Republic Act No. 10173 Compliance Standard

Data Privacy Governance & Data Processing Roles (DPA)

Effective Date: 20 September 2026 • Published by the Aperto platform operator (Draft policy pending formal entity registration)

Draft Governance Framework Under Review: The statutory role mappings (RA 10173, PIC/PIP), subprocessor disclosures, and data rights below represent proposed privacy standards. Final legal and regulatory review is pending founder confirmation.

1. Statutory Compliance & PIC / PIP Role Demarcation

Aperto operates under the statutory framework of Republic Act No. 10173 (Data Privacy Act of 2012) and the regulations issued by the National Privacy Commission (NPC) of the Philippines.

The Venue Client is the Personal Information Controller (PIC)

Your club or sports organization determines the purpose and essential means of processing player data for your facility: managing court bookings, membership lists, attendance tracking, and customer contact.

Aperto is the Personal Information Processor (PIP)

Aperto processes player and booking records solely on behalf of, and in accordance with the contractual instructions of, the Venue Client. Aperto does not sell, rent, or independently monetize venue customer lists.

2. Categories of Data Processed

  • Player Information: Full name, Philippine mobile number (`09XXXXXXXXX`), email address, and encrypted account authentication hashes.
  • Operational Booking Records: Court selection, date, start/end timestamps, payment status, GCash reference numbers, and attendance check-in timestamps.
  • Staff & Audit Records: Staff employee name, work email, role capability assignment, and immutable audit event logs (tracking booking adjustments, cancellations, and till reconciliations).

3. Authorized Third-Party Subprocessors

Aperto engages audited third-party service providers to host our application and deliver communications. All subprocessors are bound by equivalent data security and confidentiality obligations:

SubprocessorFunctionHosting Jurisdiction
Supabase Inc. / AWSDatabase infrastructure & encrypted storageSingapore (ap-southeast-1)
Vercel Inc.Edge serverless compute & application hostingUnited States / Global Edge
PayMongo Philippines, Inc.Payment gateway tokenization & merchant checkoutPhilippines (BSP Regulated)
Resend, Inc.Transactional email dispatchUnited States
Semaphore (SMS Global Tech)Philippine telecommunications SMS deliveryPhilippines (NTC Regulated)

4. Data Subject Rights, Export Guarantee & Retention Schedule

In accordance with RA 10173, individual players and venue staff retain the statutory rights to be informed, to access, to object, to erasure or blocking, and to damages. A request is recorded when it arrives, answered by the Data Protection Officer at dpo@aperto.ph, and the record names the copy, the anonymization or the closure that discharged it.

Unrestricted Venue Data Export: Venue Owners can export their full, unredacted operational data at any time via the Staff Portal in RFC 4180 CSV format. The copy is generated on request and its payload is downloadable for 24 hours; the copy generated when a client leaves stays downloadable for 30 days counted from the closure date. Aperto keeps the record that the request happened — who asked, when, and how many rows the copy held.

Retention Schedule. This is the schedule the platform runs on, so the promise and the behaviour cannot drift apart:

DataKept forAt the end of the window
Client export payload (the generated CSV)24 hours after the export is generated, or 30 days after closurePayload and download token cleared; the job row recording who asked and why is kept
Client export record (who asked, when, what it held)Kept as an audit recordKept — it is the record that the request happened
Support grant (operator access to a client's records)Maximum 7 days, revoked or expired earlierStops authorizing on the next request; the grant row is kept as the audit trail
Player identity a branch holds (name, phone, marketing consent)Until the player asks, the client asks, or the client closesAnonymized in place; the profile row and every money and booking row stay linked
Player notes written by a branchRemoved when the player is anonymizedDeleted
Bookings, receipts, refunds, money accounts, audit eventsKeptKept as financial and audit history
Outbox messages and their delivery attemptsKeptKept — they are the delivery evidence

What erasure means here: A player's request, or the venue client's, anonymizes that branch's view of the player — display name, mobile number and marketing consent are cleared, and the branch's own notes about them are deleted — while the player's profile row and every booking, receipt, refund and audit row stay linked. Bookings, receipts, refunds, money accounts and audit events are kept: they are the record of what actually happened, and erasing them would erase the evidence a venue or a player needs to settle what is owed. A client account closes as a recorded state, never as a delete.

Designated Data Protection Officer (DPO): dpo@aperto.ph
Aperto platform operator • National Privacy Commission (NPC) Compliance Protocol