Data Processing Addendum

Draft — supplements the Terms of Service and Privacy Policy.

1. Purpose of this addendum

This addendum describes how personal data is processed on your behalf when you use the service to store information about your customers, sites, jobs and employees.

2. Roles under RA 10173

[To be written by counsel: Whether your organization is the Personal Information Controller and the platform is the Personal Information Processor for the personal data stored on your behalf, or some other arrangement — unresolved (open question Q17).]

3. Categories of data subjects and data processed

See the Privacy Policy for the categories of personal data the product stores.

[To be written by counsel: An exhaustive, addendum-level list, if one is required beyond the Privacy Policy.]

4. Processor obligations

[To be written by counsel: Confidentiality, instructions-only processing, and the security measures the platform commits to.]

5. Sub-processors

Expected to include hosting and infrastructure providers, an email/SMS delivery provider, and, once selected, a payment gateway.

[To be written by counsel: The complete, named list and how tenants are notified of a change.]

6. Assistance with data subject requests

[To be written by counsel: How the platform helps a tenant respond to a data subject's request under RA 10173.]

7. Security incident notification

[To be written by counsel: Notification timelines and process, aligned with National Privacy Commission (NPC) breach notification rules.]

8. International data transfer

[To be written by counsel: Where data is hosted and processed, and the safeguards that apply.]

9. Term, termination, and return or deletion of data

[To be written by counsel: What happens to your data when the addendum or your subscription ends.]

10. Liability

[To be written by counsel: Liability allocation between the parties for this addendum.]

11. Contact

[To be written by counsel: How to reach us about this addendum.]