Privacy & Data Protection Policy

SmarTern | SDO QC | Operational Deployment Edition

SmarTern Data Privacy Statement

Your privacy matters to us. This Statement explains what personal information SmarTern collects, why we need it, and how we keep it safe. You must read and agree to this before your account is activated.

1. What is SmarTern?

SmarTern is an online platform managed by the Schools Division Office of Quezon City (SDO QC). It handles student internship programs from matching students with offices, tracking attendance and tasks, to issuing completion certificates.

This Statement covers everyone who uses SmarTern: Student Interns, School Coordinators, Office Supervisors, Head Supervisors, and IT Administrators.

2. Who is Responsible for Your Information?

SDO Quezon City is responsible for all personal data collected through SmarTern. They decide how your information is used and make sure it is handled in line with the Data Privacy Act of 2012.

The system was built by the Lumiere Research Group of FEU Institute of Technology, but they have no access to your data once SmarTern is handed over to SDO QC.

3. What Information Do We Collect?

We only collect what is needed to run your internship. This includes:

When You Register:

  • Your full name, age, and date of birth
  • Your mobile number and email address
  • Your school, department, and program
  • Your profile photo (optional)
  • Your username and password (your password is never stored in readable form)

During the Internship:

  • Your time-in and time-out when you scan the Attendance QR Code
  • Your location at the time of scanning (used only to confirm that you are on-site; GPS data is not stored and is used solely for this verification)
  • Tasks assigned to you, whether you completed them, and any supervisor remarks
  • Your skills self-assessment answers submitted during application
  • Your internship placement, certificate, and notification records

For Security Purposes:

  • Login records and the device used (kept for 90 days)
  • Pages you visited during a session (kept for 90 days)

4. What We Will Never Collect

SmarTern does not collect any of the following:

  • Government ID numbers (SSS, PhilHealth, TIN, passport, etc.)
  • Bank details or financial information
  • Fingerprints, facial scans, or other biometric data
  • Medical or health records
  • Political views, religious beliefs, or sexual orientation
  • Data from your social media accounts

5. Why Do We Use Your Information?

We use your information only to run the internship program. This includes:

  • Setting up and managing your account
  • Matching you with an appropriate office for your internship
  • Tracking your attendance and daily tasks
  • Issuing your certificate when you complete the program
  • Keeping the system secure and detecting unusual activity
  • Sending you updates and notifications about your internship
  • Generating summary reports for program management

Note: If you do not provide the required information, SDO QC may not be able to process your internship application.

6. Who Can See Your Information?

Only the people who need to see your information for their role can access it:

  • Student Interns: can only see their own profile, attendance, tasks, and placement
  • School Coordinators: can only see interns from their own school
  • Office Supervisors: can only see interns assigned to their office
  • Head Supervisor: can view overall program summaries and reports
  • IT Administrators: can access system security records but cannot read the content of your task remarks or full assessment answers

7. Do We Share Your Information with Others?

SDO QC will never sell or share your information for commercial purposes. Your data may only be shared in these situations:

  • When required by Philippine law or a government order
  • When required by the National Privacy Commission
  • With technical service providers (such as hosting companies) who help run the system, under a signed agreement that requires them to follow the same privacy standards
  • With your explicit written consent for any other purpose

8. How Do We Keep Your Information Safe?

We use a range of security measures to protect your data, including:

  • All data sent between you and SmarTern is encrypted so it cannot be read by others
  • The database and all backups are stored in an encrypted form
  • Your password is converted into an unreadable code - it is never stored as plain text
  • Admins and head supervisors must verify their identity with a second step when logging in
  • Your session automatically ends after 30 minutes of no activity
  • Your exact GPS location is deleted within 24 hours of each attendance scan
  • Each person can only access data their role allows—no one can view data outside their permission level
  • Every login and data access is recorded in a permanent log

9. How Long Do We Keep Your Information?

We keep your data only for as long as needed:

  • Profile and account details: until your account is closed, plus 1 year
  • Attendance records: until your internship ends, plus 1 year
  • Your exact GPS location: deleted within 24 hours
  • Task records: until your internship ends, plus 1 year
  • Placement records: until your internship ends, plus 3 years
  • Certificate records: kept for at least 5 years, as required by government records rules
  • Login and session records: 90 days, then automatically deleted

10. What About Automated Tools?

SmarTern uses two automated tools to assist with decisions, but neither tool ever makes a final decision on its own. A real person always reviews and confirms any outcome.

  • Matching Tool: suggests which office best fits a student's skills. Coordinators and supervisors review the suggestion before any placement is confirmed.
  • Activity Checker: flags unusual login or scan patterns for an admin to review. A flag only means something looks different from normal—it is not an accusation of wrongdoing.

Note: If your account is flagged, you will receive a notification. You will have 5 business days to send a written explanation. No action can be taken against you until a human review is completed.

11. What Are Your Rights?

Under the Data Privacy Act of 2012, you have the right to:

  • Be informed: know what data we collect and why (this Statement is how we do that)
  • Access your data: request a copy of your information; we will respond within 15 business days
  • Correct mistakes: update wrong or outdated information in your profile settings, or by written request
  • Have your data deleted: ask us to remove your data when it is no longer needed (some records must be kept by law)
  • Object to certain uses: say no to specific uses of your data, such as being included in program reports
  • Take your data elsewhere: request your information in a format you can transfer to another system
  • File a complaint: report a concern to the National Privacy Commission if you believe your rights have been violated

To exercise any of these rights, submit a written request to the Head Supervisor.

12. How Do You Give or Withdraw Consent?

When you register, you will be shown this Statement in full. You must tick a box to confirm you have read and agreed to it before your account is created. Your agreement is saved with a timestamp.

You can withdraw your consent at any time by writing to SDO QC's Data Protection Officer. Your account will be deactivated, but this will not affect your internship record, rendered hours, or certificate.

13. What If I Am Under 18?

SmarTern accounts are only for individuals who are 18 years old or older. SDO QC does not knowingly collect information from minors. If an account is found to belong to someone under 18, it will be suspended and their data will be deleted.

14. What If There Is a Data Breach?

If your personal information is ever exposed without authorization, SDO QC will:

  • Stop the breach and assess what happened within 24 hours
  • Notify affected users within 72 hours if their information is at risk
  • Report to the National Privacy Commission within 72 hours as required by law
  • Document the incident and update security controls to prevent it from happening again

You will always be told what happened, what data was involved, and what steps were taken.

15. What If This Statement Changes?

If SDO QC makes significant changes to this Statement, you will be notified through SmarTern and by email at least 15 days before the changes take effect. Continuing to use SmarTern after the update means you accept the new terms. If you do not agree, you may withdraw your consent.