Privacy Policy
Effective 9 October 2026
This policy explains how quecpf ltd ("quecpf", "we") processes personal data when operating the quecpf.com website and the CPF lookup API at api.quecpf.com, under Brazil's General Data Protection Law (Law No. 13,709/2018, "LGPD").
On this page
1. Who we are and our roles
quecpf ltd, [CNPJ / REGISTRATION NUMBER], registered at [ENDEREÇO].
- We are the controller of customer account data (registration, authentication, usage and billing) and of the data we keep in our own database.
- For lookups made by customers, the customer is the controller: it decides the purpose and legal basis of each lookup. quecpf acts as processor (operador), handling the data on the customer’s instructions and under these terms.
2. Data we process
Data sent by the customer in lookups:
- CPF and full name (required).
- The end user’s IP address, birth date and mother’s name (optional, for verification only).
- The declared purpose of the lookup.
Data obtained from external sources to answer lookups:
- Registration data linked to the CPF (name, sex, birth date, mother’s name), from a partner provider (cpf-brasil.org).
- Public lists from Brazil’s Transparency Portal (CGU): Politically Exposed Persons (PEP), CEIS, CNEP and CEAF.
- Approximate geolocation and network operator of the IP address, from DB-IP and MaxMind GeoLite2 databases kept on our servers.
- Internal records from companies in our corporate group, used solely for fraud prevention and visible only to authorized accounts.
Customer data: email, company, password (stored only as an argon2id hash), API keys (stored only as hashes), usage records and the declared legal basis.
3. Purposes and legal bases
- Answering customer lookups for fraud prevention, data subject security, and identification and onboarding (KYC): LGPD art. 7, II, V, VI and IX and art. 11, II, "g", according to the legal basis declared by the customer.
- Complying with legal and regulatory obligations and exercising rights in proceedings: art. 7, II and VI.
- Operating accounts, authenticating access, enforcing quotas, billing and support: art. 7, V (performance of a contract).
- Keeping the service secure, detecting abuse and auditing lookups: art. 7, IX (legitimate interest).
We do not use lookup data for advertising, we do not sell personal data, and we do not profile people for discriminatory purposes.
4. Minimization and response modes
By default, accounts run in "verify" mode: the API says whether the name, birth date or mother’s name sent match, and returns a masked name, without exposing the full registration data.
"Full" mode, which returns registration data, is enabled only after the customer declares the applicable legal basis and purpose, and can be revoked at any time.
CPFs with invalid check digits are rejected before any external source is queried.
5. Storage and retention
- Responses from external providers are stored permanently and encrypted, so the same CPF does not need to be fetched from the source again. Data subjects may request deletion (section 8).
- Public government lists are replaced on each official update.
- The lookup audit trail stores the CPF only as an HMAC (not reversible without our key), the middle six digits, the purpose and a result summary, for [RETENTION PERIOD] or as required by law.
- Account data is kept while the account is active and afterwards for as long as legal obligations require.
- Backups are kept for 14 days.
7. Security
- Encryption in transit (HTTPS/TLS) on every connection to the API.
- Encryption at rest (AES-256-GCM) of provider responses, birth dates and mothers’ names.
- Passwords and API keys stored only as hashes; HttpOnly, Secure, SameSite=Strict session cookie.
- Database not reachable from the internet, restrictive firewall, administrative access by SSH key only, automatic security updates.
- Per-account access control, quotas, rate limits and an audit log of every lookup.
If a security incident may create relevant risk, we will notify the ANPD and affected data subjects under LGPD art. 48.
8. Data subject rights
Under LGPD art. 18 you may request: confirmation that processing exists; access to the data; correction of incomplete, inaccurate or outdated data; anonymization, blocking or deletion of unnecessary or non-compliant data; portability; information about sharing; and review of automated decisions.
To exercise your rights, write to [EMAIL DE CONTATO / CONTACT EMAIL] with the CPF and a way to confirm your identity. We answer within 15 days. When the lookup was made by a customer, we will also forward the request to that customer as controller.
You may also file a complaint with Brazil’s National Data Protection Authority (ANPD).
10. Children and adolescents
The service is for businesses and is not directed at children or adolescents. Customers may look up minors’ CPFs only with a legal basis and in the minor’s best interest (LGPD art. 14).
11. Data protection officer and contact
Data protection officer (encarregado): [ENCARREGADO (DPO) NAME], [EMAIL DE CONTATO / CONTACT EMAIL].
Address: [ENDEREÇO].
12. Changes to this policy
We may update this policy. The effective date at the top shows the current version; customers will be notified of material changes by email with reasonable notice.