Privacy Notice
Version 2026-07-30 · effective 2026-07-01
Effective Date: July 1, 2026
INTRODUCTION
REDTECH DYNAMICS SOLUTIONS CORP. ("REDTECH") is the owner, developer, licensor, operator, and system administrator of the REDTECH Supplier Accreditation and Vendor Management Portal (the "Portal"). SAVVYCORE GLOBAL INC. ("SAVVYCORE") serves as REDTECH's authorized implementation, onboarding, training, customer success, marketing, and client support partner.
The Portal is a secure cloud-based Software-as-a-Service (SaaS) platform developed to facilitate supplier registration, supplier accreditation, vendor management, document management, procurement support, compliance monitoring, and other related business processes between independent Accrediting Partners and their respective Suppliers. The Portal provides a centralized technological environment through which Suppliers may electronically submit information and documentary requirements to Accrediting Partners, and through which Accrediting Partners may evaluate, manage, and maintain their respective supplier records in accordance with their own internal policies, procurement procedures, and business requirements.
REDTECH and SAVVYCORE recognize the importance of protecting the privacy and security of Personal Data processed through the Portal and are committed to processing such information in accordance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012, its Implementing Rules and Regulations, issuances of the National Privacy Commission, and all other applicable laws governing the protection of Personal Data.
This Privacy Notice explains how Personal Data are collected, received, recorded, organized, stored, updated, retrieved, consulted, used, transmitted, disclosed, retained, archived, deleted, and otherwise processed through the Portal. It likewise describes the respective roles and responsibilities of REDTECH, SAVVYCORE, Accrediting Partners, Suppliers, and Data Subjects in relation to the processing of Personal Data, as well as the safeguards implemented to protect such information throughout its lifecycle.
The Portal operates as a technology platform only. Except to the extent expressly provided by law or by written agreement, REDTECH and SAVVYCORE do not determine the documentary requirements, accreditation standards, supplier qualifications, procurement policies, approval criteria, commercial decisions, or vendor management policies of any Accrediting Partner. Likewise, neither REDTECH nor SAVVYCORE determines whether any Supplier shall be accredited, conditionally accredited, suspended, renewed, rejected, or otherwise accepted by an Accrediting Partner.
The authenticity, completeness, accuracy, legality, validity, and continuing correctness of all information and documents submitted through the Portal remain the sole responsibility of the Supplier submitting such information and the Accrediting Partner reviewing, evaluating, verifying, and relying upon such information. Nothing in the operation of the Portal shall be construed as a representation, certification, verification, guarantee, warranty, or confirmation by REDTECH or SAVVYCORE regarding the authenticity, completeness, legality, validity, reliability, or evidentiary value of any information, declaration, certification, permit, licence, identification document, financial statement, or other document uploaded through the Portal.
REDTECH and SAVVYCORE may access Personal Data processed through the Portal only to the extent reasonably necessary to administer, operate, maintain, secure, support, troubleshoot, improve, audit, monitor, recover, migrate, implement, or otherwise lawfully provide the Portal and its related services, or as otherwise required or permitted by applicable law. Such access shall not be construed as an assumption of responsibility for verifying the accuracy or authenticity of the information processed through the Portal, nor shall it transfer to REDTECH or SAVVYCORE any responsibility belonging to the Supplier or the relevant Accrediting Partner under applicable law, contract, or internal policy.
The Portal is designed to maintain logical segregation of information among Accrediting Partners. Each Supplier may access only its own account, records, applications, and supporting documents, subject to the permissions granted by the relevant Accrediting Partner. Each Accrediting Partner may access only the supplier records, documents, and information submitted to or maintained within its own Portal environment. Under no circumstances shall one Accrediting Partner be permitted to access, retrieve, view, or process supplier information, documents, or records belonging to another Accrediting Partner solely by reason of both entities utilizing the Portal. REDTECH implements appropriate technical and organizational measures to preserve this segregation of information and to prevent unauthorized cross-access between independent Accrediting Partners.
This Privacy Notice forms an integral part of the Terms of Use governing the Portal. By accessing, registering with, or otherwise using the Portal, each user acknowledges that he, she, or it has read and understood this Privacy Notice and agrees to the processing of Personal Data as described herein, subject always to the rights of data subjects under applicable law.
Nothing contained in this Privacy Notice shall be construed as creating a partnership, joint venture, agency, fiduciary relationship, employment relationship, procurement relationship, brokerage, distributorship, or other legal relationship between REDTECH or SAVVYCORE, on one hand, and any Supplier or Accrediting Partner, on the other, except insofar as may be necessary for the lawful provision, administration, implementation, maintenance, support, and operation of the Portal and the services directly related thereto.
DEFINITIONS AND ROLES OF THE PARTIES
For purposes of this Privacy Notice, the following terms shall have the meanings set forth below, unless the context otherwise requires.
"Portal" refers to the REDTECH Supplier Accreditation and Vendor Management Portal, including all websites, web applications, mobile interfaces, databases, software modules, application programming interfaces (APIs), cloud infrastructure, and related technologies developed, owned, operated, maintained, or licensed by REDTECH for supplier accreditation, vendor management, procurement support, document management, compliance monitoring, subscription management, and related business processes.
"REDTECH" refers to REDTECH DYNAMICS SOLUTIONS CORP., the owner, developer, licensor, operator, and system administrator of the Portal.
"SAVVYCORE" refers to SAVVYCORE GLOBAL INC., the entity authorized by REDTECH to provide implementation, onboarding, training, customer success, marketing, account management, and client support services relating to the Portal.
