Saltar al contenido
Byte and BrandBack to home

Legal

Privacy notice

This is an English translation, provided as a courtesy — it has no legal effect of its own. The Spanish version is the notice required and governed by Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), and it's the one that controls if the two ever read differently.

Version 1.2 · Last updated: September 16, 2026

1. Who is responsible for your data

Adrián Martínez Zúñiga, an individual doing business under the trade name Byte and Brand, is responsible for the processing of your personal data.

DetailValue
Trade nameByte and Brand
RFC (Mexican tax ID)MAZA831006A91
AddressYacatas 86, Col. Narvarte Poniente, Alcaldía Benito Juárez, C.P. 03020, Ciudad de México, México
Contact and privacy emailzunigama@byteandbrand.org
WhatsApp and phone55 7415 0288
Sitebyteandbrand.org

To handle ARCO rights requests we've designated a person responsible for personal data, as required by Article 29 of the Law. Write to zunigama@byteandbrand.org.

2. What data we process

We only process the data you give us, or that's generated when you use the site and our services.

From whoever contacts or hires us

CategoryDataWhere it comes from
IdentificationFull name, business name, job titleYou provide it when you contact us
ContactWhatsApp number, email, cityWhatsApp, email, phone call
Work-relatedBusiness industry, size, tools you useThe discovery call
Conversation contentWhat you write on WhatsApp or email, including attached filesYou send it
Tax and billingRFC, legal name, tax regime, CFDI use, tax address, billing emailYou provide it so we can invoice you
Financial or asset-relatedThe account you pay from, payment reference and amountYour transfer or card payment

From whoever visits the site

CategoryData
BrowsingIP address, browser and device type, operating system, language, pages viewed, time on each page, referring site or ad, campaign UTM parameters
InteractionWhich WhatsApp button you used and from which section of the page

This data is collected with cookies and equivalent technologies. Section 8 explains which ones and how to turn them off.

Data we do NOT process

  • We don't process sensitive personal data. We don't ask for racial or ethnic origin, health status, genetic information, religious or philosophical beliefs, union membership, political opinions, or sexual orientation. If you send us any of this on your own in a conversation, we delete it.
  • We don't process minors' data. Our services are aimed at businesses. If we detect data belonging to someone under 18, we remove it.
  • We don't buy or rent databases.

Financial or asset-related data requires your express consent, per Article 7 of the Law. By sending us proof of a payment or your account details to receive a refund, you're granting that consent for that purpose only.

3. What we use it for

Necessary purposes

Without these purposes we can't serve you or deliver the service. They don't require your additional consent, and you can't object to them while the relationship exists, because they ARE the relationship.

  1. Answering your message, call, or email.
  2. Preparing the diagnosis, quote, and service proposal.
  3. Signing and managing the contract: onboarding you as a client, delivery schedule, project communication.
  4. Building, publishing, and maintaining what you hired: website, automation, WhatsApp agent, campaigns.
  5. Registering domains, hosting accounts, and mailboxes in your name or your business's, when the service includes it.
  6. Billing the monthly fee and the one-time payment, and issuing the corresponding CFDI (Mexican tax invoice).
  7. Meeting tax, accounting, and legal obligations, and responding to requests from competent authorities.
  8. Providing support, handling reports, and resolving questions.
  9. Keeping a record of what was agreed for liability, dispute, or legal defense purposes.

Additional purposes

These are not necessary for the service. You can decline them now or withdraw them later, without affecting what you've already hired:

  1. Sending you content, news, or promotions from Byte and Brand by email or WhatsApp.
  2. Inviting you to webinars, demos, or events.
  3. Measuring how the site is used to improve it, with analytics tools.
  4. Measuring ad campaign performance and showing you remarketing ads.
  5. Using your business's name and logo as a case study or business reference, only if you authorize it in writing.

How to decline them. Email zunigama@byteandbrand.org with the subject Additional purposes saying which ones you don't want. We have five business days to stop applying them. You can also reply UNSUBSCRIBE to any broadcast message, or use the unsubscribe link in the email footer.

If your refusal arrives before we start processing data for those purposes, they never apply in the first place.

Automated decisions

Our WhatsApp agent NegocIA replies automatically and can classify a conversation, book an appointment, or flag a lead as interested. None of those decisions produce legal effects or significantly affect your rights: a person reviews any business agreement before it exists. You can request human intervention at any time by writing "I want to talk to a person," and you can object to the automated processing under Article 26 of the Law through the process in section 5.

