- Effective date
- July 28, 2026
- Last updated
- July 28, 2026
- Document version
- 2026-07-28
- Provided by
- Lifes Awesome Ventures Inc.
This Privacy Policy explains how Lifes Awesome Ventures Inc., provider of Prospeno (“Prospeno,” “we,” “us,” or “our”), collects, uses, stores, shares, and protects personal information in connection with Prospeno’s websites, web application, mobile applications, kiosk features, support channels, and related services (collectively, the “Service”).
Our business address is Balulang, Cagayan de Oro City 9000, Misamis Oriental, Philippines.
This Policy should be read together with the Prospeno Terms and Conditions.
1. Scope
This Policy applies to personal information processed through the Service, including information relating to public-site visitors, Company registrants and Admins, Authorized Users, employees, supervisors, managers, clients, suppliers, support contacts, and users of optional mobile, attendance, kiosk, quotation, billing, wallet, or future AI features.
A Company may have its own privacy notice and workplace policies. Those notices may also apply to information the Company collects and manages through Prospeno.
2. Our role and the Company’s role
Our role depends on the information and processing purpose.
Lifes Awesome Ventures Inc. may act as a Personal Information Controller for information used to register and administer accounts, manage subscriptions and billing, secure the platform, provide support, maintain legal-acceptance records, operate public websites, and meet our own legal obligations.
For Company-managed employee, project, attendance, expense, receipt, quotation, client, supplier, and operational data, we may act as a Personal Information Processor or service provider under the Company’s instructions.
The Company generally determines which users are added, their roles, what records are entered, whether optional attendance controls such as selfies or geofencing are enabled, how Company records are used, and how data-subject requests concerning Company-controlled records are handled.
Companies are responsible for appropriate notices, lawful basis, user administration, and lawful instructions.
3. Information we collect
The information collected depends on enabled features and use.
3.1 Account and Company information
We may collect names, email addresses, Company name and code, roles, assignments, authentication and verification status, password-reset and security events, account status, legal-policy acceptance records, support details, and preferences.
Passwords are handled through the authentication service and should not be stored by Prospeno in plain text.
3.2 Project and operational information
Companies and users may submit project names, locations, clients, contract values, budgets, schedules, assignments, tasks, notes, evidence, labor rates, work logs, attendance, overtime, timesheets, expenses, receipts, materials, requisitions, costs, fulfillment records, budget releases, liquidation records, quotations, scopes, items, prices, markups, terms, exclusions, warranties, billing, collections, payment references, salary-related records, and other enabled operational records.
Some records may contain personal information about employees, clients, suppliers, or contacts.
3.3 Attendance, field, selfie, and location information
Where enabled, we may process attendance date and time, check-in and checkout status, project or work location, selfie or evidence photograph, optional device location during an attendance action, configured geofence result, kiosk or attendance source, checkout reports, notes, issues, evidence, task updates, work logs, and synchronization status for supported workflows.
Geofencing is optional and configured by the Company. It is intended to verify a specific attendance action, not to continuously track an employee’s location in the background.
Location accuracy depends on the device, permissions, environment, network, and satellite availability.
3.4 Device, technical, security, and usage information
We may collect IP address, browser and device type, operating system, user-agent information, session and authentication events, timestamps, application version, feature interactions, error and diagnostic information, security and abuse-prevention events, upload and synchronization status, legal-acceptance evidence, and identifiers needed to keep local mobile records scoped to the signed-in account.
3.5 Files and images
Users may upload receipts, attendance selfies, task or project evidence, quotation attachments, support documents, and other operational files. Companies and users must have authority to upload them.
3.6 Support and communications
We may process support emails, requests, messages, feedback, survey responses, screenshots, logs, and troubleshooting files.
3.7 Subscription, wallet, and payment information
We may process plan and module subscriptions, wallet balances and transactions, payment references and statuses, billing contact details, invoices, receipts, refunds, reversals, or chargeback information.
Payment providers may process payment credentials directly. We do not claim to store full card or bank credentials when handled by a provider.
3.8 Optional AI information
If optional AI features are released and enabled, we may process prompts, selected quotation or project context, generated output, model and usage metadata, feedback, and audit information. Only context reasonably needed for the requested feature should be sent to the AI provider.
4. How information is collected
We collect information directly from users, from the Company or Company Admin, when users enter or upload records, automatically from browsers and devices, from service providers, through mobile permissions when activated, and through integrations expressly enabled by the Company.
5. Why we process information
We process personal information to register and administer accounts, authenticate users, provide product features, enforce permissions, support attendance and field workflows, calculate and display operational information, process subscriptions and payments, communicate about the Service, respond to support, prevent abuse, maintain legal and security records, comply with law, protect rights, and improve reliability.
Marketing communications are sent only as permitted by law and applicable preferences.
6. Lawful bases
Depending on the context, processing may be based on performance of a contract, steps before a contract, legal obligation, legitimate interests, consent where required, protection of lawful rights, Company instructions where we act as processor, or another basis permitted by law.
Consent is not treated as the basis for every processing activity. Where processing relies on consent, it may be withdrawn subject to lawful processing already performed and consequences explained at the time.
7. Attendance, selfies, and optional geofencing
A Company may use Prospeno for attendance and field evidence.
