Data & Compliance
What we do to keep information safe, who touches it, and the obligations we carry as a supplier to government.
1. Our standing
M.M. Salonga Trading has been in service since 2009 and is PhilGEPS certified, handling negotiated transactions and government biddings with local government units. That means we are routinely a party to public procurement, and the record-keeping that goes with it.
| Registered name | registered name to confirm |
| Registration number | DTI / SEC number to confirm |
| TIN | TIN to confirm |
| Accreditation | PhilGEPS certified |
| NPC registration | registration status to confirm with counsel |
2. How we protect data
The Data Privacy Act requires organisational, physical and technical measures proportionate to the risk. These are ours, described plainly rather than in generalities.
Technical
- Everything travels encrypted. The website and the staff portal are served over HTTPS only.
- The database enforces access itself. Every table holding personal information has row-level security switched on. Access is decided inside the database, so a mistake in the application cannot expose records the application was never meant to show.
- The public website cannot read customer records. The key the website uses can read the product catalog and write a quotation request. It cannot read inquiries, orders, customers or mail.
- Incoming mail is verified before it is stored. Messages delivered into our mailboxes arrive through a signed webhook; anything unsigned, altered in transit, or replayed later is rejected outright.
- No payment data exists to steal. No card or bank details are ever entered into, or stored by, this system.
Organisational
- Each member of staff has their own account. Accounts are created by the owner, and there are no shared logins.
- When somebody leaves, their account is switched off immediately. Their name stays on the work they did, because a record that rewrites its own history is not a record.
- Staff see what their job needs. The commercial figures, the team list and the system settings are the owner’s.
Physical
Records are held in managed data centres operated by the providers in section 4, not on office machines or removable drives. Paper documents at 175 Toclong II-B, Imus, Cavite are kept in the company’s own premises.
3. Who can see what
| Who | Can see |
|---|---|
| A visitor to this website | The product catalog, and the confirmation of a request they themselves just sent. |
| Our sales and accounting staff | Quotation requests, orders, customers, the offices we have contacted, and the mailbox they work from. |
| The owner | All of the above, plus revenue, the team and the system settings. |
| Our service providers | Only what running the service requires, on our instructions and for no purpose of their own. |
4. Our processors
These are the third parties that hold or handle personal information on our behalf. The list is kept current — if we change a provider, this page changes with it.
Processed in: Singapore
Processed in: United States
Processed in: Singapore, on a global network
None of them is permitted to use the information for their own purposes, and none of them sells it.
5. Cross-border transfers
Our database and our website run in Singapore. Our email provider operates from the United States. That means personal information covered by our Privacy Policy is transferred outside the Philippines in the ordinary course of us doing business.
The Data Privacy Act does not prohibit this. It makes us accountable for the information wherever it goes — we remain responsible to you for it, we choose providers that commit contractually to protecting it, and transferring it abroad does not reduce any of the rights set out in our Privacy Policy.
6. If something goes wrong
No one can promise a breach will never happen. What we can set out is what we would do.
- Contain it first — revoke the affected access, close the route in, and establish what was actually reached.
- Notify the National Privacy Commission within 72 hours of knowing about a breach that is notifiable under the Act and its implementing rules.
- Tell the people affected, describing what happened, what information was involved, and what we are doing about it — in language that is useful rather than defensive.
- Record it and fix the cause, so the same thing cannot happen twice.
7. Procurement and record-keeping
As a PhilGEPS-certified supplier we take part in negotiated transactions and public bidding. Records connected to those — quotations, purchase orders, delivery documents and invoices — are kept for as long as procurement and tax rules require, and are disclosable to the procuring entity and to auditors.
A request to delete personal information cannot override that obligation. Where we must keep a record, we will tell you so and explain why, rather than quietly do nothing.
We publish no price list. Every figure we give is a quotation prepared for a specific requirement, issued in writing with a reference number, and valid for the period stated on it. That is a commercial position, but it is also a record-keeping one: each figure we ever quoted is traceable to a document.
8. Anti-corruption
Doing business with government carries obligations beyond data protection. We do not offer, give, solicit or accept anything of value to influence the award of a contract, and we expect the same of anyone acting on our behalf. Our staff are instructed that no order is worth a breach of this.
Nothing in our pricing, our quotations or our proposals is contingent on any personal benefit to an official.
9. Reporting a concern
If you think information has been mishandled, or that someone acting for us has behaved improperly, tell us directly:
- Email privacy contact address to confirm for anything about personal information.
- Email hello@mmsalongatrading.com or call 0954 457 6000 for anything else.
You may also raise a data privacy concern directly with the National Privacy Commission. You do not have to come to us first.