you type it
Full name
So we know who we are talking to and do not open the reply with dear customer.
What this site collects, where it goes and how you have it deleted.
This policy covers myhidigital.com and its contact form. It is written to be read from beginning to end. If any line here is unclear, write to suporte@myhidigital.com and we will rewrite it. Last updated: 31 August 2026.
This site has no database. There is no table with your name inside it. The form collects your name, company, email, WhatsApp number and the challenge you tick from the list. That becomes an email arriving at suporte@myhidigital.com. The H&I partners are the people who read it. There are no tracking cookies, no advertising pixels and no analytics tool. That is why you saw no cookie banner: there is nothing to consent to. We do not sell, rent or swap your data with anyone. There is no mailing list. Ask us to delete it and we delete it.
The data controller is H&I DIGITAL, registered in Brazil under company number (CNPJ) 47.872.156/0001-26, at Rua Áustria, 11, Enseada, São Sebastião, SP, Brazil. There is no formally appointed data protection officer, because this is a small operation. H&I Digital answers for data protection itself. Contact for anything on this page: suporte@myhidigital.com. It is the same inbox that receives the forms and the same address the reply comes from. WhatsApp, if you prefer: +55 12 99626-4723.
Five fields and one technical server log. Nothing beyond this.
you type it
So we know who we are talking to and do not open the reply with dear customer.
you type it
So we understand the size and sector of the operation before we talk.
you type it
It is how we reply. It is also the channel that survives when WhatsApp fails.
you type it
Used only to reply to you. It never goes into a broadcast list or a group.
picked from a list
One option among conversion website, process automation and custom system. It lets us arrive at the call with context already.
collected by the host
The hosting provider records IP address, date, time and browser for each visit, as any web server does. It is a technical log, for security and diagnosis. We do not cross-reference it with what arrives from the form.
This list matters as much as the one above.
No field on this site asks for a document. If a contracted project needs one, that is handled in the contract, off the site.
There is no checkout, no basket and no card field anywhere on this site.
We do not ask for GPS and we do not use browser geolocation.
We do not know which pages you visited before arriving here and we build no behavioural profile of you.
We do not ask for racial origin, political opinion, religion, health, sex life, biometrics or trade union membership. If anything like that arrives in the form by mistake, we delete it.
Reading, replying and, if it makes sense for both sides, booking the 30-minute diagnostic, free and with no obligation.
Looking at your company website and understanding the sector, so we arrive at the meeting with the right questions ready.
If the conversation becomes a proposal, your contact details go into the document and then into the contract.
Technical server logs, to diagnose errors and block abuse.
We do not run targeted advertising, we do not feed what you write into an AI model, and there is no automated decision-making or profiling about you.
Purpose, article and the reason in plain English.
| Replying to you and preparing the proposalUK GDPR art. 6(1)(b) · LGPD art. 7, V | You asked us to get in touch. This is processing at your request, in the steps prior to a possible contract. |
|---|---|
| Keeping the thread of our conversationUK GDPR art. 6(1)(f) · LGPD art. 7, IX | Legitimate interest in having a record of what was agreed. You may object, and then we delete it. |
| Technical logs and site securityUK GDPR art. 6(1)(f) · LGPD art. 7, IX | Legitimate interest in keeping the site online and blocking abusive access. |
| Tax records, if we become client and supplierUK GDPR art. 6(1)(c) · LGPD art. 7, II | Legal obligation. Invoices and contracts carry their own retention period, which is not ours to shorten. |
Three categories of supplier, and nobody else.
Each of these suppliers acts as a processor: it handles the data on our instruction and for the purpose we set, not for its own. Want the names of the companies behind these categories? Ask by email and we will reply with the current list.
processor
Receives the form content and turns it into an email to us. It is the only third party that touches what you type on this site.
processor
Serves the pages and keeps the server access log. It hosts no database for this site, because this site has no database.
processor
Where your message arrives and is stored, as in any inbox.
off-site
If you message us on WhatsApp, the conversation goes through Meta, under Meta’s own policy. That is true of any WhatsApp conversation and is not a choice this site makes. Would rather not? Write to suporte@myhidigital.com.
