PLANORATerms of Use · Create Account

Privacy Notice

Effective: July 26, 2026 · Version 2026-08-v1

This is PLANORA's operational privacy notice template. The deploying institution should replace the contact information and have the notice reviewed by its Data Protection Officer or qualified Philippine counsel before public launch.

Who controls your information

PLANORA is operated by the institution or organization shown in the deployed service. That organization acts as the personal information controller for the event-management records it collects. Privacy requests may be sent to privacy@example.edu.

Information we process

Depending on the features used, PLANORA processes account and contact details; school or organization profile data; event registrations and eligibility details; payment amount, method, reference, and proof; QR/RFID attendance records; certificates; messages, support requests, feedback, supplier reviews, emergency reports, device/telemetry records, and security/audit logs. Location or presence information is processed only when an enabled event-safety feature needs it.

Why we process it

We use information to create and secure accounts, determine event eligibility, manage capacity and waitlists, collect and verify organizer-defined payments, issue passes and certificates, record attendance, send operational notices, respond to safety incidents, prevent fraud or duplicate scans, support users, create authorized reports, and maintain system security and accountability.

Who may receive it

Access is limited by role to authorized event organizers, administrators, check-in staff, and service providers needed to host the system, deliver email, store files, or support operations. Information may also be disclosed when required by law or a valid government request. PLANORA does not authorize selling attendee personal information.

Retention and deletion

Operational records are retained only for the event, service, security, audit, accounting, legal, or dispute period configured by the deploying institution. Expired authentication, audit, telemetry, and notification records are subject to scheduled cleanup. Account deletion requests are processed subject to records that must be retained for legal, financial, fraud-prevention, or audit purposes.

Security

PLANORA uses role-based access, secure sessions, CSRF protection, private file storage, upload validation, signed QR credentials, rate limits, audit logs, and encrypted transport when deployed over HTTPS. No system can guarantee absolute security; suspected incidents should be reported immediately to the privacy contact.

Your choices and rights

Subject to applicable law, you may ask to be informed, access your data, correct inaccurate information, object to certain processing, withdraw consent where consent is the basis, request erasure or blocking, request portable data, and raise a complaint. The Philippine National Privacy Commission explains these rights on its official data-subject rights page.

Updates

Material changes will be identified by a new effective date or consent version. When required, PLANORA will request renewed acknowledgement.