Privacy notice
Privacy notice
En esta página
- FUDI Rewards
- Information About the Data Controller
- 1. Scope of this Notice and Data Processing Roles
- 1.1 Restaurant Personnel Data (operators and administrators)
- 1.2 End User Data (diners)
- 1.3 Additional notice consultation
- 2. Personal Data We Collect
- 2.1 Identification and Contact
- 2.2 Account and Authentication
- 2.3 Loyalty Program Relationship
- 2.4 Billing and Collection (applicable to Restaurants)
- 2.5 Technical and Usage Data
- 2.6 Sensitive Personal Data
- 3. Purposes of Personal Data Processing
- 3.1 Primary Purposes (Necessary)
- 3.2 Secondary Purposes (Optional)
- 3.3 Statement of refusal for secondary purposes
- 4. Personal Data Transfers
- 4.1 General principle
- 4.2 Transfers for service operation
- 4.3 Consent for transfers
- 4.4 International transfers
- 5. ARCO Rights and Consent Revocation
- 5.1 Your rights
- 5.2 Procedure to exercise ARCO rights
- 5.3 Response timelines
- 5.4 Special consideration for end users (diners)
- 6. Limitation of Use or Disclosure of Data
- 6.1 Right to limit use
- 6.2 Limitation mechanisms
- 6.3 Effects of limitation
- 7. Use of Cookies and Tracking Technologies
- 7.1 What are cookies
- 7.2 Types of cookies we use
- 7.3 Similar technologies
- 7.4 Cookie control
- 7.5 Third-party cookies
- 8. Data Security and Retention
- 8.1 Implemented security measures
- 8.2 Security limitations
- 8.3 Data retention
- 8.4 Data deletion or dissociation
- 9. Changes to Privacy Notice
- 9.1 Right to update
- 9.2 Publication of changes
- 9.3 Notification of substantial changes
- 9.4 Acceptance of changes
- 10. Data Protection Authority and Complaint Procedures
- 10.1 Competent authority
- 10.2 Rights protection procedure
- 10.3 Direct attention with FUDI
- 11. Consent and Acceptance
- 11.1 Forms of consent
- 11.2 Implications of platform use
- 11.3 Additional information before granting consent
- 11.4 Right not to grant consent
- 12. Contact and Inquiries
Privacy Notice
FUDI Rewards
Last Updated: February 10, 2026
This Comprehensive Privacy Notice is issued in compliance with the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), its Regulations, and other applicable provisions in the United Mexican States.
Information About the Data Controller
- Legal Name: Padmit, S.A.P.I. de C.V. (hereinafter "FUDI")
- Address: Bosque de Jacarandas 117, Portales de la Arboleda, León, Guanajuato, México, C.P. 37100
Privacy Contact:
- Officer: Jaime Vaqueiro
- Email: privacidad@padmit.com
1. Scope of this Notice and Data Processing Roles
FUDI offers its clients (restaurants and affiliated businesses, hereinafter "Restaurants") a technology platform to operate loyalty programs, manage user communications, and generate reports.
Depending on the type of user and interaction with the Platform, personal data processing is performed under the following legal frameworks:
1.1 Restaurant Personnel Data (operators and administrators)
FUDI acts as Data Controller for personal data related to:
- Account creation and management
- Authentication and platform access
- Technical support
- Billing and payment collection
- General platform operation
1.2 End User Data (diners)
The Restaurant is the Data Controller for personal data of its diners for the purposes of its loyalty program.
FUDI acts as Data Processor, processing data solely on behalf of and under the Restaurant's instructions according to the platform's technical specifications.
1.3 Additional notice consultation
If you have questions about the processing of your data as an end user (diner), we recommend also consulting the privacy notice of the Restaurant with which you interact.
2. Personal Data We Collect
Depending on user type, interaction channel, and features used, FUDI may collect the following categories of personal data:
2.1 Identification and Contact
- Full name
- Email address
- Phone number
- Messaging identifiers (e.g., WhatsApp number) when the user voluntarily provides or authorizes their use
2.2 Account and Authentication
- Access credentials (username and password)
- Session tokens
- Access and activity logs
- Verification information (e.g., OTP or one-time codes)
2.3 Loyalty Program Relationship
- Membership number
- Program progress
- Accumulated points or registered visits
- Unlocked rewards
- Redemption history
- Loyalty transactions with associated metadata (date, time, branch, transaction number)
2.4 Billing and Collection (applicable to Restaurants)
- Business name or trade name
- Federal Taxpayer Registry (RFC)
- Tax address
- Administrative and financial contact information
- Payment and billing-related data
Important: FUDI does not store complete credit or debit card data. Payment processing is performed through certified specialized providers.
