Data Privacy Policy
Certifitax, operated by Medtax Solutions Inc.
Version 1.0. Effective 1 August 2026.
I. Introduction
Certifitax is a platform operated by Medtax Solutions Inc. (“Medtax,” “we,” “us,” or “our”) through which an Issuer generates, issues, and delivers tax certificates to the individuals and entities it pays. This Data Privacy Policy (“Policy”) describes how personal data is collected, used, stored, shared, and protected in connection with the Certifitax platform, in compliance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (“DPA”), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission (“NPC”).
This Policy covers the Certifitax platform only. Medtax provides tax, accounting, and related services outside the platform; personal data processed in the course of those services is governed by the separate privacy policy of Medtax Solutions Inc.
By registering for an account or otherwise using Certifitax, you acknowledge that you have read and understood this Policy.
Our commitments
- We do not sell, rent, or trade personal data, to anyone, at any price.
- We do not share personal data with third parties for their own purposes, and we do not obtain personal data about our users from data brokers, marketing lists, or other outside sources.
- Data submitted through Certifitax stays between the Account that submitted it, the person it concerns, and Medtax. Amazon Web Services stores the data on our instruction in encrypted form and is not permitted to access or use it for any purpose of its own. Two other services act on our instruction: an email delivery service, which handles a recipient's name and email address so a message can reach them, and Anthropic, which answers the help chat from what a user types there.
- We do not use personal data to target advertising, and we do not send marketing email to the recipients of certificates.
- We do not use real user data to test or study our systems.
These are summaries. The sections that follow set out the full terms and govern in case of any difference.
II. Scope and Application
This Policy applies to all personal data processed through the Certifitax platform. This includes personal data of the users who hold accounts on the platform, and personal data of the individuals and entities named on the certificates issued through it, typically professionals, suppliers, and other payees to whom an Issuer has made payments and from whom it has withheld tax.
III. Definition of Terms
- “Personal Data” refers to any information, whether recorded in material form or not, from which the identity of an individual is apparent or can be reasonably and directly ascertained, or which when put together with other information would directly and certainly identify an individual.
- “Sensitive Personal Information” refers to personal data about an individual’s race, ethnicity, marital status, age, health, education, genetic or sexual life, government-issued identification numbers (including the Tax Identification Number), and other information classified as sensitive under the DPA.
- “Account” refers to a registered account on the Certifitax platform, whether held by an individual in their own name or by a hospital, clinic, health maintenance organization, company, or other entity (an “Organization”).
- “Issuer” refers to an Account acting to generate, issue, or deliver a tax certificate in respect of payments it has made. An Account may act as an Issuer, as a Recipient, or as both.
- “Recipient” refers to an individual or entity named on a tax certificate issued through Certifitax as the payee of the income to which the certificate relates.
- “User” refers to any person who holds or accesses an Account on the Certifitax platform.
- “Data Subject” refers to an individual whose personal data is processed through the platform.
- “Processing” refers to any operation performed upon personal data, including collection, recording, organization, storage, updating, retrieval, use, consolidation, blocking, erasure, or destruction.
- “Data Protection Officer” or “DPO” refers to the individual designated to ensure compliance with the DPA and to serve as the primary contact for privacy-related concerns.
IV. Personal Data We Collect
We collect the following categories of personal data through the platform:
- Account information provided when a user registers and completes onboarding: first name, middle name, and last name, email address, mobile number, a password (stored only in hashed form), Tax Identification Number, tax classification, and address.
- Certificate information submitted or generated in the course of issuing a tax certificate: the name, Tax Identification Number, and address of the Recipient, the nature and amount of the income payment, the taxes withheld, the period covered, and the details of the Issuer and, for an Organization, its authorized signatory.
- Records generated by use of the platform: sign-in events, certificates generated, and the date and delivery status of certificates issued or received.
