Legal document
Comprehensive Privacy Notice
Last updated: April 26, 2026
This Privacy Notice is issued in compliance with articles 15, 16 and 17 of Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPPLFPDPPPMexican Federal Law on the Protection of Personal Data Held by Private Parties.), its Regulations, and the Privacy Notice Guidelines published by INAIINAIMexico's National Institute for Transparency, Access to Information and Personal Data Protection.. It describes who collects your personal data, for what purpose, how we protect it, and how you can exercise your rights.
1. Identity and address of the data controller
The data controller is Dixi Project S.A.S. de C.V. ("LexFlow" or the "Controller"), with offices in Mexico City, Mexico.
For any matter related to personal data, contact our Data Protection Officer at acastillejos@dixi-project.com.
2. What we are: a multi-tenant SaaS service
LexFlow is a Software-as-a-Service (SaaSSaaSSoftware as a Service — software delivered as a cloud service.) Legal Operations platform for corporate legal teams. We operate under a multi-tenant model: each customer has a logically isolated workspace with no cross-tenant access.
Services are delivered through the following channels: web portal (lexflow.com.mx, admin.lexflow.com.mx, app.lexflow.com.mx), iOS mobile app, Android mobile app, progressive web app (PWAPWAProgressive Web App — installable web app with offline capabilities.) and, soon, voice integration with Amazon Alexa for authorized queries and notifications.
3. Personal data we collect
To deliver the service we collect the following categories of personal data, either directly (when you provide them through forms, apps or files you upload) or indirectly (when generated automatically as you use the platform):
- Identification: name, surname, RFCRFCMexican Federal Taxpayer Registry — Mexico's tax ID. tax ID, CURPCURPMexican Unique Population Registry Code. for legal representatives when applicable, date of birth if recorded by the customer.
- Contact: corporate email, landline and mobile phone, registered address of entities, service-of-process addresses.
- Employment & professional: job title, area, role assigned within the tenant, bar registration when documenting internal or external counsel.
- Academic data when customers upload it as part of their record set.
- Financial: bank accounts and CLABECLABEMexican 18-digit Standardized Bank Code for transfers. codes, transaction amounts, budgets, fees, legal spend — always uploaded by the customer for their own management.
- Biometric data limited to the fingerprint hash generated by Mifiel advanced electronic signature, when the customer chooses to use it.
- Technical metadata: IPIPIntellectual Property. address, user agent, device identifiers, browser language, timestamp of every action.
- Access, read, download, edit and print logs: required for traceability and audit.
4. Sensitive personal data
LexFlow does not require or request data classified as sensitive under LFPDPPPLFPDPPPMexican Federal Law on the Protection of Personal Data Held by Private Parties. (racial origin, health, beliefs, sexual life, political opinion, union membership) to operate. If the customer chooses to upload this kind of information into its records (e.g., in a labor lawsuit), the processing is performed under the customer's responsibility as data controller, and LexFlow acts strictly as a data processor under article 50 of the LFPDPPPLFPDPPPMexican Federal Law on the Protection of Personal Data Held by Private Parties. Regulations.
5. Purposes of processing
Personal data is processed for the following primary purposes, without which the service cannot be provided:
- Provide and operate the contracted SaaSSaaSSoftware as a Service — software delivered as a cloud service. platform (corporate governance, contracts, litigation, lease accounting, IPIPIntellectual Property., compliance, etc.).
- Create and manage user accounts, authenticate them via AWS Cognito and enforce multi-factor authentication (MFAMFAMulti-Factor Authentication — second factor in addition to a password.) when required by the tenant.
- Generate and safeguard the immutable audit log required by corporate governance and financial regulation standards.
- Send operational notifications and configurable alerts via email, SMS or WhatsApp.
- Invoice and collect payments for contracted services.
- Handle support, training and legal-technical consulting requests arising from implementation.
- Comply with applicable legal obligations (tax, commercial, financial, labor).
6. Secondary purposes
Additionally, and as long as you do not object, we may process your data to improve the product through aggregated and dissociated statistical analysis; send you communications about new features, training, events and relevant legal content; and run satisfaction surveys and discovery interviews.
7. How to opt out of secondary purposes
You may object at any time by emailing acastillejos@dixi-project.com with the subject line "Opt-out from secondary purposes". Your refusal does not affect the provision of the service.
8. Artificial intelligence and personal data
LexFlow uses generative AI models (Claude Haiku 4.5 via Amazon Bedrock) to assist users with semantic search, template drafting and invoice review. We operate under the Zero Data Retention regime agreed with AWS: models do not store prompts and do not use them for retraining.
Vector retrieval is built from embeddings (irreversible mathematical representations), so the model provider does not receive the raw original text in full. Every AI call is recorded in an internal audit log with tenant, user, model, tokens, cost and outcome, available to the customer for inspection.
