How We Handle Personal Data
Effective date: 1 January 2026 · Jurisdiction: Republic of the Philippines
Nexa Luna Solutions (“Nexa Luna”, “we”, “our” or “us”) is committed to protecting the personal data of every individual who interacts with this corporate website or any of the digital platforms we operate. This Privacy Policy explains what personal data we collect, how we use it, the lawful criteria for processing it, and the rights you have under the laws of the Republic of the Philippines — in particular the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission (NPC).
1. Who we are (Personal Information Controller)
NexaLuna Solutions.PH Information Technology Services (DTI Business Name No. 8466810, sole proprietorship of Rhea Alpine Estanislao Santos), trading as “Nexa Luna Solutions”, is the Personal Information Controller responsible for the personal data collected through this corporate website (nexaluna.ph) and through the consumer-facing platforms that we own and operate. Each operated platform may publish its own platform-specific privacy notice, which applies in addition to this Policy.
We have designated a Data Protection Officer in accordance with NPC Advisory No. 2017-01. For all privacy-related enquiries, contact our Data Protection Officer at privacy@nexaluna.world.
2. Personal data we collect
Depending on how you interact with us, we may collect:
- Identification & contact data: name, company name, email, phone number, country.
- Communications data: messages submitted via the contact form, email correspondence, support tickets.
- Technical & device data: IP address, browser type, device identifiers, language, time-zone, referring URL.
- Usage data: pages visited, interactions, session duration, performance and diagnostic logs.
- Transactional data (operated platforms only): order, subscription and payment metadata processed by BSP-supervised payment service providers.
We do not knowingly collect sensitive personal information (as defined in Section 3(l) of the Data Privacy Act, e.g. health, religion, government-issued identifiers) through this corporate website. We do not knowingly process the personal data of minors under 18 without the consent of a parent or legal guardian.
3. Lawful criteria for processing (Data Privacy Act, Sections 12 and 13)
We process personal data only where a lawful criterion under the Data Privacy Act applies, namely:
- Consent — for marketing communications, optional analytics, and non-essential cookies.
- Performance of a contract — to deliver services you have requested or subscribed to.
- Legal obligation — to comply with Philippine tax, anti-money-laundering, corporate and regulatory requirements.
- Legitimate interests — for fraud prevention, network security, platform improvement, and corporate communications, where not overridden by your fundamental rights.
4. How we use personal data
We use personal data to:
- Respond to enquiries submitted via the contact form;
- Operate, secure, monitor and improve our website and platforms;
- Comply with Philippine law, regulatory requests and lawful court orders or subpoenas;
- Detect, prevent and investigate fraud, abuse and cyber-incidents;
- Send service updates and, where permitted, marketing communications you can opt out of at any time.
5. Sharing & disclosure
We do not sell personal data. We may share personal data with:
- Vetted Personal Information Processors providing hosting, analytics, communications, payments and support services, under written outsourcing or data-sharing agreements as required by the NPC;
- Professional advisers (legal, audit, compliance) under confidentiality obligations;
- Competent Philippine authorities where required by law, including the NPC, the Bureau of Internal Revenue, the Anti-Money Laundering Council, the Department of Trade and Industry, and law-enforcement units acting under the Cybercrime Prevention Act (Republic Act No. 10175).
6. Cross-border data transfers
Some of our service providers process data outside the Philippines. Where personal data is transferred abroad, Nexa Luna remains accountable for it under Section 21 of the Data Privacy Act and uses contractual and technical safeguards (including data-processing agreements, encryption and access controls) to ensure a comparable level of protection.
7. Data retention
We retain personal data only for as long as necessary for the purposes set out in this Policy and to comply with our legal obligations under Philippine corporate, tax and AML legislation (generally ten (10) years for books of account and transactional records under BIR Revenue Regulations No. 17-2013, and five (5) years for AML records). When no longer required, data is securely deleted or irreversibly anonymised.
8. Security
We implement the organisational, physical and technical security measures required by the Data Privacy Act and its IRR — including encryption in transit (TLS), access controls, least-privilege principles, secure development practices, monitoring and incident-response procedures — to protect personal data against unauthorised access, loss, alteration or disclosure.
9. Your rights as a data subject
Subject to the Data Privacy Act and its exemptions, you have the right to:
- Be informed about, and have access to, your personal data;
- Object to the processing of your personal data;
- Request rectification of inaccurate or incomplete data;
- Request the erasure or blocking of your personal data;
- Data portability, where processing is by electronic means and in a structured format;
- Be indemnified for damages sustained due to inaccurate, incomplete, outdated, false or unlawfully obtained personal data;
- Withdraw consent at any time, without affecting prior lawful processing;
- Lodge a complaint with the National Privacy Commission.
To exercise any of these rights, email privacy@nexaluna.world. We respond within the time-frames set by the NPC (as a rule, within fifteen (15) days of receipt of a valid request).
10. Data breach notification
In the event of a personal data breach that meets the criteria of NPC Circular No. 16-03, Nexa Luna will notify the National Privacy Commission and the affected data subjects within seventy-two (72) hours of knowledge of, or reasonable belief in, the breach.
11. Changes to this Policy
We may update this Privacy Policy from time to time. The “Effective date” at the top reflects the latest revision. Material changes will be communicated through this website or by direct notification where appropriate.
