← Home

Privacy policy

What this site collects, where it goes and how you have it deleted.

This policy covers myhidigital.com and its contact form. It is written to be read from beginning to end. If any line here is unclear, write to suporte@myhidigital.com and we will rewrite it. Last updated: 31 August 2026.

The short version, before the long one

This site has no database. There is no table with your name inside it. The form collects your name, company, email, WhatsApp number and the challenge you tick from the list. That becomes an email arriving at suporte@myhidigital.com. The H&I partners are the people who read it. There are no tracking cookies, no advertising pixels and no analytics tool. That is why you saw no cookie banner: there is nothing to consent to. We do not sell, rent or swap your data with anyone. There is no mailing list. Ask us to delete it and we delete it.

Who the controller is and how to reach us

The data controller is H&I DIGITAL, registered in Brazil under company number (CNPJ) 47.872.156/0001-26, at Rua Áustria, 11, Enseada, São Sebastião, SP, Brazil. There is no formally appointed data protection officer, because this is a small operation. H&I Digital answers for data protection itself. Contact for anything on this page: suporte@myhidigital.com. It is the same inbox that receives the forms and the same address the reply comes from. WhatsApp, if you prefer: +55 12 99626-4723.

What the form collects

Five fields and one technical server log. Nothing beyond this.

you type it

Full name

So we know who we are talking to and do not open the reply with dear customer.

you type it

Company name

So we understand the size and sector of the operation before we talk.

you type it

Email address

It is how we reply. It is also the channel that survives when WhatsApp fails.

you type it

WhatsApp number

Used only to reply to you. It never goes into a broadcast list or a group.

picked from a list

Main challenge

One option among conversion website, process automation and custom system. It lets us arrive at the call with context already.

collected by the host

Server access log

The hosting provider records IP address, date, time and browser for each visit, as any web server does. It is a technical log, for security and diagnosis. We do not cross-reference it with what arrives from the form.

What this site does not collect

This list matters as much as the one above.

Tax ID, company number or any identity document

No field on this site asks for a document. If a contracted project needs one, that is handled in the contract, off the site.

Payment details

There is no checkout, no basket and no card field anywhere on this site.

Precise location

We do not ask for GPS and we do not use browser geolocation.

Browsing profile

We do not know which pages you visited before arriving here and we build no behavioural profile of you.

Special category data

We do not ask for racial origin, political opinion, religion, health, sex life, biometrics or trade union membership. If anything like that arrives in the form by mistake, we delete it.

What we use the data for

Replying to you

Reading, replying and, if it makes sense for both sides, booking the 30-minute diagnostic, free and with no obligation.

Preparing for the call

Looking at your company website and understanding the sector, so we arrive at the meeting with the right questions ready.

Writing the proposal and the contract

If the conversation becomes a proposal, your contact details go into the document and then into the contract.

Keeping the site up

Technical server logs, to diagnose errors and block abuse.

Never for this

We do not run targeted advertising, we do not feed what you write into an AI model, and there is no automated decision-making or profiling about you.

Who the data is shared with

Three categories of supplier, and nobody else.

Each of these suppliers acts as a processor: it handles the data on our instruction and for the purpose we set, not for its own. Want the names of the companies behind these categories? Ask by email and we will reply with the current list.

processor

Email form service

Receives the form content and turns it into an email to us. It is the only third party that touches what you type on this site.

processor

Hosting provider

Serves the pages and keeps the server access log. It hosts no database for this site, because this site has no database.

processor

Email service

Where your message arrives and is stored, as in any inbox.

off-site

WhatsApp, if you choose that channel

If you message us on WhatsApp, the conversation goes through Meta, under Meta’s own policy. That is true of any WhatsApp conversation and is not a choice this site makes. Would rather not? Write to suporte@myhidigital.com.

Nobody else

No ad network, no analytics tool, no third-party CRM and no commercial partner receives your data. If that ever changes, this page changes first.

How long we keep it

Maximum periods. Ask sooner and we delete sooner.

up to 24 months

An enquiry that did not become a project

After that the message leaves the inbox and the archive.

for as long as the work runs

An enquiry that became a project

Once the contract ends, we keep only the minimum that legal obligation requires.

at least 5 years

Contracts and tax records

A retention period Brazilian law requires, and it can run longer depending on the tax involved. It is not ours to waive and a deletion request cannot shorten it. We say so plainly in our reply when that is the case.

the host’s rotation

Server access logs

A technical log, cleared by the hosting provider’s rotation. Brazilian internet law treats six months as the reference period for application access logs.

