Skip to content

Privacy Policy

Last updated: 27 August 2026

This policy explains what personal data Homio collects on this site, why we collect it, who we share it with and what you can require from us. It covers the site www.homio.com.br and the forms on it. Use of the Homio platform by an existing customer is governed by the services agreement, not by this document.

Homio is a Brazilian company and processes personal data primarily in Brazil and in the United States. If you are outside Brazil, section 7 explains what that means for you and which rights you have under your own law.

1. Who the controller is

Legal nameHomio Serviços e Sistemas Ltda.
Company registration (CNPJ)54.936.237/0001-08
AddressRua Henrique Novaes, 88, room 605, Vitória, Espírito Santo, 29010-490, Brazil
Controller contactcontroller@homio.com.br
General contactcontato@homio.com.br

Homio is the controller of the data described here. It decides why and how that data is processed, under Brazilian Law 13.709/2018 (the General Data Protection Law, or LGPD) and, where it applies, under the equivalent provisions of the law of your country.

2. Data protection officer

The data protection officer receives complaints and requests from individuals and communicates with the supervisory authority.

OfficerJuliana Ribeiro Paganucci
Emailprotection@homio.com.br

Writing to that address is the fastest way to exercise any right in section 8.

3. What we collect

We collect only what each action requires. You decide when to provide it: none of the forms below is required in order to browse the site.

3.1 When you book a demo

Name, email, phone number, and optionally your website address, the business Instagram account and the company name. The time slot you pick is recorded as well.

3.2 When you apply as a partner

Name, email, phone number, job title, how many active clients you serve, and whether you already resell a CRM or any software as a service.

3.3 When you subscribe to a plan

Name, company name, email, phone number, a tax identification number, and payment details. The tax identification number we ask for depends on your country: in Brazil it is the CPF or the CNPJ.

Card details are typed into a component provided by Stripe and go straight to Stripe. They do not pass through our servers and we never have access to the card number.

3.4 Automatically, as you browse

IP address, browser type and version, pages visited, date and time of access, and technical signals from the browser used to tell a person apart from a bot.

Those signals are collected by the anti automation service described in section 5. They describe characteristics of the device and of behaviour on the page, not the content of what you type.

3.5 What we deliberately do not keep

To limit abusive calls to our forms we keep a counter per identifier. That counter does not store your email, phone number or IP address. It stores only an irreversible cryptographic digest of them, which is enough to count attempts and does not allow the original value to be recovered.

4. Why we process this data, and on what legal basis

PurposeDataLegal basis
Booking and running the demo3.1Steps taken at your request before entering into a contract
Answering a partner application and assessing the partnership3.2Steps taken at your request before entering into a contract
Creating and maintaining your subscription, charging and invoicing3.3Performance of a contract, and compliance with a legal obligation
Sending confirmations and reminders you asked for3.1, 3.2, 3.3Performance of a contract, and legitimate interests
Protecting the forms against bots and abuse3.4, 3.5Legitimate interests in the security of the service
Measuring use of the site and improving the pages3.4Consent, collected in the cookie banner
Advertising and remarketing3.4Consent, collected in the cookie banner
Attributing a completed booking or subscription to an ad3.1, 3.3Consent, collected in the cookie banner

The basis names above map to article 7 of the LGPD and, for anyone in the European Economic Area or the United Kingdom, to article 6 of the GDPR: article 6(1)(b) for contract and pre contractual steps, 6(1)(c) for legal obligations, 6(1)(f) for legitimate interests and 6(1)(a) for consent.

Where the basis is consent, nothing is activated before you accept, and you can withdraw consent at any time in the banner itself, without affecting what was done before you withdrew it.

Where the basis is legitimate interests, we have assessed the processing as necessary and proportionate, and you can object through the channel in section 2.

5. Who we share it with

We do not sell personal data. We share it only with the providers the site needs in order to work, and each of them processes the data under our instructions.

WhoWhat forWhere they process
HighLevel Inc. (GoHighLevel)CRM: stores the contact, the booking and the historyUnited States
StripePayment, subscription and card dataUnited States and Brazil
Vercel Inc.Site hosting and access logsUnited States
Vercel BotID / KasadaTelling people apart from bots on the formsUnited States and Australia
SupabaseAttempt counter keyed by an irreversible digestUnited States
SpedyIssuing the Brazilian service invoiceBrazil
Google, Meta and MicrosoftUsage measurement and advertising, only after consentUnited States and elsewhere
Meta (Conversions API)Confirming from our server that a conversion happened on the site, only after consentUnited States

5.1 The server side send to Meta

The other measurement tools work through code that runs in your browser. The Conversions API works differently, which is why it is described separately.

