Privacy Policy

Your data privacy is our priority

OneHRIS Privacy Policy

Last Updated: September 22, 2026

1. Introduction

OneHRIS ("we," "us," or "our"), a product of One PHP Technology, is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy outlines how we collect, use, disclose, and protect your data in compliance with the Philippine Data Privacy Act of 2012 (RA 10173) and National Privacy Commission (NPC) regulations.

2. Data We Collect

Personal Information:

  • Company name and contact details
  • Employee names, email addresses, phone numbers
  • Government-issued IDs (SSS, TIN, PhilHealth, Pag-IBIG)
  • Employment history and records (201 files)
  • Attendance and timekeeping data
  • Payroll and compensation information
  • Leave and benefits data

3. How We Use Your Data

We use your personal information to:

  • Provide HRIS and payroll services
  • Process payroll and generate statutory reports
  • Maintain compliance with Philippine labor laws
  • Generate government-required forms (BIR, SSS, PhilHealth, Pag-IBIG)
  • Improve our services and customer support

4. Data Storage and Security

We implement industry-standard security measures:

  • Data encryption in transit and at rest
  • Role-based access controls
  • Regular security audits and updates
  • Secure Azure cloud infrastructure
  • Multi-factor authentication for admin accounts

5. Data Sharing

We do not sell your personal information. We may share data only:

  • With government agencies as required by law (BIR, SSS, etc.)
  • With your explicit consent
  • With service providers bound by confidentiality agreements

6. Your Rights

Under the Data Privacy Act, you have the right to:

  • Access your personal data
  • Request corrections to inaccurate data
  • Request deletion of data (subject to legal retention requirements)
  • Object to processing in certain circumstances
  • Lodge complaints with the National Privacy Commission

7. NPC Compliance

OneHRIS is committed to full compliance with NPC regulations. We have appointed a Data Protection Officer (DPO) and maintain proper documentation of our data processing activities. One PHP Technology, Inc. is registered with the National Privacy Commission under NPC Registration No. PIC-013-587-2025.

National Privacy Commission Certificate of Registration for One PHP Technology, Inc., NPC Registration No. PIC-013-587-2025

NPC Certificate of Registration

National Privacy Commission DPO/DPS Registered seal for One PHP Technology, Inc.

NPC DPO/DPS Registration Seal

8. Data Privacy Agreement (Customer Data)

This section applies when your organization uses OneHRIS to process personal information about its employees and applicants ("Customer Data"). It forms part of your agreement with One PHP Technology together with the Terms of Service.

8.1 Roles. Under the Data Privacy Act of 2012 (RA 10173), your organization is the personal information controller for Customer Data. One PHP Technology acts as a personal information processor and processes Customer Data on your behalf.

8.2 Instructions and purpose. We process Customer Data only to provide the services described in the Terms of Service, and on your documented instructions given through your use of OneHRIS. You are responsible for having a lawful basis, giving the required notices and obtaining any required consent from your employees and applicants.

8.3 Confidentiality. Personnel who can access Customer Data are bound by confidentiality obligations.

8.4 Security measures. We apply organizational, physical and technical measures appropriate to the risk, including encryption in transit and at rest, encryption of sensitive fields, role-based access controls, multi-factor authentication for admin accounts and hosting on Microsoft Azure.

8.5 Service providers. Our current service providers (Sub-processors) are Microsoft Azure and Amazon Web Services (AWS), used for cloud hosting and, in AWS's case, email delivery; where a customer enables ARIA, queries may also be processed by Microsoft Azure OpenAI Service. They are bound by confidentiality and data protection obligations no less protective than this section.

8.6 Personal data breaches. If we become aware of a personal data breach affecting Customer Data, we will notify you without undue delay, and in any case within 72 hours, and help you meet your notification duties to the National Privacy Commission and affected individuals.

8.7 Requests from individuals. If an individual contacts us about Customer Data, we will refer them to you. We will reasonably help you respond to requests to exercise data subject rights.

8.8 Retention and deletion. Customer Data is kept for the retention period included with your plan and then deleted, as set out in Section 7 of the Terms of Service. Daily time records are deleted automatically. Payroll records are deleted after a download period. After cancellation, Customer Data may be deleted after 30 days.

8.9 Location and transfers. Customer Data is primarily hosted on Microsoft Azure infrastructure in the Southeast Asia region. Other service providers we use (including AWS, and Microsoft Azure OpenAI Service where ARIA is enabled) are not restricted to that region, so Customer Data may be transferred to, stored, or processed in other countries. We ensure any such transfer is subject to safeguards providing a comparable level of protection, relying on those providers' own contractual and compliance safeguards together with our own security measures described in Section 8.4. This does not apply to customers on a self-hosted / on-premises deployment, where we do not host, store, or transfer Customer Data at all.

8.10 Demonstrating compliance. On reasonable request we will provide information that shows we meet our obligations under this section, including our internal data protection and security policies, within a reasonable timeframe and subject to a confidentiality commitment from you regarding any information shared.

8.11 Our compliance. One PHP Technology is compliant with the requirements of the National Privacy Commission and has appointed a Data Protection Officer. We are registered with the National Privacy Commission under Registration No. PIC-013-587-2025.

9. Contact Us

For privacy-related inquiries or to exercise your data rights:

Data Protection Officer
One PHP Technology
Email: dpo@onephp.technology
Website: onephp.technology

National Privacy Commission
For complaints or inquiries: privacy.gov.ph