Privacy Policy
Effective Date: May 10, 2026
Last Updated: July 16, 2026
This document is only available in English.
At a Glance
| What | Details |
|---|---|
| Who we are | Jesús Hernández Cabañas, operating under the trade name Delph-AI (Mexico) |
| What we do | AI-powered systematic literature review screening |
| What data we collect | Name, email, organization, title, country (account); titles and abstracts (research data); IP, browser (technical) |
| Why | To provide, secure, and improve the Service |
| AI processing | We send only titles and abstracts to AI models — never your personal data |
| Who we share with | AI providers, cloud infrastructure, payment providers — see Service Providers & Sub-Processors |
| How long we keep it | Active account: while active. After deletion: personal data anonymized after 90 days. Billing: 7 years |
| Your rights | Access, correct, delete, port, object — email privacy@delph-ai.org |
| Cookies | Essential only (authentication, session). No tracking or analytics cookies |
For complete details, please read the full policy below.
Table of Contents
- Who We Are
- Scope
- Data We Collect
- How We Use Your Data
- AI Processing
- Service Providers, Sub-Processors, and International Transfers
- Data Retention
- Your Rights
- Cookies and Similar Technologies
- Security
- Children's Privacy
- Changes to This Policy
- Additional Information for EEA Residents
- Additional Information for Brazil Residents
- Additional Information for Mexico Residents
- Additional Information for California Residents
- Contact Us
1. Who We Are
Delph-AI ("Delph-AI," "we," "us," or "our") is the data controller responsible for processing your personal data when you use the Delph-AI platform and related services (the "Service").
| Details | |
|---|---|
| Legal entity | Jesús Hernández Cabañas, operating under the trade name Delph-AI |
| Address | Gustavo Díaz Ordaz 204, Col. Francisco Villa, Xalapa, Veracruz, C.P. 91173, México |
| Privacy contact | privacy@delph-ai.org |
| EU Representative (GDPR Art. 27) | The Service is currently not directed at EEA residents (see Terms of Service §1.6). An EU Representative has not been designated. When the Service becomes available in the EEA, one will be appointed. Questions may be directed to privacy@delph-ai.org. |
| Data Protection Contact (LGPD Art. 41) | privacy@delph-ai.org |
2. Scope
This Privacy Policy applies to all personal data we collect and process when you:
- Visit our website (www.delph-ai.org);
- Create an Account and use the Service;
- Contact us via email or support channels;
- Subscribe to our communications.
This Privacy Policy does not apply to third-party websites, services, or applications linked from our Service. We encourage you to review the privacy policies of any third-party services you access.
Note for EEA residents: The Service is currently not directed at residents of the European Economic Area (EEA). If your country of residence or primary place of business is in the EEA, you are not eligible to use the Service at this time (see Terms of Service, Section 1.6). If you have questions, contact privacy@delph-ai.org.
Territorial scope and lawful bases: Delph-AI is operated from Mexico. Any references in this Privacy Policy to the GDPR, UK GDPR, LGPD, CCPA, or similar laws apply only to the extent those laws apply to our processing of your personal data and do not expand the geographic availability of the Service or constitute an offer of goods or services in those jurisdictions. The lawful bases listed in this Policy are provided as a transparency measure and do not create rights or obligations beyond applicable law.
Hosting location: We currently host core infrastructure in Google Cloud's Belgium region (europe-west1). Our choice of infrastructure region is based on security, resilience, and latency considerations, and does not mean that the Service is directed to, marketed to, or available in that region.
