Courtesy translation. This is an English translation provided for convenience. The official, legally binding text is the Spanish-language Privacy Notice. In case of any discrepancy, the Spanish version prevails.
Privacy Notice
Last updated: April 20, 2026
TsCancun, operator of iAudita and EFOSGratis.com, is responsible for the processing of your personal data in accordance with the provisions of Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations.
This Privacy Notice describes how we collect, use, protect, and retain your personal information on our tax audit and management platform.
1. Data Controller
TsCancun, with address at Av. Chapultepec #417 A PH, Col. Juárez, Mexico City, C.P. 06000, Mexico, is responsible for the processing of your personal data.
For any matter related to the privacy of your data, you may contact us at:
- Email: [email protected]
- Phone: +52 55 8526 5021
2. Personal Data We Collect
For the purposes described in this notice, we collect the following categories of information:
2.1 Identification and Contact Data
- Full name or company name (Razón Social)
- Email address (for system access and notifications)
- Phone number / WhatsApp (verification and notifications)
- Federal Taxpayer Registry (RFC)
- Tax domicile
2.2 Tax and Financial Data
- CIEC (Confidential Electronic Identification Key)
- Advanced Electronic Signature files (e.firma/FIEL): .cer certificate and .key private key
- Digital Seal Certificate (CSD) files
- Private key passwords (stored with AES-256 encryption)
- Digital Tax Receipts via Internet (CFDIs) issued and received
- Metadata of downloaded CFDIs
- Tax returns and Compliance Opinion (Opinión de Cumplimiento)
2.3 Technical and Usage Data
For security, fraud prevention, and service improvement purposes, the following are automatically recorded:
- IP address and device type (User-Agent)
- Browser type and operating system
- Access logs and actions performed (audit trails)
- Essential cookies and session tokens (see Section 9)
2.4 Data Received from Identity Providers
If you choose to sign in through an external provider (Google, Microsoft), we receive only: name, email address, profile picture, and the provider's unique identifier. The flow is one-way: from the provider to us.
2.5 Device and File Permissions
For proper operation, we may require access to:
- File storage: for uploading .XML, .PDF, .CER, and .KEY files
- Camera (optional): scanning QR codes on certificates or invoices
We do not collect sensitive personal data as defined in Article 3, section VI of the LFPDPPP (racial origin, health status, religious beliefs, sexual orientation, political opinions, etc.). The tax data processed is considered financial and operational.
3. Purposes of Processing
3.1 Primary Purposes (Essential)
- Authentication and secure access to the platform
- Verification of the user's identity
- Automated connection with SAT servers to download XMLs
- Processing and delivery of your tax receipts
- Analysis, audit, and reconciliation of tax information
- Generation of tax reports and validation against blacklists (EFOS/EDOS)
- Electronic invoicing and stamping (timbrado) (on plans that include it)
- Communication about the status of downloads and system notifications
- Detection and prevention of fraudulent or abusive use
- Technical support and customer service
- Compliance with legal and regulatory obligations
3.2 Secondary Purposes (Optional)
- Sending newsletters about tax updates
- Information about complementary services and system improvements
- Anonymous statistical analysis to improve platform performance
You may object to the secondary purposes by sending an email to [email protected], without affecting the provision of the main service.
4. Protection of Your Tax Credentials
4.1 Differentiated Use of FIEL vs CSD
We clearly distinguish the use of each type of credential:
- e.firma (FIEL): used exclusively to authenticate before the SAT and submit bulk download requests for metadata and XMLs, query the Tax Mailbox (Buzón Tributario), and obtain the Compliance Opinion. We never issue invoices or sign legal acts with your e.firma.
- CSD (Digital Seal Certificate): used only in the electronic invoicing module for stamping CFDIs that the User chooses to issue from the platform, always under express instruction.
4.2 Secure Storage
Recurring Synchronization Protocol: To ensure the integrity of your accounting, our engine makes automatic requests to the SAT WebService every 12 hours, keeping the metadata and XMLs (issued, received, and canceled) up to date without manual intervention.
Encryption at Rest (At-Rest): The e.firma files, CIEC, and passwords are stored under AES-256 encryption, the same level used by financial institutions. The decryption key is managed in isolation, ensuring that the data is only accessible by the automated download process.
No Plaintext Persistence: At no point in the data lifecycle are credentials stored or transmitted in plaintext. The entire chain of custody operates under end-to-end encryption.
- There is no human interaction with your credentials
- No employee has access to your credentials in plaintext
- You may request the deletion of your stored credentials at any time from Settings → Certificates
4.3 Clause on e.firma (FIEL) and CSD
Express Consent (Art. 9 LFPDPPP): By uploading your FIEL/CSD files via the confirmation checkbox in the upload module, the User grants express consent for their processing in accordance with the limited use described above.
LIMITATION OF LIABILITY: TsCancun does NOT use your e.firma to sign contracts, file unauthorized returns, issue CFDIs in your name without express instruction, or carry out any procedures other than those described.
The User retains at all times ownership of and legal responsibility for the use of their tax credentials. TsCancun does not share, assign, or transfer these sensitive files to unauthorized third parties.
