Last updated: August 11, 2026
Responsible party: Aranzazú Gamboa Andrade | Contact: hola@paqpaq.mx / WhatsApp +52 614 277 8738
1. Introduction and Legal Framework This Policy establishes the procedures for PAQPAQ (Aranzazú Gamboa Andrade, an individual conducting business activity) to detect, respond to, contain, notify, and resolve security incidents that compromise personal data or service availability. It complies with: the LFPDPPP and its Regulations; the Federal Consumer Protection Law (LFPC); the Federal Tax Code and SAT resolutions on CFDI security; and the terms of service of associated Logistics Operators and external Providers.
2. Definition of a Security Incident Any confirmed or reasonably suspected event that compromises the confidentiality (unauthorized access, data leak or theft), integrity (modification or corruption of data or CFDI), or availability (service interruption, ransomware, DDoS) of systems or data.
3. Severity Classification Incidents are classified within a maximum of 2 hours of detection as: Critical (confirmed data leak affecting multiple users, compromise of CFDI/CSD, total outage > 2 hours), High (unauthorized access without confirmed modification, leak affecting 1-10 users, compromise of administrative credentials), Medium (unexploited vulnerability, log anomalies, downtime < 30 min), and Low (minor event with no impact on data or services).
4. Roles, Responsibilities, and Contacts Incident Lead: Aranzazú Gamboa Andrade or designee (activates the protocol, coordinates, authorizes notifications). Emergency contact: hola@paqpaq.mx (maximum 1-hour response). Technical Team: investigates, contains, eradicates, and recovers. Communications Lead: coordinates notifications to users and authorities.
External contacts by priority: affected users (registered email + dashboard + call if critical); the relevant Logistics Operator when the incident affects integration or shared data; the external Provider of "Protect Your Shipment" when the incident affects data shared with that service (declared values, claim evidence); INAI (mandatory if a confirmed personal data leak occurs); SAT (mandatory if CFDI, CSD, or tax data are compromised); and PROFECO (mandatory if consumer rights are affected under the LFPC).
5. Response Process Phase 1 — Detection and logging (hour 0): log date/time, description, affected systems, and reporter in a centralized log; notify the Lead by phone if High/Critical. Phase 2 — Assessment and classification (hours 0-2): determine severity, affected data, number of users, and preliminary root cause. Phase 3 — Containment (hours 0-4): isolate accounts/systems, revoke sessions and API keys, force password resets, close leak vectors, and activate contingency plans. Phase 4 — Investigation and eradication (hours 4-24): forensic analysis, timeline, root cause identification, and fix implementation. Phase 5 — Recovery and validation (hours 4-48): restoration from verified backup, integrity validation, functional testing, and 72-hour intensive monitoring.
6. Notification Plan To affected users: initial communication within 24 hours and formal notification within 72 hours of confirming a personal data leak (LFPDPPP), via registered email and dashboard, plus a call if critical. To the Logistics Operator or the external Provider of "Protect Your Shipment": within 24 hours if the incident affects integration or data shared with them. To INAI: without undue delay, maximum 48 hours after confirming the leak. To SAT: within 24 hours if CFDI/CSD/tax data are compromised. To PROFECO: within 5 business days if consumer rights are affected.
User notification template: subject line "Security Incident Notification - PAQPAQ," including the incident and detection dates, type and severity, potentially affected data, actions taken, recommendations to the user (change password, monitor suspicious activity), and contact hola@paqpaq.mx.
7. Technical Security Requirements Encryption in transit (HTTPS/TLS 1.3) and at rest (AES-256), including backups. Append-only logging with a minimum 12-month retention period. Credential management under the principle of least privilege, minimum 12-character passwords, and API key rotation. Daily backups with periodic verification, maximum RTO of 4 hours and maximum RPO of 1 hour. Access monitoring and alerts with human review within 30 minutes for High/Critical severity.
8. Post-Incident Communication A "lessons learned" document within 5 business days of closure (summary, root cause, corrective and preventive actions, follow-up owner). A summarized public communication within 30 days, without disclosing exploitable technical details.
9. Testing, Audits, and Continuous Improvement Quarterly response exercises, monthly recovery tests, annual penetration tests by an independent third party, and an annual security audit or one following a High/Critical incident. This Policy is reviewed annually and after legislative changes.
10. Compliance and Accountability Staff training during onboarding and annually. Providers and contractors (Logistics Operators, external Providers such as the one for "Protect Your Shipment," Stripe, invoicing, etc.) must comply with this Policy through contractual clauses. All incidents and lessons learned are documented and retained for a minimum of 6 years in accordance with the LFPDPPP.
11. Annex: Emergency Contacts Incident Lead (internal): Aranzazú Gamboa Andrade | hola@paqpaq.mx (available 24/7 for Critical severity). Affected users: hola@paqpaq.mx. INAI: www.inai.org.mx. SAT: 01-800-601-2000 | www.sat.gob.mx. PROFECO: 01-800-468-8000 | www.gob.mx/profeco.
© 2026 Aranzazú Gamboa Andrade (PAQPAQ). All rights reserved.