Data Processing Notice

Maintained by Cyntar S.C., publisher of MagDIGuide.com.

Last updated: July 22, 2026

Data Controller

The data controller for personal data processed through MagDI Guide is Cyntar S.C., represented by Lic. Jorge Arriaga and located at Paseo de los Héroes 9111-100, Zona Urbana Río Tijuana, C.P. 22010, Tijuana, Baja California, México. Cyntar S.C. owns and publishes MagDI Guide. Privacy inquiries may be sent to privacy@magdiguide.com.

Nature and Purpose of the Website

MagDI Guide is an independent Cyntar S.C. educational and lead-generation website intended primarily for visitors in the United States and Canada. It provides general information and allows visitors to request contact from Cyntar personnel. It is not an emergency service and does not provide diagnosis or individualized medical advice through the website.

Contact and Inquiry Data

The contact form may collect your name, email address, telephone number, country or region, preferred communication method, and a general question. The site does not request medical records, diagnoses, laboratory results, medication lists, detailed medical history, BMI, prior-surgery details, or procedure-eligibility information. Visitors must not submit that information through the form, AI chat, ordinary email, SMS, or WhatsApp.

AI Chat Data

Bitrix24 provides the site’s AI-chat and CRM workflow. The chat may answer general educational questions and collect contact information so authorized Cyntar personnel can respond. It must not request medical history, diagnose, screen for eligibility, or recommend a treatment. Chat content and contact details are stored in Bitrix24 and are available only to authorized Cyntar personnel and approved technical service providers.

Information Voluntarily Included by a Visitor

A visitor may voluntarily include health-related information in a general question even though the site does not request it. When this occurs, Cyntar S.C. will limit use to responding to the inquiry, avoid using the information for advertising, and may ask the visitor to continue through an appropriate private channel. Visitors should not use the website to transmit medical records or urgent health information.

We may process IP address, device and browser type, operating system, referring page, pages viewed, approximate region, timestamps, consent choices, security events, and cookie or device identifiers. Necessary data supports security, page delivery, consent storage, and fraud prevention. Optional analytics, advertising, and personalization data is processed according to the visitor’s choices and applicable law.

We may process email, SMS, WhatsApp, and telephone contact details; opt-in wording; timestamps; source; message history; opt-out requests; suppression status; and evidence of consent. Cyntar personnel operate these channels manually through Bitrix24. No prerecorded voice, AI voice, automatic dialing, or automated marketing sequence is used.

Privacy-Request and Verification Data

When you submit a privacy, GDPR, international, Canadian, or ARCO request, we may process your identity and contact information, the request, information needed to locate relevant records, verification information, correspondence, and the outcome. Verification must be proportionate and used only to protect the request process.

Purposes of Processing

We process personal data to operate and secure the website; respond to inquiries; provide requested educational follow-up; allow Cyntar personnel to contact visitors; manage communication and cookie preferences; maintain consent and suppression records; measure site performance when permitted; measure Cyntar’s own advertising campaigns when permitted; prevent abuse; comply with law; establish or defend legal claims; and improve content and operations using limited or aggregated information.

Lawful Bases

Depending on the activity and jurisdiction, processing may rely on consent; steps taken at your request; performance of an agreement; compliance with a legal obligation; protection of legal rights; or legitimate interests such as securing the site, responding to inquiries, preventing abuse, and improving operations, provided those interests are not overridden by applicable rights.

Recipients and Service Providers

Only authorized Cyntar S.C. personnel receive and manage MagDI Guide leads. Cyntar does not sell leads or send them to OCC, Ariel Center, outside providers, manufacturers, brokers, or referral partners. Service providers may process limited information to support the website: GoDaddy for hosting and infrastructure; Bitrix24 for CRM, AI chat, and communications; Google for Google Analytics 4, Google Ads, and Google Tag Manager; Meta Platforms for Meta Pixel; Microsoft for Clarity; and the consent-management provider selected before launch. Professional advisers or public authorities may receive information when required by law.

Advertising and Measurement Platforms

When advertising consent or another legally valid permission applies, Google Ads and Meta Pixel may receive limited technical and generic conversion information. MagDI Guide does not intentionally send names, telephone numbers, email addresses, chat content, form contents, medical conditions, procedure interests, or other sensitive data to advertising platforms. The website does not display third-party ads, host paid manufacturer promotions, or receive referral fees.

International Processing and Transfers

Cyntar S.C. is established in Mexico. GoDaddy, Bitrix24, Google, Meta, Microsoft, and their approved subprocessors may process data in the United States, Canada, Mexico, the European Economic Area, or other countries where they operate. When applicable law requires a transfer safeguard, Cyntar S.C. will use an available contractual or legal mechanism and will assess the relevant provider terms.

Contact-Inquiry Retention

General inquiries, contact information, and related correspondence are normally retained for up to 24 months after the last meaningful interaction, unless a longer period is reasonably necessary to complete an active request, comply with law, resolve a dispute, or establish or defend legal claims.

Chat Retention

General chat transcripts are normally retained for up to 12 months after the last interaction. A shorter period should be used when a transcript contains information that is not needed for follow-up.

Necessary cookie data is retained for the browser session or for up to 12 months depending on function. GA4 first-party cookies may last up to two years. Clarity playback data is generally retained for 30 days, while selected or aggregated interaction data may be retained for up to nine months. Google and Meta advertising-measurement cookies used on the site generally last up to 90 days. The live cookie inventory controls if a shorter provider duration applies.

Consent and opt-out evidence may be retained for the duration of the permission and for up to five years afterward when reasonably necessary to demonstrate compliance, resolve a dispute, or meet legal obligations. Suppression records may be retained as long as needed to prevent an unwanted marketing channel from being reactivated.

Privacy-Request Retention

Privacy-rights requests, correspondence, and outcomes are normally retained for up to five years after closure. Identification documents, if exceptionally required, should be deleted earlier when they are no longer needed for verification.

Security-Log Retention

Security, fraud-prevention, and access logs are normally retained for up to 12 months, unless a longer period is required to investigate an incident, comply with law, or protect legal rights.

Automated Decision-Making

MagDI Guide does not use solely automated decision-making that produces legal or similarly significant effects. The Bitrix24 AI chat may provide general information or route an inquiry, but it does not diagnose, determine procedure eligibility, make clinical decisions, or deny access to services.

Your Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal data; withdraw consent; limit certain advertising disclosures; or complain to a regulator. EU, EEA, UK, Canadian, and equivalent international requests may be submitted through GDPR / International Data Request. Requests under Mexico’s private-sector data-protection law may be submitted through ARCO Rights Request.

Security

Cyntar S.C. uses administrative, technical, and physical measures designed to protect personal data, including encryption in transit, access controls, least-privilege access, multifactor authentication where available, vendor review, audit logging, backups, suppression controls, and documented retention procedures. No system can guarantee absolute security.

Contact Us

Contact the MagDI Guide privacy lead at privacy@magdiguide.com, or write to Cyntar S.C., Attn: Lic. Jorge Arriaga, at Paseo de los Héroes 9111-100, Zona Urbana Río Tijuana, C.P. 22010, Tijuana, Baja California, México.

Book Consultation