Dear Client, User, Candidate, or Personal Data Subject:
In compliance with the provisions of Articles 1, 8, 15, 16, and other relevant and applicable sections of the Federal Law on Protection of Personal Data Held by Private Parties (the “Law”) and its Regulations, GRUPO ISSA DE JUÁREZ, S.A. DE C.V., doing business under the trade name “Grupo ISSA Seguridad Privada” / “Grupo ISSA Private Security” (hereinafter “Grupo ISSA” or “the Company”), acting as the data controller responsible for the processing of your personal data, hereby makes this Privacy Notice available to you.
1. Identity and Domicile of the Data Controller
The controller responsible for processing your personal data is GRUPO ISSA DE JUÁREZ, S.A. DE C.V., with corporate headquarters located in Ciudad Juárez, Chihuahua, Mexico, with nationwide operational and strategic coverage, whom you may formally contact through the following channels:
2. Personal Data We Collect
Under the Law, “personal data” means any information concerning an identified or identifiable natural person. For the purposes of this Privacy Notice, and by way of example but not limitation, Grupo ISSA may collect the following categories of personal data:
2.1 Identification and contact data
Full name, date of birth, gender, marital status, home address, landline and/or mobile phone number, email address, voter ID card or other official government photo identification, CURP (Unique Population Registry Code) and RFC (Federal Taxpayer Registry), among other similar data, from clients, prospective clients, suppliers, and visitors.
2.2 Data related to contracting security services
When you contract any of Grupo ISSA’s services (e.g., on-site guarding, armed custody, executive escort, surveillance monitoring, or security consulting), we may collect information regarding the individual or legal representative contracting the service, address of the facility or property to be secured, contact details for incident reporting, and all other information necessary for the provision, execution, and follow-up of the contracted services.
2.3 Patrimonial and billing data
For the purpose of issuing official tax invoices and processing payments for contracted services, we may request fiscal data (company legal name, RFC, fiscal domicile) and, where applicable, banking references for executing wire transfers or processing service fees. Grupo ISSA does not store full credit or debit card numbers, expiration dates, or security codes (CVV) on its public website or unencrypted web systems.
2.4 Data related to job applications and security personnel
When you submit your application through our recruitment channels or apply for a position as a security officer, supervisor, or administrative personnel, in addition to standard personal data, we will collect information regarding educational background, employment history, personal and professional references, as well as documentation and records required by recruitment, training, background check, official accreditation, and registration processes mandated by applicable private security legislation in the corresponding jurisdiction.
2.5 Sensitive Personal Data
Due to the specialized nature of our private security services, for specific processes—primarily recruitment, hiring, official accreditation, and access control of security personnel—we may collect personal data categorized as sensitive under Article 3, Section VI of the Law, such as: criminal record certificates or background checks required by competent authorities, biometric data (e.g., fingerprints or facial photos for biometric access control), and health data strictly necessary to evaluate physical and psychological fitness for duty (e.g., medical evaluations, physical fitness tests, or toxicology screenings).
In compliance with Article 9 of the Law, Grupo ISSA will obtain your express written consent (via handwritten or verified digital signature) prior to processing any sensitive personal data, and such processing shall remain strictly limited to the specific purposes communicated to you at the time of collection.
2.6 Data captured by Closed-Circuit Television (CCTV) systems
In executing our monitoring, surveillance, and physical protection services—both at our own corporate facilities and, where applicable, across our clients’ premises—we may record images and video via closed-circuit television (CCTV) cameras of individuals entering such facilities. This data is utilized exclusively for security oversight, loss prevention, incident investigation, and, where required, as formal evidence before competent law enforcement and judicial authorities.
2.7 Social media platforms
Social media platforms where Grupo ISSA maintains a public profile (e.g., Facebook, Instagram, LinkedIn, among others) constitute independent communication platforms outside Grupo ISSA’s direct control. The information you share within those third-party networks does not fall under the scope of this Privacy Notice, remaining the sole responsibility of the respective platform provider and the publishing user.
2.8 Cookies and tracking technologies
Our official website (www.grupoissaseguridad.com) may use cookies or log IP addresses for the sole purpose of delivering a personalized browsing experience, analyzing web traffic preferences, and optimizing system functionality. The use of cookies does not gather sensitive personal data. You may disable cookies at any time through your web browser settings, although doing so may restrict certain interactive features of the website.
3. Purposes of Personal Data Processing
3.1 Primary purposes (strictly necessary for the relationship with Grupo ISSA)
- Evaluate, contract, and deliver requested private security services, on-site guarding, asset custody, executive protection, and/or electronic monitoring.
- Draft contracts, service orders, non-disclosure agreements, and operational documentation required to formalize and execute commercial relationships.
- Process billing, invoicing, payments, and fulfill applicable fiscal, tax, and accounting statutory obligations.
- Verify identity and manage physical access control logs for personnel and visitors entering our facilities or client sites.
- Recruit, vet, hire, train, certify, accredit, and register operational and administrative staff, fulfilling all regulatory requirements mandated by private security authorities.
