Terms of Service
These terms govern the use of Pawikan, a booking platform for joiner tour organizers and a product of SistemaPH (sistemaph.app). They also contain a proposed Data Processing Agreement for the personal data that organizers handle through the platform. They are written to be readable, but they are a pre-production draft and must not be relied on until they pass legal review.
Agreement and the two contracts
Pawikan will ask the organizer to accept these terms through a clear assent step when the documents are adopted, and will record that acceptance. Until then, creating an account or using the platform is not treated as acceptance of this draft. These terms describe the contract that is intended to apply once they are adopted and validly accepted. Two separate contracts are in play when a trip is booked:
- The platform contract between Pawikan and the organizer, for use of the software. These terms are that contract.
- The trip contract between the traveller (or the person booking for them) and the organizer, covering the trip itself, its price, inclusions, and cancellation rules. Pawikan is not a party to it.
These terms are not in effect yet. Before launch, organizers must be given a clear acceptance step and their acceptance must be recorded; using the platform today does not create acceptance of this draft. When the terms do take effect, the person accepting for an organization must be authorized to do so. How Pawikan handles data in each of its roles is described in the Privacy Policy.
What Pawikan is, and is not
Pawikan provides software that lets an organizer publish departures, collect booking and traveller details, hold slots, and record payments for manual review.
Pawikan is not the tour operator, the travel agency, the seller of the trip, or a payment custodian. Pawikan does not:
- operate trips, transport, accommodation, or activities;
- set or guarantee trip prices, inclusions, or policies;
- route payments, hold funds, or act as a payment processor or escrow;
- verify payments automatically — the organizer reviews each proof of payment and approves or rejects it;
- pay out or process refunds. A refund entry in the platform records a refund the organizer has already made; it does not move money.
Payments for trips go directly to the organizer using the organizer’s own payment details.
Accounts, credentials, and links
- Provide accurate account and organization information and keep it current.
- Keep your credentials confidential and use a strong, unique password. You are responsible for activity under your account.
- Invitations and booking capability links are secrets. Share them only with the intended person, and do not use them to bypass role limits.
- Tell us promptly if you believe an account, invitation, or booking link has been compromised.
Organizer responsibilities
As an organizer, you are responsible for:
- operating your trips lawfully, with any permits, registrations, accreditations, or insurance the law or the activity requires;
- the accuracy of your trip content, dates, inclusions, prices, and availability;
- publishing and honoring your payment, cancellation, refund, and rebooking policies, and communicating them clearly before booking;
- safety and weather decisions, and any decision to push through, reschedule, or cancel a departure;
- providing and maintaining your own direct payment details. Pawikan does not hold or route money;
- complying with the Data Privacy Act of 2012 (RA 10173) and its IRR as the controller of trip data, including giving proper notice, having a lawful basis for every category (and a section 13 exception for sensitive data), obtaining authority from group bookers, and obtaining the appropriate guardian’s consent for minors;
- using personal data only for the trip and the purposes disclosed, and sharing manifests only as necessary and lawfully.
Travellers and group bookers
- Confirm that the details you submit are accurate and that you are entitled to provide them.
- If you book for a group, confirm you have the authority to give each traveller’s details, and that those travellers have been told how their data will be used — or make sure the organizer tells them.
- Where a traveller is a minor, a parent or guardian must authorize the booking.
- Pay the organizer directly using the organizer’s payment details. Your trip contract is with the organizer, and questions about the trip, price, or refunds go to them.
Payments, proofs, and refunds
Payments go directly to the organizer. A booking is not confirmed until the organizer approves the required payment under their policy. When you upload a proof, the organizer reviews it manually; Pawikan does not verify it with a bank or wallet. A reference number already used by a non-rejected payment in the same organization and method is blocked until it is corrected; that validation is not a verification that a payment happened.
Refunds are the organizer’s decision and responsibility, under their policy and applicable law. Pawikan can record a refund the organizer has already paid; it does not send money back to a booker. Disputes about a trip, a payment, or a refund are between the booker and the organizer.
Pricing
Pricing for use of the platform is not set in this draft. No subscription tiers, per-booking fees, or other charges are created or implied by these terms. If we introduce fees or change these terms, we will present the change before it applies and obtain any acceptance the law requires; we will not impose a change through continued use alone. Nothing here should be read as a promise of a particular price or of a free tier.
