Last Updated: July 29, 2026
Effective Date: July 29, 2026
In plain language: when you use Suppliq to record your staff's attendance or your customers' details, you decide what to collect and why — so under Philippine data-privacy law you are the "controller" of that information and we are your "processor". This agreement sets out what we do with it, what we will never do with it, and what each of us is responsible for. It also means you are the one responsible for telling your staff and customers that you collect their data.
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between SUPPLIQ SOFTWARE DEVELOPMENT SERVICES ("Suppliq," "we," "us") and the business that has registered a Suppliq account ("Customer," "you").
It applies to Suppliq's processing of personal data on your behalf under the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission ("NPC"), including NPC Circular 16-02 on outsourcing and subcontracting.
Where this DPA conflicts with the Terms of Service or the Privacy Policy in respect of the processing of Merchant Data, this DPA prevails.
The platform involves two distinct categories of personal data, with different roles attaching to each:
2.1 Account Data — Suppliq is the Personal Information Controller
Information about you as our customer: the account holder's name, email address, contact number, business details, billing and payment records, and support correspondence. We determine the purposes and means of processing this data, and our handling of it is described in our Privacy Policy.
2.2 Merchant Data — you are the Personal Information Controller; Suppliq is the Personal Information Processor
Personal data you enter into, or generate through, the platform about other people — your employees and your own customers. You determine what is collected and why. We process it only to provide the Service to you, on your instructions, and never for our own purposes.
Nothing in this DPA makes Suppliq a controller of Merchant Data. If we ever determine the purposes of processing Merchant Data for our own account, we become a controller for that processing and will tell you before doing so.
Subject matter and nature: hosting, storage, organisation, retrieval, computation, transmission, backup and deletion of Merchant Data, carried out by automated means as part of operating a point-of-sale, inventory, HR and analytics platform.
Purpose: solely to provide, maintain, secure and support the Service for you, and to comply with our own legal obligations.
Duration: for as long as your account is active, plus the retention period in Section 9.
Data subjects: your employees and staff members; your customers; your suppliers' contact persons; and any other individual whose details you choose to record.
Categories of personal data:
Note on attendance photographs. Clock-in and clock-out selfies are photographs of identifiable individuals collected for workforce monitoring. You should treat them as sensitive in practice, inform your staff before enabling the feature, and be prepared to justify their collection as proportionate. You can operate attendance without photographs by disabling the selfie requirement in your payroll settings. COUNSEL: please confirm whether attendance selfies constitute "sensitive personal information" under RA 10173 §3(l) in this context, since that would raise the consent standard for our merchants.
You represent and undertake that:
You authorise us to engage the following sub-processors to provide the Service. Each is bound by obligations no less protective than those in this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage — all Merchant Data resides here | United States |
| Vercel | Application hosting; processes requests and logs technical metadata | United States |
| GoHighLevel | Transactional email to the account holder. Receives Account Data only — not staff, customer or sales records | United States |
| OpenRouter / Google Gemini | AI Insights and AI Help. Receives aggregated business summaries; prompts are not used for model training | United States |
| PayMongo | Subscription payment processing. Receives Account Data and billing details; card details are handled by PayMongo and never stored by Suppliq | Philippines |
Changes: we will update this page before engaging a new sub-processor that will process Merchant Data, and will notify account holders by email. If you object on reasonable data-protection grounds, tell us within thirty (30) days and we will work with you in good faith; if no resolution is possible you may terminate the affected Service without penalty and receive a prorated refund of prepaid fees.
Cross-border transfer: most sub-processors store data outside the Philippines, primarily in the United States. By using the Service you instruct us to make those transfers. We remain accountable for Merchant Data transferred to a sub-processor.
No system is perfectly secure. These measures reduce risk; they do not eliminate it.
If we become aware of a personal data breach affecting Merchant Data, we will notify you without undue delay and in any event within seventy-two (72) hours of becoming aware of it, providing the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.
Because you are the controller of Merchant Data, you are responsible for notifying the NPC and the affected data subjects where the breach meets the notification threshold under RA 10173 and NPC Circular 16-03. We will provide reasonable assistance and the information you need to make that notification.
Where a breach affects Account Data, Suppliq is the controller and will make the NPC and data-subject notifications itself.
If one of your employees or customers contacts us directly to exercise a right over Merchant Data, we will not respond substantively. We will direct them to you and inform you of the request without undue delay, because the decision is yours to make as controller.
The Service provides export and deletion features so you can satisfy access, portability, correction and erasure requests yourself. Where you cannot do so with those features, contact privacy@suppliq.app and we will assist.
We retain Merchant Data for as long as your account is active, including after a paid subscription lapses — ending a subscription does not delete data.
On account deletion, Merchant Data is erased from production systems immediately and irreversibly. There is no recovery window. Residual copies in encrypted infrastructure backups are purged within thirty (30) days.
You may export your data at any time while the account is active using the Service's export features. Because deletion cannot be undone, export before deleting — and note that as controller you may have your own retention obligations toward your staff, for example under the Labor Code, which deletion would prevent you from meeting.
We may retain anonymised or aggregated data that no longer identifies any individual, and records we are required to keep for legal, tax or accounting purposes, beyond that period.
On reasonable written request, and no more than once in any twelve (12) month period unless required by the NPC or following a breach, we will provide information reasonably necessary to demonstrate compliance with this DPA. Where available, we may satisfy such a request by providing our sub-processors' third-party certifications or reports.
We will cooperate with the NPC in the exercise of its functions in respect of Merchant Data.
Each party remains responsible for its own compliance with RA 10173 in respect of the role allocated to it under Section 2. The limitations of liability in the Terms of Service apply to this DPA, save that nothing in this DPA or the Terms limits either party's liability where such limitation is not permitted by law.
This DPA is governed by the laws of the Republic of the Philippines. COUNSEL: please confirm the liability allocation here is appropriate, and whether a controller indemnity in favour of Suppliq should be added for merchants who process without a lawful basis.
Questions about this DPA, or requests for assistance with a data-protection matter:
SUPPLIQ SOFTWARE DEVELOPMENT SERVICES
Email: privacy@suppliq.app
Phone: +63 952 483 3994
9th Floor, Sinocan Corporate Center
Aseana Business Park, Bay City
Tambo, Parañaque City 1701
Metro Manila, Philippines
You may also contact the National Privacy Commission at privacy.gov.ph.