Skip to main content
Data Privacy Notice

Processing of personal data on bughawinnovations.ph


This is the formal notice required under Section 14 of the Data Privacy Act of 2012 and Articles 13 and 14 of the GDPR. It identifies the Controller, states every lawful basis on which personal data is processed, lists every category of recipient, specifies every retention period, and sets out how each data subject right is to be exercised. Every statement below corresponds to a verifiable processing operation in the site.

1. Processing at a glance

No advertising, no profiling, no analytics without consent.


  • No advertising network tags, no retargeting audiences, and no behavioural advertising whatsoever are deployed on this website. No processing for the purposes of automated user profiling or automated decision-making, within the meaning of GDPR Article 22 or DPA Section 11, is carried out.
  • Google Tag Manager and Google Analytics 4 are not instantiated and no network request to Google is dispatched prior to the visitor\u2019s express acceptance of analytics in the consent management banner. Visitors who decline analytics, or who simply decline to answer the banner, are not subject to client-side analytics processing at all.
  • Contents submitted through the enquiry and hotel-interest forms are transmitted to the Controller by electronic mail and to the Controller\u2019s customer relationship management system. No form content — whether name, room count, or message body — is ever transmitted to Google Analytics or to any third-party analytics provider.
  • Personal data is not sold, bartered, or otherwise disclosed to any third party for the independent marketing purposes of that third party. The Controller does not operate a data brokerage practice.
2. Controller identity

Identity and contact details of the Personal Information Controller.


For the purposes of Section 3(i) of the DPA and Article 4(7) of the GDPR, the personal information controller and data controller (the "Controller") is:

Bughaw Innovations

Metro Manila, Philippines

E-mail: hello@bughawinnovations.ph

The Controller has not formally designated a separate Data Protection Officer within the meaning of DPA Rule VII or GDPR Article 37, having assessed that its processing operations do not meet the thresholds for mandatory designation set out in NPC Advisory Opinion 2018-01 and GDPR Article 37(1). All correspondence relating to data protection, including the exercise of data subject rights, notifications of personal data breach, and any complaint addressed to the Controller, should nevertheless be directed to the e-mail address above and will be handled by a duly authorised representative of the Controller.

The Controller acknowledges and accepts that a response will be provided within fifteen (15) working days of receipt of a duly perfected data subject request, consistent with the period prescribed by the National Privacy Commission for the exercise of the rights of the data subject.

3. Lawful bases of processing

Categories of personal data processed, and the legal basis for each.


The categories of personal data processed on or through this website, and the lawful basis for each processing operation as required by Section 12 of the DPA and Article 6 of the GDPR, are disclosed in this section.

  1. Voluntarily submitted enquiry data. — Full name, e-mail address, organisation or hotel property name, DOT star rating, approximate room count, product interest selections, and free-form message body submitted through the /contact, /for-hotels, and /inquiry routes, together with the source attribution metadata described in paragraph 3 below.
    Lawful basis: The consent of the data subject (DPA, Sec. 12(a); GDPR, Art. 6(1)(a)), and, where a commercial discussion is actively pursued, the steps taken at the request of the data subject prior to the entering into of a contract (DPA, Sec. 12(b); GDPR, Art. 6(1)(b)).
  2. Source attribution metadata. — Campaign parameters (UTM source, medium, campaign, term, content) as transmitted in the query string of the first landing URL, the hostname of any HTTP referrer, the path of the first landing page, and an ISO-8601 capture timestamp.
    Lawful basis: The legitimate interests pursued by the Controller (DPA, Sec. 12(f); GDPR, Art. 6(1)(f)) in being able to attribute inbound enquiries to the correct outreach programme so that programme efficacy may be measured. The Controller considers that this processing is proportionate and does not override the fundamental rights and freedoms of the data subject, particularly since no identifier is created and the data is retained for a limited period.
  3. Engagement tier counters. — Session-scoped counts of evidence figures and page impressions read during the visit, together with a derived engagement tier (cold / engaged / qualified).
    Lawful basis: The legitimate interests pursued by the Controller (DPA, Sec. 12(f); GDPR, Art. 6(1)(f)) in appropriately calibrating the substance of a reply to an enquiry so that a visitor who has studied the evidence base is not sent introductory material that they have already read. No identifier is created by this processing.
  4. Approximate geographic location. — Country, administrative region, and city derived from the Internet Protocol (IP) address of the inbound request. The IP address itself is resolved at the edge of the hosting stack or, where the hosting stack does not already supply it, transmitted transiently to a third-party resolver (ipwho.is) and discarded immediately after the resolution is returned. The IP address is not stored alongside the enquiry record.
    Lawful basis: The legitimate interests pursued by the Controller (DPA, Sec. 12(f); GDPR, Art. 6(1)(f)) in understanding the geographic spread of visitor interest so that commercial outreach may be appropriately sequenced.
  5. Analytics events. — Page view events, outbound link and navigation click events, evidence-figure view events, and product intent events, together with the pseudonymous Google Analytics 4 client identifier and the GA4 Consent Mode storage signals.
    Lawful basis: The freely given, specific, informed, and unambiguous consent of the data subject (DPA, Sec. 12(a); GDPR, Art. 6(1)(a)), signified by the affirmative act of accepting analytics in the consent management banner. Consent may be withdrawn at any time, as provided in Section 10 below.
  6. Rate-limiting state. — The IP address of an inbound form submission, held transiently in application memory for the sole and exclusive purpose of rate-limiting repeated form submissions from the same address.
    Lawful basis: Alternately — (i) compliance with a legal obligation to which the Controller is subject (DPA, Sec. 12(c); GDPR, Art. 6(1)(c)) in respect of the suppression of automated abuse of its contact channels; and (ii) the legitimate interests pursued by the Controller (DPA, Sec. 12(f); GDPR, Art. 6(1)(f)) in maintaining the integrity and availability of its systems.

