Tigernethost, OPC(“Tigernethost,” “we,” “us,” or “our”) is committed to protecting your personal data. This Policy describes how we collect, use, share, and safeguard the information we process about you when you visit tigernethost.com, use our client portal, purchase or use our services, or otherwise interact with us.
We process personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission (NPC). By using our services you agree to this Policy.
Who we are
Tigernethost, OPC is a One Person Corporation duly organized under Philippine law with principal address at Tigernethost Building, OG Road, San Antonio 2003, Guagua, Pampanga.
For the purposes of this Policy, we are the Personal Information Controller (PIC) for the data we collect directly from you and a Personal Information Processor (PIP) for data we host or otherwise process on behalf of our clients.
Personal data we collect
Depending on how you interact with us, we may collect:
- Identity & contact data — full name, email address, phone number, organization, mailing address, tax identification number (TIN), and any government-issued ID where required to verify identity.
- Account credentials — usernames, hashed passwords, API keys, SSH public keys, and two-factor authentication settings.
- Billing & payment data — invoice history, PHP or USD payment records, and payment card tokens issued by our payment processors. Full card numbers are never stored on our systems.
- Service usage & technical data — server logs, uptime metrics, resource usage, IP addresses, browser and device information, and cookies necessary to operate the portal.
- Communications — support tickets, chats, calls, emails, and any content you send us.
- Third-party sign-in data — where you choose to sign in with Google or Meta, the profile information those providers return (name, email, profile picture).
We do not knowingly collect data about children under 18. Our services are intended for use by legally competent persons and organizations.
How we collect your data
- Directly from you when you register, order, or contact us.
- Automatically from your device (cookies, log files, analytics) when you visit our sites.
- From third parties you have authorized (Google OAuth, Meta, domain registries, and our payment processor).
- From publicly available sources for identity verification and fraud prevention where lawful.
Why we process your data
We use your personal data for the following purposes:
- Service delivery — provisioning, operating, and maintaining the hosting, domain, cloud, and consulting services you have purchased.
- Account and billing — verifying your identity, processing payments, issuing invoices and official receipts, and complying with tax and accounting laws.
- Support & communications — responding to your inquiries and sending service, security, and transactional notices.
- Security & abuse prevention — detecting, preventing, and investigating fraud, spam, network attacks, and violations of our Terms of Service and Acceptable Use Policy.
- Product improvement & analytics — measuring performance and improving reliability and features.
- Legal compliance — complying with laws, subpoenas, and lawful orders of Philippine and other competent authorities.
- Marketing — where you have consented, sending newsletters and offers. You may withdraw consent at any time.
Legal bases
We rely on the following legal bases under Section 12 and 13 of the Data Privacy Act:
- Contract — processing necessary to fulfill our agreement with you.
- Legal obligation — processing required by law, including tax, anti-money-laundering, and law-enforcement cooperation.
- Legitimate interests — protecting our systems, our customers, and third parties from harm, provided such interests are not overridden by your rights.
- Consent — for cookies not strictly necessary, marketing, and any sensitive personal information you choose to disclose.
International transfers
Some of our sub-processors are located outside the Philippines (for example, in the United States, Singapore, or the European Union). Where we transfer personal data internationally we ensure appropriate safeguards are in place — including contractual clauses that require the recipient to protect your data to a standard comparable to Philippine law.
How long we keep data
We keep personal data only for as long as necessary for the purposes for which it was collected. Indicative retention periods are:
- Active account data — for the life of your account plus 30 days after termination, after which personal data is deleted or anonymized unless a longer period is required by law.
- Billing & accounting records — ten (10) years, in accordance with the Bureau of Internal Revenue rules.
- Security & abuse logs — up to twelve (12) months, or longer where required for ongoing investigations.
- Marketing consent records — until withdrawal, plus a reasonable period to prove compliance.
After the applicable period we securely delete, anonymize, or archive the data in a form that no longer identifies you.
Your rights as a data subject
Under the Data Privacy Act you have the right to:
- Be informed of how your data is processed;
- Access your personal data on record;
- Object to processing based on consent or legitimate interests;
- Have inaccurate data corrected (rectification);
- Have your data erased or blocked in the cases the law allows;
- Receive a copy of your data in a portable, commonly used electronic format (data portability);
- File a complaint with the National Privacy Commission (privacy.gov.ph);
- Be indemnified for damages you suffer as a result of inaccurate, incomplete, or unauthorized use of your personal information.
To exercise any of these rights, email our Data Protection Officer at [email protected]. We will respond within thirty (30) days. We may ask you to verify your identity before acting on a request.
How we protect your data
We employ reasonable organizational, physical, and technical security measures designed to protect your personal data, including:
- Encryption of data in transit (TLS 1.2+) and at rest where feasible;
- Passwords stored using industry-standard hashing (bcrypt or better);
- Multi-factor authentication on all administrative access;
- Least-privilege access controls and role separation;
- Regular vulnerability scanning and patching;
- Backups tested for restorability;
- Employee training on data privacy and confidentiality.
No system is completely secure. You must protect the confidentiality of your account credentials and notify us immediately of any suspected compromise.
Data breach notification
In the event of a personal data breach that is likely to give rise to a real risk of serious harm, we will notify the affected data subjects and the National Privacy Commission within seventy-two (72) hours of knowledge, in the manner required by NPC Circular No. 16-03.
Third-party sites and services
Our sites may link to third-party sites or embed third-party services. Their privacy practices are governed by their own policies, and we are not responsible for their content or handling of your data.
Changes to this Policy
We may update this Policy from time to time. Where changes are material we will post a notice on the site and, where practicable, email registered users at least fifteen (15) days before the change takes effect. Continued use of the services after the effective date constitutes acceptance of the updated Policy.
Email: [email protected]
