LGPD Compliance
Last updated: May 2026
Lei Geral de Proteção de Dados — Brazil’s General Data Protection Law (Law 13,709/2018)
OODA Intelligence was built from the outset around the principles of Privacy by Design and Security by Default, and is designed to meet the requirements of the LGPD across every module of the platform.
How OODA Intelligence meets the LGPD
Data encryption
Sensitive fields are encrypted with Fernet (AES-128-CBC + HMAC-SHA256). Monitoring keywords, credential data and personal information are all stored encrypted.
Multi-tenant isolation
Every organization has complete data isolation. No user of one organization can reach another organization’s data — a guarantee enforced by middleware and by filters applied to every query.
Audit trail
More than 50 types of audit event are recorded automatically: access, changes, deletions, downloads and administrative operations. Retention is configurable per plan.
Access control (RBAC)
4 access levels (Global Admin, Org Admin, Org User, Org Viewer) with granular permissions per module. Two-factor authentication (2FA) is mandatory.
Data subject rights
Full support for the rights of data subjects: access, correction, anonymization, deletion, portability and withdrawal of consent. Requests are handled within 15 (fifteen) calendar days, as required by Art. 19 §1 of the LGPD.
Data minimization
We collect only the data strictly necessary to deliver the services. Unnecessary data can be anonymized or deleted on request.
Incident notification
Documented procedures for notifying the ANPD and the affected data subjects in the event of a security incident involving personal data, within the deadlines set by law.
Data Protection Officer (DPO)
Our Data Protection Officer is available to handle data subject requests, complaints and communications from the ANPD:
- E-mail: dpo@oodaintel.com
- Address: Bauru, SP - Brazil
- Response time: Up to 15 (fifteen) calendar days from receipt, as required by Art. 19 §1 of the LGPD
Related documents
Policy version: 2026.05