Contenidos
Política de Privacidad

Nuestra política de privacidad

Effective: April 15, 2025

11 Tecnologias, S de R.L. de C.V. (collectively, "Hilos" or "we" or "us") is provider of software-as-as-service platform (https://app.hilos.io/) enabling companies to automate and scale their conversations through Whatsapp.

Within the framework of its business activities, Hilos carries out processing of personal data, acting as a data controller. Identification and contact details for Hilos are set out in the "Contact Us" section of this Privacy Policy. The purpose of this Privacy Policy is to inform you on the manner in which the data are processed by Hilos acting as a data controller when you use our site, application or subscribe to Hilos's services (collectively, the "Services"), or where you otherwise interact with Hilos, as required by the data protection laws.

This Privacy Policy describes the conditions under which Hilos carries out, as data controller, the personal data processing described hereinafter and pertaining to the personal data of any of its customer, prospect, user of its website ("you" or "data subject").

For the purposes of this Privacy Policy, the term "Data Protection Laws" collectively refers to the laws and regulations applicable to personal data protection, including the Mexican Data Protection Law on the Protection of Personal Data held by Private Parties and its Implementing Regulations ("Mexican Data Protection Law"), Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data ("GDPR") or any other data protection law or regulation, to the extent applicable.

In accordance with the Data Protection Laws, the term "personal data" in this Privacy Policy refers to any information about you that allows you to be identified directly or indirectly as a natural person.

1. PERSONAL DATA PROCESSED

The categories or personal data we collect about you depend on your activity and interactions with Hilos. The following categories of data may be collected by Hilos:

  • Identification data (including title, name, first name, nationality);
  • Contact information (including postal address, country, email address, and telephone number, communication language, Whatsapp account details);
  • Account credentials (including user name, hashed password and other similar information used to verify the identity of our customers);
  • Commercial and financial or economic information (including information about the Services you subscribe to and payment information you provide in connection with these transactions, including billing address and payment card data);
  • Professional information (including current or former employer and job title);
  • Logs data (including information we may obtain through cookies, as IP address, browser type and version, operating system, interface, the pages you view on our site or application, the pages you view immediately before and after you access the sites, and the search terms you enter on our site or application, your geographical location (in order to ensure the content displayed is relevant for where you are), the name of your access provider and inferences drawn from these information.
  • Support data (including support tickets);
  • Preferences (including how you prefer to communicate with us, newsletter subscription preferences, answers provided in the feedback survey you completed, the Services that you are interested in, any preference you communicated to us);
  • Marketing and engagement data (including newsletter subscription, emails opened, clicks, ads interactions, tracking data);
  • Other information you provide when you interact with us (including messages sent to the chatbot, information provided in emails, or other communications that you send to us or otherwise contribute, including any related metadata).

These personal data are collected either directly from you (e.g. when you uses the Services or interact with us), or from you passively (e.g. through cookies), or from third parties (e.g. publicly available databases or social media platforms).

Information collected indirectly (right to opt-out for Mexican residents only)

In the event that we obtain your personal data indirectly, you have a period of 5 (five) business days, from the time we make the first contact with you, so you can express your refusal for the processing of your personal data for secondary purposes, through the email hey@hilos.io.

