Privacy notice
Version · 1.0
Translation note and governing version. This English text is a courtesy adaptation prepared for readers outside Mexico. Atum Innovations is a Mexican company and the Spanish version of this notice is the binding one. You can reach it from the language switcher at the top of this page. If the two versions differ in meaning, the Spanish version prevails.
The short version. We only collect what you type into the contact form. We use it to reply to you. We do not sell it, we do not share it for advertising, and this site runs no analytics and no tracking scripts.
1. Who is responsible
Atum Innovations, S.A.S. de C.V. (“Atum”, “we”) is the data controller — el responsable under Mexican law — for the personal data described here. We are a Mexican company incorporated in 2026.
- Registered address: Valle del Amazonas 251, Valle de Aragón, Nezahualcóyotl, Estado de México, C.P. 57100, Mexico.
- Responsible team: Personal Data Department.
- Email for legal and privacy matters: legales@atum.mx
The Personal Data Department is the designated function for rights requests, consent withdrawals, questions and complaints. All privacy correspondence goes to that address, not to named individuals.
Which law applies. Our primary framework is Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and its implementing rules. We also honour the GDPR rights described in section 18 for people in the EEA and the UK, and the CCPA/CPRA rights described there for California residents. Where a local rule gives you more protection than Mexican law, we apply the local rule.
2. Who this notice covers
It covers people who:
- submit the contact form on this site;
- contact us by email, phone or WhatsApp at the details published on this site;
- browse this site.
It does not cover personal data we process on behalf of our clients inside their own platforms, including Punto de Encuentro. In those cases the client is the controller, Atum acts as processor, and the services agreement and data processing agreement between us govern.
3. What we collect
Only the following.
What you type into the contact form. Five fields, all required:
- Name
- Company or organization
- Work email address
- Project type, chosen from a fixed list
- Message, free text
Follow-up correspondence. The content of emails, calls or messages we exchange with you after your first enquiry, including any contact details you choose to share in them.
Technical submission data, in pseudonymized form. When you submit the form, our server records the date and time, and stores your IP address and browser user agent as one-way cryptographic hashes — we keep a fingerprint, not the value. These exist solely to rate-limit automated submissions and detect abuse. We also store a hash of the exact version of the consent text you accepted, as evidence of what you agreed to and when.
Browsing data. We collect none today. This site loads no analytics tooling and no third-party measurement scripts. See section 13.
We do not obtain data about you from any source other than you. We do not buy lists and we do not enrich your record with third-party data.
4. We do not collect sensitive personal data
We do not request, require or process sensitive personal data — data that could reveal racial or ethnic origin, present or future health status, genetic information, religious, philosophical or moral beliefs, union membership, political opinions or sexual preference. Under the CCPA/CPRA this also means we collect no “sensitive personal information”.
We do not request financial or payment data through this site, and we do not knowingly collect data from minors. This site is aimed at adults in a professional context.
Please do not put information of that kind into the message field. If we receive it anyway, we delete it as soon as we notice.
5. Primary purposes
These are necessary to deal with you. Without them we cannot answer.
a) Handling, following up on and answering your enquiry.
b) Preparing and sending proposals, quotes or technical information you ask for.
c) Scheduling and holding calls or product demos.
d) Entering into and performing a contractual relationship, where one arises.
e) Preventing abuse, fraud and automated submissions through the site’s forms.
f) Meeting legal and tax obligations and responding to lawful requests from competent authorities.
g) Demonstrating, to you or to a regulator, that we obtained your consent and on what terms.
6. Secondary purposes, and how to say no
These are not necessary to deal with you. They need separate consent.
h) Sending you product news or technical content from Atum.
i) Inviting you to events, technical sessions or satisfaction surveys.
How to refuse or opt out. Email legales@atum.mx with the subject “Secondary purposes” from the address you contacted us from, or use the unsubscribe link in any message we send you. We action it within five business days.
Refusing is not grounds for denying you the service you asked for, does not affect how we handle your enquiry, and carries no consequence for you.
7. Legal basis
For the primary purposes we rely on:
- your consent, given by accepting this notice before submitting the form;
- the necessity of managing a legal relationship, present or prospective, between you or your organization and Atum (LFPDPPP art. 10, sec. IV);
- compliance with legal obligations binding on Atum.
For the secondary purposes we rely on your consent alone, which you can withdraw at any time.
GDPR bases, if you are in the EEA or the UK: Article 6(1)(b) for pre-contractual steps taken at your request; Article 6(1)(a) for marketing communications; Article 6(1)(f) for our legitimate interest in system security and abuse prevention.
8. Processors and vendors
A processor handles data on Atum’s behalf and on our instructions. A processor’s access is not a “transfer” under Mexican law and needs no separate consent from you.
