Privacy Notice (Pilot)

Vontos · under RA 10173 (Data Privacy Act of 2012)

  1. Two roles, honestly split. For learner records, your organization is the controller (it decides why and how data is processed); Vontos is the processor operating on its instructions — see your organization's own privacy notice for learner-data rights. For staff account data (username, hashed PIN, session records), Vontos is the operator.
  2. What the platform holds. Enrollment records, learning evidence and assessments, plans and reviews, attendance, learner-voice responses, consent records, staff accounts.
  3. How it's protected. PINs stored hashed, never plaintext · append-only evidence log (corrections visible, never silent) · per-record integrity hashes · role-gated access · TLS in transit · hosting: Supabase (database, Singapore) and Vercel (application, US edge) as disclosed sub-processors.
  4. What Vontos never does. No selling data, no advertising use, no processing beyond the organization's instructions, no fees to learners.
  5. Your rights. Access, correction, and erasure requests route through your organization's DPO; Vontos assists within the committed windows. Vontos contact: carlo@vontos.co.
  6. Breach duty. Vontos notifies affected organizations without undue delay so they can meet their 72-hour NPC notification duty under RA 10173.
← Back to sign-up