Privacy Notice and Data Rights Policy

Version 4 · Effective September 16, 2026

1. INTRODUCTION

This Privacy Notice and Data Rights Policy (“Privacy Notice,” “Policy,” or “Privacy Policy”) explains how DIGITALFRAMEWORK I.T. SOLUTIONS, a sole proprietorship registered and existing under the laws of the Republic of the Philippines, with business address at 14 Gregorio St., Barangay Mariano Espeleta II, Imus City, Cavite 4103, Philippines, owned and operated by Mark Baldus (“CelebrateSync,” “Operator,” “we,” “us,” or “our”), collects, receives, uses, stores, organizes, retrieves, discloses, transfers, protects, retains, deletes, and otherwise processes personal data in connection with the CelebrateSync ecosystem.

The CelebrateSync ecosystem includes the CelebrateSync mobile application, the HostHaven organizer platform, websites and web applications, Event workspaces, event-management and guest-experience tools, invitations and RSVP functionality, Event programs, QR passes and other Event Credentials, guest-management features, supplier profiles and the Supplier Network, Public Trust features, reviews and ratings, communications and notifications, user profiles, photographs, videos, Event memories, customer-support channels, security and fraud-prevention systems, promotional engagement programs, and other software, features, products, and services that CelebrateSync may make available from time to time.

This Privacy Notice is intended to provide meaningful information about the manner in which personal data is processed throughout that ecosystem. It should be read together with the CelebrateSync Terms of Service, applicable Event-specific rules, feature-specific terms and conditions, Media Terms, Review Guidelines, Spark Points Program Terms, app permission disclosures, consent forms, and other policies or notices that may apply to a particular feature or processing activity. The Terms of Service expressly provide that the collection, use, storage, disclosure, retention, and other processing of personal data through the Services are principally governed by this Privacy Notice and Data Rights Policy.

CelebrateSync is committed to processing personal data in accordance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (“DPA”), its Implementing Rules and Regulations (“IRR”), applicable regulations, circulars, advisories and orders of the National Privacy Commission (“NPC”), and other applicable Philippine laws and regulations relating to privacy, confidentiality, cybersecurity, electronic transactions, consumer protection, intellectual property, and related matters. This Privacy Notice is intended to explain the principal data-processing activities of CelebrateSync while recognizing that the precise information processed may vary depending upon the Services used, the role of the User, the configuration of an Event, the instructions of an Event Organizer, the permissions granted by the User, and the technical features actually enabled at the relevant time.

2. DEFINITIONS

For purposes of this Agreement, the following terms shall have the meanings set forth below. Unless the context otherwise requires, words in the singular include the plural and words in the plural include the singular. Terms defined under applicable Philippine law, particularly the Data Privacy Act of 2012 and its implementing rules and regulations, shall have the meaning provided under such law to the extent applicable.

“Account” means the account, profile, or registration established by or for a User for purposes of accessing or using the Services, including associated usernames, credentials, identifiers, settings, preferences, and other account-related information.

“Agreement,” “Policy,” or “Privacy Notice” means this CelebrateSync Privacy Notice and Data Rights Policy, including any amendments, revisions, or updated versions thereof.

“Applicable Law” means all laws, statutes, regulations, rules, circulars, advisories, orders, and other legally binding requirements applicable to CelebrateSync, the Services, the User, or the relevant processing activity, including Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012, its implementing rules and regulations, and applicable issuances of the National Privacy Commission (“NPC”).

“CelebrateSync” means DIGITALFRAMEWORK I.T. SOLUTIONS, a sole proprietorship registered and existing under the laws of the Republic of the Philippines, including its proprietor, authorized representatives, personnel, contractors, and authorized service providers, as applicable. References to CelebrateSync may include any lawful successor or entity that subsequently assumes ownership or operation of the Services.

“Content” means any information or material submitted, uploaded, transmitted, posted, created, stored, displayed, or otherwise made available through the Services, including text, photographs, images, videos, audio recordings, documents, graphics, logos, artwork, reviews, ratings, comments, messages, Event materials, captions, and other materials.

“Consent” means any freely given, specific, informed, and unambiguous indication of the User's wishes by which the User signifies agreement to the processing of personal data relating to the User for a particular purpose or purposes, where consent is the applicable lawful basis under Applicable Law.

“Data Privacy Act” or “DPA” means Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012, including its implementing rules and regulations and applicable regulations, circulars, advisories, and orders issued by the NPC.

“Data Subject” means an individual whose personal data is processed by CelebrateSync or through the Services. A Data Subject may or may not be a User. For example, an invited guest whose information is entered into an Event may be a Data Subject even if the guest does not maintain a CelebrateSync Account.

“Event” means any wedding, birthday, party, corporate gathering, conference, meeting, celebration, social occasion, private function, public occasion, or other activity created, organized, administered, or supported through the Services.

“Event Data” means personal data, Content, records, and other information relating to an Event that is submitted, generated, collected, stored, or otherwise processed through the Services, including, where applicable, guest information, invitations, RSVP information, attendance records, seating assignments, Event roles, check-in information, Event Credentials, communications, photographs, videos, and other Event-related information.

“Event Credential” means any digital or electronic identifier issued or supported through the Services for purposes of identifying, authenticating, admitting, checking in, or otherwise managing a person's participation in an Event, including QR codes, digital passes, electronic tickets, digital invitations, and similar functionality.

“Event Organizer” or “Organizer” means the person or entity that creates, owns, administers, manages, or is otherwise responsible for an Event through the Services. An Event Organizer may include an individual, event planner, wedding coordinator, company, organization, venue, host, or other authorized person or entity.

“Governing Documents” means the documents, terms, policies, rules, notices, guidelines, and disclosures applicable to the User's access to or use of the Services, including the CelebrateSync Terms of Service, Privacy Notice and Data Rights Policy, applicable Event-specific rules, feature-specific terms, Media Terms, Review Guidelines, Supplier Network and Public Trust rules, Spark Points Program Terms, application permission disclosures, and other policies, notices, guidelines, or rules expressly incorporated into or made applicable to the Services.

“HostHaven” means the organizer-facing platform, dashboard, website, web application, or related functionality made available by CelebrateSync for Event Organizers and authorized Event personnel to create, configure, manage, administer, and monitor Events.

“Media” means photographs, images, videos, audio recordings, voice recordings, graphics, illustrations, Event memories, or other visual or audiovisual material submitted, uploaded, transmitted, displayed, stored, or otherwise processed through the Services.

“Personal Data” or “Personal Information” means personal data or personal information as defined under Applicable Law, including information from which an individual is identified or identifiable, whether directly or when combined with other information reasonably available to the entity processing such information.

“Personal Information Controller” or “PIC” means a person or entity that controls the processing of personal data, as defined under the DPA and Applicable Law. Depending upon the relevant processing activity, CelebrateSync or an Event Organizer may act as a PIC.

“Personal Information Processor” or “PIP” means a person or entity to whom the processing of personal data may be outsourced or entrusted by a PIC, as defined under the DPA and Applicable Law. Depending upon the relevant processing activity, CelebrateSync may act as a PIP for Event Data processed on behalf of an Event Organizer.

“Privacy Notice” means the CelebrateSync Privacy Notice and Data Rights Policy, including any amended, revised, or replacement version thereof, which describes CelebrateSync's personal-data processing practices and the rights and procedures available to Data Subjects.

“Processing” means any operation or set of operations performed upon personal data, including collection, recording, organization, storage, updating, retrieval, consultation, use, consolidation, blocking, erasure, destruction, disclosure, transmission, or other handling of personal data, as understood under Applicable Law.

“Services” means the CelebrateSync ecosystem and all products, platforms, applications, websites, software, features, tools, functionality, and related services made available, operated, administered, or authorized by CelebrateSync. For purposes of this Agreement, the Services include, where applicable, the CelebrateSync mobile application, HostHaven organizer platform, websites and web applications, Event workspaces, Event creation and management tools, invitations and RSVP functionality, Event programs, QR passes and Event Credentials, guest-management tools, supplier profiles and the Supplier Network, Public Trust features, reviews and ratings, communications and notifications, user profiles, photographs and videos, Event memories, customer-support functionality, security and fraud-prevention systems, promotional engagement programs, and any successor, replacement, supplemental, or additional functionality introduced by CelebrateSync.

“Supplier” means any individual, business, company, professional, service provider, vendor, contractor, venue, or other person or entity offering goods or services through or in connection with the Supplier Network or Services.

“Supplier Network” means the portion of the Services through which Suppliers may create or maintain profiles, describe or offer their services, interact with Event Organizers or Users, receive reviews or ratings, and otherwise participate in CelebrateSync's supplier-related functionality.

“User” means any individual who accesses, registers for, creates an Account on, interacts with, or uses the Services, whether as an Event Organizer, guest, attendee, Event personnel, Supplier, supplier representative, reviewer, contributor, or in any other authorized capacity. A person may be considered a User even if the person does not create an Account, where the person accesses or interacts with a feature of the Services without registration. Where an individual accesses the Services on behalf of an organization or other legal entity, “User” includes the individual acting in such authorized capacity.

“User Content” means Content submitted, uploaded, posted, or otherwise made available through the Services by a User, including photographs, videos, reviews, ratings, comments, Event memories, messages, profile information, documents, captions, and other materials.

“Third-Party Service Provider” means an external person or entity engaged by CelebrateSync or integrated with the Services to provide hosting, infrastructure, storage, authentication, communications, messaging, analytics, cybersecurity, monitoring, customer support, backup, content delivery, payment, professional, or other services.

Where the context requires, references to the “User” may include the relevant Data Subject, Event Organizer, or other authorized person using the Services; provided that the use of such term shall not alter the respective legal responsibilities of CelebrateSync, an Event Organizer, or another party under Applicable Law. For purposes of this Agreement, the terms “including,” “includes,” “such as,” and similar expressions are illustrative and shall not be interpreted as limiting the general meaning of the preceding terms. The headings used in this Agreement are for convenience only and shall not affect the interpretation of its provisions.

3. PRIVACY PRINCIPLES

CelebrateSync recognizes that personal data belongs to the individual to whom it relates and should be handled responsibly throughout its lifecycle. CelebrateSync therefore seeks to apply the principles of transparency, legitimate purpose, proportionality, accountability, and security to all processing activities for which it is responsible. Personal data will be collected and processed for specific, legitimate, and declared purposes. CelebrateSync will seek to limit collection to information that is reasonably necessary and relevant to the applicable purpose and will endeavor not to use personal data for purposes that are incompatible with the purpose for which the information was originally collected unless such additional processing is authorized by law or otherwise appropriately disclosed. The fact that a particular category of information can technically be collected does not mean that CelebrateSync will necessarily collect or use it. The availability of technical functionality does not by itself constitute authorization to process personal data. CelebrateSync will also seek to maintain appropriate controls over persons and organizations that have access to personal data and will implement reasonable and appropriate organizational, physical, and technical safeguards proportionate to the nature and risks of the processing.

4. RESPONSIBILITY FOR PERSONAL DATA

The role of CelebrateSync in relation to particular personal data depends upon the nature of the processing activity. In circumstances where CelebrateSync determines why personal data is collected and how it will be processed, CelebrateSync acts as a Personal Information Controller (“PIC”). This will generally include personal data processed for the administration and operation of the CelebrateSync platform itself, such as Account registration, authentication, platform security, customer support, system administration, technical operations, certain supplier-profile activities, privacy-request management, contractual records, legal compliance, fraud prevention, and other activities for which CelebrateSync independently determines the purposes and means of processing. In other circumstances, particularly where an Event Organizer creates an Event and determines what guest or attendee information should be collected, why that information is required, who should have access to it, and how it will be used for the Event, CelebrateSync may act as a Personal Information Processor (“PIP”). In that capacity, CelebrateSync processes personal data on behalf of and according to the documented instructions of the applicable Event Organizer or other controller. This distinction is particularly important for Event Data. An Event Organizer may determine, for example, that it requires a guest's name, contact details, RSVP status, seating assignment, accessibility information, dietary requirements, Event role, or other information for purposes of organizing an Event. Where the Organizer determines the purpose and means of that processing, the Organizer bears the corresponding responsibilities of a controller, while CelebrateSync provides the technology through which the Organizer's processing is carried out.

The Terms of Service likewise provide that Event Organizers are responsible for the accuracy and lawful use of Event Data and for obtaining the permissions, notices, consents, licenses, and other legal authority required for information or media that they provide through the Services. Where CelebrateSync acts as a processor, it will not independently use Event Data for unrelated purposes merely because the information is technically accessible to it. Processing will generally be limited to providing, securing, maintaining, supporting, and improving the relevant Services in accordance with the applicable instructions, contractual arrangements, and applicable law.

5. PERSONAL DATA PROCESSED

CelebrateSync may process personal data relating to persons who interact directly with the Services as well as persons whose information is submitted by another authorized person. This may include Account holders, prospective Users, Event Organizers, Event coordinators, Event personnel, invited guests, attendees, suppliers, supplier representatives, photographers, videographers, reviewers, persons appearing in Event photographs or videos, parents or guardians, authorized representatives, persons communicating with CelebrateSync, and persons whose information is otherwise lawfully submitted through the Services. A person does not necessarily need to have a CelebrateSync Account for CelebrateSync to process personal data concerning that person. For example, an Event Organizer may create an Event guest list containing the names and contact information of invited persons who have not registered for CelebrateSync. Similarly, a guest may appear in an Event photograph uploaded by another User. Where personal data is submitted by another person, the person submitting that information is responsible for ensuring that he or she has the necessary authority and lawful basis to provide the information for the applicable purpose.

6. PERSONAL DATA THAT MAY BE COLLECTED

The categories of personal data processed by CelebrateSync depend upon the Services used and the circumstances in which the information is provided. When an individual creates or maintains an Account, CelebrateSync may process information such as the person's name, username, profile name, email address, telephone or mobile number, profile photograph, account identifier, authentication information, age-related information where necessary, and other information required to administer the Account. When a person participates in an Event, CelebrateSync may process information concerning that person's participation, including the person's name, invitation status, RSVP status, attendance status, Event role, seating assignment, table assignment, check-in status, Event communications, and other information determined by the Event Organizer to be necessary for the Event. Where an Event Organizer elects to collect additional information from guests, that information may include dietary preferences, accessibility requirements, special arrangements, arrival information, or other Event-specific information. Because some such information may reveal sensitive personal information, Event Organizers should collect it only where necessary, proportionate, and supported by an appropriate lawful basis.

CelebrateSync may also process photographs, videos, audio recordings, messages, reviews, ratings, comments, Event memories, captions, documents, logos, artwork, and other User Content that a User or Event Organizer uploads or otherwise makes available through the Services. The Terms of Service provide that Users retain ownership of Content they submit, while granting CelebrateSync a limited license to process that Content to the extent reasonably necessary to operate and provide the Services, maintain security, investigate misuse, enforce applicable terms, comply with law, and respond to support, legal, privacy, or security matters.

CelebrateSync may also automatically collect technical and usage information generated through interaction with the Services. This may include IP addresses, device identifiers, operating-system information, browser information, application version, timestamps, authentication records, security logs, crash reports, diagnostic information, network information, usage information, and similar technical data. Where a feature requires location information, CelebrateSync may process location information supplied by a device or information voluntarily entered by the User. Location access will depend upon the relevant feature and the permissions granted through the operating system or application.

7. SENSITIVE PERSONAL INFORMATION

CelebrateSync recognizes that certain categories of information receive heightened protection under Philippine law. Sensitive personal information may include information concerning health, medical conditions, disability, government-issued identifiers, and other information falling within the statutory definition of sensitive personal information. CelebrateSync does not intend to collect sensitive personal information merely for convenience or because it may be useful to the platform. Where sensitive information is processed, the processing should have a specific and legitimate purpose and should be supported by an appropriate lawful basis. An Event Organizer may, for example, determine that limited accessibility or dietary information is necessary to accommodate guests at an Event. In such circumstances, the Organizer remains responsible for determining whether the information is necessary and lawful to collect and for providing appropriate notice to the affected persons. Where CelebrateSync acts as processor, it will process such information according to the Organizer's lawful instructions and applicable contractual arrangements.

8. SOURCES OF PERSONAL DATA

CelebrateSync may obtain personal data directly from the individual concerned, from an Event Organizer, from an authorized Event coordinator or staff member, from another User who has authority to provide the information, from a supplier or supplier representative, from a parent or guardian, from the individual's device or browser, from an authentication or other integrated service, from service providers, from publicly available sources, or from government or regulatory authorities where legally permitted or required. Information supplied by another person does not necessarily mean that CelebrateSync has independently verified the accuracy, completeness, or legal basis for that information. The person who submits personal data concerning another individual remains responsible for ensuring that the submission is lawful.

9. PURPOSES OF PROCESSING

CelebrateSync processes personal data primarily to provide, administer, maintain, secure, and improve the Services. Personal data may be processed to create and administer Accounts, authenticate Users, maintain profiles, manage permissions, issue and validate Event Credentials, administer Events, manage invitations and RSVPs, facilitate Event communications, provide check-in functionality, manage Event programs and seating information, support supplier profiles, administer reviews and ratings, provide customer support, troubleshoot technical problems, maintain platform performance, investigate security incidents, prevent fraud and abuse, enforce the Terms of Service, comply with legal obligations, respond to lawful requests, establish or defend legal claims, and protect the rights and security of CelebrateSync and its Users. Personal data may also be processed to maintain records demonstrating that a User accepted applicable Terms, policies, addenda, disclosures, or consent requests. The Terms of Service contemplate the recording of the relevant Account or identifier, version date, date and time of acceptance, acceptance mechanism, and applicable acknowledgment or consent selections. Where promotional communications are permitted, CelebrateSync may use contact information to communicate information about its own Services, products, updates, or promotions. Where consent is required for a particular communication or processing activity, CelebrateSync will obtain the applicable consent separately rather than treating acceptance of the Terms of Service or acknowledgment of this Privacy Notice as blanket marketing consent.

10. LAWFUL BASIS FOR PROCESSING

CelebrateSync will process personal data only where an appropriate lawful basis exists under applicable law. Depending upon the circumstances, processing may be based on the data subject's consent, the necessity of processing to perform a contract or take steps requested before entering into a contract, compliance with a legal obligation, protection of lawful rights and interests, or another lawful basis recognized under the DPA and its implementing rules. Where consent is relied upon, CelebrateSync will seek to ensure that the consent is informed, specific, freely given, and capable of being withdrawn. Consent will not be used as a substitute for another lawful basis where consent is not the appropriate basis for the relevant processing. Where processing is necessary to provide a requested Service, certain processing may occur because it is necessary to perform the applicable contractual relationship. For example, information required to create an Account, authenticate a User, issue an Event Credential, process an RSVP, or provide requested Event functionality may need to be processed in order for the requested Service to operate. Acceptance of the Terms of Service does not constitute blanket consent to every possible processing activity. The Terms expressly provide that where separate consent is legally required, that consent should be obtained through a separate mechanism identifying the relevant purpose, data category, and processing activity.

11. EVENT DATA AND ORGANIZER RESPONSIBILITY

Event Data presents a particular privacy consideration because the person using the platform may not be the person to whom the information relates. An Event Organizer may submit guest information concerning numerous individuals in order to organize an Event. CelebrateSync provides the technological infrastructure through which that information may be stored, displayed, communicated, and otherwise processed. The Organizer is responsible for determining what information is necessary for the Event and for ensuring that appropriate notices, permissions, consents, and other legal authority exist where required. The Organizer should also configure Event permissions so that individuals receive access only to information reasonably necessary for their Event role. An Organizer should not, for example, provide a supplier with access to an entire guest list merely because the supplier requires limited information concerning a particular service. CelebrateSync may provide role-based access controls, Event permissions, restricted views, or other technical measures where such functionality is available. These controls are intended to support appropriate access management but do not relieve an Organizer of its own legal responsibilities as controller of Event Data.

12. EVENT VISIBILITY AND PUBLIC INFORMATION

CelebrateSync may permit certain information to be made available to persons beyond the individual who submitted it. An Event Organizer may intentionally configure portions of an Event as accessible to invited guests, Event staff, suppliers, or other authorized persons. Certain supplier information, reviews, ratings, and Public Trust information may also be intentionally displayed publicly. Users should therefore consider carefully whether information they submit is intended to remain private or is intended to appear in an Event workspace, supplier profile, review, public directory, or other publicly accessible area. Information that a User voluntarily submits to a public-facing feature may be accessible to persons beyond the User's immediate Event or Account. CelebrateSync will not treat information as private merely because the person who submitted it expected privacy contrary to the configuration of the applicable feature. Conversely, information designated as private or restricted should not be treated as publicly available merely because it is technically stored within the same platform.

13. SUPPLIER NETWORK AND PUBLIC TRUST DATA

The Supplier Network and Public Trust features may involve the processing of information concerning suppliers and service providers. Supplier information may be submitted by the supplier itself, an Event Organizer, another User, or another lawful source. Information may include business names, supplier names, contact information, business descriptions, service categories, locations, profile photographs, reviews, ratings, responses, and other information associated with a supplier profile. CelebrateSync may process such information to facilitate discovery, maintain platform integrity, administer profiles, respond to complaints, investigate suspected inaccuracies or abuse, and operate Public Trust features. The publication of a supplier profile, rating, review, or other information does not constitute an accreditation, certification, endorsement, guarantee, or representation by CelebrateSync concerning the supplier's qualifications, reliability, licensing, insurance, safety, suitability, or performance. The Terms of Service expressly reserve this position. Where a supplier profile contains personal information relating to an individual, the individual may exercise applicable privacy rights, subject to the rights of other persons, the source of the information, and any applicable legal exceptions.

14. PHOTOGRAPHS, VIDEOS, MEMORIES, AND OTHER MEDIA

CelebrateSync may process photographs, videos, recordings, and other media uploaded or otherwise provided through the Services. Such media may contain identifiable individuals even when the person appearing in the media has never created a CelebrateSync Account. The person uploading media is responsible for ensuring that he or she has the necessary rights, permissions, notices, licenses, or other authority to upload and use the media through the Services. CelebrateSync may process media to host, store, reproduce as technically necessary, format, resize, transmit, display, moderate, secure, and otherwise provide the relevant functionality. It may also process media where reasonably necessary to investigate misuse, respond to privacy or legal complaints, protect users, comply with law, or enforce applicable policies. Private Event media will not be treated as general advertising material merely because it is stored on the platform. CelebrateSync will not intentionally use private Event media or media involving minors for public advertising without appropriate authorization where such authorization is legally required.

15. APPLICATION PERMISSIONS

Depending upon the functionality used, the CelebrateSync application may request access to device functions such as the camera, photographs or media library, notifications, storage, location, microphone, contacts, or other device capabilities. The fact that the application requests a permission does not necessarily mean that CelebrateSync will continuously collect all information accessible through that permission. The purpose of the permission will depend upon the relevant functionality. Where possible, the application will request permissions only when the corresponding feature is being used or is reasonably necessary. Users may refuse or later revoke certain device permissions through their device settings, subject to the technical capabilities of the applicable operating system. Revoking a permission may cause the associated feature to become unavailable or operate in a limited manner.

16. COOKIES AND SIMILAR TECHNOLOGIES

CelebrateSync may use cookies, software development kits, local storage, pixels, tags, logs, and similar technologies in connection with its websites, applications, and Services. These technologies may be used to maintain sessions, authenticate Users, remember preferences, protect Accounts, detect suspicious activity, understand how the Services are used, measure performance, troubleshoot technical issues, and improve the user experience. Where applicable law requires consent for a particular technology or purpose, CelebrateSync will provide an appropriate consent mechanism.

Browser and device settings may permit Users to control certain technologies, although disabling them may affect functionality.

17. THIRD-PARTY SERVICE PROVIDERS

CelebrateSync relies upon certain third-party providers to operate technical and administrative portions of the Services. These providers may include hosting and cloud infrastructure providers, database and storage providers, authentication providers, email and messaging providers, push-notification providers, cybersecurity providers, analytics providers, application monitoring providers, customer-support providers, content-delivery providers, backup providers, and other technology or professional service providers. Where such providers process personal data on behalf of CelebrateSync, CelebrateSync will seek to ensure that appropriate contractual, confidentiality, security, access-control, and data-processing safeguards are established. Third-party providers will generally receive access only to the information reasonably necessary to perform the services for which they have been engaged. Where the Services integrate with an independent third-party service that acts as its own controller, that third party may process information under its own privacy notice and terms. Users should review those terms before directly providing information to such third parties.

