Privacy Policy
Effective Date: July 17, 2026
Last Updated: July 20, 2026
1. Who We Are
Fullblown Digital is a diagnostic-first digital growth agency serving businesses in the Philippines.
Business name: Fullblown Digital
Website: https://fullblowndigital.com
Email: info@fullblowndigital.com
Business address: Ulha Village, Ulas, Davao City, Philippines
Contact number: 0907-717-7777
For purposes of the Philippine Data Privacy Act of 2012, Fullblown Digital generally acts as the Personal Information Controller for personal data collected directly through this website.
2. Scope of This Privacy Policy
This Privacy Policy explains how Fullblown Digital collects, uses, stores, shares, and protects personal data when you:
- Visit our website;
- Submit an inquiry or contact form;
- Request a Digital Health Check, website audit, social media audit, funnel audit, content audit, or brand assessment;
- Book a consultation or discovery call;
- Subscribe to our updates;
- Leave a comment;
- Download a resource;
- Request a proposal or quotation;
- Become a client, supplier, contractor, or business partner; or
- Communicate with us through email, telephone, social media, or messaging applications.
We process personal data in accordance with applicable Philippine data-protection requirements, including Republic Act No. 10173, also known as the Data Privacy Act of 2012, and its Implementing Rules and Regulations.
3. Personal Data We Collect
The information we collect depends on how you interact with us.
Information You Provide
You may provide us with:
- Your name;
- Email address;
- Mobile or telephone number;
- Business name and industry;
- Job title or role;
- Business address or operating location;
- Website and social media page links;
- Preferred communication channel;
- Information about your marketing challenges, goals, audience, budget, timeline, or project requirements;
- Answers submitted through an audit, assessment, or discovery form;
- Files, screenshots, brand materials, reports, or documents you choose to upload;
- Appointment and consultation details;
- Comments, messages, feedback, or testimonial information;
- Billing and transaction information; and
- Any other information you voluntarily provide.
Please avoid sending passwords, government identification numbers, payment-card details, health records, or other sensitive personal information unless we specifically request them through a secure and appropriate process.
Information Collected Automatically
When you visit our website, our website, hosting provider, security tools, or analytics services may automatically collect:
- Internet Protocol address;
- Browser type and version;
- Device type and operating system;
- Approximate location based on your IP address;
- Referring website or source;
- Pages viewed;
- Links or buttons clicked;
- Date, time, and length of visit;
- Cookie identifiers;
- Website errors and performance information; and
- Security, access, and spam-detection data.
Publicly Available Business Information
When you request an audit or Digital Health Check, we may review information that your business has made publicly available, such as:
- Your website;
- Public social media pages;
- Google Business Profile;
- Online reviews;
- Marketplace listings;
- Public advertisements; and
- Other public-facing digital assets.
We use this information only for legitimate assessment, research, proposal, service-delivery, or business-development purposes.
Public availability does not mean that personal data may be used without appropriate limitations or a valid purpose.
4. How We Use Your Personal Data
We may use personal data to:
- Respond to questions and inquiries;
- Confirm whether our services are suitable for your business;
- Conduct requested Digital Health Checks, audits, and assessments;
- Diagnose digital-presence, branding, content, conversion, visibility, or customer-journey gaps;
- Prepare recommendations, proposals, quotations, and project scopes;
- Schedule and conduct discovery calls, consultations, and meetings;
- Create and manage client accounts and records;
- Deliver agreed services and project outputs;
- Communicate about timelines, approvals, revisions, reports, and next steps;
- Process invoices, payments, refunds, and accounting records;
- Provide customer support;
- Improve our website, forms, content, services, and customer experience;
- Measure website performance and campaign effectiveness;
- Send educational content, service updates, event invitations, or promotional communications where permitted;
- Prevent spam, fraud, unauthorized access, and other security threats;
- Protect our legal rights and enforce agreements;
- Comply with accounting, tax, regulatory, legal, or government requirements; and
- Handle complaints, disputes, or privacy requests.
We aim to collect only information that is relevant and proportionate to the stated purpose.
5. Our Basis for Processing
Depending on the situation, we may process personal data based on the following grounds.
