Privacy Policy
Last updatedOct 1, 2026Privacy Policy
Analytica Business Solutions Inc. ("we", "us" or "our") operates The Cloud CAS, a cloud-based computerized accounting system, and the website at thecloudcas.com (together, the "Service"). We respect your privacy and process personal data in accordance with Republic Act No. 10173, the Data Privacy Act of 2012, its Implementing Rules and Regulations, and issuances of the National Privacy Commission ("NPC").
This policy explains what personal data we collect, why, who we share it with, how long we keep it, and the rights you have.
1. Who this policy covers
This policy applies to:
- Website visitors, including people who send us an inquiry or demo request;
- Users of The Cloud CAS, meaning the people our customers give access to their accounts; and
- Individuals whose data our customers put into The Cloud CAS, such as the buyers named on our customers' invoices.
For that last group, our customer (the business that issued the invoice) is the personal information controller and decides how and why the data is processed. We act as their personal information processor, processing the data only on their instructions. If you are one of their buyers and have a question about your data, please contact the business you bought from first; we will assist them in responding.
2. Personal data we collect
When you contact us through the website
| Data | Why we collect it |
|---|---|
| Name, work email, company, and optionally your phone number and job title | To reply to your inquiry and arrange a demo or quotation |
| Optional details about your business (monthly invoice volume, sales channels) and your message | To understand your needs and prepare the right walkthrough or quote |
| The type of inquiry and the date you agreed to this policy | To route your message and keep a record of your consent |
| IP address and browser information (user agent) | To protect the form against spam and abuse |
Cookies and analytics on our website
Our website uses Google Analytics, a web analytics service provided by Google, to understand how visitors find and use the site, such as which pages are viewed and how long visits last. Google Analytics uses cookies and collects information such as your approximate location, device and browser type, and the pages you visit. We use this information only in aggregate to improve the website, and we do not use it to identify you. Google processes this data under its own privacy policy.
You can block or delete cookies through your browser settings, or install the Google Analytics Opt-out Browser Add-on. Blocking these cookies does not affect your ability to use our website or contact us. Our website does not use advertising cookies.
When you use The Cloud CAS
- Account information: name, email address, the companies you belong to and your role, and your password (stored only in hashed form).
- Security information: two-factor authentication settings and recovery codes (stored encrypted), and manager PINs (stored in hashed form).
- Activity information: an audit trail of actions you take in the Service, such as creating, finalizing, cancelling or emailing documents, with the date and time.
- Technical information: IP address, browser information, and a session cookie that keeps you signed in. This cookie is strictly necessary for the Service to work.
Data our customers put into The Cloud CAS
Depending on how a customer uses the Service, this can include their buyers' names, addresses, email addresses, Taxpayer Identification Numbers (TINs), order and payment details, product serial numbers, and scanned documents such as signed credit memos and refund vouchers.
3. How we use personal data
We use personal data to:
- respond to inquiries, provide demos and prepare quotations;
- create and administer accounts, and authenticate Users;
- provide the Service, including generating invoices and emailing them to buyers on our customers' instructions;
- keep the Service secure, including detecting and preventing fraud, abuse and unauthorized access;
- provide customer support and send service-related notices (such as security alerts and changes to our terms);
- maintain audit trails and records that our customers need for tax and regulatory compliance; and
- comply with our legal obligations and respond to lawful requests from government authorities.
We do not sell personal data, and we do not use our customers' data to market to their buyers.
4. Our legal bases
Under Sections 12 and 13 of the Data Privacy Act, we process personal data on the following bases, as applicable:
- Consent, for example when you submit the contact form and agree to this policy;
- Contract, to provide the Service to our customers and their Users, and to take steps you request before entering into a contract;
- Legal obligation, including tax, accounting and record-keeping requirements; and
- Legitimate interests, such as securing the Service and preventing fraud, where these are not overridden by your fundamental rights and freedoms.
