This Policy outlines PHILGPS Corporation's commitment to
gather and manage
personal
and sensitive data (collectively, "personal data") in compliance
with
all
applicable
data privacy laws and regulations, including the Philippine Data
Privacy
Act
of 2012
("DPA") and its implementing rules and regulations ("DPA IRR"). The
terms
and
conditions under which we gather and use personal data are further
explained, as
well as how PHILGPS Corporation carries out that obligation. In the
collecting,
processing, and preservation of personal data as mandated by
applicable
legislation,
we endeavour to comply with the general privacy principles of
transparency,
legitimate purpose, and proportionality. This Policy is available on
the
PHILGPS
Corporation website at www.philgeps.com, along with any updates,
modifications, or
supplements thereto.
Definitions and construction
Definitions for some of the words used in this policy are in
Schedule 1.
Schedule 1
also includes requirements for the construction of specific terms
and
phrases used
in this Policy. We use the terms "Schedules" and "Clauses" to refer
to
the
schedules
and clauses of this Policy.
Confidentiality under Philippine Law
Information we receive from customers, whether or not it contains
personal
data, is
normally protected as privileged communications, and we are obligated to
keep that
information confidential. We strictly adhere to this professional
commitment. We
note that local laws, regulations, and authorities allow for the sharing
of
such
information under specific conditions, such as when it becomes public.
DPA Exemptions
Certain personal data and their collection and processing are excluded
from
or do
not fall under the scope of the DPA (see Schedule 2). This Policy does
not
cover
these data or actions.
Gathering and Processing of personal data
We may be able to obtain personal data in various ways. These include
where
a
natural or juridical person (a "Person") –
(i) enters into an agreement with us, whether or not written, including
an
employment contract, retainer agreement or other contract to avail of
our
services,
or supply or service contract;
(ii) submits to us any application, form, request, notice, or some other
document;
(iii) inquires after or applies for employment;
(iv) becomes an employee, officer, supplier or service provider of the
Firm;
(v) accesses, browses, visits, or uses any of our websites, platforms,
social media
presence, and other online presence; or
(vi) otherwise provides us with personal data, whether directly or
through
another
Person.
Where personal data is publicly available, we may be able to collect the
data from
such public sources, including any online presence you may have.
On the categories of personal data we collect and process, this would be
the
data
that you or other data subjects provide to us, such as your name,
address,
email
address, telephone number, age, marital status, information issued by
government
agencies, and other information that may be used to enter into or help
perform a
contract we have with you, provide you with products and services,
communicate with
you, or meet any of the purposes set out in Schedule 3.
Insofar as you disclose personal data when accessing or visiting the
PHILGPS
website, we may process such personal data as well. Further, we may
collect
and
process information that is normally collected as a standard part of
your
browsing
activity.
Purposes of gathering and processing; recipients of
personal data
We collect and process personal data for the purposes (i) for which you
have
provided the data or made it otherwise available to us or to the public,
and
to
enable us to fully and efficiently achieve those purposes, (ii) as
allowed
by
applicable law, and (iii) those purposes specified in Schedule 3
(collectively, the
"Purposes").
Recipients of personal data that we collect include persons within
PHILGPS
(including any affiliates or related companies), and third parties to
whom
we have
outsourced or may outsource certain business or operating activities,
advisers,
suppliers, and service providers, in order to achieve the Purposes. Some
of
these
entities may be outside the Philippines, so that transfer of data will
be
cross-border. We may also disclose information, whether intended to be
kept
confidential or not, upon lawful request by a governmental authority, in
response to
a court order, or when required by applicable law. Please see Schedule 3
for
more
information about persons to whom personal data may be transferred or
shared.
Consent and other lawful criteria for gathering and
processing
7.1 Where you have provided us with your personal data through any of
the
interactions mentioned in Clause 5, in providing or making available the
personal
data, you agree and consent to our collecting, using, disclosing,
sharing
and
otherwise processing the personal data for the Purposes, and in the
manner
and under
the terms and conditions, in this Policy.
