Privacy

This policy explains what personal data trustloro.com collects, why, and what you can do about it. It is written to the strictest standard we are subject to, so the same protections apply wherever you are.

Last updated: 7 September 2026
Applies to: the website trustloro.com. Client engagements are governed separately by the data-processing terms in the relevant contract.

Privacy notice under Mexican law

This section is our Aviso de Privacidad — the privacy notice Mexican law requires. That law (the Ley Federal de Protección de Datos Personales en Posesión de los Particulares) applies according to where the company is established, not where you live. Because TrustLoro is established in Mexico, this notice applies to every visitor, whatever your nationality or location. Nothing below limits the additional rights you may hold under the GDPR or California law — those are set out later in this policy.

Who is responsible

The responsable for the treatment of your personal data is Ramón Gutiérrez, trading as TrustLoro Consulting, with domicile at Fermín Riestra 1713-3, Col. Moderna, Guadalajara, Jalisco, C.P. 44190.

What we collect and why

Primary purposes — necessary for the relationship, and you cannot opt out of them while it continues: answering your enquiry, scoping and delivering an engagement, invoicing, and keeping the site secure and working.

Secondary purposes — not necessary, and you may refuse them without affecting anything else: sending you occasional articles or updates you have asked for. We do not currently run any secondary purpose. If we start, we will ask first.

The categories are ordinary identification and contact data — name, email address, company, IP address, and whatever you choose to tell us. We do not collect sensitive personal data, financial or patrimonial data, and we do not ask for your CURP, RFC or official identification through this website.

Limiting use or disclosure

You may ask us at any time to limit how we use or disclose your data, by writing to the contact address below. We are not registered with any advertising exclusion list because we do not carry out advertising treatment.

Your ARCO rights

Under Mexican law you hold four rights, known together as ARCO:

  • Acceso — to know what data we hold about you and what we do with it.
  • Rectificación — to have inaccurate or incomplete data corrected.
  • Cancelación — to have your data removed from our records.
  • Oposición — to object to a particular use of your data.

To exercise any of them, write to [email protected] with your name, a way to reply to you, proof of identity or authority to act, a clear description of the data concerned, and what you want done. We will answer within 20 business days, and act within 15 business days of that answer if the request is granted. There is no charge, though we may recover reasonable copying or delivery costs.

If you are unsatisfied, you may take the matter to Mexico’s data-protection authority — the Secretaría Anticorrupción y Buen Gobierno, which took over the functions of the former INAI in 2025.

Transfers

We do not transfer your personal data to third parties for their own purposes, and we do not sell it. The providers listed later in this policy — our host, and WordPress.org for emoji assets — act as service providers on our instructions, which is not a transfer requiring your separate consent under Mexican law. If that ever changes, we will say so here and obtain consent where the law requires it.

Changes to this notice

We will publish any change on this page and update the date at the top. Where a change materially affects your rights, we will mark it clearly rather than expect you to spot it. The current version is always the one published here.

The short version

  • We do not run analytics, advertising, or tracking pixels on this site.
  • We do not sell or share your personal information, under any definition, including California’s.
  • If you email us, we keep what you send us so we can reply.
  • One third party can see your IP address when a page loads: WordPress.org, which serves emoji assets. Details below.
  • You can ask us what we hold, ask for a copy, ask us to correct it, or ask us to delete it.

Who is responsible for your data

The controller of personal data collected through this site is Ramón Gutiérrez, trading as TrustLoro Consulting, at Fermín Riestra 1713-3, Col. Moderna, Guadalajara, Jalisco, C.P. 44190.

For any privacy question or to exercise a right described below, contact [email protected]. We are not required to appoint a Data Protection Officer and have not appointed one. We are not established in the EU or the UK and do not direct this site at people there, so we have not appointed an Article 27 representative.

What we collect, why, and on what legal basis

When you simply read the site

Our hosting provider records standard server logs: your IP address, the page requested, timestamp, referring page, and browser user-agent. These exist to keep the site running and to detect abuse. Legal basis: legitimate interests — operating and securing a website we are responsible for.

When you contact us

If you email us or book a call, we receive whatever you choose to send — typically your name, email address, company, and what you are trying to solve. We use it to answer you and, if we work together, to scope and deliver the engagement. Legal basis: steps taken at your request prior to entering a contract, and thereafter performance of that contract.

Cookies and similar technologies

We set no advertising, analytics, or profiling cookies. The only cookies this site may set are strictly necessary or functional:

  • Language preference — our translation plugin, Polylang, may store your chosen language so the site does not reset it on every page. Functional; no tracking.
  • Session and security cookies — set only for logged-in administrators, not ordinary visitors.

Because we set no non-essential cookies, we do not show a cookie consent banner. If that ever changes — for example if analytics are added — we will ask for consent before those cookies are set, not after.

Third parties that can see your data

We keep this list short on purpose, and we would rather disclose an uncomfortable detail than omit it.

  • No font CDN. Our typefaces are served from this site, not from Google. Loading them from Google’s font service would have sent your IP address to Google on every page view — a practice a German court has held infringes the GDPR — so we host them ourselves.
  • WordPress.org (emoji). WordPress loads emoji assets from its own CDN, which receives your IP address. This can be disabled.
  • WP Engine, which stores the site and its server logs on our behalf as a processor under contract, on servers in the United States.

We do not sell personal information, and we do not disclose it for cross-context behavioural advertising. We may disclose data if legally compelled, and will tell you unless prohibited from doing so.

International transfers

We operate from Mexico, and some of the providers above are established in the United States. Where data leaves the EEA or the UK, the transfer relies on the recipient’s Standard Contractual Clauses or an applicable adequacy decision.

How long we keep things

  • Enquiries and correspondence — for the life of the conversation and any resulting engagement, then 24 months so we can pick up a thread you may return to.
  • Server logs — for the period our host retains them.
  • Records we must keep by law, such as invoices, for the statutory period.

Your rights

Wherever you live, you can ask us to: confirm whether we hold data about you; give you a copy; correct it; delete it; restrict or object to how we use it; or receive it in a portable format. Where we rely on consent, you can withdraw it at any time without affecting what we did before you withdrew it.

Ask by writing to our privacy contact above. We will respond within one month. We will not charge you, and we will not treat you differently for asking. If you are in the EEA or UK and you think we have handled your data badly, you can complain to your national supervisory authority — though we would appreciate the chance to fix it first.

If you are in California

Under the CCPA as amended by the CPRA, you have the rights to know, delete, and correct, and the right to opt out of sale or sharing. We do not sell or share personal information and have not done so in the preceding twelve months, so there is no “Do Not Sell or Share My Personal Information” mechanism to offer. We do not use or disclose sensitive personal information for purposes requiring an opt-out. The categories we collect are identifiers (name, email, IP address) and internet activity (pages requested), for the business purposes described above. We do not knowingly collect data from anyone under 16. You may use an authorised agent, and we will not discriminate against you for exercising any right.

Other jurisdictions

Security

The site is served over HTTPS, kept patched, and access to its administration is limited to people who need it. No website is perfectly secure, and we will not pretend otherwise; if a breach affects your rights we will notify you and the relevant authority as required.

Children

This site is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, tell us and we will delete it.

Changes to this policy

If we change how we handle personal data, we will update this page and change the date at the top. Where a change materially affects your rights, we will say so prominently rather than relying on you to notice.