Home / Privacy Policy
Website visitors, job applicants, employees, independent contractors, commercial clients, customer service end-users, and digital platform consumers. Comprehensive data protection framework.
Philippine Data Privacy Act of 2012 (Republic Act No. 10173): Operava Global Solutions strictly adheres to statutory principles of Transparency, Legitimate Purpose, and Proportionality across all personal and sensitive personal data processing activities.
Operava Global Solutions ("Operava", "we", "us", or "our") is dedicated to protecting the privacy, confidentiality, and fundamental data rights of every individual whose personal data is entrusted to us. In conducting our technology engineering, workforce augmentation, and Business Process Outsourcing (BPO) operations, we collect only the personal information reasonably necessary for identified, lawful, and legitimate purposes.
We process all data strictly in accordance with statutory requirements, safeguard collected records through robust administrative, technical, and physical security measures, and retain data only for timeframes justified by legal mandate or business necessity.
This Privacy Policy and Notice applies comprehensively to:
We may collect and process the following categories of personal data depending on your interaction with Operava:
Under Section 3 of RA 10173, sensitive personal information (including government-issued IDs, health records, or religious affiliations) is treated with heightened care. Operava does not solicit sensitive personal data unless strictly necessary to satisfy statutory employment obligations (e.g., mandatory government benefits and pre-employment medical clearances) or where the individual has given explicit, documented consent.
Job applicants and public visitors are advised never to submit unsolicited sensitive personal data through general contact forms.
Operava collects personal information through three primary channels:
We process personal data exclusively for explicit, legitimate commercial purposes, including:
Operava employs modern recruitment technologies, including machine-learning models and artificial intelligence algorithms, to parse resumes, match technical proficiencies against open requisitions, and organize applicant pipelines.
AI tools function exclusively as administrative screening aids. All critical candidate decisions—including shortlisting, interview selections, technical evaluations, compensation offers, and rejection notices—are determined by qualified human talent acquisition specialists. We do not engage in purely automated decision-making that produces legal effects on applicants without human intervention.
In conformity with Section 12 and Section 13 of the Philippine Data Privacy Act of 2012, our processing is grounded in one or more recognized legal bases:
In many BPO, customer support, and QA testing engagements, Operava acts as a Personal Information Processor (PIP) on behalf of our enterprise Clients (who serve as Personal Information Controllers (PIC)). In such engagements:
Operava does not sell, lease, rent, or trade personal data to third-party brokers, advertisers, or telemarketers under any circumstances. Personal data is disclosed only to:
As a global, remote-first technology solutions provider, Operava may store, access, or process personal data across international boundaries. All cross-border data transmissions are governed by contractual safeguards, including standard contractual clauses and bilateral DPAs, ensuring that transferred information receives a level of protection comparable to Philippine statutory standards.
Operava enforces an enterprise-grade information security management system comprising:
Operava maintains a formally documented Security Incident Response Protocol aligned with National Privacy Commission (NPC) Circular No. 16-03. In the event of a verified data breach involving sensitive personal data that poses a real risk of serious harm, Operava will notify affected data subjects and the NPC within seventy-two (72) hours of confirmed knowledge, outlining the nature of the breach, affected records, and remedial countermeasures taken.
Personal data is retained only for the duration necessary to satisfy the commercial, contractual, or statutory purposes for which it was gathered:
Upon expiration of the retention window, digital records are purged using cryptographic erasure techniques, and physical files are destroyed via cross-cut shredding.
We utilize essential cookies to secure our websites, manage user authentication sessions, and maintain platform stability. We may also employ privacy-respecting analytics cookies to evaluate website traffic patterns and optimize user experience. Visitors may configure their web browser to reject cookies; however, certain interactive platform functions may be impaired as a result.
Candidates submitting applications through our career portals maintain the right to inspect their application records, update their contact information, or request withdrawal of their candidacy at any time. Submitting an application registers candidate data in our talent pool for future placement opportunities without guaranteeing placement.
Personnel data collected during employment or contract engagements is processed for payroll disbursement, tax withholding, health coverage administration, performance evaluation, and workplace safety compliance. Access to personnel files is restricted to authorized human resources and finance personnel.
Operava’s services, job openings, and platforms are intended exclusively for individuals aged eighteen (18) years and older. We do not knowingly solicit or collect personal information from minors. If we discover that personal data of a minor has been gathered without verified parental consent, we will promptly purge that information from our production databases.
Under Republic Act No. 10173, every data subject is entitled to exercise the following statutory rights:
To exercise any of your statutory rights under RA 10173, submit a formal written request to our Data Compliance Office at compliance@operavaglobal.com. Please include:
Operava will respond to verified privacy requests within thirty (30) business days from receipt.
For all regulatory inquiries, data subject requests, or privacy concerns, contact our designated privacy compliance team:
Data Protection & Compliance Office
Pagudpud, Ilocos Norte 2919, Republic of the Philippines
SEC Registration: 2026080262213-03
Where Operava processes personal data solely as a Data Processor on behalf of a corporate Client, any data subject request submitted directly to Operava by the Client’s customer or end-user will be promptly forwarded to that Client’s designated Data Protection Officer for authoritative review and instruction.
Our website may contain hyperlinks to external third-party websites, developer repositories, or partner portals. Operava exercises no editorial control over the privacy policies or security standards of third-party domains. We advise visitors to review the independent privacy notices of any external site they visit.
We do not engage in unsolicited promotional spam. Any marketing newsletters or industry updates sent by Operava include a direct, one-click unsubscribe mechanism. Operational notifications regarding active project sprints, milestone approvals, invoice receipts, and critical security advisories cannot be opted out of, as they are necessary to fulfill contractual obligations.
Operava takes reasonable operational measures to ensure that personal records in our custody remain accurate, current, and complete. Candidates, employees, and client representatives are encouraged to notify our administrative office of any changes to their contact details or professional status.
Operava enforces organizational accountability through regular privacy awareness training for all employees, strict confidentiality clauses in employment agreements, routine internal audits of data access logs, and formal disciplinary procedures for any unauthorized disclosure or mishandling of personal data.
Our engineering teams incorporate Privacy by Design and Privacy by Default into our software development lifecycles. We enforce database tenant isolation, automated data pseudonymization, API rate limiting, and minimal payload transfers across all internal and client-facing digital architectures.
Operava reserves the right to amend this Privacy Policy periodically to reflect technological advancements, operational improvements, or updates in statutory legislation. Revisions will be published on this page with an updated "Effective Date". Continued interaction with our services following publication constitutes acknowledgment of the revised terms.
This Privacy Policy is governed by and construed in accordance with the laws of the Republic of the Philippines, in particular Republic Act No. 10173 (Data Privacy Act of 2012), its Implementing Rules and Regulations, and administrative issuances of the National Privacy Commission (NPC).
Operava maintains internal Records of Processing Activities (ROPA), Privacy Impact Assessments (PIA) for high-risk data workflows, and documented security incident logs as required for SEC-registered Philippine corporate entities.
Operava grounds every technical and operational workflow in the five core pillars of responsible data stewardship:
Individuals are fully informed regarding why, how, and by whom their personal data is collected, stored, and utilized.
Processing is strictly confined to explicitly declared, lawful, and necessary commercial and operational objectives.
We collect only the minimum data strictly necessary to achieve our stated business and engineering requirements.
Rigorous administrative, physical, and technical controls protect data against unauthorized access, loss, or disclosure.
Operava actively demonstrates compliance through documentation, audit trails, and strict internal governance.