Privacy Policy
TUT1 - IT Services Solutions and Security LTDA, CNPJ 55.419.376/0001-27, headquartered in São Paulo, SP, Brazil ("TUT1", "we", "us"), is the controller of personal data described in this Privacy Policy under Brazil's Lei Geral de Proteção de Dados (LGPD, Law No. 13,709/2018). This policy explains what we collect, why, and the rights you have — including the fact that the Service is hosted on infrastructure located in the United States even though TUT1 is based in Brazil.
1.Controller
TUT1 - IT Services Solutions and Security LTDA, CNPJ 55.419.376/0001-27, São Paulo, SP, Brazil, is the data controller for personal data processed through the Service. You can reach our privacy contact at contactus at tut1.io.
2.Data we collect
| Category | Examples |
|---|---|
| Account data | Email address, hashed password, account preferences. |
| Billing data | Name, billing email, subscription plan and history. Card numbers are processed directly by Stripe — we do not receive or store full card data. |
| Submitted asset data | Domains and other assets you submit for scanning. |
| Scan & platform data | Subdomains, IPs, ports, certificates, CVEs, and related findings generated by the Service for your submitted assets. |
| Third-party breach data | Publicly-circulating breach records and dark web mentions matched against your domain, which may include personal data of individuals associated with your organization (see §4). |
| Technical & log data | IP address, browser/user agent, timestamps, and request logs generated by normal use of the website and platform. |
3.Purposes & legal bases
We process personal data under the following LGPD legal bases (Art. 7):
- Contract performance — to create your account, run scans, and deliver the Service you subscribed to.
- Legitimate interest — to detect and prevent abuse of the platform, to match publicly-circulating breach data against a domain for defensive security purposes, and to improve the Service.
- Legal obligation — to keep billing and tax records as required by Brazilian law.
- Consent — for optional communications, such as product updates, where you have opted in.
4.Third-party breach & dark web data
Our breach, credential exposure, and dark web monitoring features index and match data that is already circulating in public or semi-public leak sources against the domain you submitted. We do this on the basis of our legitimate interest, and yours, in identifying and remediating security exposure.
This data may include personal data of individuals who are not TUT1 customers (for example, employees or customers of the domain owner whose credentials appear in a breach). Where an individual wishes to exercise LGPD rights over data about them that appears in our platform as part of a breach dataset tied to a third party's domain, they may contact contactus at tut1.io and we will respond in accordance with applicable law.
5.Sharing & processors
We share personal data with service providers who process it on our behalf and under contract, including:
- Amazon Web Services (AWS) — cloud hosting and infrastructure (United States).
- Stripe — payment processing and billing.
- Email and support-communication providers used to operate the Service.
We do not sell personal data. We may disclose data where required by law, to enforce our Terms, or to protect the rights, safety, and security of TUT1, our customers, or the public.
6.International data transfers
We rely on the international transfer mechanisms available under LGPD Art. 33 — including standard contractual clauses with our processors where applicable — to safeguard data transferred outside Brazil.
7.Retention
- Account & scan data — retained while your account is active, and for a reasonable period after cancellation in case you reactivate, after which it is deleted or anonymized.
- Billing & invoice records — retained for the period required by Brazilian tax and accounting law.
- Technical logs — retained for a limited period for security and troubleshooting purposes, then deleted or aggregated.
8.Security
We use industry-standard safeguards, including encryption in transit (TLS) and password hashing, and restrict access to personal data to personnel who need it to operate the Service. No system is completely secure, and we cannot guarantee absolute security.
9.Your rights
Under LGPD, you have the right to: confirm the existence of processing; access your data; correct incomplete, inaccurate, or outdated data; request anonymization, blocking, or deletion of unnecessary or excessive data; request data portability; obtain information about entities with whom we share data; revoke consent; and request deletion of data processed with your consent. If you are located outside Brazil, we honor equivalent rights available to you under your local data protection law (for example, the GDPR) on a best-efforts basis.
To exercise these rights, contact contactus at tut1.io. We will respond within the timeframe required by applicable law.
10.Complaints
If you believe we have not addressed your request appropriately, you may lodge a complaint with Brazil's national data protection authority, the Autoridade Nacional de Proteção de Dados (ANPD), or with the data protection authority of your own country, where applicable.
11.Cookies
We use essential cookies required for authentication and core functionality, and may use limited analytics cookies to understand aggregate usage of the website. You can control cookies through your browser settings.
12.Children
The Service is not directed at, and may not be used by, anyone under 18 years of age.
13.Changes to this policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days' notice by email or in-app notice before the changes take effect.
14.Contact
Questions about this Privacy Policy, or requests to exercise your data protection rights, can be sent to contactus at tut1.io.