Privacy Policy

Version 2026.1 · XYPES Technologies, Tuguegarao City, Cagayan, Philippines

Draft. This has not yet been reviewed by Philippine counsel, and InspectPH has no subscribing organisations yet. It is published so it can be read and challenged before anyone's data depends on it.

Who this is for

Three groups of people appear in InspectPH, with different relationships to us. This covers all three and says which parts apply to whom.

  • Staff of a subscribing organisation — inspectors, supervisors and administrators who sign in and use the system.
  • Business owners, contact persons and representatives whose details appear because an organisation inspected their premises — a government office, or a company inspecting its own sites, contractors or tenants. Most of you never signed up for anything and may never have heard of us. There is a page written for you.
  • Officers of a subscribing organisation who deal with us commercially.

Who is responsible for your data

InspectPH is software we provide to organisations in the Philippines that run inspections — government offices and LGUs, and private companies inspecting their own sites, contractors, suppliers or tenants. When an organisation uses it, the organisation decides what is collected, why, and about whom. Under the Data Privacy Act the organisation is the Personal Information Controller and we are its Personal Information Processor. If you want a record corrected or removed, the organisation is normally the right place to ask, and we will help them answer you.

Two things we are responsible for directly, and we say so rather than hiding behind the organisation:

  • Our own records about the organisation officers we deal with commercially.
  • Our audit logs. We keep an append-only record of significant actions. Neither the organisation nor we can edit or delete it.

What we collect about organisation staff

Name, work email, phone number and profile picture, with the role and organisation. Passwords and sessions are handled by our authentication provider and we never see a password.

Beyond that, your organisation chooses whether it also keeps a job title, a department and an employee identifier. Each is off unless the organisation switches it on, because what an organisation records about its own employees is its decision and not ours.

Every inspection created, submitted, approved or returned is recorded with the person's name, their role at the time, and when.

What we collect about inspections

Whatever the organisation's form asks for. Organisations design their own inspection forms, so the fields vary: establishment name and address, the name of the representative present, a signature, scores, findings, notes and photographs.

We cannot list every field, because we do not choose them. Your organisation can tell you exactly what its forms collect. Our agreement with each organisation prohibits using these forms to collect sensitive personal information — health information, government ID numbers, offences — unless the organisation has its own lawful basis for it.

Location

Two different things, worth separating because they are not alike.

The inspector taps a button. The form has a “Confirm your location” control, and some organisation forms include a location question. Those record a position because the inspector chose to, on a visible control.

Or the organisation has switched on automatic capture. Then the position is recorded when an inspection is started, without a tap. This is off unless the organisation turns it on, and when it is on the inspector is told on the screen where it happens, every time — not once, buried in a notice at sign-in.

Neither tracks continuously, and nothing is recorded when the app is closed. Supervisors in the same organisation can see recorded positions on a map. The purpose is to confirm an inspection happened at the establishment it relates to.

If you are an inspector

We want to be straight about three things. This is monitoring of you, not only of the inspection — it is a record of where you were and when, and calling it anything else would be misleading.

We are not relying on your consent, and we would not be entitled to. The National Privacy Commission has repeatedly held that employees are seldom in a position to freely give or refuse consent to their employer. Your organisation relies on its own grounds.

Automatic capture is your organisation's decision, and it is off until they make it. It used to be on for everyone with no way to switch it off, which made it our decision rather than theirs — for a purpose only your organisation has a mandate to pursue. That was wrong and it has changed. Tapping “Confirm your location” yourself is unaffected either way; that one is your deliberate act, and always was.

Photographs

Inspectors photograph premises. Photographs are stored privately and are visible only to authorised people in the same organisation, and to us in the limited circumstances below.

Photographs of premises will sometimes include people who have nothing to do with the inspection. If you appear incidentally and want it dealt with, contact the organisation that took it, or us, and we will route it.

When a photograph is uploaded it is re-encoded, which removes the camera's own embedded metadata, including any GPS coordinates the camera recorded. If a phone cannot re-encode an image, the app refuses to send it and says so, rather than uploading the original — the position a camera embeds is the inspector's own, and an organisation that has switched automatic location capture off should not receive it by a side door. Our server checks the same thing again and strips that metadata a second time.

PDF files attached to an inspection are the exception: they are stored as they are, and any metadata inside them is kept. We would rather say so than let “metadata is removed” be read more widely than it is true.

