Client Data Privacy Notice

The company values and respects data privacy rights. As part of our operations, we process personal information entrusted to us by our Personal Information Controller (PIC) and handle such data in accordance with the Data Privacy Act of 2012, applicable regulations, and our internal policies and procedures.

  1. What Personal Data We Process
    The Company processes personal and sensitive personal information provided by the Personal Information Controller (PIC). These may include:
    • Debtor names
    • Contact information (phone numbers, email addresses, mailing addresses)
    • Financial or account-related information
    • Credit history or supporting documentation
    • Information necessary for debt-related verification
    • Communication records, and operational documentation such as but not limited to (data processing requirements, account-related records, reports, compliance and regulatory instructions, etc.) supplied by the PIC
    • Other information required by our PIC for legitimate business and regulatory purposes

    The Company does not directly collect personal data from data subjects for independent purposes. All information processed is provided by the PIC.

  2. How We Use Your Data
    We process personal data to support the Company's operational, regulatory, and service-related functions, including:
    • Conducting debt collection and account management activities
    • Verifying identity and account information
    • Recording, documenting, and monitoring account status
    • Performing internal audits, quality checks, and compliance reviews
    • Coordinating with the PIC and authorized parties when necessary
    • Complying with legal and regulatory obligations
    • Ensuring operational efficiency, accuracy, and service delivery

    Personal data is processed using secure systems and retained only as long as necessary to fulfill authorized purposes or as required by law.

  3. Data Sharing
    Personal data may be shared or disclosed under the following circumstances:
    • With the PIC, as part of authorized service requirements
    • With relevant government agencies or regulatory bodies when required by law (e.g., lawful orders, compliance audits, investigations)
    • With external auditors, legal counsel, or authorities for compliance, reporting, or legal matters

    All third parties engaged by the Company are bound by confidentiality and data protection obligations. The Company does not disclose personal data for unauthorized or unrelated purposes.

  4. Data Subject Rights
    Data subjects retain their rights under the Data Privacy Act, including:
    • Right to be informed
    • Right to access
    • Right to rectification
    • Right to object
    • Right to erasure or blocking, where applicable
    • Right to damages arising from unlawful processing

    Requests to exercise data subject rights are still coordinated with the Personal Information Controller (PIC). As a PIP, the Company does not directly act on these rights but follows a due process to ensure proper handling in line with contractual and legal requirements.

  5. Data Security and Retention
    The Company implements organizational, physical, and technical safeguards to protect personal data, such as:
    • Access controls and authentication mechanisms
    • Encryption and secure communication channels
    • Confidentiality agreements and employee training
    • System monitoring, incident response, and audit processes
    • Regular reviews of internal policies and compliance measures

    Retention periods follow documented procedures, legal requirements, and directives from the PIC. After the authorized retention period, data is securely disposed of or anonymized.

  6. Data Breach Reporting
    In the event of an actual or suspected personal data breach, the Company will:
    • Activate internal breach response procedures
    • Assess the nature, scope, and potential impact of the incident
    • Coordinate with the PIC for notification and required actions
    • Notify relevant authorities (e.g., National Privacy Commission) when legally mandated
    • Implement corrective and preventive measures
  7. Contact Information
    For concerns or inquiries regarding this Privacy Notice or the processing of personal data, you may contact:
    Data Protection Officer (DPO)

    S.P. Madrid & AssociatesContact#: +639190616514
    Email: privacy@spmadridlaw.com

    S.P. Madrid CorporationContact#: +639190616514
    Email: dpo@spmadridlaw.com

    Requests to exercise data subject rights may also be directed to the relevant Personal Information Controller (PIC).

Statement of Commitment

This Privacy Notice affirms the Company's commitment to process personal data in a lawful, fair, and transparent manner while upholding confidentiality, integrity, accountability, and full compliance with applicable laws and regulations throughout all operational and service-related activities.