Legal Compliance RA 10173 Compliant DPO Registered

Data Privacy Policy

Effective Date: January 1, 2024 • Last Updated: August 2026 • Compliant with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and National Privacy Commission (NPC) Regulations

Privacy at a Glance

NDSOR Technologies IT Solutions ("NDSOR Tech") respects your right to privacy. We engineer offline-first desktop systems, mobile apps, and enterprise cloud solutions. For website inquiries, NDSOR Tech is the Personal Information Controller. For client software deployments (NDSOR Workforce, NDSOR Pay, NDSOR Clinic, GlobalinxSys ERP), client enterprises act as Controllers, while NDSOR Tech acts strictly as a Software Licensor and Processor. We never monetize or sell your personal or biometric information.

1. Overview, Scope & Legal Commitment

NDSOR Technologies IT Solutions ("NDSOR Tech", "we", "our", or "us"), founded and managed by Nonie John B. Sortigosa, located in Zarraga, Iloilo, Philippines, is committed to safeguarding personal, sensitive, and operational data in full accordance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations (IRR), and applicable circulars of the National Privacy Commission (NPC).

This Privacy Policy governs data collected across our corporate website (ndsor.com), our desktop software suite (NDSOR Suite, NDSOR Workforce, NDSOR Pay, GlobalinxSys ERP, NDSOR Clinic EMR, Sales & Inventory Systems), our custom web platforms (RAISE Knowledge Hub, WVSUMC Clinical Evaluation System), and our bespoke IT engineering and consultation engagements.

2. Data Roles: Controller (PIC) vs. Processor (PIP)

Under RA 10173, legal responsibilities differ depending on the capacity in which data is processed:

NDSOR Tech as Controller (PIC)

Website Inquiries & Direct Commercial Relations

When you submit inquiry forms, request software demos, or contract consultation directly with NDSOR Tech, we act as the Personal Information Controller (PIC) responsible for protecting your contact records.

Client as Controller / NDSOR as Processor (PIP)

Deployed Enterprise Software & Client Databases

When client organizations deploy our software (NDSOR Workforce, NDSOR Pay, NDSOR Clinic, etc.), the Client Enterprise is the PIC. NDSOR Tech acts strictly as the Personal Information Processor (PIP) or Software Licensor. We access operational databases only upon explicit written authorization for technical support.

3. Categories of Data We Collect & Process

We process information categorized as follows:

  • Website Inquiries & Consultation Records: Full name, company name, corporate email address, contact numbers, job titles, and business requirements submitted through consultation forms, demo booking modals, or email inquiries.
  • Client Employee Masterlists & Compensation Data: Employee names, IDs, department designations, shift rosters, hourly/daily wages, piece-rate productivity tallies, and statutory contributions (SSS, PhilHealth, Pag-IBIG, BIR withholding tax) processed inside NDSOR Pay and NDSOR Workforce.
  • Biometric Attendance Telemetry: Hardware-direct communication logs interfacing with ZKTeco biometric terminals. Biometric devices calculate mathematical algorithm templates; raw biometric fingerprint or facial imagery is not transmitted to NDSOR Tech web servers. Punch logs include employee IDs, verification timestamps, terminal serials, and state indicators processed on the client's internal network.
  • Clinical, Patient & Healthcare Data: For NDSOR Clinic EMR and the WVSUMC Clinical Evaluation System, patient records, clinical encounter notes (SOAP format), physician prescriptions, surgical procedure logs, and medical residency grading rubrics are processed with strict physician-patient confidentiality under DOH and NPC clinical standards.
  • Commercial, ERP & Supply Chain Data: Retail point-of-sale transactions, wholesale inventory stock movements, ice plant pre-order batch records, fuel pump shift handoffs, and vehicle fleet GPS waypoint logs processed within GlobalinxSys ERP and Sales & Inventory Systems.
  • Technical Telemetry & Security Diagnostics: IP addresses, browser types, session timestamps, device architectures, and error diagnostics collected automatically to maintain website stability and firewall defense.