You may withdraw your consent at any time by contacting us. Withdrawal does not affect processing that already took place, or processing we carry out on another legal basis.
5. Sensitive personal information
We do not ask for sensitive personal information as defined by the Data Privacy Act through our website. Some data processed in the Service, such as TINs, is classified as sensitive personal information because it is issued by a government agency. We process it only to provide the Service on our customers' instructions and where the law permits, and protect it with the safeguards described below.
6. Who we share personal data with
We share personal data only as needed for the purposes above, with:
- Service providers that host and operate the Service for us, under contracts that require them to protect the data and use it only on our instructions. These include providers of cloud hosting and databases, file storage for PDF invoices and uploaded documents, email delivery, and website analytics;
- Our customers, who can see the data of the Users and records in their own accounts;
- Government authorities, such as the Bureau of Internal Revenue, where required by law or a lawful order, or where a customer directs us to transmit records on their behalf; and
- A successor entity, if we are involved in a merger, acquisition or sale of assets, in which case we will require it to honor this policy.
Transfers outside the Philippines
Some of our service providers may store or process data outside the Philippines. When this happens, we remain responsible for the data and require the recipient to provide a level of protection comparable to the Data Privacy Act.
7. How long we keep personal data
- Inquiries from the website are kept for up to two (2) years from our last contact with you, unless you become a customer, in which case they are kept with your account records.
- Account and activity data are kept for as long as the customer's account is active and then for the period stated in our Terms and Conditions, unless a longer period is required by law.
- Customer records, such as invoices and books of accounts, are kept for as long as the customer's subscription is active. Philippine tax laws require businesses to keep books and records for a set number of years; customers are responsible for exporting and keeping their records for those periods, and may agree with us in writing to keep them for longer.
- Backups are kept for a limited period and deleted on a rolling schedule.
When personal data is no longer needed, we delete or anonymize it securely.
8. How we protect personal data
We use organizational, physical and technical measures appropriate to the risk, including:
- encryption of data in transit (HTTPS) and encryption of secrets such as two-factor recovery codes;
- logical separation of each customer's data, so that Users can only see the companies they belong to;
- role-based access controls, optional two-factor authentication, and rate limiting of sign-in and public forms;
- audit trails of significant actions in the Service; and
- access to production systems limited to authorized personnel bound by confidentiality obligations.
No system is completely secure. If a personal data breach occurs that is likely to give rise to a real risk of serious harm, we will notify the NPC and affected individuals (or, for customer data, the affected customer) as required by law, generally within seventy-two (72) hours of knowledge of the breach.
9. Your rights
Under the Data Privacy Act, you have the right to:
- be informed about whether and how your personal data is processed;
- access your personal data;
- object to processing, including processing based on consent or legitimate interests;
- correct inaccurate or incomplete data;
- erasure or blocking of data that is unlawfully obtained, no longer necessary or processed without a valid basis;
- data portability, to obtain a copy of your data in a commonly used electronic format;
- damages, if you suffer harm due to inaccurate, incomplete, outdated, false or unlawfully obtained data or its unauthorized use; and
- file a complaint with the National Privacy Commission.
Some rights are limited by law. For example, we cannot erase an issued invoice or book entry that a customer is legally required to keep; in that case we will explain why and restrict further use of the data where possible.
To exercise your rights, contact our Data Protection Officer using the details below. We may need to verify your identity first, and we will respond within the period required by law. If your request concerns data a customer put into the Service, we will refer it to that customer and assist them in responding.
10. Children
The Service is meant for businesses and is not directed at children. We do not knowingly collect personal data from anyone under eighteen (18) through our website.
11. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page and change the "Last updated" date above. If a change is significant, we will also notify account administrators by email or in the Service.
12. Contact our Data Protection Officer
Data Protection Officer Analytica Business Solutions Inc. Guagua, Pampanga, Philippines Email: dpo@thecloudcas.com
You may also contact the National Privacy Commission at privacy.gov.ph.