Skip to content
Rooche
Platform Products FAQ Talk to us

Legal

Privacy Policy

Last updated: September 1, 2026 ← Back to home

This Privacy Policy explains how Rooche Digital IT Solutions, Inc. (“Rooche”, “we”, “us”), a corporation organized under the laws of the Republic of the Philippines, collects, uses, shares, protects, and retains personal data on the Rooche software platform. It is written to comply with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and issuances of the National Privacy Commission (NPC). For anything in this policy, you can reach us at hello@rooche.net.

Sections

  1. Scope
  2. Data we collect
  3. Sign-in providers
  4. Payments
  5. Why we process
  6. Sharing
  7. Retention
  8. Security
  9. Your rights
  10. Children
  11. Changes
  12. Contact

§1Scope — the platform and all its products

This policy applies platform-wide: to the Rooche platform itself, to all products delivered on it — currently Sumly (money ledger), Dunly (tasks), and Umento (proposals and invoicing) — and any product we add in the future, on every surface they run on (web, mobile, desktop). It covers both:

  • Organization workspaces at [company].rooche.biz/[product], where an organization administers its members’ accounts; and
  • Consumer versions at product apex domains such as sumly.rooche.biz, dunly.rooche.biz, and umento.rooche.biz, where you hold a personal account directly with us.

Individual products may publish product-specific privacy supplements at their own address (e.g. [product].rooche.biz/privacy). A supplement adds product-level detail; this platform policy governs wherever a supplement is silent or absent.

Roles under RA 10173. For personal accounts on consumer versions, Rooche is the personal information controller. For organization workspaces, the organization is the controller of the content its members create in the workspace, and Rooche processes that content on the organization’s behalf to provide the service; Rooche remains the controller of account, billing, and platform-operations data.

§2Personal data we collect

Account identifiers

When an account is created through our identity service (CEM) we collect the identifiers used to register: name, email address, and/or mobile phone number, plus a username and — for password sign-in — a password (stored only in hashed form, never in plain text).

Workspace and role data

For organization workspaces: which organization you belong to, your role and permissions, and which products you can access.

Product content you create

The content customers put into the products — for example, tasks and media in Dunly, records in Sumly, or proposals, invoices, and client details in Umento — is stored and processed to provide the service. This content belongs to the customer; we process it only to operate, secure, and support the products.

Support conversations

When you contact support from inside a product, we keep the conversation, including any attachments you send, tied to your account so we can help you and keep the history across your devices.

Technical and session data

Sign-in and session records, device/browser type, IP address, timestamps, and service logs generated as you use the platform. We use these to operate the service, keep sessions secure, and diagnose problems.

Crash reports

Our apps send crash reports so we can fix defects. Crash reports are deliberately designed to contain no personal content — they carry technical diagnostics (stack traces, app/OS version, device model), not your data.

§3Sign-in providers (Google, Facebook, Apple, phone)

Where a workspace enables them, you can sign in without a password:

  • Google, Facebook, and Apple (OAuth / Sign in with Apple). When you sign in with one of these providers, we receive your name, email address (or, for Apple, the private relay address you choose to share), and the provider’s subject identifier for your account — never your password for that service. We use these solely to create and match your account. We do not post to your accounts or access your contacts.
  • Phone sign-in (SMS one-time codes). When you sign in with your phone number, we send a one-time code via our SMS provider, which processes your number for delivery of that message only.

§4Payments

Payments are processed by our payment providers through the payment channels offered at checkout. We do not store your card numbers. We keep billing records — plan, amounts, dates, status, and the provider’s transaction references — as required to run subscriptions and to comply with tax and accounting law.

§5Why we process personal data, and on what basis

Under RA 10173, we process personal data on these lawful bases:

  • Contract — to create your account, sign you in, deliver the products, store your content, provide support, and bill subscriptions;
  • Legitimate interests — to secure the platform (session integrity, abuse and fraud prevention, workspace isolation), fix defects via crash reports, and improve the service;
  • Legal obligation — to keep records that Philippine tax, accounting, and other laws require;
  • Consent — where we ask for it specifically (for example, optional communications). You may withdraw consent at any time without affecting processing already performed.

We do not use your content or personal data for third-party advertising, and we do not profile you.

