We protect your information

Privacy Notice

Learn how we collect, use, and protect the personal information you share with Oasix.

A. Data Controller

A.1. Identity of the controller. The processing of personal data collected through oasix.com.mx, as well as by other electronic or physical means, corresponds to GREATDEN S.A. DE C.V. (hereinafter, "OASIX" or the "Controller").

A.2. Address. Av. Río Consulado Cto Interior 516, Oficina 102, Col. Tlatilco, Alcaldía Azcapotzalco, C.P. 02860, Mexico City.

A.3. Contact methods. For privacy and personal data: atencion@oasix.com.mx.

B. Data Subjects

B.1. Subjective scope. Applies to any natural person whose data is processed by OASIX.

B.2. Included groups (enunciative). Clients, prospects, site visitors, commercial allies (company contacts), suppliers and their representatives, job candidates, and attendees to events/experiences.

B.3. Collection. Anyone who provides data via web forms, mail, messaging, calls, contracts, cards, QR, event check-in, or direct communication is considered a Data Subject.

C. Categories of data we may collect

  • C.1. Identification: full name, age/date of birth, nationality, gender, CURP/RFC (if applicable), handwritten/electronic signature.
  • C.2. Contact: address, emails, phone numbers (incl. work/personal WhatsApp).
  • C.3. Tax/Billing: corporate name, RFC, tax address, CFDI/CFDI usage.
  • C.4. Preferences and service: language, number of companions, dietary restrictions, accessibility, preferred schedules, logistical comments.
  • C.5. Supplier/ally relationship: contact data of representatives, powers of attorney/identification for signing (when necessary).
  • C.6. Candidates: CV, work/educational history, references, economic expectation, availability.
  • C.7. Image and voice: photographs, audio, and video captured at events and experiences (see secondary purpose).
  • C.8. Sensitive data (exceptional cases): allergies, relevant medical conditions, or mobility when indispensable for safety/adaptation of the service. They will be processed with express consent and reinforced measures.

We do not request data on religious convictions, ideology, sexual orientation, or complete financial card information.

D. Purposes of processing

D.1. Primary purposes (indispensable for the relationship):

  • Manage requests and reservations (registrations, changes, confirmations).
  • Contracting and operation of services (experiences, tours, fan zones, restaurant/bar reservations, logistics).
  • Collection and payments via secure gateways; billing and accounting verification.
  • Customer service (incidents, rescheduling, cancellations, and refunds according to policies).
  • Legal compliance (tax, commercial, safety/health, response to authorities).
  • Supplier/ally management (registration, verification, contractual administration).
  • Selection processes (for candidates).

D.2. Secondary purposes (optional):

  • Commercial communications (promotions, newsletters, surveys, invitations).
  • Analysis and metrics of site usage, preferences, and trends to improve services.
  • Use of image/voice captured at events for promotional purposes of OASIX (site, networks, materials).
  • Basic profiling (e.g., segments by preferred destination or time slot) without automated decisions that produce legal effects.

You can choose not to receive promotional communications or deny secondary purposes by writing to atencion@oasix.com.mx. The refusal does not affect the provision of primary services.

E. Lawful basis

We process data according to the LFPDPPP under: (i) consent; (ii) execution of a contract/legal relationship; (iii) legal compliance; (iv) legitimate interest (e.g., site security, improvement metrics, fraud prevention), without undermining your rights. Sensitive data is processed strictly with express consent and when strictly necessary.

F. Transfers and recipients

F.1. National/international (when applicable):

  • Service providers necessary to operate (payment gateways, hosting, CRM, email, messaging, identity verification, venues, restaurants/bars, guides, transporters, photographers, production companies).
  • Commercial allies/partners for co-execution of the contracted service or administration.
  • Administrative or judicial authorities, when there is a valid requirement or obligation.
  • Auditors/advisors (legal, accounting, tax) under a duty of confidentiality.

F.2. Processors. Some third parties act as processors (process on behalf of the Controller) under contracts with confidentiality and security clauses.

F.3. No commercialization. We do not sell your data. Outside these scenarios, any transfer will require your express consent.

