ICTSI respects the privacy of individuals and is fully committed to protecting sensitive and personal information in accordance with its obligations under the Philippine Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations, and the existing Memorandum Circulars and Advisories issued by the National Privacy Commission (NPC).
General Privacy Policy statements:
-
ICTSI adheres to the general principles of transparency, legitimate purpose, and proportionality in the collection, processing, securing, retention, and disposal of personal information.
-
Employees, clients, customers, or third parties whose personal information is being collected shall be considered as data subjects for purposes of these policies.
-
The data subject shall be informed of the reason or purpose of collecting and processing personal data.
-
The data subject shall have the right to correct the information, especially in cases of erroneous or outdated data, and to object to the collection of personal information within the bounds allowed by privacy laws.
-
The data subject has the right to file a complaint in case of breach or unauthorized access to their personal information.
-
ICTSI shall secure the personal information of employees and third parties from whom personal information is collected and shall take adequate measures to secure both physical and digital copies of the information.
-
ICTSI shall ensure that personal information is collected and processed only by authorized personnel for legitimate purposes of the Organization.
-
Any information that is declared obsolete based on the internal privacy and retention procedures of the Organization shall be disposed of in a secure and legal manner.
-
Any suspected or actual breach of ICTSI Data Privacy Policy must be reported to the DPO or any member of the DPA Working Group.
-
Data subjects may inquire or request information from the DPA Working Group regarding any matter relating to the processing of their personal data under the custody of ICTSI, including the data privacy and security policies implemented to ensure the protection of their personal data.
ICTSI recognizes the importance of the rights of a Data Subject under the DPA as follows:
-
Right to be informed whether personal data pertaining to them shall be, are being, or have been processed
-
Right to object to the processing of their personal information given and an opportunity to withhold consent to the processing in case of changes or any amendment to the information supplied. This includes the right to object to profiling, automated processing, or decisions evaluated solely through automated algorithmic means
-
Right to access, upon demand, the contents of their personal data that were processed, sources from which personal data were obtained, names and addresses of recipients of the personal data, manner by which such data were processed, and reasons for the disclosure of the personal data to recipients, among others
-
Right to rectification in order to dispute the inaccuracy or error in the personal data and to have it corrected immediately
-
Right to erasure or blocking of their personal data from the filing system
-
Right to damages sustained due to such inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal data
-
Transmissibility of rights to the lawful heirs and assigns of the data subject
-
Right to data portability or the capability to move data from one platform or service to another
Collection of Personal Information
In collecting your personal information, ICTSI ensures that the data subject is aware of the nature, purpose, and extent of the processing of their personal information. The processing of information shall be adequate, relevant, suitable, necessary, and not excessive in relation to a declared and specified purpose.
Personal Information refers to any information, whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual.
In the performance of our services, or as part of our transactions and dealings, we process and collect the following personal information which may include, but is not limited to:
-
Name, marital status, Tax Identification Number, age, address, education, profession, business experience, business affiliation, family affiliation, and any information from which the identity of an individual is apparent or can be reasonably and directly ascertained, whether recorded in material form or not, such as CCTV footages and other visual recordings as part of our transactions with you
-
Employment history, résumé and pictures sent with it, compensation and benefits, educational background, organizational affiliation, gender, date of birth, religion, ethnicity, civil status, citizenship, physical medical history, past criminal and/or administrative records, government-issued identifying information such as Pag-IBIG, SSS, TIN, PhilHealth, Professional IDs, Passport, and Birth Certificates, and payroll information of job applicants and current employees
-
Company information, performance, history, and financial and capital, during vendor accreditation to engage in business transactions with us
-
Information you provide us when you visit or use our company website, centralized digital platforms, and other mobile and online applications, and any information you submit to our sales or customer relations agents for the update of your records or information.
