PRIVACY

Privacy Notice

Version 1.0 · Effective 10 September 2026

This Privacy Notice explains how Techbayanihan Community OS handles personal data for Techbayanihan community and nonprofit-program operations. For the processing described here, Techbayanihan determines the purposes and means of processing and acts as the personal information controller for those activities. Questions or requests may be submitted through the Contact page.

1. Personal data we process

Depending on how you use the service, we may process account and profile information such as name, email address, preferred name, professional-profile category, self-provided organization name, phone number, communication preferences, account-security data, and email-verification status.

For identity verification, the application stores verification metadata in PostgreSQL while the uploaded government-issued ID file is stored in the configured private SharePoint verification folder. Verification evidence is restricted to authorized reviewers and is not placed in public static storage or written into AuditLog.

We also process Activity participation and operations data, including registrations, group orders and invitations, ticket status, Member Activity roles, journeys, tasks, sessions, Speaker profile publication choices, volunteer committee assignments, Sponsor/Partner representative links, and Organization relationships. Organization or role information in Community OS is operational context and does not by itself prove employment, representation authority, qualification, accreditation, or endorsement.

When you contact us, we process the name, email, topic, and message you provide. Application and hosting infrastructure may also process technical and security information such as request timestamps, IP addresses, browser/user-agent information, session cookies, rate-limit events, and security logs.

2. Why we process personal data

We process personal data to create and secure Member accounts; verify email control and, where requested, identity; operate Programs and Activities; manage registration, ticketing, sessions, journeys, tasks, volunteer and stakeholder operations; communicate service and operational information; maintain audit and security records; respond to inquiries; enforce the Terms and Code of Conduct; and comply with applicable legal obligations.

Where applicable, processing may rely on consent, steps necessary to provide a requested service or perform an agreement, compliance with legal obligations, or legitimate interests that are not overridden by the rights and freedoms of the data subject. Optional communication preferences and public Speaker-profile publication are separate choices and may be changed without converting them into proof of identity or authority.

3. Privacy acknowledgment is not blanket consent

Community OS records that you acknowledged this Notice, including its version and context. That acknowledgment is evidence that the Notice was presented; it is not blanket consent for unrelated processing. Where consent is the appropriate legal basis for a specific activity, the application or operational process should obtain that consent separately.

4. Who may receive or process data

Access is limited to authorized Techbayanihan personnel and service providers that support the functions actually enabled in this release. Current infrastructure includes Railway-hosted application/PostgreSQL services and Microsoft services used through Microsoft Graph/Exchange for email and SharePoint for private identity-verification evidence. A future payment or SMS provider is not treated as active merely because a feature is planned; this Notice should be updated when additional processors or processing purposes are enabled.

We do not state that personal data is sold. Data may be disclosed when reasonably necessary to operate the service, protect users and the community, comply with lawful process, or meet applicable legal obligations.

5. International or cross-border processing

Technology providers may process or store information in locations where they operate. Where cross-border processing occurs, Techbayanihan should use appropriate contractual, organizational, and technical safeguards consistent with applicable Philippine data-protection requirements.

6. Retention and deletion

Personal data should be retained only for as long as necessary for the purposes described above, legitimate audit/history needs, security, dispute resolution, and applicable legal or accounting obligations. The current R2 application does not implement a single automated retention/deletion timer for all record types. Government-ID evidence is kept in the configured private SharePoint location and is subject to the approved operational retention/deletion process rather than public application storage.

Because some records support auditability, event history, ticket integrity, legal compliance, or dispute resolution, a deletion request may result in deletion, blocking, anonymization, or restricted retention depending on the record and applicable obligations.

7. Security

Community OS uses controls including authenticated Member/Admin access, server-side authorization, CSRF protection, secure production cookies, rate limiting, security headers, audit logging for controlled actions, and private storage for government-ID evidence. No internet service can guarantee absolute security, so users should also protect their account credentials and report suspected compromise promptly.

8. Your data-subject rights

Subject to the Data Privacy Act of 2012 and applicable rules, data subjects may have rights to be informed, object, access personal data, request correction, request erasure or blocking where applicable, data portability, claim damages where legally available, and lodge a complaint with the National Privacy Commission. Requests relating to Techbayanihan processing may be submitted through the Contact page.

9. Cookies and sessions

The application uses session cookies necessary for authenticated account and security functionality. Production session cookies are configured as Secure, HttpOnly, and SameSite=Lax. The application does not treat essential authentication/session cookies as optional marketing consent.

10. Changes to this Notice

Material changes require a new document version. Community OS records the version acknowledged in supported account and registration flows so a later update does not silently rewrite an earlier acceptance record.

Philippine privacy framework. This Notice is designed around the transparency and data-subject-rights requirements of Republic Act No. 10173 (Data Privacy Act of 2012) and its implementing rules. It should be reviewed against Techbayanihan's final organizational details, retention schedule, contracts, and operational policies before relying on it as legal advice.