Legal

Privacy Policy

How we collect, use, share, and protect personal data — written to meet the Philippine Data Privacy Act, the EU and UK GDPR, and the privacy laws of Australia, New Zealand, and Canada.

Effective date19 July 2026
Last updated19 July 2026
Applies tochensedsolutions.com

01Who we are

Chensed Solutions (TJC & Co.) is a multi-jurisdictional accounting and advisory firm with its principal office in Davao City, Philippines. In this policy, "we", "us" and "the firm" mean Chensed Solutions (TJC & Co.).

For the purposes of Republic Act No. 10173 (the Data Privacy Act of 2012, "PH DPA") we act as a personal information controller in respect of the data described below. Where the EU or UK General Data Protection Regulation applies, we act as a controller in respect of enquiry and marketing data, and generally as a processor in respect of client accounting records we handle on a client's instructions.

This policy covers this website and our general business communications. Data handling under a signed engagement is additionally governed by the engagement letter and by our Client Data Security Statement.

02Which laws apply to you

We serve clients across several jurisdictions, and the rights available to you depend on where you are and how your data reaches us.

Where you arePrimary lawSupervisory authority
PhilippinesData Privacy Act of 2012 (RA 10173) and its IRRNational Privacy Commission (NPC)
European UnionEU General Data Protection Regulation (2016/679)Your member state's data protection authority
United KingdomUK GDPR and Data Protection Act 2018Information Commissioner's Office (ICO)
AustraliaPrivacy Act 1988 and the Australian Privacy PrinciplesOffice of the Australian Information Commissioner (OAIC)
New ZealandPrivacy Act 2020 and the Information Privacy PrinciplesOffice of the Privacy Commissioner
CanadaPIPEDA (and provincial equivalents, including Quebec's Law 25)Office of the Privacy Commissioner of Canada
United StatesState privacy laws where applicableVaries by state

Where more than one regime applies, we apply the standard most protective of you.

03What we collect

a. Information you send us directly

Our enquiry form does not transmit data to this website. The "Free Consultation" form on this site opens a pre-filled message in your own email application. Nothing you type is sent to, processed by, or stored on our web server — you remain in control until you press send in your own mail client. Once you send that email, we receive and hold it as described below.

When you contact us by email, telephone, or social media, we receive: your name, email address, telephone number, the business you represent, and whatever you choose to tell us about your situation.

b. Information we collect when you become a client

Under a signed engagement we handle information necessary to deliver the service, which may include: business registration documents; Taxpayer Identification Numbers and equivalent foreign identifiers; books of account, ledgers, invoices and receipts; bank and payment-processor records; payroll and statutory contribution data for your employees; tax returns and correspondence with revenue authorities; and identification documents collected for client due diligence.

Some of this is sensitive personal information under the PH DPA (for example, government-issued identifiers) or a special category under GDPR. We collect it only where it is necessary for the engagement or required by law.

c. Information collected automatically

Our web host records standard server logs — IP address, browser type, pages requested, and timestamps — for security and diagnostics.

d. Cookies, analytics and advertising tools

Where enabled, we use Google Analytics to understand how visitors use the site in aggregate, and the Meta Pixel to measure the performance of our advertising on Facebook and Instagram and to show ads to people who have visited this site. These tools set cookies and share data with Google LLC and Meta Platforms, Inc. respectively.

You can opt out of Google Analytics using Google's browser add-on, and control Meta's advertising through your Facebook ad preferences. You can also block or delete cookies in your browser settings; the site will continue to function.

04Why we use it, and on what legal basis

PurposeGDPR lawful basisPH DPA criterion
Responding to your enquiry and preparing a proposalSteps prior to entering a contractContract / legitimate interest
Delivering accounting, tax, audit and advisory servicesPerformance of a contractContract
Filing returns and reports with revenue and corporate regulatorsLegal obligationLegal obligation
Client due diligence and anti-money-laundering checksLegal obligationLegal obligation
Keeping records for the statutory retention periodLegal obligationLegal obligation
Site security, diagnostics and fraud preventionLegitimate interestLegitimate interest
Analytics and advertising measurementConsentConsent

We do not sell personal data. We do not use your data to train machine-learning models. We do not make decisions about you by automated means alone.

05Who we share it with

We disclose personal data only where one of the following applies:

  • Regulators and authorities — the Bureau of Internal Revenue, Securities and Exchange Commission, local government units, and their equivalents in the other jurisdictions we serve, where a filing or lawful request requires it.
  • Service providers — cloud accounting platforms, document storage, and email providers that support our work, bound by contract to process data only on our instructions.
  • Professional advisers — lawyers, external auditors, or co-engaged foreign tax counsel, where an engagement requires it and you have been informed.
  • Where you instruct us to — for example, corresponding with your bank or a prospective investor.
  • Where the law compels us — under subpoena, court order, or statutory audit power.

We do not share client information between service lines, between clients, or with any affiliated business without the client's express consent. This includes Briah Creatives, a separate marketing business under common ownership: shared ownership does not mean shared client data.

06International transfers

We are based in the Philippines and our staff access data from there. If you are in the EU, UK, Australia, New Zealand, or Canada, your data will therefore be transferred outside your home jurisdiction.

Where GDPR applies, we rely on the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Addendum) as the transfer mechanism, together with the technical and organisational measures set out in our Client Data Security Statement. A copy of the relevant clauses is available on request.

07How long we keep it

  • Enquiries that do not become engagements — up to 24 months, then deleted.
  • Client accounting records — retained for the statutory preservation period applicable to the engagement. In the Philippines, books of account and supporting records must be preserved for ten years from the day following the deadline for filing the relevant return, under Section 235 of the National Internal Revenue Code and BIR regulations. Comparable periods apply in the other jurisdictions we serve.
  • Client due diligence records — for the period required by applicable anti-money-laundering rules after the relationship ends.
  • Server logs — typically 30 to 90 days.

Where a statutory retention period applies, we cannot delete records on request until it expires. We explain this when it arises.

08Your rights

Depending on where you are, you may have the right to:

  • Be informed of how your data is processed — this policy is part of how we meet that.
  • Access a copy of the personal data we hold about you.
  • Correct data that is inaccurate or incomplete.
  • Object to processing, including direct marketing, which we will stop on request.
  • Erase, block or suspend processing in the circumstances the applicable law provides.
  • Data portability — receive your data in a structured, commonly used format.
  • Withdraw consent at any time, where processing rests on consent.
  • Lodge a complaint with your supervisory authority (see section 02), and, under the PH DPA, to be indemnified for damage caused by inaccurate or unlawfully processed data.

To exercise any of these, email us at the address below. We will verify your identity before acting, and respond within 30 days — or sooner where the applicable law requires it. There is no charge unless a request is manifestly excessive.

09Children

Our services are directed to businesses. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

10Changes to this policy

We may update this policy as our services, tools, or legal obligations change. The effective date at the top of this page shows the current version. Material changes affecting existing clients will be notified directly.

11How to contact us

Privacy enquiries and data subject requests

Email admin@chensedsolutions.com with "Privacy request" in the subject line, or call (082) 227-5745 during office hours, Monday to Friday, 8:00am–5:00pm PHT.

Chensed Solutions (TJC & Co.), Davao City, Philippines.

If you are in the Philippines and are not satisfied with our response, you may complain to the National Privacy Commission. If you are in the EU, UK, Australia, New Zealand, or Canada, you may complain to the authority listed in section 02.