Your privacy is our priority. This Privacy Policy outlines how we collect, use, and protect your information when you use OneCRM, a CRM platform we host and manage for your business needs. We ensure full compliance with the Data Privacy Act of 2012 (RA 10173) of the Philippines.
1. Roles & Scope
- Controller & Processor: We act as both Personal Information Controller (PIC) and Personal Information Processor (PIP).
- Geographic Jurisdiction: This policy applies to data collected from individuals in the Philippines or processed using Philippine-based systems.
2. Data We Collect & Process
- Account Holder Data: name, email, phone, billing info, encrypted credentials.
- Client Data: contact info, projects, invoices, tickets, uploaded files.
- Usage & Cookies: IP, browser type, and activity logs.
3. Lawful Basis for Processing
- Consent: Given explicitly during registration or submission.
- Contractual Necessity: To provide CRM services.
- Legal Obligation: For billing, regulatory compliance, etc.
- Legitimate Interests: Improving service, security, and usage tracking.
4. Sensitive & Privileged Data
- We do not collect sensitive personal data unless legally required or with explicit consent.
5. Security Measures
- SSL encryption, firewalls, access controls, and daily backups.
- Aligned with National Privacy Commission (NPC) guidelines on data protection.
6. Data Breach Notification
- Affected individuals and the NPC will be notified promptly in case of a data breach.
7. Data Subject Rights
- Right to be Informed, Right to Access, Right to Rectification, Right to Erasure/Blocking, Right to Data Portability, Right to Object, Right to Damages and to file complaints with NPC.
8. Retention & Disposal
- Data is retained only as necessary and securely deleted thereafter.
9. Third-Party Processors
- We use trusted third-party services bound by confidentiality and privacy standards.
10. Accountability & Governance
- Privacy Management Program includes: appointing a DPO, impact assessments, privacy policies, security measures, and breach protocols.
11. Updates to This Policy
- You will be notified via email or platform notice of any significant updates.