When you book a demo or subscribe to a plan, and only if you accepted marketing cookies, our server tells Meta that the conversion happened. So that Meta can recognise the person without receiving your details, we send an irreversible cryptographic digest of your email and phone number, calculated before the send. The email address and the phone number themselves are not sent, and the digest does not allow them to be recovered.

This exists because tracking blockers stop part of the confirmations from arriving through the browser, and without them there is no way to know which ad brought in a real customer.

Refusing marketing cookies in the banner turns this send off, and you can change your mind at any time through the cookie preferences link in the footer.

We may also share data where there is a court order, a request from a competent authority or a legal obligation.

6. How long we keep it

DataPeriod
Contact details of someone who booked a demo and did not become a customer24 months after the last contact
Partner application that was not approved24 months after the application
Data of an active customerFor the duration of the contract
Tax and billing records5 years after termination, as a legal obligation
Site access logs6 months, as required by the Brazilian Internet Civil Framework
Form attempt counter24 hours

Once the period ends the data is deleted or anonymised, unless the law requires us to keep it longer.

7. International transfers, and where you are

Homio processes personal data in Brazil, and the providers in section 5 process it mainly in the United States. Wherever the data goes, we require the provider to offer a level of protection compatible with the law that applies to it, through contractual clauses and the safeguards set out in articles 33 to 36 of the LGPD and in the standard contractual clauses approved by the Brazilian data protection authority.

7.1 If you are in the European Economic Area or the United Kingdom

Brazil has not been the subject of an adequacy decision by the European Commission. Personal data of people in the EEA or the United Kingdom that reaches Homio is therefore transferred on the basis of the European Commission's standard contractual clauses, or the United Kingdom's international data transfer addendum, together with the measures described in section 9.

In addition to the rights in section 8, you have the right to lodge a complaint with the supervisory authority of the country where you live or work. In the United Kingdom, that authority is the Information Commissioner's Office.

7.2 If you are in California or another United States state with a privacy law

We do not sell personal information and we do not share it for cross context behavioural advertising in the sense those terms are given by the California Consumer Privacy Act. The measurement and advertising described in section 5 happens only after you consent to it in the banner, and refusing it does not change anything about the service you receive.

You may exercise the rights in section 8 through the channel in section 2, and we will not treat you differently for having exercised them.

8. Your rights

At any time, and at no cost, you can ask us to:

  • confirm whether we process data about you and give you access to it;
  • correct data that is incomplete, inaccurate or out of date;
  • anonymise, block or delete data that is unnecessary or processed outside the law;
  • port the data to another provider;
  • delete data processed on the basis of consent;
  • tell you who we share your data with;
  • withdraw consent;
  • object to processing carried out on the basis of legitimate interests;
  • restrict processing while a request of yours is being examined.

To exercise any of them, write to the officer in section 2. We answer within 15 days where Brazilian law applies, and within one month where the GDPR or the United Kingdom GDPR applies. We may ask for further information in order to confirm your identity, precisely so as not to hand your data to somebody else.

You can also complain directly to the Brazilian National Data Protection Authority (ANPD) or, if you are in the EEA or the United Kingdom, to your own supervisory authority.

9. Security

We apply technical and organisational measures proportionate to the risk, among them: encrypted traffic throughout the site, integration secrets kept outside the code and with restricted access, rate limiting and automation detection on the forms, and access to the CRM limited to the people who need it in order to work.

No system is immune. If a security incident occurs with a relevant risk to your rights, we will notify you and the competent authority within the periods the law sets.

10. Children

The site and the platform are meant for companies and professionals. We do not knowingly collect data from children or adolescents. If we identify collection of that kind, we delete the record.

11. Changes to this policy

We may update this document. The date at the top shows the last change. A relevant change will be announced on the site, and where the processing depends on consent, consent will be asked for again.

12. Contact

Questions about this policy, and any request concerning your data: protection@homio.com.br. General matters: contato@homio.com.br.