18. CROSS-BORDER PROCESSING

Some third-party technology and infrastructure providers used by CelebrateSync may store or process personal data outside the Philippines. Where personal data is transferred, stored, or accessed across borders, CelebrateSync will take reasonable measures to ensure that the processing remains subject to appropriate contractual, organizational, and technical safeguards and complies with applicable Philippine privacy requirements. The location of infrastructure may change over time as CelebrateSync changes providers, introduces new services, or modifies its technical architecture. Where a material change requires additional notice under applicable law, CelebrateSync will provide appropriate notice.

19. SECURITY MEASURES

CelebrateSync recognizes that personal data security is an ongoing process rather than a single technical measure. CelebrateSync intends to maintain reasonable and appropriate organizational, physical, and technical safeguards proportionate to the nature of the personal data processed and the risks associated with the applicable processing. Depending upon the system and circumstances, safeguards may include authentication controls, role-based permissions, access restrictions, encryption where appropriate, logging and monitoring, security testing, vulnerability management, backup procedures, secure development practices, confidentiality obligations, employee and contractor training, incident-response procedures, processor oversight, business continuity measures, and physical safeguards. Access to personal data should be limited to persons who require the information for a legitimate business, technical, support, security, legal, or operational purpose. No internet-connected system can be guaranteed to be completely secure. CelebrateSync therefore does not represent that unauthorized access, data loss, or security incidents can never occur. Instead, CelebrateSync will maintain reasonable measures designed to reduce the likelihood and impact of such incidents and will respond appropriately when incidents occur.

20. PERSONAL DATA BREACHES

CelebrateSync will maintain procedures for identifying, assessing, containing, investigating, documenting, and responding to personal-data breaches and other security incidents. Where a personal-data breach satisfies the applicable legal requirements for notification, CelebrateSync will notify the NPC and affected data subjects within the period and in the manner required by law. A qualifying breach may require notification where sensitive personal information or other information capable of enabling identity fraud has been acquired by an unauthorized person and the circumstances are reasonably likely to give rise to a real risk of serious harm. Where notification is required, CelebrateSync may provide information concerning the nature of the incident, the categories of information affected, measures taken to contain or address the incident, steps available to reduce potential harm, and other information required by applicable law. CelebrateSync may preserve relevant records, logs, communications, Content, Account information, or other evidence to investigate and respond to a security incident, comply with legal obligations, prevent further harm, or cooperate with competent authorities.

21. DATA RETENTION

CelebrateSync does not intend to retain personal data indefinitely. Personal data will generally be retained only for as long as reasonably necessary to fulfill the purpose for which it was collected or processed, unless a longer period is required or permitted by law. The appropriate retention period depends upon the type of information and the circumstances of processing. Account information may need to be retained while an Account remains active and for a reasonable period thereafter. Event information may need to remain available for the duration of the Event and for a reasonable period necessary to provide post-Event functionality, resolve disputes, maintain security, or comply with legal obligations. Transactional and accounting records, where applicable, may be retained for periods required by law. Information may also be retained where reasonably necessary to establish, exercise, or defend legal claims, investigate fraud, address security incidents, comply with regulatory requirements, preserve evidence, or satisfy a legal hold. When information is no longer reasonably required, CelebrateSync will take reasonable measures to delete, destroy, anonymize, or otherwise dispose of the information in accordance with applicable law and its retention procedures. Deletion from active systems may not result in immediate deletion from backups or disaster-recovery systems. Information retained in backups will remain subject to appropriate security measures and will be deleted or overwritten in accordance with applicable backup-retention procedures.

22. DE-IDENTIFIED AND AGGREGATED INFORMATION

CelebrateSync may create aggregated, statistical, or appropriately de-identified information from personal data for legitimate operational purposes. Such information may be used to understand general usage patterns, monitor system performance, improve Services, identify technical problems, develop new functionality, conduct security analysis, and perform other legitimate activities. Where information is intended to function as anonymized or de-identified information, CelebrateSync will take reasonable measures designed to prevent the information from being used to identify an individual.

23. AUTOMATED PROCESSING AND ARTIFICIAL INTELLIGENCE

CelebrateSync may use automated technical processes for purposes such as authentication, spam prevention, fraud detection, security monitoring, system administration, content-management assistance, and service optimization. Unless separately disclosed and lawfully implemented, CelebrateSync does not currently provide AI-based decision-making or automated decision-making that produces legal or similarly significant effects on Users. The Terms of Service expressly identify AI decision-making or decisioning as a feature that is not enabled unless separately reviewed and released by the Operator. If CelebrateSync introduces automated decision-making, profiling, artificial-intelligence functionality, or another processing activity capable of materially affecting data-subject rights, CelebrateSync will provide appropriate notice and implement applicable safeguards before activating the relevant feature.

24. CHILDREN AND MINORS

CelebrateSync's general Account functionality is intended for persons at least eighteen (18) years old unless the Operator expressly approves otherwise. The platform may nevertheless process information concerning minors because minors may attend Events, appear in Event photographs or videos, or otherwise be included in Event-related information. Event Organizers who process information concerning minors are responsible for ensuring that they have the necessary parental, guardian, legal, or other authority required for the processing. CelebrateSync will apply additional safeguards where appropriate to information concerning minors and may restrict, remove, or prevent public-facing features involving minors where necessary for privacy or safety reasons. The Services must not be used to facilitate child sexual abuse or exploitation, grooming, trafficking, sexualized minor content, or other unlawful exploitation of children. Content or Accounts presenting such risks may be restricted, removed, preserved, investigated, or reported where required or permitted by law. The Terms of Service expressly prohibit the use of the Services for such conduct and reference Republic Act No. 11930 and other applicable Philippine law.

25. DATA SUBJECT RIGHTS

Individuals whose personal data is processed by CelebrateSync may exercise rights granted by the DPA and other applicable law, subject to the conditions, exceptions, and limitations provided by law. These rights include the right to be informed, the right to access personal data, the right to correct inaccurate information, the right to object to certain processing, the right to request erasure or blocking in appropriate circumstances, the right to data portability where applicable, the right to lodge a complaint with the NPC, and the right to seek damages where authorized by law. These rights are not absolute in every circumstance. Applicable law may permit or require CelebrateSync to continue processing certain information even where a User requests deletion, restriction, or cessation of processing. For example, CelebrateSync may need to retain information to comply with law, respond to a lawful government request, establish or defend a legal claim, investigate fraud, address a security incident, preserve evidence, or satisfy another legitimate legal obligation.

26. RIGHT TO BE INFORMED

A data subject may request information concerning whether personal data relating to him or her is being processed and, where applicable, may request information concerning the purposes of processing, categories of personal data, sources, recipients or categories of recipients, retention, applicable rights, and other information required under the DPA.

This Privacy Notice is intended to provide the general information required to understand CelebrateSync's principal processing activities. A more specific response may be provided where the data subject requests information concerning a particular processing activity.

27. RIGHT TO ACCESS

A data subject may request reasonable access to personal data concerning him or her.

Where appropriate, CelebrateSync may provide a copy of the relevant information or an accessible representation of the information maintained in its systems. Access may be limited where disclosure would prejudice the rights of another person, reveal confidential information, compromise security, interfere with an investigation, violate a legal obligation, or fall within another lawful exception. Where information relates to an Event and is controlled by an Event Organizer, CelebrateSync may need to coordinate with the Organizer before responding substantively to the request.

28. RIGHT TO RECTIFICATION

A data subject may request correction of personal data that is inaccurate, incomplete, outdated, or otherwise incorrect. CelebrateSync may request sufficient information to establish what information is inaccurate and what correction is being requested. Where CelebrateSync obtained the information from an Event Organizer or another controller, CelebrateSync may coordinate the correction with that party rather than independently changing information that the Organizer or controller is responsible for maintaining. Where appropriate and technically feasible, CelebrateSync may propagate a correction to systems or processors that received the affected information.

