Privacy, Retention & Security Policy

Doc JPR Virtual Assistant — John Paulo D. Ramos, MD  |  Last updated: June 2026  |  Version 2.3

We want you to understand exactly what we collect, why, and what choices you have — in plain language, not just legal text. The short version is below; the full detail follows, and we cite the specific Philippine laws we rely on so you can check them yourself.

The short version
  • We collect only what we need to assess your request and issue your documents — your identity, contact details, a government ID, what's bothering you, and proof of payment.
  • A licensed physician personally reviews your information. We ask for payment only after the doctor approves your request.
  • Your data is encrypted, access-controlled, and never sold or used for advertising.
  • We delete your government ID within 30 days of closing your case. Medical records are kept 10 years because Philippine law requires it.
  • You can ask to see, correct, download, or delete your data at any time — email us with the subject "Privacy Request" and we'll respond within 15 business days.
  • You message us through Facebook Messenger (Meta), which has its own privacy policy we don't control. Please don't send anything there you wouldn't want stored on Messenger.
This summary is for convenience; the full sections below govern, and nothing here limits your rights under the Data Privacy Act of 2012 (RA 10173).

1. Data Controller

John Paulo D. Ramos, MD — General Medicine & Telemedicine
PRC License No. 0159928  |  PTR No. MKT10093938MN
telemedicine@jpdjr.com  |  0967 230 5477

John Paulo D. Ramos, MD is the Personal Information Controller for this service under the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations (NPC). For any privacy question or to exercise your rights, email the address above with the subject "Privacy Request".

2. What Data We Collect

CategorySpecific dataSource
IdentityFull name, date of birth, sexYou (via the intake form)
ContactMobile number, home address, Facebook Messenger PSIDYou (via Messenger)
Government IDPhoto / scan of a valid Philippine government-issued IDYou (uploaded via Messenger)
Health informationSymptoms, duration, known conditions, current medications, allergies, reason for consultationYou (via the intake form)
Payment proofScreenshot of GCash or Maya transaction confirmation, reference numberYou (uploaded via Messenger)
CommunicationChat transcript (last 40 messages, 14-day rolling window)Automatically captured from Messenger
Issued documentsMedical certificate content, prescription details, lab request items, document IDsGenerated by the physician upon issuance
Consent recordTimestamp and method of consent captureAutomatically recorded at submission
Booking recordsAppointment date, time, type of service, notification delivery statusAutomatically captured when an appointment is scheduled

3. Why We Process It (Purposes & Legal Basis)

PurposeLegal basis (RA 10173)
Evaluate teleconsultation request and issue medical documentsConsent (§12(a)) + Medical purposes by a licensed health professional (§13(e))
Identity verification (to prevent fraud)Consent; legitimate interest of the physician
Payment verificationPerformance of a service contract (§12(b))
Physician's mandatory medical record-keepingCompliance with legal obligation (§12(c))
Certificate authenticity verification (QR scan)Legitimate interest; only document validity is confirmed — no medical details disclosed
After-care follow-up (3-day wellness check)Consent; continuing care obligation
Appointment reminders (about 1 hour and 15 minutes before the call)Consent; performance of service
Daily operational digest (physician only)Legitimate interest of the physician; data not shared externally

4. Data Storage & Infrastructure Security

Records are stored in Cloudflare Workers KV, a globally distributed key-value store, and uploaded images (government IDs, payment screenshots) in Cloudflare R2 object storage. Both provide the following security properties:

⚠️ Messenger channel notice: Communication occurs via Facebook Messenger, operated by Meta Platforms, Inc. and subject to Meta's own Privacy Policy. Do not send sensitive information you are not comfortable transmitting through Messenger. For end-to-end encrypted transmission, contact Dr. Ramos directly via the email address above.

5. Retention Schedule

Data typeRetention periodBasis
Government ID photos30 days after the case is closedMinimum necessary for identity verification. Stored in Cloudflare R2 and automatically deleted by a daily privacy job 30 days after the case is closed — and immediately on a valid erasure request.
Payment proof screenshots12 months after payment dateFinancial record-keeping; stored in R2 and expired by bucket lifecycle rule
Chat transcripts14 days rolling window (last 40 messages)Operational support (live takeover); auto-expired by KV TTL
Medical records (case records, SOAP notes, issued documents)10 years minimumDOH Administrative Order No. 2016-0002 and standard Philippine medical record-keeping practice; after 10 years, records are securely deleted
Prescriptions (Rx records)10 yearsSame as above
Audit logs10 yearsCompliance; legal defence
Booking & appointment records2 yearsOperational; then purged
In-progress form and conversation session12 hoursAuto-expired when the temporary session ends
Submitted intake awaiting valid ID7 days from submissionAvailable to the physician while awaiting ID; securely deleted if incomplete

6. Data Sharing & Third Parties

We do not sell, trade, or otherwise transfer your personal data to third parties. Data may be disclosed only in the following limited circumstances:

7. Your Rights Under RA 10173 (Data Privacy Act of 2012)

To exercise any right, email telemedicine@jpdjr.com with subject "Privacy Request" and describe your request. We will respond within 15 business days.

8. Data Protection Officer

John Paulo D. Ramos, MD acts as the Personal Information Controller and Data Protection Officer for this service. Contact: telemedicine@jpdjr.com.

9. International Data Transfers

This service runs on Cloudflare, Inc. (edge hosting, encrypted storage) and uses Google LLC for an encrypted backup spreadsheet. These providers may process and store data on servers outside the Philippines under their own security and contractual safeguards. Communication occurs via Facebook Messenger (Meta Platforms, Inc.) and is subject to Meta's privacy policy.

10. Data Breach Notification

In the event of a personal-data breach that is likely to give rise to a real risk of serious harm, we will notify the National Privacy Commission and the affected patients within 72 hours of knowledge of the breach, as required by RA 10173 and NPC Circular 16-03.

11. Consent & Truthfulness Declaration

By submitting the intake form, you:

12. Policy Updates

This policy may be updated from time to time. The current version and effective date are shown at the top of this page. Continued use of the service after a material update constitutes acceptance of the revised policy. Material changes will be communicated via Messenger to active patients.