Privacy Policy
This policy explains what personal information the Philippine KOICA Fellows Association, Inc. ("PHILKOFA", "the Association", "we") collects through the members' portal and the KOFA PH mobile app, why, who can see it, how long we keep it, and the rights you have. It is written to meet the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the issuances of the National Privacy Commission.
1. Who we are
PHILKOFA is the alumni association of Filipino participants in academic and training programmes sponsored by the Korea International Cooperation Agency (KOICA). For the information described here, PHILKOFA is the personal information controller: we decide how and why it is used. The Association is independent. KOICA does not operate the portal or the app and does not receive members' information through them.
Philippine KOICA Fellows Association, Inc.7/F Del Rosario Law Centre, 21st Drive cor. 20th Drive, BGC, Taguig City
+63.2.403.9780 · contact@philkofa.org.ph
Data Protection Officer: to be named, dpo@philkofa.org.ph. Write to the Data Protection Officer about anything in this policy.
This policy covers the portal at kofaph.jothamhernandez.com, the KOFA PH app for Android and iPhone, the contact form, and activity registration. It does not cover the Association's pages on Facebook, X (Twitter) or YouTube, which follow those companies' own policies.
2. What we collect
Most of what we hold, you give us yourself: when you apply, complete your profile, register for an activity or write to us. Some is added by the officers who review applications and record payments. A small amount is created automatically when you use the portal.
| Kind of information | What it includes | Required? |
|---|---|---|
| Account | Your name, email address and password. Passwords are stored in scrambled form, so no officer can read them. | Yes |
| Contact and address | Mobile number; region, province, city or municipality, barangay, street and postal code. | Region and city yes; the rest optional |
| Profile | Middle name, title, suffix, organisation, position, sector, a short biography and a photograph. | Optional |
| Date of birth Sensitive | Your birth date, if you choose to add it. | Optional |
| KOICA programmes Sensitive | The kind of programme (for example a master's degree or a training course), course title, institution, years attended and completed, and a scan of your certificate. | At least one programme; certificate optional |
| Payments | Amount, what it was for, how you paid (bank, GCash, Maya, cash or cheque), reference number, date, and a photo of your receipt or deposit slip. We never ask for card numbers or account passwords. | When you record a payment |
| Activities | Activities you register for, number of guests, any remarks you add, and whether you attended. | When you register |
| Contributions | Publications you add or claim authorship of, project proposals, votes, offers to help, invitations, co-author requests, and documents you upload. We store the text of uploaded proposal documents so they can be read within the portal. | Only if you take part |
| Recognition points | Points awarded to you, the reason, and who awarded them. | Created by the system and officers |
| Committee records | Your membership number and status, application decisions and the messages sent to you, internal notes by the membership committee and secretariat, and a record of when and how you gave consent. | Created by officers |
| Messages to us | Name, email, subject and message sent through the contact form, and our reply. | Name, email and message |
| Technical | Sign-in cookies; for the app, the device name and when it was last used; and the server's record of the address each device connects from and the pages it asks for, kept for security. | Automatic |
Your age and your education are sensitive personal information under Section 3(l) of the Data Privacy Act. We collect them only with your consent, given for this specific purpose, and use them only to confirm your KOICA participation and recognise your credentials within the Association.
3. What we don't collect
- No government ID numbers (TIN, SSS, PhilHealth, passport).
- No payment card details. The portal takes no payments online.
- No location tracking. The app does not ask for your location, contacts or microphone. It asks for the camera and photos only when you choose to attach a receipt.
- No advertising or analytics trackers. We do not sell or rent personal information to anyone.
