Data Privacy Policy
Medtax Solutions Inc.
I. Introduction
Medtax Solutions Inc. (“Medtax,” “the Company,” “we,” “us,” or “our”) is committed to protecting the privacy and security of the personal data of our clients, customers, and other individuals we interact with in the course of providing tax, accounting, payroll, and related business process services. This Data Privacy Policy (“Policy”) describes how we collect, use, store, share, and protect personal data in compliance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (“DPA”), its Implementing Rules and Regulations (“IRR”), and the issuances of the National Privacy Commission (“NPC”).
By engaging our services, visiting our website, or otherwise providing us with your personal data, you acknowledge that you have read and understood this Policy.
II. Scope and Application
This Policy applies to all personal data collected, used, and processed by Medtax in connection with the services we provide to our clients and customers, including personal data of individuals whose information is processed by Medtax on behalf of its corporate clients (e.g., the employees of a client whose payroll or tax records Medtax processes). This Policy covers personal data collected through our offices, website, email, telephone, and other channels of communication.
III. Definition of Terms
- “Personal Data” refers to any information, whether recorded in material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained, or when put together with other information would directly and certainly identify an individual.
- “Sensitive Personal Information” refers to personal data about an individual’s race, ethnicity, marital status, age, health, education, genetic or sexual life, government-issued identification numbers (e.g., TIN, SSS, GSIS, PhilHealth, and Pag-IBIG numbers), and other information classified as sensitive under the DPA.
- “Data Subject” refers to an individual whose personal data is processed by Medtax.
- “Processing” refers to any operation performed upon personal data, including the collection, recording, organization, storage, updating, retrieval, use, consolidation, blocking, erasure, or destruction of data.
- “Data Protection Officer” or “DPO” refers to the individual designated by Medtax to ensure compliance with the DPA and to serve as the primary contact for privacy-related concerns.
IV. Personal Data We Collect
In connection with the tax preparation, filing, bookkeeping, payroll, and related services we provide, Medtax may collect the following categories of personal data from clients, customers, and their authorized representatives:
- Identification information such as full name, date of birth, civil status, and government-issued identification numbers (e.g., Tax Identification Number, SSS, GSIS, PhilHealth, and Pag-IBIG numbers).
- Contact information such as home and business address, email address, and telephone or mobile number.
- Financial and tax information such as income, assets, liabilities, bank account details, receipts, invoices, and other supporting documents necessary for tax preparation and filing.
- Employment information such as employer name, position, and compensation details, where relevant to payroll or tax processing services.
- Other information voluntarily provided by the data subject, or required by law or by government agencies (e.g., the Bureau of Internal Revenue), in connection with the services engaged.
V. How We Collect Personal Data
We collect personal data directly from clients and customers through engagement forms, consultations, email or phone correspondence, and document submissions. We may also receive personal data from the authorized representatives of our corporate clients, or from government agencies and other third parties, where necessary and permitted by law to carry out the services engaged.
VI. Purposes of Collection and Processing
Medtax collects and processes personal data for the following purposes:
- To prepare, file, and process tax returns and other regulatory filings on behalf of clients.
- To provide bookkeeping, payroll, accounting, and related business process services.
- To comply with legal and regulatory obligations, including those imposed by the Bureau of Internal Revenue and other government agencies.
- To communicate with clients regarding their engagement, including billing, invoicing, and service updates.
- To maintain records required for audit, legal, and regulatory compliance purposes.
- To improve our services and, where consent has been given, to inform clients of other services that may be of interest to them.
VII. Legal Basis for Processing
Medtax processes personal data on one or more of the following legal bases recognized under the DPA: (a) the consent of the data subject; (b) the necessity of processing for the performance of a contract or engagement with the data subject; (c) compliance with a legal obligation to which Medtax is subject; and (d) the legitimate interests pursued by Medtax, provided such interests are not overridden by the fundamental rights and freedoms of the data subject.
VIII. Disclosure and Sharing of Personal Data
Medtax does not sell, rent, or trade personal data to third parties for marketing purposes and not use for data testing. Personal data may be shared or disclosed only in the following circumstances:
- With government agencies such as the Bureau of Internal Revenue, Social Security System, PhilHealth, and Pag-IBIG Fund, as required to complete the services engaged or as mandated by law.
- With the express consent of the data subject.
- When required or permitted by law, regulation, court order, or other legal process.
IX. Data Storage, Retention, and Disposal
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal, regulatory, tax, or accounting requirements, or to establish, exercise, or defend legal claims. Upon expiration of the applicable retention period, personal data is securely disposed of or anonymized in accordance with our internal data retention and disposal procedures.
X. Data Security Measures
Medtax implements reasonable and appropriate organizational, physical, and technical security measures designed to protect personal data against accidental or unlawful destruction, alteration, disclosure, or access. These measures include, among others: restricting access to personal data on a need-to-know basis, securing systems and records with passwords and access controls, using encryption where applicable, imposing confidentiality obligations on personnel who handle personal data, and periodically reviewing our data protection policies and practices.
XI. Rights of Data Subjects
Consistent with the DPA, data subjects have the right to:
- Be informed that their personal data will be, is being, or has been processed.
- Access their personal data upon request, subject to certain exceptions provided by law.
- Object to the processing of their personal data, including processing for direct marketing, automated processing, or profiling.
- Request the correction of inaccurate or outdated personal data.
- Request the erasure or blocking of personal data under circumstances allowed by law, such as when the data is incomplete, outdated, false, unlawfully obtained, or used for an unauthorized purpose.
- Be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal data.
- Data portability, where applicable and technically feasible.
- Lodge a complaint before the National Privacy Commission.
Requests to exercise any of these rights may be sent to our Data Protection Officer using the contact details provided in Section XIV of this Policy.
XII. Data Breach Management
In the event of a personal data breach that poses a real risk of serious harm to affected data subjects, Medtax will notify the National Privacy Commission and the affected data subjects within the period prescribed under applicable NPC regulations, and will take appropriate steps to contain, assess, and mitigate the impact of the breach.
XIII. Third-Party Links and Cookies
Our website may contain links to third-party websites and may use cookies or similar technologies to improve user experience. Medtax is not responsible for the privacy practices of third-party websites. Where cookies are used, you may manage your cookie preferences through your browser settings.
XIV. Data Protection Officer
For questions, concerns, or requests relating to this Policy or the processing of your personal data, you may contact our Data Protection Officer at:
Medtax Solutions Inc.17 Xavierville Avenue, Loyola Heights, Quezon CityEmail: [DPO email address]Contact Number: [DPO contact number]
XV. Amendments to This Policy
Medtax reserves the right to update or amend this Policy from time to time to reflect changes in our data processing practices or in applicable laws and regulations. The updated Policy will be posted with a revised effective date and, where required, notice will be provided to affected data subjects.
XVI. How to Reach Us
If you have any concerns about how your personal data has been handled, you may reach out to our Data Protection Officer through the contact details in Section XIV above. You may also file a complaint with the National Privacy Commission (NPC) through www.privacy.gov.ph if you believe your data privacy rights have been violated.