Privacy Policy
This Privacy Policy explains how Athena Management ("we", "us", "our"), trading as Web by Lods.AI and based in Bacolod City, Negros Occidental, Philippines, collects, uses, stores, retains, and deletes personal data. We build and host per-business websites for small businesses. We are the Personal Information Controller (PIC) for the data described here, and we process it in accordance with the Republic Act No. 10173 (Data Privacy Act of 2012) and the rules of the National Privacy Commission (NPC).
Where this policy refers to "the Service", it covers web.lods.ai,
every per-business site we host (for example web.lods.ai/your-business/),
and any chatbot or Facebook Messenger conversation we operate on our own or a customer's behalf.
- 1. What we collect
- 2. Purpose & legal basis
- 3. Who we share with
- 4. Retention
- 5. Your rights
- 6. Security
- 7. Contact / DPO
- 8. Data deletion
1. What personal data we collect
1a. The business we work with (our customer)
- Business details you give us or that are public — business name, address, phone, email, Facebook Page link, opening hours, service list, and prices.
- Your own photos and content — images, logos, and text you provide, or that are publicly posted on your Google Business Profile and Facebook Page, used only to build and run your website.
- Billing data — payment reference numbers, dates, and amounts. We do not store full card numbers; the payment provider confirms payment directly.
1b. Your customers' enquiries (leads captured on the site we build you)
When a visitor uses a booking form, quote estimator, or chatbot on a site we host, we collect what they typed on your behalf — typically name, phone, email (if given), the service asked about, any uploaded photo, and a free-text message. We process these as processor for you, so you can reply. You remain responsible, as the business, for how you use enquiries about your own customers.
1c. Website visitors (analytics)
- Anonymous page-view counters — page visits, button clicks, and section views. No advertising cookies and no third-party tracking pixels unless you explicitly ask us to add them.
- IP address — used only for short-window rate-limiting on form submissions to prevent spam, and not retained beyond 24 hours.
1d. Messenger / chatbot contacts
If you message a Facebook Page we operate, we receive your Page-Scoped ID (PSID), your public profile name, and the message content you send. We do not receive your email, phone, or friend list unless you type it to us.
2. Why we process it (purpose & legal basis)
Under RA 10173 we must have a lawful basis for every purpose. Ours:
- To perform our contract with you — to build, host, run, and support your website and the automations in your plan, and to bill you.
- With your consent — to send confirmations, reminders, and review requests, and to run any optional feature you switch on.
- For our legitimate interests — to secure the Service, prevent spam and fraud, and improve it using aggregated, anonymized usage statistics.
- To comply with law — to keep the records we are legally required to keep (for example, billing records).
We do not sell your personal data, we do not share your customer list with anyone else, and we do not use your data or your customers' data to train external AI models.
3. Who we share data with
We use a small set of processors and platforms strictly to run the Service. Each is bound to protect your data:
- Hosting & database providers — to store and serve the website and its records.
- An AI model provider — message content is sent to generate chatbot replies and draft content; it is not used to train the provider's public models under our terms.
- Facebook / Meta — where a Messenger chatbot is used, subject to Meta's own policies.
- Payment, email, and SMS providers — to take payment and deliver transactional messages you asked for.
We may also disclose data if required by law or a lawful order from the National Privacy Commission (NPC) or the courts.
4. How long we keep it (retention)
We keep personal data only as long as we need it for the purposes above:
- While you are an active customer — for as long as your website is live with us.
- After you cancel — we retain your data for 1 year, so you can resume without rebuilding, and then it is permanently deleted.
- Archival retrieval — if, within that 1-year window, you ask us to retrieve archived data, a ₱500 processing fee applies for the retrieval work.
- Visitor IP addresses — 24 hours (rate-limiting only).
- Records we must keep by law — kept for the period the law requires, then deleted.
5. Your rights under the Data Privacy Act
The Data Privacy Act of 2012 (RA 10173) gives every data subject in the Philippines the following rights. You can exercise any of them by contacting our Data Protection Officer (Section 7):
- Right to be informed — to know that your data is being collected and why (this notice).
- Right to access — to get a copy of the personal data we hold about you.
- Right to rectification — to correct anything inaccurate or out of date.
- Right to erasure or blocking — to have your data deleted or withheld where the law allows.
- Right to object — to stop or limit processing, including for direct marketing.
- Right to data portability — to obtain your data in a structured, commonly used electronic format.
- Right to damages — to be indemnified for harm caused by unlawful processing.
- Right to complain — to lodge a complaint with the National Privacy Commission (NPC).
We respond to a verified request within a reasonable period and, for straightforward requests, usually much sooner. If you are not satisfied with how we handle it, you may complain to the National Privacy Commission (NPC) at https://privacy.gov.ph/.
6. How we protect your data (security)
We maintain organizational, physical, and technical measures appropriate to the data we hold, including:
- All connections encrypted in transit (HTTPS / TLS).
- Database access via scoped service keys, not shared human logins.
- Passwords stored only as salted hashes, never in plain text.
- Access limited to the people who need it to run the Service.
- Webhook payloads verified to prevent spoofing.
No system is perfectly secure. If a personal data breach is likely to harm you, we will notify you and the National Privacy Commission (NPC) within 72 hours of knowing about it, as RA 10173 requires.
7. Contact us / Data Protection Officer
Athena Management — operating as Web by Lods.AI
Attention: Data Protection Officer
Privacy contact: [email protected]
General contact: [email protected]
Facebook: Web by Lods.AI
To make a rights request, email [email protected] and tell us who you are (your name and business name, or the phone/PSID you contacted us with) and what you would like us to do — access, correct, delete, object, or export.
8. Data deletion (also our Meta data-deletion URL)
If you used our Facebook chatbot and want your Messenger data deleted, message our Page with the word "DELETE" or email [email protected]. We will remove your PSID and name from our inbox, delete the conversation history, and confirm on the same channel you used. This section also serves as our Data Deletion Instructions URL for Meta app review.
9. Children's data
The Service is intended for business owners (18+). We do not knowingly collect data from anyone under 18. If you believe we have, email [email protected] and we will delete it.
10. Changes to this policy
This is our current policy — it may change as the Service and the law evolve. Material changes will be posted on this page with a new "last updated" date, and (for customers) emailed before they take effect. Continued use after an update means acceptance of the revised policy.