Acceptable use
You must not use Pawikan to:
- run unlawful, fraudulent, or deceptive trips or booking pages;
- collect, use, or share personal data unlawfully, including without a lawful basis or beyond the purpose disclosed;
- scrape, crawl, overload, or probe the platform or bypass access controls;
- upload malware, or content that infringes others’ rights;
- send spam or marketing to people whose details you received for a trip, or resell personal data;
- impersonate another organizer, platform, or person.
Intellectual property and data licences
The platform, its software, and its branding — including the Pawikan name and the SistemaPH name and logo — belong to SistemaPH or its licensors. You are not granted any right to use the SistemaPH or Pawikan names or logos beyond using the platform as intended. You may not copy, resell, or reverse-engineer the platform except as the law allows.
Your content — your organization name, logo, trip descriptions, and the records you create — remains yours. You give Pawikan a limited, purpose-bound licence to host, display, process, and transmit that content only as needed to run the platform and as the Data Processing Agreement allows. That licence does not permit Pawikan to sell personal data, use it for another organization, or use it to train AI models.
Availability and changes
The platform is provided on an “as available” basis. We do not promise any particular uptime, response time, or service level; no service level agreement is created by these terms. We may add, change, or remove features, and we may perform maintenance. We will try to give reasonable notice of changes that materially affect organizers.
Suspension and termination
We may suspend or terminate access for a material breach of these terms, a security risk, unlawful use, or where the law requires it. Where reasonable, we will give notice and an opportunity to fix the issue, and the action will be proportionate to the problem.
You may stop using the platform at any time. On termination, we will make data available for return or export as described in the Data Processing Agreement. There is currently no automatic account purge on termination, and no self-service erase; the process and its timing require legal and operational review. Provisions that by their nature should survive termination — including confidentiality, data protection, and liability terms — will survive.
Rights that cannot be waived
Nothing in these terms waives or limits any right that cannot lawfully be waived, including mandatory consumer rights under Philippine law, rights under the Data Privacy Act of 2012 and its IRR, and the powers of the National Privacy Commission. Where a term conflicts with such a right, the right prevails.
Liability
Legal review required — liability and indemnity are placeholders
This draft does not contain a sweeping waiver of liability, a mandatory arbitration clause, a fixed court venue, an indemnity, or a monetary cap expressed in dollars or any invented figure. Any limitation of liability or indemnity must be drafted under Philippine law, must preserve mandatory rights, and must be reviewed before it is used. Until then, this section is an empty placeholder for review, not an agreed term.
The platform is not the organizer: the organizer is responsible for the trip and for its content. That division of responsibility does not exclude or limit any liability Pawikan has for its own acts or omissions, its own statutory obligations (including under the Data Privacy Act), or anything that cannot lawfully be excluded. No waiver or cap proposed in this draft is adopted.
Governing law and disputes
Legal review required — dispute resolution, forum, and venue
No arbitration clause, exclusive venue, or invented escalation procedure is set in this draft. The specific disputes process — informal escalation, any alternative dispute resolution, and the court or forum with jurisdiction — must be reviewed and decided before adoption. These terms are intended to be governed by Philippine law.
Contact details for legal notices are not yet published (see the operator notice below). Until a verified channel exists, notices cannot be reliably routed.
Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of these terms and applies where an organizer acts as a personal information controller (PIC) and Pawikan acts as its personal information processor (PIP) for trip and booking personal data. It is drafted with reference to RA 10173 sections 14, 20, and 21 and IRR Rule X (sections 43–45), which set out what a mandatory DPA must address.
Legal review required — this DPA is unadopted and its operational commitments are unconfirmed
Several commitments below depend on capabilities that do not exist yet, on locations and vendors that have not been verified, and on commercially agreed terms that are unresolved. Every operational commitment in this DPA requires legal and operational review before adoption, and this section is not binding until then.
