GDPR Compliance

How we protect your data and guarantee your privacy under European regulations.

Last updated: June 2, 2026

Scope: This statement applies to Luhnify's B2B API service for ID format validation. Luhnify does not perform Know-Your-Customer (KYC) checks, identity verification, or credit-risk assessments. The API returns a structural format match result only and does not confirm the authenticity or legal validity of any identity document.

1. Our Role: Data Controller & Data Processor

Luhnify SL ("Luhnify", "we", "us") operates in a dual capacity under the GDPR. As regards our customers' account data (name, email, billing information), we act as the Data Controller (Art. 4(7) GDPR). As regards the validation payloads transmitted via the API (country code, document type, document number), we act as a Data Processor (Art. 4(8) GDPR) on behalf of our customers, who are the Data Controls for any personal data contained therein. We offer a Data Processing Agreement (DPA) compliant with Art. 28 GDPR to all customers upon request at [email protected].

2. Legal Bases for Processing (Art. 6 GDPR)

We rely on the following legal bases:
  • Contract performance (Art. 6(1)(b)): processing account data and API validation logs to provide the API service, manage subscriptions, and issue invoices.
  • Legitimate interests (Art. 6(1)(f)): API usage logging (masked document number, country code, document type, IP address, user agent, response time) for service improvement, fraud detection, and security monitoring.
  • Legal obligation (Art. 6(1)(c)): retention of invoicing and financial records as required by applicable tax law.
  • Consent (Art. 6(1)(a)): optional analytics cookies and marketing communications, where you have given prior consent.

3. Data Minimization & Retention Policy

Luhnify applies data minimization at the point of collection. Document numbers submitted via the API are masked before storage: only the last four characters are retained (e.g. ***1234); the full plaintext value is never written to persistent storage. Each API call creates a scan record containing: masked document number, country code, document type, validation result, status code, masked request payload, API response payload, IP address, user agent string, response time, and billing metadata. Account data is retained from the date of account registration until account deletion, and for up to 5 years after account deletion or subscription cancellation for legal, tax, and dispute-resolution purposes. Scan records may be exported in spreadsheet format from your dashboard.

4. Data Subject Rights

If you are an individual whose personal data Luhnify processes as a Data Controller, you hold the following rights under Chapter III GDPR:
  • Access (Art. 15): request a copy of your personal data.
  • Rectification (Art. 16): correct inaccurate data directly from your dashboard Settings.
  • Erasure (Art. 17): delete your account and associated personal data via Settings → Delete Account, or by contacting us.
  • Restriction (Art. 18): restrict processing in specific circumstances.
  • Data Portability (Art. 20): receive your scan data in a structured, machine-readable format via the export feature in your dashboard.
  • Object (Art. 21): object to processing based on legitimate interests.
  • Withdraw Consent: where processing is based on consent, you may withdraw it at any time without affecting prior processing.
To exercise any right, contact our Privacy Desk at [email protected]. We will respond within 30 days as required by Art. 12 GDPR.

5. Sub-processors & International Transfers

We engage the following categories of sub-processors:
  • Amazon Web Services (AWS) — EU-West regions: cloud infrastructure and compute. Transfers governed by the AWS Data Processing Addendum incorporating Standard Contractual Clauses (SCCs) per Commission Decision 2021/914/EU.
  • Stripe Inc.: payment processing and metered billing. Acts as an independent Data Controller for payment data under its own privacy policy. Transfers to the US are covered by SCCs.
We do not transfer personal data outside the EEA unless adequate safeguards (SCCs or adequacy decisions) are in place. An up-to-date list of sub-processors is available at http://luhnify.com/legal/subprocessor.

6. Infrastructure & Technical Security Measures

All communication channels use TLS 1.2 or higher. Our cloud processing layers are logically isolated, access-controlled via least-privilege IAM policies, and hosted in certified (ISO 27001 / SOC 2 Type II) datacenters. API keys are randomly generated tokens; access to your API key is protected by authenticated dashboard sessions. We conduct periodic penetration tests and vulnerability scans. Access to production systems is restricted to authorised personnel via MFA-protected VPN.

7. Data Breach Notification (Art. 33–34 GDPR)

In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will: (a) notify the competent supervisory authority within 72 hours of becoming aware of the breach (Art. 33 GDPR); (b) notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights (Art. 34 GDPR); (c) notify affected customers (as Data Controllers) promptly so they can fulfil their own notification obligations. Security incidents can be reported to [email protected].

8. Data Protection Officer & Supervisory Authority

Although Luhnify is not currently required to appoint a DPO under Art. 37 GDPR, we have designated a Privacy Desk as a single point of contact for all data protection matters: [email protected]. If you believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local supervisory authority. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD), www.aepd.es.

For data protection enquiries contact our Privacy Desk. To report a security incident write to [email protected]. Business customers processing personal data via the API should review our Data Processing Agreement.