1. Introduction
This Philippines Privacy Disclosure supplements our general Privacy Policy and provides specific information for
individuals in the Philippines regarding how Asset Nexus Software Development and Marketing
Firm collects, uses, and protects personal data in compliance with the Data Privacy Act of
2012 (Republic Act No. 10173) and its Implementing Rules and Regulations (IRR).
Important Notice: This disclosure is specifically for Philippine residents. If you are
located outside the Philippines, please refer to our general Privacy Policy and other regional disclosures
that may apply to your jurisdiction.
2. Data Privacy Act of 2012 Compliance
2.1 Our Commitment
We are committed to protecting your personal data in accordance with the Data Privacy Act of 2012 (DPA). We have
implemented appropriate technical and organizational measures to ensure the security and confidentiality of your
personal information.
2.2 Personal Data Controller
Asset Nexus Software Development and Marketing Firm acts as the Personal Data Controller for
the personal data collected through the Asset Dispatch TMS platform. Our contact information is provided at the
end of this disclosure.
2.3 Registration with NPC
We have registered our data processing systems with the National Privacy Commission (NPC) in accordance with DPA
requirements. Our registration details are available upon request.
3. Personal Data We Collect
3.1 Definition of Personal Data
Under the DPA, "personal data" means any information whether recorded in a material form or not, from which the
identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the
information, or when put together with other information would directly and certainly identify an individual.
3.2 Types of Personal Data Collected
We collect the following types of personal data from Philippine residents:
- Common Personal Data: Name, email address, phone number, address, date of birth
- Sensitive Personal Information: Health information, medical certificates, driver's license
details, CDL information
- Privileged Information: Information arising from attorney-client relationships,
doctor-patient relationships (where applicable)
- Employment Data: Employment details, salary information, work history
- Location Data: GPS coordinates, location history, geofence data
- Financial Data: Bank account details, earnings, settlements, expense records
- Biometric Data: Facial recognition data (if used for authentication)
- Communication Data: Messages, call logs, notification preferences
4. Legal Bases for Processing
We process your personal data based on the following lawful bases under the DPA:
- Consent: You have given your consent for the processing of your personal data for specific
purposes
- Contract: Processing is necessary for the performance of a contract to which you are a
party (e.g., employment contract, service agreement)
- Legal Obligation: Processing is necessary for compliance with a legal obligation (e.g.,
FMCSA regulations, labor laws, tax requirements)
- Vital Interests: Processing is necessary to protect your life or health (e.g., emergency
response, medical assistance)
- Legitimate Interests: Processing is necessary for our legitimate interests or those of a
third party, provided that your fundamental rights and freedoms are not overridden
- Public Interest: Processing is necessary for the performance of a function carried out in
the public interest
5. Purposes of Processing
We process your personal data for the following specific purposes:
- Service Provision: To provide and operate the Asset Dispatch TMS platform and its features
- Employment Management: To manage employment relationships, payroll, and benefits
- Compliance Monitoring: To ensure compliance with FMCSA, DOT, and other regulatory
requirements
- Safety and Security: To monitor driver safety, track vehicle location, and respond to
emergencies
- Financial Processing: To process payments, settlements, and reimbursements
- Communication: To communicate with users about services, updates, and important information
- Analytics and Improvement: To analyze usage patterns and improve our services
- Legal Compliance: To comply with legal obligations and regulatory requirements
6. Data Processing Principles
We adhere to the following data processing principles under the DPA:
- Transparency: We inform you about the processing of your personal data
- Legitimate Purpose: We process personal data for specified, explicit, and legitimate
purposes
- Proportionality: We process only personal data that is adequate, relevant, and not
excessive
- Accuracy: We ensure personal data is accurate and kept up to date
- Security: We implement appropriate security measures to protect personal data
- Retention: We retain personal data only for as long as necessary for the purposes of
processing
7. Sensitive Personal Information
7.1 Definition
Under the DPA, "sensitive personal information" refers to personal information:
- About an individual's race, ethnicity, marital status, age, color, and religious or philosophical
affiliations
- About an individual's health, education, genetic or sexual life of a person, or to any proceeding for any
offense committed or alleged to have been committed by such person
- Issued by government agencies peculiar to an individual which includes, but not limited to, social security
numbers, previous or current health records, licenses or its denials, suspension or revocation, and tax
returns
- Specifically established by an executive order or an act of Congress to be kept classified
7.2 Processing Sensitive Personal Information
We process sensitive personal information only when:
- You have given explicit consent to the processing
- Processing is necessary for the exercise or performance of functions of government authorities
- Processing is necessary to protect your life or health
- Processing is necessary for medical diagnosis, treatment, or health care
- Processing is necessary for the protection of your lawful rights
- The information is necessary for the fulfillment of a contract with you
- Processing is authorized by law
8. Data Sharing and Disclosure
8.1 Sharing with Third Parties
We may share your personal data with third parties under the following circumstances:
- Your Employer: With your employer (carrier company) for employment and operational purposes
- Service Providers: With trusted third-party service providers (ELD providers, payment
processors, etc.) who assist us in providing services
- Regulatory Authorities: With government agencies when required by law (NPC, DOT, FMCSA,
etc.)
