Available lang sa Ingles ang dokumentong ito, at ang bersyong Ingles ang opisyal na teksto.

Data Processing and Outsourcing Agreement (Philippines)

Effective date: [EFFECTIVE DATE, ON PUBLICATION]
Last updated: September 10, 2026
Version: ph-dpa-v2
Supersedes: ph-dpa-v1, which continues to govern a Firm that accepted it until that Firm accepts this version

NOT YET IN FORCE. This document is a draft. It must not be published, and must not be presented to any Firm for acceptance, until every bracketed PLACEHOLDER value in it is replaced and this notice is removed.

This Data Processing and Outsourcing Agreement ("PH DPA") is entered into between Esqase, Inc. ("Esqase") and the law firm or organization that has accepted the Esqase Terms of Service and subscribes to the Professional plan ("Firm"). It is the contract required by Section 44 of the Implementing Rules and Regulations of Republic Act No. 10173, the Data Privacy Act of 2012, and it governs Esqase's processing of Personal Data on the Firm's behalf.

The Firm is the Personal Information Controller. Esqase is the Personal Information Processor. This PH DPA forms part of the Terms of Service and supplements the Data Processing Agreement; Section 15.1 states which prevails where they differ.

Capitalized terms not defined here have the meanings given to them in the Terms of Service, including Account, Authorized User, Client Data, External User, Firm, Public-Facing Features, Service, Subscription, and User Content, or in the Act and its Implementing Rules and Regulations.

1. Definitions

In this PH DPA:

  • "Act" means Republic Act No. 10173, the Data Privacy Act of 2012.
  • "Commission" or "NPC" means the National Privacy Commission.
  • "Data Subject" means an individual whose Personal Information is processed.
  • "IRR" means the Implementing Rules and Regulations of the Act, issued on 24 August 2016.
  • "NPC Circular 2023-06" means NPC Circular No. 2023-06 on the Security of Personal Data in the Government and the Private Sector, dated 1 December 2023, which repealed NPC Circular No. 16-01.
  • "Personal Data" means Personal Information, Sensitive Personal Information, and Privileged Information taken together, as those terms are defined in Section 3 of the Act, that is processed through the Service on the Firm's behalf. Personal Data is the subset of Client Data that relates to an identified or identifiable individual.
  • "Personal Data Breach" and "Security Incident" have the meanings given to them in Section 3 of the IRR.
  • "Personal Information Controller" or "PIC" means the Firm, who controls the processing of Personal Data.
  • "Personal Information Processor" or "PIP" means Esqase, who processes Personal Data on the Firm's instructions.
  • "Privileged Information" means, as Section 3(k) of the Act defines it, any and all forms of data which under the Rules of Court and other pertinent laws constitute privileged communication.
  • "Sub-processor" means a third party Esqase engages to process Personal Data on the Firm's behalf, and is a further personal information processor for the purposes of Section 44(b)(4) of the IRR.

2. Scope and Roles

2.1 Roles

The Firm determines the purposes and the extent of the processing of Personal Data it puts into the Service, and is the PIC. Esqase processes that Personal Data only on the Firm's documented instructions, and is the PIP. Section 10 of NPC Circular 2023-06 records the same relationship: where a PIC engages a service provider to store Personal Data under the PIC's control or custody, the service provider acts as a PIP.

Account, billing, and usage data that Esqase collects for its own purposes, such as Authorized User registration, Subscription billing, and product usage analytics, is processed by Esqase as a controller of that information and is governed by the Privacy Policy, not by this PH DPA.

2.2 When It Applies

This PH DPA applies where the Act applies to the Firm's processing, and takes effect when a person authorized to bind the Firm accepts it in the Service.

2.3 Esqase Does Not Advise the Firm

Esqase makes software for lawyers. Nothing in this PH DPA is legal advice, and nothing in it relieves the Firm of an obligation it owes as a PIC under the Act, the IRR, the issuances of the Commission, or its rules of professional conduct.

3. Details of the Processing

This Section sets out the matters that Section 44(a) of the IRR requires the contract to state.

3.1 Subject Matter

Esqase's provision of the Service to the Firm under the Terms of Service: a practice management platform in which the Firm records and works on its matters, contacts, documents, time, billing, and, on the Professional plan, its personal injury cases.

