HANDA-TAYO logo

HANDA-TAYO

Hazard Analytics and Notification for Disaster Awareness – Targeted Analytics for Yielding Outcomes

A Disaster Preparedness and Hazard Management System

Terms, Privacy and Location Use Notice
Version 2026-08-v1 · Effective August 2026 · Republic of the Philippines
Important: By creating a Viewer account and checking the acceptance box, you acknowledge these Terms, the Privacy Notice, and the Location Use Notice. HANDA-TAYO may then request and process device location for the disaster-management purposes described below. Browser and operating-system permission controls remain authoritative and cannot be bypassed by the website.

1. System identification and purpose

HANDA-TAYO is a web-based disaster preparedness and hazard management system developed as an academic thesis project under the College of Computer Studies of Kolehiyo ng Lungsod ng Lipa. It is intended to support hazard monitoring, emergency reporting, resident preparedness information, geographic mapping, weather awareness, notification dissemination, analytics, reporting, and disaster-response coordination.

2. Thesis researchers and current system operators

The current Thesis Researchers and System Operators are Albert Lopez, Carlo Sueno, Ashley Nicole Dimayuga, Chrizel Mae Villanueva, and Ma. Katrina Rayos. To the extent that these researchers determine the purposes and means of personal-data processing in the present thesis deployment, they act as the current Personal Information Controllers. This designation must be reviewed if operational control is later transferred to or formally shared with another organization.

3. Academic institution and beneficiary

Academic Institution: Kolehiyo ng Lungsod ng Lipa, College of Computer Studies, Barangay Marawoy, Lipa City, Batangas, Philippines.

Beneficiary: Barangay Balintawak, Lipa City, Batangas, Philippines. Barangay Balintawak is the intended beneficiary and implementation community. Beneficiary status alone does not automatically make the Barangay the Personal Information Controller unless a formal governance arrangement establishes that role.

4. Barangay Balintawak contact

Barangay Captain: Hon. Joselito S. “Lito” Pagcaliwangan
Office: Barangay Hall of Barangay Balintawak
Telephone: (043) 756 9468
Email: barangaybalintawak2024@gmail.com

5. System support and privacy contact

HANDA-TAYO Supporthandatayo@gmail.com
Email only
Data Protection OfficerAlbert Lopez
handatayo@gmail.com
Kolehiyo ng Lungsod ng Lipa – Main Campus

Users must never send passwords, one-time passwords, Security Codes, authenticator secrets, setup QR codes, access tokens, private encryption keys, or password-reset tokens through email.

6. Acceptance of the Terms

Viewer account registration requires affirmative acceptance of the current Terms, Privacy Notice, and Location Use Notice. Acceptance may be recorded electronically together with the registration or account identifier, applicable notice version, date and time, and security metadata reasonably necessary for accountability. The acceptance checkbox must not be preselected.

7. Location authorization

By accepting the registration notice, a Viewer expressly authorizes HANDA-TAYO to request and process available device location for hazard awareness, nearby-hazard identification, emergency assistance, hazard reporting, mapping, geographic validation, evacuation information, resident-location functions, incident coordination, and related disaster-preparedness and public-safety purposes.

Acceptance of these Terms does not itself grant technical browser permission. The browser or operating system independently decides whether the website may access geolocation. If permission is already granted, HANDA-TAYO may use location automatically. If the browser has not yet decided, it may display its own native permission prompt. If permission is denied, HANDA-TAYO must respect that denial.

Staff, Administrator, and Super Administrator accounts may automatically request available device location for authorized operational functions without an additional HANDA-TAYO confirmation dialog. This does not authorize undisclosed surveillance or unrelated tracking.

8. Withdrawal or disabling of location access

A user may disable browser-level geolocation through browser or device settings. Where precise location processing is based on consent, privacy concerns or withdrawal requests may be sent to handatayo@gmail.com. Withdrawal does not invalidate lawful processing that occurred before withdrawal and does not prevent processing supported by another lawful basis where applicable.

9. Privacy principles

HANDA-TAYO shall process personal information in accordance with the principles of transparency, legitimate purpose, proportionality, data minimization, accuracy, security, accountability, and appropriate retention. Personal information must not be collected merely because the System is technically capable of collecting it.

