Privacy notice

What data of yours we handle, what for, who we share it with, and how you take back control of it.

Last updated: 1 August 2026 · Version 1.0

Two items are still missing from this document

We have not yet published a physical address or a service telephone number. Mexican law requires them on two separate grounds: art. 15, section I of the LFPDPPP requires an address for receiving notices, and art. 76 BIS, section III of the Federal Consumer Protection Law requires a physical address and telephone numbers from anyone contracting by electronic means — it does not condition that on the service being paid for. We are short of them now, not from the first charge onward. In the meantime, the valid and monitored channel for everything in these documents is contact@paretolearn.com, and we are publishing the other two. We will not switch on subscription billing until both are published.

The essentials, in thirty seconds

Pareto Learn publishes original explanations of the ideas in non-fiction books. Making that work takes very little information about you, and we describe that little without hedging.

If you read only one paragraph, make it this one: to create an account we ask for your email and a password. We store your reading preferences and where you left off in each explanation. We measure how the texts are read only if you accept analytics, and you can decline without losing any feature.

  • We do not sell your data or hand it to data brokers.
  • We run no targeted advertising and no third-party trackers.
  • We do not train machine learning models on your data.
  • We ask for no sensitive data and infer none. The one nuance — which particular book you read — we spell out below.
  • Everything we measure for analytics depends on you accepting it.

Who the controller is

Today, a Mexican individual. Tomorrow, the company once incorporated. The contact address doesn't change.

Controller
Álvaro Hernández, an individual carrying on business activity, in his capacity as operator of Pareto Learn (paretolearn.com).
Address for receiving notices
Not yet published — Write to contact@paretolearn.com and we'll send it to you in writing.
Designated person for personal data
Álvaro Hernández — contact@paretolearn.com

Being an individual is not an exemption. The LFPDPPP regulates “private individuals or legal entities” that process personal data (art. 2, section XVI), and the only relevant carve-out — art. 1, section II — covers collection for exclusively personal, non-commercial use, which is not our case.

Mexican law requires designating a person to handle data subject requests (art. 29 LFPDPPP). This designation is not a GDPR data protection officer: we are not required to appoint one, because we are not a public body, we do not process special categories of data, and we do not do so on a large scale (art. 37.1 GDPR).

Pareto Learn is currently run by three partners and the company has not yet been incorporated. Once it is, the company will replace the individual as data controller. That change will be announced on this same page under “Changes to this notice”, and it will not by itself expand any purpose or any transfer.

Legal basis: Arts. 2 section XVI, 15 section I and 29 LFPDPPP; arts. 4(7), 13(1)(a) and 37(1) GDPR.

What data we handle

This is the complete list of what we handle: what we store in the database, what stays in your browser, and what our traffic analytics records. There is no hidden “other data” category. Two things sit outside the table, and both are stated: the logs any request leaves on our server, in the note right after the table, and what your browser sends to Google when it loads the fonts, which we neither receive nor store.

The table below, together with the two paragraphs that follow it, is the real inventory of what we store: what the data is, where it lives, what it is for, on what legal basis we process it if you are in the European Union, and how long we keep it.

