How the Event Registration & Attendance Management System (ERAMS) collects, uses, protects, and retains your personal data.
RA 10173 — Data Privacy Act of 2012GDPR-aligned principlesLast updated: August 4, 2026
What we collect
When you register and use ERAMS, we collect the following personal data:
Identity details — first name, last name, and (optionally) birthdate.
Contact details — email address, mobile phone number, and (optionally) city/municipality.
Academic details — course, major, year level, block, and organization role.
Attendance records — event registrations, check-in and check-out timestamps, and attendance status.
Face data (optional) — if you voluntarily enroll in face verification, we store your enrollment images and derived face descriptors used solely to verify your identity at check-in.
System activity — security-relevant actions (logins, profile changes, admin actions) recorded in audit logs.
Why we collect it
Your data is processed only for legitimate purposes connected to campus event operations:
Event management — registering you for events, managing capacity, eligibility, and communication.
Attendance verification — confirming your presence via QR scanning or optional face verification.
Certificates — generating and validating certificates of participation.
Analytics — aggregate, de-identified statistics (attendance rates, event performance) that guide event planning. Analytics never single you out.
We do not sell your personal data or share it with third parties for marketing.
Retention
We keep personal data only as long as needed for the purposes above:
Account data is retained while your account is active.
Attendance and certificate records are retained for the academic record-keeping period required by the institution.
Face enrollment data is retained until you re-enroll, request its removal, or your account is deleted.
Audit logs and backups are retained for security and disaster-recovery purposes and are purged on a rolling basis.
When data is no longer needed, it is securely deleted or anonymized.
Your rights
As a data subject under RA 10173 (and consistent with GDPR principles), you have the right to:
Access — request a copy of the personal data we hold about you.
Correction — update inaccurate or outdated details. Most fields can be edited directly on your Profile page.
Deletion — request removal of your account, face enrollment, or specific records where retention is no longer required.
Object or withdraw consent — withdraw consent to optional processing (such as face verification) at any time.
To exercise any of these rights, contact the system administrator — requests are acted on within a reasonable period as required by law.
Security measures
Passwords are stored using strong one-way hashing — never in plain text.
All database operations use prepared statements to prevent SQL injection.
Forms are protected against cross-site request forgery (CSRF), and sessions are regenerated periodically.
Administrative areas require role checks plus a secondary admin passkey gate; optional two-factor authentication is available for all accounts.
Security-relevant actions are written to an audit log, and regular database backups support disaster recovery.
Access to personal data is restricted to authorized administrators on a need-to-know basis.
Legal alignment
ERAMS processes personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173) of the Philippines and its Implementing Rules and Regulations, observing the principles of transparency, legitimate purpose, and proportionality.
The system also aligns with GDPR principles — lawfulness and consent, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability — as a benchmark of good practice.
Consent is obtained at registration and recorded with a timestamp. Optional features that process sensitive data (such as face verification) require separate, voluntary enrollment.
Contact
For privacy concerns, data access requests, corrections, or deletion requests, contact the ERAMS system administrator through your organization's admin office, or use the in-app Chat Admin feature once logged in.
If you believe your data privacy rights have been violated, you may also lodge a complaint with the National Privacy Commission (NPC) of the Philippines.