LMI Corporation Website Privacy Policy
Last updated: 21 September 2026
This Policy governs how LMI Corporation collects, uses, discloses, and protects personal data obtained through www.lmiitsolutions.com and related digital channels, in compliance with the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, applicable National Privacy Commission (NPC) issuances, and, where applicable, the EU/UK General Data Protection Regulation (GDPR).
1. Scope and Application
This Policy applies to personal data LMI Corporation collects through its corporate website, online forms (quotation requests, contact and inquiry forms, career applications), email marketing subscriptions, and any other digital touchpoint it operates. It applies to visitors, prospective and existing clients, job applicants, and newsletter subscribers.
This Policy does not govern personal data LMI processes on behalf of a client as a personal information processor under a managed-services, systems-integration, or general-contracting engagement (for example, data encountered while administering a client's network, CCTV, or IoT systems). That processing is governed by the data-sharing and confidentiality terms of the applicable service agreement or data processing addendum, not by this Policy.
Where LMI offers goods or services to, or monitors the online behavior of, individuals located in the European Economic Area, the United Kingdom, or another jurisdiction with comparable extraterritorial data protection law, the supplementary rights and obligations described in Sections 8 and 9 apply to that processing in addition to Philippine law.
2. Who We Are
Data Controller: LMI Corporation, with registered office at Blk16 Lot35 Country Home Subdivision, Brgy. Alijis, Bacolod City, Negros Occidental, Philippines 6100.
Data Protection Officer (DPO): Under Section 21 of RA 10173 and Section 26 of its Implementing Rules and Regulations, every personal information controller must designate an individual accountable for its compliance, whether or not it meets the National Privacy Commission's (NPC) registration thresholds. LMI has designated Engr. Winston H. Estrevillo as its Data Protection Officer, reachable at info@lmiitsolutions.com.
NPC registration status: LMI's registration of its data processing systems with the National Privacy Commission is ongoing. This Policy will be updated with LMI's NPC registration reference number once issued.
3. Information We Collect, Why We Use It, and How Long We Keep It
LMI collects only what is adequate, relevant, and necessary for the stated purpose, consistent with the proportionality principle in Section 11 of RA 10173.
| Category | Examples | Purpose | Legal Basis (PH DPA / GDPR) | Retention |
|---|---|---|---|---|
| Identity and contact data | Name, job title, company, email, phone number | Respond to inquiries; prepare quotations and proposals; manage the client relationship | Consent / Contract necessity (Sec. 12(b) DPA; Art. 6(1)(b) GDPR) | Duration of the relationship, plus 5 years after the last transaction for BIR/SEC record-keeping |
| Marketing preference data | Email address, opt-in status and timestamp | Send newsletters, promotions, and event invitations | Consent (Sec. 12(a) DPA; Art. 6(1)(a) GDPR) | Until consent is withdrawn, plus 3 years to evidence that consent was given |
| Website usage data | IP address, device/browser type, pages viewed, referral source, cookie identifiers | Site analytics, security monitoring, performance improvement | Legitimate interest for essential/security use (Sec. 12(f) DPA; Art. 6(1)(f) GDPR); Consent for non-essential cookies | 12–24 months, or shorter per the cookie's own expiry (Section 4) |
| Recruitment data | CV/résumé, employment history, educational background, references | Evaluate job applications | Consent / pre-contractual steps (Sec. 12(b) DPA; Art. 6(1)(b) GDPR) | 1 year from application date if unsuccessful; per 201-file rules if hired |
| Technical and project data | Site surveys, network diagrams, technical specifications submitted with a request for quotation | Prepare project proposals, scopes of work, and bids | Contract necessity / legitimate interest | Duration of the bid or project cycle, plus 5 years for record-keeping |
| Government-issued identifiers (sensitive, only where volunteered) | TIN, government ID numbers, PhilGEPS credentials submitted for public-sector bids | Comply with government procurement law (RA 9184) and tax/regulatory filing | Legal obligation (Sec. 13(b) DPA; Art. 6(1)(c) GDPR) | Per the procuring entity's document retention rule, generally 5–10 years |
Where a retention period is not fixed by law or contract, LMI retains personal data only for as long as necessary to fulfill the purpose for which it was collected, after which it is securely disposed of or anonymized.
4. Cookies and Tracking Technologies
The website uses cookies and similar technologies (pixels, local storage) in three categories:
| Category | Purpose | Consent required? |
|---|---|---|
| Strictly necessary | Site functionality, load balancing, security | No — legitimate interest |
| Analytics/performance | Traffic measurement, page-performance diagnostics | Yes, unless anonymized |
| Marketing/advertising | Retargeting, campaign measurement across sites | Yes |
A cookie consent banner allows visitors to accept or decline non-essential cookies before they are set, and to change that choice at any time through the site's cookie-preference control. Browser-level controls (blocking or deleting cookies) remain available independently of the banner. LMI does not currently use cookies to build automated profiles for legal or similarly significant decisions about visitors.
5. Consent, Marketing Communications, and Withdrawal
Where LMI relies on consent — principally for marketing emails and non-essential cookies — that consent meets the standard set by NPC Circular No. 2023-04: it is freely given, specific to each purpose, informed in plain language, and confirmed by a clear affirmative act (for example, ticking an unchecked consent box). LMI does not use pre-ticked boxes or bundle marketing consent with an unrelated transaction.
