PlansCompareFeaturesFAQSign in
Sign inPlan my setupPlan setupSetup

Tan-aw · Legal

Data Processing Addendum

The controller–processor terms governing Tan-aw's processing of personal data on the merchant's behalf.

Effective June 11, 2026Updated July 5, 2026Version 1.0

On this page

1Roles of the parties2Subject matter, duration, and scope3Controller obligations4Processor obligations5Data subjects and data categories6Sub-processors7Personal data breach8Return and deletion9Audit10Cross-border transfers11LiabilityADescription of processingBAuthorized sub-processorsCTechnical and organizational security measures
On this page tap to open
1Roles of the parties2Subject matter, duration, and scope3Controller obligations4Processor obligations5Data subjects and data categories6Sub-processors7Personal data breach8Return and deletion9Audit10Cross-border transfers11LiabilityADescription of processingBAuthorized sub-processorsCTechnical and organizational security measures

This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between Tan-aw Information Technology Services ("Tan-aw", "Processor") and the Merchant ("Controller", "you"). It governs Tan-aw's processing of personal data on the Controller's behalf under Republic Act No. 10173 (the Data Privacy Act of 2012, "DPA Act"), its IRR, and NPC issuances. Terms not defined here have the meaning given in the Terms of Service.

In case of conflict on personal data matters, this DPA prevails over the Terms.

1

Roles of the parties

  • For Customer Personal Data (data about the Merchant's customers and staff processed through the Service), the Merchant is the Personal Information Controller (PIC) and Tan-aw is the Personal Information Processor (PIP).
  • For Tan-aw's own operation of the platform (merchant account administration, billing, security, product improvement using de-identified data), Tan-aw is the controller and its Privacy Policy applies.
  • Each party is responsible for its own compliance with the DPA Act, including any required registration of its data processing system and appointment of a Data Protection Officer with the NPC.
2

Subject matter, duration, and scope

Tan-aw processes Customer Personal Data only to provide the Service for the duration of the Terms and as described in Annex A. Tan-aw processes such data only on the Controller's documented instructions (which include the Terms, this DPA, and the Controller's configured use of the Service), unless required otherwise by law — in which case Tan-aw will inform the Controller unless legally prohibited.

3

Controller obligations

The Controller:

  • determines the purposes and means of processing its Customer Personal Data;
  • warrants it has a lawful basis and has given any required privacy notice and obtained any required consent (including for push notifications, optional customer names, and the capture of fiscal and Senior Citizen/PWD data);
  • is responsible for the accuracy and lawfulness of the data and instructions it provides; and
  • will not instruct Tan-aw to process data unlawfully.
4

Processor obligations

Tan-aw will:

  1. process Customer Personal Data only on the Controller's documented instructions and only as needed to provide the Service;
  2. ensure persons authorized to process the data are bound by confidentiality;
  3. implement appropriate organizational, physical, and technical security measures (Annex C);
  4. engage sub-processors only under Section 6;
  5. assist the Controller, taking into account the nature of processing, in responding to data-subject requests (Annex A describes the data Tan-aw holds) and in meeting the Controller's security, breach-notification, and (where applicable) privacy-impact-assessment obligations;
  6. notify the Controller of a personal data breach without undue delay (Section 7);
  7. at the Controller's choice, delete or return Customer Personal Data at the end of the Service, subject to retention required by law (Section 8);
  8. make available information reasonably necessary to demonstrate compliance and allow for audits under Section 9; and
  9. inform the Controller immediately if, in Tan-aw's view, an instruction infringes the DPA Act, its IRR, or an NPC issuance.
5

Data subjects and data categories

The data subjects and categories of personal data are described in Annex A. They include anonymous customer identifiers and push tokens, optional customer names, order data, and — where the Controller chooses to capture it — fiscal/tax identifiers and Senior Citizen/PWD ID data, which are sensitive personal information requiring heightened protection.

