← Back to Suppliq

Data Processing Agreement

Last Updated: July 29, 2026

Effective Date: July 29, 2026

In plain language: when you use Suppliq to record your staff's attendance or your customers' details, you decide what to collect and why — so under Philippine data-privacy law you are the "controller" of that information and we are your "processor". This agreement sets out what we do with it, what we will never do with it, and what each of us is responsible for. It also means you are the one responsible for telling your staff and customers that you collect their data.

1. Parties and Scope

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between SUPPLIQ SOFTWARE DEVELOPMENT SERVICES ("Suppliq," "we," "us") and the business that has registered a Suppliq account ("Customer," "you").

It applies to Suppliq's processing of personal data on your behalf under the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission ("NPC"), including NPC Circular 16-02 on outsourcing and subcontracting.

Where this DPA conflicts with the Terms of Service or the Privacy Policy in respect of the processing of Merchant Data, this DPA prevails.

2. Roles of the Parties

The platform involves two distinct categories of personal data, with different roles attaching to each:

2.1 Account Data — Suppliq is the Personal Information Controller

Information about you as our customer: the account holder's name, email address, contact number, business details, billing and payment records, and support correspondence. We determine the purposes and means of processing this data, and our handling of it is described in our Privacy Policy.

2.2 Merchant Data — you are the Personal Information Controller; Suppliq is the Personal Information Processor

Personal data you enter into, or generate through, the platform about other people — your employees and your own customers. You determine what is collected and why. We process it only to provide the Service to you, on your instructions, and never for our own purposes.

Nothing in this DPA makes Suppliq a controller of Merchant Data. If we ever determine the purposes of processing Merchant Data for our own account, we become a controller for that processing and will tell you before doing so.

3. Subject Matter, Nature, Purpose and Duration

Subject matter and nature: hosting, storage, organisation, retrieval, computation, transmission, backup and deletion of Merchant Data, carried out by automated means as part of operating a point-of-sale, inventory, HR and analytics platform.

Purpose: solely to provide, maintain, secure and support the Service for you, and to comply with our own legal obligations.

Duration: for as long as your account is active, plus the retention period in Section 9.

4. Categories of Data Subjects and Personal Data

Data subjects: your employees and staff members; your customers; your suppliers' contact persons; and any other individual whose details you choose to record.

Categories of personal data:

  • Employee data — names, roles, assigned branches, login credentials, attendance records including clock-in and clock-out photographs, working hours, leave records, payroll computations, cash advances and deductions.
  • Customer data — names, contact details, purchase history, loyalty balances, credit or "utang" balances and payment records, and where you use the relevant modules, service records such as pet or laundry details.
  • Supplier data — contact person names, contact details and payment account details you record.

Note on attendance photographs. Clock-in and clock-out selfies are photographs of identifiable individuals collected for workforce monitoring. You should treat them as sensitive in practice, inform your staff before enabling the feature, and be prepared to justify their collection as proportionate. You can operate attendance without photographs by disabling the selfie requirement in your payroll settings. COUNSEL: please confirm whether attendance selfies constitute "sensitive personal information" under RA 10173 §3(l) in this context, since that would raise the consent standard for our merchants.

5. Your Responsibilities as Controller

You represent and undertake that:

  • You have a lawful basis under RA 10173 for each category of personal data you enter into the Service.
  • You have given the required privacy notice to your employees and customers, covering what you collect, why, how long you keep it, and that it is stored using a third-party platform on your behalf.
  • Where consent is the basis you rely on — most commonly for attendance photographs — you have obtained it, and you can evidence it.
  • You will respond to requests from your own employees and customers to access, correct, or erase their data, using the Service's own features to do so.
  • Your instructions to us will not require us to process personal data unlawfully.

6. Our Obligations as Processor

  • We process Merchant Data only on your documented instructions. Your use of the Service's features, and the settings you choose, constitute those instructions. We will tell you if we believe an instruction breaches RA 10173.
  • We do not sell, rent or trade Merchant Data, and we do not use it for advertising or to train artificial-intelligence models.
  • Personnel with access to Merchant Data are bound by confidentiality obligations and access it only where needed to operate or support the Service.
  • Support access to your account is deliberate, logged, and time-limited, and is used only to diagnose an issue or at your request.
  • We maintain the security measures described in Section 8 and assist you, so far as reasonably practicable, with your own obligations in respect of security, breach notification and data-subject requests.

7. Sub-processors

You authorise us to engage the following sub-processors to provide the Service. Each is bound by obligations no less protective than those in this DPA.

