ERPat, operated by BytesCrafter IT Solutions (“ERPat,” “we,” “us,” or “our”), respects your right to privacy. We are committed to processing personal information fairly, lawfully, and transparently, consistent with the Data Privacy Act of 2012 (Republic Act No. 10173, the “DPA”), its Implementing Rules and Regulations (the “IRR”), and the issuances of the National Privacy Commission (the “NPC”).
Two relationships, two roles. When you create an account directly with ERPat, we are the Personal Information Controller. When your employer or organization uses ERPat to process your records (for example, payroll and HR data), they are the Controller and ERPat acts as their Personal Information Processor. In that case, please also review your organization's own privacy notice.
1. Introduction & Scope
This Privacy Policy applies to personal information we process through the ERPat platform — our websites, web and mobile applications, APIs, and related services (collectively, the “Service”). It describes the personal information we collect, how and why we use it, who we share it with, how long we keep it, how we protect it, and the rights available to you as a data subject.
“Personal information,” “sensitive personal information,” “processing,” “personal information controller” (PIC), and “personal information processor” (PIP) have the meanings given to them in the DPA.
2. Who We Are & Our Role
ERPat provides a multi-tenant enterprise platform covering human resources, payroll, finance, inventory, operations, and related modules. Depending on the context, our role differs:
- As a Personal Information Controller (PIC): for the personal information of individuals who register accounts with us, our direct customers' contact persons, website visitors, support requesters, and prospective customers — where we determine the purposes and means of processing.
- As a Personal Information Processor (PIP): for the personal information that a Customer (your employer or organization) uploads, stores, or generates through the Service about its employees, workers, clients, and other data subjects. We process that data only on the Customer's documented instructions and for the duration of their subscription.
If you are an employee or data subject whose data is processed by an organization using ERPat, that organization is the Controller responsible for your data, and you should direct rights requests to them in the first instance; we will assist them in responding.
3. Information We Collect
| Category | Examples |
|---|---|
| Account & identity data | Name, email address, mobile number, job title or role, password (stored only as a secure hash), and verification codes. |
| Organization / business data | Company name, legal name, business type, industry, company size, tax identification or registration number, address, and website. |
| Employee & HR records (as PIP) | Personnel details, attendance, schedules, leave, compensation, payroll, statutory contributions (SSS, PhilHealth, Pag-IBIG, BIR), and related documents — uploaded by the Customer. |
| Usage & device data | IP address, browser and device type, log data, pages and features used, timestamps, and approximate location derived from IP. |
| Communications | Support tickets, emails, and feedback you send to us. |
| Cookies & identifiers | Session and preference cookies and similar technologies (see Section 7). |
We collect only what is relevant and necessary for the declared, specified, and legitimate purposes below.
4. Sensitive Personal Information
The DPA defines sensitive personal information to include information about an individual's race or ethnic origin, marital status, age, color, religious, philosophical or political affiliations; health, education, genetic or sexual life; any proceeding for an offense; and government-issued identifiers unique to an individual (such as SSS, TIN, PhilHealth, or Pag-IBIG numbers).
The Service — particularly HR and payroll modules — may process sensitive personal information that a Customer chooses to store. We process such information only where a lawful condition under Section 13 of the DPA applies (for example, the data subject's consent, or where processing is necessary to comply with employment, social security, or tax obligations), and we apply heightened safeguards to it.
5. How We Collect It
- Directly from you — when you register, configure your account, communicate with support, or otherwise use the Service.
- From your organization — when your employer or a Customer adds you as an Authorized User or uploads records about you.
- Automatically — through cookies, server logs, and analytics when you use the Service.
- From third parties — such as authentication, payment, or communication providers that support specific features you enable.
6. Why We Process It & Lawful Basis
Under the DPA, processing must rely on at least one lawful criterion (Section 12 for personal information; Section 13 for sensitive personal information). We process personal information for the purposes and bases below:
| Purpose | Lawful basis |
|---|---|
| Create and administer your account; provide the Service | Performance of a contract with you; legitimate interests. |
| Verify identity and secure accounts (e.g., email OTP) | Contract; legitimate interests in security and fraud prevention. |
| Process HR, payroll, and statutory records (as PIP) | On the Customer's documented instructions and lawful basis; compliance with legal obligations. |
| Provide support and respond to inquiries | Contract; legitimate interests. |
| Improve, monitor, and secure the Service | Legitimate interests, balanced against your rights. |
| Send service and, where permitted, marketing communications | Consent (for marketing); legitimate interests (for service notices). |
| Comply with law, regulation, or lawful orders | Compliance with a legal obligation. |
Where we rely on your consent, it is freely given, specific, informed, and evidenced, and you may withdraw it at any time without affecting prior lawful processing.
7. Cookies & Similar Technologies
We use strictly necessary cookies to keep you signed in, maintain your session and security (including CSRF protection), and remember preferences such as your appearance/theme setting. We may use limited analytics to understand and improve how the Service is used. You can control cookies through your browser settings; disabling strictly necessary cookies may prevent the Service from functioning properly.