3. Data We Collect
3.1. Data You Provide
| Category | Data | Required? | Lawful Basis |
|---|---|---|---|
| Identity | First name, last name, email address | Yes | Performance of contract |
| Professional | Academic title, position, organization, country | Optional | Consent (provided voluntarily by you) |
| Use case | Type of research (e.g., biomedical, social science) | Optional | Consent (provided voluntarily by you) |
| Research data | Bibliographic records (titles, abstracts, authors, metadata) uploaded as datasets | By user action | Performance of contract |
| Screening configuration | Inclusion/exclusion criteria, AI model selection | By user action | Performance of contract |
| Payment | Transaction and subscription identifiers from our Merchant of Record, and limited billing metadata such as name, email, billing country, order ID, subscription status, and transaction amount for fulfillment and support purposes. For approved SPEI/CFDI payments: bank transfer references and tax invoicing data such as RFC, legal name, tax regime, and fiscal postal code. We never receive or store your full credit card number, CVV, or raw payment card data | When purchasing | Performance of contract + Legal obligation |
| Communications | Content of emails or messages you send to us | When you contact us | Legitimate interest |
3.2. Data We Collect Automatically
| Category | Data | Lawful Basis |
|---|---|---|
| Authentication | Firebase UID, session token (stored in __session cookie) | Legitimate interest |
| Technical | IP address, browser type, operating system, referring URL | Legitimate interest |
| Usage | Login timestamps, pages visited within the dashboard | Legitimate interest |
3.3. Data We Do NOT Collect
We do not collect:
- Full credit card numbers, CVVs, or raw payment card data (handled by the applicable Merchant of Record and its payment partners, not by Delph-AI);
- Health data, genetic data, biometric data, or any special categories of personal data under GDPR Article 9;
- Data about children under 16;
- Location data (beyond IP-derived country);
- Social media activity or browsing history outside our Service.
Sensitive personal data: Delph-AI does not require or intentionally collect sensitive personal data from account users. Users must not upload patient-identifiable information or other sensitive personal data into the Service. Research records should be limited to public bibliographic metadata (titles, abstracts, authors), screening criteria, model selections, and screening outputs.
4. How We Use Your Data
| Purpose | Data Used | Lawful Basis | Necessary or Optional (LFPDPPP) |
|---|---|---|---|
| Create and manage your Account | Identity, authentication | Performance of contract | Necessary |
| Process Screenings (send bibliographic data to AI Models) | Research data, screening configuration | Performance of contract | Necessary |
| Process payments | Transaction identifiers, billing and tax information | Performance of contract + Legal obligation | Necessary |
| Provide customer support | Identity, communications | Performance of contract | Necessary |
| Send transactional emails (screening completed, payment receipt) | Identity (email) | Performance of contract | Necessary |
| Maintain security and prevent fraud | Technical data, authentication, login history | Legitimate interest | Necessary |
| Personalize the Service (language, preferences) | Configuration data | Performance of contract | Necessary |
| Comply with tax and legal obligations | Billing data | Legal obligation | Necessary |
| Improve the Service (using aggregated, anonymized data only) | Anonymized usage patterns | Legitimate interest | Optional |
| Analytics (if added in the future) | To be determined | Consent | Optional |
| Marketing communications (if added in the future) | Consent | Optional |
We will never use your personal data for purposes not listed above without informing you and, where required, obtaining your consent.
5. AI Processing
5.1. What Technology We Use
Delph-AI uses multiple large language models (LLMs) from different providers to evaluate bibliographic records (titles and abstracts) during the screening phase of systematic literature reviews. We use a multi-model consensus method inspired by the Delphi method, in which multiple AI models independently evaluate each record and a weighted agreement determines the final classification.
5.2. What Data AI Models Process
AI models process only:
- Titles of academic publications;
- Abstracts of academic publications;
- Inclusion and exclusion criteria defined by you.
AI models never process:
- Your name, email address, or any account data;
- Your payment information;
- Your IP address or technical data;
- Any personally identifiable information.
5.3. How AI Decisions Are Made
Each bibliographic record is independently evaluated by multiple AI models against your criteria. Each model produces a binary judgment (include or exclude). A weighted consensus mechanism (Agreement Rate) determines the final classification. The Agreement Rate is a value between 0 and 1, calculated using only valid, successfully parsed model responses — responses that cannot be parsed into a valid include or exclude judgment are excluded from the calculation. A high Agreement Rate reflects consensus among valid responses and does not necessarily mean that every selected model returned a usable response.
You can review all evaluations, modify classifications, and create alternative versions of results. AI evaluations are tools to support your research, not final determinations.
5.4. AI Evaluations Do Not Affect You Personally
Delph-AI uses automated processing and AI-assisted methods to classify and screen bibliographic records (academic publications), not people. These outputs are decision-support tools and are not intended to make decisions about individuals that produce legal or similarly significant effects. You always retain full control over the final inclusion and exclusion decisions in your systematic review.
