Privacy Policy
Last Updated: March 31, 2026
1. Introduction
OneIBP respects privacy and is committed to protecting personal data in accordance with applicable law.
This Privacy Policy explains how OneIBP collects, receives, uses, stores, shares, protects, and otherwise processes personal data in connection with the Service.
2. Service Model and Scope
OneIBP is a chapter-contracted, member-access-enabled platform.
The Service is primarily provided to subscribing chapters, offices, or organizations. Those subscribing entities may authorize chapter administrators, officers, staff, and, where enabled, members to access and use the Service.
Accordingly, personal data may be processed:
- directly from chapter administrators, officers, staff, members, and other users of the Service;
- indirectly through records, files, and information submitted or managed by a subscribing chapter;
- through the operation, support, security, and improvement of the Service.
Depending on the context, OneIBP may act:
- for certain data relating to our own operations, service administration, support, billing, security, analytics, and communications; and/or
- as a service provider processing data in connection with services provided to a subscribing chapter, office, or organization.
3. Personal Data We May Collect or Receive
We may collect or receive the following categories of personal data, depending on how the Service is used:
A. Account and identity information
- full name
- email address
- mobile number
- username
- password credentials or authentication identifiers
- role, office, or affiliation
- chapter or organization association
B. Profile and membership-related information
- member profile details
- bar-related or chapter-related details
- address and contact information
- chapter membership information
- professional details and records provided by the user or chapter
- identification details where required for legitimate platform purposes
C. Transaction and billing information
- payment status and history
- billing records
- receipts, invoice references, or official receipt references
- subscription and service order information
D. Event and certificate information
- event registrations
- attendance records
- participation details
- certificate issuance and certificate history
E. Legal-aid / activity records
- participation logs
- activity records
- internal compliance or tracking information
- supporting documents and uploads
F. Technical and device information
- IP address
- device identifiers
- browser and operating system information
- app version
- log files and diagnostic data
- usage and interaction data
G. Communications and support information
- messages sent through the Service
- support inquiries
- feedback, complaints, and requests
We may also process other information reasonably necessary for the lawful and legitimate operation of the Service.
4. Sources of Personal Data
We may collect or receive personal data:
- directly from you when you create or use an account;
- from a subscribing chapter, office, organization, or authorized administrator;
- from records, documents, files, and content uploaded into the Service;
- from your use of the Service;
- from connected service providers or integrations that you or the subscribing chapter authorize.
5. Purposes of Processing
We may process personal data for the following purposes:
- to create and manage accounts and access rights;
- to authenticate users and secure access to the Service;
- to provide platform features and requested services;
- to manage member records, events, certificates, communications, billing, and workflows;
- to generate dashboards, reports, exports, summaries, and internal records;
- to provide customer support and respond to inquiries;
- to send service-related messages, alerts, and notices;
- to monitor, maintain, improve, and secure the Service;
- to investigate misuse, fraud, incidents, or violations of law or policy;
- to comply with legal obligations, lawful orders, and regulatory requirements;
- to enforce our Terms of Service and other lawful agreements.
6. Data Sharing and Disclosure
We may share personal data only where reasonably necessary and subject to appropriate safeguards, including with:
- the relevant chapter, organization, officers, administrators, and authorized users;
- service providers who help us operate the Service, such as hosting, storage, messaging, analytics, authentication, and payment providers;
- professional advisers, auditors, and insurers, where necessary;
- regulators, courts, government agencies, or law enforcement where disclosure is required by law, lawful order, or legal process;
- another party in connection with a merger, reorganization, acquisition, financing, or sale of assets, subject to lawful safeguards.
We do not sell personal data.
7. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected or received, for legitimate business and security needs, for backup and dispute resolution purposes, or as required or permitted by law.
Retention periods may vary depending on the nature of the data, the role of the relevant chapter or user, contractual arrangements, legal requirements, and operational needs.
When personal data is no longer required, we will take reasonable steps to securely delete, anonymize, block, or dispose of it, subject to legal and operational constraints.
8. Account Deletion
Members may request deletion of their account at any time through the account settings in the mobile application.
Upon receiving a deletion request:
- your account will be deactivated immediately and a 30-day grace period will begin;
- during the grace period, you may cancel the deletion request by logging in and following the on-screen instructions;
- after the grace period expires, the deletion will be processed permanently and cannot be reversed.
What is deleted
Upon completion of account deletion, the following data will be permanently removed:
- your authentication credentials and login access;
- your contact information (email addresses, phone numbers, addresses) stored in the Service;
- your notification preferences and device tokens;
- your profile photographs and uploaded personal documents.
What is retained in anonymized form
Certain records are retained in anonymized form after account deletion to comply with legal, regulatory, tax, and audit obligations. This means your name and personal identifiers are replaced with a generic placeholder, but the underlying records are preserved. These include:
- financial records (invoices, payments, receipts, and related transaction history) — retained as required by Philippine tax and accounting regulations;
- compliance records (MCLE credits, continuing education history, legal-aid tracking records) — retained for regulatory compliance purposes;
- certificate records (issuance history) — retained for verification and audit purposes;
- event attendance records — retained in anonymized form;
- audit logs — retained for security and integrity purposes.
After anonymization, these records can no longer be linked back to you as an individual.
Important notice
Deleting your OneIBP account affects only your access to and personal data within the OneIBP platform. It does not affect your membership status with the Integrated Bar of the Philippines, your standing with any chapter, or any records maintained by official government or bar systems.
9. Data Subject Requests
Subject to applicable law and reasonable verification of identity, you may request access to, correction of, or other action regarding your personal data, as applicable.
Where personal data is processed in connection with a subscribing chapter's use of the Service, we may coordinate with, refer, or redirect the request to the relevant chapter, office, or organization, as appropriate.
10. Security Measures
We implement reasonable and appropriate organizational, physical, and technical measures designed to protect personal data against accidental or unlawful destruction, alteration, disclosure, misuse, and unauthorized access.
However, no method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect personal data, we cannot guarantee absolute security.
11. Cookies, Analytics, and Similar Technologies
We may use cookies, device storage, analytics tools, crash reports, and similar technologies to support login sessions, preferences, security, diagnostics, performance monitoring, and product improvement.
Where required by law or appropriate to the nature of the technology, we will seek consent or provide suitable controls.
12. Children and Minors
The Service is generally intended for adults and authorized users of chapters and organizations. We do not knowingly collect personal data directly from children in situations where parental consent or another lawful basis is required, unless such processing is properly authorized and lawful.
13. Third-Party Links and Services
The Service may contain links to or integrations with third-party websites, tools, or services. We are not responsible for the privacy, content, or practices of third parties. We encourage you to review their privacy notices and terms.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will post the updated version and revise the "Last Updated" date. Where appropriate, we may also provide additional notice through the Service or other communication channels.
15. Contact and Privacy Concerns
If you have questions, requests, or concerns about this Privacy Policy or our personal data practices, you may contact us through the contact details provided in the app or on our official support channels.
If applicable, requests may also be directed through the relevant chapter or authorized administrator.