Legal
Stack4Sec & the LGPD
How Stack4Sec supports compliance with Brazil's LGPD.
Terakhir diperbarui: June 25, 2026 · Stack4Sec, LLC — Wyoming, USA
Language
This document is provided in English, which is the authoritative version; any translation is for convenience only and the English version prevails.
Overview
This document applies to all cybersecurity software-as-a-service solutions, websites, applications, platforms, APIs, software, modules, features, documentation, support, and related services made available by Stack4Sec, LLC, a Wyoming limited liability company.
For purposes of this document, "Stack4Sec," "Company," "we," "us," and "our" mean Stack4Sec, LLC. "Customer," "you," and "your" mean the person or entity accessing or using the Services.
This document is incorporated into and forms part of the Stack4Sec Terms of Service. Product-specific terms may supplement this document for particular products, modules, services, or features.
This document explains how Stack4Sec approaches Brazil's Lei Geral de Protecao de Dados Pessoais (LGPD) and related guidance from the Autoridade Nacional de Protecao de Dados (ANPD). It is provided for transparency and does not constitute legal advice. Customers should consult their own counsel to determine how the LGPD applies to their organization and use of the Services.
Scope
This document applies where Stack4Sec processes personal data subject to the LGPD in connection with the Services.
Roles Under the LGPD
Depending on the processing activity, Stack4Sec may act as:
- a controller for its own business operations, such as account administration, billing, website analytics, marketing, security, and customer relationship management;
- an operator where Stack4Sec processes Customer Personal Data on behalf of Customer through the Services;
- an operator to another operator or service provider where Customer acts on behalf of a third-party controller.
The Data Processing Addendum governs Stack4Sec's operator obligations for Customer Personal Data where applicable.
Customer Responsibilities
Customer is responsible for determining the purpose and lawful basis for processing Customer Personal Data submitted to the Services. Customer is responsible for transparency notices, data subject rights, consents where required, records, security measures under Customer's control, retention decisions, and compliance with LGPD obligations applicable to Customer.
Legal Bases
Where Stack4Sec acts as controller, it may rely on legal bases available under the LGPD, such as performance of contract, legitimate interest, consent, compliance with legal or regulatory obligations, exercise of rights in legal proceedings, protection of credit, or other lawful bases applicable to the processing.
Data Subject Rights
LGPD rights may include confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, information about consent consequences, revocation of consent, and review of certain automated decisions where applicable.
Where Stack4Sec processes Customer Personal Data as operator, Customer is generally responsible for responding to data subject requests. Stack4Sec will provide reasonable assistance as required by the DPA and applicable law.
International Transfers
Stack4Sec is based in the United States and may process personal data in the United States and other countries. Where LGPD international transfer requirements apply, Stack4Sec and Customer will cooperate in good faith to use appropriate transfer mechanisms, which may include ANPD standard contractual clauses, equivalent contractual clauses, specific contractual clauses, binding corporate rules, adequacy decisions, or other mechanisms recognized under the LGPD and ANPD regulations.
Security Measures
Stack4Sec implements commercially reasonable technical and organizational measures designed to protect personal data against unauthorized access, accidental or unlawful destruction, loss, alteration, communication, or dissemination.
Customer remains responsible for security measures under its control, including access management, device security, user permissions, data minimization, and lawful submission of Customer Personal Data.
Security Incident Notification
If Stack4Sec confirms a Security Incident affecting Customer Personal Data, Stack4Sec will notify Customer in accordance with the DPA and applicable law. Customer is responsible for determining whether notification to the ANPD, data subjects, or other parties is required.
Sensitive Personal Data
Customer must not submit sensitive personal data unless necessary, lawful, permitted by the applicable agreement, and protected by appropriate safeguards. Customer is responsible for minimizing, redacting, or pseudonymizing sensitive personal data where feasible.
Automated Decisions and AI Features
AI Features may support analysis, summarization, classification, or recommendation. AI outputs do not replace human review. Customer is responsible for evaluating whether any use of AI Features triggers LGPD requirements relating to automated decisions and for providing any required notices, rights, and review mechanisms.
Retention and Deletion
Stack4Sec retains personal data only as necessary for the purposes described in the Agreement, Privacy Policy, DPA, or as required for legal, security, operational, or compliance purposes. Customer is responsible for configuring retention and deletion of Customer Content where available.
Contact
LGPD-related inquiries may be sent to:
Stack4Sec, LLC 30 N Gould St, STE R Sheridan, WY 82801 United States Email: legal@stack4sec.com
Permintaan data pribadi
Gunakan hak Anda berdasarkan GDPR/LGPD. Kami akan membalas ke email yang Anda berikan.