Privacy Policy
Last Updated: March 05, 2026Introduction
This Privacy Policy describes how ILCDB Portal ("we", "us", or "our") collects, uses, stores, and protects your personal information in accordance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules and regulations.
We are committed to protecting your privacy and ensuring that your personal data is handled in a safe and responsible manner. This policy outlines your rights as a data subject and explains how we comply with data privacy principles.
What Personal Data We Collect
Account Information:
- Username
- Email address
- Full name (First name, Middle initial, Last name)
- Account status and role
Technical Information:
- IP address
- Browser information (User Agent)
- Login timestamps
- Activity logs
- Session data
Purpose of Collection and Use
We collect and process your personal data for the following legitimate purposes:
Primary Purposes:
- User authentication and account management
- Providing access to application features
- Personalizing user experience
- Communication regarding your account
Security and Compliance:
- Security monitoring and fraud prevention
- Audit logging for compliance
- System maintenance and improvement
- Legal compliance and dispute resolution
Data Retention Policy
| Data Type | Retention Period | Purpose |
|---|---|---|
| Account Information | Duration of account + 2 years after deletion | Account management and compliance |
| Activity Logs | 12 months | Security monitoring and troubleshooting |
| Session Data | Until session expiry or logout | User authentication |
| Security Logs | 24 months | Security analysis and compliance |
Sharing of Information
We may share your information only in the following limited circumstances:
- Legal Requirements: When required by Philippine law or legal process
- Security: To protect our rights, property, or safety, or that of our users
- Service Providers: With trusted third parties who assist in operating our application (under strict confidentiality agreements)
- Consent: When you have given explicit consent
Security Measures
We implement comprehensive security measures to protect your personal data:
Technical Safeguards:
- Secure password hashing (BCrypt)
- HTTPS encryption for data transmission
- SQL injection and XSS protection
- CSRF protection for all forms
- Session security with database storage
Organizational Safeguards:
- Access controls and user authentication
- Comprehensive audit logging
- Regular security assessments
- Staff training on data privacy
- Incident response procedures
Your Data Privacy Rights
Under the Philippine Data Privacy Act, you have the following rights:
Right to be Informed
You have the right to know what personal data is being collected and how it is used.
Right of Access
You can request access to your personal data that we hold.
Right to Object
You can object to the processing of your personal data.
Right of Rectification
You can request correction of inaccurate or incomplete personal data.
Right of Erasure/Deletion
You can request deletion of your personal data under certain circumstances.
Right to Data Portability
You can request a copy of your personal data in a commonly used format.
Contact Information
Data Protection Officer (DPO)
Email: support.academy@dict.gov.ph
Phone: +63 (02) 8xxx-xxxx
Business Hours: Monday - Friday, 9:00 AM - 6:00 PM (PHT)
Complaints and Concerns
If you have concerns about how we handle your personal data, you may contact our DPO or file a complaint with the National Privacy Commission (NPC) of the Philippines.
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make significant changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify users through our application or via email
- Provide a summary of key changes where applicable
Data Privacy Principles
Our data processing activities are guided by the following principles mandated by the Philippine Data Privacy Act:
Transparency
Clear and open about data collection and use
Legitimate Purpose
Data collected for specific, legitimate purposes
Proportionality
Adequate, relevant, and not excessive
Your Consent
By using our application and creating an account, you acknowledge that you have read, understood, and agree to the collection, use, and processing of your personal data as described in this Privacy Policy.
You may withdraw your consent at any time by contacting our Data Protection Officer. However, withdrawal of consent may affect your ability to use certain features of our application.