Mahayag Digital Invites, operated by Mahayag Printing, with business address at Purok 4, Doña Andrea, Asuncion, Davao del Norte, Philippines (“Mahayag,” “we,” “us,” or “our”), respects your privacy and is committed to protecting personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission (“NPC”).
This Privacy Policy explains what personal data we collect, why and how we process it, with whom it may be shared, how long it may be retained, and the rights available to data subjects.
This Policy applies to:
- clients and prospective clients who contact us, book a consultation, submit forms, or purchase our services;
- persons whose information is provided by a client for inclusion in an invitation;
- guests who use RSVP or other interactive features of a digital invitation we host; and
- visitors to our website and online pages where applicable.
1. Personal Data We May Collect
The information we collect depends on how you interact with Mahayag.
A. Information from clients and prospective clients
We may collect:
- full name;
- mobile or telephone number;
- email address;
- Messenger name, profile link, or preferred contact method;
- event type;
- event date and venue;
- estimated guest count;
- selected package or service;
- event theme, color preferences, and design preferences;
- names of couples, celebrants, parents, entourage members, sponsors, or other persons to be displayed in the invitation;
- event schedules and related details;
- photographs, videos, music, logos, graphics, and other content submitted for use in the invitation;
- messages, inquiries, revision requests, approvals, and other communications with us;
- payment transaction references and proof of payment; and
- any other information you voluntarily provide that is reasonably necessary to fulfill your request.
We generally do not need your full bank, e-wallet password, PIN, CVV, or similar authentication credentials and will never ask you to provide them.
B. Information submitted through RSVP features
Depending on how a particular invitation is configured, guests may provide:
- name;
- attendance response;
- number of attending guests;
- guest names;
- messages to the host;
- dietary preferences or restrictions;
- responses to event-specific questions; and
- other information requested by the event host.
We encourage clients to request only information reasonably necessary for their event.
C. Information relating to children
Some events involve children, including birthdays, baptisms, and christenings.
Names, photographs, or other information relating to children may be provided by the parent, guardian, or client arranging the event. We do not intentionally solicit personal information directly from children for marketing or unrelated purposes.
The person supplying a child's information is responsible for having appropriate authority to provide it.
D. Website and technical information
Depending on the tools enabled on our website, our systems or service providers may process technical information such as:
- IP address;
- browser and device information;
- date and time of access;
- pages viewed;
- form-submission information;
- cookies or similar technologies; and
- basic website analytics.
We will use such technologies only for legitimate operational, security, analytics, or marketing purposes permitted by applicable law and subject to appropriate notices or consent where required.
2. How We Collect Personal Data
Personal data may be collected through:
- our consultation or inquiry forms;
- our Client Details Form;
- RSVP forms embedded in digital invitations;
- Messenger, Facebook, email, telephone, SMS, or other communications;
- payment confirmation records;
- files and content uploaded or sent to us;
- our website and its hosting or analytics tools; and
- information provided to us by the client when preparing an event invitation.
Where a client provides personal information relating to other people, the client should have appropriate authority or another lawful basis to provide that information to us.
3. Why We Process Personal Data
We process personal data only for specific and legitimate purposes and aim to collect only information that is adequate, relevant, and reasonably necessary for those purposes. Philippine privacy rules require legitimate purpose, transparency, and proportionality in personal-data processing. Privacy Commission
We may process information to:
- respond to inquiries;
- arrange and conduct consultations;
- prepare quotations;
- process and confirm orders;
- verify payments;
- design, customize, host, and maintain digital invitations;
- communicate with clients about project requirements;
- send previews and receive approvals;
- process revision requests;
- publish event information authorized by the client;
- operate RSVP functionality;
- provide clients with RSVP information;
- provide customer support;
- maintain transaction and business records;
- prevent fraud or abuse;
- maintain the security and functionality of our systems;
- comply with applicable legal, accounting, tax, regulatory, or government requirements; and
- handle complaints, disputes, or legal claims.
4. Lawful Bases for Processing
Not every processing activity depends solely on consent.
Depending on the circumstances, we may process personal data because:
- you have given valid consent;
- processing is necessary to take steps at your request before entering into a contract;
- processing is necessary to perform our agreement with you;
- processing is necessary for compliance with a legal obligation;
- processing is necessary for legitimate interests that are not overridden by your rights and freedoms; or
- another lawful ground under Philippine law applies.
Where we specifically rely on consent, you may withdraw that consent subject to applicable law and subject to processing that may remain necessary under another lawful basis.
A privacy notice is still required even when processing relies on a lawful basis other than consent. Privacy Commission
5. Marketing Communications
Submitting a consultation form or purchasing a service does not automatically enroll you in unrelated promotional marketing.
Where we rely on your consent to send optional promotional offers or marketing messages, we will seek that consent separately when appropriate.
