Incomplete document.
Missing the legal name, registered address and privacy contact email of the responsible company. Without those details this document is incomplete and the privacy notice does not satisfy article 15 of the LFPDPPP. They are set in the server’s .env and this message disappears.
Legal
Data processing agreement
Last updated: September 24, 2026
Version 2026-09-24.
1. The parties and their roles
[MISSING: legal name] (“Itzli”), with its address at [MISSING: registered address], acts as the data processor (“persona encargada”). The laboratory that subscribes to Itzli (“the Laboratory”) acts as the data controller (“responsable”) of the personal data of its patients and staff that it enters into the system, under Mexico’s Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP, the federal data protection law).
For any matter related to this agreement, the Laboratory can write to [MISSING: privacy email].
This agreement is part of the terms and conditions and is accepted together with them when the service is contracted; that is how its existence, scope and content are evidenced (article 51 of the LFPDPPP Regulations). Features that send images to an artificial intelligence provider additionally require express acceptance of this version from the panel (section 9).
This agreement sets out how Itzli processes the data the Laboratory entrusts to it. It does not certify the Laboratory, nor does it bring it into compliance with the LFPDPPP or any other standard: the controller’s obligations —its privacy notice, its patients’ consent, handling their rights— remain the Laboratory’s.
2. What data Itzli processes on the Laboratory’s behalf
The data that the Laboratory, its staff, its analyzers or its patients record in the Laboratory’s system:
- Its patients’ data: identification and contact details (name, date of birth, sex, phone, email, address), tax details when they request an invoice, orders and their tests, specimens, payments, and laboratory results, which are sensitive personal data (health status).
- Referring physicians’ data: name and contact details.
- Its staff’s data: name, email, phone, role, the professional license number of whoever reviews or releases results, and the record of their actions in the system.
- Documents the Laboratory uploads: expense receipts, supplier delivery notes, quality management system documents. They may contain third-party data —a reference laboratory’s invoice lists patient names—.
Excluded are the data of Itzli marketplace patient accounts and of site visitors: Itzli is the controller of those, and they are governed by its privacy notice.
3. What for, and what not for
Itzli processes that data solely to provide the service to the Laboratory:
- Recording orders, specimens, results and payments; receiving the results sent by analyzers; reviewing, releasing and delivering reports.
- Sending patients and physicians the notices the Laboratory triggers (email and phone notifications).
- Providing technical support when the Laboratory asks for it, and keeping the system secure and running.
- The artificial intelligence features the Laboratory expressly authorizes, under section 9.
Itzli does not use that data for its own purposes, does not sell it, does not use it for advertising, does not use it to train artificial intelligence models, and does not share it with any other laboratory: each laboratory sees only its own data.
4. The Laboratory’s instructions
Itzli processes the data according to the Laboratory’s instructions (article 50 of the Regulations). Instructions are this agreement and what the Laboratory configures in its panel: which of its staff sees what (roles and permissions), the language of its communications, which artificial intelligence features it authorizes, and any written instruction sent to the email in section 1. If Itzli considers that an instruction contravenes the law, it will tell the Laboratory before carrying it out.
5. Confidentiality
Itzli keeps the Laboratory’s data confidential, and requires the same of the people who work for Itzli and of its subprocessors, including after the relationship ends (article 20 of the LFPDPPP). Itzli staff access a laboratory’s data only when support, security or operation of the service requires it.
6. Security measures
These are the measures that exist in the system today. They are described as they are, including what does not exist yet, because the Laboratory needs that information to assess its own risk (article 18 of the LFPDPPP).
What exists
- Information travels encrypted (TLS) between devices and the server.
- The following are stored encrypted field by field: the data that identifies each user account (name, email, phone, professional license number, blood type and allergies), result values, the patient data stamped on each order, the data read from prescriptions, the recipients and subject of the emails the system sends, and the patient directory the Laboratory enters at its front desk (name, ID, contact details, address, billing data and notes). To search by name without decrypting the database, keyed fingerprints (HMAC) of each word are used, not the plain-text name.
- Each laboratory is isolated from the others, and access is resolved on the server by laboratory and by role.
- Reviewing or releasing a result requires a verified professional license number; each release records who signed it.
- Sensitive actions are recorded in a log that is append-only.
- Whoever administers the platform on Itzli’s side signs in with mandatory two-step verification; it is available for the Laboratory’s staff.
- The server’s internal services (database, cache) are not exposed to the internet.
- The entire database is encrypted at rest: tables, redo and undo logs, and the binary log. The master key lives in a volume separate from the data, on the same server.
What does not exist today
- The key for field-by-field encryption lives on the same server. It protects against a leaked copy of the database, not against someone who gained control of the server.
7. Subprocessors
To provide the service, Itzli relies on the providers in this list. By accepting this agreement, the Laboratory authorizes those subcontracts (articles 54 and 55 of the Regulations); each one processes the data only to provide its service. This is the list the system uses today, not a list of possible providers.
-
IONOS
- What for
- The server the system and its database run on, and the mail server the notices are sent through.
- What it receives
- All the data in section 2, because it is stored there; and the content of the emails the system sends.
- Where
- United States (server in Kansas City).
-
Google (Gmail)
- What for
- Receives a blind copy of every email the system sends, as a record of what was sent and to whom; and receives the emails sent to Itzli’s contact address.
- What it receives
- Recipient, subject and content of the emails: for example, the notice telling a patient their results are ready.
- Where
- United States and the countries where Google operates its data centers.
-
Expo (650 Industries)
- What for
- Delivers notifications to phones that have the app installed; it passes them to Apple or Google depending on the phone.