2.5 Technical and Usage Data
- IP address
- Device type and operating system
- Web browser and version
- Cookie identifiers or similar technologies
- Usage and diagnostic events
- Performance metrics
These data are used to ensure platform security and improve user experience.
2.6 Sensitive Personal Data
FUDI does not request or require sensitive personal data (racial or ethnic origin, health status, genetic information, religious, philosophical and moral beliefs, union membership, political opinions, sexual preference) as a general rule.
In case a Restaurant configures additional fields that could capture sensitive data, or the user provides them voluntarily:
- Processing will be subject to the responsible Restaurant's privacy notice
- They will be processed only according to specific instructions issued by the Restaurant
- Enhanced security measures will be applied
3. Purposes of Personal Data Processing
Personal data processing purposes are classified as primary (necessary for service provision) and secondary (additional and optional).
3.1 Primary Purposes (Necessary)
These purposes are essential for the existence, maintenance, and fulfillment of the legal relationship between you and FUDI. Refusal to process data for these purposes will prevent service provision.
a) Account management and authentication
- Create and manage Restaurant and authorized personnel accounts
- Authenticate platform access
- Verify user identity
- Prevent fraud, identity theft, and unauthorized access
b) Loyalty program operation
- Register member enrollment in loyalty programs
- Accumulate visits, points, or progress according to program rules
- Unlock rewards when requirements are met
- Process redemptions and exchanges
- Generate tickets, confirmations, and transaction receipts
c) Operational communications
- Send registration or program enrollment confirmations
- Notify accumulation and redemption transactions
- Send verification codes (OTP)
- Communicate important changes in the service or loyalty program
- Respond to support requests
These communications are sent exclusively through channels enabled by the user or Restaurant (email, WhatsApp, or others).
d) Support and customer service
- Address help requests, technical incidents, and questions
- Resolve service-related issues
- Manage complaints
- Follow up on user requests
e) Compliance with legal and contractual obligations
- Comply with applicable Mexican legislation
- Manage billing and collection from Restaurants
- Administer subscriptions and renewals
- Maintain accounting and tax records
f) Security, audit, and service quality
- Maintain platform security and integrity
- Monitor security events
- Execute internal and external audits
- Implement quality controls
- Ensure service continuity
3.2 Secondary Purposes (Optional)
These purposes are not necessary for main service provision but allow us to improve your experience. You may refuse processing of your data for these purposes at any time.
a) Informational and promotional communications
- Send information about service improvements
- Notify about new features or functionalities
- Share educational content related to loyalty programs
- Send special promotions or campaigns
These communications will be sent only:
- When express consent or user opt-in exists
- Complying with channel rules (e.g., WhatsApp Business policies)
- Including unsubscribe or cancellation mechanisms
b) Analysis and continuous improvement
- Create aggregated usage statistics
- Analyze trends and behavior patterns
- Improve user experience
- Develop new functionalities
When technically possible, these analyses are performed with aggregated, anonymized, or dissociated data.
3.3 Statement of refusal for secondary purposes
If you do not want your personal data processed for secondary purposes, you may express this through:
- Communication to the privacy contact indicated in this notice
- Use of unsubscribe mechanisms included in communications (when available)
- Account preference settings (if applicable)
4. Personal Data Transfers
4.1 General principle
FUDI does not sell, commercialize, rent, or transfer personal data to third parties for commercial purposes.
4.2 Transfers for service operation
Transfers we make are necessary for platform operation and are normally performed under the Processor framework (providers who process data on behalf of FUDI or the Restaurant, under specific instructions and confidentiality obligations).
Provider categories:
a) Technology infrastructure
- Web hosting and cloud storage services
- Data backup and recovery providers
- Performance monitoring and analysis services
- Content delivery networks (CDN)
b) Communications
- WhatsApp Business Platform (when user and/or Restaurant enable this channel)
- Transactional email services
- Push notification providers
- SMS messaging platforms (if applicable)
c) Authentication and security
- Two-factor authentication services (when available)
- OTP code generation and delivery
- Security analysis services
d) Billing and payments (applicable to Restaurants)
- PCI-DSS certified payment processors
- Electronic invoicing platforms
- Bank reconciliation services
4.3 Consent for transfers
In legally applicable cases, we will obtain your express consent for transfers not covered by LFPDPPP exceptions (Article 37).
4.4 International transfers
Some of our providers may be located abroad. In these cases:
- We ensure the destination country offers adequate protection level
- We implement contractual data protection clauses
- We apply additional security measures
5. ARCO Rights and Consent Revocation
5.1 Your rights
As a personal data subject, you have the right to:
A - Access your personal data held by FUDI R - Rectify your data when inaccurate or incomplete C - Cancel your data when you consider it unnecessary for purposes stated in this notice, being used for non-consented purposes, or the legal relationship has ended O - Object to processing of your data for specific purposes
Additionally, you have the right to revoke your consent for personal data processing at any time.
