Privacy Policy

We have updated our Privacy Policy

Sourcefit Philippines Inc.

Website publication copy | Updated 28 July 2026

At Sourcefit, we prioritize the protection of personal data and uphold the rights and interests of data subjects (owners of personally identifiable information). We recognize the value of personally identifiable information (PII) entrusted to us and are committed to managing and safeguarding it responsibly. This Privacy Policy outlines how we collect, use, and share personal information when you visit our website, www.sourcefit.com (the “Site”).


1. Data Subjects and Rights

We want you to feel secure knowing that we will handle your information with utmost care. Our privacy controls adhere to applicable data privacy regulations and are designed to protect personal data collected, used, and stored in our systems. We have mapped these regulations across our operations and developed measures to address specific requirements.

  • Right to Information. Your personal data is treated as your property, and we will not collect, process, or store it without your explicit and informed consent, except as required by law. We obtain consent through consent forms, privacy notices, and acknowledgment pages.
  • Right to Access Information. You have the right to know if we hold any personal data about you and to request access to it. We provide a written description of the information we hold and its purpose, together with access to obtain a copy.
  • Right to Object to Processing. You may object to the processing of your personal data based on consent or legitimate interest. We cease processing upon objection or withdrawal of consent, except where processing remains legally required.
  • Right to Erasure or Blocking. You may suspend, withdraw, or request the deletion of your personal data under certain circumstances, including where data is incomplete or was unlawfully obtained.
  • Right to Damages. You may claim compensation for damages resulting from inaccurate or unauthorized use of personal data, including violations of your rights.
  • Right to Data Portability. You have the right to obtain and transfer your data securely for further use.
  • Right to Rectification. You may dispute and correct inaccuracies in your personal data, and we will act promptly on valid requests.

2. Information We Collect, Use, and Why

Personally identifiable information is important to our business operations, and we handle it with care to deliver services efficiently. PII may be collected and used by our support services team for purposes including employee compensation, access management, and business development.

Types of Information We May Collect
  • Identifiers and Contacts. Your name, contact numbers, and email addresses for communication and identification purposes.
  • Biometric Information. Fingerprints for physical access control.
  • Basic Health Information. Health status and wellness data required for employment and wellness programs.
  • Location and Addresses. Mailing and physical addresses for correspondence and asset delivery.
  • Government ID Numbers. Information needed for government-mandated applications and transactions.
  • Work History, Background, and Credentials. Educational and work history for employee profiling and credential verification.

Customer information belonging to our client partners is managed exclusively by those clients to support their control and compliance with applicable privacy requirements. We do not store client information outside client-authorized environments, but may facilitate its use within client systems as necessary to provide services.

Website Information Collection

When you visit our website, we collect device information such as browser details, Internet Protocol addresses, and cookies. Contact information is collected through contact forms for communication purposes.


3. Data Privacy Principles and Legislative Requirements

We adhere to the principles of transparency, legitimate purpose, and proportionality when processing PII, ensuring fair and lawful practices.

Transparency

We obtain consent before processing PII where consent is the applicable lawful basis, and we inform data subjects of the purpose, risks, safeguards, and rights associated with processing.

Legitimate Purpose

Our processing of PII aligns with declared purposes and applicable legal requirements.

Retention

We retain PII only for specified periods based on regulatory requirements and operational necessity, and dispose of it securely afterward. In accordance with prevailing requirements, we may retain PII for up to five years; however, the retention and disposal of sensitive information may require further consent or another appropriate lawful basis.

Proportionality

We collect only the information necessary for specified purposes.

Processing

We ensure that PII processed is adequate, relevant, and not excessive in relation to the intended purpose.

Consent

Informed and active consent is obtained before data collection where consent is required, with consent forms used whenever practicable.

Privacy Impact and Risks

Privacy impact assessments and risk analyses are conducted periodically and before implementing new processes or technologies involving PII.

Disposal

Records and documents are disposed of securely in accordance with retention schedules. Clients control the disposal of customer information stored in their systems or portals.

Security Measures

PII is securely stored in databases managed by the Company’s Information Technology department. We maintain appropriate technical, physical, and organizational safeguards to protect information. These measures are regularly reviewed and updated to align with regulatory standards and technological developments. They include, but are not limited to:

  • Secure Storage. PII is stored in systems equipped with encryption and access controls designed to prevent unauthorized access.
  • Technical Safeguards. We use security technologies such as firewalls, intrusion detection systems, and encryption protocols to protect information from cyber threats.
  • Physical Security. Our facilities use access controls, surveillance systems, and other physical safeguards to prevent unauthorized access to premises and hardware.
  • Organizational Controls. We enforce policies and procedures governing the handling and processing of PII. Regular training and awareness programs help employees maintain the security of personal data.
  • Regular Review and Updates. We regularly review and update our safeguards, conduct security assessments and audits, and address identified vulnerabilities.

