Privacy policy

Last updated August 2026

What personal data Mabinn handles, what for, who else sees it, and how to exercise your rights over it. Written to be read, not to be endured.

Who is responsible, and in what capacity

Mabinn is a product of JOINLEAN, with address at Mérida, Yucatán, México. Anything concerning personal data — questions, requests, complaints — is handled at info@mabinn.com, which is also our designated personal data department.

Mexican law separates two roles, and we hold both — which one applies depends on whose data it is:

  • Controller, for the data of whoever contracts Mabinn and of the people who use the platform. We decide what it is used for and we answer for it.
  • Processor, for the data a business loads into Mabinn about its own customers — conversations, leads, quotes, sales. We handle it on that business's behalf and under its instructions. The controller there is the business, not us.

Why that distinction matters to you

If you wrote to a business through WhatsApp, Instagram or Messenger, the controller of that conversation is that business: it decided to talk to you, what to ask you and how long to keep it. We store it for them.

You can still write to us and we will route your request, but the last section of this notice explains that path in full.

What data we handle

Only what the service needs to work. Because Mabinn connects to messaging platforms, that includes:

  • Messages you exchange with a business through WhatsApp, Instagram or Messenger, including their text, timestamps and delivery status.
  • Your phone number, and the profile name your messaging platform shares with the business you wrote to.
  • Files you send in a conversation — images, documents, audio or video — stored so the business can read them later.
  • Contact and commercial details the business records about you: name, email, the product you asked about, appointments and quotes.
  • Technical data of anyone using the platform: sign-in records, device and browser, and IP address, kept for security.

Sensitive and financial data

We do not handle sensitive personal data — racial origin, health, religious or political beliefs, sexual preferences or anything comparable. We do not ask for it and there are no fields for it. If you send some inside a message it stays in that conversation, and you can ask for it to be deleted.

Financial data requires your express consent, which you give when you contract a plan. Card numbers are processed by the payment gateway and never stored by us: we keep the receipt, not the card.

Purposes that the service cannot run without

These are necessary to give you what you asked for, so they do not depend on separate consent:

  • Delivering your messages to the business and its replies back to you.
  • Letting the business follow up on your request and keeping the history of that conversation.
  • Sending operational notices you asked for, such as an appointment reminder or the status of a payment.
  • Billing, collecting and invoicing a contracted plan.
  • Keeping the service secure, preventing abuse, and complying with legal obligations.

Purposes you can say no to

These are additional: they improve the service but are not needed to provide it, so they depend on your consent and you can withdraw it at any time.

  • Sending you promotions, campaigns and commercial messages.
  • Inviting you to surveys or to try new features before they are released.

How to limit the use or disclosure of your data

Refusing the additional purposes does not affect the service in any way. Any of these works, and takes effect immediately:

  • Reply BAJA to any commercial WhatsApp message. The conversation stays open: you can still write whenever you need to.
  • Write to info@mabinn.com with the subject: no additional purposes.
  • If you have an account, turn off the notifications you do not want from the platform itself.
  • Ask the business you wrote to delete the conversation from its own panel.

Automated replies and automated decisions

A business may set up automatic replies that answer your first messages and ask a few questions before a person joins the conversation. A person can take over at any point, and does so as soon as the automated flow ends.

Those replies do not make decisions with legal effects on you and do not profile you: they classify the message and route it. Even so, you have the right to object to any automated processing that significantly affects you — write to us and a person will handle the case.

Who else sees your data

We do not sell your personal information and we do not share it for advertising. Two different things can happen with it, and the law treats them differently:

  • Processing on our behalf, which is not a transfer and needs no separate consent: Meta Platforms as the operator of WhatsApp, Instagram and Messenger; the infrastructure, storage and email providers that run the service under a confidentiality agreement; and the payment gateway.
  • Transfers to third parties, which we only make to the business you wrote to — the intended recipient of your message — and to authorities when a law or a court order requires it.

Your consent to those transfers

If you do not object to the transfers described above within five days of this notice being made available to you, the law understands that you consent to them. You can object at any time afterwards, at the same address, and we will stop.

Your ARCO rights, and how to exercise them

You may access your personal data, have it corrected if it is wrong, cancel it, or object to a specific use. You may also withdraw a consent you gave, which takes effect from that moment onwards.

Send your request to info@mabinn.com. So that we can act on it, the law asks that it include:

  • Your name and an address or any other means for us to reply to you.
  • A document proving your identity — or your representative's identity and authority.
  • A clear description of the data concerned, except when you are only asking for access.
  • Which of the four rights you want to exercise.
  • Anything that helps us find the data: the number you wrote from, the business you contacted, approximate dates.

What happens after you send it

We tell you our determination within twenty days of receiving the request and, where it succeeds, we make it effective within the following fifteen days. That period can be extended once by an equal term when the case justifies it, and we tell you why.

We verify identity before acting on any request, and a request missing the elements above does not start the clock until it is complete.

Exercising these rights is free. We could only charge justified shipping or reproduction costs if you ask for copies.

When a request does not proceed

The law lists the cases where we may decline a request. We explain the reason whenever one of them applies:

  • The identity or authority of whoever sends it is not properly established.
  • The data is not in our possession.
  • Acting on it would harm the rights of a third party.
  • A legal impediment or a decision of a competent authority prevents it.
  • What is being asked for was already done.

How long we keep it

Conversations and their attachments are kept while the business keeps its account active, because that history is what lets it attend you. A business may mark a conversation as no longer relevant or delete it; a deleted conversation stops appearing immediately and is permanently purged afterwards.

When an account is closed, its data is deleted within ninety days — the window a full backup rotation takes. Two things survive: invoices and payment records, which tax law requires us to keep for five years, and a security log of the deletion itself, kept for twelve months.

Security

Access credentials to messaging platforms are encrypted at rest, and traffic travels over encrypted connections. Access to customer data is limited to the members each business authorizes, and every message that arrives is verified as genuinely coming from the platform that sent it.

If a security breach significantly affects your data, we will tell you without delay so you can take your own measures.

These are reasonable measures, not a guarantee: no system is infallible. Whoever holds an account is responsible for their own credentials, and messages travel over infrastructure operated by Meta, under its terms and its own security.

Third-party platforms and sites

WhatsApp, Instagram and Messenger are operated by Meta, and the payment gateway by its own provider. What each of them does with your data on its own account is governed by its policies, not by this notice, and is outside our control.

The same applies to any site you reach from a link on ours.

Cookies

This website uses only the cookies needed to keep your session and remember your language. We do not use advertising cookies and we do not profile you across other sites.

You can delete or block them from your browser settings. If you block the session cookie you will not be able to sign in.

Changes to this notice

The version on this page is always the one in force, and its date says when it last changed. Changes that materially affect you are announced inside the product, and by email to account holders, before they take effect.

If you only wrote to a business

You have no account with us, and the controller of your conversation is the business you contacted. Ask it directly: it can correct or delete that conversation from its own panel, and it must answer you.

You can also write to info@mabinn.com telling us which business you wrote to and from which number or profile. We pass the request on to that business, which is the one that has to resolve it and answer you.

← Back to home