5.2 Procedure to exercise ARCO rights
To exercise any ARCO rights or revoke your consent, send a written request to the privacy contact indicated in this notice, including:
Request requirements:
- Full name of data subject and contact method to communicate the response (email, postal address, or phone)
- Verification documents: Copy of valid official identification (voter ID, passport, professional license). In case of legal representation: power of attorney signed before two witnesses or notarized power, plus representative's identification.
- Clear and precise description of: Personal data for which you seek to exercise a right. Right you wish to exercise (access, rectification, cancellation, or objection). For rectification: indicate modifications to make and provide supporting documentation
- Additional elements facilitating data location: Registered phone number. Associated email. Account or membership number (if applicable). Approximate dates of platform interaction
5.3 Response timelines
FUDI will respond to your request within LFPDPPP established timelines:
- 20 business days from request receipt date
- This period may be extended for 20 additional business days when warranted, informing you of extension reasons
5.4 Special consideration for end users (diners)
If you are an end user (diner) and your request refers to a specific Restaurant's loyalty program:
- FUDI may channel your request to the Restaurant responsible for such data
- Or request that you submit your request directly to the corresponding Restaurant
- In these cases, we will provide you with the Restaurant's contact information
6. Limitation of Use or Disclosure of Data
6.1 Right to limit use
In addition to ARCO rights, you may request that we limit the use or disclosure of your personal data, especially for secondary purposes.
6.2 Limitation mechanisms
You may exercise this right through:
a) Formal request Send communication to privacy contact clearly indicating which purposes you wish to limit.
b) Communication cancellation mechanisms In communications sent by email or WhatsApp, you may use:
- "Unsubscribe" or "opt-out" links
- Specific commands (e.g., send "STOP" or "UNSUBSCRIBE")
- Reply indicating your desire not to receive more communications
c) Account settings If the platform offers privacy settings or communication preferences, you may modify them directly from your account.
6.3 Effects of limitation
Limitation will take effect within 5 business days following receipt of your request or use of the corresponding mechanism, unless certain information must be retained by legal provision.
7. Use of Cookies and Tracking Technologies
7.1 What are cookies
Cookies are small text files stored on your device when you visit our website or use our platform. They allow recognition of your browser and remembering certain preferences.
7.2 Types of cookies we use
Essential cookies (necessary) Indispensable for basic platform functioning:
- Session authentication
- Security and fraud prevention
- Load balancing
Functional cookies Enhance user experience:
- Remember language preferences
- Save interface settings
- Remember form information
Analytics cookies Help us understand how the platform is used:
- Usage and navigation metrics
- Most visited pages
- Dwell time
- Error identification
7.3 Similar technologies
We may also use:
- Web beacons (tracking pixels): Small transparent images allowing us to know if an email was opened or page visited
- Local storage: Local browser storage for saving preferences
- Device identifiers: To recognize the device in subsequent uses
7.4 Cookie control
Management from your browser:
You can disable, block, or delete cookies from your browser settings:
- Chrome: Settings > Privacy and security > Cookies
- Firefox: Preferences > Privacy and security
- Safari: Preferences > Privacy
- Edge: Settings > Privacy, search and services
Warning: Disabling cookies may affect certain platform functionalities, including inability to log in or maintain preferences.
7.5 Third-party cookies
Some services integrated into our platform may set their own cookies (e.g., map services, embedded videos, or third-party analytics tools). We recommend consulting these services' privacy policies.
