ARC–IELP
  • Home
  • How it works
  • Compliance
  • Versión en Español
Legal document

Privacy Notice

ARC–IELP operates under principles of anonymization, aggregation, and individual non-traceability. This document describes how information is managed within the system.

Last updated
15 · 08 · 2026
Contents
  • 1 · Data controller
  • 2 · Nature of information
  • 3 · Processing purposes
  • 4 · Aggregate data use
  • 5 · Data transfers
  • 6 · Your rights
  • 7 · Withdrawal of consent
  • 8 · Data security
  • 9 · Modifications
  • 10 · Contact
  • 11 · International scope
  • 12 · Legal basis & retention (GDPR)
  • 13 · International transfers
  • 14 · Data subject rights (GDPR)
  • 15 · EU representative
  • 16 · Automated decisions
  • 17 · Supervisory authority
← Back to site
Data controller
Zabdiel Alejandro Vázquez González
Legal framework
LFPDPPP · Mexico

Pursuant to the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) of Mexico, Zabdiel Alejandro Vázquez González, acting as operator of the ARC–IELP system, makes available this Privacy Notice. International users interacting with this system acknowledge and accept these terms under Mexican data protection law.

ARC–IELP operates out of Mexico under the LFPDPPP as its base legal framework, and offers its services to organizations outside Mexico. For visitors and clients located in the European Economic Area, sections 11 through 17 of this same notice incorporate the additional safeguards and obligations required by Regulation (EU) 2016/679 (GDPR). This is a single, internationally-scoped Privacy Notice, not two separate documents.

01

Data Controller

Zabdiel Alejandro Vázquez González, self-employed individual with business activity, acting as operator of the ARC–IELP system (hereinafter "THE CONTROLLER").

THE CONTROLLER may, at any time, transfer or assign operation of the ARC–IELP system and processing of information to a commercial entity of which they are a partner, shareholder, founder or ultimate beneficial owner, without altering the purposes of processing or the terms of this notice.
02

Nature of Information Collected

The ARC–IELP system is not designed to collect or process individually identifiable personal data.

The information collected consists of:

  • aggregate organizational responses
  • non-identifiable information
  • data anonymized at source or during processing
  • information that does not allow direct or indirect identification of individuals
Core structural principles
  • Anonymization
  • Aggregation
  • Individual non-traceability

At all times the system operates in accordance with its methodological and ethical framework.

03

Processing Purposes

Information collected will be used for the following purposes:

  • structural analysis of organizational configuration
  • generation of aggregate organizational indicators
  • preparation of executive reports for decision-making
  • continuous improvement of the ARC–IELP system
  • development of analytical and methodological models
  • construction of aggregate, non-identifiable databases
  • generation of comparative analyses and organizational trends
  • development of products, tools or services derived from the system
  • evolution, scaling and future operation of ARC–IELP under different legal structures
Information will never be used for
  • individual evaluation of persons
  • disciplinary decision-making
  • identification of specific employees
04

Aggregate Data Use

THE CONTROLLER may use processed information in aggregate, anonymized and non-identifiable form for statistical, analytical, research, product development and system improvement purposes, including cumulatively over time.

Such information, being non-identifiable, does not constitute personal data under applicable law.

05

Data Transfers

Information may be processed through technological tools, platforms or operational infrastructure necessary for execution of the ARC–IELP system.

Absolute restriction
  • Individually identifiable personal data will never be transferred to third parties

Information may be transferred to related, affiliated or successor entities of THE CONTROLLER, including commercial companies that operate the ARC–IELP system in the future, maintaining the aggregate, anonymized and non-identifiable nature of the information at all times.

Aggregate and anonymized information may be used in comparative analyses or inter-organizational studies without identifying specific persons or organizations.

06

Your Rights

If THE CONTROLLER incidentally collects identifiable personal data (for example, contact details of interlocutors), data subjects may exercise their rights of access, rectification, cancellation or objection under applicable law.

These rights do not apply to information that has been anonymized, aggregated, or that does not permit identification of a natural person.
07

Withdrawal of Consent

Data subjects may request limitation of use or withdrawal of consent with respect to identifiable personal data, where applicable.

However, once information has been subjected to anonymization and aggregation processes, it is no longer considered personal data, and individual deletion or identification will not be possible.

08

Data Security

THE CONTROLLER implements technical and organizational measures aimed at:

  • anonymization of information
  • elimination of individual traceability
  • aggregate processing
  • access control to information
09

Modifications to this Notice

This privacy notice may be modified at any time as a result of legal, operational or system changes, including changes to the legal structure of the system operator.