"Accrediting Partner" refers to any corporation, partnership, sole proprietorship, government agency, government-owned or controlled corporation, financial institution, educational institution, non-profit organization, or other legal entity that subscribes to or utilizes the Portal for the purpose of registering, evaluating, accrediting, managing, monitoring, or maintaining records relating to its own Suppliers.
"Supplier" refers to any individual, sole proprietorship, partnership, corporation, cooperative, association, joint venture, or other business organization that registers with the Portal for accreditation or vendor management with one or more Accrediting Partners.
"Data Subject" refers to any identified or identifiable natural person whose Personal Data are processed through the Portal, including but not limited to proprietors, partners, directors, officers, shareholders, beneficial owners, authorized representatives, employees, contact persons, consultants, contractors, and other individuals whose Personal Data are submitted in connection with supplier accreditation or vendor management activities.
Unless otherwise defined herein, capitalized terms shall have the meanings assigned to them under the Data Privacy Act of 2012 and its Implementing Rules and Regulations.
ROLES AND RESPONSIBILITIES
The Portal has been developed to serve as a secure technology platform that enables Suppliers and Accrediting Partners to electronically exchange information and manage supplier accreditation and vendor management processes in an efficient, secure, and auditable environment. The Portal itself does not make commercial decisions, accreditation determinations, or procurement judgments.
REDTECH acts solely as the provider, owner, developer, licensor, operator, administrator, and maintainer of the Portal. In such capacity, REDTECH is responsible for the development, operation, maintenance, security, monitoring, enhancement, and technical administration of the Portal and the supporting technology infrastructure necessary for its operation.
SAVVYCORE acts solely as REDTECH's authorized implementation, onboarding, customer success, marketing, training, and support partner. Its processing of Personal Data is strictly limited to activities reasonably necessary to implement, configure, support, maintain, administer, and assist users in their authorized use of the Portal.
Each Accrediting Partner independently determines the documentary requirements, accreditation criteria, procurement policies, compliance standards, approval procedures, vendor classifications, retention policies, and other business rules applicable to its own supplier accreditation process. Consequently, each Accrediting Partner remains solely responsible for evaluating Suppliers, determining whether submitted documents satisfy its internal requirements, verifying the authenticity and sufficiency of documents submitted to it, and making all decisions relating to supplier accreditation, renewal, suspension, rejection, or continued vendor eligibility.
Each Supplier likewise remains solely responsible for ensuring that all Personal Data, business information, declarations, certifications, licences, permits, financial records, and supporting documents submitted through the Portal are accurate, complete, current, authentic, lawful, and supported by the necessary authority, consent, or other lawful basis required under applicable law. Suppliers further warrant that they possess all necessary rights and authority to disclose the Personal Data of their officers, employees, representatives, shareholders, beneficial owners, contact persons, and other individuals whose information is uploaded to the Portal.
Neither REDTECH nor SAVVYCORE verifies, certifies, guarantees, warrants, audits, investigates, validates, or independently confirms the authenticity, legality, completeness, sufficiency, reliability, or evidentiary value of any information or document submitted through the Portal, unless such verification forms part of a separate written service agreement expressly executed for that purpose. Any review or access undertaken by REDTECH or SAVVYCORE for purposes of technical support, troubleshooting, implementation, system administration, migration, maintenance, quality assurance, security monitoring, or regulatory compliance shall not be construed as a commercial, legal, financial, procurement, or compliance verification of the information submitted by any Supplier.
The Portal employs logical segregation and access controls to ensure that information remains isolated between Accrediting Partners. A Supplier may access only its own account and the information associated with that account. An Accrediting Partner may access only the supplier records, applications, documents, and information submitted to or maintained for that Accrediting Partner within its designated Portal environment. No Accrediting Partner shall be permitted to access, search, retrieve, view, or process supplier information belonging to another Accrediting Partner solely because both entities subscribe to or utilize the Portal.
REDTECH and SAVVYCORE may access Personal Data only to the extent reasonably necessary to operate, administer, maintain, secure, monitor, troubleshoot, recover, support, improve, migrate, audit, implement, or otherwise lawfully provide the Portal and its related services, or where such access is required by law, court order, lawful governmental directive, or regulatory requirement. Such access shall not transfer to REDTECH or SAVVYCORE any responsibility that properly belongs to the Supplier or the relevant Accrediting Partner under applicable law, contract, or internal policy.
Nothing contained in this Privacy Notice shall be interpreted as making REDTECH or SAVVYCORE a buyer, seller, procuring entity, supplier, contractor, consultant, broker, guarantor, certifying body, auditor, inspection agency, verification body, escrow agent, fiduciary, or representative of any Accrediting Partner or Supplier. All commercial relationships, procurement transactions, accreditation decisions, contractual obligations, and business risks remain exclusively between the relevant Accrediting Partner and the relevant Supplier.
DATA OWNERSHIP AND CONTROL
The Portal is a technology platform that facilitates the electronic collection, storage, transmission, management, and processing of information between Suppliers and Accrediting Partners. Except as otherwise expressly provided by applicable law or written agreement, the operation of the Portal shall not transfer ownership of any Personal Data, business information, supporting document, or other content submitted through the Portal to REDTECH or SAVVYCORE.
Each Supplier remains solely responsible for the ownership, authenticity, accuracy, completeness, legality, and continued validity of the information, declarations, certifications, records, and supporting documents that it submits through the Portal. Each Supplier likewise represents and warrants that it possesses the necessary authority, consent, or other lawful basis to disclose the Personal Data and documents uploaded through the Portal, including those relating to its directors, officers, employees, shareholders, beneficial owners, authorized representatives, contact persons, consultants, contractors, and other individuals whose information forms part of its supplier accreditation records.