10. Personal information that may be processed

Depending on the feature and role, HANDA-TAYO may process identity and account information, names, email addresses, contact numbers, residential addresses, Barangay and Purok information, geographic coordinates, resident profiles, emergency contacts, preparedness information, vulnerability-related information, hazard reports, emergency-assistance requests, notification records, authentication and session data, audit records, and security-event information.

11. Sensitive and restricted information

Information concerning health, disability, vulnerability, emergency circumstances, precise location, authentication, or other protected categories must receive heightened protection. Access must be restricted according to role, purpose, area authority, operational need, and applicable security controls.

12. Lawful processing

Not every HANDA-TAYO processing activity is justified solely by consent. Depending on the actual deployment and responsible organization, a lawful basis may include consent, legal obligations, protection of life or health, public order and safety, an authorized public function, or another basis recognized by Philippine law. The System must document the basis actually applicable to each processing purpose.

13. Account registration and accuracy

Users must provide truthful, current, and reasonably accurate registration information. Users must not impersonate another person, use another person’s information without authority, fabricate addresses or geographic assignments, create malicious or fraudulent accounts, or circumvent registration security controls.

14. Account security

Users are responsible for protecting usernames, passwords, Security Codes, MFA credentials, and recovery information. Privileged users may be required to perform multi-factor authentication or recent reauthentication before high-risk actions. Suspected account compromise should be reported promptly to handatayo@gmail.com.

15. User roles and authority

Viewer: may access permitted preparedness information, maintain permitted resident information, submit hazard observations or emergency reports, and use other Viewer functions.

Staff: may perform authorized operational functions within assigned geographic and functional scope.

Administrator: may perform authorized administrative and review operations within assigned authority.

Super Administrator: may exercise broader system or citywide authority where expressly authorized. No role is exempt from privacy, security, accountability, audit, and legitimate-purpose requirements.

16. Geographic and area-based access

HANDA-TAYO may restrict access by Barangay, Purok, subdivision, role, operational assignment, or other geographic scope. Users must not circumvent geographic restrictions or use access privileges to view unrelated personal information.

17. Hazard reporting

Hazard reports must be submitted in good faith. Reports may contain hazard type, severity, location, Barangay, Purok, coordinates, description, location accuracy, and other information relevant to assessment. Knowingly false, fabricated, malicious, deliberately misleading, or prank reports are prohibited.

18. Viewer reports and official hazard listings

A Viewer-submitted hazard report is ordinarily treated as a pending report until reviewed by an authorized Staff member, Administrator, or Super Administrator. Submission alone does not make the report an official hazard record. Review may include validation of location, Barangay, Purok, hazard type, severity, description, duplication, and supporting information.

19. Emergency-assistance reporting

Emergency-reporting features must be used only in good faith. False emergency requests, prank reports, fabricated locations, or deliberately misleading information intended to waste emergency resources are prohibited. HANDA-TAYO is an assistance and coordination platform and does not guarantee rescue or response within a particular time.

20. Resident, emergency-contact, vulnerability and preparedness information

Resident information may be used for legitimate disaster-preparedness, response, resident-service, and public-safety purposes. Emergency-contact information must not be repurposed for unrelated marketing or harassment. Vulnerability information must be accessible only to users with a legitimate need and appropriate authority. General analytics should use aggregated or de-identified information where practical.

21. Notifications

HANDA-TAYO may provide hazard warnings, emergency announcements, evacuation information, shelter information, road-closure notices, service interruptions, preparedness guidance, drills, all-clear messages, and other authorized public-safety communications through supported channels such as the web, SMS, or email. Delivery cannot be guaranteed because providers, networks, devices, or recipient information may fail or be unavailable.

22. Weather information

Weather information may come from external providers and may be normalized or analyzed by HANDA-TAYO. Forecasts and model-derived results are inherently uncertain. Unless clearly identified otherwise, HANDA-TAYO analytical output must not be represented as an official PAGASA warning.

