Privacy Policy
Last updated September 2026
Draft for client and legal review.
This policy explains what personal data CSRS Digital (“we”, “us”) collects through this website and the CSRS Academy member area, why we collect it, and the choices you have.
1. What we collect
We collect only what we need to run your account and your training:
- Account details — your full name, email address, mobile number, and a password. Your password is stored in hashed form; we cannot read it.
- Enrollment information — the course you enrolled in, your enrollment date and reference code, any notes you add, and the payment and access status that our team records.
- Messages you send us — contact form inquiries, support requests, community questions and replies, and reviews.
- Basic technical data — a session cookie that keeps you logged in, and your IP address, which is used briefly to limit spam and repeated login attempts.
We do not collect payment card details. Payments are made directly to CSRS Digital (for example by GCash or bank transfer) outside this website. We do not ask for government ID numbers or other sensitive personal information through this site.
2. Why we collect it
- To create and secure your account.
- To record your enrollment, verify your payment, and grant or revoke course access.
- To answer your inquiries, support requests, and community questions.
- To send service emails about your account and training, such as enrollment received or access granted.
- To publish a review you submitted, after it has been approved (see section 5).
- To keep the website secure and prevent abuse.
We do not use your data for automated decision-making or profiling.
3. Legal basis and consent
We process your personal data on the basis of your consent, which you give when you register, enroll, or send us a message; because it is necessary to provide the training or service you asked for; and, for security measures, on the basis of our legitimate interest in keeping the website safe.
You may withdraw your consent at any time by emailing us. Withdrawing consent does not affect processing that already happened, and it may mean we can no longer provide your account or course access.
4. Who can access your data
- Authorized CSRS Digital administrators, who need it to verify enrollments, grant access, and answer you.
- Service providers that host the website, store its database, and deliver email on our behalf. They may process data only under our instructions.
- Authorities, when we are required to disclose information by law.
We do not sell or rent your personal data. When you apply for a work opportunity through us, we share your application details with the relevant client only as part of that application.
5. Reviews and community posts
Questions and replies you post in the member community are visible to other logged-in members together with your name. Reviews are published on public pages only after a CSRS Digital administrator approves them, and they show a shortened form of your name (for example, “Maria S.”). You can ask us to remove a review or post at any time.
6. How long we keep it
We keep your account and enrollment records for as long as your account is active, and afterwards only for as long as we need them for legitimate business, accounting, or legal purposes. Contact form inquiries are kept for as long as needed to handle your request. When data is no longer needed, we delete or anonymize it. You may ask us to delete your account earlier (see section 8).
7. How we protect it
- Connections to the website are encrypted (HTTPS).
- Passwords are hashed, and sessions use a signed, http-only cookie.
- Member and admin areas are restricted by role, and access is checked on the server.
- Lesson content is only served to members with active access to that course.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the National Privacy Commission as required by law.
8. Your rights under the Data Privacy Act
Under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), you have the right to:
- be informed about how your personal data is processed;
- access the personal data we hold about you;
- object to processing, or withdraw your consent;
- have inaccurate or incomplete data corrected;
- have your data erased or blocked when there is no longer a lawful reason to keep it;
- obtain a copy of your data in a commonly used format (data portability);
- be indemnified for damages caused by inaccurate or unlawfully used data; and
- lodge a complaint with the National Privacy Commission.
You can update your name and mobile number yourself on the My Account page. For any other request, email csrsvaservices@gmail.com. We may need to confirm your identity before acting on a request.
9. Cookies
We use one essential session cookie to keep you logged in. It contains no advertising identifiers and is removed when you log out or when it expires. If we add optional analytics to understand how the site is used, it will be limited to aggregated usage statistics and this policy will be updated first. We do not use advertising cookies.
Course videos may be embedded from a video hosting provider, which can set its own cookies when you play a video.
10. Children
This website is intended for adults. If you are under 18, please use it only with the consent of a parent or guardian.
11. Changes to this policy
We may update this policy as the website changes. The “Last updated” date above shows the latest version. If a change is significant, we will tell registered members by email or through the member dashboard.
12. Contact
Questions or requests about your personal data can be sent to csrsvaservices@gmail.com or through our contact page. See also our Terms & Conditions.
