PRIVACY POLICY
This Privacy Policy explains how Krelio Technologies Inc. ("Krelio," "Suzy Rent," "Suzy," "we," "us," or "our") collects, uses, stores, discloses, and protects personal data when you use Suzy Rent's websites, mobile applications, Roomies, Communities, rental and property services, subscriptions, communications, and related features (collectively, the "Services" or "Platforms").
This Privacy Policy describes our personal data processing practices. It does not constitute blanket consent to all processing described in this Policy. Where consent is required by applicable law, including for particular processing of sensitive personal information, identity verification, marketing, or non-essential tracking, we request that consent separately through the relevant screen, notice, or setting. Your use of the Services remains subject to our Terms of Service.
1. Who we are
Krelio Technologies Inc. operates Suzy Rent (formerly Dormy PH) and is the personal information controller for processing activities in which we determine the purposes and means of handling personal data.
We engage service providers to process data for us under contract and in accordance with our instructions. Some organizations, such as payment providers, app stores, identity-verification providers, schools, Community partners, property businesses, or external websites, may determine their own purposes and methods for particular activities. Their privacy notices also apply to processing they independently control.
Where another organization and Krelio jointly determine an activity, we provide additional information at the relevant point in the Services where required.
2. Scope and eligibility
This Policy applies to visitors and account holders, including renters, roommate seekers, property owners, brokers, property managers, Community members and administrators, subscription customers, and people who communicate or transact through the Services, collectively referred to as Users. Separate notices may apply to employees, applicants, vendors, and business partners as indicated.
Our Services are intended for individuals who are at least eighteen (18) years old. We do not permit anyone under 18 to create or use an account on our Platforms. If we learn that an ineligible minor has submitted personal data, we may suspend the account and take reasonable steps to delete, restrict, or otherwise appropriately handle the information in accordance with applicable law.
3. Personal data we collect
3.1 Information you provide
Account and contact information, such as name, display name, username, email address, mobile number, date of birth or age information, authentication credentials or tokens, and communication preferences. Authentication credentials are protected using reasonable and appropriate technical and organizational safeguards appropriate to the nature and risks of the processing.
Profile information, such as profile photographs, biography, preferred location at a city, district, or neighborhood level, budget, target move-in period, housing and lifestyle preferences, and other information you choose to display or use for rental or roommate discovery.
Roomies activity, such as match requests, acceptances, declines, connections, blocks, reports, profile visibility settings, and premium-feature selections.
Community information, such as Communities you create or join, membership and administrator roles, affiliation information, invitations, posts, comments, reactions, event details, media, and anonymous-to-members submissions.
Communications and content, such as private messages, attachments, support requests, feedback, appeals, and information supplied with a safety or abuse report.
Rental and business information, such as listing details, inquiries, ocular bookings, applications, screening information, lease or tenant-workflow records, and information supplied by property owners, brokers, or managers.
Subscription and transaction information, such as plan, entitlement, invoice, payment status, transaction identifiers, and limited payment metadata. Payment credentials are generally collected by the relevant payment provider rather than stored directly by Krelio.
3.2 Identity and affiliation verification
Identity verification is performed through third-party identity-verification providers, including Didit Identity, Inc., and may involve subprocessors, infrastructure providers, or other technology providers engaged in the applicable verification flow. We identify or make available information concerning the applicable verification provider through the verification flow, this Policy, or the provider's applicable notices.
When you choose to complete, or are required to complete, identity verification for a clearly identified feature, our third-party service providers may process an identity document, document data, a selfie, a short liveness video, facial measurements used to compare the selfie with the document, device and network information, fraud-prevention signals, and the verification outcome. Some of these materials may constitute sensitive personal information under Philippine law or may otherwise require enhanced privacy and security safeguards because of their nature. The verification screen provides a contextual notice and requests any consent required before capture begins.
Krelio uses the verification result, provider reference, verification date and expiry, and limited review information to operate the badge, prevent misuse, and address disputes. Identity documents, selfies, videos, and biometric-derived materials are not displayed to other users or Community administrators.
Additional details regarding processing performed independently or on Krelio's behalf by a verification provider are available in the applicable provider's privacy or verification notice.
Where a Community uses school-domain, employer, organization, or partner verification, we may process the submitted address or credential, verification event, domain, organization, status, date, and expiry. We limit the visibility of submitted credentials based on the feature and applicable permissions.
3.3 Information collected automatically
Device, browser, operating system, app version, identifiers, IP address, network information, approximate location inferred from IP, language, and time zone.
Login, security, diagnostic, crash, and performance information.