To learn more about these measures and how PII is secured, please contact our Data Protection Officer.


Data Classification

To support the protection of PII and other organizational information, Sourcefit applies the following data classification scheme:

Public Business Confidential Confidential Classified
Information intended and released for public use Information that may be shared only within Sourcefit High-risk information that requires strict controls Client or organizational information subject to the highest restrictions
Examples:
Published research
Training course catalogs
Privacy Policy
Support directory
Basic emergency response plans
Publications
Press releases
Published marketing materials
Published annual reports
Public announcements
Examples:
Department policies and procedures
Employee web or intranet portals
Training materials
Pre-release articles
Non-public building plans or layouts
Non-sensitive administrative survey data
Examples:
Passwords and personal identification numbers
System credentials
Individually identifiable financial account information
Individually identifiable health or medical information
Detailed security system procedures and architectures
Examples:
Classified client data
Client trade secrets
Information-handling controls by classification
Activity Business Confidential Confidential Classified
Printing Do not leave unattended on printer trays or bins Do not leave unattended on printer trays or bins Never print unless explicitly approved
Mailing paper-based information Place in a closed mailing envelope or box Place in a closed mailing envelope or box Do not mail
Storing electronic files on work or personal devices Store only in Information Technology-approved storage, such as OneDrive Store only in Information Technology-approved storage, such as OneDrive Never store outside client systems or portals
Sharing files with authorized individuals Use approved collaboration tools and share only with specific individuals; do not use anonymous or guest links Use approved collaboration tools and share only with specific individuals; do not use anonymous or guest links Do not share
Engaging vendors to store or process data Written contracts are strongly recommended Written contracts are strongly recommended Written contracts are strongly recommended

Note: These controls apply to internal records and to records shared with third parties and vendors.


4. Restriction on Sharing PII and Marketing Use

Sharing PII

We restrict the sharing of PII with third parties unless it is necessary to fulfill contractual obligations or is required by law. Any sharing of PII is undertaken with appropriate care and safeguards designed to protect the information.

Marketing

We will not use your PII for profiling or marketing purposes unless a legitimate purpose is established or your explicit consent is obtained. Legitimate purposes may include providing relevant information about products or services that are directly related to your interests or needs.


5. Data Subject Requests and Incident Management

Exercising Data Subject Rights

You may engage our Data Protection Officer to exercise your data privacy rights, including accessing information, correcting inaccuracies, objecting to processing, or requesting erasure. Our Data Protection Officer facilitates valid requests promptly and transparently. You may submit a request using the Data Subject Action Request Form: https://forms.office.com/r/zR5p32wTHf

Reporting Incidents

In the event of a data privacy incident or breach, you may report it directly to our Data Protection Officer. The Data Protection Officer oversees incident-response procedures, including timely assessment, mitigation, escalation, and regulatory or contractual reporting where required.


6. Our Data Protection Officer

Sourcefit’s Data Protection Officer oversees all data privacy matters, manages the Data Privacy Program, responds to inquiries and data subject requests, identifies and addresses privacy risks, and supports compliance with applicable data protection laws and requirements.

For privacy inquiries, data subject requests, or incident reports, please contact:

Data Protection Officer: Carl Valencia
Email: dp*@*******it.com


7. Our Data Privacy Compliance

Sourcefit Philippines Inc. has complied with the Data Protection Officer and Personal Information Controller registration requirements of the National Privacy Commission of the Philippines in accordance with applicable NPC issuances. Sourcefit’s NPC Registration No. PIC-011-359-2025 is effective until 15 September 2026.


SOURCEFIT | PRIVACY POLICY

Privacy inquiries and incident reports: dp*@*******it.com

Our Data Privacy Compliance

Sourcefit has successfully complied with the Data Protection Officer and Personal Information Controller registration requirements of the National Privacy Commission of the Philippines, in accordance with applicable NPC issuances. Sourcefit’s NPC Registration No. PIC-011-359-2025 is effective until 15 September 2026. You may scan the QR code to get more information about our registration details.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.