1. Identity of the Data Controller
JJ INNOVATIVE RESULTS LLC (the "Controller", "we", "us", or "JJIR"), a limited liability company organized under the laws of the State of Missouri, United States of America.
For operations and data subjects in México, the corresponding controller is JJ INNOVATIVE RESULTS, S.A.S. — a Sociedad por Acciones Simplificada incorporated under the laws of the United Mexican States, RFC JIR170511NC2, constitutive folio SAS201739443 in the Registro Público de Comercio, with corporate domicile in León, Guanajuato, México.
Both entities are legally independent and operate under equivalent privacy and security policies.
1.1 How to reach us, and why we publish no postal address
JJIR is an exclusively online business. We operate no public premises, no retail location, no walk-in office, and no staffed postal address. We do not receive correspondence at any published street address, and we do not publish one: doing so would expose a private residence.
We therefore designate electronic mail as our official channel for every communication contemplated by this Policy, including the exercise of your rights:
- Privacy and data-subject rights (ARCO rights in México): privacy@jjir.org
- General support: support@jjir.org
- Security reports: security@jjir.org
- Legal notices: legal@jjir.org
This is not an omission; it is expressly contemplated for a business in our position:
- United States. Under the CCPA/CPRA regulations, a business that operates exclusively online and has a direct relationship with the consumer from whom it collects personal information is required to provide only an email address as a method for submitting requests. We meet that description.
- México. The LFPDPPP requires the responsable to provide effective means for exercising ARCO rights, and expressly contemplates electronic means. Our registered corporate domicile is not concealed — it is filed with the Registro Público de Comercio under folio SAS201739443 and with the SAT under RFC JIR170511NC2, where any data subject or competent authority may consult it. On written request to privacy@jjir.org, we will also provide it directly to any data subject or authority who needs it in order to exercise a right or conduct a proceeding.
No right described in this Policy is diminished by the absence of a street address, and we will not refuse, delay, or complicate any request on that basis.
2. Scope
This Privacy Policy applies to:
- The jjir.org website and any subdomain we operate under the JJIR brand;
- Inquiries you send to us by email or through the scheduling link published on jjir.org;
- Any mobile or web application we publish under the JJIR brand on Apple App Store, Google Play, or directly via our website.
When we provide development or operations services for a client (for example, building a web platform that the client owns), the client is the data controller of the end-user data processed by that platform, and JJIR acts as a data processor under the engagement contract. In those cases, the client's own privacy notice governs that data — not this Policy.
3. Personal Data We Collect
We collect only the minimum data necessary to respond to your inquiry and operate our services.
3.1 Data you provide
- Identification: name, business or organization name (where applicable);
- Contact: email address, phone number;
- Inquiry content: the text of your message, any attachments you choose to send, and metadata such as preferred language;
- Engagement records (paying clients only): RFC, business address, billing data, signed contracts, invoices.
3.2 Data collected automatically
- Connection metadata, recorded by our hosting provider (Google Cloud Run) in its standard request logs: IP address, browser User-Agent, requested URL, response status, latency, and referrer where the browser sends one;
- Application logs: the request method and path, used for security and reliability.
jjir.org sets no cookies and uses no analytics of any kind; §11 explains exactly what that means.
3.3 What we do not collect
- No sensitive personal data — except in certain applications. Some of our applications may process biometric data or precise location, only with your express consent, as described in §12.5. Otherwise, we do not collect or process data revealing racial or ethnic origin, religious or philosophical belief, political opinion, trade-union membership, health, genetic or biometric data, sexual orientation, precise geolocation, or government identifiers other than a tax identifier (RFC or equivalent) provided by a client for invoicing. Because we do not process sensitive personal data, the right to limit its use does not arise.
- No profiling, and automated decisions only for access. We build no behavioural profile of you. The only automated decisions we may make are access decisions in certain applications, described in §12.5; otherwise, we make no decision producing legal or similarly significant effects about you by automated means.
