|Image||Item Name||Quantity||Price||Sale Price||Total|
Lasting Impression Gift Shop (“Lasting Impression”) respects your right to privacy. This policy summarizes what personal information we may collect, how we may use this information,
and other important topics relating to your privacy and data protection.
It is Lasting Impression’s policy to comply with all applicable privacy and data protection laws. This commitment reflects the value we place on earning and keeping the trust of our customers, business partners and others who share their personal information with us.
I. General Principles of Collection, Use and Disclosure of Personal Information
To the extent required by applicable law, whenever Lasting Impression collects personal information, it will:
Provide timely and appropriate notice to you about our data practices;
Collect your personal information only for specified and legitimate purposes. The information we collect will be relevant, adequate and not excessive for the purposes for which it is collected;
Process your personal information in a manner consistent with the purposes for which it was originally collected or to which you have subsequently consented;
Take commercially reasonable steps to ensure that your personal information is reliable for its intended use, accurate, complete, and, where necessary, kept up-to-date;
Not use your personal information for direct marketing purposes without giving you an opportunity to “opt-out”; and
Take appropriate measures, by contract or otherwise, to provide adequate protection for personal information that is disclosed to a third party.
Lasting Impression values the confidentiality of personal data. This document details how the
Company uses and protects personal data for the purpose of obtaining the consent of data subjects, in accordance with the Data Privacy Act of 2012 (DPA), its Implementing Rules and
Regulations (IRR), other issuances of the National Privacy Commission (NPC) and other relevant laws of the Philippines.
II. Customer’s Personal Data
As a potential or current client you are considered a data subject. Please read this document carefully to ensure informed consent:
A. Personal Data?
Personal data refers to all types of:
Personal information – “any information, whether recorded in a material form or not,from which the identity of an individual is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information would directly and certainly identify an individual;”
Sensitive personal information – “personal information about an individual’s race, ethnic origin, marital status, age, color, religious/philosophical/political affiliations, health, education genetic or sexual life, legal proceedings, government issued identifiers and other information specifically established by an executive order or an act of congress to be kept classified;” and
Privileged information – “any and all forms of information which, under the Rules of Court and other pertinent laws, constitute privileged communication, such as, but not limited to, information which a person authorized to practice medicine, surgery or obstetrics may have acquired in attending to a patient in a professional capacity.”
B. Why does the Company collect personal data?
The Company collects, uses, processes, stores and retains personal data when reasonable and necessary to perform its business processes effectively, safely and efficiently and in accordance with corporate policies. In particular, the Company will collect your data in order to provide you with access to our various products, accessories and services being offered to the public.
C. What type of personal data does the Company collect and generate?
The Company will collect the following personal data:
D. How does the Company collect, acquire, or generate personal data?
In the course of availing our products and services, we may collect information about your preferred transactions, and product preferences. When you access our website, we may provide information about us as well as information regarding our products and services.
E. How does the Company ensure that personal data is accurate and up-to-date?
Data subjects are primarily responsible for ensuring that all personal data submitted are accurate, complete and up-to-date. From time to time, the Company requests updated data; it is important that subjects cooperate and provide the same. The Company takes reasonable steps to make sure that the personal data it collects, generates, uses or discloses are accurate, complete, and up-to-date.
F. With whom may the Company share personal data?
As a general rule, the Company does not and will not share personal data with third parties except as necessary for the proper execution of processes related to a declared purpose, or the use or disclosure is reasonable necessary, required or authorized by or under law and may not use it for any other purpose.
G. How does the Company protect personal data?
Use of secured servers and firewalls, encryption on computing devices;
Restricted access only for qualified and authorized personnel; and
Strict implementation of information security policies.
H. Where and how long does the Company keep personal data?
The Company stores personal data in both local and off-shore facilities, such as data centers (on premise and cloud) and physical document storage facilities. Personal data collected pursuant to this Consent Statement are retained for a period of three (3) years Subject to applicable laws, rules and regulations, the data subject may request personal data to be deleted from the Company’s systems, databases and hard copies within a reasonable requested date.
III. Rights of Data Subjects Under the Data Privacy Act?
Data subjects have the following rights:
Right to be informed;
Right to object;
Right to access;
Right to rectify or correct erroneous data;
Right to erase or block;
Right to secure data portability;
Right to indemnified for damages; and
Right to file a complaint.
The Company’s decisions to provide access, consider requests for correction or erasure, and address objection to process personal data as it appears in the Company’s official records, are always subject to applicable and relevant laws and/or the DPA, its IRR and other issuances of the NPC.
IV. Contact in Case of Inquiry, Feedback or Complaints
Should you have any inquiries, feedback, and/or complaints, you may reach the Company through our email address : email@example.com
You may also lodge a complaint before the National Privacy Commission (NPC). For further details, please refer to NPC’s website: https://privacy.gov.ph.
By signing your conformity below, you consent to the collection, generation, use, processing, storage and retention of your personal data by the Company for the purpose(s) described in this document. Please ensure that you have completely read and understood the terms above before signing.
You also authorize the Company to disclose your information to accredited/affiliated third parties or independent/non-affiliated third parties, whether local or foreign, in the following circumstances:
As necessary for the proper execution of processes related to the declared purpose;
The use or disclosure is reasonably necessary, required or authorized by or under law.
From time to time, it may be necessary for the Company to revise this document. Any revision made to this document shall be communicated via posting in the Company website or via email. Any change will not be applied and will not alter how the Company handles previously collected personal data without obtaining your consent, unless required by law.