This Privacy Policy explains how Sistema Hub collects, uses, discloses, retains, and protects personal data when you use GEPSCOUT (the “Service”). Sistema Hub is the personal information controller for the processing described here. We process personal data in accordance with applicable law, including the Philippine Data Privacy Act of 2012.
1. Information we process
Account and authentication information
When you sign in with Google or an email magic link, we receive or create the information needed to authenticate you. This may include your email address, name, profile image, authentication-provider identifier, verification records, session identifiers, and sign-in timestamps.
Trial, access, and payment records
We record trial timing and scan use, selected paid-access plan and status, access dates, amount and currency, and PayMongo checkout or payment identifiers needed to confirm and reconcile a purchase, handle fraud, disputes, and refunds, and meet accounting or legal obligations. PayMongo processes checkout data. We do not receive or store your full card number, CVV, or bank credentials. See PayMongo's Privacy Policy.
Temporary workspace and public-source information
When you use the workspace, our servers process your selected categories, scan progress and diagnostics, verified public bid details, public contact information, attachment metadata, and—when you request a public attachment—temporarily cached file bytes. Public-source records can contain names, work contact details, or other personal data originally published by PhilGEPS or a procuring entity. Workspace data is associated with your login-bound session so the Service can show progress, results, details, downloads, and exports.
Technical, security, and support information
We may process IP address, device and browser information, request timestamps, server logs, error and security events, and communications you send us. We use first-party authentication and workspace cookies necessary to operate the Service. We do not use third-party advertising cookies or sell behavioral profiles.
2. Why we process information
- Authenticate you and maintain your login-bound workspace.
- Run requested scans and provide results, attachments, and exports.
- Apply trial limits and paid-access periods.
- Confirm payments and handle refunds, disputes, accounting, and support.
- Send sign-in and other transactional messages.
- Secure, diagnose, maintain, and improve the Service.
- Prevent fraud, abuse, unauthorized access, and violations of our Terms.
- Comply with law and respond to valid legal requests.
Depending on the processing and applicable law, we rely on consent, steps needed to enter or perform our contract with you, compliance with legal obligations, and legitimate interests such as securing and improving the Service. Where consent is the basis, you may withdraw it without affecting earlier lawful processing.
We do not sell your personal information or use it for advertising profiling.
3. Sources
We receive information directly from you, from your authentication provider, from PayMongo, from ordinary operation of the Service, and from public PhilGEPS pages and public procuring-entity materials that you ask the Service to check.
4. When we disclose information
We disclose only what is reasonably needed:
- To Google or our email provider for authentication and transactional messages.
- To PayMongo and relevant financial providers for checkout, confirmation, refunds, fraud, and disputes.
- To hosting, database, security, and technical providers that operate the Service for us.
- To professional advisers, authorities, or other parties when required by law or reasonably necessary to protect rights, safety, and security.
- In connection with a financing, reorganization, merger, acquisition, or transfer of all or part of the business, subject to applicable safeguards.
Providers may process data in other jurisdictions under their own terms and privacy practices. We remain responsible for selecting providers and using appropriate contractual, organizational, and technical safeguards where required.
5. Retention
Temporary workspace sessions and their scan results are removed after sign-out, access expiry, or two hours of inactivity. Account, authentication, trial, payment, security, support, dispute, and legally required records may be retained longer for account operation, fraud prevention, accounting, legal claims, and compliance. Retention depends on the record's purpose, sensitivity, risk, and applicable requirements. We delete, aggregate, or de-identify data when it is no longer reasonably needed, subject to lawful preservation obligations and backups.
6. Your responsibilities for exported public data
When you download, export, or otherwise use public-source records, you become responsible for your own copies and use. You must use personal information only for a lawful, proportionate purpose and comply with applicable privacy, marketing, procurement, and records rules. Public availability does not remove every legal restriction on collection, reuse, or disclosure.
7. Your data-subject rights
Subject to the Data Privacy Act and its lawful limitations, you may exercise the right to be informed, access, object, rectify, erase or block, obtain data portability where applicable, claim damages, and file a complaint with the National Privacy Commission. You may also withdraw consent where consent is the applicable basis.
Email hello@sistemahub.com with your request and enough detail for us to understand it. We may verify your identity and authority, request clarifying information, and retain records needed to show how the request was handled. Rights can be limited where the law permits or requires continued processing.
8. Security and incidents
We use reasonable organizational and technical safeguards appropriate to the information and risk, including encrypted network connections, hashed session tokens, login-bound authorization, and access-controlled infrastructure. No online service or storage method is completely secure. If a personal data breach occurs, we will investigate and provide notices required by applicable law.
9. Children
GEPSCOUT is intended for business and professional users and is not directed to people under 18. We do not knowingly create accounts for children. Contact us if you believe a child provided personal data through the Service.
10. Changes and contact
We may update this policy to reflect legal, operational, or Service changes. We will revise the effective date and provide additional notice where required. For privacy questions, requests, or concerns, email hello@sistemahub.com.