Legal document
Personal Data Protection Policy (Mexico)
Last updated: April 26, 2026
This Policy supplements the Privacy Notice and details the technical, administrative and physical measures LexFlow has in place to comply with Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPPLFPDPPPMexican Federal Law on the Protection of Personal Data Held by Private Parties.), its Regulations, and INAIINAIMexico's National Institute for Transparency, Access to Information and Personal Data Protection. guidelines applicable to the private sector.
1. Applicable regulatory framework
- Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPPLFPDPPPMexican Federal Law on the Protection of Personal Data Held by Private Parties.) and its Regulations.
- Privacy Notice Guidelines published by INAIINAIMexico's National Institute for Transparency, Access to Information and Personal Data Protection..
- INAIINAIMexico's National Institute for Transparency, Access to Information and Personal Data Protection. recommendations for handling personal-data security incidents.
- General security provisions issued by CNBVCNBVMexican National Banking and Securities Commission. when the customer is a regulated entity.
- International best practices: ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, NIST SP 800-53.
- AWS Well-Architected Framework, Security pillar.
2. Roles under LFPDPPP
For most personal data uploaded by the customer to its records, LexFlow acts as DATA PROCESSOR under article 50 of the LFPDPPPLFPDPPPMexican Federal Law on the Protection of Personal Data Held by Private Parties. Regulations. The DATA CONTROLLER is the customer.
For personal data LexFlow collects directly (user signup, contact forms, commercial contacts, billing), LexFlow acts as DATA CONTROLLER.
3. Processing principles
We apply the principles of lawfulness, consent, information, quality, purpose, fairness, proportionality and accountability set forth in article 6 of LFPDPPPLFPDPPPMexican Federal Law on the Protection of Personal Data Held by Private Parties.. In particular:
- Limitation: we only process data strictly necessary for the declared purposes.
- Quality: we facilitate the exercise of data-subject rectification rights.
- Purpose: we do not use data for purposes other than those authorized.
- Demonstrated accountability: we maintain documented evidence of the controls in place.
4. Infrastructure: AWS and data residency
LexFlow infrastructure runs 100% on Amazon Web Services. This decision allows us to inherit AWS certifications, controls and contractual obligations:
- Primary region: us-east-2 (Ohio, United States).
- Disaster recovery region: us-east-1 (Northern Virginia).
- Data Processing Addendum signed with AWS.
- Standard contractual clauses and compliance commitments for international frameworks (GDPRGDPRGeneral Data Protection Regulation — EU data-protection law., LFPDPPPLFPDPPPMexican Federal Law on the Protection of Personal Data Held by Private Parties., LGPDLGPDBrazil's General Data Protection Law., CCPACCPACalifornia Consumer Privacy Act.).
- Applicable AWS certifications: SOC 1SOC 1System and Organization Controls 1 — internal controls over financial reporting., SOC 2 Type IISOC 2 Type IISystem and Organization Controls 2 Type II — audit of operational controls over a period., SOC 3SOC 3System and Organization Controls 3 — public summary of controls., ISO 27001ISO 27001International standard for information-security management systems., ISO 27017ISO 27017Cloud-services security standard., ISO 27018ISO 27018Personal-data protection standard for cloud services., ISO 9001, PCI DSSPCI DSSPayment Card Industry Data Security Standard. Level 1, FedRAMPFedRAMPFederal Risk and Authorization Management Program — U.S. cloud authorization for government. Moderate, HIPAAHIPAAU.S. Health Insurance Portability and Accountability Act.-eligible.
- Additional compliance programs: AWS Artifact available to the customer for inspection where applicable.
5. AWS services we use
- Amazon RDSRDSAmazon Relational Database Service — managed databases on AWS. (PostgreSQL 16) — structured storage with at-rest encryption and automatic backups.
- Amazon S3S3Amazon Simple Storage Service — object storage on AWS. — immutable document repository with SSE-S3SSE-S3Server-Side Encryption managed by Amazon S3. / SSE-KMSSSE-KMSServer-Side Encryption with keys managed by AWS Key Management Service. encryption and versioning.
- AWS Cognito — authentication, registration and MFAMFAMulti-Factor Authentication — second factor in addition to a password..
- Amazon API Gateway + AWS Lambda — auto-scaling API layer.
- Amazon SQSSQSAmazon Simple Queue Service — managed message queues. — asynchronous queues for backups, search and migration.
- Amazon EventBridge Scheduler — scheduled task execution.
- Amazon SESSESAmazon Simple Email Service — transactional email on AWS. — email notifications from notificaciones@lexflow.com.mx.
- Amazon SNSSNSAmazon Simple Notification Service — pub/sub and transactional SMS. — transactional SMS.