What data we handle
DataWhere it livesWhat forLegal basis (EU)Retention
Email address and passwordSupabase AuthCreating your account, signing in and recovering access. The password is stored as a cryptographic derivation; nobody on the team can read it.Performance of a contract (art. 6(1)(b))For as long as the account exists, plus 30 days
Display name and preferred languageprofiles tableAddressing you properly and showing the interface in your languagePerformance of a contract (art. 6(1)(b))For as long as the account exists, plus 30 days
Reading preferences: theme, justified text and font sizeprofiles table and your own browserSo reading looks the way you left it, on any devicePerformance of a contract (art. 6(1)(b))For as long as the account exists, plus 30 days
Reading progress and bookmarkuser_library tableThe “continue reading” featurePerformance of a contract (art. 6(1)(b))For as long as the account exists, plus 30 days
Reads used in the current monthuser_library tableApplying your plan's monthly limitPerformance of a contract (art. 6(1)(b))12 months. It lives in the same row as your reading progress, so when the period runs out what is deleted is the quota mark, not the row: progress follows the account's period.
Your invitation code and, if you arrived with one, who invited youprofiles tableRunning the referral programme. It has no active reward today.Contract and legitimate interests (arts. 6(1)(b) and 6(1)(f))For as long as the account exists
Pseudonymous browser identifier (anon_id)Your browser and the reading_sessions, events and affiliate_clicks tablesLinking together the reads made from the same browser. If you read while signed in, those reads are also tied to your account — including the explanation you already had open when you signed in — so in that case reading analytics is not anonymous.Your consent (art. 6(1)(a))13 months on our servers. In your browser it does not expire on its own: it stays until you clear site data or decline analytics — declining deletes it.
Active reading time, scroll depth and furthest section reachedreading_sessions tableKnowing which explanations actually get read and which get abandonedYour consent (art. 6(1)(a))13 months
Referring page, campaign parameters (utm_source, utm_medium, utm_campaign) and device typereading_sessions tableMeasuring audience and attributing where visits come from. Campaign attribution is a marketing purpose, distinct from plain audience measurement.Your consent (art. 6(1)(a))13 months
Browsing data recorded by our traffic analytics: page visited (domain and path), referring page, campaign parameters, browser, operating system, device type, country, region and city, outbound link clicks, downloads and form submissions (the fact of the submission, never its contents)Our own Plausible instance, hosted by IDONIA at a.idonia.techMeasuring site traffic. Neither your IP address nor your full browser string is stored: they are used on the fly to derive the location, the browser and the operating system, and to compute a daily identifier from a salt that is rotated and deleted every 24 hours, so your visits cannot be linked from one day to the next. While that salt exists this is not anonymous data, which is why it appears in this table.Your consent (art. 6(1)(a))13 months
Product events: page views, clicks, searches and filtersevents tableUnderstanding how the product is used and what people search for without findingYour consent (art. 6(1)(a))13 months
Clicks on bookstore links: platform, link, language, the explanation you left from, and who clicked (your anon_id browser identifier and, if you are signed in, your user identifier as well)affiliate_clicks tableMeasuring whether the affiliate model worksYour consent (art. 6(1)(a))13 months. If you do not accept analytics, no record is stored at all
Cryptographic fingerprint (salted HMAC) of your IP address at sign-up, together with your account identifier and your browser's user-agent string (up to 400 characters). All three are stored in the same row, so this fingerprint is tied to your account.signup_fingerprints tableDetecting patterns of multiple sign-ups that try to get around the free limit. It blocks nobody: it only raises a flag.Legitimate interests (art. 6(1)(f) and recital 47)12 months
Current month plus the identifier of the explanation you unlocked without an account (pl_reads cookie, signed and not readable by scripts)A first-party cookie in your browserApplying the one-explanation-per-month limit for people without an account. It identifies nobody. Without that counter we could not give you the free read you came for: it is the technical condition of that read, not a measurement about you.Performance of a contract (art. 6(1)(b)); cookie exempt from consent as strictly necessary (art. 5(3) of Directive 2002/58/EC)62 days

About the IP fingerprint: in the sign-up table we never store your IP address in the clear, only the result of running it through an HMAC function with a secret server-side salt. Even so, because we keep the salt, that value remains pseudonymised personal data, not anonymous data. We say this because calling it “anonymised” would be inaccurate, and that is why it appears in this table and within the scope of your rights.

In addition, like any web server, ours logs the requests it receives (IP address, timestamp, path and browser) in order to operate the service and detect abuse. Those logs are kept for 90 days and are not cross-referenced with your account. We process them on our legitimate interest in the security and operation of the service (art. 6(1)(f) and recital 49 GDPR).

Note: None of this is sensitive personal data under art. 2, section VI of the LFPDPPP, nor a special category under art. 9 GDPR. We do not ask for or infer ethnic origin, health status, beliefs, union membership, political opinions, sex life or biometric data. Nor do we deliberately process health data: we do not measure what you read in order to infer your physical or mental condition, we do not cross-reference the title you read with any characteristic of yours, and we do not use that signal to segment you or for anything other than deciding what to publish next. If our processing were to fall within the scope of Washington's My Health My Data Act, or of equivalent state laws on consumer health data, we will publish the separate consumer health data policy those laws require, linked prominently from the homepage, and we will ask for the separate consent they provide for.

