PRIVACY POLICY
COMPREHENSIVE PRIVACY NOTICE FOR CLIENTS, PROSPECTS, AND COMMERCIAL PARTNERS
ISSUANCE AND LEGAL ADAPTATION CONTROL
- Structure Author: Senior Corporate Legal Consultant
- Regulatory Reference Framework: New Federal Law on the Protection of Personal Data Held by Private Parties (Nueva Ley Federal de Protección de Datos Personales en Posesión de los Particulares - NLFPDPPP, published in the Official Gazette of the Federation [DOF] on March 20, 2025), in force as of March 21, 2025, and its 2011 Regulations (applicable on a transitional basis in matters that do not oppose the new Law).
- Guarantor and Supervisory Authority: Secretariat of Anticorruption and Good Government (Secretaría de Anticorrupción y Buen Gobierno - SABG) - Personal Data Protection Unit (Unidad de Protección de Datos Personales - UDPD).
- Legal Recourse for Data Subjects: Rights Protection Procedure before the SABG; Indirect Amparo Proceeding (Juicio de Amparo Indirecto) before the specialized District Courts and Collegiate Circuit Courts in matters of Access to Information and Personal Data Protection.
- Last Update Date: August 20, 2026.
COMPREHENSIVE PRIVACY NOTICE
I. Identity and Domicile of the Data Controller
The entity responsible for the processing, safeguarding, and protection of your personal data is AA INTELLIGENCE GROUP, LLC (hereinafter referred to as the “Data Controller”), a company incorporated under the laws of the State of Wyoming, United States of America, with its central corporate domicile located at 2 S Biscayne Blvd Ste 3200 - 5483 MIAMI, FL 33131, USA, and which, in order to fully comply with the laws of the United Mexican States, designates as its digital department legal@aaintelligence.tech to hear and receive notices and service of process within Mexican territory.
The Data Controller is committed to ensuring that the processing of all information concerning an identified or identifiable individual placed under its custody is carried out in strict compliance with the principles of legality, consent, notice, quality, purpose, loyalty, proportionality, and accountability established in Article 5 of the Federal Law on the Protection of Personal Data Held by Private Parties (hereinafter referred to as the “LFPDPPP” or the “Law”), its Regulations, and in accordance with the active enforcement guidelines issued by the Secretariat of Anticorruption and Good Government (SABG).
II. Categories of Personal Data Subject to Processing
In order to fulfill the purposes described in this notice, the Data Controller will collect and process the following categories of personal data from the data subject (hereinafter referred to as the “Data Subject”), under a criterion of minimization and proportionality, expressly refraining from collecting data of a sensitive nature unless authorized by the Law under specific exceptions:
- Identification and Contact Data: Full name (or corporate name in the case of represented legal entities), handwritten or digital signature, digital copy of a valid official identification (voter ID card [INE], passport, or professional license), Federal Taxpayer Registry (RFC), Unique Population Registry Code (CURP), date of birth, nationality, email address, physical address (residential or tax address), and telephone numbers (landline and mobile).
- Financial and Patrimonial Data (Recurring Charges Processing): Standardized Banking Code (CLABE), active bank account number, credit or debit card number, expiration date, security code (CVV - which is not directly stored by the Data Controller but processed securely through payment gateways under the PCI-DSS standard), billing information (Tax Status Certificate - Constancia de Situación Fiscal issued by the SAT), and transaction history of subscription or maintenance payments.
- Commercial Prospecting and Negotiation Data: Professional data of the Data Subject, legal representatives, or technical liaisons (job title, position, company, representation authority pursuant to a power of attorney), as well as data contained in non-disclosure agreements (NDA), letters of intent (LOI), financial proposals, and minutes of formal commercial negotiation meetings.
- Navigation Data and Electronic Records: IP address, type of web browser used, operating system, language preference, session cookies, web beacons, technical API call logs, timestamps, and metadata of the Data Subject’s digital behavior within our platforms or website.
III. Purposes of the Processing of Personal Data
The information collected by the Data Controller will be processed solely for the purposes informed in this notice. It is strictly prohibited to process personal data for compatible or analogous purposes not declared in this instrument, in accordance with the express prohibition of the legislation in force, unless additional express consent is obtained from the Data Subject.
A. Primary Purposes (Indispensable for the existence, validity, maintenance, and fulfillment of the legal relationship between the Data Subject and the Data Controller):
- Identification and Commercial Negotiation: To verify the identity of the Data Subject, representative, or entity, and validate the authenticity of the documents presented in order to evaluate, prospect, and formalize alliances, commercial associations, and business relationships, including but not limited to the execution of non-disclosure agreements (NDAs) to hold formal legal negotiation meetings.