- No data from third-party sources. We collect personal data from you, and from the technical metadata of your own connection. In certain applications, an administrator or another user may also give us data about you, as §12.5 describes. We do not buy lists, scrape contact data, or enrich your record from data brokers.
4. Purposes of Processing
4.1 Primary purposes (legitimate basis: contractual/pre-contractual)
- Reply to your inquiry, prepare quotes, and execute service engagements;
- Send invoices, statements, and other transactional communications;
- Provide ongoing support and maintenance for delivered software.
4.2 Secondary purposes (legitimate basis: legitimate interest, you may opt out)
- Improve the security and reliability of our services, using server logs only;
- Send infrequent service announcements to clients with an active engagement (we send no marketing newsletters from jjir.org, and we operate no mailing list).
4.3 How to limit the use or disclosure of your data
Separately from the rights in §8, and as required by the LFPDPPP, these are the means we offer to limit the use or disclosure of your personal data:
- Email privacy@jjir.org with the subject "Limit use", stating what you want limited. We confirm within five (5) business days and apply the limitation immediately.
- Ask us to stop secondary processing while keeping your engagement active — you may opt out of §4.2 without affecting §4.1.
- Ask us to hold your data without using it where we must retain it for a tax or legal obligation but no longer need it operationally. We will block it from ordinary use and keep it only for the period the law requires.
- Reply "stop" to any service announcement to be removed from further announcements.
We maintain no marketing list, no advertising audience, and no data broker relationship, so there is no exclusion registry to enrol in.
You may revoke consent for secondary purposes at any time by emailing privacy@jjir.org.
5. Legal Bases for Processing
- Performance of a contract or steps prior to entering a contract — for inquiries, quotes, engagements, billing;
- Compliance with a legal obligation — accounting and tax records;
- Legitimate interest — security, anti-abuse, and service operation;
- Explicit consent — for any data category not covered by the bases above.
We do not target, market to, or offer services in the European Union or the United Kingdom, and we make no claim of compliance with the GDPR or the UK GDPR. Should that change, this Policy will be updated before it does, not after.
6. How Long We Keep Your Data
| Category | Retention |
|---|---|
| Inquiry messages without engagement | 24 months from last contact |
| Engagement records (contracts, invoices) | 10 years after engagement end (Código de Comercio art. 38) |
| Hosting-provider request logs | 30 days, then deleted automatically by the provider |
| Diagnostics from our web applications (§12.3) | Up to 90 days |
After the retention period, data is deleted or irreversibly anonymized. There is no cookie row in this table because jjir.org sets no cookies (§11).
7. Sharing and Transfers
We do not sell, lease, or rent personal data. We share data only with:
- Service providers strictly necessary to deliver our services (e.g. transactional email delivery, payment processing, cloud hosting), each bound by written confidentiality and data-processing terms;
- Government authorities when compelled by a valid court order or applicable law;
- A successor entity in the event of a merger, acquisition, or sale of assets, in which case this Policy continues to apply.
International transfers. Personal data may move between the Mexican and United States entities identified in §1, and is held with cloud providers whose infrastructure spans both countries.
Transfers between the two entities are governed by a written Intercompany Data Protection and Transfer Agreement executed by both, under which each undertakes to apply this Privacy Policy, to maintain equivalent security measures, and to honour your rights under §8 regardless of which entity received your request. That agreement is the instrument establishing the equivalence of internal processes and policies on which the LFPDPPP permits same-group transfer without separate consent. A copy is available on request to privacy@jjir.org.
Transfers necessary to perform a contract with you rest on that separate basis. Our cloud providers are engaged under their published data-processing terms, which include the transfer safeguards they offer to all customers.
8. Your Rights
You have the right to the following. In México, the first four are known as your ARCO rights (acceso, rectificación, cancelación y oposición).
