The purpose of this policy is to protect the data or personal information acquired by UNITED ASIA AUTOMOTIVE GROUP, INC. from its website or Apps from individuals, business or companies who visits the website or App for purposes of inquiry, transacting business with UAAGI and browsing. This policy assures security of information gathered while ensuring free flow of information for effective and efficient transactions.
This applies to data or information whether personal, sensitive or business data acquired by UAAGI.
The policy comprises the following:
a. The Data collected
b. How the data is collected
c. Purpose of gathering the data
d. What to do with the data gathered
e. Data storage, disclosure and sharing
f. Security of Information
g. Data Retention and Disposal
h. Control of Data
i. Data Privacy Officer and Contact Information
3.0 DEFINITION OF TERMS
a. UAAGI refers to United Asia Automotive Group, Inc., its employees, board of directors, stockholders, officers.
b. UAAGI affiliates and subsidiaries refers to the sister company of UAAGI.
c. Consent of the data subject refers to any freely given, specific, informed indication of will, whereby the data subject agrees to the collection and processing of personal information about and/or relating to him or her. Consent shall be evidenced by written, electronic or recorded means. It may also be given on behalf of the data subject by an agent specifically authorized by the data subject to do so.
d. Data subject refers to an individual whose personal information is processed.
e. Direct marketing refers to communication by whatever means of any advertising or marketing material which is directed to particular individuals.
f. Filing system refers to any act of information relating to natural or juridical persons to the extent that, although the information is not processed byequipment operating automatically in response to instructions given for that purpose, the set is structured, either by reference to individuals or by reference to criteria relating to individuals, in such a way that specific information relating to a particular person is readily accessible.
g. Information and Communications System refers to a system for generating, sending, receiving, storing or otherwise processing electronic data messages or electronic documents and includes the computer system or other similar device by or which data is recorded, transmitted or stored and any procedure related to the recording, transmission or storage of electronic data, electronic message, or electronic document.
h. Personal information refers to any information whether recorded in a material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual.
i. Personal information controller refers to a person or organization who controls the collection, holding, processing or use of personal information, including a person or organization who instructs another person or organization to collect, hold, process, use, transfer or disclose personal information on his or her behalf. The term excludes:
(1) A person or organization who performs such functions as instructed by another person or organization; and
(2) An individual who collects, holds, processes or uses personal information in connection with the individual’s personal, family or household affairs.
j. Personal information processor refers to any natural or juridical person qualified to act as such under this Act to whom a personal information controller may outsource the processing of personal data pertaining to a data subject.
k. Processing refers to any operation or any set of operations performed upon personal information including, but not limited to, the collection, recording, organization, storage, updating or modification, retrieval, consultation, use, consolidation, blocking, erasure or destruction of data.
l. Privileged information refers to any and all forms of data which under the Rules of Court and other pertinent laws constitute privileged communication. m. Sensitive personal information refers to personal information:
(1) About an individual’s race, ethnic origin, marital status, age, color, and religious, philosophical or political affiliations;
(2) About an individual’s health, education, genetic or sexual life of a person, or to any proceeding for any offense committed or alleged to have been committed by such person, the disposal of such proceedings, or the sentence of any court in such proceedings;
(3) Issued by government agencies peculiar to an individual which includes, but not limited to, social security numbers, previous or current health records, licenses or its denials, suspension or revocation, and tax returns; and
(4) Specifically established by an executive order or an act of Congress to be kept classified.
n. One System is all-in-one management software that UAAGI and its programming partner XWARE I.T. Consultancy has designed and developed specifically for the needs of all UAAGI Dealerships, Purchasing, Unit Sales, Service and Warranty, and Parts Sales, thus, it provides for a streamlined recording of all activities done and in producing coherent and efficient reports.
o. Brand App are applications created by UAAGI and its programmers for its specific brands (FOTON, CHERY, MUTT), for its customers for proper identification of products, price, and services.
p. Marketing Activities refers to activities related to advertising or marketing and promoting the sale of UAAGI Vehicles, Spare Parts and Services. It involves sending invitation for sales promotion, marketing event, product launches and posting to social media of pictures and events related to UAAGI Products.
q. Data Processing Officer (DPO) is the person assigned to monitor internal compliance and ensure that the company processes personal data in compliance with applicable data protection laws and the Data Privacy Manual.