4. Biometric & Sensitive Personal Information Protections

Under Section 13 of Republic Act No. 10173, biometric and health data are classified as Sensitive Personal Information. NDSOR Tech adheres to stringent architectural principles:

  • Template-Only Processing: Biometric verification algorithms store mathematical vector representations on physical terminal hardware, preventing the reconstruction of original fingerprint or facial photos.
  • Premises-Local Retention: In standalone mode, biometric punch logs reside strictly within the client's local SQLite database behind the client's internal local area network (LAN).
  • Strict Purpose Limitation: Biometric timestamps are utilized exclusively for legitimate time and attendance verification, overtime calculation, and payroll generation.

5. Lawful Basis and Purposes of Processing

We process personal and enterprise information under lawful criteria recognized by Section 12 and Section 13 of the DPA:

  • Contractual Performance: Providing software licenses, activating modules, provisioning updates, conducting system migration, and delivering SLAs.
  • Legal & Statutory Compliance: Enabling clients to compute mandated statutory deductions and maintain labor compliance records required by DOLE, BIR, SSS, and PhilHealth.
  • Legitimate Interests: Hardening software infrastructure, preventing unauthorized license distribution, debugging crash reports, and maintaining cybersecurity.
  • Consent: Communicating with prospective clients who voluntarily submit consultation inquiries.

6. Technical, Organizational & Physical Safeguards

NDSOR Tech implements multi-layered security measures to guard against accidental destruction, unlawful erasure, alteration, or unauthorized access:

🔐 Cryptographic Controls

TLS 1.3 encryption across all web traffic and API synchronization endpoints, with AES-256 encrypted database archives.

🛡️ Offline Isolation

Standalone desktop architecture ensures core business databases operate completely disconnected from external internet exposure.

📋 Access Governance

Granular Role-Based Access Controls (RBAC) and soft-delete tombstone protocols preventing accidental permanent record loss.

7. Data Retention & Secure Disposal

Personal data is retained only for as long as necessary to fulfill the operational, commercial, or legal purposes for which it was gathered:

  • Website Inquiries: Retained for up to twenty-four (24) months from submission or until business negotiations conclude.
  • Client Operational Databases: Retained strictly per client policy and statutory Philippine labor/tax recordkeeping obligations (typically 3 to 10 years).
  • Secure Sanitization: When retention periods expire or upon contract termination, records are purged using NIST SP 800-88 cryptographic wiping standards.

8. Your Rights under Republic Act No. 10173

As a data subject under Philippine law, you are entitled to the following statutory rights:

Right to be Informed

To know whether personal data pertaining to you is being collected, stored, or processed.

Right to Access

To demand reasonable access to the contents of your personal data held in our systems.

Right to Rectification

To dispute any inaccuracy or error in personal data and have it corrected immediately.

Right to Erasure or Blocking

To suspend, withdraw, or order the removal of personal information upon legitimate grounds.

Right to Damages

To be indemnified for any damages sustained due to inaccurate, false, or unlawfully obtained data.

Right to Data Portability

To obtain an electronic copy of personal data processed in an interoperable format.

9. Designated Data Protection Officer (DPO) Contact

For questions regarding this Data Privacy Policy, exercising your rights under RA 10173, or reporting privacy concerns, contact our designated Data Protection Officer:

Attn: Data Protection Officer / Nonie John B. Sortigosa

Enterprise: NDSOR Technologies IT Solutions (NDSOR Tech)

Office Address: Saintsville Subd., Brgy. Poblacion Ilaud, Zarraga, Iloilo, 5004, Philippines

Official Email: sales@ndsor.com • njsortigosa@gmail.com

Telephone: (033) 321-5473 • Mobile: +63 999 910 9186

You also have the right to lodge a complaint directly with the Philippine National Privacy Commission (NPC) at privacy.gov.ph.