Each Accrediting Partner independently determines the information, documentary requirements, certifications, declarations, and other records that it requires from its Suppliers for accreditation, vendor management, procurement, compliance, or related business purposes. Accordingly, each Accrediting Partner remains solely responsible for determining the necessity, proportionality, relevance, and lawful use of the information collected through its own Portal environment, as well as for evaluating, verifying, and relying upon such information in making accreditation, procurement, vendor management, or other commercial decisions.
REDTECH and SAVVYCORE do not acquire ownership, proprietary rights, intellectual property rights, beneficial interests, commercial rights, or any independent right to exploit, publish, disclose, sell, license, monetize, or otherwise commercially use the information or documents processed through the Portal solely because such information is hosted, stored, transmitted, backed up, processed, or otherwise made available through the Portal. Any processing undertaken by REDTECH or SAVVYCORE shall be strictly limited to that which is reasonably necessary for the lawful operation, administration, maintenance, implementation, support, security, monitoring, improvement, recovery, migration, audit, or regulatory compliance of the Portal, or as otherwise permitted or required by applicable law.
The Portal employs logical segregation and access controls designed to ensure that each Accrediting Partner has access only to the supplier records, Personal Data, and supporting documents submitted specifically for its own accreditation and vendor management activities. Supplier information submitted to one Accrediting Partner shall remain logically separate from information submitted to any other Accrediting Partner. Consequently, one Accrediting Partner shall not have the ability to access, retrieve, search, view, download, or otherwise process supplier information belonging to another Accrediting Partner solely because both entities subscribe to or utilize the Portal.
Likewise, each Supplier shall have access only to its own account, applications, supporting documents, communications, and other records maintained within the Portal. Except as otherwise authorized by the relevant Accrediting Partner or required by applicable law, a Supplier shall not have access to the information, records, or documents of another Supplier.
Nothing contained in this Privacy Notice shall be interpreted as appointing REDTECH or SAVVYCORE as the owner, custodian of commercial records, verifier, certifier, auditor, or independent evaluator of the information submitted through the Portal. The responsibility for verifying the authenticity, legality, completeness, sufficiency, accuracy, and evidentiary value of Supplier information and supporting documents remains exclusively with the Supplier submitting such information and the Accrediting Partner receiving, evaluating, and relying upon such information in connection with its own accreditation, procurement, compliance, or vendor management processes.
For the avoidance of doubt, the mere hosting, storage, transmission, backup, retrieval, processing, or technical administration of information through the Portal shall not be construed as an acceptance by REDTECH or SAVVYCORE of responsibility for the substantive content of such information, nor shall it create any fiduciary, agency, procurement, verification, certification, or commercial relationship between REDTECH or SAVVYCORE and any Supplier or Accrediting Partner beyond the provision of the Portal and its related support services.
COLLECTION AND PROCESSING OF PERSONAL DATA
In the course of operating, administering, maintaining, supporting, securing, and improving the Portal, REDTECH and SAVVYCORE may collect, receive, record, organize, store, retrieve, consult, use, transmit, disclose, retain, archive, delete, or otherwise process Personal Data that are voluntarily submitted through the Portal, automatically generated through its use, or otherwise lawfully obtained in connection with supplier accreditation, vendor management, procurement support, subscription management, customer support, and other legitimate business activities carried out through the Portal.
The Personal Data processed through the Portal may originate directly from the Data Subject, from a Supplier acting through its duly authorized representatives, from an Accrediting Partner in the course of its accreditation or vendor management activities, or from other lawful sources where such collection or disclosure is authorized by law or supported by an appropriate legal basis.
Depending upon the nature of the transaction, REDTECH and SAVVYCORE may process Personal Data relating to the identity, contact details, business affiliations, employment, corporate authority, financial capacity, regulatory compliance, contractual relationships, communications, system usage, technical information, and other information reasonably necessary for the operation of the Portal and the services provided through it. The processing of such information likewise includes documents uploaded to the Portal that may contain Personal Data relating to directors, officers, shareholders, beneficial owners, employees, representatives, contact persons, consultants, contractors, or other individuals whose information is reasonably necessary for supplier accreditation or vendor management.
Personal Data processed through the Portal may include information required to establish user accounts, authenticate users, verify authority to act on behalf of a Supplier or Accrediting Partner, facilitate supplier registration, evaluate documentary submissions, maintain supplier profiles, administer subscriptions, provide technical assistance, manage communications, maintain audit records, comply with legal obligations, and perform other activities reasonably necessary for the secure and efficient operation of the Portal.
REDTECH and SAVVYCORE process Personal Data only upon the existence of a lawful basis recognized under the Data Privacy Act of 2012 and other applicable laws. Depending upon the circumstances of the processing activity, such legal basis may consist of the performance of a contract or the implementation of pre-contractual measures requested by the Data Subject, compliance with a legal obligation, the pursuit of legitimate interests that are not overridden by the fundamental rights and freedoms of the Data Subject, the protection of life and health, the performance of functions carried out in the public interest where applicable, or the consent of the Data Subject whenever consent is required under applicable law.
REDTECH and SAVVYCORE shall process Personal Data only to the extent reasonably necessary for the specific and legitimate purposes for which such information was collected. Personal Data shall not be processed in a manner incompatible with those purposes except where otherwise authorized or required by law.
