VitrifAI
  • Services
  • Operating method
  • Scope & retainers
  • Leadership
  • FAQ
Book a 30-minute call

Privacy notice

Last updated: October 9, 2026

Who I am

I'm Charlemagne R. Dumaya, trading as VitrifAI. For the personal data described in this notice, I'm the personal information controller under the Data Privacy Act of 2012 (Republic Act No. 10173).

I'm also VitrifAI's designated data protection officer (DPO), so I handle privacy questions and requests myself. You can reach me at [email protected], or by mail at 11 Kapwa Street, Marikina City, Metro Manila, Philippines.

What this notice covers

This notice covers personal data I collect when you:

  • visit vitrifai.com
  • book a call through my Calendly page
  • email me
  • talk with me before we sign an engagement

Personal data I handle for clients during an engagement is covered by our engagement agreement, not by this notice.

What I collect and why

When you visit the website

The website itself sets no cookies and runs no analytics or tracking scripts. Its fonts and images are built into the page, so loading it doesn't contact any server other than my web host's.

My website runs on Cloudflare Pages. To deliver the site and protect it from attacks, Cloudflare processes technical data about each visit, such as your IP address, your browser and device details, and the pages you request. Cloudflare does this on my behalf, as my processor. If Cloudflare needs to check that a visitor isn't an automated bot, it may set a security cookie.

The cost estimators run entirely in your browser. Your selections are never sent to me.

When you book and join a call

Booking runs through Calendly. Calendly collects your name, your email address, the time you choose, and anything you type into the booking form. Calendly processes these booking details on my behalf, as my processor, under its Data Processing Addendum. I receive them so I can prepare for the call and hold it. Calendly also adds each booking to my Google Calendar with a Google Meet link for the call, so Google LLC stores those booking details too.

We hold the call on Google Meet. When you join, Google processes technical data about your connection, such as your IP address and device details, along with the call's audio and video, under its own privacy policy.

Calendly's booking page also uses Calendly's own cookies, which Calendly manages under its privacy notice.

When you email me

I receive your name and email address, along with whatever your message contains. I use them to reply and to keep a record of our conversation. My email runs on Proton, which stores messages in encrypted form on its own servers in Switzerland, Germany, or Norway.

Please don't send sensitive personal information, such as health records or government ID numbers, before we have an engagement in place. If you send it anyway, I'll use it only to reply, then delete it within 72 hours.

When you follow a link to LinkedIn

Once you leave this site, LinkedIn's privacy policy applies.

Why I'm allowed to process your data

Section 12 of the Data Privacy Act lists the grounds for lawful processing. I rely on these:

  • Steps you ask me to take before a contract (Section 12(b)). This covers replying to your inquiry and preparing a proposal you asked for.
  • Legitimate interests (Section 12(f)). This covers keeping records of business conversations and keeping the website secure. I collect only what these purposes need, and I've weighed them against your rights.
  • Legal obligations (Section 12(c)). This covers keeping business and tax records if you become a client.

I don't sell your data or use it for advertising. I don't make automated decisions about you.

Who receives your data

I share personal data only with the providers listed below.

Provider What it does for me Where it may process data
Calendly, LLC Schedules calls, as my processor The United States, and other countries where Calendly's service providers operate
Google LLC Keeps my calendar, which Calendly updates with each booking, and hosts our video calls on Google Meet Servers around the world, including outside the Philippines
Proton AG Handles my email Switzerland, Germany, or Norway
Cloudflare, Inc. Hosts and delivers the website (Cloudflare Pages), as my processor Mainly the United States and the European Economic Area, with access from other countries where Cloudflare operates

I may also disclose personal data when the law requires it, for example to comply with a lawful order.

Transfers outside the Philippines

All four providers store or process data outside the Philippines. I stay responsible for that data under the Data Privacy Act, and each provider commits to safeguards of its own. Calendly processes booking details under its Data Processing Addendum. Google handles calendar and Google Meet data under its own privacy policy. Proton keeps data encrypted on servers it owns and operates. Cloudflare holds certifications under the Global Cross-Border Privacy Rules (CBPR) and Privacy Recognition for Processors (PRP) systems.

How long I keep your data

Data How long it's kept
Booking details (in Calendly and my calendar) and emails that don't lead to an engagement 2 years after our last contact
Sensitive personal information sent before an engagement Deleted within 72 hours
Records for clients 5 years from the day after the tax-filing deadline for the year they were recorded, as Section 235 of the National Internal Revenue Code requires
Website visit data that Cloudflare processes Cloudflare doesn't publish a fixed period. It keeps this data only as long as its business purposes or legal obligations require, then deletes it.

When a period ends, I delete the data or anonymize it.

How I protect your data

Only I can access these records. The website uses encrypted connections (HTTPS), and I use multi-factor authentication on my email and scheduling accounts.

Your rights

Under Sections 16 and 18 of the Data Privacy Act, you have the right to:

  • be informed about how your data is processed
  • access your data
  • object to processing
  • have inaccurate data corrected
  • have your data blocked, removed, or destroyed
  • get your data in a portable electronic format
  • claim damages if unlawful or inaccurate processing of your data harms you

To use any of these rights, email me at [email protected]. I'll reply within 72 hours, and I may ask you to confirm your identity first.

Complaints

If you have a concern, please contact me first so I can try to fix it. The National Privacy Commission's rules also make this the first step. Under those rules, a complaint generally moves forward only after you've told me about the problem in writing, and I either didn't act on it in a timely or appropriate way, or didn't reply within 15 calendar days (NPC Circular 2021-01, Rule II, Section 2).

After that, you can file a complaint with the National Privacy Commission through privacy.gov.ph.

Children

This website and my services are for businesses. They aren't directed at children, and I don't knowingly collect children's data.

Changes to this notice

When I change this notice, I'll update the date at the top. If a change affects how I use data you've already given me, I'll tell you before it takes effect.

VitrifAI

Delegated Data Protection Officer functions and fractional AI governance leadership.

Metro Manila, Republic of the Philippines

Practice Areas

  • Fractional DPO
  • Fractional CAIO
  • Operating method
  • Retainer estimator

Direct Contact

  • Book a 30-minute call
  • [email protected]
  • LinkedIn
  • Privacy notice
  • www.vitrifai.com
© 2026 VitrifAI. Charlemagne R. Dumaya, trading as VitrifAI. Advisory practice; not a law firm. Privacy notice
Regulatory references current as of October 8, 2026