Privacy Policy

Data Privacy Notice

This notice explains how ASV Business Solution handles Personal Data processed through Cirquolus ERP, including collection, use, storage, sharing, transfer, security, retention, and disposal.

Issued by

ASV Business Solution

Last updated

August 23, 2025

Jurisdiction

Republic of the Philippines (RA 10173 and IRR)

Data deletion

Need to request deletion of personal data collected through ASV Business Solution apps, websites, or platform integrations? Follow the dedicated request instructions.

View Instructions

1Introduction and Scope

This Notice explains how ASV Business Solution (Cirquolus) collects, uses, stores, shares, transfers, secures, retains, and disposes of Personal Data processed through the Cirquolus ERP. It applies to all individuals whose data are input, uploaded, synchronized, or otherwise processed within the system, including employees, contractors, applicants, dependents, beneficiaries, emergency contacts, and related persons.

2Roles and Accountability

The primary Personal Information Controller (PIC) is the Subscriber Client (e.g., your employer). ASV Business Solution acts as Personal Information Processor (PIP) under the Subscriber's documented instructions, and also acts as PIC for its own purposes including account administration, billing, support, security, analytics, service improvement, and legal compliance.

3Contact Information

Subscriber Client DPO: Refer to your employer's posted contact.

Cirquolus DPO: [email protected]

Address: 3F Six Sister's Building Basak, Mandaue, Cebu

Website: https://cirquolus.com

4Definitions

Personal Data includes any information that can identify an individual. Sensitive Personal Information includes data about health, biometrics, government IDs, and other special categories defined by law. Processing includes any operation on Personal Data. Derived Data means inferences, scores, or analytics generated from other data.

5How Data Enters The System

  • Direct entry by the Subscriber Client
  • Assisted entry or migration by ASV Business Solution under written instruction
  • System telemetry such as security logs, device data, and session metadata
  • Integrations configured by the Subscriber Client

6Categories of Personal Data

  • Personal and Employment Data: names, contact details, demographics, position, employment status, timekeeping, leave, evaluations, payroll data, SSS/PHIC/HDMF/TIN, bank details
  • Sensitive Personal Information: health information, biometrics, scanned IDs, disciplinary records, pregnancy/fitness-to-work data
  • Technical and Operational Data: IP, device identifiers, geolocation if enabled, access logs, usage events, error reports, audit trails
  • Family, Beneficiaries, Emergency Contacts: names, relationships, dates of birth, contact details
  • Derived and Analytical Data: performance indicators, risk scores, predictive models, aggregated benchmarks, anonymized datasets

7Purposes of Processing (Subscriber)

Human Resource management, payroll computation and compliance, time and attendance, leave administration, performance management, benefits administration, asset/warehouse/operations recording, statutory reporting, and other legitimate business operations defined by the Subscriber Client.

8Purposes of Processing (ASV Business Solution)

  • Account administration, billing, support, security, fraud prevention, maintenance
  • Quality assurance, troubleshooting, analytics, usage measurement, capacity planning, audit logging
  • Research and development using anonymized, aggregated, or otherwise non-identifying data
  • Training and improving AI/ML features and models where feasible without identifying individuals
  • Legal and regulatory compliance, dispute management, contractual enforcement

9Lawful Bases

Performance of a contract, legal obligation, legitimate interests including efficiency and security, and explicit consent where required and no other basis applies.

10Automated Decision-Making and Profiling

Analytics and indicators may support decisions. The Subscriber Client remains responsible for HR and management decisions taken in reliance on such outputs.

11Cookies and Telemetry

Cookies, device fingerprinting, tokens, and telemetry may be used for authentication, security, usage measurement, and service improvement. Disabling certain technologies may impair functionality.

12Data Sharing and Recipients

  • Subscriber Client internal recipients with a legitimate need-to-know
  • Subprocessors for hosting, backup, security, analytics, support, and notifications under contract
  • Corporate affiliates, successors, or acquiring entities for business continuity
  • Government and regulators when required by law
  • Professional advisors and insurers for audits, compliance, disputes, or risk management

ASV Business Solution does not sell Personal Data. Aggregated, anonymous, or derived data and service insights may be monetized.

13Cross-Border Transfer

Data may be transferred or accessed internationally subject to safeguards and contractual protections. Processing may occur in jurisdictions with different privacy standards with measures applied to protect Personal Data.

14Retention and Archival

  • Subscriber-controlled data is retained per the Subscriber's schedule and legal obligations
  • ASV Business Solution retains data for its stated purposes, legal needs, security, and disputes
  • Aggregated, anonymized, derived datasets and system logs may be retained indefinitely
  • Backup and disaster-recovery archives may persist beyond active retention periods

15Security Measures

Organizational, physical, and technical controls are applied including role-based access, encryption in transit and at rest where applicable, monitoring, vulnerability management, and periodic reviews. No system is 100% secure and residual risk remains.

