For business partners and enterprise clients who process data through Headstart PH.
This Data Processing Agreement ("DPA") applies to business partners, educational institutions, corporate clients, and any organisation ("Controller") that engages Headstart PH ("Processor") to process personal data on their behalf. If you are an individual user of Headstart PH, your data practices are governed by our Privacy Policy.
This DPA forms part of the agreement between the Controller and Headstart PH and supplements our Terms of Service. It sets out the rights and obligations of both parties with respect to the processing of personal data in compliance with the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations.
For the purposes of this Agreement:
This DPA governs the processing of personal data by Headstart PH as a Processor acting on documented instructions from the Controller. The Controller remains solely responsible for the lawfulness of the data processing and for ensuring that data subjects have been informed appropriately.
Headstart PH will only process personal data for the specific purposes outlined in the accompanying service agreement or as otherwise instructed in writing by the Controller, except where required by applicable Philippine law.
The Controller agrees to:
Headstart PH, as Processor, agrees to:
The Controller grants Headstart PH general authorisation to engage sub-processors. Headstart PH currently uses the following categories of sub-processors:
Headstart PH will notify the Controller of any intended changes to sub-processors with reasonable prior notice. The Controller may object to such changes in writing within 14 days. All sub-processors are bound by data protection obligations no less protective than those in this DPA.
Headstart PH will assist the Controller in fulfilling data subject rights requests under RA 10173, including:
Assist in providing transparency to data subjects.
Provide data exports within 30 days of request.
Correct inaccurate data on Controller's instruction.
Delete personal data upon verified request.
Cease processing upon Controller's instruction.
Where Headstart PH receives a data subject request directly, it will forward the request to the Controller without undue delay and within 5 business days.
Headstart PH implements appropriate technical and organisational security measures including:
In the event of a personal data breach, Headstart PH will:
Personal data processed under this DPA is primarily stored and processed within systems accessible from the Philippines. Where data is transferred internationally (e.g., via cloud infrastructure), Headstart PH ensures appropriate safeguards are in place, including contractual protections with sub-processors that meet the standards of RA 10173.
Headstart PH will retain personal data only for as long as necessary to fulfil the agreed services. Upon termination of the service agreement or written request from the Controller, Headstart PH will โ at the Controller's election โ securely delete or return all personal data within 30 days, unless retention is required by applicable Philippine law. A written confirmation of deletion will be provided upon request.
Headstart PH will make available to the Controller all information necessary to demonstrate compliance with this DPA. The Controller may conduct audits or inspections, or appoint an independent auditor to do so, with reasonable prior written notice (minimum 30 days) and no more than once per calendar year. Audit costs are borne by the Controller unless a material breach is identified.
Each party's liability under this DPA is subject to the limitations set out in the main service agreement between the parties. Headstart PH is only liable for damages caused directly by processing that does not comply with this DPA or by acting outside or contrary to the Controller's lawful instructions.
This DPA comes into effect on the date the service agreement is executed and remains in force for the duration of that agreement. Termination of the service agreement automatically terminates this DPA. Obligations under Sections 4, 7, 8, 10, and 12 survive termination.
To enter into a signed DPA with Headstart PH, or for any questions about this agreement, please contact our Data Protection Officer:
goheadstartph@gmail.comAlso see: Privacy Policy ยท Terms of Service