- Contractual Basis: To draft, formalize, and execute service agreements, software terms of use, service level agreements (SLAs), or subscription and maintenance contracts that provide a legal basis for the commercial relationship between the parties.
- Service Provision and Maintenance: To manage, provide, maintain, and optimize the software services, technological tools, digital solutions, or products contracted by the Data Subject.
- Recurring Payments and Collection Management: To process and automate the recurring charges corresponding to the contracted subscription or maintenance policy, as well as to manage refunds, charge clarifications, and administrative collection procedures.
- Tax Billing: To issue the corresponding Digital Tax Receipts via Internet (CFDI) for commercial transactions in strict compliance with the provisions of the Tax Administration Service (Servicio de Administración Tributaria - SAT) in Mexico.
- Technical Support and Customer Care: To address technical support requests, resolve access issues, answer corporate inquiries, and process complaints or suggestions.
- Security and Prevention: To prevent electronic fraud, identity theft, or unauthorized use of the Data Controller’s intellectual property, as well as to ensure the security of electronic platforms and information systems.
- Legal Compliance: To comply with tax mandates, audits, inspections by Mexican or international regulatory authorities (including anti-money laundering regulations), and any other applicable legal framework.
B. Secondary Purposes (Accessory, not necessary for the legal relationship):
- Marketing and Promotion: To send, directly or through authorized third parties, advertisements, special offers, newsletters, regulatory updates, or invitations to seminars and events organized by the Data Controller.
- Quality Evaluation: To conduct satisfaction surveys or market studies to evaluate the quality of the digital solutions and customer care provided.
Mechanism to Refuse Processing for Secondary Purposes: The Data Subject has the right to refuse the processing of their data for secondary purposes. If the data is obtained indirectly, the Data Subject has a period of 5 (five) business days to manifest their refusal by sending an email to the Data Controller’s Privacy Officer at: legal@aaintelligence.tech. Furthermore, at any time, the Data Subject may revoke their consent for these secondary purposes through the procedure established in Section V of this Notice.
IV. Transfer and Remission of Personal Data
The Data Controller covenants not to sell, rent, or transfer the personal information of the Data Subject to third parties unaffiliated with its operations without obtaining explicit authorization. However, in accordance with Article 36 of the Law, the data may be shared with the following national or international entities without requiring the consent of the Data Subject, as they fall under the exceptions provided by the applicable legal framework:
- Companies within the Same Corporate Group: Parent companies, subsidiaries, affiliates, or associates under the common control of AA INTELLIGENCE GROUP, LLC that operate under the same personal data protection policies, procedures, and standards, for purposes of system consolidation, corporate support, internal audit, and information backup on centralized servers.
- Mexican Judicial, Tax, or Administrative Authorities: Federal agencies such as the Tax Administration Service (SAT), the Secretariat of Finance and Public Credit (SHCP), or the corresponding jurisdictional bodies in Mexican territory, when the transfer is required by law, a founded and motivated administrative resolution, or for the prosecution and administration of justice.
- Technology Service Providers (Remission to Data Processors): The Data Controller utilizes cloud infrastructure services (e.g., Hostinger, AWS, Google Cloud), recurring payment processing (e.g., Stripe or Mercado Pago), and corporate email platforms whose physical servers are located outside of the United Mexican States (mainly in the United States of America and the European Union). Such communications constitute data remissions (remisiones de datos) pursuant to the Regulations of the Law, and therefore do not require the consent of the Data Subject. It is guaranteed that these remissions are executed under specific Data Processing Agreements (DPA) that contractually bind the providers to process the data solely and exclusively to comply with the instructions of the Data Controller, maintaining technical security and confidentiality measures equivalent to those provided in this notice.
V. Rights of the Data Subjects (Access, Rectification, Cancellation, and Opposition - ARCO Rights) and Revocation of Consent
1. Definition of Rights
You, in your capacity as Data Subject, or through your duly accredited legal representative, possess the following fundamental rights under Mexican law:
- Access: To know what personal data we hold about you, what we use it for, and the general conditions of its use.
- Rectification (and Update): To request the correction of your personal information if it is outdated, inaccurate, or incomplete.
- Cancellation (Subject to a Blocking Period): To request the removal of your data from our records, databases, or computer systems when you consider that it is not being used properly or upon the conclusion of your commercial relationship.
