Skip to the policy

Privacy Policy

1. Who is responsible for your data

Memorial Hospital & Sanitarium is the Personal Information Controller for the data described here. The hospital's Data Protection Officer is accountable for how that data is handled and is your first point of contact for any privacy question or request — see Contact.

2. What this system holds

The HRMS stores the following categories of personal data about hospital personnel:

3. What it deliberately does not hold

It is as important to state what is absent. This system does not store government identification numbers (SSS, PhilHealth, TIN, or Pag-IBIG), emergency-contact details, or salary figures.

Despite the word "biometric" appearing in the attendance features, no fingerprint or facial template is stored in this application. When the hospital uses a biometric terminal, the template stays on that device or with its vendor; all this system keeps is a reference ID and the fact that a scan happened at a given time.

4. Why it is collected, and on what basis

Each category above exists to serve one of the purposes this system was built for:

The lawful bases relied on are those in Sections 12 and 13 of RA 10173: processing necessary to fulfil the employment relationship, processing necessary for the hospital to comply with a legal obligation, and the legitimate interests of the hospital in running a safe and accountable workforce. Health information in leave attachments is processed for the establishment and exercise of your legal rights as an employee, and is restricted to the staff who must act on it.

Nothing is collected for a purpose beyond these. If a new feature needs a new category of personal data, this notice is updated before that collection begins.

5. Who can see it

Access inside the system is decided by role, not by curiosity. In broad terms: you can see your own records; a supervisor or department head can see the records of the staff they schedule and approve for; HR and system administrators can see what their duties require; and administrators can read the audit trail.

Outside the hospital, your personal data is never sold, rented, or used for advertising. It is disclosed only where the hospital is required or permitted to do so — for example, to the Department of Health, the Civil Service Commission, the Commission on Audit, or another government body acting within its mandate, or in response to a lawful order.

6. Automated processing and AI features

Where the hospital has switched on the optional AI scheduling and analytics features, a third-party AI service (Google Gemini) is used to write plain-language explanations of results the system has already computed.

What is sent to that service is limited to aggregate figures and pseudonymous records — never your name, employee ID, contact details, location history, or leave attachments. The AI does not decide who is scheduled, who is approved, or who is flagged: eligibility and ranking are computed inside this application, and every recommendation requires human review before it takes effect.

The workload indicator is computed automatically, inside this application, and is never sent to that service. You can see your own level, and what is driving it, on your dashboard. HR managers can see everyone's and a department head their own unit's; system administrators see only their own. When your level is high, the scheduling tools give you more rest days and fewer long weeks and night shifts. A manager can still schedule you past those limits, but only by recording a reason. The indicator is not a medical assessment.

No decision that produces a legal effect on you or similarly significantly affects you is made by automated processing alone.

7. How long it is kept

Employment records must be retained for a period even after they stop being useful day-to-day, because the Labor Code and audit rules expect an employer to be able to produce them. The hospital's approved retention schedule governs; the working proposal is three years for attendance, timesheet, and leave records, and five years for audit logs, which exist precisely to resolve later disputes.

In the interest of accuracy: automatic deletion is not yet switched on in this deployment. Until the hospital confirms and enables each retention window, records are kept and are removed only on request or through a reviewed administrative action.

Workload indicator scores are kept for 365 days and then removed by a nightly task. They can always be worked out again from the records above, so nothing the law requires is lost.

8. How it is protected

No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, the hospital will notify you and the National Privacy Commission as RA 10173 requires.

9. Your rights as a data subject

Under RA 10173 you hold the following rights over your personal data. They are yours to exercise at any time, at no cost, and using them will never be held against you.

10. How to exercise those rights

These requests are handled by people, not by a button in this app. There is no self-service export or account-deletion flow in the HRMS today, and this notice will not pretend otherwise. To make a request, contact the Data Protection Officer using the details below, stating which right you are exercising and enough detail to identify your record.

You can expect an acknowledgement and a response within a reasonable period, and the hospital will tell you if a request cannot be granted in full — for example, where a record must be retained under labour or audit rules — along with the reason.

Some corrections are faster to make directly: your own contact details can be updated from your profile page once you are signed in, and errors in attendance or leave records are usually best raised with your supervisor or the HR office first.

11. Cookies and on-device storage

This system sets no advertising or third-party tracking cookies. What it stores on your device is limited to what the app needs to work:

Clearing your browser's site data removes all of the above.

12. Changes to this notice

This notice is updated when what the system does with personal data changes. The "Last updated" date at the top of this page always reflects the last substantive revision, and material changes are announced to personnel through the usual hospital channels.

13. Contact

If you believe your rights under RA 10173 have been violated and the hospital's response does not resolve it, you may complain to the National Privacy Commission at privacy.gov.ph.