Legal
Privacy notice
This is an English translation, provided as a courtesy — it has no legal effect of its own. The Spanish version is the notice required and governed by Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), and it's the one that controls if the two ever read differently.
Version 1.2 · Last updated: September 16, 2026
1. Who is responsible for your data
Adrián Martínez Zúñiga, an individual doing business under the trade name Byte and Brand, is responsible for the processing of your personal data.
| Detail | Value |
|---|---|
| Trade name | Byte and Brand |
| RFC (Mexican tax ID) | MAZA831006A91 |
| Address | Yacatas 86, Col. Narvarte Poniente, Alcaldía Benito Juárez, C.P. 03020, Ciudad de México, México |
| Contact and privacy email | zunigama@byteandbrand.org |
| WhatsApp and phone | 55 7415 0288 |
| Site | byteandbrand.org |
To handle ARCO rights requests we've designated a person responsible for personal data, as required by Article 29 of the Law. Write to zunigama@byteandbrand.org.
2. What data we process
We only process the data you give us, or that's generated when you use the site and our services.
From whoever contacts or hires us
| Category | Data | Where it comes from |
|---|---|---|
| Identification | Full name, business name, job title | You provide it when you contact us |
| Contact | WhatsApp number, email, city | WhatsApp, email, phone call |
| Work-related | Business industry, size, tools you use | The discovery call |
| Conversation content | What you write on WhatsApp or email, including attached files | You send it |
| Tax and billing | RFC, legal name, tax regime, CFDI use, tax address, billing email | You provide it so we can invoice you |
| Financial or asset-related | The account you pay from, payment reference and amount | Your transfer or card payment |
From whoever visits the site
| Category | Data |
|---|---|
| Browsing | IP address, browser and device type, operating system, language, pages viewed, time on each page, referring site or ad, campaign UTM parameters |
| Interaction | Which WhatsApp button you used and from which section of the page |
This data is collected with cookies and equivalent technologies. Section 8 explains which ones and how to turn them off.
Data we do NOT process
- We don't process sensitive personal data. We don't ask for racial or ethnic origin, health status, genetic information, religious or philosophical beliefs, union membership, political opinions, or sexual orientation. If you send us any of this on your own in a conversation, we delete it.
- We don't process minors' data. Our services are aimed at businesses. If we detect data belonging to someone under 18, we remove it.
- We don't buy or rent databases.
Financial or asset-related data requires your express consent, per Article 7 of the Law. By sending us proof of a payment or your account details to receive a refund, you're granting that consent for that purpose only.
3. What we use it for
Necessary purposes
Without these purposes we can't serve you or deliver the service. They don't require your additional consent, and you can't object to them while the relationship exists, because they ARE the relationship.
- Answering your message, call, or email.
- Preparing the diagnosis, quote, and service proposal.
- Signing and managing the contract: onboarding you as a client, delivery schedule, project communication.
- Building, publishing, and maintaining what you hired: website, automation, WhatsApp agent, campaigns.
- Registering domains, hosting accounts, and mailboxes in your name or your business's, when the service includes it.
- Billing the monthly fee and the one-time payment, and issuing the corresponding CFDI (Mexican tax invoice).
- Meeting tax, accounting, and legal obligations, and responding to requests from competent authorities.
- Providing support, handling reports, and resolving questions.
- Keeping a record of what was agreed for liability, dispute, or legal defense purposes.
Additional purposes
These are not necessary for the service. You can decline them now or withdraw them later, without affecting what you've already hired:
- Sending you content, news, or promotions from Byte and Brand by email or WhatsApp.
- Inviting you to webinars, demos, or events.
- Measuring how the site is used to improve it, with analytics tools.
- Measuring ad campaign performance and showing you remarketing ads.
- Using your business's name and logo as a case study or business reference, only if you authorize it in writing.
How to decline them. Email zunigama@byteandbrand.org with the subject Additional purposes saying which ones you don't want. We have five business days to stop applying them. You can also reply UNSUBSCRIBE to any broadcast message, or use the unsubscribe link in the email footer.
If your refusal arrives before we start processing data for those purposes, they never apply in the first place.
