Operava Privacy and Compliance Framework

Home / Privacy Policy

Privacy Policy & Privacy Notice

Website visitors, job applicants, employees, independent contractors, commercial clients, customer service end-users, and digital platform consumers. Comprehensive data protection framework.

Entity: Operava Global Solutions Effective Date: August 17, 2026 Governing Law: Philippine Data Privacy Act of 2012 (RA 10173) Regulatory Authority: National Privacy Commission (NPC) Privacy Contact: compliance@operavaglobal.com

Philippine Data Privacy Act of 2012 (Republic Act No. 10173): Operava Global Solutions strictly adheres to statutory principles of Transparency, Legitimate Purpose, and Proportionality across all personal and sensitive personal data processing activities.

01

Organizational Commitment

Operava Global Solutions ("Operava", "we", "us", or "our") is dedicated to protecting the privacy, confidentiality, and fundamental data rights of every individual whose personal data is entrusted to us. In conducting our technology engineering, workforce augmentation, and Business Process Outsourcing (BPO) operations, we collect only the personal information reasonably necessary for identified, lawful, and legitimate purposes.

We process all data strictly in accordance with statutory requirements, safeguard collected records through robust administrative, technical, and physical security measures, and retain data only for timeframes justified by legal mandate or business necessity.

02

Who This Policy Applies To

This Privacy Policy and Notice applies comprehensively to:

  • Website Visitors: Individuals browsing our marketing websites, knowledge repositories, and public portals.
  • Job Applicants & Candidates: Individuals submitting resumes, CVs, portfolios, or applications for employment or contractor talent pools.
  • Active Employees & Contractors: Direct staff, augmented talent, and independent professionals engaged by Operava.
  • Commercial Clients & Partners: Authorized client representatives, billing administrators, and technical contacts.
  • Customer Service End-Users: End-users interacting with customer support desks or managed back-office processes handled by Operava under contract.
  • Digital Platform Users: Individuals accessing internal or client-facing project tools, dashboards, and APIs.
03

Categories of Information We Collect

We may collect and process the following categories of personal data depending on your interaction with Operava:

  • Identification & Contact Data: Full legal name, preferred name, job title, company name, corporate email address, telephone number, physical mailing address, and digital communication handles.
  • Government & Regulatory Identifiers: Tax Identification Number (TIN), Social Security System (SSS) number, PhilHealth number, Pag-IBIG HDMF number, passport copies, or government-issued photo IDs collected strictly where mandated by Philippine labor, tax, or immigration laws.
  • Professional & Career History: Detailed resumes/CVs, work history, educational credentials, certifications, technical code samples, language proficiencies, technical evaluation scores, interview notes, reference checks, and compensation expectations.
  • Commercial & Billing Records: Corporate billing addresses, authorized signatory credentials, bank account wiring instructions, purchase orders, milestone acceptance forms, and payment logs.
  • Technical & Telemetry Data: IP addresses, browser specifications, operating system versions, device identifiers, referral URLs, access timestamps, page interaction logs, and security audit trails.
04

Sensitive Personal Information

Under Section 3 of RA 10173, sensitive personal information (including government-issued IDs, health records, or religious affiliations) is treated with heightened care. Operava does not solicit sensitive personal data unless strictly necessary to satisfy statutory employment obligations (e.g., mandatory government benefits and pre-employment medical clearances) or where the individual has given explicit, documented consent.

Job applicants and public visitors are advised never to submit unsolicited sensitive personal data through general contact forms.

