LexFlow

Legal document

Comprehensive Privacy Notice

Last updated: April 26, 2026

This Privacy Notice is issued in compliance with articles 15, 16 and 17 of Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP), its Regulations, and the Privacy Notice Guidelines published by INAI. It describes who collects your personal data, for what purpose, how we protect it, and how you can exercise your rights.

1. Identity and address of the data controller

The data controller is Dixi Project S.A.S. de C.V. ("LexFlow" or the "Controller"), with offices in Mexico City, Mexico.

For any matter related to personal data, contact our Data Protection Officer at acastillejos@dixi-project.com.

2. What we are: a multi-tenant SaaS service

LexFlow is a Software-as-a-Service (SaaS) Legal Operations platform for corporate legal teams. We operate under a multi-tenant model: each customer has a logically isolated workspace with no cross-tenant access.

Services are delivered through the following channels: web portal (lexflow.com.mx, admin.lexflow.com.mx, app.lexflow.com.mx), iOS mobile app, Android mobile app, progressive web app (PWA) and, soon, voice integration with Amazon Alexa for authorized queries and notifications.

3. Personal data we collect

To deliver the service we collect the following categories of personal data, either directly (when you provide them through forms, apps or files you upload) or indirectly (when generated automatically as you use the platform):

  • Identification: name, surname, RFC tax ID, CURP for legal representatives when applicable, date of birth if recorded by the customer.
  • Contact: corporate email, landline and mobile phone, registered address of entities, service-of-process addresses.
  • Employment & professional: job title, area, role assigned within the tenant, bar registration when documenting internal or external counsel.
  • Academic data when customers upload it as part of their record set.
  • Financial: bank accounts and CLABE codes, transaction amounts, budgets, fees, legal spend — always uploaded by the customer for their own management.
  • Biometric data limited to the fingerprint hash generated by Mifiel advanced electronic signature, when the customer chooses to use it.
  • Technical metadata: IP address, user agent, device identifiers, browser language, timestamp of every action.
  • Access, read, download, edit and print logs: required for traceability and audit.

4. Sensitive personal data

LexFlow does not require or request data classified as sensitive under LFPDPPP (racial origin, health, beliefs, sexual life, political opinion, union membership) to operate. If the customer chooses to upload this kind of information into its records (e.g., in a labor lawsuit), the processing is performed under the customer's responsibility as data controller, and LexFlow acts strictly as a data processor under article 50 of the LFPDPPP Regulations.

5. Purposes of processing

Personal data is processed for the following primary purposes, without which the service cannot be provided:

  • Provide and operate the contracted SaaS platform (corporate governance, contracts, litigation, lease accounting, IP, compliance, etc.).
  • Create and manage user accounts, authenticate them via AWS Cognito and enforce multi-factor authentication (MFA) when required by the tenant.
  • Generate and safeguard the immutable audit log required by corporate governance and financial regulation standards.
  • Send operational notifications and configurable alerts via email, SMS or WhatsApp.
  • Invoice and collect payments for contracted services.
  • Handle support, training and legal-technical consulting requests arising from implementation.
  • Comply with applicable legal obligations (tax, commercial, financial, labor).

6. Secondary purposes

Additionally, and as long as you do not object, we may process your data to improve the product through aggregated and dissociated statistical analysis; send you communications about new features, training, events and relevant legal content; and run satisfaction surveys and discovery interviews.

7. How to opt out of secondary purposes

You may object at any time by emailing acastillejos@dixi-project.com with the subject line "Opt-out from secondary purposes". Your refusal does not affect the provision of the service.

8. Artificial intelligence and personal data

LexFlow uses generative AI models (Claude Haiku 4.5 via Amazon Bedrock) to assist users with semantic search, template drafting and invoice review. We operate under the Zero Data Retention regime agreed with AWS: models do not store prompts and do not use them for retraining.

Vector retrieval is built from embeddings (irreversible mathematical representations), so the model provider does not receive the raw original text in full. Every AI call is recorded in an internal audit log with tenant, user, model, tokens, cost and outcome, available to the customer for inspection.

9. Transfers and remittances

LexFlow does not sell, rent or share your personal data with third parties for purposes other than service operation. The only remittances (article 36 LFPDPPP) occur with processors that act under our documented instructions and equivalent confidentiality and security clauses:

  • Amazon Web Services, Inc. (AWS): cloud infrastructure provider (compute, storage, database, identity, messaging). Primary region us-east-2 (Ohio) with backup replica in us-east-1.
  • Anthropic, PBC: through Amazon Bedrock, exclusively to process prompts under zero retention.
  • Mifiel S.A.P.I. de C.V.: when the customer chooses to use NOM-151 advanced electronic signature.
  • Twilio / SMS and WhatsApp Business operators: when the user activates these notification channels.
  • Google reCAPTCHA: anti-spam protection on the public contact form.

10. International transfers

Data is stored in the United States of America, within AWS region us-east-2. This transfer is necessary for service provision (article 37 fraction IV LFPDPPP). AWS holds SOC 1, SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, PCI DSS and FedRAMP certifications, and has signed standard contractual clauses and compliance commitments with applicable data-protection regulations.

11. Security measures

  • AES-256 encryption at rest (AWS S3, RDS, EBS) and TLS 1.2+ in transit.
  • Logical multi-tenant isolation with mandatory tenant_id on every table and Row-Level Security in PostgreSQL as an additional safety net.
  • AWS Cognito authentication with multi-factor authentication (MFA) enforceable per organization and mandatory for privileged roles.
  • Optional Single Sign-On (SSO/SAML) per tenant.
  • Pre-signed URLs with 5-minute lifetime to access documents.
  • Immutable audit log with authoritative server-side timestamps (not client-side).
  • Outbound webhooks signed with HMAC-SHA256.
  • Encrypted automatic daily backups with at least 30-day retention.
  • Periodic penetration testing and continuous monitoring (CloudWatch, GuardDuty).

12. Data retention

Personal data is retained for the duration of the contract and for any additional periods required by applicable law (commercial, tax, labor or procedural). Audit logs are retained for the minimum period required by the customer's regulatory frameworks. Upon contract termination, the customer can export all of its information in standard formats; once the agreed transition period elapses, data is securely deleted following certified procedures.

13. Data-subject rights and consent revocation

You have the right to know (Access) what personal data we hold, request its Rectification when inaccurate, request Cancellation if you believe processing does not comply with the law, or Object to specific uses. You may also revoke previously granted consent.

To exercise these rights, send a request to acastillejos@dixi-project.com including: full name, copy of an official ID, clear description of the right being exercised and the data concerned. We will respond within a maximum of 20 business days. If you are not satisfied with the answer, you may file a complaint with INAI (https://home.inai.org.mx).

14. Cookies and similar technologies

Our website uses strictly necessary cookies to keep your session, remember language preference and improve performance. We do not use third-party advertising cookies. You may disable cookies in your browser, but some platform features may stop working correctly.

15. Changes to this notice

Any material change to this notice will be communicated through the portal and by email to the tenant administrator with at least 15 calendar days' notice before taking effect.

Data Protection Office

  • Email: acastillejos@dixi-project.com
  • Operator: Dixi Project S.A.S. de C.V. (LexFlow)
  • Response window for data-subject requests: 20 business days
  • Regulator: INAI — https://home.inai.org.mx