1. Parties and roles
- Controller. The institution (the School). It determines the purposes and means of processing its students' and personnel's personal data.
- Processor. Web Solutions Inc. (WSI). It processes that personal data only on the School's documented instructions.
- Independent controller activity. For its own commercial records, such as billing contacts and pilot enquiries, WSI acts as a controller under its Privacy Notice, not as a processor for the School.
2. Subject matter, duration, nature and purpose
- Subject matter: provision of the WSI Health Sciences AI research and learning platform to the School.
- Duration: the term of the pilot or subscription, plus the deletion window in Section 9.
- Nature and purpose: hosting accounts, authenticating users, enforcing role based access, generating educational content and evidence grounded answers requested by users, and supporting the School.
- Types of personal data: name where provided, institutional email address, hashed authentication credentials, role, organization membership, and question or topic text submitted by users.
- Categories of data subjects: the School's students, faculty, librarians, and administrative staff who are given accounts.
- Sensitive personal information: not required by the Service and not to be submitted. The Service is not for patient records.
3. Processor obligations
- Process personal data only on the School's documented instructions, including on cross border transfer, unless required otherwise by Philippine law, in which case WSI informs the School unless legally prohibited.
- Ensure personnel authorised to process personal data are bound by confidentiality obligations that survive the engagement.
- Implement the security measures in Section 5 and keep them under review.
- Assist the School, to the extent reasonable, in responding to data subject requests, in privacy impact assessments, and in consultations with the National Privacy Commission.
- Make available the information reasonably necessary to demonstrate compliance with this Agreement.
- Not process the School's personal data for WSI's own marketing, profiling, or model training purposes.
- Comply with the Data Privacy Act of 2012, its IRR, and applicable NPC circulars.
4. Controller obligations
- Ensure a lawful basis exists for the personal data it puts into the Service, including any required consent or notice to students.
- Issue its own privacy notice to its data subjects covering the use of the Service.
- Keep account rosters accurate, and revoke access for users who leave the institution.
- Ensure it holds the rights to any teaching material it uploads.
- Refrain from placing patient records or unnecessary sensitive personal information into the Service.
5. Security measures
- Organizational: role based access inside each workspace, least privilege, confidentiality obligations on personnel, a designated Data Protection Officer contact, and an incident response path.
- Technical: row level security in the database enforcing tenant isolation, privileged service credentials held server side only and never exposed to browsers or public build variables, HTTPS in transit, managed password hashing by the authentication provider, and session cookies scoped to the application.
- Physical: data centre controls operated by the hosting sub-processors named in Section 6.
- Review: measures are reviewed on material change to the Service and at least annually.
6. Sub-processors and sub-processing consent
The School gives general written authorisation for WSI to engage the sub-processors below. WSI imposes data protection obligations on each of them no less protective than this Agreement and remains fully liable to the School for their performance.
Supabase
Managed Postgres database, authentication and row level tenancy for account data.
Account email, hashed credentials, organization name, role, membership records. Cloud hosted, region selected at project setup.
Vercel
Application hosting, edge delivery and request logging for the web application.
Request metadata such as IP address and user agent, session cookies in transit. Global edge network.
Large language model provider
Generation of lesson text and grounded answer drafts from the question and retrieved sources.
The submitted question text and retrieved public source excerpts. No account credentials are sent. Provider cloud. The active provider is disclosed to each institution before a pilot starts.
WSI notifies the School in writing at least 30 days before adding or replacing a sub-processor. The School may object on reasonable data protection grounds within that period, and if the parties cannot agree on an alternative, the School may terminate the affected part of the Service without penalty for the unused portion of the term.
7. Cross border transfer
Some sub-processors operate outside the Philippines. WSI remains accountable for personal data transferred abroad under Section 21 of RA 10173 and secures contractual commitments requiring a comparable level of protection from each recipient.
8. Personal data breach
If a personal data breach affects sensitive personal information or information that may enable identity fraud, and there is a real risk of serious harm, we will notify the National Privacy Commission and the affected data subjects within 72 hours of knowledge of the breach, in line with the Data Privacy Act of 2012 and NPC Circular 16-03. Institutional administrators are notified in parallel so the school can meet its own controller obligations.
- WSI notifies the School's designated contact without undue delay and in any case within 24 hours of becoming aware of a breach affecting the School's personal data.
- The notice describes the nature of the breach, the categories and approximate number of records involved, the likely consequences, and the measures taken or proposed.
- WSI cooperates with the School's own notification duty to the National Privacy Commission and to affected data subjects.
- WSI keeps a record of breaches and remediation actions and makes the relevant entries available to the School.
9. Return and deletion on termination
- On termination or on written request, WSI deletes the School's organization record and all membership records linking users to that organization.
- Deletion is completed within 30 days of the request, and WSI confirms completion in writing.
- Individual authentication accounts are not deleted automatically, because one person may hold membership in more than one institution. WSI deletes a named account on request from the account holder or the School where the School is the sole affiliation.
- Backups and hosting logs age out under the sub-processor's standard retention window and are not restored into production after deletion.
- WSI may retain data where Philippine law requires retention, and only for as long as required.
10. Audit
On reasonable written notice, no more than once in any twelve month period unless a breach has occurred, WSI responds to a documented security questionnaire from the School and provides available assurance material about its sub-processors. On site audits are by agreement and at the School's cost.
11. Liability and precedence
Liability under this Agreement is subject to the limitations in the Terms of Service or the signed institutional agreement. In case of conflict between this Agreement and the Terms of Service on the processing of the School's personal data, this Agreement prevails.
12. Governing law
This Agreement is governed by the laws of the Republic of the Philippines, with venue as stated in the signed institutional agreement.
Annex A. Contacts
Processor contact
Web Solutions Inc.
privacy@wsi.asia
Placeholder contact, to be confirmed when the Data Protection Officer is formally designated.
Controller contact
To be completed by the School: name of institution, Data Protection Officer, and notification email address.