This Privacy Notice is issued in full compliance with the provisions of the Mexican Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), its Regulations, and the Privacy Guidelines issued by the INAI.
1. Identity and Address of the Data Controller
Data Controller / Responsible for Personal Data:
Corporate Name: SGSD — Sistemas Generales & Sistemas Digitales, S.A.S.
RFC: SGS170324HVA
Physical Address: Circuito de la Constitución 13B, Tlalnepantla, Estado de México, C.P. 54025, México.
Phone: 442 644 5404
Privacy Contact Email: [email protected]
Platform operated: QRO. VERIFICADO (
qroverificado.com)
2. Personal Data We Collect
To carry out the technical, documentary, and commercial audit process, we collect the following personal data from applicants:
- Identification Data: Full name of the responsible party or legal representative of the business, position or role within the organization.
- Contact Data: Institutional or personal email address, landline and/or mobile/WhatsApp phone number.
- Business / Fiscal Data: Commercial name, corporate name (razón social), tax identification (RFC), physical address of establishment, and web domain to be evaluated.
- Documentary Accreditation File: Copy of valid official ID (INE/Passport) of the owner or representative, updated Tax Situation Certificate (CSF/RFC), recent proof of commercial establishment address, and proof of domain administration rights.
- Payment Processing Metadata (Stripe): For online transactions processed via Stripe, Inc. / Stripe Payments Europe, only general transaction metadata (amount, currency, transaction ID) is accessible by SGSD. SGSD / QRO. VERIFICADO does NOT collect, store, or have access at any time to sensitive financial data such as full card numbers, CVV/CVC codes, or expiration dates. All card payments are encrypted directly by Stripe under PCI-DSS Level 1 security standards.
- Commercial Agents / Affiliates Program: Full name, email, WhatsApp phone, profile picture (for official credential issuance), electronic contract acceptance, and bank/tax details (bank name, CLABE account, beneficiary name, RFC) for commission payment invoicing.
3. Sensitive Personal Data
⚠️ Notice Regarding Sensitive Personal Data:
As part of the documentary accreditation process, SGSD collects copies of official government-issued identification documents (INE / Passport). Under Mexican law, these documents may contain biometric data (facial photograph) and are treated as sensitive personal data requiring special protection.
These documents are used exclusively to verify the legal identity of the representative or owner of the business under audit. They are stored on secure servers with restricted access, are not publicly disclosed under any circumstances, and are not used for any purpose other than those expressly stated in this Privacy Notice.
By submitting your documentation, you expressly consent to the collection and treatment of this sensitive data for the stated purposes.
4. Primary Purposes of Data Treatment
Your personal data will be used for the following necessary primary purposes, which are required to provide the contracted service:
- To evaluate and perform the technical, documentary, and operational audit of your digital presence under the ESCODI-QRO-001 V1.0 standard.
- To contact you regarding audit diagnoses, observations, correction periods, and the final evaluation result.
- To issue, register, and activate the Digital Trust Seal on our infrastructure and Public Registry.
- To manage and publish the public information of your verified business in our Public Registry and Directory.
- To handle support inquiries, clarifications, renewal reminders, and report notifications.
- To process payments and issue receipts or invoices through our payment gateway (Stripe).
- For the Commercial Agents Program: To validate agent registration, issue official digital credentials, record referral commissions, and execute bank transfers for commission payouts.
5. Secondary Purposes of Data Treatment
Secondary Purposes (Optional — You May Opt Out):
In addition to the primary purposes above, SGSD may use your personal data for the following secondary purposes, which are not necessary for the contracted service but allow us to improve our offerings:
- To send institutional communications, updates about new services, or improvements to existing services offered by QRO. VERIFICADO.
- To conduct statistical analysis and generate aggregate, anonymized metrics to measure the impact of the Digital Trust Validation program in the state of Querétaro.
- To invite you to satisfaction surveys or feedback programs related to the audit process.
If you do not wish your personal data to be used for secondary purposes, you may send your opt-out request to [email protected] at any time. Opting out of secondary purposes will not affect the provision of the primary contracted service.
6. Transfers of Personal Data to Third Parties
SGSD may transfer your personal data to the following third parties solely to fulfill the purposes described in this Privacy Notice:
| Recipient |
Country |
Purpose |
Legal Basis (Art. 37 LFPDPPP) |
| Stripe, Inc. / Stripe Payments Europe, Ltd. |
USA / Ireland |
Secure payment processing for validation fees and renewals. |
Necessary for contractual fulfillment. Does not require separate consent. |
| Google LLC (Analytics & Tag Manager) |
USA |
Anonymous web traffic analysis. No personal identifiers are shared; data is aggregated and anonymized. |
Statistical purposes. Anonymous data. Does not require consent. |
| Competent Judicial Authorities |
Mexico |
Disclosure of data exclusively upon formal judicial or administrative order. |
Legal obligation under Art. 37 section III LFPDPPP. |
SGSD does not sell, rent, or otherwise transfer your personal data to any third party not listed above without your prior and express consent.
