Privacy
Privacy Policy
Effective date:
The short version
- We collect what you send us through the contact form, plus a little technical data to keep the site secure.
- We use it to reply to you and to stop spam. We don't sell it, and we don't use advertising or tracking cookies.
- Enquiries are deleted automatically after 24 months.
Who we are
This website is run by DGoodman Corp, La Trinidad, Benguet, Philippines ("we", "us"). We are the personal information controller for the data described here, and we handle it in line with the Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules.
For questions about this Privacy Policy, how we handle your personal data, or to exercise your data privacy rights, contact us at [email protected].
What we collect
When you contact us
- Your name, email address and, if you give them, your company, budget and timeline.
- The type of project and your message.
- The time you agreed to this policy.
Automatically, when you use the contact form
- A one-way, keyed hash of your IP address. We store the hash, never the address itself, so we can spot abuse.
- Your browser's user agent (browser and operating system).
- The page on this site that led you to the contact form, and campaign tags in the link you followed (for example
utm_source).
To keep the site working and secure
- A session record containing your IP address and browser, kept for up to 2 hours after your last visit.
- A temporary counter linked to your IP address that limits how many messages can be sent per hour. It expires after an hour.
- Web server logs, which record IP addresses and requested pages. These are kept for up to 14 days.
How we use it, and why
- To reply to your enquiry and, if you want, prepare a quote or proposal. This is based on your consent and on steps you've asked us to take before a possible contract.
- To protect the site and our inbox from spam and abuse (hashed IPs, rate limits, spam checks). This is in our legitimate interest in running a secure website.
- To understand which pages lead people to get in touch, using the source page and campaign tags stored with an enquiry. This is in our legitimate interest in improving the website.
We don't use your data for automated decision-making, and we don't add you to a mailing list.
Cookies
We only use cookies the site needs to work. We don't use advertising or tracking cookies, so there's no cookie banner.
| Cookie | Purpose | Lasts |
|---|---|---|
dgoodman-corp-session | Keeps your session, for example form errors and the confirmation message. | 2 hours |
XSRF-TOKEN | Protects forms against cross-site request forgery. | 2 hours |
| Cloudflare security cookies | Set by Cloudflare to detect bots and protect the site. | Up to 30 minutes |
We measure visits with Cloudflare Web Analytics, which doesn't use cookies or follow you across other websites.
Who processes it for us
We don't sell or rent your data. We use these service providers, who process it only on our instructions:
- Cloudflare: delivers and protects the website, runs the spam check on the contact form (which receives your IP address), and provides cookie-free visit statistics.
- DigitalOcean: hosts the website, its database and encrypted backups in Singapore.
- Postmark: sends the confirmation email to you and the enquiry notification to us. Postmark processes email in the United States.
We may also share data with professional advisers or authorities when the law requires it.
Some of this processing happens outside the Philippines: hosting in Singapore, email in the United States, and Cloudflare's global network. We remain responsible for your data when a provider processes it for us, and we rely on our providers' contractual and security safeguards to protect it.
How long we keep it
- Enquiries: deleted automatically 24 months after you send them. If you become a client, we keep project and contract records separately, for as long as that work and our legal obligations require.
- Backups: deleted data can remain in encrypted backups for up to 14 days before the backup itself expires.
- Sessions and rate-limit counters: as listed above, a few hours at most.
How we protect it
We use reasonable and appropriate organizational, physical and technical measures to protect your data. The site is served only over HTTPS. We store IP addresses only as keyed hashes, keep the database off the public internet, and limit access to the people who need it. No method of transmission or storage is perfectly secure, but we work to protect your data and will act on any breach as the law requires.
Your rights
Under the Data Privacy Act of 2012, you have the right to:
- be informed about how your personal data is processed;
- access the personal data we hold about you;
- object to processing, including withdrawing your consent;
- have inaccurate or incomplete data corrected;
- have your data erased or blocked;
- receive your data in an electronic, commonly used format (data portability);
- be compensated for damages caused by inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorized use of your data; and
- file a complaint with the National Privacy Commission.
Withdrawing consent doesn't affect processing we did before. To exercise any of these rights, contact us at the address above. We'll respond as soon as we can, and within the period set by law. You can reach the National Privacy Commission at privacy.gov.ph.
Links to other websites
Our case studies link to other websites and apps, such as products we've built. Those have their own privacy policies, and this policy doesn't cover them. Check their policies before giving them any personal data.
Children
This website is for businesses and isn't aimed at children. We don't knowingly collect personal data from anyone under 18.
Changes to this policy
If we change how we handle personal data, we'll update this page and the date at the top.