- Legal Proceedings: In connection with legal proceedings or to protect our rights
- Business Transfers: In connection with mergers, acquisitions, or sales of business assets
8.2 International Data Transfers
Your personal data may be transferred to and processed in countries outside the Philippines. We ensure that
appropriate safeguards are in place for such transfers, including:
- Standard contractual clauses approved by the NPC
- Adequacy determinations by the NPC
- Binding corporate rules (where applicable)
- Other appropriate safeguards as required by the DPA
9. Data Subject Rights
As a data subject under the DPA, you have the following rights:
9.1 Right to be Informed
- You have the right to be informed whether personal data pertaining to you shall be, are being, or have been
processed
- You have the right to be informed of the processing details, including the purposes, scope, and recipients
of your personal data
9.2 Right to Access
- You have the right to access your personal data that we hold
- You have the right to obtain a copy of your personal data in a commonly used format
- Requests for access should be made in writing and will be processed within 30 days
9.3 Right to Object
- You have the right to object to the processing of your personal data
- You may object to processing based on legitimate interests if you have compelling legitimate grounds
- You may object to processing for direct marketing purposes at any time
9.4 Right to Erasure or Blocking
- You have the right to request the erasure or blocking of your personal data
- We will comply with such requests when personal data is no longer necessary for the purposes of processing
- Certain exceptions apply where retention is required by law or for legitimate business purposes
9.5 Right to Damages
- You have the right to claim damages if your personal data is processed in violation of the DPA
- Damages may include material damage and moral damages
9.6 Right to Data Portability
- You have the right to receive your personal data in a structured, commonly used, and machine-readable format
- You have the right to transmit your personal data to another controller without hindrance
9.7 Right to File a Complaint
- You have the right to file a complaint with the National Privacy Commission if you believe your rights under
the DPA have been violated
- Complaints can be filed through the NPC's official channels
10. Exercising Your Rights
10.1 How to Make a Request
To exercise any of your rights as a data subject, you may:
- Send a written request to our Data Protection Officer
- Include your full name, contact information, and a clear description of your request
- Provide proof of identity to verify your request
- Specify the personal data to which your request relates
10.2 Response Time
We will acknowledge your request within 5 working days of receipt and will respond to your request within 30
days, subject to the complexity of your request. If we need additional time, we will inform you and provide an
explanation.
10.3 Fees
We will not charge fees for processing your data subject rights requests, except in cases where requests are
manifestly unfounded, excessive, or repetitive. In such cases, we may charge a reasonable fee based on
administrative costs.
11. Data Security
11.1 Security Measures
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption: Data is encrypted in transit and at rest
- Access Controls: Role-based access control restricts data access to authorized personnel
- Authentication: Multi-factor authentication and secure login protocols
- Regular Audits: Regular security audits and vulnerability assessments
- Employee Training: Regular training on data protection and privacy
- Incident Response: Procedures for detecting, reporting, and responding to data breaches
11.2 Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the National Privacy Commission within 72 hours of becoming aware of the breach
- Notify you without undue delay if the breach poses a high risk to your rights and freedoms
- Provide details of the breach, its likely consequences, and measures taken to address it
12. Data Retention
12.1 Retention Periods
We retain your personal data for the following periods:
- Personal Information: Duration of employment plus 5 years
- Location Data: 6 months to 2 years depending on purpose
- HOS Data: 6 months as required by FMCSA
- Load Data: 7 years for business and legal purposes
- Financial Records: 7 years as required by tax laws
- Employment Records: Duration of employment plus 10 years
- Communications: 1-2 years for business purposes
12.2 Secure Disposal
When personal data is no longer needed for its intended purpose, we will securely dispose of it using
appropriate methods such as deletion, shredding, or anonymization.
13. Children's Privacy
The Asset Dispatch TMS platform is not intended for use by individuals under the age of 18. We do not knowingly
collect personal data from children. If we become aware that we have collected personal data from a child
without parental consent, we will take immediate steps to delete such information.
14. Changes to This Disclosure
We may update this Philippines Privacy Disclosure from time to time to reflect changes in our practices, changes
in DPA regulations, or other relevant developments. We will post the updated disclosure on this page with the
revision date and will notify users of material changes.
15. Data Protection Officer
We have designated a Data Protection Officer (DPO) to oversee our compliance with the DPA and to serve as the
point of contact for data subject inquiries.
16. Contact Information
For questions, concerns, or requests regarding this Philippines Privacy Disclosure or your data subject rights,
please contact us:
17. National Privacy Commission
If you believe your rights under the Data Privacy Act of 2012 have been violated and you wish to file a
complaint with the National Privacy Commission, you may contact them at:
This Philippines Privacy Disclosure is effective as of May 7, 2026, and will remain in effect until replaced by
a revised version.