Sub-processor Purpose Location
Supabase Database, authentication and file storage — all Merchant Data resides here United States
Vercel Application hosting; processes requests and logs technical metadata United States
GoHighLevel Transactional email to the account holder. Receives Account Data only — not staff, customer or sales records United States
OpenRouter / Google Gemini AI Insights and AI Help. Receives aggregated business summaries; prompts are not used for model training United States
PayMongo Subscription payment processing. Receives Account Data and billing details; card details are handled by PayMongo and never stored by Suppliq Philippines

Changes: we will update this page before engaging a new sub-processor that will process Merchant Data, and will notify account holders by email. If you object on reasonable data-protection grounds, tell us within thirty (30) days and we will work with you in good faith; if no resolution is possible you may terminate the affected Service without penalty and receive a prorated refund of prepaid fees.

Cross-border transfer: most sub-processors store data outside the Philippines, primarily in the United States. By using the Service you instruct us to make those transfers. We remain accountable for Merchant Data transferred to a sub-processor.

8. Security Measures

  • Encryption of data in transit (TLS) and at rest at the infrastructure layer.
  • Tenant isolation enforced in the database itself through row-level security, so one merchant's data is not reachable from another merchant's session.
  • Role-based access control within each account — owner, admin, manager, staff and viewer — with per-branch restriction available.
  • Audit logging of security-relevant actions, including stock adjustments, voided transactions and permission changes.
  • Authentication managed by our infrastructure provider; Suppliq personnel do not have access to your password.
  • Regular backups, with restoration procedures maintained by our infrastructure provider.

No system is perfectly secure. These measures reduce risk; they do not eliminate it.

9. Personal Data Breach

If we become aware of a personal data breach affecting Merchant Data, we will notify you without undue delay and in any event within seventy-two (72) hours of becoming aware of it, providing the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.

Because you are the controller of Merchant Data, you are responsible for notifying the NPC and the affected data subjects where the breach meets the notification threshold under RA 10173 and NPC Circular 16-03. We will provide reasonable assistance and the information you need to make that notification.

Where a breach affects Account Data, Suppliq is the controller and will make the NPC and data-subject notifications itself.

10. Data Subject Requests

If one of your employees or customers contacts us directly to exercise a right over Merchant Data, we will not respond substantively. We will direct them to you and inform you of the request without undue delay, because the decision is yours to make as controller.

The Service provides export and deletion features so you can satisfy access, portability, correction and erasure requests yourself. Where you cannot do so with those features, contact privacy@suppliq.app and we will assist.

11. Retention, Return and Deletion

We retain Merchant Data for as long as your account is active, including after a paid subscription lapses — ending a subscription does not delete data.

On account deletion, Merchant Data is erased from production systems immediately and irreversibly. There is no recovery window. Residual copies in encrypted infrastructure backups are purged within thirty (30) days.

You may export your data at any time while the account is active using the Service's export features. Because deletion cannot be undone, export before deleting — and note that as controller you may have your own retention obligations toward your staff, for example under the Labor Code, which deletion would prevent you from meeting.

We may retain anonymised or aggregated data that no longer identifies any individual, and records we are required to keep for legal, tax or accounting purposes, beyond that period.

12. Audit and Cooperation

On reasonable written request, and no more than once in any twelve (12) month period unless required by the NPC or following a breach, we will provide information reasonably necessary to demonstrate compliance with this DPA. Where available, we may satisfy such a request by providing our sub-processors' third-party certifications or reports.

We will cooperate with the NPC in the exercise of its functions in respect of Merchant Data.

13. Liability and Governing Law

Each party remains responsible for its own compliance with RA 10173 in respect of the role allocated to it under Section 2. The limitations of liability in the Terms of Service apply to this DPA, save that nothing in this DPA or the Terms limits either party's liability where such limitation is not permitted by law.

This DPA is governed by the laws of the Republic of the Philippines. COUNSEL: please confirm the liability allocation here is appropriate, and whether a controller indemnity in favour of Suppliq should be added for merchants who process without a lawful basis.

14. Contact

Questions about this DPA, or requests for assistance with a data-protection matter:

SUPPLIQ SOFTWARE DEVELOPMENT SERVICES
Email: privacy@suppliq.app
Phone: +63 952 483 3994
9th Floor, Sinocan Corporate Center
Aseana Business Park, Bay City
Tambo, Parañaque City 1701
Metro Manila, Philippines

You may also contact the National Privacy Commission at privacy.gov.ph.

Privacy Policy Refund Policy Terms of Service Contact