01

About RA 10173 — The Data Privacy Act of 2012

Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (DPA), is the primary Philippine law governing the collection, storage, and use of personal information. It is implemented and enforced by the National Privacy Commission (NPC), an independent body established under the Act.

The DPA applies to the processing of personal information of natural persons (Filipino citizens and non-citizens alike) by any natural and juridical person in the government or private sector. It covers information processed by wholly or partly automated means, as well as non-automated information intended for use in a filing system.

Kaayu Technology Inc. is incorporated and primarily operates in the Philippines, making RA 10173 our foundational data protection framework. This page explains our compliance obligations under the DPA and the rights of data subjects we serve.

Law Reference

Republic Act No. 10173 — Data Privacy Act of 2012, as implemented by the Implementing Rules and Regulations (IRR). Full text available at the National Privacy Commission: privacy.gov.ph.

02

Our Role: Personal Information Controller & Processor

The DPA distinguishes between a Personal Information Controller (PIC) — who controls the collection, holding, processing, or use of personal information — and a Personal Information Processor (PIP) — who processes personal information on behalf of a PIC.

Kaayu as Personal Information Processor (PIP)

When gym operators use Kaayu to manage their members' data — names, contact details, fitness records, access logs, payment history — the gym operator is the PIC and Kaayu acts as their PIP. We process member data strictly under the operator's instructions, for purposes defined by the operator, and do not use it for our own commercial purposes.

Gym operators who require a formal Sub-Processing Agreement may request one by emailing legal@kaayu.online.

Kaayu as Personal Information Controller (PIC)

Kaayu acts as a PIC for personal data it collects for its own business purposes: operator and staff account contacts, billing information, marketing opt-in records, platform usage data, and support communications. For this data, Kaayu bears full responsibility for DPA compliance.

Sub-Processing Agreement

A DPA-compliant sub-processing agreement is available to all Philippine gym operator clients. Email legal@kaayu.online with the subject line "Sub-Processing Agreement Request".

03

Lawful Criteria for Processing

Under Section 12 of RA 10173, processing of personal information is permitted only when at least one of the following criteria applies. Section 13 applies additional, stricter criteria for sensitive personal information.

Processing ActivityLawful CriterionDPA Section
Operator account management and platform accessContract necessity — required to deliver the subscribed serviceSec. 12(b)
Billing, invoicing, and payment processingContract necessity; legal obligation (BIR record-keeping)Sec. 12(b) & (c)
Platform security, fraud prevention, abuse detectionLegitimate interests — protecting the platform and its users from harmSec. 12(f)
Aggregate anonymised product analyticsLegitimate interests — improving and developing the platformSec. 12(f)
Marketing emails and product communicationsConsent — opt-in at account creation or via communication preferencesSec. 12(a)
Health/fitness data entered by gym operatorsExplicit consent of the data subject (obtained by the gym as PIC)Sec. 13(b)
Tax and financial record retentionLegal obligation — BIR Revenue Regulations and NIRC requirementsSec. 12(c)

Gym operators (as PICs) are responsible for identifying and documenting their own lawful criteria for processing their members' personal information within the Kaayu platform.

04

Data Subject Rights

Sections 16 through 20 of RA 10173 grant data subjects the following rights with respect to their personal information. For data for which Kaayu is the PIC, these rights may be exercised directly with us. For gym member data (where the gym operator is the PIC), members should contact their gym operator first.

🇵🇭
Information & Access
Secs. 16 & 17
  • Be informed before data is collected
  • Know what data is held and why
  • Access a copy of your personal data
  • Know who has received your data
✏️
Correction & Erasure
Secs. 16(c) & (d)
  • Dispute and correct inaccurate data
  • Request deletion or blocking of data
  • Withdraw consent for processing
  • Subject to lawful retention obligations
🛑
Object & Damages
Secs. 18, 19 & 20
  • Object to processing on lawful grounds
  • Opt out of direct marketing
  • Data portability (Sec. 18)
  • Claim damages for DPA violations

To exercise any of the above rights regarding data for which Kaayu is the PIC, email privacy@kaayu.online with the subject line "DPA Rights Request." We will acknowledge within 3 business days and resolve your request within 15 business days, extendable by a further 15 business days with notice.

Gym Member Rights

If you are a gym member whose data is managed by a gym that uses Kaayu, your gym is the Personal Information Controller for your membership records. Please contact your gym directly. The gym may then coordinate with Kaayu to fulfil your request.

05

Sensitive Personal Information

Section 3(l) of RA 10173 defines sensitive personal information as personal information about a data subject's race, ethnic origin, marital status, age, colour, religious, philosophical or political affiliations, health, education, genetic or sexual life, legal proceedings, and government-issued identification numbers.

In the context of gym management, the most commonly encountered sensitive personal information includes:

  • Health and medical data — pre-existing conditions, injuries, doctor's clearances collected for fitness assessments or specialised programmes
  • Government-issued ID numbers — used for identity verification (e.g., PhilSys, driver's licence) when required by the gym
  • Financial account details — where direct debit or bank-linked payment methods are used

Kaayu applies heightened protections for sensitive personal information stored within the platform: additional field-level encryption, stricter role-based access controls (only authorised staff can view), and comprehensive audit logging of all access events.

Operator Obligation

Gym operators (as PICs) must obtain the explicit consent of data subjects before collecting sensitive personal information, as required by Section 13(b) of RA 10173. Kaayu provides consent-logging tools within the platform, but operators are responsible for obtaining and documenting that consent.

06

NPC Registration

Under NPC Circular 17-01, personal information controllers that employ at least 250 persons, or those who process sensitive personal information of at least 1,000 individuals, are required to register their data processing systems with the National Privacy Commission.

