Effective Date
Effective Date: January 2025
Last Updated: January 2025
1. Introduction
Central Philippine Adventist College ("CPAC," "we," "us," or "our") operates the myVita Mobile Hub mobile application ("App") available on Google Play Store and Apple App Store. We are committed to protecting your privacy and handling your personal information with care and transparency.
App Information:
- App Name: myVita Mobile Hub
- Developer: Central Philippine Adventist College
- Platforms: Android (Google Play Store) and iOS (Apple App Store)
- Privacy Policy URL: https://myvita.cpac.edu.ph/privacy-policy
This Privacy Policy explains:
- What information we collect and why
- How we use and protect your data
- Who we share your data with
- Your rights regarding your information
- How to request data deletion
- How to contact us with questions or concerns
By downloading, installing, or using the myVita Mobile Hub app, you agree to the practices described in this policy.
This policy applies to all users of the myVita Mobile Hub application and is accessible both within the app and at the URL above.
2. App Store Data Safety & Privacy
This section addresses Google Play's Data Safety and Apple App Store's Privacy requirements and provides transparency about how the myVita Mobile Hub handles your data.
2.1 Data Collection Summary
Personal Information Collected:
- ✓ Name and contact information (email, phone)
- ✓ Student identification numbers
- ✓ Photos (profile pictures - optional)
Financial Information Collected:
- ✓ Payment information and transaction history
- ✓ Student account balances
Academic Information Collected:
- ✓ Grades and academic performance
- ✓ Class schedules and enrollment
- ✓ Attendance records
- ✓ Residence hall information
Location Data Collected:
- ✓ Approximate location (for campus services)
- ✓ Precise location (for attendance verification - optional)
2.2 Data Usage and Purpose
All data collected is used for:
- ✓ App functionality (primary purpose)
- ✓ Analytics to improve app performance
- ✓ Security and fraud prevention
- ✓ Account management and authentication
- ✓ Personalization of user experience
- ✓ Communication with users
Data is NOT used for:
- ✗ Advertising or marketing to third parties
- ✗ Selling to data brokers
- ✗ Purposes unrelated to educational services
2.3 Data Sharing
We share data with:
- Firebase (Google) - Push notifications and analytics
- Payment processors - Secure transaction processing
- Cloud storage providers - Encrypted data backup
All data shared with third parties is:
- Encrypted in transit using HTTPS/TLS
- Subject to contractual confidentiality agreements
- Limited to what's necessary for specific services
- Never sold or used for third-party advertising
2.4 Data Security Practices
- ✓ Data encrypted in transit (HTTPS/TLS 1.3)
- ✓ Data encrypted at rest (AES-256)
- ✓ Secure authentication and session management
- ✓ Regular security audits and testing
- ✓ Access controls and monitoring
2.5 User Rights and Data Control
- ✓ You can request data deletion at any time
- ✓ You can access and download your data
- ✓ You can update or correct your information
- ✓ You control notification and location permissions
2.6 Data Deletion
You can request deletion of your account and data by:
- In-app: Settings > Account > Delete Account
- Email: privacy@cpac.edu.ph with subject "Data Deletion Request"
- In-person: Visit the Data Protection Office
Deletion timeline: 30 days for most data (some records retained for legal compliance)
3. Mobile Permissions Explained
The myVita Mobile Hub requests the following permissions on Android and iOS devices. Here's what each permission is used for:
Android Permissions
Required Permissions
INTERNET
Purpose: Connect to CPAC servers to access academic and financial information
Required: Yes - app cannot function without internet
ACCESS_NETWORK_STATE
Purpose: Check internet connectivity to provide appropriate error messages
Required: Yes - ensures smooth user experience
RECEIVE (Firebase Cloud Messaging)
Purpose: Receive push notifications for grades, announcements, and alerts
Required: No - you can disable in device settings
Impact if denied: You won't receive push notifications
Optional Permissions
ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION
Purpose: Verify attendance at campus locations
Required: No - you can deny this permission
Impact if denied: Cannot use location-based attendance; must use manual check-in
Control: Can be managed in device Settings > Apps > myVita > Permissions
CAMERA
Purpose: Take or update profile photo, scan QR codes for campus services
Required: No - you can deny this permission
Impact if denied: Cannot take new profile photos; must upload from gallery
Control: Can be managed in device Settings > Apps > myVita > Permissions
We Do NOT Request These Permissions (Android)
- ✗ Access to contacts
- ✗ Access to SMS or call logs
- ✗ Access to microphone (audio recording)
- ✗ Access to calendar
- ✗ Bluetooth connectivity
- ✗ NFC
- ✗ Background location (location only when app is open)
iOS Permissions
The myVita Mobile Hub requests the following iOS permissions:
Required Permissions
Network Access
Purpose: Connect to CPAC servers to access academic and financial information
Required: Yes - app cannot function without internet
Notifications
Purpose: Receive push notifications for grades, announcements, and alerts
Required: No - you can disable in iOS Settings
Impact if denied: You won't receive push notifications
Control: Can be managed in iOS Settings > Notifications > myVita
Optional Permissions
Location Services
Purpose: Verify attendance at campus locations
