PRIVACY NOTICE FOR CLIENTS – MEXICO
DATA PROTECTION UNDER FEDERAL DATA PROTECTION HELD BY PRIVATE PARTIES ACT (THE “ACT”)
To run our business, New Earth Sanctuary (“NES”) processes information about individuals (“Personal Data”), including information about our current, former and prospective clients (“you”).
NES takes your privacy seriously.
NEWEARTH SANCTUARY S.A. DE C.V. (jointly and severally, hereinafter, “NES”, “we”, “our”, or “us”) is located at Bacalar, Quintana Roo, Republic of Mexico hereby provides you with this privacy notice (the “Notice”) the purpose of which is to notify you of what data we may collect and how it is processed and stored, what your rights are and how to exercise those rights.
This notice applies to any and all information that relates to an identified or identifiable natural person, that could be considered as (i) Simple Personal Data, (ii) Financial Personal Data, and/or (iii) Sensitive Personal Data (together or individually hereinafter referred to as “Personal Data”).
With regards to “Client” and/or “Prospect” the meaning of such terms means an individual that was, is, or may be a Client and/or Prospect, or was, is or may be an individual that NES provides or will provide services to.
Table of Contents
What does this Notice cover?
This Notice applies to any and all forms of use (“processing”) of Personal Data by us in Mexico if you are a former, current, or prospective client of any of NES.
What types of Personal Data do we collect?
For prospective clients with whom we have not yet made contact, we may collect (to the extent permitted by applicable law):
- personal identification details (such as name, address, gender, nationality), contact information (such as telephone number, e-mail address), and family details (such as marital status);
- information related to professional profile (such as directorship / positions and professional networks) and information related to company ownership and financial background.
For former and current clients or prospective clients with whom we are taking steps to enter into a contractual relationship, we collect (to the extent permitted by applicable law):
- personal details such as your name, identification numbers such as Citizen Number (CURP) and Federal Taxpayer Number (RFC), date of birth, KYC documents (including a copy of your national identity card or passport, source of wealth), phone number, physical and electronic address, and family details such as the name of your spouse, partner, or children;
- financial information, including payment and transaction records and information relating to your assets (including fixed properties), financial statements, liabilities, taxes, revenues, earnings, and investments (including your investment objectives);
- tax domicile and other tax-related documents and information;
- where relevant, professional information about you, such as your job title and work experience;
- your knowledge of and experience in investment matters;
- details of our interactions with you and the products and services you use, including electronic interactions across various channels such as e-mails and mobile applications;
- any records of phone calls between you and NES; specifically, phone log information such as your phone number, calling-party number, receiving-party number, forwarding numbers, time and date of calls and messages, duration of calls, routing information, and types of calls;
- identifiers we assign to you, such as your client, business relation, partner, or account number, including identifiers for accounting purposes;
- when you access NES websites or our applications, data transmitted by your browser or device you are using and automatically recorded by our server, including date and time of the access, name of the accessed file as well as the transmitted data volume and the performance of the access, your device, your web browser, browser language and requesting domain, and IP address (additional data will only be recorded via our Website if their disclosure is made voluntarily, e.g., in the course of a registration or request). When you visit a NES website, that website will contain additional information about how we use your information while you are visiting that website; and
- in some cases (where permitted by law), sensitive Personal Data, such as your political opinions or affiliations, and, to the extent legally possible, information relating to criminal convictions or offenses. NES will, as defined in the Act, request your written and express consent to do so.
We may use cookies, tracking technologies and other means (e.g., web beacons, pixels, gifs, tags, unique identifiers) to collect and process the above information from different channels, including email, and devices that you use to interact with us.
For our usage of cookies and other tracking technologies in relation to NES websites please also refer to the NES Website Usage and Cookie Notice available at:
https://newearthbacalar.cloud/cookies-policy
We may use Personal Data for analytics and measurement (incl. machine learning) to process the above information, including profiling based on the processing of your Personal Data, for instance by looking at information we obtain via cookies and tracking technologies.
The above-mentioned Personal Data mentioned are collected from:
- Information that you directly provide;
- Information that NES receives from the entities that are part of the Corporate Group of the Client and/or Prospect;
- Information that NES may receive from third parties such as past services providers.
- Information NES may collect from public registers (which, depending on the product or service you receive and the country of the NES entity with which you have a contractual relationship, may include beneficial ownership and other registers), public administration or other third-party sources, such as wealth screening services, credit reference agencies, fraud prevention agencies, intermediaries that facilitate data portability, and other NES Group entities.
If relevant to the products and services we provide to you, we will also collect information about your related investors or account holders, business partners (including other shareholders or beneficial owners), dependents or family members, representatives, and agents.
Where you are an institutional or corporate client or investor, we may also collect information about your directors, representatives, employees or shareholders or beneficial owner. Before providing NES with this information, you should provide a copy of this Notice to those individuals.
For which purposes do we process Personal Data?
- Client Onboarding.
For example: to verify your identity and assess your application. For legal and regulatory compliance checks (for example, to comply with anti-money laundering regulations, and prevent fraud), please see Section e) below.
