Skip to content
CRMEX

Privacy Notice

Last updated:

In accordance with articles 14, 15 and 16 of the Mexican Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), published in the Official Gazette on 20 March 2025, Nweb ("the Data Controller") provides this comprehensive Privacy Notice regarding the processing of your personal data, including the Google user data that CRMEX accesses when you connect Gmail.

1. Data controller

Nweb, operator of the CRMEX brand, domiciled in Mexico, is responsible for the processing of your personal data under this notice. You can reach us at crmex@nweb.cloud for any matter related to data protection. This notice covers the data of site visitors, prospects and customers, and the Gmail data CRMEX processes when a user connects their Google account. It does not cover the data you load into the CRM about your own customers (contacts, companies and deals), for which you are the controller and we act as processor.

2. Personal data we collect

We may collect identification and contact data (name, email address, phone number and country), organization details, billing data (tax ID, legal name, tax regime and tax address) and technical account data (IP address, access timestamps and activity logs). We do not collect sensitive personal data. Your card details are processed directly by the payment provider and are not stored by us. If you connect Gmail, we also process the Google user data described in sections 3 to 7.

3. Google user data we access (Gmail)

If you connect your Gmail account from CRMEX (Settings > Integrations), the application requests access via OAuth 2.0 to the Google Gmail API. With your consent, CRMEX accesses the following Google user data: (a) gmail.send, to send email from your Gmail address; (b) gmail.readonly, to sync incoming messages and match them to contacts and deals by email address; and (c) gmail.modify, to update thread state (for example, mark as read) when you reply from the CRM. The data involved includes subject, body, recipients, date, thread identifiers, attachments you attach when sending, conversation metadata, and the access and refresh tokens Google issues to keep the connection. We do not access other Google services on your account. We do not read your mail until you connect Gmail. On the Self-Hosted modality that data is processed on your own server; on the Hosted modality, on Nweb infrastructure at app.crmex.mx.

4. How we use Google user data

We use Gmail Google user data only to provide the visible email features inside CRMEX: send and reply to email from a contact or deal record, show message history on the activity timeline, periodically sync inbound mail so the team can see unreplied conversations (for example in My Day), and, if enabled in your deployment, record opens of outbound messages via a 1×1 pixel. We do not use Gmail content for advertising, profiling, resale, credit scoring, or to train artificial intelligence or machine-learning models. Use is limited to providing and improving those email features that you see in the CRMEX user interface.

5. How we share, transfer, or disclose Google user data

We do not sell, rent, or otherwise commercialize Google user data. We do not transfer it to advertising platforms, data brokers, or information resellers. On the Hosted modality, synced messages and tokens are stored in our database and in the hosting infrastructure that operates the service on our behalf; that is a disclosure to a processor, not a commercial transfer. On the Self-Hosted modality we have no access to your Gmail: the data never leaves your infrastructure. We only disclose Google data if the law requires it, if it is necessary to investigate a security abuse, or as part of a merger or sale of assets after notice and, where applicable, your consent. Members of your organization who already have CRM access may see emails linked to the contacts and deals their role allows them to see. We do not share that content with third parties outside your organization.

6. Storage, security, retention, and deletion of Google user data

Gmail OAuth tokens are stored encrypted. Traffic is encrypted in transit with TLS. On Hosted, synced messages are kept in your CRMEX account for as long as the account exists or until you delete them in the CRM; tokens are kept for as long as Gmail remains connected. You can disconnect Gmail in Settings > Integrations, or revoke access in your Google Account (Google Account > Security > Third-party access). On disconnect we delete the tokens and stop syncing. Messages already stored in the CRM remain part of your customer history until you delete them or close the account, except where law requires retention. You may request deletion of your Google user data by writing to crmex@nweb.cloud. On Self-Hosted, retention and deletion happen on your server under your control.

7. Limited Use of Google user data

CRMEX use of data obtained from Google APIs, including Gmail, complies with Google Limited Use requirements: the data is used only to provide or improve user-facing features that are prominent in the CRMEX interface; it is not transferred to third parties except to operate those features, for security, to comply with law, or in a corporate transaction with notice; Nweb personnel do not read your Gmail content unless you authorize it for a specific support case, or when required for security or by law. We do not use Google Workspace APIs to develop, improve, or train non-personalized AI or ML models. We do not use Gmail data for personalized ads, retargeting, or interest-based advertising.