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Cancel (delete) data we hold, subject to legal retention obligations;
- Object to specific processing activities, including secondary purposes;
- Withdraw consent at any time, without retroactive effect;
- Data portability — request your data in a structured, commonly used format;
- Lodge a complaint with the competent supervisory authority. In México this is the Secretaría Anticorrupción y Buen Gobierno, through its deconcentrated body Transparencia para el Pueblo, which assumed the functions of the former INAI when that institute was extinguished on 21 March 2025. In the United States, the Federal Trade Commission or your state attorney general.
To exercise any of these rights, email privacy@jjir.org from the address associated with your data, with the subject line "Data subject request". We respond within thirty (30) days. If we need to verify your identity we will ask only for what is strictly necessary to do so, and we will not use that information for any other purpose.
8.1 We will not penalise you for exercising a right
We do not and will not discriminate against you for exercising any right in this Policy. We will not deny you a service, charge you a different price, provide a different level or quality of service, or suggest that we might, because you made a request. This is your right under the CCPA/CPRA and we apply it to everyone, wherever you are.
8.2 Authorised agents
You may use an authorised agent to make a request on your behalf. We will ask the agent for written proof of authorisation, and we may contact you directly to confirm it before acting.
8.3 If we say no — how to appeal
If we decline a request in whole or in part, we will tell you why, in writing, within the thirty (30) days.
You may then appeal by replying to that decision, or by emailing privacy@jjir.org with the subject "Appeal". A different person from the one who made the original decision will review it, and we will respond with our reasoned decision within forty-five (45) days. If we still decline, we will tell you how to complain to the supervisory authority named above.
This appeal route is available to everyone. Several US state privacy laws — including those of Virginia, Colorado, and Connecticut — require it, and we saw no reason to offer it only to residents of those states.
8.4 We do not sell or share your personal data
We do not sell personal data, and we do not "share" it as that term is defined by the CCPA/CPRA — that is, we do not disclose it for cross-context behavioural advertising. We have never done either. Because we do not, there is no "Do Not Sell or Share My Personal Information" mechanism to offer, and its absence is not an oversight.
9. Security
On jjir.org. The site is served over HTTPS with a strict Content-Security-Policy, HSTS, and related response headers. It stores no personal data, accepts no form submissions, has no login, sets no cookies, and makes no outbound network calls; it renders fixed pages and nothing else. Its hosting service account holds no access rights to any other system.
For data you send us and for client engagements. Correspondence and engagement records are held in access-controlled business systems protected by multi-factor authentication, encrypted in transit and at rest by the providers that host them, and available only to personnel who need them.
In software we build for clients. Access controls, audit logging, secret management, and dependency review are defined per engagement in the applicable contract and technical specification, and are described there rather than here — the appropriate controls depend on what the system does.
No system is completely secure, but we treat data protection as a primary engineering concern rather than an afterthought. To report a suspected vulnerability, email security@jjir.org.
10. Children
Our services are business-to-business and are not directed to children, with one exception: certain applications (§12.5) may allow a parent or guardian to enrol a minor, and a minor aged thirteen (13) to seventeen (17) may then use the application directly. The parent's or guardian's consent covers the minor's data, including any biometric data, and may be revoked at any time, with immediate deletion. No application of ours is directed to children under thirteen. Otherwise, we do not knowingly collect personal data from anyone under thirteen (13), the threshold set by the US Children's Online Privacy Protection Act. In México, personal data of a minor may only be processed with the consent of a parent or legal guardian, and we do not seek or accept it without that consent.
If you believe a child has provided us data, contact privacy@jjir.org and we will delete it without requiring you to prove anything first.
11. Cookies and tracking
jjir.org sets no cookies. Not strictly necessary ones, not analytics, not advertising. There is nothing to consent to and nothing to opt out of, which is why you see no cookie banner.
We use no analytics product of any kind — no Google Analytics, no tag manager, no pixel, no third-party script. Every page is rendered on our own server and served from our own domain, and the site loads no resource from any third party. The site has no login, no contact form and no shopping basket, so it has nothing to keep state for.
