These terms and conditions set forth the specific terms and conditions governing the use and operation of the Bank of the Philippine Islands (“BPI” or the “BANK”) BPI OneQR Mobile Application (as defined below) and the Merchant Portal (the “BPI OneQR Mobile Application Terms and Conditions”). The BPI OneQR Mobile Application Terms and Conditions supplement and form part of the P2M Merchant Agreement (the “Agreement”) acceded to by the MERCHANT in relation to its availment of the QR P2M Facilities. For the avoidance of doubt, any reference to the Agreement includes the BPI OneQR Mobile Application Terms and Conditions.
By downloading, installing, accessing and using the BPI OneQR Mobile Application and/or the Merchant Portal (as applicable), the MERCHANT agrees to be bound by and accept these BPI OneQR Mobile Application Terms and Conditions.
1. Additional Definitions
(a) Terms defined elsewhere in the Agreement have the same meaning when used in the BPI OneQR Mobile Application Terms and Conditions. In addition to said terms, the following terms when used in the Agreement have the meaning indicated below:
(i) “Authorized User” means the officer, employee, agent, representative, or other personnel of the MERCHANT identified in the Merchant Enrolment and Amendment Form and duly authorized by the MERCHANT to use, manage, and access the QR P2M Facilities and/or the Platform. For the avoidance of doubt, any reference to the MERCHANT includes the Authorized User.
(ii) “Biometric Login” means one of the Bank’s authentication methods and the Authorized User’s alternative unique identification in place of the Username and Password, which allows the Authorized User to log in to the BPI OneQR Mobile Application installed in such Authorized User’s Linked Device via the Authorized User’s biometrics (e.g., the Authorized User’s electronic face identification or any of the Authorized User’s fingerprints), provided that such biometrics are available features in the Linked Device and saved by the Authorized User in the said Linked Device’s settings.
(iii) “BPI OneQR Mobile Application” means the software application of the Bank that is designed to run on a smartphone, tablet or such other portable device allowing the MERCHANT and/or Authorized Users to use, access, and manage the QR P2M Facilities through said portable device. For the avoidance of doubt, any reference in the Agreement to the Platform includes the BPI OneQR Mobile Application.
(iv) “Linked Device” means an internet-enabled mobile device/s paired with the Authorized User’s Username for logging into the BPI OneQR Mobile Application. The linking of the mobile device/s of an Authorized User with his/her Username is authenticated using the OTP (as defined below). Mobile device/s may be linked to only one Username at any given time. As such, only the Username linked via OTP (as defined below) to the mobile device/s may log in to the BPI OneQR Mobile Application installed in the said mobile device/s.
(v) “Login Credentials” means the Username and Password of the Authorized User.
(vi) “One-Time PIN” or “OTP” means one of the Bank’s authentication methods, which is a security code that is only valid for a single transaction and is intended to add an extra layer of security. For each transaction wherein the OTP is required by the Bank, the OTP is sent via e-mail to the Authorized User’s Registered E-mail Address and the Authorized User will be prompted by the Platform to directly input the OTP on the space provided therein in order to authorize, confirm, and complete the corresponding transaction.
(vii) “Password” means a string of special characters, letters, and/or numbers, created and nominated by the Authorized User, which when used in conjunction with the Username, serves as the Authorized User’s unique identification for the purpose of authenticating and accessing the QR P2M Facilities through the Platform.
(viii) “Registered Mobile Number” refers to the Philippine mobile number provided by the MERCHANT to the BANK and reflected in the Merchant Enrolment and Amendment Form or any other document required by the BANK, as such documents may be updated by the MERCHANT from time to time in accordance with the Bank’s information updating guidelines.
(ix) “Registered E-mail Address” refers to the e-mail address provided by the MERCHANT to the BANK and reflected in the Merchant Enrolment and Amendment Form or any other document required by the BANK, as such documents may be updated by the MERCHANT from time to time in accordance with the Bank’s information updating guidelines.
(x) “Username” means a string of special characters, letters, and/or numbers nominated by the Authorized User, which when used in conjunction with the Password, serves as the Authorized User’s single unique identification for the purpose of authenticating and accessing the BPI OneQR Mobile Application and any or all of the Platform.
