Privacy Policy
Draft — reflects the Data Privacy Act of 2012 (RA 10173) as topics to be covered, not final legal text.
1. Who this policy covers
This policy covers two groups: the staff, technicians and owners of a business using the service ("tenants"), and the customers and contacts a tenant adds to run their own business — for example, a customer's name, phone number and site address entered by the tenant.
2. Personal data we process
Depending on how a tenant uses the service, this can include: names, phone numbers and email addresses; Philippine addresses (street, barangay, city, province, postal code); photos and signatures captured during a service visit; and, for a tenant's own employees, government ID numbers and pay rates.
3. Purpose and legal basis
[To be written by counsel: The specific purpose and legal basis under RA 10173 for each category of processing above (e.g. contract performance, consent, legitimate interest).]
4. Consent
For a customer contact, the service records whether they have consented to be emailed or texted, separately for each channel, and the moment that consent was last given or withdrawn. A tenant's staff should not message a contact who has not consented on that channel.
5. Who we share data with
[To be written by counsel: The complete list of processors and sub-processors — expected to include hosting and infrastructure providers, an email/SMS delivery provider, and, once selected, a payment gateway — and the terms under which each of them may access data.]
6. Your rights under the Data Privacy Act
[To be written by counsel: How to exercise the rights the Data Privacy Act gives a data subject: the right to be informed, to access, to object, to correct, to erasure or blocking, to damages, to file a complaint with the National Privacy Commission, and to data portability.]
7. Retention
The product generally archives records rather than deleting them, so that financial and audit history stays intact.
[To be written by counsel: Specific retention periods per category of data, and the erasure process for a data subject request.]
8. Security measures
[To be written by counsel: The technical and organizational security measures in place.]
9. Cross-border data transfer
[To be written by counsel: Where data is hosted and processed, and the safeguards that apply to any transfer outside the Philippines.]
10. Data breach notification
[To be written by counsel: How and when affected tenants and data subjects are notified of a personal data breach.]
11. Changes to this policy
[To be written by counsel: How and when this policy may change, and how you will be notified.]
12. Contact and Data Protection Officer
[To be written by counsel: How to reach us, and the designated Data Protection Officer under RA 10173.]
See also the Terms of Service and the Data Processing Addendum.