Privacy Notice
This is a courtesy translation. This privacy notice is issued under Mexican law (LFPDPPP) and governs a Mexican company's processing of your data regardless of where you access this site from. The Spanish-language version is the legally binding original; in the event of any conflict or inconsistency between the two, the Spanish text prevails.
1. Who is responsible for processing your personal data
FIXTEAM, S.A. de C.V., registered at Belisario Dominguez No 2116 No Int L 34 INT 5. Las Arboledas, Tuxtla Gutierrez, Chiapas, Mexico 29030 (referred to below as "InfoSecDash" or "we"), is the data controller for your personal data under Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations.
InfoSecDash (infosecdash.com) is a site operated by FIXTEAM, S.A. de C.V. For anything related to this notice, the contact person is Miguel Ángel Ramírez Fregoso, at [email protected]. If you want to report a security vulnerability on the site, there's a separate channel for that: responsible disclosure.
2. Personal data we collect
Depending on which service on the site you use, we may collect:
- If you subscribe to the newsletter (/en/registro.html): full name, email address, the type of newsletter you chose (daily digest or by category) and, if applicable, the categories you're interested in.
- If you write to us through the contact form (/en/contacto.html), for example to ask about advertising on the site: name, email address, company or brand (if applicable), and the content of the message you send us.
We do not ask for or collect sensitive personal data (ethnic or racial origin, health status, religious beliefs, sexual preferences, political opinions, among others) on any form on the site.
Data collected automatically
When you submit a form, your IP address may be processed temporarily solely for security purposes — for example, to limit how many times a form can be submitted from the same address in a short period, to prevent abuse or spam. This information is not stored together with your other personal data and is not used to identify or profile you.
In addition, when you open a story we log the visit to keep a count of the most-read stories. To avoid counting the same person more than once on the same day, we store a cryptographic fingerprint of your IP address, not the address itself. That fingerprint is computed with HMAC-SHA-256 using a secret key known only to our server: your IP is never stored as plain text, and without that key the fingerprint cannot be traced back to a specific address. It is also not linked to your name, your email, or any other data you've given us. Its only use is to keep the same visit from being counted twice.
Visits from automated crawlers (search engines and similar) are discarded and not logged.
3. Purposes of processing
Primary purposes (necessary for the service you requested):
- Sending you the cybersecurity newsletter you chose when you signed up.
- Responding to messages you send us through the contact form.
- Applying security and abuse-prevention measures on our forms.
- Keeping an aggregate count of the site's most-read stories, without identifying who read them.
InfoSecDash currently does not use your personal data for secondary purposes (marketing, advertising directed at you, sales prospecting, nor do we share it with third parties for purposes other than those described here). If this changes, we will update this notice and, where the law requires it, ask for your express consent before using your data for those new purposes.
4. Transfers and data processors
To send you the newsletter we use an outside email delivery provider (Resend). That provider only processes your name and email to deliver the newsletter on our behalf and under our instructions — it cannot use your data for its own purposes. This counts as a data processor (not a transfer to a third party that decides what to do with your data), under Article 3, Section III of the LFPDPPP.
When the original outlet's icon is shown on some stories, your browser requests it directly from Google's public icon service — Google may receive your IP address as part of that request, the same as happens when loading any image hosted outside this site.
The site's fonts are loaded from Google's public font service (fonts.googleapis.com and
fonts.gstatic.com). As with the icons, your browser requests them directly from Google, which
may receive your IP address as part of that request.
The site runs behind Cloudflare, which acts as a content delivery network and a protection layer against attacks. By its nature, all traffic to InfoSecDash passes through its infrastructure, so Cloudflare processes your IP address and technical connection data to deliver the site to you and filter malicious traffic. Cloudflare also injects its web analytics tool (Web Analytics), which measures visits and page performance without using cookies and without building a cross-site profile of you. We do not use Google Analytics or any other advertising tracking tool.
We do not sell, rent, or share your personal data with third parties for purposes other than those described in this notice.
5. About the news we publish
The content of InfoSecDash's stories comes from public sources (the RSS feeds openly published by various cybersecurity outlets) and is processed with artificial intelligence to generate an original summary, translation, and classification — we never reproduce the source's full article.
Some stories may mention the names of people, companies, or organizations — for example, in the context of a data breach or a ransomware attack. That information is already public in the original source cited in each report, and InfoSecDash does not collect additional personal data about those people beyond what is necessary to write the news summary: we do not build profiles or files on the people mentioned in stories.
If you believe a story published on InfoSecDash contains personal data of yours that you'd like corrected or removed from the site, write to us at [email protected] and we'll review your request. If the data comes from the original source, you may also need to contact that outlet directly to have it changed at the origin.
6. How to exercise your ARCO rights
Under Mexican law you have the right to Access the personal data we hold about you, Rectify it if it's outdated or inaccurate, Cancel it when you believe it is no longer needed for any of the purposes in this notice, or Oppose its use for specific purposes.
To exercise any of these rights, write to us at [email protected] including:
- Your full name and the email you registered or wrote to us with.
- A clear description of the personal data you want to exercise your right over.
- Any document that helps verify your identity or your request.
We will respond within a maximum of 20 business days, as required by the LFPDPPP.
If you subscribed to the newsletter, you can also unsubscribe at any time with one click from the unsubscribe link included in every email — no need to write to us or wait for the process above.
7. Withdrawing your consent
You can withdraw the consent you gave us to process your personal data at any time, through the same channels as the previous section. Withdrawing it does not affect processing that already took place before your request.
8. Minors
InfoSecDash's services are intended for adults. We do not knowingly collect personal data from minors. If you are the parent or guardian of a minor who registered their data on this site without your authorization, contact us to have it removed.
9. Use of cookies
InfoSecDash's public site does not set any cookies: no session cookies, no tracking cookies, no advertising cookies. You can verify this yourself in your browser's developer tools. The Cloudflare analytics described in section 4 also doesn't use cookies. The admin panel (CMS), used exclusively by the InfoSecDash team, does use a technical session cookie — that cookie doesn't affect you as a visitor to the public site.
What we do save in your browser is your light/dark theme preference, in
local storage (under the key infosecdash-theme). It's not a cookie, it's
never sent to our server or to any third party, and it exists only so the site looks the way you left it
last time. You can delete it from your browser's settings whenever you want.
10. Changes to this privacy notice
We may modify this notice to comply with legislative updates, changes to our internal practices, or new services we offer. Any change will be published on this same page, updating the date at the top. We recommend reviewing it periodically.
11. Data protection authority
If you believe your right to personal data protection has been violated, or suspect any breach of the LFPDPPP's provisions, you have the right to contact Mexico's National Institute for Transparency, Access to Information and Personal Data Protection (INAI) — or whichever body assumes its functions.