Parties and scope
The parties are the organizer (as PIC) and Pawikan (as PIP). “Pawikan” is used in this draft as the product name of a SistemaPH product; whether Pawikan or SistemaPH is a registered trade name or business name, and which legal entity acts as PIP, has not been confirmed. The organizer’s legal identity is taken from the account and any signed agreement, and must be verified on onboarding. The operating legal entity behind Pawikan and SistemaPH, its address, and its contact for data protection must be filled in before this DPA is binding. This DPA covers the personal data described below that Pawikan processes to provide the platform.
Precedence
For personal data protection, this DPA takes precedence over any conflicting term in the rest of these terms. Mandatory provisions of RA 10173, its IRR, and other applicable law always prevail over this DPA.
Subject matter, nature, and purpose
The subject matter is the processing needed to operate the platform for the organizer: hosting trip pages; collecting and storing booking, traveller, emergency contact, and payment-proof data; compiling and exporting manifests; sending notifications; providing support; securing the service; and keeping audit records. The nature of the processing includes collecting, storing, organizing, retrieving, transmitting, restricting, and deleting data, in each case under the organizer’s documented instructions.
Data subjects, categories, sensitive data, and duration
- Data subjects: bookers, travellers, emergency contacts, and, where relevant, the organizer’s staff whose details appear in a booking.
- Categories: the booker’s name, mobile number, and optional email; each traveller’s full name, birthdate, optional sex, nationality, and optional mobile; each traveller’s emergency contact name and number; trip and booking details; free-text notes to the organizer; payment amounts, references, status, and the proof image or document; and audit and security metadata.
- Sensitive personal information: potentially birthdate (age) and any sensitive details placed in free-text notes; government ID data only if an organizer opts in and it is collected in future. The organizer must have a section 13 basis for any sensitive data before it is collected.
- Duration: for as long as the service is provided and the organizer needs the data to run the trip, plus any retention required by law and by the retention rules in this DPA.
Documented instructions and transfers
Pawikan will process personal data only on the organizer’s documented instructions, including with respect to transfers of personal data to another country, unless the law requires otherwise. If Pawikan is required by law to process data without the organizer’s instruction, it will tell the organizer before processing unless the law prohibits that notice. If Pawikan considers that an instruction infringes data protection law, it will tell the organizer immediately and will not carry out that instruction; the processing is paused until the parties resolve it.
Authorized persons and security
Pawikan will ensure that people authorized to process the data are bound by confidentiality obligations that survive the end of their engagement, and that they are given appropriate training and access limits. Pawikan will implement appropriate technical, organizational, and physical security measures under IRR section 25, including organization-scoped authorization, row-level security, private storage with short-lived signed URLs, and audit logging, having regard to the risk and the nature of the data.
Organizer responsibilities and PIC accountability
The organizer is the PIC and is accountable to data subjects and the NPC. The organizer is responsible for providing proper notice, establishing and documenting a lawful basis for all personal data (and a section 13 exception for sensitive data), obtaining authority from group bookers, obtaining guardian consent for minors, telling emergency contacts, minimizing the data collected, keeping it accurate, and honoring data subject rights. Pawikan’s role as PIP, and the organizer’s status as PIC, do not eliminate Pawikan’s own direct obligations under the Data Privacy Act and its IRR, including accurate records of processing, security, and breach notification duties.
Purpose limitation
Pawikan will not reuse personal data for its own purposes, use it across organizations, use it for another organization’s marketing, sell it, or use it to train artificial intelligence models. Processing is limited to providing the service to the organizer and to Pawikan’s own lawful, limited compliance and security obligations.
Subprocessors
Pawikan will engage another processor (a subprocessor) only on the organizer’s prior, documented instructions or authorization, and will put in place a contract that imposes data protection duties equivalent to those in this DPA. Pawikan remains responsible to the organizer for its subprocessors’ performance of those duties. The current planned providers are listed in the Privacy Policy, and the list is not yet final or verified. Before adding or replacing a subprocessor, Pawikan will provide advance notice of its identity, purpose, and locations and obtain the organizer’s documented authorization. The organizer may raise a data protection objection; the parties must resolve it or stop the affected processing and arrange termination and return or deletion of the affected data. Mere continued use does not authorize a new subprocessor.