2. CHARACTERISTICS OF THE PROCESSING

MAIN CATEGORIES OF PROCESSING PURPOSES LEGAL BASIS OF THE PROCESSING (IF AND TO THE EXTENT REQUIRED BY APPLICABLE LAWS)
Use of the site/application
  • Access to the site and Services (i.e. enabling you to access to the site or Services and to create a personal account for ordering Services).
  • Management and answer to our customers and prospects’ general inquiries and requests.
  • Placement and reading of cookies or other trackers which are used for the sole purpose of carrying out the transmission of a communication or which are necessary for the provision of the Services you requested.
  • Audience measurement.
  • Prevention and detection of security incidents (e.g. fraud detection, access control).
  • Legitimate interest; or Performance of pre-contractual measures taken at your request; or Performance of the contract.
  • Performance of pre-contractual measures taken at your request and/or performance of the contract.
  • Legitimate interest.
  • Legitimate interest; or Consent where required by Data Protection Laws.
  • Legitimate interest.
Management of our relationship with our customers and prospects
  • Engaging with prospects (i.e. assessment of whether or not we can provide services to you or your business or organization).
  • Management of orders (i.e. monitoring of our contractual relationship with you, confirmation of the orders, follow-up of the relationship, payment).
  • Provision of support services (i.e. tracking customer inquiries and providing responses to customer inquiries).
  • Management of your requests, questions and claims.
  • Marketing purposes (i.e. communications regarding our Services, by electronic mail, by post or via your phone: calls, chatbot, SMS and MMS, instant messaging or social media).
  • Improving our Services and website/application (i.e. collection of your opinion on Hilos Services, including through data analytics, surveys and questionnaires and understanding how you use our Services in order to improve them).
  • Establish statistics, financial and commercial studies, perform analytics in order to provide you with personalized content.
  • Pre-contractual measures (processing necessary in order to take steps at your request prior entering into a contract).
  • Performance of a contract with you; or Compliance with our legal obligations.
  • Performance of a contract with you.
  • Performance of pre-contractual measures taken at your request; or Performance of the contract.
  • Legitimate interest; or Consent where required by Data Protection Laws.
  • Legitimate interest; or Consent where required by Data Protection Laws.
  • Legitimate interest, or Consent where required by Data Protection Laws.
Compliance with our legal and regulatory obligations and defending our rights
  • Management of your requests to exercise your rights (registration, communications with you, excerpts of required information).
  • Storage of the evidence necessary for defending our rights within the framework of judicial and other claims brought against us and for fighting fraud.
  • Management of requests from public or judicial authorities and communications with authorities.
  • Storage of invoices and other mandatory documents for the management of our general accounting and tax obligations.
  • Compliance with our legal obligations.
  • Legitimate interest; or Compliance with our legal obligations.
  • Legitimate interest; or Compliance with our legal obligations.
  • Compliance with our legal obligations.

If we need to process your personal data for purposes other than those listed in the table above, you may be informed and we will take all additional steps that may be necessary to ensure compliance with Data Protection Laws of any further processing.

Necessary and secondary purposes (for Mexican residents only)

The purposes of the data processing described in this Privacy Policy are necessary to comply with legal or contractual obligations. Therefore, your consent would not be required, except for the secondary purposes which are for audience measurement and marketing purposes.

Unless you indicate otherwise, we can collect and process your personal data for the secondary purposes listed above. You may, at any time, request your consent withdrawal for secondary purposes, according to Section 6 ("Your Rights Regarding Your Personal Data") described below.

3. COOKIES

We may collect technical information automatically from your computer or mobile device across different sites through the use of cookies or similar tracking technologies.

A cookie is a small data file that can be placed on your computer or mobile device when you visit a website. Cookies help analyze web traffic and let us know when and how you visit a particular site.

For more information about how we use cookies, the types of cookies we use, and how to manage your cookie preferences, please refer to our Cookies Policy.

4. DISCLOSURE OF YOUR PERSONAL DATA

4.1. Recipients of your personal data

The personal data we collect may be disclosed to the following categories of recipients for achieving the purposes of the processing described in this Privacy Policy:

i. our parent and affiliated companies;ii. our service providers involved in all or part of the processing identified and acting on our behalf (in particular, IT service providers, hosting provider, payment provider, digital service tool provider, among other contractors);iii. our partners who operate services available on our site/application;iv. our partners involved in the process of delivering personalized ads (including social networks), in particular to enable us to obtain relevant information about your interests, to better understand your profile and to send you personalized ads and offers corresponding to your choices and interests;v. audit, law firms, judicial and ministerial officials, administrative or judicial authorities before whom a dispute is brought, within the framework of compliance with our legal and regulatory obligations and to enable us to defend our rights and interests; andvi. entities in charge of our external control, such as statutory and other auditors, and entities in charge of internal auditing;

Some of our partners may further process your personal data for their own purposes as separate data controller. For instance, when you interact with links or ads on our site or application that redirect to other sites or applications, the third parties operating these sites, services or ads may process your personal data under their own responsibility as separate data controllers. We invite you to read their personal data protection policies to know the terms and conditions applicable to the processing of your personal data that these actors carry out.

In addition, some of our partners may be joint controllers of the processing. In such case we enter into a joint controller agreement in order to determine the respective responsibilities of each party for compliance with the obligations under Data Protection Laws.

Necessary and secondary purposes for the data transfers (for Mexican residents only)

All transfers are necessary to comply with legal or contractual obligations, except for personalized ads which is a secondary purpose. Unless you object to such processing by notifying us through our email, we may transfer your personal data to business partners for personalized ads purposes.

4.2 Transfers of personal data

Hilos is established in Mexico and may process your personal data for the purposes described above in Mexico or other countries, which may include the United States and countries located outside the European Union (i.e. EEA, Switzerland and United Kingdom).

