Legal & Compliance

Privacy Policy

This Privacy Policy explains how Zoho Corporation Brasil Tecnologia Ltda. collects, uses, stores, and protects your personal data when you visit our website or interact with our services. We are committed to handling your information responsibly, transparently, and in full compliance with Brazil's Lei Geral de Proteção de Dados (LGPD — Law No. 13,709/2018), the European Union's General Data Protection Regulation (GDPR), and other applicable privacy frameworks.

Last updated: June 18, 2025

Introduction

Zoho Corporation Brasil Tecnologia Ltda. ("we", "our", or "the Company") is a Brazilian legal entity registered under CNPJ 35.881.833/0001-93, headquartered at Rodovia Jose Carlos Daux SC 401, 4190, Sala 402 Torre A, Saco Grande, Florianópolis — SC, Brazil. We operate this website (the "Site") to provide information about Zoho's software solutions and to facilitate contact between prospective clients and our commercial team.

We understand that when you visit our Site, interact with our content, or submit a contact request, you are placing trust in us. This policy is our promise to be clear about what data we collect, why we collect it, how long we keep it, and what control you have over it. We do not sell personal data. We do not use personal data for purposes incompatible with those stated here.

This document should be read alongside any other notices we display at specific points of data collection, for example, a consent banner at the time you accept cookies, or a disclosure accompanying a contact form. Where any specific notice conflicts with this general policy, the specific notice prevails for that context.

Applicable law: Our primary legal obligations arise under Brazil's LGPD (Lei Geral de Proteção de Dados Pessoais, Law No. 13,709 of August 14, 2018). Where visitors access this Site from within the European Economic Area, the GDPR also applies. We design our data practices to satisfy both frameworks simultaneously.

Information We Collect

We collect personal data only to the extent strictly necessary for the purposes described in this policy. The categories below describe all data we may receive about you, whether you actively provide it or whether it is generated automatically by your interaction with the Site.

2.1 — Data You Provide Directly

When you use any contact form, request a demonstration, subscribe to a newsletter, or send us an inquiry by email, you may provide us with:

  • Full name — to address you personally and manage our communication records.
  • Business email address — our primary channel for responding to your request.
  • Telephone number — if provided, used only to follow up on your inquiry when email is insufficient.
  • Company name and role — helps our team understand your context and recommend appropriate Zoho solutions.
  • Message content — the free-text body of your inquiry, which we retain as part of your correspondence record.
  • Any attachments or additional information — documents or details you choose to include with your message.

Providing this data is entirely voluntary. However, without a valid email address we are unable to respond to your inquiry.

2.2 — Data Collected Automatically

When you browse the Site, our servers and third-party analytics tools automatically receive certain technical information:

  • IP address — recorded by our web server logs for security monitoring and geographic analytics (aggregated only).
  • Browser type, version, and language — used to optimize the Site's rendering for your device.
  • Operating system and device type — desktop, tablet, or mobile, used for responsive design analytics.
  • Referring URL — the page you came from before arriving at this Site, used to understand our traffic sources.
  • Pages visited and time spent — aggregated session data to improve navigation and content.
  • Click interactions and scroll depth — collected via analytics scripts to identify which parts of the Site engage visitors most.
  • Cookie identifiers — see Section 4 for full detail on the cookies we use and how to control them.

2.3 — Data We Do Not Collect

This Site is informational in nature and does not process payments, create user accounts, or collect sensitive personal data as defined by the LGPD (e.g., health data, racial origin, biometric data, political opinions, or data relating to children). If any future feature of the Site requires collecting sensitive data, we will obtain your explicit prior consent and update this policy accordingly.

How We Use Your Information

We process personal data only when we have a recognized legal basis to do so. Under both the LGPD and the GDPR, each processing activity must be justified by one of the lawful bases provided in those statutes. The table below summarizes our principal processing activities, the purpose, and the legal basis we rely upon.

  • Responding to contact form submissions and inquiries. When you reach out to us, we use your contact details to reply, provide the information requested, and follow up as needed. Legal basis: performance of pre-contractual measures at your request (LGPD Art. 7, V; GDPR Art. 6(1)(b)).
  • Sending commercial communications about Zoho products. If you consent to marketing communications — either by checking a box on a form or by opting in via email — we may send you product updates, event invitations, and relevant offers. Legal basis: consent (LGPD Art. 7, I; GDPR Art. 6(1)(a)). You may withdraw consent at any time using the unsubscribe link in any such email.
  • Improving Site performance and user experience. Aggregated analytics data is used to understand how visitors navigate the Site, identify technical problems, and prioritize content improvements. Legal basis: our legitimate interest in maintaining an effective, functional website (LGPD Art. 7, IX; GDPR Art. 6(1)(f)).
  • Security monitoring and fraud prevention. IP addresses and server logs are reviewed to detect unauthorized access attempts, bot traffic, or other threats to the integrity of our systems. Legal basis: legitimate interest and legal obligation (LGPD Art. 7, II and IX; GDPR Art. 6(1)(c) and (f)).
  • Compliance with legal obligations. We may process and retain data as required by Brazilian tax law, corporate regulations, court orders, or requests from competent public authorities. Legal basis: compliance with a legal obligation (LGPD Art. 7, II; GDPR Art. 6(1)(c)).

