Skip to content
Reestly

Privacy Policy.

Last updated: January 2025 · Reestly Technologies Inc. · One Global Place, BGC, Taguig City, Metro Manila, Philippines

Reestly Technologies Inc. ("Reestly", "we", "us"), organized under the laws of the Republic of the Philippines, respects your privacy in accordance with Republic Act No. 10173 — the Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations (IRR), and the issuances of the National Privacy Commission (NPC). This policy explains what personal information we collect, why, how we protect it, and the rights you can exercise.

1. Scope

This policy covers personal data processed through our website, the Reestly platform (POS, inventory, HRIS, payroll, and analytics services), and our business communications. It applies to website visitors, prospective customers, and platform users — including the personal data of your employees that you process using our HRIS tools, where we act strictly as a personal information processor on your documented instructions.

2. Personal information we collect

  • Account & business data: name, business name, job role, email, phone number, business address, and TIN for billing.
  • Usage data: device information, IP address, browser type, pages visited, and product interaction logs.
  • Payroll & HR data (on your behalf): employee names, government IDs (SSS, PhilHealth, Pag-IBIG, TIN), attendance, and salary data.
  • Cookies & tracking: see our Cookie Policy.

3. Purposes of processing

  • To provide, operate, maintain, and secure the Reestly platform and services you requested (contractual necessity).
  • To process payments and billing for subscriptions.
  • To send service announcements, product updates, and — with your consent — marketing communications.
  • To comply with legal obligations under Philippine law (BIR record-keeping, BSP-related requirements of payment partners, AML obligations where applicable).
  • To improve our services through aggregated, de-identified analytics.

4. Lawful basis and consent

We process personal data based on: (a) your consent, which you may withdraw at any time; (b) the performance of a contract with you; (c) compliance with legal obligations; and (d) our legitimate interests, balanced against your rights under the DPA. Withdrawal of consent does not affect the lawfulness of processing already carried out.

5. Data sharing and disclosure

We do not sell your personal data. We share it only with: (a) service providers and subprocessors under data-processing agreements (cloud hosting, payment gateways); (b) government authorities when required by law, court order, or valid NPC directive; and (c) affiliates within the Vaultera Labs group under the same protections. All third parties are bound by confidentiality and security obligations no less protective than this policy.

6. Cross-border transfers

Where data is transferred outside the Philippines (for example, to international cloud infrastructure), we ensure an adequate level of protection through contractual safeguards consistent with NPC Advisory No. 2020-04 and Section 46 of the DPA IRR.

7. Data security and retention

We implement organizational, physical, and technical security measures — encryption in transit and at rest, access controls, audit logging, and regular vulnerability testing — consistent with Section 34(c) of the DPA IRR. Personal data is retained only as long as necessary for the stated purposes or as required by law (e.g., BIR retention rules for financial records); thereafter it is securely deleted or anonymized.

8. Your rights as a data subject

Under Sections 16 and 18 of the DPA, you have the right to:

  • Be informed whether your personal data is being processed;
  • Reasonable access to your personal data, including a copy in an intelligible format;
  • Rectification of inaccurate or incomplete data;
  • Erasure or blocking of data processed unlawfully or no longer necessary;
  • Object to processing, including direct marketing;
  • Damages for violations of the DPA; and
  • Data portability where applicable.

9. Exercising your rights & complaints

To exercise any right or inquire about our processing, contact our Data Protection Officer at dpo@reestly.com or our office address. We will respond within thirty (30) days in accordance with NPC rules. If you believe your rights have been violated, you may also file a complaint with the National Privacy Commission (npc.gov.ph).

10. Changes to this policy

We may update this policy to reflect changes in law or our practices. Material changes will be announced on our website or by email at least thirty (30) days before taking effect. Continued use of the services after the effective date constitutes acceptance.

11. Contact

Data Protection Officer, Reestly Technologies Inc., One Global Place, 5th Avenue, Bonifacio Global City, Taguig City, Metro Manila, Philippines 1634 · dpo@reestly.com