1. Overview & scope
hellopinas ("we", "our", "us") operates the website at hellopinas.com and provides enterprise digital solutions including web development, mobile applications, AI integration, and business automation services. This Privacy Policy describes how we collect, use, store, share, and protect personal data in connection with our website and services.
This Policy applies to all individuals who interact with us, including website visitors, prospective clients, existing clients, and business contacts, regardless of their location. We are committed to complying with applicable data protection laws across all regions in which we operate, including the EU General Data Protection Regulation (GDPR), the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), applicable Asia-Pacific privacy frameworks, and the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
2. Data controller
The data controller responsible for your personal data is:
hellopinas
Philippines
Email: ask@hellopinas.com
Phone: +63 945 830 5626
For EU/EEA residents, we act as the data controller under Article 4(7) of the GDPR. Where we process data on behalf of clients, we act as a data processor and enter into appropriate Data Processing Agreements (DPAs).
3. Information we collect
3.1 Information you provide directly
- Contact details: name, email address, phone number, company name
- Inquiry and project details submitted through our contact form
- Communications you send us by email or other channels
- Business information provided during service engagements
3.2 Information collected automatically
When you visit our website, we automatically collect technical data including:
- IP address and approximate geolocation (country or city level)
- Browser type, version, and language settings
- Operating system and device type
- Pages visited, time spent, and navigation paths
- Referring URLs and search terms
- Cookie identifiers and session data
3.3 Security monitoring data
We log activity for cybersecurity purposes. If you attempt to access restricted administrative paths, we collect and log your IP address, user agent, attempted credentials, and behavioural patterns for threat analysis and security incident reporting. This processing is based on our legitimate interest in protecting our systems and users.
3.4 Information from third parties
We may receive information about you from third-party sources such as business partners, referral sources, and publicly available professional directories, which we combine with information we already hold about you.
4. Lawful basis for processing (GDPR Article 6)
For users in the EU/EEA, we process personal data only where we have a valid lawful basis:
| Processing activity | Lawful basis |
|---|---|
| Responding to contact form inquiries | Legitimate interests (Art. 6(1)(f)) / Pre-contractual steps (Art. 6(1)(b)) |
| Delivering contracted services | Performance of a contract (Art. 6(1)(b)) |
| Website analytics and performance monitoring | Legitimate interests (Art. 6(1)(f)) |
| Security monitoring and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Marketing communications (where opted in) | Consent (Art. 6(1)(a)) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Cookie placement (non-essential) | Consent (Art. 6(1)(a)) |
Where we rely on legitimate interests, we have conducted a balancing test and determined that our interests do not override your fundamental rights and freedoms. You may request a copy of our legitimate interests assessment by contacting us.
5. How we use your information
- To respond to your inquiries and provide requested information about our services
- To deliver, manage, and improve the services we provide to you
- To communicate with you about your project, account, or service updates
- To send marketing communications where you have consented or where permitted by applicable law
- To analyse website usage and improve user experience
- To detect, investigate, and prevent fraud, security incidents, and other illegal activity
- To comply with legal and regulatory obligations
- To enforce our Terms of Use and other agreements
- To conduct business operations including invoicing, accounting, and record-keeping
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects without your explicit consent.
7. International data transfers
hellopinas is headquartered in the Philippines and serves clients across EMEA and APAC. Your personal data may be transferred to and processed in countries outside your country of residence, including the United States and other jurisdictions where we operate.
7.1 EU/EEA transfers
When transferring personal data from the EU/EEA to third countries, we rely on one or more of the following safeguards as required by GDPR Chapter V:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Binding Corporate Rules where relevant
7.2 Other EMEA transfers
For transfers involving individuals in other EMEA jurisdictions outside the EU/EEA, we apply appropriate contractual safeguards to ensure an adequate level of protection for personal data, consistent with applicable local law.
7.3 Asia-Pacific transfers
For transfers involving personal data of individuals in the Philippines, India, or other Asia-Pacific jurisdictions, we comply with applicable cross-border transfer requirements including the APEC Cross-Border Privacy Rules (CBPR) framework where applicable.
8. Data retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our general retention periods are:
| Data category | Retention period |
|---|---|
| Contact form inquiries (no contract formed) | 2 years from last contact |
| Client project and contract data | 7 years from contract end (legal/tax obligations) |
| Website analytics data | 26 months (Google Analytics default) |
| Security and access logs | 12 months |
| Marketing consent records | Until consent is withdrawn, plus 3 years |
| Cookie consent records | 1 year |
When data is no longer required, we securely delete or anonymise it in accordance with our data disposal procedures.
9. Security measures
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- HTTPS/TLS encryption for all data in transit
- HTTP Strict Transport Security (HSTS) headers
- Content Security Policy (CSP) and XSS protection headers
- Access controls and authentication requirements for internal systems
- Regular security monitoring and intrusion detection
- Logging of unauthorised access attempts
- Vendor security assessments for third-party processors
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware (as required by GDPR Article 33) and will notify affected individuals without undue delay where required.
