Privacy Notice
Last updated 2026-08-20
Who this is from
Sentro is software used by licensed Philippine financial advisers and their agencies to manage their client relationships. It is operated by [Registered entity].
This notice explains what we do with personal data, and is given under the Data Privacy Act of 2012 (Republic Act No. 10173).
Who controls your data depends on who you are
This distinction matters, and it decides who you should contact.
If you are an adviser or agency staff member, we are the personal information controller for your account. You deal with us directly.
If you are a client of an adviser, your adviser’s agency is the personal information controller. They decided to collect your data and they decide what happens to it. We are only a personal information processor: we hold and process it on their instructions and do not use it for our own purposes. To exercise your rights over that data, contact your adviser or their agency. We will help them respond, but we cannot act on their records without their instruction.
What we hold about advisers
Adviser account
- Full name
- Email address
- Mobile number
- Profile photo
- Insurance licence number
- Password (stored only as an argon2id hash)
Why: To create and secure your account, identify you within your agency, and contact you about the service.
Lawful basis: Performance of our contract with you or your agency.
Technical and security records
- IP address at sign-in and on public form submissions
- Session records
- Audit log of changes made, with the user who made them
- Email delivery logs
Why: To keep accounts secure, investigate misuse, and be able to reconstruct who changed what.
Lawful basis: Our legitimate interest in operating the service securely, and our obligations under RA 10173 to account for processing.
What advisers record about their clients
Advisers use Sentro to record the following about the people they serve. We hold this on the agency’s behalf.
Client identity and contact details
- Name, including middle and preferred name
- Date of birth
- Gender
- Civil status
- Email, mobile and alternate phone
- City, province, postal code and country
Why: So an adviser can identify, contact and service the people in their book.
Lawful basis: Consent obtained by the adviser, or the legitimate interests of the agency in servicing an existing relationship.
Client financial and employment information
- Occupation and employer
- Annual income band
- Policies held, premiums, payment history
- Fund holdings and valuations
- Needs-analysis inputs and results
Why: To prepare a financial needs analysis, service policies, and track premiums falling due.
Lawful basis: Consent, and performance of the insurance relationship the adviser holds with the client.
Health-related and beneficiary informationSensitive
- Benefits attached to a policy, including critical illness, disability and hospital cover
- Beneficiary names, relationships and dates of birth
- Any health information an adviser records in notes or uploads as a document
Why: To record what a policy covers and who benefits from it.
Lawful basis: The data subject's consent, which RA 10173 requires to be specific for sensitive personal information.
Messages, documents and files
- Messages between an adviser and a client
- Uploaded documents, forms and attachments
- Appointment records and interaction notes
Why: To hold the correspondence and paperwork of an advisory relationship in one place.
Lawful basis: Performance of the advisory relationship.
Sensitive personal information
Some of what advisers record is sensitive personal information under the Act — in particular health-related details, such as the critical illness, disability or hospital benefits attached to a policy, and anything an adviser notes or uploads about a person’s health.
The Act requires specific consent for this, given by the person concerned. Advisers are responsible for obtaining it, and Sentro records whether consent was given, when, and how it was captured.
Where your data is kept
Sentro runs on infrastructure located in Singapore (Southeast Asia), and email we send on your behalf is processed in Tokyo, Japan. Your data therefore leaves the Philippines. The Act permits this, and we remain accountable for it wherever it is held: the same protections in this notice apply, and our agreements with those providers require them to keep it secure.
How we protect it
- Connections are encrypted in transit (TLS).
- Passwords are never stored — only an argon2id hash of them.
- Access tokens for connected services, such as Google Calendar, are encrypted at rest.
- Every agency’s data is isolated from every other. Advisers see only their own clients; managers see their team’s; nobody sees another agency’s.
- Changes to records are written to an audit log recording who made them and when.
- Messages between an adviser and a client are private to the people in the conversation. Managers and agency administrators cannot read them.
Who else sees it
We do not sell personal data, and we do not use it for advertising.
We use a small number of service providers who process data on our behalf and only on our instructions: a hosting provider, an email delivery provider for notifications and sign-in links, and — only where an adviser explicitly connects it — Google Calendar. A calendar connection is made by the adviser, for their own diary, and can be disconnected by them at any time.
How long we keep it
For as long as the agency’s subscription is active and its records are needed for the advisory relationship. Insurance records commonly need to be kept for years after a policy ends, and the retention period is the agency’s decision as controller. When an agency leaves, we delete or return its data on request.
Your rights
Under the Act you have the following rights.
- To be informed
- You may ask whether your personal data is held, and why.
- To access
- You may ask for a copy of the personal data held about you.
- To object
- You may object to processing, including direct marketing, at any time.
- To correct
- You may have inaccurate or incomplete data corrected.
- To erasure or blocking
- You may ask for data to be removed or withheld where it is unlawful, unnecessary, or you have withdrawn consent.
- To data portability
- Where processing is by consent or contract and is automated, you may obtain your data in a structured, commonly used electronic format.
- To damages
- You may claim compensation for damage caused by inaccurate, unlawfully obtained or unauthorised use of your personal data.
- To complain
- You may lodge a complaint with the National Privacy Commission.
To exercise any of these, write to [privacy contact]. If you are a client of an adviser, contact your adviser’s agency first — they control your records.
If something goes wrong
If a personal data breach occurs that is likely to put anyone at risk, we notify the National Privacy Commission and the people affected within 72 hours of establishing it, as the Act requires. Where we hold the data as a processor, we notify the controlling agency immediately so they can meet that deadline.
Our Data Protection Officer
[Data Protection Officer]
You may also complain directly to the National Privacy Commission at privacy.gov.ph.