Legal › The agreement

Data processing agreement

You are the controller of your people's data; we process it on your instructions. The Philippine Data Privacy Act, in practice.

This Data Processing Agreement forms part of the Terms of Service between Web and Cloud Innovation Ltd ("the Processor") and the Customer ("the Controller") and governs the processing of personal data through the Service.

It is written to satisfy Article 28 of the General Data Protection Regulation (EU) 2016/679, which applies to us because we are established in Malta, and the Data Privacy Act of 2012 (Republic Act 10173) of the Philippines, which applies where your business and the people whose data you hold are there. Where the two differ, the stricter obligation is the one we perform.

1Roles

You are the controller of the personal data you put into the Service, and the personal information controller for the purposes of RA 10173. You decide what is collected, why, and for how long it is kept.

We are the processor, and the personal information processor for the purposes of RA 10173. We process personal data only to provide the Service to you.

Where we decide something for ourselves — our own billing records, our own security logs, our own staff — we are a controller of that data, and our own privacy notice covers it.

2Instructions

We process personal data only on your documented instructions, which are: this agreement, the Terms of Service, the configuration and settings of your own installation, and anything else you ask us in writing.

We will tell you if we believe an instruction breaches data protection law. We are not obliged to carry out an instruction that would.

Where the law requires us to process personal data for another reason, we will tell you before doing so unless that law forbids it.

3Confidentiality

Every person who is authorised by us to process your personal data is bound by a duty of confidence that survives the end of their engagement, and is given access only to what their work requires.

4Security

We apply the technical and organisational measures set out in Annex 2, having regard to the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing, as well as the risk to the people concerned.

We may change a measure for one that is at least as protective. We will not weaken the overall level of protection.

5Sub-Processors

You give us general authorisation to engage the sub-processors named in the Sub-processor list, which forms part of this agreement.

We impose data protection obligations on each sub-processor that are no less protective than these, and we remain fully liable to you for their performance.

We will tell you at least thirty (30) days before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you to find a solution, and if none can be found you may terminate the affected part of the Service without penalty and receive a refund of fees paid for the period after termination.

6The Rights Of The People Concerned

The Service is built so that you can answer a request yourself: every record can be read, corrected, exported and deleted from within it, and the audit log shows who has seen a document.

Where a person contacts us directly about data we hold for you, we will not answer for you. We will pass the request to you without undue delay and help you to answer it.

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures with requests to exercise rights of access, rectification, erasure, restriction, portability and objection, and with the equivalent rights under RA 10173.

7Breach

We will notify you without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting your personal data.

The notification will describe, as far as we know it at the time: what happened, when, the categories and approximate number of people and records concerned, the likely consequences, and the measures taken or proposed. We will keep you updated as we learn more.

You remain responsible for notifying your supervisory authority and the people concerned where the law requires it. Under the GDPR that is within seventy-two (72) hours of your becoming aware; under RA 10173 it is within seventy-two (72) hours to the National Privacy Commission and the affected data subjects. We will give you what you need to do it in time.

We will also assist you, so far as is reasonable, with data protection impact assessments and prior consultations.

8Deletion And Return

On the end of the Service, and at your choice, we will return your personal data to you or delete it, in the way and within the periods set out in the Terms of Service.

Backups already taken are deleted as they age out of the rotation, and are not restored except to recover the Service. Where the law requires us to keep something, we keep only that, and only for as long as required.

9Audit

We will make available to you the information reasonably necessary to demonstrate compliance with this agreement, and will contribute to audits conducted by you or an auditor you appoint.

An audit may be requested once in any twelve (12) month period, or after a breach affecting your data, on thirty (30) days' notice, at a reasonable time, without unreasonable disruption, subject to confidentiality, and at your cost unless the audit finds a material breach by us.

10International Transfers

The Service is operated from Malta, in the European Union, and your data may be stored or processed there, in the country where your installation is hosted, and by the sub-processors named in the Sub-processor list.

Where personal data protected by the GDPR is transferred outside the European Economic Area, we rely on an adequacy decision where one covers the destination, and otherwise on the European Commission's Standard Contractual Clauses together with any supplementary measures the transfer requires.

Where personal information protected by RA 10173 leaves the Philippines, you remain accountable for it, and we undertake to give it a comparable level of protection through this agreement and the contracts we hold with our sub-processors.

11Liability And Precedence

The limitations of liability in the Terms of Service apply to this agreement, except where the law does not permit them to.

If this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails. If it conflicts with the Standard Contractual Clauses, those clauses prevail.

Annex 1 — What Is Processed

Subject matter — the provision of the Service described in the Terms of Service.

Duration — for as long as the subscription lasts, plus the deletion periods in the Terms of Service.

Nature and purpose — hosting, storage, display, transmission, backup, encryption, and automated reading of uploaded documents to copy their printed details into a record.

Categories of data subjects — your tenants and guests and the people living with them; your staff, applicants and former staff; your contractors and suppliers; your visitors and callers recorded at the gate; the people you name as emergency or reference contacts; your own administrators and users.

Types of personal data — names and contact details; addresses and unit occupancy; identification documents and the numbers on them; dates of birth; nationality and civil status where a form asks; bank and payment details; employment terms, wages, contributions, attendance, performance and disciplinary records; tenancy terms, charges, payments and arrears; photographs of property, receipts and incidents; vehicle plates; signatures, and the time, network address, device and — where the person allows it — the location at which a document was signed; sign-in records.

Special categories and sensitive information — the Service is not intended for health data, and you should not put it there. Government identification numbers, and in some functions the fact of a disciplinary process, are sensitive personal information under RA 10173, and are handled as Annex 2 describes.

Annex 2 — Technical And Organisational Measures

Separation — each business is served from its own database file. There is no shared table from which one customer's rows could be returned to another.

Encryption in transit — the Service is served over HTTPS, with strict transport security requested by every page.

Encryption at rest — uploaded identification documents, receipts and signed papers are encrypted with a symmetric key held on the server, outside the folders that are mirrored offsite, so that a copy of a backup does not carry the means to read them.

Access control — named accounts, roles and per-function capabilities; an authenticator-app second factor available on every account and enforceable for administrators; sign-in throttling that defends both an address and an account after repeated failures; sessions that are regenerated at sign-in, expire, and carry cookies that script cannot read.

Accountability — an append-only audit log of sign-ins, document views, record changes and administrative actions, readable by you.

Application hardening — a content security policy that refuses foreign scripts and framing, output escaping, prepared statements throughout, tokens on every state-changing form, and internal directories refused by the web server.

Resilience — nightly database snapshots, an offsite copy under separate access, and error logs retained so that an incident can be reconstructed.

Organisational — a documented incident procedure, background-appropriate confidentiality obligations on everyone with access, and a policy of least privilege for administrative access to the servers.

Annex 3 — Sub-Processors

As set out in the Sub-processor list, which is published with these documents and forms part of this agreement.

12Acceptance Record

Accepted by: —
Business: the Customer
Document version: (shown in the margin)
Document fingerprint: (shown in the margin)
Accepted at: —
Network address: —
Device: —
Acceptance record: —