Privacy Notice
This notice describes how ParaOn processes personal data under the Philippine Data Privacy Act of 2012 (RA 10173) and NPC circulars. Lawful bases include contract (subscriptions), consent (marketing/waitlist where applicable), and legitimate interests (security, fraud prevention).
What we collect
Account email and name, organization name, billing metadata, invoice records, support messages, and technical logs (IP, correlation IDs). We never store card PAN/CVV on our origin — payments use hosted checkout (SAQ-A).
Consent
Checkout requires an explicit, unticked auto-renewal consent before recurring billing. Marketing waitlist sign-ups are consent-based. Site analytics is cookieless by default (no consent banner). If non-essential marketing cookies are ever enabled, a prior opt-in consent banner is required before those scripts load.
Retention
Contact submissions are anonymized after 12 months. Application logs are retained 30 days hot / 12 months cold; traces 30 days. Audit logs, payment ledgers, and invoices are retained for 10 years (BIR). Encrypted webhook evidence is retained for 7 years.
Your rights
You may request access, correction, or deletion of personal data, subject to legal retention exemptions for audit/ledger/invoices. Submit a request below or email privacy@paraon.ph.
Data-subject request
72-hour breach path
- Detect and contain (SEV1 if payments or PII exposure).
- Assess personal-data impact with the DPO.
- Notify the NPC and affected users within 72 hours when required.
- Postmortem within 5 working days for SEV1/SEV2.
Full runbook: docs/compliance/breach-incident-runbook.md
DPO
Data Protection Officer: dpo@paraon.ph. NPC registration is pursued when thresholds are met.