We do not track you across sites, we do not build a profile of you, we do not fingerprint your browser, and we load no third-party script, font, or image that could do so on our behalf. Your language preference travels in the page address (?lang=en / ?lang=es), not in storage on your device.
An application of ours that requires you to sign in may use strictly necessary cookies; §12.5 and that application's own privacy notice describe them. This section is about jjir.org, the website you are reading.
12. Applications We Publish
§2 brings applications we publish under the JJIR brand within the scope of this Policy. This section describes the processing that is specific to them. It does not describe jjir.org, which is covered by §3 and §11.
12.1 Applications that record audio or video
Some JJIR applications record video or audio, using your device's camera or audio produced by other applications on your device. That material is processed entirely on your device and saved to your own device storage or photo library. It is never transmitted to us, and we never receive it, in whole or in part. (This does not cover photographs that an application takes for identity or access verification, which do reach us; see §12.5.) Access to your camera or photo library is requested by the operating system, granted by you, and can be withdrawn by you at any time in your device's settings.
12.2 Documents and text you load into an application
Where an application lets you load your own text — lyrics, notes, scripts or similar — that content stays on your device. We never receive it, and it is excluded from the diagnostic reports described below.
12.3 Diagnostics and reliability
What happens depends on whether you use one of our applications on the web or installed on your phone or tablet.
Web applications and online services we operate. Like any online service, they automatically record technical diagnostics so that we can detect and fix faults quickly and keep the service reliable. These may include errors and warnings, response times, the pages or functions involved, the steps of signing in, your IP address and browser or device type, and — if you are signed in — the account involved. We use them only to operate, secure and repair the service: never for advertising, never to build a profile of you, and they are never sold or shared with third parties beyond the hosting providers that store them (§7). They are kept for up to ninety (90) days, except entries that must form part of an audit record, which are kept as §12.5 describes.
Applications installed on your device (iOS and Android). These send no diagnostics automatically. An application may offer to send us a technical report when something goes wrong: you are shown the entire report before anything is sent, and it is sent from your own email account, which means we also receive the address you send it from. A report contains only technical information about what the application did — device model, operating system version, application version, timings, counters and error messages. It never contains recorded audio or video, text or documents you have loaded, or passwords, keys or other credentials. We use it solely to diagnose the problem you reported, and keep it under §6 together with the inquiry it belongs to.
In neither case do we use third-party analytics, advertising or tracking pixels.
12.4 Statistics provided to us by app stores
Apple and Google make aggregate crash and performance statistics available to developers in respect of users who have enabled the corresponding setting on their own device ("Share With App Developers" on iOS; "usage and diagnostics" on Android). That data reaches us from the app store, not from the application, it reaches us in aggregate form, and we do not receive your identity with it. You control it in your device settings, not with us.
12.5 Applications with accounts, access control or payments
Some of our applications may require an account, control physical access, or handle payments. Each such application identifies itself as one of them in its own privacy notice, published on its own website, which states exactly which of the following it uses, and which governs where it is more specific than this section. For those applications, the controller is JJIR — the entities identified in §1.
Depending on the application, it may process:
- Identification and contact: name, email, telephone, address, a messaging handle if you provide one, and — for invoicing — RFC and fiscal data;
- Account security: passkeys (only the public key would reach us; the private key never leaves your device), sessions, sign-in attempts, and device keys used to confirm that a request comes from your registered device;
- Sensitive personal data — biometrics: a facial template (a numerical representation of your face) and facial photographs, used only to verify identity at access points, and processed only with your express consent;
- Identity documents and vehicles: photographs of identity documents and of vehicle plates, and plate numbers, used to verify identity and, where applicable, to check a plate against a public stolen-vehicle registry;
- Access records: entries and exits, and the access point, time and method used;
- Precise location: your device's location at the moment you use a feature that needs it, such as confirming that you are at an access point, and in the background only if you turn on a feature that requires it;
- Device data: model, operating system, language, time zone, installation identifiers and push-notification tokens. None of our applications collects an advertising identifier or tracks you across other companies' apps;
- Diagnostics: as described in §12.3 — automatic for web applications, never automatic for applications installed on your device;
- Payments: payment references and history. We store no card data at all — not even partial digits; cards are handled entirely by the payment processor, which only confirms that a payment succeeded;
- Content you create: messages, reports, bookings, votes and feedback, including any screenshot you attach;
- Other people's data you register — such as visitors, guests or household members — which you confirm you are entitled to give us;
- Access to a third-party account, only if you connect it — for example a calendar or document service;
- Electronic-acceptance records: who accepted which document, when, from which IP address and device, and the document's fingerprint, which may be certified under the Mexican standard NOM-151.