29. RIGHT TO OBJECT

A data subject may object to processing where the DPA or other applicable law provides a right to object. The effect of an objection depends upon the lawful basis and purpose of the relevant processing. For example, where personal data is processed solely for promotional communications on a basis that permits objection, CelebrateSync may stop the relevant promotional processing. An objection will not necessarily prevent processing required to provide an Event, maintain Account security, comply with law, establish or defend legal claims, or perform another lawful and necessary activity.

30. RIGHT TO WITHDRAW CONSENT

Where CelebrateSync processes personal data on the basis of consent, the data subject may withdraw that consent, subject to applicable law. Withdrawal will not invalidate processing that occurred before the withdrawal and will not necessarily require processing to stop where another lawful basis applies. If withdrawal of consent means that a particular optional feature can no longer be provided, CelebrateSync may explain that consequence to the User.

31. RIGHT TO ERASURE OR BLOCKING

A data subject may request deletion, destruction, or blocking of personal data where the statutory conditions for such a request are satisfied. CelebrateSync will assess the request in light of the purpose for which the information is processed and any applicable legal or operational retention requirement. Deletion may be declined or delayed where information must lawfully be retained for legal compliance, regulatory purposes, security investigations, fraud prevention, dispute resolution, contractual records, legal claims, or other lawful preservation purposes. Where deletion is appropriate, CelebrateSync may delete the information from active systems and apply the applicable deletion process to other systems in accordance with its technical architecture and retention procedures.

32. RIGHT TO DATA PORTABILITY

Where applicable under Philippine law, a data subject may request personal data in a structured, commonly used, and machine-readable format and may request transmission of that information to another entity where the statutory requirements are satisfied. The right to portability does not require CelebrateSync to disclose information concerning other individuals or proprietary information belonging to CelebrateSync or another party. The manner and format of a portability response may depend upon technical feasibility and the nature of the relevant data.

33. RIGHT TO DAMAGES

Nothing in this Policy limits any right of a data subject to seek damages or other remedies provided under the DPA or applicable law. Where a data subject suffers damage because of unlawful processing, inaccurate information, unauthorized use, or another actionable violation, the person may pursue remedies available under Philippine law.

34. RIGHT TO FILE A COMPLAINT

A data subject who believes that CelebrateSync has improperly processed personal data may first contact CelebrateSync so that the concern can be investigated and, where appropriate, resolved. A complaint may concern unauthorized processing, excessive collection, unauthorized disclosure, inaccurate personal information, refusal to honor an applicable privacy right, inappropriate Event-data access, security incidents, consent, direct marketing, supplier information, or another privacy-related concern. Nothing in this Policy prevents a data subject from filing a complaint with the National Privacy Commission or seeking relief from another competent governmental, regulatory, judicial, or administrative authority.

35. SUBMITTING A DATA RIGHTS REQUEST

A data-subject request should ordinarily be submitted through privacy@celebratesync.app or through another privacy-request mechanism made available by CelebrateSync. The request should identify the person making the request, provide a reliable means of communication, identify the Account or Event concerned where applicable, describe the right being exercised, and explain the requested action with sufficient detail to allow CelebrateSync to locate and assess the relevant information.

A requester should not submit unnecessary sensitive personal information merely to initiate a request. CelebrateSync may ask for additional information where reasonably necessary to verify identity, authority, or the scope of the request.

36. IDENTITY AND AUTHORITY VERIFICATION

Privacy rights must not become a mechanism through which one person obtains or changes another person's personal data. CelebrateSync may therefore undertake reasonable identity-verification measures before providing personal data, changing information, deleting information, or otherwise acting on a request. Verification may include authentication through an existing Account, confirmation through a registered email address, confirmation through another established communication channel, or reasonable documentation demonstrating identity or authority. Where a representative makes the request, CelebrateSync may require evidence that the representative is authorized to act on behalf of the data subject. The verification process will be proportionate to the sensitivity of the requested information and the risk associated with unauthorized disclosure.

37. REQUESTS MADE BY REPRESENTATIVES

A data subject may exercise rights through an authorized representative where permitted by law. CelebrateSync may request evidence of the representative's identity and authority before acting on the request. Where the representative is a parent, guardian, legal representative, heir, or other person exercising rights under a legally recognized authority, appropriate supporting documentation may be required.

38. REQUESTS CONCERNING EVENT DATA

Where an Event Organizer is the controller of Event Data, CelebrateSync may not have independent authority to determine whether the information should be deleted, changed, disclosed, or otherwise processed. In such circumstances, CelebrateSync may verify the identity of the requester and then coordinate with the applicable Event Organizer or other controller. CelebrateSync may implement the Organizer's lawful instructions, subject to its contractual obligations and applicable law, and may provide reasonable assistance necessary to enable the controller to respond to the data subject. A request to delete a CelebrateSync Account therefore does not automatically require deletion of all Event Data maintained for an Event where that Event Data is controlled independently by an Event Organizer.

39. REQUESTS INVOLVING OTHER PEOPLE'S DATA

A person exercising a privacy right concerning his or her own personal data is not automatically entitled to receive personal data concerning other individuals. Where a requested record contains information relating to multiple people, CelebrateSync may redact, anonymize, restrict, or otherwise protect information concerning other persons before responding. CelebrateSync may also decline disclosure where separating the information would not reasonably protect the other individual's rights or where another legal exception applies.

40. SECURITY AND ACCOUNT-COMPROMISE REQUESTS

Requests involving compromised Accounts, stolen credentials, unauthorized access, duplicated QR passes, suspicious Event access, unauthorized profile changes, or suspected disclosure of personal information may be treated as security incidents rather than ordinary data-access requests. CelebrateSync may take immediate protective measures, including temporarily restricting access, invalidating credentials, requiring additional verification, preserving relevant logs, investigating activity, or notifying affected parties where required.

41. HANDLING OF PRIVACY REQUESTS

Upon receipt of a request, CelebrateSync will determine the nature and scope of the request, verify the identity or authority of the requester where appropriate, determine whether CelebrateSync is acting as PIC or PIP in relation to the relevant information, identify any applicable legal or contractual limitations, and coordinate with another controller where necessary. CelebrateSync will endeavor to respond within the periods required by applicable law and, where no specific statutory period applies, within a reasonable period appropriate to the nature and complexity of the request. Where additional time or information is reasonably required, CelebrateSync may communicate the reason and any additional information necessary to process the request. Where a request is denied in whole or in part, CelebrateSync will provide an explanation where required by law.

42. PRIVACY REQUEST RECORDS

CelebrateSync may maintain records of privacy requests, communications, identity-verification steps, decisions, actions taken, and relevant correspondence. Such records may be necessary to demonstrate accountability, investigate complaints, comply with regulatory requirements, defend legal claims, monitor privacy performance, and improve the data-rights process. Privacy-request records will themselves be subject to appropriate access restrictions, security controls, and retention requirements.

43. DATA PROTECTION OFFICER

CelebrateSync will designate a Data Protection Officer (“DPO”) or other responsible privacy representative where required by applicable law. The DPO or designated privacy representative will oversee or coordinate the organization's privacy compliance activities, including privacy inquiries, data-subject requests, privacy assessments, security incidents, privacy policies, processor arrangements, employee awareness, and regulatory coordination. The current privacy contact is:

Data Protection Officer / Privacy Contact: Mark Baldus

Position: Operator

Email: privacy@celebratesync.app

Business Address: 14 Gregorio St., Barangay Mariano Espeleta II, Imus City, Cavite 4103, Philippines

Where CelebrateSync transitions from its present sole proprietorship structure to a corporation, one-person corporation, or another legal entity, the identity and contact details of the applicable PIC and DPO may be updated through a revised Privacy Notice.

44. PRIVACY IMPACT ASSESSMENTS

CelebrateSync may conduct Privacy Impact Assessments (“PIAs”) for processing activities that present heightened privacy risks. A PIA may examine the personal data involved, the purpose of processing, lawful basis, data flows, recipients, retention, security measures, risks to data subjects, processor relationships, cross-border transfers, and available mitigation measures. PIAs may be particularly appropriate before introducing functionality involving sensitive personal information, minors, location information, large-scale Event data, new forms of profiling, artificial intelligence, biometric information, or other processing presenting elevated privacy risks.