We use the following categories of vendor. We do not name them individually because they can change; if you need the current named list, request it in writing at legales@atum.mx.
| Category | What for |
|---|---|
| Web hosting provider | Serving this site and running the contact form endpoint |
| Corporate email provider | Receiving your enquiry and replying to you |
| Professional services providers | Legal, accounting and tax advice, under a duty of confidentiality |
All are contractually bound to process data only on our instructions, to keep it confidential, and to maintain security measures equivalent to ours.
International storage. Some vendors may store information outside Mexico, including in the United States and the European Union. Where that happens we require contractual guarantees of equivalent protection, including standard contractual clauses where applicable. If you are in the EEA or the UK, note that your data may be processed in Mexico, which does not hold a European adequacy decision; the safeguard we rely on is the contractual one described here.
9. Transfers
Atum does not sell, rent or trade your personal data. We do not disclose it for advertising.
The following transfers do not require your consent, because Mexican law permits them:
- To competent authorities, under a duly founded and reasoned request, or where necessary to establish or defend a legal claim.
- To our outside legal, accounting or audit advisors, under a duty of confidentiality, where necessary for Atum to meet an obligation.
- Where necessary under a contract entered into, or to be entered into, in your interest.
- In a merger, spin-off or acquisition of Atum, to the acquirer, which becomes bound by this same notice.
Any other transfer requires your prior, express consent, which we would request case by case, naming the recipient and the purpose.
10. Your ARCO rights
Mexican law gives you four rights, known together as ARCO:
- Access the personal data we hold about you and the conditions of its processing;
- Rectify it when it is inaccurate or incomplete;
- Cancel it when you believe it is not needed for the purposes in this notice;
- Object to its processing for specific purposes, or entirely where you have a legitimate reason.
Functionally these cover the same ground as the GDPR rights of access, rectification, erasure and objection, and as the CCPA rights to know, correct and delete. You do not need to work out which framework applies to you — write to us and we will apply whichever gives you more.
Where to send it. To the Personal Data Department at legales@atum.mx, subject “ARCO rights”.
What the request must contain (LFPDPPP art. 29):
- Your full name and an address or other means of replying to you.
- Proof of identity — valid government-issued ID — or, if you act through a representative or authorized agent, the document establishing that authority.
- A clear, precise description of the data the request concerns.
- Anything that helps us locate the data, such as the email address you wrote from or the approximate date of your original enquiry.
- For a rectification, additionally: the exact change requested and documentation supporting it.
Timelines. We will tell you our determination within a maximum of twenty business days of receiving the request. Where the request is well founded, we give it effect within fifteen business days of that answer. Each period may be extended once, by an equal period, where circumstances justify it; we would tell you about the extension and why. For California residents, this is well inside the CCPA’s 45-day window.
Cost. Exercising these rights is free. You would only cover justified shipping costs or the cost of reproducing copies, if any.
When we can say no. We may refuse where the law allows: you are not the data subject or cannot establish authority; the data is not in our records; granting the request would harm a third party’s rights; a legal impediment or an authority’s decision prevents it; or the correction, deletion or objection has already been made. In every case we explain the reason in writing.
11. Withdrawing consent
You can withdraw the consent you gave us at any time, through the same channel and with the same requirements as section 10, using the subject “Withdrawal of consent”.
Two honest caveats:
- Withdrawal is not retroactive: it does not undo processing carried out before we received it.
- It does not apply where processing is necessary to meet a legal obligation binding on us, or to keep and perform a contract in force between us. In that case we keep only the minimum required and we tell you so.
12. Limiting the use and disclosure of your data
Separately from the ARCO rights, you can ask us to limit the use or disclosure of your data without deleting it:
- Email the Personal Data Department, legales@atum.mx, subject “Limit use”. We confirm your entry on our exclusion list within five business days.
- Unsubscribe link in any commercial message we send you.
- Mexico’s Public Registry to Avoid Advertising, run by the federal consumer protection authority. Registering there also binds us.
While you are on our exclusion list we send you nothing for secondary purposes.
13. Cookies and tracking
This section describes what the site actually does today, not a generic template.
What we do not use: advertising cookies, social media pixels, fingerprinting, web beacons, third-party analytics, and third-party profiling scripts. This site loads no analytics tool at all. There is no Google Analytics or equivalent.
The one cookie that exists. Strictly necessary for the site to work, and exempt from consent:
| Name | What it stores | Lifetime |
|---|---|---|
atum_lang |
Your language preference, so we don’t ask twice | 12 months |
It is a first-party cookie. It goes to no external server and it does not identify you.
Browser local storage. We keep two values in your browser’s local storage. These are not cookies, they are never sent to a server with each request, and they identify nobody:
| Key | What it stores |
|---|---|
atum.motion.v1 |
Whether you turned site animation off |
atum.consent.v1 |
Your cookie category choices, if you ever made any |
About the consent banner. The granular consent logic is built and ready, but the banner only appears if a measurement tool is ever configured. None is configured today, so there is nothing to consent to and no banner is shown. If that changes, we will ask for your consent before loading any measurement script, and this section will be updated with the specifics.
