1. Who we are
AX9 LLC ("Felismed", "we"), a limited liability company organized under the laws of the State of Texas, USA, with its address at 17350 State Hwy 249, Ste 220 #36956, Houston, Texas 77064, United States of America, develops and operates the Felismed platform (felismed.com and app.felismed.com).
For any question about this policy or your personal data, write to contact@ax9.io.
This policy is issued under Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties published on March 20, 2025 (the "LFPDPPP") and other applicable Mexican regulations.
2. Who this policy covers
Felismed processes personal data in two different roles:
- As controller, for data about clinics that subscribe to Felismed, their representatives, staff members with an account (front desk, clinicians, administrators), people who request a demo, and visitors to felismed.com.
- As processor, for patient data each clinic records in Felismed. The clinic is the controller, and Felismed processes that data only on the clinic’s behalf and according to its instructions.
If you are a patient of a clinic that uses Felismed, your clinic’s privacy notice applies to you. See section 9 for how to exercise your rights.
3. Personal data we process
As controller, we may process:
- Identity and contact: name, email, phone and WhatsApp number, role and optional profile photo.
- Professional data: specialty, professional license number and the clinic where you work.
- Tax and billing data: legal name, RFC, tax regime, postal code and tax address, CFDI use and tax status certificate.
- Subscription payment data: processed by Conekta, our payment processing provider. Felismed does not store card numbers.
- Usage and technical data: IP address, browser and device type, access dates and times, actions in the platform and security logs.
- Communications: messages you send us by email, form or WhatsApp.
We do not request sensitive personal data from clinics or their staff. Patient health data is processed by Felismed only as a processor, as described in section 2.
4. Purposes
Primary purposes, necessary for our relationship:
- Creating and managing the clinic account and staff accounts.
- Providing the service: scheduling, clinical records, WhatsApp messaging, payments and invoicing.
- Issuing invoices (CFDI) for the subscription and meeting tax obligations.
- Providing technical support and handling requests.
- Keeping the platform secure and preventing fraud and unauthorized access.
- Complying with legal obligations and requests from competent authorities.
Secondary purposes, not necessary for the service:
- Sending product news, event invitations and educational content.
- Satisfaction surveys and research to improve Felismed.
- Aggregate usage statistics.
To opt out of secondary purposes at any time, email contact@ax9.io with the subject "Secondary purposes" or use the unsubscribe link in any email. Opting out does not affect the service.
5. Patient data (Felismed as processor)
Clinics record patient data in Felismed, including health data that the LFPDPPP treats as sensitive. For that data:
- The clinic is the controller and must have its own privacy notice and obtain the patient’s express written consent where the law requires it.
- Felismed processes the data only to provide the service to the clinic, does not use it for its own purposes, does not sell it and shares it only with the sub-processors needed to run the platform.
- When the relationship with the clinic ends, the data is returned or deleted as set out in the Terms of Service and the Data Deletion page.
6. Service providers and transfers
We rely on providers that process data on our behalf under confidentiality and security obligations:
| Provider | Service | Location |
|---|---|---|
| Supabase | Database, authentication, file storage and sign-in emails | United States |
| Cloud provider to be designated | Hosting of app.felismed.com | United States |
| Meta Platforms (WhatsApp Business Platform) | Sending and receiving WhatsApp messages | United States and others |
| Facturapi | CFDI stamping with the SAT | Mexico |
| PostHog | App usage analytics, with no patient personal data | United States |
| Conekta | Subscription payment processing | Mexico |
Disclosures to processors do not require your consent under the LFPDPPP.
On felismed.com, PostHog does not use cookies: it computes a temporary identifier from your IP and browser that is discarded the same day and is not stored.
We only transfer data to third parties without your consent where the law allows it, for example when required by a competent authority, or to companies in the same group operating under the same policies.
7. ARCO rights and withdrawing consent
You have the right to access, rectify, cancel or object to the processing of your personal data (ARCO rights), and to withdraw your consent.
Send your request to contact@ax9.io with the subject "ARCO rights", including:
- Your name and a way to contact you.
- A copy of official ID or, if acting for someone else, proof of representation.
- A clear description of the right you wish to exercise and the data concerned.
- Any document that helps us locate your data.
We will respond within 20 business days of receipt and, if the request is granted, carry it out within the following 15 business days.
8. Limiting use or disclosure
You can ask to be added to our internal exclusion list so you don't receive promotional communications by writing to contact@ax9.io. You can also register with PROFECO’s Public Registry to Avoid Advertising.
9. If you are a patient
Your data belongs to your clinic’s records, so direct access, correction, deletion or objection requests to the clinic. If you contact us instead, we will forward your request to the clinic within 5 business days and let you know.
To stop receiving WhatsApp messages from your clinic, ask the clinic. Once it records that you withdrew consent, Felismed stops sending you automated messages.
11. Retention
We keep your data while you have an active account and afterwards for as long as needed to meet legal, tax or contractual obligations; for example, tax records are kept for the period required by Mexico’s Federal Tax Code. After that, data is securely deleted.
12. Security
We apply administrative, technical and physical safeguards to protect data against damage, loss, alteration, destruction or unauthorized use, access or processing. The main measures are described on the Security page.
If a security breach significantly affects your rights, we will inform you without delay so you can take action.
13. Changes
We may update this policy to reflect legal or service changes. The current version is published at felismed.com/privacidad with its update date, and we will notify you by email of material changes.
14. Authority
If you believe your data protection rights have been violated, you may contact Mexico’s Secretaría Anticorrupción y Buen Gobierno, the authority responsible for personal data held by private parties.
Related documents
Questions about this document? Write to contact@ax9.io