In accordance with the principles of transparency, legitimate purpose, and proportionality under the Data Privacy Act of 2012, REDTECH and SAVVYCORE endeavor to ensure that only Personal Data reasonably necessary for the relevant processing activity are collected and processed. Data Subjects, Suppliers, and Accrediting Partners are likewise encouraged not to upload or disclose information that is excessive, unnecessary, or unrelated to the accreditation, procurement, or vendor management process.
The categories of Personal Data processed through the Portal may evolve as additional functionalities, regulatory requirements, business processes, or service offerings are introduced. Where such changes materially affect the processing of Personal Data, REDTECH shall provide the appropriate notice or obtain such consent as may be required under applicable law before implementing the relevant processing activity.
For the avoidance of doubt, any access by REDTECH or SAVVYCORE to Personal Data processed through the Portal is undertaken solely for purposes reasonably necessary to operate, administer, maintain, implement, secure, support, troubleshoot, monitor, audit, recover, migrate, improve, or otherwise lawfully provide the Portal and its related services, or as otherwise required by applicable law. Such access shall not be construed as an assumption of responsibility to determine the authenticity, completeness, legal sufficiency, or evidentiary value of any information or document submitted through the Portal. The responsibility for verifying the accuracy, validity, and authenticity of supplier information and supporting documents remains exclusively with the Supplier submitting such information and the Accrediting Partner reviewing and relying upon such information in connection with its own accreditation or procurement processes.
PURPOSES OF PROCESSING PERSONAL DATA
REDTECH and SAVVYCORE process Personal Data solely for legitimate, specified, and lawful purposes that are reasonably necessary for the operation, administration, maintenance, security, implementation, support, and continuous improvement of the Portal and the services provided through it. Personal Data shall not be processed for purposes that are incompatible with those described in this Privacy Notice unless otherwise authorized by the Data Subject or permitted under applicable law.
Without limiting the foregoing, Personal Data may be processed to establish, create, administer, and maintain user accounts; authenticate users and authorized representatives; verify user identity and authority; facilitate supplier registration, supplier accreditation, subscription management, vendor management, and procurement support activities; receive, organize, store, retrieve, transmit, and maintain supplier information and supporting documents; enable Accrediting Partners to review, evaluate, and manage supplier applications; facilitate communications between Suppliers and Accrediting Partners; and provide the services and functionalities made available through the Portal.
REDTECH and SAVVYCORE may likewise process Personal Data to administer subscriptions, provide implementation services, conduct onboarding and user training, deliver customer support, respond to inquiries and service requests, resolve technical issues, investigate reported incidents, improve user experience, develop new functionalities, enhance system performance, monitor service quality, and ensure the reliable and efficient operation of the Portal.
Personal Data may further be processed to maintain appropriate audit trails, generate system logs, monitor system activity, detect unauthorized access, investigate cybersecurity incidents, prevent fraud and other unlawful activities, enforce the Terms of Use and other contractual arrangements, protect the rights and legitimate interests of REDTECH, SAVVYCORE, Accrediting Partners, Suppliers, and other authorized users, and maintain the confidentiality, integrity, availability, and security of the Portal.
Where necessary, Personal Data may also be processed to comply with applicable laws, regulations, judicial or administrative orders, lawful governmental requests, regulatory examinations, audit requirements, tax obligations, reporting obligations, and other legal or regulatory requirements imposed upon REDTECH, SAVVYCORE, or the operation of the Portal.
REDTECH and SAVVYCORE may likewise process Personal Data for internal administrative purposes, including information security management, business continuity planning, disaster recovery, data backup and restoration, system maintenance, software development, quality assurance, product testing, risk management, internal audit, legal compliance, corporate governance, and other operational activities reasonably necessary to maintain the Portal and its supporting infrastructure.
Personal Data may also be processed to establish, exercise, or defend legal claims, resolve disputes, investigate complaints, respond to law enforcement requests, protect the legal rights and property of REDTECH, SAVVYCORE, Accrediting Partners, Suppliers, and other affected parties, or otherwise pursue legitimate interests that are not inconsistent with applicable law.
Notwithstanding the foregoing, REDTECH and SAVVYCORE do not process Personal Data for the purpose of determining whether a Supplier satisfies the accreditation requirements of an Accrediting Partner, verifying the authenticity or legal sufficiency of supplier-submitted documents, conducting due diligence on behalf of an Accrediting Partner, or making procurement, commercial, financial, or accreditation decisions. Such activities remain exclusively within the authority, responsibility, and discretion of the relevant Accrediting Partner in accordance with its own internal policies and procedures.
Similarly, nothing in this Privacy Notice shall be construed as authorizing REDTECH or SAVVYCORE to use Supplier information for their own independent commercial purposes unrelated to the operation and support of the Portal. Except where otherwise authorized by the Data Subject or permitted by applicable law, Personal Data shall not be sold, rented, licensed, commercially exploited, or otherwise disclosed to unrelated third parties for their own marketing or commercial purposes.
For the avoidance of doubt, any access by REDTECH or SAVVYCORE to Personal Data shall be limited to the minimum extent reasonably necessary to perform their respective functions as the technology provider and implementation and support partner of the Portal. Such access shall not be interpreted as assuming the role of the Accrediting Partner, nor shall it transfer to REDTECH or SAVVYCORE any responsibility to verify, validate, certify, approve, reject, investigate, or otherwise determine the accuracy, authenticity, completeness, or legal effect of any information or document submitted through the Portal.