Pages and screens viewed, clicks, searches, referrals, feature use, and interactions with listings, profiles, Communities, and communications.
Cookie, SDK, analytics, and similar technology data, subject to applicable settings and consent choices.
3.4 Information from other sources
We may receive information from other users, Community administrators, property businesses, schools or organizations, authentication providers, payment and verification providers, customer-support and security providers, and other parties involved in a feature you use. For example, another user may send a match request, mention your account in a report, invite you to a Community, or provide information relevant to a rental transaction.
A person or organization that submits personal data about another individual is responsible for having lawful authority or another appropriate basis to provide that information. Krelio processes such information only for purposes described in this Policy, a contextual notice, our Terms of Service, or as otherwise permitted by law, and remains responsible for Krelio's own processing obligations under applicable law.
4. Roomies, Matching, and Premium features
Roomies is designed for authenticated, in-platform roommate discovery. Your profile is displayed according to the visibility and audience controls available for the feature. Contact details, full date of birth, exact residence, identity-verification materials, and other fields designated as private are not displayed merely because another person can view your profile.
We may use profile details, roommate preferences, approximate location, availability, activity, Community membership, prior interactions, verification status, and trust-and-safety information to organize and recommend profiles, Communities, listings, or content.
Recommendations help users discover options. They do not guarantee identity, compatibility, availability, conduct, safety, tenancy eligibility, or a successful roommate or rental arrangement. We may adjust, limit, or withhold recommendations to protect platform integrity, prevent spam or abuse, enforce our rules, or comply with law.
Premium subscriptions may increase feature limits or provide additional profile, discovery, or communication options. Features described as unlimited, unrestricted, or uncapped remain subject to reasonable technical, security, fair-use, anti-spam, and abuse-prevention measures. Instant messaging or similar features do not override a recipient's privacy, blocking, reporting, or message-request controls.
We may use automated processing or profiling to organize, rank, recommend, secure, or personalize profiles, Communities, listings, content, or other features. Where applicable law imposes specific transparency, registration, review, or other safeguards in relation to automated decision-making or profiling, we comply with those requirements.
Automated recommendations do not guarantee identity, compatibility, availability, conduct, safety, tenancy eligibility, or any particular outcome.
5. Communities and information shared with others
Communities may be public, private, or closed. Our Services identify the relevant audience and admission rules. Content posted in a public area may be viewed by a broad audience. Private and closed Communities limit access to eligible members but do not make information confidential in every circumstance.
Community administrators may manage membership, review requests, enforce rules, moderate Community content, and access information made available through their assigned permissions. Their role does not by itself give them access to private messages or raw identity-verification materials.
An administrator or sponsoring organization may act independently of Krelio when it collects information through an external form or uses information outside the Services. Its own policies and responsibilities apply to those activities.
When a post is labeled anonymous, the author's name and profile are hidden from ordinary Community members. Anonymous posting does not make the author anonymous to Krelio. The post remains associated with the relevant Suzy account so authorized personnel may investigate abuse, process appeals, protect users and the public, enforce our rules, and respond to valid legal requirements.
Community administrators do not receive an anonymous author's identity merely because they administer a Community. Where reasonably necessary and proportionate for a specific safety, abuse, fraud, or moderation matter, and where permitted by law, Krelio may disclose limited identifying information to an authorized administrator or another person with a legitimate need to know. If a particular Community or feature uses a materially different anonymity model, we provide notice at the relevant point before submission.
A person who can view a profile, message, or post may copy, save, take a screenshot of, or share it outside Suzy. Our rules prohibit harassment, unauthorized disclosure, and misuse of personal information, and suspected misuse may be reported to us. No platform can technically prevent every off-platform copy, so use the available audience and visibility controls when sharing personal information.
6. Private messages, reports, and moderation
Private messages are visible to their participants and are not displayed publicly. We do not use private-message content for advertising or roommate-compatibility scoring.
Messages are processed automatically to deliver and secure the messaging service. Limited, authorized human review may occur only where reasonably necessary to investigate a user report; provide requested support; detect or address spam, fraud, serious abuse, or a security incident; enforce our Terms of Service or Community Guidelines; protect users or the public; respond to an emergency; or comply with law. Review is limited to information reasonably relevant to the issue and is subject to access controls.
When a user submits a report, our authorized personnel may review the report, information supplied with it, relevant account and technical records, and content reasonably connected to the reported event. We may provide the reported user with a general reason for an action and an opportunity to appeal, but we do not disclose the reporter's identity except where required by law or reasonably necessary to protect rights and safety.