When your personal data is transferred to countries other than your home country, you may not have the same rights and protections as you do under local law. Any international transfers of such personal data will be done in accordance with Data Protection Laws. This may include implementing adequate protection for the transfer of your personal data to recipients in those countries by entering into international data transfer agreement drawn up in accordance with Data Protection Laws, such as the European Commission's Standard Contractual Clauses, or any other valid mechanisms that may be available, or ensuring additional measures to guarantee a level of protection for your personal data that is materially equivalent to the one provided in the European Union.

5. RETENTION PERIOD

We may retain your personal data for a period of time consistent with the original purpose of collection or as long as required to fulfill our legal obligations.

After expiry of the applicable retention periods, your personal data will be deleted. If there is any data that we are unable, for technical reasons, to delete entirely from our systems, we will implement appropriate measures to prevent any further use of such data.

In some circumstances, we may anonymize personal data so that it may no longer be associated with a data subject, and in such cases we may use that anonymized information without further notice to you and outside of this Privacy Policy (because, once anonymized, it ceases to constitute a personal data within the meaning of Data Protection laws).

Further information regarding retention is available upon request. Please see the "Contact Us" section of this Privacy Policy.

6. YOUR RIGHTS REGARDING YOUR PERSONAL DATA

You may have certain rights relating to your personal data, subject to the local data protection laws as applicable. Please note that you can only exercise these rights with respect to personal data that Hilos processes about you as a data controller.

Depending on the applicable Data Protection Law and, in particular, if you are located in Mexico, the European Union, or the United States, these rights may include:

For Mexican residents

As regards your personal data, you have the following rights:

  • Right to access your personal data as well as information regarding the conditions and general aspects of the processing.
  • Right to rectify/correct your personal data where inaccurate or incomplete;
  • Right to limit the use/divulgation of your personal data;
  • Right to cancellation and erasure of personal data: you have the right to request the cancellation of your personal data at any time if you believe it is not being processed in accordance with the principles and obligations established by the Mexican Data Protection Law. The cancellation may apply to all of your personal data contained in a database or only a part of it, as requested.
  • Right to object to the processing of personal data or request its cessation at any time when:i. there is a legitimate reason and your specific situation requires it, justifying that even if the processing is lawful, it must cease to prevent harm to you, orii. you wish to express your objection to the processing of your personal data to prevent its use for specific purposes.

This right of objection does not apply when the processing is necessary to fulfill a legal obligation imposed on the data controller.

  • Right to withdraw consent, at any time, without retroactive effect.

Should you have any doubts or complaints regarding the processing of your personal data, or to know more about the applicable requirements and procedure to exercise your rights, you may contact us using the details provided in the "Contact Us" section below.

For European Union residents

As regards your personal data, you have the right to access, rectify, erase, object to, limit the processing of your personal data and the right to portability of your personal data, to the extent permitted by the Data Protection Laws.

You may also withdraw your consent at any time, in cases where it has been requested.

  • Right of access: You may request access to your personal data that we collect and process. If you make an access request, we will provide you with a copy of your personal data in our possession and all other information legally required.
  • Right to object: You may object, at any time, for reasons relating to your specific situation, to the processing of your personal data where this is based on our legitimate interest, unless our legitimate interest overrides your own interests, rights and freedoms, or the processing is necessary for determining, exercising or defending rights in a court of law. You may also, at any time, object to our processing of your personal data when such processing is carried out for the purpose of commercial prospecting by electronic means or by mail, including when the relevant processing constitutes profiling.
  • Right of rectification: At any time, you can request that we rectify any personal data about you that is inaccurate or incomplete.
  • Right to erasure: You may request the erasure of your personal data on the terms provided for by the Data Protection Laws, except where such data must be stored to enable us to comply with legal obligations, or to enable us to exercise or defend our rights or where it is necessary to perform the contract between us.
  • Right to limit processing: You may request to limit processing of your personal data on the terms provided for by the Data Protection Laws.
  • Right to portability: You have the right to portability of personal data you have provided to us and that we process by automated means, where the processing we carry out is based on your consent or on the performance of a contract or pre-contractual measures, provided that exercising such right does not infringe third parties' rights and freedoms.
  • Right to lodge a complaint: After having contacted us in this respect, if you believe that your rights relating to your personal data have not been respected, you may submit a claim to your local data protection authority. Contact details for data protection authorities in the European Union is available here.

In addition, if you are a French resident, you have the right to give general or specific instructions pertaining to the manner in which you wish to exercise the rights, after your death. The general instructions pertain to all personal data about you, and you can revoke them at any time. They may be registered with a trusted digital third party certified by the French Data Protection Authority. The special instructions pertain to the processing referred to in these instructions and are registered with us: they are subject to your specific consent and you may revoke them at any time.

