Skip to content
Orbis Orbis
  • Home
  • Solutions
    • Social Branding
    • 360° Agency
    • Sales Performance
    • Strategy
  • Industries
    • Real Estate
    • Retail & Ecommerce
    • Tourism & Hospitality
    • Fashion & Beauty
    • Industrial
    • Legal & Accounting
    • Health & Wellness
    • Addiction Clinic
  • Services
    • Web Design
      • Web Design Agency
      • Wordpress Web Design
      • Custom Web Design
      • Corporate Web Design
      • Ecommerce Design
      • Shopify Web Design
      • Tienda Nube Web Design
      • Landing Page Design
    • Social Media Management
      • Social Media Agency
      • Community Management
      • Content Strategy
      • Social Listening & Reputation
      • Reporting & Optimization
      • Audit
    • Social Ads
      • Social Ads Agency
      • Meta / Facebook Ads
      • Instagram Ads
      • Tiktok Ads
      • Linkedin Ads
      • Pinterest Ads
      • Spotify Ads
    • Paid Media
      • Google Ads Partner Agency
      • Paid Media Agency
      • Google Display
      • Google Shopping
      • Google Search Ads
      • Google Youtube
      • Microsoft Ads
    • SEO
      • SEO Agency
      • SEO for Ecommerce
      • Local SEO
      • International SEO
      • SEO for B2B
      • AEO AI SEO
      • Link Building
    • Content Creation
      • Content Creation Agency
      • UGC Content
      • Influencers
      • Commercial Photography
      • Video Production
      • Commercial Drone Footage
    • Implementations
      • CRM Bitrix24
      • CRM Kommo
      • Siteminder
      • Automations
      • Chatbots
      • Integrations
  • Success Stories
  • Blog
  • More
    • Our Agency
    • Work Culture
    • Careers
    • Internships
  • Free Consultation
Free Consultation

Legal

Home / Privacy Notice
Privacy Notice Last updated: June 19, 2026
On this page

This Comprehensive Privacy Notice explains how Orbis processes your personal data through this website and the associated digital marketing services. The entity responsible for processing is determined by your country of residence or location at the time your data is collected, as detailed below.

1. Who is the Controller of your data?

The entity responsible for processing your personal data is determined by your country of residence or location:

If you are located in Mexico

  • Controller: Orbis Agencia de Marketing Digital, S.A.S. de C.V.
  • Address: Calzada Villa Plata 430, interior 5, Jesús María, Aguascalientes, Mexico, C.P. 20908.
  • RFC: OAM2201187A3.
  • ARCO/privacy email: hola@orbis.agency
  • Person responsible for Personal Data: Sergio Guillermo Caballero Real.
  • Applicable framework: Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) 2025.

If you are located outside Mexico

  • Controller: Orbis Agency LLC.
  • Jurisdiction of incorporation: State of Delaware, USA.
  • Address: 651 N Broad St, Suite 201, Middletown, DE 19709, New Castle County, USA.
  • Privacy email: hola@orbis.agency
  • Responsible contact (EU / United Kingdom / Brazil): Guillermo Alberto Caballero Biard — hola@orbis.agency.
  • Applicable framework: the user's local law (GDPR, UK GDPR, CCPA/CPRA, LGPD, among others).

The site determines the responsible entity according to your country (geolocation and/or your declaration) and displays the contact details of the corresponding entity. Data communications between the two Orbis group entities constitute an international transfer, described below.

2. Authority in Mexico (SABG)

With the constitutional reform of December 2024 that abolished the INAI, the powers in matters of protection of personal data held by private parties were transferred to the Secretaría Anticorrupción y Buen Gobierno (SABG), under the new Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) published in the Official Gazette of the Federation on March 20, 2025. The SABG concentrates the powers of investigation, audit, and sanction; the new framework also created the decentralized body "Transparencia para el Pueblo".

You may turn to the SABG if you consider that your rights regarding the protection of personal data have been infringed.