Depending on configuration, the Service may request camera access for a selfie or evidence, location access during check-in, project or worksite selection, and checkout reporting information.
Geofencing:
- is optional;
- is configured by the Company for selected locations or projects;
- may require a user to be within a configured area to check in;
- is not intended as continuous background tracking; and
- may be disabled by Companies that do not need it.
A user may deny permissions, but a configured Company workflow may then be unavailable. Companies are responsible for notices, lawful basis, and fair handling of attendance disputes.
10. International and cross-border processing
Some providers or infrastructure may process or store information outside the Philippines.
Where this occurs, we use reasonable contractual, organizational, and technical measures appropriate to the information and applicable law.
We do not promise that all data remains exclusively in the Philippines unless expressly stated for a specific arrangement.
11. Data retention
We retain information only as long as reasonably necessary for providing the Service, active Company instructions, backup and recovery, billing, audit, legal acceptance, security, fraud prevention, dispute resolution, enforcement, and legal obligations.
Retention depends on the category and relationship.
When information is deleted from active systems, copies may remain temporarily in backups or logs until normal rotation, unless preservation is required.
Integration connection data
When a Company disconnects an optional integration such as QuickBooks Online or Google Drive, Prospeno deletes active encrypted OAuth credentials and marks the connection as disconnected.
For QuickBooks Online, connection metadata (such as provider, connection status, timestamps, and external account identifiers needed for audit) may be retained for security, troubleshooting, and lawful business records. Saved account-mapping configuration may remain until changed or removed by an authorized administrator, but it cannot be used to access QuickBooks without a new authorized connection.
For Google Drive, Prospeno may retain non-secret connection metadata, project-folder mappings, timestamps, and security audit records according to the general retention principles above, but these records cannot be used to access Google Drive without renewed authorization. Files already stored in the customer’s own Google Drive are not automatically deleted when the integration is disconnected.
Integration audit events may be retained according to the general retention principles above.
Companies should export and retain records they must keep. Account closure does not necessarily require immediate deletion of audit, payment, legal-acceptance, or security records.
12. Security
We use reasonable and appropriate measures designed to protect personal information, including authenticated access, role-based permissions, Company-level data isolation, server-side validation, encrypted network transmission where supported, restricted administrative access, security logging, backups, credential and secret management, and provider safeguards.
No transmission, storage, or security method is perfect. Users and Companies must also maintain secure credentials, devices, and access practices.
We do not claim perfect, “bank-grade,” or “military-grade” security or certifications we have not obtained.
13. Personal data breaches
We maintain procedures to assess and respond to suspected personal data breaches.
Where notification is required by law, we will notify the appropriate regulator and affected persons under the applicable conditions and timeframe.
Companies must promptly notify us of suspected compromise or misuse affecting the Service.
14. Rights of data subjects
Subject to applicable law and exceptions, a person may have rights to be informed, access personal information, object to certain processing, correct inaccurate information, request erasure or blocking where applicable, withdraw consent where processing relies on consent, obtain portability where applicable, lodge a complaint with the National Privacy Commission, and seek damages as provided by law.
Some records are controlled by the Company. An employee request concerning attendance, salary, project assignment, or workplace records may need to be addressed to the employer or Company. We will reasonably assist where we act as processor.
Rights may be limited where processing is required by law, contract, security, or defense of legal claims.
15. Exercising privacy rights
Requests may be sent to support@prospeno.com.
Please describe the request and the account or Company involved. We may verify identity and authority before acting and will avoid requesting more identification than reasonably necessary.
Where the Company controls the information, we may refer or coordinate the request with it.
We will respond according to applicable law, subject to lawful extensions, exceptions, and verification.
16. Marketing communications
Service, billing, account, and security messages are necessary communications and may be sent without marketing consent where permitted.
Marketing communications will be sent only as permitted by law and preferences. Recipients may unsubscribe from promotional email. Unsubscribing does not stop necessary service messages.
Marketing consent is not required to create a Prospeno account.
17. Children
The Service is designed for businesses and workforce operations and is not intentionally directed to children.
Companies must not add or process information about minors unless they have a lawful basis, safeguards, and authority.
If we learn that information was submitted unlawfully concerning a child, we may work with the Company to restrict or delete it as appropriate.
18. Automated calculations and optional AI
Prospeno uses programmed calculations and rules to produce outputs from Company-entered data. These outputs depend on the quality and status of the underlying records and should be reviewed.
If optional AI features are released and enabled, relevant prompts and selected context may be processed by an AI provider; AI output may be inaccurate and is not authoritative; users must review drafts and analyses; usage records may be kept; and Prospeno’s application logic and approved records remain authoritative.
We do not claim that unreleased AI features are active.
19. Changes to this Policy
We may update this Policy to reflect changes in the Service, law, security practices, or processing activities.
For material changes, we will provide reasonable notice and may require acknowledgment or reacceptance. Minor editorial or clarification changes may not require reacceptance.
The effective date and document version identify the current Policy.
20. Contact and complaints
Lifes Awesome Ventures Inc.
Balulang, Cagayan de Oro City 9000
Misamis Oriental, Philippines
Email: support@prospeno.com
You may also lodge a complaint with the National Privacy Commission of the Philippines where applicable.