- What it receives
- The phone’s identifier and the notification’s title and text.
- Where
- United States.
-
OpenAI
- What for
- The artificial intelligence features the Laboratory authorizes. None is on by default.
- What it receives
- Only what the authorized purpose needs: aggregated business figures, quality management texts, the catalog, or the image of an expense receipt or delivery note (section 9). Never prescriptions or results.
- Where
- United States.
-
Stripe
- What for
- Bills the Laboratory’s subscription to Itzli.
- What it receives
- Billing data of the Laboratory and of the person who subscribes. It receives no patient data; it is listed so that the full picture is visible.
- Where
- United States.
The following are not used today, even though the system has room for them: WhatsApp messaging, CFDI stamping through an authorized provider (PAC), and online payments by patients. If any of them is turned on, or if a subprocessor is added or changed, Itzli will publish it on this page and notify the Laboratory administrator’s email at least 30 days in advance. If the Laboratory disagrees, it may object in writing; if no alternative is found, it may terminate the service without penalty.
8. The data leaves Mexico
All the subprocessors on the list are outside Mexico, starting with the server. Sharing data between a controller and its processor —and from the processor to its authorized subprocessors— is a remission (“remisión”), not a transfer: it does not require the data subject’s consent (article 2, section XX, of the LFPDPPP and article 53 of the Regulations). Even so, the Laboratory must state in its own privacy notice that its patients’ data is hosted abroad.
9. Artificial intelligence: nothing without express authorization
The panel’s artificial intelligence features stay off until the Laboratory turns them on. Each one is authorized separately, by purpose; authorizing one does not authorize another.
- Only the Laboratory’s primary administrator (the person who subscribed) can authorize them, from the “My lab” section of the panel. Who, when and the previous value are recorded in the log.
- Those that send an image —reading an expense receipt or a supplier delivery note— additionally require accepting this version of the agreement when turning them on. If the agreement changes version, those features switch off on their own until the new one is accepted.
- An image may carry patient data: a reference laboratory’s invoice usually lists them. If the Laboratory authorizes reading photos, it is responsible for not photographing documents with patient data, or for covering that data first.
- The provider may keep what it receives for up to 30 days for abuse monitoring, and its automated image review may keep an image for longer. Itzli has not contracted zero data retention with the provider; if it does, this page will say so.
- What belongs to the patient does not leave, with or without the Laboratory’s authorization: prescriptions, results, values, directory names, history. There is no switch for that.
- The Laboratory can turn off any feature at any time, from the same place. Turning it off stops further sending; what was already sent cannot be recalled from the provider.
10. Patients’ rights (ARCO)
Requests for access, rectification, cancellation or objection are handled by the Laboratory, as controller, within the legal time limits: a response within 20 business days at most and execution within the following 15 (article 31 of the LFPDPPP). Itzli assists it as follows:
- From the panel, the Laboratory can view and correct its patients’ data and download their reports.
- Whatever cannot be done from the panel, Itzli delivers or carries out upon the Laboratory’s written request within 10 business days at most.
- If a request reaches Itzli directly, Itzli forwards it to the Laboratory within 5 business days at most and does not answer it on its own.
- Released results and the record of who reviewed them are part of a record whose retention is required by health regulations; Itzli carries out a cancellation only on the Laboratory’s instruction.
11. If a security breach occurs
If Itzli confirms an unauthorized loss, theft, copy, access or alteration of the Laboratory’s data, it will notify the Laboratory without delay and no later than 72 hours after confirming it, at the primary administrator’s email. The notice will state, with what is known at that point: what happened, what data was compromised, what measures were taken, what the data subject can do to protect themselves, and whom to ask (article 65 of the Regulations). Informing affected patients falls to the Laboratory as controller (article 19 of the LFPDPPP); Itzli will give it the information it needs to do so.
12. Verification
The Laboratory may request in writing information about the measures on this page and how they were applied to its data, and Itzli will provide it. Upon request, Itzli will provide the records of its laboratory’s sensitive-action log. If an authority opens an inspection, Itzli will cooperate with the Laboratory and give it the information it holds. If an authority asks Itzli for the Laboratory’s data, Itzli will inform the Laboratory, unless the law prohibits it.
13. At termination: return and deletion
When the service ends, the Laboratory may request a full export of its data, which Itzli will deliver in a machine-readable format within 30 days at most. Afterwards, Itzli will delete the Laboratory’s data from its systems, except what a law requires it to keep, and will confirm the deletion in writing (article 50, section V, of the Regulations). Today, export and deletion are carried out by Itzli’s technical team on request, not by a button in the panel.
The obligation to retain the clinical record (NOM-004-SSA3-2012) is the Laboratory’s: exporting its data before requesting deletion is what allows it to meet that obligation.
14. If Itzli departs from the instructions
If Itzli were to use the data for a purpose other than the one instructed, or transfer it in breach of the Laboratory’s instructions, it would assume a controller’s obligations over that processing (article 53 of the Regulations), without prejudice to the terms and conditions.
15. Changes to this agreement
Each version is published on this page with its number. Changes that broaden what Itzli may do with the data —a purpose, a subprocessor— are announced 30 days in advance (section 7). Features that send images require accepting the current version again.
16. Governing law and authority
This agreement is governed by the Ley Federal de Protección de Datos Personales en Posesión de los Particulares published in the Diario Oficial de la Federación on March 20, 2025, and by its 2011 Regulations insofar as they do not conflict with it, until new ones are issued. The competent authority is the Secretaría Anticorrupción y Buen Gobierno (Ministry of Anti-Corruption and Good Governance), which took over the functions of the now-dissolved INAI.