(b) Headings used herein are for convenience and reference only and do not affect the meaning or interpretation of the Agreement. Unless the context otherwise requires, words denoting the singular include the plural and vice versa, and words denoting persons include individuals, corporations, partnerships, joint ventures, trusts, unincorporated organizations, and any political subdivision, agency, or instrumentality. Any reference to a law or statute is construed as a reference to such law or statute as the same may have been, or may from time to time be, amended, substituted, or re-enacted.
2. Access to BPI OneQR Mobile Application and/or the Merchant Portal
The MERCHANT acknowledges and agrees that:
(a) The Bank has provided sufficient instructions and/or guidelines on how to use the BPI OneQR Mobile Application and/or the Merchant Portal under and pursuant to these BPI OneQR Mobile Application Terms and Conditions and continues to do so through amendments and supplements from time to time, as well as, the Bank’s rules, regulations, and policies, as communicated through the BANK’s announcements, publications and notifications on the BANK’s website. The MERCHANT is responsible for following, and is responsible for causing the Authorized Users to follow, the said instructions and/or guidelines. Only after understanding and accepting the instructions and/or guidelines of the Bank may the MERCHANT and/or the Authorized User be eligible to access the BPI OneQR Mobile Application with the use of the Linked Device and/or the Merchant Portal. The MERCHANT shall be solely responsible for any and all adverse consequences of its access and use of an internet connection and/or the internet-enabled device. The MERCHANT hereby holds the Bank free and harmless, and shall indemnify/reimburse the Bank, from any and all claims, liabilities, costs, payments, damages and expenses, arising from or in connection with its access and use of an internet connection and/or the internet-enabled device (including the Linked Device).
(b) Through the BPI OneQR Mobile Application and/or the Merchant Portal that may be provided by the Bank under the Agreement, the MERCHANT, through the Authorized User, may be able to access the features available in the BPI OneQR Mobile Application and/or the Merchant Portal using the Login Credentials or (if access is through the BPI OneQR Mobile Application) Biometric Login, provided that in the latter case, only if and when Biometric Login is available and enabled.
(c) Although the BPI OneQR Mobile Application is designed to be accessible seven (7) days a week, twenty-four (24) hours a day, at certain times, the BPI OneQR Mobile Application may not be available due to any Force Majeure Event or system maintenance. In case of scheduled system maintenance, the same shall be priorly announced to the public through the Bank’s official website, news outlets, the Bank’s social media accounts, or any of the Bank’s official communication channels. Any scheduled system maintenance could occur as early as 10:00 PM (Philippine Standard Time) on a banking day, or as otherwise required and solely determined by the Bank and shall be published in the Bank’s official website. The Bank shall in no event be held liable for any delay, non-performance or failure to perform any of its obligations under the Agreement, as well as any and all claims, liabilities, costs, payments, damages and expenses, for reasons due to, arising from or in connection with, directly or indirectly, any such Force Majeure Event or scheduled and announced system maintenance. For this purpose, “Force Majeure Event” means circumstances beyond the affected party’s reasonable control, including, without limitation, acts of God, natural disasters, calamities, earthquakes, fire, extreme weather, volcanic activity, explosions, floods, wars, rebellion, civil or military disturbances, sabotage, acts of terrorism, criminal acts or willful misconduct by a party other than the affected party, its officers or employees, epidemics, pandemics, loss or malfunction of utilities or facilities, power outages, catastrophic accidents, electrical or mechanical failure, computer hardware or software failure, system failure or system downtime, network or telecommunication failure, causes or acts attributable to third persons or parties, labor disputes, strikes, walk-outs, riots, lock-outs, industrial disturbances, or governmental actions.
(d) The MERCHANT shall immediately update, and/or cause the Authorized User to immediately update, the Bank of any changes to the Authorized User’s Registered Mobile Number and/or Registered E-mail Address in accordance with the Bank’s information updating guidelines. The MERCHANT is solely responsible for verifying and, if necessary, correcting in accordance with the Bank’s established guidelines and procedures the mobile number and/or e-mail address reflected in the Bank’s records as the Registered Mobile Number and/or Registered E-mail Address of the Authorized User. In no event shall the Bank be held liable for sending any such OTP/s to the e-mail address reflected as the Registered E-mail Address of the Authorized User in the Bank’s records at the time the Bank sent such OTP/s.