We will never use your data for purposes that are incompatible with those listed above without giving you prior notice and, where required, obtaining your renewed consent.

No automated decision-making: We do not subject any visitor's personal data to fully automated decisions — including profiling — that produce legal effects or similarly significant impacts on you. All substantive decisions involving your data involve human review.

Cookies & Tracking Technologies

This Site uses cookies and similar technologies (pixel tags, local storage objects) to make the website function correctly and to understand how it is used. A cookie is a small text file placed on your device by a website server. Cookies cannot run programs or deliver viruses; they serve only to identify your device during and between visits.

4.1 — Cookie Categories We Use

Category Purpose Duration Basis
Strictly Necessary Enable core site functions: page navigation, security tokens, load balancing. The site cannot operate without these. Session / up to 1 year Not subject to consent — required for the service
Analytics & Performance Measure traffic volumes, page popularity, and user journeys using Google Analytics 4 (GA4). Data is anonymized at collection. Up to 13 months Consent
Advertising & Remarketing Google Ads conversion tracking and Google remarketing tags allow us to measure ad effectiveness and show relevant Zoho ads on other platforms to previous visitors. Up to 90 days Consent
Functional Remember your language preference and any form pre-fill data you have explicitly saved, improving repeat visit convenience. Up to 12 months Consent

4.2 — Third-Party Cookies

Some cookies are placed by third-party services that appear on our pages. The principal third-party providers whose cookies may be active on this Site include:

  • Google LLC — Google Analytics 4 (analytics), Google Ads conversion tracking, and Google Tag Manager. Google's privacy policy is available at policies.google.com/privacy.
  • Meta Platforms Ireland Ltd. — Facebook Pixel for conversion measurement, if active. Meta's data policy is available at facebook.com/privacy/policy.
  • Zoho Corporation Pvt. Ltd. — Parent-company analytics and CRM tracking scripts for lead management, governed by Zoho's global privacy policy at zoho.com/privacy.html.

We have no direct control over the cookies set by these third parties, but we do control whether their scripts are loaded on this Site. Non-essential third-party scripts load only after you provide cookie consent.

4.3 — Managing Your Cookie Preferences

When you first visit the Site, a consent banner gives you the choice to accept or decline non-essential cookies. You can change your preferences at any time by clicking the "Cookie Settings" link in the footer. You may also control cookies directly through your browser:

  • Chrome: Settings → Privacy and Security → Cookies and other site data
  • Firefox: Preferences → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Manage Website Data
  • Edge: Settings → Privacy, search, and services → Cookies and site permissions

Blocking all cookies may impair certain Site functionality. Blocking strictly necessary cookies is not recommended and may prevent pages from loading correctly.

Google Analytics opt-out: You can prevent Google Analytics from collecting your data across all websites by installing the Google Analytics Opt-out Browser Add-on. We have also enabled IP anonymization on all our GA4 properties, meaning the last octet of your IP address is zeroed before any data is stored by Google.

Sharing With Third Parties

We do not sell, rent, or trade your personal data with third parties for their independent commercial purposes. We may share data in the following limited and specific circumstances:

5.1 — Group Companies

Zoho Corporation Brasil Tecnologia Ltda. is part of the Zoho Corporation group. Lead data and contact inquiry information may be shared internally with Zoho Corporation Pvt. Ltd. (India) and its regional affiliates for the purpose of processing your inquiry, assigning it to the appropriate product team, and providing you with a timely response. All group entities are bound by Zoho's internal data governance standards.

5.2 — Service Providers (Data Processors)

We engage third-party companies to perform services on our behalf. These processors act only on our documented instructions and are contractually prohibited from using your data for any other purpose. Current categories of processors include:

  • Cloud hosting and infrastructure providers — for secure storage of server logs and form submission data.
  • Email delivery services — for sending confirmation emails and follow-up communications in response to your inquiry.
  • CRM and customer support tools — Zoho CRM and Zoho Desk, operated by Zoho Corporation Pvt. Ltd., used to track and respond to inquiries.
  • Web analytics providers — Google Analytics, as detailed in Section 4.
  • Legal and compliance advisors — who may review data as necessary to provide professional advice, subject to professional secrecy obligations.

