Privacy Policy

Draft — reflects the Data Privacy Act of 2012 (RA 10173) as topics to be covered, not final legal text.

1. Who this policy covers

This policy covers two groups: the staff, technicians and owners of a business using the service ("tenants"), and the customers and contacts a tenant adds to run their own business — for example, a customer's name, phone number and site address entered by the tenant.

2. Personal data we process

Depending on how a tenant uses the service, this can include: names, phone numbers and email addresses; Philippine addresses (street, barangay, city, province, postal code); photos and signatures captured during a service visit; and, for a tenant's own employees, government ID numbers and pay rates.

3. Purpose and legal basis

[To be written by counsel: The specific purpose and legal basis under RA 10173 for each category of processing above (e.g. contract performance, consent, legitimate interest).]

4. Consent

For a customer contact, the service records whether they have consented to be emailed or texted, separately for each channel, and the moment that consent was last given or withdrawn. A tenant's staff should not message a contact who has not consented on that channel.

5. Who we share data with

[To be written by counsel: The complete list of processors and sub-processors — expected to include hosting and infrastructure providers, an email/SMS delivery provider, and, once selected, a payment gateway — and the terms under which each of them may access data.]

6. Your rights under the Data Privacy Act

[To be written by counsel: How to exercise the rights the Data Privacy Act gives a data subject: the right to be informed, to access, to object, to correct, to erasure or blocking, to damages, to file a complaint with the National Privacy Commission, and to data portability.]

7. Retention

The product generally archives records rather than deleting them, so that financial and audit history stays intact.

[To be written by counsel: Specific retention periods per category of data, and the erasure process for a data subject request.]

8. Security measures

[To be written by counsel: The technical and organizational security measures in place.]

9. Cross-border data transfer

[To be written by counsel: Where data is hosted and processed, and the safeguards that apply to any transfer outside the Philippines.]

10. Data breach notification

[To be written by counsel: How and when affected tenants and data subjects are notified of a personal data breach.]

11. Changes to this policy

[To be written by counsel: How and when this policy may change, and how you will be notified.]

12. Contact and Data Protection Officer

[To be written by counsel: How to reach us, and the designated Data Protection Officer under RA 10173.]

See also the Terms of Service and the Data Processing Addendum.