Privacy Policy
Last updated: August 1, 2026
This Privacy Policy (“Policy”) describes how RUBRIX DESENVOLVIMENTO DE SOFTWARE PARA DOCUMENTOS ELETRÔNICOS LTDA., a Brazilian limited liability company enrolled with the CNPJ/MF under No. 67.021.890/0001-99, headquartered in Florianópolis, Santa Catarina, Brazil (“Rubrix”, “we”, “us”), processes personal data in connection with the website rubrix.lat, the Rubrix platform and its related APIs and services (collectively, the “Platform”).
This Policy applies in accordance with Brazilian Law No. 13,709/2018 (“LGPD”) and, where applicable, with the data protection laws of the other countries where the Platform operates. It complements our Terms of Service.
1. Rubrix's Roles in Data Processing
1.1. Rubrix plays different roles depending on the processing context:
- Controller — when it defines the purposes and means of processing, such as for account registration and administration data, billing, customer service, marketing, information security, fraud prevention, issuance of digital certificates by the Rubrix CA and generation of the audit trails required for the integrity of the service.
- Processor — when it processes personal data on behalf of and under the instructions of its customers, such as the content of Electronic Documents submitted to the Platform and the data of Signers designated by customers in their signature flows. In these cases, the customer who sent the document is the controller of the data.
1.2. Data processing agreements are available for corporate customers.
2. Data We Collect
2.1. Account and registration data
- Name, email, phone number, company and role (when provided);
- Access credentials (passwords stored in protected form);
- Account access and usage records (date, time, IP address), as required by the Brazilian Internet Framework.
2.2. Signer data
- Name and national identifier (such as CPF in Brazil, RUT in Chile and equivalents in other countries);
- Email and/or phone number used to send the signature link;
- IP address, device and browser data, date and time of signature flow events;
- Evidence of the authentication method used (for example, FinanceID, gov.br or digital certificate).
2.3. FinanceID data
- Identity confirmation derived from the instant payment transaction (such as the payer's name and identifier returned by the financial institution within the payment scheme);
- Identifiers of the transaction used for verification.
We do not collect or store bank balances, statements, banking passwords or credentials for accessing your bank account. The transaction is processed by your own financial institution.
2.4. Digital certificate data
- Data contained in the certificate used or issued for the signature (such as the holder's name and identifier), including in the single-use certificates issued by the Rubrix CA.
2.5. Electronic Documents
- The content of documents submitted to the Platform, processed temporarily and exclusively for the execution of the signature flow, as per section 4.
2.6. Website browsing data
- Cookies and analytics identifiers (see section 12);
- Data voluntarily submitted through contact forms (name, email, company, message).
2.7. Billing data
- Registration and tax data required for issuing invoices and billing. Payment card data, where applicable, is processed by third-party payment providers.
3. Purposes and Legal Bases
| Purpose | Data involved | Legal basis (LGPD) |
|---|---|---|
| Providing the Platform, executing signature flows and issuing single-use certificates | Account, Signers, FinanceID, certificates, documents | Performance of a contract or preliminary procedures (art. 7, V) |
| Generating and preserving audit trails and signature evidence | Signers, flow events, IP, authentication | Performance of a contract; regular exercise of rights (art. 7, V and VI); legitimate interest (art. 7, IX) |
| Verifying identity and preventing fraud | FinanceID, national identifiers, IP, device | Legitimate interest (art. 7, IX); fraud prevention and data subject safety (art. 11, II, “g”, where applicable) |
| Billing, collection and tax obligations | Registration, billing | Performance of a contract; compliance with a legal obligation (art. 7, II and V) |
| Keeping application access records | Access logs | Compliance with a legal obligation — Brazilian Internet Framework (art. 7, II) |
| Support, operational communication and customer service | Account, contact details | Performance of a contract (art. 7, V); legitimate interest (art. 7, IX) |
| Information security and Platform improvement | Logs, technical data, usage metrics | Legitimate interest (art. 7, IX) |
| Marketing and commercial communication | Contact details, browsing | Consent (art. 7, I); legitimate interest (art. 7, IX), with the right to object |
| Analytics cookies | Browsing | Consent (art. 7, I) |
4. Documents: Temporary Storage
4.1. Rubrix is not a document storage service. Electronic Documents remain available on the Platform only for the time needed to complete the signature flow and are automatically removed from the servers after the applicable period, as indicated on the Platform.
4.2. Documents are encrypted in transit and at rest. Access to their content is restricted to what is strictly necessary to provide the service.
4.3. The signed PDF remains valid after removal: the digital certificate is embedded in the file itself and can be verified in any compatible reader, independently of Rubrix.
5. Audit Trail and Evidence
5.1. To ensure the integrity, authenticity and evidentiary value of signatures, Rubrix generates and preserves audit trails containing, among others, flow events, date and time, IP address, authentication method and data of the certificate used.
5.2. This evidence may be retained for the applicable statute-of-limitations periods, even after the document is deleted or the account is closed, based on the regular exercise of rights and the legitimate interest of the signing parties.