You may withdraw marketing consent or opt out of future promotional messages at any time by contacting us or using an available unsubscribe or opt-out method.
Service-related communications—such as payment confirmation, design previews, revision notices, delivery information, or hosting-expiration reminders—may still be sent where necessary to provide the service you requested.
6. RSVP and Guest Information
When an event guest submits an RSVP through an invitation we host, the information is processed so the event host can manage attendance and related event arrangements.
The event client generally determines why guest RSVP information is requested. Mahayag provides the technical functionality required to collect, store, display, and support that information as part of the digital invitation service.
Mahayag may also process RSVP information to the limited extent necessary for hosting, security, troubleshooting, customer support, and compliance with legal obligations.
Clients should not configure RSVP forms to request excessive or unnecessary personal information.
If an RSVP form requests potentially sensitive information, such as health-related dietary information, the request should be genuinely necessary and appropriately disclosed.
7. Sensitive Personal Information
Under Philippine law, certain categories of information receive heightened protection.
We do not intentionally request sensitive personal information unless it is reasonably necessary for the service or voluntarily and appropriately provided.
For example, dietary restrictions may sometimes disclose health-related information.
Where sensitive information is processed, we will take reasonable measures appropriate to its nature and the risks involved.
8. Photographs, Videos, and Event Content
Clients may provide photographs, videos, names, music, and other materials for publication in their digital invitation.
These materials will normally be used only to create, host, maintain, and support the requested invitation.
Because an invitation link may be shared with guests or forwarded by recipients, clients should consider carefully which information they choose to make visible on a published invitation.
Mahayag is not responsible for a recipient independently copying or redistributing information that was lawfully made available through the invitation, although we will take reasonable steps to protect information under our control.
9. Portfolio and Social Media Use
We do not automatically treat identifiable client photographs, names, or private event information as permission for advertising use.
If we want to feature an identifiable completed invitation or client content in our:
- portfolio;
- Facebook page;
- website;
- Instagram;
- TikTok;
- advertisements; or
- other promotional materials,
we may seek the client's permission.
We may use sufficiently anonymized design examples where individuals are no longer reasonably identifiable, subject to applicable law.
10. Payment Information
Payments may be made using payment services such as GCash, Maya, bank transfer, or other methods communicated to the client.
We may retain transaction references, payment confirmation records, and proof of payment where reasonably necessary for:
- verifying payments;
- customer support;
- bookkeeping;
- accounting;
- tax compliance; and
- dispute resolution.
We do not require or intentionally store your payment-platform passwords, OTPs, PINs, or similar authentication credentials.
11. Who May Receive Personal Data
We do not sell personal data to advertisers.
Personal information may, however, be processed or disclosed to service providers that are reasonably necessary for operating our business, such as:
- website and funnel hosting providers;
- GoHighLevel/Zappify and related infrastructure;
- cloud storage providers;
- domain and website hosting services;
- email or messaging providers;
- scheduling systems;
- payment providers;
- analytics or security providers; and
- other technical service providers supporting our business.
These providers may process data only to the extent reasonably necessary to provide their respective services or as permitted by law.
We may also disclose information:
- where required by Philippine law;
- in response to a lawful court order, subpoena, or government request;
- to protect our legal rights;
- to investigate fraud or security incidents; or
- where the data subject has authorized the disclosure.
The Data Privacy Act requires personal information controllers to ensure that third parties processing data on their behalf implement appropriate security measures. Privacy Commission
12. Overseas or Cloud Processing
Some service providers or their infrastructure may store or process data using servers located outside the Philippines.
Where this occurs, we will take reasonable steps appropriate to the circumstances to ensure that personal data remains protected consistently with applicable Philippine privacy requirements.
Use of an overseas technology provider does not remove our responsibility for personal data that we control.
13. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, legitimate business requirements, dispute resolution, or applicable legal obligations.
As a general operational guideline:
- invitation website and RSVP data may remain active for the validity or hosting period included in the client's package;
- once that service period expires, the invitation or dashboard may be disabled or removed;
- project files may be retained temporarily after completion to support revisions, troubleshooting, renewal, or recovery;
- transaction and accounting records may be retained for the period required by applicable tax, accounting, or legal requirements; and
- information that no longer has a legitimate purpose for retention may be securely deleted, anonymized, or otherwise disposed of.
The NPC requires data subjects to be informed about the retention period or the criteria used to determine it. Privacy Commission
A request for deletion does not necessarily require us to delete information that we must lawfully retain.
14. Security of Personal Data
We implement reasonable and appropriate organizational, physical, and technical safeguards designed to protect personal data against:
- unauthorized access;
- unlawful disclosure;
- alteration;
- misuse;
- destruction;
- loss; and
- other unlawful processing.