Legal basis: Arts. 15 section II and 18 LFPDPPP; arts. 5(1)(c), 13(1) and 13(2) GDPR.

What we use your data for

Some purposes are essential to providing the service. Others are separable: if you say no, the product works exactly the same.

Necessary purposes

  • Creating and maintaining your account, and letting you sign in and out.
  • Showing you the explanations, remembering where you were and honouring your reading preferences.
  • Applying the reading limits of whichever plan you are on.
  • Protecting the service against abuse, fraud and unauthorised access.
  • Answering what you write to us and meeting our legal obligations.

Separable purposes

  • Reading analytics: understanding which explanations work and which don't, so we can decide what to publish next. Depends on your consent.
  • Campaign attribution: knowing which link or campaign brought you here. Depends on your consent.
  • The referral programme, once it has an active reward.
  • Product communications that are not strictly necessary, if we ever send them.

If we ever wanted to use your data for a purpose other than those in this notice — advertising profiling, monetised personalised recommendations, or model training, say — we would have to ask you again. That is not a marketing promise: it is what the law requires.

Legal basis: Art. 11 LFPDPPP; arts. 5(1)(b) and 6(4) GDPR.

Who we share your data with

With the providers that keep the site running, acting on our instructions. And with two genuine third parties: Google, for the fonts, and Amazon, if you click a bookstore link.

Mexican law draws a distinction that often gets blurred. When a provider processes data on our behalf and under our instructions, it acts as a processor within the meaning of art. 2, section XII LFPDPPP. Passing data to it is not a transfer: art. 2, section XX defines a transfer as a communication made to someone other than the data subject, the controller or the processor, so the processor falls outside the concept by legal definition. That is why it does not require your acceptance. When data reaches someone who decides independently what to do with it, that is a transfer to a third party.

Providers working on our behalf

  • Supabase — database, authentication and file storage. The servers are in the United States (us-east-1 region).
  • IDONIA — hosts, at a.idonia.tech, the self-hosted Plausible instance we use for analytics. It is our own instance, not a measurement service shared across several sites.
  • The provider of the server the site runs on, which hosts the site and its technical logs. And GitHub, Inc., in the United States, which hosts the code repository and runs the deployment: it holds code only, no data about the people who use the site.
  • Google Workspace — the contact@paretolearn.com mailbox.

Third parties that decide on their own

  • Google LLC — the site's fonts are currently served from Google's CDN. That means that when any page loads, your browser requests those files from Google, and your IP address travels with that request. We do this on our legitimate interest in serving the page (art. 6(1)(f) GDPR), and the cookie policy explains why that basis is arguable. We say so because it is true and because we would rather say it than not: we are migrating the fonts to our own domain, and when that happens this line will disappear from this notice.
  • Amazon and the other linked bookstores — if you click one of those links, you leave our site. From that moment Amazon handles your data as an independent controller under its own privacy policy. We send it no data about you: the link carries nothing that identifies you. What we do, if you accepted analytics, is keep a record on our side that the click was yours: the row is tied to your browser identifier and, if you were signed in, to your account as well.
  • Competent authorities, where there is a legal obligation or a properly founded request.

Note: We do not sell your data, we do not hand it to data brokers, there are no ad networks on the site and there is no third-party pixel.

Legal basis: Arts. 2 sections XII and XX, and 35 LFPDPPP; arts. 4(8), 13(1)(e) and 28 GDPR; judgment of the Court of Justice of the European Union in Fashion ID, C-40/17, of 29 July 2019, on joint controllership where a third party's resources are embedded.

Where data is stored, and international transfers

The database is in the United States. If you live in the European Union this matters to you; if you live in Mexico, the law asks nothing special of you because of it.

Our database, authentication and file storage run on Supabase, in its us-east-1 region (United States). The contact mailbox is on Google Workspace. The analytics instance is hosted by IDONIA.

