Privacy Policy
How we handle personal data — as a controller for our own business, and as a processor for the systems we build and run for clients.
1. Who we are
Dinnox IT Solutions is a sole proprietorship registered with the Philippine Department of Trade and Industry under Business Name No. 4753153, with a national scope. We build and operate custom software, cloud and AI systems for businesses and institutions.
| Registered name | Dinnox IT Solutions |
|---|---|
| Proprietor | Baumel Llorente Tandogon |
| DTI Business Name No. | 4753153 |
| Address | 1102 Park Centrale Building, J.M. del Mar St., Cebu IT Park, Apas, Cebu City 6000, Philippines |
| Privacy contact | inquiry@dinnoxit.com |
This notice explains how we handle personal data under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission (NPC).
2. Our two roles
Most privacy notices describe a single role. Ours has to describe two, because we handle personal data in two very different capacities, and your rights differ depending on which one applies.
As a Personal Information Controller (PIC)
For our own business — visitors to this website, people who email us, prospective and current clients, and our suppliers — we decide what personal data is collected and why. That processing is described in sections 3 to 7.
As a Personal Information Processor (PIP)
When we build, host or maintain a system for a client, the personal data inside that system belongs to the client's own users — their employees, customers or members. The client is the Controller and decides what is collected and why; we process it only on their documented instructions. That relationship is described in section 8.
A worked example. ShopSmart is operated by ShopSmart Consumer Goods Trading, a separate legal person. They are the Controller for ShopSmart's buyers and merchants. Dinnox IT Solutions is their Processor. If you are a ShopSmart user, the notice that governs your data is ShopSmart's, not this one — and requests about your data should go to them.
3. What this website collects
Very little, and we would rather say so plainly than pad this section.
- No cookies. This site sets no cookies of any kind, so there is no consent banner to click.
- No analytics or tracking. There is no Google Analytics, Google Tag Manager, Meta Pixel, Hotjar, Clarity, or any comparable tool.
- No third-party scripts, fonts or embeds. Every asset is served from our own domain, so no other company observes your visit.
- No account or login. There is nothing here to sign up for.
The contact and newsletter forms on this site do not submit anything to a server. They assemble a message and hand it to your own email application, which you then choose to send or discard. Until you press send in your own mail client, nothing reaches us.
Like any website, ours is served by a web server that processes your IP address and request in order to deliver the page. We do not build profiles or analytics from that traffic.
4. When you contact us
If you email us, request a consultation, or engage us commercially, we hold what you choose to give us. Typically:
- Your name and the organisation you represent
- Your email address and phone number
- What you told us about your requirements, systems or project
- Correspondence and meeting records relating to the engagement
- For clients: billing and statutory records we are required to keep
5. How we use information
- To answer your enquiry and prepare proposals or quotations
- To deliver, support and maintain services under an agreement with you
- To issue invoices and meet tax, accounting and regulatory obligations
- To keep our systems secure and investigate misuse
We do not sell personal data. We do not share it for anyone else's marketing. We do not use it to train AI models.
6. Lawful basis
Under RA 10173 we rely on the criteria for lawful processing that fit the purpose: your consent where you have volunteered information; necessity for a contract to which you are a party or steps taken at your request; compliance with a legal obligation, such as tax and accounting records; and our legitimate interests in running, securing and improving our business, where those interests are not overridden by your rights.
7. Sharing and disclosure
We disclose personal data only where it is necessary, and only to:
- Infrastructure and service providers that host or transmit our systems and communications, bound by their own terms and by our instructions
- Professional advisers such as accountants, where required
- Government authorities, where we are legally compelled, or to establish, exercise or defend legal claims
We do not disclose one client's data to another client.
8. Data in client systems
Where we act as a Processor, we handle personal data on the Controller's instructions. In that capacity we undertake to:
- Process personal data only for the purposes the client has specified, and not for our own purposes
- Apply organisational, physical and technical security measures appropriate to the risk
- Restrict access to personnel who need it to perform the work, under a duty of confidentiality
- Engage subprocessors only where the client's agreement permits it, on terms no less protective than our own
- Notify the Controller without undue delay upon becoming aware of a personal data breach, so they can meet their own notification duties
- Assist the Controller in responding to requests from data subjects
- Return or dispose of personal data at the end of the engagement, as the Controller directs and subject to any retention required by law
If you are a user of a system we built for someone else — an employee whose HR records sit in HRIS Workbench, or a customer of a business running one of our platforms — please direct your privacy request to that organisation. They are the Controller. If you contact us instead, we will refer you to them rather than act on their data ourselves.
9. Retention
We keep personal data only as long as it serves the purpose it was collected for. Enquiries that do not lead to an engagement are kept only as long as they remain commercially relevant. Records tied to a contract are kept for the life of the engagement and afterwards for as long as Philippine tax, accounting and limitation periods require. Data held as a Processor is retained according to the client's instructions and their own agreement with us, not ours.
10. Security
We apply access control, encryption in transit, network and host hardening, logging, backups and least-privilege administration to the systems we run, and we review these as systems change.
We describe our practices honestly and do not claim certifications we do not hold. No system can be guaranteed absolutely secure, and we do not pretend otherwise.
11. International transfers
We are based in Cebu City and most processing happens in the Philippines. We serve clients in the Philippines, Australia, the United Arab Emirates and Europe, and systems may be hosted in the region a client requires, so personal data may be transferred across borders.
Where we transfer personal data out of the Philippines we remain accountable for it under RA 10173. Where a client or their users are covered by the EU General Data Protection Regulation, the transfer and processing terms in that client's agreement govern, in addition to this notice.
12. Your rights
Under the Data Privacy Act you have the right to:
- Be informed that your personal data is being processed
- Access the personal data we hold about you
- Object to processing, including for direct marketing
- Have inaccurate data corrected
- Request erasure or blocking where the law allows
- Data portability for data processed by electronic means
- Be indemnified for damages from inaccurate, false or unlawfully obtained use of your data
- Lodge a complaint with the National Privacy Commission
To exercise any of these, email inquiry@dinnoxit.com. We may need to verify your identity before acting, so that we do not disclose your data to someone else. We aim to respond within a reasonable period and, where practicable, within the timeframes set by NPC issuances.
13. Complaints
If you are not satisfied with how we have handled your personal data, please raise it with us first — most issues are resolved quickly. You also have the right to complain directly to the National Privacy Commission of the Philippines.
14. Changes
We may update this notice as our services or the law change. The effective date at the top of this page always reflects the current version. Material changes affecting how we handle your data will be made prominent rather than slipped in quietly.
15. Contact
Dinnox IT Solutions
1102 Park Centrale Building, J.M. del Mar St.
Cebu IT Park, Apas, Cebu City 6000, Philippines
inquiry@dinnoxit.com
+63 919 070 3469
See also our Terms of Use.