Virtual Bears

Privacy Policy

Effective Date: 19 June 2026 | Last Updated: 19 June 2026

Virtual Bears ("we", "us", or "our") is committed to protecting the privacy of everyone who visits our website, contacts us, or engages us to deliver software development services. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the rights available to you depending on where you are located. We operate across multiple markets including the Philippines, Australia, United Kingdom, Singapore, and the Netherlands / European Union. Where the laws of those jurisdictions impose specific obligations or grant additional rights, we address those directly in the relevant sections below.

1. Who We Are

Company name: Virtual Bears

Website: virtualbears.ph

Email: bears@virtualbears.ph

Virtual Bears is a custom software development company. For the purposes of applicable data protection law, Virtual Bears acts as the data controller in respect of personal data collected through our website and business development activities. Where we process personal data on behalf of clients as part of a software delivery engagement, we act as a data processor under the terms of a separate Data Processing Agreement.

2. Personal Data We Collect

We collect personal data through the following channels:

2.1 Contact Form Submissions

When you submit an enquiry through our website contact form, we collect the following:

2.2 Discovery Call Bookings

When you book a discovery call with our team, we collect:

2.3 Email Newsletter Sign-Ups

When you subscribe to receive communications from us, we collect:

2.4 Cookies and Website Analytics

When you visit our website, we automatically collect certain technical and usage data through cookies and analytics tools, including:

For full details of the cookies we use and how to manage your preferences, see Section 7 (Cookies) below.

2.5 Client Project Data

In the course of delivering software development services to clients, we may access or process personal data that belongs to our clients or their end users. This data is processed solely on the instructions of our clients and is governed by a Data Processing Agreement entered into at the start of each engagement. This Privacy Policy does not cover the processing of client project data.

3. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

Responding to enquiries: To respond to contact form submissions and answer questions about our services.

Scheduling and conducting discovery calls: To book, prepare for, and follow up on discovery calls with prospective clients.

Sending marketing communications: To send newsletters, updates, and service information to subscribers who have opted in. You can unsubscribe at any time.

Improving our website: To understand how visitors use our website and identify areas for improvement using analytics data.

Managing our business relationship: To manage the commercial and contractual relationship with clients, including proposals, scoping, invoicing, and project delivery.

Complying with legal obligations: To meet our legal and regulatory obligations in the jurisdictions we operate in.

4. Legal Basis For Processing

Where data protection law requires us to identify a legal basis for processing your personal data, we rely on the following:

Legitimate interests: Processing enquiries, managing business relationships, and improving our services — where our interests are not overridden by your rights.

Consent: Sending marketing communications and placing non-essential cookies — where you have given clear, informed consent.

Contract: Processing personal data necessary to perform a contract with you or take steps at your request before entering into a contract.

Legal obligation: Processing required to comply with applicable law.

For individuals in the European Union (including the Netherlands) and United Kingdom, these legal bases correspond to those defined under the UK GDPR and EU GDPR respectively. You have the right to withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.

5. How Long We Keep Your Data

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law.

Enquiry and contact data: Retained for 2 years from the date of last contact, unless a commercial relationship is established.

Client and project data: Retained for the duration of the engagement and for 7 years following project completion, in line with standard commercial record-keeping requirements.

Marketing subscriber data: Retained until you unsubscribe or withdraw consent. We review inactive subscriber lists periodically and remove contacts who have not engaged within 2 years.

Analytics data: Retained in aggregated or anonymized form. Raw session data is typically retained for 14 months in line with standard analytics platform defaults.

When personal data is no longer required, it is securely deleted or anonymized.

6. Who We Share Your Data With

We do not sell your personal data. We share personal data only in the following circumstances:

Service providers: We use a limited number of third-party service providers to operate our website and business — including email platforms, scheduling tools, analytics providers, and cloud infrastructure. These providers act as data processors and are contractually bound to process data only on our instructions and to appropriate security standards.

