Privacy notice
Mi Web PyME · June 2026
Courtesy translation. This document is provided in English for your convenience. Mi Web PyME operates under Mexican law, and the Spanish version is the legally binding one. In the event of any discrepancy, the Spanish text prevails.
- Data controller
- Mi Web PyME, with address at Parque Tecnológico Orión, PIT2, Avenida Heroico Colegio Militar no. 4700, Colonia Nombre de Dios, Chihuahua, Chihuahua, Mexico.
- Privacy contact
- privacidad@miwebpyme.com
- Website
- www.miwebpyme.com
- WhatsApp Business
- 614 132 0099
1. Scope of this notice
This Privacy Notice applies to prospects, clients, business representatives, suppliers, commercial partners, website users and any person who provides data to Mi Web PyME through forms, WhatsApp, email, telephone, contracts, quotes, briefs, advertising platforms or any other authorized channel.
Mi Web PyME processes personal data in accordance with the principles of lawfulness, purpose, loyalty, consent, quality, proportionality, information and accountability, and limits its use to the purposes described in this document.
2. Personal data we may collect
Depending on the service requested, the following categories may be processed:
- Identification and contact: name, telephone, WhatsApp, email address, postal address, job title, and the company or business represented.
- Commercial and project information: industry, products, services, business hours, copy, logos, photographs, videos, testimonials, social media accounts and any other material needed to build or publish the project.
- Tax and payment information: RFC (Mexican tax ID), legal name, tax regime, tax postal code, proof of tax situation, CFDI use, receipts, payment references, deposits, final payments, refunds and chargebacks.
- Technical information: domain, hosting, email accounts, configurations, temporary access credentials, activity logs and any data required to connect services or providers.
- Browsing data: IP address, device, browser, operating system, date and time of access, pages visited, traffic source, and interaction with forms or buttons.
Mi Web PyME does not request banking passwords, PINs, one-time codes, security codes or full card numbers. Card payments are processed directly by financial providers or payment gateways under their own terms and notices.
3. Sensitive personal data
Mi Web PyME does not request sensitive personal data as an ordinary part of its services. Users are asked not to send information regarding health, ethnic origin, beliefs, political opinions, sexual preferences, biometric data or other sensitive categories. Should an exceptional project require such processing, the purpose will be disclosed beforehand and the corresponding express consent will be obtained.
4. Primary purposes
Data will be used for the activities necessary to initiate, carry out and manage the commercial relationship:
- Responding to enquiries, identifying prospects, preparing quotes and following up on contracting.
- Building the client file, validating payments, issuing tax receipts, and managing deposits, final payments, renewals, clarifications or refunds.
- Developing, configuring, publishing, maintaining and supporting websites, online sales, domains, hosting, SSL certificates, business email accounts, forms, analytics tools and related services.
- Integrating copy, images, products, prices, contact details and any other material provided for the project.
- Coordinating technology providers and performing the configurations required to deliver the service.
- Communicating about missing information, progress, reviews, approvals, delivery, support, renewal and continuity of the service.
- Protecting accounts and infrastructure; preventing fraud, spam, phishing, unauthorized access, security incidents and misuse.
- Complying with legal, tax, administrative and contractual obligations; keeping records and responding to requests from authorities or to rights requests.
Missing essential data may prevent us from quoting, contracting, invoicing, developing, publishing, operating or supporting the service.
5. Secondary purposes
Independently of the purposes above, Mi Web PyME may use contact details and public project information to:
- Send promotions, news, commercial information and follow-ups about related services.
- Conduct surveys, satisfaction measurements and statistical analysis to improve processes and service.
- Display the project, trade name, logo and public results in our portfolio, website, social media, presentations or case studies.
The data subject may refuse these purposes or withdraw authorization at any time by writing to privacidad@miwebpyme.com, without affecting delivery of the main service. No testimonials, non-public personal images or confidential information will be published without the corresponding authorization.
6. Online sales and buyer data
When Mi Web PyME develops or configures an online sales solution for a client, it may have technical or temporary access to buyer data such as name, telephone, email, delivery address, billing details, products, orders and purchase-related communications.
The business offering the products or services is the primary controller of that data and must have its own privacy notice and its own purchase, shipping, cancellation, return and security policies. Mi Web PyME acts solely as a data processor when handling that data on the client's instructions, and will not use it for its own incompatible purposes.
Full card details must be processed by the selected payment gateway and must not be stored outside its authorized mechanisms.
7. Sales representatives and commercial partners
Mi Web PyME may work with authorized sales representatives, promoters or partners to attend prospects, provide commercial information and channel contracting. These persons may only collect the minimum data required, use authorized channels, and handle information in accordance with instructions and with confidentiality, security, return and deletion obligations.
