Scientific & Clinical Governance

Privacy Policy

CELLMEX is committed to responsible stewardship of personal, clinical, scientific and research information. This policy explains how personal data may be collected, used, protected, shared and retained across our website and related activities.

Policy AreaPrivacy & Data Governance
DocumentCM-PRV-001
Version1.0
Section 01

Purpose

This Privacy Policy explains how CELLMEX collects, uses, stores, protects, shares and otherwise processes personal data obtained through the CELLMEX website, patient and physician enquiries, clinical services, research activities, laboratory interactions and related professional communications.

CELLMEX recognises privacy as an essential component of patient trust, ethical research and responsible clinical governance. Personal data should be processed lawfully, fairly, transparently and only for defined and legitimate purposes.

This policy is intended to function as CELLMEX's integral website privacy notice. Additional or specialised privacy notices may be provided for particular clinical, research, employment, donor, investigator or contractual activities where required.
Section 02

Scope

This policy applies to personal data processed by CELLMEX in connection with its website, digital communications, patient coordination, physician referrals, clinical evaluation, laboratory and scientific activities, research programmes, professional collaborations and administrative operations.

It may apply to patients and prospective patients, donors, research participants, physicians, investigators, collaborators, website visitors, suppliers, contractors and other individuals who interact with CELLMEX.

Section 03

Identity of the Data Controller

For purposes of personal-data processing covered by this policy, the responsible organisation is CELLMEX / Stem Cell Medical Clinic, Marina Vallarta, Puerto Vallarta, Jalisco, Mexico.

Questions concerning this notice, personal-data handling or privacy rights may be directed to info@cellmex.com or by telephone at +52 322 308 0021.

Where a specific clinical, research or contractual activity is conducted through another identified legal entity, collaborator or institution, the corresponding activity-specific notice or agreement may identify that entity as an independent or joint controller, as applicable.

Section 04

Applicable Privacy Framework

CELLMEX processes personal data in accordance with applicable Mexican law and other privacy or data-protection requirements that may apply to a particular activity or individual.

For private-sector processing in Mexico, the principal framework includes the Ley Federal de Protección de Datos Personales en Posesión de los Particulares and applicable implementing provisions. Where services, research or communications involve another jurisdiction, additional requirements may apply.

References to international privacy standards in this policy do not mean that every foreign privacy law applies to every CELLMEX activity.

Section 05

Privacy and Data-Protection Principles

Lawfulness & Transparency

Personal data should be collected and used under an appropriate legal basis and with meaningful notice to the individual.

Purpose Limitation

Information should be used for defined purposes and not repurposed incompatibly without appropriate justification or notice.

Data Minimisation

CELLMEX seeks to collect information reasonably necessary for the relevant clinical, scientific, operational or legal purpose.

Security & Confidentiality

Personal data should be protected against unauthorised access, loss, alteration, misuse or disclosure through proportionate safeguards.

Section 06

Personal Data We May Collect

Depending on the nature of the interaction, CELLMEX may collect:

  • Name, date of birth, age, sex, nationality and contact details;
  • Identity and travel-document information where relevant to international patient coordination;
  • Address and geographic information voluntarily supplied for care or logistics;
  • Physician, clinic, hospital or professional-affiliation details;
  • Appointment, enquiry, referral and communication history;
  • Billing, invoicing and transaction-related information;
  • Website technical information such as IP address, browser type, device information and basic usage data;
  • Other information voluntarily submitted through forms, email, telephone or secure communication channels.
Section 07

Sensitive Personal Data and Health Information

Clinical, genetic, biometric and health-related information may constitute sensitive personal data and requires heightened protection.

Where relevant to patient care, research or laboratory activity, CELLMEX may process information concerning diagnosis, medical history, medications, allergies, imaging, laboratory results, prior treatments, physician notes, biological specimens, cellular or tissue information, genetic or genomic data and treatment follow-up.

CELLMEX seeks to limit processing of sensitive data to what is reasonably necessary for the identified purpose and to obtain express consent where required by applicable law.

Section 08

Sources of Personal Data

Personal data may be obtained directly from the individual, from an authorised representative, referring physician, clinic or hospital, from research or laboratory collaborators, from service providers acting under instruction, or from other lawful sources.

Where information is received from a third party, CELLMEX expects that the disclosure has an appropriate legal, professional or consent basis.

