Privacy Policy

Last updated: SEPTEMBER 15, 2026

This document is published in English. English is the authoritative version.

Pursuant to the provisions of (i) the Federal Law on the Protection of Personal Data Held by Private Parties (the “LFPD”); (ii) the Regulations of the LFPD; and (iii) the Privacy Notice Guidelines published in the Official Gazette of the Federation, Payroll Software & Services S de RL de CV (“Runa HR”), as the Controller of the personal data it collects, makes this Privacy Policy (the “Policy”) available to its customers and users of digital platforms (each referred to as the “Owner”).

Runa HR requires certain personal data to be processed in order to be able to create profiles for interested customers, improve, personalize and provide various products and services, set up customer accounts and profiles, and send promotional offers. Runa HR may obtain this data through:

  • (i) its website(s) and landing page(s) (the “Site”)
  • (ii) any link, microsite or access directly related to the Site and
  • (iii) software as a service called “Runa HR HR” (the “Platform”).

Runa HR reserves the right to modify the content of this Policy at any time. Any change to the Notice will be communicated to the Owner through a general notification on the Site and/or the Platform. The corresponding modification will take effect from the day following its publication.

I. Identity and address of Runa HR

Runa HR is a commercial company duly incorporated in accordance with Mexican law.

Runa HR’s address is located at Av Isaac Newton 82 Int 1, Polanco, Miguel Hidalgo, Ciudad de México, México, 11560.

II. Personal Data subject to processing

The Personal Data that Runa HR will process:

  • Personal information including: Name, gender, date of birth, social security number, federal taxpayer registration (“RFC”), telephone number and email; and
  • Information on the person’s bank account

The Client acknowledges that the aforementioned Personal Data may be stored using cloud storage. Where applicable, Runa HR will ensure that the corresponding provider complies with the provisions of the LFPD Regulations.

Runa HR will at no time collect data from the Client that may be considered sensitive, in accordance with the LFPD or its Regulations.

III. Purpose of processing data

The Personal Data processed by Runa HR will be used to carry out the following purposes:

Primary purposes

  • Identify the Owner;
  • Improve, personalize and provide various products and services to the Owner;
  • Configure the Owner’s account.
  • If they transfer personal data, they must establish a checkbox for the express acceptance of the terms and conditions of the privacy notice.

Secondary purposes

  • Provide training and -in general- content of interest or use to the Owners; and
  • Use the Personal Data for marketing, advertising or commercial prospecting purposes.

The Owner may express their refusal to the processing of their data for secondary purposes by sending an email to that effect to info@runahr.com, which must contain their contact information and any other information that allows a response to said report, refraining from providing confidential information of which they are not the Owner or of which they are not authorized to transfer.

IV. Consent of the Owner

The Owner declares that:

  • This Policy has been made known to him/her by Runa HR:
  • He/she has read, understood and agreed to the terms set forth in this Notice, and therefore gives his/her consent regarding the processing of his/her Personal Data, specifically regarding the purpose related to the transfer of his/her data, and;
  • The use of the Site and/or the Platform constitutes tacit confirmation of his/her consent to the provisions of this Policy. The Owner must refrain from continuing to use the Site and/or the Platform if he/she does not consent to the provisions set forth in this Policy.

Runa HR assumes that the information provided by the Owner belongs to the latter. If this is not the case, the Owner must immediately inform Runa HR of this circumstance by sending an email to info@runahr.com, which must contain their contact information and any other information that allows them to respond to this report, refraining from providing additional information that they are not the Owner of or that they are not authorized to transfer.

The Owner may revoke the aforementioned consent at any time. To revoke the consent provided, the Owner must communicate this circumstance to Runa HR by sending an email to info@runahr.com indicating the reasons that motivate them to communicate the revocation, as well as the information that allows Runa HR to respond and follow up on said revocation.

If the Owner wishes to limit the use or disclosure of any of his/her Personal Data, he/she may at any time send a statement of such limitation by sending an email to info@runahr.com, which will include the Personal Data whose processing he/she wishes to limit, the reasons for which he/she wishes to limit it, as well as the information that will allow Runa HR to follow up on said request. If the Owner’s request is granted, Runa HR will register the Owner on the exclusion list that it will have prepared for this purpose.

V. Rights of Access, Rectification, Cancellation and Opposition (“ARCO”).

The Owners have the right to:

  • Know what Personal Data is processed by Runa HR and the purposes of its processing (right of access);
  • Request the correction of their Personal Data if it is outdated, inaccurate or incomplete (right of rectification);
  • Have their Personal Data deleted from Runa HR’s records or databases when they consider that it is not being used appropriately (right of cancellation); and
  • Oppose the use of your Personal Data for specific purposes (right to object) (collectively, the “ARCO” rights)

The ARCO rights may be exercised at any time by sending an email to info@runahr.com. The request for any of the ARCO rights must be accompanied by the following:

  • The name of the Owner and/or his/her address or email address, so that Runa HR can communicate the response to your request;
  • The documents that prove the identity or, where applicable, the legal representation of the Owner;
  • The clear and precise description of the Personal Data in respect of which you seek to exercise any of the ARCO rights;
  • The reasons that support or justify the exercise of the corresponding ARCO right;
  • The format or medium in which you want Runa HR to respond to your request, when applicable;
  • Any other element or document that facilitates the follow-up to the Owner’s request.