- Client Relationship Management.
For example: to manage our relationship with you, including communicating with you in relation to the products and services you obtain from us and from our business partners, handling customer service-related queries and complaints, facilitating debt recovery activities, making decisions regarding credit or your identity, tracing your whereabouts, and closing your account (in accordance with applicable law) if it remains dormant and we are unable to contact you after a period of time;
To help us to learn more about you as a client, your preferences on the products and services you receive, and other products and services – including those offered by us, NES Group entities, and our business partners – you may be interested in receiving, including profiling based on the processing of your Personal Data, for instance by looking at the types of applications, platforms, products and services that you use from us, information we obtain via tracking technology and how you like to be contacted;
To collect and analyze your individualized and personal or anonymous and group-based activity and potential interests in the use of our products and services, of NES websites, our applications for mobile devices and NES platforms, multimedia portals and social networks.
- Product implementation and execution.
For example: to provide products and services to you and ensuring their proper execution, for instance by ensuring that we can identify you and make payments to and from your accounts in accordance with your instructions;
- Engaging in prospecting and business development and / or protecting and enhancing the NES brand.
For example: to evaluate whether and how NES may offer products, services and events – including those offered by us, NES Group entities, and our other business partners – that may be of interest to you;
To contact you for direct marketing purposes about products and services we think will be of interest to you, including those offered by us, NES Group entities, and our other business partners, and facilitating competitions and promotions.
- Compliance and Risk Management and / or Crime Prevention, Detection and Investigation.
For example: to carry out legal and regulatory compliance checks as part of the onboarding process, including to comply with anti-money laundering regulations and fraud prevention;
To meet our on-going regulatory and compliance obligations (e.g., anti-money laundering and tax laws), including in relation to recording and monitoring communications, apply a risk classification to ongoing business relationships, disclosures to tax authorities, regulators and other judicial and governmental bodies or in proceedings and investigating or preventing crime;
To receive and handle complaints, requests or reports from you or third parties made to designated units within NES or the NES Group;
To reply to any actual or potential proceedings, requests or the inquiries of a public or judicial authority;
To prevent and detect crime, including fraud or criminal activity, misuses of our products or services as well as the security of our IT systems, architecture and networks.
- Supporting, Enhancing and Maintaining NES’s technology.
For example: to take steps to improve our products and services and our use of technology, including testing and upgrading of systems and processes, implementing investor portal and community networks and conducting market research to understand how to improve of our existing products and services or learn about other products and services we can provide including but not limited to use digital currencies and platforms;
To analyze the results of our marketing activities to measure their effectiveness and relevance of our campaigns.
- Other purposes.
For example: for the NES Group’s prudent operational management (including credit and risk management, technological support services, reporting, insurance, audit, systems and products training and administrative purposes);
To collect data to ensure the security of buildings, the safety of staff and visitors, as well as property and information located, stored on or accessible from the premises, to prevent, and if necessary, investigate unauthorized access to secure premises (e.g., maintaining building access logs and CCTV system images to prevent, detect and investigate a theft of equipment or asset owned by NES, visitor or staff, or threats to the safety of personnel working at the office);
To undertake transactional and statistical analysis, and related research; or to exercise our duties and/or rights vis-à-vis you or third parties.
In case you do not want your data to be processed for direct marketing purposes, please let us know by contacting us as indicated in Section 7 below.
How do we protect Personal Data?
All NES employees accessing Personal Data must comply with our internal rules and processes in relation to the processing of your Personal Data to protect them and ensure their confidentiality.
NES and and companies in our Group have also implemented adequate technical and organizational measures to protect your Personal Data against unauthorized, accidental, or unlawful destruction, loss, alteration, misuse, disclosure, or access and against all other unlawful forms of processing.
Who has access to Personal Data and with whom are they shared?
5.1 Within the NES Group
We usually share Personal Data with other companies of the group to which we belong (the “NES Group”) for NES’ Corporate Management, to ensure a consistently high service standard across our group, and to provide services and products to you. Other companies of the NES Group may process your Personal Data on behalf and upon request of NES.
5.2 Outside NES and the NES Group
5.2.1 Third Parties
We share Personal Data with financial services institutions and comparable institutions and to our professional advisers and consultants to perform the business relationship with you. In particular, when providing products and services to you, we may share personal data with persons acting on your behalf or otherwise involved (depending on the type of product or service you receive from NES).
5.2.2 Service Providers
In some instances, we may also share Personal Data with our suppliers, who are contractually bound to confidentiality, such as IT and hosting providers, marketing providers, communication services and printing providers, debt collection, tracing, debt recovery, fraud prevention, lawyers and others. When we do so we take steps to ensure they meet our data security standards, so that your Personal Data remains secure.
Where NES transfers your data to service providers processing data on NES behalf, we take steps to ensure they meet our data security standards, so that your Personal Data remains secure
5.2.3 Public or regulatory authorities
If required from time to time, we disclose Personal Data to public authorities, regulators, governmental bodies, or courts or parties to proceedings where we are required to disclose information by applicable law or regulation, under a code of practice or conduct, at their request, or to safeguard our legitimate interests.