5.5. We Do Not Train AI Models with Your Data
Delph-AI does not use your data to train, fine-tune, or improve any AI model. We use contractual restrictions, provider settings, or routing controls to prevent training or non-transient data retention where these protections are available and verified for each provider. We do not represent that a provider is subject to a no-training commitment unless that commitment has been contractually confirmed or technically enforced for our integration. For the current no-training status of each provider, see our Service Providers & Sub-Processors page.
5.6. AI Providers
We currently use AI models from the following providers:
| Provider | Models | Data Location |
|---|---|---|
| OpenAI | GPT-4 series (see Sub-Processors for current versions) | US (EU data residency available) |
| Anthropic | Claude series (see Sub-Processors for current versions) | US |
| Google (Vertex AI) | Gemini series (see Sub-Processors for current versions) | Belgium for Gemini 2.5; US or global for other models (varies by model) |
| Mistral | Mistral series (see Sub-Processors for current versions) | EU (Paris, France) |
| xAI | Grok series (see Sub-Processors for current versions) | US (EU endpoint available) |
| DeepSeek (direct API) | DeepSeek V4 series (see Sub-Processors for current versions) | People's Republic of China |
| Meta (model developer; via Vertex AI) | Llama 4 series (see Sub-Processors for current versions) | US (via Google Vertex AI MaaS) |
| Alibaba Cloud (model developer; via Vertex AI) | Qwen3 series (see Sub-Processors for current versions) | US / Global (via Google Vertex AI MaaS) |
For the complete and current list, see our Sub-Processors page.
6. Service Providers, Sub-Processors, and International Transfers
6.1. Service Providers and Sub-Processors
We use the following categories of third-party service providers (sub-processors) to operate the Service:
| Category | Provider | Purpose | Location |
|---|---|---|---|
| Cloud infrastructure | Google Cloud Platform | Hosting (Cloud Run, Cloud SQL) | EU (Belgium — europe-west1) |
| AI Models | Google Vertex AI | AI model inference (including partner models) | Belgium / US / Global (varies by model and partner) |
| AI Models | OpenAI | AI model inference | US / EU |
| AI Models | Anthropic | AI model inference | US |
| AI Models | Mistral | AI model inference | EU (France) |
| AI Models | xAI | AI model inference | US |
| AI Models | DeepSeek (direct API) | AI model inference | China |
| AI Models | Meta (model developer; via Vertex AI MaaS) | AI model inference (partner model) | US |
| AI Models | Alibaba Cloud (model developer; via Vertex AI MaaS) | AI model inference (partner model) | US / Global |
| Authentication | Firebase (Google) | User authentication | US |
| Payments (MoR) | Dodo Payments Inc. | Merchant of Record — checkout, billing, taxes, refunds | US |
| Payments (MoR backup) | Paddle | Merchant of Record — checkout, billing, taxes, refunds | US / Canada / UK |
| Resend | Transactional email delivery | US |
For the complete list with DPA links and transfer mechanisms, see our Service Providers & Sub-Processors page. We will update that page when we add or change providers.