3. What personal data do we collect?

Through the site's forms and tools (contact form, ROI calculator, newsletter subscription) we may collect:

  • Identification and contact data: name, email address, telephone.
  • Professional / company data: company name, website, position, industry/sector and, when you contract or invoice, address and RFC.
  • Message / project data: information you voluntarily include in your inquiry or in the calculator (for example, budget, metrics, objectives).
  • Browsing and technical data: IP address, cookie identifiers, device/browser type, pages visited, and analytics metrics (see our Cookies Policy).

We do not intentionally collect sensitive data. If in any case it were required, we would inform you and, in accordance with articles 8 and 9 of the LFPDPPP, we would obtain your express, written consent. Financial or asset data, where applicable, requires express consent.

4. For what purposes do we use your data?

Necessary purposes (origin of the processing; do not require your additional consent)

  • Handle your inquiries, contact requests, and quote requests.
  • Provide and administer the contracted services and manage the contractual relationship.
  • Generate the ROI calculator results you request.
  • Comply with legal, tax, and contractual obligations.

Secondary / voluntary purposes (you may refuse without affecting the service)

  • Sending of newsletters, bulletins, content, and marketing communications.
  • Commercial prospecting and lead follow-up.
  • Profiling and segmentation for marketing purposes.
  • Analytics and improvement of our services and experience.

Don't want the secondary purposes? You can refuse now by ticking the corresponding box on the form, or at any time by writing to our privacy email. Your refusal will not be grounds for denying you the services you request.

5. Legal basis / grounds for processing

  • Mexico (LFPDPPP): implied consent for ordinary personal data (upon making this notice available to you and your not expressing objection); express for financial/asset data; express and written for sensitive data. Consent is free, specific, and informed.
  • EU/EEA and United Kingdom (GDPR / UK GDPR, art. 6): performance of a contract; consent (newsletter/marketing); legitimate interest (B2B prospecting and service improvement, subject to a prior balancing test, with your right to object); and legal obligation.
  • USA (CCPA/CPRA): opt-out model; we process data on the basis of the contractual and business relationship, respecting your exclusion rights.
  • Brazil (LGPD), Canada, Australia, etc.: consent, performance of contract, or legitimate interest as applicable.

6. Your rights

Mexico — ARCO rights and revocation

You have the right to Access, Rectify (including updating), Cancel, and Object to the processing of your data, as well as to object to automated decisions or profiling that affect you without human intervention. You may also revoke your consent and limit the use or disclosure of your data. (The LFPDPPP protects the personal data of natural persons; the data of legal entities are not subject to this law, without prejudice to the information of their contact personnel, which is personal data.)

  • How to exercise them: send your request to the privacy email indicated, identifying yourself and clearly describing the data and the right you wish to exercise.
  • Response time: up to 20 business days from receipt; if granted, it will take effect within the 15 days following the response.
  • Revocation of consent: by the same means; it will take effect for future processing, except for legal retention obligations.
  • You may turn to the SABG if you consider your rights infringed.

Users outside Mexico — rights by framework

  • GDPR / UK GDPR: access, rectification, erasure ("right to be forgotten"), restriction, portability, objection, and not to be subject to automated decisions. Response within 1 month (extendable by 2 months). Right to lodge a complaint with your authority (AEPD in Spain, CNIL in France, etc., or the ICO / Information Commission in the United Kingdom).
  • USA (CCPA/CPRA): to know, access, delete, correct, opt out of the "sale" / "sharing", and limit the use of sensitive information, without discrimination for exercising your rights; response within around 45 days. We honor the Global Privacy Control (GPC) signal.
  • Brazil (LGPD): confirmation, access, correction, anonymization/deletion, portability, information on sharing, and revocation; response within 15 days. Authority: ANPD.
  • Canada, Australia, Switzerland, South Africa, etc.: rights of access, correction, deletion/objection, and withdrawal of consent in accordance with their regulations.

7. Transfers and data communications

To operate the site and provide our services, we may share data with:

  • Between the Orbis group entities (from Orbis Agencia de Marketing Digital, S.A.S. de C.V. to Orbis Agency LLC and vice versa) for support, centralized tools, and administration. This constitutes an international transfer.
  • Processors / providers that process data on our behalf: hosting on our own DigitalOcean; CRM our own internal system and Kommo; email marketing Mailchimp; telephony Zadarma; analytics and measurement Google Analytics (GA4), Google Tag Manager, Ahrefs, Semrush; advertising and platforms Google, Meta, TikTok, LinkedIn, Pinterest, and Microsoft (Bing). These providers process the data in accordance with our instructions and the corresponding data processing agreements (DPA/SCC).

