Privacy Policy (Global Account)
Privacy Policy
PIER 5 S.A. de C.V. (hereinafter, the "Company"), with address at Paseo de la Reforma 296, floor 14, suite 1400, Colonia Juárez, Cuauhtémoc Borough, C.P. 06600, Mexico City, Mexico, publishes this Privacy Notice for the purpose of using and protecting the Personal Data of its Users that is in our possession, and to regulate its legitimate, controlled and informed processing, in order to guarantee privacy and the right to self-determination and in compliance with the legal provisions on the protection of personal data such as the Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP).
To this end, the Company informs the following:
In this Policy, "Personal Data" means any information relating to you as an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to your physical, physiological, genetic, mental, economic, cultural or social identity. For the avoidance of doubt, the term Personal Data does not include information from which you cannot be identified (anonymous data or unidentified data).
In this Policy, "Processing" means any operation or set of operations performed on Personal Data or on a set of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, cancellation or destruction.
For everything related to the processing and protection of your Personal Data, you may contact us by sending an email to the following address privacy@arqfinance.com.
1. HOW WE COLLECT YOUR INFORMATION
We collect your personal information when:
you visit our website or mobile applications;
you contact us through the applications or by other direct means of electronic communication;
you interact with us or with our service;
you enter into a contract with us or give us your express consent (for example, to use our service);
you give us instructions related to your account; and/or
you establish any other relationship with us or interact with us or our services.
Additionally, we will automatically collect the following information when you use our applications: (i) the type of domain you use to connect to the Internet; (ii) the assigned IP address; (iii) your location/geolocation; (iv) your access information; (v) the date and time of access to the applications; (vi) the pages visited; (vii) unique device identifiers; (viii) the type of browser used; (ix) the operating system and/or platform used; (x) the search engine and keywords used; and (xi) any other similar identifying information for communications with the applications.
With respect to Geolocation, this data will be collected only if you authorize its collection from your device. In accordance with applicable laws and regulations, if you do not authorize access to your geolocation, you may not be able to (i) open an Account, (ii) access your Account and/or (iii) carry out any transaction.
2. PURPOSE OF THE USE OF YOUR PERSONAL DATA
The personal information you provide us will be used for the following primary purposes:
Fulfilling the contractual relationship arising from the request and/or contracting of our products or services.
Verifying, confirming and validating your identity.
Compiling your identification file and transaction history.
Contacting you in the event of unusual activity, responding to requests for assistance or when required by any applicable law or authority.
Managing, operating and monitoring the services provided by the Company.
Audit processes by the competent authorities.
Complying with the notices established for the prevention of money laundering with respect to vulnerable activities.
Your personal data may be used for the following secondary purposes:
Sending you offers of the services provided by the Company.
Preparing customer profiles to offer products and services.
Sharing some of your contact data, in anonymized format, with digital advertising platforms, for the purpose of excluding the Company's active Users from advertising campaigns, avoiding unnecessary expenses on targeted advertising. You may object to this sharing at any time by deactivating the personalized ads option in the application or by contacting us through the channels indicated in this Policy.
If the customer does not wish their personal data to be processed for these secondary purposes, they may at any time state this and object to or revoke their consent; these actions will not be grounds for denial of the provision of services.
3. PERSONAL DATA TO BE COLLECTED
Paternal surname, maternal surname and name or names; country of birth, nationality, sex; date of birth; home address in the country of residence and, in the event of having an address in national territory, this will also be collected, comprising the name of the street, avenue or roadway in question, duly specified; exterior number and, where applicable, interior number; neighborhood or subdivision; city or town, federal entity, state, province, department or similar political division as applicable; postal code and country; occupation, profession, activity or line of business the customer engages in; Unique Population Registry Code (CURP), Federal Taxpayer Registry (RFC); telephone number; email address; Standardized Bank Code (CLABE) at the Financial Institution and corresponding to the User's name. Likewise, official identification documents and their data (issuing authority and number) and, where applicable, proof of address will be requested, digitized to verify the accuracy of the data provided.
