Privacy Policy — SuperDMZ

Last updated: June 1, 2026

DestinoLivre Tecnologia Ltda, operator of the SuperDMZ service, takes your privacy seriously. This policy describes what data we collect, how we use it, with whom we share it, and your rights, in compliance with Brazil's LGPD (Law 13.709/2018) and the EU's GDPR.

For technical details on how traffic inside tunnels is processed (TLS, log retention, opaque TCP mode) and our vulnerability disclosure policy, see our Security page.

1. Data controller

The controller of personal data processed by SuperDMZ is DestinoLivre Tecnologia Ltda. For any privacy-related questions, write to [email protected].

2. Data we collect

We collect only what we need to deliver the service:
  • Account: name, email and password (stored only as a one-way hash — not even we can recover it; bcrypt algorithm).
  • Billing: handled entirely by Stripe. We do not store credit card numbers on our servers — we only receive the payment status, last 4 digits and brand.
  • Service usage: tunnels created (hostname, allowed IPs, port), aggregated traffic per tunnel and per month, online/offline status.
  • Technical logs: IP address, browser, date and time, actions performed in the panel (create/edit/delete tunnel, login). Tunnel access tokens are automatically redacted in logs.
  • Communication: messages sent through the contact or support forms (name, email and content).

3. How we use your data

  • Operate and maintain the service (authentication, tunnel provisioning, billing).
  • Send operational notifications by email (2FA verification, tunnel offline, payment receipts).
  • Detect and prevent fraud, abuse and attacks against the infrastructure.
  • Comply with legal and tax obligations.
  • Improve the product (aggregated and anonymous usage analytics).

4. Legal bases for processing

We process your data on the grounds of: contract performance (delivering the service), legal obligation (tax, regulatory), legitimate interest (infrastructure security, fraud prevention) and consent (where applicable, such as optional cookies).

5. Sharing with third parties

To deliver the service, we share strictly necessary data with:
  • Stripe (USA) — payment processing. Receives name, email and card data (sent directly from your browser via Stripe Elements, never passing through our servers).
  • Brevo / Sendinblue (EU) — transactional email delivery (2FA, welcome, alerts).
  • GoDaddy (USA) — creation and removal of DNS records (CNAME for HTTP tunnels on the dmzgate.com domain).
  • Cloudflare (USA) — authoritative DNS for the superdmz.com domain (does not receive your personal data — only DNS queries).
  • Anthropic (USA) — AI provider used in specific features (automatic translation of admin-panel notices and silent-flag signup analysis to detect manifestly fictitious data). When a signup is analyzed, we send name, email, declared country and source IP to the Anthropic API. We do not use the response to automatically block signups: the result is only used to display a friendly warning to the user and for administrator audit. Per Anthropic's commercial terms, data sent via the API is NOT used to train models.

We never sell, rent or assign your data for third-party advertising or marketing.

6. Cookies and similar technologies

We use a minimum set of cookies, all first-party (from our own domain):
  • PHPSESSID — required to keep your session logged in (essential).
  • sdmz_lang — stores your selected language (preference, expires in 1 year).
  • _csrf — protects forms against CSRF attacks (essential).
  • sdmz_cookie_ok — records that you have seen this notice (preference).

We do not use ad-tracking cookies, social network cookies or third-party analytics.

7. How long we keep data

  • Active account: for as long as your account exists.
  • Deleted account: data is purged 48h after deletion confirmation (there is a recovery window via email link).
  • Invoices and tax records: 5 years after the last payment, per legal requirement (tax and accounting).
  • Access logs (nginx): 14 days, with tokens automatically masked.
  • Application logs (audit): 90 days.

8. Your rights as data subject

You may, at any time:
  • Request access to your data.
  • Fix incorrect data directly in the panel (Account page).
  • Change your primary email (with code confirmation + alert to the old email).
  • Request account deletion directly in the panel.
  • Request data portability (export in a readable format).
  • Withdraw consent and revoke processing authorizations.
  • File a complaint with the data protection authority (ANPD in Brazil, your local DPA in the EU).

Written requests: [email protected].

9. Security

We implement technical and organizational measures to protect your data: TLS 1.2/1.3 on all connections, passwords stored as a one-way hash (bcrypt), optional email 2FA, encryption at rest for sensitive secrets, network isolation of nodes, server hardening (UFW, fail2ban) and continuous security auditing.

10. Processing of minors' data

SuperDMZ is a technical network infrastructure service directed to professionals and businesses (system administrators, developers, DevOps teams), and its use presupposes legal majority (18 years in Brazil, or the applicable age of majority in your jurisdiction) due to the contractual nature of the agreement and the responsibility for the data registered and the traffic passing through the tunnels. The tool itself carries no sensitive, inappropriate or harmful content in any aspect — it is network tunneling software, with no editorial media, communities, public chat, comments or any entertainment-oriented interface. We do not perform active age verification during registration, as the product is not directed to minors.

In compliance with applicable data protection law (LGPD Art. 14 in Brazil, GDPR in the EU), if we become aware that an account was created by someone under 18 without the specific and highlighted consent of at least one parent or legal guardian, the account will be suspended and associated data will be deleted. Legal guardians who identify this situation can request immediate deletion at [email protected].

11. Changes to this policy

We may update this policy to reflect changes to the service or to the law. The last-updated date appears at the top. Material changes will be communicated by email to registered users.

12. Contact

To exercise your rights, ask questions or file complaints: [email protected].
DestinoLivre Tecnologia Ltda — Brazil.