6.2. International Data Transfers
Delph-AI operates from Mexico. Because we and some of our sub-processors are located outside the European Economic Area (EEA), your data may be transferred internationally. We ensure adequate protection through:
| Mechanism | Description |
|---|---|
| Standard Contractual Clauses (SCCs) | EU-approved contractual clauses (Commission Implementing Decision 2021/914) included in our agreements with sub-processors outside the EEA |
| EU-US Data Privacy Framework (DPF) | For sub-processors certified under the DPF (e.g., Google) |
| EU-Brazil Adequacy Decision | Mutual recognition of adequacy between the EU and Brazil (ANPD Resolution CD/ANPD No. 32, January 2026) eliminates the need for SCCs for EU-Brazil transfers |
| Adequate jurisdiction | For sub-processors in EU member states (Mistral in France, GCP in Belgium) |
We do not transfer your data to any country without ensuring appropriate safeguards are in place.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy. Specific retention periods:
| Data | Retention Period | Basis |
|---|---|---|
| Active account data (name, email, profile) | While your account is active | Contract performance |
| Personal data after account deletion | Anonymized after 90-day grace period | GDPR Art. 17 — right to erasure |
| Projects after deletion | Restorable for 60 days, then anonymized | Business purpose + user convenience |
| Screenings after deletion (non-draft) | Restorable for 30 days, then anonymized | Business purpose + user convenience |
| Draft Screenings after deletion | Immediately and permanently deleted | No retention needed |
| Bibliographic records (titles, abstracts) | Retained indefinitely in anonymized form | Public academic data, de-identified |
| Billing, tax, and transaction data (including Mexican CFDI invoices where applicable) | Up to 7 years from the transaction date, unless a longer period is legally required | Legal obligation (e.g., Mexican Federal Tax Code) |
| Security and audit logs | Maximum 12 months | Legitimate interest (security) |
| Session cookies | Duration of the browser session | Functionality |
Anonymization process: After the grace period expires, we will anonymize your personal data by replacing identifying fields (name, email, organization, title, position, country) with null values or irreversible hashes. Once anonymized, data cannot be re-associated with you.
Blocking prior to deletion: Where required by applicable law (including applicable Mexican privacy law), Delph-AI will apply a blocking period to relevant personal data following a deletion or cancellation request, during which the data is restricted from ordinary processing and retained solely to address potential legal obligations or claims arising from its prior processing. The restoration grace period described above is an operational recovery period and is separate from any legally required blocking period. Upon completion of any applicable blocking period, personal data will be anonymized or deleted in accordance with this Section.
8. Your Rights
You have the following rights regarding your personal data. To exercise any of these rights, contact us at privacy@delph-ai.org. We will respond within 30 days of receiving your verified request, or sooner where required by applicable law.
| Right | Description | GDPR | LGPD | LFPDPPP | CCPA |
|---|---|---|---|---|---|
| Access | Obtain a copy of your personal data | ✓ | ✓ | ✓ (ARCO) | ✓ |
| Rectification | Correct inaccurate or incomplete data | ✓ | ✓ | ✓ (ARCO) | ✓ |
| Erasure ("right to be forgotten") | Request deletion of your personal data | ✓ | ✓ | ✓ (ARCO — "Cancelación") | ✓ |
| Portability | Receive your data in a structured, machine-readable format | ✓ | ✓ | — | — |
| Restriction | Limit how we process your data | ✓ | ✓ (blocking) | — | — |
| Objection | Object to processing based on legitimate interest | ✓ | ✓ | ✓ (ARCO — "Oposición") | — |
| Withdraw consent | Revoke consent previously given | ✓ | ✓ | ✓ | — |
| Opt-out of sale | We do not sell your data | — | — | — | ✓ (N/A — we don't sell) |
| Non-discrimination | We will not discriminate against you for exercising your rights | — | — | — | ✓ |
| Not be subject to solely automated decisions | Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to applicable exceptions and safeguards | ✓ (Art. 22) | — | — | — |
| Request review of automated decisions | Request human review of decisions made solely on automated processing of personal data that affect your interests | — | ✓ (Art. 20) | — | — |
| Object to qualifying automated processing | Object where automated processing, without human intervention, evaluates personal aspects and produces unwanted legal effects or significantly affects your interests, rights, or freedoms | — | — | ✓ (Art. 26-II) | — |
How to exercise your rights:
- Send an email to privacy@delph-ai.org specifying which right you wish to exercise;
- We will verify your identity before processing your request;
- We will respond within 30 days of receiving your verified request, or sooner where required by local law;
- There is no fee for exercising your rights;
- If we cannot fulfill your request, we will explain why.
Right to complain: You have the right to lodge a complaint with your local data protection authority. For EEA residents, see Section 13. For Brazil residents, see Section 14.
9. Cookies and Similar Technologies
9.1. Cookies We Use
We use only strictly necessary cookies that are essential for the Service to function:
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
__session | Firebase authentication token | Essential | Session |
| Payment checkout cookies (Dodo Payments, Paddle) | Payment processing, fraud prevention, checkout security | Essential | Session / persistent, as determined by the provider |
| Framework session cookies | Application state, CSRF protection | Essential | Session |
9.2. No Tracking or Analytics Cookies
As of the effective date of this Privacy Policy, we do not use:
- Analytics cookies (Google Analytics, Mixpanel, PostHog, etc.);
- Advertising or remarketing cookies;
- Social media tracking pixels;
- Any other non-essential cookies.
