Privacy Policy
Last updated:
1. Information we collect, acquire and generate
Personal-data processing must follow the principles of transparency, proportionality and legitimate purpose under Republic Act No. 10173, or the Data Privacy Act of 2012. Depending on the service used, information may be provided directly by you, recorded by authorized personnel during a walk-in transaction, or generated while your request is processed:
- Resident and account information: username, full name, birth date, address, mobile number, email address and account or verification status.
- Certificate and supporting records: requested certificate, purpose, applicant details, uploaded ID images and supporting documents, and information needed for the particular certificate. An ID or document may contain sensitive personal information, such as a government-issued identifier. For walk-in requests, personnel may record the documents physically presented and their validation results instead of uploading copies.
- Processing and transaction history: request numbers, staff assignments, screening or interview schedules, review notes, decisions, status changes, issuance details, transaction records, notifications and audit entries identifying relevant actions and actors.
- Account security and technical information: password hashes, OTP verification records, session identifiers and account activity. Access or application logs may contain IP addresses, timestamps, requested URLs and error details. Essential session cookies help maintain login and protect requests.
Only information relevant to the requested service should be submitted or collected. A guest request does not require an account, but its applicant details and documents still receive the same privacy considerations.
2. Use of personal data
Information is used to register and verify accounts, maintain resident information, receive and process certificate requests, validate submitted requirements, schedule screening, communicate updates, track requests, prepare certificates, maintain transaction and audit history, and support account recovery and profile changes.
Reports and service analytics summarize request volumes, status, processing time, peak periods and other service measures. Basic demand forecasts support service planning; they are not automated decisions about an individual resident's eligibility. Research or presentation materials should use aggregated or de-identified information and must not expose identifiable resident records without an appropriate lawful basis and authorization.
The responsible operator must identify the lawful basis applicable to each activity. Depending on the circumstances, this may involve consent, applicable legal obligations or authorized public functions. Sensitive personal information requires an applicable basis and safeguards under the law. Reading or acknowledging this policy is not blanket consent to unrelated uses and does not waive your privacy rights. Personal information is not collected for sale or unrelated advertising.
3. Sharing, disclosure and access to personal data
Access within the application is limited by configured roles and permissions. Authorized barangay personnel and system administrators may access information relevant to their assigned duties. Database, hosting and backup administrators may also have technical access and must protect that access separately from application permissions.
Information may be disclosed to authorized recipients for the requested service, to contracted providers necessary to operate the system, or when required or permitted by applicable law. Other disclosures require an appropriate lawful basis, including consent where applicable. Sharing must be limited to what is necessary; resident records are not intended for public posting, unrelated marketing or unrestricted access by researchers or evaluators.
The current hosted deployment uses Hostinger. The configured email provider may be Google/Gmail, an SMTP provider or Resend, depending on the installation. Providers process information needed to supply hosting, database or email services, subject to their terms and configured locations. This policy does not guarantee that every service or backup is located within the Philippines.
4. Email verification and Google services
The system sends OTPs and other service-related emails to the address supplied for the relevant workflow. The configured email provider receives the recipient address and message content needed for delivery, which may include a name, verification code or service-related information.
When Gmail API delivery is configured, the system's sender account,
dontreply.additionhills@gmail.com, is authorized to send email using
gmail.send over HTTPS. This permission does not provide access to read, search or
delete the sender's inbox. You do not need to authorize access to your own Google account
simply to receive an OTP. Sender credentials and authorization tokens are kept on the server
and must not be published or included in verification messages.
Google API information and authorization are used only for the stated email-delivery function, not for advertising or unrelated profiling. Use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google's handling of information is also described in the Google Privacy Policy.
Never share a verification code. If you receive an unexpected OTP, do not use or forward it; report the concern through the contact below.
5. Storage, security and retention
Resident, account and request records are stored in the configured database. Uploaded documents are stored separately by the application. Logs, reports, exports and backups may contain additional copies. The application uses password hashing, verification checks and role-based access controls; these measures do not remove every security risk.
The responsible operator must maintain appropriate organizational, physical and technical safeguards against unauthorized access, disclosure, alteration, loss or unlawful disposal, including protection of uploads, credentials, exports and backups.
Personal information should be retained only as necessary for the stated purposes and applicable recordkeeping or legal requirements, then securely disposed of under an approved retention schedule. The system does not currently apply a single automatic deletion period to all records, documents, logs and backups. This policy therefore does not promise deletion after a fixed number of days or immediate removal from every backup.
6. Handling of data security incidents and breaches
Suspected unauthorized access, lost documents or other privacy incidents should be reported promptly through the contact below. The responsible operator must document and investigate incidents, take reasonable steps to contain them and reduce harm, and notify the National Privacy Commission and affected individuals when required by applicable law and regulations.
Avoid including passwords, OTPs, full ID images or unnecessary sensitive information in an initial incident report. Further details should be provided through an appropriate secure channel.
7. Access, correction and your privacy rights
Subject to applicable conditions and exceptions, you may request information about how your data is processed, access to your personal information, correction of inaccurate records, objection to processing, blocking or erasure, and data portability where applicable. You may withdraw consent for processing that relies on consent and raise a complaint with the National Privacy Commission.
Use available profile features to update editable account information, or contact support for resident-record corrections and other privacy requests. Identity and authority must be verified before records are disclosed or changed. Some information may need to be retained for lawful recordkeeping, audit or other applicable obligations. Withdrawing consent may affect a service that depends on that consent, but does not automatically erase every historical record.
8. Contact and privacy requests
For system privacy concerns, access or correction requests, or suspected data incidents, contact system support at dontreply.additionhills@gmail.com. For questions about resident records or certificate processing, you may also contact the Barangay Addition Hills office through its established service channels.
Describe your request and provide only the details needed to identify the concern. Do not email passwords, OTPs, authorization tokens, full ID copies or unrelated sensitive data. The address above is a system support contact, not an identification of an appointed barangay Data Protection Officer.
9. Review and changes to this policy
This policy should be reviewed when system features, service providers, legal requirements or approved data practices change. Revisions will be posted on this page with an updated revision date. Publishing this policy does not itself certify legal compliance, establish legal authority to process data or replace the responsible organization's approval and operating procedures.