Required: No - you can deny this permission
Location Usage: "While Using the App" only (not "Always")
Impact if denied: Cannot use location-based attendance; must use manual check-in
Control: Can be managed in iOS Settings > Privacy & Security > Location Services > myVita
Camera
Purpose: Take or update profile photo, scan QR codes for campus services
Required: No - you can deny this permission
Impact if denied: Cannot take new profile photos; must upload from photo library
Control: Can be managed in iOS Settings > Privacy & Security > Camera > myVita
Photo Library
Purpose: Select photos for profile picture
Required: No - you can deny this permission
Impact if denied: Cannot upload photos from library; must use camera
Control: Can be managed in iOS Settings > Privacy & Security > Photos > myVita
We Do NOT Request These Permissions (iOS)
- ✗ Access to contacts
- ✗ Access to calendars
- ✗ Access to reminders
- ✗ Microphone access
- ✗ Bluetooth
- ✗ Face ID / Touch ID (biometric data)
- ✗ Health data
- ✗ HomeKit
- ✗ Media & Apple Music
- ✗ Motion & Fitness activity
- ✗ Speech recognition
- ✗ Background location (location only when app is in use)
4. Information We Collect
4.1 Personal and Academic Information
Account Information:
- Email address and password (encrypted)
- Student ID number
- Full name
- Contact information (phone number, emergency contacts)
- Profile photo (optional)
Academic Information:
- Course enrollment and class schedules
- Grades and academic performance records
- Attendance records and history
- Academic progress reports
- Faculty feedback and comments
- Residence hall assignments and room information
Financial Information:
- Student account balances
- Transaction history
- Payment records and receipts
- Billing statements
4.2 Device and Technical Information
Device Data:
- Device model and manufacturer
- Operating system type and version
- Unique device identifiers (Android ID, IMEI, iOS IDFA/IDFV)
- Screen resolution and device settings
App Usage Data:
- Features and screens accessed
- Session duration and frequency
- App version and build number
- Interaction patterns within the app
4.3 Location Information
We collect location data only when necessary and with your permission:
Campus Location Services:
- GPS coordinates for attendance verification (when enabled)
- Location-based campus service access
- Emergency response location data
Important Notes:
- Location is collected ONLY when the app is in use (foreground)
- We do NOT track your location in the background
- You can deny location permission and use manual attendance check-in
- You can revoke location access at any time in device settings
5. How We Use Your Information
5.1 To Provide Academic Services
- Display your grades, schedules, and academic records
- Track and report attendance
- Monitor academic progress and performance
- Facilitate communication with faculty and advisors
- Provide personalized academic recommendations
- Generate transcripts and academic reports
- Manage residence hall information and assignments
5.2 To Manage Financial Services
- Display current account balances and financial obligations
- Process and record payments securely
- Generate billing statements and receipts
- Send payment reminders and financial alerts
- Provide financial aid information
5.3 For Communication and Notifications
Send push notifications about:
- Class cancellations or schedule changes
- Grade postings and academic updates
- Payment deadlines and financial alerts
- Campus announcements and events
- Emergency notifications
6. Advertising and Monetization
The myVita Mobile Hub app does NOT:
- Display advertisements
- Collect data for advertising purposes
- Share data with advertising networks
- Use tracking for marketing purposes
- Monetize user data in any way
This is a free educational app provided to CPAC students with no advertising or in-app purchases.
7. Data Storage and Security
7.1 Where We Store Your Data
Local Device Storage:
- Encrypted cache data for offline access
- Session tokens (automatically expire)
- User preferences and settings
CPAC Secure Servers:
- Primary database hosted on secure institutional servers
- Located in the Philippines
- Protected by firewalls and intrusion detection systems
Cloud Services:
- Firebase (Google Cloud Platform) for push notifications and analytics
- Encrypted backup storage
- Compliant with international security standards
7.2 Security Measures We Implement
Data Encryption:
- All data transmitted using HTTPS/TLS 1.3 encryption
- Passwords hashed using industry-standard algorithms (bcrypt)
- Sensitive data encrypted at rest using AES-256
Access Controls:
- Role-based access control (RBAC) system
- Multi-factor authentication for administrative access
- Regular access audits and permission reviews
- Automatic session timeout after 30 minutes of inactivity
Security Monitoring:
- 24/7 security monitoring and threat detection
- Regular security assessments and penetration testing
- Automated vulnerability scanning
- Incident response procedures
7.3 Data Retention Periods
| Data Type |
Retention Period |
Reason |
| Academic Records |
Enrollment period + 7 years |
Regulatory requirement |
| Financial Data |
7 years |
Legal and tax requirements |
| Attendance Records |
5 years |
Institutional policy |
| App Usage Data |
2 years |
Analytics and improvement |
| Log Files |
90 days (30 days for IP addresses) |
Security and troubleshooting |
| Personal Information |
Until account deletion or graduation |
Service provision |
Upon Account Deletion: Most personal data is deleted within 30 days, except where retention is required by law or legitimate institutional needs.
