Trejo Gutiérrez Abogados, S.C.
Date of last update: 21 september 2026
I. IDENTITY AND ADDRESS OF THE DATA CONTROLLER
In compliance with the Federal Law on Protection of Personal Data Held by Private Parties (the “LFPDPPP”), its Regulations, and the Privacy Notice Guidelines issued by the National Institute of Transparency, Access to Information, and Personal Data Protection (the “INAI”), Trejo Gutiérrez Abogados, S.C., with domicile at Pablo Quiroga 3614, Torres de Satélite, Monterrey, Nuevo León, C.P. 64950, México, RFC (Federal Taxpayer Registry number) TGA210128GL6 and website https://trejogutierrez.com, hereby makes available to Data Subjects this Comprehensive Privacy Notice.
The Data Controller is a [legal entity/individual] incorporated under the laws of the United Mexican States and engaged in the development, commercialization, distribution, and support of software solutions (the “Software” or the “Services”).
II. PERSONAL DATA COLLECTED
For the purposes set forth in this Privacy Notice, the Data Controller may collect the following categories of personal data:
a) Identification data
- – Full name
- – Date of birth
- – Nationality
- – Photographic image (where applicable, for user profile)
- – Unique Population Registry Code (CURP), where applicable
b) Contact data
- – Email address
- – Landline and/or mobile telephone number
- – Mailing address
c) Employment or professional data
- – Name of the company or organization to which the individual belongs
- – Position or title
- – Area or department
d) Financial and billing data
- – Banking data (account number, CLABE interbank code, banking institution)
- – Tax data: RFC (Federal Taxpayer Registry number), corporate or business name, tax regime, tax domicile, tax zip code
- – Credit or debit card data (processed through secure payment gateways; the Data Controller does not directly store card data)
- – Tax Status Certificate, where applicable
e) Software usage and technical data
- – Username and access credentials (encrypted password)
- – Activity logs within the Software (usage logs)
- – IP address
- – Device type, model, and operating system
- – Browser type and version
- – Approximate geolocation data (derived from the IP address)
- – Browsing data, pages visited, session duration, and usage patterns
- – Unique device identifiers
f) Technical support data
- – Incident records and support requests
- – Content of communications with the support team (emails, chats, recorded calls, where applicable)
- – Screenshots or other information voluntarily provided for incident resolution
Sensitive personal data
The Data Controller hereby informs that, as a general rule, it does not collect sensitive personal data as defined in Article 3, Section VI, of the LFPDPPP. Notwithstanding the foregoing, in the event that, due to the nature of the Services or a specific requirement, it becomes necessary to collect sensitive personal data (such as health data, racial or ethnic origin, religious beliefs, union membership, political opinions, sexual preference, biometric data, among others), the Data Controller shall do so only upon the express written consent of the Data Subject, through specific mechanisms that will be made available for such purpose.
III. PURPOSES OF PROCESSING
The personal data collected shall be processed for the following purposes:
a) Primary purposes (necessary for the legal relationship)
The following purposes are necessary and give rise to the legal relationship between the Data Subject and the Data Controller:
- – Creation, administration, and management of user accounts in the Software.
- – Provision, operation, and maintenance of the contracted Software Services.
- – Identity verification and user authentication.
- – Payment processing, invoicing, collection, and subscription management.
- – Fulfillment of contractual obligations arising from the terms and conditions of use, license agreements, or service agreements.
- – Provision of technical support, incident management, and troubleshooting.
- – Sending service-related notifications, Software updates, security alerts, and operational communications.
- – Compliance with applicable legal, tax, and regulatory obligations.
- – Processing of ARCO Rights exercise requests and requests from competent authorities.
b) Secondary purposes (not necessary for the legal relationship)
Additionally, and subject to the prior consent of the Data Subject, the personal data may be processed for the following purposes that are not necessary for the legal relationship, but which allow the Data Controller to improve its services and offer a better user experience:
- – Marketing, advertising, and commercial prospecting.