11. Your rights: EU / EEA (GDPR)
If you are located in the European Union or European Economic Area, you have the following rights under the GDPR:
- Right of access (Art. 15): obtain a copy of your personal data and information about how it is processed
- Right to rectification (Art. 16): correct inaccurate or incomplete personal data
- Right to erasure (Art. 17): request deletion of your data where no legitimate grounds for retention exist
- Right to restriction of processing (Art. 18): request that we limit how we use your data in certain circumstances
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format
- Right to object (Art. 21): object to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making (Art. 22): not be subject to solely automated decisions with significant effects
- Right to withdraw consent at any time, without affecting prior processing
You also have the right to lodge a complaint with your local supervisory authority. In the EU, you can find your national Data Protection Authority at edpb.europa.eu.
We will respond to all verified requests within 30 days. In complex cases, we may extend this by a further two months and will notify you accordingly.
12. Your rights: other EMEA & APAC jurisdictions
If you are located in the wider EMEA or APAC region and are not already covered by the EU/EEA provisions above or the specific Asia-Pacific jurisdictions listed below, we are nonetheless committed to honouring your data protection rights to the extent required by applicable local law. Depending on your jurisdiction, this generally includes the right to:
- Be informed about the collection and processing of your personal data
- Access your personal data held by us
- Correct inaccurate or incomplete personal data
- Request erasure of your personal data where processing is no longer necessary
- Object to processing of your personal data
- Withdraw consent at any time
- Request restriction of processing in certain circumstances
- Lodge a complaint with your local data protection authority, where one exists
To exercise any of these rights, contact us. We will respond within 30 days, or within the timeframe required by applicable local law.
13. Your rights: Asia-Pacific
Philippines (Data Privacy Act of 2012: Republic Act 10173)
If you are located in the Philippines, you have the following rights under the Data Privacy Act of 2012 and its Implementing Rules and Regulations:
- Right to be informed: know what personal data is being collected and how it will be used
- Right to access: obtain a copy of your personal data
- Right to object: refuse or withdraw consent to processing
- Right to erasure or blocking: suspend, withdraw, or order the blocking, removal, or destruction of your data
- Right to damages: be indemnified for damages sustained due to inaccurate, incomplete, or unlawfully obtained data
- Right to data portability: obtain a copy of your data in an electronic or structured format
- Right to rectification: correct inaccurate or incomplete data
- Right to file a complaint with the National Privacy Commission (NPC)
India (Digital Personal Data Protection Act 2023)
If you are located in India, you have the following rights under the Digital Personal Data Protection Act 2023:
- Right to access information about your personal data being processed
- Right to correction and erasure of inaccurate or incomplete personal data
- Right to grievance redressal
- Right to nominate another individual to exercise rights on your behalf
- Right to withdraw consent at any time
Other Asia-Pacific jurisdictions
We also respect the privacy rights of individuals in Australia (Privacy Act 1988), Singapore (Personal Data Protection Act 2012), and other Asia-Pacific jurisdictions. Residents of these countries may contact us to exercise applicable rights under their local laws.
14. Your rights: United States (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights:
- Right to know: request disclosure of the categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of third parties with whom we share it
- Right to delete: request deletion of personal information we have collected, subject to certain exceptions
- Right to correct: request correction of inaccurate personal information
- Right to opt out of sale or sharing: we do not sell or share personal information for cross-context behavioural advertising
- Right to limit use of sensitive personal information: we do not use sensitive personal information beyond what is necessary to provide our services
- Right to non-discrimination: we will not discriminate against you for exercising your rights
Categories of personal information collected
- Identifiers: name, email address, IP address, phone number
- Commercial information: service inquiries and project details
- Internet or other electronic network activity: browsing and interactions on our site
- Geolocation data: approximate location derived from IP address
- Inferences: derived from the above to understand preferences
We do not sell personal information as defined under the CCPA/CPRA. To submit a verifiable consumer request, contact us with the subject line "CCPA Request". We will respond within 45 days, with a possible 45-day extension where reasonably necessary.
Residents of other US states with applicable privacy laws (Virginia CDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA, and others) may also contact us to exercise applicable rights.
15. Children's privacy
Our website and services are not directed to individuals under the age of 18, or the applicable age of digital consent in your jurisdiction. We do not knowingly collect personal data from children. If you believe we have inadvertently collected information from a child, please contact us immediately and we will take prompt steps to delete it.
For EU residents, the age of digital consent varies by member state (13–16 years). We do not knowingly process data of minors below the applicable age of consent without verifiable parental consent.
16. Third-party links & services
Our website may contain links to third-party websites, services, or social media platforms. This Privacy Policy does not apply to those third-party sites. We encourage you to review the privacy policies of any third-party services you access through our website. We are not responsible for the privacy practices or content of third-party sites.
17. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "last updated" date at the top of this page
- Post a prominent notice on our website
- Where required by law, notify you directly by email
We encourage you to review this Policy periodically. Your continued use of our website after any changes constitutes your acceptance of the updated Policy, to the extent permitted by applicable law.
18. Contact & data protection
To exercise any of your rights, submit a privacy request, or raise a concern about our data practices, please get in touch.
hellopinas: privacy team
Email: ask@hellopinas.com
Phone: +63 945 830 5626
Manila, Philippines
Subject line: "Privacy request: [your region]"
We aim to respond to all privacy requests within 30 days. For complex requests, we may extend this period by up to two months and will inform you of the extension and the reasons for it.
If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction.