How Notipa's website and demo handle personal data, and how self-hosted deployments work under the Philippines' Data Privacy Act of 2012.
Last updated: July 25, 2026
On this page
This policy covers two things Notipa (the project) directly controls: the notipa.org marketing website, and the public app.notipa.org demo instance used to try the software before installing it. It does not cover data processed by a school, NGO, or ministry of education running their own self-hosted copy of Notipa — see section 3 for why that's a separate matter.
Notipa is developed and published from the Philippines, and this policy is written primarily to comply with the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, as administered by the National Privacy Commission (NPC). Where a self-hosted deployment operates in another jurisdiction, the school or organization running it is responsible for complying with whatever data protection law applies there — for example the EU/UK GDPR, India's Digital Personal Data Protection Act, or the United States' COPPA for services directed at children under 13.
Notipa is free, open-source software distributed under the MIT licence. When a school or organization downloads it and runs their own instance with Docker, that school or organization — not the Notipa project — is the personal information controller for any data entered into that instance: student names, guardian contact details, announcements, homework, fee notices, and permission slip responses. The Notipa project never receives, stores, or has access to data held on a self-hosted instance. Each deploying school is responsible for publishing its own privacy notice to its families, appointing a Data Protection Officer if RA 10173 or local law requires one, and registering with the NPC or equivalent authority if its processing meets the registration threshold.
This website is a static informational page. It does not use tracking cookies, analytics scripts, or advertising pixels, and it does not ask visitors to create an account or submit a form. The only personal data that may pass through this site is:
The public demo at app.notipa.org uses pre-created sample accounts and sample student/guardian data so visitors can try the software. Do not enter real personal information into the demo — it runs on shared infrastructure, is reset from time to time, and is not intended to store anything real. Any data you type into the demo is used solely to render the demo session and may be cleared without notice.
Notipa's core purpose is school-to-parent communication, which means self-hosted instances necessarily process information about children (such as a student's name and class). Under RA 10173, this can qualify as sensitive personal information requiring a higher standard of care. Because each self-hosted instance is controlled by the deploying school, that school is responsible for obtaining any required parental consent, limiting collection to what's needed to run the service, and restricting access to teachers/administrators on a need-to-know basis — all of which the software supports through its role-based permissions. The notipa.org website and app.notipa.org demo do not knowingly collect real information about identifiable children.
If you are a data subject whose personal information is processed by a Notipa instance, the Data Privacy Act gives you the right to: be informed that your data is being processed; access your data; object to or withhold consent for processing; correct inaccurate data; erasure or blocking of unlawfully processed data; data portability; and to be indemnified for damages from a data breach. For a self-hosted instance, these rights are exercised against the school or organization running it, as the controller. For this website or the demo, you can exercise these rights by contacting us using the details in section 11.
This website is served statically with no server-side data processing beyond standard access logs. The Notipa application itself ships with authentication, role-based access control enforced at the data layer (not just hidden in the UI), and encouragement to run instances behind HTTPS. Security of a given self-hosted instance — server hardening, backups, TLS, credential management — is the responsibility of whoever deploys it.
Server access logs for this website are retained only as long as the hosting provider's default logging policy requires for security purposes. Demo data on app.notipa.org is retained only until the next reset of the shared demo instance. Data retention for a self-hosted instance is controlled entirely by the school or organization running it.
This policy may be updated as the website or demo instance changes. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be reflected here before they take effect.
Questions about this policy, or requests relating to your rights under RA 10173 regarding this website or the app.notipa.org demo, can be sent to theovanstratum1953@gmail.com. If your question concerns data held in a specific school's self-hosted instance, please contact that school directly — the Notipa project has no access to that data.