GigNet, S.A. de C.V.
Website and Mobile App
Version: June 2026 | Last updated: June 2026
1. Identity and Address of the Responsible Party. GigNet SA de CV (hereinafter “GigNet” or the “Responsible Party”), with address for receiving notifications at Avenida Bonampak, SM 03, Mzn. 8, Lote 58-02, Plaza Vía, Third Floor, Cancún, Quintana Roo, Mexico, CP 77500, is responsible for the legitimate, controlled and informed processing of the personal data it collects from its prospects, clients and users (hereinafter the “Data Subject”), in compliance with the Federal Law on the Protection of Personal Data Held by Private Parties (hereinafter “LFPD PPP”), published in the Official Gazette of the Federation on March 20, 2025 and its latest amendment on November 14, 2025, as well as its Regulations and other applicable regulations.
Contact information for privacy matters:
2. Personal Data Subject to Processing. In order to provide its connectivity services, GigNet collects your personal data through the following means: (i) directly, when the Data Subject enters it on the website www.gignet.mx (the “Website”); (ii) directly, through the GigNet mobile application (the “App”); (iii) directly, when the Data Subject provides it at our service centers, by telephone , by email and through instant messaging systems or through social networks; (iv) indirectly, when other companies transfer data to us; and (v) indirectly, through publicly accessible sources authorized by the LFPDPPP.
2.1 Non-Sensitive Personal Data
2.1.1 Identification and contact:
2.1.2. Usage and browsing data (collected automatically):
IP address, type and version of browser, or operating system.
Mobile device identifiers (IDFA/GAID) in the App.
Pages visited, duration of stay, links followed.
Connectivity service usage statistics.
Push notification token (in the App, when the Data Subject grants their consent).
2.2. Sensitive Personal Data. GigNet does not generally collect sensitive personal data under the terms of Article 2, Fraction VI, of the LFPDPPP. In the event that a specific process requires its processing, the Data Controller will request the express and written consent of the Data Subject, in accordance with Article 8 of the LFPDPPP, through a mechanism that proves it.
2.3 Financial and Asset Data.
GigNet will collect the following financial and asset data when they are strictly necessary for the hiring and operation of its telecommunications services. In accordance with Article 7 of the LFPDPPP, their processing requires the express consent of the Data Subject:
Bank account: debit or checking account number (collected solely for direct debit payments and collection).
Interbank CLABE: 18-digit standardized bank code for direct debit or refund instructions.
Financial institution: name of the bank or institution issuing the account or card.
Payment history: record of payments made, dates, amounts, methods used, and outstanding balance with GigNet.
Billing information: RFC with homoclave, tax regime, proof of fiscal situation, use of CFDI, and email for sending digital tax receipts.
These data will be processed exclusively for the following linked purposes:
Billing: issuance of digital tax receipts (CFDI) for the services contracted, in accordance with the Fiscal Code of the Federation.
Collection: management of ordinary collection, direct debit of recurring charges, and, where appropriate, extrajudicial or judicial collection.
Payment validation: confirmation, reconciliation, and accreditation of payments received, including recurring charges and online payments.
Fraud prevention: detection of unusual operations, financial identity verification, and prevention of improper use of the service or payment methods.
GigNet does not store full credit or debit card numbers. Card payment processing is carried out exclusively through payment processors certified under current PCI-DSS standards. The CLABE and bank account are used solely for the direct debit purposes authorized by the Data Subject and are never shared with third parties unrelated to the provision of the service.
2.4. Data Processing in Contracts with Legal Entities.
When GigNet’s services are contracted by a legal entity (company, corporation, developer, hotel, institution, or organization), GigNet may process the personal data of the natural persons linked to said entity who participate in the contractual relationship, including:
Legal representative and administrators: full name, CURP, official identification, notarial instrument proving representation powers.
Technical contacts: name, position, email, and phone number of the person responsible for the infrastructure or installation of the service.
Financial contacts: name, position, email, and phone number of the person responsible for payments, billing, and collection of the contracting entity.
Operational contacts: name, position, email, and phone number of the persons designated for the management, support, and monitoring of the service on-site.
