Legal
Privacy policy
Last updated: 10 September 2026. First-version copy for launch; it may be revised with legal counsel.
This policy describes how LetzCNPJ handles personal data under Brazil’s LGPD (Law 13.709/2018) for CNPJ/QSA consult and monitoring.
We collect account data (name, email, hashed password, company name) and, if you subscribe, Stripe identifiers (customer and subscription). We do not store card numbers.
When you consult a CNPJ we store the official snapshot (including QSA/partners, registration status, address, capital, CNAE, company contacts) to compute diffs versus the previous consult and, if you enable alerts, to email the recipients you add.
Typical legal bases are performance of the contract and legitimate interest in security, fraud prevention, and billing. Alert recipients are provided by you; your company must have a lawful basis to add them.
We do not sell CNPJ databases. Essential processors: Serpro (data source), Stripe (payments), Amazon SES (email), and, if configured, xAI/Grok only to summarize the consult payload — never platform secrets.
We keep data while the account exists and as needed for legal and tax duties. You may request access, correction, deletion, or portability via support, subject to legal retention.
We use session and locale cookies. Production traffic uses HTTPS.