- Address incident reports, emergencies, customer support requests, claims, or inquiries regarding contracted security operations.
- Comply with all applicable federal, state, and municipal legal obligations, regulatory mandates, and formal directives issued by competent authorities in the field of private security.
3.2 Secondary purposes (non-essential, but enabling us to provide improved services)
- Send commercial communications, corporate newsletters, industry updates, and new security service offerings.
- Conduct service quality surveys, client satisfaction evaluations, and internal operational analytics.
- Direct contact for commercial marketing and business outreach.
If you do not wish your personal data to be processed for these secondary purposes, you may notify us at any time by sending your request to the email address specified in Section 7 of this Notice. Your refusal to permit secondary processing will under no circumstances compromise or affect the provision of the security services contracted with the Company.
4. Principles and Security Measures
Grupo ISSA is committed to upholding the principles of legality, consent, information, data quality, purpose limitation, loyalty, proportionality, and accountability set forth in the Law.
Your personal data is safeguarded under strict administrative, technical, and physical security measures, including role-based database access controls, firewalls, and encryption where appropriate, preventing damage, loss, alteration, destruction, or unauthorized access, use, or disclosure.
Nonetheless, no electronic storage or transmission system is completely invulnerable; in the event of any security breach that materially impacts your patrimonial or moral rights, Grupo ISSA will promptly inform you in accordance with the procedures established by the Law.
5. Transfer of Personal Data
Grupo ISSA may transfer your personal data to domestic or international third parties under the following circumstances:
- To competent authorities: When required pursuant to a legal obligation, court order, or official regulatory mandate governing private security operations.
- To affiliated support service providers: Specialized third-party vendors who assist in fulfilling operational services (e.g., certified training centers, payroll processors, IT infrastructure and hosting providers), all of whom are contractually bound to maintain strict confidentiality and data protection standards aligned with this Notice.
- To Grupo ISSA clients: Exclusively regarding information strictly necessary for operational coordination, site clearance, and deployment (e.g., identity verification and official accreditation credentials of assigned security personnel).
Unless you express your opposition to these transfers through the mechanisms detailed in this Notice, your consent will be deemed granted, except with respect to sensitive personal data, for which express written consent will always be obtained.
6. Consent
By providing your personal data to Grupo ISSA directly, via physical or electronic forms, through our website, or by any other means, you acknowledge and grant your consent for your data to be processed in accordance with the terms and purposes set forth in this Privacy Notice. In the case of sensitive personal data, such consent will always be obtained expressly and in writing.
If, within a period of two (2) months following the receipt or publication of this Privacy Notice or any amendments hereto, you do not express your opposition, your tacit consent shall be deemed granted for the processing of your data for the described purposes, with the exception of sensitive data.
7. ARCO Rights (Access, Rectification, Cancellation, and Opposition)
You hold the right to know what personal data we hold about you, what we use it for, and the conditions of its treatment (Access); to request the correction of your personal data if it is outdated, inaccurate, or incomplete (Rectification); to request that we delete your data from our records or databases when you consider it is not being utilized in accordance with the principles, duties, and obligations established under the Law (Cancellation); and to object to the processing of your personal data for specific purposes (Opposition). These prerogatives are collectively known as ARCO Rights.
Procedure for Exercising Your ARCO Rights
You must submit a formal written request addressed to the Data Protection Department of Grupo ISSA via email at ventas@grupoissaseguridad.com, or in writing to the Company’s corporate domicile, providing the following information and documentation:
- Full name of the data subject and a valid address or email to communicate the response to your request.
- Official documents establishing your identity or, where applicable, the legal representation of the data subject.
- A clear and accurate description of the personal data with respect to which you seek to exercise any of the ARCO rights.
- Any additional documentation or information that assists in locating the relevant personal data.
Grupo ISSA will issue a formal resolution within a maximum period of twenty (20) business days from the date your request is received, a term that may be extended once for an equal duration when justified by the circumstances of the matter. If the request is determined to be substantiated, the requested action will become effective within fifteen (15) business days following the date the response is communicated.
If you believe that your right to personal data protection has been infringed, you have the right to file a complaint before the National Institute for Transparency, Access to Information and Personal Data Protection (INAI) (home.inai.org.mx).
8. Limitation of Use or Disclosure of Your Data
You may at any time request that we limit the use or disclosure of your personal data for specific non-essential purposes (such as commercial marketing or prospecting) by submitting your request to the Data Protection Department at ventas@grupoissaseguridad.com, or through the options available on our website.
9. Amendments to the Privacy Notice
Grupo ISSA reserves the right to modify, update, or revise this Privacy Notice at any time in response to legislative updates, internal corporate policies, evolving operational security standards, or industry best practices. Any modifications will be continuously accessible to the public via our official website in the Privacy Notice section.
This Privacy Notice was last updated in August 2026.
10. Informational Nature and Acceptance
The content of this Privacy Notice is informational. To express your acceptance or refusal regarding this Notice or the transfer of your personal data, you are invited to utilize the mechanisms provided by Grupo ISSA across its intake forms, service agreements, official website, or by direct communication to the Data Protection Department.