RID3780 Online Hub Privacy Policy
Rotary International District 3780 Online Platform
Effective Date: 17 September 2026
Rotary International District 3780 respects the privacy of its members, guests, participants, volunteers, website visitors, and other users of its online services.
This Privacy Policy explains how personal information may be collected, used, stored, disclosed, and protected when you use:
rotarydistrict3780.org;- authorized Rotary Club websites hosted under
*.rotarydistrict3780.org; hub.rotarydistrict3780.org;- Event and Project registration services;
- member Profiles and directories;
- Stories, comments, and other publishing features;
- payment and registration-related services; and
- other authorized District 3780 online services operating within this platform.
Collectively, these services are referred to in this Policy as the “Platform.”
This Policy is intended to support compliance with the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, applicable issuances of the National Privacy Commission of the Philippines, and other applicable privacy requirements.
1. Who We Are
The Platform supports the activities of Rotary International District 3780, its participating Rotary Clubs, District officers, committees, members, Event organizers, Project organizers, and authorized administrators.
Depending on the activity, personal information may be processed by:
- Rotary International District 3780;
- an individual Rotary Club operating a Club website or activity;
- authorized District or Club officers;
- Event or Project organizers;
- approved technical or service providers; and
- payment or communications providers necessary to deliver the requested service.
The entity responsible for a particular Event, Project, Club activity, or registration may also act as the operational custodian of information collected for that activity.
2. Information We May Collect
The information collected depends on how you use the Platform.
2.1 Account Information
When you create or use an account, we may collect:
- full name;
- nickname or preferred display name;
- email address;
- mobile number;
- username;
- account status;
- authentication-related information;
- assigned Platform roles;
- associated Rotary Club;
- account creation and last-access information; and
- administrative or security records associated with your account.
Passwords are handled through the Platform’s authentication system and should not be visible in plain text to ordinary administrators.
2.2 Rotary Member Profile Information
Members may provide information including:
- profile photograph;
- banner or background image;
- nickname;
- full name;
- email address;
- mobile number;
- Rotary International identification number, where supplied;
- Rotary Club;
- member classification;
- Club position;
- District designation;
- Rotary Year;
- year first joining Rotary;
- Rotary experience;
- biography;
- professional or service information; and
- other information voluntarily supplied for a member Profile.
Certain Profile information is required to maintain a complete member account, while other fields are optional.
2.3 Profile Privacy Settings
Some Profile fields may be configured as:
- Public;
- Visible to logged-in users; or
- Private.
The Platform applies these visibility settings when displaying Profile information to ordinary users.
However, authorized administrators may have access to information necessary for:
- account administration;
- member verification;
- District or Club operations;
- security;
- investigation of misuse;
- support; or
- legal and regulatory compliance.
Information specifically designated as operationally necessary, such as Rotary Club or certain current-role information, may not always have individual privacy controls.
2.4 Event Registration Information
When registering for an Event, we may collect:
- registrant name;
- email address;
- mobile number;
- Rotary Club;
- Rotary International identification number;
- organization or affiliation;
- registration type;
- number of attendees;
- attendee names;
- attendee contact details;
- group or team information;
- custom Event registration responses;
- ticket or registration numbers;
- Event allocation information;
- payment status;
- payment reference;
- attendance or check-in status; and
- other information required by the Event organizer.
Some Events may allow guest registration without requiring a Platform account.
2.5 Project Participation Information
When joining or supporting a Project, we may collect:
- registrant or participant name;
- email address;
- mobile number;
- Rotary Club;
- Rotary International identification number;
- organization or group;
- selected participation types;
- volunteer commitments;
- quantities of goods or materials pledged;
- monetary participation amounts;
- attendee or volunteer details;
- responses to custom Project fields;
- payment status;
- transaction references; and
- participation status.
For non-monetary support, information may include descriptions such as:
Volunteers — 5 Rotarians
Rice — 25 kilograms
Medical supplies — 10 boxes
where voluntarily supplied by the participant.
2.6 Stories, Comments, and Published Content
If you submit or publish content, we may process:
- author identity;
- Club affiliation;
- Story title;
- summary;
- article content;
- categories;
- tags;
- Strategic Pillars;
- Areas of Focus;
- publication date;
- photographs;
- images;
- captions;
- comments;
- editorial status;
- review decisions; and
- publication history.
Some of this information may become publicly visible where the content is approved for publication.
2.7 Photographs, Videos, and Media
The Platform may store photographs, illustrations, documents, videos, and other files uploaded by authorized users.
These files may contain:
- identifiable persons;
- Event participants;
- Project beneficiaries;
- Club members;
- volunteers;
- Event venues; or
- other contextual information.
