1. COVERAGE
This Privacy Notice provides details about the applicant/user’s information collected and processed by AND FINANCING CORPORATION, a Financing Corporation duly registered in the Philippines, in relation to use of the application Etomo (the “APP” or “Application”) and its services. In compliance with Republic Act No. 10173 or the Data Privacy Act of 2012, this Privacy Notice specifically discusses what personal information is/are collected and processed, the purposes for which they are processed, which persons have access to the personal information, the security of the personal information, retention of personal information, how users can access and/or update their information, and how to delete the same.
2. DEFINITION OF TERMS
AND FC, is a Financing Company duly incorporated as AND Financing Corporation under SEC registration number CS201840930. AND Financing Corporation shall hereinafter be referred to as the “Lender”.
CUSTOMER INFORMATION means the applicant/user’s Personal Data, confidential information, tax information, salary information, and other relevant information about the applicant/user’s transactions and use of the Lender’s App.
DPO or the Data Protection Officer is the individual that ensures, in an independent manner, that Lender complies with the laws protecting the applicant/user’s Personal Data. The DPO’s duties and responsibilities shall be governed by and consistent with the provisions of the Data Privacy Act of 2012 and its implementing rules and regulations as well as official orders or directives from the National Privacy Commission.
FACILITY means the electronic platform accessible through the internet through the Etomo APP and Etomo’s website.
MOBILE APPLICATION refers to the APP available on Etomo (Google Play or App Store)
PRE-LOAN refers to the process wherein the applicant/user signs up for the APP and/or up to loan application where the user’s/applicant’s Personal Data and other information shall be verified, evaluated and will be subject to internal policies and procedures of the Lender. Furthermore, for the loan application, the Applicant declares its intention to request for a Loan in accordance with the general conditions, and all other information and documents forming an integral part of the Loan Agreement.
POST-LOAN refers to the process wherein the user’s/applicant submits personal data and other information including the Lender’s final irrevocable decision granting or denying the loan application in accordance with the Terms and Conditions of Use, and all other documents forming an integral part of the Loan Agreement. It shall contain the following details but not limited to Loan Amount, Maturity Date, Interest, and other information included in compliance with the Republic Act No. 3765 “Truth in Lending Act”.
PERSONAL DATA refers to all types of Personal Information.
-
- “Personal information” refers to any information, whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual.
- Sensitive personal information refers to personal information:
- About an individual’s race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations;
- About an individual’s health, education, genetic or sexual life of a person, or to any proceeding for any offense committed or alleged to have been committed by such individual, the disposal of such proceedings, or the sentence of any court in such proceedings;
- Issued by government agencies peculiar to an individual which includes, but is not limited to, social security numbers, previous or current health records, licenses or its denials, suspension or revocation, and tax returns; and
- Specifically established by an executive order or an act of Congress to be kept classified.
3. WHAT DATA IS COLLECTED AND PROCESSED
The Lender collects and processes personal data of persons who sign up for and/or use the APP, specifically:
-
Full name (First, Middle, and Last Name), birth date, residential address (Unit#, Street, Barangay, City, Province), Type of House Ownership, contact number/s email address, Facebook details, employment information, bank account details, financial history, bills payment history, government-issued identifications and Tax identification; app listing.
-
Information from third parties pertaining to the applicant/user obtained, upon applicant/user’s authorization, from user’s present employers or past employers, from credit card companies regarding applicant/user’s transactions, financial credit, remittance and bills payment history, etc. (“Transaction, Credit and Payment Information”) , and
-
Traffic and usage information generated from the user’s visit and use of the mobile app and website
Other Personal Data may be collected through various means including: cookies, flash cookies, general log information, user browsing behavior, user searches and transactions and other information from third-parties.
4. PURPOSE OF COLLECTION AND PROCESSING
The Lender collects, processes, uses, discloses, stores and retains personal data of its applicants and employees:
-
To ascertain the identity of the applicant/user;
-
To validate the personal data provided
-
To analyze data and generating applicant scoring, including profiling, in order to provide appropriate and useful services to borrowers and to eventually generate a credit score and user credit profile.