No processing of sensitive personal information or special categories of personal data. — The Controller does not process any category of data described as "sensitive personal information" under Section 3(l) of the DPA or as "special categories of personal data" under GDPR Article 9, including data relating to health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data, or data concerning sex life or sexual orientation. No processing of such data therefore takes place under Section 13 of the DPA or GDPR Article 9.

4. Cookies and storage

Cookies, local storage, and automated collection during browsing.


The following first-party and (where consented) third-party cookies and browser storage mechanisms are placed. This register is maintained for the purposes of DPA Rule VIII, NPC Advisory Opinion No. 2017-01, and Recital 30 of the GDPR.

Google Analytics 4 and Vercel Analytics are each gated behind the same consent choice and are instantiated only after the visitor has affirmatively accepted analytics in the consent management banner. What is transmitted to the analytics providers is limited to page paths viewed, navigation and outbound link clicks, evidence-figure view events, and any campaign code transmitted in the landing URL. Form contents are never transmitted to an analytics provider.

Register of cookies and browser storage mechanisms deployed by bughawinnovations.ph
NameTypeProcessing purposeRetentionLawful basis
bughaw_analytics_consentFirst-party cookieRecords the visitor’s acceptance or rejection of analytics storage so that the consent banner is not re-presented on every subsequent page impression.180 days from last choiceNecessary cookie (DPA, Rule V; GDPR Art. 6(1)(f))
bughaw_attributionFirst-party cookieCaptures the provenance of a first visit — campaign parameters (UTM source, medium, campaign, term, content), the hostname of any referring site, the landing path, and a capture timestamp. Attached, if at all, only to an enquiry subsequently submitted so that the Controller may attribute the enquiry to the correct outreach channel.30 days from captureLegitimate interest (DPA, Sec. 12(f); GDPR Art. 6(1)(f))
bg_evidence, bg_pages, bg_tier, bg_seen_article, bg_from_articleFirst-party session storageMaintains session-scoped counters of evidence figures and page impressions read, and a derived engagement tier. If a form is submitted these values accompany it so that the Controller may appropriately tailor its reply. No persistent identifier is created and no value is transmitted to third-party processors without the visitor’s prior consent to analytics.Until the browsing session is terminatedLegitimate interest (DPA, Sec. 12(f); GDPR Art. 6(1)(f))
_ga, _ga_<STREAM_ID>, _gid, _gatThird-party cookie (Google Analytics 4)Provides Google Analytics 4 with a pseudonymous client identifier so that page and traffic counts are not double-counted per visitor. Written only after the visitor has affirmatively granted analytics consent; swept from storage upon withdrawal of that consent.Up to 2 years, or immediately upon withdrawal of consentConsent (DPA, Sec. 12(a); GDPR Art. 6(1)(a))

Consent to the storage of analytics cookies is revocable at any time, as of right. The Controller provides the mechanism below, on the face of this Notice, for the immediate amendment of a previous choice. Upon withdrawal of consent the Controller\u2019s client-side code will sweep all cookies written by Google Analytics 4 from the visitor\u2019s browser and dispatch an updated consent-state signal to Google Tag Manager so that further storage ceases immediately, without requiring a page reload.