4. SENSITIVE PERSONAL DATA
The Company will not request sensitive personal data, which according to Article 3, section VI of the LFPDPPP are: those personal data that affect the most intimate sphere of their holder, or whose improper use may give rise to discrimination or entail a serious risk to them. In particular, data that may reveal aspects such as racial or ethnic origin, present and future health status, genetic information, religious, philosophical and moral beliefs, union membership, political opinions, or sexual preference are considered sensitive.
5. AUTOMATED DECISIONS
We do not use fully automated decision-making methods that produce legal effects concerning you or that significantly affect you, except when we carry out risk analysis regarding our customers to comply with applicable anti-money laundering and counter-terrorism financing legislation.
When automated decision-making occurs, you have the right to: (i) express your point of view; (ii) contest the decision; and (iii) request the intervention of a natural person in its review. To exercise this right, contact us through the details indicated in this Notice.
6. TRANSFER OF PERSONAL DATA
The Company may disclose or transfer your Personal Data at the request of the competent authority or in any of the other cases established in Articles 10 and 37 of the LFPDPPP, for which the consent of the holder of said personal data is not required, in accordance with the LFPDPPP itself and its Regulations.
In addition, the Company may share your Personal Data with:
Companies belonging to the Company's Corporate Group. That is, any affiliate, subsidiary or holding company of the company or any other company thereof.
Suppliers that provide services to the company for the maintenance or fulfillment of the contractual relationship with its Users.
Providers of risk management, information security, specialized software necessary for the fulfillment of the contractual relationship that binds us with our Users, providers of specialized fraud prevention software and the like.
Digital advertising platforms, for the secondary purpose described in Section 1, always in anonymized format prior to transfer.
The data may only be shared with third parties that comply with the purposes established in this notice. It should be noted that the Company will not sell, assign or transfer your personal data to third parties outside the company, its affiliates, subsidiaries and related parties, without your prior consent, on the understanding that the recipient of the data will assume the same obligations that correspond to the Company.
When your Personal Data is held outside Mexico, we will ensure that it has an adequate level of protection. We require our service providers to establish and maintain appropriate security measures to maintain the security and confidentiality of your Personal Data, through strict standards and legal agreements.
In the event that the transmission of the Data is made from Mexico to a recipient in a country with a different regime regarding the protection of personal data, we will ensure that such transfer does not adversely affect the level of protection of your Personal Data, and that it is based on appropriate security measures, such as standard protection clauses or binding corporate rules in accordance with the LFPDPPP and its Regulations.
In addition, we may transfer and receive your personal information to a third party as part of the sale or provision of some or all of our business and assets, or as part of any restructuring or reorganization of the business, or if we are required to do so to comply with a legal obligation. In any case, we will take steps to ensure that your privacy rights continue to be protected.
7. SECURITY MEASURES TO PROTECT PERSONAL DATA
Your personal data will be protected under strict confidentiality, and to prevent any damage, loss, alteration, destruction or improper or unauthorized use or disclosure, we have implemented physical, technical and administrative security measures in accordance with the Federal Law on the Protection of Personal Data Held by Private Parties and its Regulations.
The User may revoke consent, limit the use they may have given us for the processing of their personal data and object to the use of their personal data for secondary purposes. However, it is important to note that we will not be able to address your request or cease use immediately in all cases, since it is possible that due to some legal obligation we must continue to process your personal data. Likewise, it must be considered that, for certain purposes, the revocation of consent will imply that we cannot continue providing the service you requested, or the conclusion of your relationship with us.
To revoke your consent or limit the use of your personal data, you must submit your request to the following email privacy@arqfinance.com, which must contain the following requirements: (i) name of the information holder, their address and email or other means to communicate the response; (ii) documents that prove their identity or the corresponding legal representation; (iii) a clear and precise description of the personal data or purposes for which the corresponding right of revocation or objection is exercised; and (iv) any other element that facilitates the location of the personal data.
8. RETENTION PERIOD OF YOUR PERSONAL DATA
We retain your information only for as long as necessary to carry out the purposes for which it was collected, as indicated in this Notice. Records may be kept in various formats (physical or electronic).
