Effective Date: September 09, 2025

This Privacy Policy explains how we collect, use, disclose, retain, and protect your personal data when you use BookaDerma Marketplace (the “Site”) and related services. The Site is operated by Yagya Labs Inc. in the Philippines (registered office at P. Burgos St, San Fernando City, 2500 La Union, Philippines). For privacy questions or to exercise data rights, contact our DPO at privacy@bookaderma.com. For order and delivery support, email support@bookaderma.com. This Policy aligns with the Data Privacy Act of 2012 (RA 10173) and NPC issuances, plus RA 8792 (E‑Commerce) and RA 7394 (Consumer Act).

1) Data We Collect

Account & Identity; Order & Payment (tokens/last 4 digits only); Prescription data (if Rx purchase); Support communications; Device/Usage data; Optional marketing preferences.

2) Purposes & Legal Bases

Contract (fulfillment, payments, support).

Legitimate interests (fraud/security, service analytics/UX, policy enforcement, legal claims; direct marketing of similar products—opt out anytime).

Legal obligations (records, tax/audit, recalls/safety communications, compliance with regulators).

Consent (non‑essential cookies/SDKs, marketing beyond similar products, prescription uploads where consent is appropriate).

3) How We Use Data

Provide and secure the Services; route orders to licensed Sellers; validate prescriptions; enable shipping/tracking; deliver support; personalize (where permitted); prevent fraud; comply with law including recalls.

4) Sharing

Sellers (licensed pharmacies/merchants) receive only the data needed to fulfill/dispense orders (and Rx verification data if applicable) and act as independent controllers/processors under RA 10173.

Processors: payments, fraud tools, hosting/CDN, couriers, email/SMS, analytics, support vendors—under contracts with confidentiality/security.

Authorities/legal; and in corporate transactions with safeguards. We do not sell personal data.

5) International Transfers

Some providers process data outside the Philippines; we implement safeguards (contractual clauses, security due‑diligence).

6) Retention

Account/profile: while active + up to 5 years after last activity (or longer if required).

Orders/invoices/tax: 5–10 years.

Rx verification logs: typically 2–5 years (or per law).

Support: 3 years. Marketing consent logs: 2 years post opt‑out. Security logs: 6–24 months.

Deletion/anonymization when no longer necessary.

7) Your Rights

Access, correction, deletion (where applicable), objection/restriction, portability (where feasible), and withdrawal of consent; complaint to the NPC.

How to exercise: email privacy@bookaderma.com; we may request identification and details to locate your data.

8) Security

Organizational/physical/technical safeguards (access controls, encryption in transit, RBAC, hardened cloud, secure SDLC, vendor due‑diligence). We will assess incidents and notify NPC/affected individuals when required.

9) Cookies & Similar Technologies

We use cookies/SDKs for essential operations and—if you consent—analytics/advertising/personalization.

Types: Essential (always on), Analytics (consent), Advertising (consent), Functional (consent).

Choices: Accept all / Reject non‑essential / Manage preferences via banner and “Cookie Settings”; change anytime.

Legal bases: essential = legitimate interests; others = consent. Some third parties (analytics/ad partners) place cookies; see Cookie Notice for vendors/purposes/durations.

Withdrawal/browser controls: withdraw via Cookie Settings; browser/device controls available; blocking essentials may break features.

10) Marketing

Service messages are required. Marketing is sent only under legitimate interests or consent; opt out anytime.

11) Third‑Party Links; 12) Children

Third‑party sites/apps are governed by their own policies; review them before sharing data.

Services are for adults (18+). If we learn a minor’s data was collected, we will delete it unless retention is legally required.

13) Changes to this Policy

Updates take effect upon posting with a new Effective Date; material updates will be highlighted in‑Site.

14) Contact

Yagya Labs Inc. (BookaDerma Marketplace) — Registered office: P. Burgos St, San Fernando City, 2500 La Union, Philippines

Privacy/DPO: privacy@bookaderma.com    Support: support@bookaderma.com