Your current setting: Checking…

5. Enquiry processing

Processing of enquiry and hotel-interest form submissions.


Submissions made through the contact form and the hotel-interest form are processed as follows. Each processing step is disclosed in accordance with Section 14 of the DPA and Articles 13(1)(c) and 14(1)(c) of the GDPR.

  1. Validation and anti-abuse screening. — The submission is validated for field presence and field format, including electronic mail address format and length bounds. A server-side anti-bot field (honeypot) is evaluated; if it contains a value the submission is discarded without further processing and without notification that it has been discarded, consistent with the need not to signal the existence of the control to automated submitters. The sole data value logged in this connection is the submitting electronic mail address, solely for the purpose of diagnosing false positives.
  2. Geographic resolution. — The IP address of the inbound request is extracted and resolved to an approximate country, region, and city, either directly from geographic headers supplied at the edge of the hosting stack (Cloudflare IP-country, IP-region, and IP-city headers) or, where those headers are not available, by a single transient lookup to the ipwho.is geolocation service. The IP address is not retained with the resulting enquiry record; it is also held briefly in application memory solely for the purpose of rate-limiting repeated submissions.
  3. Attribution and engagement metadata. — Any existing attribution cookie and engagement session-storage values, together with the pseudonymous GA4 client identifier (if, and only if, analytics consent has been granted), are serialised as an attribution block. The purpose is to allow the Controller\u2019s commercial team to identify which outreach programme was responsible for the enquiry and whether the enquirer had already reviewed the evidence base on the site.
  4. Customer relationship record. — A record of the enquiry, inclusive of the attribution block, is created in the Controller\u2019s customer relationship management system.
  5. Internal notification. — An electronic mail message containing the full enquiry record and the attribution block is transmitted to the Controller\u2019s authorised internal recipients by means of the Controller\u2019s electronic mail service provider.
  6. Submitter confirmation. — For the /contact and /for-hotels routes a confirmation electronic mail is transmitted back to the electronic mail address supplied by the submitter, confirming receipt and stating the Controller\u2019s expected response window. No confirmation is sent where the anti-bot field is tripped.
6. Recipients and transfers

Categories of recipients, and cross-border transfer safeguards.


Personal data is disclosed only to the following categories of processor and recipient. Each such disclosure is made in accordance with Section 15 of the DPA and Article 28 of the GDPR and is subject to appropriate safeguards for the protection of personal data.

  • Vercel, Inc. — Edge hosting and edge-analytics provider. Processes visitor request data and (where applicable) Vercel Analytics events. Processing location: United States of America. Vercel, Inc. is a signatory to the EU\u2013U.S. Data Privacy Framework and the processing is further subject to Vercel\u2019s publicly available data processing addendum, which incorporates European Commission Standard Contractual Clauses for transfers from the EEA to third countries.
  • Google LLC / Google Ireland Limited. — Provider of Google Tag Manager and Google Analytics 4. Processes analytics events and associated client identifiers only where the visitor has affirmatively consented to analytics storage. Processing location: United States of America and Ireland. Google Analytics 4 is configured with a fourteen-month data retention window and automatic user deletion at expiry. Transfers are covered by the Google Controller-Controller Data Protection Terms incorporating European Commission Standard Contractual Clauses and, for transfers from the EEA/UK, the EU\u2013U.S. Data Privacy Framework certification of Google LLC.
  • Electronic mail service provider. — Transmits internal notification messages and (where applicable) submitter confirmation messages, each containing the enquiry record and the attribution block.
  • Customer relationship management system provider. — Hosts the Controller\u2019s customer relationship records, including the enquiry record and the attribution block.
  • ipwho.is — Transient recipient of the IP address, for the sole purpose of resolving an approximate geographic location where the edge hosting stack does not already provide one, in accordance with the processing described in Section 3(4) above. No IP address is retained by the Controller after resolution.

No disclosure for independent marketing. — Personal data is not sold, rented, leased, or otherwise disclosed to any third party for the independent direct marketing or independent advertising purposes of that third party. No data brokerage operation is conducted by the Controller.

