COMPREHENSIVE PRIVACY NOTICE

Asociación Mexicana de Salud Administrada A.C. (AMSAAC)

Last updated: August 6, 2026

In compliance with the Federal Law on the Protection of Personal Data Held by Private Parties, its Regulations, and other applicable provisions, Asociación Mexicana de Salud Administrada A.C. (AMSAAC) (hereinafter "AMSAAC") makes this Privacy Notice available to its members, affiliates, legal representatives, suppliers, strategic partners, event participants, website visitors, and any person whose personal data is processed by the Association.

 

I. Data Controller

Asociación Mexicana de Salud Administrada A.C. (AMSAAC) is responsible for the processing, use, storage, and protection of the personal data it collects.

Address: Pending

Email for privacy matters: Pending

Telephone: Pending

 

II. Personal data we may collect

Depending on the relationship with AMSAAC, we may collect:

Identification data

  • Full name.
  • Company or organization.
  • Job title.
  • Signature.
  • Nationality.
  • Federal Taxpayer Registry (RFC) number, where applicable.
  • CURP (Unique Population Registry Code), when necessary.

Contact data

  • Address.
  • Telephone number.
  • Email address.
  • Professional contact details.

Employment and professional data

  • Company.
  • Position.
  • Specialty.
  • Professional experience.
  • Certifications.
  • Institutional affiliations.

 

Financial and tax data

When a contractual relationship exists:

  • Bank details.
  • Billing information.
  • Tax status certificates.

Electronic data

  • IP address.
  • Browser.
  • Cookies.
  • Device identifiers.
  • Platform access logs.
  • Security logs.

 

III. Sensitive personal data

As a general rule, AMSAAC does not request sensitive personal data. However, in the course of academic, scientific, regulatory, or technological innovation activities related to digital health, artificial intelligence, clinical research, or technology assessment, sensitive data strictly necessary to fulfill said purposes may be processed, always in accordance with applicable legislation and, where appropriate, subject to the express consent of the data subject.

Under no circumstances will AMSAAC commercialize sensitive personal data.

 

IV. Purposes of processing

 

Personal data may be used for the following purposes:

Primary purposes

  • Administering associate memberships.
  • Compiling administrative files.
  • Managing affiliation processes.
  • Entering into contracts and agreements.
  • Issuing tax receipts.
  • Organizing congresses, forums, seminars, and training sessions.
  • Managing certifications and academic programs.
  • Following up on information requests.
  • Handling inquiries and communications.
  • Administering the website and digital platforms.
  • Complying with legal obligations.
  • Implementing information security controls.
  • Managing national and international institutional relationships.

Secondary purposes

Additionally, subject to consent where required, data may be used for:

  • Sending newsletters.
  • Event invitations.
  • Statistical studies.
  • Surveys.
  • Sectoral research.
  • Institutional publications.
  • Disseminating initiatives related to managed health.
  • Promoting digital health and artificial intelligence projects.
  • Developing sectoral indicators.

The data subject may object to processing for secondary purposes using the mechanisms described in this Notice.

 

V. Tracking technologies

Our website may use:

  • Cookies.
  • Web beacons.
  • Similar technologies.

These tools allow for improving the user experience, obtaining browsing statistics, and strengthening information security.

Users may disable such technologies via their browser settings.

 

VI. Transfer of personal data

AMSAAC may transfer personal data when necessary to:

  • Competent authorities.
  • Educational institutions.
  • Certification bodies.
  • National and international health sector organizations.
  • Technology providers.
  • Specialized service providers.
  • Academic institutions. Auditors.
  • Developers of technology solutions.

All transfers will be carried out only when there is a legal basis, a contractual relationship, or the data subject's consent, as applicable.

When technology providers are involved, AMSAAC will execute the necessary legal instruments to ensure the protection of personal data.

 

VII. Artificial Intelligence and Digital Health

As part of its corporate purpose, AMSAAC promotes the responsible use of digital health technologies and artificial intelligence.

When these technologies are used in processes involving analysis, automation, decision support, or the generation of indicators, AMSAAC will ensure their use adheres to principles of:

  • Legality.
  • Transparency.
  • Explainability.
  • Fairness.
  • Non-discrimination.
  • Human oversight.
  • Information security.
  • Personal data protection.
  • Algorithmic governance.
  • Cybersecurity.

When the nature of the data processing requires it, priority will be given to the use of anonymized or pseudonymized data.

 

VIII. Information security

AMSAAC implements administrative, physical, and technical security measures designed to protect personal data against:

  • Damage.
  • Alteration.
  • Loss.
  • Destruction.
  • Unauthorized access.
  • Misuse.
  • Disclosure.
  • Illicit processing.

It also promotes policies regarding risk management, operational continuity, and cybersecurity.

 

IX. ARCO Rights

Data subjects may exercise their rights regarding the following at any time:

  • Access.
  • Rectification.
  • Cancellation.
  • Opposition.

They may also:

  • Revoke their consent.
  • Request a limitation on the use or disclosure of their data.

Requests must be sent to the email address designated by AMSAAC and include:

  • The data subject's name.
  • A means of receiving a response.
  • Documents proving identity or legal representation.
  • A clear description of the request.
  • Documents facilitating the location of the data.

AMSAAC will respond within the timeframes established by applicable legislation.

 

X. Data retention

Personal data will be retained only for the time necessary to fulfill the described purposes, applicable legal obligations, and the retention periods stipulated by relevant regulations.

Once these periods have expired, the data will be deleted, blocked, anonymized, or destroyed in accordance with the Association's internal procedures.

 

XI. Changes to the Privacy Notice

AMSAAC may modify this Privacy Notice to address:

  • Legal amendments.
  • Regulatory changes.
  • New institutional policies. Introduction of new services.
  • Technological changes.

The modifications will be available on the Association's official website.

 

XII. Competent authority

If the data subject believes that their right to the protection of personal data has been violated, they may appeal to the competent authorities regarding personal data protection in accordance with current Mexican legislation.

 

XIII. Consent

By providing personal data through any means, the data subject acknowledges having read this Privacy Notice and, where required by applicable law, grants consent for the processing of their personal data in accordance with the purposes described herein.

Asociación Mexicana de Salud Administrada A.C. (AMSAAC)

Committed to personal data protection, information security, responsible digital health, trustworthy artificial intelligence, and ethical data governance in the healthcare sector.