Scope
This policy applies to data collected at heydomus.com and any subdomain operated by Strategy Labs LLC, when you sign up for an account, browse the marketing site, or use the Domus platform.
When your community (org) uses Domus to host its own data (member records, donations, etc.), that organization is the data controller and its own privacy policy applies. Domus is the processor.
Data we collect
We collect:
- Account data: name, email, organization, role, country — whatever you submit on the waitlist form or sign-up flow.
- Usage data: anonymous metrics about how the site is used (pages viewed, broad geography). We use this to improve the product.
- Communications: messages you send us via WhatsApp, email or in-app chat — kept as long as needed to support you.
- Cookies: a minimal set for authentication and basic analytics. We do not run advertising trackers.
Why we use it
- To operate, secure, and improve the Domus service.
- To reach out about your account, the waitlist, or important changes.
- To comply with law (taxes, fraud prevention, lawful requests).
We do not sell your data, share it with advertisers, or use it to train third-party AI models.
Your rights
Wherever you are, you can:
- Ask for a copy of the data we hold about you.
- Ask us to correct or delete it.
- Withdraw any consent you've given.
- File a complaint with your local data protection authority (ANPD in Brazil, AEPD in Spain, etc.).
For LGPD (Brazil) and GDPR (EU/UK) requests, email legal@heydomus.com. We respond within 30 days.
How long we keep data
We retain account data for as long as the account is active, plus up to 60 days after deletion for backups and lawful obligations. Anonymized usage metrics may be kept indefinitely.
International transfers
Strategy Labs LLC is incorporated in Delaware, United States. Data may be processed in the US, EU and Brazil through reputable infrastructure providers (Vercel, Neon, Cloudflare). We rely on standard contractual clauses where required.
Subprocessors
We rely on the following third parties to run the service:
- Vercel (hosting / CDN) — United States.
- Neon (Postgres database) — São Paulo, Brazil region.
- Resend (transactional email) — United States.
- Cloudflare (DNS, edge) — global.
This list may evolve. Material changes go in the changelog at the bottom of this page.
Security
All traffic is TLS-encrypted. Passwords are hashed with industry-standard algorithms. Internal access to customer data follows the principle of least privilege and is logged.
No system is 100% secure. We disclose breaches affecting your data within 72 hours as required by GDPR/LGPD.
Children's data
Domus is not aimed at children under 13. If your community operates ministries for minors, you're responsible for obtaining parental consent before storing data in Domus.
Changes to this policy
We notify account owners at least 30 days before any material change. The date at the top of this page is always current.
Contact
Questions or requests: legal@heydomus.com
Strategy Labs LLC, Delaware, United States.