Consent
We may ask for your consent before:
- Sending optional marketing communications;
- Adding you to an email or messaging list;
- Publishing a testimonial, photograph, video, or case study;
- Using non-essential advertising or analytics cookies; or
- Processing information for another optional purpose.
You may withdraw your consent at any time.
Withdrawing consent does not affect processing that was lawfully completed before the withdrawal.
Contract or Steps Before Entering a Contract
We may process information when necessary to:
- Respond to your request for a proposal;
- Evaluate project requirements;
- Prepare an agreement;
- Deliver contracted services; or
- Manage an existing client relationship.
Legal Obligations
We may retain or disclose information when required by applicable laws, lawful government requests, tax obligations, accounting requirements, court orders, or regulatory processes.
Legitimate Business Interests
We may process limited personal data where reasonably necessary to:
- Operate and secure the website;
- Respond to business inquiries;
- Improve our services;
- Maintain business records;
- Prevent fraud or misuse;
- Understand how visitors use the website; or
- Communicate with existing clients about related services.
We consider the purpose, necessity, proportionality, and potential effect on your privacy before relying on this basis.
6. Digital Health Checks and Audit Requests
When you request a Digital Health Check or audit, we may collect your contact details, business information, website address, social media pages, goals, challenges, and answers to diagnostic questions.
We use this information to:
- Understand the symptoms your business is experiencing;
- Identify likely digital or customer-journey gaps;
- Review relevant public-facing business assets;
- Prepare findings or recommendations; and
- Contact you about the assessment and appropriate next step.
Submitting an audit request does not require you to purchase a service.
Audit findings may be retained for follow-up, quality assurance, proposal preparation, and internal recordkeeping.
We will not publish identifiable audit findings as a case study without appropriate permission.
7. Contact Forms, Bookings, Messenger, and Other Communications
When you contact us through a website form, email, telephone, social media platform, Messenger, or appointment-booking service, we receive the information you choose to provide.
The platform you use may independently collect or process information under its own privacy policy. Fullblown Digital does not control the privacy practices of third-party communication platforms.
We may retain correspondence to:
- Respond to your request;
- Maintain an accurate history of our communication;
- Prepare a proposal;
- Deliver services;
- Resolve concerns; or
- Improve our client experience.
8. Comments
When visitors leave comments on the website, we may collect:
- Information entered in the comment form;
- The visitor’s IP address; and
- The browser user-agent string.
This information may be used for comment moderation, website security, and spam detection.
An anonymized string created from your email address, sometimes called a hash, may be provided to the Gravatar service to determine whether you use it.
After your comment is approved, your Gravatar profile image may appear publicly beside your comment.
Comments and associated information that you choose to publish may be visible to other visitors, indexed by search engines, or copied by third parties.
9. Media and Uploaded Files
When uploading images, screenshots, documents, videos, or other files:
- Do not upload information you are not authorized to share;
- Remove confidential client, employee, or customer information where possible;
- Avoid uploading images containing embedded location information, including EXIF GPS data; and
- Use secure transfer methods when sending confidential project materials.
Visitors may be able to download and extract location information from images publicly displayed on the website.
Files submitted privately for an audit, inquiry, or project will not normally be published unless you authorize publication or publication is required to perform an agreed service.
10. Cookies and Similar Technologies
Cookies are small files placed on your device to support website functions, remember preferences, measure activity, or assist with advertising.
We may use the following types of cookies.
Essential Cookies
These support functions such as:
- Website security;
- Form submission;
- Session management;
- Login authentication;
- Fraud prevention; and
- Cookie-preference storage.
Essential cookies may be used without optional marketing consent where they are necessary for website operation.
Preference Cookies
These remember choices such as language, display settings, login status, or previously entered information.
Analytics Cookies
These help us understand how visitors find and use the website, including popular pages, traffic sources, engagement, and technical performance.
Marketing Cookies
Where enabled, these may help measure advertising campaigns, track conversions, or display more relevant advertisements on other platforms.
Non-essential analytics and marketing technologies should be activated according to the preferences selected through the website’s cookie-consent tool.
You can also control or delete cookies through your browser settings. Blocking some cookies may affect website functionality.
