Effective date: August 3, 2026
Last updated: August 3, 2026
This Privacy Policy explains how the operator of this independent Pag-IBIG information website collects, uses, stores, shares, and protects personal data when you visit or interact with this website. It also explains your privacy rights and the choices available to you.
This website is an independent informational resource. It is not operated by, affiliated with, endorsed by, or connected to Pag-IBIG Fund, the Home Development Mutual Fund, or any Philippine government agency. Do not submit Pag-IBIG passwords, one-time passwords, card details, government identification numbers, copies of identification documents, loan documents, or other sensitive account information through this website.
1. Who we are and who controls your data
The data controller for personal data collected directly through this website is the website operator trading under the site identity Independent Pag-IBIG Information Resource.
- Website: https://darkgrey-wolf-175133.hostingersite.com/
- Privacy contact: itstiffanynoam@gmail.com
For data processed independently by third parties, such as Google, hosting providers, advertising partners, embedded services, or external websites, those parties may act as separate controllers or processors under their own privacy notices.
2. Scope of this policy
This policy applies to information collected through this website, including its pages, articles, navigation features, search function, comments if enabled, contact communications, cookies, consent tools, advertising technologies, and related technical systems.
This policy does not apply to the official Pag-IBIG Fund website, Virtual Pag-IBIG, government portals, banks, payment providers, social networks, or other third-party websites linked from our content. Those services have their own privacy practices and policies.
3. Personal data we may collect
Information you provide voluntarily
- Your name, email address, and the contents of a message when you contact us.
- Information included in a comment, feedback submission, or privacy request if those features are available.
- Any other information you choose to provide directly to the website operator.
Please provide only the minimum information necessary. Do not send passwords, one-time passwords, full card numbers, bank credentials, Pag-IBIG account credentials, copies of identification documents, or sensitive financial and government records.
Information collected automatically
- Internet Protocol address.
- Browser type, browser version, operating system, device type, and language settings.
- Referring page, pages visited, links clicked, date and time of access, and approximate session activity.
- Technical error information, security events, and server log data.
- Cookie identifiers, consent choices, advertising identifiers, and similar online identifiers where applicable.
- General location derived from an IP address, such as country or region. We do not intentionally collect precise GPS location through this website.
Information received from third parties
We may receive aggregated reports, technical information, consent signals, advertising reports, fraud-prevention information, or service-performance data from hosting providers, advertising platforms, consent management platforms, security providers, and other service providers. We do not ask those providers to give us information that directly identifies you unless it is necessary for a legitimate support, legal, or security purpose.
4. How we use personal data
- To operate, maintain, secure, and improve the website.
- To display pages, process navigation, and provide search and accessibility features.
- To answer messages, feedback, complaints, and privacy requests.
- To detect spam, malicious traffic, abuse, fraud, and security incidents.
- To understand general website usage and improve content quality.
- To remember consent choices and cookie preferences.
- To display, measure, limit, and improve advertising when advertising services are enabled.
- To comply with legal obligations, enforce website rules, and establish or defend legal claims.
- To protect the rights, safety, property, and security of visitors, the website operator, and third parties.
5. Legal bases under the GDPR and UK GDPR
When the General Data Protection Regulation or UK GDPR applies, we rely on one or more of the following legal bases:
- Consent: for non-essential cookies, personalized advertising, certain analytics technologies, and other processing that legally requires prior permission. You may withdraw consent at any time.
- Legitimate interests: for essential website operation, security, fraud prevention, basic audience measurement, content improvement, responding to ordinary inquiries, and protecting legal rights, provided those interests are not overridden by your rights and freedoms.
- Legal obligation: when processing is necessary to comply with tax, accounting, regulatory, court, law-enforcement, or other legal requirements.
- Contract or steps before a contract: if you ask us to provide a service that requires processing your information. The website currently provides informational content and does not offer Pag-IBIG account services.
- Vital interests: in rare circumstances where processing is necessary to protect someone from a serious and immediate threat.
Where we rely on legitimate interests, we consider the nature of the information, the purpose of processing, the likely impact on users, and the safeguards available.
6. Cookies and similar technologies
Cookies are small files stored on your browser or device. Similar technologies include local storage, pixels, tags, software development tools, and web beacons. These technologies may be used to keep the website working, protect it from abuse, remember preferences, measure performance, and support advertising.
Types of cookies that may be used
- Strictly necessary cookies: needed for security, consent management, load balancing, core WordPress functions, and essential website operation.
- Preference cookies: remember settings such as cookie choices or interface preferences.