- Opposition: To object to the processing of your personal data for specific purposes. In particular, the Data Subject has the right to object to their personal data being subjected to automated processing (including artificial intelligence, algorithms, or automated profiling) that evaluates aspects of their profile without human intervention, and that produces adverse legal effects or significantly affects their interests.
2. Submission Channel and Application Requirements
To exercise any of the ARCO Rights or to revoke previously granted consent, the Data Subject or their legal representative must send a formal written request to the Data Controller’s Privacy Officer at: legal@aaintelligence.tech.
To validate its processing, the ARCO request must mandatorily contain and include:
- The full name of the Data Subject, complete address, or other means (such as an email address) to communicate the response.
- A digitized copy of the documents proving the identity of the Data Subject (voter ID [INE], Passport, or Professional License). If acting through a legal representative, a copy of the document proving the identity of the representative must be attached, as well as the public instrument (power of attorney) or a power of attorney letter signed before two witnesses that demonstrates their representation authority beyond doubt.
- A clear, precise, and concise description of the ARCO right to be exercised and the specific personal data on which the request is made (in the case of Rectification, the applicant must also indicate the modifications to be made and attach supporting documents justifying the change).
- Any other element or document that facilitates the location of the personal data within the Data Controller’s systems.
3. Procedure and Legal Timelines for Response
The Data Controller will process and resolve requests in accordance with the following mandatory timelines dictated by federal law:
- Acknowledgement and Correction Notice: The Data Controller will send an acknowledgement of receipt of the request within a maximum period of 5 (five) business days. If the request is imprecise or incomplete, the Data Controller will issue a correction notice to the Data Subject only once within this period, giving them 10 (ten) business days to remedy the omissions; if no response is received within this period, the request will be deemed as not submitted.
- Determination of Admissibility: The Data Controller will notify the Data Subject of the decision regarding the admissibility of the request within a maximum period of 20 (twenty) business days from the day following the date the fully integrated request was received.
- Implementation of the Measure: If the request is declared admissible, the Data Controller will execute the corresponding measure within a maximum period of 15 (fifteen) business days from the day following the date the admissibility decision was notified to the Data Subject.
- Extension: The aforementioned resolution and implementation periods may be extended only once for an equal period, provided that the Data Controller justifies and technically demonstrates that the complexity of the case or the cross-border processing of the data warrants the delay, notifying the Data Subject in writing in a timely manner.
4. Technical Blocking Period Protocol
The Data Subject understands that, in the event of exercising the right of Cancellation, the data cannot be immediately erased from the physical servers or cloud systems. Pursuant to Article 21 of the Law, the Data Controller will implement a mandatory technical Blocking Period.
During this period, the Data Subject’s data will be completely dissociated from the ordinary and commercial operations of the company, remaining isolated and safeguarded with robust security measures solely to respond to potential civil, commercial, or tax liabilities (such as the 5-year accounting retention period required by Article 30 of the Mexican Federal Tax Code or the 10-year retention period for commercial contracts established in Article 46 of the Mexican Code of Commerce). Once the statute of limitations for these legal liabilities has expired, the Data Controller will proceed with the logical, physical, and irreversible erasure of the information from its servers.
VI. Means to Limit the Use or Disclosure of Your Personal Data
In order to offer alternative and free options for the Data Subject to voluntarily restrict the disclosure or use of their data for accessory purposes, the Data Controller offers the following mechanisms:
- Direct Unsubscribe Link: All electronic communications of a commercial, promotional, or advertising nature sent by the Data Controller incorporate an automated unsubscribe link at the footer of the email, allowing the Data Subject to immediately suspend the receipt of advertising campaigns.
- Internal Exclusion Lists: The Data Subject may request formal registration in the Data Controller’s “Advertising Exclusion List” by sending an email to legal@aaintelligence.tech, indicating their desire not to be contacted for marketing purposes.
- Public State Registries (REPEP and REUS): The Data Subject is informed of the existence of legal tools independent of the Data Controller to limit commercial or telephone advertising, such as the Public Registry to Avoid Advertising (REPEP) administered by the Federal Consumer Protection Agency (PROFECO) or the Public Registry of Users (REUS) of the National Commission for the Protection and Defense of Financial Services Users (CONDUSEF).
VII. Use of Cookies and Automated Tracking Technologies
The Data Controller uses cookies, web beacons, and other technical navigation metadata on its web portals and software platforms to manage sessions, remember configurations, personalize user experience, and compile aggregated traffic statistics.