DISCLOSURE, SHARING, AND AUTHORIZED ACCESS TO PERSONAL DATA
REDTECH and SAVVYCORE recognize that all Personal Data processed through the Portal are confidential and shall be protected in accordance with applicable privacy and data protection laws. Except as otherwise authorized by the Data Subject, required by applicable law, or permitted under this Privacy Notice, Personal Data shall not be disclosed to any person who does not have a legitimate and lawful need to access such information.
The Portal has been designed to maintain strict logical segregation of information among Accrediting Partners. Each Accrediting Partner is provided with its own dedicated Portal environment through which it may receive, review, evaluate, and manage supplier information submitted specifically for its own accreditation and vendor management activities. Information submitted to one Accrediting Partner shall remain logically isolated from information submitted to any other Accrediting Partner.
Accordingly, an Accrediting Partner shall have access only to the supplier applications, Personal Data, supporting documents, communications, audit records, and other information submitted to, generated for, or maintained within its own Portal environment. An Accrediting Partner shall not be permitted to access, retrieve, search, view, download, process, or otherwise obtain information relating to suppliers accredited by or applying to another Accrediting Partner solely because both entities utilize the Portal.
Likewise, each Supplier shall have access only to its own Portal account and to the Personal Data, applications, supporting documents, communications, notifications, and records associated with that account. A Supplier shall not have access to the records, documents, applications, or Personal Data of any other Supplier unless such access is expressly authorized by the relevant Accrediting Partner or otherwise permitted under applicable law.
REDTECH and SAVVYCORE may access Personal Data processed through the Portal only to the extent reasonably necessary to perform their respective functions as the technology provider and implementation and support partner of the Portal. Such access may include activities relating to system administration, infrastructure management, cybersecurity, technical maintenance, software updates, troubleshooting, customer support, implementation, onboarding, user training, disaster recovery, business continuity, audit, system monitoring, performance optimization, regulatory compliance, legal compliance, incident investigation, and other operational activities reasonably necessary for the lawful provision of the Portal and its related services.
Any access by REDTECH or SAVVYCORE to Personal Data shall be limited to the minimum information reasonably necessary for the specific operational purpose involved and shall be subject to appropriate confidentiality obligations, internal access controls, and organizational and technical safeguards designed to prevent unauthorized processing or disclosure.
Neither REDTECH nor SAVVYCORE shall disclose Personal Data to unrelated third parties for their independent commercial, advertising, or marketing purposes. Likewise, neither REDTECH nor SAVVYCORE shall permit one Accrediting Partner to access another Accrediting Partner's supplier records, applications, supporting documents, or other confidential information except where such disclosure is expressly authorized by all affected parties or required by applicable law.
REDTECH may engage reputable third-party service providers to assist in the hosting, operation, maintenance, security, monitoring, backup, disaster recovery, communications, technical support, or other operational requirements of the Portal. Where such service providers necessarily process Personal Data in the performance of their services, REDTECH shall take reasonable steps to ensure that appropriate contractual, organizational, and technical safeguards are implemented to protect such information and that such service providers process Personal Data only in accordance with REDTECH's documented instructions and applicable law.
Personal Data may likewise be disclosed where such disclosure is necessary to comply with a lawful order of a court or tribunal, a lawful request from a government agency or regulatory authority, a subpoena, search warrant, or other compulsory legal process, or where disclosure is otherwise required or expressly authorized by applicable law. REDTECH and SAVVYCORE may also disclose Personal Data where reasonably necessary to establish, exercise, or defend legal claims, investigate fraud or unlawful activity, protect the rights, property, or safety of REDTECH, SAVVYCORE, Accrediting Partners, Suppliers, Data Subjects, or other affected persons, or respond to actual or suspected cybersecurity incidents affecting the Portal.
Except as expressly provided in this Privacy Notice or as otherwise required by applicable law, REDTECH and SAVVYCORE shall not determine which Accrediting Partner may access Supplier information, nor shall they independently disclose Supplier information to another Accrediting Partner. Access to Supplier information is determined by the Supplier's submission of information to a particular Accrediting Partner through the Portal and by the authorization rules established within the Portal for that Accrediting Partner's environment.
For the avoidance of doubt, any disclosure or access permitted under this Section shall not be construed as transferring to REDTECH or SAVVYCORE ownership of the Personal Data, authority to make procurement or accreditation decisions, or responsibility for verifying the truthfulness, authenticity, completeness, legal sufficiency, or continuing validity of information submitted through the Portal. Such responsibilities remain exclusively with the Supplier providing the information and the Accrediting Partner evaluating and relying upon such information in connection with its own accreditation, procurement, compliance, or vendor management processes.
SECURITY OF PERSONAL DATA
REDTECH recognizes that the confidentiality, integrity, and availability of Personal Data are fundamental to the operation of the Portal. Accordingly, REDTECH implements and continuously maintains reasonable and appropriate administrative, organizational, physical, and technical safeguards designed to protect Personal Data against accidental or unlawful destruction, alteration, loss, unauthorized disclosure, unauthorized access, misuse, or any other form of unlawful processing.
The security measures implemented by REDTECH are selected and periodically reviewed having regard to the nature of the Personal Data processed, the risks presented by the processing activities, prevailing industry standards, applicable legal and regulatory requirements, technological developments, and the operational requirements of the Portal. Such safeguards may be enhanced, modified, or supplemented from time to time as part of REDTECH's continuing commitment to information security and data protection.
Access to Personal Data within the Portal is governed by role-based access controls and the principle of least privilege. REDTECH grants access to Personal Data only to those officers, employees, contractors, consultants, or authorized service providers whose access is reasonably necessary for the performance of their assigned responsibilities. SAVVYCORE likewise restricts access to Personal Data only to personnel who require such access in connection with implementation, onboarding, customer support, training, technical coordination, or other authorized services relating to the Portal.