3.2 Duration

The term of the Firm's Subscription, followed by the retention and deletion periods in Section 10. The processing is continuous for as long as the Firm uses the Service.

3.3 Nature and Purpose of the Processing

The purpose is to provide, operate, maintain, secure, and support the Service as the Firm directs. The nature of the processing is collection, recording, organization, structuring, storage, retrieval, use, transmission, disclosure to the recipients the Firm designates, indexing and search, backup, restriction, erasure, and destruction, carried out by automated means.

3.4 Type of Processing

The processing is done under an outsourcing agreement between the Firm as PIC and Esqase as PIP. Esqase engages the Sub-processors listed in Section 5.2, and processing by those Sub-processors is subcontracting within the meaning of Section 43 of the IRR.

3.5 Types of Personal Data

The Firm may submit to the Service:

Personal Information, which may include the name, email address, telephone number, postal address, employer, and role of a Data Subject; matter and case details, including leads and intake form submissions; billing and financial records, including trust and operating account transactions; documents and their contents; communications, including email, phone and meeting logs, notes, comments, and internal messages, and files shared through them; calendar events and scheduling information; eSignature audit trail data, being signer identity, IP address, timestamp, and device information; credentials used to verify an External User's access to a link the Firm has shared; technical identifiers collected when an External User opens a page the Firm shares, including IP address and browser and device information; device tokens used to deliver push notifications; and Authorized User account information.

Sensitive Personal Information, within the meaning of Section 3(l) of the Act, which may include information about a Data Subject's age, marital status, race or ethnic origin, and religious, philosophical, or political affiliations; information about a Data Subject's health, including the medical records, treatment histories, and medical bills a Firm records on a personal injury case on the Professional plan; information about any proceeding for an offense committed or alleged to have been committed by a Data Subject, its disposal, or the sentence of any court in it; and government-issued numbers and documents peculiar to an individual, including Tax Identification Numbers, Social Security System, Government Service Insurance System, PhilHealth and Pag-IBIG numbers, driver's licences, professional licences, passports, and tax returns.

Privileged Information, within the meaning of Section 3(k) of the Act, being the attorney-client communications and work product that a law firm holds in the ordinary course. Section 12 states how Esqase treats it.

Esqase does not require, and does not ask for, any particular category. What the Service holds is what the Firm and its Authorized Users put into it.

3.6 Categories of Data Subjects

The Firm's clients and prospective clients; its contacts; opposing parties and their representatives; witnesses and other third parties whose details the Firm records; treating providers, insurers, adjusters, and other participants in a claim; the Firm's Authorized Users; and External Users who interact with the Firm through the Public-Facing Features described in Section 8 of the Terms of Service, including document signers, document recipients, form submitters, payers, and booking invitees.

3.7 Recipients

Personal Data is disclosed only to the Firm's own Authorized Users, to the External Users the Firm designates, to the Sub-processors listed in Section 5.2 for the purpose stated against each, and to a public authority where Section 4.10 permits it.

3.8 Geographic Location of the Processing

Storage and primary processing take place in the United States, on Google Cloud infrastructure. For a Firm in the Philippines, both parts of the artificial intelligence processing described in Section 11, the document indexing and the search embeddings, also take place in the United States. From the Effective date stated above, a request reaches the Service through a Google Cloud global load balancer in front of services running in the United States; Cloudflare provides name resolution for Esqase's domains and does not route or cache the Service's traffic. Sub-processor locations are stated in Section 5.2 and published at esqase.com/subprocessors.

The Firm instructs Esqase to process and store Personal Data in those locations. Esqase remains accountable to the Firm for Personal Data it transfers to a Sub-processor, and the Firm remains accountable under Section 21 of the Act for Personal Data transferred to Esqase.

3.9 Obligations and Rights of the Firm as PIC

The Firm's obligations and rights under this PH DPA are stated in Section 13. In summary, the Firm gives the instructions, decides who may see what, holds the lawful basis for the processing under Sections 12 and 13 of the Act, answers to Data Subjects and to the Commission, and has the rights of audit, breach notice, assistance, return, and deletion this PH DPA gives it.

