Student Data
Privacy Policy
Kumpas is committed to protecting your personal data. This policy outlines your rights under the Data Privacy Act of 2012.
Governing Law
RA 10173 (DPA 2012)
Regulator
National Privacy Commission
Data Use
Career guidance only
Kumpas is a career guidance system built for Filipino guidance counselors. It helps counselors generate structured, data-backed career assessments for their students using a five-agent AI pipeline powered by the Gemini API and built on Next.js.
This Privacy Policy explains what data Kumpas processes, why it processes it, how it is protected, and the rights students and their guardians hold under Republic Act No. 10173, the Data Privacy Act of 2012 (DPA), and its Implementing Rules and Regulations.
By using Kumpas, the guidance counselor and/or their institution acknowledges that they have secured proper consent from the student or their guardian before entering any student data into the system, and that they have read and agreed to this policy.
The school or institution deploying Kumpas is the Personal Information Controller (PIC) for all student data processed through the system. Kumpas acts as a Personal Information Processor (PIP) operating on behalf of the school.
As the PIC, the school is responsible for:
- Securing proper student and/or guardian consent before a counseling session is processed
- Ensuring data entered into Kumpas is limited to what is necessary for career guidance
- Designating a Data Protection Officer (DPO) as the student's primary point of contact for all data requests
- Ensuring counselors are trained on responsible data handling under RA 10173
Kumpas does not independently collect or solicit student data — all data enters the system through the guidance counselor's input.
Kumpas processes only the data that a guidance counselor actively enters into the system. No data is collected passively. This includes:
COUNSELOR SESSION NOTES
- Typed notes written by the guidance counselor describing the student's career interests, aspirations, academic situation, family context, and any concerns raised during the session
- These notes are the primary input for the AI pipeline
OPTIONAL ACADEMIC DOCUMENTS
- NCAE (National Career Assessment Examination) results — uploaded as a document image or PDF
- NAT (National Achievement Test) scores — uploaded as a document image or PDF
- Report Card excerpts — uploaded by the counselor to provide academic context
WHAT WE DO NOT COLLECT
- Audio or video recordings of any kind — Kumpas has no recording capability
- Biometric data of any kind
- Student names in downstream AI components — names are removed by the first Gemini agent before any analysis step receives the data
- Social media accounts, device data, or browsing activity
- Medical records or clinical diagnoses
Data entered into Kumpas is used solely to generate a career assessment report for the student. The pipeline operates as follows:
SESSION INTAKE LAYER
The counselor's notes and uploaded academic documents are sent to the first Gemini agent (Session Intake Layer). As part of structuring the data, this agent removes PII — student names are replaced with "the student", specific school names and sub-province locations are redacted. The resulting structured output contains no direct identifiers and is what all downstream agents receive.
THREE-AGENT ANALYSIS
Three specialist Gemini agents analyze the de-identified structured intake output in parallel: the Feasibility Analyst (SCCT framework), the Labor Market Analyst (LMI/DOLE data framework), and the Job Demand Analyst (JD-R Model). Each produces a scored assessment.
ADJACENT CAREER FINDER
A fifth Gemini agent synthesizes all three assessments to identify 3–4 adjacent career paths the student may not have considered, scored against the same frameworks.
REPORT GENERATION
A Career Assessment Report is generated and displayed to the guidance counselor. This report is for in-session use only and is not transmitted to any third party without consent.
LEGAL BASIS FOR PROCESSING
- Consent — the student or guardian has given express consent (Section 12(a), RA 10173)
- Legitimate purpose — career guidance is a core educational function (Section 12(b), RA 10173)
- Proportionality — only data necessary for the guidance session is processed
Kumpas does not sell personal data. Data sharing with third parties is strictly limited.
WHO WE SHARE DATA WITH
- Google (Gemini API) — student session data is processed by Gemini models across all five pipeline stages. The first Gemini agent (Session Intake Layer) performs PII redaction as part of its structuring task — removing student names, specific school names, and sub-province locations. All subsequent Gemini agents operate on this already de-identified output. Google acts as a sub-processor under data processing terms.
