LEGAL

Privacy Policy

Last updated: March 2026

1. Data Controller

Genesis Business (hereinafter, "Genesis"), located in Los Mochis, Sinaloa, Mexico, is responsible for the processing of your personal data in accordance with Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations. This Privacy Policy applies to all personal data collected through our website (genesisbusiness.net), our platform (app.genesisbusiness.net), contact forms, email and any other communication channel.

2. Personal Data Collected

For the purposes stated in this Policy, we may collect the following categories of personal data:

  • Identification data: Full name, company or business name, position or title.
  • Contact data: Email address, phone number / WhatsApp, business address.
  • Platform usage data: Registration information, activity within the platform (sales, products, customers, employees, expenses), configuration preferences, IP address, browser type and device.
  • Financial data: Billing information processed by Stripe (Genesis does NOT store credit or debit card data directly).

3. Purpose of Data Processing

Your personal data will be used for the following primary purposes (necessary for the contractual relationship) and secondary purposes (optional):

  • Primary purposes: Create and manage your account, provide contracted services (ERP, marketing, design, web, AI), process payments and billing, provide technical support, and comply with legal obligations.
  • Secondary purposes: Send communications about new services, updates or promotions, conduct satisfaction surveys, and generate internal statistics and reports with anonymized data.
  • If you do not wish your data to be processed for secondary purposes, you may send your request to privacidad@genesisbusiness.net. Refusal will not affect service delivery.
  • We do not make automated decisions or profiling that produce legal effects on you.

4. ARCO Rights

You have the right to Access, Rectify, Cancel or Oppose the processing of your personal data (ARCO rights), as well as to revoke consent granted and to limit the use or disclosure of your data. To exercise these rights, send a request to privacidad@genesisbusiness.net, including: (1) your full name, (2) email associated with your account, (3) clear description of the right you wish to exercise, and (4) any document proving your identity. We will respond within a maximum of 20 business days from receipt of the complete request. If the request is valid, it will be effective within the following 15 business days. Deadlines may be extended once, with justification.

5. Cookies and Tracking Technologies

Our website and platform use cookies and similar technologies. The types of cookies we use are:

  • Essential cookies: Necessary for platform operation (user session, language preferences). These cannot be disabled.
  • Analytics cookies: We use Google Analytics and Vercel Analytics to understand how users interact with our site, improve browsing experience and measure performance. This data is anonymized and aggregated.
  • You can accept or decline non-essential cookies through the banner shown when entering the site. You can also configure your browser to block or delete cookies, although this may affect site functionality.

6. Third-Party Data Transfers

We do not sell, rent or share your personal data with third parties for marketing purposes. Data may only be transferred to the following third parties, under strict confidentiality and security obligations:

  • Technology infrastructure providers: Vercel (hosting), Neon (database) — servers located in the United States. These transfers are made under the exceptions of Article 37 of the LFPDPPP.
  • Service providers: Stripe (payment processing), Resend (email delivery), Google Analytics (web analytics), Sentry (error monitoring).
  • Competent authorities: When required by law, regulation, legal process or applicable government request.

7. Security Measures

Genesis implements administrative, technical and physical security measures to protect your personal data against damage, loss, alteration, destruction, unauthorized use, access or processing. These measures include: data encryption in transit via HTTPS/TLS, data encryption at rest, role-based access controls, passwords hashed with secure algorithms (bcrypt), error and suspicious activity monitoring, periodic database backups, and periodic security policy reviews. While we strive to protect your data, no transmission or storage system is completely secure, and we cannot guarantee absolute information security.

8. Data Retention

We will retain your personal data for as long as you maintain an active account on our platform and for such additional time as necessary to comply with our legal obligations, resolve disputes and enforce our agreements. Data from cancelled accounts is retained for 30 calendar days to allow export, after which it is permanently deleted. Data collected through the contact form is retained for a maximum of 12 months. Billing records are retained for the period required by Mexican tax legislation (5 years).

9. Children's Rights

The Platform is not directed at individuals under 18 years of age. We do not intentionally collect personal data from minors. In particular:

  • Account creation by individuals under 18 is not permitted.
  • If Genesis becomes aware that it has collected data from a minor without verifiable parental consent, it will take steps to delete such information.
  • If you are a parent or guardian and believe your child has provided personal data, contact privacidad@genesisbusiness.net.

10. International Transfers

Your personal data may be transferred to and processed on servers located outside Mexico, specifically in the United States (where our infrastructure providers Vercel and Neon are hosted). These transfers are made under the exceptions provided in Article 37 of the LFPDPPP, as they are necessary for the fulfillment of the contractual relationship. International providers are contractually obligated to protect your data with security measures equivalent to or greater than those required by Mexican legislation.

11. Changes to this Privacy Policy

We reserve the right to modify this Privacy Policy at any time. Any substantial changes will be notified by posting on this page with the corresponding update date and, when possible, by email. We recommend reviewing this Policy periodically. Continued use of our services after the publication of changes constitutes your acceptance of them.

12. Contact and Complaints

For any questions, ARCO rights exercise requests, complaints or inquiries related to the processing of your personal data, you may contact us at: Email: privacidad@genesisbusiness.net. WhatsApp: at the number published on our website. If you believe your right to personal data protection has been violated, you may file a complaint with Mexico's National Institute for Transparency, Access to Information and Personal Data Protection (INAI) through their website: www.inai.org.mx.