ImobGo
← Back

Data protection and LGPD

Privacy and information security are part of the product, not an afterthought. This page summarizes, in plain language, how ImobGo handles personal data in compliance with Brazilian Law No. 13.709/2018 (LGPD).

1. Our commitment

Agents trust ImobGo with sensitive data — their own and that of every client, lead and owner. We treat that data with the same rigor we apply to money in the wallet: least-privilege access, a record of who accessed what, and nothing shared without a legal basis. Privacy by default and by design.

2. Roles: controller and processor

Regarding each agent's or agency's data, CodeBloodedCorp usually acts as processor — we handle data for the purpose you define, as controller of your clients' data. For your own account data (registration, billing, platform usage), we act as controller. Exact roles are detailed in the data processing agreement (DPA) provided at contract time.

3. Separation between accounts

Every agent and every agency operates in a separate area. No data flows between accounts: queries are always filtered by the account that owns the information, both in the application and in the database. That separation is the first line of defense for your clients' privacy.

4. Information security

We apply encryption in transit (TLS) and at rest, role-based access control, least privilege, strong authentication for administrative access and auditing of sensitive operations. Infrastructure runs on a mainstream cloud provider with daily backups and point-in-time recovery.

5. Purpose and minimization

We collect only the data needed to operate the platform and deliver the contracted service: managing properties, clients, offers, inspections, partnerships and commissions. We don't use your clients' data for advertising, nor do we sell it to third parties.

6. Data subject rights

Every data subject has the right to: confirmation and access; correction of incomplete or outdated data; anonymization, blocking or deletion of unnecessary or non-compliant data; portability; information about sharing; and withdrawal of consent. Requests about an agent's client data are forwarded to that agent (the controller); requests about your account we handle directly.

7. Vendors involved

To operate we use a lean set of vendors (hosting, transactional email, payment processing). All are contractually bound to security and privacy standards compatible with the LGPD. An up-to-date list is available on request.

8. Security incidents

In the event of an incident that may cause relevant risk or harm to data subjects, we notify affected controllers and, where applicable, Brazil's National Data Protection Authority (ANPD), within the deadlines and in the form required by the LGPD.

9. Retention and deletion

We keep data for as long as the contractual relationship lasts and for the period required to meet legal obligations. Once an account is closed, data is deleted or anonymized within a defined period, except where retention is required by law.

10. Data protection officer (DPO) and contact

Data protection officer: CodeBloodedCorp. To exercise rights, ask questions or report a privacy concern, write to [email protected]. We reply within 15 business days.

Last updated: 10/08/2026