Legal
Privacy policy
Last updated: September 18, 2026
This English version is provided for convenience. If it differs from the Spanish version, the Spanish version prevails.
This notice explains how Valeria Valenzuela Vichy, who offers her services under the trade name Healthbrand, processes the personal data of people who contact us, of our clients, and of people who message the businesses for which we implement our WhatsApp CRM. It is issued under Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (published March 20, 2025) and the WhatsApp Business platform policies of Meta.
1. Who is responsible
The controller of your data is Valeria Valenzuela Vichy, an individual registered in Mexico, who operates under the trade name Healthbrand. Healthbrand is not a company: in this notice, "Healthbrand", "we" and "us" refer to her.
- Mexican tax ID (RFC): VAVV950929BU5
- Email: [email protected]
- WhatsApp: +52 229 463 1956
2. How our service works
We implement for each business its own WhatsApp CRM with an AI agent. The server that runs the CRM and the AI provider are contracted in the business's name, and its phone number and WhatsApp Business account stay its own, in its own Meta business portfolio. So conversation data lives on the business's infrastructure, not ours.
3. Our two roles
- Controller of the data of people who contact us, request a quote or hire our services.
- Processor of the data a business handles in its WhatsApp CRM, such as conversations with its customers. In that case the business is the controller: it decides how that data is used and must have its own privacy notice. Healthbrand processes it only while implementing the system and, if the business hires support, while providing it, always on the business's instructions.
4. What data we process
If you contact us or hire a service
- Name, phone or WhatsApp number, email, company and industry.
- Any information about your operation that you share so we can prepare a quote.
- If you fill in the form on this website: your name, WhatsApp number, email, company, industry and, if you write it, what you'd like to automate. It is stored in Healthbrand's CRM so we can answer and follow up with you on WhatsApp.
- If you become a client: billing details (name or company name, tax ID, tax regime and tax address).
In a business's WhatsApp CRM
- Team users: name, email, password (stored in irreversible form, never in plain text) and technical session records such as IP address and browser.
- Data the CRM receives from Meta through the WhatsApp Business API: each contact's phone number or WhatsApp user ID, profile name, message content and files (text, images, audio, documents and locations), delivery and read statuses, and the IDs of the business's WhatsApp Business account and phone number.
- Data added by the business: notes, sales stage, contact details, message templates and the business information the AI agent uses to reply.
- WhatsApp connection credentials, stored encrypted.
- Only if the business turns these features on: booked appointments; the ID of the Meta ad a conversation came from and the conversion events reported to Meta; and credentials for integrations such as calendars or video calls, also stored encrypted.
Healthbrand does not ask for sensitive personal data. If a business receives sensitive data in its conversations because of its industry (for example, health information), it is responsible for obtaining explicit consent from those people.
If you only visit this website
This website uses no tracking, analytics or advertising cookies. The contact form sends your answers directly to Healthbrand's CRM, without going through third parties. Our servers log technical data for each visit, such as IP address, to run and protect the site and the form. WhatsApp buttons take you to WhatsApp, a Meta service with its own privacy policy.
5. Why we use it
- To answer your messages and prepare your quote.
- To implement the service you hire, support you if you hire support, and invoice.
- To set up and test the business's WhatsApp CRM: connect its number, prepare its stages and the AI agent, and check that everything works.
- To keep the service secure and meet legal obligations.
All of these are necessary to provide the service. We do not sell personal data, we do not use it for our own advertising, and we never use a business's customer conversations for anything other than serving that business.
6. Use of artificial intelligence
When a business turns on the AI agent, the CRM sends the recent conversation history and the business information configured in the CRM to the AI model provider contracted by the business, to generate each reply. The agent can hand the conversation to a team member at any time, and it does not pretend to be human.
7. Who it is shared with
Only with the providers needed to deliver the service, and with authorities when required by law:
| Provider | Purpose | Account holder |
|---|---|---|
| Meta Platforms (WhatsApp Business) | Sending and receiving WhatsApp messages and, if enabled, reporting ad conversions | The business |
| Server provider (for example, Hostinger) | The server that runs the WhatsApp CRM | The business |
| OpenRouter and the AI model provider | Generating the agent's replies, when the business turns it on | The business |
| Integrations enabled by the business (for example, calendar or video calls) | Creating appointments or meetings | The business |
| Hostinger | The server for this website and Healthbrand's internal systems, including the CRM that receives form requests | Valeria Valenzuela Vichy (Healthbrand) |
| Cloudflare | DNS, security and web traffic delivery | Valeria Valenzuela Vichy (Healthbrand) and, where applicable, the business |
8. International transfers
Healthbrand's servers are located in the United States, and several of the providers above operate outside Mexico. Each business's CRM server is in whatever country its chosen provider offers. When you use our services, your data may be processed in those countries, always for the purposes described in this notice.
9. How long we keep it
- WhatsApp CRM data: lives on the business's server, under its control, for as long as the business decides. Healthbrand only has access during implementation and, if hired, during support. When that ends, we remove our access and delete any copies we hold within 30 days.
- Prospect contact details: while the business conversation continues or until you ask us to delete them.
- Tax records: for as long as tax law requires.
10. How we protect it
- WhatsApp and integration credentials are stored encrypted (AES-256).
- All traffic is encrypted over HTTPS.
- Each business has its own CRM instance, and each user signs in with their own account.
- Access to the infrastructure is restricted and protected.
11. Your rights
You can request access to your data, its correction or deletion, object to its use, and withdraw your consent. Email [email protected] with your name, a way to reach you, the right you want to exercise and, if applicable, the business you messaged on WhatsApp. We will verify your identity and respond within 20 business days.
If your data is in a business's WhatsApp CRM, you can contact that business, as the controller, or us, and we will follow up with them. To delete data, see also Data deletion.
If you believe your data protection rights have been violated, you can file a complaint with Mexico's Ministry of Anti-Corruption and Good Governance (Secretaría Anticorrupción y Buen Gobierno), the competent authority.
12. Changes to this notice
If the way we process data changes, we will update this notice and its date. When a change is significant, we will let our clients know by email or WhatsApp.