Automated decisions
Our WhatsApp agent NegocIA replies automatically and can classify a conversation, book an appointment, or flag a lead as interested. None of those decisions produce legal effects or significantly affect your rights: a person reviews any business agreement before it exists. You can request human intervention at any time by writing "I want to talk to a person," and you can object to the automated processing under Article 26 of the Law through the process in section 5.
4. How to limit the use or disclosure of your data
These are the options we offer, in addition to the ARCO rights in section 5:
| I want to | How to do it |
|---|---|
| Stop receiving marketing messages | Reply UNSUBSCRIBE on WhatsApp, use the unsubscribe link in the email, or write to zunigama@byteandbrand.org |
| Keep my data out of advertising and analytics | Email us with the subject Additional purposes; you can also block cookies per section 8 |
| Be added to an exclusion list | Request it by email and we'll add you to our internal exclusion list, checked before any send |
| Prevent my data from being transferred | State it per the clause in section 7 |
You can also register with PROFECO's Public Registry of Consumers (repep.profeco.gob.mx) to stop receiving advertising from any provider.
5. Your ARCO rights and how to exercise them
You have the right to access your data, to rectify it when it's wrong or incomplete, to cancel it when it should no longer be processed, and to object to processing for a legitimate reason (ARCO). Exercising one isn't a requirement for exercising another.
Where to file
By email to zunigama@byteandbrand.org, with the subject ARCO rights request.
What the request must include
- Your name and an address or email to receive the response.
- A copy of a valid government ID (INE, passport, or professional license). If acting through a representative, also the power of attorney and the representative's ID.
- A clear description of the data the right applies to — except for access requests, where this isn't needed.
- Which right you're exercising and exactly what you're requesting.
- Anything that helps us locate the information: approximate date, the WhatsApp number you wrote from, an invoice number.
If you're requesting rectification, also say what needs correcting and attach supporting documentation (Article 30).
Timeframes
| Stage | Timeframe |
|---|---|
| We communicate our decision | 20 days from when we receive the request |
| If granted, we act on it | The following 15 days after that notice |
| Extension | Once, for an equal period, when circumstances justify it |
These are the timeframes in Article 31 of the Law. We reply through the same channel you wrote to us on, unless you request otherwise.
Cost
It's free. We can only charge for reproduction, copying, or shipping costs. If you provide the medium to reproduce the data, it's delivered at no cost. If you repeat the same request within twelve months, the charge can't exceed three times the current UMA (Mexico's official measure-and-update unit) (Article 34).
When we can refuse
We can fully or partially deny the request when you're not verified as the data subject, when we don't have your data, when it would harm a third party's rights, when there's a legal restriction or an authority's ruling, or when what's requested has already been done (Article 33). In any of those cases, we tell you why.
There's also data we can't cancel while the reason for keeping it still applies: data that's part of an ongoing contract, data we must retain under tax law, and data necessary to fulfill an obligation we've taken on (Article 25).
6. Withdrawing your consent
You can withdraw the consent you gave us at any time, with no retroactive effect. It's requested the same way and with the same requirements as section 5, with the subject Consent withdrawal, and the same timeframes apply.
Keep in mind that withdrawing consent for the necessary purposes in section 3 may mean we can no longer provide the service you hired, and that some data must be retained by law even if you withdraw consent.
7. Transfers and disclosures
We don't sell, rent, or trade your personal data.
To operate, we use providers that process data on our behalf and under our instructions — they're processors, and giving them data is a disclosure, not a transfer:
| Provider | What for | Where it's based |
|---|---|---|
| Hostinger International | Site, domain, and email hosting | European Union |
| Google (Workspace, Analytics, Ads) | Email, site measurement, and campaigns | United States |
| Meta Platforms (WhatsApp Business, Pixel, Ads) | WhatsApp conversations, measurement, and campaigns | United States |
| Google (Gemini) and OpenAI | Generating the WhatsApp agent's replies and content | United States |
| Stripe | Card payment processing | United States |
| Microsoft (Clarity) | Heatmaps and session recordings, to understand how the site is used | United States |
This notice and the purposes you agreed to are communicated to all of them, per Article 35 of the Law.