8. Purposes of processing

Primary purposes, necessary for our contractual relationship and which do not require additional consent under article 9, section IV of the LFPDPPP: (a) respond to contact or quote requests, (b) create and manage your account and subscription on the Hosted modality, (c) send you operational notices about the service, incidents and changes to these documents, (d) comply with legal and tax obligations, such as issuing CFDI invoices, (e) prevent fraud and unauthorized access, and (f) provide the Gmail integration described in sections 3 to 7 when you connect it. Secondary purposes, which you may object to without affecting your account: sending you commercial communications about new features and promotions, and inviting you to satisfaction surveys. Gmail data is not used for secondary purposes.

9. Options to limit the use or disclosure of your data

You may object to processing for secondary purposes, at no cost, by writing to crmex@nweb.cloud with the subject "Limitation of use", or through the unsubscribe link at the bottom of every commercial email. Your objection will take effect within five business days and will not stop operational notices, which are essential to providing the service. To stop processing Gmail data, disconnect Gmail in the application or revoke access in your Google Account, as described in section 6.

10. Onward processing and transfers

To operate the service we rely on infrastructure, transactional email and payment processing providers that process data on our behalf and under our instructions. Under article 35 of the LFPDPPP, these communications are remisiones (disclosures to a processor) rather than transfers, and therefore do not require your consent. We do not sell, rent or otherwise commercialize your personal data. Beyond the above, we only transfer data without your consent in the cases set out in article 36, notably upon a duly grounded request from a competent authority or to defend a right in legal proceedings. Google user data is also governed by sections 5 and 7.

11. ARCO rights and withdrawal of consent

You have the right to Access, Rectify, Cancel or Object (ARCO rights) to the processing of your personal data, and to withdraw your consent at any time without retroactive effect. Send your request to crmex@nweb.cloud including, under article 28: your name and a means to communicate our response, a document evidencing your identity or your representative’s authority, a clear description of the data involved, and the right you wish to exercise. We will communicate our determination within a maximum of twenty business days and, if it is well founded, give effect to it within the following fifteen business days, under article 31; both periods may be extended once for an equal term where circumstances justify it. Exercising these rights is free of charge, except for the reproduction or shipping costs contemplated in article 34. Cancellation does not apply where data must be retained by legal mandate, such as tax records.

12. Security measures

We maintain administrative, technical and physical security measures under article 18 of the LFPDPPP: encryption in transit with TLS, encryption of Gmail OAuth tokens, access control, periodic backups and activity logging. Everyone involved in processing is bound by the duty of confidentiality set out in article 20, which survives the end of their relationship with us. On the Self-Hosted modality, the security of the infrastructure where you install the software is your responsibility.

13. Security breaches

If a security breach occurs that significantly affects your economic or moral rights, we will inform you immediately under article 19 of the LFPDPPP, describing the nature of the incident, the data involved, the recommended steps and the corrective actions taken.

14. Retention period

We retain your account data for as long as the contractual relationship is in force. On termination we block it under article 24 of the LFPDPPP for the limitation period applicable to claims arising from the agreement and then delete it, except for tax records, which are kept for five years under the Federal Tax Code. Specific retention of Gmail Google user data is described in section 6.

15. Cookies and similar technologies

This informational website does not use first-party or third-party cookies for advertising, analytics or profiling, so you will not see a cookie consent banner. We do use your browser’s local storage to remember the language you choose (key "crmex-lang") and, on your first visit to the home page, we read your browser language to suggest the matching version. That preference is stored only on your device, is never sent to our servers, and you can clear it from your browser settings. The application (app.crmex.mx) uses a strictly necessary cookie to keep your session securely signed in, which does not require prior consent.

16. Changes to this Privacy Notice

We reserve the right to update this Privacy Notice when applicable regulations, our operating model or our processing practices change, including how we use Google user data. Any modification will be published on this same page along with its corresponding update date and, where the change is material, we will notify you by email at the address registered in your account and, if the change affects the use of Google data, we will ask for new consent before using it in a new way.

17. Supervisory authority

If you believe your right to personal data protection has been infringed, you may file a data protection claim with the Secretaría Anticorrupción y Buen Gobierno, the authority that assumed these powers after the INAI was dissolved. The deadline to do so is fifteen business days following the date we communicate our response, under article 40 of the LFPDPPP.