← Back to Home

PRIVACY POLICY

COMPREHENSIVE PRIVACY NOTICE FOR CLIENTS, PROSPECTS, AND COMMERCIAL PARTNERS



COMPREHENSIVE PRIVACY NOTICE

I. Identity and Domicile of the Data Controller

The entity responsible for the processing, safeguarding, and protection of your personal data is AA INTELLIGENCE GROUP, LLC (hereinafter referred to as the “Data Controller”), a company incorporated under the laws of the State of Wyoming, United States of America, with its central corporate domicile located at 2 S Biscayne Blvd Ste 3200 - 5483 MIAMI, FL 33131, USA, and which, in order to fully comply with the laws of the United Mexican States, designates as its digital department legal@aaintelligence.tech to hear and receive notices and service of process within Mexican territory.

The Data Controller is committed to ensuring that the processing of all information concerning an identified or identifiable individual placed under its custody is carried out in strict compliance with the principles of legality, consent, notice, quality, purpose, loyalty, proportionality, and accountability established in Article 5 of the Federal Law on the Protection of Personal Data Held by Private Parties (hereinafter referred to as the “LFPDPPP” or the “Law”), its Regulations, and in accordance with the active enforcement guidelines issued by the Secretariat of Anticorruption and Good Government (SABG).


II. Categories of Personal Data Subject to Processing

In order to fulfill the purposes described in this notice, the Data Controller will collect and process the following categories of personal data from the data subject (hereinafter referred to as the “Data Subject”), under a criterion of minimization and proportionality, expressly refraining from collecting data of a sensitive nature unless authorized by the Law under specific exceptions:

  1. Identification and Contact Data: Full name (or corporate name in the case of represented legal entities), handwritten or digital signature, digital copy of a valid official identification (voter ID card [INE], passport, or professional license), Federal Taxpayer Registry (RFC), Unique Population Registry Code (CURP), date of birth, nationality, email address, physical address (residential or tax address), and telephone numbers (landline and mobile).
  2. Financial and Patrimonial Data (Recurring Charges Processing): Standardized Banking Code (CLABE), active bank account number, credit or debit card number, expiration date, security code (CVV - which is not directly stored by the Data Controller but processed securely through payment gateways under the PCI-DSS standard), billing information (Tax Status Certificate - Constancia de Situación Fiscal issued by the SAT), and transaction history of subscription or maintenance payments.
  3. Commercial Prospecting and Negotiation Data: Professional data of the Data Subject, legal representatives, or technical liaisons (job title, position, company, representation authority pursuant to a power of attorney), as well as data contained in non-disclosure agreements (NDA), letters of intent (LOI), financial proposals, and minutes of formal commercial negotiation meetings.
  4. Navigation Data and Electronic Records: IP address, type of web browser used, operating system, language preference, session cookies, web beacons, technical API call logs, timestamps, and metadata of the Data Subject’s digital behavior within our platforms or website.

III. Purposes of the Processing of Personal Data

The information collected by the Data Controller will be processed solely for the purposes informed in this notice. It is strictly prohibited to process personal data for compatible or analogous purposes not declared in this instrument, in accordance with the express prohibition of the legislation in force, unless additional express consent is obtained from the Data Subject.

  1. Identification and Commercial Negotiation: To verify the identity of the Data Subject, representative, or entity, and validate the authenticity of the documents presented in order to evaluate, prospect, and formalize alliances, commercial associations, and business relationships, including but not limited to the execution of non-disclosure agreements (NDAs) to hold formal legal negotiation meetings.
  2. Contractual Basis: To draft, formalize, and execute service agreements, software terms of use, service level agreements (SLAs), or subscription and maintenance contracts that provide a legal basis for the commercial relationship between the parties.
  3. Service Provision and Maintenance: To manage, provide, maintain, and optimize the software services, technological tools, digital solutions, or products contracted by the Data Subject.
  4. Recurring Payments and Collection Management: To process and automate the recurring charges corresponding to the contracted subscription or maintenance policy, as well as to manage refunds, charge clarifications, and administrative collection procedures.
  5. Tax Billing: To issue the corresponding Digital Tax Receipts via Internet (CFDI) for commercial transactions in strict compliance with the provisions of the Tax Administration Service (Servicio de Administración Tributaria - SAT) in Mexico.
  6. Technical Support and Customer Care: To address technical support requests, resolve access issues, answer corporate inquiries, and process complaints or suggestions.
  7. Security and Prevention: To prevent electronic fraud, identity theft, or unauthorized use of the Data Controller’s intellectual property, as well as to ensure the security of electronic platforms and information systems.
  8. Legal Compliance: To comply with tax mandates, audits, inspections by Mexican or international regulatory authorities (including anti-money laundering regulations), and any other applicable legal framework.
  1. Marketing and Promotion: To send, directly or through authorized third parties, advertisements, special offers, newsletters, regulatory updates, or invitations to seminars and events organized by the Data Controller.
  2. Quality Evaluation: To conduct satisfaction surveys or market studies to evaluate the quality of the digital solutions and customer care provided.

