This Privacy Notice is issued in full compliance with the provisions of the Mexican Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), its Regulations, and the Privacy Guidelines issued by the INAI.
1. Identity and Address of the Data Controller
Data Controller / Responsible for Personal Data:
Corporate Name: SGSD — Sistemas Generales & Sistemas Digitales, S.A.S.
RFC: SGS170324HVA
Physical Address: Circuito de la Constitución 13B, Tlalnepantla, Estado de México, C.P. 54025, México.
Phone: 442 644 5404
Privacy Contact Email: [email protected]
Platform operated: QRO. VERIFICADO (
qroverificado.com)
2. Personal Data We Collect
To carry out the technical, documentary, and commercial audit process under the ESCODI-QRO-001 V1.0 standard, we collect the following personal data from applicants:
- Identification Data: Full legal name of the applicant or legal representative, Official Identification Number / Voter Key (Clave de Elector), and Unique Population Registry Code (CURP), extracted directly and verified through official identity documentation.
- Contact Data: Institutional or personal email address, landline and/or mobile/WhatsApp phone number for operational communications and notifications.
- Business and Operational Data: Commercial brand name or corporate name (razón social), web domain address to be evaluated, business category (giro), municipality within the state of Querétaro, and physical operational address.
- Documentary Accreditation File: Copy or digital capture of valid official government-issued photo ID (INE/Passport) and recent proof of physical address (electricity bill CFE, water, property tax predial, landline telephone, or bank statement no older than 3 calendar months) of the commercial establishment or operational headquarters.
- Payment Processing Metadata (Stripe): For online transactions processed via Stripe, Inc. / Stripe Payments Europe, only general transaction metadata (amount, currency, transaction ID) is accessible by SGSD. SGSD / QRO. VERIFICADO does NOT collect, store, or have access at any time to sensitive financial data such as full card numbers, CVV/CVC codes, or expiration dates. All card payments are encrypted directly by Stripe under PCI-DSS Level 1 security standards.
- Commercial Agents / Affiliates Program: Full name, email, WhatsApp phone, profile picture (for official credential issuance), electronic contract acceptance, and bank/tax details (bank name, CLABE account, beneficiary name, RFC) for commission payment invoicing.
3. Sensitive Personal Data and Facial Biometrics
⚠️ Notice Regarding Sensitive Personal Data and Facial Biometric Recognition:
As part of the digital trust accreditation process, SGSD collects and processes official government-issued identification documents (INE / Passport) along with facial biometric data (facial geometry features, facial recognition vectors, real-time active/passive liveness detection, and technical face matching similarity scores).
Under Articles 3 fraction VI and 9 of the Mexican LFPDPPP, biometric data is categorized as sensitive personal data requiring explicit written or electronic consent and reinforced protection measures.
Purpose and Processing Architecture: These biometric data are collected and processed through encrypted channels powered by our specialized digital identity infrastructure provider, Didit Protocol S.L., exclusively to verify with mathematical precision that the individual initiating the accreditation process legitimately matches the identity presented in the official document, thereby preventing digital fraud, identity theft, and corporate impersonation.
SGSD only stores the resulting technical verification dictamen (cryptographic hash, verification timestamp, technical biometric similarity percentage, and authentication status). Biometric templates are never sold, rented, or repurposed for commercial, marketing, or profiling uses.
By initiating the identity verification process or submitting your documentation, you grant your express and informed consent for the collection and processing of your sensitive biometric data for these specified security purposes.
4. Primary Purposes of Data Treatment
Your personal data will be used for the following necessary primary purposes, which are required to provide the contracted service:
- To evaluate and perform the technical, documentary, and operational audit of your digital presence under the ESCODI-QRO-001 V1.0 standard.
- To technically and biometrically authenticate applicant identity via official document scanning, liveness detection, and algorithmic facial matching to prevent identity theft and certify legitimate commercial representation.
- To contact you regarding audit diagnoses, observations, correction periods, and the final evaluation result.
- To issue, register, and activate the Digital Trust Seal on our infrastructure and Public Registry.
- To manage and publish the public information of your verified business in our Public Registry and Directory.
- To handle support inquiries, clarifications, renewal reminders, and report notifications.
- To process payments and issue receipts or invoices through our payment gateway (Stripe).
- For the Commercial Agents Program: To validate agent registration, issue official digital credentials, record referral commissions, and execute bank transfers for commission payouts.
5. Secondary Purposes of Data Treatment
Secondary Purposes (Optional — You May Opt Out):
In addition to the primary purposes above, SGSD may use your personal data for the following secondary purposes, which are not necessary for the contracted service but allow us to improve our offerings:
- To send institutional communications, updates about new services, or improvements to existing services offered by QRO. VERIFICADO.
- To conduct statistical analysis and generate aggregate, anonymized metrics to measure the impact of the Digital Trust Validation program in the state of Querétaro.
- To invite you to satisfaction surveys or feedback programs related to the audit process.
- To publish testimonials, ratings, and opinions that you voluntarily submit through our satisfaction surveys on our public platforms, landing pages, or directories, provided that you grant explicit consent for publication.
If you do not wish your personal data to be used for secondary purposes, you may send your opt-out request to [email protected] at any time. Opting out of secondary purposes will not affect the provision of the primary contracted service.