Users uploading media are responsible for ensuring that they have an appropriate basis to upload and publish it.
Special care should be exercised when uploading images involving minors, vulnerable persons, medical situations, or beneficiaries in sensitive circumstances.
2.8 Payment Information
For transactions involving a payment, we may collect or process:
- payment amount;
- payment method;
- invoice or transaction reference;
- gateway reference;
- payment status;
- payment date;
- payer information;
- Event or Project related to the payment;
- manual payment proof;
- bank or wallet transfer evidence;
- uploaded receipt or screenshot;
- administrative verification information; and
- refund, reversal, or cancellation status where applicable.
The Platform may use payment services such as:
- PayFusion;
- IntegraLink;
- bank transfer;
- GCash;
- Maya; or
- other approved payment channels.
For gateway-managed transactions, payment credentials such as card numbers, wallet credentials, passwords, or one-time passwords should normally be handled directly by the payment provider and are not intended to be stored by the Impact3780 Platform.
2.9 QR Codes and Attendance Information
For Events and certain Project activities, the Platform may generate secure QR credentials.
We may process:
- registration number;
- QR credential status;
- QR issuance date;
- check-in status;
- date and time of check-in;
- Event or Project attended;
- administrator who processed the check-in; and
- related audit information.
For paid Event registrations, QR access may depend on confirmed payment status.
Operational QR credentials are not intended for unrestricted public access.
2.10 Club Website Administration Information
When a user requests administrative access to a Club website, we may process:
- name;
- email;
- Platform account;
- Rotary Club;
- Club office or position;
- access request;
- approval or denial status;
- approving administrator; and
- relevant administrative notes.
Club website administrative rights do not arise automatically from changing a Profile’s Club affiliation.
2.11 Technical and Security Information
When you use the Platform, technical information may be automatically collected, including:
- IP address;
- browser type;
- device type;
- operating system;
- referring page;
- visited URLs;
- access date and time;
- login events;
- failed login attempts;
- system errors;
- application logs;
- session information;
- security events; and
- audit records.
This information may be used for security, diagnostics, fraud prevention, system performance, and troubleshooting.
3. How We Use Personal Information
Personal information may be used to:
- create and manage accounts;
- verify users and member affiliations;
- maintain member Profiles;
- provide Club websites;
- process Event registrations;
- manage Project participation;
- process and verify payments;
- issue registration confirmations;
- generate Event tickets and QR Codes;
- conduct check-in;
- send transactional emails;
- administer Club and District activities;
- manage editorial review of Stories;
- publish approved District and Club content;
- maintain District directories;
- support reporting and governance;
- prevent fraud or abuse;
- investigate security incidents;
- provide technical support;
- comply with legal or regulatory requirements; and
- improve Platform functionality and user experience.
4. Basis for Processing
Depending on the circumstances, the Platform may process personal information based on one or more of the following:
- your consent;
- your request to participate in an Event, Project, Club, or Platform service;
- performance of an agreement or requested transaction;
- legitimate operational interests of Rotary International District 3780 or participating Clubs;
- compliance with legal obligations;
- protection of users, systems, or property;
- establishment, exercise, or defense of legal claims; or
- another lawful basis recognized under Philippine law.
Where consent is the appropriate basis, you may withdraw consent subject to legal, contractual, operational, or record-retention requirements.
5. Public Information
Certain information is intended to be publicly visible.
Examples may include:
- nickname;
- Rotary Club;
- Club position;
- District designation;
- public Profile information;
- publicly published Stories;
- author name;
- photographs;
- Club information;
- Project information;
- Event information; and
- public comments where enabled.
Public information may be:
- indexed by search engines;
- shared through social media;
- copied or archived by third parties; or
- accessible outside the Philippines.
Users should therefore carefully consider what information they designate as public.
6. Information Visible Only to Logged-In Users
Some Platform information may be restricted to authenticated users, such as:
- selected member Profile fields;
- internal member directories;
- Club-specific operational information;
- authenticated comments;
- administrative resources; or
- other restricted content.
Logged-in visibility does not mean that information should be treated as unrestricted public information.
Users must not scrape, harvest, export, republish, or use restricted member information for unauthorized solicitation or commercial purposes.
7. Private Information
Information designated as private may be accessible only to:
- the account holder;
- authorized District or Club administrators;
- authorized Event or Project organizers;
- technical administrators with a legitimate need for access; or
- service providers acting under appropriate instructions.
Private information should not be publicly displayed unless required by law or authorized by the data subject.
8. Sharing of Personal Information
We do not sell personal information.