Mechanism to Refuse Processing for Secondary Purposes: The Data Subject has the right to refuse the processing of their data for secondary purposes. If the data is obtained indirectly, the Data Subject has a period of 5 (five) business days to manifest their refusal by sending an email to the Data Controller’s Privacy Officer at: legal@aaintelligence.tech. Furthermore, at any time, the Data Subject may revoke their consent for these secondary purposes through the procedure established in Section V of this Notice.


IV. Transfer and Remission of Personal Data

The Data Controller covenants not to sell, rent, or transfer the personal information of the Data Subject to third parties unaffiliated with its operations without obtaining explicit authorization. However, in accordance with Article 36 of the Law, the data may be shared with the following national or international entities without requiring the consent of the Data Subject, as they fall under the exceptions provided by the applicable legal framework:

  1. Companies within the Same Corporate Group: Parent companies, subsidiaries, affiliates, or associates under the common control of AA INTELLIGENCE GROUP, LLC that operate under the same personal data protection policies, procedures, and standards, for purposes of system consolidation, corporate support, internal audit, and information backup on centralized servers.
  2. Mexican Judicial, Tax, or Administrative Authorities: Federal agencies such as the Tax Administration Service (SAT), the Secretariat of Finance and Public Credit (SHCP), or the corresponding jurisdictional bodies in Mexican territory, when the transfer is required by law, a founded and motivated administrative resolution, or for the prosecution and administration of justice.
  3. Technology Service Providers (Remission to Data Processors): The Data Controller utilizes cloud infrastructure services (e.g., Hostinger, AWS, Google Cloud), recurring payment processing (e.g., Stripe or Mercado Pago), and corporate email platforms whose physical servers are located outside of the United Mexican States (mainly in the United States of America and the European Union). Such communications constitute data remissions (remisiones de datos) pursuant to the Regulations of the Law, and therefore do not require the consent of the Data Subject. It is guaranteed that these remissions are executed under specific Data Processing Agreements (DPA) that contractually bind the providers to process the data solely and exclusively to comply with the instructions of the Data Controller, maintaining technical security and confidentiality measures equivalent to those provided in this notice.

1. Definition of Rights

You, in your capacity as Data Subject, or through your duly accredited legal representative, possess the following fundamental rights under Mexican law:

2. Submission Channel and Application Requirements

To exercise any of the ARCO Rights or to revoke previously granted consent, the Data Subject or their legal representative must send a formal written request to the Data Controller’s Privacy Officer at: legal@aaintelligence.tech.

To validate its processing, the ARCO request must mandatorily contain and include:

  1. The full name of the Data Subject, complete address, or other means (such as an email address) to communicate the response.
  2. A digitized copy of the documents proving the identity of the Data Subject (voter ID [INE], Passport, or Professional License). If acting through a legal representative, a copy of the document proving the identity of the representative must be attached, as well as the public instrument (power of attorney) or a power of attorney letter signed before two witnesses that demonstrates their representation authority beyond doubt.
  3. A clear, precise, and concise description of the ARCO right to be exercised and the specific personal data on which the request is made (in the case of Rectification, the applicant must also indicate the modifications to be made and attach supporting documents justifying the change).
  4. Any other element or document that facilitates the location of the personal data within the Data Controller’s systems.

The Data Controller will process and resolve requests in accordance with the following mandatory timelines dictated by federal law:

4. Technical Blocking Period Protocol

The Data Subject understands that, in the event of exercising the right of Cancellation, the data cannot be immediately erased from the physical servers or cloud systems. Pursuant to Article 21 of the Law, the Data Controller will implement a mandatory technical Blocking Period.

During this period, the Data Subject’s data will be completely dissociated from the ordinary and commercial operations of the company, remaining isolated and safeguarded with robust security measures solely to respond to potential civil, commercial, or tax liabilities (such as the 5-year accounting retention period required by Article 30 of the Mexican Federal Tax Code or the 10-year retention period for commercial contracts established in Article 46 of the Mexican Code of Commerce). Once the statute of limitations for these legal liabilities has expired, the Data Controller will proceed with the logical, physical, and irreversible erasure of the information from its servers.