(e) The Bank reserves the right and is authorized to suspend, terminate, remove, disable, or discontinue access to or use of the BPI OneQR Mobile Application (or any part thereof) or any other Platform at any time without prior notice (i) if and when the Authorized User (1) violates any term or condition in the Agreement, or (2) violates or fails to comply with applicable laws, rules, policies and regulations; or (ii) if the Bank, at its sole option and discretion, reasonably determines that suspension, termination, removal, disabling or discontinuance of access to or use of any or all of the BPI OneQR Mobile Application or any other Platform is necessary to protect the interests of the Bank, its clients, or third parties. In any such event, the Bank shall in no event be liable to me or any person for any and all claims, liabilities, costs, payments, damages and expenses, arising from or in connection with the suspension, termination, removal, disabling or discontinuance of the BPI OneQR Mobile Application (or any part thereof).
3. Use of Password, Biometric Login and other authentication method/s
(a) The MERCHANT shall ensure that the Authorized User shall keep in confidence his/her Password and/or OTP and under no circumstances shall the Authorized User share or divulge his/her Password and/or the OTP received from the BANK to any person or entity even if the MerCHANT or the Authorized User believes that said person or entity is a personnel, agent, or representative of and/or acting on behalf of the BANK. The Password and/or OTP shall be known only to the relevant Authorized User and as such, any transaction using the Password and/or OTP shall be binding upon the MERCHANT. The Bank shall, in no event, require the Authorized User to divulge his/her Password and/or the OTP through phone call, text, e-mail, or any other means to any person or to any entity. The Password and/or the OTP shall only be required by the Bank to be keyed in when the Authorized User accesses or uses the BPI OneQR Mobile Application or any other Platform.
(b) The MERCHANT hereby assumes full responsibility for all transactions made with respect to the Account/s through any of the Platform using the Authorized User’s Login Credentials, Biometric Login, or any of the Bank’s authentication method/s. The Bank shall in no event be held liable for any and all claims, liabilities, costs, payments, damages and expenses, arising from or in connection with the use of the Login Credentials, Biometric Login, and/or any of the Bank’s authentication method/s, including any transactions made in the Account/s using such Login Credentials, Biometric Login, and/or any of the Bank’s authentication method/s.
(c) The MERCHANT shall secure, and shall cause the Authorized User to secure, at all times, all the Linked Devices and immediately inform the Bank through its established guidelines and procedures if any of those devices are no longer in the MERCHANT and/or the Authorized User’s possession. The BANK shall in no event be held liable for any and all claims, liabilities, costs, payments, damages and expenses, arising from or in connection with any unauthorized transactions in the BPI OneQR Mobile Application using the Linked Device.
(d) If Biometric Login is enabled on the BPI OneQR Mobile Application, any biometrics saved in the Linked Device’s settings can be used to access the BPI OneQR Mobile Application features. The MERCHANT hereby assumes full responsibility for all the biometrics enrolled in the Linked Device and for the Linked Device into which the biometrics of the Authorized User is/are saved. The Bank shall in no event be held liable for any activity and/or transaction made by any person accessing the Linked Device using any of the biometrics saved in the Linked Device’s settings, regardless of whether such activity and/or transaction was authorized by the MERCHANT.
(e) The MERCHANT shall cause the Authorized User to change his/her Password from time to time as may be deemed necessary in order to fully safeguard and ensure the security of access to the BPI OneQR Mobile Application and any other Platform. Should the MERCHANT determine that the Password has been or may be compromised, the MERCHANT shall cause the Authorized User to immediately change his/her Password through the BPI OneQR Mobile Application or any other Platform’s reset facility and/or immediately inform the Bank through its established guidelines and procedures.