WordPress-Related Cookies
Where the relevant WordPress features are enabled:
- A temporary cookie may be placed when you visit a login page to check whether your browser accepts cookies;
- Login cookies may remember your authentication status;
- Display-preference cookies may remember screen settings;
- Selecting “Remember Me” may extend your login session;
- Logging out removes applicable login cookies;
- Comment cookies may remember your name, email address, or website for convenience; and
- Editing or publishing content may create a cookie identifying the related post.
Actual cookie names, providers, purposes, and retention periods depend on the website’s configuration.
11. Embedded Content and Third-Party Links
Pages on this website may include embedded content, such as:
- Videos;
- Social media posts;
- Maps;
- Calendars;
- Forms;
- Reviews;
- Images;
- Articles; or
- Other external content.
Embedded content may behave as though you directly visited the third-party website.
Those providers may collect data, place cookies, use tracking technologies, or monitor your interaction with the embedded material, particularly when you are logged in to their service.
Our website may also contain links to third-party websites. This Privacy Policy does not control how those third parties collect or use personal data.
12. Marketing Communications
We may send educational content, audit invitations, service updates, event information, or promotional messages when:
- You have provided consent;
- You have requested the information;
- The communication relates to an existing client relationship; or
- Another lawful basis applies.
You can stop optional marketing communications by:
- Selecting the unsubscribe option in an email;
- Replying with an opt-out request;
- Changing your communication preferences; or
- Contacting us at info@fullblowndigital.com.
Opting out of marketing does not prevent us from sending necessary service, billing, security, or contractual communications.
13. Who We Share Personal Data With
We may share limited personal data with trusted parties that help us operate the website and deliver services, including:
- Website hosting and domain providers;
- Email and business-communication services;
- Customer relationship management systems;
- Cloud-storage and file-transfer services;
- Appointment and calendar providers;
- Analytics and reporting providers;
- Spam-prevention and cybersecurity services;
- Payment processors and financial institutions;
- Accounting, tax, legal, and professional advisers;
- Contractors, freelancers, or production partners involved in an agreed project; and
- Government authorities where disclosure is legally required.
These parties should receive only the information reasonably necessary to perform their role.
We may also disclose information:
- To protect the safety, security, rights, or property of Fullblown Digital, its clients, or others;
- To investigate fraud, misuse, or unlawful activity;
- In connection with a merger, restructuring, financing, sale, or transfer of business assets; or
- With your direction or consent.
Fullblown Digital does not rent personal data.
14. Service Provider Activities for Our Clients
In some client projects, Fullblown Digital may process personal data on behalf of a client, such as when managing:
- Advertising campaigns;
- Email marketing;
- Customer relationship management systems;
- Website forms;
- E-commerce platforms;
- Lead-generation funnels;
- Social media messages; or
- Customer databases.
In these circumstances, the client generally determines why and how the information is processed, while Fullblown Digital acts as a service provider or Personal Information Processor.
Privacy requests involving client-controlled data may need to be directed to the relevant client.
We will reasonably assist the client in handling valid requests where required.
15. International and Cross-Border Processing
Some website, cloud, analytics, communication, payment, or project-management providers may process or store information outside the Philippines.
When personal data is transferred internationally, we take reasonable steps to use appropriate service providers, contractual protections, access controls, and other safeguards suitable to the nature of the information and processing activity.
16. How Long We Retain Personal Data
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, contractual, accounting, security, dispute-resolution, and business-record requirements.
Retention may depend on the type of record:
- General inquiries: Retained for a reasonable follow-up period;
- Audit and assessment requests: Retained while the assessment, recommendation, or related proposal remains relevant;
- Client and project records: Retained during the engagement and for a reasonable period afterward;
- Contracts, invoices, and accounting records: Retained for the period required by applicable law;
- Marketing records: Retained until consent is withdrawn, the person unsubscribes, or the information is no longer reasonably needed;
- Comments: May be retained indefinitely to preserve discussion history and help recognize follow-up comments;
- Website-security logs: Retained for a limited period based on security needs and provider settings; and
- Uploaded project files: Retained according to the project agreement, service requirements, backup cycle, or legal obligation.
Information may be retained longer when necessary to establish, exercise, or defend legal claims, investigate security incidents, or comply with lawful requirements.
When information is no longer required, we take reasonable steps to securely delete, destroy, anonymize, or restrict access to it.
17. How We Protect Personal Data
We use reasonable organizational, physical, and technical safeguards appropriate to our operations and the nature of the information, which may include:
- Access restrictions;
- Password and account controls;
- Multi-factor authentication where supported;
- Secure hosting;
- Encrypted connections;
- Antivirus and security monitoring;
- Backup procedures;
- Staff or contractor confidentiality obligations;
- Limited access based on work requirements;
- Vendor review; and
- Secure disposal or deletion practices.
No website, transmission method, or storage system can be guaranteed to be completely secure.
Please avoid sending highly confidential information through ordinary website forms or unencrypted email.
18. Your Data-Privacy Rights
Under the Philippine Data Privacy Act, data subjects may have the following rights:
- The right to be informed;
- The right to access personal data;
- The right to object to certain processing;
- The right to correct inaccurate or incomplete information;
- The right to erasure or blocking in appropriate circumstances;
- The right to data portability where applicable;
- The right to claim damages where legally available; and
- The right to file a complaint with the National Privacy Commission.
To exercise a privacy right, contact us using the following details:
Email: info@fullblowndigital.com
Contact number: 0907-717-7777
Business address: Ulha Village, Ulas, Davao City, Philippines
Please include:
- Your full name;
- The nature of your relationship with Fullblown Digital;
- The right you wish to exercise;
- A description of the relevant information; and
- Sufficient information for us to verify your identity.
We may request reasonable proof of identity before acting on a request. This protects your information from unauthorized access or deletion.
Certain requests may be limited where retention or continued processing is required by law, necessary for legal claims, needed to complete a contract, or otherwise permitted by applicable data-protection requirements.
You may also file a complaint with the Philippine National Privacy Commission if you believe your privacy rights have been violated.
19. Children’s Privacy
Our website and services are intended primarily for business owners, professionals, employees, and authorized business representatives.
We do not knowingly collect personal data directly from children under 18 for marketing or service-engagement purposes without appropriate authorization.
A parent or legal guardian who believes a child has submitted personal data may contact us to request review or removal.
20. Password Resets and Website Accounts
Where website accounts are available, account information may include your name, username, email address, profile details, login history, and security information.
Users may generally view, edit, or delete information in their profiles, subject to technical, administrative, security, and legal limitations. Usernames may not always be changeable.
Website administrators may access account information where necessary to provide support, maintain security, or administer the website.
When a password reset is requested, technical information such as the requesting IP address may be included in security notifications or processed to prevent unauthorized access.
21. Automated Spam and Security Checks
Comments, contact forms, login attempts, and website activity may be checked using automated spam-detection, fraud-prevention, or security services.
These services may process information such as:
- IP address;
- Browser information;
- Form content;
- Email address;
- Referring page; and
- Interaction patterns.
Automated security checks are used to protect the website and its visitors. They are not intended to make legal or similarly significant decisions about individuals.
22. Changes to This Privacy Policy
We may update this Privacy Policy when:
- Our website features change;
- We introduce or remove service providers;
- Our business processes change;
- Legal or regulatory requirements change; or
- We identify a need for clearer privacy information.
The updated policy will be posted on this page with a revised “Last Updated” date.
Where a change materially affects how personal data is processed, we may provide an additional notice or request new consent where required.
23. Contact Us
For questions, requests, complaints, or concerns about this Privacy Policy or the handling of personal data, contact:
Fullblown Digital
Website: https://fullblowndigital.com
Email: info@fullblowndigital.com
Business address: Ulha Village, Ulas, Davao City, Philippines
Contact number: 0907-717-7777
Website Compliance Checklist
Before publishing this policy:
- Confirm the actual providers used for website hosting, analytics, advertising pixels, forms, email marketing, CRM, appointment booking, payments, cloud storage, chat, and spam protection.
- Run a cookie scan and document the actual cookie names, providers, purposes, and retention periods.
- Confirm whether website comments, user accounts, Gravatar, and password-reset features are enabled.
- Add separate consent checkboxes for audit submissions and optional marketing communications.
- Link this Privacy Policy beside every contact, audit, booking, newsletter, and lead-generation form.
- Keep optional marketing consent separate from the information required to respond to an inquiry.
- Have the final policy reviewed by a Philippine privacy professional or lawyer before publication.

