Welcome to the Harvester Mission Maganda Church Event Management System (CEMS). This notice explains how we collect, use, and protect your personal data in compliance with the Philippines' Data Privacy Act of 2012 (DPA). Your privacy is important to us, and we are committed to safeguarding your information.
What Personal Information Do We Collect?
We collect personal information necessary to manage church events and your participation. This includes:
- Identity Information: Your first name, middle name (optional), and last name.
- Contact Information: Your email address and contact number (optional).
- Profile Information: Your profile picture (optional) and a secure password (stored as a hashed value).
We also collect non-personal data for system operations, such as user IDs and timestamps.
How and Why We Use Your Information
We collect and process your information for the following specific purposes:
- To Create and Manage Your Account: Your name and contact details are used to create your user account and allow you to log in to the system.
- For Event Management: We use your data to register you for events, track your attendance, and assign event roles.
- To Facilitate Communication: Your email and contact number are used to send you important event announcements and reminders.
- To Improve Church Administration: Aggregated data on event participation helps us generate reports for administrative planning and assess member engagement.
Your data is processed only for these purposes, which are compatible with our church's administrative functions. The system is not designed to disclose your personal information to external third parties.
How We Protect Your Data
We have implemented reasonable organizational, physical, and technical security measures to protect your personal data against unauthorized access, use, or disclosure.
- Technical Security: Your password is encrypted using a hashing algorithm, which means it cannot be viewed by anyone, not even our administrators. We also utilize standard security practices to protect data in transit and at rest.
- Organizational Security: Access to personal data is restricted to authorized church leaders (Pastors and staff) on a "need-to-know" basis through role-based access control (RBAC).
- Physical Security: While our system is hosted on the cloud, we rely on our service provider, Hostinger, to maintain the physical security of the servers where your data is stored.
Your Rights as a Data Subject
Under the DPA of 2012, you have the following rights concerning your personal data:
- Right to be Informed: You have the right to know what personal information we are collecting and why.
- Right to Object: You can object to the processing of your data if it is based on legitimate interests or consent.
- Right to Access: You can request a copy of the personal information we hold about you.
- Right to Correct: You have the right to have any inaccurate personal information corrected.
- Right to Erasure or Blocking: You can request the deletion of your personal information from the system.
If you wish to exercise any of these rights, please contact the Church Administrator, who will facilitate your request.
Data Retention and Disposal
We will retain your personal information for as long as you are an active member of the church. If you request that your account be deleted, or if the data is no longer necessary for the stated purposes, your data will be securely and permanently deleted from our database.
Questions or Concerns?
If you have any questions about this privacy notice or our data processing activities, please contact our designated Church Administrator.
By using the Church Event Management System (CEMS), you acknowledge that you have read and understood this Data Privacy Notice and agree to the collection and processing of your personal data as described.