These data will be processed exclusively for the administration, operation, billing, and support of the contractual relationship between GigNet and the contracting legal entity. The legal entity is responsible for informing each of its collaborators whose data it provides to GigNet about the content of this Privacy Notice and for obtaining, if applicable, the corresponding internal authorizations.
2.5. Personal Data of Minors.
GigNet does not collect personal data from minors under 18 years of age. If the Data Subject registers data of a minor without proving parental authority or guardianship, GigNet may cancel the registration without any liability.
3. Purposes of the Processing.
3.1. Primary Purposes.
The following purposes are necessary for the existence, maintenance, and compliance of the legal relationship between GigNet and the Data Subject. Without them, GigNet would not be able to provide its services:
Identify and verify the identity of the Data Subject for contracting and accessing the services.
Conclude, administer, and execute the connectivity services contract.
Activate, manage, operate, and provide technical support to the contracted services (residential internet, business internet, Mesh WiFi).
Perform billing, collection management, and payment processing.
Manage clarifications, complaints, and claims related to the services.
Send operational communications regarding the service (maintenance, interruptions, updates).
Comply with applicable legal obligations, including those derived from the Law on Telecommunications and Broadcasting and the provisions of the Telecommunications Regulatory Commission, the Digital Transformation and Telecommunications Agency, or their equivalent.
Respond to requirements from competent authorities within the framework of the law.
Guarantee network security and prevent fraud, unauthorized access, and illegal conduct.
Process and follow up on requests to exercise ARCO Rights.
Conduct video surveillance activities in GigNet’s facilities, data centers, network nodes, and customer service centers, with the purpose of guaranteeing the physical security of people, assets, and technological infrastructure. Recordings will be kept for a maximum period of 30 calendar days, unless they must be preserved by requirement of a competent authority or in the context of an ongoing investigation.
Manage technical incidents, claims, and ordinary, judicial, and extrajudicial collection processes.
3.2. Secondary Purposes.
The following purposes are not necessary for the provision of the service, but they allow GigNet to improve its offers and maintain the commercial relationship. The Data Subject may object to them without affecting the provision of the service:
3.3. Mechanism to object to secondary purposes.
If the Data Subject does not wish their data to be processed for the indicated secondary purposes, they may express their refusal at any time by sending an email to privacidad@gignetmexico.com, indicating “Refusal of secondary purposes” in the subject line. This refusal shall not be a reason to suspend or limit the contracted services.
4. Personal Data Transfers.
In compliance with Article 35 of the LFPDPPP, GigNet may transfer personal data to domestic or foreign third parties. In all cases, the receiving third party assumes the same obligations that correspond to the Data Controller who transferred the data. The transfers made by GigNet are detailed below:
| Recipient | Purpose | Consent Required |
|---|---|---|
| HubSpot, Inc. (USA) | Contact management and delivery of service and marketing communications | No (Art. 36, sec. IV and VII LFPDPPP) |
| Mailchimp / Intuit Inc. (USA) | Management of promotional and service emails | No (Art. 36, sec. IV and VII LFPDPPP) |
| Constant Contact, Inc. (USA) | Delivery of newsletters and mass communications | No (Art. 36, sec. IV and VII LFPDPPP) |
| Federal and local authorities | Compliance with legal obligations, judicial mandates, or administrative requests | No (Art. 36, sec. I and V LFPDPPP) |
| GigNet S.A. de C.V.; Sanalto Redes Peninsular, S.A.P.I. de C.V.; and affiliated, holding, or subsidiary companies involved in providing the service | Coordinated network operation, provision of connectivity services, technical support, billing, and user service within the areas where each entity operates infrastructure | No (Art. 36, sec. III LFPDPPP) |
| Network infrastructure providers | Technical operation of the network and provision of the contracted service | No (Art. 36, sec. VII LFPDPPP) |
The transfers identified in the table above fall within the assumptions of Article 36 of the LFPDPPP that do not require the consent of the Data Subject. Any additional transfer subject to consent will be informed to the Data Subject prior to being carried out.
For the purposes of this Notice, the group entities that participate in the provision of the services are: GigNet S.A. de C.V. (Data Controller), Sanalto Redes Peninsular, S.A.P.I. de C.V., and other affiliated or holding companies that operate under the same internal processes and policies, under the terms of Article 36, fraction III of the LFPDPPP. These entities operate under data protection standards equivalent to those established in this Notice and assume the same obligations as the Data Controller regarding the data they receive.