7. Retention and deletion

Retention periods for each category of personal data.


In accordance with the storage limitation principle in Section 11 of the DPA and Article 5(1)(e) of the GDPR, personal data is retained only for so long as is reasonably necessary for the purposes for which it was collected. The specific retention periods are as follows:

  • Enquiry records (internal mail). — Retained for the duration of any active commercial discussion and, following the conclusion of active discussion, for a further period of two (2) years, so that a previously terminated discussion may be re-commenced without loss of institutional context. At the expiry of that period the record is deleted unless the Controller is required by applicable law or by a lawful request of a competent authority to retain it for a longer period, or unless the data subject has in writing requested earlier deletion, in which case earlier deletion is effected without undue delay.
  • Google Analytics 4 data. — Retained by Google for fourteen (14) months from collection and automatically deleted by Google thereafter in accordance with the Controller\u2019s account configuration.
  • Attribution cookie. — Retained for thirty (30) days from capture, as set out in the storage register above.
  • Consent record cookie. — Retained for one hundred and eighty (180) days from the date of the most recent choice, as set out in the storage register above.
  • Engagement tier counters. — Retained only for the duration of the browsing session and deleted immediately upon closure of the tab or the browser.
  • Rate-limiting state. — The IP address is held in application memory only for the duration of the rate-limiting window applicable to the relevant submission endpoint, after which it is overwritten or garbage-collected.
8. Security measures

Organizational, physical, and technical security measures.


Pursuant to Section 24 of the DPA and Article 32 of the GDPR, the Controller has implemented appropriate organizational, physical, and technical security measures for the protection of personal data against accidental or unlawful destruction, accidental loss, alteration, unauthorised disclosure or access, and all other unlawful forms of processing. These measures include, without limitation:

  • Transport-layer security in the form of enforced HTTPS (TLS 1.2 and above) for all connections between the visitor\u2019s client and the website.
  • SameSite=Lax and Secure cookie flags on all cookies written by the Controller, in accordance with current best practice for browser storage security.
  • Server-side input validation, length bounds, and anti-bot controls on all form submission endpoints, as more particularly described in Section 5(1) above.
  • Role-based access controls on the Controller\u2019s customer relationship management system and electronic mail platform, with access to enquiry records restricted to authorised personnel of the Controller on a need-to-know basis.
  • Written processing agreements with all processors described in Section 6 above, containing the minimum guarantees required by Section 15 of the DPA and Article 28(3) of the GDPR.

No system of security measures, however robust, can guarantee absolute security. The obligation of the Controller is nevertheless one of reasonable care, consistent with the nature and scale of its processing operations and the sensitivity of the data processed.

9. Personal data breach

Personal data breach notification procedures.


In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, the Controller will notify the National Privacy Commission of the breach without undue delay and, where feasible, not later than seventy-two (72) hours after having become aware of it, in accordance with Section 20 of the DPA and NPC Circular No. 16-04. Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, the Controller will further communicate the breach to the affected data subjects without undue delay, in accordance with Section 21 of the DPA and GDPR Article 34. Where processing is subject to the GDPR, the notification obligations in Articles 33 and 34 of the GDPR will additionally be complied with, including notification to the competent supervisory authority of the relevant Member State.

10. Data subject rights

Rights of the data subject and how to exercise them.


A data subject whose personal data is processed by the Controller enjoys the following rights. The rights under the DPA are available to all data subjects. The additional rights particularised under the GDPR are available, in the alternative, to data subjects who are physically present in the European Economic Area or the United Kingdom at the time of the processing in question, or who are EEA or UK persons to whose data the GDPR applies by virtue of its territorial scope.