This supplements but does not supersede nor replace any other consents
you
may have
previously provided or will provide to us in respect of your personal
data,
or the
existence of a lawful basis or bases for the collection and processing
of
your
personal data.
7.2 Applicable law allows us to process your personal data in accordance
with other
criteria or where the data is not covered by the DPA. We may process
your
information if you have given us specific permission (i.e., express
consent)
to use
your personal information for a specific purpose, or in situations where
your
permission can be inferred (i.e., implied consent). You can withdraw
your
consent at
any time.
Scope and method of gathering and processing
8.1 We utilize standard manual and computerized methods and systems to
file,
store
and process personal data. Collection and processing of personal data
will
be
undertaken in accordance with the principles set out in this Policy and
as
required
by law.
We file, store, and process personal data using manual and electronic
procedures.
Personal Data will be gathered and processed in compliance with the
guidelines
outlined in this policy and as required by the law.
8.2 We will store and retain personal data for such period as may be
required by
applicable law or as may be needed to enable us to fully and efficiently
achieve the
Purposes.
We will keep personal data for as long as necessary to fulfil the
purposes
in a
complete and effective manner, or as long as required by relevant law.
8.2.1 10 years for all government agencies
All data collected and used by government agencies will be archived for
a
period of
10 years.
8.2.2 5 years for resigned employees
a. employment contract
b. COE
c. 2316
All data related to resigned employees will be archived for a period of
5
years.
This includes, but is not limited to:
Employment Contracts: Ensuring access to contractual agreements for
reference and
compliance purposes.
Certificates of Employment: Retaining proof of employment for
verification
and
future reference.
BIR Form 2316: Archiving tax-related documents to meet regulatory
requirements.
Amendments and supplements
We may amend or update this Policy. You agree to be bound by the general
terms of
this Policy as revised on some occasions, upon the amendment or
supplement
being
published on our website or otherwise implored to you. Kindly check our
website from
time to time for updated information about, or amendments or supplements
to,
the
Policy.
Rights of data subjects
Under the DPA, data subjects have the following rights:
10.1 Right to object
You have the right to infer your nonacceptance to the gathering and
processing of
your personal data as a subject, including processing for direct
marketing,
automated processing, or profiling. You also have the right to be
notified
and to
disapprove your consent to further processing in case there are any
modifications or
amendments to information given to you. Once you have advised us of the
withholding
of your consent, further processing of your personal data will no longer
be
allowed,
unless:
(i) The processing is required in conformity with a subpoena, lawful
order,
or as
required by law; or
(ii) The collection and processing is undertaken in conformity with any
lawful
basis
or criteria indicated under Clause 7.2.
10.2 Right to access
Upon your request, you may be given access to your personal data which
we
gather
and
process, as indicated in Clause 5. You also have the right to request
access
to the
incidents pertaining to the processing and gathering of your personal
data,
insofar
as allowed by law.
10.3 Right to rectification
You have the right to query any lapse or error in your personal data and
may
request
us to immediately rectify it. Upon your request and after correction has
been made,
we will advise any recipient of your personal data of its error and the
subsequent
rectification that was made.
10.4 Right to erasure or blocking
In the insufficiency of any other legal ground or overruling legitimate
interest for
the lawful processing of your personal data, or when there is valid
proof
that your
personal data is lacking, outdated, incorrect, or has been unlawfully
obtained, you
may request us to suspend, withdraw, or order the blocking, erasure, or
destruction
of your personal data from our filing system. We may also advise those
who
have
previously received your processed personal data.
10.5 Right to damages
You have the right to be remunerated for any damages yielded due to
inaccurate,
incomplete, outdated, false, or unauthorized gathering and use of your
personal
data, taking into account any violation of your rights and liberties as
a
data
subject, as provided by law.
