Legal

Privacy Notice

How Beira Training collects, uses, shares, protects and retains your personal data, and how you can exercise your rights over it.

Last updated: August 12, 2026

1. Data Controller

Beira Training, with address in Zapopan, Jalisco, Mexico, and contact email hola@beiratraining.com, is the controller of the personal data collected through the site and the online course platform available at beiratraining.com (together, "the Platform").

This Privacy Notice is issued under the Mexican Federal Law on the Protection of Personal Data Held by Private Parties and its implementing regulations, and describes the processing we carry out as controller. Where we act on behalf of a corporate customer, the section on company staff data also applies.

2. Who This Applies To

This notice applies to: (a) visitors to the public site who browse the catalogue or submit the enquiry form for companies; (b) students with an account on the Platform, whether they purchased it themselves or received a seat from their employer; (c) people who administer a company account; and (d) anyone verifying a certificate using its folio.

3. Personal Data We Process

Depending on your relationship with us, we may process the following categories of data:

Identification and contact data

  • Full name, as it must appear on the certificate.
  • Email address and, where you provide it, phone number.
  • Password, always stored using a key derivation function (Argon2id) and readable by no one at Beira Training.
  • Profile picture, if you choose to upload one.
  • Company, job title or department, where you provide them or where your employer records them when assigning you a seat.

Training data

  • Courses and paths purchased or assigned, and the date access was granted.
  • Progress through the content, lessons completed and viewing time.
  • Answers, attempts and scores for quizzes and exams.
  • Certificates issued, with their folio, issue date and final score.

Billing and payment data

  • Tax details you provide for the issuance of your receipt.
  • Purchase history: product acquired, amount, currency and payment status.
  • Your full card details are captured and held directly within the infrastructure of the payment processor, which complies with the PCI DSS standard. Beira Training neither receives nor stores them; we only learn the outcome of the transaction and, where applicable, the last digits and the card brand.

Technical and security data

  • IP address, browser and device identifier (user agent) and the date and time of each relevant operation, recorded in an immutable audit log.
  • Session and sign-in data and, if you enable two-factor authentication, the secret required to validate it.
  • Technical video playback metrics (quality, stalls, device), which we use to diagnose playback problems.

Data from the enquiry form for companies

  • Name, company, work email, phone number and the content of your enquiry, when you request information about training for teams.

4. Sensitive Personal Data

We neither request nor process sensitive personal data: we do not ask for health data, ethnic origin, beliefs, union membership, sexual preferences or biometric data. Please do not include such data in free-text fields such as your profile, your support enquiries or the contact form.

5. What We Use Your Data For

Primary purposes

These are necessary to provide the service; without them the relationship cannot be maintained:

  • Creating and administering your account, authenticating you and protecting access.
  • Processing your purchase, charging the amount and issuing the corresponding tax receipt.
  • Granting access to the content acquired and recording your progress and results.
  • Issuing your certificates and enabling their public verification by folio.
  • Sending you operational communications: purchase confirmation, email verification, password recovery, security alerts, certificate issuance and notices about changes to the service or to these documents.
  • Handling your support requests.
  • Preventing fraud and misuse, and maintaining the audit log that provides traceability of operations.
  • Complying with legal, tax and accounting obligations.

Secondary purposes

These are not necessary for the service and you may object to them without affecting your access to what you already purchased:

  • Sending you information about new courses, paths, content and promotions.
  • Inviting you to answer satisfaction or content improvement surveys.
  • Producing aggregate statistics and usage analysis to improve the catalogue and the Platform.

How to refuse consent for secondary purposes

You may refuse from the outset by writing to hola@beiratraining.com with the subject "Secondary purposes", or at any later time using the unsubscribe link included in every such communication. The opt-out applies immediately and does not affect the operational communications described above, which are part of the service.