Global Privacy Control. Because we run no advertising or analytics trackers and do not sell or share personal information, there is nothing for a GPC signal to switch off. If we ever add measurement, we will honour GPC as a valid opt-out.
How to control it. Clear this site’s cookies and local storage from your browser settings, any time, with no downside: the site keeps working and simply forgets your preferences.
14. Security
We apply reasonable administrative, technical and physical safeguards against damage, loss, alteration, destruction, and unauthorized use, access or processing. They include:
- TLS encryption in transit across the whole site;
- one-way cryptographic hashing of the IP address and user agent tied to each submission;
- enquiry records stored outside the server’s public directory, with restricted permissions;
- least-privilege access control with multi-factor authentication;
- access audit logging;
- backups with tested restores;
- confidentiality agreements with our staff and vendors.
On security frameworks, the only wording we use — here and everywhere else on this site — is this: architecture designed in line with ISO 27001 controls and the SOC 2 trust services criteria. Atum holds no certification under either framework, and we will not claim otherwise.
No system is infallible. If a breach occurred that significantly affected your rights, we would notify you without delay so you could take appropriate steps.
15. Retention
| Data | How long we keep it |
|---|---|
| Enquiries that do not lead to a commercial relationship | 24 months from last contact, then deleted or anonymized |
| Data tied to a contractual relationship | For the life of the contract, plus the periods required by Mexican tax and commercial law, which are at least five years |
| Pseudonymized IP and user agent fingerprints | With the enquiry record they belong to, for the same period |
| Rate-limiting buckets | Generated per day and discarded on expiry; they do not accumulate |
| Consent evidence | For the life of the relationship and the limitation period for claims arising from it |
At the end of a retention period, data is blocked before erasure, as Mexican law requires.
16. Changes to this notice
We may update this notice for legal reasons, changes to our services, or changes in our privacy practices.
Where it is published. The version in force is always on this page, with its update date shown above the text and a version number.
How you are told. Changes take effect on publication. Where a change is material — the identity of the controller, the purposes, or the conditions of transfer — we notify you by email if we hold that detail, and post a prominent notice on the site for at least thirty calendar days. If a change requires fresh consent, we ask before applying it.
We suggest checking this page from time to time.
17. Complaints
If you believe your data protection rights have been infringed, that we handled a request badly, or that we missed the deadlines in section 10, you can bring a rights protection proceeding before Mexico’s national data protection authority for the private sector — the National Institute for Transparency, Access to Information and Personal Data Protection (INAI), or the authority that has taken over its functions.
The proceeding must be started within fifteen business days of receiving our answer, or of the deadline for that answer passing. It can be filed directly or electronically, at no cost.
Nothing stops you from going straight to the regulator, but we would appreciate the chance to fix it first: write to legales@atum.mx.
If you are in the EEA or the UK, you may also lodge a complaint with your national supervisory authority. California residents may contact the California Privacy Protection Agency or the California Attorney General.
18. Additional rights where you live
European Economic Area and United Kingdom (GDPR). On top of the above you have the rights to restriction of processing, to data portability in a structured, commonly used, machine-readable format, to object to processing based on legitimate interests, and not to be subject to automated decision-making producing legal or similarly significant effects — we make no such decisions and do no profiling. Atum has not appointed an Article 27 EU representative, as it does not systematically target the European market.
California (CCPA/CPRA). In the past twelve months we have collected the categories of “identifiers” (name, work email) and “commercial information” (the project type and message describing what you want) set out in section 3, obtained directly from you, for the business purposes in sections 5 and 6. We disclosed them to service providers only, in the categories listed in section 8.
- We have not sold personal information. We have not shared it for cross-context behavioral advertising. We have never done either. That is why there is no “Do Not Sell or Share My Personal Information” link on this site: there would be nothing to opt out of.
- We collect no sensitive personal information, so the right to limit its use has nothing to operate on.
- You have the rights to know what we collect and why, to delete it, to correct it, to opt out of sale or sharing, and to non-discrimination for exercising any of them. We do not offer financial incentives for personal data, so there is no incentive programme to disclose.
- How to exercise them: email legales@atum.mx. We verify your identity by replying to the address on file and asking you to confirm details of your enquiry — a proportionate check, since we hold no account credentials. An authorized agent may act for you with written permission that we can verify.
- We respond within 45 calendar days, extendable once by a further 45 where reasonably necessary, and we will tell you if we extend.
Other US states. If you live in a state with a comprehensive privacy law — such as Virginia, Colorado, Connecticut, Utah or Texas — write to us at the same address. We apply the same access, correction, deletion and portability handling, and we do not process personal data for targeted advertising, sale or profiling in furtherance of decisions with legal effects.
19. Contact
Questions about this notice or about how we handle your data:
Personal Data Department · legales@atum.mx
Atum Innovations, S.A.S. de C.V. · Valle del Amazonas 251, Valle de Aragón, Nezahualcóyotl, Estado de México, C.P. 57100, Mexico.
See also our Terms of service.