G. Security measures

  • G.1. Administrative, technical, and physical controls proportional to the risk: access control, principle of least privilege, logs, training, confidentiality agreements.
  • G.2. Technological security: TLS/SSL encryption, network segmentation, password hashing, access logs, certified gateways (e.g., PCI DSS), anti-fraud monitoring.
  • G.3. Incident management: internal response procedure for breaches; notification to data subjects and authorities when legally appropriate.
  • G.4. Even with reinforced measures, no system is invulnerable; liability is limited according to the law and T&Cs.

H. Data retention

H.1. We retain data only for the time necessary for declared purposes and legal terms (tax, commercial, prescription).

H.2. Once purposes/terms are fulfilled, we proceed to secure deletion, blocking, or anonymization.

H.3. Criteria: type of data, risk, regulatory obligations, defense of rights, and operational needs.

I. ARCO rights, use limitation, and consent revocation

I.1. ARCO exercise. Send a request to atencion@oasix.com.mx with: full name and copy of identification; description of the rights to exercise (access/rectification/cancellation/opposition); data/period to locate; and means to notify the response.

I.2. Deadlines. We will respond within a maximum of 20 business days; if applicable, we will execute it within the following 15 business days.

I.3. Prevention. If information is missing, we will request it within 5 business days; you will have 10 business days to complete it.

I.4. Limitation of use/disclosure. You may request enrollment/update in our do-not-contact lists (marketing opt-out).

I.5. Revocation. You may revoke your consent for non-essential purposes; for primary purposes, revocation may make it impossible to provide/continue the service.

I.6. Alternate means. You may also exercise rights through a legal representative with sufficient powers.

J. Minors and persons with limited capacity

J.1. We do not intentionally collect data from minors under 18 without the consent of a mother/father/guardian.

J.2. If we detect registration without authorization, we will proceed to delete it.

J.3. For access to age-restricted experiences (e.g., alcohol), identification may be requested.

K. Cookies, web beacons, and similar technologies

K.1. Purpose. We use cookies and similar technologies to: (i) remember sessions/preferences (language, time zone), (ii) analytics on site use and performance, (iii) security and fraud prevention, (iv) eventually advertising and retargeting.

K.2. Types. Essential: site/checkout operation. Performance/analytics: metrics and improvements (e.g., visited pages, session time). Functional: remember user options. Advertising: show relevant ads (if enabled).

K.3. Management. You can disable them in your browser or configure preferences; disabling essential cookies may affect functionality.

K.4. "Do Not Track" signals. If your browser sends a DNT signal, we will make reasonable efforts to respect this preference according to our technical capabilities.

K.5. Third parties. Third-party analytics/ads tools (if used) operate under their own policies; we suggest reviewing them.

L. Automated decisions and profiling

L.1. We do not make automated decisions that produce significant legal effects.

L.2. We may perform basic profiling (segments by destination/schedules/frequency) to improve communications; you can object via ARCO.

M. Use of image in events/experiences

M.1. In activities organized by OASIX, we may record photo/video/voice for documentation and promotion.

M.2. Before capture for promotional purposes, we will seek to place signage or a visible clause; you may express reasonable opposition when viable without affecting operation/security.

M.3. When it concerns minors, we require the guardian's consent.

N. International transfers and hosting

N.1. Some technology providers may host or process data outside Mexico under contractual clauses and adequate safeguards.

N.2. We adopt measures to ensure that such third parties maintain equivalent security and confidentiality standards.

O. Complaints and means of defense

O.1. If you consider that your right to data protection has been violated, you may go to OASIX (atencion@oasix.com.mx).

O.2. You may also file a complaint with the INAI according to the legal deadlines and procedures.

P. Modifications to the Notice

P.1. We may modify this Notice due to legal, regulatory, contractual, technological, or operational changes.

P.2. The current version will be available at oasix.com.mx and will enter into force upon publication. We recommend reviewing it periodically.

Q. Acceptance

Q.1. By providing data, browsing the site, submitting forms, contracting, or attending events/experiences, you declare that you have read and accept this Notice.

Q.2. For secondary purposes and/or sensitive data, we will obtain your express consent.