Skip to content
Data Processing Agreement

Your renters’ data, your rules.

Last updated 24 September 2026 · Draft for legal review before launch

You decide what your business collects from renters; we process it for you, only the way you tell us to. This agreement spells out both sides’ duties under the Data Privacy Act. It is part of our Terms and you accept it at sign-up — no separate signature needed. Need a countersigned copy for your records? Email dpo@ceerent.com.

01Parties & how this applies

This Data Processing Agreement (“DPA”) is between:

  • You, the operator — the rental business that uses CeeRent. For your renters’ personal data, you are the personal information controller (PIC).
  • CeeRent — [Registered business name — added at launch], SEC reg. no. [SEC registration no. — added at launch], [Registered address — added at launch]. For your renters’ personal data, we are your personal information processor (PIP).

This DPA forms part of our Terms of Service. You accept it when you create an account and tick the box at sign-up. It applies for as long as we process personal data for you. If it conflicts with the Terms on anything about personal data, this DPA wins.

It is written to meet section 14 of the Data Privacy Act of 2012 (RA 10173) and sections 43 to 45 of its Implementing Rules and Regulations (IRR), which require a contract between a controller and a processor. Words like “personal information”, “sensitive personal information”, “processing” and “personal data breach” mean what they mean in that law.

This DPA does not cover data we control ourselves — your own account and billing data, or visitors to ceerent.com — which our Privacy Notice covers. It also doesn’t cover a renter’s reusable “verify once” record, which we hold as controller with the renter’s own consent.

02What we process, and why

Subject matterProviding CeeRent to you: your booking site, payments and deposits, renter verification, e-signed agreements, handover records, messaging, fleet tools, GPS and AI features you turn on.
Nature of processingCollecting (through your booking site and staff apps), storing, organising, displaying, sending messages, matching licence and selfie images, AI-assisted suggestions, exporting, and deleting.
PurposeOnly to provide CeeRent to you under the Terms and your instructions.
DurationWhile you subscribe, plus up to 90 days after your account closes, then deletion (see End of service).
LocationOur hosting and the subprocessors listed in our Privacy Notice, including locations outside the Philippines.

03Kinds of data & people

Data subjects

  • Your renters and would-be renters (people who inquire or start a booking)
  • Additional drivers and people named in a booking (for example a split payment with friends)
  • Co-owners of vehicles you manage, if you add them
  • People who message your Facebook Page, if you connect Messenger
  • Anyone who appears incidentally in handover photos

Personal information

  • Name, email, mobile number, address, date of birth
  • Booking details, payments and refunds (no full card numbers — those stay with Xendit), deposits and claims
  • Handover photos, odometer and fuel readings, damage notes
  • Signed rental agreements and e-signature records
  • Messages, including Messenger conversations
  • Vehicle location and trips from GPS, if you turn it on

Sensitive personal information

  • Driver’s licence number, details and image, and any other government-issued ID
  • Selfie images taken to check a licence belongs to the renter

These are sensitive personal information under section 3(l) of the Data Privacy Act. They get the extra protections listed under Security measures.

04Your obligations as controller

You agree that:

  • You have a lawful basis under sections 12 and 13 of the Data Privacy Act for everything you ask us to process — especially licence, ID and selfie checks, and GPS tracking.
  • You give renters a privacy notice that says who you are, what you collect, why, who receives it (including CeeRent as your processor), how long you keep it, and how to exercise their rights. Your booking site comes with a starter privacy notice built from your business details — check that it matches how you actually operate. Its content is your responsibility.
  • You get consent where it’s needed, in a way that meets NPC Circular 2023-04 — specific, not bundled with the rental terms, and easy to withdraw. Marketing to renters needs its own opt-in.
  • You collect only what you need and set a retention period that fits your purposes (the default for ID and licence images is 90 days after the rental).
  • You handle your renters’ requests (access, correction, deletion, objection, portability) and complaints. We help — see Helping you.
  • You control your team’s access. Give each staff member their own sign-in and the least access their job needs, and remove access when they leave.
  • You handle your own registration with the NPC if your business is required to register, and appoint your own DPO where the law requires.
  • Your instructions to us follow the law.

05Our obligations as processor

As required by section 44 of the IRR, we will:

  1. Act only on your documented instructions. Your instructions are these Terms and DPA, your settings in CeeRent, and what your authorised users do in it. That includes transfers outside the Philippines described in our Privacy Notice. We won’t use your renters’ data for our own purposes, sell it, or market to your renters. If we think an instruction breaks the law, we will tell you straight away.
  2. Keep it confidential. Everyone at CeeRent who can access personal data is bound by a confidentiality obligation that continues after they leave, and has access only as far as their job requires.
  3. Keep it secure with the organisational, physical and technical measures listed under Security measures.
  4. Use subprocessors only as set out below, under written contracts with data protection obligations at least as protective as this DPA. We stay responsible to you for their work.
  5. Help you answer data subject requests through tools in CeeRent (renter data requests, export, correction and anonymised deletion) and, where needed, by hand.
  6. Help you meet your own obligations — security, breach notification, privacy impact assessments and questions from the NPC — as far as the information we have allows.
  7. Tell you about breaches as described under Breach notification.
  8. Return or delete the data when the service ends, as described under End of service.
  9. Show that we comply. We give you the information you reasonably need to show compliance and allow audits as described under Audits & information.