4.0 PERSONAL INFORMATION SHALL INCLUDE BUT NOT LIMITED TO FOLLOWING:
iv. Civil Status
v. Contact Information
vi. Social Security System (SSS) Information
vii. Tax Identification Number (TIN)
viii. Philhealth Information ix. Home Development Mutual Fund (Pag-Ibig) Information
x. National Bureau of Investigation (NBI) Clearance
xi. Police Clearance
xii. Barangay Clearance
xiii. Birth Certificate
xiv. Marriage Certificate
xv. 1 Birth Certificate of Children
xvi. Valid government I.D.
xvii. Pre-employment medical results
xviii. Family Background
xix. Educational Background
xx. Work Experiences
xxi. Data Subject’s Pictures
xxii. Medical Information or Results
b. Business/ Corporations
i. Corporate Name
ii. Corporate Address
iii. Representative’s Name
iv. Representative’s Address
v. Representative’s Civil Status
vi. Representative’s Age
vii. Representative’s Contact Information
viii. Representative’s Tax Identification Number (TIN)
ix. Company Background
x. Company Profile
xi. Name of stockholders
xii. Name of Directors
xiii. Name of Corporate Officers
xiv. Name of Company Representatives
xv. 5.0 Business Permit
xvi. Department of Trade and Industry (DTI) Registration
xvii. Articles of Incorporation and By Laws
xviii. Securities and Exchange Commission (SEC) Certificate
xix. General Information Sheet (GIS)
xx. Bureau of Internal Revenue (BIR) Registration
xxi. List of clients
xxii. List of suppliers
xxiii. Financial Capacity
xxiv. Data Subject’s Pictures and Logo
5.0 HOW DATA IS COLLECTED
The data is collected through the following:
a. When inquiring at UAAGI’s brand website.
b. When participating UAAGI’s marketing activities
c. When communicating with UAAGI
d. Application for employment at UAAGI
e. Employment at UAAGI
f. Upon product or service inquiry
g. Upon request for company accreditation
h. Endorsement of information from our accredited Dealerships
i. During negotiations with UAAGI
j. Upon entering into sales or contractual relationship with UAAGI
k. Upon entering into Business Transaction with UAAGI
l. Walk-in clients.
m. Those freely given by the data subject to UAAGI.
n. Upon entering UAAGI’s company premises
o. Usage of UAAGI App
6.0 PURPOSE OF GATHERING THE DATA
The gathering of data shall be for the following purpose:
a. Sales transactions
b. Service Transactions
c. Contractual Relationships
d. Business Negotiations
e. Business Transactions
f. Purchase Transactions
g. Application for Employment
h. 201 Employment file
i. Marketing Activity
j. Brand Promotions
k. Digital Marketing
l. Supplier Accreditation
m. Invitation for UAAGI events
n. For purposes of providing excellent customer service
7.0 WHAT TO DO WITH THE DATA GATHERED
a. Sales/ Parts/ After Sales Transactions or Services
i. Data gathered from browsing our website, communicating with UAAGI, marketing activities, inquiries, walk-in clients, or those endorsed by UAAGI’s accredited Dealerships shall be used by our Sales Department for purposes of introducing and selling our products and services.
ii. Data gathered from browsing our website, apps or communicating with UAAGI, marketing activities, inquiries and walk-in clients may be endorsed to our Accredited Dealerships for purposes of introducing and selling our products and services to potential clients.
iii. Data gathered from our clients shall likewise be shared to UAAGI’s Manufacturers and Assemblers and UAAGI Suppliers for purposes of providing the utmost customer service to its clients
iv. Data gathered may also be shared to bank partners, insurance companies or government agencies whennecessary for processing of sales and service transactions, bank financing application, application for compulsory third party application for insurance and Land Transportation Office (LTO) registration.
b. Marketing Activity
i. Data gathered shall be used for marketing activities such as invitation for sales promotion, marketing events and product launches whether actual or virtual.
ii. Data gathered shall be used as client references and shall be endorsed to our authorized sales agents and accredited Dealerships for purposes of sales transactions with UAAGI.
iii. Data gathered such as pictures of Data Subject during marketing events or business transactions may be used by UAAGI in promotional activities, including digital marketing.
c. Supplier Accreditation
i. Data gathered for purposes of supplier’s accreditation shall be used by UAAGI in accrediting its suppliers for purposes of sales transactions, product inquiries, processing of payments, tax purposes and other related transactions.
