PRIVACY AND DATA PROTECTION POLICY
1.- IDENTITY AND ADDRESS OF THE DATA CONTROLLER
In compliance with the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), its Regulation, and the INAI Guidelines, the data controller is:
Controller: Dr. Hiram Abif Espinosa Custodio
Trade name: Instituto Médico del Prado México
Address: Calle Leibnitz 20, Office 401, Colonia Anzures, Alcaldía Miguel Hidalgo, C.P. 11590, Mexico City.
Phone: +52 55 4590 9909
Contact email: info@drespinosacustodio.com
COFEPRIS Operating Notice: 2409135036X00306
2.- PERSONAL DATA COLLECTED
For the provision of medical and administrative services, the Institute may collect the following personal data:
- Identification and contact data: full name, age, phone number, email, official ID, address.
- Health-sensitive data: medical history, diagnoses, medical treatments, clinical photographs, and test results.
- Fiscal or billing data: RFC, tax address, bank details for billing or payments.
In compliance with Article 9 of the LFPDPPP, the processing of sensitive health data requires and is carried out under the user’s express written consent.
3.- PURPOSES OF PROCESSING
The collected personal data will be used for the following purposes:
a) Main purposes (necessary for the medical and contractual relationship):
- Provide specialized medical services and clinical follow-up.
- Create and maintain clinical records according to NOM-004-SSA3-2012.
- Schedule appointments, procedures, and check-ups.
- Issue invoices, manage payments, and comply with legal obligations.
- Communicate with the patient for appointment reminders and medical follow-up.
b) Secondary purposes (optional):
- Send information about treatments, promotions, or news related to the clinic.
- Conduct satisfaction surveys or service evaluations.
If you do not want your data to be used for secondary purposes, you can notify us by sending an email to info@drespinosacustodio.com. Refusal to use your data for these purposes will not affect the provision of contracted medical services.
4.- DATA TRANSFERS
The Institute does not share your personal data with third parties, except in the following cases:
- Legal obligation or request from a competent authority.
- Billing: fiscal data may be shared with an external accountant exclusively for tax purposes.
- Service providers: subcontracted laboratories or medical specialists, only to fulfill the described purposes and under confidentiality clauses.
No international transfers of personal data are carried out.
5.- LEGAL BASES AND CONSENT
The processing of your personal data is based on the following legal grounds:
- Express consent of the data subject, in accordance with Articles 8, 9, and 12 of the LFPDPPP.
- Compliance with obligations arising from the medical and contractual relationship.
- Legal obligations under the General Health Law and applicable regulations.
6.- ARCO RIGHTS AND WITHDRAWAL OF CONSENT
You have the right to Access, Rectify, Cancel, or Oppose (ARCO) the processing of your personal data, as well as to withdraw your consent at any time.
To exercise these rights, you must send a request to info@drespinosacustodio.com including:
- Full name of the data subject.
- Copy of a valid official ID.
- Clear description of the data and the right you wish to exercise.
Legal deadlines:
- Response to your request within a maximum of 20 business days.
- If applicable, the measure will be applied within the following 15 business days.
7.- WAYS TO LIMIT THE USE OR DISCLOSURE OF DATA
If you wish to limit the use or disclosure of your personal data (e.g., stop receiving promotional information), you may request it by sending an email to info@drespinosacustodio.com. The Institute will register your request in the internal exclusion list.
8.- DATA SECURITY
Instituto Médico del Prado México implements the necessary administrative, technical, and physical measures to protect personal data against damage, loss, alteration, destruction, or unauthorized access, in accordance with Article 19 of the LFPDPPP and Article 61 of its Regulation.
Access to the data is restricted only to authorized personnel who need it to fulfill the established purposes.
9.- USE OF COOKIES AND SIMILAR TECHNOLOGIES
Our website may use cookies or similar technologies to improve the user experience.
These technologies allow remembering your language preference, geographic zone, or session.
You can disable them directly from your browser settings.
For more information, please see our Cookies Notice available at: www.drespinosacustodio.com/aviso-legal-mexico/
10.- CHANGES TO THE PRIVACY POLICY
This Privacy Policy may be modified to adapt to regulatory or internal changes. Updates will be published on the official website of the Institute, indicating the date of the latest modification.
Last update: October 8, 2025
11.- DATA PROTECTION AUTHORITY
If you consider that your right to personal data protection has been violated, you may contact:
National Institute for Transparency, Access to Information and Personal Data Protection (INAI)
Website: www.inai.org.mx
Phone: 800-835-4324
12.- COMPLIANCE WITH HEALTH REGULATIONS
Instituto Médico del Prado México declares compliance with the General Health Law, its Regulation on the provision of medical care services, and NOM-004-SSA3-2012 (Clinical Records), as well as the applicable COFEPRIS provisions.
LEGAL REVIEW CLAUSE
This Privacy Policy was drafted in accordance with the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), its Regulation, the INAI Guidelines, and other applicable provisions, including those issued by COFEPRIS. It has been legally reviewed and updated as of its last revision, October 8, 2025.