6. Public Verification of Certificates

Every certificate issued carries a public folio. Anyone who knows that folio can check online, without an account, the full name of the person who earned it, the course covered, the issue date, the final score and whether the certificate remains valid or has been revoked.

That check is the very purpose of the document: without it the certificate would be useless as evidence before an auditor or a customer. By obtaining a certificate you consent to this limited disclosure.

The verification page is excluded from search engine indexing and does not allow folios to be listed or searched by name: it only responds to a specific folio that someone already holds. If you do not want a certificate issued in your name, tell us before completing the course.

7. Data of Corporate Customers' Staff

When a company purchases seats for its staff or contracts the Competency Management Module, it enters data about its employees into the Platform.

With respect to that data, the corporate customer acts as controller and Beira Training as processor: we process it solely on the customer's instructions and to provide the contracted service, without using it for our own purposes beyond those described in this notice.

It is for the corporate customer to inform its staff about the processing and to have a legitimate basis for carrying it out. The employee retains, vis-à-vis Beira Training, their rights over their personal account and their certificates, and may exercise them through the channels set out in this notice.

Competency Management Module data

The module is a subscription tool with which a company documents the competencies each position requires and assesses its staff against them. The information a company records in it may include:

  • Employee identification and employment data: name, email, position, department and position assignment dates.
  • Competency assessments, self-assessments, scores and detected gaps.
  • Evidence and attachments the company uploads as support (external certificates, degrees, training records).
  • Detected training needs, annual training plans and effectiveness verifications.

Retention and deletion of module data

When the subscription is cancelled, module data stays read-only with export available for 30 (thirty) calendar days, is then blocked while export is preserved, and 120 (one hundred and twenty) calendar days after the cancellation it is permanently and irreversibly deleted, attachments included. We send an email before the block and again before the deletion.

That deletion reaches only the module. Employees' accounts, their course progress and their certificates are unaffected, because they are not part of the subscription.

Where access to the module comes from an AdminISO subscription rather than being contracted here, the same cycle starts as soon as that subscription ends.

8. Who We Share Your Data With

We do not sell or trade your personal data, nor do we share it with third parties so they can send you their own advertising.

To operate the Platform we use providers that process data on our behalf and on our instructions. Each one receives only what is indispensable for its function:

  • Application hosting and execution, including aggregate traffic analytics (provider in the United States).
  • Managed database, where account, course and progress information resides.
  • File storage: certificate PDFs, images and course resources (provider with a global distribution network).
  • Video hosting and playback, including technical playback metrics (provider in the United States).
  • Payment processing and invoicing (PCI DSS compliant provider).
  • Transactional email delivery.
  • Caching and rate limiting, to protect the Platform against abuse.

Other cases

  • Competent authorities, where there is a duly founded request or a legal obligation. We limit disclosure to the minimum required and, where the law allows, we inform you.
  • Legal, accounting or audit advisers, bound by confidentiality obligations.
  • In the event of a merger, acquisition or corporate restructuring, the acquirer, which will be bound to honour this notice. We will inform you if this occurs.

International transfers

Some of the providers above process information outside Mexico, mainly in the United States and the European Union. These are transfers necessary to provide the service you contract, covered by agreements imposing confidentiality and security obligations equivalent to those in this notice and, where applicable, by the Standard Contractual Clauses approved by the European Commission.

9. Cookies and Similar Technologies

The Platform uses cookies that are strictly necessary to keep your session active and to remember your language and currency preferences, plus browser local storage for the theme preference. We do not use advertising or cross-site tracking cookies. The full detail, with the name and duration of each cookie, is in the Cookie Policy.

10. Information Security

We apply reasonable administrative, technical and physical measures to protect your personal data against loss, misuse, alteration or unauthorized access. Among others:

  • Encryption of communications in transit and encryption of information at rest.
  • Passwords stored using resistant key derivation functions (Argon2id), never in plain text.
  • Two-factor authentication available for every account.
  • Role-based access control and separation of each corporate customer's data.
  • Attempt and traffic rate limiting to contain automated attacks.
  • An immutable audit log recording the user, IP address and timestamp of every relevant operation, including support actions performed on behalf of a user.
  • Regular backups of the information.

