1. Data controller
VORTA Company, domiciled in Zapopan, Jalisco, Mexico, is the controller of your personal data under the Mexican Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP).

Legal
At VORTA we take the privacy of your data seriously. This policy explains what information we collect, how we use it, and the rights you have over it.
Last updated: September 27, 2026
VORTA Company, domiciled in Zapopan, Jalisco, Mexico, is the controller of your personal data under the Mexican Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP).
We collect the following personal data: • Identification data: full name, email address. • Company data: name, line of business, number of employees, country. • Usage data: modules used, sessions, interactions with the system. • Payment data: processed by PCI DSS-certified third parties — VORTA does not store card data. • Technical cookies: to keep your session active and improve your experience.
We use your data to: • Create and manage your VORTA Client Hub account. • Provide, personalize, and improve the service. • Send you communications related to your account (no advertising without consent). • Comply with legal and accounting obligations. • Analyze product usage in an aggregated, anonymized way to improve features.
We use essential technical cookies required for the service to function (authentication, language preferences). We do not use third-party advertising tracking cookies. You can disable cookies in your browser settings, although this may affect the functionality of the service.
Your data may be shared with: • Supabase (database infrastructure — USA, compliant with EU SCCs). • Vercel (hosting platform — USA). • Anthropic (AI processing for diagnostics — USA). • OpenAI (AI processing — USA). We do not sell or transfer your personal data to third parties for commercial purposes.
You have the right to Access, Rectify, Cancel, or Object to the processing of your personal data (ARCO rights under Mexican law). To exercise them, send an email to: admin@vorta.mx With the subject "Ejercicio de derechos ARCO" and include: your full name, registered email, the right you wish to exercise, and any supporting documentation where applicable. We will respond within a maximum of 20 business days.
We retain data for the duration of the service and according to documented applicable periods. An account-closure request starts a traceable export, restriction, and deletion process. Fiscal, accounting, security, or legally held data may be retained for the required period and is deleted or anonymized when that period ends. The applicable timeline is communicated when the request is confirmed.
We implement verifiable technical and organizational controls: HTTPS/TLS, tenant isolation, role-based permissions, operational audit trails, and mandatory TOTP AAL2 for privileged Commerce access in production. Backup, restore, monitoring, and independent review are release gates for each environment. For more information, see our Security page.
We may update this policy from time to time. We will notify you by email if the changes are material. The current version will always be available at vortacompany.com/privacidad.
For any questions about this policy: Email: admin@vorta.mx Address: Zapopan, Jalisco, Mexico
When the feature is available and you choose to connect Google Calendar, we ask for your authorization through Google. We receive your Google account identifier and email to associate the connection with you. We retrieve titles, dates, times, links and information needed to identify events from your primary calendar and display them alongside your Vorta work. This connection does not access Gmail, Drive files or secondary calendars. We use this access to display your personal events and create, update or delete the copies Vorta generates of your appointments and scheduled work. Copies include titles and times; appointments may include the customer and service names. We do not copy task instructions, notes, customer phone numbers or customer email addresses, or send invitations. Changes in Google do not change the original work in Vorta. Personal events are fetched when you open the calendar and processed temporarily for display; they are not stored as tasks in our database. They are not shown to teammates or administrators or sent to Sofía or AI providers. We do not use Google data to train AI models, serve advertising, sell data or assess creditworthiness. We store the connected account identifier and email, connection status and necessary synchronization records. Credentials that keep synchronization working while you are away from Vorta are stored encrypted. Google processes the events we synchronize; our hosting and database providers, Vercel and Supabase, process data needed to deliver this feature. Human access to Google data is limited to your specific consent, security needs or legal obligations. You can disconnect from the Vorta calendar. This deletes stored credentials and stops future reads and updates; an operation already in progress may finish. Existing copies remain in Google, where you can delete them. You can also revoke permission in your Google account connections. Disconnecting does not automatically delete the connection record or synchronization records: to request their deletion, contact admin@vorta.mx; the retention periods and exceptions in section 7 apply. Our handling and transfer of Google data follow the Google API Services User Data Policy, including its Limited Use requirements. This section limits any general description of data use or sharing elsewhere in this policy.