5.3 — Legal Disclosure

We may disclose personal data if required to do so by law, court order, or governmental authority — including Brazil's National Data Protection Authority (ANPD), the Federal Revenue Service (Receita Federal), or any other competent body acting within its legal mandate. Where permitted, we will notify you of such a request before disclosing your data.

5.4 — Business Transfers

In the event of a merger, acquisition, asset sale, or reorganization involving the Company, personal data held by us may be transferred to the successor entity as part of the transaction. We will provide you with advance notice if your data becomes subject to a different privacy policy as a result of such a transfer, and we will give you a meaningful opportunity to object or delete your data before the transfer takes effect.

5.5 — International Transfers

Because the Zoho group operates globally, some of your data may be processed on servers located outside Brazil — primarily in India and the United States. When we transfer personal data internationally, we ensure an adequate level of protection is in place through one or more of the following mechanisms: data processing agreements incorporating standard contractual clauses; transfers to jurisdictions recognized as adequate by the ANPD; or the recipient's binding corporate rules. You may request a copy of the relevant safeguard documents by contacting us at the address in Section 11.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, to maintain records required by law, and to resolve any disputes or enforce our agreements. The following retention periods reflect our current practice:

  • Contact form submissions and email inquiries: Retained for a maximum of 24 months from the date of last substantive interaction. If the inquiry progresses to a commercial relationship, relevant records are retained for the duration of that relationship plus 5 years (in compliance with Brazilian civil and tax law).
  • Analytics data: Aggregated, anonymized analytics data collected via Google Analytics is retained in GA4 for up to 14 months per our account settings. Raw IP addresses in server logs are retained for a maximum of 90 days before being automatically purged.
  • Cookie consent records: We maintain a log of your consent choice — not the substance of your browsing, but the fact that consent was given or refused and when — for 12 months from the date of each choice, to satisfy our accountability obligations.
  • Legal and compliance records: Any data retained specifically to comply with a legal obligation (e.g., tax records, regulatory filings) is retained for the period mandated by the applicable law, typically 5 to 10 years depending on the nature of the obligation.

When retention periods expire, data is securely deleted or irrevocably anonymized. Where complete deletion is not technically feasible in backup systems, we isolate the data so it cannot be accessed for active processing until the next backup rotation allows for deletion.

Data Security

We take the security of your personal data seriously and implement a layered set of technical and organizational measures designed to protect it against unauthorized access, accidental loss, alteration, or destruction. Our approach includes:

  • Encryption in transit: All data exchanged between your browser and our servers is encrypted using TLS 1.2 or higher. Our HTTPS configuration is kept current and tested regularly.
  • Encryption at rest: Data stored on our servers and in cloud databases is encrypted using AES-256 or equivalent standards.
  • Access controls: Personal data is accessible only to authorized personnel who have a documented need to process it. Access is granted on a least-privilege basis and reviewed quarterly.
  • Internal data handling policies: Our team members who process personal data receive regular training on data protection obligations and are bound by confidentiality obligations.
  • Penetration testing and vulnerability management: Our technical infrastructure is subject to regular vulnerability scans. Critical findings are remediated within defined SLAs.
  • Incident response: We maintain a documented incident response plan. In the event of a data breach that poses a risk to your rights and freedoms, we will notify the ANPD within 72 hours of becoming aware of the incident, and affected individuals will be notified without undue delay, as required by the LGPD.

Important: No method of electronic transmission or storage is 100% secure. While we strive to use commercially reasonable means to protect your personal data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of any credentials you use to interact with our services.

Your Rights

Under the LGPD (Art. 18) and the GDPR (Arts. 15–22), you have a comprehensive set of rights with respect to your personal data. We are committed to honoring these rights promptly and without unnecessary obstacles. Below is a plain-language summary of each right and how it applies to your interactions with us.