Geographic location of processing
Legal review required — processing locations are unresolved and block a binding DPA
The countries and regions in which personal data is stored and processed, and the access jurisdictions of providers and staff, have not been verified. This is an unresolved item that must be documented in an annex or schedule before this DPA is binding. Under RA 10173 section 21, the organizer remains accountable for domestic and international transfers and must use contractual or other reasonable means to ensure comparable protection. Pawikan must support those safeguards; an approved processing-location and subprocessor schedule is required before adoption. Pawikan will give the organizer advance notice of a material change to those locations, and the organizer will be able to object; the parties will work to resolve the objection, or the organizer may stop using the affected processing and terminate the affected service. Continued use of the platform is not a blank general permission to any future transfer.
Assistance with rights, compliance, and audits
Pawikan will assist the organizer in responding to data subject requests, meeting its compliance obligations (including privacy impact and risk assessments required by the law and the NPC), and cooperating with the NPC. Pawikan will also assist with audits and inspections, and provide the evidence reasonably needed, in a way that does not expose another tenant’s personal data or trade secrets. If the organizer must inspect shared infrastructure, the logistics and safeguards are to be agreed, and this activity requires operational and legal review before it can be represented as available.
Personal data breach
Pawikan will notify the organizer promptly and without undue delay after becoming aware of a personal data breach affecting the organizer’s data, and will provide information as it becomes available rather than waiting for a full investigation to finish, along with reasonable cooperation.
The parties distinguish two different duties:
- As PIC, the organizer is responsible for notifying the NPC and affected data subjects within 72 hours upon knowledge or reasonable belief by the PIC or PIP that a notifiable breach has occurred under IRR section 38. The clock does not wait for the organizer to finish an investigation or receive a final report.
- As PIP, Pawikan must notify the organizer promptly when it learns of a breach, and must support the organizer’s notification. The PIP’s own immediate notice to the PIC is separate from the PIC’s 72-hour regulator clock.
IRR section 38 requires notification when sensitive personal information, or other information that could enable identity fraud, is reasonably believed to have been acquired by an unauthorized person and the PIC or NPC believes this is likely to create a real risk of serious harm. Other incidents must still be documented and addressed. Pawikan has the controller’s notification duties for breaches of its own account and platform-security data.
Legal and operational review required — incident response
Confirm and test the incident-response plan, escalation contacts, internal notice deadline, and applicable NPC notification procedures before adoption. No fixed internal service deadline has been agreed. This does not extend or waive any statutory deadline or the obligation to notify the organizer promptly.
Disclosure to authorities
If Pawikan receives a legally binding request to disclose personal data, it will disclose only what the request lawfully requires, and will notify the organizer unless the law prohibits notice. Pawikan will not voluntarily disclose personal data to a third party for that third party’s own purposes.
Return or deletion at the end of the service
When the service ends, the organizer may choose to have Pawikan return the personal data or delete it. Pawikan will return or delete all copies it holds, unless the law authorizes or requires it to keep isolated copies for a defined period (for records Pawikan must retain under law). Where the law requires retention, those copies will remain protected by this DPA and used only for the purpose that justified retaining them.
Legal review required — export, deletion, and backup timing are not implemented
The exact export format, the deletion deadline for live systems, the handling of backups, and any automated deletion functionality are not finalized and are not currently implemented as a guarantee. Do not rely on a specific turnaround time. These operational and legal details must be agreed and built before this clause is treated as a commitment.
Liability and review status
The liability arrangements for this DPA must be consistent with the liability section of these terms and with Philippine law, and must not limit mandatory rights. They are unresolved and require legal review. All operational commitments in this DPA — breach timing, export and deletion, audit assistance, subprocessors, locations, retention, and security descriptions — must be confirmed against the actual system and the commercial agreement before this DPA is adopted.
Changes to these terms
We may update these terms and the DPA as the service and the law change. Material changes require notice consistent with the law and the DPA, and we need a lawful basis for any new processing purpose. We will not treat continued use as blanket consent to retroactive changes.
Primary sources for this draft are the Data Privacy Act of 2012 (RA 10173) and its Implementing Rules and Regulations. Other NPC issuances may apply and have not all been reviewed.
Contact
Questions about a trip, a booking, a payment, or a refund go to the organizer. Once a verified platform contact is published, it will be listed here and in the footer.