Privacy Notice
Privacy Notice
Delta Earthmoving, Inc. ("Delta", "we", "us") respects your privacy and is committed to protecting the personal and business information entrusted to us. We adhere to the principles of transparency, legitimate purpose and proportionality in processing data, as required by the National Privacy Commission (NPC).
This Privacy Notice explains what information we collect through this system (Atrium), why we collect it, how we use, share, protect, keep and dispose of it, and how you can exercise your rights — including how to access your data, how to request its removal, and how to recover it before removal becomes final. It applies to all data we collect, use, process, store and dispose of — sensitive or not — for every person and organization we deal with: job applicants, employees, system users, helpdesk requesters, clients, suppliers and business contacts.
Governing laws and standards
We process data in accordance with the laws of the Republic of the Philippines, including:
- Republic Act No. 10173 — Data Privacy Act of 2012 (DPA) and its Implementing Rules and Regulations, together with NPC circulars and advisories (including breach-management and data-sharing rules);
- Republic Act No. 10175 — Cybercrime Prevention Act of 2012 (including its data-preservation requirements);
- Republic Act No. 8792 — Electronic Commerce Act of 2000 (validity of electronic documents and records);
- The Labor Code of the Philippines (P.D. 442, as amended) and Department of Labor and Employment record-keeping rules;
- The National Internal Revenue Code §235 and BIR Revenue Regulations No. 17-2013 (ten-year preservation of books and records);
- R.A. 11199 (Social Security Act), R.A. 11223 (Universal Health Care Act) and R.A. 9679 (Pag-IBIG Fund Law) record obligations for employment data.
Where this notice states a practice, the practice is enforced by the system itself wherever automation is possible; the current enforced retention periods are published in the Retention Schedule at the bottom of this page.
What we collect
Submission of information is voluntary; however, declining to provide requested information may prevent us from processing your application, request or transaction.
- Job applicants (careers portal, walk-in and paper intake): name, address, contact details, date and place of birth, sex, civil status, citizenship, education, employment history, trainings, skills, character references, family and emergency-contact details, statutory identifiers (SSS, TIN, PhilHealth, Pag-IBIG), résumé and photo, and — where provided — sensitive personal information as defined by DPA §3(l), such as religion and health-assessment results. Uploaded documents processed for form auto-fill are parsed entirely on our own servers and the transient copies are deleted on the short clocks shown in the Retention Schedule.
- Employees: the applicant data carried into the 201 file on hiring, plus employment lifecycle records (position, movements, trainings, separation details).
- System users (staff accounts): name, work email, avatar, preferences, and a sign-in audit trail (email, device user-agent, sign-in errors).
- Helpdesk requesters: name, email, project assignment, department, IP address and the contact information you supply with a ticket.
- Clients and care enquirers: contact details and the details of your enquiry or service agreement.
- Suppliers and business contacts: representative names, contact details and transaction records.
Why we use it
Each category is used only for the purpose it was collected for: facilitating recruitment and selection; administering employment; operating IT support and helpdesk services; managing client enquiries, agreements and services; procurement and supplier management; and meeting our legal and regulatory obligations. We do not sell personal data, and we do not use it for automated decision-making or profiling.
How we keep and protect it
We implement organizational, physical and technical security measures that we regularly maintain, including: each client organization's data is held in a physically separate database and file store (no shared tables between organizations); encrypted connections (HTTPS); role-based access control on every module; document text-extraction performed locally on our servers (no cloud OCR or external AI service receives your documents); error-monitoring that is scrubbed of personal data before leaving the system; validated and size-limited file uploads; audit logging of administrative actions; and encrypted nightly backups stored on servers we control.
Who has access
Access is role-based and limited to the teams that need it: application data is accessed by the Human Resources team and Management; helpdesk tickets by the Communication and Information Technology (CIT) team; client and supplier records by the responsible operating teams. Administrative access is logged and auditable.
Data sharing and disclosure
We do not sell or rent your data. It leaves our systems only in these cases:
- Email delivery — notification and verification emails necessarily carry the recipient address and the notification content to our mail provider.
- Google reCAPTCHA — the staff sign-up page sends a spam-protection token and your IP address to Google as part of the reCAPTCHA protocol; no application data is included.
- Browser push notifications — if you enable them, notification titles pass through your browser vendor's push service; we do not place personal data in push payloads.
- Backups — encrypted copies of the databases are transferred nightly between servers controlled by us.
- Lawful requests — we disclose information to authorities when validly required (for example under a warrant or order contemplated by R.A. 10175).
Some of these recipients (such as Google and browser push services) process data outside the Philippines. Where a cross-border transfer occurs, it is limited to the minimum described above and is covered by the recipient's contractual and legal safeguards. Any future sharing of personal data with a third party for its own purposes will be covered by a Data Sharing Agreement as required by NPC rules; we will update this notice before any such sharing begins.
How long we keep it
We keep data only as long as necessary for the purpose it was collected for, or as long as the law requires. The Retention Schedule at the bottom of this page shows the current, system-enforced periods — those values are live configuration, not copies, so what you read is what the system does. Employee records are retained after separation for the statutorily required period (tax, labor and social-legislation record rules cited above). Unsuccessful application data is retained for the pooling window shown in the schedule, then anonymized automatically.
Backups: when data is deleted or anonymized, copies may persist in rotated backups for the backup window shown in the schedule. After that window, the erased data is gone from backups as well — this is the "true erasure" horizon we commit to.
Your rights
Under the Data Privacy Act of 2012, you are accorded these eight (8) rights:
- The right to Information. You have the right to be informed that your personal data will be, are being, or were, collected and processed.
- The right to Object. You have the right to object to the processing of your personal data for purposes other than the intention which they were collected for.