(f) The Bank, at its sole discretion, is entitled to act on the instructions received via any and all of the BPI OneQR Mobile Application or any other Platform which the Bank reasonably believes emanated from the MERCHANT or the Authorized User by virtue of the use of Login Credentials, Biometrics Login, and/or any of the Bank’s authentication methods. The Bank shall not be liable for acting in accordance with or based on the requests and/or instructions made in the BPI OneQR Mobile Application or any other Platform through the use of the Login Credentials, Biometric Login, and any of the Bank’s authentication method/s.
4. Features of the BPI OneQR Mobile Application and/or Merchant Portal
Subject to the Agreement, the MERCHANT acknowledges the following features and functionalities inherent in the BPI OneQR Mobile Application and the Merchant Portal, as these may be amended, modified, supplemented, or discontinued:
(a) PRE AND POST LOGIN PAGE – the page in the relevant Platform where the Authorized User can log-in using his/her Username and Password or, where applicable, Biometric Login (e.g., any fingerprint or face identification);
(b) BIOMETRIC SETTING – the page in the BPI OneQR Mobile Application where the Authorized User can enable or disable (through the enable/disable button and/or toggle on/off feature) the Biometric Login as an authentication method;
(c) TRANSACTION HISTORY – the tool in the relevant Platform where the Authorized User can access, view, and download the transaction details; and
(d) QR GENERATION (STATIC AND DYNAMIC) – the tool in the relevant Platform where the Authorized User can generate static and dynamic QR;
(e) CHANGE PASSWORD – the tool in the relevant Platform where the Authorized User can perform a password change.
5. Updates
New updates, upgrades, enhancements, fixes, expansions, improvements, modifications, and replacements may be introduced by the Bank as part of the BPI OneQR Mobile Application or any other Platform, from time to time (“Updates”). The MERCHANT shall be notified of these Updates through any of the Bank’s official communication channels. By using or causing the Authorized User to use such updates when they become available, the MERCHANT agrees to be bound by the applicable terms and conditions concerning these Updates, which specific terms and conditions, if and when such Updates are availed, are deemed incorporated herein by reference.
Any reference to the QR P2M Facilities and/or Platform includes the Updates once available.
6. Customer Service and Complaints
(a) The MERCHANT agrees and acknowledges that it can file requests and complaints through the following QR P2M Facility channels:
- P2M Merchant Hotline: 8580-4140 and 85804141
- Email address: agencybanking-customerservice@bpi.com.ph
For urgent concerns or those that may require immediate attention (e.g., unauthorized transactions), the MERCHANT shall not rely on e-mail or accomplish forms in the BANK’s website but instead, shall immediately call the P2M Merchant Hotline specified above.
(b) The MERCHANT shall provide the Bank with necessary information to be used for the investigation and resolution of its requests and complaints. The Bank shall provide the MERCHANT with the prescribed processing time to resolve a complaint.
(c) The Bank may change the official facilities and channels provided in Section 6(a) from time to time. The MERCHANT shall keep itself apprised and updated regarding the Bank’s announcements of changes in the Bank’s official facilities and channels, as the same may change from time to time, as well as, regarding the Bank’s announcements on online security.
7. Communication to and from the BANK
(a) In the event that the MERCHANT or the Authorized User receives communication purporting to be from the BANK but originates from an unofficial number, e-mail address, and/or website, the MERCHANT shall, and shall cause the Authorized User to, protect itself/himself/herself from any such attempt to obtain any personal data and Account information, such as the Login Credentials, authentication information (e.g., OTP), and other Account details, by any such entity disguising as the Bank in such unofficial communication. The MERCHANT shall, and shall cause the Authorized User to remain vigilant against cyberattacks that may appear to make unauthorized use of the Bank’s logo and/or tradename. The MERCHANT shall report any such suspected activity to the Bank immediately.
(b) The MERCHANT hereby holds the Bank free and harmless, and shall indemnify/reimburse the Bank, from any and all claims, liabilities, costs, payments, damages and expenses, arising from or in connection with its failure to keep itself updated with the Bank’s official facilities and channels, as well as, any disclosure of any or all of any personal data of its stockholders, directors/trustees, officers, employees, agents, or other personnel (including the Authorized User) and/or Account information to any entity other than the Bank, even if the entity makes an unauthorized use of the Bank’s logo and/or tradename.
