Privacy Policy
Last updated: September 27, 2026
Overview
eSerbisyo ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, eSerbisyo.com, and related services (collectively, the "Services").
We comply with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, as well as applicable international standards. By using our Services, you agree to the collection and use of information in accordance with this policy.
Information We Collect
We collect the following categories of personal information:
- Account & Identity Data: Name, email address, phone number, barangay, city/municipality, province/region, role (Admin/Staff/Super Admin), MFA status.
- Document Request Data: Applicant name, email, form responses, uploaded verification files (selfie, valid ID), tracking numbers, status, timestamps, PDF download tokens.
- Resident Directory Data (Grow/Scale plans): Household composition, resident demographics, contact details, emergency contacts, photos.
- Ambulance Booking Data (Grow/Scale plans): Pickup/drop-off locations, patient details, medical category, dispatch logs, unit assignments, completion status.
- Technical & Usage Data: IP address, browser/user agent, device info, access timestamps, feature usage, error logs, audit trail events.
- Communication Data: Contact form submissions, inquiry type, messages, email correspondence, newsletter opt-in status.
How We Use Your Information
We process personal data for the following lawful purposes:
- Service Delivery: Process document requests, generate QR-coded PDFs, manage approval workflows, send email notifications, enable walk-in mode, provide QR verification.
- Account Management: Authenticate users, enforce MFA, manage roles/permissions, maintain tenant isolation.
- Security & Fraud Prevention: Turnstile bot protection, MFA enforcement, audit logging, anomaly detection, rate limiting.
- Service Improvement: Analytics (KPI dashboards), feature usage tracking, bug fixing, performance monitoring.
- Communication: Transactional emails (approval, rejection, download links, ambulance status), inquiry responses, optional newsletter (opt-in only).
- Legal Compliance: Audit trails for DILG/local government requirements, data retention policies, lawful basis documentation.
Appwrite Data Processing Addendum (DPA)
Important: Appwrite DPA
eSerbisyo runs on Appwrite Cloud (Pro tier). As a data controller, you (the barangay/LGU) enter into a Data Processing Addendum (DPA) directly with Appwrite when you accept their Terms of Service. eSerbisyo acts as a data processor on your behalf within the Appwrite platform.
- Appwrite's standard DPA is available at: https://appwrite.io/dpa
- The DPA covers: scope of processing, data subject rights, security measures, sub-processor management, breach notification, international transfers, and liability.
- Appwrite's sub-processors (AWS, Google Cloud, etc.) are listed at: https://appwrite.io/subprocessors
- By using eSerbisyo, you acknowledge that your data is processed on Appwrite Cloud under their DPA. eSerbisyo cannot modify or negotiate Appwrite's DPA on your behalf.
Recommendation: Review Appwrite's DPA with your Data Protection Officer (DPO) or legal counsel before onboarding. If you require a signed DPA copy for compliance records, request it from Appwrite support or download from your Appwrite Console.
Data Retention & Deletion
We retain personal data only as long as necessary for the purposes described in this policy, or as required by law.
- Document Requests: 7 years from approval/rejection (configurable per barangay policy), then anonymized or deleted.
- Verification Files (Selfie/ID): Deleted immediately after PDF download, or 90 days after request completion if never downloaded.
- Ambulance Requests: 7 years from completion/cancellation.
- Resident Directory: Retained while barangay subscription is active; deleted within 90 days of contract termination.
- Audit Logs: 7 years (configurable).
- Account Data: Retained while account is active; deleted within 90 days of deletion request.
- Backups: Encrypted backups retained for 30 days; purged thereafter.
You may request deletion of your data at any time (see "Your Rights"
below). The cleanup-pdfs Appwrite Function runs hourly to
enforce retention policies automatically.
Security Measures
We implement appropriate technical and organizational measures to protect personal data:
- Encryption: TLS 1.2+ in transit; AES-256 at rest (Appwrite-managed). PDF downloads served over HTTPS with one-time tokens.
- Access Control: Role-based access (Super Admin / Barangay Admin / Staff / Citizen), tenant isolation at database level, MFA enforced for all staff actions.
- Authentication: Appwrite Account with email/password + optional TOTP MFA. Session cookies are HttpOnly, Secure, SameSite=Lax.
- Bot Protection: Cloudflare Turnstile on all public forms (submit, download, track, login, contact).
- Audit Logging: All admin actions logged with actor, timestamp, entity, and metadata. Immutable append-only store.
- Vulnerability Management: Dependencies scanned via npm audit; Appwrite handles infrastructure patching.
- Incident Response: Breach notification within 72 hours per NPC Circular 16-03; coordinated with Appwrite and affected tenants.
Your Rights (Data Subject Rights)
Under the Data Privacy Act of 2012, you have the following rights:
- Access: Request a copy of your personal data.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Request deletion (subject to legal retention).
- Restriction: Limit processing in certain circumstances.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing for direct marketing or legitimate interests.
- Complaint: Lodge a complaint with the National Privacy Commission (NPC).
To exercise these rights, email privacy@eserbisyo.com or use the contact form. We respond within 15 business days per NPC guidelines. Identity verification may be required.
Children's Privacy
Our Services are not directed to children under 13 (or the applicable age of digital consent in the Philippines). We do not knowingly collect personal information from children. If you believe we have collected data from a child without parental consent, contact us immediately.
International Data Transfers
Appwrite Cloud may process data in regions outside the Philippines (e.g., Singapore, US, EU) depending on the project region selected. Appwrite ensures adequate safeguards via Standard Contractual Clauses (SCCs) and/or adequacy decisions. Our custom Azure VM for PDF conversion is deployed in a region you select (default: Southeast Asia).
Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email and a prominent notice on our website. The "Last Updated" date at the top indicates the most recent revision.
Contact Us
For questions, concerns, or to exercise your rights:
- Email: privacy@eserbisyo.com
- General inquiries: support@eserbisyo.com
- Contact form: /contact
Data Protection Officer (DPO): Rodney Dela Cruz — dpo@eserbisyo.com
Summary of Key Points
- We collect only data necessary for barangay document & ambulance services.
- Data is stored in Appwrite Cloud (Pro tier) — SOC 2 Type II, GDPR-ready.
- Email via Brevo; bot protection via Cloudflare Turnstile.
- PDF conversion runs on our private Azure VM — no third-party SaaS sees document content.
- You have full DPA rights; Appwrite DPA at appwrite.io/dpa.
- Retention: 7 years for requests; verification files deleted after download.
- Contact DPO: dpo@eserbisyo.com