Banking passwords, PINs, one-time codes, full card numbers, buyer databases, and payments to personal or third-party accounts must never be given to sales representatives. Tax documentation, access credentials and sensitive information must be sent exclusively through official channels.
8. Processors, providers and transfers
To deliver the service, Mi Web PyME may pass data to processors acting on its instructions, including providers of domains, hosting, email, storage, development, support, invoicing, security, analytics and communications. Access is limited to the information necessary for the service, and reasonable confidentiality and security conditions are required.
Transfers may also be made to banks, payment gateways, tax, administrative or judicial authorities, advisors and third parties when necessary to fulfil the legal relationship, comply with a legal obligation, protect rights or act on an instruction from the data subject.
Some providers may operate or store information outside Mexico. Such use will be limited to what is necessary and will be subject to their policies, terms and security measures. Transfers requiring consent will be carried out in accordance with applicable law.
9. Cookies and tracking technologies
The website may use cookies, server logs, tags or pixels to operate correctly, maintain security, remember preferences, measure visits, analyse browsing and evaluate campaigns. These technologies may collect IP address, device, browser, pages visited, session duration, traffic source and interactions.
Non-essential cookies can be managed through the mechanism available on the website or from the browser settings. Disabling technical cookies may limit some functionality.
10. Security and responsible use
Mi Web PyME maintains reasonable administrative, technical and physical measures appropriate to the nature of the data and the risks identified. These measures include access control, passwords, SSL certificates, backups, system updates, activity logging, limited permissions, confidentiality agreements and preventive suspension of compromised accounts.
No system is completely invulnerable. Clients and users must protect their passwords, devices and credentials; report suspicious activity; and avoid sharing credentials or sending information through unauthorized channels.
11. Security breaches
If a breach occurs that may significantly affect the property or moral rights of data subjects, Mi Web PyME will take reasonable containment, investigation and remediation actions, and will notify affected persons where legally required. The communication may describe the nature of the incident, the data compromised, the measures taken and recommendations to reduce risk.
12. Retention and deletion
Data will be retained for the duration of the commercial relationship and for as long as necessary to deliver the service, manage renewals, support, invoicing, clarifications, contractual responsibilities and legal retention periods.
Once the purposes have been fulfilled, data will be blocked and subsequently deleted, destroyed or anonymized, unless a legal obligation or legitimate reason to retain it exists.
Backups may temporarily retain information until their ordinary replacement cycle is complete. Temporary access credentials must be revoked or changed once they are no longer needed.
13. ARCO rights, revocation and limitation
The data subject may request access to their data; rectification of incorrect information; cancellation where applicable; objection to certain uses; revocation of consent; or limitation of use and disclosure, including opting out of promotional communications and exclusion from the portfolio.
Requests must be sent to privacidad@miwebpyme.com and must include:
- The data subject's name and a means of receiving a reply.
- A document proving identity and, where applicable, legal representation.
- A clear description of the right or measure requested and of the data involved.
- Details that help locate the information; for rectification, the changes requested and supporting documents.
Mi Web PyME will communicate its determination within 20 business days of receiving a complete request. If the request is granted, it will be carried out within the following 15 business days. These periods may be extended once for an equal period where justified.
Cancellation or revocation will not apply to data that must be retained to comply with legal, tax or contractual obligations, resolve disputes or exercise rights. The procedure is free of charge, except for reasonable reproduction or delivery costs where legally applicable.
14. Minors and third-party data
Our services are directed at adults with legal capacity to enter into contracts. Mi Web PyME does not knowingly collect data from minors without authorization from their parents or legal guardians. Any client providing data, photographs or materials belonging to employees, collaborators, buyers, minors or any third party declares that they have sufficient authorization and legal basis for their use, publication or disclosure.
15. Changes to this notice
Mi Web PyME may update this notice due to legal, operational, technological, commercial or provider changes. The current version and its update date will be available at www.miwebpyme.com. Where a change requires new consent, it will be requested by email, WhatsApp, form or another authorized means.
16. Consent
By providing data after this notice has been made available, the data subject acknowledges having been informed about the controller, the data processed, the purposes, the third parties involved and the mechanisms for exercising their rights. Where the law requires express consent, Mi Web PyME will provide a specific mechanism to obtain it.
Short-form notice for forms and sales representatives
Mi Web PyME will use your data to respond to your enquiry, prepare a quote, follow up commercially and, where applicable, manage the contracting and delivery of the service. To learn about the full processing and exercise your rights, see www.miwebpyme.com/en/privacy-notice or write to privacidad@miwebpyme.com.
Mi Web PyME June 2026