VI. Use of cookies, web beacons or similar or analogous technologies.

Runa HR may use cookies, web beacons and other technologies to monitor your behavior as an Internet user, in order to provide you with a better service and user experience when browsing the Site and/or the Platform, as well as to offer you new products based on your preferences. The Personal Data that Runa HR obtains from these tracking technologies are particularly the following: browsing time, browsing time, sections consulted and previously accessed Internet pages, IP address of origin, browser used, operating system, making it possible to monitor your behavior as a user of Internet services.

VII. Google Calendar integration

Runa GO offers an optional integration with Google Calendar. This section describes exactly what that integration does and what data it touches.

How it is enabled

The integration is opt-in and is enabled at the organization level. An account administrator at the Client connects a single Google account through Google's OAuth consent flow. Individual Owners are not asked to connect their own Google accounts, and the integration is not required in order to use the Platform.

What Runa GO can access

Runa GO requests only scopes that Google classifies as non-sensitive. The calendar access described below is governed by https://www.googleapis.com/auth/calendar.app.created. Alongside it, Runa GO requests the standard identity scopes — https://www.googleapis.com/auth/userinfo.email (equivalently expressed as openid and email) and https://www.googleapis.com/auth/userinfo.profile, which Google includes by default for applications listed on the Google Workspace Marketplace — solely in order to identify the Google account making the connection.

This scope permits an application to create secondary Google calendars and to manage events on calendars it has created. It grants no access whatsoever to any calendar or event that existed beforehand, including the connecting administrator's own primary calendar. Using this scope, Runa GO:

  • Creates one shared calendar for the Client's organization, used solely for this feature.
  • Creates, updates and deletes events on that calendar to reflect absences approved on the Platform.

Runa GO cannot read, modify or delete any other calendar or event in the connected Google account, because the scope granted does not allow it. It cannot list the calendars in that account, and it never reads the content of events it did not itself create.

From those identity scopes Runa GO reads and retains exactly one item: the e-mail address of the Google account used to make the connection, so that the connection can be displayed in the Platform and attributed to the administrator who created it. Runa GO does not use or retain any other information associated with that account — no name, photograph or contact list — even where the scope granted would permit it.

What appears on the shared calendar

Only absences under time-off policies that an account administrator has explicitly enabled for calendar display are published. This setting is off by default for every policy. Event titles default to a neutral form such as “Ana García — Out of office”, and the name of the time-off policy is not shown unless an administrator separately chooses to include it. This is intended to avoid disclosing the reason for an absence, including any absence relating to health.

The shared calendar is intended to be made visible to the Client's personnel. Sharing is carried out by the account administrator within Google Calendar; Runa GO cannot grant calendar access on the Client's behalf. Owners whose absences are published should understand that their name and the dates of their absence will be visible to the colleagues with whom the Client shares that calendar.

Limited use

Calendar data is used solely to operate the feature described above. Runa HR does not:

  • Read, access or store the content of any calendar event other than those Runa GO itself created.
  • Use calendar data for advertising, marketing, commercial prospecting or profiling.
  • Use calendar data to train generalised artificial intelligence or machine learning models.
  • Sell calendar data, or transfer it to third parties other than as strictly necessary to operate the feature.

Runa HR's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Storage and retention

The OAuth refresh token obtained when the calendar is connected is encrypted at rest using AES-256-GCM authenticated encryption. Runa GO does not store Google access tokens; they are obtained from Google as needed and held only in memory for the duration of a request. Within the Platform, Runa HR retains only the minimum metadata needed to link a leave request to the calendar event created for it — in practice, the event identifier assigned by Google. Events created on the shared calendar continue to exist in Google Calendar after Runa GO creates them, subject to Google's own retention policies.

Disconnecting and revoking access

An account administrator may disconnect the integration at any time from the shared calendar settings in the time-off section of the Platform, at which point the stored credentials are deleted and synchronization stops. Credentials are also deleted when the Client's company account is deleted.

Disconnecting prevents Runa GO from using the connection, but it does not by itself withdraw the authorization recorded by Google, and it does not remove events already created on the shared calendar. To withdraw the authorization, the connected Google account should also revoke Runa GO's access at https://myaccount.google.com/permissions. The shared calendar and the events on it may be deleted from within the Platform, or directly in Google Calendar.

Google as an independent controller

Google is an independent controller of the Personal Data held in the connected Google account. Runa HR's processing of calendar data is limited to what is described in this section; any other processing by Google is governed by Google's own privacy policy, and not by this Policy.