Legal Document
Privacy Policy
Last updated: July 28, 2026 · Version 2.0
This Policy describes how Coruzen Security collects, uses, stores and protects personal data, in compliance with the LGPD (Brazil's General Data Protection Law, Law 13.709/2018), the GDPR (European Union) and the CCPA (California).
1. Introduction and scope
This Privacy Policy applies to all personal data processed by Coruzen in providing the Coruzen Security platform, including data from registered users, from visitors of the corporate website, and data technically collected while analyzing domains. By using the Service, the data subject acknowledges the practices described here.
2. Data controller
Coruzen is the controller of the personal data processed on security.coruzen.com. For any privacy matter, or to exercise your rights, contact security@coruzen.com.
3. Data we collect
We collect the minimum necessary to operate the Service, depending on the context of use:
- Registration data: name, email and access credentials;
- The URL submitted for analysis and the technical scan results (score, findings, public headers and metadata of the Analyzed Domain);
- A SHA-256 hash of your IP address and User-Agent — we never store the raw IP;
- CPF (PIX payments only): used exclusively to create the charge with our payment provider and never stored on our servers;
- Payment data, processed directly by PCI DSS-certified providers — we never see your card number;
- Technical and browsing data on the corporate website (IP address, device type, browser and pages visited), collected for security and diagnostic purposes.
4. Data technically collected about the analyzed domain
While running an analysis, the Service transiently processes technically public information about the Analyzed Domain (such as HTTP headers, certificates, public files and metadata), exclusively to produce the Report requested by the User.
This information is not used for any purpose other than producing the Report, is not shared with third parties for commercial purposes, and is retained according to the periods described in Clause 8.
5. Legal bases
- Contract performance: running the analysis and delivering the purchased report;
- Legitimate interest: fraud and abuse prevention, platform security and audit logs;
- Consent: optional email communications;
- Legal obligation: retention of tax and transaction records.
6. How we use data
To run scans, deliver reports, provide support, prevent abuse and improve the service. We do not sell or rent your personal data.
7. Sharing (processors)
We share data only with providers essential to operations, each subject to its own privacy policy:
- Payment processing (PCI DSS-certified providers);
- Transactional email delivery;
- Cloud hosting and infrastructure;
- Managed database;
- Rate limiting;
- Error and performance monitoring.
An up-to-date list of processors is available on request at security@coruzen.com.
8. Retention
- Free scan results: 30 days;
- Paid reports: 12 months, or until you request deletion;
- Audit and transaction records: for the period required by law.
9. Security
We use TLS on every connection, hashing of sensitive data, role-based access control, least privilege and continuous monitoring.
No system is absolutely immune to failures or security incidents. While we adopt controls aligned with market best practices, we cannot guarantee absolute security against every form of unauthorized access, cyberattack or third-party technical failure. In the event of a relevant incident involving personal data, we will notify affected data subjects and the relevant authority, within the timeframes and in the manner required by applicable law.
10. Cooperation with authorities and misuse prevention
For fraud prevention, abuse prevention and cooperation with legitimate investigations, we keep an HMAC-SHA256 hash of the IP address and User-Agent associated with each requested analysis — never the raw IP address. This hash cannot be reversed to reveal the original IP.
Upon a court order or a request from a competent authority regarding misuse of the platform against third parties, Coruzen may compute the same hash from a candidate IP address supplied by the authority and check whether it matches an existing record, confirming or ruling out the match without ever storing, reconstructing or disclosing any data subject's raw IP address. Searches and exports performed for this purpose are recorded in an internal audit log, noting who accessed them and when.
11. Your rights
Under the LGPD, GDPR and CCPA you may request:
- Confirmation of processing and access to your data;
- Correction of incomplete or outdated data;
- Deletion, anonymization or portability;
- Withdrawal of consent and information about sharing.
To exercise your rights, write to security@coruzen.com. You may also file a complaint with your local data protection authority.
12. International transfers
Our providers may process data outside Brazil (US/EU). In such cases we adopt appropriate contractual safeguards, as required by applicable law.
13. Cookies
We do not use tracking or advertising cookies. We only use strictly necessary session and security cookies (authentication and language preference).
14. Children
The Service is not directed at minors under 18 and we do not knowingly collect children's data. Should Coruzen become aware that a minor's data was collected without an adequate legal basis, that data will be deleted.
15. Data Protection Officer (DPO)
To exercise your rights as a data subject or to clarify questions about this Policy, contact our Data Protection Officer (DPO) at security@coruzen.com.
16. Changes
Updates to this Policy will be published on this page with a new date and version. Material changes will be communicated by email when applicable.
Exercise your rights
Data Protection Officer — reply within 15 days.