Privacy Policy
Last updated: October 22, 2025
WhereInRio Imobiliária Ltda., headquartered in Rio de Janeiro/RJ, registered under CNPJ No. 12.301.766/0001-95 and CRECI J 6820 (hereinafter “WhereInRio” or the “Controller”), in accordance with Law No. 13.709/2018 (LGPD – Brazilian General Data Protection Law), hereby publishes its Privacy Policy, applicable to the website www.whereinrio.com (the “Website”) and related interactions.
This Policy establishes principles, guidelines, and responsibilities regarding the processing of personal data carried out by WhereInRio. It applies to clients, visitors, suppliers, and partners who provide us with data through the Website, emails, forms, applications, contracts, messages, and other online and offline means.
2.1 Data provided by the data subject
Identification: full name; date of birth; CPF (when required); number and copy of identification documents (e.g., ID, driver’s license, passport) when required by law or for a legal transaction.
Contact: email; phone (landline/mobile); postal address.
Real estate profile: interests, preferences, price range, region, and interaction history.
Contracting information: financial and banking data, income and address proof, solely for analysis and contractual purposes or legal compliance.
Sensitive data: as a rule, we do not request sensitive data (art. 5, II, LGPD). In exceptional cases (e.g., biometric element from an ID document), processing will follow art. 11 of the LGPD, with explicit consent and reinforced safeguards.
2.2 Data automatically collected
Device and browsing data: IP address, browser type and version, operating system, screen resolution, language.
Website usage: pages visited, access dates/times, session duration, clicks, and interactions.
Cookies and online identifiers (see Section 10).
Approximate location (country/city) derived from IP.
2.3 Third-party data (where applicable)
We may receive public data or data shared by partners necessary for service execution (e.g., real estate platforms, data validation providers), in compliance with the LGPD and existing agreements.
We process your data to:
WhereInRio processes personal data based on the legal grounds provided in art. 7 of the LGPD, including:
Your data may be shared with:
When necessary, data may be transferred to other countries in compliance with the LGPD and the International Data Transfer Regulation (Resolution CD/ANPD No. 19/2024), through valid mechanisms such as:
Personal data will be kept:
You may, at any time and upon request, exercise your rights under the LGPD, including:
confirmation, access, correction, anonymization, portability, deletion, information on sharing, opposition, consent withdrawal, and review of automated decisions.
Contact channel: info@whereinrio.com
We adopt adequate technical and administrative measures — encryption, HTTPS, access control, log management, backups, environment segregation, testing, and training — to protect data from unauthorized access, loss, alteration, or disclosure.
If a security incident occurs that may cause risk or significant harm to data subjects, we will notify the ANPD and the affected individuals, in accordance with art. 48 of the LGPD and Resolution CD/ANPD No. 15/2024.
We use cookies for site functionality, analytics, and personalization.
We may modify this Policy to reflect legal, regulatory, or operational changes. The latest version will always be available on the Website. For material changes, we will display a notice and, when applicable, notify registered users by email.
Email: info@whereinrio.com
Address: Rua Farme de Amoedo, nº 80B, Ipanema, Rio de Janeiro-RJ, 22420-020.
Our services are not intended for children (under 12 years old), and we do not knowingly collect their data. If we identify any processing involving children or adolescents, we will ensure the child’s best interest and obtain parental consent when required, as provided in art. 14 of the LGPD.