Our support team only accesses your account when you approve it. Access is time-limited, and every action is logged in your audit log.

06Subprocessors

  • You give us general permission to use the subprocessors listed in our Privacy Notice.
  • We will email the owner at least 30 days before we add or replace a subprocessor that handles your renters’ data.
  • If you have a reasonable data protection objection, tell us within that period. We’ll try to find a fix. If we can’t, you may cancel the affected service or your subscription and get a pro-rata refund of prepaid fees for the unused period.
  • Some subprocessors are only used when you turn on the feature — Messenger (Meta), 3D models (Meshy) and GPS (self-hosted Traccar).

07Helping you with renter requests

  • Renters can send access, correction and deletion requests from their account on your booking site. You get a notification and can complete them from the customer’s page.
  • Deleting a renter’s data anonymises their records so bookings and invoices still add up for tax, and removes their licence, ID and selfie images.
  • If a renter contacts us directly about data you control, we pass the request to you within 5 working days and don’t answer it ourselves unless you ask us to or the law requires it.
  • If an authority asks us for your renters’ data, we tell you first unless the law forbids it, and we share only what is legally required.

08Breach notification

  • If we become aware of a personal data breach affecting your renters’ data, we will tell you without undue delay, and in any case within 72 hours of becoming aware of it.
  • We will tell you what we know: what happened, what data and roughly how many people are affected, likely consequences, what we have done to contain it, and a contact person. If we don’t know everything yet, we send what we have and follow up.
  • Under NPC Circular 16-03, you as controller must notify the NPC and affected renters within 72 hours when the breach involves sensitive personal information (or information that could enable identity fraud) and is likely to cause a real risk of serious harm. We’ll give you what you need to do that, including a draft notice.
  • We keep records of all security incidents and breaches, including ones that don’t need to be reported.

09Security measures

In place

  • Encryption in transit (HTTPS/TLS) for all traffic, and encryption at rest for databases and file storage.
  • Each operator’s data is kept separate from other operators’ at the database level.
  • Role-based access for your team; two-step sign-in (2FA) required for owners and managers; session controls including “sign out everywhere”.
  • Licence, ID and selfie images are visible only to staff whose role allows it, and are deleted automatically according to your retention setting.
  • Support access only with your approval, limited in time, and every action written to your audit log.
  • An audit log of staff and support actions that you can review and export.
  • Regular backups, stored encrypted.
  • Card data is handled by Xendit, which is responsible for PCI-DSS compliance. Full card numbers never reach our servers.
  • CeeRent staff: confidentiality obligations, and least-privilege access to production systems with 2FA.
  • Subprocessors bound by data protection terms.

Being completed before launch

  • Appointing a named Data Protection Officer and registering with the NPC.
  • A written security incident and breach response plan.
  • Privacy and security training for everyone at CeeRent who can access personal data.
  • An independent penetration test.

Planned after launch

  • Regular penetration tests and vulnerability reviews.
  • Tested restore drills and published recovery targets.

We may change these measures over time, but we won’t lower the overall level of protection. See our Security page for more.

10Audits & information

  • On request, we’ll give you written answers to reasonable security and privacy questionnaires, and a summary of our security measures.
  • If that isn’t enough to show compliance — or the NPC requires it — you (or an independent auditor you choose, bound by confidentiality) may audit our compliance with this DPA, with 30 days’ notice, during business hours, not more than once a year unless there has been a breach.
  • Audits must not give access to other operators’ data or put the security of the service at risk. Each side pays its own costs, unless the audit finds that we materially broke this DPA.

11End of service: return & deletion

  • Return: you can export your data in CSV or JSON at any time, including for 90 days after your account closes.
  • Deletion: 90 days after your account closes, we delete your renters’ personal data, photos and documents. You can ask us in writing to delete it sooner.
  • Copies in backups are deleted when the backup cycle ends, and are not restored except to recover from an incident.
  • We keep data longer only where the law requires it, and then only for that purpose.

12Liability & term

  • Each of us is responsible to renters and to the NPC as the Data Privacy Act provides. As controller, you remain accountable for your renters’ data, including data we process for you.
  • Between us, the liability limits in the Terms apply to this DPA, except where the law doesn’t allow them to be limited.
  • This DPA starts when you accept the Terms and lasts until we have deleted or returned all of your renters’ personal data. The confidentiality and security duties continue for as long as we hold any of it.
  • This DPA is governed by Philippine law, with the same venue as the Terms.

Questions about this DPA: dpo@ceerent.com.

Questions about this page? Email privacy@ceerent.com or see Contact.