05

Methods of Data Collection

Operava collects personal information through three primary channels:

  • Direct Collection: Provided voluntarily when you fill out contact forms, submit a resume via our careers portal, schedule a consultation, or execute a commercial agreement.
  • Client-Provisioned Data: Provided by commercial clients who engage Operava to execute BPO, customer support, or QA workflows under a signed Data Processing Agreement (DPA).
  • Automated Telemetry: Gathered automatically through server logs, session cookies, and infrastructure monitoring tools when you interact with our digital platforms.
06

Legitimate Processing Purposes

We process personal data exclusively for explicit, legitimate commercial purposes, including:

  • Delivering contracted custom software engineering, web/mobile development, cloud DevOps, and managed BPO services.
  • Screening, evaluating, interviewing, and placing talent in accordance with client project requirements.
  • Managing employment contracts, processing payroll, and administering statutory benefits under DOLE, SSS, PhilHealth, and Pag-IBIG mandates.
  • Invoicing, fee collections, statutory tax compliance, and commercial accounting audits.
  • Resolving customer inquiries, managing support tickets, and fulfilling service level agreements (SLAs).
  • Protecting IT infrastructure from cybersecurity threats, DDoS attacks, unauthorized intrusion, and fraudulent activities.
  • Complying with lawful directives issued by Philippine regulatory agencies and law enforcement authorities.
07

AI-Assisted Recruitment & Evaluation

Operava employs modern recruitment technologies, including machine-learning models and artificial intelligence algorithms, to parse resumes, match technical proficiencies against open requisitions, and organize applicant pipelines.

Mandatory Human Oversight

AI tools function exclusively as administrative screening aids. All critical candidate decisions—including shortlisting, interview selections, technical evaluations, compensation offers, and rejection notices—are determined by qualified human talent acquisition specialists. We do not engage in purely automated decision-making that produces legal effects on applicants without human intervention.

08

Lawful Basis for Processing

In conformity with Section 12 and Section 13 of the Philippine Data Privacy Act of 2012, our processing is grounded in one or more recognized legal bases:

  • Consent: The data subject has given explicit, informed consent for specific processing operations.
  • Contractual Necessity: Processing is required to perform our obligations under an employment contract, Statement of Work, or service agreement.
  • Legal Obligation: Processing is mandated to comply with statutory laws, tax regulations (BIR), or labor codes (DOLE).
  • Legitimate Interests: Processing is necessary for our legitimate commercial interests (e.g., maintaining platform security), except where overridden by the fundamental rights of the data subject.
09

Client Data & Outsourced Processing (Processor Role)

In many BPO, customer support, and QA testing engagements, Operava acts as a Personal Information Processor (PIP) on behalf of our enterprise Clients (who serve as Personal Information Controllers (PIC)). In such engagements:

  • Operava processes client end-user data strictly under documented instructions from the Client.
  • We bind all personnel handling client data to strict, enforceable non-disclosure agreements.
  • We do not sub-contract processing or engage sub-processors without client notification and authorization.
  • Upon termination of the service contract, Operava deletes or returns all client-held data in accordance with the executed Data Processing Agreement.
10

Information Sharing & Third-Party Disclosure

Operava does not sell, lease, rent, or trade personal data to third-party brokers, advertisers, or telemarketers under any circumstances. Personal data is disclosed only to:

  • Authorized Operava employees, contractors, and project team members on a strict need-to-know basis.
  • Trusted cloud infrastructure partners (e.g., Amazon Web Services, Google Cloud Platform) maintaining enterprise security certifications (ISO 27001, SOC 2).
  • Licensed financial institutions and payment gateways to execute authorized commercial disbursements.
  • External legal counsel, certified public accountants, and auditors bound by professional duties of confidentiality.
  • Philippine regulatory or judicial bodies when legally compelled by valid subpoena, search warrant, or court order.
11

Cross-Border Data Transfers & International Processing

As a global, remote-first technology solutions provider, Operava may store, access, or process personal data across international boundaries. All cross-border data transmissions are governed by contractual safeguards, including standard contractual clauses and bilateral DPAs, ensuring that transferred information receives a level of protection comparable to Philippine statutory standards.