For people residing in the European Union or the European Economic Area, those data flows rely on the Standard Contractual Clauses of Commission Implementing Decision (EU) 2021/914, which form part of Supabase's data processing agreement. That agreement, with the clauses already incorporated, is published by Supabase at supabase.com/legal/dpa, and the official text of the clauses is that of Commission Implementing Decision (EU) 2021/914 itself, available at eur-lex.europa.eu. If you would rather we sent it to you than go looking for it, write to contact@paretolearn.com and we will send you a copy, free of charge. Supabase is not certified under the EU–U.S. Data Privacy Framework, so we do not invoke it. Google LLC is an active participant in that framework, covered by Commission Implementing Decision (EU) 2023/1795 of 10 July 2023.

For people residing in Mexico, the LFPDPPP imposes no adequacy requirements or standard clauses for data to leave the country, and hosting in the United States requires no authorisation from any authority.

Note: We are evaluating moving the database to a European Supabase region. It is not an obligation we have today: it is the cleanest way to make this section unnecessary.

What doesn't exist yet

Part of this section is still open. We name the provider of the server the site runs on, and GitHub, as processors, but we do not yet say here which country their servers are in, or which safeguard covers that data flow if either sits outside the European Economic Area. We are not going to write it from memory: we will check it against the contracts and publish it in this same section. In the meantime, if you need to know sooner, write to contact@paretolearn.com and we will give it to you in writing.

Legal basis: Arts. 44, 45, 46 and 13(1)(f) GDPR; Commission Implementing Decision (EU) 2021/914 of 4 June 2021; Commission Implementing Decision (EU) 2023/1795 of 10 July 2023; art. 35 LFPDPPP.

How long we keep each thing

These are the periods we apply. When they run out, the data is deleted or turned into an aggregate statistic that no longer speaks about anyone.

  • Account, profile, preferences, progress and bookmarks: for as long as the account exists. If you ask us to delete it, 30 more days of grace in case it was a mistake, and then it goes.
  • Monthly quota used: 12 months.
  • Reading analytics (reading_sessions and events) and bookstore link clicks: 13 months as individual records. After that they are irreversibly aggregated and stop being personal data.
  • Traffic analytics in our own Plausible instance: 13 months.
  • Cryptographic IP fingerprint from sign-up: 12 months.
  • Cookie for reads without an account (pl_reads): 62 days.
  • Web server logs: 90 days.
  • Emails you send us: 24 months from the close of the matter, so we can evidence how we responded.

What doesn't exist yet

As of this version, automatic purging of these records is not yet in production: we run it manually and periodically. And two of the periods above are not even configured to enforce themselves: web server log rotation and the mailbox retention policy. The periods above are the commitment we make and we are putting it in place; automation is what's missing, and saying so is more useful than implying work that isn't done yet.

Legal basis: Arts. 10, 11 and 12 LFPDPPP; arts. 5(1)(c), 5(1)(e), 13(2)(a) and 25 GDPR.

Your rights

You can see what we hold about you, correct it, take it with you, object to some uses and ask us to delete it.

  • Access: find out what data of yours we process and get a copy.
  • Rectification: correct anything wrong or incomplete.
  • Cancellation or erasure: ask us to delete data once it is no longer necessary, or once you withdraw the consent it rested on.
  • Objection: ask us to stop processing data we handle on legitimate interests, for reasons relating to your situation.
  • Restriction of processing: ask us to keep the data but stop using it while a dispute is resolved.
  • Portability: receive, in a machine-readable file, and have transmitted to another controller, the data you provided to us and also the data we observed from your activity — your reading progress and bookmarks, your reading sessions and product events — provided we process it on your consent or to perform the contract.
  • Withdraw your consent to analytics at any time, without that affecting anything we did before you withdrew it.
  • Lodge a complaint with the relevant authority: your country's supervisory authority if you are in the European Union, the Secretaría Anticorrupción y Buen Gobierno if you are in Mexico, and your state Attorney General or the Federal Trade Commission if you are in the United States.

Note: Two honest clarifications. Portability and restriction are GDPR rights: Mexican law recognises only access, rectification, cancellation and objection. If you live in Mexico and ask us for an export, we will still give it to you, but as a courtesy and not as a legal obligation. And objection only makes sense against what we process on legitimate interests; against what we process to perform the contract, the remedy is not objecting but closing the account.

Legal basis: Arts. 21 to 27 and 31 to 34 LFPDPPP; arts. 15 to 22 GDPR.

How to exercise your rights

Write to contact@paretolearn.com from your account's email and tell us what you want. We do it by hand, within the legal deadlines, and free of charge.

