Attendae
← Legal center 🇲🇽 ES

Legal → Data Processing Agreement

Data Processing Agreement (DPA)

Last updated: March 24, 2026 · Pursuant to LFPDPPP Art. 36 and Art. 50 of the Regulation

Who needs this document? This DPA applies to all institutions that use Attendae to manage events and load participant data. By accepting the Terms of Service, the Institution automatically accepts this DPA. No separate signature is required. This document formalizes the roles of each party with respect to participant personal data under Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP).

Contents

  1. Parties and roles
  2. Subject
  3. Processing instructions
  4. Processor obligations (Attendae)
  5. Controller obligations (Institution)
  6. Sub-processors
  7. Data subject rights
  8. Security incidents
  9. Return and deletion of data
  10. Term and termination
  11. Governing law

1 Parties and roles

Attendae — Data Processor (Encargado)

Cristian Jesus Torres Pacheco · RFC: TOPC840408QL7 · Morelia, Michoacán, Mexico · legal@attendae.com

Processes participant data under the Institution's instructions, solely to provide the attendance management service.

Institution — Data Controller (Responsable)

The institution that creates an account on Attendae and loads participant data into the platform.

Determines the purposes and means of processing participant data; bears primary responsibility under the LFPDPPP.

2 Subject

This DPA governs the processing of personal data of event participants (name, email, institutional identifier, attendance records, geolocation coordinates during check-in) carried out by Attendae on behalf of the Institution in order to provide the attendance management and certificate issuance service.

This DPA supplements and forms an integral part of the Terms of Service agreed to by the Institution upon account registration. In case of conflict, the Terms of Service shall prevail.

3 Processing instructions

Attendae processes participant personal data solely according to the documented instructions of the Institution, which consist of:

  • Recording and verifying event session attendance.
  • Issuing participation certificates when the Institution activates this feature.
  • Sending certificates and related communications to participants by email.
  • Making certificates verifiable through the public verification portal.
  • Generating attendance and participation reports for the Institution's internal use.

Attendae will not process participant data for any purpose other than those listed above without the Institution's documented instruction, except when required by applicable law.

4 Processor obligations (Attendae)

  • Process participant data exclusively for the purposes established in this DPA and under the Institution's instructions.
  • Implement adequate technical and organizational security measures to protect participant data (detailed in the Security Policy).
  • Not transfer or disclose participant data to third parties not listed as sub-processors, except when required by law.
  • Assist the Institution in fulfilling its obligations to respond to data subject rights (ARCO) requests within the timeframes provided for in this DPA.
  • Notify the Institution without undue delay (maximum 72 hours) of any security breach involving participant data, with information about the nature of the breach, data affected, and measures adopted.
  • Delete or return participant data to the Institution at the end of the service relationship, as described in section 9.
  • Make available to the Institution all information necessary to demonstrate compliance with the obligations in this DPA and cooperate in audits reasonably requested by the Institution.

5 Controller obligations (Institution)

  • Ensure the lawful basis for processing participant data, including obtaining necessary consents from participants prior to loading their data into Attendae.
  • Provide participants with a privacy notice in accordance with the LFPDPPP (Arts. 15–16) before collecting their data.
  • Obtain specific, informed consent for geolocation of participants when using that feature.
  • Obtain verifiable parental/guardian consent when loading data of participants under 18 years of age.
  • Attend to participant data subject rights (ARCO) requests promptly, assisted by Attendae when needed.
  • Use Attendae only for the legitimate purposes described in the Terms of Service and the Acceptable Use Policy.
  • Notify Attendae immediately of any ARCO request or complaint received from a participant related to data processed through Attendae.

6 Sub-processors

The Institution authorizes Attendae to engage the following sub-processors to provide the service:

  • Banahosting — web hosting and infrastructure (Mexico / USA)
  • Stripe, Inc. — payment processing (USA)

For the complete and updated list, see the Sub-processors page. Attendae will notify the Institution at least 15 calendar days before adding or replacing a sub-processor. The Institution may object to the change before it takes effect.

7 Data subject rights

When a participant exercises their ARCO rights (access, rectification, cancellation, opposition) and their request relates to data processed by Attendae on behalf of the Institution:

  • If the request is submitted directly to Attendae, Attendae will forward it to the Institution within 5 business days.
  • The Institution has up to 20 business days from receipt of the forwarded request to respond to the participant, in accordance with the LFPDPPP (Art. 32).
  • Attendae will provide technical assistance to the Institution (such as data exports or deletions) to facilitate complying with the data subject's request.

8 Security incidents

In the event of a security breach affecting participant data:

  1. Attendae will notify the Institution within 72 hours of becoming aware of the breach.
  2. The notification will include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.
  3. The Institution, as Data Controller, is responsible for notifying affected participants and INAI (Mexico's data protection authority) in accordance with the LFPDPPP and its Regulation.
  4. Attendae will cooperate with the Institution and provide all available information to facilitate notifications and incident response.

9 Return and deletion of data

Upon termination of the service relationship, whether by account cancellation, suspension, or expiration:

  • The Institution has a 30-day period from cancellation to request an export of its participant data, attendance records, and certificates in CSV or XLSX format.
  • After that period, Attendae will proceed to delete participant data from active databases, retaining only billing and tax records as required by Mexican fiscal law.
  • Attendae will provide written confirmation of deletion within 30 business days of the request.

Participant data in Attendae belongs to the Institution. Attendae is its custodian as Processor. Upon termination, Attendae has no right to retain participant data beyond what is required by applicable law.

10 Term and termination

This DPA is effective from the date of account registration and remains in force for as long as the Institution maintains an active account on Attendae. It terminates automatically upon account cancellation, subject to the data deletion provisions in section 9.

Termination of the DPA does not affect any rights or obligations that arose prior to termination or that, by their nature, survive termination — including confidentiality obligations, indemnification, and data retention/deletion.

11 Governing law

This DPA is governed by the laws of the United Mexican States, specifically the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulation. Any dispute arising from this DPA shall be resolved before the competent courts in Morelia, Michoacán, Mexico.

Last updated: March 24, 2026. This DPA supersedes any previous version. Contact: legal@attendae.com

All documents Home Terms Privacy DPA Data Rights Minors Acceptable Use Refunds SLA Security Cookies Sub-processors Retention Contact 🇲🇽 Español

© 2026 Attendae. All rights reserved.