Compliance

Legal and regulatory compliance

How Centriu maintains compliance with the LGPD, the Marco Civil and the requirements of international standards — across security, privacy, data subject rights and service management.

Transparency about our position. Centriu is not a certified company and does not use seals or logos suggesting official certification. The practices described represent internal operational adjustments, in compliance with applicable legislation and aligned with the requirements of international standards — not certification granted by an accredited body.
Compliance focus areas

Where we ensure compliance

Six focus areas that connect applicable legislation to international best practices in day-to-day operations.

Legal and regulatory compliance

Processes structured in compliance with applicable Brazilian legislation.

  • Lei Geral de Proteção de Dados (LGPD — Lei nº 13.709/2018).
  • Marco Civil da Internet (Lei nº 12.965/2014).
  • Defined legal bases and the principles of purpose and minimization.

Alignment with international standards

Practices structured in accordance with the requirements of recognized ISO standards.

  • ISO/IEC 27001, 27701, 20000-1, 42001 and 37001.
  • Risk-based approach and continuous improvement.
  • Details on the ISO Compliance page.

Information security

Controls to protect the confidentiality, integrity and availability of information.

  • Encryption in transit and at rest and segregation of environments.
  • Access control based on the principle of least privilege.
  • Logs, audit trails and incident management.

Privacy and data subject rights

Responsible handling of personal data and fulfillment of the rights set out in the LGPD.

  • Privacy by design and by default.
  • Fulfillment of data subject rights within appropriate timeframes.
  • Record of processing activities (ROPA) and data protection clauses (DPA).

Availability and service management

Operations structured to deliver stable and predictable services.

  • Service level indicators and targets (SLAs/SLOs).
  • Incident management and controlled changes.
  • Continuous monitoring and a public status page.

Channels and documents

Points of contact and compliance materials available when needed.

  • Privacy channel and integrity channel.
  • Draft DPA and list of subprocessors upon request.
  • Security contact for responsible reporting.

Legal notice: the compliance practices described on this page represent internal operational adjustments, in observance of applicable legislation (including Lei nº 13.709/2018 and Lei nº 12.965/2014) and the adoption of good practices aligned with the requirements of international standards. Centriu does not claim to hold certification and does not use seals, logos or any elements suggesting official certification. Any certifications can only be issued by duly accredited certification bodies.