Cadastra data practices
Privacy Policy
This Policy describes how Cadastra collects, uses, discloses, retains, and protects personal data in connection with Cadastra.
If your organization provides your account or uploads personal data, it may control that processing. Direct organization-specific privacy requests to your organization first.
01Scope and Roles
This Policy applies to the Cadastra website, accounts, applications, support, and related services. Depending on the context, we may act as a personal information controller for account, billing, security, and service-management data, and as a personal information processor when an organization directs us to process personal data in its Project Data.
02Data We Collect
- Account and workspace data: email address, name, profile photo, organization, role, authentication identifiers, and account preferences.
- Professional profile data: information you choose to provide for project documents, such as PRC, PTR, TIN, community tax certificate details, validity dates, signature image, and accreditation information.
- Project Data: survey observations, coordinates, parcel and landowner information, technical descriptions, plans, drawings, reports, uploaded files, annotations, and project metadata.
- Technical and activity data: device and browser information, IP address, session and cookie data, request and error logs, security events, and audit records of actions in the Service.
- Communications and transaction data: support messages, feedback, plan, billing, invoice, and payment-status information. Payment card details may be collected directly by a payment processor rather than Cadastra.
- Connected-account data: if you sign in with Google or another enabled provider, the provider supplies authentication identifiers and profile information covered by the permission screen.
03Why We Process Data
We process data to create and secure accounts; provide workspaces, drafting, computation, reports, storage, and support; authenticate users; administer plans and payments; maintain audit trails; prevent fraud and abuse; diagnose and improve performance; communicate service and legal notices; comply with law; and establish or defend legal claims.
Our lawful bases may include performance of a contract, compliance with legal obligations, legitimate interests in operating and securing the Service, and consent where required. An organization that uploads Project Data is responsible for identifying its lawful basis and providing required notices.
04How We Share Data
We may share data with authorized members and administrators of your workspace; infrastructure, authentication, communications, analytics, support, and payment providers acting under appropriate obligations; professional advisers; a successor in a merger or business transfer; and government authorities or other parties when required by law or necessary to protect rights, safety, and security.
We do not sell Project Data. We do not disclose it for third-party advertising.
05International Processing
Service providers may process data outside the Philippines. Where personal data is transferred, we use contractual or other reasonable safeguards intended to provide a comparable level of protection, subject to applicable law.
06Retention
We retain personal data for as long as needed to provide the Service, fulfill the purposes described here, comply with legal and accounting duties, resolve disputes, and enforce agreements. Retention varies by data type and workspace instructions. Backups and logs may remain for a limited period after deletion. We may retain de-identified data that no longer identifies a person.
07Security
We use reasonable organizational, physical, and technical safeguards designed to preserve confidentiality, integrity, and availability. No method of storage or transmission is completely secure. Users must protect credentials, control workspace access, keep independent project backups, and notify us of suspected compromise.
08Your Choices and Rights
Subject to the Data Privacy Act of 2012 and other applicable law, you may have rights to be informed, object, access, correct, erase or block personal data, withdraw consent, obtain data portability where applicable, lodge a complaint with the National Privacy Commission, and seek damages for qualifying violations.
Requests may be subject to identity verification, legal exceptions, and the rights of others. For Project Data controlled by your organization, we may refer the request to that organization.
09Cookies and Authentication
The Service uses cookies or similar local technologies needed for authentication, security, preferences, and core operation. Blocking essential cookies may prevent sign-in or other features from working. Any non-essential analytics or marketing technology will be described or offered with choices where required.
10Children
The Service is intended for professionals and organizations and is not directed to children. Do not submit a child’s personal data unless you have a lawful professional need, authority to do so, and appropriate safeguards.
11Changes and Contact
We may update this Policy. The effective date and version at the top identify the current version, and we will notify users of material changes when required.
To exercise privacy rights or ask a question, contact:
Cadastra Use the support contact provided in the Service.