To act on the request we need to be able to confirm it is you. Writing from the email address tied to the account and telling us which right you are exercising and over what data is enough. If that doesn't let us identify you, we will ask for something more — and only the bare minimum.

If you reside in the European Union or the European Economic Area, we will answer without undue delay and at the latest within one month of receiving the request, extendable by two further months if the matter is complex; in that case we would tell you within the first month and explain why.

If you reside in Mexico, we will communicate our determination within a maximum of twenty days of receiving the request, and give it effect within the following fifteen days. Both periods may be extended once, by an equal period, where the circumstances justify it.

Exercising these rights is free. Since everything is delivered by download or email, there are no reproduction or delivery costs to pass on.

What doesn't exist yet

There is no button in your account today to download your data or delete it. The only real route is to write to contact@paretolearn.com, and we do it by hand within the deadlines above. We are building account-level export and deletion; until they exist, we are not going to write that they do.

Legal basis: Arts. 22, 23, 24, 31, 33 and 34 LFPDPPP; arts. 12(3), 12(4) and 12(5) GDPR.

How we protect your data

Encryption, permissions that deny by default, and the smallest possible number of people with access.

  • All traffic runs over HTTPS, and the database is encrypted at rest and in transit.
  • Passwords are not stored: what is stored is their cryptographic derivation, which nobody on the team can reverse.
  • Tables holding personal data use row-level security that denies by default: without an explicit rule, nobody sees anything.
  • The service key that can bypass those rules lives only on the server, never in the browser and never in the code repository.
  • The whole site sits behind a global rate limit per IP address, the same for every route: there are no tighter limits on the sensitive endpoints yet, and adding them is still pending. Email verification at sign-up is switched on in our Supabase Auth configuration.
  • Only the project's partners have access to the database, under a duty of confidentiality that survives their leaving the project.

Note: We are not going to promise you absolute security, because nobody can. We are going to tell you what we do, and tell you if something fails.

Legal basis: Arts. 18 and 20 LFPDPPP; art. 32 GDPR.

What we do if there is a security breach

We tell you. We tell the authority where the GDPR requires it — or, if you are in the United States, your state's law.

If you reside in Mexico and a security breach occurs that significantly affects your economic or moral rights, we will notify you immediately, with the information you need to take action. Mexican law does not require notifying the authority, and we are not going to claim it does in order to look thorough.

Where the GDPR applies, we will notify the supervisory authority without undue delay and at the latest within 72 hours of becoming aware, and we will tell you where the risk to your rights and freedoms is high. We document every breach internally, whether or not it is notified.

If you reside in the United States, a breach is governed by your state's notification law. All fifty states have one and none of them exempts us for being small: what decides whether it reaches us is the activity we direct at that state, not our revenue. The pair we hold — your email together with the credential that opens your account — falls within those laws' definition of personal information; we store the password only as a cryptographic derivation, and even so we treat it as covered rather than argue about whether a hash is a password. Our commitment, whichever state you live in: we will notify you without delay and in no case later than thirty calendar days after we discover the breach or are notified of it. Notice to your state's authority does depend on which state it is, because neither the deadlines nor the thresholds line up: California requires a sample copy of the notification to be sent to the Attorney General within fifteen calendar days of notifying you, where more than five hundred residents of that state are affected (Cal. Civ. Code § 1798.82(a) and (f)); Vermont requires a preliminary notice to its Attorney General within fourteen business days and with no minimum number of affected residents; Texas, from two hundred and fifty affected residents. We will meet whichever deadline applies to your state; we are not going to write that one single standard covers all fifty.

Legal basis: Art. 19 LFPDPPP; arts. 33 and 34 GDPR; Cal. Civ. Code § 1798.82, as amended by Senate Bill 446, and the other U.S. state breach notification laws.

Minors

The service is not aimed at minors and we do not ask anyone's age.

Pareto Learn is not directed at minors and, in particular, it is not directed to children under thirteen, nor do we knowingly collect their personal information within the meaning of the United States Children's Online Privacy Protection Act and its implementing rule, 16 CFR Part 312. The service is intended for adults under the law of wherever you live. We do not ask for or verify anyone's age at sign-up, and we would rather say so than imply a control that doesn't exist. If we detect, or are told, that an account belongs to a child under thirteen, we delete it along with its data, no questions asked. If the account belongs to a minor aged thirteen or over, we delete it at the request of whoever holds parental responsibility or guardianship.

