Legal
Last updated: October 1, 2024 · In compliance with RA 10173 (Data Privacy Act of 2012)
This Agreement governs how HRisPH Technologies, Inc. processes personal data as a Personal Information Processor (PIP) on behalf of subscribers (Personal Information Controllers) under Philippine law.
In this Agreement:
**"Controller" / "Personal Information Controller (PIC)"** means the Subscriber, who determines the purposes and means of processing personal data of their employees.
**"Processor" / "Personal Information Processor (PIP)"** means HRisPH Technologies, Inc., which processes personal data on behalf of the Subscriber.
**"Personal Data"** means any information relating to identified or identifiable natural persons.
**"Sensitive Personal Information"** has the meaning given under Section 3(l) of RA 10173, and includes government IDs, salary information, and health data.
**"Processing"** means any operation performed on personal data, including collection, recording, organization, storage, updating, retrieval, consultation, use, disclosure, or deletion.
**"Data Breach"** means a security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
This DPA governs the processing of personal data by HRISPH (Processor) on behalf of the Subscriber (Controller) in connection with the provision of HRIS and payroll services ("Services") under the main Terms of Service.
The Processor shall process personal data only for the following purposes:
The Controller (Subscriber) agrees to:
HRISPH (Processor) agrees to:
The Processor shall assist the Controller in responding to the following data subject rights under RA 10173:
The Processor shall respond to rights request inquiries forwarded by the Controller within 5 business days. The Controller remains responsible for the final response to data subjects.
The Processor implements the following technical and organizational measures:
**Technical Measures:**
**Organizational Measures:**
The Controller authorizes HRISPH to engage the following categories of sub-processors:
The Processor shall notify the Controller of any intended changes to sub-processors at least 30 days in advance, giving the Controller the opportunity to object.
In the event of a personal data breach affecting Controller's data:
For breach notifications and security incidents, contact: security@hrisph.com
This DPA is effective from the date the Controller accepts HRISPH's Terms of Service and remains in force for the duration of the subscription.
Upon termination, the Processor shall:
Data retained for legal compliance purposes (e.g., BIR-mandated 10-year payroll record retention) shall be handled as specified in the main Privacy Policy.
This DPA is governed by the laws of the Republic of the Philippines, including RA 10173 (Data Privacy Act of 2012) and its Implementing Rules and Regulations.
Disputes shall be resolved in accordance with the dispute resolution provisions of the main Terms of Service.
**Data Protection Officer — HRisPH Technologies, Inc.** 8F Ayala Avenue Tower, 6750 Ayala Ave Makati City, Metro Manila 1226
Email: privacy@hrisph.com Phone: +63 2 8888 4747 NPC Registration No.: [Pending — to be updated upon registration completion]