12

Comprehensive Security Safeguards

Operava enforces an enterprise-grade information security management system comprising:

  • Technical Measures: Industry-standard TLS 1.3 encryption for data in transit; AES-256 cryptographic encryption for data at rest; mandatory Multi-Factor Authentication (MFA); and automated intrusion prevention systems.
  • Organizational Controls: Documented security policies; least-privilege Role-Based Access Controls (RBAC); mandatory background checks for technical personnel; and periodic privacy compliance training.
  • Physical Safeguards: Encrypted endpoint device management; remote-wipe capabilities for lost or stolen hardware; and strict access limits to corporate physical and virtual infrastructure.
13

Security Incident & Breach Management

Operava maintains a formally documented Security Incident Response Protocol aligned with National Privacy Commission (NPC) Circular No. 16-03. In the event of a verified data breach involving sensitive personal data that poses a real risk of serious harm, Operava will notify affected data subjects and the NPC within seventy-two (72) hours of confirmed knowledge, outlining the nature of the breach, affected records, and remedial countermeasures taken.

14

Data Retention & Secure Disposal

Personal data is retained only for the duration necessary to satisfy the commercial, contractual, or statutory purposes for which it was gathered:

  • Candidate Profiles: Retained for active talent pipelining for up to twenty-four (24) months, after which records are archived or securely scrubbed unless renewed by the candidate.
  • Tax & Accounting Records: Retained for ten (10) years in compliance with Philippine Bureau of Internal Revenue (BIR) statutory audit requirements.
  • Employee Personnel Records: Retained for statutory durations mandated by the Department of Labor and Employment (DOLE).

Upon expiration of the retention window, digital records are purged using cryptographic erasure techniques, and physical files are destroyed via cross-cut shredding.

15

Cookies & Tracking Technologies

We utilize essential cookies to secure our websites, manage user authentication sessions, and maintain platform stability. We may also employ privacy-respecting analytics cookies to evaluate website traffic patterns and optimize user experience. Visitors may configure their web browser to reject cookies; however, certain interactive platform functions may be impaired as a result.

16

Candidate & Job Applicant Rights

Candidates submitting applications through our career portals maintain the right to inspect their application records, update their contact information, or request withdrawal of their candidacy at any time. Submitting an application registers candidate data in our talent pool for future placement opportunities without guaranteeing placement.

17

Employee & Independent Contractor Records

Personnel data collected during employment or contract engagements is processed for payroll disbursement, tax withholding, health coverage administration, performance evaluation, and workplace safety compliance. Access to personnel files is restricted to authorized human resources and finance personnel.

18

Protection of Minors

Operava’s services, job openings, and platforms are intended exclusively for individuals aged eighteen (18) years and older. We do not knowingly solicit or collect personal information from minors. If we discover that personal data of a minor has been gathered without verified parental consent, we will promptly purge that information from our production databases.

19

Full Enumeration of Data Subject Rights

Under Republic Act No. 10173, every data subject is entitled to exercise the following statutory rights:

  • Right to be Informed: To be notified whether personal data pertaining to you is being or has been processed.
  • Right to Access: To request reasonable access to your personal data held in our systems, including the source, purpose, and recipients of such data.
  • Right to Rectification: To dispute inaccuracies or errors in your data and have Operava correct them expeditiously.
  • Right to Erasure or Blocking: To request the suspension, withdrawal, removal, or destruction of your personal data upon legitimate grounds established by law.
  • Right to Object: To object to processing of personal data for direct marketing, automated profiling, or commercial research.
  • Right to Data Portability: To obtain a copy of your electronic data in an open, commonly used, machine-readable format.
  • Right to File a Complaint: To lodge a formal complaint with the National Privacy Commission (NPC) if your privacy rights have been violated.
  • Right to Indemnification: To be indemnified for verified damages sustained due to inaccurate, incomplete, or unlawful processing.
20

How to Exercise Your Privacy Rights

To exercise any of your statutory rights under RA 10173, submit a formal written request to our Data Compliance Office at compliance@operavaglobal.com. Please include:

  • Your full legal name and primary contact information.
  • Your relationship with Operava (e.g., website visitor, job applicant, commercial client, contractor).
  • A precise specification of the right you wish to exercise and the specific records in question.
  • A copy of a valid government-issued ID to enable reliable identity verification.

