Our commitment to protecting personal data under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission.
Last updated: 28 August 2026
BOVA respects your privacy and is committed to protecting the personal data we collect and process.
We process personal data in accordance with Republic Act No. 10173, also known as the Data Privacy Act of 2012 (DPA), its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission (NPC).
We follow the principles of transparency, legitimate purpose, and proportionality. We collect and process only personal data that is reasonably necessary for identified and legitimate purposes, use it only in accordance with those purposes, and retain it only for as long as necessary or as required by law.
Depending on how you interact with BOVA, we may collect personal data such as:
We only collect information that is relevant and reasonably necessary for the purpose for which it is processed.
We may process personal data for purposes including:
We will not use personal data for purposes incompatible with the purpose for which it was collected unless permitted by law or otherwise properly disclosed and authorized.
We process personal data only when a lawful basis exists under applicable law.
Depending on the circumstances, processing may be based on:
Where consent is the applicable basis, you may withdraw your consent, subject to any legal or contractual consequences and to situations where another lawful basis permits continued processing.
Under the Data Privacy Act, you may have the following rights, subject to applicable legal conditions and limitations:
These rights are subject to the conditions, exceptions, and limitations provided under the DPA and other applicable laws and regulations.
We do not sell your personal data.
We may disclose or share personal data with authorized personnel, service providers, personal information processors, contractors, professional advisers, regulators, government authorities, or other third parties where reasonably necessary for legitimate and disclosed purposes, to provide our services, to comply with legal obligations, or as otherwise permitted by law.
Where we engage personal information processors, we require appropriate contractual and organizational safeguards for the protection and confidentiality of personal data.
Some service providers may process or store personal data outside the Philippines. Where this occurs, BOVA will take appropriate measures required under applicable data protection laws and regulations.
We implement reasonable and appropriate organizational, physical, and technical measures designed to protect personal data against unauthorized access, alteration, disclosure, loss, destruction, or other unlawful processing.
Access to personal data is limited to authorized personnel who have a legitimate business need to access it.
Where applicable, access credentials are managed through appropriate security controls, and access is removed or adjusted when personnel no longer require access because of a role change, account transition, or separation from BOVA.
No method of transmission, storage, or electronic security is completely risk-free. We continuously review and improve our safeguards as appropriate to the nature and risks of the personal data we process.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, to provide our services, to satisfy contractual or business requirements, to comply with applicable legal or regulatory obligations, or to establish, exercise, or defend legal claims.
When personal data is no longer required, we will securely delete, destroy, anonymize, or otherwise dispose of it in accordance with applicable requirements and our internal retention and disposal practices.
BOVA maintains procedures for responding to personal data breaches.
Where a personal data breach is subject to mandatory notification under applicable law, BOVA will notify the National Privacy Commission and affected data subjects within the period required by law, including the applicable 72-hour notification period, subject to the conditions and exceptions provided under the DPA and its implementing rules.
Where required, notifications will include relevant information about the nature of the breach, the personal data involved, measures taken to address the incident, and steps that affected individuals may take to reduce potential risks.
To exercise your rights, ask questions about how we process your personal data, or raise a privacy concern, contact us at:
Email: contact@bovaoffice.com
Please provide sufficient information for us to verify your identity and locate the relevant records. We may request additional information where reasonably necessary to protect personal data and prevent unauthorized disclosure.
We will handle privacy requests in accordance with applicable law and our internal procedures.
You may also have the right to lodge a complaint with the National Privacy Commission if you believe your personal data or privacy rights have been violated.
For more detailed information about the personal data we collect, the purposes and methods of processing, data recipients, retention practices, cookies or similar technologies, and other privacy practices, please see our full Privacy Policy.