How ISET processes personal data — what we collect, why, how long we keep it, and the rights you hold under the Data Privacy Act of 2012.
ISET Inc. ("ISET", "we") processes personal data in connection with this site, the Console, and the registry, acting as a personal information controller under Republic Act No. 10173 and establishing its registration with the National Privacy Commission. Privacy matters: dpo@iset.finance.
| Context | Data | Purpose · basis |
|---|---|---|
| Contact form | Name, organisation, email, your message | Answering your inquiry · consent |
| Console account | Email; passkey credential identifier and public key (never a password, never your biometrics — those stay on your device) | Secure sign-in · contract and legitimate interest |
| Issuer application | Institution details, contact persons, due-diligence material you provide | Qualification review · steps prior to a contract |
| Registry events | Signed lifecycle events (issue, consent, transfer) with their references and timestamps | The registry's evidentiary function · legal obligation and legitimate interest |
| Session cookie | iset_session — a signed session token | Keeping you signed in · strictly necessary. We run no analytics and no advertising trackers. |
Data is processed on infrastructure operated under common trusteeship with this site — including the secured identity and audit engine that signs and verifies records — and on the content-delivery and email infrastructure necessary to serve the site and answer mail. Processors act under instructions limited to these purposes.
Inquiries are kept for as long as needed to answer them and for a reasonable record thereafter. Account data is kept while the account exists. Registry events are different: they form a hash-chained evidentiary ledger, and their integrity depends on retention — they are kept for as long as the records they evidence may have legal effect. Where erasure is requested, we erase what the evidentiary function does not require.
Under RA 10173 you may request access, correction, erasure or blocking, object to processing, ask for a copy of your data in a portable form, and claim damages for violations. Write to dpo@iset.finance — we answer within the periods the law provides. You may also complain to the National Privacy Commission (privacy.gov.ph).
Sign-in is phishing-resistant (passkeys, WebAuthn). Lifecycle events are signed with post-quantum cryptography (NIST FIPS 204) and hash-chained, so tampering is detectable. Access to gated material is restricted to verified counterparties on an approved list.
We may revise this notice by posting an updated version with a new effective date. Material changes affecting account holders are notified by email.