6. Data Sharing
6.1. Rubrix does not sell personal data. We share data only when necessary, with:
- Trust service providers and certificate authorities, for issuing certificates, timestamps and validating signatures;
- Financial institutions and payment schemes, in the context of identity verification via FinanceID;
- Infrastructure and cloud computing providers that host the Platform;
- Communication providers (email, messaging), for sending signature flow links and notifications;
- Payment and billing providers, for processing charges;
- Analytics providers, as described in the cookies section;
- Public authorities, when required by law, regulation or order of a competent authority;
- Parties to corporate transactions (merger, acquisition, reorganization), preserving the safeguards of this Policy;
- The other parties to the signature flow: the sender and Signers have access to the necessary data of the document and the corresponding audit trail.
6.2. We require our suppliers to undertake contractual commitments of confidentiality and data protection compatible with this Policy and applicable law.
7. International Transfers
7.1. Because we operate in multiple Latin American countries and use infrastructure providers that may process data outside the data subject's country, personal data may be transferred internationally.
7.2. In such cases, we adopt the mechanisms permitted by art. 33 of the LGPD and applicable local laws, such as transfers to countries with an adequate level of protection, specific contractual clauses or standard contractual clauses, ensuring a level of protection compatible with this Policy.
8. Retention and Deletion
| Category | Retention period |
|---|---|
| Electronic Documents | Only during the signature flow window; automatic removal after the period indicated on the Platform |
| Audit trails and signature evidence | For the applicable statute-of-limitations periods, for evidentiary purposes |
| Account data | For the duration of the account and, after closure, for the applicable legal periods |
| Access records (logs) | At least 6 months, as per the Brazilian Internet Framework |
| Tax and billing data | For the periods required by tax legislation |
| Marketing data | Until consent is withdrawn or the data subject objects |
8.1. Once the applicable periods have elapsed, data is securely deleted or anonymized. Anonymized data may be kept for statistical purposes.
9. Information Security
9.1. We adopt technical and organizational measures consistent with market best practices, including: encryption of data in transit and at rest, need-based access control, event logging and monitoring, environment segregation and incident response processes. The Platform was built by a team experienced in high-criticality digital signature infrastructure.
9.2. No system is absolutely immune to incidents. In the event of a security incident that may create relevant risk or damage to data subjects, Rubrix will notify those affected and the Brazilian National Data Protection Authority (ANPD), under applicable law.
10. Data Subject Rights
10.1. Under art. 18 of the LGPD, you may at any time request from Rubrix:
- confirmation of the existence of processing and access to your data;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or excessive data or data processed in non-compliance with the LGPD;
- data portability, subject to applicable regulations;
- deletion of data processed on the basis of consent, except in the cases of retention permitted by law;
- information on the entities with which your data has been shared;
- information on the possibility of refusing consent and the consequences of refusal;
- withdrawal of consent and objection to processing based on legitimate interest.
10.2. Requests may be made through the channel indicated in section 15 and will be answered within the legal deadlines. We may request additional information to confirm your identity before fulfilling a request.
10.3. Some data may be retained even after a deletion request, where there is a legal obligation, regular exercise of rights or another legal basis for retention — such as the audit trails of documents already signed.
10.4. You may also file a complaint with the ANPD or the competent data protection authority in your country. Where the legislation of another country applies (such as the GDPR in the European Union), you may exercise the rights provided for in that legislation.
11. When Rubrix Acts as Processor
11.1. When you receive a document to sign through the Platform, the party that defined the content of the document and designated you as Signer was the sender (our customer), who acts as controller of that data. In these cases, we recommend that requests regarding the content of the document be addressed first to the sender.
11.2. Rubrix, as processor, will process such data in accordance with the lawful instructions of the controller and will cooperate, to the extent technically possible, with the fulfillment of data subject rights.
12. Cookies and Similar Technologies
12.1. We use the following categories of cookies:
- Essential: necessary for the operation of the website and the Platform (such as session, security and language preference). They do not depend on consent.
- Analytics: used for audience metrics and experience improvement (such as Google Analytics, via Google Tag Manager). They are loaded only with your consent, expressed through the cookie banner.
12.2. You may manage or withdraw your consent at any time through the cookie banner or your browser settings. Disabling essential cookies may impair the operation of the website.
13. Children and Adolescents
13.1. The Platform is not intended for individuals under 18 years of age. We do not knowingly collect data from children and adolescents. If we identify processing under these conditions without proper legal support, the data will be deleted.
14. Changes to this Policy
14.1. This Policy may be updated from time to time to reflect legal, regulatory or operational changes. The current version will always be available on this page, with the update date indicated at the top. Material changes will be communicated through the available channels, with reasonable notice.
15. Data Protection Officer and Contact
15.1. Rubrix maintains a Data Protection Officer (DPO), pursuant to art. 41 of the LGPD. To exercise your rights or ask questions about this Policy, please contact us:
- Email: contato.rubrix@gmail.com (subject: “Privacy”);
- Address: Florianópolis, Santa Catarina, Brazil.