23. Analytics, automated processing and AI-assisted functions

HANDA-TAYO may generate analytics, rules-based assessments, statistical results, or AI-assisted recommendations for preparedness and decision support. Such output must not be presented as guaranteed fact when it is predictive or probabilistic. Human review should remain available for high-impact operational decisions.

24. Maps and GIS

Maps, coordinates, Barangay or Purok boundaries, hazard markers, evacuation centers, infrastructure, and other geographic datasets may be inaccurate or outdated. Device positioning may also contain error. Official geographic records should be used when exact jurisdictional boundaries matter.

25. Cookies, sessions and technical data

HANDA-TAYO may use cookies or equivalent mechanisms necessary for authentication, session management, CSRF protection, security, and user preferences. Essential security mechanisms may be required for the System to function securely.

26. Audit and security logging

The System may maintain logs for security, accountability, troubleshooting, incident response, legal compliance, and operational integrity. Logs may record account identifiers, timestamps, actions, affected resources, outcomes, request identifiers, authorization decisions, and administrative events. Authentication secrets must not be intentionally logged.

27. Data-subject rights

Subject to applicable Philippine law, identity verification, and lawful exceptions, data subjects may exercise applicable rights relating to being informed, access, correction, objection, withdrawal of consent, erasure or blocking where applicable, portability where applicable, damages, and complaints. Requests may be sent to the DPO at handatayo@gmail.com.

28. Identity verification for privacy requests

Before disclosing, correcting, exporting, deleting, or otherwise acting on protected information, HANDA-TAYO may reasonably verify the requester’s identity and authority. Verification should be proportionate to the sensitivity of the requested information.

29. Retention and disposal

Personal information must not be retained indefinitely merely because storage is available. Retention must be justified by operational, legal, security, audit, academic, disaster-management, or other legitimate requirements. When retention is no longer justified, information should be securely deleted, anonymized, or otherwise disposed of under approved procedures.

30. Backups

Deletion from the active database may not immediately remove information from secured backups. Backup copies may remain until expiration under the approved backup-retention schedule and must remain restricted from ordinary operational access.

31. Data sharing and external providers

Personal information may only be shared with authorized recipients and for lawful purposes. External hosting, mapping, weather, communication, anti-automation, monitoring, or infrastructure providers may be used when appropriate safeguards and contractual responsibilities are in place. Use of third-party providers does not remove the accountability of the responsible Personal Information Controller.

32. Security measures

HANDA-TAYO should maintain reasonable and appropriate organizational, physical, and technical safeguards including strong authentication, multi-factor authentication, role-based access control, area scoping, least privilege, encryption, secure communications, audit logging, backups, vulnerability management, monitoring, and incident-response procedures.

33. Security incidents and personal-data breaches

Suspected unauthorized access, disclosure, credential compromise, malware, or other security incidents must be promptly assessed. Where applicable law or National Privacy Commission requirements mandate notification, the responsible controller must follow the required breach-management process.

34. Acceptable use

HANDA-TAYO may only be used for lawful and authorized purposes. Users must respect assigned roles, permissions, area restrictions, access purposes, and operational policies.

35. Prohibited conduct

Unauthorized access, credential theft, fraudulent resident information, false hazards or emergencies, unauthorized bulk extraction, audit manipulation, malicious software, service interference, unauthorized penetration testing, bypassing security controls, harassment, discrimination, unauthorized surveillance, or misuse of privileged access are prohibited.

36. Privileged-user responsibilities

Staff, Administrators, and Super Administrators must use elevated privileges only for legitimate authorized duties, protect confidential resident and emergency information, follow area restrictions, preserve auditability, comply with reauthentication requirements, and avoid unrelated access to personal information.

37. Confidentiality

Non-public personal, operational, security-sensitive, or emergency information obtained through HANDA-TAYO must not be copied, published, exported, photographed, forwarded, or disclosed without appropriate authority or lawful justification.

38. Intellectual property and user-submitted content

Ownership of HANDA-TAYO source code, documentation, research outputs, branding, and related materials remains subject to applicable law, academic policy, contracts, and third-party licenses. By submitting hazard or emergency information, users authorize the System to store, validate, display, analyze, transmit, and archive that content as reasonably necessary for legitimate HANDA-TAYO functions.