4. Obligations of Esqase as Personal Information Processor

This Section states the stipulations that Section 44(b) of the IRR requires. Esqase will:

4.1 Process Only on Documented Instructions

Process Personal Data only upon the documented instructions of the Firm, including as to any transfer of Personal Data to another country or an international organization, unless the transfer is authorized by law. The Firm's documented instructions consist of the Terms of Service, the Data Processing Agreement, this PH DPA, and the configuration choices and actions the Firm and its Authorized Users take in the Service, including through the Esqase API. Taken together, those are the Firm's complete documented instructions, and Esqase may treat them as such.

4.2 Impose Confidentiality on Its Personnel

Ensure that an obligation of confidentiality is imposed on the persons authorized to process the Personal Data, that those persons are trained on privacy and data protection, and that access is limited to personnel who need it to provide, support, or secure the Service.

4.3 Implement Security Measures

Implement appropriate organizational, physical, and technical security measures, and comply with the Act, the IRR, and the issuances of the Commission, including NPC Circular 2023-06. The measures are described in Section 6.

4.4 Not Engage Another Processor Without Prior Instruction

Not engage another processor without the prior instruction of the Firm, and ensure that any such arrangement carries the same data protection obligations as this PH DPA, taking into account the nature of the processing. Section 5 states how that instruction is given and how it is changed.

4.5 Assist With Data Subject Requests

Assist the Firm, by appropriate technical and organizational measures and to the extent possible, to fulfill its obligation to respond to requests by Data Subjects relating to the exercise of their rights under Chapter IV of the Act. Section 8 states how.

4.6 Assist With the Firm's Compliance

Assist the Firm in ensuring compliance with the Act, the IRR, other relevant laws, and the issuances of the Commission, taking into account the nature of the processing and the information available to Esqase. That assistance includes providing the information the Firm reasonably needs for a privacy impact assessment under Section 5 of NPC Circular 2023-06, for a breach report under Sections 38 to 41 of the IRR, and for the Firm's own records of processing.

4.7 Delete or Return the Personal Data

At the Firm's choice, delete or return all Personal Data to the Firm after the end of the provision of services relating to the processing, including deleting existing copies unless storage is authorized by the Act or another law. Section 10 states the mechanism and the periods.

4.8 Make Information Available and Allow Audits

Make available to the Firm all information necessary to demonstrate compliance with the obligations laid down in the Act, and allow for and contribute to audits, including inspections, conducted by the Firm or by another auditor the Firm mandates. Section 9 states how.

4.9 Report an Infringing Instruction

Immediately inform the Firm if, in Esqase's opinion, an instruction infringes the Act, the IRR, or any issuance of the Commission. Esqase may suspend the processing under that instruction until the Firm confirms or withdraws it.

4.10 Handle Government Demands

Handle a subpoena, court order, warrant, or other legally binding demand for Personal Data as Section 18 of the Data Processing Agreement provides, including notifying the Firm before disclosing anything unless notice is prohibited by law, challenging the demand where there is a reasonable basis to consider it unlawful, disclosing only the minimum it is legally compelled to disclose, and referring the requesting authority to the Firm where it is able to do so.

4.11 Comply as a PIP in Its Own Right

Comply with the requirements of the Act, the IRR, other applicable laws, and the issuances of the Commission, in addition to its obligations under this PH DPA, as Section 45 of the IRR requires. Where the Act and the issuances of the Commission require Esqase to designate and register a Data Protection Officer or to register a data processing system, Esqase will do so.

5. Sub-processing

5.1 The Firm's Prior Instruction

The Firm's acceptance of this PH DPA is its prior instruction, for the purposes of Section 44(b)(4) of the IRR, for Esqase to engage each Sub-processor listed in Section 5.2 for the purpose stated against it. Esqase will not engage a further Sub-processor except in accordance with Section 5.3.

5.2 The Sub-processors

Each of these processes Personal Data on the Firm's behalf. The authoritative and current list is published at esqase.com/subprocessors, which forms part of this PH DPA.