4. How to limit the use or disclosure of your data

These are the options we offer, in addition to the ARCO rights in section 5:

I want toHow to do it
Stop receiving marketing messagesReply UNSUBSCRIBE on WhatsApp, use the unsubscribe link in the email, or write to zunigama@byteandbrand.org
Keep my data out of advertising and analyticsEmail us with the subject Additional purposes; you can also block cookies per section 8
Be added to an exclusion listRequest it by email and we'll add you to our internal exclusion list, checked before any send
Prevent my data from being transferredState it per the clause in section 7

You can also register with PROFECO's Public Registry of Consumers (repep.profeco.gob.mx) to stop receiving advertising from any provider.

5. Your ARCO rights and how to exercise them

You have the right to access your data, to rectify it when it's wrong or incomplete, to cancel it when it should no longer be processed, and to object to processing for a legitimate reason (ARCO). Exercising one isn't a requirement for exercising another.

Where to file

By email to zunigama@byteandbrand.org, with the subject ARCO rights request.

What the request must include

  1. Your name and an address or email to receive the response.
  2. A copy of a valid government ID (INE, passport, or professional license). If acting through a representative, also the power of attorney and the representative's ID.
  3. A clear description of the data the right applies to — except for access requests, where this isn't needed.
  4. Which right you're exercising and exactly what you're requesting.
  5. Anything that helps us locate the information: approximate date, the WhatsApp number you wrote from, an invoice number.

If you're requesting rectification, also say what needs correcting and attach supporting documentation (Article 30).

Timeframes

StageTimeframe
We communicate our decision20 days from when we receive the request
If granted, we act on itThe following 15 days after that notice
ExtensionOnce, for an equal period, when circumstances justify it

These are the timeframes in Article 31 of the Law. We reply through the same channel you wrote to us on, unless you request otherwise.

Cost

It's free. We can only charge for reproduction, copying, or shipping costs. If you provide the medium to reproduce the data, it's delivered at no cost. If you repeat the same request within twelve months, the charge can't exceed three times the current UMA (Mexico's official measure-and-update unit) (Article 34).

When we can refuse

We can fully or partially deny the request when you're not verified as the data subject, when we don't have your data, when it would harm a third party's rights, when there's a legal restriction or an authority's ruling, or when what's requested has already been done (Article 33). In any of those cases, we tell you why.

There's also data we can't cancel while the reason for keeping it still applies: data that's part of an ongoing contract, data we must retain under tax law, and data necessary to fulfill an obligation we've taken on (Article 25).

6. Withdrawing your consent

You can withdraw the consent you gave us at any time, with no retroactive effect. It's requested the same way and with the same requirements as section 5, with the subject Consent withdrawal, and the same timeframes apply.

Keep in mind that withdrawing consent for the necessary purposes in section 3 may mean we can no longer provide the service you hired, and that some data must be retained by law even if you withdraw consent.

7. Transfers and disclosures

We don't sell, rent, or trade your personal data.

To operate, we use providers that process data on our behalf and under our instructions — they're processors, and giving them data is a disclosure, not a transfer:

ProviderWhat forWhere it's based
Hostinger InternationalSite, domain, and email hostingEuropean Union
Google (Workspace, Analytics, Ads)Email, site measurement, and campaignsUnited States
Meta Platforms (WhatsApp Business, Pixel, Ads)WhatsApp conversations, measurement, and campaignsUnited States
Google (Gemini) and OpenAIGenerating the WhatsApp agent's replies and contentUnited States
StripeCard payment processingUnited States
Microsoft (Clarity)Heatmaps and session recordings, to understand how the site is usedUnited States

This notice and the purposes you agreed to are communicated to all of them, per Article 35 of the Law.

We may also transfer data without your consent in the cases under Article 36, in particular:

  • To Mexico's Tax Administration Service (SAT) and our accountant, to issue CFDIs and meet tax obligations.
  • To competent authorities, when there's a properly founded and justified request.
  • To legal counsel, when necessary to recognize, exercise, or defend a right in a legal proceeding.
  • Whatever is necessary to maintain or fulfill the legal relationship between you and us.

Transfer clause. If you do not consent to your data being transferred to third parties other than the processors listed above and the cases under Article 36 of the Law, email us at zunigama@byteandbrand.org with the subject I do not consent to transfers. If you say nothing, we understand you accept the transfers described. You can change your mind at any time.

8. Cookies and tracking technologies

The site uses cookies and local storage. We don't use cookies to identify you by name.