No ad network, no analytics tool, no third-party CRM and no commercial partner receives your data. If that ever changes, this page changes first.
Maximum periods. Ask sooner and we delete sooner.
up to 24 months
After that the message leaves the inbox and the archive.
for as long as the work runs
Once the contract ends, we keep only the minimum that legal obligation requires.
at least 5 years
A retention period Brazilian law requires, and it can run longer depending on the tax involved. It is not ours to waive and a deletion request cannot shorten it. We say so plainly in our reply when that is the case.
the host’s rotation
A technical log, cleared by the hosting provider’s rotation. Brazilian internet law treats six months as the reference period for application access logs.
H&I engineering sits in Brazil. If you write from London or anywhere else in the UK, your message is read in Brazil. Brazil is not covered by a UK adequacy decision. So when data leaves the UK, the contract with the supplier has to carry the standard data protection clauses: the IDTA or the UK Addendum to the standard contractual clauses. Going the other way, the ANPD standard clauses apply. The form service, the hosting provider and the email service may process the data outside Brazil and the UK, under the standard clauses in each of their contracts. Beyond those three, there is no transfer to anyone.
The two regimes give you very nearly the same list. It applies to you under either.
Find out whether we hold data about you, and get a copy of what we hold.
Correct data that is wrong, incomplete or out of date.
Ask us to delete. We delete, except what the law requires us to keep. In that case we tell you exactly what stayed and why.
Object to processing we carry out on the basis of legitimate interests.
UK GDPR
Ask us to freeze use of the data while a challenge of yours is resolved.
Receive your data in a machine-readable format, to take elsewhere.
LGPD
Find out who we shared your data with, public body or private company.
Where processing depends on consent, you withdraw it whenever you like, with no reason given.
There is no automated decision-making about you here, so there is nothing to review. If that ever exists, this page will say what it is and how to ask for a human review.
No special form, no account and no fee.
step 1
Subject line: personal data. Say what you want: access, rectification, erasure, portability, objection.
within 5 days
If we need to be sure it is really you, we ask only for what settles that and nothing more. We do not ask for identity documents as a matter of course.
within 15 days
The LGPD says 15 days and the UK GDPR says one month. We work to the shorter of the two. It is free of charge.
regulator
Complain to the regulator. In the UK, the ICO, at ico.org.uk. In Brazil, the ANPD, at gov.br/anpd. You do not have to come to us first, though we would rather sort it out with you directly.
No military-grade encryption badge. This is what actually exists, and it can be checked.
It is static files served by the host. There is no login, no admin panel and no table with your name inside this site. What does not exist cannot leak.
The site is served only over an encrypted connection, with http redirected to https and security headers set on the server.
It goes from your browser to the form service, which sends the email. One intermediary only, and it is named on this page.
The messages are read by the two partners. There is no intern and no contractor with access to that inbox.
A breach that poses a real risk to you is reported to the competent regulator, the ICO in the UK, the ANPD in Brazil, within 72 hours of our becoming aware of it, and to you as soon as the risk is established.
This site is aimed at businesses and the people who decide for them. It is not built for under-18s and asks for no data about children or teenagers. If we notice we have received a child’s data without the authorisation of whoever is responsible for them, we delete it and say so.
Last updated: 31 August 2026. This is the first version of this policy. The previous site had no privacy page. There was only a line under the form saying details were protected and would not be shared with third parties, without saying where they ended up. An earlier version sent the form content to an external database service. That path was removed, and that is why this page exists. When the policy changes, the date above changes with it and the change is described here. A material change in how we use your data is emailed to everyone who has already been in touch.
Write to suporte@myhidigital.com. It is the same address for asking, for requesting a copy and for having it deleted. We are the ones who reply.
The official channel for anything about privacy.
Quicker for a chat about a project. For a formal data request, use email instead: it leaves a record.