1. Scope and our role
This page explains how TRACTIONCORE ("we," "us," or "our") meets its obligations under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and, where applicable, the UK GDPR and the Data Protection Act 2018. It supplements our Privacy Notice and should be read together with it.
Depending on the circumstances, TRACTIONCORE acts either as a controller — for example, when processing personal data of website visitors, prospects, or our own talent network — or as a processor on behalf of a Client, for example when delivering managed services that involve the Client's data subjects. Where we act as a processor, we process personal data only on documented instructions from the Client and under a written data processing agreement.
2. Personal data we process
The categories of personal data we process are described in our Privacy Notice and typically include identification and contact details, professional and recruitment information, engagement and billing details, and technical data such as IP address, device data, and usage information.
3. Lawful bases for processing
We rely on the following lawful bases, as applicable:
- Consent — for example, for certain marketing communications and non-essential cookies, which you may withdraw at any time.
- Contract — where processing is necessary to enter into or perform a contract with you or the entity you represent.
- Legal obligation — where we must process data to comply with applicable law.
- Legitimate interests — for example, securing our services, preventing fraud, and improving our offerings, balanced against your rights and freedoms.
- Vital interests — in the limited circumstances where processing is necessary to protect life.
4. Your rights under GDPR / UK GDPR
Subject to the conditions and exceptions in applicable law, you have the right to:
- Be informed about how we process your personal data.
- Access a copy of the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten") where there is no overriding lawful reason for continued processing.
- Restriction of processing in specified circumstances.
- Data portability of data you provided, where processing is based on consent or contract and carried out by automated means.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Not be subject to solely automated decisions producing legal or similarly significant effects, including profiling, without safeguards.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
5. Exercising your rights
You may exercise any of these rights by contacting our Data Protection Officer at privacy@tractioncore.com. We will respond within one month of receiving your request, which may be extended by up to two further months where requests are complex or numerous, and we will inform you if an extension is required. We may ask you to verify your identity before acting on a request.
6. International data transfers
TRACTIONCORE is headquartered in the Philippines, and some of our service providers are located outside the EEA and the UK. Where we transfer personal data from the EEA or the UK to a third country, we put appropriate safeguards in place, including the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum or IDTA, and, where relevant, supplementary technical and organizational measures, together with transfer risk assessments.
7. Sub-processors
Where we act as a processor, we engage sub-processors to support delivery, including cloud hosting and infrastructure, communications, CRM, analytics, and payment processing providers. Sub-processors are bound by written agreements imposing data protection obligations no less protective than those in our agreement with the Client. A current list of sub-processors is available on request, and Clients are notified of intended changes as provided in the applicable data processing agreement.
8. Security of processing (Article 32)
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in our Data Security Protocol. These include encryption at rest and in transit, access controls and role-based provisioning, centralized credential management, enterprise endpoint and identity management, monitoring and logging, personnel vetting and training, and confidentiality obligations for all personnel with access to personal data.
9. Personal data breach notification
We maintain incident response procedures and a Data Breach Response Team. Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority without undue delay and, where required, within 72 hours of becoming aware of the breach, and will inform affected data subjects without undue delay where the breach is likely to result in a high risk. Where we act as a processor, we will notify the affected controller without undue delay.
10. Data Protection Officer and representatives
TRACTIONCORE has appointed a Data Protection Officer (DPO) responsible for overseeing data protection compliance and acting as a contact point for data subjects and supervisory authorities. Where required, we appoint a representative in the European Union and/or the United Kingdom. The DPO can be reached at privacy@tractioncore.com.
11. Records, DPIA, and accountability
We maintain Records of Processing Activities (ROPA), conduct Data Protection Impact Assessments (DPIA) for higher-risk processing, apply data protection by design and by default, and maintain appropriate data processing agreements with Clients and sub-processors. These measures support our accountability obligations under the GDPR and UK GDPR.
12. Cookies and consent
We use cookies and similar technologies as described in our Cookie Policy. Where consent is required, non-essential cookies are deployed only after consent is obtained, and you may update or withdraw your preferences at any time.
13. Supervisory authorities and complaints
If you believe we have not complied with applicable data protection law, you have the right to lodge a complaint with a supervisory authority. In the EEA, this is typically the authority in your country of residence, place of work, or where the alleged infringement occurred. In the UK, the supervisory authority is the Information Commissioner's Office (ICO). We would appreciate the opportunity to address your concern directly first, and you may contact our DPO at any time.
14. Changes to this statement
We may update this GDPR and UK GDPR statement from time to time to reflect changes in law, our practices, or our services. Updates will be posted on this page with a revised effective date.
15. Contact us
Legal advice notice: This page describes our compliance posture in good faith and does not constitute legal advice. Clients should obtain independent legal advice on their own obligations under the GDPR and UK GDPR.
Questions about our GDPR or UK GDPR compliance may be directed to our Legal and Compliance Department using the details below.
Legal & Compliance Department
Contact the Data Protection Officer.
For GDPR or UK GDPR requests, data processing agreements, or transfer enquiries, contact the department directly.
Vertis North, Vita St., cor. Sola Drive, Quezon City, National Capital Region, Philippines 1105