Transfer safeguards:

  • Mexico: transfers are disclosed in this notice; except for legal exceptions, they require your consent. You may express your refusal to transfers that are not necessary for the relationship. A distinction is made between transfer (to another controller) and remittance (to a processor).
  • EU/EEA: Standard Contractual Clauses (SCC, Decision (EU) 2021/914) + transfer impact assessment (TIA); or EU-US Data Privacy Framework if the importer is certified.
  • United Kingdom: IDTA or Addendum to the EU SCCs.
  • Brazil: international transfer mechanisms of the LGPD (arts. 33-36), including the ANPD Standard Contractual Clauses (CCP) approved by Resolução CD/ANPD nº 19/2024 (published on August 23, 2024). The adaptation period ended on August 23, 2025, so their incorporation into international transfer contracts is now mandatory.
  • Turkey (KVKK), Switzerland, Japan (APPI), etc.: mechanisms provided by each regulation (adequacy decision, clauses, or consent, as the case may be).

8. Data retention

  • Contact/lead data: as long as there is interest or relationship and, thereafter, for the applicable legal limitation periods, with a maximum reference period of 72 months (6 years).
  • Client data: during the contractual relationship and the tax/legal retention periods; as a general reference, up to 72 months (6 years) after the last processing, unless a different legal obligation applies.
  • Newsletter subscription: until you unsubscribe.
  • Cookie/analytics data: according to the duration indicated in the Cookies Policy.

Once the purposes and periods are concluded (general reference: 72 months), the data is securely deleted or anonymized.

9. Security measures and breaches

We implement reasonable administrative, technical, and physical security measures to protect your data against loss, misuse, or unauthorized access. In the event of a security breach that significantly affects your patrimonial or moral rights, we will notify you and notify the authority where the law requires it (LFPDPPP in Mexico; GDPR/UK GDPR, LGPD, and other frameworks for international users).

10. Cookies and tracking technologies

The site uses cookies and tracking technologies (analytics and marketing). Non-essential cookies are only activated with your prior consent where the model is opt-in. See the details, categories, and how to manage them in the Cookies Policy.

11. Minors

The site is aimed at professionals and businesses; it is not directed at minors and we do not knowingly collect their data. If we detect a minor's data without the parental consent required by applicable law, we will delete it.

12. Social media

Social media (Facebook, Instagram, X/Twitter, LinkedIn, TikTok, Pinterest, among others) are third-party platforms external to Orbis and are not under its responsibility. The information you publish or provide within those platforms is governed by the policies and responsibility of each provider and of whoever publishes it, and does not form part of the data subject to this Privacy Notice.

13. IP addresses and server activity log

The site's servers may automatically detect the IP address and domain used by the user. The IP address is assigned automatically upon connecting to the Internet and is recorded in the server activity log, which allows the subsequent processing of the data for exclusively statistical purposes (number of page impressions, visits to the services, order of visit, point of access, etc.).

14. Changes to the Privacy Notice

We may update this Notice. We will publish the version in force on the site with its date; substantial changes will be communicated through the available means (site and, where applicable, email).

15. Regional provisions

When your controller is Orbis Agency LLC, in addition to the general rules of this notice, the specific provisions of your jurisdiction apply:

Mexico

LFPDPPP 2025 (authority: SABG), LFPC/PROFECO, and the Commercial Code. Implied consent for ordinary data; ARCO + revocation with response within 20 business days; comprehensive, simplified, and short notice; security measures and breach notification. Regime of infractions and penalties in UMA: generally, from 100 to 160,000 UMA, and up to 320,000 UMA in aggravated cases; the amounts are doubled in the case of sensitive data. With the daily UMA in force in 2026 ($117.31 MXN, INEGI, as of February 1, 2026), the range is approximately equivalent to $11,731 – $37.5 M MXN. The UMA is updated annually, so the peso equivalent varies year to year.

