Comprehensive privacy notice

Grower: mobile app, web Console and the machines' local panel.
Version: 2026-09-29 · Versión en español

This is an English translation of the Spanish privacy notice (aviso de privacidad integral). If the two differ, the Spanish version prevails.

Tlachia Systems, S.A. de C.V. ("Tlachia", "we") develops and operates Grower, a platform to monitor and operate fertigation machines. This notice explains what personal data we process when you use the Grower app for iPhone and Android, the web Console, the machine's local panel and this website; why we use it, who we share it with and how you can exercise your rights. We issue it under Mexico's Federal Law on the Protection of Personal Data Held by Private Parties, published in the Official Gazette (DOF) on March 20, 2025 (the "Law").

Contents
  1. Controller and contact
  2. Who this notice applies to
  3. Personal data we process
  4. How we obtain your data
  5. Purposes
  6. Providers that process data on our behalf
  7. Transfers
  8. How to limit the use or disclosure of your data
  9. ARCO rights
  10. Revoking consent
  11. Deleting your account
  12. How long we keep your data
  13. Cookies and similar technologies
  14. Security
  15. Changes to this notice
  16. Authority

1. Controller and contact

The party responsible for processing your personal data (the controller) is:

Tlachia Systems, S.A. de C.V.
Av. Felipe Carrillo Puerto No. 1001 Int. 2 A
Zona Industrial Benito Juárez
Querétaro, Qro. 76120, Mexico

Our Personal Data Department handles your requests and questions about this notice:

2. Who this notice applies to

This notice applies to people who use Grower (staff or collaborators of the organizations that are our customers, such as growers and agricultural companies) and to visitors of grower.digital.

Grower has no open sign-up: accounts are created by your organization's administrator. Your organization decides who can access its machines, and the operating records of its machines belong to it. If your organization has its own privacy notice for its staff, that notice also applies to what it does with your data.

3. Personal data we process

3.1 Your account data (all products)

3.2 Mobile app (iPhone and Android)

On your phone, the app keeps your session in the system's secure storage, your preferences (such as language) and a temporary copy of your machines' information. When you sign out, the stored session is deleted and the notification token is unregistered. The app does not access your location, camera, microphone, photos or contacts, and it does not use advertising identifiers.

3.3 Web Console

3.4 The machine's local panel

The machine panel is used with a per-machine PIN shared by the team that operates it, which does not identify a person. The machine stores the PIN only as a cryptographic hash. Commands given from the panel are recorded as made "from the local panel", without a person's name.

3.5 Machine data

Sensor readings, valve and pump status, recipes, alarms, configuration and the location (coordinates) of the site where the machine is installed. This is your organization's operating data. It is personal data only when it can be linked to a person, for example when the grower is an individual or when we record which user gave a command. In that case we protect it like the rest of your data.

3.6 Support

If you write to us, we process your name, your email address and the information you share in order to help you.

3.7 This website (grower.digital)

It uses no cookies, analytics or third-party resources, and we keep no visitor logs. The server uses your IP address only to deliver the page.

Sensitive data. We do not process sensitive personal data. We do not process users' financial or property data either: the app and the Console do not process payments.

Minors. Grower is a work tool and is not directed at minors.

4. How we obtain your data

5. Purposes

Primary purposes

These are necessary to provide the service your organization contracted, so they do not require your consent (article 9, section IV, of the Law):

  1. Create, manage and protect your account, and verify your identity when you sign in.
  2. Let you monitor and operate the machines of your organization that you have access to.
  3. Send you notifications about alarms, recipes and manual control of those machines.
  4. Record in an audit log who gave each command, when and with what result, for security, traceability, incident handling and your organization's audit commitments.
  5. Send you service emails: invitation, email verification and password or second-factor setup.
  6. Detect, diagnose and fix faults, and protect the service against unauthorized use.
  7. Handle your support and ARCO requests.
  8. Comply with legal obligations and requests from competent authorities.

Secondary purpose

It is not necessary for the service and you may refuse it:

  1. Measure, in pseudonymized form, how Console features are used in order to improve the product, when product analytics is enabled.

If you do not want your data used for this purpose, email us at any time at contacto@tlachia.org with the subject "Refusal of secondary purpose". Refusing does not affect your access to the service. If you do not object, we will understand that you accept it (tacit consent, article 7 of the Law).

We do not use your data for advertising, we do not sell it and we do not build commercial profiles with it.

6. Providers that process data on our behalf

To provide the service we use providers that process data only on our behalf and under our instructions (processors, "personas encargadas", article 2, section XII, of the Law). Sharing data with them is not a transfer (article 2, section XX) and does not require your consent. We require them to keep it confidential and secure.

