Effective date: August 8, 2026 · Policy version: 40.40.1
Western Philippines University is responsible for personal data processed through the WPU Library Research Hub, AIRA, and Messenger Helpdesk. This notice applies to public portal visitors, researchers, library clients, Messenger users, and people identified in scholarly metadata.
We follow the Philippine Data Privacy Act of 2012 and its implementing rules, including the principles of transparency, legitimate purpose, proportionality, data minimization, security, and accountability. Public availability of information does not, by itself, remove privacy responsibilities.
1. Personal data and research metadata we process
- Accounts and identity: name, institutional identifier, email address, role, campus, college, department, course or program, year level, affiliation, and account/security records.
- Library requests and support: request details, contact information, messages, feedback, problem reports, conversation status, and correspondence.
- Messenger: Page-scoped sender ID, profile details made available by Meta, messages, selected options, timestamps, and delivery or response status.
- Portal use and security: searches, resource and feature interactions, access purpose, client type, consent or preference state, session identifiers, date and time, referring page, browser/user-agent data, and an IP address or privacy-preserving hash when required for security, rate limiting, support, or approved analytics.
- Private research workspaces: saved records, notes, tags, literature-review decisions, tool inputs and outputs, citations, research questions, and project activity.
- Scholarly metadata: title, author or contributor name, ORCID or other identifier, affiliation, abstract, keywords, publication date, publisher, journal or repository, DOI/ISBN/ISSN, language, format, license or rights statement, provenance, and source URL.
Please do not enter passwords, government identifiers, health records, confidential participant data, unpublished sensitive research, or other sensitive personal information into public research tools or AIRA.
2. Where the data comes from
Data may come directly from you; from authorized WPU records and library staff; from Meta/Facebook Messenger; from approved institutional repositories and OAI-PMH feeds; or from scholarly services and source pages such as Crossref, OpenAlex, Semantic Scholar, PubMed, ORCID, Unpaywall, DOAJ, CORE, publishers, and repositories when configured and permitted.
Repository connectors are intended to collect bibliographic metadata and available abstracts through approved interfaces. The Research Hub does not treat repository presence as proof that full text is open access and does not mirror external PDFs by default.
3. Why we process data and the applicable basis
The basis depends on the activity. We process data only when an applicable legal ground exists, which may include your consent; steps necessary to provide a requested service or manage an account; compliance with a legal or institutional obligation; protection of lawful interests and system security; or performance of the University's educational, research, and library functions.
- Provide discovery, citation, research-workspace, helpdesk, Messenger, and resource-access services.
- Authenticate users, protect accounts, prevent abuse, investigate incidents, and maintain reliable systems.
- Improve metadata quality, deduplicate records, verify identifiers, and preserve provenance and withdrawal status.
- Produce authorized library statistics, service evaluation, collection-development reports, and accreditation evidence.
- Generate research-support drafts and recommendations that a user must independently review.
Consent is not used as a blanket justification for every activity. Where optional analytics rely on a preference, you may change that preference through the portal. Essential security, transaction, and service records may still be processed when another lawful ground applies.
4. Metadata, privacy, and copyright boundary
Author names, ORCID records, affiliations, and other metadata linked to an identifiable person can be personal information even when displayed publicly. We limit collection to metadata relevant to discovery, citation, provenance, and research support and provide a correction, objection, and removal-request channel.
Mere facts or data may not be protected by copyright, but abstracts, descriptions, images, database selection or arrangement, and other expressive content may be protected. The Research Hub must honor source licenses, repository policies, API terms, rights statements, attribution requirements, withdrawal notices, and access controls. Educational or research purpose does not automatically make every reuse fair use. Where permission is unclear, the system should keep a metadata-only record, use only an authorized or appropriately limited excerpt, and link to the original source.
5. Sharing, service providers, and international processing
We do not sell personal data. Data may be disclosed only as necessary to authorized WPU personnel; contracted hosting, email, security, analytics, or technical providers; Meta when Messenger is used; approved scholarly metadata services; a configured AI provider when an AI-assisted feature is deliberately used; or public authorities when required by law.
A configured external AI service may receive the prompt and the minimum metadata or evidence needed to answer. Private workspace notes and full documents should not be sent unless the feature clearly says so and the University has approved that processing. Providers may operate outside the Philippines; WPU must use appropriate contractual, security, and accountability safeguards for such processing.
6. Automated and AI-assisted processing
AIRA, semantic search, ranking, citation, and research tools may classify, summarize, recommend, or generate drafts. They can be incomplete or inaccurate and do not make decisions that produce legal effects about a person. Users remain responsible for checking original sources, citations, research ethics, and academic-integrity requirements. Material decisions affecting a person must include appropriate human review.
7. Cookies, local storage, and analytics choices
The service may use session cookies or browser storage for sign-in, security, preferences, pending actions, and continuity between pages. Optional usage analytics should respect the portal preference and supported browser privacy signals such as Do Not Track or Global Privacy Control. Disabling optional analytics does not disable records necessary to deliver a requested service, secure the system, or document a transaction.
8. Retention and deletion
We keep personal data only for a documented period that is necessary for its stated purpose, legal obligations, security, dispute handling, and approved institutional records management. The system includes configurable purge controls with operational defaults of 90 days for guest research context, 180 days for research events, and 365 days for portal analytics; WPU must formally approve the applicable schedule and run the purge process before relying on those periods.
Account, library-transaction, Messenger, incident, and research-workspace records may require different approved periods. Deletion requests remain subject to lawful retention requirements, pending investigations, and records that must be preserved. See the Data Deletion page.
9. Security and personal data breaches
WPU applies reasonable organizational, physical, and technical measures based on the nature and risk of the data, including role-based access, confidentiality, input validation, logging, backups, secure configuration, and incident response. No online system can promise absolute security.
Security incidents are documented and assessed. When a breach meets the legal notification threshold, WPU will notify the National Privacy Commission and affected data subjects within the period required by applicable rules.
10. Your rights
Subject to applicable law, you may request to be informed, access your personal data, correct inaccurate data, object to or restrict certain processing, withdraw consent for consent-based processing, request erasure or blocking, obtain portable data where applicable, file a complaint, and seek damages for unlawful processing. Identity and authority may be verified before a request is completed.
If you are an author or contributor and believe a harvested record is inaccurate, withdrawn, unlawfully exposed, or inconsistent with its source rights, send the record URL, source repository, requested correction, and supporting information to the contact below.
11. Contact and complaints
For privacy questions, rights requests, metadata corrections, or escalation to the University's designated Data Protection Officer:
Western Philippines University University Library
Email: library@wpu.edu.ph
You may also raise a concern with the Philippine National Privacy Commission. Contact details and complaint procedures are available at privacy.gov.ph.
The Library will route DPO escalations to the University's designated privacy office. For Meta App Settings, use the full public URL of this page as the Privacy Policy URL.