Right of Access (Art. 15 GDPR / Art. 18, I–II LGPD)
You may request confirmation that we hold personal data about you, and receive a copy of that data in a clear, structured format, together with details of the purposes, categories, and recipients involved.
Right to Correction (Art. 16 GDPR / Art. 18, III LGPD)
If personal data we hold about you is inaccurate, incomplete, or out of date, you can ask us to correct or supplement it. We will act on valid requests within 15 days.
Right to Deletion / Erasure (Art. 17 GDPR / Art. 18, VI LGPD)
You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent (and no other legal basis applies), or when processing was unlawful. Certain legal retention obligations may prevent complete deletion in all cases.
Right to Object & Restriction (Arts. 18, 21 GDPR / Art. 18, IV LGPD)
You may object to processing based on our legitimate interests, and you may request that we restrict processing while a dispute about accuracy or lawfulness is resolved. You also have an absolute right to object to direct marketing at any time.
Right to Data Portability (Art. 20 GDPR / Art. 18, V LGPD)
Where processing is based on consent or contractual necessity and is carried out by automated means, you may receive your data in a machine-readable format (CSV or JSON) and transmit it to another controller.
Right to Withdraw Consent (Art. 7(3) GDPR / Art. 8, §5 LGPD)
Where we process your data on the basis of consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Right to Information on Sharing (Art. 18, VII LGPD)
You may ask us to identify the public and private entities with which we have shared your personal data. We will provide a specific, itemized response to such requests within the statutory timeframe.
Right to Lodge a Complaint (ANPD / Supervisory Authority)
If you believe we have handled your data unlawfully, you have the right to lodge a complaint with Brazil's ANPD (gov.br/anpd) or, for EEA residents, with your national supervisory authority.

How to Exercise Your Rights

To submit any data rights request, please send an email to contato@zoho-us.site with the subject line "Data Rights Request". Include: (a) your full name; (b) the email address you used when contacting us; (c) a clear description of the right you wish to exercise; and (d) any information that helps us locate your records. We may ask you to verify your identity before processing the request — this is to protect you against unauthorized access to your data.

We will acknowledge your request within 5 business days and provide a substantive response within 15 calendar days (LGPD) or 30 calendar days (GDPR), extendable by a further 30 days in complex cases, with prior notification to you explaining the reason for the extension. All responses are provided free of charge.

Children's Privacy

This Site and the services offered by Zoho Corporation Brasil Tecnologia Ltda. are directed exclusively to businesses and adult professionals. We do not knowingly solicit, collect, or process personal data from individuals under the age of 18.

If we become aware that we have inadvertently collected personal data from a minor without verified parental or guardian consent, we will take immediate steps to delete that data from our records. If you believe a minor may have submitted information through this Site, please contact us immediately at contato@zoho-us.site so that we can investigate and remedy the situation without delay.

Parents or guardians who believe their child's data may have been collected by us also have the right to request access, correction, or deletion of that data in accordance with Section 8 of this policy, acting on the child's behalf.

Changes to This Policy

We review this Privacy Policy at least once a year and update it whenever our data practices change materially — for example, if we introduce new cookies, begin sharing data with a new category of third party, or if the law changes in a way that affects your rights. The "Last updated" date at the top of this page always reflects when the most recent version was published.

For significant changes that materially affect your rights or the way we handle your data, we will provide more prominent notice — such as a banner notification on the Site's home page, or a direct email to anyone whose address we hold — at least 15 days before the changes take effect, giving you time to review the updated terms and, where relevant, to withdraw consent or exercise your rights under the previous terms.

Your continued use of this Site after the effective date of any update constitutes your acknowledgment of the revised policy. If you disagree with any changes, you are free to discontinue using the Site and to request deletion of your data as described in Section 8. Previous versions of this policy are available upon request by contacting us at the address in Section 11.

Version history: The current version of this Privacy Policy was last updated on June 18, 2025. This is the initial published version of the policy for this website. Future revisions will be numbered sequentially (v1.1, v1.2, etc.) for easy reference.

Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data rights, have concerns about how your information is being handled, or need to report a suspected data incident, please get in touch. We aim to respond to all privacy-related communications within 5 business days.

For formal data rights requests, please follow the process described in Section 8. For all other privacy inquiries — including questions about specific cookies, requests for copies of data transfer safeguards, or clarification of our legal bases — the contact details below apply.

Zoho Corporation Brasil Tecnologia Ltda.
CNPJ 35.881.833/0001-93 · Data Controller
Registered Address
Rodovia Jose Carlos Daux SC 401, 4190
Sala 402 Torre A, Saco Grande
Florianópolis — SC, Brazil
Privacy & Data Rights Inquiries
contato@zoho-us.site
Please use the subject line "Privacy Policy Inquiry" or "Data Rights Request" so our team can route your message correctly.
Supervisory Authority (Brazil)
Autoridade Nacional de Proteção de Dados (ANPD)
www.gov.br/anpd

We are committed to working with you to resolve any concerns about your privacy in good faith. If you are not satisfied with our response to a complaint, you have the right to escalate the matter to the ANPD or, if you are located in the EEA, to your local data protection authority, without prejudice to any other administrative or judicial remedies available to you.