Professional advisors: We may share data with legal, financial, or compliance advisors where necessary for business operations or legal compliance.

Legal requirements: We may disclose personal data where required to do so by law, court order, or regulatory authority.

Business transfers: In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred as part of that transaction, subject to equivalent privacy protections.

We do not transfer personal data to third parties for their own marketing purposes.

7. Cookies

Our website uses cookies and similar tracking technologies. Cookies are small text files stored on your device that help us understand how visitors use our site.

7.1 Types Of Cookies We Use

Strictly necessary cookies: Required for the website to function correctly. These cannot be disabled.

Analytics cookies: Used to collect anonymized data about how visitors use our website (e.g. pages visited, time on site). We use this to improve the website experience.

Preference cookies: Used to remember your choices and settings (e.g. cookie consent preferences).

7.2 Managing Cookies

When you first visit our website, you will be presented with a cookie consent banner. You can choose to accept or decline non-essential cookies at that point. You can also manage or withdraw your consent at any time through your browser settings or by contacting us at bears@virtualbears.ph.

Please note that disabling certain cookies may affect the functionality of our website.

8. International Data Transfers

Virtual Bears operates across the Philippines and the Netherlands. Personal data may be transferred between these locations in the course of our business operations.

Where personal data originating in the European Union or United Kingdom is transferred to countries not recognized as providing an adequate level of data protection, we ensure appropriate safeguards are in place — including Standard Contractual Clauses (SCCs) approved by the relevant supervisory authority, or other transfer mechanisms permitted under applicable law.

If you would like further information about the safeguards we apply to international transfers, please contact us at bears@virtualbears.ph.

9. Your Privacy Rights

Depending on where you are located, you may have the following rights in relation to your personal data:

9.1 European Union And Netherlands (EU GDPR)

To exercise these rights, contact us at bears@virtualbears.ph. You also have the right to lodge a complaint with your national supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

9.2 United Kingdom (UK GDPR)

Individuals in the United Kingdom have equivalent rights to those described above under the UK GDPR. You may also lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

9.3 Australia (Privacy Act 1988)

Individuals in Australia have the right to access personal information we hold about them and to request correction of inaccurate information under the Australian Privacy Act 1988 and the Australian Privacy Principles. Complaints may be directed to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

9.4 Singapore (PDPA)

Individuals in Singapore have the right to access and correct personal data we hold about them under the Personal Data Protection Act 2012 (PDPA). You may also withdraw consent to our collection, use, or disclosure of your personal data, subject to legal and contractual restrictions. Complaints may be directed to the Personal Data Protection Commission (PDPC) at pdpc.gov.sg.

9.5 Philippines (Data Privacy Act 2012)

Individuals in the Philippines have the following rights under the Data Privacy Act of 2012 (Republic Act No. 10173):

Complaints may be directed to the National Privacy Commission (NPC) at privacy.gov.ph

10. Data Security

We take the security of your personal data seriously. We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, or alteration. These measures include:

No method of transmission over the internet or electronic storage is completely secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority in accordance with applicable law.

11. Children's Privacy

Our website and services are directed at businesses and professionals. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us immediately at bears@virtualbears.ph and we will take steps to delete it.

12. Third-Party Links

Our website may contain links to third-party websites. This Privacy Policy applies only to our website and services. We are not responsible for the privacy practices of third-party sites and encourage you to review their privacy policies before providing any personal data.

13. Changes To This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational structure. When we make material changes, we will update the “Last Updated” date at the top of this document. We encourage you to review this policy periodically.

For significant changes that affect how we process your data, we will notify you directly where we have contact details for you, or by placing a prominent notice on our website.

14. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your privacy rights, or want to raise a concern about how we handle your personal data, please contact us:

Email: bears@virtualbears.ph

Website: virtualbears.ph

We aim to respond to all privacy-related requests within 30 days. For complex requests, we may extend this period by a further two months where permitted by applicable law, and will notify you of any extension within the initial 30-day period.

Scroll to Top