Privacy notice
Privacy Policy
This notice explains what personal data the Human Resource Management System of Memorial Hospital & Sanitarium holds about you as a member of hospital personnel, why it is held, who can see it, and the rights you hold over it under the Data Privacy Act of 2012 (Republic Act No. 10173).
1. Who is responsible for your data
Memorial Hospital & Sanitarium is the Personal Information Controller for the data described here. The hospital's Data Protection Officer is accountable for how that data is handled and is your first point of contact for any privacy question or request — see Contact.
2. What this system holds
The HRMS stores the following categories of personal data about hospital personnel:
| Category | What it includes |
|---|---|
| Identity and contact | Your name and suffix, work email, employee ID, phone number, and address. |
| Employment record | Department, position, employment status, and your assigned role in this system. |
| Attendance | Check-in and check-out times, and — where a punch is made from a device — the latitude and longitude, IP address, and browser or device identifier recorded with it. |
| Schedules and preferences | Shift assignments, rotations, day-off preferences, and shift-swap requests. |
| Leave | Leave applications, balances, approvals, and any file you attach. Attachments may contain health information, such as a medical certificate. |
| Timesheets | Hours worked per pay period and their approval history. |
| Account security | Your password (stored only as a one-way hash, never in readable form), two-factor settings, active sessions, and the QR-signing secret tied to your attendance code. |
| Biometric device linkage | The reference ID issued by the biometric terminal and the metadata of each scan event. |
| Audit trail | A record of significant actions taken in the system, with the IP address and device that made them. |
| Workload indicator | A daily burnout risk score, worked out from the attendance, roster and leave records above, including how many sick and emergency leave requests you filed recently. Nothing new is collected to produce it. |
3. What it deliberately does not hold
It is as important to state what is absent. This system does not store government identification numbers (SSS, PhilHealth, TIN, or Pag-IBIG), emergency-contact details, or salary figures.
Despite the word "biometric" appearing in the attendance features, no fingerprint or facial template is stored in this application. When the hospital uses a biometric terminal, the template stays on that device or with its vendor; all this system keeps is a reference ID and the fact that a scan happened at a given time.
4. Why it is collected, and on what basis
Each category above exists to serve one of the purposes this system was built for:
- Verifying attendance. Location, IP, and device details exist so that a recorded punch can be tied to a real workplace at a real time, and so that duplicate or out-of-area check-ins can be detected.
- Scheduling the workforce. Names, roles, departments, and availability are the minimum needed to staff every shift and to keep coverage safe.
- Administering leave and preparing payroll input. Leave entitlements and approved hours have to be recorded accurately for you to be paid correctly.
- Accountability and security. Audit logs and session records exist so that a disputed change or a suspected compromise can be reconstructed.
- Preventing overwork. The workload indicator exists so that rosters give staff who have been working long hours without a break more rest. It is not used for disciplinary, performance, or promotion decisions.
The lawful bases relied on are those in Sections 12 and 13 of RA 10173: processing necessary to fulfil the employment relationship, processing necessary for the hospital to comply with a legal obligation, and the legitimate interests of the hospital in running a safe and accountable workforce. Health information in leave attachments is processed for the establishment and exercise of your legal rights as an employee, and is restricted to the staff who must act on it.
Nothing is collected for a purpose beyond these. If a new feature needs a new category of personal data, this notice is updated before that collection begins.
6. Automated processing and AI features
Where the hospital has switched on the optional AI scheduling and analytics features, a third-party AI service (Google Gemini) is used to write plain-language explanations of results the system has already computed.
What is sent to that service is limited to aggregate figures and pseudonymous records — never your name, employee ID, contact details, location history, or leave attachments. The AI does not decide who is scheduled, who is approved, or who is flagged: eligibility and ranking are computed inside this application, and every recommendation requires human review before it takes effect.
The workload indicator is computed automatically, inside this application, and is never sent to that service. You can see your own level, and what is driving it, on your dashboard. HR managers can see everyone's and a department head their own unit's; system administrators see only their own. When your level is high, the scheduling tools give you more rest days and fewer long weeks and night shifts. A manager can still schedule you past those limits, but only by recording a reason. The indicator is not a medical assessment.