10.1 Rights under the Data Privacy Act of 2012 (RA 10173)

  • Right to be informed (Sec. 14) — the right to the information contained in this Notice prior to the commencement of processing.
  • Right of access (Sec. 19) — the right to obtain from the Controller a confirmation as to whether or not personal data concerning the data subject is being processed, and, where that is the case, access to the personal data and to the information listed in Section 19 of the DPA.
  • Right to object (Sec. 19) — the right to object to and to withhold consent to the processing of personal data, including processing for purposes of direct marketing, profiling, automated processing, or other processing based on legitimate interests.
  • Right to erasure or blocking (Sec. 19) — the right to the removal, or the restriction of further use, of personal data that is incomplete, outdated, unlawfully obtained, or used for unauthorised purposes, or where any of the grounds set out in Section 20 of the DPA are established.
  • Right to rectification (Sec. 19) — the right to the correction of inaccurate or incomplete personal data.
  • Right to data portability (Sec. 19) — the right to obtain a copy of personal data concerning the data subject in a structured, machine-readable, and commonly used format, and to transmit that data to another controller.
  • Right to damages (Sec. 19) — the right to be indemnified for any damages sustained as a result of inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorised use of personal data.
  • Right to lodge a complaint (Sec. 25) — the right to file a complaint with the National Privacy Commission in respect of any processing that is alleged to be in contravention of the DPA or its implementing rules and regulations.

10.2 Rights under the General Data Protection Regulation (GDPR)

  • Right of access (Art. 15) — equivalent to the DPA right of access, including the right to be advised of the lawful basis, the categories of recipient, the envisaged retention period, and the existence of any automated decision-making.
  • Right to rectification (Art. 16) — equivalent to the DPA right to rectification.
  • Right to erasure ("right to be forgotten") (Art. 17) — the right to obtain from the Controller the erasure of personal data concerning the data subject where one of the grounds in Article 17(1) is established, including obsolescence, withdrawal of consent, absence of lawful basis, or unlawful processing.
  • Right to restriction of processing (Art. 18) — the right to the restriction of processing in the circumstances set out in Article 18(1), including during the pendency of a request for rectification, or where processing is unlawful but erasure is objected to.
  • Right to data portability (Art. 20) — the right to receive personal data provided to the Controller in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from the Controller.
  • Right to object (Art. 21) — the right, at any time and on grounds relating to the data subject\u2019s particular situation, to object to processing that is based on Article 6(1)(e) or (f), including processing for the purposes of legitimate interests or of direct marketing.
  • Right to withdraw consent (Art. 7(3)) — the right to withdraw consent to processing at any time, without affecting the lawfulness of processing based on consent before its withdrawal. Withdrawal is effected through the mechanism provided on the face of this Notice or by written request to the Controller at the address stated in Section 2.
  • Right to complain to a supervisory authority (Art. 77) — the right to lodge a complaint with a supervisory authority of the Member State of the data subject\u2019s habitual residence, place of work, or place of the alleged infringement, in respect of any processing that is alleged to be in contravention of the GDPR.

Mode of exercise. — A data subject who wishes to exercise any of the rights set out in this section may do so by written communication, by electronic mail, addressed to the Controller at:

hello@bughawinnovations.ph

The Controller does not require any particular form of words. Where the identity of the requesting person cannot be immediately confirmed on the basis of the information already held, the Controller may request reasonable additional information for the sole purpose of confirming the identity of the requesting person before complying with the request, in accordance with DPA Rule XI, Sec. 3 and GDPR Article 12(6).

11. Children

Processing of personal data of minors.


This website is not directed at, and its commercial offering is not intended for, persons below the age of eighteen (18) years, or the age of majority applicable in the jurisdiction of the visitor, whichever is higher. The Controller does not knowingly solicit, collect, or process personal data from children within the meaning of Section 3(k) of the DPA or GDPR Article 8. If the Controller at any time becomes aware that personal data of a child has been collected through the website without the verified consent of the parent or legal guardian, the Controller will take all reasonable steps to delete that data without undue delay. A parent or legal guardian who becomes aware that a child may have submitted personal data without consent is invited to contact the Controller at the address stated in Section 2 in order to request the removal of that data.

12. Amendments

Amendments to this Data Privacy Notice.


The Controller reserves the right to amend this Data Privacy Notice from time to time in order to reflect changes in law, changes in processing operations, or for any other lawful reason. Material amendments will be identified on the face of this Notice by update of the "Last updated" date appearing below, and by a fresh request for consent where the amendment would alter the scope or the purpose of processing previously carried out on the basis of consent. In the case of non-material amendments that do not alter the scope of previously given consent, the updated Notice will be published on this page without the necessity of a further consent solicitation, provided always that the data subject\u2019s right to withdraw consent and the other rights enumerated in Section 10 above remain exercisable at all times.

A data subject who wishes to be notified of any material amendment to this Notice should register that request by written communication addressed to the Controller at the contact particulars set out in Section 2.


Last updated: 22 August 2026