If we introduce non-essential cookies in the future, we will: (a) update this Privacy Policy; (b) implement a cookie consent banner with granular opt-in controls; and (c) obtain your explicit consent before placing any non-essential cookies.
9.3. Do Not Track
Because we do not use tracking cookies or third-party analytics, the Do Not Track (DNT) browser signal is not applicable to our Service.
10. Security
We implement appropriate technical and organizational measures to protect your personal data, including:
| Measure | Description |
|---|---|
| Encryption in transit | All data transmitted over HTTPS/TLS |
| Encryption at rest | AES-256 encryption (Google Cloud Platform default) |
| Authentication | Firebase Authentication with ID tokens; no passwords stored by Delph-AI |
| Payment security | Merchant of Record checkout and tokenization — we never receive or store card data. Our Merchant of Record partners maintain PCI-DSS compliance for payment processing |
| Access control | Role-based access, principle of least privilege |
| Input validation | All user inputs validated and sanitized (Zod) |
| Security headers | Content Security Policy (CSP), HSTS, X-Frame-Options, X-Content-Type-Options |
| Infrastructure | Google Cloud Platform with automated security patching |
No system is perfectly secure. While we take commercially reasonable measures to protect your data, we cannot guarantee absolute security. If you become aware of a security vulnerability, please report it to security@delph-ai.org.
11. Children's Privacy
The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that data promptly. If you believe we have collected data from a child under 16, please contact us at privacy@delph-ai.org.
12. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes:
(a) We will provide at least 30 days' notice via the email address associated with your Account and a prominent banner within the Service;
(b) The notice will include a summary of the changes and a link to the updated policy;
(c) Your continued use of the Service after the notice period constitutes acceptance of the updated policy;
(d) We will make previous versions of this policy available upon request where reasonably practicable.
13. Additional Information for EEA Residents
If you are located in the European Economic Area (EEA), the following additional information applies:
13.1. Legal Bases for Processing
We process your personal data based on the legal bases described in Section 3 and 4, primarily:
- Performance of a contract (Art. 6(1)(b)): to provide the Service you have signed up for;
- Legitimate interest (Art. 6(1)(f)): for security, fraud prevention, and service improvement, where our interests do not override your rights;
- Legal obligation (Art. 6(1)(c)): for tax and regulatory compliance;
- Consent (Art. 6(1)(a)): for any future analytics or marketing communications (we will ask for your explicit opt-in).
13.2. EU Representative
The Service is currently not directed at EEA residents (see Terms of Service §1.6 and Section 2 of this Privacy Policy). Delph-AI has not yet designated an EU Representative under Article 27 of the GDPR. When the Service becomes available in the EEA, an EU Representative will be appointed. Any privacy-related inquiries from EEA residents may be directed to privacy@delph-ai.org.
13.3. Right to Complain
You have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
13.4. International Transfers
For details on how we protect your data during international transfers, see Section 6.2. We rely on Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework.
14. Additional Information for Brazil Residents
If you are located in Brazil, the following additional information applies under the Lei Geral de Proteção de Dados (LGPD — Law No. 13,709/2018):
14.1. Your Rights Under the LGPD
In addition to the rights listed in Section 8, you have the right to:
- Confirm the existence of processing of your personal data;
- Request anonymization, blocking, or deletion of unnecessary or excessive data;
- Request information about public and private entities with which your data has been shared;
- Request information about the possibility of denying consent and its consequences;
- Revoke consent at any time.
14.2. Data Protection Officer (Encarregado)
Our Data Protection Contact for LGPD purposes is reachable at: privacy@delph-ai.org
14.3. Response Time
We will respond to your requests within 15 days for a complete statement, in accordance with LGPD Article 19, II. For a simplified confirmation of the existence and type of processing, we will respond as soon as practicable.