A Tax Identification Number is sensitive personal information under the DPA. It is collected because a tax certificate cannot be issued without it, and it is handled under the security measures described in Section XIII.
V. How We Collect Personal Data
Personal data processed through Certifitax is collected only from our own users, through the platform itself. Data is entered or uploaded either by the Issuer of a certificate or by the Recipient receiving it. We do not obtain personal data about a user from data brokers, marketing lists, public sources, or any other third party.
Where an Issuer submits data about a Recipient, the Recipient is identified on the certificate that results and can view that certificate through the platform, so the data is visible to the person it concerns.
VI. Purposes of Processing
Personal data is processed through Certifitax for the following purposes:
- To create and authenticate user accounts and verify the tax details required to issue a certificate.
- To generate tax certificates from the information supplied by an Issuer, and to deliver those certificates to the Recipients that Issuer identifies.
- To give both the Issuer and the Recipient continued access to the certificates issued to or by them.
- To maintain the security and integrity of the platform, including preventing and investigating unauthorized access.
- To notify users of matters affecting their account, the security of the platform, or the certificates issued to or by them.
- To comply with legal and regulatory obligations, and to establish, exercise, or defend legal claims.
Personal data is not processed for any other purpose without a lawful basis for doing so.
VII. Legal Basis for Processing
Medtax processes personal data on one or more of the following bases recognized under the DPA: the necessity of processing for the performance of a contract with the user; compliance with a legal obligation, including the obligation of a withholding agent to issue a certificate to its payee; the legitimate interests pursued by Medtax or by the Issuer, where not overridden by the rights of the data subject; and, where applicable, the consent of the data subject.
Certain personal data processed through Certifitax is sensitive personal information under the DPA, in particular the Tax Identification Number of a user or of a Recipient. Medtax processes that information on the basis provided under Section 13(b) of the DPA: the processing is provided for by existing laws and regulations, namely the National Internal Revenue Code and the issuances of the Bureau of Internal Revenue, which require a withholding agent to issue a certificate of tax withheld to its payee and require that certificate to state the Tax Identification Number of both parties. A certificate cannot lawfully be issued without it.
Where applicable, Medtax also relies on Section 13(f) of the DPA, which permits the processing of sensitive personal information for the protection of the lawful rights and interests of the parties and for the establishment, exercise, or defense of legal claims, including the right of a Recipient to claim the tax credit to which a certificate entitles them. Medtax does not rely on legitimate interests as a basis for processing sensitive personal information.
The issuing of a certificate to a Recipient does not rest on that Recipient’s consent. A withholding agent is required by law to issue it, and the Recipient is entitled to receive it.
VIII. Roles and Responsibilities
This section sets out who is answerable for what.
- Controller and processor. For personal data an Issuer uploads, encodes, or generates on Certifitax, including a Recipient’s name, Tax Identification Number, address, income payments, and taxes withheld, the Issuer is the personal information controller, whether the Issuer is an Organization or an individual. Medtax acts solely as a personal information processor, processing that data on the Issuer’s instructions and only as necessary to operate the platform and deliver the certificates. Medtax does not determine the purposes for which that data is processed. For account data that a user provides directly in order to hold an Account, Medtax is the controller.
- Accuracy and content. The Issuer is solely responsible for the accuracy, completeness, legality, and timeliness of all data and documents it uploads, encodes, or generates, and for the certificates it issues. Medtax does not verify, audit, validate, or correct that content, and generates certificates from the figures supplied to it.
- No tax advice or representation. Certifitax is a document generation and delivery tool. Medtax does not, through Certifitax, prepare or file returns, compute tax liabilities, act as a taxpayer’s representative before the Bureau of Internal Revenue or any other authority, or provide tax, accounting, or legal advice. Compliance with withholding, filing, reporting, and record-keeping obligations remains with the Issuer and the Recipient.
