Privacy Policy

Last updated: June 2, 2026

At Luhnify ("Luhnify", "we", "us"), protecting your information is a core responsibility. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the rights you hold over it. It applies to all users of our website and API service.

1. Who We Are

Luhnify provides a B2B SaaS API for ID format validation: given a country, an ID type, and an ID string, our API returns whether the string matches the expected structural format for that combination. We are not a KYC provider and we do not verify the authenticity, ownership, or legal validity of any identity document. Our registered address and data controller details are available by contacting us at [email protected].

2. Information We Collect

  • Account data: name, organisation name, email address, and password (stored as a one-way hash), collected when you register.
  • Billing data: billing address and tax ID (CIF/NIF/VAT) for invoicing. We do not store card details; all payment data is handled by Stripe, Inc.
  • API scan records: every API call creates a persistent scan record containing the masked document number (last 4 characters only), country code, document type, validation result, status code, masked request payload, full API response payload, IP address, user agent string, response time, and billing metadata. The full plaintext document number is never stored.
  • Support communications: content of emails or form submissions you send to us.
  • Analytics & cookies: if you consent, we use cookies and analytics tools to understand how the website is used. See Section 7 for details.

3. How We Use Your Information

We process your data for the following purposes, each tied to a legal basis under Art. 6 GDPR:
  • Providing and maintaining the API service — contract performance
  • Processing payments and issuing invoices — contract performance / legal obligation
  • Sending transactional emails (account events, quota alerts, support replies) — contract performance
  • Fraud detection, abuse prevention, and security monitoring — legitimate interests
  • API usage logging (masked document number, country code, document type, IP address, user agent, response time) for service improvement and quota enforcement — legitimate interests
  • Marketing communications (opt-in only) — consent

We will never use submitted ID strings to profile individuals or build datasets for resale.

4. Data Sharing & Sub-processors

We do not sell, rent, or lease your personal data. We share data only with the following categories of trusted sub-processors:
  • Amazon Web Services (AWS) — EU-West: cloud hosting, compute, and database infrastructure.
  • Stripe, Inc.: payment processing and metered billing. Stripe acts as an independent Data Controller for card and payment data.
  • Transactional email provider: delivery of system notifications; no marketing access.

An up-to-date sub-processor list is maintained at http://luhnify.com/legal/subprocessor. We contractually require all sub-processors to implement equivalent data protection standards.

5. Data Retention

  • Account data: retained from the date of account registration until account deletion, and for up to 5 years after account deletion or subscription cancellation for legal, tax, and dispute-resolution purposes.
  • API scan records: retained for the duration of the contractual relationship. You may export your scan history in spreadsheet format from your dashboard at any time.
  • Support communications: retained for up to 3 years.

6. Security

We implement the following technical and organisational measures: TLS 1.2+ on all connections, hashed passwords, randomly generated API keys protected by authenticated dashboard sessions, logically isolated database networks, least-privilege access controls, MFA-protected production access, periodic penetration testing, and hosting in ISO 27001 / SOC 2 Type II certified datacenters. In the event of a personal data breach we will notify the competent supervisory authority within 72 hours and affected users without undue delay where required by Art. 33–34 GDPR.

7. Cookies & Analytics

We use the following categories of cookies:
  • Strictly necessary: session authentication, CSRF protection, and cookie-consent preference. These do not require consent.
  • Analytics (opt-in): aggregate, anonymised usage metrics to improve our website and application. Enabled only with your explicit consent via our cookie banner.

You can manage or withdraw your consent at any time via the Cookie Settings link in the footer.

8. Your Rights

Depending on your location, you may exercise the following rights:
  • EEA/UK residents (GDPR / UK GDPR): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. To exercise any of these rights, contact our Privacy Desk at [email protected]. If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority (our lead authority is the AEPD, www.aepd.es).
  • California residents (CCPA/CPRA): right to know, right to delete, right to opt out of sale (we do not sell personal information), and right to non-discrimination. Submit requests to [email protected].

You can manage most account-related rights directly in your Dashboard Settings. For all other requests, contact our Privacy Desk. We respond within 30 days.

9. International Transfers

Your personal data is processed primarily within the EEA. Where data is transferred to a third country (e.g., Stripe's US infrastructure), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914/EU) or other recognised transfer mechanisms.

10. Changes to This Policy

We will notify registered users of material changes to this Privacy Policy by email at least 14 days before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the service after the effective date constitutes acceptance.

For data protection enquiries, contact our Privacy Desk. Business customers processing personal data via the API should also review our Data Processing Agreement.