1. Introduction
EASINET Security & Wireless Communication Services ("we", "us" or "our") is committed to protecting the privacy and personal information of our subscribers, applicants, and website visitors. This Privacy Policy explains how we collect, use, store, share and protect your personal data in compliance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012, and its Implementing Rules and Regulations.
It applies to this website, our online application form, our customer portal, and to the internet service we provide to your home or business. By applying for or using our service, you confirm that you have read and understood this policy.
2. Who We Are
EASINET Security & Wireless Communication Services is the Personal Information Controller responsible for the personal data described in this policy. We decide what data is collected, why, and how it is handled.
Our principal office is at 011 Purok 1 Bagong Silang, Plaridel, Bulacan.
We run our billing, subscriber and network management systems on iSPRO PH, a platform provider that acts as our Personal Information Processor. iSPRO PH processes your data only on our documented instructions and is contractually bound to keep it confidential and secure. We remain accountable to you for how your data is handled.
3. Information We Collect
We collect only what we need to assess your application, connect you, keep you connected, and bill you correctly.
Identity and contact information
- Your full name
- Your email address
- Your mobile or landline number
- Your service and installation address
- The geographic coordinates (latitude and longitude) you provide when you pin your location on our application map, which we use to check whether you fall inside our coverage area
- Your account number with us
- Any government-issued identification, proof of billing or similar document you submit in support of your application
Service and technical information
- The internet plan you select and your connection type (PPPoE or IPoE/DHCP)
- The PPPoE username and password issued to your connection
- The IP address assigned to your connection and the MAC address of the equipment connected to our network
- The make, model, serial number, configuration and operating status of the modem, ONU or router installed at your premises, which we may read and adjust remotely in order to diagnose and fix faults
- Session records showing when your connection started and ended, how long it lasted, and how much data it carried
- The network access point (NAP) and port your line is connected to, and the coverage area you belong to
Billing and payment information
- Invoices issued to you, their billing period, amounts and due dates
- Payments received, their amounts, dates and the method used (cash, bank transfer, GCash, Maya, QR Ph or another channel)
- Reference numbers generated by our payment processors
- Your arrears, disconnection and reconnection history
We do not store your full card number, bank login or e-wallet PIN. Those are handled directly by the payment processor you choose.
Communications and portal use
- Support tickets you file, including any photos or files you attach
- SMS and email notices we send you, and your correspondence with our staff
- Your sign-in records, IP address, and browser and device information when you use our customer portal
- Actions recorded in our activity log, such as changes made to your account by our staff
4. How We Collect It
- Directly from you, when you complete our online application form, sign up at our office, use our customer portal, file a support ticket, or speak with our staff
- Automatically from our network, as our routers and authentication servers generate technical and session records while your service is active
- From our personnel, when our installers and field technicians record the details of your installation, including your location and the equipment fitted
5. Purpose of Data Collection
Your personal information is collected and processed for the following purposes:
- Assessing your application and checking whether your location falls within our coverage area
- Provisioning, activating, configuring and maintaining your internet connection
- Diagnosing faults and providing technical support, including remote inspection of the equipment at your premises
- Issuing invoices, collecting payments and keeping your account records
- Sending you service advisories, billing reminders, payment confirmations and maintenance notices by SMS or email
- Managing overdue accounts, including the temporary isolation of a connection that remains unpaid past its grace period, and its restoration once your payment is recorded
- Protecting the security and integrity of our network, and detecting, preventing and investigating fraud, abuse or unlawful use of our service
- Planning our capacity and expanding our coverage
- Complying with Philippine law and with the lawful requirements of regulators such as the National Telecommunications Commission
- Improving our service and the quality of our customer support
6. Legal Basis for Processing
We process your personal data under Section 12 of the Data Privacy Act, on one or more of the following grounds:
- Your consent, which you give when you submit an application, accept our terms of service, or otherwise agree to this policy
- The necessity of processing to perform our service contract with you, or to take steps at your request before entering into that contract
- Compliance with a legal obligation to which we are subject
- Our legitimate interests in securing our network, preventing fraud and abuse, and collecting amounts lawfully due to us, where those interests are not overridden by your rights as a data subject
Where you submit a government-issued identification document or other sensitive personal information, we process it under Section 13 of the Act on the basis of your consent, and only for the purposes set out above.
7. Data Sharing and Disclosure
We do not sell, trade or rent your personal information to anyone. We share it only where it is necessary, and only with:
- iSPRO PH, our platform provider, which hosts our billing, subscriber and network management systems as our Personal Information Processor
- Payment processors, banks and electronic wallet operators, so that we can accept and reconcile your payments
- SMS and email gateway providers, so that the notices we send actually reach you
- Our employees, installers, field technicians and accredited contractors, limited in each case to what that person needs in order to do their work for you
- Government agencies, regulators, courts and law enforcement, including the National Telecommunications Commission, the Department of Information and Communications Technology and the National Privacy Commission, where required by law, subpoena, warrant or other lawful order
- Our professional advisers, and any collection agency we engage in respect of an unpaid account
Everyone we share your data with is bound by contract or by law to keep it confidential and to use it only for the purpose for which it was disclosed.
