Skip to content
Nodo Guanajuato
InicioNosotros
Explorar +
01 Agenda02 Proyectos03 Convocatorias04 Recursos
RedDirectorioContacto
Iniciar una conversación ↗
Menú
InicioNosotrosExplorarAgendaProyectosConvocatoriasRecursosRedDirectorioContacto

Institutional data framework

Español ↗

Comprehensive privacy notice

This notice explains how Nodo Guanajuato A.C. processes personal data across its websites, forms, programs, applications, and digital integrations, including tools that connect to and publish content on third-party accounts.

Controller: Nodo Guanajuato A.C.Effective: August 14, 2026Version 2.0
On this pageControllerScopeData we processPurposesApps and integrationsProviders and transfersRetention and securityYour rightsCookiesChanges and law

1. Identity and address of the controller

Nodo Guanajuato Asociación Civil (Nodo Guanajuato A.C.) is the controller responsible for the personal data described in this notice.

Address: San Clemente 16, Colonia San Clemente, Guanajuato, Guanajuato, Postal Code 36010, Mexico.

Data Protection Office: contacto@gto.rgmx.global

Website: https://gto.rgmx.global/

2. Scope

This notice covers websites and subservices operated by Nodo Guanajuato A.C., as well as forms, registrations, programs, internal tools, prototypes, applications, and connectors that identify this notice as applicable.

It may cover several applications and several authorized accounts on third-party platforms. Each application keeps separate credentials and permissions, while relying on this common framework whenever Nodo Guanajuato A.C. is the controller.

3. Personal data we may process

Data you provide

  • Name, organization, role, country, email address, phone number, and contact preferences.
  • Information included in requests, forms, proposals, program registrations, and communications.
  • Content, titles, descriptions, media files, editorial instructions, and publishing dates you choose to upload or schedule.

Account and integration data

  • Platform-provided account identifiers, display name, avatar, and authorization status.
  • Access or refresh tokens, granted permissions, and technical data required to maintain an authorized connection. We do not ask for or store your platform password.
  • Upload and publication metadata, such as content ID, status, date, destination account, and technical response from the platform.

Technical data

  • IP address, date and time, browser, operating system, requested URL, security logs, errors, and audit events.

Sensitive data. We do not ordinarily request sensitive, financial, or asset-related personal data. If a specific activity requires sensitive data, we will request express consent as required. Please avoid including sensitive data unnecessarily in forms or content.

4. Purposes of processing

Primary purposes

  • Respond to requests, verify identity, and manage relationships with participants, partners, suppliers, and users.
  • Operate programs, registrations, events, projects, communities, and digital services.
  • Authenticate authorized accounts, enable integrations, and perform actions requested by the user.
  • Upload content as a draft, schedule it, or publish it directly to an authorized account; report results and retain minimal operational evidence.
  • Prevent fraud, abuse, or unauthorized access and maintain continuity, security, and support.
  • Meet legal, contractual, tax, accounting, and competent-authority requirements.

Secondary purposes

With authorization or where legally permitted, we may send calls for participation, newsletters, invitations, institutional content, and surveys. You may object or withdraw consent by writing to contacto@gto.rgmx.global. Refusal will not affect the primary service you requested.

5. Applications, accounts, and third-party platforms

Our tools may use third-party authorization mechanisms, including TikTok Login Kit and Content Posting API. A connection is created only when a person with authority over the account approves the permissions displayed by the platform.

  • We use information received from a platform only to authenticate, display the connected account, and perform requested uploads or publications.
  • We do not sell platform data or use it to build advertising profiles.
  • You can revoke access in the platform settings and ask us to delete associated data.
  • Revoking a connection does not automatically remove posts already visible on the platform; those posts must also be managed through the relevant account.
  • Third-party platforms process data under their own notices and terms. Nodo Guanajuato A.C. does not control their independent practices.

6. Service providers, third parties, and transfers

Processors may handle data on our behalf for hosting, email, security, storage, support, strictly necessary analytics, and automation. They are subject to instructions, confidentiality, and appropriate safeguards.

When you request a connection or publication, we send the destination platform only the data and content needed to carry out that instruction. Some platforms or providers may process information outside Mexico.

We do not sell personal data. Transfers to third parties other than processors will take place with consent when consent is required, or without consent only where applicable law permits it, including the cases set out in Article 36 of Mexico's Federal Law for the Protection of Personal Data Held by Private Parties.

7. Retention and security

We retain data only as long as needed for the stated purposes, the relevant relationship, legal obligations, and dispute resolution. Tokens are retained while a connection remains active or until they expire, are revoked, or are deleted at your request. Technical and publication logs are kept for periods proportionate to security, audit, and support needs.

We apply reasonable administrative, technical, and physical safeguards, including access controls, minimization, secret management, encryption where appropriate, audit logs, backups, and incident-response procedures. No system is completely infallible; we will provide legally required notice of significant security incidents.

8. ARCO rights, withdrawal, and deletion

You may request access, rectification, cancellation, or objection (known in Mexico as ARCO rights), limit use or disclosure, withdraw consent, and request deletion of data associated with an application or connected account.

Email contacto@gto.rgmx.global with your name and reply channel; the right or request involved; information sufficient to verify identity or representation; the relevant data or account; and, where applicable, documents supporting a correction. Never send passwords or tokens.

We will respond within applicable legal time limits. Mexican law generally provides up to twenty business days to communicate a determination and, if granted, fifteen additional business days to implement it, subject to a justified extension for an equal period.

Deletion may be subject to a blocking period or retention required for legal, contractual, tax, security, or legal-defense purposes. To disconnect an account faster, also revoke access through the relevant platform.

9. Cookies and similar technologies

The website may use cookies strictly necessary for security, session continuity, preferences, and functionality. If we add non-essential measurement or advertising technologies, we will identify them and provide consent controls where required. We do not claim to collect shopping or advertising habits when those functions are not active.

You can adjust cookies in your browser. Disabling essential cookies may prevent some functions from working.

10. Changes, language, and governing framework

We will publish material changes at this URL and show their effective date. If a change requires additional consent, we will request it through an appropriate channel.

Because the controller is established in Mexico, this notice is governed by applicable Mexican law, particularly the Federal Law for the Protection of Personal Data Held by Private Parties, enacted on March 20, 2025, with the latest official amendment consulted dated November 14, 2025, and applicable implementing provisions. The competent federal authority is Mexico's Ministry of Anti-Corruption and Good Governance, without prejudice to any other competent authority or mandatory rights that may apply where a person resides.

This English version supports international accessibility. If it conflicts with the Spanish version, the Spanish version prevails unless mandatory law requires otherwise.

Official source consulted: Chamber of Deputies of the Mexican Congress, current text of the Federal Law for the Protection of Personal Data Held by Private Parties.

Nodo Guanajuato

Trabajo global con raíces en Guanajuato, México.

AgendaProyectos públicosConvocatoriasRecursosRedDirectorioPrivacidadRed Global MX

© 2026 Nodo Guanajuato A.C.