VI. Means to Limit the Use or Disclosure of Your Personal Data

In order to offer alternative and free options for the Data Subject to voluntarily restrict the disclosure or use of their data for accessory purposes, the Data Controller offers the following mechanisms:

  1. Direct Unsubscribe Link: All electronic communications of a commercial, promotional, or advertising nature sent by the Data Controller incorporate an automated unsubscribe link at the footer of the email, allowing the Data Subject to immediately suspend the receipt of advertising campaigns.
  2. Internal Exclusion Lists: The Data Subject may request formal registration in the Data Controller’s “Advertising Exclusion List” by sending an email to legal@aaintelligence.tech, indicating their desire not to be contacted for marketing purposes.
  3. Public State Registries (REPEP and REUS): The Data Subject is informed of the existence of legal tools independent of the Data Controller to limit commercial or telephone advertising, such as the Public Registry to Avoid Advertising (REPEP) administered by the Federal Consumer Protection Agency (PROFECO) or the Public Registry of Users (REUS) of the National Commission for the Protection and Defense of Financial Services Users (CONDUSEF).

VII. Use of Cookies and Automated Tracking Technologies

The Data Controller uses cookies, web beacons, and other technical navigation metadata on its web portals and software platforms to manage sessions, remember configurations, personalize user experience, and compile aggregated traffic statistics.

Procedure for the Technical Deactivation of Tracking Technologies: The Data Subject may block, deactivate, or delete these cookies by modifying the configuration of their device’s internet browser. Below are the technical deactivation paths for the most commonly used browsers:


VIII. Security Measures and Incident Protocols

To ensure that your personal data is not subject to damage, loss, alteration, destruction, or unauthorized processing, the Data Controller maintains and implements strict administrative, physical, and technical security measures, which are no less than those implemented to safeguard its own confidential information. These measures include role-based restricted access internal policies (least privilege), data encryption in transit (TLS/SSL) and at rest, use of certified servers, and strict confidentiality and non-disclosure agreements signed by all employees and administrative staff involved in data processing.

Vulnerability and Incident Notification Protocol: In the event of any security breach or incident that significantly compromises your personal data (especially financial or patrimonial data) and that could adversely affect your moral or patrimonial rights, the Data Controller will notify the Data Subject immediately via their registered email. This notification will transparently detail: the nature of the incident, the categories of data compromised, the immediate actions implemented to mitigate the impact, and the security recommendations suggested for the Data Subject. Likewise, the corresponding reports will be presented to the Personal Data Protection Unit (UDPD) of the Secretariat of Anticorruption and Good Government within the established legal timeframes.


IX. Modifications to the Privacy Notice

The Data Controller reserves the right to make modifications, additions, reforms, or updates to this Comprehensive Privacy Notice at any time to address legislative reforms, enforcement criteria issued by the SABG, judicial guidelines, internal corporate policies, or new characteristics in the LLC’s subscription, maintenance, or transborder transaction models.

Any substantive change or update to this Privacy Notice will be officially published on our corporate website: aaintelligence.tech/privacy. Modifications to the Comprehensive Privacy Notice will take full legal effect and be binding on the processing of information 7 (seven) business days after the date of their publication on the aforementioned digital portal.


The Data Subject is formally informed that if they consider that their human right to the protection of personal data has been violated by the Data Controller, or if their requests in the exercise of ARCO Rights have not been satisfactorily addressed in a timely manner according to the legal periods described in this Notice, they have the right to appeal before the Secretariat of Anticorruption and Good Government (SABG) to file the corresponding complaint or claim through the Rights Protection Procedure, in accordance with the provisions of Articles 40 to 50 of the Federal Law on the Protection of Personal Data Held by Private Parties.


By using our website, registering on our platforms, holding formal negotiation meetings, or exchanging information through the execution of an NDA with the Data Controller, you manifest that this Comprehensive Privacy Notice has been made available to you and that you tacitly consent to the processing of your general personal data under the terms described herein.


In compliance with Article 8 of the Law and the NLFPDPPP, I expressly authorize the Data Controller in writing to process my patrimonial and financial data for the sole purpose of managing recurring charges, processing payments derived from my subscription or maintenance policy, and performing the corresponding tax invoicing in accordance with the terms set forth in this Comprehensive Privacy Notice.

Name of the Data Subject / Representative: ______________________________________ Handwritten Signature / Digital Consent: _________________________________ Date of Subscription: _________________________________________________