Sub-processorPurposeLocation
Google LLC (Google Cloud)Cloud infrastructure: the application runtime (Cloud Run), the background job runtime (Cloud Functions), the database (Cloud SQL for PostgreSQL), file storage (Cloud Storage), the secret store (Secret Manager), the network perimeter every request passes through (Cloud Load Balancing, Cloud Armor, and Cloud CDN, which caches static assets only and never an authenticated response), and the log store (Cloud Logging). Firebase Data Connect is not used at all, and Firebase App Hosting serves only the public marketing and documentation website at esqase.com, which holds no Personal DataUnited States
Google LLC (Firebase)Sign-in (Identity Platform); the real-time signals that tell an open page that something it is showing has changed, which are identifiers and timestamps and carry no record content (Firestore); push notification delivery, which for a Firm that has accepted this PH DPA carries no record content, as Section 6.1 describes (Cloud Messaging); and verification that a request comes from a genuine Esqase application, which receives no record content (App Check)United States
Google LLC (Vertex AI)Artificial intelligence models used for search indexing and document descriptions, as described in Section 11United States
Cloudflare, Inc.Name resolution for Esqase's domains, and delivery of and protection for the marketing website at esqase.com. Cloudflare does not route or cache the traffic of the Esqase applications, which reaches Google Cloud's load balancer directlyUnited States, on a global network
Resend, Inc.Transactional email delivery, including messages Esqase sends to a Firm's clients on the Firm's behalfUnited States
Google LLC (Gmail, Google Calendar, Google Meet APIs)Email, calendar, and meeting integration, when enabled by an Authorized UserUnited States
Microsoft Corporation (Outlook, Outlook Calendar, Microsoft Teams APIs)Email, calendar, and meeting integration, when enabled by an Authorized UserUnited States
Zoom Communications, Inc.Meeting link integration, when enabled by an Authorized UserUnited States
PostHog, Inc.Product analytics. Receives the Firm's name, the name and email address of the Authorized User signing in, the record identifiers of the records that user acts on, and technical data such as IP address, device, and browser. Does not receive matter titles, client or contact names, document names or contents, message text, search terms, form answers, or any amountUnited States

Rows marked "when enabled" describe optional integrations. They process Personal Data only after an Authorized User connects the service, and disconnecting it revokes Esqase's access.

5.3 Changes to the List

Esqase will give the Firm at least 14 days' prior written notice by email before adding or replacing a Sub-processor that will process Personal Data. A Firm may subscribe to those notices at legal@esqase.com. If the Firm has reasonable objections relating to the protection of Personal Data, it must notify Esqase at that address within 14 days of the notice, with the grounds. The parties will work in good faith to resolve the objection. If it is not resolved, the Firm may terminate the affected portion of the Service, or the Subscription where the affected portion cannot reasonably be separated, and Esqase will refund the prorated portion of any prepaid fees covering the period after the termination date.

5.4 Flow-Down and Liability

Esqase will enter into a written agreement with each Sub-processor imposing data protection obligations at least as protective as those in this PH DPA, taking into account the nature of the processing. Esqase remains liable to the Firm for the performance of each Sub-processor's data protection obligations, subject to Section 15.4.

6. Security Measures

6.1 The Measures

Esqase implements and maintains the organizational, physical, and technical measures required by Section 20 of the Act and by NPC Circular 2023-06. They are the measures described in Section 5.1 of the Data Processing Agreement. Each one is in force in the Service on the Effective date stated above, and this Section describes the platform as it operates from that date.

Access control. Access is role based, under an access control policy that limits access to Personal Data to authorized personnel on a need-to-know basis, as Section 13 of NPC Circular 2023-06 requires. Every record carries the identity of the Firm that owns it. Row level security is enabled and forced on every table in the database, and the application connects as a role that cannot bypass it, so a read or a write outside the Firms the acting user belongs to fails at the data layer rather than in the interface, and no Firm can reach another Firm's records. A write is checked in the database itself, on every statement, against the acting user's membership of that Firm and the permissions of that user's role, so a write the role does not allow fails the same way.

Database least privilege. Each application service connects to the database as its own identity, authenticated by the cloud platform rather than by a password; no database password exists in Esqase's systems. Those identities are members of one of four database roles: one that owns the schema and is used only to apply changes to it, one for the web applications, one for background jobs, and one that can only read. None of the four can bypass row level security or act as a database superuser, and the application refuses to open a connection whose role could. Every connection carries a statement timeout, an idle-transaction timeout, and a lock timeout, so no query can hold a connection or a lock open indefinitely.

