Privacy Notice (Pilot)
Vontos · under RA 10173 (Data Privacy Act of 2012)
- Two roles, honestly split. For learner records, your organization is the controller (it decides why and how data is processed); Vontos is the processor operating on its instructions — see your organization's own privacy notice for learner-data rights. For staff account data (username, hashed PIN, session records), Vontos is the operator.
- What the platform holds. Enrollment records, learning evidence and assessments, plans and reviews, attendance, learner-voice responses, consent records, staff accounts.
- How it's protected. PINs stored hashed, never plaintext · append-only evidence log (corrections visible, never silent) · per-record integrity hashes · role-gated access · TLS in transit · hosting: Supabase (database, Singapore) and Vercel (application, US edge) as disclosed sub-processors.
- What Vontos never does. No selling data, no advertising use, no processing beyond the organization's instructions, no fees to learners.
- Your rights. Access, correction, and erasure requests route through your organization's DPO; Vontos assists within the committed windows. Vontos contact: carlo@vontos.co.
- Breach duty. Vontos notifies affected organizations without undue delay so they can meet their 72-hour NPC notification duty under RA 10173.