LGPD compliance in corporate travel management
Loupit is fully compliant with Brazil's LGPD (Law 13.709/2018). See how we handle company, traveller and approver data with a defined purpose, a legal basis, configurable consent and strong protection of corporate information.
- Purpose and legal basis for every processing activity
- Consent by category, revocable at any time
- Encryption in transit and at rest
- Complete audit trail for every decision
Get a summary of our LGPD compliance
Like what you saw? Start free with 2 fields
No credit card and no agency exclusivity. We email you a confirmation link.
Corporate travel involves sensitive data: who travels, where to, how much the company spends and who approved each purchase. That is why privacy and data protection are part of the Loupit product, not a contractual annex. This page explains, in plain language, our data policies, how consent works and which controls protect your company's information.
Data policies behind our compliance
Five fronts applied across the whole lifecycle of corporate data.
Purpose and minimisation
We only collect what is needed to quote, approve, buy and report a trip.
- Every field has a documented purpose
- No use of corporate data for undeclared purposes
- Optional fields clearly identified
Legal basis and contracts
Processing always relies on a defined legal basis — contract, legal obligation or consent.
- Controller and processor roles defined
- Data protection clauses with agencies and suppliers
- Records of processing activities
Information security
Encryption, card tokenisation and anti-fraud protect payments and personal data.
- TLS in transit and encryption at rest
- Tokenised card data, never exposed in reports
- Monitoring and incident response
Role-based access control
Each person sees only what their role requires: traveller, approver, manager or finance.
- Permissions configurable per company and cost centre
- Strict segregation between companies
- Immediate access revocation on offboarding
Audit and retention
Every decision is recorded, with retention periods aligned to tax and legal duties.
- Audit trail of requests, approvals and purchases
- Retention defined per data type
- Secure deletion at the end of the period
Consent and preferences
You decide which cookies and communications you allow — and can change your mind anytime.
Necessary
Essential for login, security and platform operation. Always on.
Preferences
Store language, currency and display settings to improve your experience.
Statistics
Aggregated usage metrics. Loaded only after your explicit consent.
Marketing
Communications and remarketing. Optional and revocable in one click.
Data subject rights
Requests are handled through a dedicated channel, with deadlines and records.
- Confirmation that processing exists
- Access to the personal data processed
- Correction of incomplete or outdated data
- Anonymisation, blocking or deletion of unnecessary data
- Data portability to another provider
- Information about sharing with agencies and suppliers
- Withdrawal of consent at any time
How data flows through a booking
From the travel request to expense reporting, traceable at every step.
- 1
Request
The traveller submits route, dates and cost centre — no unnecessary data.
- 2
Comparison
We query agencies and suppliers sharing only the minimum needed to quote.
- 3
Approval
The approver decides within policy; the decision is recorded.
- 4
Purchase
Payment with tokenised cards and anti-fraud; no sensitive data in emails.
- 5
Reporting
Reports and expense with role-based access and a full audit trail.
LGPD frequently asked questions
The most common questions from legal, compliance and information security teams.
Want your compliance team to review Loupit?
Create your free account and share our data policies, access controls and audit trail with your legal and information security teams.