17/03/2026
Privacy Policy / Privacy Notice
Effective Date: 3/17/2026
Utopia Memorial Garden (“we,” “us,” or “our”) respects your right to privacy and is committed to protecting your personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules and regulations.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you contact us through Facebook, Messenger, lead forms, phone, SMS, email, or other channels.
1. Who We Are
Business Name: Utopia Memorial Garden
Business Address: Laoac, Pangasinan
Contact Email: [email protected]
2. Personal Data We May Collect
We may collect the following personal data, depending on your inquiry and your interaction with us:
Full name
Mobile number
Email address
City / location
Type of inquiry
Buyer category or profile information you voluntarily provide
Message contents, chat history, call notes, or inquiry details
Records of your appointments, requests, or transactions with us
Any other information you voluntarily submit
Where applicable and lawful, we may also collect documents or information needed to process a reservation, purchase, contract, billing, or service request.
3. How We Collect Your Personal Data
We may collect your personal data through:
page messages / Messenger
Facebook lead forms or instant forms
Calls, SMS, and email
Website or online forms, if any
In-person inquiries
Referrals or agents acting on your behalf
Contracts, reservation forms, or other transaction documents
4. Why We Process Your Personal Data
We process your personal data for legitimate and specific purposes, including:
To respond to your inquiries and requests
To provide information about our products, services, availability, pricing, and related offerings
To verify your request and communicate with you
To arrange appointments, site visits, or follow-ups
To prepare quotations, reservation documents, contracts, receipts, or transaction records
To provide customer support and after-sales service
To comply with legal, regulatory, accounting, tax, and record-keeping requirements
To protect our lawful rights and prevent fraud, misuse, or unauthorized access
To improve our customer service and internal processes
To send updates, promotions, or marketing messages only where permitted by law and, when required, with your consent
5. Basis for Processing
We may process your personal data on one or more of the following legal bases, as applicable:
Your consent
The need to take steps at your request before entering into a contract
The performance of a contract with you
Compliance with a legal obligation
Our legitimate interests, provided these are not overridden by your fundamental rights and freedoms
Where sensitive personal information is involved, we will process it only when allowed by law and with the appropriate lawful basis. The DPA allows processing of ordinary personal information under several bases in Section 12, and sensitive personal information only under narrower grounds in Section 13.
6. Who May Receive Your Personal Data
We may share your personal data only when reasonably necessary and subject to appropriate safeguards, with:
Our authorized employees, representatives, or staff
Our authorized sales, admin, customer support, or operations personnel
Service providers who help us operate our communications, storage, payment, or business systems
Professional advisers such as accountants, auditors, or legal counsel, when necessary
Government agencies, regulators, courts, or law enforcement, when required by law
Other parties with your consent or as otherwise permitted by law
If we use third-party platforms or service providers, we require them to handle personal data with appropriate safeguards. Under the DPA, a personal information controller may subcontract processing but remains responsible for ensuring proper safeguards and lawful processing.
7. Data Storage and Retention
We keep your personal data only for as long as necessary for the purposes stated in this Privacy Policy, unless a longer retention period is required or permitted by law.
As a general guide:
Inquiry-only records: up to [12 / 24] months from last contact
Transaction or customer records: for as long as necessary to complete the transaction and satisfy legal, tax, accounting, warranty, or record-keeping requirements
Marketing consent records: until consent is withdrawn or as otherwise necessary to document compliance
After the retention period, we will securely delete, dispose of, anonymize, or block your personal data, as appropriate.
8. Security Measures
We implement reasonable and appropriate organizational, physical, and technical security measures designed to protect your personal data against unauthorized access, disclosure, misuse, alteration, loss, or destruction.
These measures may include, where appropriate:
Restricted access to records
Password protection and account controls
Device and account security measures
Secure storage practices
Staff authorization and confidentiality controls
Record disposal procedures
The NPC’s guidance expects organizations to implement appropriate organizational, physical, and technical measures, and the DPA/IRR require policies that take account of the nature, scope, context, purposes, and risks of processing.
9. Your Rights as a Data Subject
Subject to applicable law and conditions, you may have the right to:
Be informed
Access your personal data
Object to processing
Correct or rectify inaccurate data
Erase or block data, when applicable
Obtain damages where authorized by law
Data portability, when applicable
Lodge a complaint with the National Privacy Commission
These rights are recognized under the DPA and NPC guidance.
10. How to Exercise Your Rights
To exercise your rights or make a privacy-related request, contact us at:
Email: [EMAIL ADDRESS]
Phone: [PHONE NUMBER]
Address: [BUSINESS ADDRESS]
Please provide enough information for us to verify your identity and process your request.
11. Breach and Incident Handling
If a personal data breach occurs, we will assess it and take appropriate action in accordance with applicable law and NPC rules. NPC guidance states that not every breach requires notification, but notification becomes mandatory when the breach meets specified conditions, including involvement of sensitive or identity-fraud-enabling data, unauthorized acquisition, and real risk of serious harm.
12. Minors
If personal data of a minor is submitted to us, the parent, guardian, or authorized adult making the submission represents that they are authorized to do so.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any updated version will be posted on the page where this Privacy Policy is published, with the revised effective date.
14. Contact Us
For any questions, requests, or concerns about this Privacy Policy or our handling of personal data, please contact:
Utopia Memorial Garden