The Human Resource Management Office ("HRMO," "we," "us," or "our") of the Local Government of Jasaan operates the HRMO Jasaan Management System (the "System"), an internal application used to manage employee records, daily time records (DTR), leave, and payroll for its personnel. This Privacy Policy explains what information the System collects, how it is used, who it is shared with, and the rights you have over it, consistent with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations.
This Policy applies to all users of the System, including HR/Admin personnel and employees who hold an account, as well as prospective account holders who submit an account request through the onboarding page. It does not apply to third-party sites that may be linked from the System.
1. Information We Collect
1.1 Identity and Account Information
- Full name, employee record number, date of birth, and position, used to verify your identity when you request an account.
- Email address and, if provided, phone number.
- Password and authentication credentials, which are created and managed through Firebase Authentication — we never see or store your password in plain text.
- Account role (e.g., Admin/HR or Employee) and account status (pending, active, rejected).
- Profile photo, if you upload one.
1.2 Employment and Payroll Information
- Department, category, employment type, assigned work schedule, and compensation rate.
- Statutory and other deduction figures administered by HR (e.g., GSIS, PhilHealth, Pag-IBIG/HDMF, withholding tax, SSS, and salary/emergency loans) used to compute payroll.
1.3 Attendance and Time Records
Time-in/time-out records are captured either through biometric devices installed at office premises or through Daily Time Record (DTR) files uploaded by HR. When a biometric device is used, the device itself performs the fingerprint or facial match — the System does not receive or store fingerprint images or biometric templates. Only the resulting punch record (device ID, your employee identifier, timestamp, and in/out status) is transmitted to and stored in the System to compute rendered hours, tardiness, and payroll.
1.4 Leave Records
- Leave requests, leave type, dates, reason, and approval history (including department-head and HR/Admin action).
- Leave balances and, where applicable, leave ledger documents (e.g., CSC Form No. 6) uploaded by HR.
1.5 Notifications and Communications
- Push notification subscription details, if you enable browser/device notifications, used solely to deliver in-app alerts (e.g., leave status, account approval).
- Transactional emails (e.g., account verification, approval/rejection notices, password reset) sent via our email delivery provider.
1.6 Technical and Security Information
- Session data stored in a secure, httpOnly cookie used to keep you signed in and enforce role-based access.
- Basic technical data such as browser/device type, needed for the System to function and to detect and prevent automated abuse (e.g., bot-verification challenges on sensitive forms).
2. How We Use Your Information
We use the information described above to:
- Verify your identity and process account requests submitted through onboarding.
- Operate your account, authenticate sign-ins, and enforce role-based access to System features.
- Compute attendance, tardiness, leave credits, and payroll in accordance with applicable civil service and compensation rules.
- Process, route, and record leave requests and approvals.
- Send account, approval, and other transactional notifications relevant to your employment.
- Maintain the security, integrity, and audit trail of HR and payroll records.
- Comply with legal, regulatory, and government reporting obligations.
We do not use your personal information for advertising, and we do not sell your data.
3. Legal Basis for Processing
We process personal information under the Data Privacy Act on the basis of: (a) your consent when you submit an account request; (b) the necessity of processing to fulfill the employer-employee relationship and administer compensation and benefits; and (c) compliance with legal obligations imposed on the LGU as a government employer (e.g., remittance of GSIS, PhilHealth, and Pag-IBIG contributions, and civil service leave rules).
4. Who We Share Information With
We do not disclose your personal information to third parties for their own marketing purposes. Information is shared only as follows:
- Authorized HRMO/Admin personnel, on a need-to-know basis, to process payroll, leave, and account requests.
- Department heads, limited to leave-request information for employees within their department, for endorsement purposes.
- Service providers that help operate the System under contractual confidentiality obligations, namely: Firebase (Google) for authentication and, if used, file storage; an email delivery provider for transactional email; Cloudflare Turnstile for bot/abuse protection on public forms; and push notification services (e.g., your browser vendor's push service) to deliver notifications you opt into.
- Government agencies (e.g., GSIS, PhilHealth, Pag-IBIG, BIR) where required for statutory remittance or reporting.
- Where required by law, court order, or to protect the rights, property, or safety of the LGU, its employees, or the public.
5. Data Retention
We retain personnel, payroll, attendance, and leave records for as long as your employment subsists and thereafter for the period required by the National Archives of the Philippines, the Commission on Audit, and other applicable government records retention rules. Account credentials are retained for as long as your account remains active and are deactivated upon separation, unless a longer retention period is required by law.
6. Data Security
We apply organizational and technical safeguards appropriate to the sensitivity of the data we hold, including: encrypted transmission (HTTPS), secure httpOnly session cookies, role-based access controls that limit visibility of records under Admin-restricted areas, and password management delegated to Firebase Authentication rather than stored by us directly. No system can guarantee absolute security; if you believe your account has been compromised, contact HRMO immediately.
7. Your Rights
Under the Data Privacy Act of 2012, you have the right to:
- Be informed that your personal data is being processed, as described in this Policy.
- Access your personal, employment, and payroll records held in the System.
- Request correction of inaccurate or outdated information.
- Object to or request the restriction of processing, subject to our legal and statutory obligations as an employer.
- Request erasure or blocking of your data where processing is no longer necessary or was unlawfully obtained, subject to records-retention laws.
- Lodge a complaint with the National Privacy Commission (NPC) if you believe your rights have been violated.
To exercise any of these rights, contact HRMO using the details in Section 10 below.
8. Cookies
The System uses a single essential session cookie to keep you signed in and to enforce route access based on your role. We do not use third-party advertising or tracking cookies. Disabling cookies in your browser will prevent you from signing in.
9. Children's Data
The System is intended solely for use by LGU Jasaan personnel and account applicants of legal working age. It is not directed to, and we do not knowingly collect information from, children.
10. Contact Us
For questions about this Privacy Policy or to exercise your data privacy rights, contact the HRMO Data Protection Officer:
- Office: Human Resource Management Office, Local Government of Jasaan
- Email: [email protected] (please update to the designated DPO email)
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the System or in applicable law. Material changes will be posted on this page with a revised effective date.