Retention periods are determined based on the type of record and applicable legal or regulatory obligations. As a general reference:
Personal data collected in compliance with legal obligations (for example, AML/CTF): minimum 10 (ten) years.
Personal data collected under a contract: 6 (six) years after its termination, in accordance with our legitimate interests and for the purpose of defending ourselves against any legal claim.
Data collected based on the holder's consent: until consent is revoked, and as long as there is no other legal obligation for its retention.
However, we may retain your personal data for longer periods when such action is necessary to comply with a legal obligation, to protect vital interests, when we have a legitimate interest in doing so, or when required to do so by a competent judicial authority.
9. ARCO RIGHTS AND REVOCATION OF CONSENT
Under the terms permitted by applicable regulations, it is your right to know what Personal Data we store, what we use it for and the conditions of use that the Company gives it; likewise, it is your right to request the rectification of your personal information in the event that it is outdated, inaccurate or incomplete, to have us delete your personal data from our records or databases when you consider that they are not being used in accordance with the principles, duties and obligations provided for in the regulations, as well as to object to the use of your personal data for specific purposes. All of the above is known as ARCO rights (Access, Rectification, Cancellation and Objection).
You have the right to request at any time access, rectification, cancellation or objection regarding the personal data that concern you, unless it is not appropriate under the terms of applicable regulations, of which we will inform you if that is the case.
For the exercise of any of the ARCO rights, the customer must submit the respective request to the following email privacy@arqfinance.com. This request must contain the following requirements: (i) name of the information holder, their address and email or other means to communicate the response; (ii) documents that prove their identity or the corresponding legal representation; (iii) a clear and precise description of the personal data with respect to which the corresponding right is exercised; and (iv) any other element that facilitates the location of the personal data. The customer has the obligation to observe the pertinent requirements for the exercise of their ARCO Rights. In the case of Rectification requests, the holder must also indicate the modifications to be made and provide documentation supporting their request.
The Company will communicate to the data holder, through the email indicated for these purposes, the determination adopted regarding their request, within a maximum period of twenty days from the date of its receipt. If the request is appropriate, it will be made effective within fifteen days from the date on which the response is communicated. These periods may be extended once for an equal period, provided that the circumstances of the case justify it. In the case of requests for access to personal data, delivery will proceed upon prior accreditation of the identity of the applicant or legal representative, as appropriate.
10. ADDITIONAL DATA PROTECTION RIGHTS
In addition to the ARCO rights, and in accordance with applicable regulations and international best practices on data protection, you have the following rights:
Right to data portability. When processing is based on your consent or is necessary for the performance of a contract to which you are a party, you have the right to receive the personal information you have provided us in a structured, commonly used and readable format.
Right not to be subject to automated decision-making. Under the terms described in the Automated Decisions section of this Notice, you have the right to express your point of view and contest any decision based on automated processing that affects you.
Right to opt out of direct marketing. You may decide at any time whether or not you wish to receive information from us in accordance with our secondary purposes, including commercial or marketing communications, without this affecting the provision of the primary services.
Right to withdraw your consent. When the legal basis for the processing of your personal information is your consent, you have the right to revoke it at any time by contacting us through privacy@arqfinance.com. This may affect the services we can provide you, of which we will inform you in a timely manner.
Right to file a complaint. If you wish to file a complaint about how we have handled your Personal Data, you can contact us. If you do not receive a response within a reasonable period, or if your complaint was not resolved satisfactorily, you have the right to file a claim with the Ministry of Anti-Corruption and Good Governance.
The exercise of any of these rights is not a prerequisite for, nor does it prevent, the exercise of another.
11. SECURITY BREACHES
We have prepared procedures to handle any suspected breach of the Personal Data protection obligations. In the event of a breach of the security of your Personal Data at any stage of processing, and that this significantly affects your property or moral rights, we will notify you immediately through the email you provided us, so that you are able to take the necessary measures to defend your rights.
12. USE OF COOKIES, WEB BEACONS OR ANY OTHER SIMILAR OR ANALOGOUS TECHNOLOGY
"Cookies": Defined as programming information contained in a text file that is saved in your Internet browser or elsewhere on your hard drive. You can manage their acceptance directly in your browser preferences, taking into account that, if you decide to block them, you may not be able to access the content of our application. The Company may use cookies to distinguish your browser from others in our application, as well as to collect statistics about them.