Section 09

Primary Purposes of Processing

CELLMEX may process personal data for primary purposes including:

  • Responding to enquiries and evaluating requests for information;
  • Patient intake, clinical assessment, medical coordination and physician review;
  • Scheduling and communicating regarding appointments or services;
  • Obtaining, reviewing and maintaining medical records;
  • Laboratory, specimen and quality-related activities;
  • Research screening and ethically authorised research activities;
  • Safety monitoring and adverse-event follow-up;
  • Billing, accounting, payment administration and fraud prevention;
  • Regulatory, legal, quality and compliance obligations;
  • Maintaining clinical, research and administrative records;
  • Protecting the safety, integrity and security of CELLMEX systems, personnel and facilities.
Section 10

Secondary and Optional Purposes

Where permitted and subject to applicable consent or opt-out requirements, CELLMEX may use contact information for professional updates, educational material, invitations to scientific events, service information, patient-experience communications or other non-essential communications.

Individuals may request that their data not be used for optional communications without affecting necessary clinical, administrative or legal processing.

Section 12

Clinical Records and Medical Confidentiality

Medical information is treated as confidential and should be accessed only by personnel or authorised parties who require it for legitimate clinical, scientific, quality, administrative or legal purposes.

Clinical records may be retained for periods required by medical-record, professional, regulatory, research, contractual or legal obligations. Privacy rights do not require CELLMEX to destroy records that must lawfully be preserved.

Section 13

Research Data

Where CELLMEX conducts or participates in human-subject research, privacy protections operate together with the CELLMEX Research Ethics & Human Subjects Policy.

Research data may be coded, pseudonymised or de-identified where scientifically appropriate. Access should be limited according to protocol, role and applicable ethical or regulatory requirements.

Research participants may receive an additional study-specific consent form and privacy notice describing the particular data uses, retention, sharing, specimen handling and publication arrangements for that project.

Section 14

Biological Specimens and Donor Materials

Biological specimens may contain or be linked to personal and sensitive information. CELLMEX therefore treats specimen identifiers, donor records, chain-of-custody information and associated clinical data as protected information.

Specimen processing, storage, transfer and research use should remain consistent with applicable consent, ethics approval, laboratory controls, contractual restrictions and law.

Section 15

Genetic and Genomic Data

Genetic and genomic information can be uniquely identifying and may reveal information about biological relatives. CELLMEX applies heightened caution to such data.

Where relevant, consent and governance arrangements should address the purpose of analysis, data security, future research use, sharing, incidental findings, clinically actionable findings and realistic re-identification risks.

Section 16

Children and Individuals Requiring Representation

CELLMEX does not knowingly seek unnecessary personal information from children through the general website.

When information concerning a minor or a person lacking legal capacity is required for clinical care or authorised research, it should be obtained and processed through a parent, guardian or other legally authorised representative, with additional protections where required.

Section 17

Website Technologies, Cookies and Analytics

The CELLMEX website may use essential cookies and similar technologies necessary for security, functionality, session management and basic site operation. It may also use analytics or preference technologies to understand website performance and improve user experience.

Where required, optional cookies should be subject to appropriate consent or preference controls. CELLMEX does not intend to use health information submitted through patient or clinical forms for behavioural advertising.

Browser settings may permit users to block or delete cookies, although disabling essential technologies may affect website functionality.

Section 18

Website Forms, Email and Electronic Communications

Information submitted through website forms, ordinary email, messaging platforms or telephone communications may be stored as part of the relevant enquiry, patient, research or administrative record.

Individuals should avoid transmitting unnecessary sensitive medical information through unsecured channels. Where CELLMEX provides a designated secure method for clinical records or sensitive documents, that method should be used when practicable.

Section 19

Artificial Intelligence and Automated Processing

CELLMEX may use software-assisted tools, including artificial intelligence, for limited administrative, organisational, analytical, documentation or research-support functions.

Material clinical decisions should not be based solely on unverified automated output. Where sensitive information is processed by an external technology provider, CELLMEX should consider confidentiality, contractual controls, security and the necessity of the data involved.

Section 20

Disclosure and Sharing of Personal Data

Personal data may be disclosed where reasonably necessary to authorised physicians, laboratories, hospitals, research collaborators, ethics or regulatory bodies, service providers, professional advisers, insurers, logistics providers or other parties involved in an authorised activity.

CELLMEX seeks to limit disclosures to information reasonably necessary for the relevant purpose and to use confidentiality, contractual or legal safeguards where appropriate.