(c) The Bank may respond to the MERCHANT’s communications by e-mail on any matter related to the BPI OneQR Mobile Application or any other Platform using the e-mail address registered with the Bank. The MERCHANT is aware of the possible risks involved in connection with the giving and receiving of notices and other communication via e-mail. Such e-mail could be transmitted improperly or may never reach the MERCHANT or may become known to third parties thus losing their confidential nature. The Bank accepts no responsibility for the occurrence of any such circumstances or for any action, claim, loss, damage, or cost arising or incurred by the MERCHANT as a result of or in connection with any such circumstances. The MERCHANT shall be solely responsible for making its own independent appraisal and assessment of any possible risks in relation to the giving and receiving of notices and communication via e-mail.
(d) Where applicable, the MERCHANT hereby authorizes the Bank to send promotional offers, advertisements, surveys or such other similar programs of the Bank, its subsidiaries, affiliates and partner institutions, by communicating to the MERCHANT in writing, or by e-mail to the registered e-mail address, or by short messaging service (SMS) to the Registered Mobile Number, or by such other electronic transmission which the Bank, at its option, considers appropriate and effective, or through the Bank channels or any one of them including posting in the Bank’s website.
(e) The Bank may send any notice or communication to the MERCHANT via mail, e-mail, short messaging service (SMS), other Bank channels, or any one of them, including posting on the BPI website, BPI OneQR Mobile Application, Merchant Portal, or by such other electronic transmission or use of a Platform which the Bank, at its option, considers appropriate and effective, any of which mode of communication or transmission when sent shall be valid and effective notice to the MERCHANT.
8. Other agreements
(a) The MERCHANT agrees that where particular transactions, products and services are subject to specific terms and conditions agreed upon between itself and the Bank, insofar as not inconsistent herewith, such terms and conditions are made integral parts of the Agreement by reference and shall likewise be resorted to in instances where they are applicable.
(b) The MERCHANT further agrees to be bound, where applicable, by the terms and conditions of the Bank governing PRODUCTS, SERVICES, FACILITIES, AND CHANNELS including any amendments or supplements thereto, as well as, other terms and conditions implemented by the Bank in relation to its products and/or services.
(c) The Agreement shall be governed by all applicable rules and regulations of the Bangko Sentral ng Pilipinas (BSP) available at https://www.bsp.gov.ph.
9. Amendments
The Bank may modify, amend or revise the Agreement or any of the terms and conditions applicable to any of the services provided through BPI OneQR Mobile Application from time to time. The MERCHANT shall be notified of any such modification, amendment or revision via mail, e-mail, posting on the Bank’s website, BPI OneQR Mobile Application or by such other electronic transmission or use of an electronic platform which the Bank, at its option, considers appropriate and effective. Any such modification, amendment or revision shall be valid and binding upon the MERCHANT on the date of effectivity specified in the notice, subject to compliance with applicable legal and regulatory requirements, provided, however, that: (i) amendments required by law; and (ii) amendments necessary to prevent considerable losses and/or material risks to the BANK (as determined by the BANK in its sole discretion), shall take effect immediately or as required by law. Notwithstanding any provision to the contrary, the MERCHANT’s continued use and/or availment of any of the services and facilities offered by the Bank thereafter shall constitute its acceptance of the modifications, amendments or revisions to the Agreement or any of the applicable terms and conditions.
10. Intellectual Property Rights
All Intellectual Property Rights arising from or in connection with the BPI OneQR Mobile Application and/or the Merchant Portal are owned by the Bank or licensed from a third party. The MERCHANT shall not do any act or thing inconsistent with the Bank’s or such third party’s ownership of the Intellectual Property Rights. In the event of any infringement or suspected infringement of the Bank’s or such third party’s Intellectual Property Rights, the MERCHANT shall notify the Bank thereof and shall take such reasonable action as the Bank shall direct in relation to such infringement. The MERCHANT shall not engage in any activity or commit any act, directly or indirectly, that may contest, dispute, or otherwise impair the Intellectual Property Rights of the Bank (or its licensors).