10.6 Right to data portability
In case your personal data was processed via electronic means and in a
standardized
and typically used format, you have the right to obtain a copy of your
personal data
in such electronic or standardized format for your further use, subject
to
the
regulations of the National Privacy Commission with notice to the
practice
of such
right.
10.7 Limitation on rights; manner of exercising
The rights specified under this item are not applicable if personal data
are
processed only for scientific and statistical research purposes, and
without
being
used as premise for executing any activity or taking any decision in
view of
you as
the data subject. Your rights as a data subject are also contingent upon
other
restrictions provided by law.
The law warrants you to practice your rights as depicted in this Policy
in a
rational and sensible manner, and with consideration to rights of other
parties.
All requests, stipulations or notifications which you may raise under
this
Policy or
applicable law must be in the form of writing, and will only be regarded
as
made and
received if sent in conformity with Clause 14.2.
Security Measures
We have taken appropriate security measures to protect your personal
data
against
unauthorized access or unauthorized alteration, disclosure, or
destruction.
These
measures include internal reviews of our data collection, storage, and
processing
practices, as well as physical security measures to protect your
information
against
unauthorized access. As part of our efforts to ensure your information
is
protected,
we restrict access to personal data to personnel who would need that
information to
perform their functions.
We have implemented suitable security protocols to protect your personal
data from
unwanted access, alteration, disclosure, or destruction.These
precautions
include
physical security measures and internal inspections of our data
collecting,
storage,
and processing procedures. We limit access to personal data to employees
who
require
it to carry out their duties as part of our efforts to protect your
information.
Data breaches
We will adhere to the pertinent provisions of rules and circulars on
handling
personal data security breaches, including notification to you or to the
National
Privacy Commission, where an unauthorized obtainment of sensitive
personal
information or information that may be used to allow identity fraud has
been
acquired by an unauthorized individual, and is likely to give rise to a
serious risk
and harm to the affected data subject. Please note that under applicable
law, not
all personal data breaches are required to be reported.
Data PrivacyOfficer
The Data Protection Officer (DPO) is the individual principally
responsible
for
ensuring PHILGPS Corporation’s compliance with applicable laws and
regulations for
the protection of data privacy and security. The DPO is responsible for
the
supervision and enforcement of this Policy, and the relevant contact
details
are as
follows:
Data Protection Officer: Jann Alfred Galibut
PHILGPS Corporation
203 Crispina Building
1589 Quezon Avenue West Triangle
Quezon City
+639274878589
jann@philgps.com
Inquiries; notices
14.1 For any request for information associated with this Policy, please
contact our
Data Protection Officer via the details indicated above.
14.2 All requests, stipulations or notifications which a data subject
may
declare
or
submit to us under this Policy must be in the form of writing, should be
addressed
to the Data Protection Officer using the contact details above, and will
be
considered duly given (i) on the delivery date if delivered personally,
(ii)
on the
fifth Working Day following the send date if delivered by a nationally
accepted
next-day courier service and the service has verified delivery, or (iii)
if
given by
electronic mail, when such electronic mail is transmitted to the email
address
specified above and the proper confirmation has been received by the
sender
via
email.
Schedule 1 -
Definition
of
Terms
Definitions
Whenever used in this Policy, the following terms shall have the
respective
meanings as set forth below:
"Business Day" means any day that Philippine banks are open for
business
in
Makati City,
"DPA" means the Data Privacy Act of 2012 and its implementing rules
and
regulations, as well as the circulars issued by the National Privacy
Commission
from time to time.
"Person" means any natural or juridical person.
"personal data" means personal information and sensitive personal
information.
"personal information" refers to any information, whether recorded
in a
material
form or not, from which the identity of an individual is apparent or
can
be
reasonably and directly ascertained by the entity holding the
information, or
when put together with other information, would directly and
certainly
identify
an individual;
"Policy" means this data privacy policy as may be amended, modified
or
supplemented from time to time.