No decision that produces a legal effect on you or similarly significantly affects you is made by automated processing alone.
7. How long it is kept
Employment records must be retained for a period even after they stop being useful day-to-day, because the Labor Code and audit rules expect an employer to be able to produce them. The hospital's approved retention schedule governs; the working proposal is three years for attendance, timesheet, and leave records, and five years for audit logs, which exist precisely to resolve later disputes.
In the interest of accuracy: automatic deletion is not yet switched on in this deployment. Until the hospital confirms and enables each retention window, records are kept and are removed only on request or through a reviewed administrative action.
Workload indicator scores are kept for 365 days and then removed by a nightly task. They can always be worked out again from the records above, so nothing the law requires is lost.
8. How it is protected
- Passwords are stored only as one-way hashes and can never be read back, including by administrators.
- Access is enforced by role, so an account can only reach the records its duties require.
- Two-factor authentication is available, and required for administrative accounts.
- Sign-in attempts and password resets are rate-limited, and only one active session is allowed per account.
- Idle sessions time out, and the installed mobile app can be locked behind a device PIN or fingerprint.
- Uploaded leave attachments are stored outside the public web root and are served only to authorised viewers.
- Significant actions are written to an audit log that ordinary users cannot alter.
No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, the hospital will notify you and the National Privacy Commission as RA 10173 requires.
9. Your rights as a data subject
Under RA 10173 you hold the following rights over your personal data. They are yours to exercise at any time, at no cost, and using them will never be held against you.
- Right to be informed
- To know that your personal data is being collected and processed, and why — which is what this notice is for.
- Right to access
- To be given a copy of the personal data held about you, along with how it was obtained, who it has been disclosed to, and how long it will be kept.
- Right to rectification
- To have inaccurate or incomplete data about you corrected, and to have the correction passed on to anyone it was previously disclosed to.
- Right to erasure or blocking
- To have your data removed or withheld from further processing where it is incomplete, outdated, false, unlawfully obtained, or no longer necessary — subject to the records the hospital is legally required to retain.
- Right to object
- To object to processing, including processing based on consent or on legitimate interests, and to withdraw consent you previously gave.
- Right to data portability
- To obtain your data in an electronic, structured, commonly used format that you can move elsewhere.
- Right to damages
- To be indemnified for damage suffered because of inaccurate, incomplete, outdated, false, or unlawfully obtained use of your personal data.
- Right to file a complaint
- To lodge a complaint with the hospital's Data Protection Officer and, if unsatisfied, with the National Privacy Commission at privacy.gov.ph.
These rights are inherited by your lawful heirs and assigns should you pass away or become incapacitated.
10. How to exercise those rights
These requests are handled by people, not by a button in this app. There is no self-service export or account-deletion flow in the HRMS today, and this notice will not pretend otherwise. To make a request, contact the Data Protection Officer using the details below, stating which right you are exercising and enough detail to identify your record.
You can expect an acknowledgement and a response within a reasonable period, and the hospital will tell you if a request cannot be granted in full — for example, where a record must be retained under labour or audit rules — along with the reason.
Some corrections are faster to make directly: your own contact details can be updated from your profile page once you are signed in, and errors in attendance or leave records are usually best raised with your supervisor or the HR office first.
12. Changes to this notice
This notice is updated when what the system does with personal data changes. The "Last updated" date at the top of this page always reflects the last substantive revision, and material changes are announced to personnel through the usual hospital channels.
13. Contact
Data Protection Officer
Human Resource Management Office, Memorial Hospital & Sanitarium
Requests may be filed in person at the office named above, or through your department head.
If you believe your rights under RA 10173 have been violated and the hospital's response does not resolve it, you may complain to the National Privacy Commission at privacy.gov.ph.
This notice describes how this software actually behaves today. Where a safeguard is planned but not yet switched on, it says so rather than claiming otherwise.