At Luhnify ("Luhnify", "we", "us"), protecting your information is a core responsibility. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the rights you hold over it. It applies to all users of our website and API service.
1. Who We Are
Luhnify provides a B2B SaaS API for
ID format validation: given a country, an ID type, and an ID string, our API returns whether the string matches the expected structural format for that combination. We are
not a KYC provider and we do not verify the authenticity, ownership, or legal validity of any identity document. Our registered address and data controller details are available by contacting us at
[email protected].
2. Information We Collect
- Account data: name, organisation name, email address, and password (stored as a one-way hash), collected when you register.
- Billing data: billing address and tax ID (CIF/NIF/VAT) for invoicing. We do not store card details; all payment data is handled by Stripe, Inc.
- API scan records: every API call creates a persistent scan record containing the masked document number (last 4 characters only), country code, document type, validation result, status code, masked request payload, full API response payload, IP address, user agent string, response time, and billing metadata. The full plaintext document number is never stored.
- Support communications: content of emails or form submissions you send to us.
- Analytics & cookies: if you consent, we use cookies and analytics tools to understand how the website is used. See Section 7 for details.
3. How We Use Your Information
We process your data for the following purposes, each tied to a legal basis under Art. 6 GDPR:
- Providing and maintaining the API service — contract performance
- Processing payments and issuing invoices — contract performance / legal obligation
- Sending transactional emails (account events, quota alerts, support replies) — contract performance
- Fraud detection, abuse prevention, and security monitoring — legitimate interests
- API usage logging (masked document number, country code, document type, IP address, user agent, response time) for service improvement and quota enforcement — legitimate interests
- Marketing communications (opt-in only) — consent
We will never use submitted ID strings to profile individuals or build datasets for resale.
4. Data Sharing & Sub-processors
We do not sell, rent, or lease your personal data. We share data only with the following categories of trusted sub-processors:
- Amazon Web Services (AWS) — EU-West: cloud hosting, compute, and database infrastructure.
- Stripe, Inc.: payment processing and metered billing. Stripe acts as an independent Data Controller for card and payment data.
- Transactional email provider: delivery of system notifications; no marketing access.
An up-to-date sub-processor list is maintained at http://luhnify.com/legal/subprocessor. We contractually require all sub-processors to implement equivalent data protection standards.
5. Data Retention
- Account data: retained from the date of account registration until account deletion, and for up to 5 years after account deletion or subscription cancellation for legal, tax, and dispute-resolution purposes.
- API scan records: retained for the duration of the contractual relationship. You may export your scan history in spreadsheet format from your dashboard at any time.
- Support communications: retained for up to 3 years.
6. Security
We implement the following technical and organisational measures: TLS 1.2+ on all connections, hashed passwords, randomly generated API keys protected by authenticated dashboard sessions, logically isolated database networks, least-privilege access controls, MFA-protected production access, periodic penetration testing, and hosting in ISO 27001 / SOC 2 Type II certified datacenters. In the event of a personal data breach we will notify the competent supervisory authority within 72 hours and affected users without undue delay where required by Art. 33–34 GDPR.
7. Cookies & Analytics
We use the following categories of cookies:
- Strictly necessary: session authentication, CSRF protection, and cookie-consent preference. These do not require consent.
- Analytics (opt-in): aggregate, anonymised usage metrics to improve our website and application. Enabled only with your explicit consent via our cookie banner.
You can manage or withdraw your consent at any time via the Cookie Settings link in the footer.
8. Your Rights
Depending on your location, you may exercise the following rights:
- EEA/UK residents (GDPR / UK GDPR): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. To exercise any of these rights, contact our Privacy Desk at [email protected]. If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority (our lead authority is the AEPD, www.aepd.es).
- California residents (CCPA/CPRA): right to know, right to delete, right to opt out of sale (we do not sell personal information), and right to non-discrimination. Submit requests to [email protected].
You can manage most account-related rights directly in your Dashboard Settings. For all other requests, contact our Privacy Desk. We respond within 30 days.
9. International Transfers
Your personal data is processed primarily within the EEA. Where data is transferred to a third country (e.g., Stripe's US infrastructure), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914/EU) or other recognised transfer mechanisms.
10. Changes to This Policy
We will notify registered users of material changes to this Privacy Policy by email at least 14 days before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the service after the effective date constitutes acceptance.