Data Privacy Governance & Data Processing Roles (DPA)
Effective Date: 20 September 2026 • Published by the Aperto platform operator (Draft policy pending formal entity registration)
1. Statutory Compliance & PIC / PIP Role Demarcation
Aperto operates under the statutory framework of Republic Act No. 10173 (Data Privacy Act of 2012) and the regulations issued by the National Privacy Commission (NPC) of the Philippines.
Your club or sports organization determines the purpose and essential means of processing player data for your facility: managing court bookings, membership lists, attendance tracking, and customer contact.
Aperto processes player and booking records solely on behalf of, and in accordance with the contractual instructions of, the Venue Client. Aperto does not sell, rent, or independently monetize venue customer lists.
2. Categories of Data Processed
- Player Information: Full name, Philippine mobile number (`09XXXXXXXXX`), email address, and encrypted account authentication hashes.
- Operational Booking Records: Court selection, date, start/end timestamps, payment status, GCash reference numbers, and attendance check-in timestamps.
- Staff & Audit Records: Staff employee name, work email, role capability assignment, and immutable audit event logs (tracking booking adjustments, cancellations, and till reconciliations).
3. Authorized Third-Party Subprocessors
Aperto engages audited third-party service providers to host our application and deliver communications. All subprocessors are bound by equivalent data security and confidentiality obligations:
| Subprocessor | Function | Hosting Jurisdiction |
|---|---|---|
| Supabase Inc. / AWS | Database infrastructure & encrypted storage | Singapore (ap-southeast-1) |
| Vercel Inc. | Edge serverless compute & application hosting | United States / Global Edge |
| PayMongo Philippines, Inc. | Payment gateway tokenization & merchant checkout | Philippines (BSP Regulated) |
| Resend, Inc. | Transactional email dispatch | United States |
| Semaphore (SMS Global Tech) | Philippine telecommunications SMS delivery | Philippines (NTC Regulated) |
4. Data Subject Rights, Export Guarantee & Retention Schedule
In accordance with RA 10173, individual players and venue staff retain the statutory rights to be informed, to access, to object, to erasure or blocking, and to damages. A request is recorded when it arrives, answered by the Data Protection Officer at dpo@aperto.ph, and the record names the copy, the anonymization or the closure that discharged it.
Unrestricted Venue Data Export: Venue Owners can export their full, unredacted operational data at any time via the Staff Portal in RFC 4180 CSV format. The copy is generated on request and its payload is downloadable for 24 hours; the copy generated when a client leaves stays downloadable for 30 days counted from the closure date. Aperto keeps the record that the request happened — who asked, when, and how many rows the copy held.
Retention Schedule. This is the schedule the platform runs on, so the promise and the behaviour cannot drift apart:
| Data | Kept for | At the end of the window |
|---|---|---|
| Client export payload (the generated CSV) | 24 hours after the export is generated, or 30 days after closure | Payload and download token cleared; the job row recording who asked and why is kept |
| Client export record (who asked, when, what it held) | Kept as an audit record | Kept — it is the record that the request happened |
| Support grant (operator access to a client's records) | Maximum 7 days, revoked or expired earlier | Stops authorizing on the next request; the grant row is kept as the audit trail |
| Player identity a branch holds (name, phone, marketing consent) | Until the player asks, the client asks, or the client closes | Anonymized in place; the profile row and every money and booking row stay linked |
| Player notes written by a branch | Removed when the player is anonymized | Deleted |
| Bookings, receipts, refunds, money accounts, audit events | Kept | Kept as financial and audit history |
| Outbox messages and their delivery attempts | Kept | Kept — they are the delivery evidence |
What erasure means here: A player's request, or the venue client's, anonymizes that branch's view of the player — display name, mobile number and marketing consent are cleared, and the branch's own notes about them are deleted — while the player's profile row and every booking, receipt, refund and audit row stay linked. Bookings, receipts, refunds, money accounts and audit events are kept: they are the record of what actually happened, and erasing them would erase the evidence a venue or a player needs to settle what is owed. A client account closes as a recorded state, never as a delete.