LexFlow

Legal document

Personal Data Protection Policy (Mexico)

Last updated: April 26, 2026

This Policy supplements the Privacy Notice and details the technical, administrative and physical measures LexFlow has in place to comply with Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP), its Regulations, and INAI guidelines applicable to the private sector.

1. Applicable regulatory framework

  • Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations.
  • Privacy Notice Guidelines published by INAI.
  • INAI recommendations for handling personal-data security incidents.
  • General security provisions issued by CNBV when the customer is a regulated entity.
  • International best practices: ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, NIST SP 800-53.
  • AWS Well-Architected Framework, Security pillar.

2. Roles under LFPDPPP

For most personal data uploaded by the customer to its records, LexFlow acts as DATA PROCESSOR under article 50 of the LFPDPPP Regulations. The DATA CONTROLLER is the customer.

For personal data LexFlow collects directly (user signup, contact forms, commercial contacts, billing), LexFlow acts as DATA CONTROLLER.

3. Processing principles

We apply the principles of lawfulness, consent, information, quality, purpose, fairness, proportionality and accountability set forth in article 6 of LFPDPPP. In particular:

  • Limitation: we only process data strictly necessary for the declared purposes.
  • Quality: we facilitate the exercise of data-subject rectification rights.
  • Purpose: we do not use data for purposes other than those authorized.
  • Demonstrated accountability: we maintain documented evidence of the controls in place.

4. Infrastructure: AWS and data residency

LexFlow infrastructure runs 100% on Amazon Web Services. This decision allows us to inherit AWS certifications, controls and contractual obligations:

  • Primary region: us-east-2 (Ohio, United States).
  • Disaster recovery region: us-east-1 (Northern Virginia).
  • Data Processing Addendum signed with AWS.
  • Standard contractual clauses and compliance commitments for international frameworks (GDPR, LFPDPPP, LGPD, CCPA).
  • Applicable AWS certifications: SOC 1, SOC 2 Type II, SOC 3, ISO 27001, ISO 27017, ISO 27018, ISO 9001, PCI DSS Level 1, FedRAMP Moderate, HIPAA-eligible.
  • Additional compliance programs: AWS Artifact available to the customer for inspection where applicable.

5. AWS services we use

  • Amazon RDS (PostgreSQL 16) — structured storage with at-rest encryption and automatic backups.
  • Amazon S3 — immutable document repository with SSE-S3 / SSE-KMS encryption and versioning.
  • AWS Cognito — authentication, registration and MFA.
  • Amazon API Gateway + AWS Lambda — auto-scaling API layer.
  • Amazon SQS — asynchronous queues for backups, search and migration.
  • Amazon EventBridge Scheduler — scheduled task execution.
  • Amazon SES — email notifications from notificaciones@lexflow.com.mx.
  • Amazon SNS — transactional SMS.
  • Amazon Bedrock + Anthropic Claude Haiku 4.5 — generative AI with zero retention.
  • Amazon Textract — asynchronous OCR for scanned documents.
  • AWS KMS — encryption-key management.
  • Amazon CloudWatch + AWS GuardDuty — observability and threat detection.

6. Technical security measures

  • AES-256 encryption at rest on every store (RDS, S3, EBS).
  • TLS 1.2+ in transit with certificates issued by AWS Certificate Manager.
  • Multi-tenant isolation: every record carries a tenant_id and is filtered by middleware on every query. Row-Level Security in PostgreSQL as an extra safety net on sensitive tables.
  • Role segregation (RBAC) enforced at the API layer, not just in the UI.
  • Hardened configuration baselines, periodically reviewed via Infrastructure-as-Code (Terraform).
  • Pre-signed URLs with a maximum 5-minute lifetime to access documents.
  • Outbound webhooks signed with HMAC-SHA256 for origin verification.
  • Strict outbound URL validation (anti-SSRF): RFC1918 private ranges, link-local, loopback and non-https schemes are blocked.
  • Automated CI checks: 25+ pytest tests, dependency scanning and static analysis.
  • Periodic internal and external penetration testing.

7. Administrative measures

  • Internal access-control policy based on least-privilege.
  • Confidentiality agreements signed by all personnel.
  • Mandatory annual training on personal data protection.
  • Formal designation of the Data Protection Office.
  • Information-asset inventory and classification matrix.
  • Documented incident-response and business-continuity procedures.

8. Physical measures

Operations run in AWS data centers, physically protected by biometric access controls, 24/7 surveillance, redundant power and cooling, and zone compartmentalization. LexFlow does not operate any data center of its own.

9. Audit log

Every relevant action (login, read, edit, delete, download, print, export) is recorded in an immutable audit log with authoritative server-side timestamps. The customer can export the log for internal or regulatory audit; it includes source IP and user agent.

10. Incident management

In the event of a security incident affecting personal data, LexFlow will:

  • Notify the affected customer within 72 hours of detection, with the information available at the time.
  • Document the scope, root causes and corrective actions implemented.
  • Support the customer in its duty to notify INAI and data subjects when applicable.
  • Preserve evidence in line with the LFPDPPP Regulations.

11. Mobile apps and permissions

iOS and Android mobile apps request only the permissions required for the offered function (push notifications, camera access to upload documents, biometrics for sign-in). Contacts, photos or location are not accessed without explicit user authorization, and these permissions can be revoked at any time from the device settings.

12. Amazon Alexa integration

When the customer enables the Amazon Alexa integration, voice requests are processed inside the Alexa Skills ecosystem under Amazon's terms. LexFlow receives the intent already transcribed and authenticated by Alexa and never has access to the raw voice recording. Activating the skill requires account linking and MFA when applicable.

13. How to exercise rights

Data subjects may exercise their rights as described in the Privacy Notice. If they are not satisfied with the response, they may file a complaint with INAI at https://home.inai.org.mx.

14. Contact and authority

For personal-data protection topics, write to acastillejos@dixi-project.com with the subject "Data protection". The competent national authority is the National Institute for Transparency, Access to Information and Personal Data Protection (INAI).

Data Protection Office

  • Email: acastillejos@dixi-project.com
  • Operator: Dixi Project S.A.S. de C.V. (LexFlow)
  • Authority: INAI — https://home.inai.org.mx
  • Framework: LFPDPPP, Regulations and INAI guidelines