Information may be shared where reasonably necessary with:
- Rotary International District 3780 officers and committees;
- participating Rotary Clubs;
- authorized Club officers;
- Event organizers;
- Project organizers;
- District Public Image personnel;
- Community Service personnel;
- authorized administrators;
- hosting and infrastructure providers;
- email service providers;
- payment gateways;
- technical support providers;
- security providers; and
- government or regulatory authorities where legally required.
Information sharing should be limited to what is reasonably necessary for the relevant purpose.
9. Payment Providers
When you select an external payment gateway, information necessary to process the transaction may be sent to that provider.
This may include:
- payer name;
- email;
- payment amount;
- invoice description;
- transaction reference;
- Event or Project identifier;
- success or failure return URLs; and
- other information required by the provider.
Payment providers process information under their own terms and privacy policies.
The Platform should not expose payment gateway API credentials, secret keys, webhook secrets, or authorization headers to ordinary users.
10. Manual Payment Proof
Where manual payment is permitted, users may upload:
- screenshots;
- deposit slips;
- transfer confirmations;
- bank receipts; or
- other payment evidence.
These files may contain sensitive financial information.
Users should avoid uploading unnecessary information such as:
- account passwords;
- PINs;
- one-time passwords;
- full payment-card numbers;
- unnecessary account balances; or
- unrelated transactions.
Manual payment evidence should be accessible only to personnel authorized to verify or reconcile payments.
11. Cookies and Similar Technologies
The Platform may use cookies or similar technologies to:
- maintain user sessions;
- authenticate users;
- remember settings;
- protect forms;
- support website functionality;
- improve performance;
- prevent abuse; and
- understand general Platform usage.
Some third-party services embedded in the Platform may also set cookies according to their own policies.
Users may configure their browser to restrict certain cookies, although doing so may prevent some Platform functions from working correctly.
12. Analytics
The Platform may use privacy-conscious analytics or technical monitoring tools to understand:
- page visits;
- system performance;
- traffic patterns;
- errors;
- device types; and
- feature usage.
Where third-party analytics services are used, appropriate privacy and security configurations should be applied.
13. Email Communications
We may send transactional messages relating to:
- account activity;
- Event registration;
- Project participation;
- payment status;
- Story review;
- administrative access;
- QR Code availability;
- Event reminders;
- Club website administration;
- security; and
- service notices.
Transactional communications may be necessary to provide the service you requested and may not always be treated as optional marketing messages.
Promotional or non-essential communications should be managed separately where appropriate.
14. Children and Youth Participants
Rotary activities may involve Interact members, Rotaractors, students, youth participants, families, or other younger persons.
Where personal information relating to minors is collected, the relevant Event, Project, Club, or District organizer should apply appropriate consent, safeguarding, access, and disclosure procedures.
The Platform should avoid publicly displaying unnecessary information concerning minors.
Photographs, contact information, identification information, medical information, or other sensitive information concerning minors should be handled with particular care.
15. Sensitive Personal Information
The Platform generally seeks to avoid collecting unnecessary sensitive personal information.
However, certain activities may require information that could be considered sensitive under Philippine law.
Where such information is necessary, access should be restricted and additional safeguards applied.
Users should not enter medical, financial, government identification, or other sensitive information into open-text fields unless it is genuinely necessary for the applicable activity.
16. Data Accuracy
Users are encouraged to keep their information accurate and current.
Members may update information through their Profile where available.
Certain administrative records may require correction by an authorized District or Club administrator.
Users should contact the Platform if they believe information about them is materially inaccurate.
17. Data Retention
Personal information is retained only for as long as reasonably necessary for:
- the purpose for which it was collected;
- District or Club operational requirements;
- accounting and financial reconciliation;
- Event or Project records;
- audit requirements;
- security;
- dispute resolution;
- legal obligations; or
- legitimate historical and archival purposes.
Different types of data may have different retention periods.
For example:
- active member Profile information may be retained while the account remains active;
- Event registrations may be retained for administrative and reporting purposes;
- payment records may require longer retention for financial or audit purposes;
- security logs may be retained for a defined security period;
- published Stories may remain part of the historical District archive.
Where information is no longer reasonably required, it may be deleted, anonymized, or archived with appropriately restricted access.
18. Account Deactivation and Historical Records
Account deactivation does not necessarily result in immediate deletion of every record associated with the account.
The District may need to retain information relating to:
- past Event participation;
- Project participation;
- financial transactions;
- published Stories;
- administrative approvals;
- security events;
- legal obligations; or
- historical Rotary records.
Where practical, personal information may be minimized or anonymized while retaining legitimate institutional records.
19. Information Security
The Platform uses reasonable organizational and technical measures intended to protect personal information.
