Data and privacy

Privacy Policy

Last updated: 2026-09-27. How Clivon handles data from Radar and the Growth and Launch forms, contracting, onboarding, operations and support.

What data can be collected

Clivon provides assisted automation, governance and operations solutions for the real estate market.

  • Customer contact, identification and commercial information.
  • Property materials, files, links, notes and flow usage data.
  • Information needed for diagnosis, contracting, onboarding, service delivery and support.
  • Technical navigation data and attribution parameters present in the access, such as UTM, fbclid and gclid.

Radar and diagnosis forms

The /growth and /launch pages provide a public diagnosis form. This is a commercial prospecting flow started by the visitor, who voluntarily requests contact.

  • Growth data: company, name, WhatsApp number, main operational bottleneck, desired time window and, optionally, preferred contact date and time.
  • Launch data: company, development, WhatsApp number, launch stage, decision to unlock and, optionally, city, preferred date and time.
  • Radar data: name, company, role, company type, commercial team size, continuous lead-flow status, authorized channels, the five qualitative answers and the attribution data described below. The complete result is unlocked only after durable submission confirmation.
  • Radar separation and qualification: complete answers remain in the dedicated intake. Only real estate agencies with at least three commercial team members and continuous lead flow create a Growth lead. Growth receives only authorized contact details, campaign, qualification, derived profile, priority axes, qualitative summary and next action; it never receives the five complete answers.
  • Qualitative profile: Radar only counts the five choices provided to identify one axis or a tie. It uses no benchmark or credit score and makes no automated decision with legal or similarly significant effects.
  • Campaign attribution: the form may record utm_source, utm_medium, utm_campaign, utm_content, utm_term, Google click identifiers (gclid, gbraid and wbraid), the landing-page URL and referrer. Arbitrary query parameters are not forwarded.
  • Purpose of commercial data: to deliver the requested diagnosis and, through independently authorized channels, allow Clivon's team to contact the visitor. Attribution data is used exclusively to attribute and measure the source of that request.
  • Radar legal basis: explicit consent under Brazilian Law 13,709/2018, article 7, I. Consent to record the diagnosis is required; e-mail and WhatsApp contact permissions are independent. The data subject may withdraw consent and request deletion at any time. Growth and Launch remain separately described under legitimate interest.
  • Retention criterion: each submission records a 12-month expiration date. Automated deletion is not active yet; until it is implemented, removal after that date depends on an operational review or a data-subject request, subject to applicable legal retention grounds.
  • Radar retention: each intake expires after 12 months, and public activation requires a validated daily automated deletion routine.
  • Processor: data is stored by a cloud database provider contracted by Clivon, which may process and store information outside Brazil. We treat this as an international transfer even though the specific project region is not published here.
  • Meta Pixel: Clivon's public pages, including Growth, Launch and Radar, load Clivon's Meta Pixel. It records the page view and, only after the server confirms a Growth or Launch diagnosis submission or a Radar reading, a lead event carrying the form type (diagnostico_reuniao or radar_avaliacao). Name, WhatsApp, e-mail, company, role, answers and messages are not sent to Meta, not even hashed, and advanced matching is not used. Meta receives technical browsing data, such as the page address, browser, IP address and the _fbp cookie, and may process it outside Brazil, which we treat as an international transfer. Growth and Launch do not load Meta CAPI.

Contracting and transaction records

  • Payment terms and methods are defined in the proposal and contract accepted by the customer.
  • When an external provider is used, it processes the required data under its own rules and applicable obligations.
  • Clivon does not store full card details on its public pages.
  • References and records from transactions completed through the prior flow may continue to be processed for support, reconciliation, fraud prevention, compliance and the regular exercise of rights.

Use of data

  • Public-form data is used to address the requested diagnosis and conduct the corresponding commercial contact. If a contract is signed, the required data may also be used for onboarding, contracted services and support, subject to the proposal and contract.
  • The four UTM parameters recorded with the diagnosis are used to attribute and measure the source of that request. Navigation events on the routes described in the next section may measure journey continuity.
  • Customers must provide information and materials they are authorized to use.

Cookies, local storage and integrations

  • Local storage may keep the visual theme preference. Historical return and intake routes may also keep a prior transaction's external reference to recover status and service continuity.
  • Technical routes from the prior checkout may use session storage, IndexedDB and essential cookies for bootstrap identity, attribution and duplicate-action prevention. These identifiers are not full card details.
  • Attribution parameters present in the access may accompany the journey. Growth and Launch diagnosis forms record only the four UTM parameters listed above.
  • Public pages load the Meta Pixel described in the data section, limited to page views and confirmed leads. Meta CAPI remains disabled on those pages.
  • Public pages load the Google Ads tag to measure the source of requests originating from ads. It does not load in authenticated areas; outside Radar, it also does not load when the browser sends Do Not Track or Global Privacy Control. Consent Mode v2 starts with advertising storage, user data, ad personalization and analytics denied. Only Radar sends a conversion, and only after the backend confirms a new qualified lead: a conversion event without name, e-mail, phone number, company or answers is sent with a technical submission identifier to prevent duplicate counting.
  • Meta Pixel does not load in authenticated areas or when the browser sends Do Not Track or Global Privacy Control. On the historical confirmation, pending, failure and intake routes, the public Meta Pixel configuration remains disabled; there, the integration code does not request the external script or forward events to Meta.
  • Any activation of CAPI or of new Meta events will require a specific decision and configuration. This policy will be updated before that activation.

Data safety and requests

Data Protection Officer and exercising your rights

  • Controller: CLIVON TECNOLOGIA E PROMOÇÃO DE VENDAS LTDA, Brazilian registry CNPJ 40.284.458/0001-34, at Rua Alferes Frazão, 11, suite 604, Chácara Califórnia, São Paulo, SP, ZIP 03405-050, Brazil.
  • Data Protection Officer and data-subject contact: [email protected].
  • You may request access, correction or deletion, withdraw Radar consent, or object to processing based on legitimate interest, including the Growth and Launch diagnosis forms. See Data Deletion.
  • We respond to data-subject requests through the channel above within 15 days.