International transfers

H&I engineering sits in Brazil. If you write from London or anywhere else in the UK, your message is read in Brazil. Brazil is not covered by a UK adequacy decision. So when data leaves the UK, the contract with the supplier has to carry the standard data protection clauses: the IDTA or the UK Addendum to the standard contractual clauses. Going the other way, the ANPD standard clauses apply. The form service, the hosting provider and the email service may process the data outside Brazil and the UK, under the standard clauses in each of their contracts. Beyond those three, there is no transfer to anyone.

Cookies: no banner, because there is no tracker

This site uses no tracking cookies, no advertising pixels and no analytics tool. No Google Analytics, no Meta pixel, no heatmap, no session recording. That is why you saw no cookie banner on arrival. There is nothing to consent to. What your browser may store is a technical preference of yours, such as the language you picked. It stays on your device and is never sent to us. If we ever want to measure something, this page is updated before the measurement goes live, and then consent will be asked for. We will not switch on a tracker and mention it afterwards.

Your rights, under the UK GDPR and the LGPD

The two regimes give you very nearly the same list. It applies to you under either.

Confirmation and access

Find out whether we hold data about you, and get a copy of what we hold.

Rectification

Correct data that is wrong, incomplete or out of date.

Erasure

Ask us to delete. We delete, except what the law requires us to keep. In that case we tell you exactly what stayed and why.

Objection

Object to processing we carry out on the basis of legitimate interests.

UK GDPR

Restriction of processing

Ask us to freeze use of the data while a challenge of yours is resolved.

Portability

Receive your data in a machine-readable format, to take elsewhere.

LGPD

Information on sharing

Find out who we shared your data with, public body or private company.

Withdraw consent

Where processing depends on consent, you withdraw it whenever you like, with no reason given.

Review of automated decisions

There is no automated decision-making about you here, so there is nothing to review. If that ever exists, this page will say what it is and how to ask for a human review.

How to exercise them, in practice

No special form, no account and no fee.

  1. Write to suporte@myhidigital.com

    step 1

    Subject line: personal data. Say what you want: access, rectification, erasure, portability, objection.

  2. We confirm receipt

    within 5 days

    If we need to be sure it is really you, we ask only for what settles that and nothing more. We do not ask for identity documents as a matter of course.

  3. We reply with what was done

    within 15 days

    The LGPD says 15 days and the UK GDPR says one month. We work to the shorter of the two. It is free of charge.

  4. If the answer does not settle it

    regulator

    Complain to the regulator. In the UK, the ICO, at ico.org.uk. In Brazil, the ANPD, at gov.br/anpd. You do not have to come to us first, though we would rather sort it out with you directly.

How the data is protected

No military-grade encryption badge. This is what actually exists, and it can be checked.

The site has no database

It is static files served by the host. There is no login, no admin panel and no table with your name inside this site. What does not exist cannot leak.

HTTPS enforced

The site is served only over an encrypted connection, with http redirected to https and security headers set on the server.

The form does not pass through a server of ours

It goes from your browser to the form service, which sends the email. One intermediary only, and it is named on this page.

Access limited to the partners

The messages are read by the two partners. There is no intern and no contractor with access to that inbox.

If there is an incident

A breach that poses a real risk to you is reported to the competent regulator, the ICO in the UK, the ANPD in Brazil, within 72 hours of our becoming aware of it, and to you as soon as the risk is established.

Children

This site is aimed at businesses and the people who decide for them. It is not built for under-18s and asks for no data about children or teenagers. If we notice we have received a child’s data without the authorisation of whoever is responsible for them, we delete it and say so.

Last updated, and what changed

Last updated: 31 August 2026. This is the first version of this policy. The previous site had no privacy page. There was only a line under the form saying details were protected and would not be shared with third parties, without saying where they ended up. An earlier version sent the form content to an external database service. That path was removed, and that is why this page exists. When the policy changes, the date above changes with it and the change is described here. A material change in how we use your data is emailed to everyone who has already been in touch.

A question about your data?

Write to suporte@myhidigital.com. It is the same address for asking, for requesting a copy and for having it deleted. We are the ones who reply.

Ask about my data

Email

suporte@myhidigital.com

The official channel for anything about privacy.

WhatsApp

+55 12 99626-4723

Quicker for a chat about a project. For a formal data request, use email instead: it leaves a record.