Data Processing Agreement
How OneHRIS processes personal data on your behalf
Last Updated: September 24, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between One PHP Technology, Inc. ("OneHRIS," "we," "us," or "our"), NPC Registration No. PIC-013-587-2025, and the client company using the OneHRIS platform ("Client," "you," or "Controller"), and supplements the OneHRIS Terms of Service. It governs the processing of personal data that Client submits to or generates within the OneHRIS platform in the course of using our HRIS and payroll services.
1. Definitions
For purposes of this DPA, terms have the meanings given to them under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations ("DPA Law"), including:
- "Personal Data" means any information relating to an identified or identifiable individual, including Sensitive Personal Information as defined under the DPA Law (e.g., government-issued ID numbers, health information relevant to leave/benefits administration).
- "Processing" means any operation performed on Personal Data, including collection, recording, organization, storage, updating, retrieval, use, dissemination, or destruction.
- "Personal Information Controller" ("Controller") means the party who decides what Personal Data is processed and why — in this relationship, the Client.
- "Personal Information Processor" ("Processor") means the party who processes Personal Data on behalf of and under the instructions of a Controller — in this relationship, OneHRIS.
- "Data Subject" means the individual whose Personal Data is processed — principally Client's employees, job applicants, and dependents as applicable.
- "Sub-processor" means any third party engaged by OneHRIS to process Personal Data on OneHRIS's behalf in providing the service to Client.
2. Roles of the Parties
Client is the Personal Information Controller for all Personal Data it submits to or generates within the OneHRIS platform (employee records, payroll data, attendance data, applicant data, and similar). OneHRIS acts as a Personal Information Processor, processing that data solely to provide the contracted HRIS/payroll services and solely on Client's documented instructions, except where OneHRIS is required to process data by Philippine law (e.g., generating statutory government reports).
3. Scope and Purpose of Processing
OneHRIS processes Personal Data only as necessary to:
- Provide the HRIS, payroll, attendance, leave, and (where enabled) recruitment/ATS modules Client has subscribed to.
- Generate statutory government reports and remittance files (BIR, SSS, PhilHealth, Pag-IBIG) on Client's behalf.
- Provide customer support in connection with the above.
- Maintain the security, availability, and integrity of the platform.
OneHRIS does not use Client's Personal Data for its own marketing purposes, does not sell it, and does not process it for any purpose outside this scope without Client's separate written instruction.
4. Processor Obligations
OneHRIS will:
- Process Personal Data only on Client's documented instructions (which include the instructions inherent in Client's configuration and use of the platform).
- Ensure personnel authorized to process Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures proportionate to the risk (see Section 6).
- Assist Client, to the extent reasonably possible given the nature of the processing, in responding to Data Subject rights requests and in meeting Client's own obligations under the DPA Law (see Section 8).
- Notify Client of a Personal Data Breach without undue delay (see Section 7).
- Not engage a new Sub-processor without giving Client the opportunity to object (see Section 5).
- Delete or return Personal Data at the end of the service relationship, per Client's instruction and subject to Section 9 (Retention).
5. Sub-processors
OneHRIS's current Sub-processors are Microsoft Azure and Amazon Web Services (AWS), used for cloud infrastructure hosting and, in AWS's case, transactional email delivery. As stated in Section 4, OneHRIS will give Client the opportunity to object before engaging a new Sub-processor. Any Sub-processor is bound by data protection obligations no less protective than those in this DPA.
6. Security Measures
OneHRIS maintains security measures consistent with those described in our Privacy Policy, including encryption of data in transit and at rest, role-based access controls, regular security review, and multi-factor authentication for administrative accounts.
7. Personal Data Breach Notification
OneHRIS will notify Client without undue delay, and in any case within 72 hours of becoming aware of a Personal Data Breach affecting Client's data, providing the information reasonably available at the time and reasonably requested by Client to meet Client's own notification obligations to the National Privacy Commission and affected Data Subjects under the DPA Law.
8. Assistance with Data Subject Rights
Where a Data Subject exercises a right under the DPA Law (access, correction, erasure, objection, or complaint) directly with OneHRIS regarding data Client controls, OneHRIS will promptly redirect the request to Client and provide reasonable assistance to help Client respond, given the nature of the processing and information available to OneHRIS.
9. Data Retention and Deletion
Personal Data is retained in the OneHRIS platform for the duration of the service relationship, subject to the historical data retention period included in Client's subscription tier: 1 year (Essential/Free tier), 2 years (Pro tier), or 3 years (Enterprise tier), unless a longer period is required by Philippine law (including statutory retention periods for payroll and employment records under BIR, SSS, PhilHealth, and Pag-IBIG regulations, which may exceed the platform retention period) or otherwise agreed with Client. Upon termination of the service relationship, OneHRIS will delete or return Client's Personal Data in accordance with this same retention schedule, except where continued retention is required by law.
10. Audit Rights
OneHRIS agrees to reasonably cooperate with Client's audit requests to demonstrate compliance with this DPA, including making available relevant documentation — such as OneHRIS's internal data protection and security policies — upon Client's written request. OneHRIS will respond within a reasonable timeframe and may require reasonable advance notice and a confidentiality commitment from Client regarding any information shared.
11. International Data Transfers
OneHRIS's cloud-hosted service is provided using Microsoft Azure and Amazon Web Services (AWS) infrastructure, which is not restricted to data centers within the Asia-Pacific region. As a result, Personal Data may be transferred to, stored, or processed in countries outside the Philippines. OneHRIS will ensure any such transfer is subject to safeguards providing a level of protection for Personal Data comparable to that required under the DPA Law, relying on: Microsoft Azure's and AWS's own contractual and compliance safeguards for their respective infrastructure, together with OneHRIS's own internal security and data protection measures described in Section 6.
This section does not apply to Client deployments using OneHRIS's self-hosted / on-premises option (where offered under a dedicated-infrastructure agreement). In that arrangement, OneHRIS does not host, store, or transfer Client's Personal Data — all data resides and is processed entirely within Client's own infrastructure, and Client is solely responsible for that infrastructure's data residency, security, and any applicable international transfer obligations.
12. Liability
Each party's liability arising out of or in connection with this DPA is subject to the Limitation of Liability set out in Section 8 of the OneHRIS Terms of Service (excluding indirect, incidental, special, or consequential damages; total liability capped at the amount paid by Client in the preceding 12 months).
Notwithstanding that cap, nothing in this DPA limits or excludes either party's liability for: (a) a breach of the confidentiality or data protection obligations set out in this DPA; or (b) fraud or willful misconduct. Each party remains solely responsible for any administrative fine or penalty imposed directly on it by the National Privacy Commission for its own violation of the DPA Law; such fines are not subject to indemnification by the other party.
Each party will indemnify the other against third-party claims, damages, fines, or penalties arising from the indemnifying party's own breach of this DPA or violation of the DPA Law.
13. Term
This DPA remains in effect for as long as OneHRIS processes Personal Data on Client's behalf under the OneHRIS Terms of Service, and survives termination of that agreement to the extent needed to give effect to Sections 7 (Breach Notification), 9 (Retention and Deletion), and any surviving confidentiality obligations.
14. Contact
Questions about this DPA can be directed to:
Data Protection Officer
One PHP Technology, Inc.
Email: dpo@onephp.technology
Website: onephp.technology
See also: Privacy Policy | Terms of Service