Privacy Policy
Last updated: 27 August 2026
This policy explains what personal data Homio collects on this site, why we collect it, who we share it with and what you can require from us. It covers the site www.homio.com.br and the forms on it. Use of the Homio platform by an existing customer is governed by the services agreement, not by this document.
Homio is a Brazilian company and processes personal data primarily in Brazil and in the United States. If you are outside Brazil, section 7 explains what that means for you and which rights you have under your own law.
1. Who the controller is
| Legal name | Homio Serviços e Sistemas Ltda. |
| Company registration (CNPJ) | 54.936.237/0001-08 |
| Address | Rua Henrique Novaes, 88, room 605, Vitória, Espírito Santo, 29010-490, Brazil |
| Controller contact | controller@homio.com.br |
| General contact | contato@homio.com.br |
Homio is the controller of the data described here. It decides why and how that data is processed, under Brazilian Law 13.709/2018 (the General Data Protection Law, or LGPD) and, where it applies, under the equivalent provisions of the law of your country.
2. Data protection officer
The data protection officer receives complaints and requests from individuals and communicates with the supervisory authority.
| Officer | Juliana Ribeiro Paganucci |
| protection@homio.com.br |
Writing to that address is the fastest way to exercise any right in section 8.
3. What we collect
We collect only what each action requires. You decide when to provide it: none of the forms below is required in order to browse the site.
3.1 When you book a demo
Name, email, phone number, and optionally your website address, the business Instagram account and the company name. The time slot you pick is recorded as well.
3.2 When you apply as a partner
Name, email, phone number, job title, how many active clients you serve, and whether you already resell a CRM or any software as a service.
3.3 When you subscribe to a plan
Name, company name, email, phone number, a tax identification number, and payment details. The tax identification number we ask for depends on your country: in Brazil it is the CPF or the CNPJ.
Card details are typed into a component provided by Stripe and go straight to Stripe. They do not pass through our servers and we never have access to the card number.
3.4 Automatically, as you browse
IP address, browser type and version, pages visited, date and time of access, and technical signals from the browser used to tell a person apart from a bot.
Those signals are collected by the anti automation service described in section 5. They describe characteristics of the device and of behaviour on the page, not the content of what you type.
3.5 What we deliberately do not keep
To limit abusive calls to our forms we keep a counter per identifier. That counter does not store your email, phone number or IP address. It stores only an irreversible cryptographic digest of them, which is enough to count attempts and does not allow the original value to be recovered.
4. Why we process this data, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Booking and running the demo | 3.1 | Steps taken at your request before entering into a contract |
| Answering a partner application and assessing the partnership | 3.2 | Steps taken at your request before entering into a contract |
| Creating and maintaining your subscription, charging and invoicing | 3.3 | Performance of a contract, and compliance with a legal obligation |
| Sending confirmations and reminders you asked for | 3.1, 3.2, 3.3 | Performance of a contract, and legitimate interests |
| Protecting the forms against bots and abuse | 3.4, 3.5 | Legitimate interests in the security of the service |
| Measuring use of the site and improving the pages | 3.4 | Consent, collected in the cookie banner |
| Advertising and remarketing | 3.4 | Consent, collected in the cookie banner |
| Attributing a completed booking or subscription to an ad | 3.1, 3.3 | Consent, collected in the cookie banner |
The basis names above map to article 7 of the LGPD and, for anyone in the European Economic Area or the United Kingdom, to article 6 of the GDPR: article 6(1)(b) for contract and pre contractual steps, 6(1)(c) for legal obligations, 6(1)(f) for legitimate interests and 6(1)(a) for consent.
Where the basis is consent, nothing is activated before you accept, and you can withdraw consent at any time in the banner itself, without affecting what was done before you withdrew it.
Where the basis is legitimate interests, we have assessed the processing as necessary and proportionate, and you can object through the channel in section 2.
5. Who we share it with
We do not sell personal data. We share it only with the providers the site needs in order to work, and each of them processes the data under our instructions.
| Who | What for | Where they process |
|---|---|---|
| HighLevel Inc. (GoHighLevel) | CRM: stores the contact, the booking and the history | United States |
| Stripe | Payment, subscription and card data | United States and Brazil |
| Vercel Inc. | Site hosting and access logs | United States |
| Vercel BotID / Kasada | Telling people apart from bots on the forms | United States and Australia |
| Supabase | Attempt counter keyed by an irreversible digest | United States |
| Spedy | Issuing the Brazilian service invoice | Brazil |
| Google, Meta and Microsoft | Usage measurement and advertising, only after consent | United States and elsewhere |
| Meta (Conversions API) | Confirming from our server that a conversion happened on the site, only after consent | United States |
5.1 The server side send to Meta
The other measurement tools work through code that runs in your browser. The Conversions API works differently, which is why it is described separately.