7. Verified badges
A verified badge means only that the account completed the particular identity, liveness, affiliation, or other check identified by Suzy at or before the time the badge was issued. It is not a background check, credit check, endorsement, assurance of compatibility, or guarantee that a person is safe, suitable, or will continue to use accurate information.
We may request reverification or suspend, remove, or decline a badge when information expires, appears inconsistent, the account changes materially, a risk signal is detected, the verification cannot be completed, or continued display would be misleading. An unsuccessful or uncertain automated result may be reviewed or appealed through our support or privacy channels where the applicable feature permits.
8. Why we process personal data
We process personal data to create, authenticate, maintain, and secure accounts and to provide profiles, Roomies, matching, messages, Communities, listings, subscriptions, and support.
We process personal data to display information and deliver interactions according to the feature you use, the action you request, and the visibility settings you select.
We process personal data to verify identity or affiliation, operate badges, detect impersonation, and prevent fraud, spam, abuse, and attempts to evade safety controls.
We process personal data to process subscriptions, payments, refunds, entitlements, accounting, and transaction support.
We process personal data to personalize and recommend relevant profiles, Communities, listings, or content and measure how the Services perform.
We process personal data to send service communications and, with the choices required by law, promotional communications.
We process personal data to enforce our agreements, investigate reports, resolve disputes, protect users and Krelio, comply with legal requirements, and establish, exercise, or defend legal claims.
We process personal data to develop, test, maintain, and improve the reliability, accessibility, security, and functionality of the Services using personal data, aggregated information, and deidentified information as appropriate.
9. Lawful bases
The lawful basis applicable to a processing activity depends on the nature of the personal data and the purpose of processing.
9.1 Personal information
For personal information governed by Section 12 of the Data Privacy Act of 2012, our lawful bases may include consent where consent is the appropriate or required basis for the particular activity.
Processing may be necessary for a contract or for steps taken at your request before entering into a contract, including creating and administering an account, providing requested platform functionality, delivering match requests and messages, administering subscriptions or transactions, or providing requested support.
We may process personal information where necessary to comply with legal obligations applicable to Krelio.
We may process personal information where permitted by law to protect life, health, or other vital interests.
We may process personal information where necessary for legitimate interests pursued by Krelio or a third party, including securing the Services, preventing fraud and abuse, maintaining platform integrity, improving reliability, understanding feature performance, enforcing our agreements, and protecting lawful rights, provided those interests are not overridden by the fundamental rights and freedoms of the data subject.
Where required, we assess the purpose, necessity, and balance of interests before relying on legitimate interests.
We may also rely on another lawful ground expressly permitted by applicable law.
9.2 Sensitive personal information and privileged information
Where information constitutes sensitive personal information or privileged information, we process it only when a condition permitted under Section 13 of the Data Privacy Act of 2012 or another applicable law is satisfied.
Depending on the activity, this may include specific consent obtained before processing; processing expressly authorized by existing law or regulation; processing necessary in circumstances involving life or health as permitted by law; processing necessary for the protection of lawful rights and interests in court proceedings or for the establishment, exercise, or defense of legal claims; disclosure to a government or public authority as permitted by law; or another condition expressly permitted by applicable law.
We do not treat legitimate interest under Section 12 of the Data Privacy Act, by itself, as sufficient authority to process sensitive personal information where Section 13 requires an additional or different lawful condition.
Where processing is based on consent, you may withdraw your consent through available settings or by contacting us. Withdrawal does not affect processing already lawfully completed and may make a consent-dependent feature unavailable.
We may continue processing where another lawful basis applies, including legal compliance, platform safety, fraud prevention, or the establishment, exercise, or defense of legal claims.
10. When we disclose personal data
We disclose personal data only for purposes described in this Policy or otherwise permitted by law, including to:
Other users and Community members, according to the feature you use, the action you request, and your settings.
Community administrators, schools, organizations, and Community partners, for membership, affiliation, administration, or moderation where permitted by the feature, applicable notice, lawful basis, and any contractual or other safeguards required by law.
Property owners, brokers, managers, renters, and other counterparties when you initiate an inquiry, application, booking, transaction, or other rental-related interaction.
Hosting, infrastructure, authentication, communications, analytics, customer-support, payment, identity-verification, security, moderation, and fraud-prevention providers that support the Services and process personal data subject to applicable contractual, confidentiality, security, and data-protection requirements.
Professional advisers, auditors, insurers, banks, and financing sources, subject to appropriate confidentiality or legal obligations.
Affiliated companies where reasonably necessary to operate, secure, support, reorganize, or finance the Services.
Government authorities, courts, regulators, law-enforcement bodies, or other appropriate parties where disclosure is required or permitted by law, valid legal process, an emergency, or the need to protect rights, property, safety, or security.
