Sourcefit Philippines Inc.
Website publication copy | Updated 28 July 2026
At Sourcefit, we prioritize the protection of personal data and uphold the rights and interests of data subjects (owners of personally identifiable information). We recognize the value of personally identifiable information (PII) entrusted to us and are committed to managing and safeguarding it responsibly. This Privacy Policy outlines how we collect, use, and share personal information when you visit our website, www.sourcefit.com (the “Site”).
1. Data Subjects and Rights
We want you to feel secure knowing that we will handle your information with utmost care. Our privacy controls adhere to applicable data privacy regulations and are designed to protect personal data collected, used, and stored in our systems. We have mapped these regulations across our operations and developed measures to address specific requirements.
- Right to Information. Your personal data is treated as your property, and we will not collect, process, or store it without your explicit and informed consent, except as required by law. We obtain consent through consent forms, privacy notices, and acknowledgment pages.
- Right to Access Information. You have the right to know if we hold any personal data about you and to request access to it. We provide a written description of the information we hold and its purpose, together with access to obtain a copy.
- Right to Object to Processing. You may object to the processing of your personal data based on consent or legitimate interest. We cease processing upon objection or withdrawal of consent, except where processing remains legally required.
- Right to Erasure or Blocking. You may suspend, withdraw, or request the deletion of your personal data under certain circumstances, including where data is incomplete or was unlawfully obtained.
- Right to Damages. You may claim compensation for damages resulting from inaccurate or unauthorized use of personal data, including violations of your rights.
- Right to Data Portability. You have the right to obtain and transfer your data securely for further use.
- Right to Rectification. You may dispute and correct inaccuracies in your personal data, and we will act promptly on valid requests.
2. Information We Collect, Use, and Why
Personally identifiable information is important to our business operations, and we handle it with care to deliver services efficiently. PII may be collected and used by our support services team for purposes including employee compensation, access management, and business development.
Types of Information We May Collect
- Identifiers and Contacts. Your name, contact numbers, and email addresses for communication and identification purposes.
- Biometric Information. Fingerprints for physical access control.
- Basic Health Information. Health status and wellness data required for employment and wellness programs.
- Location and Addresses. Mailing and physical addresses for correspondence and asset delivery.
- Government ID Numbers. Information needed for government-mandated applications and transactions.
- Work History, Background, and Credentials. Educational and work history for employee profiling and credential verification.
Customer information belonging to our client partners is managed exclusively by those clients to support their control and compliance with applicable privacy requirements. We do not store client information outside client-authorized environments, but may facilitate its use within client systems as necessary to provide services.
Website Information Collection
When you visit our website, we collect device information such as browser details, Internet Protocol addresses, and cookies. Contact information is collected through contact forms for communication purposes.
3. Data Privacy Principles and Legislative Requirements
We adhere to the principles of transparency, legitimate purpose, and proportionality when processing PII, ensuring fair and lawful practices.
Transparency
We obtain consent before processing PII where consent is the applicable lawful basis, and we inform data subjects of the purpose, risks, safeguards, and rights associated with processing.
Legitimate Purpose
Our processing of PII aligns with declared purposes and applicable legal requirements.
Retention
We retain PII only for specified periods based on regulatory requirements and operational necessity, and dispose of it securely afterward. In accordance with prevailing requirements, we may retain PII for up to five years; however, the retention and disposal of sensitive information may require further consent or another appropriate lawful basis.
Proportionality
We collect only the information necessary for specified purposes.
Processing
We ensure that PII processed is adequate, relevant, and not excessive in relation to the intended purpose.
Consent
Informed and active consent is obtained before data collection where consent is required, with consent forms used whenever practicable.
Privacy Impact and Risks
Privacy impact assessments and risk analyses are conducted periodically and before implementing new processes or technologies involving PII.
Disposal
Records and documents are disposed of securely in accordance with retention schedules. Clients control the disposal of customer information stored in their systems or portals.
Security Measures
PII is securely stored in databases managed by the Company’s Information Technology department. We maintain appropriate technical, physical, and organizational safeguards to protect information. These measures are regularly reviewed and updated to align with regulatory standards and technological developments. They include, but are not limited to:
- Secure Storage. PII is stored in systems equipped with encryption and access controls designed to prevent unauthorized access.
- Technical Safeguards. We use security technologies such as firewalls, intrusion detection systems, and encryption protocols to protect information from cyber threats.
- Physical Security. Our facilities use access controls, surveillance systems, and other physical safeguards to prevent unauthorized access to premises and hardware.