European Union / EEA (Spain, Portugal, France, Germany, Italy, Ireland)

GDPR (EU) 2016/679 + national laws (LOPDGPD Spain, BDSG Germany, Codice Privacy Italy, Lei 58/2019 Portugal, DPA 2018 Ireland, French law). Article 6 bases; rights arts. 15-22; response within 1 month. Transfers to the USA with SCC 2021/914 + TIA or EU-US DPF. Designated responsible contact: Guillermo Alberto Caballero Biard (hola@orbis.agency).

United Kingdom

UK GDPR + DPA 2018, amended by the Data (Use and Access) Act 2025 (DUAA; Royal Assent on June 19, 2025, phased entry into force 2025-2026). The authority is the ICO (Information Commissioner's Office), which the DUAA progressively transforms into the Information Commission as the reform is implemented. Transfers via IDTA or Addendum to the SCCs. Designated responsible contact: Guillermo Alberto Caballero Biard (hola@orbis.agency).

United States

No comprehensive federal law. CCPA/CPRA (California) with CPPA regulations effective in 2026 (automated decisions, risk assessments, audits). Opt-out model, "Do Not Sell or Share" and "Limit Sensitive PI" links, recognition of GPC. Other states: Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), Oregon, Montana, etc. Email: CAN-SPAM; SMS/calls: TCPA; testimonials/reviews: FTC Endorsement Guides.

Canada

PIPEDA (Bill C-27/CPPA not passed) and Quebec Law 25 (designated privacy officer, PIAs, breach register, transfer rules). Anti-spam: CASL.

Brazil

LGPD (Lei 13.709/2018), authority ANPD. Rights with response within 15 days. ANPD Standard Contractual Clauses (Resolução 19/2024) mandatory for international transfers since August 23, 2025. Privacy and cookie notice in Portuguese; designated contact officer: Guillermo Alberto Caballero Biard (hola@orbis.agency). Consumer: CDC, Marco Civil da Internet, and Decreto 7.962/2013 (7-day right of withdrawal).

Australia and New Zealand

Australia: Privacy Act 1988 (2024 reform, phased 2025-2026): informed and unambiguous consent, restriction of pre-ticked boxes and dark patterns, transparency in automated decisions. New Zealand: Privacy Act 2020 (13 IPPs, breach notification, IPP 12 for overseas disclosures). Spam Act 2003.

South Africa

POPIA (regulator: Information Regulator). 8 conditions for lawful processing; consent via banner before deploying cookies; article 72 transfers.

Switzerland

nFADP (in force September 1, 2023), aligned with GDPR. Consent for tracking/analytics/advertising/profiling; necessary ones exempt. Switzerland maintains EU adequacy.

Turkey

KVKK (Law 6698, amended by Law 7499 of March 2024, in force June 1, 2024). The international transfer regime was restructured (Transfer Regulation in force since September 1, 2024): in addition to the data subject's explicit consent, the adequacy decision, standard clauses, binding corporate rules (BCR), and written undertaking with authorization from the authority (KVKK) were incorporated as mechanisms. Explicit consent remains a valid basis for processing; the reform expanded the transfer routes beyond consent. In the event of a data breach, notification to the authority (KVKK) must be made as soon as possible (a criterion interpreted as 72 hours) from becoming aware of it.

Japan

APPI (authority PPC). Transfer to a third party in a foreign country requires prior consent + information on the recipient country's regime. Mutual adequacy with the EU.

UAE / Dubai

Federal PDPL (Decree-Law 45/2021) and, if the operation is in the DIFC, DIFC Data Protection Law No. 5 of 2020 (amendments effective July 15, 2025), aligned with GDPR. ADGM has its own regime. The applicable zone (Federal, DIFC, or ADGM regime) depends on where the entity is established or considered to operate; by default the Federal regime (PDPL) is assumed.

Andorra and Monaco

Andorra: Llei 29/2021 (Andorra does have an EU adequacy decision). Monaco: Loi n.º 1.565 (in force since December 2024, replacing Loi 1.165/1993), aligned with the GDPR, Directive 2016/680, and Convention 108+; authority APDP. Monaco does NOT yet have an EU adequacy decision (the European Commission's review remains ongoing as of mid-2026), so transfers from the EU/EEA to Monaco require safeguards such as the SCCs.