- Measurement or analytics cookies: help understand page usage, performance, and technical problems. These will be used only in accordance with applicable consent requirements.
- Advertising cookies: may be used by Google and other advertising partners to serve, limit, personalize, and measure advertisements when advertising is enabled.
You can control cookies through the consent banner where available and through your browser settings. Blocking all cookies may affect some website functions. Withdrawal of consent does not affect processing that occurred lawfully before withdrawal.
7. Google AdSense and advertising
This website may use Google AdSense and may work with Google-certified advertising vendors or networks. Advertising may not be active at all times. When Google advertising is enabled, the following practices may apply:
- Third-party vendors, including Google, may use cookies to serve ads based on a user’s prior visits to this website or other websites.
- Google’s use of advertising cookies enables Google and its partners to serve ads based on visits to this website and other websites on the Internet.
- Google and other vendors may use cookies, web beacons, IP addresses, device information, and other identifiers to deliver, measure, limit, and report advertising.
- Ads may be personalized based on consent and applicable law, or non-personalized based on contextual information such as the page being viewed, general location, and limited technical information.
- Other third-party vendors or ad networks may also place or read cookies or use similar technologies where enabled and legally permitted.
You can learn how Google uses information from partner websites at https://policies.google.com/technologies/partner-sites.
You may manage or opt out of personalized advertising through Google Ads Settings at https://adssettings.google.com/. You may also review industry opt-out choices at https://www.aboutads.info/choices/. Opting out of personalized advertising does not necessarily stop all advertising. You may still see non-personalized or contextual ads.
The specific advertising vendors used may change. Where required, the active consent management platform will identify participating vendors and provide links to their privacy information before consent is requested.
8. Consent for visitors in the EEA, United Kingdom, and Switzerland
When advertising or other non-essential technologies are enabled for visitors in the European Economic Area, United Kingdom, or Switzerland, we intend to use a Google-certified Consent Management Platform that supports the IAB Europe Transparency and Consent Framework where required by Google policy.
The consent interface may allow you to accept, reject, or manage purposes and vendors. Non-essential cookies and personalized advertising technologies will not be used before consent where prior consent is legally required. You may later change or withdraw your choice through the privacy or consent settings made available on the website.
Consent is specific, informed, and freely given. Refusing consent should not prevent access to ordinary informational content, although ads and optional features may operate differently.
9. Comments and user-generated content
If comments are enabled and you submit a comment, we may collect the information entered in the comment form, your IP address, browser user-agent information, the comment time, and spam-detection data. Approved comments and the display name you provide may become public. Do not include private account information or sensitive personal data in a public comment.
An anonymized value derived from an email address may be sent to the Gravatar service to determine whether you use that service. Gravatar and its provider process data under their own privacy terms.
10. Embedded content and external services
Pages may contain embedded videos, maps, documents, social media posts, forms, or other content provided by third parties. Embedded content may behave as though you visited the third-party website directly. Those providers may collect data, use cookies, receive your IP address, and monitor interaction with the embedded material, especially when you are signed in to their service.
We try to limit unnecessary embedded tracking, but we do not control the privacy practices of external providers. Review the relevant third-party privacy notice before interacting with embedded content or following an external link.
11. Who may receive personal data
We do not sell personal data in the ordinary meaning of exchanging it for money. We may disclose or make data available to the following categories of recipients when necessary:
- Website hosting, content-delivery, database, backup, and technical support providers.
- Security, spam-prevention, fraud-prevention, and monitoring providers.
- Consent management platforms and cookie-preference providers.
- Google and other advertising technology providers when advertising is enabled.
- Email, communication, and administrative service providers used to respond to inquiries.
- Professional advisers such as lawyers, accountants, or insurers when reasonably necessary.
- Government agencies, regulators, courts, law-enforcement authorities, or other parties when disclosure is required by law or necessary to protect legal rights and safety.
- A successor operator in connection with a merger, reorganization, sale, or transfer of the website, subject to appropriate confidentiality and privacy safeguards.
Service providers are expected to process information only for authorized purposes and to protect it appropriately. Some third parties, including advertising providers, may determine their own purposes and act as independent data controllers.
12. International data transfers
The website can be accessed globally, and service providers may process information in countries other than the country where you live. Those countries may have different data-protection laws.
Where GDPR or UK GDPR transfer restrictions apply, transfers may rely on an adequacy decision, approved standard contractual clauses, another lawful transfer mechanism, or a limited legal exception. Additional technical and contractual safeguards may be used where appropriate.
