Privacy Policy

Last updated: May 30, 2026

At Aluma we take seriously the privacy of the families, students and teachers that trust our platform. This Privacy Policy explains which personal data we collect, the purposes for which we process it, and how you can exercise your rights under Mexico's Federal Law for the Protection of Personal Data Held by Private Parties (LFPDPPP) and its Regulations.

1. Data controller

The controller of your personal data is Aluma, a platform operated for extracurricular education centers in Mexico. For any matter related to this Policy you can reach us at terminos@usaaluma.com.

2. Personal data we collect

Depending on your role on the platform, we may collect:

  • Identification data: name, date of birth, email address, phone number.
  • Family contact data: name and contact details of guardians or authorized persons.
  • Academic data: enrolled classes, attendance, teacher notes, student progress.
  • Billing data: address, tax ID, and payment references. We do not store card numbers or CVVs — those are processed directly by Stripe.
  • Usage data: IP address, device identifier, visited pages and access logs.

3. Purposes of processing

Primary purposes (necessary to deliver the service):

  • Create and manage your account, or that of your child.
  • Allow the center to enroll you in classes, record attendance and bill tuition.
  • Send operational notifications about classes, payments and messages from the center.
  • Comply with applicable tax, accounting and legal obligations.

Secondary purposes (you can opt out without losing service):

  • Improve the platform and develop new features.
  • Send you product updates, surveys or educational materials.

4. Minors

Aluma is used at centers that teach children and teens. Personal data of minors is processed only with authorization from a parent or legal guardian, who acts on their behalf. Minors cannot create an account on their own; they must be enrolled by a guardian with an active membership at a center. When a minor has read-only access to the app, it is granted only with the guardian's explicit authorization.

5. Transfers and processors

To operate the platform we share data with the following processors, under contracts that require them to comply with the LFPDPPP:

  • Stripe, Inc. — card payment processing and recurring billing.
  • Mailgun Technologies, Inc. — transactional email and notifications.
  • Vercel Inc. and our infrastructure providers — hosting and content delivery.
  • Anthropic, PBC — AI-assisted features when enabled by the center.
  • Competent authorities when required by law.

We do not sell, rent or otherwise commercially transfer your personal data to third parties outside the above.

6. Centers as co-controllers

Each education center is a co-controller of the data of the families, students and teachers linked to its organization within Aluma. The center decides who can access what information inside its own workspace. To learn the internal policies of a specific center, contact that center's administration directly.

7. ARCO rights and consent withdrawal

You have the right to Access, Rectify, Cancel or Object to the processing of your personal data, as well as to revoke any consent you have given us. To exercise these rights send a request to terminos@usaaluma.com including:

  • Your full name and a way to contact you.
  • Proof of identity or legal representation.
  • A clear description of the data and the right you wish to exercise.

We will respond within 20 business days. If your request is granted, we will act on it within 15 business days thereafter.

8. Cookies and similar technologies

We use strictly necessary cookies to keep your session active and remember your preferences (language, light/dark theme). We also use aggregate analytics cookies to understand how the platform is used. You can disable cookies in your browser; some features may be affected.

9. Security measures

We maintain reasonable administrative, technical and physical safeguards to protect your personal data: encryption in transit (TLS), encryption at rest, role-based access control, logical separation between centers (multi-tenancy with Row-Level Security), regular backups and access audits.

10. Retention

We retain your data while your account or membership is active, and for the additional periods required by tax, accounting and legal obligations. After those periods, the data is cancelled or anonymized.

11. Changes to this Policy

We may update this Privacy Policy. We will notify you of material changes by email or via a prominent notice in the platform. The last-updated date appears at the top of the document.

12. Contact

If you have questions about this Policy or about how we handle your data, write to terminos@usaaluma.com. You may also contact INAI (Mexico's National Institute for Transparency, Access to Information and Personal Data Protection) at inai.org.mx.