Privacy

Privacy Policy

Last updated: July 22, 2026

This Privacy Policy explains how the CSU-Gonzaga Consultation System (the “System”), operated by Cagayan State University – Gonzaga Campus (the “University”, “we”, “us”), collects, uses, and protects your personal information when you use the platform to schedule and manage academic consultations. By using the System, you agree to the practices described here. We handle personal data in line with the Data Privacy Act of 2012 (Republic Act No. 10173) of the Philippines.

1. Information we collect

  • Account information — your name, University ID number, role (student, faculty, or administrator), college/department and academic program, year level (for students), designation (for faculty), and, if you provide them, a mobile number, an alternative email, and a profile photo.
  • Authentication data — your password, stored only as a securely hashed value and never in plain text.
  • Consultation records — the faculty and student involved, the date and time, the stated purpose and specific concern, the venue, the action taken or resolution, time spent, status, and the applicable semester and school year.
  • Faculty availability — the consultation schedules and time slots faculty publish.
  • Usage and technical data — your notifications, and an audit log of key actions performed in the System.
  • Access and device data — when you sign in, we record the date and time, your IP address, an approximate location (country and city derived from that IP address), and device information (browser, operating system, and device type, taken from your browser’s user-agent). This is used for security and accountability only. The location is approximate and may not reflect where you actually are — a VPN, proxy, or shared campus network can change it.

2. How we use your information

  • To create and manage your account and verify your identity.
  • To let students book consultations and faculty manage schedules, approve, decline, reschedule, and complete sessions.
  • To send notifications and reminders (in-app and, where enabled, real-time) about your appointments and relevant announcements.
  • To maintain official University consultation records and generate institutional reports.
  • To secure the platform by detecting and preventing unauthorized access, abuse, and fraud.
  • To let authorized administrators review recent sign-in activity — including approximate location and device — so unusual or suspicious access to an account can be identified.

3. Notifications

The System sends in-app (“bell”) notifications and, where the real-time service is enabled, instant alerts about appointment approvals, declines, reschedule suggestions, newly opened slots relevant to your program and year level, day-before reminders, and University announcements.

4. How we share information

  • Within the University — your consultation details are visible to the specific faculty member and student involved, and to authorized administrators for oversight and record-keeping. Your sign-in records (time, IP address, approximate location, and device) are visible only to authorized administrators, not to other students or faculty.
  • Service providers — the System is hosted on third-party cloud infrastructure and may use a real-time messaging service to deliver instant notifications. These providers process data only to operate the platform on our behalf.
  • Legal and institutional requirements — we may disclose information where required by law or University policy.
  • We do not sell your personal information or use it for advertising.

5. How we protect your information

We apply safeguards appropriate to an academic system, including:

  • Password hashing (bcrypt) — passwords are never stored or displayed in plain text.
  • Role-based access control, so users only see what their role permits.
  • Account lockout and network-level rate limiting to resist brute-force sign-in attempts.
  • A mandatory password change for first-time and administrator-issued temporary credentials.
  • Session timeouts that sign you out after a period of inactivity.
  • Cross-site request forgery (CSRF) protection and an audit trail of sensitive actions.
  • Optional encryption of the connection to the database.

No system can be guaranteed completely secure, but we work continuously to safeguard your data.

6. Data retention

We retain your account and consultation records for as long as needed to provide the service and to meet the University’s academic record-keeping requirements. Short-lived security data, such as sign-in attempt records used for rate limiting, is automatically pruned. Audit logs — including sign-in records with IP address, approximate location, and device — are retained for security and accountability.

7. Your rights

Consistent with the Data Privacy Act, you may access and update your profile information within the System’s account settings, request correction of inaccurate data, and raise concerns about how your data is handled. Password resets are performed by an administrator. To exercise these rights or ask questions, contact us using the details below.

8. Cookies and sessions

The System uses a secure session cookie to keep you signed in. Your session expires after a period of inactivity, after which you will need to sign in again. We do not use advertising or third-party tracking cookies.

9. Eligibility

The System is intended for enrolled students, faculty, and authorized staff of Cagayan State University – Gonzaga Campus. Accounts are created and managed by the University.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by the “Last updated” date above and, where appropriate, communicated through the System.

11. Contact us

For privacy questions or requests, please contact the system administrator or your department head, Cagayan State University – Gonzaga Campus.