6

Sub-processors

  • The Controller provides a general authorization for Tan-aw to engage the sub-processors listed in Annex B to provide the Service, including the transfer of personal data offshore to the locations stated there (notably Singapore for hosting and the United States for application performance monitoring).
  • Tan-aw will flow down to each sub-processor, by written agreement, obligations of confidentiality, security aligned to the NPC's requirements (NPC Circular 2023-06), personal data breach notification, audit / inspection, data-subject-rights assistance, and return or deletion of personal data — substantially the same as those in this DPA — and remains responsible for its sub-processors' performance.
  • Tan-aw will give the Controller advance notice of any intended addition or replacement of a sub-processor, and the Controller may object on reasonable data-protection grounds.
7

Personal data breach

Tan-aw will notify the Controller without undue delay, and in any event within forty-eight (48) hours of knowledge of, or reasonable belief that, a personal data breach affecting Customer Personal Data has occurred — so that the Controller can meet its own obligation under NPC Circular 16-03 to notify the NPC and affected data subjects within seventy-two (72) hours of knowledge. Tan-aw will provide the information the Controller reasonably needs for those notifications. The parties will cooperate in investigating and remediating the breach. As the PIC, the Controller is generally responsible for notifying the NPC and affected data subjects.

8

Return and deletion

On termination or expiry of the Service, Tan-aw will, at the Controller's election and within a reasonable period (after an export window), return and/or delete Customer Personal Data. Fiscal and statutory-discount records (receipts, invoices, source documents, Senior Citizen / PWD substantiation records, and TINs) must by law be preserved for the BIR-required period (currently five (5) years from the applicable filing deadline following NIRC Section 235 as amended by RA 11976 and RR 7-2024); the Controller remains the accountable taxpayer, and on termination these records are included in the Controller's export for its continued preservation. Tan-aw deletes its copies after the export window unless the Controller purchases archival or Tan-aw is required to retain them by law or a legal hold. While Tan-aw holds records within their mandatory retention period, the RA 10173 Section 16 erasure right does not attach to them. Retention windows are described in the Privacy Policy Section 8.

9

Audit

Tan-aw will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable prior notice, no more than once per year (unless required by an authority or following a breach), during business hours, subject to confidentiality and without compromising other merchants' data or platform security.

10

Cross-border transfers

Personal data is processed offshore by certain sub-processors (Annex B) — notably Microsoft Azure in Singapore (cloud hosting and infrastructure) and New Relic in the United States (application performance monitoring). The Philippines imposes no data-localization requirement, and neither provider operates a datacenter within the Philippines, so this offshore processing is necessary to deliver the Service; it is lawful provided appropriate cross-border safeguards are in place.

For these transfers the parties adopt the NPC's Model Contractual Clauses for Cross-Border Transfers of Personal Data (NPC Advisory No. 2024-01) — voluntary under NPC guidance, and incorporated here as contractual safeguards — which require confidentiality, sub-processor approval, audit rights, minimum security, and protection of data-subject rights. They are backed by each sub-processor's own data processing agreement carrying the 2021 EU Standard Contractual Clauses (Microsoft Products & Services DPA) and the EU-US Data Privacy Framework with 2021 SCCs as fallback (New Relic DPA). Tan-aw remains responsible for the transferred data and ensures it receives a level of protection comparable to RA 10173 (Section 21). The Controller authorizes these transfers to the extent necessary to provide the Service.

11

Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. Nothing in this DPA limits any liability that cannot be limited under the DPA Act.


A

Description of processing

Item Detail
Subject matter Provision of the Tan-aw ordering, notification, fiscal, and payment-recording Service.
Duration For the term of the Terms of Service (operational data retained per plan — Starter up to 31 days, Standard and above up to 5 years while subscribed). On exit, data is exported and then deleted per Section 8 (optional paid archival; legal holds excepted).
Nature & purpose Creating and tracking orders; delivering "order ready" notifications; recording receipts and statutory discounts; recording payment method/reference; account and security operations.
Categories of data subjects The Controller's customers (largely anonymous); the Controller's Authorized Users/staff; Senior Citizen / PWD beneficiaries named on receipts.
Categories of personal data App install identifier; push notification token + platform; order claim/link tokens; optional customer name; order contents and status; notification delivery logs; payment method, amount, and reference number; staff name, email, federated identity, role, audit logs, session/IP data.
Sensitive personal information Customer Taxpayer Identification Numbers (encrypted); Senior Citizen / PWD ID type and number (ID number encrypted at rest; never written to logs, snapshots, or exports in readable form).
Special note No card primary account numbers (PANs) are stored by Tan-aw; card/e-wallet details are processed by the payment gateway.
B