5. Data Transfers
Your personal data may be transferred to the following entities:
5.1 Institutional Transfers
- Tax Administration Service (SAT): due to the nature of the service
- Authorized Certification Providers (PAC): for stamping invoices
- Competent authorities: in legally provided cases
5.2 Infrastructure Providers (Data Processors)
To operate the service we use providers contractually bound by confidentiality clauses:
- Cloudflare, Inc. (USA) — DDoS protection, CDN, WAF
- SMTP2GO Ltd. (New Zealand/USA) — delivery of email notifications
- Stripe Inc. (USA) — payment processing (we do not store full card data, only tokens)
- Google LLC and Microsoft Corp. (USA) — optional OAuth authentication
These transfers may involve sending data to servers located outside Mexico. All providers comply with international security standards (SOC 2, ISO 27001, or equivalents).
5.3 Third-Party Applications Authorized by the User
When you explicitly authorize an external application (e.g., AI assistants such as Anthropic's Claude or OpenAI) via our API/MCP protocol, the queried data is transmitted to that application's servers. You may revoke access at any time.
We do not sell, rent, or share your information with third parties for advertising purposes.
6. Security Measures
We implement administrative, technical, and physical measures to protect your information:
- AES-256 encryption for credentials and sensitive data (at rest)
- TLS 1.2+ with 256-bit encryption in all communications
- Passwords hashed with SHA-256 + Argon2ID
- Security monitoring and intrusion detection
- Automatic jails against malicious scanning
- Restricted access to authorized personnel under confidentiality agreements
- Backup and recovery protocols
Breach notification (Art. 20 LFPDPPP): In the event of a security breach that significantly affects the User's financial or moral rights, we will notify you by email within a period of no more than 72 hours from its detection, detailing the nature of the incident, the data compromised, corrective actions, and recommendations.
7. Data Retention and Account Termination
We retain your personal information for as long as you maintain an active account on the platform.
30-day download window:
When you cancel your subscription or remove a company (RFC) from the platform, we retain your data for a period of 30 calendar days, during which we send a secure download link to the registered email address containing all the information associated with your account (CFDIs, reports, uploaded files, certificates, logs, etc.).
After 30 days have elapsed without you downloading the information, all data is permanently and irrecoverably deleted from our servers.
Note: The obligation to retain accounting information for 5-10 years under Art. 30 of the CFF rests with the taxpayer, not TsCancun. We are solely a supporting technological tool.
8. ARCO Rights
In accordance with the LFPDPPP, you have the right to:
- Access the personal data we hold about you
- Rectify incorrect or incomplete information
- Cancel the processing of your data
- Object to the use of your data for specific purposes
8.1 Procedure to Exercise Your Rights (Art. 29 LFPDPPP)
Send your request to [email protected] indicating:
- Full name and RFC
- A clear and precise description of your request
- Valid official identification (INE/passport) of the data subject or notarized power of attorney of the legal representative
- Email address to receive the response
Response timelines (Art. 32 LFPDPPP):
- We will respond on the admissibility of the request within a maximum of 20 business days
- If admissible, it will take effect within the following 15 business days
- The timelines may be extended once for an equal period when circumstances justify it
Appeal before INAI: If you believe your ARCO rights have not been satisfactorily addressed, you may file a complaint with the National Institute for Transparency, Access to Information and Protection of Personal Data (INAI): www.inai.org.mx.
9. Use of Cookies and Tracking Technologies
9.1 Authenticated Application
Within the secure area we use essential cookies only:
- Security (CSRF): prevent Cross-Site Request Forgery attacks
- Authentication: session cookies and JWT Tokens
- Preferences: local settings (dark mode, filters, etc.)
9.2 Public Site (landing and marketing pages)
On the public pages we use third-party analytics tools to measure visits and optimize content:
- Google Analytics 4 (Google LLC) — aggregated metrics
- Microsoft Clarity (Microsoft Corp.) — heatmaps and anonymous session recordings
- Meta Pixel (Meta Platforms) — advertising campaign attribution
- reCAPTCHA v3 (Google LLC) — anti-fraud protection on forms
These tools are only activated after your explicit consent via the cookie banner. No tax data is shared with them.
No advertising tracking in the app: within the authenticated area we do not use advertising tracking cookies. Only essential cookies.
10. Changes to the Privacy Notice
We reserve the right to modify this notice at any time. Changes will be published on this page with the corresponding update date.
For substantial changes that affect the processing of your data, we will notify registered users via email at least 15 days in advance of its entry into force.
11. Contact — Privacy Department
In accordance with Article 30 of the LFPDPPP, TsCancun has designated a Privacy Department responsible for handling ARCO requests:
TsCancun (iAudita / EFOSGratis.com)
Privacy Department
Av. Chapultepec #417 A PH, Col. Juárez
Mexico City, C.P. 06000, Mexico
Email: [email protected]
Phone: +52 55 8526 5021
Last updated: April 20, 2026 · Version 2.0
By using our services, you accept the terms of this Privacy Notice.