Parties involved in a proposed or completed financing, reorganization, merger, acquisition, asset sale, insolvency proceeding, or similar corporate transaction, subject to applicable lawful safeguards.
Processors acting for Krelio are required to handle personal data for authorized purposes and apply appropriate safeguards. A recipient acting as an independent personal information controller is responsible for its own processing under applicable law.
Krelio does not sell personal data. We do not provide raw identity-verification materials or private-message content to advertisers.
We may preserve, access, or disclose information when we reasonably believe it is necessary to comply with applicable law or valid legal process; protect Krelio, users, or others; investigate fraud, abuse, or violations; respond to emergencies; or establish, exercise, or defend legal claims.
We assess the validity and scope of legal requests and disclose information reasonably necessary for the applicable purpose. Where lawful and appropriate, we may notify the affected user.
11. International Processing
Krelio and its service providers may process personal data in the Philippines and in other countries where they operate. Privacy laws in those countries may differ from Philippine law.
Where required, we use contracts and other appropriate safeguards for cross-border processing and require recipients to protect personal data consistently with applicable obligations.
Identity-verification and other service providers may process personal data in locations described in their applicable notices, contracts, or subprocessor information. The relevant location may depend on the provider, service configuration, infrastructure, support arrangements, payment services, app stores, or communication services involved.
12. Cookies, Analytics, and Communications
We use necessary cookies, SDKs, and similar technologies for authentication, security, preferences, fraud prevention, and service delivery. We may also use analytics, diagnostics, advertising, or session-replay technologies in accordance with applicable notice and consent requirements.
You can manage available choices through cookie controls, account settings, device settings, browser settings, or relevant provider controls.
Analytics are used to understand feature performance and diagnose problems, not to read private conversations or raw identity-verification submissions.
Where session-replay technology is enabled, it is configured to exclude or mask passwords, payment credentials, private messages, identity-verification screens, and designated sensitive fields.
Service messages about security, transactions, account changes, match requests, or Community activity are part of the Services. Marketing messages are separate and include the opt-out method required for the applicable channel. Opting out of marketing does not stop essential service communications.
13. Retention and deletion
We retain personal data only for as long as reasonably necessary to provide the Services, maintain account and transaction records, protect users, prevent repeat fraud or abuse, resolve disputes, enforce agreements, comply with legal and regulatory requirements, and protect legal rights.
Typical retention periods and criteria include:
Account and profile data: generally while the account is active and thereafter for the limited period reasonably necessary for purposes described in this Policy. Following a verified deletion request, the profile is removed from active discovery and our deletion or deidentification workflow begins, generally within 30 days for active systems where technically practicable and subject to the exceptions below.
Messages and Community content: until deleted, removed, or the relevant account or Community is closed. Residual active-system copies may remain for a limited period while deletion propagates through applicable systems. Copies already received, copied, or created independently by another user may be outside Krelio's control.
Reports, moderation, appeals, blocks, and fraud-prevention records: generally up to 24 months after resolution, and longer where reasonably necessary for an active dispute, repeat-abuse prevention, security investigation, or legal claim.
Identity-verification materials: for the period disclosed in the applicable verification flow or provider notice and no longer than reasonably necessary for the applicable verification, security, fraud-prevention, audit, dispute, or legal purpose. Retention may depend on the verification provider and configuration selected by Krelio.
Krelio may retain the limited verification result, provider reference, verification date or expiry, and related review information for as long as reasonably needed to operate or audit the badge, prevent misuse, investigate disputes, or comply with law.
Security and access logs: generally up to 12 months, and longer where reasonably necessary for an active investigation or legal requirement.
Subscription, payment, tax, accounting, and transaction records: for the applicable statutory, audit, contractual, accounting, or dispute period.
Backups: through a rolling backup and disaster-recovery cycle according to our applicable continuity and security procedures. Personal data deleted from active systems may remain temporarily in protected backups until those backups are overwritten, expire, or are otherwise deleted in accordance with the applicable cycle. Backup data is access-restricted and maintained for continuity, recovery, security, and related legitimate purposes rather than ordinary production use.
We may isolate and retain a record for longer where required by law, valid legal process, an active transaction or dispute, a security investigation, a documented legal hold, another person's rights, or the establishment, exercise, or defense of legal claims.
Access remains restricted and the record is deleted or deidentified when the applicable reason for retention ends, subject to lawful retention requirements.
Information that has been aggregated or deidentified so that it no longer reasonably identifies an individual may be retained and used for analytics, research, security, service improvement, and other lawful business purposes.