- Organizational Controls. We enforce policies and procedures governing the handling and processing of PII. Regular training and awareness programs help employees maintain the security of personal data.
- Regular Review and Updates. We regularly review and update our safeguards, conduct security assessments and audits, and address identified vulnerabilities.
To learn more about these measures and how PII is secured, please contact our Data Protection Officer.
Data Classification
To support the protection of PII and other organizational information, Sourcefit applies the following data classification scheme:
| Public | Business Confidential | Confidential | Classified |
|---|---|---|---|
| Information intended and released for public use | Information that may be shared only within Sourcefit | High-risk information that requires strict controls | Client or organizational information subject to the highest restrictions |
| Examples: Published research Training course catalogs Privacy Policy Support directory Basic emergency response plans Publications Press releases Published marketing materials Published annual reports Public announcements |
Examples: Department policies and procedures Employee web or intranet portals Training materials Pre-release articles Non-public building plans or layouts Non-sensitive administrative survey data |
Examples: Passwords and personal identification numbers System credentials Individually identifiable financial account information Individually identifiable health or medical information Detailed security system procedures and architectures |
Examples: Classified client data Client trade secrets |
Information-handling controls by classification
| Activity | Business Confidential | Confidential | Classified |
|---|---|---|---|
| Printing | Do not leave unattended on printer trays or bins | Do not leave unattended on printer trays or bins | Never print unless explicitly approved |
| Mailing paper-based information | Place in a closed mailing envelope or box | Place in a closed mailing envelope or box | Do not mail |
| Storing electronic files on work or personal devices | Store only in Information Technology-approved storage, such as OneDrive | Store only in Information Technology-approved storage, such as OneDrive | Never store outside client systems or portals |
| Sharing files with authorized individuals | Use approved collaboration tools and share only with specific individuals; do not use anonymous or guest links | Use approved collaboration tools and share only with specific individuals; do not use anonymous or guest links | Do not share |
| Engaging vendors to store or process data | Written contracts are strongly recommended | Written contracts are strongly recommended | Written contracts are strongly recommended |
Note: These controls apply to internal records and to records shared with third parties and vendors.
4. Restriction on Sharing PII and Marketing Use
Sharing PII
We restrict the sharing of PII with third parties unless it is necessary to fulfill contractual obligations or is required by law. Any sharing of PII is undertaken with appropriate care and safeguards designed to protect the information.
Marketing
We will not use your PII for profiling or marketing purposes unless a legitimate purpose is established or your explicit consent is obtained. Legitimate purposes may include providing relevant information about products or services that are directly related to your interests or needs.
5. Data Subject Requests and Incident Management
Exercising Data Subject Rights
You may engage our Data Protection Officer to exercise your data privacy rights, including accessing information, correcting inaccuracies, objecting to processing, or requesting erasure. Our Data Protection Officer facilitates valid requests promptly and transparently. You may submit a request using the Data Subject Action Request Form: https://forms.office.com/r/zR5p32wTHf
Reporting Incidents
In the event of a data privacy incident or breach, you may report it directly to our Data Protection Officer. The Data Protection Officer oversees incident-response procedures, including timely assessment, mitigation, escalation, and regulatory or contractual reporting where required.
6. Our Data Protection Officer
Sourcefit’s Data Protection Officer oversees all data privacy matters, manages the Data Privacy Program, responds to inquiries and data subject requests, identifies and addresses privacy risks, and supports compliance with applicable data protection laws and requirements.
For privacy inquiries, data subject requests, or incident reports, please contact:
Data Protection Officer: Carl Valencia
Email: dp*@*******it.com
7. Our Data Privacy Compliance
Sourcefit Philippines Inc. has complied with the Data Protection Officer and Personal Information Controller registration requirements of the National Privacy Commission of the Philippines in accordance with applicable NPC issuances. Sourcefit’s NPC Registration No. PIC-011-359-2025 is effective until 15 September 2026.
SOURCEFIT | PRIVACY POLICY
Privacy inquiries and incident reports: dp*@*******it.com
Our Data Privacy Compliance
![]() |
![]() |
Sourcefit has successfully complied with the Data Protection Officer and Personal Information Controller registration requirements of the National Privacy Commission of the Philippines, in accordance with applicable NPC issuances. Sourcefit’s NPC Registration No. PIC-011-359-2025 is effective until 15 September 2026. You may scan the QR code to get more information about our registration details.