7. ARCO Rights (Access, Rectification, Cancellation, Opposition)
You have the following rights regarding your personal data held by SGSD:
- Access: To know what personal data we hold about you, the purposes of its treatment, and the conditions of its use.
- Rectification: To request correction of your personal data if it is inaccurate, incomplete, or outdated.
- Cancellation: To request deletion of your personal data from our records when it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
- Opposition: To oppose the treatment of your personal data for specific purposes.
How to Exercise Your ARCO Rights
To exercise any of your ARCO rights, submit your written request to: [email protected]
Your request must include:
- Your full name and contact email address.
- The web domain registered in our system (if applicable).
- A clear description of the right you wish to exercise and the data to which your request refers.
- A copy of an official government-issued ID to verify your identity.
Response Deadline: SGSD will respond to your ARCO request within 20 business days from the date of receipt, as established in Article 32 of the LFPDPPP. If the request is upheld, the corresponding measures will be implemented within 15 business days of communicating the response.
8. Revocation of Consent
You may revoke your consent to the treatment of your personal data at any time. However, please note that revocation of consent may prevent SGSD from providing the contracted services in whole or in part.
To revoke your consent, send a written request to [email protected] stating the specific data and purposes for which you wish to revoke consent. SGSD will process your request within 20 business days and inform you of the consequences of such revocation on the contracted services.
9. Limitation of Use and Disclosure
You have the right to request that SGSD limit the use or disclosure of your personal data. To exercise this right, send a request to [email protected] specifying:
- The specific data whose use or disclosure you wish to limit.
- The specific uses or disclosures you wish to restrict.
SGSD will evaluate your request and inform you of the outcome within 20 business days. Please note that certain limitations may affect the provision of contracted services that depend on the use of such data.
Additionally, you may register your personal data in the INAI Public Registry of Suppressed Persons (REPEP) to prevent your data from being used for advertising or commercial prospecting purposes. For more information, visit: repep.inai.org.mx
10. Security Measures
SGSD implements the following technical, administrative, and physical security measures to protect your personal data against unauthorized access, damage, loss, alteration, or disclosure:
- Technical measures: Storage encryption on secure servers, HTTPS/TLS encrypted data transmission, restricted access controls with multi-factor authentication for authorized personnel, automated security monitoring systems (AVM-QRO), and session management protocols.
- Administrative measures: Confidentiality agreements with authorized audit staff, internal policies for data handling and incident response, and periodic security reviews.
- Physical measures: Access controls to server infrastructure managed by certified hosting providers, with physical security perimeters.
- Payment security: Payment data processed exclusively through Stripe under PCI-DSS Level 1 certification — the highest security standard in the payment industry.
11. Data Retention Periods
SGSD retains personal data only for the time necessary to fulfill the purposes described in this Privacy Notice, subject to applicable legal and fiscal obligations:
- Audit documentation (INE, CSF, proof of address): Retained for the duration of the active validation and for a minimum of 5 years thereafter, in compliance with fiscal record-keeping obligations under Mexican tax law.
- Contact and business data: Retained for the duration of the commercial relationship and up to 3 years after the last interaction or service expiration.
- Payment transaction metadata: Retained for 5 years in compliance with fiscal and anti-money laundering regulations.
- Commercial Agents Program data: Retained for the duration of the active agent agreement and for 5 years after termination for fiscal and commission record purposes.
Upon expiration of the applicable retention period, data will be securely deleted or anonymized.
12. Use of Cookies and Analytical Tools
Our website uses cookies and third-party tracking technologies (including Google Analytics and Google Tag Manager) to analyze web traffic, understand navigation patterns, and continuously improve the user experience. Information collected by these tools is aggregated and anonymous and is not associated with your personal identity. You may configure your browser at any time to block or receive alerts about cookies.
13. Changes to This Privacy Notice
This Privacy Notice may be modified or updated due to new legal requirements, internal policy changes, or new service practices. Any updates will be published on this page: https://qroverificado.com/aviso-privacidad.php
When changes are material, we will notify affected users via email to the address registered in our system at least 10 business days before the changes take effect. Continued use of our services after notification constitutes acceptance of the updated Privacy Notice.
14. Supervisory Authority
If you believe your data protection rights have been violated, you may file a complaint with the National Institute for Transparency, Access to Information and Personal Data Protection (INAI):