Authorized sub-processors

Sub-processor Role / service Personal-data categories Processing location Transfer mechanism / safeguards
Microsoft Corporation (Microsoft Azure) Cloud infrastructure & hosting (AKS), database, storage, key management; optionally Azure Monitor / Application Insights / Log Analytics (observability) Substantially all platform data — account/profile, order & transaction records, payment metadata (no PAN), operational records, application logs Azure Southeast Asia (Singapore) (no Azure region exists in the Philippines) Microsoft Products and Services DPA (incorporated into the Product Terms) with 2021 EU SCCs (+ UK IDTA); mapped to the NPC Model Contractual Clauses per Section 10
Microsoft Entra External ID Authentication / identity Staff and (future) verified-customer identity claims: email, name, federated identifiers, MFA assurance Microsoft global infrastructure Microsoft Products & Services DPA / 2021 EU SCCs; mapped to NPC MCCs
New Relic, Inc. Application performance monitoring, error tracking, infrastructure metrics, log management (telemetry only) Technical telemetry: IP addresses, device/session identifiers, account/user IDs embedded in traces, request metadata, error payloads, performance metrics — PII-minimized at source United States (EU region selectable) New Relic DPA (incorporated into its Terms of Service); EU-US Data Privacy Framework certified, with 2021 SCCs as fallback; mapped to NPC MCCs
Google Firebase Cloud Messaging (FCM) Push notification delivery (Android + cross-platform) Device push token, platform, message metadata Google global infrastructure Firebase Data Processing and Security Terms (incorporated into the Firebase ToS) with EU SCCs; mapped to NPC MCCs
Apple Push Notification service (APNs) iOS push notification delivery Device push token, message metadata Apple global infrastructure Apple Developer Program License Agreement (Section 3.3.7(C) / Attachment 1); no personal data is included in push payloads

Tan-aw's subscription-billing payment gateway is not listed above because it does not process Customer Personal Data: Customers never pay through the Service, and the gateway handles only the Merchant's own payment method for Tan-aw subscription fees — a relationship in which Tan-aw acts as controller, disclosed in the Privacy Policy (Section 7) and governed by the gateway's own data-sharing terms.

C

Technical and organizational security measures

  • Encryption in transit — TLS for all API and web traffic.
  • Encryption at rest of sensitive identifiers — field-level encryption (symmetric AES via Fernet) for Taxpayer Identification Numbers and Senior Citizen/PWD ID numbers; these are never emitted to logs, snapshots, or backups in readable form. Encryption keys are managed so the data remains producible for a BIR audit within the retention window. (Applied as the "appropriate" technical measure under RA 10173 Section 20 / IRR Rule VI Section 28(g) and NPC Circular 2023-06, not as an absolute statutory mandate.)
  • Authentication — federated identity via Microsoft Entra External ID with multi-factor authentication for high-trust roles; strong password hashing for local credentials; short-lived sessions with refresh-token rotation.
  • Access control & tenant isolation — strict per-organization data isolation with object-level authorization on every route, so one merchant cannot access another's data; least-privilege, role-based access for staff.
  • Auditing — organization audit logs of sensitive actions.
  • Maintenance & retention — routine pruning of stale device tokens and notification logs, and tiered retention/erasure of order data.

Related documents

Terms of ServiceThe agreement between Tan-aw and the businesses that subscribe to and use the platform.Read →Privacy PolicyHow Tan-aw collects, uses, shares, and protects personal data across the platform and ReadyNa.Read →Refund PolicyHow Tan-aw refunds the subscription fees merchants pay for the platform.Read →

Questions about this document?

Reach the Tan-aw team — we usually reply within two business days.

[email protected]

© 2026 Tan-aw Information Technology Services · DTI Business Name Reg. No. 8229411 · Selenia 208, Mirea Residences, Amang Rodriguez Avenue, Santolan, Pasig City

The platform that powers seamless order management.

Terms & ConditionsPrivacy PolicyRefund Policy

© 2026 Tan-aw Information Technology Services · Santolan, Pasig City · +63 917 114 4927 · [email protected]. All rights reserved.