Minors. Such an application may allow a parent or guardian to enrol a minor; see §10.
Automated decisions. Where an application verifies identity automatically — by face or by vehicle plate — to decide whether an access point opens, other means of access remain available, and you may ask for any such decision to be reviewed by a person.
Cookies and on-device storage. Unlike jjir.org, an application that requires you to sign in may use cookies and storage on your device, strictly necessary ones only: to keep you signed in, to protect against cross-site request forgery, and to remember interface preferences. No analytics or advertising cookies.
Service providers. Depending on the application: cloud hosting and storage in the United States; key custody; document and plate recognition; face comparison; push notifications; payment processing; electronic invoicing (CFDI); email; text-message verification; network protection; camera-management platforms; stolen-vehicle registry checks (which receive only a plate); postal-code lookup (which receives only a postal code); and electronic-certification and timestamping services (which receive only a document fingerprint). Each application's own notice names its providers. Transfers to the United States take place under §7.
How long data is kept. Each application's own notice states its periods. As maximums that any of them observes:
- Visitors' data, including photographs and facial templates: destroyed no more than ninety (90) days after the visit;
- Your facial template: destroyed when you leave the service or close your account, and never more than ninety (90) days after the service ends;
- Access records: separated from the person after no more than twelve (12) months;
- Sessions: end when you sign out or, at the latest, thirty (30) days after you sign in;
- Audit records: kept for at least five (5) years, and written once — nobody can alter or delete them;
- Payment, invoicing and contract-acceptance records: ten (10) years, as the Código de Comercio (art. 38) requires of a merchant's transaction records.
Deleting your account. Each such application offers account deletion both inside the application and on its website. Deletion destroys biometric data, passkeys and sessions and anonymizes your profile; records the law requires us to keep — payments, invoices, and access and audit records — are kept for the period required.
13. Changes to This Policy
We may update this Policy. The version and effective date appear at the top. For material changes (a new processing purpose, a new category of data, a new recipient), we notify clients with active engagements at least thirty (30) days in advance by email.
14. Governing Law
For data subjects in México: this Policy is governed by the Ley Federal de Protección de Datos Personales en Posesión de los Particulares published in the Diario Oficial de la Federación on 20 March 2025 and in force since 21 March 2025, which replaced the 2010 law of the same name. The competent authority is the Secretaría Anticorrupción y Buen Gobierno through Transparencia para el Pueblo.
For data subjects in the United States: this Policy is governed by applicable state privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, OCPA, ICPA, DPDPA, TDPSA, and others as enacted) and federal law (FTC Act §5).
For all other jurisdictions, equivalent rights apply on a comity basis.
15. Contact
To exercise your rights, raise a concern, or request the integral version of this Policy:
- Privacy and data-subject rights (ARCO rights in México): privacy@jjir.org
- General support: support@jjir.org
- Security reports: security@jjir.org
- Legal notices: legal@jjir.org
- Official domain: jjir.org
We publish no postal address, for the reasons and on the legal basis set out in §1.1. If you require our registered corporate domicile in order to exercise a right or to bring a proceeding, ask at privacy@jjir.org and we will provide it in writing; it is also on file with the Registro Público de Comercio under folio SAS201739443.