Privacy Policy
Last updated August 3, 2026 · 12 sections · about 3 min read
1.Who we are & our role#
Sali is operated by Lloyd Rez Encallado, doing business as Lloyd Rez Encallado Software Publishing Services. We are the data controller for agency account information, and a data processor acting on behalf of agencies for the guest data they collect through their events. You can reach our Data Protection Officer at privacy@sali.com.ph.
2.What we collect#
Account details (name, email, workspace, role); event and client data you create; guest registration data submitted through your public event pages (which may include name, email, phone, and custom fields you define); check-in records; and limited payment metadata. We do not store card numbers.
3.How we use it & legal basis#
We process personal data to operate registration and check-in, generate reports for your clients, send transactional emails and SMS, process billing, and secure the platform. Under the Data Privacy Act of 2012, our processing relies on your consent, the performance of our contract with your agency, and our legitimate interests in operating and securing the service.
4.Cookies#
We use strictly necessary cookies for authentication and session management, and preference cookies (such as appearance and sidebar state). On our public marketing site only, we also use analytics and advertising cookies — but only if you consent to them first. We never place analytics or advertising cookies on event registration pages, client report links, or inside the signed-in dashboard. See our Cookie Notice to review or withdraw your choice.
5.Sharing & sub-processors#
We never sell personal data. Guest data is shared only with the agency workspace that collected it and, where enabled, the client that commissioned the event. We use vetted sub-processors to operate Sali — including PayMongo (payments), Movider (SMS), our email provider, and our cloud hosting providers — each bound to protect the data they handle.
6.Data on check-in devices#
To allow check-in without a network connection, the check-in app may download a per-event snapshot of guest data (name, email, check-in code, and status) and store it in the browser on the staff device. This snapshot is used only while offline, is cleared on logout, and expires automatically.
7.International transfers#
Where a sub-processor or host stores data outside the Philippines, we take steps to ensure the transfer has appropriate safeguards consistent with the Data Privacy Act of 2012. [List transfer destinations and safeguards.]
8.Security#
We protect data with encryption in transit (HTTPS), access controls, scoped authentication tokens, and role-based permissions. No system is completely secure, and we cannot guarantee absolute security.
9.Data retention#
Guest and event records are retained for the lifetime of your workspace, or deleted within 30 days of a written request — except where we must retain certain records longer, such as financial and invoice records kept to comply with Philippine tax and accounting requirements.
10.Your rights#
Subject to the Data Privacy Act of 2012, you and data subjects may request access, correction, deletion, objection, or portability of personal data by contacting privacy@sali.com.ph. Guest requests relating to a specific event should generally be directed to the agency that collected the data. You also have the right to lodge a complaint with the National Privacy Commission (NPC).
11.Data breach notification#
If a personal-data breach likely to cause serious harm occurs, we will notify the National Privacy Commission and affected data subjects in line with the Data Privacy Act of 2012 and its implementing rules and regulations.
12.Changes to this policy#
We may update this Privacy Policy and will post the revised version with a new “last updated” date. Material changes will be communicated where reasonable.