39. System availability and external-service limitations

HANDA-TAYO cannot guarantee uninterrupted operation. Maintenance, power failure, Internet disruption, provider outages, cloud failures, security incidents, disasters, or other circumstances may affect availability. Critical safety decisions should not rely exclusively on a single electronic service or notification channel.

40. Accuracy and decision-support disclaimer

Information from users, administrators, geographic datasets, weather providers, automated processing, or third parties may contain errors, delays, omissions, or uncertainty. HANDA-TAYO assists human decision-making and emergency coordination but does not replace competent public authorities, official emergency channels, or professional judgment.

41. Limitation of responsibility

To the extent permitted by Philippine law, the Thesis Researchers and System Operators should not be responsible for harm caused exclusively by circumstances reasonably beyond their control, including unavailable telecommunications, external-provider failures, or knowingly inaccurate user submissions. Nothing in these Terms excludes a legal obligation or statutory responsibility that cannot lawfully be excluded.

42. Research and academic use

Appropriately protected or anonymized information may be used for legitimate research, testing, evaluation, or academic reporting where lawfully permitted. Personally identifiable information must not be placed in thesis publications, demonstrations, screenshots, or presentations unless properly authorized.

43. Beneficiary and government-authority limitation

Barangay Balintawak is the beneficiary and intended implementation community. Unless a formal adoption, agreement, authorization, data-sharing arrangement, or other governance instrument establishes otherwise, HANDA-TAYO’s thesis status must not be represented as meaning that every System output constitutes an official Barangay or government decision.

44. Suspension and termination

Accounts may be restricted, suspended, or terminated where reasonably necessary for security, fraud prevention, abuse, unauthorized access, malicious reporting, privilege misuse, investigation, or other legitimate operational reasons. Termination does not automatically require immediate deletion of records that remain lawfully necessary for audit, security, legal, or disaster-management purposes.

45. Changes to these Terms

HANDA-TAYO may revise these Terms when System functionality, privacy practices, legal requirements, security requirements, ownership, beneficiary arrangements, or processing purposes materially change. Each version should have a distinct identifier and effective date. Where new consent is legally required, the System should request affirmative reacceptance.

46. Governing law

These Terms are governed by applicable laws of the Republic of the Philippines, including where applicable Republic Act No. 10173 (Data Privacy Act of 2012), Republic Act No. 8792 (Electronic Commerce Act of 2000), Republic Act No. 10175 (Cybercrime Prevention Act of 2012), Republic Act No. 10121 (Philippine Disaster Risk Reduction and Management Act of 2010), Republic Act No. 8293 (Intellectual Property Code), their implementing rules, and applicable National Privacy Commission issuances.

47. Complaints and dispute channels

Technical concerns may be sent to handatayo@gmail.com. Privacy concerns may be sent to the DPO at handatayo@gmail.com. Barangay administrative concerns may be sent to barangaybalintawak2024@gmail.com. Nothing in these Terms prevents a person from seeking lawful remedies before the National Privacy Commission, courts, government agencies, or other competent authorities.

48. Severability and no waiver

If any provision is determined to be invalid or unenforceable, the remaining provisions continue to apply to the greatest extent permitted by law. Failure to immediately enforce a provision does not automatically waive that provision or any legal right.

49. Viewer registration acknowledgment

Registration acknowledgment: “I have read and agree to the HANDA-TAYO Terms and Conditions, Privacy Notice and Consent, and Location Use Notice. I understand the purposes for which my personal information is processed and authorize HANDA-TAYO to request and process my device location for hazard awareness, emergency assistance, hazard reporting, mapping, evacuation information, nearby-hazard identification, and related disaster-preparedness and emergency-management functions. I understand that my browser or device independently controls whether technical access to my location is granted.”

50. Final acknowledgment

Acceptance of these Terms does not authorize HANDA-TAYO to bypass browser security, perform undisclosed surveillance, process personal information for unrelated purposes, or disregard Philippine privacy law. Users remain responsible for complying with applicable authorized-use and security obligations.

Return to HANDA-TAYO