4. Why we use it, and on what legal basis
| Purpose | Legal basis (RA 10173) |
|---|---|
| Verifying your KOICA participation and deciding your application | Your consent, given when you apply (Sections 12(a) and 13(a)) |
| Keeping the membership roster, issuing your membership number and running your account | Your consent, and the membership you asked to enter (Section 12(b)) |
| Recording fees and other payments, and keeping the Association's financial records | The membership relationship, and the Association's legal duties for its books (Section 12(c)) |
| Organising activities and taking attendance | Your request when you register. Health or dietary details you add in remarks are used only to make arrangements for you. |
| The member directory, publications library and project proposals | Your consent, managed through your directory settings |
| Awarding recognition points | Your consent, and the Association's legitimate interest in recognising members' contributions (Section 12(f)) |
| Sending notices about your application, payments, proposals and activities | The membership relationship |
| Answering messages sent through the contact form | Your request |
| Keeping the portal secure and preventing misuse | The Association's legitimate interest (Section 12(f)) |
Decisions and points. Points are added automatically only for facts an officer has already confirmed: a verified programme or publication, recorded attendance, an officer term, a verified payment or an endorsed proposal. No decision about your membership is made by the system alone. Officers review every application, and any use of points for recognition or eligibility is decided by people, under the Association's rules.
5. Who can see your information
You can see and change most of your own record on your profile page.
Officers see only what their role needs:
- the membership committee and secretariat: member records, KOICA programmes and certificates, and application reviews;
- the Treasurer: payments and receipts, and the member details needed to match them;
- the projects and publications committees: the proposals, documents and publication claims they review;
- activity organisers: registrations for their activities;
- the site manager: messages sent through the contact form;
- a small number of administrators who maintain the system and can see all records.
Other members. Only active and honorary members can use the directory. By default it shows your name and nothing else. Your photo, email, mobile number, location (including your chapter), workplace, KOICA programmes, publications, degree, biography and points stay hidden until you choose to share each one. You can leave the directory at any time.
Whatever your directory settings, other members see your name beside work you take part in: proposals you lead or join, offers of help you make, and publications you author or add. Votes on proposals are shown only as totals.
The public sees no member information, except the names, positions and photographs of the Association's officers on the About page, and the total number of active members.
6. Outside services we rely on
We do not sell, rent or trade personal information. We share it only with the following, and only as far as each needs:
- Hosting: [provider] stores the portal and its data on servers in [country].
- Backup storage: [provider] holds the nightly backups. They are encrypted before they leave our system, so the provider cannot read them.
- Email delivery: [provider] delivers the emails the portal sends: application decisions, replies to your messages, password resets and notices.
- Google Fonts: the website loads its typeface from Google, which receives your device's internet address when a page opens. The app does not.
- Gravatar: if you have not uploaded a photo, the website may ask Gravatar (a service of Automattic Inc.) for a picture linked to your email address. It sends a scrambled code made from your email, never the address itself. This happens only when you, an officer, or a member you allow to see your photo views your profile.
- Authorities: when the law requires it, for example a court order or a lawful request from a government agency.
Google and Automattic are based outside the Philippines, so the limited information described above leaves the country. We do not transfer sensitive personal information to any outside party. [To confirm: we do not share the membership roster with KOICA or anyone else.]
8. How long we keep it
The Data Privacy Act allows personal information to be kept only as long as it is needed for the purpose it was collected for, to establish or defend legal claims, for legitimate business purposes, or as the law provides (Section 11(e); Implementing Rules, Section 19(d)). We do not keep anything indefinitely "in case". Each period below states its basis.