A reasonable limit

No system is entirely invulnerable. Should a breach occur that significantly affects your rights, we will notify you without undue delay so you can take appropriate measures.

11. How Long We Keep Your Data

We keep your data while your account is active and for as long as necessary to fulfil the purposes described.

When you delete your account we first apply a logical deletion: the account becomes inaccessible immediately and your data is retained for up to 90 (ninety) calendar days before final erasure. During that period you may ask us to reinstate it. That margin prevents irreversible loss from a single click.

Some information survives account deletion by its very nature:

  • Certificates issued and their verification record, because they attest to something that happened and third parties may need to verify them. They contain the name, the course, the date and the score.
  • Purchase records and tax receipts, for the period required by tax law.
  • Audit logs, which are immutable by design and are kept for traceability and security purposes.

12. Your Data Protection Rights

You have the right to access your personal data, to rectify it where it is inaccurate or incomplete, to cancel it where you consider it is not necessary for the purposes disclosed, and to object to its processing for specific purposes (in Mexico, the so-called ARCO rights).

How to exercise them

Send your request to hola@beiratraining.com stating: your name and a means of replying to you; documents proving your identity (or legal representation, where applicable); a clear description of the data your request concerns; and any detail that helps us locate it.

We will answer your request within a maximum of 20 (twenty) business days and, where it is well founded, give effect to it within the following 15 (fifteen) business days. Exercising these rights is free of charge; only justified shipping or reproduction costs could be charged.

Several of these actions require no request at all: from your account settings you can update your profile data, change your password, adjust your preferences and delete your account.

Limits

Cancellation or objection may not proceed where there is a legal obligation to retain the information, where it is necessary to perform an ongoing contract or to evidence compliance with obligations. In particular, a validly issued certificate is not deleted at the data subject's request, because it documents a fact verifiable by third parties; an error in the name or another detail can, however, be corrected through the right of rectification.

Withdrawing consent

You may withdraw the consent you gave us at any time, through the same channel provided for data rights requests. Withdrawal has no retroactive effect and may make it impossible for us to continue providing the service, in which case we will tell you.

Supervisory authority

If you consider that your right to the protection of personal data has been infringed, you may turn to the competent data protection authority in Mexico.

13. Users Outside Mexico

European Economic Area and United Kingdom

If you are in the EEA or the United Kingdom, you additionally have the rights of access, rectification, erasure, restriction, portability and objection provided by the General Data Protection Regulation. The legal bases for our processing are performance of the contract (providing the service), compliance with legal obligations, our legitimate interest in security and service improvement, and your consent for the secondary purposes. You have the right to lodge a complaint with the supervisory authority in your country.

California

If you are a California resident, you have the right to know what personal information we collect, to request its deletion and not to be discriminated against for exercising those rights. Beira Training does not sell or share your personal information within the meaning of the CCPA/CPRA.

14. Minors

The Platform is aimed at professionals and companies, and its use requires being of legal age. We do not knowingly collect data from anyone under 18. If we detect that an account was created with a minor's data, we will delete it along with the associated information.

15. Changes to This Notice

We may update this Privacy Notice to reflect changes in the service, in our providers or in applicable law. The version in force is always the one published on this page, bearing the date at the top.

Where a change materially affects the purposes of the processing or the conditions under which we share your information, we will notify you by email at least 30 (thirty) calendar days before it takes effect.

16. Contact

For any question about this Privacy Notice, to exercise your rights or to request further information about the processing of your data, write to us at hola@beiratraining.com. We reply within a maximum of 10 business days, without prejudice to the legal deadlines applicable to data rights requests.

Data controller

Beira Training

Zapopan, Jalisco, México

hola@beiratraining.com