8. Data Security and Retention
8.1 Implemented security measures
FUDI implements administrative, technical, and physical security measures to protect your personal data against:
- Damage, loss, or alteration
- Accidental or unlawful destruction
- Unauthorized access, use, or processing
- Improper disclosure
Technical measures:
- Encryption of data in transit (HTTPS/TLS)
- Encryption of data at rest for sensitive information
- Firewalls and intrusion detection systems
- Role-based access controls
- Continuous security monitoring
- Periodic penetration testing
Administrative measures:
- Information security policies
- Personnel training on data protection
- Confidentiality agreements with employees and providers
- Incident management procedures
- Regular internal audits
Physical measures:
- Data centers with physical access controls
- Video surveillance systems
- Backups in geographically distributed locations
8.2 Security limitations
Despite our efforts, no security system is infallible. FUDI cannot guarantee absolute data security but commits to:
- Promptly notify any security breach
- Take immediate corrective measures
- Cooperate with authorities when necessary
8.3 Data retention
Temporal limitation principle:
FUDI will retain your personal data only for the time:
- Necessary to fulfill purposes described in this notice
- Required by legal, tax, or contractual obligations
- Relevant for defense of possible claims
General retention periods:
- Restaurant personnel data: While commercial relationship exists and up to 5 years thereafter for tax compliance
- End user (diner) data: According to responsible Restaurant's instructions, typically while user maintains active membership and up to 2 years after last activity
- Access and security logs: Up to 1 year for security analysis
- Tax and accounting information: According to periods established by Mexican legislation (minimum 5 years)
8.4 Data deletion or dissociation
Once retention periods have elapsed:
- Data will be securely deleted (permanent erasure, media destruction)
- Or dissociated/anonymized irreversibly when technically possible, allowing use for statistical purposes without identifying individuals
9. Changes to Privacy Notice
9.1 Right to update
FUDI reserves the right to update this Privacy Notice at any time to reflect:
- Changes in Mexican legislation or applicable regulations
- New data processing practices
- Platform or service modifications
- Data protection authority recommendations
- Security measure improvements
9.2 Publication of changes
Modifications to this notice will be available at:
- Website: https://fudirewards.com/privacy/
- Customer portal: Accessible from platform
- Current version: Always identified with last update date
9.3 Notification of substantial changes
When changes are substantial (affecting purposes, transfers, or rights), FUDI will notify through:
- Email to registered address
- Prominent message when logging into platform
- WhatsApp communication (when user has authorized it)
- Website notice
9.4 Acceptance of changes
Continued use of the platform after publication of changes constitutes acceptance of the updated Privacy Notice.
If you disagree with modifications, you may:
- Exercise your ARCO rights before they take effect
- Cancel your account or membership
- Revoke your consent
10. Data Protection Authority and Complaint Procedures
10.1 Competent authority
If you believe your personal data protection right has been violated by FUDI, you may approach the:
National Institute for Transparency, Access to Information and Personal Data Protection (INAI)
- Website: https://home.inai.org.mx/
- Phone: 800 835 4324 (toll-free from anywhere in Mexico)
- Address: Insurgentes Sur 3211, Colonia Insurgentes Cuicuilco, Coyoacán Borough, ZIP 04530, Mexico City
10.2 Rights protection procedure
INAI has an ARCO rights protection procedure (Articles 49 to 53 of LFPDPPP) when:
- The controller does not respond to your request within established timelines
- The response is unsatisfactory
- You consider the response incomplete or did not address your request
10.3 Direct attention with FUDI
Before approaching INAI, we invite you to:
- Contact our privacy department directly
- Present your complaint informally
- Allow us to resolve your situation quickly and directly
FUDI commits to:
- Address any complaint or question related to data protection
- Provide clear and complete responses
- Implement corrective measures when necessary
- Maintain transparent communication with data subjects
11. Consent and Acceptance
11.1 Forms of consent
Consent for processing your personal data may be expressed in the following ways:
a) Tacit consent For primary purposes, understood as granted through:
- Platform use
- Voluntary provision of personal data
- Absence of contrary statement
b) Express consent For secondary purposes or specific cases, collected through:
- Acceptance of checkboxes at registration
- Email confirmation
- Active opt-in in WhatsApp communications
- Document signatures when applicable
c) Express written consent For sensitive data (if requested), through:
- Physically signed forms
- Advanced electronic signature
- Documentation with acknowledgment of receipt
11.2 Implications of platform use
Simple platform use and/or provision of personal data implies:
- You have read and understood this Privacy Notice
- You accept the terms and conditions established herein
- You consent to processing described for primary purposes
11.3 Additional information before granting consent
Before providing your personal data or using the platform, we recommend:
- Carefully read this Privacy Notice
- Consult the Restaurant's Privacy Notice (end users)
- Review the platform's Terms and Conditions of use
- Contact us if you have questions or require clarifications
11.4 Right not to grant consent
You have the right to not grant your consent for processing your data. However, you should consider that:
- Refusal for primary purposes will prevent service provision
- Refusal for secondary purposes will not affect main service
12. Contact and Inquiries
For any questions, comments, requests, or exercise of rights related to this Privacy Notice, you may contact us through:
Privacy Department
Email: privacidad@padmit.com
Address: Bosque de Jacarandas 117, Portales de la Arboleda, León, Guanajuato, México. 37100.
Service hours: Monday to Friday from 9:00 AM to 6:00 PM (Central Mexico time)
Response time: We commit to responding to your general inquiries within 5 business days following receipt.
Last update date: February 10, 2026
Version: 1.0
This Privacy Notice complies with requirements established in Articles 15 and 16 of the Federal Law on Protection of Personal Data Held by Private Parties and its Regulations.