Measures may include access controls, password protection, secure cloud services, platform security settings, limited personnel access, backups, and reasonable monitoring or incident-response practices.
Philippine privacy law expressly requires reasonable and appropriate organizational, physical, and technical safeguards. Privacy Commission
No internet or electronic-storage system can guarantee absolute security, but we are responsible for taking reasonable measures appropriate to the risks of our processing.
15. Personal Data Breaches
We maintain procedures for responding to security incidents involving personal data.
Where a personal data breach meets the legal threshold requiring notification, we will notify the National Privacy Commission and affected data subjects within the time required by applicable law.
Under current NPC rules, qualifying breaches generally require notification within 72 hours after knowledge or reasonable belief that a reportable breach occurred. Privacy Commission
Not every minor security incident automatically triggers public or individual notification; the applicable legal criteria will be assessed based on the circumstances.
16. Your Rights as a Data Subject
Subject to the conditions and limitations provided by Philippine law, data subjects have rights including:
- Right to be informed — to know whether and how personal data is processed;
- Right to access — to request access to personal data held about you;
- Right to object — to object to certain processing;
- Right to rectification — to correct inaccurate or incomplete information;
- Right to erasure or blocking — to request deletion, suspension, withdrawal, or blocking where legally applicable;
- Right to data portability — where applicable, to obtain data in a structured and commonly used format;
- Right to damages — to seek compensation where allowed by law for violations of your privacy rights; and
- Right to file a complaint with the National Privacy Commission.
These rights are recognized by the Data Privacy Act and NPC guidance. Privacy Commission
17. How to Exercise Your Privacy Rights
To make a privacy request, contact us using the information at the end of this Policy.
Please provide enough information for us to:
- identify you;
- locate the relevant records; and
- understand your request.
We may take reasonable steps to verify your identity before disclosing, correcting, deleting, or transferring personal information.
We will respond within the timeframe required by applicable Philippine law and NPC rules.
18. Withdrawal of Consent
Where processing is based specifically on consent, you may withdraw your consent by contacting us.
Withdrawal will not affect processing that was lawful before the withdrawal.
It may also not apply where continued processing is permitted or required under another lawful basis—for example, where information must be retained to satisfy legal, accounting, or contractual obligations.
19. Cookies and Similar Technologies
Our website may use cookies or similar technologies necessary for:
- basic site functionality;
- forms;
- authentication;
- security;
- analytics; or
- advertising features that we choose to enable.
Where non-essential tracking technologies require consent under applicable rules, we will provide an appropriate consent mechanism.
Browser settings may also allow you to block or delete cookies, although doing so may interfere with some website functions.
If we later deploy advertising tools such as the Meta Pixel, Google Analytics, or comparable technologies, this Privacy Policy and our cookie notice should be updated to accurately describe those tools.
20. Automated Decision-Making
We do not currently make significant decisions about clients solely through automated decision-making or profiling.
If this changes, we will update our privacy notice as required.
The right to be informed includes information about automated decision-making or profiling where applicable. Privacy Commission
21. External Links and Messaging Platforms
Our website or digital invitations may link to:
- Google Maps;
- Facebook;
- Messenger;
- external payment services;
- social media platforms; or
- other third-party websites.
Those services operate under their own privacy policies and practices.
Mahayag does not control how independent third-party services process information once a user leaves our website or directly interacts with those third parties.
22. Changes to This Privacy Policy
We may update this Privacy Policy when our practices, systems, services, or legal obligations change.
The latest version will be posted on our website together with the Last Updated date.
If a change materially affects a processing activity that previously relied on consent, we will determine whether fresh consent or another notice is required under applicable Philippine privacy law.
NPC guidance indicates that fresh consent is not necessarily required merely because terms change when the purpose, scope, method, and extent of the processing remain the same as originally disclosed. Privacy Commission
23. Privacy Contact
Questions, concerns, requests, or complaints regarding personal data may be sent to:
Mahayag Digital Invites
Operated by Mahayag Printing
Business Address: Purok 4, Doña Andrea
Asuncion, Davao del Norte
Philippines
Email: [email protected]
Phone: +63 936 423 6388
Website: invites.kentorven.com
Facebook: Mahayag Printing and Digital Invitation Services
Privacy Contact Person: Kent Orven Julian
You do not necessarily need to publicly call this person your “Data Protection Officer” unless you have actually designated that person in accordance with your compliance arrangements. Using “Privacy Contact Person” is safer until you determine your formal NPC/DPO obligations.
24. Complaints to the National Privacy Commission
If you believe your rights under Philippine data privacy law have been violated, you may contact or file a complaint with the:
National Privacy Commission of the Philippines
Official website: privacy.gov.ph
You may first contact us so we have the opportunity to investigate and address your concern, but nothing in this Policy prevents you from exercising any right or remedy available under Philippine law.