8. Information Sharing and Disclosure
8.1 Internal Sharing Within CPAC
Your information is shared only with authorized CPAC personnel who need it to perform their duties:
- Faculty Members: Access to grades, attendance, and academic information for their courses
- Academic Advisors: View academic progress and course history
- Registrar's Office: Manage enrollment, transcripts, and academic records
- Finance Office: Process payments and manage student accounts
- Student Services: Provide support and campus services
- IT Department: Maintain and support the app infrastructure
All internal staff are bound by confidentiality agreements and data protection policies.
8.2 Third-Party Service Providers
We work with trusted third parties who help us operate the app. They only receive data necessary for their specific services:
Firebase/Google Cloud Platform:
- Purpose: Push notifications, analytics, and cloud storage
- Data Shared: Device tokens, usage analytics, encrypted backups
- Privacy Policy: https://policies.google.com/privacy
- Data Processing Agreement: In place and compliant with GDPR standards
8.3 What We Never Do
- We do not sell your personal information to third parties
- We do not share your data for marketing purposes without consent
- We do not use your academic records for advertising
- We do not provide student lists to external organizations
9. Your Rights and Choices
9.1 Access and Control Your Data
View Your Information:
- Access all personal and academic data through the app
- Request a complete copy of your data in portable format (CSV/PDF)
Update Your Information:
- Edit profile information, contact details, and preferences
- Update profile photo and personal settings
- Request corrections to inaccurate information
9.2 How to Exercise Your Rights
Within the App:
Settings > Privacy & Data
By Email:
privacy@cpac.edu.ph
In Person:
Visit the Data Protection Office at the Administration Building
Response Time: We will respond to requests within 15 business days.
10. Children's Privacy
The myVita Mobile Hub is designed for students enrolled at CPAC. While we accept students of various ages, we take additional precautions for users under 18:
- Parental consent required for students under 18 during enrollment
- Limited data collection for minor students
- Enhanced security measures for accounts of minors
- No marketing or third-party sharing of minors' data
Age Rating:
- Google Play Store: Teen (13+)
- Apple App Store: 12+ (Infrequent/Mild Medical/Treatment Information)
11. International Data Transfers
Primary Storage: Your data is primarily stored on servers in the Philippines.
Cloud Services: Some data may be processed through international cloud services (Firebase/Google Cloud), which may involve transfer to servers outside the Philippines.
Safeguards: We ensure appropriate protections through:
- Standard contractual clauses
- Data processing agreements
- Compliance with EU-US data transfer frameworks where applicable
- Encryption during transit and at rest
12. Cookies and Tracking Technologies
The myVita Mobile Hub app uses the following technologies:
- Session Management: Authentication tokens (stored securely on device), Session cookies (expire after logout or 30 minutes)
- Analytics: Firebase Analytics to understand app usage, Anonymized data collection, Opt-out available in Settings > Privacy > Analytics
We do not use third-party advertising trackers or cookies.
14. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or for other operational reasons.
How We Notify You:
- In-app notification for significant changes
- Email notification to your registered address
- Updated "Last Updated" date at the top of this policy
- Summary of changes posted in the app
Your Continued Use: Using the app after changes are posted constitutes acceptance of the updated policy. If you disagree with changes, you may discontinue use or contact us with concerns.
15. Compliance and Legal Framework
This Privacy Policy complies with:
- Philippine Data Privacy Act of 2012 (Republic Act No. 10173)
- Data Privacy Act Implementing Rules and Regulations
- National Privacy Commission Circulars and Advisories
- Family Educational Rights and Privacy Act (FERPA) principles
- Google Play Store Privacy Requirements
- Google Play Developer Program Policies
- Apple App Store Review Guidelines
- Apple App Store Privacy Requirements
- iOS App Tracking Transparency (ATT) Framework
- Firebase/Google Privacy Standards
- Commission on Higher Education (CHED) regulations
16. Your Consent
By creating an account and using the myVita Mobile Hub app, you acknowledge that you have:
- Read and understood this Privacy Policy
- Agreed to the collection, use, and disclosure of your information as described
- Understood your rights and how to exercise them
- Consented to data processing necessary for app functionality
You may withdraw consent at any time by discontinuing use and requesting account deletion, subject to our legal retention obligations.
Questions or Concerns?
If you have questions about this Privacy Policy, how we handle your data, or wish to exercise your rights, please don't hesitate to contact our Data Protection Officer at privacy@cpac.edu.ph.
Thank you for trusting CPAC with your information.