45. PROCESSOR OVERSIGHT

Where CelebrateSync engages a third party to process personal data on its behalf, CelebrateSync will seek to ensure that the processor is subject to appropriate contractual and operational safeguards. Processors may be required to process personal data only for authorized purposes, maintain confidentiality, apply appropriate security controls, restrict access, assist with data-subject rights and security incidents where applicable, maintain appropriate records, and return or delete information when required. CelebrateSync may conduct reasonable due diligence concerning the privacy and security practices of processors where appropriate to the nature and risk of the processing.

46. DATA SHARING AND DATA-SHARING ARRANGEMENTS

Where CelebrateSync shares personal data with another independent Personal Information Controller, the parties will seek to establish an appropriate legal basis and, where required, a data-sharing agreement or other appropriate arrangement. The applicable arrangement may address the purpose of sharing, categories of data, responsibilities of each party, permitted uses, security requirements, retention, data-subject rights, incident management, and other applicable requirements.

47. ACCOUNT DELETION AND PRIVACY

Where an Account-deletion functionality is available, Users may request deletion of their Account through the applicable feature. Account deletion does not necessarily require immediate deletion of every record associated with the Account. Certain information may need to remain available to comply with law, establish or defend legal claims, prevent fraud, investigate security incidents, maintain contractual records, resolve disputes, or satisfy other legitimate preservation requirements. Similarly, deletion of an Account does not automatically delete Event Data controlled by an Event Organizer, because that Event Data may be processed independently of the User's personal Account. Where deletion is appropriate, CelebrateSync will apply its applicable deletion and retention procedures.

48. PUBLIC CONTENT AND PRIVACY RIGHTS

The exercise of a privacy right concerning publicly accessible information may require consideration of the rights and interests of other persons. For example, deleting a supplier profile may affect information supplied by a business, reviews submitted by other Users, or records required for the integrity of the Public Trust system. CelebrateSync will therefore assess deletion, correction, restriction, or objection requests in context rather than automatically removing all information whenever a request is received. Where appropriate, CelebrateSync may correct information, restrict visibility, remove identifying information, anonymize information, annotate a disputed record, or take another proportionate measure.

49. LEGAL AND REGULATORY REQUESTS

CelebrateSync may disclose personal data where required or authorized by law, including in response to a subpoena, warrant, court order, lawful government request, regulatory request, or other legally enforceable process. Where legally permitted and reasonably appropriate, CelebrateSync may notify the affected person of the request before disclosure. CelebrateSync may also preserve information where reasonably necessary to comply with a legal preservation obligation or to protect its lawful rights.

50. LEGAL HOLDS

Where litigation, regulatory proceedings, investigations, or another legal matter is reasonably anticipated or ongoing, CelebrateSync may place relevant information under a legal hold. Information subject to a legal hold may not be deleted even where the ordinary retention period has expired. The hold will remain in effect for as long as reasonably necessary to satisfy the applicable legal or evidentiary requirement.

51. PRIVACY COMPLAINTS AND INTERNAL REDRESS

CelebrateSync encourages individuals to raise privacy concerns directly through the designated Privacy Contact before pursuing external remedies, where doing so is appropriate. Upon receiving a complaint, CelebrateSync may review the relevant records, determine the applicable processing role, consult the Event Organizer or another controller where necessary, investigate relevant systems, and determine whether corrective action is appropriate. Corrective measures may include correcting information, restricting access, removing information, modifying permissions, deleting information where appropriate, strengthening security controls, retraining personnel, reviewing a processor relationship, or implementing another appropriate measure.

52. NO ABSOLUTE RIGHT TO DELETION OR ACCESS

The rights described in this Policy are subject to the limitations and exceptions established by Philippine law. Accordingly, CelebrateSync does not represent that every request for access, correction, objection, portability, deletion, or restriction will necessarily result in the requested action. A request may be limited where necessary to protect another person's privacy, preserve confidential information, maintain security, comply with law, establish or defend legal claims, prevent fraud, preserve evidence, or satisfy another lawful obligation. Where CelebrateSync cannot comply fully with a request, it will endeavor to explain the applicable limitation where required.

53. PRIVACY BY DESIGN

CelebrateSync intends to incorporate privacy considerations into the design and development of its Services. Where appropriate, product development may consider data minimization, privacy-friendly defaults, role-based access, retention controls, deletion mechanisms, consent requirements, privacy impact assessments, security testing, processor assessments, logging, and other measures designed to reduce unnecessary privacy risks. The introduction of a new feature that materially changes the nature or scope of personal-data processing may result in an updated Privacy Notice, additional feature-specific disclosure, or separate consent request where legally required.

54. CHANGES TO THIS POLICY

CelebrateSync may revise this Privacy Notice and Data Rights Policy from time to time.

Changes may reflect new Services, changes in the way the platform operates, changes in technology, new processors, changes in law or regulatory requirements, security improvements, organizational changes, or other legitimate developments. The version date and effective date will be updated whenever a new version is issued. Where a change materially affects the rights or expectations of active Users and additional notice or consent is required by law, CelebrateSync will provide the appropriate notice or obtain the applicable consent. CelebrateSync will not use an amendment to this Policy to retroactively authorize processing that was unlawful when undertaken.

55. TRANSITION TO A SUCCESSOR ENTITY

CelebrateSync may transition from its current sole proprietorship structure to a corporation, one-person corporation, or other successor entity. Where such a transition occurs, personal data may be transferred to the successor entity to the extent reasonably necessary to continue operating the Services, fulfill contractual obligations, maintain legitimate business records, preserve security, comply with law, and otherwise continue the relevant business. Any successor entity will remain subject to applicable data-protection obligations. Where required, CelebrateSync will provide an updated privacy notice identifying the successor entity and relevant changes in data-controller information.

56. GOVERNING LAW

This Privacy Notice and Data Rights Policy shall be governed by and construed in accordance with the laws of the Republic of the Philippines, without prejudice to mandatory statutory rights and remedies available to data subjects under applicable law. Nothing in this Policy shall be interpreted as waiving any right that cannot legally be waived.

57. CONTACT INFORMATION

For privacy inquiries, data-subject requests, complaints, security concerns involving personal data, or other matters concerning the processing of personal data, the following channels may be used: DIGITALFRAMEWORK I.T. SOLUTIONS CelebrateSync / HostHaven Data Protection Officer / Privacy Contact: Mark Baldus

Privacy: privacy@celebratesync.app Legal: legal@celebratesync.app Support: support@celebratesync.app Abuse / Safety Reports: reportabuse@celebratesync.app

Business Address: 14 Gregorio St., Barangay Mariano Espeleta II, Imus City, Cavite 4103, Philippines

In-application reporting or privacy-request mechanisms may also be provided for particular features.

58. USER ACKNOWLEDGMENT

Before accessing a feature for which acknowledgment of this Privacy Notice is appropriate, CelebrateSync may present the following:

[ ] I acknowledge that I have read and understood the CelebrateSync Privacy Notice and Data Rights Policy.

This acknowledgment confirms that the User has been provided reasonable access to the Privacy Notice. It should not be interpreted as blanket consent to all processing activities. Where separate consent is legally required, CelebrateSync will present a separate consent mechanism identifying the specific purpose, category of personal data, nature of processing, and other information required by applicable law. The consent mechanism should not be pre-selected, and the User should be able to refuse optional processing without being denied unrelated functionality where such processing is not necessary for the requested Service.

59. SEPARATE CONSENT FOR OPTIONAL PROCESSING

Where appropriate, CelebrateSync may request separate consent for optional processing, including optional marketing communications, optional location functionality, optional access to media or device functions, promotional use of photographs or videos, processing of sensitive personal information for optional purposes, profiling, personalized recommendations, or other processing activities requiring specific consent.

The relevant consent request should explain the purpose and nature of the processing sufficiently for the User to make an informed decision. Withdrawal of consent should be reasonably accessible and should not require the User to withdraw consent to unrelated processing.

60. RELATIONSHIP WITH THE TERMS OF SERVICE

This Privacy Notice and Data Rights Policy forms part of the legal framework governing the CelebrateSync Services. The Terms of Service govern the contractual relationship between CelebrateSync and Users concerning access to and use of the Services. This Privacy Notice and Data Rights Policy governs the processing of personal data by CelebrateSync and explains the rights and procedures applicable to data subjects. Feature-specific privacy notices, Event-specific notices, Media Terms, consent forms, application permission disclosures, and other privacy-related documents may supplement this Policy where a particular feature requires additional information. If a provision of this Policy conflicts with a mandatory requirement of Philippine data-protection law, the mandatory legal requirement shall prevail.