The Data Subject may object to transfers that depend on their consent through the procedure described in Section 6 of this Notice. Likewise, the Data Subject has the right to exercise their ARCO rights directly before the third-party recipients, under the terms of their respective privacy notices.
5.Use of Cookies, Web Beacons, and Similar Technologies.
The Website and the App use cookies, web beacons, and similar technologies (hereinafter “Cookies”) to improve the Data Subject’s experience and fulfill the purposes described in this Notice. Through these technologies, the following information can be collected:
Type of device, browser, and operating system used.
Pages visited before and after the Website.
Links followed and duration of stay.
IP address and browsing statistics.
In the App: device identifiers (IDFA/GAID) and usage statistics.
Types of Cookies used:
Necessary cookies: essential for the basic operation of the Website and the App. They cannot be deactivated.
Functionality cookies: remember the Data Subject’s preferences to improve their experience.
Analysis and performance cookies: allow measuring the use of the service and improving its performance.
Advertising and targeting cookies: record preferences to show relevant content.
The Data Subject can manage or disable cookies from their browser settings or, in the case of the App, from the device settings. Disabling necessary cookies may affect the functionality of the service. For more information, consult the guides for each browser:
Google Chrome: https://support.google.com/chrome/answer/95647
Mozilla Firefox: https://support.mozilla.org/es/kb/habilitar-y-deshabilitar-cookies
Apple Safari: https://support.apple.com/es-mx/guide/safari/sfri11471/mac
Microsoft Edge: https://support.microsoft.com/es-es/microsoft-edge/eliminar-las-cookies-en-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09
For cookie management on mobile devices, consult the privacy options in Settings > Privacy of your iOS or Android device.
6. ARCO Rights and Revocation of Consent.
In accordance with Articles 21 to 34 of the LFPDPPP, the Data Subject has the right to Access, Rectify, Cancel, or Oppose (“ARCO Rights”) the processing of their personal data, as well as to revoke the consent granted for its processing.
Access: to know what personal data GigNet possesses and the conditions of its processing.
Rectification: to request the correction of inaccurate, incomplete, or outdated data.
Cancellation: to request the deletion of your data. This will result in a blocking period prior to its definitive elimination, in accordance with Article 24 of the LFPDPPP.
Opposition: to object to the processing of your data for legitimate reasons or when used for direct marketing purposes.
Revocation of consent: to withdraw the consent granted at any time, without retroactive effects.
The Data Subject or their legal representative may submit their request through any of the following means:
Email: privacidad@gignetmexico.com (with the subject line “ARCO Request”)
In writing: addressed to the Personal Data Department at the address indicated in Section 1 of this Notice.
Full name of the Data Subject and address or means of contact to receive the response.
Document proving the identity of the Data Subject (valid official identification). In case of legal representation, a public instrument or a simple power of attorney signed before two witnesses.
Clear and precise description of the personal data regarding which the right is exercised.
Indication of the right wished to be exercised (Access, Rectification, Cancellation, or Opposition) or a statement of revocation of consent.
For rectification requests: documentation supporting the requested modifications.
Any other element that facilitates the location of the personal data.
6.4 Response times. GigNet will communicate the decision adopted to the Data Subject within a maximum period of 20 business days from the receipt of the request. If the request is appropriate, it will become effective within 15 business days following the communication of the response. Both terms may be extended only once for an equal period when circumstances justify it (Art. 31 LFPDPPP).
6.5 Gratuity. The exercise of ARCO Rights is free of charge (Art. 34 LFPDPPP). Only costs for reproduction, copies, or shipping may be charged. If the Data Subject provides the magnetic or electronic medium to reproduce the data, it will be delivered at no cost. In the case of repeated requests within a period of less than twelve months, the cost shall not exceed three times the current Unit of Measure and Update (UMA).
6.6 Grounds for inadmissibility. GigNet may deny the exercise of ARCO Rights only under the assumptions of Article 33 of the LFPDPPP, including: when the applicant is not duly accredited; when the data is not in the possession of the Data Controller; when the rights of third parties are injured; or when there is a legal impediment or a resolution from a competent authority. The denial may be partial.