Where your data is

Your data is stored outside the Philippines, and processed outside it too. It is held in India and handled by servers in the United States. We are telling you this here rather than in a footnote, because for a system holding Philippine inspection records it is something you are entitled to weigh.

  • Database, sign-in and photographs — Supabase, Mumbai, India.
  • The application itself — Vercel, Washington DC, United States.
  • Invitation and password-reset email — Supabase, following the above.
  • Map backgrounds — OpenStreetMap tile servers, outside the Philippines.

This is lawful — the Data Privacy Act does not require data to stay in the country — but under its accountability principle the responsibility for data sent abroad stays with the organisation and with us. We are reviewing whether to move to a Philippine or ASEAN region.

When a map is displayed, the coordinates being viewed are necessarily sent to the tile server that draws it. We send it nothing else.

We do not process payment cards. Subscriptions are invoiced manually. No card details reach us in any form. We do not sell data, do not share it for advertising, and run no advertising or analytics trackers.

How long we keep things

This depends on who holds the record, and the two answers are not close to each other.

If a government office holds it. Inspection records held by a government agency are public records under the National Archives Act. It may not destroy them without prior written authority from the National Archives of the Philippines, and unauthorised destruction carries criminal penalties. So for those records we do not offer a button that deletes them after a period, and the system refuses the deletion until the authority has been recorded against it.

The retention period comes from that office's own approved Records Disposition Schedule: we have not yet sourced a general figure and will not state one until we can.

If a private organisation holds it. None of that applies. There is no National Archives authority for a company to obtain, and the Data Privacy Act points the other way — personal data should not be kept longer than the purpose requires. It sets its own retention period and can delete inspection records when it decides to. We do not hold it back.

On an inspector's phone, the saved copy of the establishment list is cleared on sign-out and expires by itself after seven days. Inspections completed but not yet sent are not deleted on sign-out — that is their work, often collected where there is no signal, and destroying it to tidy up would be the wrong trade. It stays until it sends, and they are told so.

The audit log is different. It cannot be edited or deleted by the organisation, by you, or by us. If an inspection record is erased or anonymised, the log entry recording that it existed remains.

If you are staff, you can read your own entries — they are on your profile page: what you did, and what was done to your staff record. Not being able to edit a log is not the same as not being able to see it, and for a while this system confused the two.

When we look at organisation data

We can enter an organisation's workspace to diagnose a problem. Every such access is recorded in that organisation's audit log and marked as a platform access, so the organisation can see when we have been in.

Keeping it safe

Access is separated by organisation in the database itself. Photographs are stored in a private bucket. Connections are encrypted in transit.

Two things we would rather you heard from us than discovered: data held on an inspector's phone for offline work is not encrypted on the device, so an unsent inspection is readable by anyone who can unlock that phone until it sends. And we are a very small vendor — our security commitments to organisations are written to be ones we can actually meet.

Your rights

Under the Data Privacy Act you have the right to be informed, to access your data, to correct it, to object to processing, to have data erased or blocked in defined circumstances, to data portability, to be indemnified for damage, and to complain to the National Privacy Commission.

Where to ask. If your data is in an inspection or establishment record, ask the organisation — it holds it and it decides. For anything we hold as controller, ask us.

How to ask. There is a form — no account needed, because most of the people with the strongest claim have none. Or email dataprotection@xypes.com; both reach the same person. We acknowledge within 5 working days and tell you plainly whether it is ours to answer or the organisation's. That is our own commitment rather than a statutory deadline — we would rather promise something we can keep than quote a period nobody is bound by.

Two honest limits. We may refuse erasure where the law requires the record to be kept, and we will tell you which law we are relying on. And we cannot delete audit log entries for anyone.

You can complain to us first, but you do not have to. The National Privacy Commission takes complaints directly, at privacy.gov.ph.

Which country's rules apply

InspectPH is offered to organisations in the Philippines — public and private — and this policy is written to Philippine law. If we later offer the service elsewhere we will publish annexes to this policy rather than separate policies, so one document binds everyone and it is always clear which version applies. Every version stays available from a stable address to anyone, wherever they are. We will not show you a different policy based on where we think you are.

Changes

Each version has a number and an effective date, and previous versions stay published. If we change something that materially affects you we will say so and, for organisations, ask them to accept the new version.

Contact

Data Protection Officer: Dennis Tobias — dataprotection@xypes.com

XYPES Technologies, Tuguegarao City, Cagayan, Philippines.

National Privacy Commission — privacy.gov.ph