Last updated: 12 January 2026
Comprehensive Privacy Notice
1. Data controller
Mxrepist S.A.P.I. de C.V. (hereinafter "Mxrepist"), with legal domicile at Av. Paseo de la Reforma 250, Floor 8, Colonia Juárez, Cuauhtémoc, ZIP 06600, Mexico City, is responsible for processing your personal data in accordance with the Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) and its regulations.
2. Personal data we collect
We collect identification data (name, INE, CURP, photograph), contact data (email, phone, address), financial data (CLABE, tax information, credit history through credit-information agencies), and net-worth data when you participate as an investor. Sensitive data is never collected without your express written consent.
3. Purposes
We use your data to: (i) verify your identity in accordance with the UIF regulations; (ii) operate your account and execute the loan agreements; (iii) comply with tax obligations before the SAT; (iv) prevent fraud and money laundering; (v) send you commercial information, subject to authorisation. You may object to secondary purposes at any time.
4. Transfers
We share your data with Banco Actinver (trustee), with credit-information agencies (Buró de Crédito and Círculo de Crédito), with the CNBV, UIF and SAT when the law requires, and with our external auditors. None of these transfers require additional consent under article 37 of LFPDPPP.
5. ARCO rights
You can exercise your rights of Access, Rectification, Cancellation and Opposition, as well as revoke your consent, by sending a request to privacidad@mxrepist.com. We will reply within twenty business days as per article 32 of LFPDPPP. If you consider your right infringed, you may lodge a complaint before the INAI.
6. Use of cookies and similar technologies
Our site uses cookies as detailed in the Cookie Policy. We implement Google Consent Mode v2 to respect your decisions about analytics, advertising and personalisation.
7. Security
We apply administrative, physical and technical measures to protect your data against loss, alteration or unauthorised access. We rely on TLS 1.3 encryption in transit, AES-256 at rest and ISO/IEC 27001 controls audited annually.
8. Changes to the notice
Any modification will be published at this same address. We recommend reviewing it periodically. The version in force at the time of contracting is the one applicable to the relationship.