6. Transfers of Personal Data to Third Parties
SGSD may transfer your personal data to the following third parties solely to fulfill the purposes described in this Privacy Notice:
| Recipient |
Country |
Purpose |
Legal Basis (Art. 37 LFPDPPP) |
| Didit Protocol S.L. / Didit Identity |
Spain / European Union |
Identity verification infrastructure: official identity document validation (OCR/NFC), active liveness detection, and facial biometric matching. |
Necessary for contractual performance, identity authentication, and fraud prevention (Art. 37 fraction IV LFPDPPP) under express consent. |
| Stripe, Inc. / Stripe Payments Europe, Ltd. |
USA / Ireland |
Secure payment processing for validation fees and renewals. |
Necessary for contractual fulfillment. Does not require separate consent. |
| Google LLC (Analytics & Tag Manager) |
USA |
Anonymous web traffic analysis. No personal identifiers are shared; data is aggregated and anonymized. |
Statistical purposes. Anonymous data. Does not require consent. |
| Competent Judicial Authorities |
Mexico |
Disclosure of data exclusively upon formal judicial or administrative order. |
Legal obligation under Art. 37 section III LFPDPPP. |
SGSD does not sell, rent, or otherwise transfer your personal data to any third party not listed above without your prior and express consent.
7. ARCO Rights (Access, Rectification, Cancellation, Opposition)
You have the following rights regarding your personal data held by SGSD:
- Access: To know what personal data we hold about you, the purposes of its treatment, and the conditions of its use.
- Rectification: To request correction of your personal data if it is inaccurate, incomplete, or outdated.
- Cancellation: To request deletion of your personal data from our records when it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
- Opposition: To oppose the treatment of your personal data for specific purposes.
How to Exercise Your ARCO Rights
To exercise any of your ARCO rights, submit your written request to: [email protected]
Your request must include:
- Your full name and contact email address.
- The web domain registered in our system (if applicable).
- A clear description of the right you wish to exercise and the data to which your request refers.
- A copy of an official government-issued ID to verify your identity.
Response Deadline: SGSD will respond to your ARCO request within 20 business days from the date of receipt, as established in Article 32 of the LFPDPPP. If the request is upheld, the corresponding measures will be implemented within 15 business days of communicating the response.
8. Revocation of Consent
You may revoke your consent to the treatment of your personal data at any time. However, please note that revocation of consent may prevent SGSD from providing the contracted services in whole or in part.
To revoke your consent, send a written request to [email protected] stating the specific data and purposes for which you wish to revoke consent. SGSD will process your request within 20 business days and inform you of the consequences of such revocation on the contracted services.
9. Limitation of Use and Disclosure
You have the right to request that SGSD limit the use or disclosure of your personal data. To exercise this right, send a request to [email protected] specifying:
- The specific data whose use or disclosure you wish to limit.
- The specific uses or disclosures you wish to restrict.
SGSD will evaluate your request and inform you of the outcome within 20 business days. Please note that certain limitations may affect the provision of contracted services that depend on the use of such data.
Additionally, you may register your personal data in the INAI Public Registry of Suppressed Persons (REPEP) to prevent your data from being used for advertising or commercial prospecting purposes. For more information, visit: repep.inai.org.mx
10. Security Measures
SGSD implements the following technical, administrative, and physical security measures to protect your personal data against unauthorized access, damage, loss, alteration, or disclosure:
- Technical measures: Storage encryption on secure servers, HTTPS/TLS encrypted data transmission, restricted access controls with multi-factor authentication for authorized personnel, automated security monitoring systems (AVM-QRO), and session management protocols.
- Administrative measures: Confidentiality agreements with authorized audit staff, internal policies for data handling and incident response, and periodic security reviews.
- Physical measures: Access controls to server infrastructure managed by certified hosting providers, with physical security perimeters.
- Payment security: Payment data processed exclusively through Stripe under PCI-DSS Level 1 certification — the highest security standard in the payment industry.
11. Data Retention Periods
SGSD retains personal data only for the time necessary to fulfill the purposes described in this Privacy Notice, subject to applicable legal and fiscal obligations:
- Accreditation and identity file (official ID dictamen, biometric verification hashes, and proof of address): Retained for the duration of the active validation and for a minimum of 5 years thereafter, in compliance with audit trail standards and fiscal record-keeping obligations under Mexican law.
- Contact and business data: Retained for the duration of the commercial relationship and up to 3 years after the last interaction or service expiration.
- Payment transaction metadata: Retained for 5 years in compliance with fiscal and anti-money laundering regulations.
- Commercial Agents Program data: Retained for the duration of the active agent agreement and for 5 years after termination for fiscal and commission record purposes.
Upon expiration of the applicable retention period, data will be securely deleted or anonymized.
12. Use of Cookies and Analytical Tools
Our website uses cookies and third-party tracking technologies (including Google Analytics and Google Tag Manager) to analyze web traffic, understand navigation patterns, and continuously improve the user experience. Information collected by these tools is aggregated and anonymous and is not associated with your personal identity. You may configure your browser at any time to block or receive alerts about cookies.
13. Changes to This Privacy Notice
This Privacy Notice may be modified or updated due to new legal requirements, internal policy changes, or new service practices. Any updates will be published on this page: https://qroverificado.com/aviso-privacidad.php
When changes are material, we will notify affected users via email to the address registered in our system at least 10 business days before the changes take effect. Continued use of our services after notification constitutes acceptance of the updated Privacy Notice.
14. Supervisory Authority
If you believe your data protection rights have been violated, you may file a complaint with the National Institute for Transparency, Access to Information and Personal Data Protection (INAI):