Interfy
Data Protection

LGPD / GDPR

How Interfy handles personal data in compliance with LGPD and GDPR, and how to exercise your data subject rights.

Last updated: September 1, 2026

Interfy treats personal data protection as a core part of its architecture, addressing both Brazil's General Data Protection Law (Law No. 13,709/2018) and the European General Data Protection Regulation (GDPR). This document is a standard draft and should be reviewed by legal counsel before final publication.

Certifications and compliance

See full details
  • ISO/IEC 27001:2022

  • SOC 2 Type II

    In progress
  • LGPD

  • GDPR

  • HIPAA Ready

    BAA available

1. Our commitment

We adopt privacy by design across every product on the platform, with technical and organizational controls that support ongoing compliance with LGPD and GDPR.

2. Roles: controller and processor

For registration and platform usage data, Interfy acts as the controller. For Customer Content stored on the platform, Interfy acts as a processor, handling data strictly according to the instructions of the controlling customer.

3. Legal bases for processing

  • Contract performance, to deliver the contracted services
  • Compliance with a legal or regulatory obligation
  • Legitimate interest, for platform security and improvement
  • Consent, for marketing communications and non-essential cookies

4. Data subject rights

Data subjects may request access, correction, anonymization, deletion, portability, or information about the sharing of their personal data, under LGPD and, where applicable, GDPR.

5. How to exercise your rights

Requests can be sent to privacy@interfy.ai. We will respond within the applicable legal timeframes and may request additional information to confirm the requester's identity.

6. Technical and organizational security measures

  • Workspace isolation and a dedicated database per customer
  • AES-256 encryption at rest and TLS 1.2+ in transit
  • Role-based access control (RBAC) and multi-factor authentication (MFA)
  • Enterprise authentication via SSO, SAML 2.0, OAuth 2.0 and AD/LDAP
  • IP-based access restriction (IP blocking)
  • Immutable, searchable audit logs and trails
  • 24/7 security monitoring with automated incident response
  • Automated encrypted backups and disaster recovery with geographic replication
  • Multi-AZ infrastructure on AWS, with a 99.99% availability SLA
See our full security architecture

7. International data transfer

When personal data is transferred between countries, Interfy adopts contractual clauses and technical safeguards compatible with LGPD and GDPR requirements for international transfers.

8. Data Protection Officer (DPO)

Our Data Protection Officer can be reached at privacy@interfy.ai for matters related to personal data processing.

9. Updates

This document may be updated to reflect legislative, regulatory or platform changes. The last updated date is always shown at the top of the page.