Effective Date: July 30, 2023
Last Updated: April 19, 2026
In strict adherence to Republic Act No. 10173, otherwise known as the Data
Privacy Act of
2012 (DPA),
and the directives of the National Privacy Commission (NPC) of the Philippines,
StrataMedica
(the “Company,” “we,” “us,” or “our”) is committed to protecting the fundamental human right to
privacy while ensuring the free flow of information to promote innovation and growth.
-
INTRODUCTION
This Data Privacy Policy (the “Policy”) outlines our practices regarding the collection,
use, storage, and protection of information obtained through our platform. By accessing
our services, you acknowledge that you have read, understood, and agreed to the terms of
this Policy.
-
PERSONAL INFORMATION CONTROLLER
StrataMedica serves as the Personal Information Controller (PIC) as
defined under
the DPA. This means we are responsible for the control and processing of your personal
data and determine the specific purposes for which such data is utilized.
-
CATEGORIES OF INFORMATION COLLECTED
To provide our specialized services effectively, we collect and process the
following:
-
Personal Information: Information that establishes your identity,
including but not
limited to your full name, primary email address, mobile/telephone number, and
permanent or current residential address.
-
Sensitive Personal Information: Given the nature of our services,
we process
information concerning an individual's health, including medical history,
therapy records, psychological assessments, and other related clinical data.
-
Technical and Usage Data: Automatically collected data such as
Internet
Protocol (IP) addresses, browser types, device identifiers, cookies, and
telemetry regarding your interaction with our digital interfaces.
-
PURPOSE OF PROCESSING
The processing of personal data is anchored on the principles of Transparency, Legitimate
Purpose, and Proportionality. Data is processed for:
- Service Facilitation: Managing bookings, appointments, and the
delivery of therapeutic services.
- Administrative Operations: Identity verification, secure payment
processing, and customer support.
- Service Optimization: Internal analytics to improve system
functionality and user experience.
- Legal Compliance: Adhering to statutory requirements, tax
obligations, and lawful orders from government agencies.
-
LEGAL BASIS FOR PROCESSING
We process your data based on the following legal frameworks:
- Consent: Explicit permission granted by you for specific processing
activities.
- Contractual Necessity: Processing required to fulfill our
obligations under
the Service Agreement.
- Legal Obligation: Processing mandated by Philippine law or
regulatory
bodies.
-
DATA SHARING AND DISCLOSURE
We do not sell, rent, or lease your personal data to third parties. Disclosure is limited
to:
- Authorized Personnel: Licensed Therapists and clinical staff
directly involved in your care.
- Service Providers: Third-party partners (e.g., payment gateways,
cloud hosting) bound by strict
Data Sharing Agreements (DSA).
- Law Enforcement: When such disclosure is necessary to comply with a
judicial proceeding or legal process.
-
DATA SECURITY MEASURES
The Company employs a "Defense-in-Depth" strategy to protect your information,
utilizing:
- Technical Safeguards: Advanced encryption protocols (AES-256) for
data at rest and in transit.
- Physical Safeguards: Secure data centers and restricted access to
physical files.
- Organizational Safeguards: Regular staff training, non-disclosure
agreements (NDAs), and periodic privacy impact assessments.
-
RETENTION AND DISPOSAL
Personal data shall be retained only for as long as necessary to fulfill the purposes
outlined in this Policy or as required by clinical record-keeping regulations. Upon the
expiration of the retention period, data shall be disposed of through secure
de-identification or physical destruction to prevent further processing.
-
RIGHTS OF THE DATA SUBJECT
As a data subject under the DPA, you are entitled to:
- Right to be Informed: To know whether your data is being processed.
- Right to Access: To demand reasonable access to your personal
information.
- Right to Rectification: To dispute and correct inaccuracies in your
records.
- Right to Erasure/Blocking: To request the removal of your data from
our systems.
- Right to Damages: To be indemnified for any damages sustained due
to inaccurate, incomplete, or unauthorized use of personal data.
-
DATA BREACH NOTIFICATION
In compliance with NPC Circular No. 16-03, StrataMedica maintains a Data Breach
Response Team. In the event of a confirmed personal data breach, we will
notify the
affected users and the National Privacy Commission within seventy-two (72)
hours of
knowledge of the breach.
-
AMENDMENTS
The Company reserves the right to modify this Policy at any time. Changes will be
effective immediately upon posting the revised version on our platform. Your continued
use of our services constitutes an acceptance of the updated Policy.
-
CONTACT INFORMATION
For inquiries, requests for access, or concerns regarding your privacy rights, please
contact our
Data Protection Officer (DPO):.
Attention: Data Protection Officer
Address: Naga City, Philippines
Email: admin@stratamedica.com
By registering for an account and using our services, you acknowledge that you have read,
understood,
and agree to the terms of this Data Privacy Policy.