For this purpose, “Intellectual Property Rights” means the right, title, and interest to/in any (i) names (including trade names and business names, logos, trademarks, and service marks, patents and patent applications, business methods, know-how, inventions, and discoveries that may be patentable, software and computer code, designs, copyrights in both published works and unpublished works, confidential information, and other intellectual property rights and interests, whether registered or unregistered, and (ii) the benefit of all applications and rights to use any or all of the rights, assets, and/or items referred to in item (i). Intellectual Property Rights includes all intellectual property rights registered under the BANK’s name and/or duly licensed to the BANK by an affiliate or subsidiary of the BANK or by a third party.
11. Disclaimer of warranties
(a) To the full extent allowed by applicable laws, all warranties, whether express or implied by law or statute, are excluded from the Agreement, including, but not limited to, any implied warranties of merchantability, title, fitness for a particular purpose, and non-infringement. The Bank does not represent or warrant to the MERCHANT that the Merchant Portal, BPI OneQR Mobile Application, and other Platforms (if any) will meet all of the MERCHANT’s requirements, will be uninterrupted, timely, secure or free from error, will function to meet the Authorized User’s requirements, and will be compatible with future products or services of the Bank. Access to the Merchant Portal, BPI OneQR Mobile Application, and other Platforms (if any) is provided as is.
(b) While the Bank has used commercially reasonable efforts to design for and test the Merchant Portal, BPI OneQR Mobile Application, and other Platforms (if any) on most browsers, devices, and operating systems, it does not guarantee that the Merchant Portal, BPI OneQR Mobile Application, and other Platforms (if any) will work or be compatible on all browsers, devices, or operating systems.
12. Limitation of Liability and Indemnity
(a) The MERCHANT agrees to hold the Bank, its subsidiaries and affiliates, successors and assigns, and Outsourced Service Providers (as defined below) including any of their respective directors, officers, agents and representatives, free and harmless, as well as indemnified from any and all liabilities, costs, damages, claims, losses, or suits of whatever nature, arising out of or in connection with the implementation of the Agreement and/or the use and access of the Merchant Portal, BPI P2M Mobile Application, or any other Platform, unless the loss or damage actually incurred is solely and directly caused by the gross negligence or willful misconduct of the Bank.
(b) The Bank shall not be liable for any losses or damages resulting from circumstances over which the Bank has no direct control, including, but not limited to, the linking of the Linked Device, unauthorized access to any OTP sent to the Registered E-mail Address, the MERCHANT or Authorized User’s disclosure of any personal data, Login Credentials, and/or OTP to other persons – regardless of whether such disclosure was intentional or inadvertent, the failure of electronic or mechanical equipment or communication lines or other interconnection problems, any Force Majeure Event, or other such other similar events.
(c) To the full extent allowed by applicable laws, the Bank shall not be liable to the MERCHANT for any special, consequential, indirect, exemplary, incidental or punitive damages, including but not limited to lost profits or actual or anticipated revenue, lost opportunities and business interruption, howsoever caused, whether under a theory of contract, warranty, tort (including negligence), product liability, or otherwise, arising out of or in connection with the Agreement or its termination, and irrespective of whether the MERCHANT has advised the Bank of the possibility of any such loss or damage.
13. Other internet-based services of the BPI Group of Companies
(a) The MERCHANT understands that the Merchant Portal and/or BPI OneQR Mobile Application may now, or in the future, provide other internet-based services pertaining to other members of the BPI Group of Companies which the MERCHANT may desire to avail.
(b) By applying for registration to avail of such internet-based services and subsequently availing of such other internet-based services, the MERCHANT hereby likewise agrees to be governed by the respective terms and conditions of the specific internet-based service availed, including those that may be issued by the other member/s of the BPI Group of Companies offering such service.
(c) “BPI Group of Companies” refer to the BANK and its Affiliates. “Affiliate” means a corporation, partnership, or other form of association which is directly or indirectly Controlled by the BANK. The term “Controlled” means (i) ownership of at least twenty percent (20%) of the total issued and outstanding capital stock in such corporation or association; (ii) the right to elect at least twenty percent (20%) of the number of directors in the corporation or association; or (iii) the right to cause the direction of the management and policies of such corporation, partnership, or other form of association, whether through the ownership of shares, directorship, management, community of interest, or contract.