For United States residents

As regards your personal data and in particular if you are located in the State of California, you may have the right to request that we disclose certain information to you about our collection and use of your personal data over the past 12 months. Once we receive and confirm your verifiable consumer request, we will disclose to you:

  • The categories of personal data we collected about you and the categories of sources for the personal information we collected about you.
  • Our business or commercial purpose for collecting that personal data.
  • The categories of third parties with whom we share that personal data.
  • The specific pieces of personal data we collected about you (also called a data portability request).

You may also have the right to request that we delete any of your personal data we collected from you and retained, subject to certain exceptions provided by law. Once we receive and confirm your request, we will delete your personal data from our records, unless an exception applies.

For Brazilian residents

In accordance with the Brazilian General Data Protection Law ("LGPD"), you have the following rights:

  • Confirm whether we process your personal data and receive confirmation of such processing.
  • Access your personal data that we hold.
  • Request the correction of any personal data that is incomplete, inaccurate, or outdated.
  • Request the anonymization, blocking, or deletion of data that is unnecessary, excessive, or processed in violation of the LGPD.
  • Request the portability of your personal data to another service or product provider, in accordance with Brazilian Data Protection Authority regulations and subject to commercial and industrial confidentiality.
  • Request the deletion of personal data processed based on your consent.
  • Request information about public and private entities with which we have shared your personal data.
  • Be informed about the possibility of refusing to provide consent and the consequences of such refusal.
  • Withdraw your consent at any time.
  • Object to the processing of your personal data when it is based on a legal ground other than consent, in case of non-compliance with the LGPD.
  • Request a review of decisions made solely through automated processing, including those that affect your personal, professional, consumer, or credit profile, or other aspects of your personality. You can also request clear and adequate information about the criteria and procedures used in such decisions, subject to commercial and industrial secrecy.
  • File a complaint with the Brazilian Data Protection Authority regarding the processing of your personal data.

Exercising your rights

In order to exercise your rights, you can send us an email or letter to the addresses below, specifying the right you wish to exercise, the personal data involved in your request and indicating your first and last names as well as the email address associated with your customer or loyalty account (if applicable):

  • Email: hey@hilos.io.
  • Letter: Av Paseo de la Reforma 404, Piso 1, 06600, Cuauhtémoc, Ciudad de México, México.

In the event that you request access to your personal data to a person who is presumed to be the data controller and this person turns out not to be the data controller, it shall be sufficient to indicate this fact to you by any of the means referred to in this section, in order for the request to be considered fulfilled.

Please note that Hilos may (in whole or in part) deny access to the personal data, or to rectify or cancel it, or grant opposition to its processing, in accordance with Data Protection Law, which may include the following cases:

i. When the applicant is not the owner of the personal data, or the legal representative is not duly accredited to do so;ii. When the applicant's personal data are not found in our database;iii. When the rights of a third party are infringed;iv. When there is a legal impediment, or the resolution of a competent authority, which restricts access to the personal data, or does not allow the rectification, cancellation or opposition thereof; andv. When the rectification, erasure or objection has been previously made.

For Mexican residents only:

If you are a Mexican resident, your request must include at least the following information:

(i) Your full name and address, or any another suitable means to receive a response to your request;(ii) Documents proving your identity or, if applicable, that of your legal representative;(iii) The clear and precise description of the personal data with respect to which you seek to exercise any of your rights (except in the case of the right of access) and/or revoke consent to its processing.

In the case of request for rectification of personal data, you shall indicate the modifications to be made and provide the documentation supporting this request.

(iv) The description of the right sought to be exercised, or what you are requesting (revocation of consent to the processing, for example); and(v) Any other element or document that facilitates the location of the personal data, if applicable.

The obligation of access to the information shall be deemed fulfilled when the personal data is made available to you; or by means of electronic documents.

7. CHANGES TO THIS PRIVACY POLICY

We may change this Privacy Policy at any time depending on the applicable legal and regulatory framework or changes in our business, and, in particular, the Services we offer you.

We will notify you of the changes provided to this Privacy Policy by posting a new privacy policy on this page. If we make any changes that materially change the ways we process or protect your information, we may provide additional notification of the changes.

8. CONTACT US

If you have any questions or comments about this Privacy Policy or wish to exercise your rights under Data Protection Laws, please do not hesitate to contact us at: hey@hilos.io

The Data Controller is 11 Tecnologias, S de R.L. de C.V., with domicile for legal service located at: Av Paseo de la Reforma 404, Piso 1, 06600, Cuauhtémoc, Ciudad de México, México.

9. TERMS AND TRANSLATIONS

Terms not expressly defined herein will have the same definition set forth by Data Protection Laws.

If you are a Mexican resident, note that the Spanish version of this Privacy Policy is available on this page.