Authentication. Sign-in is by email and password with email verification, and by two-factor authentication using an authenticator app or an emailed one-time code, with single-use recovery codes. Two-factor authentication is required for every member of a Firm that has accepted this PH DPA, which is the multifactor authentication Section 16 of NPC Circular 2023-06 calls for where personnel have online access to Sensitive Personal Information and Privileged Information. A member who has not enrolled is sent to enrolment and cannot use the application until enrolment is complete, and a Firm Owner cannot switch the requirement off while this PH DPA is in force.

Session limits. Sessions are verified on the server on every request and last at most 12 hours. A session on the firm dashboard or the client portal ends after 1 hour without activity, and a session on Esqase's internal staff console ends after 30 minutes.

Encryption in transit. All traffic between clients and servers uses TLS, and every Esqase application sends HTTP Strict Transport Security, so a browser will not fall back to an unencrypted connection. A request to the Esqase applications reaches them only through Google Cloud's global load balancer, which terminates TLS and applies Google Cloud Armor's protections against attack and automated abuse; the application services accept no connection from the public internet. A small number of background endpoints sit outside the load balancer. One of them, the billing provider's webhook, is reachable from the public internet, carries no Personal Data, and verifies the provider's cryptographic signature on every request before it is processed.

Encryption at rest. The database and the file storage are encrypted at rest with keys managed by the underlying cloud platform. Two-factor authentication seeds and document share tokens are additionally encrypted by Esqase at the application layer, with AES-256-GCM, before they are stored.

Key management. Esqase's platform secrets and signing keys are held in Google Secret Manager, separately from the data they protect.

Audit logging. Every create, update, delete, and restore of a record is written to a single append-only audit log in the same database transaction as the change, with the identity of the actor, the time, the action, and the record. Opening and downloading a record are recorded the same way. A database trigger refuses every attempt to delete an audit row and every attempt to change one, except for five columns that record which identity and which matter an existing row belongs to and that cannot change what the row says happened. Audit records are retained for at least six years, which is the log retention Section 29 of NPC Circular 2023-06 contemplates. Changes to the database schema and to database roles are recorded by the database engine itself, and those records, together with the platform's own data-access logs, are written to a separate log store retained for seven years.

Threat and vulnerability management. Esqase's software dependencies are scanned weekly for updates, and updates are applied through the ordinary change process, addressing Section 32 of NPC Circular 2023-06.

Analytics. Session replay is not enabled in any Esqase application. PostHog is the only analytics processor, and no Esqase application loads Google Analytics. Esqase's product analytics carry record identifiers and never record content: no client or contact name, no matter title, no document name or contents, no note or message text, no search term, and no amount.

Notification content. For a Firm that has accepted this PH DPA, outbound push notifications and notification emails carry no record content: no client, matter, document, or provider names. That control covers those two channels. Email the Firm itself sends to its own client through the Service, such as a shared document invitation or an invoice reminder, carries the content the Firm puts in it.

Physical security. Production infrastructure runs in Google Cloud data centers, which operate their own physical and environmental controls. Esqase holds no physical filing system containing the Firm's Personal Data.

6.2 Updates

Esqase may update its security measures from time to time to reflect evolving risks and the issuances of the Commission, provided that an update does not materially reduce the overall level of protection.

6.3 Disposal

Where Personal Data is disposed of or destroyed, Esqase does so in a manner that prevents further processing, unauthorized disclosure, and unauthorized access, consistent with Sections 28 and 30 of NPC Circular 2023-06.

7. Personal Data Breach Notification

7.1 Notice to the Firm, Within 48 Hours

Esqase will notify the Firm of a Security Incident or Personal Data Breach affecting Personal Data processed under this PH DPA without undue delay, and in any event within forty-eight (48) hours of knowledge or reasonable belief.

The window matters more here than in most jurisdictions. Under Section 38(a) of the IRR the 72-hour clock for notifying the Commission and affected Data Subjects starts on knowledge of, or reasonable belief by, the PIC or the PIP. Esqase's own knowledge therefore starts the Firm's clock, and this Section is written to leave the Firm the greater part of it.

Esqase will not delay the initial notification in order to complete its investigation.