Consent may be withdrawn at any time, at no cost, through the unsubscribe link in every marketing email or by writing to info@lmiitsolutions.com. Withdrawal takes effect without undue delay and does not affect the lawfulness of processing carried out before it, nor does it affect processing carried out under a different legal basis (for example, an active service agreement).
6. Disclosure to Third Parties, Service Providers, and Government Authorities
LMI does not sell or trade personal data. It discloses personal data only in the following circumstances:
- Service providers (personal information processors) engaged to operate the website, send email marketing, host data, or provide IT infrastructure — bound by written agreements requiring a level of protection at least equivalent to this Policy and RA 10173, and prohibited from using the data for their own purposes.
- Professional advisers (external auditors, legal counsel, banks) where necessary to obtain their services.
- Government and regulatory authorities — the NPC, BIR, SEC, PhilGEPS, or a court — where disclosure is required by law, a valid legal order, or to establish, exercise, or defend a legal claim.
- A successor entity, in the event of a corporate restructuring, merger, or asset sale involving NEXAL, LMI, or CoreXchange, subject to the same confidentiality and purpose-limitation commitments in this Policy.
Each disclosure is limited to what is necessary for the specific purpose; LMI remains accountable for personal data it discloses to a processor acting on its behalf, per Section 21 of RA 10173.
7. Cross-Border Data Transfers
Some service providers LMI uses (cloud hosting, email marketing platforms, analytics tools) may store or process data outside the Philippines. Before any such transfer, LMI verifies that the recipient maintains data protection standards comparable to RA 10173, principally through contractual safeguards (data processing agreements incorporating confidentiality, security, and breach-notification obligations equivalent to Philippine law).
For transfers falling within GDPR scope (Section 1), LMI relies on one of the recognized transfer mechanisms under Chapter V of the GDPR — an adequacy decision, the European Commission's Standard Contractual Clauses, or another approved safeguard — before personal data leaves the EEA/UK, or before it is transferred onward to a third country.
8. Data Security Measures and Breach Notification
LMI applies organizational, physical, and technical security measures proportionate to the nature and risk of the personal data it holds, per Section 20 of RA 10173 — access controls, encryption in transit for web forms, restricted administrative access to the marketing and CRM databases, and periodic review of its Sophos/Meraki-based network security stack.
If a personal data breach involving sensitive personal information, or information that could enable identity fraud, is reasonably believed to create a real risk of serious harm, LMI will:
- Notify the National Privacy Commission within seventy-two (72) hours of knowledge of, or reasonable belief that, a breach occurred, per NPC Circular No. 16-03;
- Notify affected data subjects without unreasonable delay, describing the nature of the breach, the data involved, and the remedial measures taken; and
- Document the incident and the response taken in LMI's breach register, available to the NPC on request.
For breaches falling within GDPR scope, notification to the relevant EU/UK supervisory authority follows the 72-hour standard under Article 33 GDPR.
9. Your Privacy Rights
| Right | RA 10173 (Sec. 16–18) | GDPR (where applicable) | How to exercise |
|---|---|---|---|
| Be informed | Right to information on data processing | Arts. 13–14 | This Policy and any layered notice shown at the point of collection |
| Access | Right to reasonable access to your data | Art. 15 | Written request to the DPO |
| Correction/rectification | Right to dispute and correct inaccuracies | Art. 16 | Written request to the DPO |
| Erasure/blocking | Right to suspend, withdraw, block, remove, or destroy unlawfully processed data | Art. 17 (right to be forgotten) | Written request to the DPO |
| Object | Right to object to processing, including for direct marketing | Art. 21 | Unsubscribe link, or written request |
| Data portability | Right to obtain data in electronic/structured format | Art. 20 | Written request to the DPO |
| Damages | Right to be indemnified for damages from unauthorized or unlawful processing | Art. 82 (compensation) | Civil action / NPC complaint |
| Lodge a complaint | Right to file a complaint with the NPC | Right to lodge a complaint with a supervisory authority | complaints@privacy.gov.ph (NPC) or the competent EU/UK supervisory authority |
LMI responds to a verified rights request within a reasonable period and, in any event, without undue delay. It may request proof of identity before acting on a request to prevent unauthorized access to another person's data. There is no charge for exercising these rights, except where a request is manifestly unfounded or excessive.
10. Children's Privacy and Third-Party Links
The website is directed at businesses and professionals and is not intended for children. LMI does not knowingly collect personal data from individuals under 18 without the consent of a parent or legal guardian. If LMI becomes aware that it has done so, it will delete the data promptly.
The website may link to third-party sites (partner portals, social media, payment or scheduling tools). LMI is not responsible for the privacy practices of those third parties; visitors should review each site's own privacy policy before submitting personal data there.
11. Changes to This Policy; Contact Us and Complaints
LMI may update this Policy to reflect changes in its practices or in applicable law. The "Last Updated" date at the top of this Policy will change accordingly; material changes affecting how previously collected data is used will be notified by email to active subscribers or by a prominent website notice before taking effect.
To exercise your rights, ask a question, or raise a concern, contact: Engr. Winston H. Estrevillo, Data Protection Officer, LMI Corporation, Blk16 Lot35 Country Home Subdivision, Brgy. Alijis, Bacolod City, Negros Occidental, Philippines 6100 · info@lmiitsolutions.com
If you are not satisfied with LMI's response, you may file a complaint with: National Privacy Commission (Philippines) – complaints@privacy.gov.ph – privacy.gov.ph or, for GDPR-scoped processing, the data protection supervisory authority in your EU/UK member state of residence.