- Amazon Bedrock + Anthropic Claude Haiku 4.5 — generative AI with zero retention.
- Amazon Textract — asynchronous OCROCROptical Character Recognition. for scanned documents.
- AWS KMSKMSAWS Key Management Service — AWS cryptographic-key management. — encryption-key management.
- Amazon CloudWatch + AWS GuardDuty — observability and threat detection.
6. Technical security measures
- AES-256AES-256Advanced Encryption Standard with 256-bit key. encryption at rest on every store (RDSRDSAmazon Relational Database Service — managed databases on AWS., S3S3Amazon Simple Storage Service — object storage on AWS., EBSEBSAmazon Elastic Block Store — block volumes for EC2.).
- TLS 1.2+TLS 1.2+Transport Layer Security version 1.2 or higher. in transit with certificates issued by AWS Certificate Manager.
- Multi-tenant isolation: every record carries a tenant_id and is filtered by middleware on every query. Row-Level Security in PostgreSQL as an extra safety net on sensitive tables.
- Role segregation (RBACRBACRole-Based Access Control.) enforced at the API layer, not just in the UI.
- Hardened configuration baselines, periodically reviewed via Infrastructure-as-Code (Terraform).
- Pre-signed URLs with a maximum 5-minute lifetime to access documents.
- Outbound webhooks signed with HMACHMACHash-based Message Authentication Code.-SHA256 for origin verification.
- Strict outbound URL validation (anti-SSRFSSRFServer-Side Request Forgery — attacker tricks the server into making unintended internal requests.): RFC1918RFC1918RFC 1918 — reserved private IP address ranges. private ranges, link-local, loopback and non-https schemes are blocked.
- Automated CI checks: 25+ pytest tests, dependency scanning and static analysis.
- Periodic internal and external penetration testing.
7. Administrative measures
- Internal access-control policy based on least-privilege.
- Confidentiality agreements signed by all personnel.
- Mandatory annual training on personal data protection.
- Formal designation of the Data Protection Office.
- Information-asset inventory and classification matrix.
- Documented incident-response and business-continuity procedures.
8. Physical measures
Operations run in AWS data centers, physically protected by biometric access controls, 24/7 surveillance, redundant power and cooling, and zone compartmentalization. LexFlow does not operate any data center of its own.
9. Audit log
Every relevant action (login, read, edit, delete, download, print, export) is recorded in an immutable audit log with authoritative server-side timestamps. The customer can export the log for internal or regulatory audit; it includes source IPIPIntellectual Property. and user agent.
10. Incident management
In the event of a security incident affecting personal data, LexFlow will:
- Notify the affected customer within 72 hours of detection, with the information available at the time.
- Document the scope, root causes and corrective actions implemented.
- Support the customer in its duty to notify INAIINAIMexico's National Institute for Transparency, Access to Information and Personal Data Protection. and data subjects when applicable.
- Preserve evidence in line with the LFPDPPPLFPDPPPMexican Federal Law on the Protection of Personal Data Held by Private Parties. Regulations.
11. Mobile apps and permissions
iOS and Android mobile apps request only the permissions required for the offered function (push notifications, camera access to upload documents, biometrics for sign-in). Contacts, photos or location are not accessed without explicit user authorization, and these permissions can be revoked at any time from the device settings.
12. Amazon Alexa integration
When the customer enables the Amazon Alexa integration, voice requests are processed inside the Alexa Skills ecosystem under Amazon's terms. LexFlow receives the intent already transcribed and authenticated by Alexa and never has access to the raw voice recording. Activating the skill requires account linking and MFAMFAMulti-Factor Authentication — second factor in addition to a password. when applicable.
13. How to exercise rights
Data subjects may exercise their rights as described in the Privacy Notice. If they are not satisfied with the response, they may file a complaint with INAIINAIMexico's National Institute for Transparency, Access to Information and Personal Data Protection. at https://home.inai.org.mx.
14. Contact and authority
For personal-data protection topics, write to acastillejos@dixi-project.com with the subject "Data protection". The competent national authority is the National Institute for Transparency, Access to Information and Personal Data Protection (INAIINAIMexico's National Institute for Transparency, Access to Information and Personal Data Protection.).
Data Protection Office
- Email: acastillejos@dixi-project.com
- Operator: Dixi Project S.A.S. de C.V. (LexFlow)
- Authority: INAIINAIMexico's National Institute for Transparency, Access to Information and Personal Data Protection. — https://home.inai.org.mx
- Framework: LFPDPPPLFPDPPPMexican Federal Law on the Protection of Personal Data Held by Private Parties., Regulations and INAIINAIMexico's National Institute for Transparency, Access to Information and Personal Data Protection. guidelines