When you book a demo or subscribe to a plan, and only if you accepted marketing cookies, our server tells Meta that the conversion happened. So that Meta can recognise the person without receiving your details, we send an irreversible cryptographic digest of your email and phone number, calculated before the send. The email address and the phone number themselves are not sent, and the digest does not allow them to be recovered.
This exists because tracking blockers stop part of the confirmations from arriving through the browser, and without them there is no way to know which ad brought in a real customer.
Refusing marketing cookies in the banner turns this send off, and you can change your mind at any time through the cookie preferences link in the footer.
We may also share data where there is a court order, a request from a competent authority or a legal obligation.
6. How long we keep it
| Data | Period |
|---|---|
| Contact details of someone who booked a demo and did not become a customer | 24 months after the last contact |
| Partner application that was not approved | 24 months after the application |
| Data of an active customer | For the duration of the contract |
| Tax and billing records | 5 years after termination, as a legal obligation |
| Site access logs | 6 months, as required by the Brazilian Internet Civil Framework |
| Form attempt counter | 24 hours |
Once the period ends the data is deleted or anonymised, unless the law requires us to keep it longer.
7. International transfers, and where you are
Homio processes personal data in Brazil, and the providers in section 5 process it mainly in the United States. Wherever the data goes, we require the provider to offer a level of protection compatible with the law that applies to it, through contractual clauses and the safeguards set out in articles 33 to 36 of the LGPD and in the standard contractual clauses approved by the Brazilian data protection authority.
7.1 If you are in the European Economic Area or the United Kingdom
Brazil has not been the subject of an adequacy decision by the European Commission. Personal data of people in the EEA or the United Kingdom that reaches Homio is therefore transferred on the basis of the European Commission's standard contractual clauses, or the United Kingdom's international data transfer addendum, together with the measures described in section 9.
In addition to the rights in section 8, you have the right to lodge a complaint with the supervisory authority of the country where you live or work. In the United Kingdom, that authority is the Information Commissioner's Office.
7.2 If you are in California or another United States state with a privacy law
We do not sell personal information and we do not share it for cross context behavioural advertising in the sense those terms are given by the California Consumer Privacy Act. The measurement and advertising described in section 5 happens only after you consent to it in the banner, and refusing it does not change anything about the service you receive.
You may exercise the rights in section 8 through the channel in section 2, and we will not treat you differently for having exercised them.
8. Your rights
At any time, and at no cost, you can ask us to:
- confirm whether we process data about you and give you access to it;
- correct data that is incomplete, inaccurate or out of date;
- anonymise, block or delete data that is unnecessary or processed outside the law;
- port the data to another provider;
- delete data processed on the basis of consent;
- tell you who we share your data with;
- withdraw consent;
- object to processing carried out on the basis of legitimate interests;
- restrict processing while a request of yours is being examined.
To exercise any of them, write to the officer in section 2. We answer within 15 days where Brazilian law applies, and within one month where the GDPR or the United Kingdom GDPR applies. We may ask for further information in order to confirm your identity, precisely so as not to hand your data to somebody else.
You can also complain directly to the Brazilian National Data Protection Authority (ANPD) or, if you are in the EEA or the United Kingdom, to your own supervisory authority.
9. Security
We apply technical and organisational measures proportionate to the risk, among them: encrypted traffic throughout the site, integration secrets kept outside the code and with restricted access, rate limiting and automation detection on the forms, and access to the CRM limited to the people who need it in order to work.
No system is immune. If a security incident occurs with a relevant risk to your rights, we will notify you and the competent authority within the periods the law sets.
10. Children
The site and the platform are meant for companies and professionals. We do not knowingly collect data from children or adolescents. If we identify collection of that kind, we delete the record.
11. Changes to this policy
We may update this document. The date at the top shows the last change. A relevant change will be announced on the site, and where the processing depends on consent, consent will be asked for again.
12. Contact
Questions about this policy, and any request concerning your data: protection@homio.com.br. General matters: contato@homio.com.br.