"processing" refers to any operation or any set of operations
performed
upon
personal data including, but not limited to, the collection,
recording,
organization, storage, updating, or modification, retrieval,
consultation, use,
consolidation, blocking, erasure, or destruction of data. Processing
may
be
performed through automated means, or manual processing, if the
personal
data
are contained or are intended to be contained in a filing system.
"sensitive personal information" refers to personal information:
(1)
about an
individual’s race, ethnic origin, marital status, age, color, and
religious,
philosophical or political affiliations; (2) about an individual’s
health,
education, genetic or sexual life of a person, or to any proceeding
for
any
offense committed or alleged to have been committed by such
individual,
the
disposal of such proceedings, or the sentence of any court in such
proceedings;
(3) issued by government agencies peculiar to an individual which
includes, but
is not limited to, social security numbers, previous or current
health
records,
licenses or its denials, suspension or revocation, and tax returns;
or
(4)
specifically established by an executive order or an act of Congress
to
be kept
classified.
Construction
Whenever the word, "include," "includes" or "including" are used in
this
Policy,
they shall be deemed to be followed by the words "without
limitation".
The meaning assigned to each term used here will be equally
applicable
to both
the singular and plural forms of such term, and the words denoting
any
gender
shall include all genders.
Schedule 2 -
Personal
data
not covered
This Policy does not apply to the following information:
Information processed for the purpose of allowing public access to
information that fall within matters of public concern, pertaining to:
(i) Information about any individual who is or was an officer or employee
of
government that relates to his or her position or functions;
(ii) Information about an individual who is or was performing a service
under
contract for a government institution, but only insofar as it relates to
such
service, including his name and the terms of his contract; and
(iii) Information relating to a benefit of a financial nature conferred on
an
individual upon the discretion of the government, such as the granting of a
license or permit, including the name of the individual and the exact nature
of
the benefit: Provided, that they do not include benefits given in the course
of
an ordinary transaction or as a matter of right.
Personal information that will be processed for research purpose, intended
for a public benefit, subject to the requirements of applicable laws,
regulations, or ethical standards; and
Information necessary in order to carry out the functions of public
authority, in accordance with a constitutionally or statutorily mandated
function pertaining to law enforcement or regulatory function, including the
performance of the functions of the independent, central monetary authority,
subject to restrictions provided by law.
Schedule 3 -
Purposes
for
collection and processing of personal data
General
We use personal data to:
comply with and exercise our rights under contracts and agreements,
and
the
law, as may be required by our operations and in pursuit of our
legitimate
business and commercial objectives;
(ii) perform and improve our services, and address concerns or
questions about
those services;
(iii) implement efficiencies and best practices;
(iv) obtain services and advice for our operations and business;
(v) research and data gathering exercises;
(vi) market, promote and share information about the firm and our
services;
(vii) communicate with you; and;
(viii) allow audits and diligence for compliance and other review
by
advisers
or
third parties. In this regard, we will require such advisers or
third
parties to
enter into a confidentiality agreement.
Employee Data
We may collect and process personal data from current or prospective
employees
in order to initiate, carry out, or terminate an employment
agreement,
including
the results of certain medical examinations that are part of
conditions
of
employment.
For job applicants, we may process personal data required in order
to
initiate
the employment application process. The collected personal data of
any
applicant, who may not have been hired, may be retained by the firm
for
purposes
of future selection process.
For job applicants, we may process personal data required in order
to
initiate
the employment application process. The collected personal data of
any
applicant, who may not have been hired, may be retained by the firm
for
purposes
of future selection process.
We may share an applicant’s or an employee’s personal data when
expressly
authorized by law or when the applicant or employee concerned has
given
consent,
as when the Company is provided as a reference.
Company files, records (whether or not electronic), computers,
devices
and
facilities are the property of PHILGPS, and we may examine and
review
their
contents at any time, whether or not an officer, employee or other
staff
has
personal data, property or other information stored therein.