# Privacy notice

> This notice explains what personal data Omirant Systems collects through this website, why we collect it, and the rights you have over it. It is issued under Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP).

- Canonical URL: https://omirant.com/en/privacy
- This page in Spanish: https://omirant.com/privacy.md
- Last updated: 2026-07-28

## Who is responsible for your data

Omirant Systems, a Conecta company, is the party responsible (“responsable”) for processing personal data collected through omirant.com.

## What personal data we collect

We collect only what you type into the contact form on this site. Depending on which form you use, that is:

- Your name
- Your work email address
- Your company name
- Your role
- Your region or city
- Information about your business: number of sites, vertical, regions, current tooling, security-review requirements, and whether you have an internal IT team

We do not collect sensitive personal data as the LFPDPPP defines it — nothing on health, religion, ethnic origin, political views, sexual orientation or financial details. Please do not put any of it in the free-text fields.

We do not buy contact lists, and we do not knowingly collect personal data from children.

## Why we process it

Primary purposes — necessary to give you what you asked for:

- To respond to your enquiry
- To work out which of your sites we would cover, and prepare a scope and a quote
- To arrange and hold the conversations that follow from your request
- To keep a record of our dealings with you, and to meet legal and accounting obligations

Secondary purposes — not necessary, and you may refuse them without affecting anything above: sending you occasional updates about Omirant's service. If you would rather we did not, reply to any message from us or write to the address below, and we will stop.

We do not use your data for automated decision-making or profiling, and we never sell it.

## Who else sees it

We do not sell, rent or trade your personal data, and we do not transfer it to third parties for their own purposes.

We do rely on a small number of service providers that process data strictly on our behalf and under contract — website hosting and email. They may use the data only to provide that service to us. Some operate servers outside Mexico; where that is so, the transfer is limited to what is necessary to deliver the service you asked for, as permitted by LFPDPPP art. 37.

We may also disclose data where a law, a court, or a competent authority requires it.

## How long we keep it

Enquiries that do not turn into a commercial relationship are kept for up to 24 months, so we can pick the conversation back up if you return to us, and are then deleted.

If you become a client, your data is kept for the length of the relationship and afterwards for the period required by applicable commercial and tax law.

Server logs are kept for a short operational period — no more than 12 months — and then discarded.

## Your ARCO rights

You have the right to Access your personal data, to Rectify it when it is inaccurate or incomplete, to Cancel it when you believe it is not being handled properly, and to Oppose its use for particular purposes. You may also revoke your consent at any time, and limit the use or disclosure of your data.

To exercise any of these rights, write to the contact address below with: your name and a way to reach you, proof of your identity (or of your representative's authority), a clear description of the data concerned, and what you are asking us to do.

We will answer within 20 business days of receiving a complete request, and where it is granted we will act on it within the following 15 business days, as the LFPDPPP requires. There is no charge, beyond justified delivery costs if you ask for a physical copy.

Revoking consent or asking us to delete your data does not undo processing that has already happened, and may mean we can no longer respond to your enquiry.

If you are not satisfied with our response, you may file a complaint with INAI, Mexico's national data protection authority, at inai.org.mx.

## How we protect it

The site is served over HTTPS only. Access to submitted enquiries is limited to the people at Omirant who need it in order to reply to you. Our internal security programme is modelled on ISO 27001 and SOC 2 Type II — both are targets we are working towards, not certifications we hold.

No system is perfectly secure. If a breach ever materially affects your rights, we will tell you without delay so you can take steps to protect yourself.

## Cookies and tracking

This site sets no cookies and runs no analytics or advertising trackers. The single item stored in your browser records your answer to the cookie notice. The cookie policy explains it in full.

## Changes to this notice

We may update this notice as the service, the law, or our own practices change. The current version always lives at this address, with the date it took effect shown at the top. If a change materially affects how we handle your data we will say so plainly here and, where the law requires it, contact you directly.

## Questions about this document

Omirant Systems · hello@omirant.com
