Data privacy
Privacy Policy
This policy explains what personal data Aizen collects through the website, why it is processed, who may receive it, how long it is kept, and how Philippine data-subject rights may be exercised.
Effective and last updated:
1. Who controls website data
Aizen Agentry is the personal information controller for personal data collected through this public website, unless a separate notice or signed agreement states otherwise.
- Privacy contact
- mari@aizenagentry.com
- Website
- aizenagentry.com and its published pages
- Primary jurisdiction
- Republic of the Philippines
This policy is intended to support the Data Privacy Act of 2012, its Implementing Rules and Regulations, and relevant National Privacy Commission issuances. Aizen will apply the principles of transparency, legitimate purpose, and proportionality to website data.
2. Personal data collected
Information you submit
- name, work email, firm or company, and role;
- approximate firm or team size;
- selected service or inquiry topic;
- whether the proposed work may involve sensitive information;
- current knowledge or file systems described in the form;
- the workflow, decision, or problem described in free text; and
- follow-up communications and information voluntarily provided after the inquiry.
Technical and usage information
The hosting and security infrastructure may process request information needed to deliver and protect the website, such as IP address, request time, requested page, browser data, device data, and security logs. If you accept analytics, Google Analytics may process a first-party client identifier, page views, session statistics, approximate location, browser information, device information, and interaction events configured for the site.
Cookie preference
The site stores your analytics choice in browser local storage underaizen_cookie_consent_v1. This preference is necessary to remember whether you accepted or rejected analytics. It is not used for advertising.
3. Do not send privileged or sensitive material through public forms
Website forms are for initial qualification. Do not submit client files, case records, privileged communications, passwords, secret keys, government identifiers, health data, financial account data, criminal-case information, or other sensitive personal information unless Aizen has provided an approved secure channel and the parties have established a lawful basis, scope, and safeguard for that processing.
If sensitive or privileged information is sent unexpectedly, Aizen may restrict access, delete it where lawful and practical, ask the sender to use an approved channel, or take another reasonable protective step.
4. Purposes and lawful basis
| Purpose | Data | Primary basis |
|---|---|---|
| Respond to inquiries and assess service fit | Contact, organization, topic, and message data | Steps requested before a possible contract and legitimate business interests |
| Prepare proposals, schedule discussions, and maintain follow-up | Inquiry and communication history | Pre-contract steps, contract performance where applicable, and legitimate business interests |
| Operate, secure, diagnose, and prevent abuse of the website | Request, device, and security-log data | Legitimate interests and compliance with legal or security obligations |
| Measure website use through Google Analytics | Analytics identifiers and usage events | Your affirmative consent |
| Comply with law, establish or defend claims, and respond to lawful authority | Relevant records | Legal obligation and lawful rights or interests |
Aizen will not use website inquiry data for a materially incompatible purpose without an appropriate lawful basis and notice. Consent may be withdrawn where processing depends on consent. Withdrawal does not affect processing already lawfully completed.
6. Recipients and service providers
Personal data may be disclosed only as reasonably necessary to:
- Netlify or the website host and form-processing provider;
- Google Analytics, only after analytics consent;
- email, communications, scheduling, storage, security, and professional-service providers used to handle the inquiry;
- Aizen personnel or contractors with a business need and confidentiality duty;
- legal, accounting, insurance, cybersecurity, or other professional advisers; and
- government authorities, courts, regulators, or other parties when disclosure is required or permitted by law.
Aizen does not sell website inquiry data. A provider may process data outside the Philippines. Where cross-border processing occurs, Aizen will use contractual, organizational, or technical measures reasonably intended to provide a comparable level of protection, subject to the provider's role and applicable law.
7. Retention
- Website inquiries and related correspondence are ordinarily kept for up to 24 months after the last meaningful interaction.
- Records connected to a signed engagement are kept for the contract period and any additional period reasonably needed for tax, accounting, audit, legal-claim, or regulatory requirements.
- Security logs are kept only for the period reasonably necessary to investigate abuse, maintain reliability, and meet legal obligations.
- Google Analytics event-level retention depends on the configured Google Analytics property and should not exceed the period justified for website measurement.
- Consent choices remain in browser storage until changed, cleared by the user, or replaced by a later policy version.
Aizen may keep a record longer when required by law, reasonably necessary to establish, exercise, or defend legal claims, or needed for a legitimate business purpose consistent with applicable standards. Data that is no longer needed should be securely deleted, anonymized, or restricted.
8. Security
Aizen uses reasonable organizational, physical, and technical measures appropriate to the nature of website data. Measures may include access restriction, account security, provider controls, encrypted transmission, backups, logging, incident handling, and secure disposal. No online system can be guaranteed secure against every threat.
When a personal data breach requires notification, Aizen will assess and manage it under applicable Philippine requirements, including the notification duties and timelines that apply to the circumstances.
9. Your rights under Philippine data privacy law
Subject to legal conditions and valid limitations, you may exercise the rights to:
- be informed about processing;
- object to processing or withdraw consent where applicable;
- access personal data and information about its processing;
- correct inaccurate or incomplete data;
- request erasure, blocking, suspension, or destruction where legal grounds exist;
- obtain data portability where applicable;
- seek damages for violations recognized by law; and
- file a complaint with the National Privacy Commission.
Send a request to mari@aizenagentry.com with enough information to identify the relevant record and request. Aizen may verify identity and authority before acting. Some requests may be limited when retention or processing is required for a legal obligation, a legal claim, a valid contract, the rights of another person, or another lawful ground.
You may review the NPC data-subject rights guideor file a complaint with the NPC.
10. Client deployments and processor roles
This public policy governs website data. A client-controlled private AI deployment requires a separate privacy and security assessment. Depending on the agreed processing, the client may act as the personal information controller and Aizen may act as a personal information processor following documented client instructions.
The signed agreement should identify the parties' roles, data categories, lawful basis, instructions, authorized users, sub-processors, retention, security measures, breach reporting, return or deletion, audit rights, privileged information, and cross-border transfers. The client remains responsible for the lawfulness of the data and instructions it supplies, subject to duties expressly assumed by Aizen and mandatory law.
11. Children
The website is directed to business and professional users and is not intended to collect personal data from children. Contact Aizen if you believe a child submitted personal data through the website so the situation can be assessed and handled appropriately.
12. Changes and contact
Aizen may update this policy when the website, processing, providers, or law changes. Material changes should be communicated through an updated notice or another reasonable channel. The effective date identifies the current version.
Privacy questions and requests may be sent tomari@aizenagentry.com.
