Skip to main content
HugLabs
COMPLIANCE

Built for Regulatory Requirements

HugLabs products are designed with privacy and compliance at their core. We help you meet your regulatory obligations without compromising on functionality.

0
Frameworks
See sub-processor list
Data Residency
Ongoing
Reviews
DATA PROTECTION

Privacy Frameworks

Full compliance with Brazilian and international data protection regulations.

LGPD Compliance

Compliant

Full compliance with Lei n. 13.709/2018 (Brazilian General Data Protection Law).

  • Data subject rights: Access, correction, deletion, portability
  • Legal basis documentation for all processing
  • Privacy contact: privacy@huglabs.ai (DPO appointment in progress)
  • Cookie preferences are controlled through your browser settings

GDPR Readiness

Ready

Ready for EU customer data processing with comprehensive safeguards.

  • Standard Contractual Clauses (SCCs) — planned
  • Data Processing Addendum (DPA) — planned; contact us
  • Right to erasure — honored via privacy@huglabs.ai
  • Data portability — planned
CERTIFICATION

SOC2 Roadmap

Our journey to SOC2 certification is underway.

Certification Status

In Progress

We are actively working toward SOC2 certification to meet enterprise security requirements.

Trust Service Criteria

SecurityAvailabilityConfidentiality

Timeline

Planned

SOC2 Type I Audit

Point-in-time assessment of our security controls and policies.

Planned

SOC2 Type II Certification

Full certification demonstrating operational effectiveness over time.

AGREEMENTS

Data Processing Agreement

Comprehensive legal framework for enterprise data handling.

Purpose Limitation

Clear definitions of data processing purposes and restrictions on unauthorized use.

Security Measures

Technical and organizational measures to protect personal data at rest and in transit.

Sub-processor Management

Transparent sub-processor list with notification of changes.

TRANSPARENCY

Sub-processors

Third-party services that process data on our behalf.

ProviderServiceLocation
FormspreeContact / lead form processingUSA
DATA LIFECYCLE

Retention Policy

Clear guidelines on how long we retain different types of data.

User Data

Active + 30 days

Retained while account is active plus 30 days after deletion request.

Processed Data

Session Only

Used only to improve user experience during active sessions.

Operational Logs

90 days

System and application logs for operational monitoring.

Security Logs

1 year

Security event logs retained for compliance and forensics.

Complete Deletion

Upon request via privacy@huglabs.ai, we will delete the contact data you submitted through our forms (processed by our form provider) and confirm when done.

Questions About Compliance?

Our team is ready to discuss your specific regulatory requirements and how HugLabs can help you stay compliant.

Contact Compliance Team

Continue Exploring

Discover more about ContractStudio