61. VERSION CONTROL

Policy: CelebrateSync Privacy Notice and Data Rights Policy Version: 3.0 Version Date: September 16, 2026 Effective Date: September 16, 2026

Previous versions of this Privacy Notice may be maintained for accountability, audit, regulatory, contractual, and legal purposes.

62. Launch Feature Status and Privacy Scope

The privacy disclosures in this Privacy Notice are intended to correspond to the Services, features, and processing activities actually enabled by CelebrateSync at the relevant time.

Certain features may be under development, disabled, limited to internal testing, subject to pilot release, or gated pending additional legal, technical, operational, or app-store review. These may include, without limitation, public reviews and ratings, supplier payouts, marketplace checkout, targeted advertising, facial-recognition functionality, AI-based decisioning, paid purchase of Spark Points, public minor media, cross-border expansion, and other higher-risk features.

The inclusion of a feature category in this Privacy Notice does not necessarily mean that the feature is active for all Users, all Events, all territories, or all account types. Where a disabled, gated, or pilot feature becomes active and materially changes the nature or scope of personal-data processing, CelebrateSync will update the applicable Privacy Notice, feature disclosure, consent mechanism, subprocessor register, retention schedule, app-store disclosure, or other relevant document before or at the time required by applicable law.

63. Platform Fees and Billing Data

Where CelebrateSync or HostHaven charges platform fees, event activation fees, app upgrades, subscriptions, storage upgrades, media-processing allowances, internal digital-tool fees, or other fees for access to the Operator’s own digital services, CelebrateSync may process personal data and transactional information necessary to administer those charges.

Such information may include billing contact details, invoice details, product or plan selected, platform-fee status, entitlement records, subscription or renewal status, app-store purchase identifiers, payment confirmation records, refund or cancellation records, tax or receipt information, fraud-prevention records, support communications, and related accounting or compliance records.

Payment processing may be handled by third-party payment processors, app stores, banks, payment gateways, or other payment-service providers. CelebrateSync does not intend to store full payment-card details unless expressly disclosed and lawfully implemented. Billing and payment-related personal data may be retained where reasonably necessary for accounting, tax, audit, dispute, chargeback, fraud-prevention, legal, regulatory, or customer-support purposes.

64. Supplier Settlement Exclusion

At initial launch, CelebrateSync and HostHaven do not process supplier settlement funds and do not act as escrow provider, payment intermediary, merchant of record for supplier services, payout provider, trustee, custodian, or guarantor of supplier payment or supplier performance.

Where an Organizer records supplier balances, deposits, due amounts, payment notes, invoice notes, or similar information in HostHaven, such records are Organizer-entered Event Data used for operational tracking. Unless the applicable feature expressly states otherwise under separately approved terms, such records do not mean that CelebrateSync has verified, received, held, released, guaranteed, or settled any supplier payment.

If CelebrateSync later enables marketplace checkout, supplier payouts, escrow-like functionality, split settlement, supplier deposits, commissions, or related payment features, additional payment, privacy, consumer, tax, refund, settlement, dispute, and provider-specific disclosures may be required before activation.

65. App Permission Purpose Details

The CelebrateSync mobile application may request access to device permissions only where the relevant feature reasonably requires such access and the User grants the permission through the applicable operating-system or application control.

Camera access may be used for QR scanning, profile capture, event-media capture, or similar camera-based features where enabled. Photo or media-library access may be used for uploading event photographs, videos, memories, profile images, gallery materials, or other media selected by the User. Notification permission may be used for account alerts, Event updates, RSVP reminders, security notices, operational messages, role cues, guest instructions, and similar notices. Location permission may be used only where a live feature reasonably requires location information, such as directions, proximity-based functionality, venue assistance, or other location-dependent services.

Contacts, calendar, microphone, broad media-library access, background location, or other higher-sensitivity permissions should not be requested unless tied to a live, reviewed feature with an accurate purpose string and appropriate user-facing disclosure. A User may refuse or revoke permissions through device settings, subject to the limitations of the operating system and the functionality requested.

66. Account Deletion and Store Compliance Data

Where a User creates an Account, CelebrateSync should provide an in-application account-deletion path where required by applicable app-store rules, and may also provide a web-based or support-assisted deletion route.

Account deletion may involve processing deletion-request records, including request timestamp, account identifier, verification status, communication records, action taken, completion status, residual retention basis, and related audit information. Such records may be retained where reasonably necessary to demonstrate compliance, prevent fraud, resolve disputes, respond to complaints, or satisfy legal obligations.

Account deletion does not necessarily result in immediate deletion of all records associated with the User. Certain information may be retained where required or permitted by law, including organizer-controlled Event Data, legal holds, security logs, abuse reports, child-safety records, billing records, transaction records, privacy-request records, backup data, dispute records, and information needed to protect the rights of other persons.

67. First Invitation and Guest Notice

Where an Event Organizer uploads, enters, imports, or otherwise provides guest information before the guest registers for CelebrateSync, the first invitation, RSVP page, QR pass page, or Event-access screen should provide a concise privacy notice appropriate to the context.

That notice should inform the guest that the Organizer supplied or authorized the use of the guest’s information for Event-related purposes, identify or describe the Organizer as the party responsible for the Event where applicable, explain that CelebrateSync operates the platform used to provide the Event functionality, link to this Privacy Notice, and provide a reasonable contact route for privacy questions or data-rights requests.

This first-layer notice is intended to avoid relying solely on a full Privacy Notice after the guest’s information has already been received, while still allowing the detailed Privacy Notice to provide the complete explanation of processing activities, roles, rights, retention, and contacts.

Sample First-Layer Guest Notice

Your name and contact details may have been provided by the Event Organizer so you can receive this invitation, RSVP, access event information, receive event updates, or use event-related features. CelebrateSync operates the technology platform used for this Event. The Event Organizer is responsible for the Event and may determine what guest information is needed for Event purposes. Please review the CelebrateSync Privacy Notice for more information about how personal data is processed and how you may exercise your privacy rights.

68. Role-Based Access and Audit Data

CelebrateSync may process role-assignment records, access grants, workspace permissions, role acceptance records, invitation logs, QR scan logs, Event lookups, staff activity, supplier access activity, media-operator activity, security and parking status, host or show-control actions, client approval actions, revocation logs, and other Event-access or audit data.

Such records may be processed to provide Event functionality, enforce role-based access, maintain least-privilege controls, support guest and Event security, investigate misuse, resolve disputes, verify attendance or access events, maintain accountability, respond to privacy or security incidents, and comply with legal or contractual obligations.

Access to role-based audit data should be limited to persons who have a legitimate need for the information, such as the Operator, authorized support personnel, the relevant Organizer, or other authorized role-holders, subject to applicable law and platform controls.

69. Sensitive Event Notes Minimization

Certain Event-related fields may reveal sensitive personal information or privacy-sensitive circumstances. These may include allergies, accessibility needs, mobility limitations, disability-related information, religious observance, dietary restrictions that reveal health or religion, incident reports, VIP or security notes, parking or accessibility notes, medical context, minor information, or other information requiring heightened care.

CelebrateSync and Organizers should apply data-minimization principles to such information. Sensitive Event notes should be collected only where necessary for a legitimate Event purpose, should be limited to what is relevant, should avoid unnecessary free-text collection where structured fields are sufficient, and should be visible only to roles that reasonably need the information for the Event.

Organizers remain responsible for determining whether such information is necessary to collect and for ensuring that appropriate notices, lawful basis, consents, access limits, and safeguards are in place where required.

70. Media Metadata, EXIF, and Location in Photos

Photographs, videos, and other media uploaded to the Services may contain metadata, including timestamps, device information, file properties, embedded location information, camera settings, or other EXIF or technical data.

CelebrateSync may process media metadata where reasonably necessary to provide gallery functionality, organize media, support upload and display, troubleshoot technical issues, investigate misuse, respond to privacy or copyright complaints, maintain security, or comply with legal obligations.