- – Sending newsletters, promotions, offers, and commercial communications regarding products and services of the Data Controller or of third parties with which it has commercial relationships.
- – Conducting satisfaction surveys and market research.
- – Preparation of statistical analyses, usage profiles, and user behavior studies for the improvement of the Services.
- – Content personalization and recommendations within the Software.
- – Participation in loyalty programs, contests, or promotions
In the event that the Data Subject does not wish his or her personal data to be processed for the aforementioned secondary purposes, said Data Subject may express his or her objection in accordance with the mechanism described in Section IV of this Privacy Notice. The refusal to allow the use of your personal data for secondary purposes shall not constitute grounds for denying you the services and products that you request or contract with us.
IV. MECHANISM TO OBJECT TO SECONDARY PURPOSE PROCESSING
The Data Subject may express his or her objection to the processing of personal data for the secondary purposes set forth in Section III, subsection (b), primarily through the means established in Section XIII of this privacy notice.
The Data Controller shall have a maximum period of twenty (20) business days, counted from the date on which the request is received, to communicate the determination to the Data Subject. If the request is deemed appropriate, it shall become effective within the fifteen (15) business days following the communication of the response.
V. PERSONAL DATA TRANSFERS
The Data Controller may transfer the personal data of the Data Subject to third parties, whether domestic or international, under the following terms and conditions:
a) Transfers requiring consent (Article 36 of the LFPDPPP)
The Data Controller may transfer personal data to the following third parties, for the purposes indicated below, requiring the consent of the Data Subject:
- – Corporate group companies: For internal administrative purposes, customer management, and service improvement.
- – Business partners and strategic allies: For the offering of complementary products and services, subject to the prior consent of the Data Subject.
b) Transfers not requiring consent (Article 37 of the LFPDPPP)
The Data Controller may transfer personal data without the consent of the Data Subject in the following circumstances provided for by the LFPDPPP:
- – Cloud service providers (hosting and infrastructure): For the storage, processing, and backup of data necessary for the operation of the Software. These providers may be located outside the national territory.
- – Payment processors: For the processing of payment transactions and fraud prevention.
- – Competent authorities: When the transfer is necessary for the fulfillment of legal obligations, judicial resolutions, requests from competent authorities, or for the recognition, exercise, or defense of a right in judicial proceedings.
- – Controlling companies, subsidiaries, or affiliates: Under the common control of the same group, or to a parent company or any company of the same group as the Data Controller that operates under the same internal processes and policies, pursuant to Article 37, Section II, of the LFPDPPP.
The Data Controller undertakes that personal data transfers shall be carried out in accordance with the principles and provisions of the LFPDPPP, and that the receiving third parties shall assume the same personal data protection obligations applicable to the Data Controller.
VI. MEANS AND PROCEDURE TO EXERCISE ARCO RIGHTS
The Data Subject, or his or her duly accredited legal representative, has the right to exercise at any time his or her ARCO Rights (Access, Rectification, Cancellation, and Opposition), pursuant to Articles 28 through 35 of the LFPDPPP.
a) Definition of ARCO Rights
- – Access: To know what personal data we hold in our databases, how we use it, and the conditions of processing.
- – Rectification: To request the correction of personal data in the event that it is inaccurate, incomplete, or not up to date.
- – Cancellation: To request the deletion of personal data from our databases when the Data Subject considers that it is not being processed in accordance with the principles, duties, and obligations of the LFPDPPP.
- – Opposition: To object to the processing of personal data with respect to a specific purpose.
b) Procedure to exercise ARCO Rights
To exercise any of the ARCO Rights, the Data Subject or his or her legal representative shall submit a request (hereinafter, the “ARCO Request”). The Data Subject may initiate the process directly through the means established in Section XIII of this privacy notice.
c) Requirements for the ARCO Request (Article 29 of the LFPDPPP)
The ARCO Request shall contain, at a minimum, the following information:
- – Full name of the Data Subject and, where applicable, of the legal representative.