Any modifications will be available through the official channels of the ARC–IELP system.

10

Contact

For any questions regarding this privacy notice, please contact us through the official channels of the ARC–IELP system.

contact@arc-ielp.com →

11

International Scope

This notice operates under Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), the legal framework of THE CONTROLLER's country of operation. To the extent ARC–IELP offers its services to, or monitors the behavior of, individuals located in the European Economic Area (EEA) — including the European Union — Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"), additionally applies pursuant to its Article 3(2).

Sections 11 through 17 complement, without replacing, sections 1 through 10, and apply specifically to such data subjects.

These provisions do not imply that THE CONTROLLER is established in any EU member state, nor do they make the technology providers referenced in this document joint controllers.
12

Legal Basis for Processing and Retention

Under Article 6 GDPR, each processing purpose relies on the following legal basis:

  • Delivery of the service contracted by the client organization — performance of a contract (Art. 6(1)(b))
  • Responding to information requests and commercial communication — consent (Art. 6(1)(a)) or legitimate interest in the pre-contractual phase (Art. 6(1)(f))
  • Usage analytics via cookies (Google Analytics, Google Ads) — prior user consent (Art. 6(1)(a)), obtained through the site's cookie banner
  • Site performance analytics via Vercel Analytics — legitimate interest (Art. 6(1)(f)), as this tool does not set cookies or collect persistent identifiers (see Cookie Policy)
  • Compliance with tax, accounting or legal obligations — legal obligation (Art. 6(1)(c))

Personal data incidentally collected (e.g., contact details of business interlocutors) is retained only for as long as necessary to fulfill the purpose for which it was collected, for the duration of the business relationship, and, where applicable, for the legally applicable limitation periods. Cookies and similar technologies are retained for the periods listed in the Cookie Policy →.

13

International Data Transfers

ARC–IELP's technical infrastructure relies on providers based in the United States, including Vercel Inc. (website hosting and analytics) and Google LLC (analytics and advertising, subject to consent). These transfers rely, as applicable to each provider, on the European Commission's Standard Contractual Clauses and/or the provider's certification under the EU-U.S. Data Privacy Framework, where the provider participates in it.

Data subjects may request further information on the applicable safeguards through the contact channels in section 10.

14

Data Subject Rights (GDPR)

In addition to the rights described in section 6 under Mexican law, data subjects located in the EEA may exercise the following rights with respect to any personal data THE CONTROLLER incidentally processes:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure / "right to be forgotten" (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR)
  • Withdrawal of consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal (Art. 7(3) GDPR)
  • Not to be subject to a decision based solely on automated processing (Art. 22 GDPR — see section 16)
These rights do not apply to information that has been anonymized, aggregated, or that by its nature does not permit identification of a natural person — under Recital 26 GDPR, such information falls outside the Regulation's scope.

Requests may be submitted through the contact channels in section 10.

15

EU Representative

[PENDING — Name, EU member-state postal address, and contact details of the representative designated under Art. 27 GDPR]

Article 27 GDPR requires controllers without an establishment in the European Union that offer goods or services to individuals located there to designate a representative within a member state. This section will be updated with the designated representative's details once that designation is finalized.
16

Automated Decision-Making and Profiling

The ARC–IELP system does not make decisions based solely on automated processing, including profiling, that produce legal effects concerning a natural person or similarly significantly affect them. The indicators and reports generated are aggregate and organizational in nature, not individual, in line with the core principles described in section 2.

17

Supervisory Authority

Without prejudice to any other administrative or judicial remedy, any data subject located in the EEA has the right to lodge a complaint with the data protection supervisory authority of their habitual residence, place of work, or the place of the alleged infringement, if they consider that the processing of their personal data infringes the GDPR.

The list of EU member-state supervisory authorities is publicly available through the European Data Protection Board (edpb.europa.eu).
Legal framework
LFPDPPP (Mexico) · Regulation (EU) 2016/679 — GDPR (sections 11-17, EEA visitors)
Effective date
Effective as of March 22, 2026. Sections 11-17 (GDPR) added August 15, 2026. Subject to modification as a result of operational or legal changes to the system.
ARC IELP
Organizational Performance Intelligence. Leading indicators, not lagging reports.
Contact contact@arc-ielp.com
  • Privacy · Terms · Privacidad (ES) · Cookies · Cookie preferences
© 2026 ARC–IELP · All rights reserved arc-ielp.com