| Record | How long | Basis |
|---|---|---|
| Membership roster: your name, membership number and years of membership | For as long as the Association exists | The Revised Corporation Code (RA 11232), Section 73(b), requires the Association to keep and preserve its list of members. |
| The rest of your member record: profile, address, application, KOICA programmes and certificates | While you are a member, then 5 years after your membership ends. After that it is deleted, leaving only the roster entry above. | RA 10173, Section 11(e), for defending legal claims; the Civil Code, Article 1149, sets 5 years for actions with no other period. |
| Applications that are declined or withdrawn | 1 year after the decision | RA 10173, Section 11(e). Benchmarked against the National Archives' 1-year period for applications.* |
| Payment records, receipts and deposit slips | 10 years after the year the payment was made | The Tax Code, Section 235, as amended by the Ease of Paying Taxes Act (RA 11976), and Revenue Regulations No. 7-2024 require at least 5 years. We keep 10 because Section 222(a) allows an assessment up to 10 years later. Also benchmarked against the National Archives' 10-year period for receipts and vouchers.* |
| Messages sent through the contact form | 2 years after we act on them | RA 10173, Section 11(e). Benchmarked against the National Archives' 2-year period for inquiries and routine correspondence.* |
| Notices in your account | 1 year | RA 10173, Section 11(e). Kept only as long as they remain useful to you. |
| Server records of connections | 90 days; records of sign-ins and security events, 1 year | RA 10173, Sections 11(e) and 20, which require security measures and the ability to investigate incidents. |
| App sign-ins | Until they expire (180 days) or you sign out | RA 10173, Section 11(e). |
| Backups | Up to 12 months, then overwritten | RA 10173, Section 20, which requires recovery from incidents. A record deleted from the portal can remain in a backup until that backup expires. It is never restored except to recover from a failure. |
* The National Archives' General Records Disposition Schedule (RA 9470) binds government offices, not private associations. We use its periods as a benchmark for comparable records, not as a legal requirement on the Association.
Publications and endorsed proposals form part of the Association's record of its members' work and may be kept for longer. If you ask, we will remove your name from them where that does not misrepresent the work of your co-authors or team.
9. How we keep it safe
- All connections to the portal and the app are encrypted.
- Passwords are stored in scrambled form. For the app, the server keeps only a fingerprint of your sign-in key, never the key itself.
- Photos, certificates, receipts and documents are kept apart from the public part of the site. They open only through links that stop working within 2 hours, and only for people allowed to see them.
- Repeated failed sign-in attempts are blocked for a time.
- Officers see only the records their role requires. Access is removed when an officer leaves office.
- Officers who handle personal information are bound to keep it confidential.
- The database and uploaded files are backed up every night, encrypted, to storage outside the system.
No system is perfectly secure. If a breach puts your information at real risk, we will tell you and the National Privacy Commission within 72 hours of learning of it, as the Commission's rules require, and explain what we are doing about it.
10. Your rights
Under Sections 16 to 18 of the Data Privacy Act you have the right to:
- be informed of how your information is used (this policy);
- access the information we hold about you, and learn where it came from, who has received it and when it was last changed;
- correct anything inaccurate or incomplete;
- object to a use of your information, and withdraw your consent;
- have your information blocked, removed or destroyed when it is no longer needed or was processed unlawfully;
- receive a copy of your information in a common electronic format;
- be compensated for damage caused by inaccurate, incomplete or unlawfully used information; and
- complain to the National Privacy Commission.
Things you can do yourself on your profile page or in the app: correct your details, change what the directory shows, leave the directory, and remove KOICA programmes (at least one must remain). You can also withdraw your own proposals, documents and publication claims.
For anything else, including closing your account, getting a copy of your information or withdrawing consent, write to the Data Protection Officer at dpo@philkofa.org.ph. We will reply within 15 working days, and may first need to confirm who you are. If you withdraw consent, we can no longer keep you on the membership roster. We will tell you what we still have to keep, such as payment records, and why.
If you are not satisfied with our answer, you may complain to the National Privacy Commission through privacy.gov.ph.
11. Children, and changes to this policy
Membership is for adults who have completed a KOICA-sponsored programme. The portal and the app are not meant for anyone under 18, and we do not knowingly collect their information.
If we change this policy in a way that affects how your information is used, we will tell members by email and in the portal at least 30 days before the change takes effect, and ask for your consent again where the law requires it. Earlier versions are available from the Data Protection Officer.