Ecuador

Ley Orgánica de Protección de Datos Personales (LOPDP, published in 2021), aligned with the GDPR: legal bases, data subject rights, and international transfer regime. Its sanctioning regime has been in force since May 26, 2023 and the General Regulation (Decreto 904) was published in November 2023; with subsequent resolutions from the authority (2025) operationalizing technical aspects. Penalties may reach up to 1% of annual turnover. Authority: Superintendencia de Protección de Datos Personales (SPDP).

16. Simplified Privacy Notice

For forms, landing pages, and the ROI calculator, we make available the following simplified notice:

"Your personal data will be processed by Orbis Agencia de Marketing Digital, S.A.S. de C.V. (if you are in Mexico) or Orbis Agency LLC (if you are outside Mexico) to handle your request and, if you authorize it, to send you marketing communications. You may exercise your rights and learn about transfers and purposes in the Comprehensive Privacy Notice. I agree to receive marketing communications (optional)."

Questions about your data?

To exercise your rights or resolve any doubt about this Notice, write to us at hola@orbis.agency (we also assist at hola@somosorbis.com).

Phones: Aguascalientes +52 (449) 787 0001 · CDMX +52 (55) 8920 5202 · USA +1 (929) 224 5544.

Data officer (Mexico): Sergio Guillermo Caballero Real.

See also our Terms and Conditions and our Cookies Policy.

Orbis

Digital marketing agency in México. Strategy, performance and creativity that move the needle for your business.

Company
  • Orbis Agency
  • Work Culture
  • Careers
  • Internships
  • Success Stories
  • Brand Guideline
  • Contact Us
Industries
  • Real Estate
  • Retail & Ecommerce
  • Tourism & Hospitality
  • Fashion & Beauty
  • Industrial
  • Legal & Accounting
  • Health & Wellness
  • Addiction Clinic
Solutions
  • Social Branding
  • 360° Agency
  • Sales Performance
  • Strategy
Resources
  • Blog
  • Marketing Dictionary
  • ROI & ROAS Calculator
  • Affiliate Program
  • Partners Program
  • Ambassadors & Partners
México
  • AGS: +52 (449) 787 0001
  • CDMX: +52 (55) 8920 5202
  • WhatsApp
USA
  • +1 (929) 224 5544
Secure payment methods
Google Partners Bitrix24 Siteminder Kommo Zadarma Ahrefs
® Orbis Agencia de Marketing Digital S.A.S. de C.V. · © 2026
  • Terms & Conditions
  • Privacy Policy
  • Cookies
  • Cookie preferences
  • Sitemap
Select your country or region
Norteamérica
México México United States United States Canada Canada
Latinoamérica
Argentina Argentina Brasil Brasil Chile Chile Colombia Colombia Costa Rica Costa Rica Ecuador Ecuador El Salvador El Salvador Guatemala Guatemala Honduras Honduras Panamá Panamá Paraguay Paraguay Perú Perú Uruguay Uruguay
Europa
Andorra Andorra Deutschland Deutschland España España France France Ireland Ireland Italia Italia Monaco Monaco Portugal Portugal United Kingdom United Kingdom Schweiz Schweiz Türkiye Türkiye
Resto del mundo
Australia Australia الإمارات الإمارات 日本 日本 New Zealand New Zealand South Africa South Africa

No results for your search.

Book your free consultation
We use cookies 🍪

We use our own and third-party cookies for analytics and marketing. You can accept them all, reject them, or choose which ones you allow. See our Cookie Policy.

Cookie preferences

Choose which categories of cookies you want to allow. You can change this anytime from the "Cookie preferences" link in the footer.

Necessary Always active

Essential for the site to work (security, forms, preferences). They cannot be disabled.

Functional

Enable extra features such as the support chat or the CRM (e.g. Kommo). Without them, some interactive features may not be available.

Analytics

Help us understand how the site is used (e.g. Google Analytics, Metricool, Ahrefs) to improve it. Data in aggregate form.

Marketing

Allow us to show you relevant advertising and measure campaigns on and off the site (e.g. Meta, TikTok, LinkedIn, Pinterest, X).