ISETPrivacy Notice
Legal · Privacy Notice · RA 10173

Privacy Notice

How ISET processes personal data — what we collect, why, how long we keep it, and the rights you hold under the Data Privacy Act of 2012.

Effective 11 June 2026 · ISET

1Who is responsible

ISET Inc. ("ISET", "we") processes personal data in connection with this site, the Console, and the registry, acting as a personal information controller under Republic Act No. 10173 and establishing its registration with the National Privacy Commission. Privacy matters: dpo@iset.finance.

2What we collect, and why

ContextDataPurpose · basis
Contact formName, organisation, email, your messageAnswering your inquiry · consent
Console accountEmail; passkey credential identifier and public key (never a password, never your biometrics — those stay on your device)Secure sign-in · contract and legitimate interest
Issuer applicationInstitution details, contact persons, due-diligence material you provideQualification review · steps prior to a contract
Registry eventsSigned lifecycle events (issue, consent, transfer) with their references and timestampsThe registry's evidentiary function · legal obligation and legitimate interest
Session cookieiset_session — a signed session tokenKeeping you signed in · strictly necessary. We run no analytics and no advertising trackers.

3What we do not do

4Where data is processed

Data is processed on infrastructure operated under common trusteeship with this site — including the secured identity and audit engine that signs and verifies records — and on the content-delivery and email infrastructure necessary to serve the site and answer mail. Processors act under instructions limited to these purposes.

5Retention

Inquiries are kept for as long as needed to answer them and for a reasonable record thereafter. Account data is kept while the account exists. Registry events are different: they form a hash-chained evidentiary ledger, and their integrity depends on retention — they are kept for as long as the records they evidence may have legal effect. Where erasure is requested, we erase what the evidentiary function does not require.

6Your rights

Under RA 10173 you may request access, correction, erasure or blocking, object to processing, ask for a copy of your data in a portable form, and claim damages for violations. Write to dpo@iset.finance — we answer within the periods the law provides. You may also complain to the National Privacy Commission (privacy.gov.ph).

7Security

Sign-in is phishing-resistant (passkeys, WebAuthn). Lifecycle events are signed with post-quantum cryptography (NIST FIPS 204) and hash-chained, so tampering is detectable. Access to gated material is restricted to verified counterparties on an approved list.

8Changes

We may revise this notice by posting an updated version with a new effective date. Material changes affecting account holders are notified by email.