Automated decisions and profiling

There are no automated decisions about you. There are per-user activity statistics, and the GDPR calls that profiling: we say so rather than deny it. No decision affecting you comes out of those figures.

We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. What we do do, and would rather say plainly: for internal use we keep activity statistics per registered user — sessions, active time, distinct pieces of content, active days, completed reads, and the dates of first and last activity — tied to your account and not only to a browser pseudonym. The reading figures are only filled in if you accepted analytics; if you declined, your row is still there but at zero. They serve one purpose: knowing how many of the people who sign up actually get round to reading, and who comes back, and deciding from that what we build and publish next. That falls within the definition of profiling in art. 4(4) GDPR, so we are not going to write that we do not profile. What does not happen is any decision about you coming out of it: nothing we measure changes your plan, your limits, what you see or what you pay. The monthly read counter and the multiple-sign-up flag are fixed, checkable rules, not assessments of you as a person.

The multiple-sign-up flag, moreover, blocks nobody: it just tells us to look at it by hand. Behind a single IP address there may be an office, a university or an entire mobile network, and throwing real people out over that signal would cost far more than it would solve.

Legal basis: Arts. 4(4) and 22 GDPR; Article 29 Working Party Guidelines WP251rev.01 on automated individual decision-making and profiling, endorsed by the European Data Protection Board.

European Union / EEA

If you reside in the European Union or the EEA

Europe is not our market, but we do measure how people read and we do offer terms written for Union consumers. We apply the GDPR rather than argue about whether it reaches us.

We are established in Mexico and our main market is Mexico and Latin America. There are no euro prices, no European domain, no campaigns aimed at Union countries, and the English version is built for the United States. The fact that the site can be viewed from Europe, or that it is in Spanish, would not be enough to say we are “offering goods or services” to people in the Union within the meaning of art. 3(2)(a) GDPR: recital 23 says so itself. But there is one indication that does weigh, and we are not going to hide it: our terms include a section written specifically for Union consumers, with a fourteen-day right of withdrawal, and offering terms drafted for that audience is exactly the kind of signal that recital treats as evidence of envisaging offering services there.

What we do do, if you accept analytics, is measure your reading behaviour: active time, progress and sections reached, tied together by a persistent identifier. That may fall within the “monitoring of behaviour” of art. 3(2)(b). That is why we apply the GDPR to visitors from the Union: assuming it seems more honest than hunting for a loophole.

You may lodge a complaint with the supervisory authority of your country of residence, your place of work, or the place of the alleged infringement. The directory of authorities is published by the European Data Protection Board at edpb.europa.eu.

What doesn't exist yet

We have not yet designated a representative in the European Union, and this is no longer an open decision. We measure the reading behaviour of anyone who accepts analytics on a continuous — not occasional — basis, and we offer contract terms written specifically for Union consumers, so the exemption in art. 27(2) GDPR is not available to us and art. 27(1) requires us to designate one. We commit to doing so and to publishing the representative's name and address here as soon as we do; until then this is an unmet obligation and we state it as such. The alternative — stopping the measurement of European visitors and withdrawing the terms written for Union consumers — is also on the table, and if we choose it we will say so on this same page. We would rather write that here than sign a document declaring compliance that does not exist.

Legal basis: Arts. 3(2), 12, 13, 27, 77 and recitals 23 and 24 GDPR; European Data Protection Board Guidelines 3/2018 on territorial scope.

Mexico

If you reside in Mexico

This section completes the comprehensive privacy notice Mexican law requires, and tells you which authority to go to.

This document is the comprehensive privacy notice within the meaning of art. 15 LFPDPPP. Its minimum content is covered as follows: the controller's identity, under “Who the controller is”; the data processed and the fact that none of it is sensitive, under “What data we handle”; the purposes and which of them require your consent, under “What we use your data for”; the options for limiting the use or disclosure of your data, under “Consent” and in the cookie policy; the means for exercising your ARCO rights, under “How to exercise your rights”; and the procedure for communicating changes, in the final section. One element is missing: the controller's address required by section I is not published yet, so on that point this notice is incomplete — we say so here rather than treat it as covered. We will publish it once we have one.