16Data Subject Rights

Rights include being informed, access, rectification, erasure/blocking, portability, objection, and damages for violations subject to law and applicable exceptions. For workforce data, contact your employer's DPO. For ASV Business Solution as PIC, contact the Cirquolus DPO at [email protected].

17Breach Notification and Incident Response

In the event of a personal data breach meeting legal notification thresholds, the National Privacy Commission and affected data subjects will be notified consistent with applicable timelines and requirements.

18NPC Registration and Compliance

Where required, PICs and PIPs will register with the National Privacy Commission and maintain records of processing activities, data-sharing agreements, and data protection measures.

19Employer Monitoring and BYOD

Where configured by the Subscriber Client, access events, device metadata, geolocation if enabled, and workspace activity may be logged. The Subscriber Client is responsible for informing staff and for related employment policies.

20AI/ML, Analytics, and Ownership of Derived Outputs

Anonymized, aggregated, or otherwise non-identifying data may be used to train, test, and improve algorithms, models, and features. To the maximum extent permitted by law, ASV Business Solution owns all intellectual property in service-generated analytics, metrics, models, and derived datasets that do not identify individuals.

21Marketing and Service Communications

System, security, update, and billing notifications may be sent. Marketing communications may be sent where permitted by law or consent; opting out of marketing does not affect essential service communications.

22Government Requests and Law Enforcement

Data may be disclosed when required by law, lawful order, or regulatory process. Where permissible and feasible, the relevant PIC may be notified prior to disclosure.

23Business Transfers

In mergers, acquisitions, restructurings, or asset sales, data may be transferred to a successor entity subject to this Notice or equivalent protection.

24Third-Party Links and Integrations

Subscriber-enabled integrations are governed by their own policies and the Subscriber's configuration. ASV Business Solution is not responsible for third-party privacy practices.

25Children's Data

The service is not intended for children outside workforce and benefits contexts. If children's data is processed, the Subscriber Client is responsible for appropriate consents or legal bases.

26Limitation of Liability

To the maximum extent permitted by law, ASV Business Solution is not liable for unlawful processing by the Subscriber Client, inaccuracies introduced by users, or third-party failures beyond reasonable control. Aggregate liability is limited to subscription fees paid by the Subscriber Client for the twelve months preceding the event.

27Indemnity

Users and Subscriber Clients agree to indemnify and hold ASV Business Solution harmless from third-party claims arising from misuse of the service, violation of this Notice, or unlawful instructions.

28International Interpretation; Severability; No Waiver

If any provision is held invalid, the remainder remains enforceable. Failure to enforce a provision is not a waiver. Headings are for convenience only.

29Governing Law, Venue, and Arbitration

Philippine law governs. The parties irrevocably submit to the exclusive jurisdiction of the courts of Cebu City, Philippines, for provisional remedies, confirmation, recognition, and enforcement of any arbitral award, and for any matter not subject to arbitration.

As a condition precedent to any cause of action, the aggrieved party must first: (i) deliver a written notice describing the dispute in reasonable detail; (ii) engage in good-faith executive-level negotiations for at least thirty (30) calendar days after receipt of the notice; and (iii) if still unresolved, participate in a non-binding mediation held in Cebu City, Philippines. Only after completion of this dispute-resolution process may any suit, action, proceeding, or arbitration be initiated.

Arbitration Clause. In the event any dispute arises between the parties, whether during or after the term of this Agreement, a meeting shall first be held between representatives of each party with decision-making authority in offices located in Cebu City, Philippines, to the exclusion of other cities, as agreed by the parties. The parties will attempt in good faith to negotiate an informal resolution. If the dispute is not resolved within fifteen (15) Business Days, the dispute shall be submitted to arbitration seated in Cebu City, Philippines. Upon the written request of either party, the parties shall select a single arbitrator from among persons agreed by the parties; if the parties are unable to agree within thirty (30) days after receipt of such written notice, either party may proceed to have an arbitrator appointed. The arbitration shall be confidential, the award shall be final and binding, and judgment on the award may be entered in the courts of Cebu City, Philippines.

30Changes to This Notice

This Notice may be amended. Material changes will be communicated to Subscriber Clients and posted with an updated Last Updated date. Continued use after the effective date constitutes acceptance.

31Layered and Just-in-Time Notices

A layered approach may be used including concise prompts at first use and links to this full Notice. Module-specific prompts may appear where required.

32Consent and Continued Use

Where consent is required, it must be freely given, specific, informed, and evidenced. Where other bases apply, processing proceeds accordingly. Continued access or use may be treated as acknowledgement of this Notice and acceptance of updates to the extent allowed by law.

33How to Raise Concerns

Contact your employer's DPO for workforce data issues. For ASV Business Solution as PIC or unresolved concerns, email [email protected]. If unresolved, you may lodge a complaint with the National Privacy Commission: 5th Floor, Delegation Building, PICC Complex, Roxas Boulevard, Pasay; Hotline: 8452-4-NPC (8452-4672); Website: https://privacy.gov.ph/