All personnel of REDTECH and SAVVYCORE who are authorized to process Personal Data are expected to observe strict confidentiality and to comply with applicable privacy laws, internal security policies, contractual confidentiality obligations, and such other information security requirements as may be implemented from time to time. Appropriate disciplinary, contractual, or legal measures may be taken against persons who unlawfully access, use, disclose, alter, or otherwise process Personal Data in violation of applicable law or company policy.
To maintain the security of the Portal, REDTECH may employ authentication mechanisms, encryption technologies where appropriate, audit logging, activity monitoring, network security controls, vulnerability assessments, software updates, backup and recovery procedures, disaster recovery mechanisms, system redundancy, and other safeguards reasonably designed to preserve the confidentiality, integrity, availability, and resilience of the Portal and the Personal Data processed therein. The specific technical safeguards implemented by REDTECH form part of its internal security program and may be modified without prior notice where reasonably necessary to address operational, technological, or cybersecurity considerations.
Suppliers and Accrediting Partners likewise share responsibility for protecting the security of the Portal. Each user is responsible for maintaining the confidentiality of account credentials, passwords, authentication devices, and other security information issued or selected for access to the Portal. Users shall ensure that only authorized personnel are granted access to their respective accounts and shall promptly update access rights whenever personnel cease to require such access or are no longer authorized to act on behalf of the organization.
Users shall immediately notify REDTECH upon becoming aware of any actual or suspected unauthorized access, compromise of user credentials, cybersecurity incident, suspected data breach, malware infection, or other event that may materially affect the security of the Portal or the confidentiality of Personal Data. Prompt reporting enables REDTECH to investigate the incident, implement appropriate containment measures, and reduce the potential impact upon affected users.
While REDTECH and SAVVYCORE implement reasonable and appropriate safeguards consistent with applicable law and generally accepted industry practices, no information technology system, communications network, cloud environment, software application, or method of electronic storage or transmission can be guaranteed to be completely secure or immune from unauthorized acts. Accordingly, REDTECH and SAVVYCORE do not warrant that the Portal will be uninterrupted, error-free, or invulnerable to cyberattacks, malicious software, unauthorized intrusions, distributed denial-of-service attacks, telecommunications failures, hardware failures, software defects, force majeure events, or other circumstances beyond their reasonable control.
Nothing in this Privacy Notice shall be construed as creating an obligation on the part of REDTECH or SAVVYCORE to guarantee the absolute security of the Portal or the complete prevention of every cybersecurity incident. Liability for any security incident shall be determined in accordance with applicable law, the specific facts and circumstances of the incident, and the respective obligations of the parties. The occurrence of an unauthorized cyberattack, unlawful intrusion, malicious act, or other security incident shall not, by itself, establish negligence, fault, or liability on the part of REDTECH or SAVVYCORE.
The implementation of security measures by REDTECH and SAVVYCORE does not diminish the independent responsibility of each Accrediting Partner and Supplier to implement appropriate internal safeguards over their own devices, networks, personnel, records, and information systems. Each Accrediting Partner and Supplier remains responsible for protecting the confidentiality of Personal Data within its own organization and for complying with its respective obligations under applicable privacy, procurement, cybersecurity, and information security laws.
RETENTION, DELETION, AND DISPOSAL OF PERSONAL DATA
REDTECH and SAVVYCORE retain Personal Data only for as long as reasonably necessary to fulfil the purposes described in this Privacy Notice, to provide and support the Portal, to comply with applicable contractual, legal, regulatory, accounting, taxation, audit, and operational requirements, to protect legitimate business interests, to resolve disputes, to establish, exercise, or defend legal claims, or as otherwise permitted or required by applicable law.
The applicable retention period shall depend upon the nature of the Personal Data involved, the purpose for which such information was collected or generated, the retention requirements established by the relevant Accrediting Partner, applicable laws and regulations, contractual obligations, operational requirements, and the legitimate interests of REDTECH, SAVVYCORE, the Accrediting Partner, the Supplier, and other affected parties.
The termination, suspension, expiration, or non-renewal of a Supplier's accreditation or an Accrediting Partner's subscription to the Portal shall not automatically require the immediate deletion of Personal Data maintained within the Portal. REDTECH may continue to retain such information where retention remains reasonably necessary to complete pending transactions, preserve audit trails, comply with legal or regulatory obligations, maintain system integrity, restore backup data, investigate incidents, resolve disputes, enforce contractual rights, protect legitimate business interests, or satisfy other lawful purposes recognized under applicable law.
Where Personal Data are no longer necessary for the purposes for which they were collected and no legal, contractual, regulatory, operational, or legitimate business purpose justifies their continued retention, REDTECH shall take reasonable steps to securely delete, anonymize, archive, or otherwise dispose of such Personal Data in a manner appropriate to the nature of the information and consistent with applicable law and generally accepted information security practices.
The deletion of Personal Data from active production systems does not necessarily require the immediate removal of such information from archival media, disaster recovery systems, system backups, audit logs, or other security and business continuity records. Such information may continue to be retained for a reasonable period until the applicable backup media are overwritten, retired, securely destroyed, or otherwise disposed of in accordance with REDTECH's internal retention and information security policies, provided that access to such retained information remains appropriately restricted.
Where an Accrediting Partner instructs REDTECH, pursuant to applicable contractual arrangements, to delete or return Personal Data under its control, REDTECH shall use commercially reasonable efforts to comply with such instructions, subject always to applicable legal obligations, the protection of the rights and legitimate interests of REDTECH and SAVVYCORE, the existence of lawful retention requirements, the preservation of system integrity, disaster recovery requirements, audit obligations, or the establishment, exercise, or defense of legal claims.
