Lumiardi Emblem
LUMIARDI
Privacy & Data Protection (LGPD)

Privacy Policy and LGPD

Version: August 24, 2026Brazilian General Data Protection Law (Law No. 13,709/2018)CD/ANPD Resolution No. 15/2024
Identification of the Personal Data Controller

Legal Name

LUMIARDI GESTÃO DE CONTEÚDO LTDA.

Registered Office

Av. Alm. Julio de Sá Bierrenbach, 65 – Bloco 2 – Sala 315 – Barra Olímpica/RJ

Official Privacy & DPO Channel

contact@lumiardi.com

Target Audience

Exclusively Persons Aged 18 or Over

1. Controller

Personal data processing within the Lumiardi platform is carried out by LUMIARDI GESTÃO DE CONTEÚDO LTDA., headquartered at Av. Alm. Julio de Sá Bierrenbach, 65 – Bloco 2 – Sala 315 – Barra Olímpica, Rio de Janeiro/RJ, acting as Controller under art. 5, VI, of Law No. 13,709/2018 (LGPD).

Direct privacy and data subject communication channel: contact@lumiardi.com.

2. What Data May Be Processed

2.1. Depending on the nature of the user's relationship with the platform, the following may be processed:

2.1.1. Registration Data

  • Legal name and stage name;
  • CPF / Tax ID;
  • Date of birth;
  • Contact phone / WhatsApp;
  • Registered email;
  • Declared location (country, state and city).

2.1.2. Identification & KYC Data

  • Official photo ID (ID card, driver's license, passport);
  • Data extracted from the document via OCR;
  • Result of facial biometric validation (liveness check);
  • Unequivocal confirmation of legal age (18+).

2.1.3. Platform Technical Data

  • IP address and logical connection port;
  • Device and operating system identifiers;
  • Browser, resolution and session parameters;
  • Access logs and timestamp records;
  • Interactions, searches and browsing within the ecosystem.

2.1.4. Financial and Billing Data

  • Payment tokenization information;
  • Transaction and subscription history;
  • Anti-fraud and risk analysis data;
  • Billing information and invoices.

3. Purposes of Processing

3.1. The personal data collected is processed in strict compliance with the necessity principle for the following purposes:

• Registration and onboarding• Authentication and 2FA• System security• Age verification (18+)• Identity verification• Fraud prevention• Payment processing• Content moderation• Handling of reports• Legal/regulatory compliance• Regular exercise of rights• Ecosystem administration

4. Applicable Legal Bases

4.1. Every data processing activity at Lumiardi is duly grounded on the legal bases authorized by the LGPD:

  • Performance of a contract: to provide the contracted services (art. 7, V);
  • Compliance with a legal or regulatory obligation: fulfillment of tax obligations and retention of logs under the Marco Civil da Internet (art. 7, II);
  • Regular exercise of rights: in administrative, arbitral or judicial proceedings (art. 7, VI);
  • Fraud prevention and data subject security: in registration identification and authentication processes (art. 11, II, 'g');
  • Legitimate interest: to improve features and security (art. 7, IX);
  • Consent: where expressly required for specific purposes (art. 7, I).

5. Processing of Sensitive Data and Biometrics

5.1. Where biometric data (such as facial liveness checks for accreditation) or other sensitive data is processed, Lumiardi will apply a specific legal basis (fraud prevention and security under art. 11, II, 'g' of the LGPD), reinforced encryption controls and ongoing assessment of necessity and proportionality.

6. Age Verification (Age Assurance)

6.1. Lumiardi may use specialized document verification and age-check providers holding international security certifications.

6.2. Whenever technically possible and feasible, priority will be given to obtaining strictly the result required for the age decision (e.g. over 18: pass/fail), minimizing the retention of raw files.

7. Sharing of Data with Third Parties

7.1. Data may be shared, on a strict and secure basis, with partners essential to the provision of the services:

• Hosting infrastructure• Cloud and storage providers• Age Assurance providers• KYC and biometrics engines• Anti-fraud solutions• Payment gateways• Information security systems• Moderation tools• Legal counsel• Public and judicial authorities

8. Processors and Sub-processors

8.1. Lumiardi enters into formal agreements with all its data processors and sub-processors, setting strict obligations regarding information security, confidentiality, strict purpose limitation, retention periods, incident notification and restrictions on subcontracting.

9. International Data Transfer

9.1. International data transfers (such as to AWS/Cloudflare cloud servers located abroad) will be carried out through legitimate mechanisms provided for in the LGPD and in the regulations issued by the ANPD.

9.2. The ANPD has specific regulations on international transfers and standard contractual clauses, which are strictly observed by Lumiardi.

10. Data Retention and Storage

10.1. Personal data will be retained only for the period strictly necessary to:

  • Achieve the purposes for which it was collected;
  • Comply with legal or regulatory retention obligations;
  • Ensure the regular exercise of rights in potential claims;
  • Prevent fraud and maintain system security;
  • Legitimately preserve audit evidence.

11. Information Security Measures

11.1. Lumiardi adopts robust technical and administrative measures to protect personal data against unauthorized access, leaks or incidents:

Strict Access ControlAES-256 / TLS EncryptionEnvironment SegregationMulti-Factor Authentication (2FA)Log AuditingEncrypted Backups24/7 MonitoringIncident Response Plan

12. Security Incident Procedure and Management

12.1. Lumiardi maintains a formal procedure for responding to and remediating information security incidents.

12.2. Where a security incident may pose a relevant risk or harm to data subjects, the procedures and deadlines for notifying the National Data Protection Authority (ANPD) and the affected data subjects will be strictly observed, pursuant to CD/ANPD Resolution No. 15/2024.

13. Data Subject Rights

13.1. In accordance with art. 18 of the LGPD, the data subject may, by formal request through the privacy channel, request:

✓ Confirmation of the existence of processing;
✓ Full access to the personal data processed;
✓ Correction of incomplete, inaccurate or outdated data;
✓ Anonymization, blocking or deletion of unnecessary data;
✓ Portability of data to another provider;
✓ Deletion of data processed on the basis of consent;
✓ Information about the entities with which the data has been shared;
✓ Review of automated decisions, where applicable.

14. Cookie and Tracking Policy

14.1. The platform uses strictly necessary and analytics cookies for:

  • Authentication and maintaining a secure session;
  • Fraud prevention and mitigation of cyberattacks;
  • Operational functioning and system stability;
  • Analysis of performance metrics and telemetry;
  • Preserving the user's language and browsing preferences.

15. Protection of Children and Adolescents

15.1. The Lumiardi platform is exclusively and strictly intended for persons aged 18 or over.

15.2. If registrations or data of minors are identified in breach of this restriction, immediate measures will be taken to block and securely purge them and, where legally applicable, to notify the competent authorities.

16. Data Subject Support Channel & 17. Data Protection Officer (DPO)

To exercise your rights as a data subject or to send questions regarding data processing, please contact our Data Protection Officer (DPO):

Data Protection Officer (DPO): Lumiardi Privacy and Data Protection Unit

Official Email: contact@lumiardi.com

Address: Av. Alm. Julio de Sá Bierrenbach, 65 – Bloco 2 – Sala 315 – Barra Olímpica/RJ

18. Changes to this Privacy Policy

18.1. This Privacy Policy may be updated periodically to reflect legislative, ANPD regulatory, technological or operational developments of the platform. Previous versions may be made available upon request through the data subject channel.

LUMIARDI GESTÃO DE CONTEÚDO LTDA.

DPO Channel: contact@lumiardi.com