1. General Information
This Privacy Policy (hereinafter, “Privacy Notice”) describes how heymaia® (hereinafter, “THE CONTROLLER”), a registered trademark operated by Eng. Hugo Israel Santiago Barragan, collects, uses, stores, protects and, when applicable, shares the personal data it obtains from its clients, prospects and website users.
This Privacy Notice is issued in compliance with the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations, in force in the United Mexican States.
1.1 Identity and Address of the Controller
Controller: heymaia® / Eng. Hugo Israel Santiago Barragan Address: Tijuana, Baja California, Mexico Email: [email protected] Phone: +52 1 664 318 8306 Website: https://heymaia.io
2. Personal Data We Collect
2.1 General Personal Data
THE CONTROLLER may collect the following personal data:
Identification data:
- Full name
- Company name (in case of legal entities)
- RFC (Federal Taxpayer Registry)
- Tax address
Contact data:
- Email address
- Landline and/or mobile phone number
- WhatsApp, Telegram or Slack address
Professional and employment data:
- Company or organization name
- Position or job title
- Business sector
Financial and billing data:
- Bank details for transfers (when THE HOLDER provides them for refund purposes)
- Tax information for invoice issuance
- Payment history
2.2 Sensitive Personal Data
heymaia® does NOT collect sensitive personal data from its clients. Sensitive data is considered to be that which reveals racial or ethnic origin, health status, genetic information, religious, philosophical and moral beliefs, union affiliation, political opinions or sexual preference.
In the event that, due to the nature of the contracted project, THE CLIENT provides sensitive data of third parties (for example, for the development of a health system), THE CLIENT will be solely responsible for the processing of such data before their own users, and must have the corresponding privacy notices and consents.
2.3 Automatically Collected Data
Through the heymaia® website, the following may be automatically collected:
- IP address
- Browser and device type
- Operating system
- Pages visited and time spent
- Cookies and similar technologies (see section 9)
3. Purposes of Data Processing
3.1 Primary Purposes (Necessary)
Personal data will be used for the following essential purposes:
- Identify and contact THE HOLDER for the provision of services
- Prepare quotes, proposals and contracts
- Manage the commercial and contractual relationship
- Issue invoices and tax receipts
- Process payments and maintain accounting records
- Provide technical support and customer service
- Follow up on projects in development
- Comply with legal and tax obligations
- Respond to requests for exercising ARCO rights
3.2 Secondary Purposes (Optional)
With THE HOLDER’s consent, data may be used for:
- Send information about new services, promotions or offers
- Conduct satisfaction surveys
- Send informative bulletins or newsletters
- Contact to offer additional services
- Prepare statistics and market analysis (in anonymized form)
If you do not wish your data to be processed for secondary purposes, you may express this by sending an email to: [email protected] with the subject “Exclusion of secondary purposes”.
4. Legal Basis for Processing
The processing of personal data is carried out based on:
- The consent of THE HOLDER, granted by providing their data and accepting this Privacy Notice
- The contractual relationship existing or to be established between the parties
- The legitimate interest of THE CONTROLLER for the management of its commercial activity
- Compliance with legal obligations (tax, commercial, labor)
5. Transfer of Personal Data
5.1 Transfers Requiring Consent
heymaia® may transfer personal data to third parties in the following cases, for which THE HOLDER’s consent is required:
- Hosting and cloud storage service providers
- Email and communications service providers
- Project management and CRM tools
- Electronic billing platforms
5.2 Transfers Not Requiring Consent
In accordance with LFPDPPP, consent is not required for the following transfers:
- To competent authorities when there is a legal obligation
- To companies in the same corporate group operating under the same privacy policies
- When necessary for the fulfillment of a contract entered into in THE HOLDER’s interest
- When necessary for the maintenance or fulfillment of a legal relationship
5.3 International Transfers
Some of the service providers used by heymaia® may be located outside of Mexico (primarily in the United States). By accepting this Privacy Notice, THE HOLDER consents to the international transfer of their data to such providers, who are required to maintain the confidentiality and security of the information.
6. ARCO Rights
THE HOLDER has the right to:
6.1 Access
Know what personal data we have about you and what we use it for.
6.2 Rectification
Request the correction of your personal data if it is inaccurate, incomplete or not up to date.
6.3 Cancellation
Request the deletion of your personal data from our records or databases when you consider that it is not being processed in accordance with the law or this Notice.
6.4 Opposition
Object to the processing of your personal data for specific purposes.
6.5 Procedure to Exercise ARCO Rights
To exercise any of these rights, THE HOLDER must send a request to the email [email protected] with the subject “ARCO Request”, including:
- Full name of the holder
- Clear and precise description of the personal data for which you seek to exercise any ARCO right
- Any element or document that facilitates the location of personal data
- Indication of the right you wish to exercise (Access, Rectification, Cancellation or Opposition)
- In case of rectification, indicate the modifications to be made and provide documentation supporting your request
- Preferred means to receive the response (email or address)
- Copy of valid official identification (INE, passport or professional license)
Response deadlines:
- heymaia® will respond to the request within a maximum period of 20 business days from the date of receipt
- If the request is deemed appropriate, it will be made effective within 15 business days following the communication of the response
- The deadlines may be extended once, for an equal period, when the circumstances of the case justify it
7. Limitation of Use and Disclosure
7.1 Revocation of Consent
THE HOLDER may revoke the consent granted for the processing of their personal data at any time, without retroactive effects. To do so, they must send a request to the email [email protected] with the subject “Revocation of consent”.
