Skip to content
THE COLLEGE OF MAASIN · NISI DOMINUS FRUSTRAOfficial website
The College of Maasin Official Website
www.cm.edu.ph
Privacy notice

Privacy Notice

How the College handles personal information when you use this service. Please read this notice with the Cookie Policy and the relevant College policies.

Controller: The College of Maasin, Inc.Last reviewed: 11 October 2026Applies to: www.cm.edu.ph
This notice is specific to The College of Maasin Official Website. Separate College systems may have their own workflows and record types. The College must keep this notice aligned with actual production processing and its approved records schedule.

1. Who is responsible

The College of Maasin, Inc. is the data controller for the institutional purposes described in this notice, subject to confirmation of the specific roles of any contracted service provider. This service supports the following activity:

The official website provides institutional information, program/admission content, announcements, and links to online services. The public site identifies The College of Maasin, Inc. and publishes its physical address, telephone number, and general email. The public HTML does not provide a complete source-level inventory of CMS plugins, cookies, embedded media, or analytics.

2. Information processed

Depending on the feature you use and your role, categories may include:

Depending on pages and features used: basic server request logs (such as requested URL, timestamp, client/browser details and IP address), search or contact form input where a form is offered, details users voluntarily send through published contact channels, admin/editor account data, security records, and data sent to third parties when users follow external links or interact with embedded content. Confirm this against the production CMS and hosting configuration.

The College should not collect fields or device data that are unnecessary for the stated purpose. Sensitive personal information or information relating to minors must receive the additional protection required by law and applicable College policy.

3. Purposes and lawful basis

The service may process information for these purposes:

For each processing purpose, the College must document the appropriate lawful basis under the Data Privacy Act and other applicable laws. Depending on the activity, this may include compliance with a legal obligation, a service or contract, legitimate interests after a necessity/balancing assessment, consent where genuinely appropriate, or another basis provided by law. This notice does not state that all school processing is based on consent, and a notice dismissal is not consent to unrelated processing.

4. Who may receive information

Access may be provided to authorized College offices and personnel whose duties require it, and to approved technology, hosting, support, backup, or security providers acting under appropriate instructions and confidentiality/security safeguards. Information may also be disclosed where required or authorized by law, to protect rights and system security, or as otherwise permitted by the applicable lawful basis. Access should be role-based and logged where appropriate. The College does not sell personal information.

Where the service links to another College system or an external website, the destination may have its own controller, processing purposes, and privacy notice. Review that notice separately. The College should document cross-border processing or hosting locations and use safeguards required by law.

5. Retention and secure disposal

The website/communications owner must document the hosting log retention period, form/inquiry retention, CMS audit retention, and any separate records retained by linked services. Adopt the College-approved records schedule and applicable legal requirements; do not assume that the web host’s default log rotation is an approved institutional policy.

Retain information only as long as necessary for the declared purpose, applicable legal or academic requirements, and the establishment, exercise, or defense of legal claims. When retention is no longer justified, the College should securely delete, destroy, or irreversibly anonymize records under its approved schedule, subject to lawful holds.

6. Security and incident handling

The College should use access controls, role-based permissions, appropriate authentication, secure connections, audit trails, backups, staff confidentiality measures, and incident-response procedures proportionate to the information and the risks. Access should be limited to personnel and service providers who need it for an authorized purpose. No system can promise absolute security; suspected misuse or exposure should be reported promptly through official College channels so it can be assessed and handled under the applicable breach-response rules.

7. Your privacy rights

Subject to the Data Privacy Act of 2012 (Republic Act No. 10173), its implementing rules, applicable lawful bases, and the facts of a request, data subjects may exercise rights including the right to be informed, access, correction, object, erasure or blocking where legally available, damages, file a complaint with the National Privacy Commission, and data portability where applicable. A person may withdraw consent where processing is based on consent, without affecting processing already lawfully carried out or processing supported by another lawful basis.

Send requests through the College’s official contact channels above. The College may need to verify identity, clarify the requested records, consider other people’s rights, and apply legal or institutional recordkeeping obligations. The relevant office should respond within the period required by applicable law and policy.

8. Cookies, browser storage, and automated processing

The Cookie Policy describes known browser storage. This notice does not promise that every decision made by the service is automated or that every record is anonymous. The College should document any automated decision or profiling that has legal or similarly significant effects, as well as the available review route, before enabling it.

9. Updates to this notice

The College may revise this notice when its service, providers, purposes, or legal obligations change. The published copy should display its review date and make material changes easy to find. Do not treat mere dismissal of a notice as consent to a new purpose that requires consent.

10. Contact the College

Data controller: The College of Maasin, Inc., R. Kangleon Street, Tunga-Tunga, Maasin City, Southern Leyte 6600, Philippines.

General contact: College contact page, telephone (053) 570 8671, or collegeofmaasin1925@yahoo.com. Please identify your request as a data privacy matter and ask to be referred to the College’s designated Data Protection Officer (DPO).

Before the College approves this draft, the system owner should add the current DPO’s direct, monitored contact information and confirm that the official contact routes can receive and route data-subject requests.

This notice is designed around the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and applicable National Privacy Commission issuances. Read the National Privacy Commission’s Data Privacy Act resource and Implementing Rules and Regulations. This page is not a substitute for the College’s processing inventory, Data Protection Officer review, or legal assessment.