Section 21

Domestic and International Data Transfers

CELLMEX serves international patients and may collaborate with physicians, laboratories, institutions and service providers outside Mexico. Personal data may therefore be transferred across borders where necessary for authorised clinical, research, laboratory, logistics or administrative purposes.

Transfers should be made in accordance with applicable privacy law, consent requirements, contractual safeguards and professional confidentiality obligations. A transfer to another jurisdiction may result in information being subject to that jurisdiction's laws.

Section 22

Service Providers and Data Processors

CELLMEX may engage technology, hosting, communications, payment, laboratory, record-management, logistics or professional service providers that process data on its behalf.

Where appropriate, providers should be subject to contractual obligations addressing confidentiality, security, permitted processing and return or deletion of data.

Section 23

Information Security

CELLMEX seeks to maintain administrative, technical and physical safeguards proportionate to the sensitivity and nature of the information processed.

Safeguards may include role-based access, password controls, encryption, secure storage, access logging, confidentiality requirements, staff training, controlled backups, device security, physical restrictions and incident-response procedures.

No information system can be guaranteed to be completely secure. CELLMEX therefore combines preventive controls with monitoring, response and corrective action.
Section 24

Security Incidents and Data Breaches

Suspected loss, unauthorised access, alteration, disclosure or destruction of personal data should be promptly evaluated under CELLMEX incident-response procedures.

Where a security breach materially affects an individual's rights or interests, CELLMEX will provide notification and take other action as required by applicable law. Notifications may include information reasonably necessary for affected individuals to protect themselves.

Section 25

Data Retention and Disposal

Personal data should not be retained indefinitely without a legitimate purpose. Retention periods depend on the nature of the record and may be determined by medical, research, tax, contractual, regulatory, quality, litigation or professional requirements.

When information is no longer required and no lawful retention obligation applies, CELLMEX may securely delete, destroy, anonymise or otherwise dispose of it using methods appropriate to the medium and sensitivity involved.

Section 26

ARCO Rights

Subject to applicable Mexican law, individuals may exercise rights of Access, Rectification, Cancellation and Opposition (ARCO) regarding their personal data.

  • Access: request information about personal data held and its processing;
  • Rectification: request correction of inaccurate or incomplete information;
  • Cancellation: request deletion or blocking where legally appropriate;
  • Opposition: object to certain processing where the legal requirements are met.

The exercise of one ARCO right does not necessarily depend upon exercising another first.

Section 27

How to Exercise Privacy Rights

Requests concerning ARCO rights, withdrawal of consent or limitation of use or disclosure may be submitted to info@cellmex.com.

A request should provide sufficient information to verify identity, identify the relevant records and describe the right being exercised. Where a representative acts for an individual, CELLMEX may request documentation establishing authority.

CELLMEX may deny or limit a request where permitted or required by law, including where records must be retained, another person's rights would be affected, or the request conflicts with legal or regulatory obligations.

Section 28

Limiting Use or Disclosure

Individuals may request limitation of non-essential uses or disclosures of their personal data, particularly optional promotional or informational communications.

Such limitations may not apply to processing necessary for medical care, patient safety, contractual performance, research integrity, legal compliance, quality obligations, security or defence of legal rights.

Section 30

Individuals Outside Mexico

Persons interacting with CELLMEX from outside Mexico may have additional rights under the law of their jurisdiction where that law applies to the particular processing activity.

CELLMEX will evaluate such requests according to the applicable legal framework, the location and nature of the processing, and the relationship between the individual and CELLMEX.

Section 31

Changes to This Privacy Policy

CELLMEX may revise this policy to reflect changes in law, technology, services, research activities, security practices or organisational requirements.

Material changes will be communicated through the website or another appropriate channel. The current version and document identifier displayed on this page indicate the governing website version.

Section 32

Privacy Contact

Questions, requests or concerns regarding privacy or personal-data processing may be directed to:

CELLMEX
Privacy & Data Governance
Marina Vallarta
Puerto Vallarta, Jalisco, Mexico

Email: info@cellmex.com
Telephone: +52 322 308 0021

Privacy Notice

This website policy is intended to provide transparent information concerning CELLMEX personal-data practices. Specific clinical, research, donor, employment or contractual activities may require additional privacy notices, consents or data-processing terms.

Document ID: CM-PRV-001  |  Version 1.0  |  Privacy & Data Governance