d. Contractual Relationship
i. Data gathered shall be used in drafting contracts, memorandums, and other legal documents for purposes of entering into business transactions with UAAGI.
e. Legal Matters
i. Data gathered shall be used for establishment, exercise of UAAGI’s legal claims or defense.
f. Business Negotiations
i. Data gathered may be used for negotiations for possible business transactions with UAAGI.
g. Purchase Transactions.
i. Data gathered shall be used for transactions entered into by UAAGI other than the transactions above- mentioned.
h. Application for Employment and Employment at UAAGI
i. Data gathered from UAAGI employees shall be used for employee information to be submitted to government agencies in connection with their employment, client referrals in terms of sales transactions and services, background investigation and other third party transactions which require divulging employee information for legitimate purpose.
ii. Personal Information gathered from employees or prospective employees may be used in legal claims and defense in cases filed by and against the company.
iii. Personal Information gathered from employees or prospective employees may be divulged to third parties conducting background investigations.
8.0 DATA STORAGE, DISCLOSURE AND SHARING
Data gathered shall be stored at UAAGI’s One System, Digital Data Base, Servers, Cloud, and Warehouses, Filing Cabinets and Vaults.
The name and contact information of unsuccessful employment applicants are stored in UAAGI’s data base and filing cabinets for future reference. Personal Information of UAAGI employees shall be stored in their 201 files Filing and AMS System.
Personal information of UAAGI separated employees shall be stored in UAAGI Warehouse and AMS System. Personal or Business/ Corporate Data of clients, suppliers or those other than the employees of UAAGI shall be disclosed and shared with UAAGI authorized Sales Teams, accredited Dealerships, Assemblers and Manufacturers, Suppliers, Bank Partners, Insurance Companies and to those providing shared services with UAAGI, UAAGI’s affiliates and subsidiaries. The personal information shall be stored UAAGI’s One System, Digital Data Base, Servers, Cloud, and Warehouses, Filing Cabinets and Vaults.
The data to be disclosed and shared shall only be limited to such extent necessary to render effective the purpose for which the Data is gathered such as but not limited to transactions with UAAGI, marketing activities or employment.
The data collected may also be disclosed to courts and government agencies pursuant to and in compliance with applicable laws and regulations, subpoena or court order.
9.0 ACCESS TO PERSONAL DATA/ INFORMATION
Access to Personal Data or Information of employees and applicants shall be restricted to Human Resource and Administration Division, Finance Division and Legal and Compliance Division.
Access to Personal or Business Data of clients, suppliers or those other than the employees of UAAGI shall be limited to Sales and Marketing Division, Dealer Development Division, Legal and Compliance Division and Finance Division.
10.0 SECURITY OF INFORMATION
UAAGI is committed is ensuring the security of the data gathered from the data subject and UAAGI undertakes to make the necessary actions and security measures in collecting, receiving, transmitting, sharing, storing and disposing of the data gathered.
UAAGI likewise undertakes to gather the necessary consent forms in gathering data as well as entering into agreements such as but not limited to Data Sharing Agreement or Non-Disclosure Agreement for the protection of the Data Subjects.
Should there be unauthorized access of data from UAAGI due to hacking, unauthorized sharing of information or downloading of information, or any kind of breach in information, UAAGI shall immediately inform the Data Subject about such breach as well as place security measures to impede the further leakage of Data or breach of information.
11.0 DATA RETENTION AND DISPOSAL
UAAGI shall keep the data only for as long as it is necessary.
Personal information are only kept for five (5) years from the time of its last transaction or communication with UAAGI except when retention thereof for a longer period is necessary such as but not limited to after sales service or if there is an existing or possible legal claim against or by UAAGI from the Data Subject.
The Disposal of the Data shall be through deletion in the ONE System, App, Digital Data Base or shredding or burning of hard copy files.
12.0 CONTROL OF DATA
The Data Subject can request for a copy of his or her personal data or business data and the same may be updated or revised if the same is incorrect or inaccurate.
The Data Subject may likewise request for the deletion, blocking, revision or updating of his or her personal information by writing a letter or email to our Data Privacy Officer.
12.0 DATA PRIVACY OFFICER AND CONTACT INFORMATIO
Data Privacy Officer
84424076-78 loc. 5122
Lot Beside Bldg. 1055 Argonaut Highway, Subic Bay Freeport Zone
CHANGES TO POLICY
UAAGI reserves the right to change, revise or modify this policy as necessary.