ProviderPurposeDataLocation
Hetzner Online GmbH Grower cloud servers: database, sign-in and services All platform data Data center in the United States
Hetzner Online GmbH (Storage Box) Backups, encrypted before they leave our server Encrypted copy of the database European Union
Functional Software, Inc. (Sentry) Crash reports from the app, the Console, the cloud and the machines Technical crash data, internal identifiers (organization, machine) and the IP address the report is sent from; no name or email address United States
PostHog, Inc. (PostHog Cloud EU) Console product analytics, when enabled Pseudonymous user and organization identifier, pages and usage events, technical browser data and IP address European Union (Germany)
Google LLC (Firebase Cloud Messaging) Deliver notifications to Android phones Phone token and a notice with generic text and internal event identifiers (type, severity, code, organization and machine); no name or email address United States
Apple Inc. (Apple Push Notification service) Deliver notifications to iPhones Phone token and a notice with generic text and internal event identifiers; no name or email address United States
Sendinblue SAS (Brevo) Send service emails Your email address, your name and the message content (invitation or password links) European Union (France)

These external services receive no personal data:

7. Transfers

We do not sell or rent your data. We share it with third parties only in these cases, which do not require your consent (article 36 of the Law):

If we ever want to make a transfer that requires your consent, we will ask you first and update this notice.

8. How to limit the use or disclosure of your data

9. ARCO rights

You have the right to:

How to submit a request

Email contacto@tlachia.org with the subject "ARCO rights", or send a letter to the address in section 1. Under article 28 of the Law, include:

  1. Your name and an email or postal address where we can send the reply.
  2. A document proving your identity or, if a representative acts for you, their identity and proof of representation.
  3. A clear description of the data concerned (not needed for the right of access).
  4. The right you are exercising or what you are requesting.
  5. Anything that helps us locate your information, such as your account email and your organization's name.

For a rectification, tell us what should change and attach supporting documents.

Time limits and response

Some data cannot be cancelled while it is needed to perform the contract with your organization or to meet a legal obligation (article 25). In particular, the command audit log is kept for 5 years: when your account is cancelled those records are blocked, meaning they are kept only to address possible liabilities, and they are deleted when that period ends (articles 2, section III, and 24).

If you disagree with our response, you may file a rights protection request with the Ministry of Anti-Corruption and Good Government (Secretaría Anticorrupción y Buen Gobierno) within 15 business days of the date we communicate it to you. If we do not respond, you may file it as soon as our deadline to respond expires (article 40).

10. Revoking consent

You may revoke any consent you have given us at any time, through the same channel and with the same requirements as an ARCO request, using the subject "Revocation of consent". Revocation has no retroactive effect (article 7). If you revoke processing that is necessary for the service, we may be unable to keep your account; if so, we will explain this in our reply. We respond within the time limits in section 9.

11. Deleting your account

You can ask us to close your account at any time, directly or through your organization's administrator, by emailing contacto@tlachia.org with the subject "Delete my account". We treat it as a cancellation request (section 9) and resolve it within those time limits. In the meantime, we disable your access as soon as we confirm the request comes from you or your organization. When we handle it:

The steps are also in Support › Delete your account.

12. How long we keep your data

DataPeriod
Account: name, email address, role and machine accessWhile the account exists. When it is cancelled, it is deleted or anonymized as described in section 11.
Sign-in records (date, time, IP address, application)14 days
Notification tokenUntil you sign out, Apple or Google invalidate it or your account is removed
Command audit log5 years; then it is deleted automatically
Crash reportsUp to 90 days
Console product analyticsUp to 12 months
Server technical logs (they include failed sign-in attempts, with the IP address and the username entered)14 days in the central log system; each service's local copies are overwritten automatically once they reach a maximum size
Encrypted backupsUp to 6 months (7 daily, 4 weekly and 6 monthly)
Machine readingsPer-second detail, 30 days; per-minute, hourly and daily summaries, for as long as the service with your organization lasts
Support emails and ARCO requestsUp to 2 years after they are handled

13. Cookies and similar technologies

You can delete or block cookies and local storage in your browser settings. If you block the sign-in cookies, you will not be able to use the Console.

14. Security

If a security breach significantly affects your property or moral rights, we will inform you immediately so you can take action (article 19).

15. Changes to this notice

We will publish any change on this page with a new version date. If the change is significant, such as new purposes, new types of data or transfers that require your consent, we will also let you know in the app, in the Console or by email before it applies.

16. Authority

The authority for the protection of personal data held by private parties in Mexico is the Ministry of Anti-Corruption and Good Government (Secretaría Anticorrupción y Buen Gobierno).

Version: 2026-09-29