← All policies

Privacy Policy — Hummingbird (DepEd Abra · DRRM deployment)

DRAFT for review by the Division's Data Protection Officer against the Data Privacy Act of 2012 (RA 10173), its IRR, and NPC issuances, before publication. Written to match actual system behavior as of 2026-07-12.

1. Roles

  • Personal information controller: the Schools Division of Abra (DepEd) — it determines why and how personnel data is processed in its deployment.
  • Personal information processor: Razeflow (operator), and its sub-processors below. Processing is limited to providing the service.
Sub-processorWhat it handlesWhere it processes
SupabaseDatabase, authentication, file storageAsia-Pacific (Singapore)
VercelApplication hosting and deliveryAsia-Pacific (Singapore) — functions pinned to sin1
BrevoTransactional email (sign-in confirmation, password reset)European Union
PhilSMSSMS alerts, when enabled by the DivisionPhilippines

Cross-border transfer. Some processing happens outside the Philippines (Singapore, and the EU for email). The Division remains the controller throughout; sub-processors act only on documented instructions and may not use the data for their own purposes. Personal data in email and SMS is limited to what the message requires — a name, a work email address or a mobile number — never report content or learner data.

  • Data Protection Officer (Division — the controller): DepEd DRRM Abra — the Division's DRRM office is the point of contact for data-protection matters concerning your personal data. *Still outstanding: RA 10173 registration with the National Privacy Commission names an individual, not an office, so the Division must designate the person who holds this role and record their name here. The duty is the Division's as personal information controller, not the operator's.*
  • Data-protection contact (Razeflow — the processor): dpo@razeflow.onl — for questions about how the platform handles data technically: storage, retention, deletion, sub-processors, security. This is not the Division's DPO and cannot decide anything about your data on the Division's behalf; a request to exercise your rights should go to the Division above, and we will act only on their documented instruction.

2. What we collect — and what we deliberately do not

Account data (staff/personnel only): name, work email, contact number, position, role, assigned school/scope; authentication events. Operational data: damage reports (aggregate counts and cost estimates), preparedness records, building/equipment registries, assistance requests, uploaded documents, advisories. Photos: images of damaged infrastructure attached to reports. Camera EXIF location and time are retained on purpose — they are the field evidence that verifies where and when a photo was taken; suspicious distances from the school are flagged for review. Audit data: every change is logged with the acting user's name, role, action, and timestamp — this is a government accountability record. Device data: reports composed offline are stored on the composing device until synchronized (see docs/offline/OFFLINE_DATA_POLICY.md); push subscriptions (browser endpoint keys) if the user enables notifications.

We do not collect learner-level personal data. The system stores *aggregate counts* (e.g. "24 learners affected") — individual learner records remain exclusively in DepEd LIS/EBEIS. No advertising trackers, no sale of data, no profiling.

3. Legal basis and purpose

Processing is performed for the Division's mandated DRRM functions (preparedness, response, damage assessment, recovery reporting) — a public function of the Department of Education. Staff account data is processed as necessary for that function and for system security (authentication, audit).

4. Storage, security, retention

Data is stored in managed cloud infrastructure (Supabase/Vercel; region per project configuration). Controls include: HTTPS with HSTS, role-based and row-level access scoping (a school account can read only what its role allows), a single audited write path, frozen-after-approval records, forced password change on first sign-in, admin-initiated resets, and "sign out of all devices". Retention follows the Data Retention Policy: operational reports and audit logs are retained as official records; account data is removed on account deletion except the name attribution on records already filed.

5. Your rights (RA 10173)

Personnel may access and correct their account data (profile page), request deletion of their account (Division Administration), and raise concerns with the Division's Data Protection Officer or the National Privacy Commission. Note: filed reports and audit entries are official records and are retained with the author's name even after account deletion.

6. Cookies

Only essential authentication cookies — see the Cookie Policy.

7. Breach notification

Security incidents affecting personal data are handled per the Division's incident procedures and NPC breach-notification rules (72-hour window for notifiable breaches). Operator contact for a suspected breach: dpo@razeflow.onl — a security incident touching personal data is a data-protection matter, so it goes to the data-protection address rather than general support.