary purposes, including advertising, profiling, content personalization, or sharing with third parties for purposes unrelated to verification, in accordance with Article 14-A of Law No. 8.069/1990, as amended by Law No. 15.211/2025.

4. Personal Data Collected by Product

LEGITIMUZ collects the minimum amount of personal data necessary to perform each service. The table below details the data processed by product, purpose, and applicable legal basis.

ProductData CollectedPurposeLegal Basis (LGPD)
LegitFace — LegitIDFacial photography, liveness video, biometric templateBiometric identity verification and liveness detectionArt. 11, II, “a” and “g” (legal obligation and fraud prevention)
LegitFace — LegitIDBiometric template (derived)Fraud prevention in the ecosystem (controller)Art. 11, II, “g” (fraud prevention)
LegitDocImage of the document, name, CPF, RG, date of birth, parentage.Document data capture and extraction (OCR)Art. 7, V (contract execution) and art. 7, II (legal obligation)
LegitCheckCPF, name, date of birth, search resultsDocument validation and consultation of restrictive databasesArt. 7, II (legal obligation) and art. 7, IX (legitimate interest)
ECA DigitalDocument image, facial photograph, liveness video, date of birth. Result retained: age range (18+/under). Raw data deleted after verification.Age verification (ECA Digital)Art. 7, II (legal obligation) and, when biometric data is present, art. 11, II, “a” (LGPD)
AllAnonymized or minimized dataImprovement of statistical models and analysesArt. 7, IX (legitimate interest) with LIA

Biometric data

The facial photograph and liveness video processed by LegitFace constitute biometric data, classified as sensitive personal data under Article 5, II, of the LGPD. The processing of this data complies with the provisions of Article 11, II, of the LGPD.

Age verification (ECA Digital)

When the verification is specifically intended to ascertain the user's age for compliance with Law No. 15.211/2025, the data collected for this purpose will not be used for advertising, profiling, content personalization, or sharing with third parties for purposes unrelated to the verification, in accordance with Article 14-A of the ECA, as amended by Law No. 15.211/2025. LEGITIMUZ applies the principle of minimization: after the verification is completed, it retains only the result (confirmation of age range: under or over 18 years), eliminating the raw data used in the process, except when retention is required by a specific legal obligation and for the period strictly necessary to fulfill that obligation.

5. Data Sharing

The sharing of personal data occurs strictly to the extent necessary, observing the following circumstances:

  • Partners and suppliers: to enable the provision of services, including data hosting, cloud infrastructure, and electronic communications.
  • LEGITIMUZ customers: The verification result (approved/rejected) is shared with the Client who requested the service. Raw biometric data is not shared with the Client, except when expressly stipulated in the contract.
  • Financial institutions and partners: for risk analysis, regulatory compliance, or fraud prevention.
  • Authorities and legal bodies: for compliance with legal obligations, court orders or requests from competent authorities, including ANPD, COAF and SPA/MF.

Whenever possible, the data shared is anonymized or limited to the bare minimum.

6. Data Security

LEGITIMUZ adopts technical, administrative, and organizational security measures, including:

  • Access control with authentication and credential management.
  • Recording and monitoring access logs.
  • Regular backups and business continuity plan.
  • Data encryption in transit (TLS) and at rest (AES-256).
  • Access is restricted to authorized personnel, under a duty of absolute confidentiality.
  • ISO 27001 Certification, which certifies the compliance of the information security management system.
  • Security incident management program with notification to the ANPD within 72 hours, when applicable, in accordance with Resolution CD/ANPD No. 15/2024.

7. International Data Transfer

Personal data may be transferred to servers located abroad or to LEGITIMUZ's international clients. These transfers are carried out in accordance with Article 33 of the LGPD, through the adoption of at least one of the following safeguards:

  • Transfer to countries or international organizations that provide an adequate level of protection, as assessed by the ANPD.
  • Standard contractual clauses approved by the ANPD.
  • Transfer required for the execution of the contract or for compliance with a legal obligation.

8. Rights of the Data Subject

In accordance with articles 17 to 22 of the LGPD, the Data Subject may exercise the following rights:

  • Confirmation and access: to confirm if treatment is available and obtain a copy of the data.
  • Rectification: to correct incorrect or outdated data.
  • Explanation: to obtain information about the purpose, form, and duration of treatment, as well as about sharing.
  • Cancellation: to request the deletion, anonymization, or blocking of data, subject to the circumstances under which data is legitimately retained.
  • Opposition: to contest a particular treatment or revoke consent, when applicable.
  • Portability: to request the transfer of data to another controller, in accordance with ANPD regulations.
  • Review of automated decisions: LEGITIMUZ uses automated means in the processing of identity verification, liveness and fraud detection (LegitFace, LegitID, LegitDoc, LegitCheck). The final decision to accept or reject the verification result rests with the Client. The Data Subject may request information about the criteria used in the automated processing.

📧 To exercise any right: [email protected]. Response time: 15 (fifteen) days, pursuant to article 19 of the LGPD.

9. Storage Period

Personal data is kept for the time necessary for the purposes described in this Policy. Retention periods vary according to the data category and purpose:

  • Verification data as instructed by the customer: maintained in accordance with the instructions and contractual timeframe defined by the controlling Client.
  • Biometric data (LegitFace, LegitID): are deleted after the verification process is complete, except when retention is necessary to comply with a legal obligation or to prevent fraud, in which case they are kept for the maximum period or until the applicable legal obligation is fulfilled.
  • Age verification data (ECA Digital): processed based on the principles of minimization and specific purpose. After the verification is complete, LEGITIMUZ retains only the verification result (confirmation of age range: under or over 18 years), immediately deleting the raw data used in the process, including images, documents, and temporary biometric data. The retention of raw data only occurs when there is a specific legal obligation requiring it and for the period strictly necessary to fulfill that obligation, and its use for any secondary purpose is prohibited.
  • Data for compliance with AML/CFT (Anti-Money Laundering/Combating the Financing of Terrorism): maintained for the periods required by applicable legislation, which may extend for up to 10 (ten) years after the termination of the relationship.
  • Documentary data (Legit Doce Legit Check): maintained for the contractual term or for the period necessary to fulfill legal obligations, whichever is longer.

10. Changes to this Policy

LEGITIMUZ may modify this Policy whenever there are changes in data processing or applicable legislation. The date of the last update will always be indicated at the beginning of the document. We recommend periodic review.

11. Contact

Data Protection Officer (DPO):
Thomas Hannickel
📧 [email protected]