Legal
Privacy notice
In short
We process the minimum needed to run each client's workspace: logins, the decision record, content and the reports clients import. We do not sell data, we do not use advertising cookies, and you have rights under the Philippine Data Privacy Act.
01Who is responsible
For your login (your name, email address and sign-in records), IBITS decides how that data is used and is the personal information controller.
For data inside a client workspace (for example leads, content featuring people, and imported reports), the client organization is the controller and IBITS processes it on their behalf under the service agreement and a data processing arrangement.
02What we process
| Category | Examples |
|---|---|
| Account | Name, email address, role, sign-in times, password (stored only as a hash by the authentication service) |
| Activity record | Who approved, edited, scheduled, published or imported what, and when (the audit trail) |
| Content and assets | Copy, images and video, including people who appear in them, with the rights and consent details the client records |
| Leads | When the client uses lead capture: contact details, the consent given, and follow-up notes |
| Imported reports | Platform and marketplace results. Marketplace order IDs are hashed before storage; buyer details are not imported |
| Technical | Essential cookies (see the cookie notice) and server logs used to keep the service secure |
03Why, and on what basis
- To provide the service your organization contracted (contract), including sign-in, approvals, publishing proof and reporting.
- To keep workspaces secure and separated, and to investigate misuse (legitimate interest).
- To keep the records the law or the service agreement requires (legal obligation and contract).
- Lead data is processed on the consent the client collected, for the purposes stated when it was collected.
04Sensitive information
GrowthOS is not designed for health records or other sensitive personal information. Clients should not upload patient records or health details about identifiable people. Product claims about health are handled as approved marketing claims, not personal data.
06How long we keep it
We keep workspace data for as long as the client's service agreement runs, then return it through authorized exports and delete or archive it as the agreement and the law require. Login data is kept while you have access to any workspace. Audit records are kept for as long as the related decisions may need to be shown.
07How we protect it
Workspaces are separated by database-enforced access rules, files are private and served through short-lived signed links, and platform credentials are encrypted. See security.
08Your rights
Under the Data Privacy Act of 2012 (Republic Act No. 10173) you have the right to:
- be informed about how your data is processed,
- access your data and get a copy in a commonly used format,
- object to processing and withdraw consent where processing relies on it,
- have inaccurate data corrected,
- have data erased or blocked where it is no longer lawfully needed,
- be indemnified for damages caused by unlawful processing, and
- lodge a complaint with the National Privacy Commission.
For data inside a client workspace, we will pass your request to that client and help them respond.
09Contact and changes
For privacy questions and requests, contact your IBITS account contact, named in your service agreement. We may update this notice; the date at the top shows the latest version.