- Research institutions and academic organizations — only anonymized, aggregated data (no individual identifiers) may be used for peer-reviewed studies on career outcomes and educational planning, and only with explicit consent
- Government agencies (e.g., CHED, DepEd, TESDA) — where required by law or in support of national education policy
WHAT IS NEVER SHARED
- Raw counselor session notes
- Uploaded academic documents (NCAE, NAT, Report Card)
- Individual career assessment reports
- Any data that could identify a specific student
OPT-OUT Students and guardians may opt out of having their anonymized data included in any external research sharing by submitting a written request to the school's Data Protection Officer. Opting out does not affect access to the Kumpas career guidance service.
DATA STORAGE
- Session notes and uploaded documents are processed in-session and are not permanently stored on Kumpas servers beyond what is necessary to generate the report
- Student names and precise location identifiers are removed by the first Gemini agent during the Session Intake Layer step, before downstream agents receive any data
- Generated reports are stored temporarily in the browser's session storage and are cleared when the browser session ends
- All data in transit is encrypted using TLS 1.2+
DATA RETENTION
- Kumpas does not maintain a persistent database of student records beyond the active session
- The school's own document retention policies govern how long counselor notes and printed reports are kept
- Upon written request, any residual student data will be deleted within 30 calendar days
DATA LOCALIZATION All five pipeline agents run via the Gemini API, which may route requests through Google's global infrastructure. Appropriate safeguards are in place under NPC Circular No. 16-01 for cross-border data transfers. Raw session notes (containing PII) are only sent to the first Gemini agent. All subsequent agents receive only the de-identified structured output produced by that first call.
Right to Be Informed
You have the right to know what personal data is collected, why, and how it will be used — which is the purpose of this document.
Right to Access
Request a copy of the personal data Kumpas holds about the student at any time via the school's DPO.
Right to Rectification
If any personal data entered into the system is inaccurate or incomplete, you may request it be corrected before or after report generation.
Right to Erasure / Blocking
Request deletion or blocking of personal data if it was collected unlawfully, is no longer necessary, or if consent is withdrawn.
Right to Object
Object to the processing of personal data for purposes beyond career guidance as stated in this policy.
Right to Data Portability
Request a copy of your career assessment data in a structured, human-readable format.
Right to File a Complaint
File a complaint with the National Privacy Commission at complaints@privacy.gov.ph or privacy.gov.ph if you believe your rights have been violated.
Kumpas implements technical and organizational safeguards appropriate to the sensitivity of student data:
TECHNICAL SAFEGUARDS
- PII redaction by first Gemini agent — the Session Intake Layer agent is instructed to remove student names, specific school names, and sub-province location identifiers as part of its structuring task. Raw notes are sent only to this one agent; all downstream Gemini agents operate exclusively on the de-identified structured output
- No audio or video capability — all input is text-based, eliminating the risk of inadvertent voice or image capture during sessions
- Encryption of data in transit (TLS 1.2+) on all API calls
- Session-scoped storage — report data is held in browser session storage and is not written to persistent server-side databases
ORGANIZATIONAL SAFEGUARDS
- Kumpas is operated by guidance counselors, who are bound by their institution's data handling policies and RA 10173
- AI sub-processors (Google Gemini) operate under data processing agreements
- System access is limited to the guidance counselor actively running the session
BREACH NOTIFICATION In the event of a personal data breach affecting student records, affected individuals and the National Privacy Commission will be notified within 72 hours of discovery, in accordance with NPC Circular No. 16-03.
For questions, requests, or complaints about how Kumpas handles personal data, please contact:
YOUR SCHOOL'S DATA PROTECTION OFFICER The school deploying Kumpas is the primary point of contact for all data subject requests. The school's DPO is responsible for receiving and acting on requests within the timelines required by RA 10173.
NATIONAL PRIVACY COMMISSION (NPC) National Privacy Commission 5th Floor, Delegation Building PICC Complex, Roxas Boulevard Pasay City, Metro Manila 1307
Email: complaints@privacy.gov.ph Website: privacy.gov.ph Hotline: (02) 8234-2228
This Privacy Policy was last reviewed in 2025 and will be updated as necessary to reflect changes in Kumpas's data practices, the Gemini API's data handling terms, or applicable Philippine law.
Request Data Deletion
Students and guardians may request deletion of all personal data by contacting the school's Data Protection Officer. Requests will be fulfilled within 30 calendar days in accordance with NPC guidelines.