Nothing in this Privacy Notice shall require REDTECH or SAVVYCORE to delete Personal Data where such deletion would violate applicable law, impair compliance with legal or regulatory obligations, compromise ongoing investigations, prejudice the resolution of disputes, interfere with the enforcement of contractual rights, undermine information security measures, or otherwise adversely affect the lawful operation, maintenance, security, or integrity of the Portal.
The retention of Personal Data by REDTECH and SAVVYCORE pursuant to this Section shall not be construed as ownership of such information, nor shall it transfer to REDTECH or SAVVYCORE responsibility for determining the continuing accuracy, authenticity, legal sufficiency, or commercial relevance of the retained information. Responsibility for the substantive accuracy, completeness, and validity of Supplier information and supporting documents shall remain with the Supplier that submitted such information and the Accrediting Partner that collected, evaluated, maintained, or relied upon such information in connection with its accreditation, procurement, compliance, or vendor management processes.
THIRD-PARTY SERVICE PROVIDERS AND CROSS-BORDER PROCESSING
In the course of operating, maintaining, securing, and continuously improving the Portal, REDTECH may engage independent third-party service providers to perform services that are reasonably necessary for the operation and support of the Portal. Such services may include, among others, cloud hosting, infrastructure management, data storage, cybersecurity, disaster recovery, data backup, system monitoring, software development, application programming interfaces (APIs), electronic communications, authentication services, technical support, payment processing, analytics, and other technology or operational services required for the efficient delivery of the Portal.
Where the performance of such services reasonably requires access to or processing of Personal Data, REDTECH shall take appropriate measures to ensure that such third-party service providers process Personal Data only for the purposes for which they have been engaged, only in accordance with REDTECH's documented instructions where applicable, and subject to appropriate contractual, organizational, and technical safeguards designed to protect the confidentiality, integrity, and security of Personal Data.
REDTECH endeavors to engage only reputable service providers that maintain security measures and privacy standards appropriate to the nature of the services being provided. However, each independent service provider remains responsible for complying with its own contractual and legal obligations applicable to the services it performs.
To support the availability, reliability, scalability, resilience, and security of the Portal, Personal Data may be processed, stored, transmitted, backed up, replicated, or otherwise made accessible through information technology infrastructure located within or outside the Republic of the Philippines. Such processing may occur where cloud infrastructure, backup facilities, disaster recovery environments, content delivery networks, software platforms, or other technology services operate across multiple jurisdictions.
Where Personal Data are transferred outside the Philippines, REDTECH shall take reasonable steps to ensure that such transfers are undertaken in accordance with the Data Privacy Act of 2012, its Implementing Rules and Regulations, applicable issuances of the National Privacy Commission, and other applicable laws governing cross-border transfers of Personal Data. Where appropriate, REDTECH shall implement contractual safeguards or other lawful mechanisms reasonably designed to ensure that Personal Data continue to receive a level of protection substantially comparable to that required under Philippine law.
The use of third-party technology providers shall not be construed as transferring ownership of Personal Data to such providers. Any Personal Data processed by third-party service providers shall remain subject to the confidentiality obligations, contractual restrictions, and applicable legal requirements governing the services they perform on behalf of REDTECH.
Nothing in this Privacy Notice shall be interpreted as making REDTECH responsible for the independent privacy practices, security controls, or legal compliance of third-party services that are not owned, operated, or controlled by REDTECH. Where the Portal permits integration with or access to independent third-party websites, applications, payment gateways, communication platforms, identity verification providers, government systems, or other external services, such services shall remain governed by their own respective privacy notices, terms of use, and data protection practices. Users are encouraged to review the applicable privacy policies of such third parties before providing Personal Data through their respective platforms.
The engagement of third-party service providers by REDTECH shall not diminish the independent responsibilities of Suppliers and Accrediting Partners under applicable privacy laws. Suppliers remain responsible for ensuring that the Personal Data and documents they submit through the Portal may lawfully be processed for the intended purposes, while Accrediting Partners remain responsible for determining the necessity, proportionality, and lawfulness of the Personal Data they require from Suppliers in connection with their own accreditation, procurement, compliance, and vendor management processes.
Except as expressly provided in this Privacy Notice, required by applicable law, or reasonably necessary for the operation and support of the Portal, REDTECH and SAVVYCORE shall not disclose Personal Data to unrelated third parties for their own independent commercial, advertising, profiling, or marketing purposes without the appropriate lawful basis under applicable law.
RIGHTS OF DATA SUBJECTS
REDTECH and SAVVYCORE recognize and respect the rights of Data Subjects under Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012, its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission. Subject to applicable law and the limitations prescribed therein, every Data Subject whose Personal Data are processed through the Portal may exercise the rights granted under the Data Privacy Act.
A Data Subject may request confirmation as to whether Personal Data relating to him or her are being processed through the Portal and, where applicable, may request access to such Personal Data together with information concerning the purposes of processing, the categories of Personal Data involved, the sources from which such information was obtained, the recipients to whom such information has been disclosed where authorized by law, and such other information as may be required under applicable privacy laws.
Where Personal Data maintained through the Portal are inaccurate, incomplete, outdated, misleading, or unlawfully obtained, a Data Subject may request their correction, rectification, completion, updating, blocking, or deletion, as may be appropriate under applicable law. REDTECH and SAVVYCORE shall evaluate such requests in accordance with their respective responsibilities under this Privacy Notice and applicable law.