-
To contact applicant/users for promos, offers, and other marketing initiatives relating to the Lender’s products and services, whether electronic means, by email, post, or by cellphone, SMS or social media, or by sending newsletters (e.g. in case where the company sends the users updates on new product features, announce events, loyalty programmes, product demonstrations, and other activities that Lender organized), which can also be send using automated means. Communications will relate to products and services of the financial products, services and the like.
-
For payout through remittance or bank account or digital wallet.
-
For collection purposes.
-
For incentivized personal network sharing.
-
To process data for market research, statistical analysis, and other research that will improve our products, services, including those of our principal, affiliates, and subsidiaries.
-
To include study for customer satisfaction study and analysis.
5. WHO HAS ACCESS TO THE PERSONAL DATA
Personal Data is accessed exclusively for the above purposes. As such, only the following have access thereto:
-
CUSTOMER SERVICE AND COLLECTION/DISBURSEMENT
-
Only to the extent necessary to address complaints and/or concerns
-
As necessary to effect collection and disbursement of the loan
-
-
CREDIT SCORING SYSTEM MAINTENANCE
-
Only to the extent needed for maintaining the system
-
-
DATA PROTECTION OFFICER/INCIDENT RESPONSE TEAM
-
Only to the extent necessary to respond to a complaint, concern and/or data breach or security threat
-
-
INTERNAL and/or EXTERNAL AUDIT
-
Only to the extent necessary to complete such function
-
-
RISK MANAGEMENT,* FINANCE and COMPLIANCE DEPARTMENTS
-
Only to the extent necessary for the Lender to effectively manage its financial exposure and risks and to ensure compliance with government regulations
-
-
Third party KYC/payout partners
-
Only to the extent necessary to effect KYC and/or payout
-
6. SHARING OF PERSONAL DATA
As a matter of policy, the Lender will not share applicant/user’s personal data, without the applicant/user’s consent to third parties. The Lender shall share anonymized information for analytics with AND Solutions Pte. Ltd., its affiliate and technology partner, to better improve the product and its offerings.
Anonymized information refers to data which has been stripped of all identifiers or indicators which can lead to its association with any particular individual.
As a borrower, applicant/user’s Personal Data will be shared with the Lender through the APP in order to allow the Lender to assess the data and other information needed for the Lender to confirm the applicant/user’s credit score and process the applicant/user’s loan application.
The Personal Data of the applicant/user may also be shared to third parties (e.g. banks, remittance centers, billing companies) who are engaged, used or is otherwise authorized by either the Lender or the applicant/user to provide any support or service for purposes of facilitating the loan application by the applicant/user.
The Personal Data of an applicant/user, may be shared and disclosed to the following:
-
The Lender and AND FC which are necessary for the conduct of the Lender’s business
-
Third party providers who require the information to facilitate the loan, but not limited to the disbursement, remittance, payment collection, credit check (credit bureaus, service providers, service history, bank history, financial history, spending history, among others), background check, or processing of loan to the borrower, etc.
-
The government, regulatory agencies, and fraud prevention agencies for the purposes of identifying, preventing, detecting or handling fraud, money laundering, or other crimes, and for other lawful purposes; and
-
Other entities as may be required by law or as public interest may warrant.
All data processing, subcontracting, or data sharing agreements will be in accordance with the requirements under the Data Privacy Act Of 2012, or applicable laws and regulations as may be hereafter passed and implemented. To the extent that such processing, subcontracting, or data sharing requires notice or consent, the Lender will provide or request for such notice and/or consent, in each case, prior to any processing or sharing of the Personal Data.
7. SECURITY OF PERSONAL INFORMATION
As a matter of policy, the Lender implements a paperless system. Thus, physical records are kept to a minimum. In the event that these are used, the files shall be kept under physical lock and key with only authorized personnel having access to the said files.
In any case, all systems are operated in a secure environment, with each system employing necessary security or encryption systems to deter unauthorized access. The system uses AES 256-bit encryption over all personal information at rest or in transit.
8. RETENTION OF PERSONAL INFORMATION
In general, the Personal Data will be retained by the Lender for the duration of the activities and transactions in connection with the products and services availed in the mobile application or in the website, and/or such period of time required for legal and regulatory purposes. Moreover, the Lender may retain copies of your Personal Data in the Lender’s archives for the purpose of determining its continuing obligations or pursuant to its bona fide record retention or data-backing up policies, access to which shall be restricted on a need-to-know basis, as may be required under applicable laws and regulations.
