This Privacy Notice is issued in full compliance with the provisions of the Mexican Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations.
Data Controller / Responsible for Personal Data:
The legal entity responsible for collecting, protecting, and treating your personal data for the platform
QRO. VERIFICADO is
SGSD — Sistemas Generales & Sistemas Digitales (Sociedad por Acciones Simplificada), with RFC
SGS170324HVA, phone
442 644 5404, and contact email
[email protected].
1. Personal Data and Documentation We Collect
To carry out the technical, documentary, and commercial audit process, we collect the following personal data and documentation from the applicant:
- Contact Information: Full name of the responsible party or legal representative of the business, institutional email address, phone number (landline and/or mobile/WhatsApp).
- Business Information: Commercial name, corporate name, tax identification (RFC), physical establishment address, and web domain to be evaluated.
- Documentary Accreditation File: Copy of valid official ID (INE/Passport) of the owner or representative, updated Tax Situation Certificate (RFC), recent proof of commercial address, and proof of domain administration rights.
- Payment Processing Metadata (Stripe): For online transactions processed via Stripe (Stripe, Inc. / Stripe Payments Europe), only general transaction metadata is processed. SGSD / QRO. VERIFICADO does NOT collect, store, or have access at any time to sensitive financial or credit card data (such as full card numbers, CVV/CVC codes, or expiration dates). All card payments are encrypted directly by Stripe under PCI-DSS Level 1 security standards.
- Commercial Agents / Affiliates Program: Full name, email, WhatsApp phone, profile picture (for official credential), signature or electronic acceptance of contract, and bank/tax details (Bank, CLABE, Beneficiary Name, RFC) for commission payment invoicing.
2. Safe Keeping and Confidentiality of Audit Files
All documentation submitted to compile the audit file is treated with the character of strictly confidential.
SGSD implements technical, administrative, and physical security measures to guarantee that:
- Documents are stored on secure servers with storage encryption and restricted access limited only to authorized audit staff.
- No public disclosure is made of any sensitive documents contained in the file.
- Under no circumstances are these data or documents transferred, rented, or sold to third parties, except under an explicit judicial order issued by a competent authority.
- Retention of audit records is maintained during the active validity of the verification and preserved in accordance with fiscal and legal record-keeping requirements.
3. Use of Cookies and Analytical Tools
Our website uses cookies and tracking technologies (including Google Analytics and Google Tag Manager) to analyze web traffic, understand user navigation patterns, and continuously improve user experience. The information collected by these tools is aggregated and anonymous, and is not associated with your personal identity. You may configure your browser to block or alert you about cookies at any time.
4. Purposes of Data Treatment
Your personal data will be used exclusively for the following necessary primary purposes:
- To evaluate and perform the technical, documentary, and operational audit of your digital presence.
- To contact you regarding audit diagnosis, observations, and final evaluation results.
- To issue, register, and validate the Digital Trust Seal on our infrastructure.
- To manage and publish the public information of your verified business in our Public Registry and Directory.
- To handle support inquiries, clarifications, and report notifications.
- For the Commercial Agents Program: To validate applicant registration, issue official digital credentials, record accumulated referral commissions, and execute bank transfers for commission payouts.
5. ARCO Rights (Access, Rectification, Cancellation, Opposition)
You have the right to know what personal data we hold about you, what we use it for, and the conditions of its use (Access). Likewise, it is your right to request the correction of your information if it is outdated or inaccurate (Rectification); to request deletion from our records when you consider it is not being used properly (Cancellation); as well as to oppose the use of your data for specific purposes (Opposition).
To exercise any of your ARCO rights, please submit your request via email to: [email protected], including your full name, business domain, and specific request details.
6. Transfers of Personal Data
SGSD does not transfer your personal data to third parties without your prior consent, except for the exceptions provided in Article 37 of the LFPDPPP or upon formal judicial mandate from competent authorities.
7. Changes to the Privacy Notice
This Privacy Notice may undergo modifications or updates derived from legal requirements, internal policies, or new service practices. Any updates will be published directly on this page: https://qroverificado.com/aviso-privacidad.php.