5.2.4 Others
• A potential buyer, transferee, merger partner or seller and their advisers in connection with an actual or potential transfer or merger of part or all of NES’s business or assets, or any associated rights or interests, or to acquire a business or enter into a merger with it;
• Any legitimate recipient required by applicable laws or regulations.
5.3 Data transfers to other countries
NES gives notice that to comply with the purposes set out in Section 3, NES may transfer Personal Data to third parties, in the understanding that these are obliged to maintain the confidentiality of the provided Personal Data and comply with the terms and conditions of the Notice. NES may transfer the collected Personal Data to NES´ national or foreign entities or subsidiaries, which share internal policies and processes for the proper corporate management. Furthermore, if any such third parties are located inside or outside Mexico, to the extent that we require your consent for any such transfer, we understand that by the terms of this Notice that we have obtained your implied consent absent any specific withdrawal of such consent by you, as indicated in Section 11 below.
How long do we store your data?
NES will only retain Personal Data for as long as necessary to fulfill the purpose for which it was collected or to comply with legal, regulatory, or internal policy requirements.
To help us do this, we apply criteria to determine the appropriate periods for retaining your Personal Data depending on its purpose.
In general, although there may be limited exceptions, data is kept for the time period defined in the NES Records Retention Schedule.
As far as necessary, we will keep your data for the duration of our banking relationship subject to applicable legal and regulatory requirements. In addition, we might process your data after the termination of our banking relationship for compliance or risk management purposes in accordance with the applicable laws as well as pursuant to various retention and documentation obligations or if it is in NES’ legitimate interest.
However, if you wish to have your Personal Data removed from our databases, you can make a request as described in Section 7 below, which we will review as set out therein.
What are your rights and how can you exercise them?
7.1 Your rights (ARCO rights)
You have a right to access and to obtain information regarding your Personal Data that we process. If you believe that any information we hold about you is inaccurate or incomplete, you may also request the rectification of your Personal Data.
You also have the right to:
• object to the processing of your Personal Data;
• cancel your Personal Data.
Cancellation of personal data will lead to a blocking period following which the data will be erased. The data controller may retain data exclusively for purposes pertaining to responsibilities arising from processing. The blocking period will be equal to the limitation period for actions arising from the legal relationship governing processing pursuant to applicable law.
When Personal Data is processed for direct marketing purposes, your right to object extends to direct marketing. You may object to direct marketing revoking your consent granted to us by emailing us at the address indicated in Section 7.2 at any time containing a request to be registered in the “Advertising Exclusion List”, in order not to receive promotional information about our products and services.
NES will process all “ARCO rights” requests, as required under applicable data protection rules but these rights are not absolute: they do not always apply, and exemptions may be engaged.
In order to process your request we will require you to verify your identity and/or provide information that helps us to understand your request better.
If we cannot comply with your request, we will explain why.
7.2 Exercising your rights
If you or your legal representative would like to exercise any of the above-mentioned ARCO rights, please send an e- mail to:
Operations@newearthbacalar.com
Mentioning your name, address or any other means to communicate the response to your request and the purpose of such request, specifying which ARCO Right established in the Act do you want to exercise.
Upon receipt of such request, NES will consider it in accordance with the Act, its Regulations and the internal privacy policies of NES and shall respond to your request within a period of twenty (20) business days from receipt.
If you are not satisfied with how NES processes your Personal Data, we would like to discuss it with you to understand how we can rectify the issue.
If you would like to speak to us about our use of your Personal Data, you can contact us by emailing operations@newearthbacalar.com or by using the contact details that can be found at: www.newearthbacalar.com.
Changes to your Personal Data
We are committed to keeping your Personal Data accurate and up to date. Therefore, if your Personal Data changes or you would like to make any amendment to the information please inform us of the change as soon as possible.
Updates to this Notice
This Notice was issued in October 2023.
We reserve the right to amend it from time to time. Any amendment or update to this Notice we will make available to you at www.newearthbacalar.com
Please visit the NES website frequently to understand the current Notice, as the terms of this Notice are closely related to you.
Consent
By providing you with this Notice, you are deemed to consent to the treatment of your Personal Data by NES as described in this Notice unless you provide an express objection, by sending an email to operations@newearthbacalar.com
Your consent applies to your Personal Data, whether the consent is provided as a result of this Notice; personally, or through any third party; or through any other electronic, optic, sound, audio visual means, or through any other technology or means available to NES. It shall not be necessary to obtain an express consent for processing the Personal Data if it is aimed at performing the obligations arising from a legal relationship between you and NES, or in respect of the events referred to in Article 10 of the Act.
All of this is without prejudice to your right to exercise the ARCO Rights (as set out in clause 7.1 above) upon the terms of the Act, and to exercise any right through the communication process established in this Notice.
By providing any third-party Personal Data to NES, you further confirm that you have provided the Third Party with a copy of this Notice and have obtained their consent to any handling of their Personal Data by NES.