TypeWhat it doesCan it be turned off?
NecessaryKeep the page working and remember your privacy choicesNo, the site can't operate without them
Measurement (Google Analytics 4, Microsoft Clarity)Count visits, page views, and WhatsApp clicks, in aggregate; Clarity also generates heatmaps and recordings of how the page is used, without capturing what you type into text fieldsYes
Advertising (Google Ads, Meta Pixel, TikTok Pixel)Measure which ad brought the visit and enable remarketingYes

Measurement and advertising cookies don't turn on by themselves. The first time you visit, the site asks you. Until you accept, those tags don't load and your browser makes zero requests to Google, Meta, Microsoft, or TikTok. If you choose Necessary only, they never load.

How to change your mind

At the bottom of any page, under Cookie preferences. It reopens the question, and your new answer replaces the previous one.

How to turn them off from outside the site too

  • From your browser: Chrome, Safari, Firefox, and Edge all let you block or delete cookies from their privacy settings.
  • Google Analytics: opt-out add-on at tools.google.com/dlpage/gaoptout.
  • Google ads: adssettings.google.com.
  • Meta ads: your Facebook or Instagram account's ad preferences.
  • Microsoft Clarity has no dedicated opt-out add-on: it's blocked the same way as any other third-party cookie, from your browser's privacy settings.

Blocking measurement and advertising cookies doesn't affect how the site works.

9. How long we keep your data

We keep each piece of data only as long as necessary for the purpose that justified it. Once that ends, it's blocked and then deleted (Article 10).

DataPeriod
Prospect who didn't hire us24 months from the last contact
Active clientFor as long as the relationship lasts
Former client5 years from the last CFDI, per the retention period in Mexico's Federal Tax Code
Tax receipts and accounting records5 years
Records of contractual non-compliance72 months from the date of non-compliance, then deleted
Browsing and analytics data14 months
ARCO rights requests and their responses5 years, as proof of compliance

10. How we protect your data

We maintain administrative, technical, and physical security measures under Article 18 of the Law:

  • Encryption in transit (HTTPS/TLS) on the site and in forms.
  • Two-factor authentication on email, hosting, repository, and ad-platform accounts.
  • Need-to-know access: each person only sees the data for the project they're working on.
  • Managed, non-shared passwords.
  • A duty of confidentiality for everyone involved in processing, which survives even after the relationship ends (Article 20).
  • Regular backups and an annual review of access and providers.

Breaches. If a security breach occurs that significantly affects your property or moral rights, we tell you immediately by email and WhatsApp, with what happened, which data was affected, what we're doing about it, and what we recommend you do (Article 19).

11. When we process data on behalf of a client

In addition to being responsible for its own data, Byte and Brand acts as a processor when it operates websites, forms, automations, or WhatsApp agents for a client, and in doing so processes that client's end customers' data.

  • Our client is the data controller, not us. They define the purposes and publish their own privacy notice.
  • We process that data only per their instructions and to deliver the service to them.
  • We don't use it for our own purposes, we don't cross-reference it with our own databases, and we don't transfer it except on their instruction or a legal obligation.
  • We keep it confidential, under the same duty that survives after the relationship ends.
  • When the contract ends, we return or delete it, as instructed.

If you're an end customer of a business we serve and want to exercise your rights, the request goes to that business. If it reaches us instead, we'll forward it and let you know who to contact.

12. Changes to this notice

This notice may change due to new legal obligations, or changes to our services or privacy practices.

How you'll find out. The current version is always published on this page, with its last-updated date and version number. If a change affects the purposes of processing, we notify you by email or WhatsApp before applying it and, when the law requires it, we ask for your consent again (Article 11).

13. If you're not satisfied

If you believe your data protection rights were violated, you can file a data protection request with the competent authority, which today is Mexico's Secretaría Anticorrupción y Buen Gobierno (Anti-Corruption and Good Governance Secretariat).

The deadline is 15 days from when we communicate our response. If we didn't respond, it runs from when our deadline expired (Article 40).

Before that, write to us — most things get resolved by just asking.

14. Consent

By providing us your personal data through any channel — WhatsApp, email, a form, a phone call, or signing a contract — and not expressing your will to the contrary, you grant your tacit consent to the processing described in this notice, under Article 7 of Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP).

Financial or asset-related data requires your express consent, which you grant by sending us that information for the purpose stated in section 2.

This page is a courtesy translation. The notice required by Mexican law is the Spanish version — Aviso de privacidad. If this translation and the Spanish original ever conflict, the Spanish version controls.

Notice prepared under Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), published in the Official Gazette of the Federation on March 20, 2025, last amended November 14, 2025. This English page is a translation for convenience; the Spanish version is the legally governing one.