- – Domicile or other means for communicating the response to the request.
- – Copy of a valid official identification document of the Data Subject (voter identification card, passport, professional license, or equivalent document) and, where applicable, of the legal representative, together with the document evidencing the representation.
- – Clear and precise description of the personal data with respect to which the exercise of any of the ARCO Rights is sought.
- – Any other element or document that facilitates the location of the personal data.
- – In the case of rectification requests, the Data Subject shall indicate the modifications to be made and provide the documentation supporting the request.
d) Response deadlines
The Data Controller shall communicate to the Data Subject the determination adopted with respect to the ARCO Request within a maximum period of twenty (20) business days, counted from the date on which the complete request was received. If the request is deemed appropriate, the Data Controller shall implement it within the fifteen (15) business days following the date on which the response is communicated (Article 32 of the LFPDPPP).
The aforementioned deadlines may be extended once, for an equal period, provided that the circumstances of the case so justify, in accordance with Article 32 of the LFPDPPP.
e) Right to file a complaint with INAI
In the event that the Data Subject considers that his or her right to personal data protection has been violated by any conduct of the Data Controller, or presumes that in the processing of his or her personal data there exists a violation of the provisions set forth in the LFPDPPP and other applicable regulations, the Data Subject may file the corresponding complaint or report with the INAI. For further information, visit www.inai.org.mx or call 800 835 4324 (TELINAI).
VII. MECHANISMS AND PROCEDURES TO REVOKE CONSENT
The Data Subject may revoke the consent granted to the Data Controller for the processing of personal data, pursuant to Article 8 of the LFPDPPP and Article 21 of its Regulations, provided that no legal provision prevents such revocation.
To revoke consent, the Data Subject shall submit a request through the same means indicated in Section VI, subsection (b), of this Privacy Notice, clearly and precisely indicating:
- – Full name and identification data.
- – The express manifestation of the intent to revoke consent for the processing of personal data.
- – The specific personal data and/or purposes with respect to which consent is to be revoked.
- – Copy of a valid official identification document.
The Data Controller shall communicate the determination to the Data Subject within a maximum period of twenty (20) business days, counted from the receipt of the request. If the request is deemed appropriate, the revocation shall become effective within the following fifteen (15) business days.
It is important to note that the revocation of consent shall not have retroactive effects, pursuant to Article 8 of the LFPDPPP. Furthermore, it should be considered that for certain purposes, the revocation of consent shall result in the Data Controller being unable to continue providing the requested service, or in the termination of the contractual relationship.
VIII. OPTIONS AND MEANS TO LIMIT THE USE OR DISCLOSURE OF PERSONAL DATA
In order that the Data Subject may limit the use and disclosure of personal data, the Data Controller makes the following mechanisms available:
- – Exclusion list: The Data Subject may request registration on the Data Controller’s exclusion list to stop receiving commercial, advertising, or marketing communications, by sending an email to [Email for ARCO rights] with the subject line “Exclusion list”.
- – Preference settings: Through the privacy settings section within the Software, the Data Subject may manage communication preferences and limit the processing of certain data.
- – Public Registry to Avoid Advertising (REPEP): The Data Subject may register his or her telephone number with the REPEP of the Federal Consumer Protection Agency (PROFECO) to avoid receiving telephone advertising. For further information, visit www.repep.profeco.gob.mx.
IX. USE OF COOKIES, WEB BEACONS, AND TRACKING TECHNOLOGIES
The Data Controller hereby informs that on its website, digital platforms, and/or Software, it uses cookies, web beacons, tracking pixels, and other similar tracking technologies (hereinafter, the “Tracking Technologies”) to enhance the user experience, analyze browsing behavior, and personalize the services.
a) Types of technologies used
- – Essential or technical cookies: Necessary for the operation of the website and the Software, including user authentication, session management, and security.