-
Telemetry and usage metrics when you access or use our online products, mobile and web applications, platforms, and digital services. This includes information about your interactions with our digital platforms, such as app-clicks, features visited, page response times, download errors, session statistics, and other diagnostic usage data
-
Text, queries, prompts, and contextual data intentionally inputted in our integrated Artificial Intelligence (AI) tools, support bots, and internal productivity features
Use of Personal Information
The Processing of Personal Information is for purposes of:
-
Identification in company records and corporate housekeeping;
-
Corporate transactions, business operations, and the implementation, management, and optimization of digital transformation systems across global business units;
-
Compliance with requirements, including reportorial obligations to the Securities and Exchange Commission (SEC), the Philippine Stock Exchange (PSE), the Bureau of Internal Revenue (BIR), port authorities, relevant local government units, and other appropriate government agencies or offices;
-
Maintenance of security within and around the premises as well as the security of ICTSI’s digital infrastructure and networks. This includes physical and logical access control, visitor management, incident monitoring, investigation of security incidents, protection of personnel, assets, cargo, facilities, equipment, information systems, networks, data repositories, cloud environments, and other business resources, and the use of physical and electronic security measures such as CCTV, intrusion detection systems, and other security technologies, where permitted by law;
-
Compliance with legal processes or lawful orders of judicial and quasi-judicial bodies, or any other government agencies and instrumentalities; and
-
Any other legitimate business activities of ICTSI, which includes leveraging aggregated and pseudonymized application usage information to:
a. Better understand user behaviors to optimize interface designs and streamline navigation;
b. Monitor app stability, diagnose technical errors, and evaluate system performance across different global regions;
c. Identify usage trends to design, test, and deploy new features and digital capabilities that benefit all users; and
d. Utilize machine learning models to enhance business productivity, generate predictive analytical reports, and automate routine workflows, provided that such processing applies data minimization, is subjected to human oversight (human-in-the-loop safeguards), and enforces rigorous measures against bias and technical inaccuracy
Sharing and Cross-Border Transfer of Personal Information
ICTSI may share or disclose Personal Information of Data Subjects to:
-
The SEC, PSE, BIR, port authorities, relevant local government units, and other appropriate government agencies or offices and other competent authorities which by law, rules, or regulations require us to disclose the personal information;
-
Any judicial and quasi-judicial bodies or government agencies pursuant to a lawful order, subpoena, writ, court process, investigation or other exercise of lawful authority;
-
Other subsidiaries, affiliates, and business units of the parent company as part of international business operations and integrated digital infrastructure, provided that such transfers are governed by cross-border data transfer agreements, binding corporate rules, or strict contractual safeguards to maintain uniform privacy protections and are subject to appropriate organizational, physical and technical security measures consistent with applicable data protection laws;
-
Any agent, contractor, consultant, adviser, auditor, underwriter, or service provider that ICTSI engages to carry out legitimate business activities or services, including third-party vendors and partners responsible for the design, development, cloud hosting, operational management, optimization, and maintenance of ICTSI’s online products, applications, and digital platforms, provided that such entities ensure strict confidentiality and adhere to the security provisions of the DPA through formal Data Sharing or Outsourcing Agreements or equivalent contractual arrangements that impose and ensure data protection, confidentiality, security, breach notification, and data processing obligations.
-
Our employees or other personnel handling your transactions and requests
ICTSI shall ensure that any disclosure, transfer, or sharing of Personal Information is limited to what is necessary for the specified purpose and is subject to appropriate safeguards, including confidentiality obligations, data processing agreements, organizational measures, and technical security controls, in accordance with the Data Privacy Act of 2012, its Implementing Rules and Regulations, and applicable issuances of the NPC.
Retention and Security of Personal Information
Personal Information collected shall be retained as long as necessary in order to:
-
Fulfill the declared, specified, and legitimate purposes provided above, or when the processing relevant to the purpose has been completed or terminated;
-
Exercise or defend legal claimss;
-
Comply with laws, regulations, or lawful court order.
Thereafter, your personal data shall be disposed of or discarded in a secure manner that would prevent further processing, unauthorized access, or disclosure to any other party or the public.
ICTSI ensures the integrity and confidentiality of your personal information by providing suitable and adequate organizational, physical, and technical security measures, policies, and procedures intended to reduce the risks of accidental destruction or loss, or unauthorized disclosure or access to such information.
As part of our ICTSI’s digital transformation initiatives, physical and cloud-based access to servers, database clusters, and network equipment is highly restricted to authorized personnel only. Various advanced security appliances, encryption protocols, and monitoring devices are employed to safeguard ICTSI’s localized and global network systems.
Policy Update
he Data Privacy Policy shall be updated periodically to comply with applicable laws, rules, and regulations and to further improve the security procedures in the processing of Personal Information.
For any report or concern regarding the Data Privacy Policy, you may contact our Data Protection Officer at:
-
Postal Address: ICTSI 2/F Administration Building MICT Compound, Port Area Manila, Philippines 1012
-
Email address: privacy@ictsi.com