9. Transfers and remittances
LexFlow does not sell, rent or share your personal data with third parties for purposes other than service operation. The only remittances (article 36 LFPDPPPLFPDPPPMexican Federal Law on the Protection of Personal Data Held by Private Parties.) occur with processors that act under our documented instructions and equivalent confidentiality and security clauses:
- Amazon Web Services, Inc. (AWS): cloud infrastructure provider (compute, storage, database, identity, messaging). Primary region us-east-2 (Ohio) with backup replica in us-east-1.
- Anthropic, PBC: through Amazon Bedrock, exclusively to process prompts under zero retention.
- Mifiel S.A.P.I. de C.V.: when the customer chooses to use NOM-151NOM-151Mexican Official Standard 151: data-message preservation and advanced electronic-signature certification. advanced electronic signature.
- Twilio / SMS and WhatsApp Business operators: when the user activates these notification channels.
- Google reCAPTCHA: anti-spam protection on the public contact form.
10. International transfers
Data is stored in the United States of America, within AWS region us-east-2. This transfer is necessary for service provision (article 37 fraction IV LFPDPPPLFPDPPPMexican Federal Law on the Protection of Personal Data Held by Private Parties.). AWS holds SOC 1SOC 1System and Organization Controls 1 — internal controls over financial reporting., SOC 2 Type IISOC 2 Type IISystem and Organization Controls 2 Type II — audit of operational controls over a period., ISO 27001ISO 27001International standard for information-security management systems., ISO 27017ISO 27017Cloud-services security standard., ISO 27018ISO 27018Personal-data protection standard for cloud services., PCI DSSPCI DSSPayment Card Industry Data Security Standard. and FedRAMPFedRAMPFederal Risk and Authorization Management Program — U.S. cloud authorization for government. certifications, and has signed standard contractual clauses and compliance commitments with applicable data-protection regulations.
11. Security measures
- AES-256AES-256Advanced Encryption Standard with 256-bit key. encryption at rest (AWS S3S3Amazon Simple Storage Service — object storage on AWS., RDSRDSAmazon Relational Database Service — managed databases on AWS., EBSEBSAmazon Elastic Block Store — block volumes for EC2.) and TLS 1.2+TLS 1.2+Transport Layer Security version 1.2 or higher. in transit.
- Logical multi-tenant isolation with mandatory tenant_id on every table and Row-Level Security in PostgreSQL as an additional safety net.
- AWS Cognito authentication with multi-factor authentication (MFAMFAMulti-Factor Authentication — second factor in addition to a password.) enforceable per organization and mandatory for privileged roles.
- Optional Single Sign-On (SSOSSOSingle Sign-On across multiple applications./SAMLSAMLSecurity Assertion Markup Language — XML-based protocol for enterprise SSO.) per tenant.
- Pre-signed URLs with 5-minute lifetime to access documents.
- Immutable audit log with authoritative server-side timestamps (not client-side).
- Outbound webhooks signed with HMACHMACHash-based Message Authentication Code.-SHA256.
- Encrypted automatic daily backups with at least 30-day retention.
- Periodic penetration testing and continuous monitoring (CloudWatch, GuardDuty).
12. Data retention
Personal data is retained for the duration of the contract and for any additional periods required by applicable law (commercial, tax, labor or procedural). Audit logs are retained for the minimum period required by the customer's regulatory frameworks. Upon contract termination, the customer can export all of its information in standard formats; once the agreed transition period elapses, data is securely deleted following certified procedures.
13. Data-subject rights and consent revocation
You have the right to know (Access) what personal data we hold, request its Rectification when inaccurate, request Cancellation if you believe processing does not comply with the law, or Object to specific uses. You may also revoke previously granted consent.
To exercise these rights, send a request to acastillejos@dixi-project.com including: full name, copy of an official ID, clear description of the right being exercised and the data concerned. We will respond within a maximum of 20 business days. If you are not satisfied with the answer, you may file a complaint with INAIINAIMexico's National Institute for Transparency, Access to Information and Personal Data Protection. (https://home.inai.org.mx).
14. Cookies and similar technologies
Our website uses strictly necessary cookies to keep your session, remember language preference and improve performance. We do not use third-party advertising cookies. You may disable cookies in your browser, but some platform features may stop working correctly.
15. Changes to this notice
Any material change to this notice will be communicated through the portal and by email to the tenant administrator with at least 15 calendar days' notice before taking effect.
Data Protection Office
- Email: acastillejos@dixi-project.com
- Operator: Dixi Project S.A.S. de C.V. (LexFlow)
- Response window for data-subject requests: 20 business days
- Regulator: INAIINAIMexico's National Institute for Transparency, Access to Information and Personal Data Protection. — https://home.inai.org.mx