Data Processing Terms
Last updated: 11 October 2026
For customers of the Aquila Dimensions CRM. These terms are also set out in the Annex to our Terms of Service.
These Data Processing Terms apply when your company uses the Aquila Dimensions CRM and puts personal data about its own clients, contacts or other people into it ("customer personal data"). They form part of our Terms of Service. In these Data Processing Terms, "you" means the CRM customer and "we" means Aquila Softwares Corporation, operating as Aquila Dimensions.
If these Data Processing Terms conflict with any other part of the Terms of Service on how customer personal data is handled, these Data Processing Terms apply.
DP1. Our roles
- You are the personal information controller for customer personal data. You decide what data goes into the CRM and why.
- We are your personal information processor. We process customer personal data only to provide the CRM to you.
- You must have a lawful basis for the customer personal data you put into the CRM, and you must give your clients any notice the law requires.
- Reminder emails sent through the CRM to your clients are sent on your behalf.
DP2. Details of the processing
- Subject matter: providing the Aquila Dimensions CRM.
- Duration: while you use the CRM, plus the period in section DP9.
- Nature and purpose: storing, organising, displaying, exporting and deleting your records, generating invoices, proposals and reports, and sending reminder emails to your clients on your behalf.
- Types of personal data: names, contact details (such as email, phone and address), company details, invoice, payment, collection and withholding records, proposals, notes, and any other data you choose to enter.
- Categories of people: your clients, your clients' contacts, and other people whose details you choose to enter.
DP3. Your instructions
- We process customer personal data only on your documented instructions. Your instructions are these Terms, your settings and your use of the CRM's features, and any other written instructions you give us that we agree to.
- We do not use customer personal data for our own purposes, and we never sell it or use it for marketing.
- If the law requires us to process customer personal data in another way, we will tell you first, unless the law does not allow us to.
- If we believe an instruction breaks data protection law, we will tell you.
DP4. Confidentiality of our people
Only staff and contractors who need access to provide or support the CRM can access customer personal data. They are bound by a duty of confidentiality.
DP5. Security
We use organisational, physical and technical measures to protect customer personal data, including:
- encrypted connections (HTTPS);
- passwords stored only in hashed form;
- access limited to people who need it; and
- a separate workspace for each customer.
We review these measures from time to time and will not reduce the overall level of protection.
DP6. Sub-processors
You allow us to use these sub-processors:
| Sub-processor | What they do |
|---|---|
| DigitalOcean | Hosting the CRM and its data |
| Our email delivery provider | Sending account emails and the reminder emails sent on your behalf |
| aq-pay and its QR Ph payment partners | Processing your payments to us |
- Each sub-processor is bound by written terms that protect personal data at least as well as these Data Processing Terms.
- We stay responsible to you for our sub-processors' work.
- We will tell you by email at least 14 days before we add or replace a sub-processor. If you object on reasonable data protection grounds, tell us. If we cannot resolve your concern, you may stop using the CRM. Because there is no automatic renewal, you will not be charged again.
- You can ask us for the name of our email delivery provider at any time.
DP7. Helping you with requests from your clients
- If one of your clients asks us to access, correct, delete or object to the use of their data, we will pass the request to you and will not answer it ourselves, unless the law requires us to.
- We will give you reasonable help, through the CRM's features or otherwise, so you can respond to requests from your clients and meet your other duties under data protection law.
DP8. Data breaches
- If we become aware of a personal data breach affecting customer personal data, we will tell you without undue delay, and in time for you to meet the 72-hour notification deadline under National Privacy Commission rules.
- We will give you the information we have about the breach, what we are doing about it, and what you may need to do. We will update you as we learn more.
- We will help you notify the National Privacy Commission and affected people where required.
DP9. Return and deletion
- You can export your customer data to CSV at any time while your workspace is active. If your workspace is locked, email us and we will help you export it.
- If you close your account, or your workspace stays locked, we keep your data for a period we will announce in advance by email before any deletion. After that period, we delete customer personal data.
- Deleted data may stay in backup copies for a short time until those copies are overwritten.
- We may keep copies only where the law requires us to.
DP10. Audits and information requests
- On reasonable notice, you may ask us for the information you need to check that we are meeting these Data Processing Terms. We will answer reasonable written questions and security questionnaires, and share summaries of our security measures and our sub-processors' security commitments.
- Any other kind of audit must be agreed in writing in advance, must be at your cost, and must protect the confidentiality and security of our other customers.
DP11. Transfers outside the Philippines
- The CRM is hosted with DigitalOcean, which may store data in data centres outside the Philippines. Our email delivery provider may also process data outside the Philippines.
- You allow these transfers. We protect transferred data with contracts and our providers' security commitments, and we remain responsible for it.
- EU and UK customers: if the GDPR applies to your customer personal data, you can ask us for a Standard Contractual Clauses addendum by emailing marketing@aquilasoftwares.com.
DP12. Contact
Questions about these Data Processing Terms can go to our Data Protection Officer, Jason Te, at marketing@aquilasoftwares.com (attention: Data Protection Officer), or by post to: Data Protection Officer, Aquila Softwares Corporation, 212 ENM Bldg, Sampaloc St, Juna Subdivision, Matina Crossing, Davao City, Philippines.