CelebrateSync should determine, according to the feature and technical implementation, whether metadata is retained, stripped, transformed, hidden, displayed, indexed, or used for moderation or security purposes. Private Event media should not expose unnecessary metadata to guests, suppliers, public viewers, or unauthorized persons. Where metadata handling materially affects privacy expectations, the applicable feature should provide appropriate notice or controls.

71. Public Reviews and Reviewer Privacy

Where public reviews, ratings, supplier responses, or Public Trust features are enabled, CelebrateSync may process review-related information, including reviewer account identifiers, display names, chosen anonymity or display settings, Event or supplier relationship, rating, review text, media attachments, moderation status, report history, supplier responses, dispute evidence, integrity signals, and related audit records.

Reviewer identity should be handled according to the published display setting and applicable Review Guidelines. CelebrateSync should not disclose a reviewer’s private identity to a supplier beyond what is publicly displayed unless disclosure is required by law, necessary for a lawful dispute process, necessary to protect rights or safety, or otherwise legally permitted.

Review-related processing may be used to determine eligibility, prevent fake or manipulated reviews, detect conflicts of interest, investigate abuse, support supplier responses, enforce Review Guidelines, respond to legal requests, and maintain the integrity of the Public Trust system.

72. Child-Safety and Urgent Report Records

Reports involving minors, OSAEC/CSAEM, grooming, trafficking, sexualized minor content, child-safety risks, or non-consensual intimate media may require urgent restriction, preservation, internal escalation, documentation, and reporting.

CelebrateSync may process, retain, preserve, restrict, disclose, or otherwise handle relevant account data, traffic data, content data, report data, communications, logs, media, identifiers, and related evidence where required or permitted by law, where necessary to protect a child or another person, where necessary to investigate or respond to suspected unlawful conduct, or where required by a lawful request from a competent authority.

The Operator may be unable to notify a User or affected person about certain preservation, disclosure, restriction, or reporting actions where notice is prohibited, confidential, unsafe, or likely to compromise an investigation, child-safety response, or legal obligation.

73. Spark Points Data

Where Spark Points or similar engagement points are enabled, CelebrateSync may process information necessary to administer the program, including point balances, earning activity, eligible tasks, redemption or usage history, expiration, reversal, adjustment, anti-abuse signals, feature entitlements, account status, support disputes, and related audit records.

Spark Points data does not represent cash, stored value, electronic money, supplier credit, deposit, payout, marketplace balance, or external reward entitlement. Spark Points may not be redeemed for cash or used for supplier payments unless a separately reviewed and lawfully implemented feature expressly provides otherwise.

CelebrateSync may restrict, reverse, expire, suspend, or disable Spark Points where reasonably necessary to address fraud, abuse, technical error, legal risk, program changes, account restrictions, or other legitimate operational reasons. Spark Points may be disabled or limited for minors or accounts presenting elevated abuse, safety, or legal risk.

74. AI and Third-Party Suggestion Providers

Where CelebrateSync enables AI-assisted gift ideas, planning prompts, summaries, recommendations, drafting tools, classification tools, or similar functionality, CelebrateSync may process the personal data reasonably necessary to provide the requested feature.

If such functionality involves a third-party AI or suggestion provider, CelebrateSync should disclose, before or at the time required by law, the categories of data shared, the purpose of sharing, the relevant provider or category of provider, applicable retention behavior where known, whether the provider uses submitted data for training or improvement, and any available user controls.

AI-based decisioning, facial recognition, biometric identification, automated supplier scoring that materially affects visibility or eligibility, child-safety determinations without appropriate review, legal decisions, financial decisions, medical decisions, and other legally or similarly significant automated decisions remain disabled unless separately reviewed, disclosed, and implemented with appropriate safeguards.

75. AdMob, Affiliate, Analytics, and Tracking Distinctions

CelebrateSync may use different technologies for different purposes, including operational analytics, crash diagnostics, performance monitoring, security logging, non-personalized advertising, contextual advertising, affiliate links, sponsored listings, and other promotional or measurement features.

CelebrateSync should distinguish these activities from targeted advertising, behavioral advertising, cross-platform retargeting, lookalike audiences, event-data advertising, guest-list advertising, and advertising based on minors or sensitive Event Data. At launch, targeted advertising and cross-platform retargeting remain disabled unless separately reviewed and implemented with appropriate privacy, consent, app-store, platform, and regional controls.

If AdMob or another advertising SDK is enabled, the relevant app-store privacy nutrition labels, data-safety answers, ATT or tracking settings where applicable, consent flows, SDK configuration, and this Privacy Notice must match the actual technical implementation.

76. Subprocessor Register Publication

CelebrateSync will maintain a Subprocessor Register before production launch of any feature that relies on active third-party processors handling personal data.

The register should identify, where reasonably available, the provider name, purpose, category of processing, categories of data involved, processing location or region, status of the provider, and any relevant public reference or contact information. Provider rows should distinguish active, inactive, gated, planned, test-only, or future providers so that CelebrateSync does not overstate the use of services that are not yet active.

The Subprocessor Register may be made publicly available, made available upon request, or maintained in another form appropriate to the nature of the Services and applicable law. Material changes to active subprocessors may require notice, update, or review according to the applicable agreement, law, or policy.

77. Retention Schedule Incorporation

This Privacy Notice should be read together with CelebrateSync’s Retention Schedule, which provides category-specific retention guidance for different types of records and processing activities.

General retention wording in this Privacy Notice explains the governing principles, but operational execution may require more specific retention periods or event-based retention triggers. The Retention Schedule should address, where applicable, account records, Event Data, guest records, media, QR and check-in logs, support records, billing records, security logs, privacy requests, moderation records, supplier profiles, reviews, Spark Points, analytics, backups, legal holds, child-safety preservation, cybercrime preservation, accounting and tax retention, and other relevant categories.

Where this Privacy Notice and the Retention Schedule appear to differ, the more specific lawful retention rule or the applicable legal requirement should govern, subject to counsel review and applicable law.

78. ROPA and PIA Commitments

CelebrateSync may maintain Records of Processing Activities or similar internal accountability records for material processing activities involving account data, Event data, guest data, media, supplier data, public reviews, support, billing, analytics, security, Spark Points, app-store disclosures, and other material processing activities.

CelebrateSync may also conduct or update Privacy Impact Assessments for processing activities that present heightened privacy risks. Such activities may include processing involving minors, Event media, sensitive Event data, public reviews, supplier trust features, legal holds, cross-border processing, rewarded ads if enabled, AI suggestions if enabled, location features, new analytics tools, or other features involving elevated privacy or security risk.

ROPA and PIA records are primarily internal accountability documents and may not be publicly disclosed in full where doing so would reveal confidential, security-sensitive, proprietary, or personal information. CelebrateSync may, however, describe its privacy-governance practices in public-facing policies where appropriate.

79. Regional Availability and International Users

CelebrateSync is currently designed as a Philippines-first platform. Users, Events, suppliers, app-store visitors, website visitors, or public-page viewers outside the Philippines may nevertheless access certain parts of the Services depending on technical availability, app-store territory settings, website accessibility, invitation links, search visibility, or other circumstances.

CelebrateSync does not represent that the Services are fully localized, legally reviewed, or compliant for every jurisdiction unless expressly stated in an applicable regional notice or agreement. If CelebrateSync expands materially outside the Philippines, additional regional privacy notices, transfer disclosures, age-signal controls, consumer disclosures, data-rights mechanisms, representative arrangements, tax or payment notices, app-store configurations, or other legal and operational mechanisms may be required.

Territory availability is therefore both a product-configuration matter and a legal-compliance matter. Product availability, app-store country settings, website access, supplier pages, and legal disclosures should remain aligned.

80. Versioning, Consent, and Evidence

CelebrateSync may maintain records showing the version of the Terms of Service, Privacy Notice, addenda, disclosures, consent forms, and other applicable policies presented to or accepted by a User.

Such records may include the policy version, effective date, date and time of presentation or acceptance, User identifier, Account identifier, Event context, role, device or session information where appropriate, method of acceptance, optional consent selections, withdrawal records, material-change notices, renewed acceptance records, and related audit information.

These records may be processed to demonstrate privacy accountability, confirm contractual or consent history, support app-store review, investigate disputes, respond to privacy inquiries, enforce applicable terms, comply with legal obligations, and maintain the integrity of the Services. Consent and acceptance evidence should be retained according to the Retention Schedule and applicable law.