- Requests from Recipients. A Recipient who wishes to access, correct, object to, or erase data appearing on a certificate should direct the request to the Issuer. Where Medtax receives such a request directly, it will refer the Recipient to the Issuer and act only on that Issuer’s lawful instruction. Certain requests cannot be given effect where the record must be retained by law.
- What Medtax remains responsible for. As personal information processor, Medtax remains responsible for implementing security measures for the data it holds, processing that data only as instructed, the conduct of its personnel and service providers, and notifying the Issuer of a personal data breach affecting the platform, in each case as required under the DPA.
Nothing in this section limits any right a data subject has under the DPA, or any obligation Medtax owes as a personal information processor.
IX. Disclosure and Sharing
Medtax does not sell, rent, or trade personal data. We do not use the personal data of our users to test, develop, or study our systems; testing and development are carried out using seeded or synthetic data. Personal data is disclosed only in the following circumstances:
- To the Recipient named on a certificate, and to the Issuer, the two parties the record belongs to.
- To the service provider described in Section X, which stores data on our instruction and may not use it for its own purposes.
- To government agencies, including the Bureau of Internal Revenue, where required by law or to complete the service requested.
- With the express consent of the data subject.
- Where required or permitted by law, regulation, court order, or other legal process.
Personal data of a Recipient obtained through the platform is used only to generate and deliver that Recipient’s certificates, to give the Recipient access to them, and to meet legal and record-keeping obligations. It is not disclosed to other Accounts on the platform and is not shared with third parties for their own marketing purposes.
We do not use a Recipient’s personal data, including the contents of their certificates, the identity of the Issuers that pay them, or the amounts involved, to select, target, or personalize any promotional message. We do not send promotional or marketing email to Recipients. Medtax may publish information about its other services within the platform itself, shown to users generally rather than chosen on the basis of any individual’s data. Email sent to a Recipient is limited to the delivery of their certificates and notices concerning their account or the security of the platform.
X. Service Providers and Location of Processing
Medtax engages a third-party service provider to host the Certifitax platform and to store the data it holds. That provider processes personal data solely on our instructions, for the purpose of providing that service to us, and under contractual obligations of confidentiality and security. It is not permitted to use personal data for its own purposes.
- Cloud hosting and storage: Amazon Web Services. Platform data, including issued certificates, is stored on infrastructure provided by that service.
Certificates and account notifications are sent through an email delivery service acting on our instruction. It handles the recipient's name and email address so the message can reach them, and nothing else. The help chat is answered by Anthropic, which receives what the user types in order to answer it.
Depending on the data centre region in use, personal data processed through the platform may be stored outside the Philippines. Medtax remains accountable for that data under the DPA, and any such transfer is subject to contractual protections with the hosting provider designed to ensure a comparable level of protection to that required under Philippine law. The regions currently in use are published on our Service Providers page, and are updated when they change. A data subject may contact our Data Protection Officer for further information about these safeguards.
XI. Retention
Tax certificates issued through Certifitax, and the personal data appearing on them, are retained for five (5) years, consistent with the record-keeping period applicable to taxpayers under Philippine tax regulations. Both the Issuer and the Recipient retain access to those certificates for that period.
Other personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal, regulatory, tax, or accounting requirements, or to establish, exercise, or defend legal claims. Upon expiration of the applicable retention period, personal data is securely disposed of or anonymized. Retention periods may be revised in accordance with Section XVIII of this Policy.
XII. Account Closure and Deletion
A user may ask us to close their Certifitax account and delete their account data at any time. On such a request we delete the personal data held for the account, including name, email address, mobile number, password, Tax Identification Number, tax classification, address, and sign-in records, and the account can no longer be used. This is carried out promptly, subject only to any copy retained in routine system backups, which is overwritten in the ordinary course.
Tax certificates already issued through the platform are treated differently, and closing an account does not delete them. A certificate is a record of both the Issuer and the individual named on it, and both may be required by law to produce it. Certificates are therefore retained for the five-year period described above, held in restricted access, and released only to the Issuer, to the individual named on them, or as required by law or lawful order.
