Interfy
Privacy & Transparency

Privacy Policy

Interfy's Privacy Policy: what data we collect, how we use it, who we share it with, and your rights.

Last updated: September 1, 2026

This Privacy Policy describes how Interfy Corporation collects, uses, shares and protects personal data in connection with the Interfy platform, in compliance with Brazil's General Data Protection Law (LGPD) and, where applicable, the European General Data Protection Regulation (GDPR). This document is a standard draft and should be reviewed by legal counsel before final publication.

Certifications and compliance

See full details
  • ISO/IEC 27001:2022

  • SOC 2 Type II

    In progress
  • LGPD

  • GDPR

  • HIPAA Ready

    BAA available

1. Who we are

Interfy Corporation, headquartered in Orlando, Florida, United States, is the controller of personal data processed through the Interfy platform, except when acting as a processor on behalf of a customer.

2. What data we collect

  • Registration data: name, email, phone, company and job title
  • Platform usage data: access logs, actions taken and configuration preferences
  • Customer Content: documents, processes and other information entered into the platform by the customer
  • Technical data: IP address, device type and browser

3. How we use data

  • Provide and maintain the contracted services
  • Authenticate users and protect accounts from unauthorized access
  • Send operational, support and, with consent, marketing communications
  • Comply with legal and regulatory obligations

4. Data sharing

Personal data may be shared with infrastructure providers (such as AWS cloud services), payment processors and other processors strictly necessary to deliver the service, always under contractual confidentiality and security obligations. We do not sell personal data to third parties.

5. Cookies and similar technologies

We use essential cookies for the site to function and, with consent, analytics cookies to understand platform usage and improve the user experience.

6. Data retention

Personal data is kept for as long as necessary to fulfill the purposes described in this Policy, or as required by law, and is later deleted or anonymized.

7. Information security

We apply security in multiple layers, from the architecture to day-to-day operations:

  • Workspace isolation and a dedicated database per customer, with no sharing
  • Advanced encryption: data in transit (TLS 1.2+) and at rest (AES-256)
  • Granular access control (RBAC) by role, group and sensitivity level
  • Enterprise authentication: SSO, SAML 2.0, OAuth 2.0, AD/LDAP and MFA
  • IP-based access restriction (IP blocking)
  • Immutable, searchable audit logs and trails
  • 24/7 security monitoring, automated encrypted backups and disaster recovery with geographic replication
  • Multi-AZ infrastructure on AWS, certified ISO/IEC 27001:2022, with SOC 2 Type II in progress
See our full security architecture

8. Your rights (LGPD/GDPR)

  • Confirmation that processing exists and access to your data
  • Correction of incomplete, inaccurate or outdated data
  • Anonymization, blocking or deletion of unnecessary data
  • Portability of your data to another service provider
  • Withdrawal of consent, where applicable

9. International data transfer

Because we operate on a global infrastructure, personal data may be transferred between countries, always with contractual and technical safeguards compatible with LGPD and GDPR.

10. Changes to this policy

This Policy may be updated periodically. Material changes will be communicated by email or notice on the platform.

11. Contact our Data Protection Officer (DPO)

To exercise your rights or ask questions about this Policy, contact our Data Protection Officer at privacy@interfy.ai.