1. Identity of the Data Controller
JJ Innovative Results, LLC (the "Controller", "we", "us", or "JJIR"), a limited liability company organized under the laws of the State of Missouri, State of Missouri, United States of America.
For operations and data subjects in México, the corresponding controller is JJ INNOVATIVE RESULTS, S.A.S. — a Sociedad por Acciones Simplificada incorporated under the laws of the United Mexican States, RFC JIR170511NC2, constitutive folio SAS201739443 in the Registro Público de Comercio, with corporate domicile in León, Guanajuato, México.
Both entities are legally independent and operate under equivalent privacy and security policies.
1.1 How to reach us, and why we publish no postal address
JJIR is an exclusively online business. We operate no public premises, no retail location, no walk-in office, and no staffed postal address. We do not receive correspondence at any published street address, and we do not publish one: doing so would expose a private residence.
We therefore designate electronic mail as our official channel for every communication contemplated by this Policy, including the exercise of your rights:
- Privacy and data-subject rights: privacy@jjir.org
- General support: support@jjir.org
- Security reports: security@jjir.org
- Legal notices: legal@jjir.org
This is not an omission; it is expressly contemplated for a business in our position:
- United States. Under the CCPA/CPRA regulations, a business that operates exclusively online and has a direct relationship with the consumer from whom it collects personal information is required to provide only an email address as a method for submitting requests. We meet that description.
- México. The LFPDPPP requires the responsable to provide effective means for exercising ARCO rights, and expressly contemplates electronic means. Our registered corporate domicile is not concealed — it is filed with the Registro Público de Comercio under folio SAS201739443 and with the SAT under RFC JIR170511NC2, where any data subject or competent authority may consult it. On written request to privacy@jjir.org, we will also provide it directly to any data subject or authority who needs it in order to exercise a right or conduct a proceeding.
No right described in this Policy is diminished by the absence of a street address, and we will not refuse, delay, or complicate any request on that basis.
2. Scope
This Privacy Policy applies to:
- The jjir.org website and any subdomain we operate under the JJIR brand;
- Inquiries you send to us by email or through the scheduling link published on jjir.org;
- Any mobile or web application we publish under the JJIR brand on Apple App Store, Google Play, or directly via our website.
When we provide development or operations services for a client (for example, building a web platform that the client owns), the client is the data controller of the end-user data processed by that platform, and JJIR acts as a data processor under the engagement contract. In those cases, the client's own privacy notice governs that data — not this Policy.
3. Personal Data We Collect
We collect only the minimum data necessary to respond to your inquiry and operate our services.
3.1 Data you provide
- Identification: name, business or organization name (where applicable);
- Contact: email address, phone number;
- Inquiry content: the text of your message, any attachments you choose to send, and metadata such as preferred language;
- Engagement records (paying clients only): RFC, business address, billing data, signed contracts, invoices.
3.2 Data collected automatically
- Connection metadata, recorded by our hosting provider (Google Cloud Run) in its standard request logs: IP address, browser User-Agent, requested URL, response status, latency, and referrer where the browser sends one;
- Application logs: the request method and path, used for security and reliability.
jjir.org sets no cookies at all. There is no session cookie, no tracking cookie, no analytics cookie, and no advertising cookie. The site has no login, no contact form, and no shopping basket, so it has nothing to keep state for. Your language choice is carried in the page address itself (`?lang=en` or `?lang=es`) and is not stored on your device or on our servers.
We use no analytics product of any kind on jjir.org — no Google Analytics, no tag manager, no pixel, no third-party script. Every page is rendered on our own server and served from our own domain; the site loads no resource from any third party.
3.3 What we do not collect
- No sensitive personal data. We do not collect or process data revealing racial or ethnic origin, religious or philosophical belief, political opinion, trade-union membership, health, genetic or biometric data, sexual orientation, precise geolocation, or government identifiers other than a tax identifier (RFC or equivalent) provided by a client for invoicing. Because we do not process sensitive personal data, the right to limit its use does not arise.
- No automated decision-making or profiling. We make no decision producing legal or similarly significant effects about you by automated means, and we build no behavioural profile of you.
- No data from third-party sources. We collect personal data from you, and from the technical metadata of your own connection. We do not buy lists, scrape contact data, or enrich your record from data brokers.