7.2 What the Notice Contains

The notification will state, to the extent known at the time, and will be supplemented as more becomes known:

  • the nature of the breach, including how it happened, when it occurred, and when it was discovered;
  • the Personal Data possibly involved, including whether Sensitive Personal Information or Privileged Information is involved;
  • the categories and approximate number of Data Subjects affected;
  • the likely consequences;
  • the measures Esqase has taken or proposes to take to address the breach and to reduce its harm or negative consequences; and
  • the name and contact details of the person at Esqase from whom the Firm can obtain further information.

Those are the contents Section 39 of the IRR requires the Firm's own notification to carry, so the Firm can build its report from what it receives.

7.3 Who Notifies the Commission

The Firm decides whether a breach is notifiable and makes the notification to the Commission and to affected Data Subjects. Esqase will not notify the Commission or any Data Subject on the Firm's behalf unless the Firm instructs it to in writing. Esqase will provide the information and cooperation the Firm reasonably needs for its notification and for any subsequent investigation by the Commission, including an on-site examination under Section 38(c) of the IRR to the extent it concerns Esqase's processing.

7.4 Documentation and Mitigation

Esqase documents every Security Incident and Personal Data Breach in a written report and will make the report available to the Firm on request, so that the Firm can meet its documentation duty under Section 41(b) of the IRR. Esqase will take reasonable steps to mitigate the effect of any breach.

7.5 Not an Admission

A notification under this Section is not an acknowledgement by Esqase of fault or liability.

8. Data Subject Requests

Esqase will provide the Firm with reasonable technical and organizational assistance to help it respond to a Data Subject exercising a right under Chapter IV of the Act, including the rights to be informed, to object, to access, to rectification, to erasure or blocking, to damages, and to data portability.

Most requests can be met by the Firm itself: Authorized Users can search, read, correct, export, and delete the Firm's records in the Service. Where a request cannot be met that way, Esqase will assist within 10 business days of the Firm's written request.

If Esqase receives a request directly from a Data Subject, it will promptly inform the Firm and will not respond to the request on the Firm's behalf, unless the Firm instructs it to or the law requires Esqase to respond.

9. Audits and Inspections

Esqase will make available to the Firm the information reasonably necessary to demonstrate compliance with this PH DPA and with the Act, and will allow for and contribute to audits, including inspections, conducted by the Firm or by an auditor the Firm mandates.

Esqase will ordinarily satisfy a request by providing its current security documentation, a description of the controls it maintains and monitors, its Sub-processor list, and a completed security questionnaire. Where that documentation does not answer the request, the Firm may audit on the following terms: no more than once in any twelve-month period, unless a Personal Data Breach has occurred or the Act, the Commission, or another regulator requires otherwise; on at least 30 days' prior written notice; during normal business hours; at the Firm's expense; under an agreed scope; in a manner that minimizes disruption to Esqase's operations; and without extending to the data or systems of any other customer. Esqase may approve the auditor in advance, such approval not to be unreasonably withheld, and may require the Firm and its auditors to execute a reasonable confidentiality agreement first.

Nothing in this Section limits the Commission's own authority to investigate or to conduct a compliance check.

10. Return and Deletion of Personal Data

10.1 Export

While the Subscription is active, and during the recovery period in Section 10.2, Authorized Users may read and retrieve the Firm's records in the Service and download documents, invoices, and other records individually, and the Firm Owner may export the Firm's records as a machine-readable file from the billing settings. Section 18.5 of the Terms of Service states what that export covers and the limits on it. On the Firm's written request made during that period, Esqase will provide the remaining categories of Personal Data it holds for the Firm in a structured, commonly used, and machine-readable format.

A Firm that moves from the Professional plan to the Standard plan keeps its personal injury records. They are retained, not deleted, and the Firm Owner can export them at any time from its billing settings.

10.2 Deletion

This is what happens, and when.