Consent and its revocation. You may revoke, at any time and without retroactive effect, any consent you have given us, through the routes described under “Consent”. To limit the use or disclosure of your data you may use those same routes, and to stop receiving any commercial communication it is enough to reply to the email asking for it.

The competent authority for personal data held by private parties is now the Secretaría Anticorrupción y Buen Gobierno, through its Personal Data Protection Unit. INAI has been dissolved and is no longer the authority you can turn to. If you are not satisfied with our response to an ARCO request, you may bring a rights protection proceeding before that Secretariat within fifteen days of the date we communicate that response to you. And if we do not respond at all, that limit does not apply to you: you may bring it as soon as our response deadline expires, with no cut-off date, attaching the acknowledgement of the request you filed with us.

Transfer clause (art. 35 LFPDPPP)

Pareto Learn does not transfer your personal data to third parties other than those named under “Who we share your data with”. The providers listed as “providers working on our behalf” are not third parties: they are processors handling the data on our behalf and under our instructions, and passing data to them is not a transfer within the meaning of art. 2, section XX LFPDPPP, so it is not subject to your acceptance. If you do not wish your data to be transferred to the named third parties, write to contact@paretolearn.com. In practice, the most direct way to avoid the transfer to Amazon is not to click the bookstore links; the transfer to Google for fonts will disappear once we finish serving them from our own domain, and until then you can only avoid it by blocking those resources in your browser.

On cookies, the Mexican rule is to inform you at the moment they are used and to give you a way to disable them; it does not require prior consent the way European law does. We ask for prior consent anyway, because we also serve visitors from the European Union and because we prefer the more protective standard.

Legal basis: Arts. 7, 11, 15, 16, 19, 29, 35, 36 and 38 to 44 LFPDPPP; art. 14, third paragraph, of Mexico's 2011 LFPDPPP implementing regulation, whose status is uncertain and on which we rest no obligation by itself.

If you reside in the United States

One California law reaches us even though we are small, and we answer it here. The state privacy laws everyone names do not.

What does reach us. The California Online Privacy Protection Act, Cal. Bus. & Prof. Code §§ 22575–22579, applies to any commercial website that collects personal information from California residents, with no revenue, headcount or volume threshold. It applies to us, and it requires us to disclose two things. First: we do not respond to the browser's “Do Not Track” signal, because we do not track your activity across different sites and there would be nothing to switch off. Second: the only third-party resource the page loads is Google's fonts, which receive your IP address in that request and do not follow you from site to site. Both are set out in detail in the cookie policy.

What does not reach us, and why we say so anyway. We are not a “business” under the California Consumer Privacy Act: we do not have annual gross revenues above 26,625,000 dollars, we do not buy, sell or share the personal information of 100,000 consumers or households, and we derive no revenue at all from selling or sharing personal information. Those are the three thresholds in Cal. Civ. Code § 1798.140(d), and the revenue figure is adjusted by the California Privacy Protection Agency every odd-numbered year; the one in force applies from 1 January 2025. We meet none of the three, and not by a narrow margin. The other state privacy laws in force do not reach us either: some by threshold, and the ones without a threshold — Texas and Nebraska — through their small-business exception, which leaves a single obligation standing, not selling sensitive data without consent, and we process no sensitive data at all. We say this rather than advertise compliance that is not required of us today.

What we give you anyway. Free of charge and through the same route as everyone else: to know what data of yours we hold and get a copy, to correct it, to delete it, to take it with you in a machine-readable file, and not to be treated worse for asking. Write to contact@paretolearn.com. We do not sell or share your personal information within the meaning of those laws, and we never have. If we ever did, we would publish a “Do Not Sell or Share My Personal Information” link here before starting, not after.

If you are not satisfied with our answer, you may go to your state Attorney General or to the Federal Trade Commission. We do not point you to the California Privacy Protection Agency: its authority is exercised over “businesses” under the California statute, and we have just explained why we are not one.