"Web beacons": The Company may use tracking technologies such as "web beacons" to collect data about your visits to the mobile application; similar to "cookies," they are small electronic images embedded in web content or in email messages, which are usually not visible to users and which allow us to generate almost personalized content to offer you a better experience when using our application.
Through cookies and web beacons, the Company will not collect personal data.
Biometric data: In the remote account opening process, we may collect and use information that identifies you through an image taken from the device you use to access our services. For more information, consult the terms and conditions of our products and services.
13. CHANGES TO THE PRIVACY NOTICE
The Company may modify, change and/or update this Privacy Notice as a result of new legal requirements; our own needs due to the products or services we offer; our privacy practices; changes in our business model, or for other reasons. We are committed to keeping you informed about the changes this privacy notice may undergo, through our application or by email.
The User has the obligation to frequently review the policies to learn about the modifications. The entry into force of the changes to this Privacy Notice will be ten days after its publication; within the five days following its publication, the User must state via email if they do not agree with them, in which case the provision of services will be suspended. Once said period has elapsed, it will be understood that the User accepts the modifications to the Privacy Notice.
14. ACCEPTANCE
This Privacy Notice is subject to the express consent of the data holder, which constitutes a legal agreement between the User and the Company. The use of the Company's services will be considered the express manifestation of the customer's will and of their agreement with this Privacy Notice, without excluding that there may be an additional express form of manifesting the customer's will.
15. AUTHORITY
The competent authority regarding the protection of personal data in Mexico is the Ministry of Anti-Corruption and Good Governance. In the event that the User considers that their rights are being violated, they may turn to the Ministry of Anti-Corruption and Good Governance to obtain more information and assistance in this regard.
16. REQUEST DATA DELETION
You have the right to delete your Company account whenever you wish. To delete your account, open the "profile" section and choose "personal data." At the bottom of the section, you will see an option to "close account." Tap this button and you can confirm that you want to close your account.
Data classified as restricted or confidential will be securely deleted when it is no longer needed. The Company will evaluate the data and deletion practices of external providers in accordance with the Third-Party Management Policy. Only third parties that comply with The Company Inc.'s requirements for secure data deletion will be used for the storage and processing of restricted or confidential data. The Company will ensure that all restricted and confidential data is securely deleted from company devices before or at the time of their disposal. Confidential and restricted printed materials will be shredded or otherwise disposed of using a secure method.
Personally Identifiable Information (PII) will be collected, used and retained only for as long as the company has a legitimate business purpose. PII will be deleted and securely disposed of upon termination of the contract in accordance with company policy, contractual commitments and all relevant laws and regulations. PII will also be deleted in response to a verified consumer or data subject request, when the company has no legitimate business interest or other legal obligation to retain the data.
ANNEX A - Data Retention Matrix
System or application | Data description | Retention period |
DolarApp Inc. SaaS Products (AWS) | Customer data | Up to 5 years after contract termination |
DolarApp Inc. AutoSupport | Customer instance and metadata, debugging data | Indefinite |
DolarApp Inc. Customer Support Tickets (Salesforce) | Support tickets and cases | Indefinite |
DolarApp Inc. Customer Support Phone Conversations (TalkDesk) | Support phone conversations | Indefinite |
DolarApp Inc. Security Event Data (Splunk) | System and security log and event data, network data flow logs | Local: indefinite AWS instance: 1 year |
DolarApp Inc. Vulnerability Scan Data (Qualys) | Vulnerability scan results and data detection | 6 months Host (asset) data is retained until deleted and removed from Qualys |
DolarApp Inc. Customer Sales (Salesforce) | Opportunity and Sales data | Indefinite |
DolarApp Inc. Quality Control and Test Data (TestRail) | Quality control, test scenarios and results data | Indefinite |
Security Policies | Security Policies | 1 year after being archived |
Temporary files | AWS/tmp ephemeral storage | Automatically when the process ends |
Last updated: May 22, 2026