13. Data retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including security, legal, accounting, dispute-resolution, and compliance needs. Retention is determined using factors such as the type and sensitivity of data, the risk of harm, the purpose of processing, legal requirements, and whether the purpose can be achieved in another way.
- Ordinary inquiry emails and related correspondence may be retained for up to 24 months after the last meaningful interaction, unless a longer period is needed for a legal or security reason.
- Security logs and server records are retained according to the hosting provider’s operational, backup, and security schedules and may be kept longer when an incident is investigated.
- Cookie-consent records may be retained for as long as necessary to demonstrate compliance and manage your choices.
- Comments and their metadata may be retained while the comment remains published or while needed for moderation, spam prevention, and recordkeeping.
- Information required for a legal claim or legal obligation may be retained until the relevant obligation or limitation period ends.
- Backup copies may remain temporarily after deletion until they are overwritten under normal backup cycles.
14. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. Safeguards may include access controls, software updates, secure hosting, encrypted transmission, backups, spam protection, and security monitoring.
No online system is completely secure. You are responsible for using a secure device and connection and for avoiding the submission of sensitive credentials or documents. If we become aware of a personal-data breach, we will assess it and provide notifications where required by applicable law.
15. Your rights under the GDPR and UK GDPR
Depending on the circumstances and applicable law, you may have the right to:
- Request confirmation of whether we process your personal data.
- Request access to your personal data and information about how it is processed.
- Request correction of inaccurate or incomplete information.
- Request deletion of personal data in certain circumstances.
- Request restriction of processing in certain circumstances.
- Object to processing based on legitimate interests.
- Object at any time to direct marketing.
- Receive certain data in a structured, commonly used, machine-readable format and request transmission to another controller where technically feasible.
- Withdraw consent at any time where processing is based on consent.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to legal exceptions.
- Lodge a complaint with the data-protection authority in your country or place of work, or where you believe an infringement occurred.
These rights are not absolute. We may need to verify your identity and may refuse or limit a request where permitted by law, including when a request would adversely affect another person’s rights, compromise security, or conflict with a legal obligation.
16. Rights under Philippine data-protection law
Where the Philippine Data Privacy Act of 2012 applies, data subjects may have rights including the right to be informed, object, access, correct, erase or block information in qualifying circumstances, obtain data portability where applicable, and seek damages or file a complaint.
Complaints concerning Philippine data-protection rights may be submitted to the National Privacy Commission, subject to its rules and procedures. You may first contact us so we can review and address the concern.
17. United States privacy choices
Residents of certain United States states may have rights to know, access, correct, delete, or obtain a copy of personal data and to opt out of certain targeted advertising, sales, or sharing as those terms are defined by applicable law. The availability and scope of these rights depend on the law and whether it applies to this website.
Where a legally recognized browser-based opt-out signal, such as Global Privacy Control, must be honored, we will process it as required by applicable law and supported technology. We do not discriminate against users for exercising applicable privacy rights.
18. Children
This website provides general informational content and is not directed to children under 16. We do not knowingly collect personal data from children under 16 through forms, advertising profiles, or other interactive features. A parent or guardian who believes a child has provided personal data may contact us to request review and deletion.
19. Automated decision-making
We do not use personal data collected directly by this website to make solely automated decisions that produce legal or similarly significant effects. Advertising providers may use automated systems to select or measure ads. Those systems are governed by the provider’s privacy terms, applicable consent choices, and relevant law.
20. Links to third-party websites
Our articles link to official Pag-IBIG services, government websites, banks, payment providers, maps, social networks, and other external resources. A link does not mean that we control or endorse the third party’s privacy practices. Review the destination’s privacy policy before providing personal information or completing a transaction.
21. Changes to this policy
We may update this Privacy Policy when website features, advertising services, vendors, legal requirements, or data practices change. The revised policy will show a new last-updated date. Material changes may also be communicated through a website notice or renewed consent request where required.
22. How to exercise your rights or contact us
To ask a privacy question, withdraw consent where a website control is unavailable, or exercise an applicable data right, email itstiffanynoam@gmail.com with the subject line Privacy Request.
Please describe the request clearly and identify the website interaction involved. Do not send passwords, one-time passwords, full payment details, copies of identification documents, or Pag-IBIG account credentials unless we specifically request limited verification information and explain why it is necessary. We may ask for reasonable information to verify identity before acting on a request.
We aim to respond within the period required by applicable law. GDPR and UK GDPR requests are generally answered within one month, although the period may be extended where legally permitted for complex or numerous requests.
