Attendae
← Legal center 🇲🇽 ES

Legal center → Minor Protection Policy

Minor Protection Policy

Special provisions for events that include participants under 18 years of age

Contents

  1. Scope and definitions
  2. Attendae platform access
  3. Institution obligations
  4. Geolocation for minors
  5. Certificates for minors
  6. Attendae's obligations as Processor
  7. Parental and guardian rights
  8. Contact

1 Scope and definitions

This policy applies whenever an institution uses Attendae to manage events where some or all participants are minors — individuals under 18 years of age under Mexican law (Civil Code and LFPDPPP).

The Attendae platform itself (attendae.app) is a tool for institutional administrators only. Administrators must be adults. This policy covers the processing of personal data belonging to minor participants in events managed through the platform.

Important: The institution is the Data Controller for minor participant data. Attendae processes this data as a Processor following the institution's instructions. The institution bears primary responsibility for compliance with legal requirements when processing minors' data.

2 Attendae platform access

Minors do not register for or log in to the Attendae platform directly. The only platform interaction available to event participants (of any age) is:

  • Accessing a personal participation link (attendae.app/mi/{token}) sent by the organizing institution
  • Scanning a QR code for check-in at an event session
  • Viewing or downloading their own participation certificate

These interactions do not require account creation and do not involve collection of data beyond what is described in the Participant Privacy Notice.

3 Institution obligations

When an institution processes the personal data of minor participants through Attendae, it must ensure:

  • 1Obtaining the consent of a parent or legal guardian before collecting the minor's personal data, as required by Article 9 of Mexico's LFPDPPP. Implied consent from the minor's own registration is not sufficient.
  • 2Providing parents or guardians with a clear privacy notice explaining what data is collected, why, and how to exercise ARCO rights on the minor's behalf.
  • 3Collecting only the data that is strictly necessary for attendance management — full name, email (which may be the parent's email for young minors), and attendance records.
  • 4Ensuring that participant lists (XLSX/CSV) uploaded to Attendae containing minors' data were compiled in compliance with applicable legal requirements, including verifiable parental consent.
  • 5Maintaining records of consent and being able to demonstrate compliance in the event of a data protection inquiry or ARCO request.
  • 6Implementing appropriate measures to ensure that the minor's personal participation link (/mi/{token}) is shared only with the minor and their parent/guardian, and not made publicly accessible.

Institutions are encouraged to consult their own legal counsel when designing data collection practices for events involving minors, particularly for sensitive categories of participants (children under 12, vulnerable populations, health-related events).

4 Geolocation for minors

Geolocation check-in (which captures GPS coordinates at the moment of check-in) is configured at the institution level. The institution decides whether to enable it for a given event or session.

When an event includes minor participants and geolocation is enabled, the institution must:

  • Explicitly disclose the use of geolocation in the privacy notice provided to parents/guardians
  • Obtain specific consent for location data collection, separate from general attendance data consent where required
  • Ensure that geolocation data for minors is accessible only to authorized institution personnel

Attendae does not continuously track location. Only a single coordinate at the moment of check-in is captured and stored per check-in event. This data is used solely for geofence validation and audit purposes.

5 Certificates for minors

Participation certificates may be issued to minor participants in the same manner as adult participants. The certificate includes:

  • The minor's full name (as entered in the system)
  • The event name and organizing institution
  • A unique folio number and QR verification code

Certificates are publicly verifiable by anyone with the folio number or QR code. This is fundamental to the certificate's purpose as a verifiable credential. The institution must inform parents/guardians of this public verifiability before issuing certificates to minors.

Certificates are emailed to the address associated with the participant record. For minor participants, institutions should consider using a parent/guardian email address rather than the minor's own email if the minor is young.

6 Attendae's obligations as Processor

Attendae commits to:

  • Processing minor participant data only on the documented instructions of the institution (Data Controller)
  • Applying the same technical and organizational security measures to minor participant data as to all other personal data on the platform
  • Not using minor participant data for any purpose beyond operating the platform for the institution
  • Notifying the institution of any security incident that may affect minor participant data within 72 hours of discovery
  • Assisting the institution in responding to ARCO requests submitted by parents or guardians on behalf of minor participants
  • Deleting or anonymizing minor participant data upon the institution's request or upon account termination, subject to retention requirements

7 Parental and guardian rights

Parents and legal guardians may exercise ARCO rights (Access, Rectification, Cancellation, Opposition) on behalf of a minor participant. To do so:

  • Contact the organizing institution in the first instance, as the Data Controller
  • If the institution does not respond appropriately, contact Attendae at privacidad@attendae.com
  • Requests must include proof of identity and proof of legal guardianship or parental relationship

See ARCO Rights for general process details and response timelines.

8 Contact

Privacy Officer: privacidad@attendae.com
Subject line: Minor Protection — [institution name or event name]

Attendae takes the protection of minor data seriously. Institutions that identify any concern about how minor participant data is being handled on the platform should contact us immediately.

Legal center Terms of Service Privacy Policy Privacy Notice Participant Privacy ARCO Rights Acceptable Use Refund Policy SLA DPA Data Retention Security Policy Cookie Policy Sub-processors Home Contact 🇲🇽 Versión en español

© 2026 Attendae. All rights reserved.