7. Options to Limit the Use or Disclosure of Your Data.
In addition to exercising ARCO Rights, the Data Subject has the following mechanisms:
8. Security Measures.
GigNet has implemented administrative, technical, and physical security measures in accordance with Article 18 of the LFPDPPP, in order to protect personal data against loss, theft, unauthorized use, alteration, or destruction. These measures include access controls, encryption of data in transit and at rest, and confidentiality commitments from personnel.
In the event of a security breach that could significantly affect the asset or moral rights of the Data Subject, GigNet will notify them immediately in accordance with Article 19 of the LFPDPPP.
9. Retention of Personal Data.
Personal data will be retained for the time necessary to fulfill the purposes for which they were collected and, in any case, for the period established by applicable law. Upon conclusion of the legal relationship with the Data Subject, the data will be blocked and subsequently deleted, unless they must be kept by legal provision or for the exercise of rights and fulfillment of obligations.
Depending on the nature and purpose of each category of data, GigNet applies the following retention periods:
Contract data and contractual documentation: during the term of the contractual relationship and for an additional period of 10 years from its termination, in compliance with the Law on Telecommunications and Broadcasting and applicable tax legislation.
Identification data and vouchers (INE, CURP, RFC, proof of address): during the term of the contract and for 5 additional years after its termination, unless otherwise required by law.
Billing data and financial records: for 10 years in accordance with Article 30 of the Fiscal Code of the Federation.
Video surveillance records: maximum 30 calendar days, unless required by a competent authority or an ongoing investigation.
Usage, navigation, and App metrics data: for the duration of the active service and up to 2 additional years for anonymous statistical analysis.
Telecommunications traffic data (session records, network logs): for 2 years in accordance with the obligations of the Law on Telecommunications and Broadcasting.
Data related to non-compliance with contractual obligations will be deleted 72 months after the date of the non-compliance, in accordance with Article 10 of the LFPDPPP.
10. Changes to the Privacy Notice.
GigNet reserves the right to update or modify this Privacy Notice at any time, in response to legislative changes, modifications in its data processing practices, or new requirements for the provision of its services.
Updates will be available on the Website in the “Privacy Notice” section (www.gignet.mx/nosotros/aviso-privacidad/) and in the App. In the event that the changes affect processing activities based on the consent of the Data Subject, GigNet will collect a new consent when legally necessary. The Data Subject is recommended to review this Notice periodically.
11. Supervisory Authority.
In the event that the Data Subject considers that GigNet has violated their right to the protection of personal data, they may file a complaint or report with the Secretariat of Anti-Corruption and Good Government, the competent authority for personal data in the possession of private parties under the current LFPDPPP. For more information: www.anticorrupcion.gob.mx.
Likewise, in its capacity as a marketing company and/or concessionaire of telecommunications services, GigNet is subject to regulation by the Telecommunications Regulatory Commission, the Digital Transformation and Telecommunications Agency, or their equivalent. For matters related to service quality or users’ minimum rights, the Data Subject may visit: https://www.gob.mx/crt.
12. Consent.
By providing their personal data to GigNet, whether through the Website, the App, in person, by telephone, or by any other means, and having this Privacy Notice made available to them, the Data Subject states that they have read and understood its terms and grant their tacit consent for the processing of their personal data for the primary purposes described herein, under the terms of Article 7 of the LFPDPPP.
For the processing of financial or asset data, as well as for secondary purposes that require it, GigNet will obtain the express consent of the Data Subject in accordance with Articles 7 and 8 of the LFPDPPP.
13. Digital Risks.
The Data Subject is requested to verify at all times that they provide their personal data solely through GigNet’s official service channels. Always verify that the website is www.gignet.mx. In case of doubt, contact us via email at privacidad@gignetmexico.com or by phone at +52 (998) 690 0610. GigNet will not request passwords, bank details, or sensitive information via unsolicited emails or text messages.
Update date: June 2026
Stay up to update with our latest news and products.
We solve your connectivity problems by becoming your trusted partner. We are proven experts at what we do, with extensive international experience as a premier service provider.
We solve your connectivity problems by becoming your trusted partner. We are proven experts at what we do, with extensive international experience as a premier service provider.