It is important to note that in certain cases revocation will not be possible immediately, as heymaia® may be required to continue processing the data by legal provision or for the fulfillment of pending contractual obligations.
7.2 Limitation of Use for Secondary Purposes
If THE HOLDER wishes to limit the use of their data only to primary purposes, they may request it by sending an email to [email protected] with the subject “Limitation of purposes”.
8. Security Measures
heymaia® implements administrative, technical and physical security measures to protect personal data against damage, loss, alteration, destruction, unauthorized use, access or processing:
8.1 Administrative Measures
- Internal information handling policies
- Staff training on data protection
- Confidentiality agreements with collaborators and suppliers
8.2 Technical Measures
- Encryption of data in transit (SSL/TLS)
- Secure passwords and two-factor authentication
- Periodic information backups
- Updated security software and antivirus
- Role-based access control
8.3 Physical Measures
- Restricted access to computer equipment
- Secure storage of physical documents (when applicable)
9. Use of Cookies and Tracking Technologies
9.1 What are Cookies?
Cookies are small text files that are stored on the user’s device when visiting a website. They allow preferences to be remembered and improve the browsing experience.
9.2 Types of Cookies We Use
Strictly necessary cookies:
- Allow basic website navigation
- Do not require consent
Analytics and performance cookies:
- Help us understand how visitors interact with the site
- We use tools such as Google Analytics
Functionality cookies:
- Allow user preferences to be remembered
9.3 Cookie Control
THE HOLDER can configure their browser to reject all cookies or to notify them when a cookie is sent. However, if you disable cookies, it is possible that some site functions may not operate correctly.
For more information on how to manage cookies:
- Google Chrome: chrome://settings/cookies
- Mozilla Firefox: about:preferences#privacy
- Safari: Preferences > Privacy
- Microsoft Edge: edge://settings/privacy
10. Third Party Data
10.1 Data Provided by THE CLIENT
During the provision of services, THE CLIENT may provide personal data of third parties (employees, client’s customers, end users, etc.) for the development of software projects, websites or automations.
In these cases:
- THE CLIENT is responsible for the processing of such data before their own users
- heymaia® acts only as a data processor
- THE CLIENT guarantees that they have the consent of the holders to share such data
- heymaia® will process this data only in accordance with THE CLIENT’s instructions and for the purposes of the contracted project
10.2 Obligations of THE CLIENT
THE CLIENT is obligated to:
- Have their own privacy notices for their users
- Obtain the necessary consent before sharing data with heymaia®
- Inform heymaia® about any restrictions on the use of the data provided
- Keep their own privacy notices up to date
11. Data Retention
11.1 Retention Period
Personal data will be retained for:
- During the commercial relationship: All the time that the provision of services lasts
- After the relationship ends: For an additional period of 5 years to comply with legal, tax and accounting obligations
- Billing data: In accordance with the provisions of the Federal Tax Code (minimum 5 years)
11.2 Data Deletion
Once the retention period has elapsed, personal data will be deleted securely through:
- Secure deletion of digital files
- Destruction of physical documents (when applicable)
12. Minors
heymaia® does not intentionally collect personal data from minors. Our services are aimed at individuals over 18 years of age or businesses.
If THE CONTROLLER becomes aware that it has collected data from a minor without the consent of their parents or guardians, it will proceed to delete such information immediately.
13. Changes to the Privacy Notice
heymaia® reserves the right to modify this Privacy Notice at any time to adapt it to legislative changes, jurisprudence, internal policies or new requirements.
Any modification will be notified through:
- Publication on the website https://heymaia.io
- Email to active clients (when changes are substantial)
THE HOLDER is recommended to periodically review this Privacy Notice to be informed about how their data is protected.
The date of last update is indicated at the beginning of this document.
14. Competent Authority
If THE HOLDER considers that their right to the protection of personal data has been violated, they may go before the competent authority in Mexico:
Secretariat of Anti-Corruption and Good Government (Formerly INAI - National Institute of Transparency, Access to Information and Protection of Personal Data)
Website: https://www.gob.mx Phone: 800 835 4324
15. Consent
By providing their personal data to heymaia®, whether through the website, email, telephone, instant messaging or any other means, THE HOLDER:
- Declares having read and understood this Privacy Notice
- Accepts the terms and conditions established herein
- Grants their consent for the processing of their data in accordance with the purposes described
- Consents to the data transfers mentioned in section 5
If THE HOLDER does not agree with the terms of this Privacy Notice, they must refrain from providing their personal data to heymaia®.
16. Contact
For any questions, clarifications or requests related to the protection of your personal data, you can contact us through:
heymaia®
- Email: [email protected]
- Phone: +52 1 664 318 8306
- Location: Tijuana, Baja California, Mexico
By contracting the services of heymaia® or providing their personal data, THE HOLDER declares having read, understood and accepted this Privacy Notice.
© 2026 heymaia® - All rights reserved.