Back to home

Privacy Policy

How Curupira collects, uses, retains and protects personal data — and the rights you have over it.

Last updated: July 25, 2026

1. Controller and Data Protection Officer

Curupira is an OAuth2 / OpenID Connect identity and access management service. The controller responsible for the personal data described in this policy is DW Corp LTDA (also trading as DW Serviços de Alto Valor Agregado), CNPJ 38.501.143/0001-50, registered at SHN Quadra 1 Bloco A Conj. A Salas 1413, Asa Norte, Brasília/DF, CEP 70701-000, Brazil.

Our Data Protection Officer (Encarregado) can be reached at privacy@dwcorp.com.br for any question about this policy or how your personal data is handled. General company contact: dream@dwcorp.com.br.

2. Personal data we collect

To provide the identity service, we process the following categories of personal data:

  • Account data — your email address and a securely hashed password (passwords are never stored in plaintext), together with an optional given and family name.
  • Authentication and security data — the IP address, user agent and timestamp recorded with each login attempt (successful, failed or blocked), and session identifiers held in a cookie.
  • Event and audit records — event logs of authentication activity (for example, token issuance) and audit logs of administrative changes, which may reference your account.
  • Authorization data — the tenant, applications, roles and role groups associated with your account, which determine what you can access.

3. Legal bases for processing

We process personal data on the legal bases set out in Art. 7 of Brazil's LGPD and — for users in the European Union — the corresponding bases in Art. 6 of the GDPR:

  • Performance of a contract (LGPD Art. 7, V; GDPR Art. 6(1)(b)) — to authenticate you, issue tokens and provide the service you or your organization requested.
  • Legitimate interest (LGPD Art. 7, IX and Art. 10; GDPR Art. 6(1)(f)) — to record login attempts and events for security, abuse prevention and incident investigation.
  • Compliance with a legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)) — where retention or disclosure is required by law.

4. How we use your data

We use personal data only to operate and secure the service, in line with the LGPD Art. 6 principles (finalidade, adequação, necessidade) and the GDPR Art. 5 principles of purpose limitation and data minimisation. Specifically, we use it to:

  • authenticate users and issue and validate OAuth2 / OpenID Connect tokens;
  • enforce roles, role groups and tenant isolation to control access;
  • detect suspicious activity, rate-limit abuse and investigate security incidents;
  • keep audit and event records of administrative and authentication activity.
  • We do not use your data for advertising, and we do not sell personal data.

5. Sharing and subprocessors

We do not sell personal data. We share it only with the infrastructure and observability providers (subprocessors) needed to operate the service — for example hosting, database and logging/metrics providers — each bound to process it only on our instructions.

We may also disclose data where required by law or to protect the rights, safety or property of Curupira, DW Corp LTDA or its users.

6. Support access by our staff

To provide technical support, investigate incidents and keep the service secure and reliable, a limited number of authorised DW Corp personnel hold a super-administrator role that can access tenant configuration and, where strictly necessary, the personal data processed within your tenant. This access is limited to what the task at hand requires.

Support access follows the principle of least privilege and is used only for legitimate operational purposes — such as resolving a support request you raise, diagnosing a malfunction or responding to a security incident. Our staff do not access your data for any unrelated purpose.

These administrative actions are recorded in our audit logs (actor, action, affected resource and timestamp) so that access can be reviewed and accounted for. You can request information about administrative access affecting your tenant at privacy@dwcorp.com.br.

7. Retention and deletion

We keep personal data only as long as necessary for the purpose it was collected, applying storage limitation (GDPR Art. 5(1)(e)) and the LGPD necessity principle (necessidade). Security logs are minimised in layers by a scheduled background job:

To delete your account and personal data, see the step-by-step options on our Data Deletion page (/data-deletion): self-service, SSO-link removal, or by request.

  • Account data is kept while your account is active.
  • In login-attempt and event logs, personal data is anonymised in place at around 90 days — the last octet of an IPv4 address is masked, user agents are dropped and free-form metadata is cleared — so aggregate security analysis survives without keeping identifiers.
  • Those login-attempt and event log rows are then deleted in full at 120 days.
  • Audit logs of administrative changes are kept longer for compliance and are anonymised (rather than deleted) once past their window.

8. Your rights

Under Art. 18 of the LGPD (and, for EU users, Articles 15–22 of the GDPR), you have rights over your personal data. Curupira provides self-service tooling for the two most common ones:

  • Access and data portability (LGPD Art. 18, II and V; GDPR Art. 15 and Art. 20) — you can export a structured, machine-readable JSON copy of your account and the security-log records that reference you, directly from your account.
  • Deletion / erasure (LGPD Art. 18, VI; GDPR Art. 17) — you can request deletion of your account from your account; we soft-delete and anonymise your record and the logs that reference you, and end your active sessions.
  • Confirmation, correction, anonymisation, information about sharing, and objection (LGPD Art. 18) — contact us to exercise these.
  • To exercise any right, contact our Data Protection Officer at privacy@dwcorp.com.br.

9. Security

Passwords are stored only as Argon2id hashes, never in plaintext, and connection secrets (such as SSO client secrets) are encrypted at rest with AES-256-GCM. Data is protected in transit with TLS. Access is protected by scoped, signed OAuth2 tokens, role-based access control and tenant isolation, and authentication activity is monitored through login-attempt, event and audit logs. We apply rate limiting and brute-force lockout on sign-in, and send security headers including a Content-Security-Policy.

10. International data transfers

Where personal data is transferred outside its country of origin (including outside the European Economic Area), we rely on appropriate safeguards, such as standard contractual clauses or an equivalent legal mechanism, so the data keeps an adequate level of protection.

11. Cookies

The Curupira identity service uses a strictly necessary, first-party session cookie to keep you signed in during authentication. It is essential to the service, is not used for advertising or cross-site tracking, and cannot be disabled without breaking sign-in.

12. Changes to this policy

We may update this policy from time to time. We will post the updated version here and revise the last updated date shown above; where changes are material, we will provide a more prominent notice.

13. Contact and the ANPD

For any privacy question or to exercise your rights, contact DW Corp LTDA (CNPJ 38.501.143/0001-50), SHN Quadra 1 Bloco A Conj. A Salas 1413, Asa Norte, Brasília/DF, CEP 70701-000, Brazil — Data Protection Officer: privacy@dwcorp.com.br.

You also have the right to lodge a complaint with Brazil's National Data Protection Authority (ANPD — https://www.gov.br/anpd) or, for EU users, your local supervisory authority.