Operava will respond to verified privacy requests within thirty (30) business days from receipt.

21

Designated Privacy Contacts & Data Protection Officer

For all regulatory inquiries, data subject requests, or privacy concerns, contact our designated privacy compliance team:

Operava Global Solutions

Data Protection & Compliance Office
Pagudpud, Ilocos Norte 2919, Republic of the Philippines
SEC Registration: 2026080262213-03

Data Protection Officer compliance@operavaglobal.com
Customer Support cs@operavaglobal.com
Corporate Headquarters hello@operavaglobal.com
22

Client / Processor Coordination

Where Operava processes personal data solely as a Data Processor on behalf of a corporate Client, any data subject request submitted directly to Operava by the Client’s customer or end-user will be promptly forwarded to that Client’s designated Data Protection Officer for authoritative review and instruction.

23

Third-Party Websites & Integrations

Our website may contain hyperlinks to external third-party websites, developer repositories, or partner portals. Operava exercises no editorial control over the privacy policies or security standards of third-party domains. We advise visitors to review the independent privacy notices of any external site they visit.

24

Direct Marketing & Operational Communications

We do not engage in unsolicited promotional spam. Any marketing newsletters or industry updates sent by Operava include a direct, one-click unsubscribe mechanism. Operational notifications regarding active project sprints, milestone approvals, invoice receipts, and critical security advisories cannot be opted out of, as they are necessary to fulfill contractual obligations.

25

Data Accuracy & Maintenance

Operava takes reasonable operational measures to ensure that personal records in our custody remain accurate, current, and complete. Candidates, employees, and client representatives are encouraged to notify our administrative office of any changes to their contact details or professional status.

26

Organizational Accountability & Staff Training

Operava enforces organizational accountability through regular privacy awareness training for all employees, strict confidentiality clauses in employment agreements, routine internal audits of data access logs, and formal disciplinary procedures for any unauthorized disclosure or mishandling of personal data.

27

Privacy by Design & System Architecture

Our engineering teams incorporate Privacy by Design and Privacy by Default into our software development lifecycles. We enforce database tenant isolation, automated data pseudonymization, API rate limiting, and minimal payload transfers across all internal and client-facing digital architectures.

28

Policy Updates & Amendments

Operava reserves the right to amend this Privacy Policy periodically to reflect technological advancements, operational improvements, or updates in statutory legislation. Revisions will be published on this page with an updated "Effective Date". Continued interaction with our services following publication constitutes acknowledgment of the revised terms.

29

Governing Law & Regulatory Oversight

This Privacy Policy is governed by and construed in accordance with the laws of the Republic of the Philippines, in particular Republic Act No. 10173 (Data Privacy Act of 2012), its Implementing Rules and Regulations, and administrative issuances of the National Privacy Commission (NPC).

30

Regulatory Compliance Documentation & Audits

Operava maintains internal Records of Processing Activities (ROPA), Privacy Impact Assessments (PIA) for high-risk data workflows, and documented security incident logs as required for SEC-registered Philippine corporate entities.

31

Core Privacy Principles

Operava grounds every technical and operational workflow in the five core pillars of responsible data stewardship:

Transparency

Individuals are fully informed regarding why, how, and by whom their personal data is collected, stored, and utilized.

Legitimate Purpose

Processing is strictly confined to explicitly declared, lawful, and necessary commercial and operational objectives.

Proportionality

We collect only the minimum data strictly necessary to achieve our stated business and engineering requirements.

Security

Rigorous administrative, physical, and technical controls protect data against unauthorized access, loss, or disclosure.

Accountability

Operava actively demonstrates compliance through documentation, audit trails, and strict internal governance.