Kaayu Technology Inc. maintains NPC registration as required for a SaaS platform processing personal data of gym members across multiple operators in the Philippines.

Kaayu NPC Registration

Kaayu Technology Inc. is registered with the National Privacy Commission. Our registration is renewed annually in accordance with NPC requirements. Gym operators may verify our registration status directly with the NPC at privacy.gov.ph.

Philippine gym operators who process the personal data of 1,000 or more individuals may themselves be required to register with the NPC. We recommend consulting NPC Circular 17-01 or contacting the NPC directly at info@privacy.gov.ph to assess your registration obligations.

07

Data Retention

Kaayu retains personal data only for as long as necessary for the purposes for which it was collected, or as mandated by Philippine law. Our retention schedule is:

  • Active operator accounts: Data retained for the duration of the contract plus 12 months for data export and reactivation support.
  • Terminated accounts: Personal data anonymised within 90 days; system logs purged within 180 days.
  • Financial and billing records: Retained for 10 years to comply with BIR Revenue Regulations and the National Internal Revenue Code (NIRC).
  • Security and access logs: Retained for 12 months for incident investigation and regulatory compliance purposes.
  • Backup media: Backup snapshots overwritten within 30 days of account deletion to ensure complete data purging.
  • Marketing consent records: Retained for 3 years after last interaction, or until consent is withdrawn, whichever is earlier.

Gym operators can configure their own data retention policies for member records within the Kaayu platform. Kaayu provides bulk anonymisation and deletion tools to assist operators in meeting their own retention obligations.

08

Security Measures

Section 20 of RA 10173 and its IRR require PICs and PIPs to implement reasonable and appropriate security measures. Kaayu's security programme is aligned with NPC guidelines and international best practices:

Technical Measures

  • AES-256 encryption for all personal data at rest; additional field-level encryption for sensitive personal information
  • TLS 1.3 for all data in transit between clients, servers, and third-party integrations
  • Multi-factor authentication (MFA) available for all operator and staff accounts
  • Role-based access controls (RBAC) limiting access to personal data on a need-to-know basis
  • Annual third-party penetration testing and continuous automated vulnerability scanning
  • Comprehensive audit trails for all access to and modifications of personal data

Organisational Measures

  • Documented Privacy Manual maintained and updated annually, available to data subjects on request
  • Privacy Impact Assessments (PIAs) conducted for new features and data processing activities
  • Mandatory data privacy training for all staff, conducted annually
  • Confidentiality agreements and data processing clauses in all employment and contractor contracts
  • Vendor due diligence programme for all third-party sub-processors
  • Data Sharing Agreements (DSAs) in place with all entities with whom personal data is shared

Physical Measures

  • Servers hosted in secure, access-controlled data facilities with 24/7 physical security
  • Clean desk and clear screen policy for staff with access to personal data
  • Restricted physical access to production infrastructure — least privilege principle
09

Personal Data Breach Notification

Section 20(f) of RA 10173 and NPC Circular 16-03 require prompt notification of personal data breaches to the NPC and to affected data subjects. Kaayu's breach response process is as follows:

Notification to the NPC

Where Kaayu acts as PIC: if a personal data breach involves sensitive personal information, or information likely to be used to enable identity fraud, we will notify the NPC within 72 hours of becoming aware of the breach. Where Kaayu acts as PIP, we will notify the affected gym operator immediately so they can fulfil their own notification obligations.

Notification to Data Subjects

Where a breach is likely to give rise to a real risk of serious harm to affected data subjects, Kaayu (or the gym operator as PIC) will notify those individuals directly, in clear and plain language, describing the nature of the breach, the data involved, and the measures being taken.

Incident Response Steps

  • Detect: Automated alerting and 24/7 monitoring to identify potential incidents immediately
  • Contain: Immediate isolation of affected systems; preservation of forensic evidence
  • Assess: Classification of breach severity, scope, and applicable notification thresholds
  • Notify: NPC and/or data subjects notified within required timeframes
  • Review: Post-incident root cause analysis and remediation to prevent recurrence
Report a Security Issue

To report a suspected data breach or security vulnerability, contact us immediately at security@kaayu.online. All reports are acknowledged within 24 hours.

10

Data Protection Officer

In accordance with NPC Advisory No. 17-01, Kaayu has designated and registered a Data Protection Officer (DPO) with the National Privacy Commission. The DPO is responsible for overseeing our compliance with RA 10173, advising on data protection matters, and serving as the primary point of contact for data subjects and the NPC.

Contact Our Data Protection Officer

Data Protection Officer
Kaayu Technology Inc.
Email: dpo@kaayu.online
Phone: +63 947 984 1430
Address: Manila, Philippines

The DPO can be contacted to exercise data subject rights, request a copy of our Privacy Manual, raise concerns about our data processing activities, or inquire about our NPC registration. We aim to respond to all DPO inquiries within 5 business days.

11

Filing a Complaint with the NPC

If you believe that Kaayu (or a gym operator using Kaayu) has violated your rights under RA 10173, you have the right to file a complaint with the National Privacy Commission. The NPC has the authority to investigate complaints and impose sanctions including fines and imprisonment for serious violations.

Before filing with the NPC, we encourage you to contact us directly at privacy@kaayu.online — most concerns can be resolved quickly and informally, and we take every privacy complaint seriously.

National Privacy Commission

National Privacy Commission (NPC)
Website: privacy.gov.ph
Email: info@privacy.gov.ph
Hotline: 1-800-1-PRIVACY (1-800-1-774-8229)
Address: 5th Floor, Delegation Building, PICC Complex, Pasay City, Metro Manila

The NPC's complaints process, timelines, and forms are available at privacy.gov.ph/complaints. Complaints must generally be filed within 1 year from knowledge of the violation.