- The right to Access. You have the right to obtain a copy of your personal data, stored in the database or in manual filing system, held by Delta upon demand.
- The right to Correct. You have the right to dispute and rectify any inaccuracy or error in your personal data.
- The right to Erase. You have the right to erasure or blocking when your personal data is no longer necessary for the purposes for which it was collected, or when it was obtained without your consent.
- The right to Damages. You have the right to be indemnified for any damages sustained.
- The right to Data Portability. You have the right to obtain a copy of your personal data in a structured, commonly used and machine readable format.
- The right to File a Complaint. You have the right to file a complaint with the National Privacy Commission if you feel that any of your data privacy rights have been violated.
How to exercise them:
- Access and correction — applicants can view and edit their own information at any time in the applicant portal; staff users can view their own profile in the system. For a complete copy of your data, or for categories without a self-service view, contact our Data Protection Officer (below).
- Removal (erasure) — applicants can request deletion of their data directly in the applicant portal (Privacy & data page). All other requests — employees, users, clients, suppliers, or applicants whose situation blocks self-service — go to the Data Protection Officer, who follows a documented erasure procedure.
- Recovery — a portal deletion request does not execute immediately: it enters a grace period (shown in the Retention Schedule) during which you can cancel the request and keep your data. After the grace period ends the data is anonymized and cannot be recovered, except that backup copies persist until the backup window lapses as described above.
What deletion means here
When we erase on request, we anonymize: your identity — names, addresses, contact details, identifiers, documents and photographs — is permanently removed or destroyed. De-identified statistical records (for example, that an application for a given position reached a given stage in a given month, or de-identified examination scores) are retained for reporting and are no longer attributable to you in the ordinary course; we disclose this retention here as required by the transparency principle. Records we must keep under a separate legal basis — for example statutory employment records, or records retained under legitimate interest such as fraud- and misconduct-prevention lists — are unaffected by an erasure request; where this applies, the Data Protection Officer will explain the basis on request.
If you have been hired, your applicant data becomes part of your employment records and follows the statutory employee retention rules; portal self-service deletion no longer applies, and requests go through the Data Protection Officer. If you have an application currently in progress, we will ask you to withdraw it (or wait for it to conclude) before the erasure proceeds.
Corporate and business data
Atrium also holds business records of client organizations, suppliers and counterparties — contracts, service agreements, enquiries, procurement and transaction records. We protect these with the same security measures described above, treat them as confidential, retain them for the periods required by statutory, tax and commercial obligations, and dispose of them securely. When a client organization's relationship with us ends, its data (a physically separate database and file store) is decommissioned under a documented procedure, including the lapse of its backups.
Cookies
This system uses only the cookies it needs to operate: a session cookie (keeps you signed in), a security (CSRF) cookie (protects forms against forgery), and preference cookies (such as language or theme). We do not use third-party analytics or advertising cookies. You can disable cookies in your browser, but signing in requires the session and security cookies.
Breach notification
If a data breach occurs that is likely to give rise to a real risk of serious harm, we will notify the National Privacy Commission and the affected data subjects within seventy-two (72) hours of knowledge of the breach, in accordance with NPC breach-management rules.
Changes and updates
We may amend this Privacy Notice from time to time; the current version is always the one posted on this page, and material changes take effect upon posting. This Privacy Notice is effective on Feb. 28, 2018 and was last updated on July 19, 2026.
Who will you contact?
If you have inquiries, concerns or complaints regarding how Delta uses your data, or to exercise any of your rights, please contact our Data Protection Officer:
- CHQ Address: 14/F CyberOne Bldg. Eastwood Ave., Eastwood City, Brgy. Bagumbayan, Quezon City, Philippines
- E-mail: dpo@deltaearthmoving.com
- Tel. No.: (632) 8687-1000
- Mobile No.: +63915-671-1431
You may also lodge a complaint with the National Privacy Commission (privacy.gov.ph).
Retention Schedule
The periods below are the values currently enforced by the system. When a period ends, the personal data in that category is deleted or anonymized automatically unless a legal obligation requires longer keeping.
| Data category | Kept for | Basis |
|---|---|---|
| Unsuccessful job applications (pooling window) | 365 day(s) | Published notice promise (1 year pooling); DPA storage limitation. |
| Uploaded résumé auto-fill source files | 24 hour(s) | Data minimization (RA 10173 §11). |
| Statutory-ID images used for auto-fill | 1 hour(s) | Sensitive personal information (RA 10173 §3(l)). |
| Auto-fill extracted text (accuracy review window) | 365 day(s) | OCR-accuracy window (CF3). |
| Scanned paper application form images | 24 hour(s) | Data minimization (RA 10173 §11). |
| Scanned form extracted text (accuracy review window) | 365 day(s) | OCR-accuracy window (CF3). |
| Helpdesk ticket contact information (after ticket close) | 730 day(s) | Published notice promise (2 years). |
| Care enquiry personal details (after close/convert) | 730 day(s) | DPA storage limitation; published practice. |
| Sign-in audit trail | 365 day(s) | RA 10175 six-month traffic-data preservation floor. |
| Employee records after separation (policy-managed) | 10 year(s) | NIRC §235 / BIR RR 17-2013 ten-year preservation; DOLE/SSS/PhilHealth/Pag-IBIG record rules. |
| Deletion-request grace period (cancellable recovery window) | 15 day(s) | Erasure without undue delay (RA 10173 §16(e)) with a bounded recovery window. |
| Encrypted backup rotation (true-erasure horizon) (policy-managed) | 30 day(s) | Disclosed erasure horizon; backups are company-controlled. |
| Audit event log | 90 day(s) | Operational audit trail. |
| System/error log | 28 day(s) | Operational diagnostics. |