14. Security
We maintain reasonable and appropriate organizational, physical, and technical measures designed to protect personal data, taking into account its nature, sensitivity, volume, and the risks of processing.
Measures may include role-based access controls, authentication controls, cryptographic protections where appropriate, monitoring, testing, personnel confidentiality obligations, vendor safeguards, backup and continuity controls, and incident-response procedures.
No online service, storage system, or transmission method can eliminate every risk.
You are responsible for protecting your devices and account access and should notify us promptly if you believe your account has been compromised.
Where a personal data breach requires notification under applicable law or National Privacy Commission requirements, we notify affected individuals and the National Privacy Commission as required.
15. Your rights and choices
Subject to the Data Privacy Act of 2012 and applicable conditions and limitations, you may have the right to:
Be informed whether and how your personal data is processed, including qualifying automated decision-making or profiling.
Request access to your personal data and information about its sources, recipients, processing, and relevant automated processes where applicable.
Dispute inaccuracies and request correction of inaccurate, incomplete, outdated, or otherwise incorrect personal data.
Object to certain processing, subject to applicable legal conditions and exceptions.
Withdraw consent where processing is based on consent. Withdrawal does not invalidate processing lawfully undertaken before withdrawal.
Request blocking, removal, erasure, or destruction where the legal conditions are satisfied.
Request data portability where the conditions for data portability apply, including obtaining qualifying personal data in a commonly used, structured, machine-readable, or otherwise legally required format.
Lodge a complaint with the National Privacy Commission in accordance with its applicable rules and procedures.
To protect users, we may request information reasonably necessary to verify your identity and authority before acting on a request. An authorized representative may be required to provide proof of authority.
We may seek clarification when a request is incomplete, overly broad, vexatious, manifestly unreasonable, or otherwise cannot reasonably be processed without additional information, subject to applicable law.
We encourage you to contact our privacy office at [email protected] so we can investigate and seek to resolve your concern promptly.
The National Privacy Commission's rules generally require a complainant to first notify the respondent in writing and provide an opportunity to address an alleged privacy violation or personal data breach before a complaint is filed, subject to applicable rules, exceptions, or waiver mechanisms of the Commission.
Nothing in this Policy restricts a right to approach the National Privacy Commission where permitted by law.
Privacy rights are subject to legal limitations. We may retain information required by law or reasonably needed for transactions, another person's rights, fraud prevention, platform safety, disputes, investigations, or legal claims.
Where required, we explain a refusal or limitation. Exercising a privacy right will not result in unlawful discrimination, although deleting or withholding information may make an account or feature unavailable where that information is necessary to provide it.
16. Account deactivation and deletion
You may deactivate or request deletion of your account through available in-app controls or by contacting our Data Protection Officer. Deactivation removes the profile from active discovery while preserving the account for possible reactivation. A verified deletion request begins deletion or deidentification under the retention rules above.
Account deletion may not immediately remove information that another user copied or shared outside the Services; must be retained for transactions, taxes, accounting, legal compliance, safety, fraud prevention, disputes, enforcement, or legal claims; forms part of an investigation, moderation action, or report; remains temporarily in protected backups; or has been aggregated or deidentified so that it no longer reasonably identifies you.
Limited contextual content may remain where removal would compromise another user's records or the integrity of a Community discussion, provided account information is removed, minimized, or deidentified where reasonably practicable and legally required.
17. Third-party services and policy changes
The Services may link to or integrate with third-party websites, applications, app stores, payment services, social platforms, or other services. Their own terms and privacy notices govern processing they independently control.
Krelio is not responsible for the privacy practices of a third party acting outside Krelio's instructions and control, except to the extent applicable law imposes responsibility on Krelio for the relevant processing, selection, disclosure, or relationship.
We may update this Policy to reflect changes in the Services, our practices, technology, legal requirements, or organizational structure. We post the revised Policy and update its effective date.
For material changes, we provide additional notice appropriate to the circumstances, such as an in-app notice or email. Where law requires consent for a new or materially different processing activity, we request it separately.
A revised Privacy Policy does not retroactively authorize processing that required consent when the data was collected.
18. Contact and complaints
Questions, complaints, appeals, and privacy-rights requests may be sent to:
Data Protection Officer
Krelio Technologies Inc. / Suzy Rent
Email: [email protected]
General support: [email protected]
Unit 1015, 10th Floor, Parkway Corporate Center, Corporate Ave., corner Parkway Place, Filinvest City, Alabang, Muntinlupa 1781, Philippines
You may also exercise any right to file a complaint with the National Privacy Commission in accordance with applicable law and Commission procedures.
Effective: 30 August 2026
Last Updated: 30 August 2026