Master Privacy Policy and Data Processing Agreement

Document ID: OTI-POL-2026-V4.1
Effective Date: May 26, 2026
Entity: Optima Tech Innovations Limited (Hong Kong SAR)

1. Executive Summary & Legal Framework

Optima Tech Innovations Limited ("Optima," "we," "our," "us," or the "Company") strictly operates as a Enterprise Platform-as-a-Service (PaaS) and Digital Connection Bridge. We provide secure API routing infrastructure connecting end-users with independent, SEC-licensed financial institutions in the Republic of the Philippines.

CRITICAL NOTICE: WE ARE NOT A LENDER, FINANCING COMPANY, OR CREDIT REPORTING AGENCY. WE DO NOT ISSUE LOANS OR MAKE CREDIT DECISIONS.

This Master Privacy Policy governs the collection, encryption, transit, and destruction of your personal data in strict compliance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) ("DPA"), its Implementing Rules and Regulations (IRR), and applicable data protection frameworks in the Hong Kong Special Administrative Region.

2. Definitions and Roles

3. Exhaustive Scope of Information Processed

To facilitate the digital routing protocol, we process data through the principle of absolute data minimization. We collect only the following data payloads:

A. Voluntarily Submitted Identity & Financial Data

  • Full legal name, residential address, date of birth, and nationality.
  • Contact infrastructure: Mobile telecommunications number and verified email address.
  • Employment matrices: Employer name, occupational category, tenure, and stated income brackets.
  • Routing parameters: Desired financial product specifications, requested amounts, and preferred terms.

B. Automated Technical & Telemetry Data

  • Internet Protocol (IP) addresses, Media Access Control (MAC) addresses, and geolocation data (city-level strictly for anti-fraud mapping).
  • Device fingerprints, including OS version, browser type, UUID, and hardware model.
  • API request timestamps, payload size, and cryptographic handshake records.
STRICT EXCLUSIONS (WHAT WE NEVER COLLECT): Under no circumstances does Optima Tech Innovations Limited request, scrape, bypass permissions to acquire, or store your Contact Lists (Phonebook), SMS/MMS Messages, Call Logs, Personal Photo Galleries, or Biometric identifiers. Any representation to the contrary is false.

4. Legal Basis and Purpose of Processing

Pursuant to Section 12 of the DPA, we process your data based on your explicit, freely given consent and the necessity of processing to fulfill a pre-contractual step requested by you. Purposes include:

5. Data Sharing, Sub-Processors, and Third-Party Transfer

We are a conduit. By initiating a submission, you authorize the cross-border and domestic transfer of your data to:

Commercial Prohibition: Optima Tech Innovations Limited categorically does not engage in the sale, leasing, brokering, or unauthorized commercialization of your personal data to marketing agencies or unauthorized third parties.

6. Cryptographic Security & Data Protection Standards

We deploy enterprise-grade cryptographic protocols to secure your data pipeline:

7. Incident Response and Data Breach Notification

In the highly unlikely event of a security breach compromising the confidentiality of your personal data, Optima Tech Innovations Limited has established a rapid Incident Response Plan (IRP). In accordance with NPC Circular 16-03, if a breach poses a real risk of serious harm, we will:

  1. Notify the National Privacy Commission within seventy-two (72) hours of discovering the breach.
  2. Notify affected Data Subjects via email or platform notification, detailing the nature of the breach, the specific data compromised, and mitigation measures recommended.
  3. Deploy forensic containment protocols to isolate the compromised network segment.

8. Data Retention and Cryptographic Wiping

We operate predominantly on a stateless routing paradigm. Personal Identity Information (PII) is retained in our secure caches only for the duration necessary to achieve a successful API handshake with the third-party institution (typically milliseconds to a maximum of 72 hours in case of network retries). Once successful transmission is confirmed, PII is subjected to cryptographic wiping. De-identified, aggregated technical telemetry (e.g., API success rates) may be retained for up to five (5) years for diagnostic and SLA auditing purposes.

9. Data Subject Rights (DSR) & Deletion Protocols

Pursuant to the Philippine DPA, you are entitled to comprehensive rights regarding your personal data. We provide dedicated channels to exercise these rights:

MANDATORY DATA DELETION / ERASURE REQUESTS

You possess the absolute right to demand the immediate suspension, withdrawal, or permanent cryptographic erasure of your personal data from Optima's routing servers and databases. To exercise this right:

Submit a formal written request to our Data Protection Officer:

SLA for Deletion: We will acknowledge your request within 48 hours and execute the permanent erasure protocol across our primary and backup nodes within 15 to 30 calendar days, providing a Certificate of Deletion upon completion. Note: Deleting data from our bridge does not delete data already successfully transmitted to the Third-Party Financial Institution; you must contact them separately.

10. Cookies, Web Beacons, and Tracking Technologies

Our web interfaces utilize strictly necessary session cookies to maintain state during your application routing process. We do not deploy persistent tracking cookies, third-party advertising pixels, or cross-site tracking beacons. You may configure your browser to reject cookies, though this will result in the immediate failure of the application routing process due to security token invalidation.

11. Automated Decision-Making and Profiling

Optima Tech Innovations Limited does not engage in automated credit scoring, algorithmic underwriting, or behavioral profiling. Any approval, denial, or credit limit assignment is executed entirely by the proprietary algorithms of the independent Third-Party Licensed Financial Institution.

12. Contact the Data Protection Officer (DPO)

Our appointed Data Protection Officer is responsible for overseeing compliance with this policy and the DPA. All legal, compliance, or privacy inquiries must be directed to:

Office of the Data Protection Officer
Optima Tech Innovations Limited
[Insert Specific HK Registered Address, e.g., Suite 1502, Central Plaza, Wan Chai]
Hong Kong SAR
Email: dpo@optimatechinnovations.com