Teleconsult

Privacy

Privacy policy

How Hasa Mee S. Hagape-Bascon collects, uses, and protects your personal and health information — and the rights you have over it.

Last updated 5 August 2026

Who is responsible

This site is run by a single practitioner, and it is that practitioner — not a company or a platform — who decides what happens to your information. The contact details at the end of this policy reach them directly.

Your consultation and anything you tell me during it are treated as confidential medical information, in line with the duty of confidentiality that applies to any clinical consultation.

As a solo practitioner I fall below the National Privacy Commission's registration thresholds and am not registered with it. I act as my own contact for any question about your information.

What I collect

Only what is needed to arrange and provide your care. There is no tracking, no advertising, and no profiling of any kind on this site.

  • Your account — your name, email address, and phone number if you give one, plus the date you registered and the date you confirmed your email.
  • Your bookings — the date and time you chose, and the short reason for the visit you entered when booking.
  • Your clinical record — the notes, diagnosis, prescriptions, and medical certificates I write up after a consultation, and any private notes I keep to provide your continuing care.
  • Messages — anything you send through the contact form (name, email, phone if given, subject, and message), together with my replies.
  • A record of the emails sent to you — confirmations, reminders, and notices — so I can see what reached you and avoid sending it twice.

What I do not collect

There are no analytics, advertising, or social-media tracking scripts on this site. Nothing you do here is measured for marketing, shared with an advertising network, or sold — to anyone, ever.

Video consultations are not recorded. No copy of the call is made by this site or kept anywhere afterwards.

I never ask for payment card details on this site, and there is nowhere here to enter them. Payment is arranged separately once your booking is confirmed.

Cookies

This site sets one cookie for you, and only after you sign in. It holds a signed reference to your account so that your appointments page knows who you are. It lasts 30 days, cannot be read by scripts in your browser, and is used for nothing but keeping you signed in.

There are no advertising, analytics, or third-party cookies, which is why this site never asks you to accept any. Signing out clears it; so does clearing your browser's cookies.

Why I am allowed to hold it

Under the Data Privacy Act of 2012 (Republic Act 10173), health information is sensitive personal information and needs a specific basis. Mine is your consent: you give it when you register and book, and holding the information is necessary for me to provide the care you asked for.

You can withdraw that consent at any time by asking me to close your account. Withdrawing it does not undo care already given, and where the law or my professional obligations require me to retain a clinical record, I will tell you plainly which parts I have to keep and why.

Who else sees it

Your record is visible to you and to me. It is not shared with anyone else without your consent, except where the law obliges me to disclose it.

Running the site does mean a small number of service providers handle your information on my behalf, strictly to do their job:

  • The email service that delivers your sign-in codes, booking confirmations, and reminders. It sees your email address and the contents of those messages.
  • The hosting and database provider where the site and your records are stored.
  • Video calls run on the free, public Jitsi Meet service (meet.jit.si), which is operated independently of this site. Your call passes through their infrastructure under their own privacy terms; this site does not send them your name, your email, or anything from your record. Room links are derived from your appointment so they are not guessable, but treat the link as private and do not share it.

How it is protected

Signing in is by a password you choose, stored only as a salted one-way hash — never in any form that can be read back, here or anywhere else. A one-time code sent to your email is what confirms the address in the first place, and what gets you back in if you forget the password. An address has to be confirmed before it can book anything, and messages are only ever sent to a confirmed address.

Your session cookie is cryptographically signed, so it cannot be forged or edited to impersonate someone else. The provider portal is separately password-protected and supports two-factor authentication, and repeated failed sign-in attempts are throttled.

No system is perfect, and this is a small personal practice rather than a hospital. If anything happens that puts your information at risk, I will tell you and notify the National Privacy Commission as the law requires.

How long I keep it

Clinical records are kept for 5 years after your most recent consultation, and account details for as long as your account is open. Enquiries sent through the contact form are kept while they are being dealt with and for a reasonable period afterwards.

When you ask me to close your account, I delete what I am not obliged to keep and tell you what remains.

Your rights

The Data Privacy Act gives you real, enforceable rights over your information. On this site they work like this:

  • See it — sign in at any time to read your own appointments, prescriptions, and certificates. Ask me and I will give you the rest of what I hold.
  • Correct it — tell me anything that is wrong or out of date and I will fix it.
  • Get a copy — ask and I will send you your information in a form you can keep or take to another practitioner.
  • Have it deleted — ask me to close your account. I will delete everything I am not legally obliged to keep, and be specific about anything I must retain.
  • Object, or withdraw consent — you can tell me to stop using your information, understanding that I may then be unable to continue providing care.
  • Complain — if you think I have mishandled your information, tell me first and I will put it right. You can also complain to the National Privacy Commission at privacy.gov.ph, and you have a right to be compensated for damage caused by mishandling.

Children

Where a patient is a minor, bookings should be made and consent given by a parent or legal guardian, who is then the person I correspond with about that care.

Changes to this policy

If this policy changes in a way that affects you, I will update the date at the top and, where the change is significant, tell you directly rather than relying on you to notice.

Asking about your information

To see, correct, export, or delete what I hold about you — or to raise a concern about any of the above — reach me directly:

Or use the contact form. I answer these myself.

In an emergency, do not use this site. For chest pain, difficulty breathing, sudden weakness or trouble speaking, severe bleeding, or any life-threatening symptom, contact your local emergency services immediately.