Weaving0
Legal

Privacy Notice

Please read this Privacy Notice carefully to understand our policies and practices regarding your Personal Data and how we treat it. It explains how your Personal Data is collected, used, and disclosed by Nephila Web Technology, Inc. (“NWTI”, “we”, “us”), and how you can access and update it and make choices about its use.

This Notice covers both our online and offline data-collection activities — across websites, apps, third-party social networks, client calls, points of sale and events — and may change from time to time.

1 · Sources of Personal Data

This Notice applies to Personal Data that we collect from or about you, through the methods described below, from the following sources:

  • NWTI Website — the official website of Nephila Web (www.nephilaweb.com.ph).
  • NWTI LMS Site — the Learning Management sites of Nephila Web (lms.nephilaweb.com.ph and event sites).
  • E-mail, text and other electronic messages exchanged between you and Nephila.
  • Offline registration forms — printed or digital forms collected via postal mail, learning events, webinars and other promotions.
  • Advertising interactions — interactions with our advertisements on third-party apps.
  • Data we create — Personal Data we generate in the course of our interactions with you.
  • Data from other sources — third-party social networks (Facebook, Google, etc.), market research, and other publicly available data.

2 · Collection of Personal Data

Depending on how you interact with Nephila (online, offline, over the phone), we collect various types of information:

  • Personal contact information — name, postal address, e-mail address, social network details, or phone number.
  • Account login information — login ID/email, screen name, password (stored in unrecoverable form), and/or security question and answer.
  • Demographic information & interests — year of birth, age range, gender, and geographic location.
  • Website/communication usage — your IP address, operating system and browser type, for system administration and statistics.
  • Consumer-generated content — photos, videos, stories or media you create and share with us or upload to our sites.
  • Third-party social network information — basic profile information you allow a network such as Facebook to share with us.
  • Payment and financial information — handled by us or our payment processors in a manner compliant with applicable laws.

Sensitive Personal Data. We do not seek to collect or process sensitive personal data in the ordinary course of business. Where necessary, we rely on your prior express consent, or on lawful bases such as the prevention of crime, the establishment or defense of legal claims, and compliance with applicable law.

3 · Use of Personal Data

  • Customer service — to serve you better and communicate announcements and updates on our services.
  • Webinars — to issue certificates and invite you to future sessions that help the education community improve.
  • Third-party social networks — to understand your concerns about our products and services and provide useful information.
  • Phone calls & online registrations — to understand your needs in relation to the services we provide.

4 · Disclosure & Sharing

  • On a learning management site, your name, position and company may be shared with co-participants, sponsors and the event organizer.
  • We will otherwise disclose your personal data for legal reasons only.

5 · Storage, Retention & Destruction

Storage. Your personal information is stored with the security measures described in Section 6.

Retention. In accordance with applicable laws, we keep your Personal Data for as long as necessary to satisfy the purposes for which it was collected, or to comply with legal requirements.

Destruction. Data stored on an event LMS site is no longer accessible once the site is shut down (typically 30 days after the event); contact details may be retained for future invites. You may request deletion of your data on our LMS site or database.

6 · Security

We implement the following security measures:

  • User access control for CRM, Google Drive, LMS, and local machines.
  • SSL across our sites.
  • Vulnerability Assessment / Penetration Testing (VAPT) conducted monthly.
  • Encryption across our systems and providers, with data encrypted at rest and in transit (e.g. AES on Google Drive).
  • Full-disk encryption on local machines running Ubuntu Core, protecting data if a device is lost or stolen.

As an ISO 27001-certified organisation, information security is embedded across our processes.

7 · Rights of Individuals

Access to Personal Data. You have the right to access, review and request a copy of the information we hold about you, and to request information on its source. These rights can be exercised by emailing us with proof of identity where required by law.

Additional rights. Where provided by law, you can request the deletion, portability, correction or revision of your Personal Data; limit its use and disclosure; revoke consent to our processing; and object to the processing of your Personal Data — including the right to lodge a complaint with the National Privacy Commission.

In certain circumstances we may be required to retain some Personal Data after a deletion request to satisfy legal or contractual obligations. We require registered users to verify their identity before accessing or changing account information, to help prevent unauthorised access.

8 · Data Protection Officer

Jennie May V. Alvarez, CPA

Data Protection Officer

Philippine Social Science Center, Commonwealth Ave., Diliman, Quezon City, Philippines

T: (+632) 8285-7450 · M: +63 917 587 8851

E: dpo@nephilaweb.com.ph