Supplier contract template
Data Processing Terms
These terms form a starting template for a supplier that processes personal information on behalf of Cebu OK Travel. They become binding only when both parties accept them in a signed agreement or written service contract.
Parties and roles
The controller is Cebu OK Travel Services, trading as Cebu OK Travel, DTI Registration No. 7236268, at Emilio Osmeña Street, Cebu City, Cebu 6000, Philippines. The processor is the supplier identified in the signed agreement. Each party remains responsible for obligations assigned to it by applicable privacy law.
Documented instructions
The processor will process personal information only for the service, duration, purposes, data types, and customer groups described in the signed agreement and only on documented instructions from Cebu OK Travel, unless the law requires otherwise.
Confidentiality and security
The processor will limit access to authorized personnel under confidentiality duties. It will maintain appropriate organizational, physical, and technical safeguards, including access control, secure transmission, vulnerability management, backups where relevant, and secure disposal.
Subprocessors and transfers
The processor will disclose material subprocessors and obtain authorization where required. It remains responsible for equivalent privacy and security duties. Cross-border processing must use safeguards required by applicable law.
Customer rights and cooperation
The processor will promptly assist with verified access, correction, deletion, portability, objection, restriction, and consent-withdrawal requests. It will also assist with privacy assessments, regulator questions, and evidence of compliance.
Security incidents
The processor will notify Cebu OK Travel without undue delay after learning of a personal-data incident. The notice must describe the incident, affected information, likely impact, containment, remediation, and contact person. The processor will preserve relevant evidence and support legally required notifications.
Return, deletion, and audit
At the end of the service, the processor will return or securely delete personal information unless law requires retention. It will provide information reasonably needed to verify compliance and address material findings.
Details required before signature
Every executed agreement must identify the processor's legal name and address, service description, processing duration, data categories, customer groups, security measures, subprocessors, transfer locations, retention rules, incident contact, liability terms, governing law, effective date, and authorized signatures.
Contract requests: [email protected].