14. Consent to processing of personal data
The MERCHANT acknowledges and agrees that information relating to it, its organization, its representatives (including personal data of the MERCHANT’s officers and directors, authorized signatories, employees, beneficial owners, agents, users, beneficiaries, customers, and other personnel), transactions, business, credit relationships, and Accounts, provided by the MERCHANT and made available to or in the possession of the BANK or any of its Affiliates (collectively, the “Merchant Information”), or updated from time to time, may be collected, used, stored, consolidated, processed, profiled, benchmarked, disclosed, and shared to or by the BANK or by and among the BANK, any member of the BPI Group of Companies, and the Outsourced Service Providers (as defined below), and their successors and assigns, for any or all of the following (the “Purposes”):
(a) To approve, manage, facilitate, administer, implement and provide the services, transactions, and facilities availed and/or selected by the MERCHANT;
(b) To comply with the BANK’s operational, audit, administrative, credit and risk management processes, policies and procedures, the terms and conditions governing the BANK’s Products, Services, Facilities and Channels, BSP rules and regulations, legal and regulatory requirements of government regulators, supervisory bodies, tax authorities, or courts of competent jurisdiction, as the same may be amended or supplemented from time to time;
(c) To comply with applicable laws of the Philippines and those of other jurisdictions including the United States Foreign Account Tax Compliance Act (“FATCA”), the laws on the prevention of money laundering and the implementation of know-your-customer and sanction screening checks, as the same may be amended or supplemented from time to time;
(d) To develop and enhance product, business and customer offerings of the BANK and/or its Affiliates, which may include the conduct of product, system, statistical or business analysis, surveys, schemes, planning, and research;
(e) To pursue marketing, sales, promotional, advertising, and business initiatives (the “Marketing Initiatives”), which may include the development, formulation, dissemination, distribution, and rollout of Marketing Initiatives information, materials, documents, or brochures relating to the products, services, events, promotions, programs, and offers of the BANK or any member of the BPI Group of Companies or those provided by third parties which the BANK or any member of the BPI Group of Companies, under a duty of confidentiality, has contracted with through a partnership, joint venture, servicing or tie-up arrangement in connection with the Marketing Initiatives (the “Program Partners”);
(f) To carry out, fulfill, and complete the transactions authorized by the MERCHANT in connection with the BANK’s performance of the services, the QR P2M Facilities and the Agreement.
Pursuant to the foregoing Purposes, the BANK may share and disclose the Merchant Information, whether within or outside the Philippines, under a duty of confidentiality:
(i) to other members of the BPI Group of Companies;
(ii) to the BANK’s directors, officers, employees, professional advisers, legal counsels, auditors, joint venture partners, loyalty program partners, the Program Partners, agents, representatives, service providers, and third parties providing services to the BANK on a need-to-know basis;
(iii) to credit information companies, credit bureaus, the Credit Information Corporation (CIC) (pursuant to Republic Act No. 9510 and its implementing rules and regulations), financial institutions, banking and credit industry associations, credit protection provider or guarantee institutions, brokers, insurers, and underwriters (collectively, the “Credit Entities”), in relation to the MERCHANT’s availment of credit facilities of the BANK, if any;
(iv) to any judicial, governmental, regulatory, or supervisory body of the Philippines or those of other jurisdictions, including tax authorities in compliance with FATCA, as the same may be amended or supplemented from time to time;
(v) to any potential transferee or assignee of the BANK’s rights and/or obligations under the relevant contracts or agreements or in connection with any sale, acquisition, merger, or consolidation of any member of the BPI Group of Companies;
(vi) to the representatives, agents, or service providers engaged by the BANK or by any member of the BPI Group of Companies to perform (whether within or outside the Philippines) data processing, collection, consolidation, storage, and such other services in connection with the Accounts, the QR P2M Facilities, the Platforms, and the Agreement (the “Outsourced Service Providers”);
(vii) to representatives, agents, or service providers engaged by the BANK, by any member of the BPI Group of Companies, or by Program Partners, in connection with Marketing Initiatives, whether the same are undertaken individually by the BANK or by each member of the BPI Group of Companies or pursued by members of the BPI Group of Companies together or with Program Partners, under a joint venture initiative, servicing agreement, cross-selling arrangement, loyalty or promo program, or any project undertaking on a collective or tie-up basis; and
(viii) to such other persons or entities that the BANK, any member of the BPI Group of Companies, the Credit Entities (if applicable), or the Outsourced Service Providers, may engage or contract with to facilitate or carry out any or all of the foregoing Purposes.
