Privacy Notice
Last updated August 2026
In one sentence: your school runs its records on ParentLINK; we process those records only for the school, only to run the school, and a child’s data is never used for anything else — no advertising, no selling, no profiling.
Who is responsible for your data
Under the Data Privacy Act of 2012 (RA 10173), the school your family is enrolled in is the personal information controller: it decides what is collected and why. ParentLINK (the operator of this system) is the school’s personal information processor: we store and process records on the school’s documented instructions under a Data Processing Agreement, and for no purpose of our own.
Questions and requests about your data go first to your school’s Data Protection Officer (ask the school office). ParentLINK’s own DPO can be reached through the school, and assists with any request the school passes on.
What is collected
- Learner records — name, LRN, birth date, sex, address, and the school records the law requires: enrollment, attendance, grades, and the DepEd school forms built from them.
- Guardian records — name, relationship, mobile number and/or email, and the link to your children, which is what authorises what you see in the app.
- Financial records — assessments, payments, receipts, and payment proofs you submit (reference numbers and screenshots).
- Communication — announcements, and messages between families and school staff.
- Technical records — sign-ins, device registrations for notifications, and an audit trail of who did what, kept because school records demand accountability.
Why, and on what basis
Processing is done to operate the school: enrollment and records the school is legally required to keep (legal obligation under DepEd regulation), billing and receipts (contract), communication with families and the safety of learners (legitimate interest of a school, and the school’s official mandate). Optional processing — a learner’s photo, for example — is consented separately and never bundled with enrollment.
Children’s data
The data subject of most records here is a child. Rights over a learner’s data are exercised by the parent or legal guardian. Messages between families and school staff are retained for up to seven years as a child-safeguarding measure — there is deliberately no private, unrecorded channel between a staff member and a family, and both sides are told so in the product. Consistent with RA 11930, children’s data is handled with data residency and transfer safeguards set out below.
Retention
- Permanent academic records (Form 137 / SF10 and the grades behind them) are retained as DepEd regulations require — permanently, transferred with the learner.
- Financial records are retained per BIR and accounting rules.
- Family–staff messages: up to seven years (safeguarding).
- Everything else is time-bounded under the school’s retention schedule and purged when its period lapses.
Who else touches the data
Sub-processors are limited to what the service needs to run: cloud hosting, push notification delivery, SMS delivery, and payment processing — each under contract, listed publicly, and updated when the list changes. Data is hosted in the Asia-Pacific region; any cross-border storage is disclosed here and in the school’s Data Processing Agreement. A Philippines-only deployment is available to schools that require it. Nobody’s data is sold, rented, or used for advertising — ever.
Security
Every school’s records are isolated from every other school’s at the database layer. Access is role-based and logged; reading a permanent record or reviewing a family’s messages is itself a recorded act. Passwords are stored only as modern one-way hashes; sessions are short-lived and revocable; uploads are content-checked. Security measures follow NPC Circular 16-01, and breach response follows NPC Circular 16-03 — if a breach ever affects you, the school will notify you and the NPC as the rules require.
Your rights
Under RA 10173 you may ask to access, correct, or object to processing of your data, ask for a copy, or complain. Route requests through your school’s DPO; the school and ParentLINK resolve them through a recorded data-subject-request workflow. You may also complain directly to the National Privacy Commission (privacy.gov.ph).
Changes
When this notice changes materially, the date above changes and schools are told, so they can tell their families. Continued use after a change does not waive any right the law gives you.