Privacy Policy
This site collects nothing beyond what is needed to serve the pages. The product processes data on behalf of the client, with consent per step, hashes instead of data and erasure by key destruction. Courtesy translation. The Portuguese version at hummand.com.br is the binding one.
1. Who we are and what this policy covers
Hummand Consultoria LTDA, CNPJ 56.919.986/0001-52, headquartered in João Pessoa, Paraíba, Brazil, is responsible for the processing described in this policy, under the Brazilian General Data Protection Law (Law 13,709/2018, LGPD). The policy covers this site (hummand.com.br and labs.hummand.com.br) and the contact channels. In the products, Hummand is the processor: it processes data on behalf of the client, which is the controller, under contract; what the product processes and for how long is described at hummand.com.br/en/lgpd and in the effective policy the client dashboard reads directly from the service.
2. What this site collects
Nothing beyond what is needed to serve the pages:
- There is no form, sign-up, cookies, pixels or third-party fonts. This site stores nothing in your browser.
- Aggregate audience measurement with Cloudflare Web Analytics: no cookies, no fingerprinting and no individual identification. The browser sends Cloudflare the page visited, the referring page and technical data about the device (browser, system, screen size), and only the aggregate is visible to Hummand. Policy: cloudflare.com/privacypolicy.
- Hosting (Cloudflare Pages) logs accesses (IP address, page, date and time, browser) for security and operations, under Cloudflare's privacy policy.
- The receipt verifier at labs.hummand.com.br/verificar runs entirely in your browser and sends the receipt nowhere. If you ask it to fetch the public key, the browser queries Hummand's gateway; nothing else leaves.
3. Contact channels
When you write to [email protected] or [email protected], we process what you send in order to reply. Legal basis: consent (art. 7, I) or pre-contractual steps and contract performance (art. 7, V). We keep the conversation for the duration of the request and, at most, five years, for records and defence in proceedings.
4. What the product processes, on behalf of the client
When a person performs an act through Hummand at the request of a client:
- They consent per step, with versioned text: the general one before anything and the biometric one before any capture. Biometric data is sensitive; the legal basis is specific, highlighted consent (art. 11, I), collected in the journey itself.
- Live presence and match run in a certified third-party component and return a result; the image and the template are discarded at the end of the step. No image and no template persist at any moment.
- The reference the client gives the person, the reference image when there is one, the act context and the text of each consent enter the record and the receipt as hashes. The context stays encrypted; only the hash leaves.
- Encrypted verdict and CPF are retained for 90 days; consent evidence and event trail, for five years; then they are destroyed by key, automatically.
- Erasure on request is performed by the client, by act or by the opaque reference, through key destruction, with a record of who erased and when. Portability and erasure by CPF do not exist, and the reason is at hummand.com.br/en/lgpd.
5. Sharing
We do not sell, rent or transfer personal data. We share only with:
- The processors the service needs: the cloud that hosts the product and provides the certified live-presence component (AWS, with the use of data to train AI turned off), the site's hosting and aggregate audience measurement (Cloudflare) and, when the client contracts it, the civil identity source (Serpro), from which only the verdict persists.
- Public authorities, when required by law, court order or regulatory proceeding.
6. International transfers
The cloud that hosts the product and the live-presence component may process data outside Brazil. Those transfers rely on art. 33 of the LGPD, through contractual data-protection clauses and the recognized adequacy of the destination country.
7. Your rights
As a data subject, you may request at any time, at [email protected]:
- Confirmation that processing exists and access to the data (art. 18, I and II);
- Correction of incomplete, inaccurate or outdated data (art. 18, III);
- Anonymization, blocking or deletion of unnecessary, excessive or unlawfully processed data (art. 18, IV);
- Deletion of data processed on the basis of consent (art. 18, VI) and withdrawal of consent (art. 18, IX);
- Information about whom we share with (art. 18, VII) and about the possibility of not consenting (art. 18, VIII);
- Review of decisions made solely by automated means (art. 20). Hummand makes no decision about the person: it records what happened; the decision is the client's.
- In the product, the request arrives through the client, which is the controller; Hummand performs the erasure by act or by reference. We reply within fifteen days.
8. Security
Data key per record, wrapped in a managed key module; per-client isolation in the database; decryption trail with a hash chain; erasure by key destruction; TLS in transport. The limits that still exist are written at hummand.com.br/en/seguranca. In case of an incident with relevant risk, we notify the authority (ANPD) and the data subjects, under art. 48.
9. Data protection officer
Hummand's data protection officer is Vinícius Lisboa, available for the exercise of rights, complaints and enquiries at [email protected].
10. Updates
This policy changes when the site or the product changes; the date at the top is that of the version in force. Material changes are communicated to clients thirty days in advance. The version in force is always at hummand.com.br/privacidade.
Verify a receipt
Paste the JSON and the public key. No account, nothing sent: it runs in your browser.
Open the verifier