Servo IT Solutions OPC Privacy Notice
Welcome to Servo IT Solutions OPC (“Servo”, “We”, “Our”, “Us”). We are committed to protecting the privacy and security of the personal data we process. This Privacy Notice explains our practices regarding the data processed through our software services and our website, in compliance with the Data Privacy Act of 2012.Our Role in Data Processing
A. As Personal Information Processor (PIP)
For the majority of the data processed through our platform, we act as a Personal Information Processor (PIP). This means we process personal data strictly on behalf of our clients (the organizations who subscribe to our service), who are the Personal Information Controllers (PICs).- We do not control the data: The PIC determines what data is collected, why it is collected, and how long it is retained.
- We follow instructions: We process this data solely to provide the agreed-upon services to our clients, as outlined in our agreements.
- If you are an end-user of a client: Direct any requests or questions regarding your data privacy rights to the specific organization that collected your information.
B. As a Personal Information Controller (PIC)
We act as a PIC for data we collect directly when you:- Use our systems
- Visit our website
- Inquire about our services
- Request support assistance
- Apply for a job with us
Personal Data Collected
We collect only the personal information necessary to authenticate users and maintain security within our systems.a. Personal Details
- First name
- Lastname
- Number
b. Login Credentials
- Username
- Passwords
- Security Codes
c. System and Security Logs
When you access our systems, we automatically collect:- IP address
- Browser type
- Device or computer name (if applicable)
- Login timestamps and activity logs
Purpose of Personal Data Processing
We use your personal data to:- Authenticate and grant system access
- Secure user accounts and prevent unauthorized access
- Monitor system performance and ensure reliability
- Detect, investigate, and prevent security incidents
- Maintain audit and compliance logs
Basis of Processing
We process your personal data based on one or more of the following lawful criteria:- Necessity in relation to entering or performing a contract
- Our legitimate interests as a SaaS provider
- Compliance with legal obligations and regulatory requirements
How Data is Collected
We collect personal data through the following means:- Information you directly provide in forms
- Emails or communications sent to us
- Cookies, analytics tools, and web tracking technologies
- User login and system activity within our systems
How Data is Used
Your personal data is used only for legitimate purposes related to our business, specifically to:- Verify your identity and relationship with your organization
- Provide, operate, and maintain services
- Customize and improve website content and functionality
- Monitor usage trends for security, troubleshooting, and analytics
- Send notifications or marketing communications (subject to preferences and laws)
Disclosure/Sharing
We may disclose or share your personal data under the following circumstances:- With authorized Servo personnel
- With business partners when necessary and lawful
- With government authorities as required by law
Risks Involved
While we implement appropriate safeguards to protect your personal data, the following risks may still exist, as with any online service:- Unauthorized access due to compromised devices or weak passwords
- Interception of data during transmission
- Potential data breaches due to sophisticated cyberattacks
- Unauthorized disclosure of personal data when users upload screenshots, videos, or recordings containing visible personal information to public platforms or unauthorized third-party services.
How Data is Protected
We apply organizational, physical, and technical measures to protect your personal data, such as:- Role-based access controls
- Staff training and confidentiality obligations
- Secure development and change control processes
- Firewalls and security monitoring tools
- Encryption for data in transit and at rest
- Regular policy and security reviews
Storage, Security, Disposal, and Retention
Storage
For on-premises systems, all data is stored within the organization’s servers controlled by the PIC. For cloud services, data is stored in secure cloud infrastructure in various regions. By using the application, you acknowledge that your data may be subject to the laws of these regions. We access data only for authorized support, troubleshooting, or maintenance.Security
- Encryption in transit and at rest
- Secure password hashing
- Role-based access control
- Firewalls and network protection
- Audit logging and transaction tracking
- Regular data backups
- Restricted administrative access
Client responsibility when submitting support materials
When requesting support assistance, clients and authorized users must ensure that any files, screenshots, screen recordings, videos, logs, or other materials submitted to us do not unnecessarily expose personal information, sensitive personal information, login credentials, payment details, guest records, employee records, or other confidential data. Clients must not upload, publish, or share support-related materials containing visible personal data to public or third-party platforms such as YouTube, Facebook, TikTok, cloud drives with public links, or similar social media/file-sharing platforms for the purpose of submitting them to Servo support. If a video, screenshot, or recording is necessary for troubleshooting, the client must submit it only through Servo’s authorized support channels and, where practicable, mask, blur, crop, redact, or anonymize any personal data before submission. We may refuse to access, process, or use publicly shared support materials containing exposed personal data and may request the client to remove the public content and resubmit a redacted version through the authorized support ticket system. The client, as Personal Information Controller, remains responsible for ensuring that personal data under its control is disclosed to Servo only through secure and authorized channels and only to the extent necessary for support, troubleshooting, maintenance, or other agreed services.Disposal and Retention
The PIC determines and enforces data retention periods. Default guidance:- Reservation Records: 5 years
- Financial Records: 10 years
- Guest Profiles:
- Retained as long as the PIC maintains an active relationship with the guest or until manually deleted
- Automated Data Privacy Sweeps anonymize data once retention periods are exceeded
- Audit Logs: per internal hotel policy
Changes to the Privacy Notice
We may update this notice to reflect changes in our practices, technologies, or legal requirements. Updates will be posted with an updated effective date.Rights of Data Subjects
As a data subject, and subject to applicable laws, you have the following rights:- Right to be informed
- Right to access
- Right to rectification
- Right to object
- Right to erasure or blocking
- Right to data portability
- Right to damages
- Right to file a complaint with the NPC
How to File a Complaint
If there is a complaint regarding data processing, contact the Data Protection Officer listed below. You may also file a complaint with the National Privacy Commission.Data Protection Officer Contact Details
Name: John Carlo Guevarra
Tel. No.: 0917 704 1324
Email: [email protected]