14.4. International Transfers
Transfers of personal data from Brazil to the European Union are covered by the mutual adequacy decision between Brazil and the EU (ANPD Resolution CD/ANPD No. 32, January 2026). For transfers to the United States, we implement appropriate safeguards as required by the LGPD, including contractual provisions with our sub-processors.
14.5. Supervisory Authority
You may file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD): https://www.gov.br/anpd/
15. Additional Information for Mexico Residents
If you are located in Mexico, the following additional information applies under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), as currently in force.
15.1. Comprehensive Privacy Notice
This Privacy Policy is our comprehensive privacy notice (Aviso de Privacidad Integral). Section 1 identifies the data controller and its address. Section 3 describes the personal data we process and identifies sensitive personal data, if any. Section 4 describes the purposes of processing and distinguishes purposes that are necessary to provide the Service from optional purposes that require your consent. Section 7 describes retention periods. Section 12 explains how we notify material changes to this Policy.
We do not require or intentionally collect sensitive personal data from account users. The Service should not be used to upload patient-identifiable information or other sensitive personal data.
15.2. Consent and Legal Exceptions
Where Mexican law permits processing without consent — including when processing is required by law, relates to data from public sources, involves data previously dissociated from you, or is necessary to maintain or perform our legal relationship with you — we rely on those legal exceptions. Where consent is required, your consent may be tacit unless Mexican law requires express consent.
15.3. Limiting Use or Disclosure
You may limit the use or disclosure of your personal data, or withdraw consent for optional purposes, by contacting us at privacy@delph-ai.org. Optional purposes include future analytics, marketing, or other non-essential uses identified as Optional in Section 4. Refusing or withdrawing consent for optional purposes will not affect your access to the core Service.
15.4. ARCO Rights
You may exercise your ARCO rights (Acceso, Rectificación, Cancelación, and Oposición) by contacting us at privacy@delph-ai.org. Your request should include your name and contact information, reasonable proof of identity, a description of the personal data involved, and the specific right you wish to exercise. We will respond within 20 business days, or sooner if required by applicable law. If approved, we will make the response effective within 15 business days. These periods may be extended once for an equal period when justified.
15.5. Objection to Automated Processing
Under applicable Mexican law (LFPDPPP 2025), you may object to automated processing of your personal data that, without human intervention, evaluates personal aspects about you and produces unwanted legal effects or significantly affects your interests, rights, or freedoms. To exercise this right, contact privacy@delph-ai.org. Note that Delph-AI's screening function evaluates bibliographic records (academic publications), not individuals, and is not designed to produce legal effects about you personally.
15.6. Security Breach Notices
If a security breach involving personal data significantly affects your rights, we will notify you as required by Mexican law so that you can take appropriate measures.
15.7. Supervisory Authority
You may submit a data protection complaint before the Secretaría Anticorrupción y Buen Gobierno, the Mexican authority that assumed the relevant private-sector data protection functions formerly exercised by INAI.
16. Additional Information for California Residents
If you are a resident of California, the following additional information applies as a matter of good practice, even though the California Consumer Privacy Act (CCPA/CPRA) does not currently apply to Delph-AI based on our size and revenue:
16.1. Categories of Personal Information
We collect the following categories of personal information as defined by the CCPA: identifiers (name, email), professional information (title, organization), internet activity (IP, browser), and commercial information (transaction history).
16.2. We Do Not Sell Your Personal Information
We do not sell your personal information to third parties as defined by the CCPA. We do not share your personal information for cross-context behavioral advertising.
16.3. Your Rights
You have the right to: know what personal information we collect; request deletion of your personal information; request correction of inaccurate information; and not be discriminated against for exercising your rights. To exercise these rights, contact us at privacy@delph-ai.org.
17. Contact Us
If you have questions about this Privacy Policy or wish to exercise any of your rights, please contact us:
| Purpose | Contact |
|---|---|
| Privacy inquiries and data subject requests | privacy@delph-ai.org |
| Legal inquiries | legal@delph-ai.org |
| Security vulnerability reports | security@delph-ai.org |
| General support | support@delph-ai.org |
Mailing address: Gustavo Díaz Ordaz 204, Col. Francisco Villa, Xalapa, Veracruz, C.P. 91173, México