Data Processing Agreement
Last updated August 3, 2026 · 14 sections · about 3 min read
1.Roles#
For guest data collected through your events, you are the Personal Information Controller (PIC) and Sali is the Personal Information Processor (PIP) under the Data Privacy Act of 2012 (RA 10173). Sali processes that data only on your behalf. This DPA is incorporated into our Terms of Service by reference.
2.Scope, duration & purpose#
Sali processes personal data to provide event registration, QR and offline check-in, guest communication (email/SMS), analytics and reporting, and billing — for as long as you use Sali, plus the retention period below.
3.Data & data subjects#
Data subjects are your event guests and your own users. Personal data includes names, emails, mobile numbers, custom form fields you define, check-in records, and check-in codes. Sali does not store payment card numbers and does not intend to process sensitive personal information.
4.Your responsibilities#
You warrant a lawful basis to collect guest data and to share it with Sali and with the client that commissioned the event, and that you have given data subjects the required privacy notice — including for SMS/email and opt-out rights.
5.Our obligations as processor#
In line with IRR §44, Sali will: process only on your documented instructions; keep authorised personnel under confidentiality; apply appropriate security measures; not engage a sub-processor without authorisation and equivalent safeguards; assist you with data-subject requests and your compliance duties; delete or return data at the end of the engagement; and make available information to demonstrate compliance and allow audits.
6.Sub-processors#
You authorise Sali to engage vetted sub-processors, each bound by equivalent obligations: PayMongo (payments — no card data stored by Sali), Movider (SMS), our email provider, and our cloud hosting providers. We give prior notice of any new or replacement sub-processor and a chance to object on data-protection grounds.
7.Security#
Organizational, physical, and technical measures per IRR §§25–29: encryption in transit, scoped access tokens, role-based access, per-agency isolation, encrypted sessions, monitoring, and restore capability. The offline check-in cache on staff devices holds only name/email/code/status, is cleared on logout, and auto-expires.
8.Data-subject rights#
We assist you, so far as technically possible, to honour data subjects’ rights to be informed, object, access, rectify, erase/block, portability, damages, and to complain to the National Privacy Commission (NPC). Guest requests about a specific event are generally directed to you as controller.
9.Retention, return & deletion#
On termination or your written request, we delete or return your personal data within 30 days, including copies, except records we must retain by law (e.g. financial records for BIR) and routine backups that expire on their normal cycle.
10.Audit#
We make available information necessary to demonstrate compliance and allow reasonable audits on prior notice — typically no more than once a year, except following a breach or where required by the NPC.
11.Data breach notification#
We notify you without undue delay after becoming aware of a breach affecting your data. Where Sali is the controller of the affected data, we notify the NPC and affected data subjects within 72 hours of knowledge of a qualifying breach, per IRR §38.
12.International transfers#
Where a sub-processor or host stores data outside the Philippines, Sali remains accountable and ensures appropriate safeguards consistent with the Act and its IRR.
13.Data Protection Officer#
Sali’s designated Data Protection Officer can be reached at privacy@sali.com.ph. The full, signable DPA (including our registered details and sub-processor locations) is available on request.
14.Precedence & governing law#
This DPA forms part of the Terms of Service and, for personal-data processing, prevails over them in case of conflict. It is governed by the laws of the Republic of the Philippines.