- – Performance and analytics cookies: Enable the collection of information on how users interact with the Software and the website, in order to improve their operation and performance.
- – Functionality cookies: Enable the remembering of user preferences (language, region, interface settings) to offer a personalized experience.
- – Advertising and marketing cookies: Used to display relevant advertisements to the user and measure the effectiveness of advertising campaigns.
- – Web beacons and tracking pixels: Technologies that allow monitoring user behavior on the website and in emails sent by the Data Controller.
b) Data obtained
Through the Tracking Technologies, the following data may be obtained:
- – IP address and approximate geographic location.
- – Browser type, language, and operating system.
- – Pages visited, time spent, browsing flows, and usage patterns.
- – Date and time of access.
- – Referring website (referrer).
- – Unique session and device identifiers.
c) How to disable tracking technologies
The Data Subject may disable or manage the use of cookies and tracking technologies through the following mechanisms:
- – Browser settings: Most browsers allow managing, blocking, or deleting cookies through their settings or preferences menu.
- – Cookie banner and settings: Upon entering the website, a cookie banner will be displayed through which the Data Subject may manage preferences, as well as accept or reject non-essential cookies. The Data Subject may modify preferences at any time through the cookie settings link available in the footer of the website.
It is important to note that disabling certain essential cookies may affect the functionality of the Software or the website, preventing access to certain features or services.
X. AMENDMENTS TO THE PRIVACY NOTICE
The Data Controller reserves the right to make, at any time, amendments or updates to this Privacy Notice, whether due to new legislative or regulatory requirements, business needs, changes in privacy practices, or any other cause, in accordance with the provisions of Article 19 of the Regulations of the LFPDPPP.
The Data Controller shall notify the Data Subject of any material change to this Privacy Notice through the following means:
- – Publication on the website: The updated version of the Privacy Notice will be available at [Website]/privacy-notice.
- – Email: A notification shall be sent to the email address registered by the Data Subject, informing of the amendments made.
- – In-Software notification: A notice or notification may be displayed within the Software platform upon user login.
The date of last update shall be visible at the top of this page. The Data Subject is advised to periodically review this Privacy Notice on the Data Controller’s website to remain informed of any changes.
XI. CONSENT
In accordance with Articles 8 and 9 of the LFPDPPP, consent for the processing of personal data may be:
- – Tacit: Obtained when, having made this Privacy Notice available to the Data Subject, said Data Subject does not express opposition to the processing of personal data. In particular, browsing the website, creating an account, or using the Software shall constitute tacit consent pursuant to this Privacy Notice.
- – Express: For the processing of financial or patrimonial data, as well as sensitive personal data (in the event that such data is collected), the Data Controller shall obtain express consent through checkboxes or acceptance pop-ups in the corresponding forms.
By browsing this website, registering an account, or using our services, you acknowledge having read and understood this Privacy Notice and consent to the processing of your personal data in accordance with the terms described herein.
XII. APPLICABLE LAW AND JURISDICTION
This Privacy Notice is governed by the provisions of the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), its Regulations, the Privacy Notice Guidelines, and other applicable regulations of the United Mexican States.
For any dispute arising from this Privacy Notice, the parties submit to the jurisdiction of the competent courts of Mexico City, waiving any other jurisdiction that may correspond to them by reason of their present or future domicile.
XIII. CONTACT DETAILS OF THE PERSONAL DATA PROTECTION DEPARTMENT
For any questions, clarifications, or comments related to this Privacy Notice, the processing of your personal data, or the exercise of your rights, the Data Subject may contact the Personal Data Protection Department of the Data Controller through:
- – Email: contacto@trejogutierrez.com
- – Telephone: +52-81-1022-3480
- – Address: Pablo Quiroga 3614, Torres de Satélite, Monterrey, Nuevo León, C.P. 64950, México.
- – Website: https://trejogutierrez.com
- – Business hours: 10:00 AM – 4:00 PM, Monday to Friday