§6Sharing — who receives personal data

We do not sell personal data. We share it only with processors that help us run the platform, limited to these categories: hosting (infrastructure the platform runs on), email delivery, SMS delivery (one-time sign-in codes), payment processing, and crash reporting. Each processor receives only what its function requires and is bound to process it only on our instructions.

Sub-processors
FunctionProviderData involved
Hosting & infrastructureCloud hosting & infrastructure providerAll platform data, at rest and in transit
Email deliveryEmail delivery serviceRecipient address, message content (e.g. verification links)
SMS deliverySMS / one-time-code gatewayPhone number, one-time code message
Payment processingPayment processor (only where checkout is offered)Billing identity, transaction references
Crash reportingCrash-diagnostics serviceTechnical diagnostics only (no personal content)

The categories above describe the types of providers involved in operating the platform; specific sub-processors can be identified on request at hello@rooche.net.

Within an organization workspace, your organization’s administrators can see your account, role, and the content in their workspace — that is how organization workspaces work.

We may also disclose personal data where the law requires it (for example, a lawful order of a Philippine court or authority), or to protect the rights, safety, and security of the platform and its users. If Rooche is involved in a merger, acquisition, or sale of assets, personal data may transfer with the business, subject to this policy.

§7Retention — how long we keep data

  • Active accounts. We keep your data for as long as your account or workspace is active.
  • Deletions are soft-deleted first. When records are deleted in the products, they are soft-deleted (“tombstoned”) — flagged as deleted rather than immediately destroyed — which protects against accidents and preserves workspace integrity, and are purged in the ordinary course thereafter.
  • Billing suspension never deletes data. If access is suspended for non-payment, your data is retained intact and access resumes on settlement.
  • Trial expiry. A trial workspace that never becomes a paid customer is subject to deletion after the stated post-expiry clock (communicated in the product and/or by email), after which its data is permanently deleted.
  • Legal retention. Billing and tax records are retained for the periods Philippine law requires, even after account closure.

§8Security measures

We implement organizational, physical, and technical measures appropriate to the risks, as RA 10173 requires, including:

  • Isolated per-company workspaces — each organization’s deployment is its own, at its own address; customers’ data is not pooled;
  • Encrypted transport — traffic to and within the platform’s public surfaces uses TLS;
  • Role-based access — what a signed-in user can see and do is governed by their role, enforced on the server;
  • hashed passwords, tokenized sessions, and access limited to personnel who need it to operate and support the service.

Our Security page describes these measures in more detail. No system is perfectly secure. If a personal data breach occurs that requires notification, we will notify the NPC and affected data subjects in accordance with RA 10173 and NPC rules.

§9Your rights under RA 10173

As a data subject under the Data Privacy Act of 2012, you have the right to:

  • be informed — to know that and how your personal data is processed (this policy);
  • access — to obtain the personal data we hold about you;
  • rectification — to have inaccurate or outdated data corrected;
  • erasure or blocking — to have data removed where processing is unlawful, no longer necessary, or otherwise as the Act provides;
  • object — to processing based on consent or legitimate interests;
  • data portability — to receive your data in a commonly used electronic format;
  • damages — to be indemnified for damages sustained due to unlawful processing;
  • lodge a complaint — with the National Privacy Commission (privacy.gov.ph).

To exercise any of these rights, email hello@rooche.net from the address associated with your account (or otherwise verify your identity). We will respond within the periods required by the Act. If you are a member of an organization workspace, some requests about workspace content may need to be resolved with your organization, which controls that content — we will help route them.

§10Children

The platform is business and productivity software and is not directed at minors. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us at hello@rooche.net and we will delete it.

§11Changes to this policy

We may update this policy as the platform and the law evolve. We will post the updated policy at rooche.biz/privacy and update the “Last updated” date; for material changes we will give notice in the product or by email before they take effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

§12Contact

Rooche Digital IT Solutions, Inc.
Republic of the Philippines
hello@rooche.net

You may also contact the National Privacy Commission of the Philippines regarding your rights under RA 10173.

See also our Terms of Service — the agreement that governs use of the Rooche platform and all of its products — and our Security page.

© 2026 Rooche Digital IT Solutions, Inc. Privacy · Terms · Security