- Strictly Necessary (Essential) Cookies: Aimed at the technical operation of the portal, session authentication, and security. They do not require consent and cannot be deactivated without affecting the system’s operability.
- Performance, Analytical, or Marketing (Optional) Cookies: These analyze portal traffic (e.g., Google Analytics). They require the express consent of the user, which is collected upon entry through the portal’s cookie acceptance banner.
Procedure for the Technical Deactivation of Tracking Technologies: The Data Subject may block, deactivate, or delete these cookies by modifying the configuration of their device’s internet browser. Below are the technical deactivation paths for the most commonly used browsers:
- Google Chrome (Windows or macOS Systems):
- Open the browser and click on the three vertical dots in the upper right corner.
- Select Settings and go to Privacy and security.
- Click on Third-party cookies (or Site settings).
- Select the Block all cookies option or add the specific URL of our platforms to the manual block list.
- Apple Safari (macOS System):
- Open the browser, click on the Safari tab in the top menu bar, and select Settings (or Preferences).
- Go to the Privacy section.
- Check the box to Block all cookies or configure specific tracking permissions.
VIII. Security Measures and Incident Protocols
To ensure that your personal data is not subject to damage, loss, alteration, destruction, or unauthorized processing, the Data Controller maintains and implements strict administrative, physical, and technical security measures, which are no less than those implemented to safeguard its own confidential information. These measures include role-based restricted access internal policies (least privilege), data encryption in transit (TLS/SSL) and at rest, use of certified servers, and strict confidentiality and non-disclosure agreements signed by all employees and administrative staff involved in data processing.
Vulnerability and Incident Notification Protocol: In the event of any security breach or incident that significantly compromises your personal data (especially financial or patrimonial data) and that could adversely affect your moral or patrimonial rights, the Data Controller will notify the Data Subject immediately via their registered email. This notification will transparently detail: the nature of the incident, the categories of data compromised, the immediate actions implemented to mitigate the impact, and the security recommendations suggested for the Data Subject. Likewise, the corresponding reports will be presented to the Personal Data Protection Unit (UDPD) of the Secretariat of Anticorruption and Good Government within the established legal timeframes.
IX. Modifications to the Privacy Notice
The Data Controller reserves the right to make modifications, additions, reforms, or updates to this Comprehensive Privacy Notice at any time to address legislative reforms, enforcement criteria issued by the SABG, judicial guidelines, internal corporate policies, or new characteristics in the LLC’s subscription, maintenance, or transborder transaction models.
Any substantive change or update to this Privacy Notice will be officially published on our corporate website: aaintelligence.tech/privacy. Modifications to the Comprehensive Privacy Notice will take full legal effect and be binding on the processing of information 7 (seven) business days after the date of their publication on the aforementioned digital portal.
X. Competent Authority and Legal Recourse
The Data Subject is formally informed that if they consider that their human right to the protection of personal data has been violated by the Data Controller, or if their requests in the exercise of ARCO Rights have not been satisfactorily addressed in a timely manner according to the legal periods described in this Notice, they have the right to appeal before the Secretariat of Anticorruption and Good Government (SABG) to file the corresponding complaint or claim through the Rights Protection Procedure, in accordance with the provisions of Articles 40 to 50 of the Federal Law on the Protection of Personal Data Held by Private Parties.
- Authority’s Website: gob.mx/buengobierno
- Agency Address: Av. Insurgentes Sur 1735, Col. Guadalupe Inn, Alc. Álvaro Obregón, C.P. 01020, Mexico City.
XI. Declaration of Acceptance and Express Consent
By using our website, registering on our platforms, holding formal negotiation meetings, or exchanging information through the execution of an NDA with the Data Controller, you manifest that this Comprehensive Privacy Notice has been made available to you and that you tacitly consent to the processing of your general personal data under the terms described herein.
EXPRESS CONSENT CLAUSE FOR THE PROCESSING OF PATRIMONIAL AND FINANCIAL DATA (RECURRING CHARGES AND SUBSCRIPTIONS)
In compliance with Article 8 of the Law and the NLFPDPPP, I expressly authorize the Data Controller in writing to process my patrimonial and financial data for the sole purpose of managing recurring charges, processing payments derived from my subscription or maintenance policy, and performing the corresponding tax invoicing in accordance with the terms set forth in this Comprehensive Privacy Notice.
Name of the Data Subject / Representative: ______________________________________ Handwritten Signature / Digital Consent: _________________________________ Date of Subscription: _________________________________________________