Who is accountable
Cybersecurity and Cloudware Solutions Inc. operates PIA360. The subscribing organization remains accountable for the processing activities and PIA evidence it controls. Privacy inquiries may be sent to info@cybersecurity-cloudware.com.
Information processed
Account, organization, role and access information; processing-system descriptions; assessment, flow, stakeholder, risk, control, approval and report records; and essential security, session, diagnostic and audit metadata.
Purposes and lawful basis
PIA360 authenticates authorized users, maintains a processing inventory, supports and documents PIAs, generates accountable records, protects the service, and responds to legal and contractual duties. Each underlying activity must document its own valid DPA Section 12 or 13 basis.
Access and disclosure
Access is tenant-scoped and role-based. It is limited to authorized organization users, separately authenticated administrators and approved service providers. Disclosures and processors must be recorded, purpose-limited and safeguarded.
Retention and rights
Assessment, account, audit and backup records follow documented retention and secure-disposal schedules. Subject to lawful limitations and identity verification, data subjects may exercise the rights provided by the Data Privacy Act of 2012 and complain to the National Privacy Commission.
Security and automated assistance
PIA360 uses least privilege, independent administration, origin and CSRF controls, audit trails, session revocation and administrator MFA. Calculations and suggestions are decision support only; they do not make a legal, DPO, approval or residual-risk decision.