Where the requested Personal Data are maintained on behalf of, submitted to, or controlled by an Accrediting Partner, REDTECH and SAVVYCORE may coordinate with the relevant Accrediting Partner to facilitate the processing of the request. Nothing in this Privacy Notice shall require REDTECH or SAVVYCORE to unilaterally alter, delete, suppress, release, or otherwise modify records that are maintained under the authority or control of an Accrediting Partner where doing so would exceed their respective authority or conflict with applicable law, contractual obligations, or the legitimate interests of the relevant Accrediting Partner.
Where processing is based solely upon the consent of the Data Subject, such consent may be withdrawn at any time in the manner prescribed by applicable law. The withdrawal of consent shall not affect the lawfulness of any processing undertaken prior to such withdrawal, nor shall it affect processing carried out on another lawful basis recognized under the Data Privacy Act of 2012.
A Data Subject may likewise object to the processing of Personal Data or exercise such other rights as may be available under applicable privacy laws, including, where legally applicable, the right to data portability and the right to seek damages for violations of the Data Privacy Act. Such rights shall be exercised in accordance with applicable law and subject to the limitations, exceptions, and conditions recognized thereunder.
The exercise of any data subject right shall not prejudice the rights and legitimate interests of REDTECH, SAVVYCORE, Accrediting Partners, Suppliers, other Data Subjects, or third parties. REDTECH and SAVVYCORE reserve the right to decline, defer, or limit the implementation of a request where compliance would violate applicable law, compromise information security, prejudice an ongoing investigation, interfere with legal proceedings, impair the rights of another person, disclose confidential business information, reveal trade secrets, breach contractual confidentiality obligations, or otherwise exceed the authority legally vested in REDTECH or SAVVYCORE.
REDTECH may require reasonable proof of identity, authority, or representation before acting upon any request relating to Personal Data. Requests that are fraudulent, manifestly unfounded, repetitive, excessive, or otherwise constitute an abuse of rights may be denied or subjected to reasonable verification procedures as permitted by applicable law.
The exercise of rights under this Privacy Notice shall not relieve Suppliers or Accrediting Partners of their independent obligations under applicable privacy laws, nor shall it transfer to REDTECH or SAVVYCORE the responsibility for determining the accuracy, authenticity, completeness, or legal sufficiency of information and documents submitted through the Portal. The respective roles and responsibilities established under this Privacy Notice shall continue to apply notwithstanding the exercise of any right by a Data Subject.
CONTACT INFORMATION AND EXERCISE OF PRIVACY RIGHTS
Data Subjects who wish to exercise any of their rights under the Data Privacy Act of 2012, request access to or correction of their Personal Data, withdraw consent where applicable, report a suspected privacy incident, or raise any concern regarding the processing of their Personal Data through the Portal may contact REDTECH through its designated Data Protection Officer or authorized privacy representative to protect the confidentiality and security of Personal Data, REDTECH may require the requesting party to provide reasonable proof of identity, authority, or representation before acting upon any request. REDTECH may likewise request additional information where reasonably necessary to verify the identity of the requester, clarify the nature of the request, or determine the lawful basis for granting the requested action.
Where the Personal Data that are the subject of the request are maintained on behalf of, controlled by, or submitted to an Accrediting Partner, REDTECH may coordinate with the relevant Accrediting Partner in facilitating the appropriate response. Nothing in this Privacy Notice shall require REDTECH or SAVVYCORE to take actions that are legally reserved to the relevant Accrediting Partner or that would conflict with applicable law, contractual obligations, or the legitimate rights of another party.
REDTECH shall endeavour to acknowledge and respond to requests within a reasonable period and in accordance with the Data Privacy Act of 2012, its Implementing Rules and Regulations, and other applicable laws.
AMENDMENTS TO THIS PRIVACY NOTICE
REDTECH reserves the right to amend, supplement, revise, or update this Privacy Notice from time to time to reflect changes in applicable laws and regulations, decisions or issuances of the National Privacy Commission, technological developments, enhancements to the Portal, changes in business operations, or other legitimate operational or legal requirements.
Any revised version of this Privacy Notice shall become effective on the date specified therein, unless a different effectivity date is expressly provided. Where required by applicable law or where the amendments materially affect the processing of Personal Data, REDTECH shall provide appropriate notice through the Portal, electronic mail, or such other reasonable means of communication as REDTECH may determine.
The continued access to or use of the Portal following the effectivity of any amendment shall constitute acknowledgment of the updated Privacy Notice, without prejudice to any rights afforded to Data Subjects under applicable law.
GOVERNING LAW
This Privacy Notice shall be governed by and construed in accordance with the laws of the Republic of the Philippines, particularly Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012, its Implementing Rules and Regulations, and all other applicable laws, rules, regulations, and lawful issuances governing the processing and protection of Personal Data.
Nothing contained in this Privacy Notice shall be interpreted as limiting or waiving any right, remedy, obligation, or protection provided under applicable privacy and data protection laws.
EFFECTIVITY
This Privacy Notice shall take effect on July 1, 2026 and shall remain in full force and effect until amended, revised, or replaced by REDTECH.
REDTECH remains committed to ensuring that Personal Data entrusted through the Portal are processed lawfully, fairly, transparently, and responsibly, consistent with the principles of transparency, legitimate purpose, and proportionality under the Data Privacy Act of 2012. REDTECH shall continue to implement reasonable and appropriate safeguards to protect Personal Data while providing a secure, reliable, and efficient technology platform for Suppliers and Accrediting Partners.