RA 10173 Compliant

Privacy Policy & Notice

v2026.1

1. Information We Collect

Convention App processes personal and sensitive personal information in compliance with the National Privacy Commission (NPC) mandates:

A. Personal & Professional Profile

Full name, contact details, email address, mailing address, PRC license number, PRC expiry, PTR records, primary specialty, and medical society affiliations.

B. Operational & Event Scan Data

Continuing Medical Education (CME) unit logs, convention attendance QR code scans, society membership status validations, and portal access timestamps.

C. Technical & Biometric Identifiers

Cryptographic device installation UUID, IP address, device telemetry, and local OS biometric authentication handshakes (no raw biometric templates are stored on our servers).

2. Operational Purposes

  • Validation and synchronization of medical society membership rosters.
  • Automated accreditation tracking and issuance of Continuing Medical Education (CME) unit credits.
  • Secure token handoffs (SSO) to verified external society web portals and convention webviews.
  • Essential security broadcasts, account recovery notifications, and statutory compliance updates.

3. Data Sharing & Token Handoffs

We do not sell, rent, or commercialize your information. Data is shared exclusively with accredited medical societies, official event organizers, and regulatory bodies (e.g., PRC) strictly for CME certification and membership fulfillment.

4. Data Protection Officer (DPO)

Under RA 10173, you retain the right to access, rectify, object to, or request data portability. For inquiries or data subject requests, contact our DPO:

DPO Office Email: [email protected]

Account & Data Erasure Request

Initiating a deletion request will immediately soft-delete your account and start a statutory holding window. During this period, the request is reviewed by our DPO to verify compliance with mandatory medical CME log retention laws before final, irreversible purging.