PRE-LOAN REQUEST and/or UNSUBSCRIPTION
The Lender shall maintain all personal data for a period of five (5) years reckoned from the last login. Thereafter, it shall be tagged for deletion or archiving, as the case may be. Prior to such activity, the Lender shall notify the User of such pending activity and secure instructions to the contrary through notice to the last registered email and/or mobile address made available.
Failing to communicate instructions to the contrary acts as a waiver to any action against AND FC for any violation of relevant provisions to the Data Privacy Act of 2012.
POST-LOAN REQUEST
The Lender shall maintain all personal data for a period of ten (10) years, in case of possible legal disputes; unless a longer period is required by law or contract, in which case, it will be retained for such period.
However, all personal data of the applicant/user shall be retained for a period of ten (10) years, pursuant to law on establishing claims based on contracts, reckoned from the time the obligation is extinguished. For avoidance of doubt, the act of unsubscribing from the APP does not in anyway cancel existing loan obligations, and must be repaid in accordance with the terms of the loan agreement.
DPO AND YOUR RIGHTS
The Data Protection Office may be reached through the following details:
- (dpo@andfc.ph)
- 09178775363
- 2F Unit D-08 St. Francis Square Mall Bank Drive Corner Julia Vargas Avenue Mandaluyong Cit
The applicant/user, as data subject, possesses the several rights in relation to your personal information under the Data Privacy Act of 2012, including the right to lodge a complaint with the National Privacy Commission. These rights are as follows:
-
The right to be informed that Personal Information pertaining to him or her shall be, are being, or have been processed, the scope and data of the processing, and to be informed of the identity of the data controller;
-
The right to object to the processing of his or her personal information, including processing for direct marketing, automated processing or profiling. The data subject will also be given the opportunity to withhold consent to the processing in case of changes or any amendment to the information supplied or declared to the data subject in the preceding paragraph.
-
The right to reasonable access, upon demand, any information regarding the processing of his personal information, the sources from which his or her personal information was obtained, and the designation, name or identity, and address of the personal information controller.
-
The right to rectification or the right to dispute the inaccuracy or error in the personal information and have the personal information controller correct it immediately and accordingly, unless the request is vexatious or otherwise unreasonable.
-
The right to erasure or blocking, or to suspend, withdraw or order the blocking, removal or destruction of his or her personal information from the personal information controller’s filing system.
-
The right to damages, or to be indemnified for any damages sustained due to such inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorized use of personal information, taking into account any violation of his or her rights and freedoms as data subject.
The applicant/user has the right to request access to his/her personal data. You may send us a request for access via email. Depending on the complexity and difficulty of the request, the Lender may charge a fee for providing access to your personal information.
DELETION AND/OR AMENDMENT OF PERSONAL INFORMATION
All physical personal data records cleared for destruction by the DPO shall be shredded using industry grade equipment.
As to deletion of digital personal data records, the same shall be in compliance with this Policy, subject to final clearance and authority of the DPO.
As for amendment of Personal Data POST LOAN, all requests for change or update of Personal Data shall be done only with the authority of the DPO. For requests made PRE-LOAN, the data subject may request for assistance with CUSTOMER SERVICE to make the necessary rectifications.
LOG DATA
Like many mobile application and website operators, Lender may collect information that the applicant/user’s browser sends whenever the applicant/user accesses the APP or the website (“Log Data”). This Log Data may include information such as the applicant/user’s computer’s Internet Protocol (IP) address, browser type version, the pages of the APP or website visited, the time and date of their visit, the time spent on those pages and other statistics that can be derived.
CHANGES ON OUR PRIVACY POLICY
This Privacy Policy is in effect as of November 23, 2018 and shall continue to remain in effect unless otherwise amended.
Lender reserves the right to amend this Privacy Policy from time to time, upon due notification to its users, applicants, and/or visitors.
If changes to this Privacy Policy will affect certain Personal Data, the Lender shall notify its applicants/users through the e-mail address provided or by posting a public notice on the APP or through the website.
REGULATORY COMPLIANCE
etomo is owned and operated by AND Financing Corporation with SEC Registration No.CS201840930 and Certificate of Authority No. 1187. Please read the Terms of Use and Terms and Conditions before proceeding with any transactions.