  • On termination, records are marked deleted rather than erased. Deleting a Firm ends its Subscription and marks the Firm and its records deleted. They are not visible in the Service and are not processed for any purpose other than restoring them.
  • A 30-day recovery window. Esqase retains Personal Data for 30 days after the Account is terminated so that the Firm can recover it, as Section 18.5 of the Terms of Service provides.
  • Then the primary stores are purged. At the end of that period Esqase deletes or anonymizes Personal Data in the database and the file storage, in a manner that meets Section 6.3. On the Firm's written request Esqase will act sooner, and will confirm in writing when the deletion is complete.
  • Backups expire on the platform's own schedule. Backup copies of the database and the file storage are made and expired by the underlying Google Cloud services. They cannot be edited or selectively purged, and Personal Data in them is deleted when the backup that holds it expires, within an outer bound of 90 days.
  • The audit trail is kept. The audit log described in Section 6.1 is append-only: a database trigger refuses any deletion, and it is retained for at least six years. It records who did what, when, and to which record, and an entry may include an identifier or a name. It is not deleted on termination. Esqase retains it under Section 10.3 as a record required for accountability under the Act and by Section 29 of NPC Circular 2023-06, keeps it isolated from further processing, and uses it only to evidence what was done in the Service.

10.3 Retention Required by Law

Esqase may retain Personal Data where applicable law requires it, or where it is subject to a legal hold. Where it does, Esqase will retain only what is required, keep it isolated from further processing, continue to protect it under Section 6, notify the Firm of the retention obligation, and delete it when the obligation ends. The append-only audit log is the one record Esqase cannot delete on request; it is retained for the period stated in Section 10.2.

11. Artificial Intelligence and No Training on the Firm's Content

The Service can use Google's Vertex AI to make records findable. Two things happen, and they are not the same:

  • Document indexing. Where the Firm turns this on, the contents of documents the Firm uploads to or writes in the Service, which may include Sensitive Personal Information and Privileged Information, are sent to a Google Gemini model, which returns a short description and keywords that Esqase stores with the document and uses for search. This is off by default for a Firm that accepts this PH DPA. Accepting this PH DPA switches it off for the whole Firm, and a Firm Owner must turn it back on deliberately in the Service's settings. A personal injury case carries a second switch of its own, which also starts off, so a document on a personal injury matter is sent only when both are on. Turning a switch off stops documents added or updated after that point from being sent; it does not delete output already stored.
  • Search embeddings. Text drawn from records including contacts, matters, tasks, events, notes, documents, invoices, payments, activities, communication logs, form submissions, firm members, and invitations is sent to a Google text embedding model, which returns the numeric representations that power search. Search terms entered in the Service are sent to the same model so that a query can be compared against those records. This processing is required for search to function and is not covered by the switch described above. A Firm that does not want a category of Personal Data processed this way should not put it in a searchable record.

For a Firm in the Philippines, both take place in the United States.

Esqase does not use Personal Data to train, fine-tune, or improve any artificial intelligence or machine learning model, its own or anyone else's, and its agreement with Google prohibits Google from using Personal Data to train or fine-tune Google's models without Esqase's prior permission or instruction, which Esqase does not give. Model output is stored within the Firm's own tenant and is not used for any other Firm. No decision about any Data Subject is made by these models, so the processing is not automated decision-making that produces a legal effect on a Data Subject.

12. Confidentiality and Privilege

Personal Data in the Service will ordinarily include Privileged Information as Section 3(k) of the Act defines it. Esqase treats all Client Data as confidential, as Section 5.4 of the Terms of Service provides, and:

  • accesses it only as necessary to provide, support, or secure the Service, or as the Firm instructs, or as required by law;
  • does not disclose it to another Firm or to any third party except to a Sub-processor listed in Section 5.2 for the purpose stated against it, or as Section 4.10 permits;
  • does not assert, waive, or purport to waive any privilege or protection over it, and will not do so on the Firm's behalf; and
  • will refer a demand for it to the Firm where it is able to do so, so that the Firm can assert privilege itself.

The parties do not intend Esqase's processing of Privileged Information as a PIP to waive any privilege, work product protection, or professional secrecy, and this PH DPA is to be read consistently with that intention. Esqase does not process Sensitive Personal Information or Privileged Information for any purpose of its own, and the Firm is responsible for holding a basis for its processing under Sections 12 and 13 of the Act.

13. Obligations of the Firm

13.1 Lawful Basis and Notices

The Firm is responsible for the accuracy, quality, and lawfulness of the Personal Data it submits, for the means by which it obtained it, and for holding a criterion for lawful processing under Section 12 of the Act and, for Sensitive Personal Information and Privileged Information, under Section 13. The Firm will give the notices to, and obtain the consents from, Data Subjects that are necessary for Esqase and its Sub-processors to process Personal Data as this PH DPA describes.