The foregoing constitutes the express consent of the MERCHANT under the applicable bank secrecy, confidentiality and data privacy laws of the Philippines and other jurisdictions, including without limitation, the provisions of Republic Act No. 1405 (The Law on Secrecy of Bank Deposits), Republic Act No. 6426 (The Foreign Currency Deposit Act), Republic Act No. 10173 (The Data Privacy Act of 2012), Republic Act No. 8791 (The General Banking Law), Republic Act No. 9510 (The Credit Information System Act) and as applicable, their respective implementing rules and regulations (“IRR”) (collectively, the “Bank Secrecy and Privacy Laws”), and the MERCHANT agrees to hold the BANK, each member of the BPI Group of Companies, their successors and assigns, and their respective directors, officers, employees, authorized representatives, agents and service providers, free and harmless from any and all liabilities, claims, damages, suits, costs, and expenses resulting from or in connection with the implementation of the Purposes and authorities conferred by the MERCHANT under the Agreement.
15. Data privacy policy
(a) The BANK’s Data Privacy Policy which explains how it collects, protects, uses, shares, consolidates, and stores information (including personal data) is published at www.bpi.com.ph and deemed incorporated by reference in the Agreement. The BANK acknowledges and agrees that, in the course of implementing the QR P2M Facilities, it may receive or have access to personal data of the MERCHANT’s officers, directors, authorized signatories, employees, beneficial owners, agents, users, beneficiaries, customers and other personnel. As used in the Agreement, the term “personal data” has the meaning ascribed to it under the IRR of the Data Privacy Act of 2012. The BANK agrees to comply at all times with the requirements on the collection, processing, and handling of personal data under the Data Privacy Act of 2012 and its IRR.
For the avoidance of doubt, to the extent that applicable confidentiality, bank secrecy, or other laws impose non-disclosure requirements on certain relevant information but permits a party to provide consent thereto, the express consent provided herein shall constitute the MERCHANT’s written consent for purposes of such applicable laws. Any agreement between the MERCHANT and the BANK to maintain confidentiality of information shall continue to be observed to the extent that such agreement is not otherwise inconsistent with the consent to disclosure of Merchant Information authorized under the Agreement.
(b) The MERCHANT understands that its continued access into the Bank’s network of websites, applications, or use of this service will constitute its acceptance of the BPI Data Privacy Policy as the same may be revised or updated from time to time.
16. Declaration
The MERCHANT hereby declares that: (i) all the statements, information and supporting documents provided by it are true, correct, accurate, and updated; (ii) where the information or data provided was collected by it from third party sources, the relevant consent has been secured by it from the relevant parties to whom such information relates; (iii) any material misrepresentations or falsity or omission on the MERCHANT’s part will be construed as an act to defraud the Bank and may be a ground for the termination of the Agreement, or the cancellation or termination of its access to any or all of the Platforms, without prejudice to such civil and/or criminal liability that the Bank may pursue against the MERCHANT; (iv) the Bank may impose such terms, conditions and requirements as it may deem necessary or proper relative to the MERCHANT’s availment of any of the Platforms; (v) the MERCHANT shall notify the Bank of any material change affecting the information provided by it; and (vi) in using any of the Platforms, the MERCHANT shall comply with all applicable laws, rules, and regulations.
17. Governing law and venue
The Agreement shall be governed by and construed in accordance with the laws of the Republic of the Philippines. Any dispute arising hereunder shall be submitted to the exclusive jurisdiction of the proper courts of Makati City, Philippines, to the exclusion of all other venues.
BPI is regulated by Bangko Sentral ng Pilipinas. https://www.bsp.gov.ph