Information security as an architectural requirement
The protection of the data entrusted to DPO Privacy is treated as an architectural requirement, not as an additional feature. This page describes the technical and organizational controls adopted on the platform.
This is a courtesy translation. In case of any discrepancy, the Portuguese version prevails.
Encryption
Access to the platform only through an encrypted connection (HTTPS).
Data on data subjects, requests, suppliers and contacts receives an additional layer of application-level encryption, using AES-256-GCM.
Passwords are never stored in readable text: they use a hashing algorithm designed for credentials (bcrypt).
Infrastructure
Operation on a managed cloud, with a managed PostgreSQL database.
Data location, backup retention and the list of sub-processors are provided upon contracting and updated whenever there is a change.
Access control
Role-based profiles, in line with the principle of least privilege.
Segregation of duties between those who record, review and approve information.
Multi-factor authentication.
Sessions with automatic expiration and review of the access granted.
Audit trail
Relevant changes are recorded in a trail protected against editing and deletion in the database itself.
The history of the personal data inventory is hash-chained, which makes it possible to demonstrate that the records have not been altered.
Isolation between organizations
Multi-tenant architecture with logical isolation.
Each operation is bound to the organization of the authenticated user, and any route that does not declare this binding is rejected.
Monitoring
Continuous monitoring of application availability, performance and errors.
In the event of a security incident posing a relevant risk to data subjects, notification to the ANPD (Brazilian Data Protection Authority) and to those affected follows Article 48 of the LGPD (Brazilian General Data Protection Law, Law No. 13,709/2018).
Privacy by design
What we ask of our customers, we apply here
Minimization
Collection limited to what is necessary to provide the service.
Customer control
The data entered into the platform belongs to the customer organization and is processed according to its instructions.
Artificial intelligence under control
AI features remain disabled until an express decision by the organization, and suggestions undergo human validation.
Portability
Information can be exported at any time during the term of the contract.
Responsible disclosure
Vulnerability reporting
DPO Privacy receives and handles reports of potential vulnerabilities as a priority. Send your report to seguranca@dpoprivacy.com.br.
What to include in the report
Description of the vulnerability and its potential impact
Steps to reproduce
Date of identification and the researcher's contact details
We acknowledge receipt, keep the researcher informed about the analysis and the fix, and take no action against anyone who acts in good faith and observes these guidelines.
Prohibited conduct during research
Accessing, altering or deleting third-party data
Degrading the availability of the service
Using social engineering
Publicly disclosing the vulnerability before it is fixed
For information on the platform's artificial intelligence, see DPOia Transparency. For information on the processing of personal data by DPO Privacy, see the Privacy Policy.