We may also transfer data without your consent in the cases under Article 36, in particular:
- To Mexico's Tax Administration Service (SAT) and our accountant, to issue CFDIs and meet tax obligations.
- To competent authorities, when there's a properly founded and justified request.
- To legal counsel, when necessary to recognize, exercise, or defend a right in a legal proceeding.
- Whatever is necessary to maintain or fulfill the legal relationship between you and us.
Transfer clause. If you do not consent to your data being transferred to third parties other than the processors listed above and the cases under Article 36 of the Law, email us at zunigama@byteandbrand.org with the subject I do not consent to transfers. If you say nothing, we understand you accept the transfers described. You can change your mind at any time.
9. How long we keep your data
We keep each piece of data only as long as necessary for the purpose that justified it. Once that ends, it's blocked and then deleted (Article 10).
| Data | Period |
|---|---|
| Prospect who didn't hire us | 24 months from the last contact |
| Active client | For as long as the relationship lasts |
| Former client | 5 years from the last CFDI, per the retention period in Mexico's Federal Tax Code |
| Tax receipts and accounting records | 5 years |
| Records of contractual non-compliance | 72 months from the date of non-compliance, then deleted |
| Browsing and analytics data | 14 months |
| ARCO rights requests and their responses | 5 years, as proof of compliance |
10. How we protect your data
We maintain administrative, technical, and physical security measures under Article 18 of the Law:
- Encryption in transit (HTTPS/TLS) on the site and in forms.
- Two-factor authentication on email, hosting, repository, and ad-platform accounts.
- Need-to-know access: each person only sees the data for the project they're working on.
- Managed, non-shared passwords.
- A duty of confidentiality for everyone involved in processing, which survives even after the relationship ends (Article 20).
- Regular backups and an annual review of access and providers.
Breaches. If a security breach occurs that significantly affects your property or moral rights, we tell you immediately by email and WhatsApp, with what happened, which data was affected, what we're doing about it, and what we recommend you do (Article 19).
11. When we process data on behalf of a client
In addition to being responsible for its own data, Byte and Brand acts as a processor when it operates websites, forms, automations, or WhatsApp agents for a client, and in doing so processes that client's end customers' data.
- Our client is the data controller, not us. They define the purposes and publish their own privacy notice.
- We process that data only per their instructions and to deliver the service to them.
- We don't use it for our own purposes, we don't cross-reference it with our own databases, and we don't transfer it except on their instruction or a legal obligation.
- We keep it confidential, under the same duty that survives after the relationship ends.
- When the contract ends, we return or delete it, as instructed.
If you're an end customer of a business we serve and want to exercise your rights, the request goes to that business. If it reaches us instead, we'll forward it and let you know who to contact.
12. Changes to this notice
This notice may change due to new legal obligations, or changes to our services or privacy practices.
How you'll find out. The current version is always published on this page, with its last-updated date and version number. If a change affects the purposes of processing, we notify you by email or WhatsApp before applying it and, when the law requires it, we ask for your consent again (Article 11).
13. If you're not satisfied
If you believe your data protection rights were violated, you can file a data protection request with the competent authority, which today is Mexico's Secretaría Anticorrupción y Buen Gobierno (Anti-Corruption and Good Governance Secretariat).
The deadline is 15 days from when we communicate our response. If we didn't respond, it runs from when our deadline expired (Article 40).
Before that, write to us — most things get resolved by just asking.
14. Consent
By providing us your personal data through any channel — WhatsApp, email, a form, a phone call, or signing a contract — and not expressing your will to the contrary, you grant your tacit consent to the processing described in this notice, under Article 7 of Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP).
Financial or asset-related data requires your express consent, which you grant by sending us that information for the purpose stated in section 2.
This page is a courtesy translation. The notice required by Mexican law is the Spanish version — Aviso de privacidad. If this translation and the Spanish original ever conflict, the Spanish version controls.
Notice prepared under Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), published in the Official Gazette of the Federation on March 20, 2025, last amended November 14, 2025. This English page is a translation for convenience; the Spanish version is the legally governing one.