4. Purposes of Processing
4.1 Primary purposes (legitimate basis: contractual/pre-contractual)
- Reply to your inquiry, prepare quotes, and execute service engagements;
- Send invoices, statements, and other transactional communications;
- Provide ongoing support and maintenance for delivered software.
4.2 Secondary purposes (legitimate basis: legitimate interest, you may opt out)
- Improve the security and reliability of our services, using server logs only;
- Send infrequent service announcements to clients with an active engagement (we send no marketing newsletters from jjir.org, and we operate no mailing list).
4.3 How to limit the use or disclosure of your data
Separately from the rights in §8, and as required by the LFPDPPP, these are the means we offer to limit the use or disclosure of your personal data:
- Email privacy@jjir.org with the subject "Limit use", stating what you want limited. We confirm within five (5) business days and apply the limitation immediately.
- Ask us to stop secondary processing while keeping your engagement active — you may opt out of §4.2 without affecting §4.1.
- Ask us to hold your data without using it where we must retain it for a tax or legal obligation but no longer need it operationally. We will block it from ordinary use and keep it only for the period the law requires.
- Reply "stop" to any service announcement to be removed from further announcements.
We maintain no marketing list, no advertising audience, and no data broker relationship, so there is no exclusion registry to enrol in.
You may revoke consent for secondary purposes at any time by emailing privacy@jjir.org.
5. Legal Bases for Processing
- Performance of a contract or steps prior to entering a contract — for inquiries, quotes, engagements, billing;
- Compliance with a legal obligation — accounting and tax records;
- Legitimate interest — security, anti-abuse, and service operation;
- Explicit consent — for any data category not covered by the bases above.
We do not target, market to, or offer services in the European Union or the United Kingdom, and we make no claim of compliance with the GDPR or the UK GDPR. Should that change, this Policy will be updated before it does, not after.
6. How Long We Keep Your Data
| Category | Retention | |---|---| | Inquiry messages without engagement | 24 months from last contact | | Engagement records (contracts, invoices) | 5 years after engagement end (tax-law minimum) | | Hosting-provider request logs | 30 days, then deleted automatically by the provider |
After the retention period, data is deleted or irreversibly anonymized. There is no cookie row in this table because jjir.org sets no cookies (§11).
7. Sharing and Transfers
We do not sell, lease, or rent personal data. We share data only with:
- Service providers strictly necessary to deliver our services (e.g. transactional email delivery, payment processing, cloud hosting), each bound by written confidentiality and data-processing terms;
- Government authorities when compelled by a valid court order or applicable law;
- A successor entity in the event of a merger, acquisition, or sale of assets, in which case this Policy continues to apply.
International transfers. Personal data may move between the Mexican and United States entities identified in §1, and is held with cloud providers whose infrastructure spans both countries.
Transfers between the two entities are governed by a written Intercompany Data Protection and Transfer Agreement executed by both, under which each undertakes to apply this Privacy Policy, to maintain equivalent security measures, and to honour your rights under §8 regardless of which entity received your request. That agreement is the instrument establishing the equivalence of internal processes and policies on which the LFPDPPP permits same-group transfer without separate consent. A copy is available on request to privacy@jjir.org.
Transfers necessary to perform a contract with you rest on that separate basis. Our cloud providers are engaged under their published data-processing terms, which include the transfer safeguards they offer to all customers.
8. Your Rights
You have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Cancel (delete) data we hold, subject to legal retention obligations;
- Object to specific processing activities, including secondary purposes;
- Withdraw consent at any time, without retroactive effect;
- Data portability — request your data in a structured, commonly used format;
- Lodge a complaint with the competent supervisory authority. In México this is the Secretaría Anticorrupción y Buen Gobierno, through its deconcentrated body Transparencia para el Pueblo, which assumed the functions of the former INAI when that institute was extinguished on 21 March 2025. In the United States, the Federal Trade Commission or your state attorney general.
To exercise any of these rights, email privacy@jjir.org from the address associated with your data, with the subject line "Data subject request". We respond within thirty (30) days. If we need to verify your identity we will ask only for what is strictly necessary to do so, and we will not use that information for any other purpose.
8.1 We will not penalise you for exercising a right
We do not and will not discriminate against you for exercising any right in this Policy. We will not deny you a service, charge you a different price, provide a different level or quality of service, or suggest that we might, because you made a request. This is your right under the CCPA/CPRA and we apply it to everyone, wherever you are.