8. Data Retention
- We keep your account records for as long as your service is active, and for a reasonable period afterwards so that we can resolve disputes, enforce our agreements and complete any collection.
- Billing, payment and accounting records are kept for ten (10) years, in line with the Bureau of Internal Revenue rules on the preservation of books of accounts and accounting records.
- Connection and traffic records, such as session logs and assigned addresses, are kept for at least six (6) months, as required of service providers by Section 13 of Republic Act No. 10175 (the Cybercrime Prevention Act of 2012), and for longer where we are lawfully directed to preserve them.
- Applications that are not approved are kept for twelve (12) months so that we can answer follow-up questions and reconsider them if our coverage changes, and are then deleted.
At the end of these periods your personal data is securely deleted or anonymised so that you can no longer be identified from it.
9. Data Storage and Security
We implement organisational, physical and technical measures appropriate to the risks, to protect your personal data against accidental or unlawful loss, alteration, disclosure, access or destruction. These include:
- Encryption of traffic between you and our website, application form and customer portal using HTTPS/TLS
- Storage of passwords as one-way cryptographic hashes, so that they are never visible to our staff
- Encrypted storage of network equipment credentials
- Role-based access control, so that each employee holds only the permissions their role requires and subscriber records are reachable only by staff with a legitimate business need
- An activity log that records sign-ins and administrative changes to accounts
- Nightly backups, protected to the same standard as live data
- Confidentiality obligations on our personnel, who are instructed on their duties under the Data Privacy Act
No system can be guaranteed absolutely secure, but we review these measures regularly and improve them as our service and the threats to it change.
10. Your Rights Under the Data Privacy Act
As a data subject, you have the following rights:
- Right to be Informed
- You have the right to know whether your personal data is being processed, and to be told how and why before we collect it.
- Right to Access
- You may request a copy of the personal data we hold about you, together with information on how it has been processed and to whom it has been disclosed.
- Right to Rectification
- You may require us to correct any inaccurate or incomplete personal data, and to inform anyone we have shared it with of the correction.
- Right to Erasure or Blocking
- You may require us to suspend, withdraw, block or delete your personal data where it is incomplete, outdated, false, unlawfully obtained, used for an unauthorised purpose, or no longer necessary — subject to the retention periods described above.
- Right to Object
- You may object to the processing of your personal data, and withdraw consent you have given. Where the processing is necessary to provide your internet service, withdrawing consent may mean we can no longer provide that service.
- Right to Data Portability
- You may obtain a copy of your personal data in a structured, commonly used and machine-readable format.
- Right to Damages
- You may be indemnified for damages sustained because of inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorised use of your personal data.
- Right to File a Complaint
- You may lodge a complaint with the National Privacy Commission if you believe your rights have been violated.
To exercise any of these rights, contact our Data Protection Officer using the details below. We may ask you to verify your identity first, so that we do not disclose your data to someone else. We will respond within fifteen (15) days of receiving your request, and will tell you if we need more time and why.
11. Cookies and Website Analytics
Our website and customer portal use cookies that are necessary for them to work: a session cookie that keeps you signed in and protects our forms against cross-site request forgery, and a small cookie that remembers whether you prefer the light or dark display. We do not use advertising cookies and we do not track you across other websites.
Some page assets, such as fonts and icons, are loaded from third-party content delivery networks, which will see your IP address as part of serving those files.
You may configure your browser to refuse cookies, but the customer portal will then be unable to sign you in.
12. Children
Our service is contracted by adults. We do not knowingly collect personal information from a child except as part of a subscription held by a parent or guardian, or with that parent or guardian's consent. If you believe we hold a child's personal data without the necessary consent, please contact our Data Protection Officer and we will delete it.
13. Personal Data Breach
We maintain procedures to detect, contain and investigate personal data breaches. Where a breach involves sensitive personal information, or information that may be used to enable identity fraud, and there is a real risk of serious harm to you, we will notify the National Privacy Commission and the affected data subjects within seventy-two (72) hours of becoming aware of it, as required by the Implementing Rules and Regulations of the Data Privacy Act.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our systems or the law. The current version is always published on this page with its revision date, and we will communicate material changes through our usual channels. We encourage you to review this policy periodically.
15. Contact Us
If you have questions, concerns or requests about this Privacy Policy or about your personal data, please contact our Data Protection Officer:
If you believe your rights under the Data Privacy Act have been violated, you may also lodge a complaint with the National Privacy Commission: