Privacy policy
Draft for legal review — preliminary version.
This policy explains which personal data Xeke collects, what it is used for and what your rights are under Brazil's General Data Protection Law (Law 13.709/2018).
01Who the controller is
Xeke is the controller of the personal data processed on this site and in the app. The legal name, tax ID and address of the controller will be stated here before publication.
02Data we collect
Registration data: name, CPF, date of birth, ID document, address, phone and e-mail.
Usage data: pages visited, device, browser and IP address, collected through cookies and analytics tools.
Transaction data: activity carried out in the account, once the app is available.
03Why we process it
To open and maintain your account, carry out the operations you request, prevent fraud, meet legal and regulatory obligations and improve our products.
The legal bases used are performance of a contract, compliance with a legal obligation, legitimate interest and, where applicable, your consent.
04Cookies
We use cookies that are necessary for the site to work and analytics cookies, which are only activated with your consent. You can change your choice at any time in the cookie banner.
05Sharing
We may share data with the partner financial institution responsible for banking services, with technology service providers and with authorities when required by law.
We do not sell personal data.
06How long we keep it
We keep data for as long as needed for the purposes described and for the legal periods applicable to the financial sector, even after the account is closed.
07Your rights
You can request confirmation of processing, access, correction, anonymisation, portability and deletion of your data, and withdraw consent.
The data protection officer's contact channel will be published before launch.
08Security
We apply technical and organisational measures to protect data, such as access control, encryption in transit and monitoring of suspicious activity.
Preliminary document, written as a working basis. It must be reviewed and approved by legal counsel, with the details of the controller, the data protection officer and the partner institution, before going live.