8.2 Authorised agents
You may use an authorised agent to make a request on your behalf. We will ask the agent for written proof of authorisation, and we may contact you directly to confirm it before acting.
8.3 If we say no — how to appeal
If we decline a request in whole or in part, we will tell you why, in writing, within the thirty (30) days.
You may then appeal by replying to that decision, or by emailing privacy@jjir.org with the subject "Appeal". A different person from the one who made the original decision will review it, and we will respond with our reasoned decision within forty-five (45) days. If we still decline, we will tell you how to complain to the supervisory authority named above.
This appeal route is available to everyone. Several US state privacy laws — including those of Virginia, Colorado, and Connecticut — require it, and we saw no reason to offer it only to residents of those states.
8.4 We do not sell or share your personal data
We do not sell personal data, and we do not "share" it as that term is defined by the CCPA/CPRA — that is, we do not disclose it for cross-context behavioural advertising. We have never done either. Because we do not, there is no "Do Not Sell or Share My Personal Information" mechanism to offer, and its absence is not an oversight.
9. Security
On jjir.org. The site is served over HTTPS with a strict Content-Security-Policy, HSTS, and related response headers. It stores no personal data, accepts no form submissions, has no login, sets no cookies, and makes no outbound network calls; it renders fixed pages and nothing else. Its hosting service account holds no access rights to any other system.
For data you send us and for client engagements. Correspondence and engagement records are held in access-controlled business systems protected by multi-factor authentication, encrypted in transit and at rest by the providers that host them, and available only to personnel who need them.
In software we build for clients. Access controls, audit logging, secret management, and dependency review are defined per engagement in the applicable contract and technical specification, and are described there rather than here — the appropriate controls depend on what the system does.
No system is completely secure, but we treat data protection as a primary engineering concern rather than an afterthought. To report a suspected vulnerability, email security@jjir.org.
10. Children
Our services are business-to-business and are not directed to children. We do not knowingly collect personal data from anyone under thirteen (13), the threshold set by the US Children's Online Privacy Protection Act. In México, personal data of a minor may only be processed with the consent of a parent or legal guardian, and we do not seek or accept it without that consent.
If you believe a child has provided us data, contact privacy@jjir.org and we will delete it without requiring you to prove anything first.
11. Cookies and tracking
jjir.org sets no cookies. Not strictly necessary ones, not analytics, not advertising. There is nothing to consent to and nothing to opt out of, which is why you see no cookie banner.
We do not track you across sites, we do not build a profile of you, we do not fingerprint your browser, and we load no third-party script, font, or image that could do so on our behalf. Your language preference travels in the page address (`?lang=en` / `?lang=es`), not in storage on your device.
If a JJIR-published application requires a session in order to log you in, that application's own privacy notice describes it. This section is about jjir.org, the website you are reading.
12. Changes to This Policy
We may update this Policy. The version and effective date appear at the top. For material changes (a new processing purpose, a new category of data, a new recipient), we notify clients with active engagements at least thirty (30) days in advance by email.
13. Governing Law
For data subjects in México: this Policy is governed by the Ley Federal de Protección de Datos Personales en Posesión de los Particulares published in the Diario Oficial de la Federación on 20 March 2025 and in force since 21 March 2025, which replaced the 2010 law of the same name. The competent authority is the Secretaría Anticorrupción y Buen Gobierno through Transparencia para el Pueblo.
For data subjects in the United States: this Policy is governed by applicable state privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, OCPA, ICPA, DPDPA, TDPSA, and others as enacted) and federal law (FTC Act §5).
For all other jurisdictions, equivalent rights apply on a comity basis.
14. Contact
To exercise your rights, raise a concern, or request the integral version of this Policy:
- Privacy and data-subject rights: privacy@jjir.org
- General support: support@jjir.org
- Security reports: security@jjir.org
- Legal notices: legal@jjir.org
- Official domain: jjir.org
We publish no postal address, for the reasons and on the legal basis set out in §1.1. If you require our registered corporate domicile in order to exercise a right or to bring a proceeding, ask at privacy@jjir.org and we will provide it in writing; it is also on file with the Registro Público de Comercio under folio SAS201739443.