8. How We Share & Disclose Information
We do not sell personal information. We disclose it only as needed and with appropriate safeguards:
- Service providers / sub-processors — hosting, storage, email, SMS, analytics, and similar providers who process data on our behalf under confidentiality and data-protection obligations;
- Within your organization — to administrators and Authorized Users as configured by the Customer;
- Government and statutory bodies — where you use the Service to meet obligations to agencies such as the BIR, SSS, PhilHealth, and Pag-IBIG, or where disclosure is required by law;
- Legal and safety — to comply with a subpoena, lawful order, or legal process, or to protect rights, property, and safety; and
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
9. Cross-Border Data Transfers
Your personal information is primarily processed and stored in or for the Philippines. Where data is transferred to or accessed from another country (for example, by a cloud provider or sub-processor), we remain accountable for it and take reasonable steps to ensure it is afforded a comparable level of protection, consistent with the DPA and applicable contractual safeguards.
10. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, to provide the Service, and to comply with legal, tax, accounting, or reporting requirements. Customer Data processed as a PIP is retained for the duration of the Customer's subscription and a limited export window thereafter, after which it is deleted or anonymized in the ordinary course, subject to backup cycles and any legal hold. Retention periods for employment and payroll records are determined by the Customer in line with applicable law.
11. How We Protect Your Data
Consistent with Section 20 of the DPA, we maintain organizational, physical, and technical security measures designed to protect personal information against accidental or unlawful destruction, alteration, disclosure, or access, including:
- Encryption of data in transit (HTTPS/TLS) and protection of credentials using strong, salted hashing;
- Role-based access controls, the principle of least privilege, and tenant isolation in multi-tenant deployments;
- Security middleware (input sanitization, secure headers, rate limiting, CSRF protection) and audit logging;
- Regular backups, and review of our safeguards as technology and risks evolve; and
- Confidentiality obligations for personnel and sub-processors with access to personal information.
No system can be guaranteed completely secure; you also play an essential role by keeping your credentials confidential and your software up to date.
12. Data Breach Management
We maintain a personal data breach response procedure. In the event of a personal data breach that meets the notification criteria under the DPA and NPC Circular 16-03, we will notify the National Privacy Commission and the affected data subjects within seventy-two (72) hours of knowledge of, or reasonable belief in, the breach, and we will take steps to contain, assess, and remediate the incident. When ERPat acts as a PIP, we will promptly notify the relevant Customer (Controller) so they can meet their notification obligations.
13. Your Rights as a Data Subject
Subject to the conditions and exceptions in the DPA, you have the right to:
- Be informed whether your personal information is being or has been processed, and to receive certain information before entry into our processing systems;
- Access your personal information and details about how it is processed;
- Object to processing, including for direct marketing or automated processing;
- Rectify (correct) inaccurate or erroneous personal information;
- Erasure or blocking — to suspend, withdraw, or order the removal of your personal information under the conditions set by law;
- Data portability — to obtain a copy of data you provided in a commonly used, electronic format;
- File a complaint with the NPC; and
- Damages — to be indemnified for damages sustained due to unlawful or unauthorized processing.
The right to access and to data portability may also be transmissible to the lawful heirs and assigns of the data subject. To exercise your rights, contact our Data Protection Officer (Section 15). If your data is held by an organization using ERPat, please direct your request to that organization; we will support them in responding.
14. Children's Privacy
The Service is intended for use by organizations and adults (18 years and older). We do not knowingly collect personal information directly from children to create accounts. Where a Customer processes records relating to minors (for example, dependents in HR records), the Customer is responsible for obtaining any consent required by law.
15. Data Protection Officer & How to Contact Us
We have designated a Data Protection Officer (DPO) responsible for overseeing our compliance with the DPA. To ask a question, exercise your rights, or raise a privacy concern, contact us:
Data Protection Officer — ERPat / BytesCrafter IT Solutions
Privacy & DPO: [email protected]
Support: [email protected]
Website: https://erpat.app
We will respond to verified requests within a reasonable period and in accordance with the DPA.
16. Complaints to the National Privacy Commission
If you believe your data privacy rights have been violated and we have not adequately addressed your concern, you may lodge a complaint with the National Privacy Commission:
National Privacy Commission (NPC)
[email protected] · [email protected]
PICC Complex, Roxas Boulevard, Pasay City, Metro Manila, Philippines
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will revise the “Last Updated” date above and, for material changes, provide reasonable notice. Your continued use of the Service after the changes take effect constitutes acceptance of the updated Policy.
This Privacy Policy is provided for general informational purposes and as a starting template aligned with the Philippine Data Privacy Act of 2012. It does not constitute legal advice. We recommend review by a qualified Data Protection Officer or legal counsel to reflect your specific processing activities.