A Recipient who wishes to have a certificate itself corrected or erased should direct the request to the Issuer, which is the controller for that record. Medtax will act on that Issuer’s lawful instruction. Where a certificate must be retained to meet a legal obligation, neither Medtax nor the Issuer is able to erase it before the end of the applicable retention period.
Where an account has been inactive for an extended period, we may close it after giving notice to the registered email address. Retention of certificates already issued is unaffected.
XIII. Security Measures
Medtax implements reasonable and appropriate organizational, physical, and technical security measures designed to protect personal data against accidental or unlawful destruction, alteration, disclosure, or access. These include restricting access to personal data on a need-to-know basis, securing systems and records with access controls, imposing confidentiality obligations on personnel who handle personal data, and periodically reviewing our data protection policies and practices.
Data transmitted to and from the platform is encrypted in transit using industry-standard transport layer security, and data stored by the platform, including issued certificates, is encrypted at rest. Account passwords are stored only in hashed form and are not recoverable by Medtax personnel.
XIV. Rights of Data Subjects
Consistent with the DPA, data subjects have the right to:
- Be informed that their personal data will be, is being, or has been processed.
- Access their personal data upon request, subject to certain exceptions provided by law.
- Object to the processing of their personal data, including processing for direct marketing, automated processing, or profiling.
- Request the correction of inaccurate or outdated personal data.
- Request the erasure or blocking of personal data under circumstances allowed by law, such as when the data is incomplete, outdated, false, unlawfully obtained, or used for an unauthorized purpose.
- Be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal data.
- Data portability, where applicable and technically feasible.
- Lodge a complaint before the National Privacy Commission.
Requests may be sent to our Data Protection Officer using the contact details in Section XVII. Where the request concerns data appearing on a certificate, Section VIII item 4 applies and the request is directed to the Issuer.
XV. Data Breach Management
In the event of a personal data breach affecting the platform, Medtax will notify the affected Issuer without undue delay so that it may meet its own obligations as controller, and will assist that Issuer in doing so. Where Medtax is the controller of the affected data, and in any case where a breach poses a real risk of serious harm, Medtax will notify the National Privacy Commission and the affected data subjects within the period prescribed under applicable NPC regulations. In all cases Medtax will take appropriate steps to contain, assess, and mitigate the impact of the breach.
XVI. Cookies and Local Storage
The platform sets only cookies that are strictly necessary for it to function: a session cookie that keeps a user signed in, and cookies that protect sign-in against cross-site request forgery. We do not use advertising, tracking, or third-party analytics cookies, and we do not track users across other websites. The platform also stores interface preferences in your browser’s local storage; these stay on your device and are not sent to us.
Session cookies may be cleared through your browser settings, though doing so will sign you out. Our website may contain links to third-party websites; Medtax is not responsible for the privacy practices of those websites.
XVII. Data Protection Officer
For questions, concerns, or requests relating to this Policy or the processing of your personal data, you may contact our Data Protection Officer. The same officer is responsible for Medtax Solutions Inc. and for the Certifitax platform.
Medtax Solutions Inc.Suite 9D, Valero Tower, Valero Street, Bel-Air, Salcedo Village, Makati City, Philippines 1227Email: dpo@certifi.taxContact Number: +63 976 298 9000
XVIII. Amendments to This Policy
Medtax reserves the right to update or amend this Policy from time to time to reflect changes in our data processing practices or in applicable laws and regulations. The updated Policy will be posted with a revised effective date and, where required, notice will be provided to affected data subjects.
XIX. How to Reach Us
If you have any concerns about how your personal data has been handled, you may reach our Data Protection Officer through the contact details in Section XVII above. You may also file a complaint with the National Privacy Commission through www.privacy.gov.ph if you believe your data privacy rights have been violated.