DATA PRIVACY POLICY
This Data Privacy Policy is hereby adopted by p+d (“Company”), in compliance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (“DPA”), its Implementing Rules and Regulations (“IRR”), and all issuances of the National Privacy Commission (“NPC”). This Policy governs the manner by which personal and sensitive personal information are collected, processed, stored, shared, retained, and disposed of through the Company’s website, pplusd.com, and all related online services.
1. COLLECTION OF PERSONAL INFORMATION
The Company collects, receives, and processes personal information voluntarily submitted by users, including but not limited to:
- Full name;
- Contact information (email address, mobile number);
- Account credentials created for the Client Portal;
- Medical-related information submitted voluntarily through forms, consultations, or health questionnaires;
- Transaction details and service preferences;
- IP address, browser details, and usage analytics automatically generated by the system.
2. PURPOSES OF PROCESSING
Personal data are collected and processed strictly for the following legitimate and lawful purposes:
- Creation and management of user accounts and patient profiles;
- Verification of identity and prevention of fraudulent access;
- Provision of services, consultations, health programs, and subscription-based formulations;
- Communication regarding appointments, updates, follow-ups, and advisories;
- Compliance with regulatory requirements applicable to health and wellness services;
- Website optimization, analytics, and service improvement;
- Record-keeping consistent with lawful business purposes.
3. LEGAL BASIS FOR PROCESSING
The Company processes personal and sensitive personal information based on any of the following lawful grounds:
- The data subject’s express and voluntary consent;
- Performance of a contract or provision of requested services;
- Compliance with legal and regulatory obligations;
- Protection of vitally important interests of the data subject;
- Legitimate interests of the Company, provided such interests do not override fundamental rights and freedoms.
4. STORAGE, RETENTION, AND SECURITY
The Company adopts reasonable and appropriate organizational, physical, and technical security measures to ensure the confidentiality, integrity, and availability of personal data. These measures include encrypted storage, restricted administrative access, regular security audits, SSL-protected transactions, and secure authentication protocols.
Personal data shall be retained only for as long as necessary to fulfill the declared purposes or as required by law, after which such data shall be securely deleted or anonymized.
5. DISCLOSURE AND DATA SHARING
The Company shall not disclose, sell, or share personal data to unauthorized third parties. Disclosure shall be made only under the following circumstances:
- To service providers necessary for the operation of the website or delivery of services, bound by strict confidentiality obligations;
- When required by law, subpoena, or lawful order of competent governmental authorities;
- With the express and written consent of the data subject.
6. RIGHTS OF THE DATA SUBJECT
In accordance with the DPA, users and clients are entitled to the following rights:
- Right to be informed;
- Right to access;
- Right to object;
- Right to erasure or blocking;
- Right to damages;
- Right to rectify or correct personal data;
- Right to data portability.
7. USE OF COOKIES AND ANALYTICS
The website uses cookies, web beacons, and similar technologies for analytics, functionality enhancement, and user experience improvement. Users may disable cookies through browser settings, however certain functions may not operate optimally.
8. AMENDMENTS
The Company reserves the right to amend, modify, or revise this Policy at any time to comply with regulatory changes or to enhance data protection measures. Updated versions shall be posted on this website.
9. CONTACT INFORMATION
For inquiries, concerns, or the exercise of data subject rights, the Company’s Data Protection Officer (“DPO”) may be contacted at:
Email: support@pplusd.com
Website: https://pplusd.com
By using this website, you acknowledge that you have read, understood, and agree to be bound by this Data Privacy Policy.