What doesn't exist yet

We give you these rights voluntarily, and precisely for that reason we have to tell you what we handle them with: they are exercised by hand, by writing to us, and with the same gaps we admit under “How to exercise your rights”. There is still no button in your account to download your data or delete it. We do not want the one section where we promise polish to be the one that binds us least.

Legal basis: Cal. Bus. & Prof. Code §§ 22575–22579; Cal. Civ. Code § 1798.140(d), whose revenue threshold is adjusted under § 1798.199.95(d); Section 5 of the Federal Trade Commission Act.

Changes to this notice

We publish them here, with a new date, and if they matter we tell you before they take effect.

Any change to this notice is published on this same page and updates the “last updated” date shown above. If the change is substantial — a new purpose, a new third party, a longer retention period — we will tell you by email if you have an account, and by a visible notice on the site for at least thirty calendar days before it takes effect.

We keep previous versions of this document. If you want to know what it said the day you created your account, ask contact@paretolearn.com and we'll send it.

Legal basis: Art. 15 section VI LFPDPPP; art. 5(2) GDPR.

Contact

For anything related to this notice — exercising your rights, revoking a consent, asking us an uncomfortable question or pointing out a mistake — write to contact@paretolearn.com. A person answers, not a form.

How to verify what this document says

Every rule we cite was checked against its official text on the date of this version. These are the texts and their dates:

  • Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) — a new law published in the Official Gazette on 20 March 2025, in force since 21 March 2025, last amended 14 November 2025. It repealed the 2010 law, and the article numbering changed.
  • Mexico's Federal Consumer Protection Law (LFPC) — last amended in the Official Gazette on 12 December 2025, adding sections VIII and IX to art. 76 BIS on subscriptions with recurring charges.
  • Mexico's Federal Copyright Law (LFDA) — published in the Official Gazette on 24 December 1996, last amended in the Official Gazette on 14 May 2026.
  • Regulation (EU) 2016/679 (GDPR) — consolidated text, including the corrigendum published in OJ L 127 of 23 May 2018.
  • Directive 2002/58/EC on privacy and electronic communications, as amended by Directive 2009/136/EC, and its national implementing laws.
  • Directive 2011/83/EU on consumer rights, as amended by Directive (EU) 2019/2161.
  • California Civil Code § 1798.82 — as amended by Senate Bill 446, approved by the Governor on 3 October 2025 and in force since 1 January 2026, which replaced the “without unreasonable delay” standard with a thirty-calendar-day deadline from discovery for notifying consumers and added a fifteen-calendar-day deadline for the sample copy to the Attorney General.
  • California Online Privacy Protection Act — Cal. Bus. & Prof. Code §§ 22575–22579, with no applicability threshold.
  • California Consumer Privacy Act — Cal. Civ. Code § 1798.140(d), text in force. The revenue threshold in the definition of “business” is adjusted by the California Privacy Protection Agency every odd-numbered year under § 1798.199.95(d): 26,625,000 dollars from 1 January 2025, against the 25,000,000 the text of the section still states.
  • Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries — published in OJ L 199 of 7 June 2021.

Two points we do not treat as settled

  • Mexico's 2011 implementing regulation was never expressly repealed, but it develops a law that was, and the new regulation has not been published. We use it as an interpretive guide where it does not contradict the law in force, and we do not rest any obligation on it alone.
  • The 2021 EU Standard Contractual Clauses do cover an exporter that, like us, is not established in the Union but falls within the GDPR through its article 3(2): Clause 13(a) says so expressly. What is still open is something else: that clause makes the competent supervisory authority the one of the Member State where our representative in the Union is established, and we have not designated one yet, so Annex I.C is not settled. The additional set of clauses the Commission announced in 2022 addresses a different situation — an importer whose processing is already directly subject to the GDPR — we have no record that it was adopted, and we understand it does not concern us. We say it this way rather than claim the chain is seamlessly covered.
ParetoLearn

The 20% of concepts that give you 80% of the understanding.

Pareto Learn publishes original, independent explanations of ideas: it does not reproduce the books it references and is not affiliated with their authors or publishers.

Disclosure: book pages include affiliate links. If you buy through them, Pareto Learn may earn a commission at no extra cost to you. Amazon's programme is not approved yet, so today those links earn nothing.

© 2026 Pareto Learn. All rights reserved.