How the Archiving and Records Management System collects, uses, protects, and retains personal information.
Effective August 17, 2026
The Municipality of Bay, Laguna operates the Archiving and Records Management System (LGU-ARMS) to manage the official records of the Sangguniang Bayan and its barangays. This policy explains what personal information the system handles and the rights you have over it under Republic Act No. 10173, the Data Privacy Act of 2012. It covers both the web portal and the mobile application, which share one database.
The Municipality of Bay, Laguna is the Personal Information Controller (PIC) for all data in LGU-ARMS. It decides what is collected and why, and is accountable for its protection. Questions, requests, and complaints may be directed to the Data Protection Officer listed in Section 11.
LGU-ARMS is a closed, internal system. It is not open to the general public. This policy covers:
We collect only what the system needs to operate. We do not collect financial account details, biometrics, or location beyond the barangay/municipality you are assigned to.
| Data | Why it is collected |
|---|---|
| Full name (first, middle, last) | Identifies you in records, audit trails, and document signatories |
| Email address | Login credential; delivery of approvals, temporary passwords, and password resets |
| Mobile / phone number | Optional. Official contact within the LGU |
| Department, position, role | Determines what you are permitted to see and do |
| Barangay, municipality, province | Scopes your access to your own barangay's records |
| Profile picture | Optional. Display only |
| Password | Stored only as a bcrypt hash. The plain password is never stored and cannot be recovered by anyone, including administrators |
| Data | Why it is collected |
|---|---|
| IP address | Detecting unauthorized access and abuse |
| Browser / device identifier | Same as above; distinguishing sessions |
| Login timestamps & failed attempts | Account lockout after repeated failures |
| Audit trail | A permanent record of who created, edited, approved, or deleted each record, and when. Required for the integrity of official documents |
| Session & mobile auth tokens | Keeping you signed in; expire automatically |
| Password reset codes (OTP) | Verifying a reset request; short-lived and single-use |
You cannot opt out of the audit trail. It exists so that official records cannot be altered without attribution, and it is a control expected of a government records system.
Minutes, agendas, attendance, committee membership, comments, resolutions, ordinances, and executive orders are stored as entered by the secretariat. These are public records under the Local Government Code and typically contain the names, positions, and statements of officials acting in their official capacity.
When a QR code on an official document is scanned, the system records the time of the scan and a verification count. No account is required and the scanner is not identified personally. The verification page discloses only whether the document is authentic — never its contents.
Processing is carried out under Sections 12 and 13 of RA 10173, specifically:
We do not use your information for advertising, profiling, or automated decision-making that produces legal effects, and we do not sell or rent it to anyone.
LGU-ARMS includes optional AI features: drafting assistance for minutes, and natural-language
search across documents. These are powered by the Google Gemini API
(model gemini-2.5-flash), operated by Google LLC.
If you prefer not to use these features, simply do not invoke them. Every AI action is optional and manually triggered; nothing is sent to Google in the background.
Your information stays inside the LGU except in the following cases:
| Category | Retention period |
|---|---|
| Official records | Permanent. Legislative records are archived indefinitely under RA 7160 and National Archives retention rules |
| Active accounts | For as long as the account is active, plus the period required for audit |
| Deactivated accounts | Retained rather than deleted, so that past entries in official records remain correctly attributed |
| Audit trail | Permanent — it is part of the integrity of the records it describes |
| Rejected registrations | Disposed of once the applicant has been notified and any appeal period has lapsed |
| Sessions, tokens, OTPs | Expire automatically; OTPs within minutes, sessions within one hour of inactivity |
No system is perfectly secure. In the event of a personal data breach posing a real risk to affected persons, the LGU will notify the National Privacy Commission and the affected data subjects within 72 hours of knowledge of the breach, as required by law.
Section 16 of RA 10173 gives you the right to:
To exercise any of these, contact the Data Protection Officer below. We will respond within a reasonable period, ordinarily 15 working days. We may ask you to verify your identity first.
The web portal sets a session cookie to keep you signed in, and an optional "remember this device" cookie if you choose it. These are strictly functional — there are no advertising, analytics, or third-party tracking cookies anywhere in the system.
The mobile application stores an authentication token on your device so you do not have to sign in repeatedly. Signing out deletes it. Uninstalling the app removes all locally stored data from your device; it does not delete your account.
For any privacy concern, request, or complaint:
We may update this policy as the system changes or as the law requires. The effective date at the top of this page always reflects the current version. Material changes — for example, a new category of data or a new third-party processor — will be announced in the system, and continued use after the effective date constitutes acknowledgement.
LGU-ARMS is intended solely for authorized government personnel. It is not directed at, and accounts are not issued to, persons under 18 years of age.