13.2 Its Own Compliance Program

The Firm remains responsible for its own obligations as a PIC, including those in Section 4 of NPC Circular 2023-06: designating and registering its Data Protection Officer, registering its data processing systems where required, keeping an inventory of them, conducting a privacy impact assessment, maintaining a privacy management program, training its personnel, and complying with the orders of the Commission.

13.3 Configuration and Sharing

The Firm decides which Authorized Users and External Users may access which records, including through document sharing, eSignature requests, booking pages, intake forms, and payment pages. Esqase acts on those configuration choices as instructions from the Firm.

13.4 Account Security

The Firm is responsible for the security of its own accounts, for removing an Authorized User who leaves, and for the roles it grants.

14. Duration, Termination, and Survival

This PH DPA takes effect when the Firm accepts it and remains in effect for as long as Esqase processes Personal Data on the Firm's behalf. Sections 4.2, 4.7, 6, 7, 9, 10, 11, 12, 15, and 16 survive its termination for as long as Esqase holds Personal Data and for as long thereafter as is necessary to give them effect.

Either party may terminate this PH DPA on written notice if the other materially breaches it and does not cure the breach within 30 days. Termination of the Subscription terminates this PH DPA, subject to Section 10 and to the survival stated above.

15. Precedence, Changes, and Acceptance

15.1 Precedence

For a Firm to which the Act applies, this PH DPA prevails over the Data Processing Agreement and over the Terms of Service where they conflict on the processing of Personal Data. In all other respects those agreements govern, and this PH DPA is read together with them. Where this PH DPA is silent, the Data Processing Agreement applies, including its Section 19 on country-specific terms and the Philippines Supplement that Section refers to.

Esqase offers one country-specific agreement to a Firm: this PH DPA, or the Business Associate Agreement, according to the country recorded in the Firm's settings. If a Firm has accepted both, the one that matches the Firm's currently registered country governs, and the other has no effect for as long as that remains the registered country.

15.2 No Reduction of Statutory Protection

Nothing in this PH DPA reduces a protection the Act, the IRR, or an issuance of the Commission requires. Any provision that would do so is read down to the extent necessary to comply.

15.3 Changes

Esqase may update this PH DPA where the change is required by law or by an issuance of the Commission, reflects a change to the Service, or updates the Sub-processor list in Section 5.2. Esqase will post the updated document at esqase.com/ph/data-processing-agreement, revise the version identifier and the Last updated date, and, where a change materially reduces the protections in it, notify the Firm by email at least 14 days before it takes effect. A change to the Sub-processor list is made on the notice period in Section 5.3.

15.4 Limitation of Liability

Each party's liability under this PH DPA is subject to the limitations in Section 16 of the Terms of Service, to the extent the Act permits those limitations to apply.

15.5 Acceptance

This PH DPA is entered into when a person authorized to bind the Firm accepts it in the Service. Esqase records the acceptance, the version accepted, the name and title of the person who accepted it, and the date and time. A Firm that requires a countersigned copy may request one at legal@esqase.com; a countersigned copy records the same terms and does not vary them.

16. Governing Law and Venue

This PH DPA is governed by the laws of the Republic of the Philippines as to the rights and obligations the Act, the IRR, and the issuances of the Commission create, and in all other respects by the law stated in Section 19 of the Terms of Service. Nothing in this Section, and nothing in the arbitration provisions of the Terms of Service, limits the jurisdiction of the Commission or of the Philippine courts over a matter the Act reserves to them, or a Data Subject's right to complain to the Commission.

17. Contact

For questions about this PH DPA, to give a notice under it, or to request a countersigned copy, contact:

Esqase, Inc.
Attention: Data Protection Officer
2810 N Church St STE 89268
Wilmington, DE 19802, United States
legal@esqase.com

Esqase's designated Data Protection Officer, who also serves as its Compliance Officer for Privacy for the purposes of the Act, is Kristoffer Bello, reachable at the address above. Esqase acknowledges a request under this PH DPA within five business days and responds within the period the Act allows.

Isang plataporma para sa buong praktis ninyo