Pursuant to the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) of Mexico, Zabdiel Alejandro Vázquez González, acting as operator of the ARC–IELP system, makes available this Privacy Notice. International users interacting with this system acknowledge and accept these terms under Mexican data protection law.
ARC–IELP operates out of Mexico under the LFPDPPP as its base legal framework, and offers its services to organizations outside Mexico. For visitors and clients located in the European Economic Area, sections 11 through 17 of this same notice incorporate the additional safeguards and obligations required by Regulation (EU) 2016/679 (GDPR). This is a single, internationally-scoped Privacy Notice, not two separate documents.
Data Controller
Zabdiel Alejandro Vázquez González, self-employed individual with business activity, acting as operator of the ARC–IELP system (hereinafter "THE CONTROLLER").
Nature of Information Collected
The ARC–IELP system is not designed to collect or process individually identifiable personal data.
The information collected consists of:
- aggregate organizational responses
- non-identifiable information
- data anonymized at source or during processing
- information that does not allow direct or indirect identification of individuals
- Anonymization
- Aggregation
- Individual non-traceability
At all times the system operates in accordance with its methodological and ethical framework.
Processing Purposes
Information collected will be used for the following purposes:
- structural analysis of organizational configuration
- generation of aggregate organizational indicators
- preparation of executive reports for decision-making
- continuous improvement of the ARC–IELP system
- development of analytical and methodological models
- construction of aggregate, non-identifiable databases
- generation of comparative analyses and organizational trends
- development of products, tools or services derived from the system
- evolution, scaling and future operation of ARC–IELP under different legal structures
- individual evaluation of persons
- disciplinary decision-making
- identification of specific employees
Aggregate Data Use
THE CONTROLLER may use processed information in aggregate, anonymized and non-identifiable form for statistical, analytical, research, product development and system improvement purposes, including cumulatively over time.
Such information, being non-identifiable, does not constitute personal data under applicable law.
Data Transfers
Information may be processed through technological tools, platforms or operational infrastructure necessary for execution of the ARC–IELP system.
- Individually identifiable personal data will never be transferred to third parties
Information may be transferred to related, affiliated or successor entities of THE CONTROLLER, including commercial companies that operate the ARC–IELP system in the future, maintaining the aggregate, anonymized and non-identifiable nature of the information at all times.
Aggregate and anonymized information may be used in comparative analyses or inter-organizational studies without identifying specific persons or organizations.
Your Rights
If THE CONTROLLER incidentally collects identifiable personal data (for example, contact details of interlocutors), data subjects may exercise their rights of access, rectification, cancellation or objection under applicable law.
Withdrawal of Consent
Data subjects may request limitation of use or withdrawal of consent with respect to identifiable personal data, where applicable.
However, once information has been subjected to anonymization and aggregation processes, it is no longer considered personal data, and individual deletion or identification will not be possible.
Data Security
THE CONTROLLER implements technical and organizational measures aimed at:
- anonymization of information
- elimination of individual traceability
- aggregate processing
- access control to information
Modifications to this Notice
This privacy notice may be modified at any time as a result of legal, operational or system changes, including changes to the legal structure of the system operator.
Any modifications will be available through the official channels of the ARC–IELP system.
Contact
For any questions regarding this privacy notice, please contact us through the official channels of the ARC–IELP system.
International Scope
This notice operates under Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), the legal framework of THE CONTROLLER's country of operation. To the extent ARC–IELP offers its services to, or monitors the behavior of, individuals located in the European Economic Area (EEA) — including the European Union — Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"), additionally applies pursuant to its Article 3(2).
Sections 11 through 17 complement, without replacing, sections 1 through 10, and apply specifically to such data subjects.
Legal Basis for Processing and Retention
Under Article 6 GDPR, each processing purpose relies on the following legal basis:
- Delivery of the service contracted by the client organization — performance of a contract (Art. 6(1)(b))
- Responding to information requests and commercial communication — consent (Art. 6(1)(a)) or legitimate interest in the pre-contractual phase (Art. 6(1)(f))
- Usage analytics via cookies (Google Analytics, Google Ads) — prior user consent (Art. 6(1)(a)), obtained through the site's cookie banner
- Site performance analytics via Vercel Analytics — legitimate interest (Art. 6(1)(f)), as this tool does not set cookies or collect persistent identifiers (see Cookie Policy)
- Compliance with tax, accounting or legal obligations — legal obligation (Art. 6(1)(c))
Personal data incidentally collected (e.g., contact details of business interlocutors) is retained only for as long as necessary to fulfill the purpose for which it was collected, for the duration of the business relationship, and, where applicable, for the legally applicable limitation periods. Cookies and similar technologies are retained for the periods listed in the Cookie Policy →.
International Data Transfers
ARC–IELP's technical infrastructure relies on providers based in the United States, including Vercel Inc. (website hosting and analytics) and Google LLC (analytics and advertising, subject to consent). These transfers rely, as applicable to each provider, on the European Commission's Standard Contractual Clauses and/or the provider's certification under the EU-U.S. Data Privacy Framework, where the provider participates in it.
Data subjects may request further information on the applicable safeguards through the contact channels in section 10.
Data Subject Rights (GDPR)
In addition to the rights described in section 6 under Mexican law, data subjects located in the EEA may exercise the following rights with respect to any personal data THE CONTROLLER incidentally processes:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure / "right to be forgotten" (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal (Art. 7(3) GDPR)
- Not to be subject to a decision based solely on automated processing (Art. 22 GDPR — see section 16)
Requests may be submitted through the contact channels in section 10.
EU Representative
[PENDING — Name, EU member-state postal address, and contact details of the representative designated under Art. 27 GDPR]
Automated Decision-Making and Profiling
The ARC–IELP system does not make decisions based solely on automated processing, including profiling, that produce legal effects concerning a natural person or similarly significantly affect them. The indicators and reports generated are aggregate and organizational in nature, not individual, in line with the core principles described in section 2.
Supervisory Authority
Without prejudice to any other administrative or judicial remedy, any data subject located in the EEA has the right to lodge a complaint with the data protection supervisory authority of their habitual residence, place of work, or the place of the alleged infringement, if they consider that the processing of their personal data infringes the GDPR.