Data Privacy Policy
Effective Date: January 1, 2024 • Last Updated: August 2026 • Compliant with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and National Privacy Commission (NPC) Regulations
Privacy at a Glance
NDSOR Technologies IT Solutions ("NDSOR Tech") respects your right to privacy. We engineer offline-first desktop systems, mobile apps, and enterprise cloud solutions. For website inquiries, NDSOR Tech is the Personal Information Controller. For client software deployments (NDSOR Workforce, NDSOR Pay, NDSOR Clinic, GlobalinxSys ERP), client enterprises act as Controllers, while NDSOR Tech acts strictly as a Software Licensor and Processor. We never monetize or sell your personal or biometric information.
1. Overview, Scope & Legal Commitment
NDSOR Technologies IT Solutions ("NDSOR Tech", "we", "our", or "us"), founded and managed by Nonie John B. Sortigosa, located in Zarraga, Iloilo, Philippines, is committed to safeguarding personal, sensitive, and operational data in full accordance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations (IRR), and applicable circulars of the National Privacy Commission (NPC).
This Privacy Policy governs data collected across our corporate website (ndsor.com), our desktop software suite (NDSOR Suite, NDSOR Workforce, NDSOR Pay, GlobalinxSys ERP, NDSOR Clinic EMR, Sales & Inventory Systems), our custom web platforms (RAISE Knowledge Hub, WVSUMC Clinical Evaluation System), and our bespoke IT engineering and consultation engagements.
2. Data Roles: Controller (PIC) vs. Processor (PIP)
Under RA 10173, legal responsibilities differ depending on the capacity in which data is processed:
Website Inquiries & Direct Commercial Relations
When you submit inquiry forms, request software demos, or contract consultation directly with NDSOR Tech, we act as the Personal Information Controller (PIC) responsible for protecting your contact records.
Deployed Enterprise Software & Client Databases
When client organizations deploy our software (NDSOR Workforce, NDSOR Pay, NDSOR Clinic, etc.), the Client Enterprise is the PIC. NDSOR Tech acts strictly as the Personal Information Processor (PIP) or Software Licensor. We access operational databases only upon explicit written authorization for technical support.
3. Categories of Data We Collect & Process
We process information categorized as follows:
- Website Inquiries & Consultation Records: Full name, company name, corporate email address, contact numbers, job titles, and business requirements submitted through consultation forms, demo booking modals, or email inquiries.
- Client Employee Masterlists & Compensation Data: Employee names, IDs, department designations, shift rosters, hourly/daily wages, piece-rate productivity tallies, and statutory contributions (SSS, PhilHealth, Pag-IBIG, BIR withholding tax) processed inside NDSOR Pay and NDSOR Workforce.
- Biometric Attendance Telemetry: Hardware-direct communication logs interfacing with ZKTeco biometric terminals. Biometric devices calculate mathematical algorithm templates; raw biometric fingerprint or facial imagery is not transmitted to NDSOR Tech web servers. Punch logs include employee IDs, verification timestamps, terminal serials, and state indicators processed on the client's internal network.
- Clinical, Patient & Healthcare Data: For NDSOR Clinic EMR and the WVSUMC Clinical Evaluation System, patient records, clinical encounter notes (SOAP format), physician prescriptions, surgical procedure logs, and medical residency grading rubrics are processed with strict physician-patient confidentiality under DOH and NPC clinical standards.
- Commercial, ERP & Supply Chain Data: Retail point-of-sale transactions, wholesale inventory stock movements, ice plant pre-order batch records, fuel pump shift handoffs, and vehicle fleet GPS waypoint logs processed within GlobalinxSys ERP and Sales & Inventory Systems.
- Technical Telemetry & Security Diagnostics: IP addresses, browser types, session timestamps, device architectures, and error diagnostics collected automatically to maintain website stability and firewall defense.
4. Biometric & Sensitive Personal Information Protections
Under Section 13 of Republic Act No. 10173, biometric and health data are classified as Sensitive Personal Information. NDSOR Tech adheres to stringent architectural principles:
- Template-Only Processing: Biometric verification algorithms store mathematical vector representations on physical terminal hardware, preventing the reconstruction of original fingerprint or facial photos.
- Premises-Local Retention: In standalone mode, biometric punch logs reside strictly within the client's local SQLite database behind the client's internal local area network (LAN).
- Strict Purpose Limitation: Biometric timestamps are utilized exclusively for legitimate time and attendance verification, overtime calculation, and payroll generation.
5. Lawful Basis and Purposes of Processing
We process personal and enterprise information under lawful criteria recognized by Section 12 and Section 13 of the DPA:
- Contractual Performance: Providing software licenses, activating modules, provisioning updates, conducting system migration, and delivering SLAs.
- Legal & Statutory Compliance: Enabling clients to compute mandated statutory deductions and maintain labor compliance records required by DOLE, BIR, SSS, and PhilHealth.
- Legitimate Interests: Hardening software infrastructure, preventing unauthorized license distribution, debugging crash reports, and maintaining cybersecurity.
- Consent: Communicating with prospective clients who voluntarily submit consultation inquiries.
6. Technical, Organizational & Physical Safeguards
NDSOR Tech implements multi-layered security measures to guard against accidental destruction, unlawful erasure, alteration, or unauthorized access:
TLS 1.3 encryption across all web traffic and API synchronization endpoints, with AES-256 encrypted database archives.
Standalone desktop architecture ensures core business databases operate completely disconnected from external internet exposure.
Granular Role-Based Access Controls (RBAC) and soft-delete tombstone protocols preventing accidental permanent record loss.
7. Data Retention & Secure Disposal
Personal data is retained only for as long as necessary to fulfill the operational, commercial, or legal purposes for which it was gathered:
- Website Inquiries: Retained for up to twenty-four (24) months from submission or until business negotiations conclude.
- Client Operational Databases: Retained strictly per client policy and statutory Philippine labor/tax recordkeeping obligations (typically 3 to 10 years).
- Secure Sanitization: When retention periods expire or upon contract termination, records are purged using NIST SP 800-88 cryptographic wiping standards.
8. Your Rights under Republic Act No. 10173
As a data subject under Philippine law, you are entitled to the following statutory rights:
To know whether personal data pertaining to you is being collected, stored, or processed.
To demand reasonable access to the contents of your personal data held in our systems.
To dispute any inaccuracy or error in personal data and have it corrected immediately.
To suspend, withdraw, or order the removal of personal information upon legitimate grounds.
To be indemnified for any damages sustained due to inaccurate, false, or unlawfully obtained data.
To obtain an electronic copy of personal data processed in an interoperable format.
9. Designated Data Protection Officer (DPO) Contact
For questions regarding this Data Privacy Policy, exercising your rights under RA 10173, or reporting privacy concerns, contact our designated Data Protection Officer:
Attn: Data Protection Officer / Nonie John B. Sortigosa
Enterprise: NDSOR Technologies IT Solutions (NDSOR Tech)
Office Address: Saintsville Subd., Brgy. Poblacion Ilaud, Zarraga, Iloilo, 5004, Philippines
Official Email: sales@ndsor.com • njsortigosa@gmail.com
Telephone: (033) 321-5473 • Mobile: +63 999 910 9186
You also have the right to lodge a complaint directly with the Philippine National Privacy Commission (NPC) at privacy.gov.ph.