Measures may include:
- role-based access controls;
- authenticated administration;
- permission checks;
- protected administrative pages;
- server-side authorization;
- secure password handling;
- HTTPS encryption;
- controlled access to payment evidence;
- randomized access credentials;
- QR credential protection;
- audit logs;
- file access restrictions;
- server security controls;
- backups; and
- software security updates.
No system can guarantee absolute security.
Users should protect their own account credentials and immediately report suspected unauthorized access.
20. Data Breaches and Security Incidents
If a personal data breach or security incident occurs, the District may take steps including:
- containing the incident;
- investigating its scope;
- securing affected systems;
- preserving relevant evidence;
- evaluating potential harm;
- notifying affected persons where required; and
- reporting the incident to the National Privacy Commission or other authorities where legally required.
21. Cross-Border Processing
Some infrastructure or service providers may process data outside the Philippines.
Where international processing occurs, reasonable measures should be taken to ensure that personal information remains appropriately protected and is processed consistently with applicable privacy requirements.
22. Third-Party Websites
The Platform may link to websites operated by:
- Rotary International;
- Rotary Clubs;
- partner organizations;
- payment providers;
- social media platforms;
- Event venues;
- service providers; or
- other third parties.
This Privacy Policy does not govern independent third-party websites.
Users should review the privacy policies of external services before providing personal information.
23. Your Privacy Rights
Subject to applicable law, data subjects may have rights including the right to:
- be informed about the processing of their personal information;
- access personal information held about them;
- object to certain processing;
- correct inaccurate or incomplete information;
- request deletion or blocking where legally appropriate;
- withdraw consent where processing depends on consent;
- request data portability where applicable;
- file a complaint;
- seek damages where provided by law; and
- exercise other rights recognized under the Data Privacy Act.
Some requests may be subject to exceptions where information must be retained for legal, contractual, security, audit, or legitimate organizational purposes.
24. Requests to Access, Correct, or Delete Information
Users may first update available information through:
My Profile
Where information cannot be changed directly, a request may be submitted to the District.
For privacy and security purposes, we may require reasonable verification of identity before acting on a request.
Requests should identify:
- the person making the request;
- the information concerned;
- the requested action; and
- sufficient information to allow the District to locate the relevant record.
25. Administrative and Audit Access
Authorized personnel may access records where reasonably required for:
- Event administration;
- Project administration;
- payment verification;
- Club website support;
- member verification;
- content moderation;
- Public Image review;
- District governance;
- system troubleshooting;
- fraud prevention;
- information security; or
- compliance.
Administrative access should be based on assigned roles and legitimate operational responsibilities.
26. Club Responsibilities
Rotary Clubs using District-hosted websites and Platform tools are expected to:
- limit access to authorized officers;
- protect member information;
- avoid downloading or sharing member information unnecessarily;
- respect member privacy settings;
- obtain appropriate permission for photographs and content;
- avoid publishing unnecessary sensitive information;
- promptly remove access from former administrators when appropriate; and
- report suspected privacy or security incidents.
Club website access does not authorize unrestricted use of District-wide member information.
27. Public Image and Editorial Review
Stories submitted to Club or District Public Image workflows may be accessible to authorized reviewers.
Reviewers may access information needed to:
- verify authorship;
- evaluate content;
- check classification and metadata;
- request revisions;
- approve publication;
- determine District-wide publication; or
- consider inclusion in District publications.
Editorial decisions and review history may be recorded for governance and audit purposes.
28. Automated Decisions
The Platform may automatically perform operational actions such as:
- calculating Profile completion;
- determining whether payment is required;
- expiring unpaid registrations;
- releasing reserved Event capacity;
- issuing or revoking QR eligibility;
- calculating Event capacity;
- filtering directory results; or
- displaying content according to permissions.
These functions primarily implement predetermined operational rules rather than making legal or similarly significant decisions about individuals.
Where a user believes an automated system action is incorrect, the matter may be referred to an authorized administrator for review.
29. Changes to This Privacy Policy
The Platform will continue to evolve.
This Privacy Policy may be updated to reflect:
- new Platform functionality;
- new payment or communications services;
- changes in privacy law;
- changes in Rotary policies;
- security improvements; or
- operational changes.
The current version will be published on:
Where appropriate, material changes may also be communicated through the Platform or by email.
30. Contact and Privacy Concerns
Questions, correction requests, privacy concerns, or reports of suspected misuse of personal information may be directed to:
Rotary International District 3780
Website: https://rotarydistrict3780.org
District Information and Communications / Platform Support
Email: dico@rotarydistrict3780.org
Where a matter concerns a particular Rotary Club, Event, or Project, the request may also be referred to the responsible Club officer, organizer, or authorized District administrator.
Complaints concerning data privacy may also be submitted to the National Privacy Commission of the Philippines in accordance with applicable law.
