This Privacy Policy explains how phparm collects, uses, stores, and protects the personal information of Filipino players on the phparm.club platform, in compliance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations.
This policy is drafted in accordance with the Philippine Data Privacy Act of 2012 (RA 10173) and registered with the National Privacy Commission (NPC) of the Philippines.
This Privacy Policy ("Policy") is issued by phparm ("phparm," "we," "us," or "our"), the operator of the online gaming platform accessible at phparm.club. This Policy describes how phparm processes the personal data of individuals ("you," "Data Subject," or "Player") who: (a) register for a phparm player account; (b) access or use the phparm Platform; (c) contact phparm support; or (d) interact with phparm through any other channel.
This Policy applies to all personal data processing activities conducted by phparm in connection with the Platform, including data collected through the website, mobile browser interface, customer support communications, payment processing, and marketing communications. It applies to all Filipino players and any individual whose personal data is processed by phparm in connection with Platform operations, regardless of their location.
This Policy should be read together with the phparm Terms & Conditions, the Responsible Gaming Policy, and any specific consent notices presented to you at the point of data collection. By registering for a phparm account, you acknowledge that you have read and understood this Policy.
For the purposes of the Philippine Data Privacy Act of 2012, phparm is the Personal Information Controller (PIC) in respect of personal data processed through the phparm Platform. As PIC, phparm determines the purposes and means of processing your personal data and is responsible for ensuring that processing is conducted lawfully, fairly, and transparently in accordance with the DPA.
phparm has designated a Data Protection Officer (DPO) responsible for overseeing compliance with the DPA, managing data subject rights requests, and coordinating with the National Privacy Commission. The DPO can be contacted through the details provided in Section 16 of this Policy.
Third-party service providers engaged by phparm — including game providers, payment processors, and identity verification services — act as Personal Information Processors (PIPs) where they process personal data on phparm's behalf under binding data processing agreements. phparm remains responsible for ensuring that all PIPs provide sufficient data protection guarantees consistent with the DPA.
phparm collects personal data that is adequate, relevant, and limited to what is necessary for the purposes described in this Policy. The categories of personal data phparm processes are set out below.
| Category | Specific Data Elements | Purpose |
|---|---|---|
| Identity Data | Full legal name, date of birth, gender, nationality, government-issued ID type and number | KYC verification, age restriction compliance, PAGCOR regulatory reporting |
| Contact Data | Email address, Philippine mobile number, residential address | Account management, transaction alerts, support communications, 2FA delivery |
| Financial Data | GCash or Maya account number (last digits), bank account details, transaction history, deposit and withdrawal records | Payment processing, AML compliance, withdrawal verification, tax reporting where required |
| KYC Documents | Scanned/photographed government ID, selfie or liveness verification image, proof of payment method ownership | Identity verification, fraud prevention, PAGCOR KYC compliance |
| Technical Data | IP address, device type and identifier, browser type and version, operating system, session tokens, login timestamps | Account security, fraud detection, session management, platform improvement |
| Game Activity Data | Game session records, bet amounts, win/loss outcomes, game preferences, session duration | Game result verification, responsible gaming monitoring, PAGCOR reporting, bonus eligibility assessment |
| Communication Data | Support chat transcripts, email correspondence, complaint records | Customer service delivery, dispute resolution, quality assurance, legal compliance |
| Marketing Preferences | Opt-in/opt-out status, preferred communication channels, promotion interaction history | Sending relevant promotional communications to consenting players only |
phparm collects personal data through the following means:
Data you provide directly to phparm when: completing the registration form; submitting KYC verification documents; making deposits or requesting withdrawals; contacting phparm customer support; responding to surveys or promotions; or adjusting your account settings or responsible gaming preferences.
Technical and usage data collected automatically when you access the phparm Platform, including through cookies, browser local storage, session logs, server-side game outcome records, and security monitoring systems. See Section 11 for full details on cookies and tracking technologies used by phparm.
phparm may receive data about you from third parties in the following circumstances: (a) identity verification providers who conduct KYC checks on phparm's behalf; (b) payment processors such as GCash and Maya who confirm transaction details; (c) fraud detection services who flag potentially suspicious activity patterns; and (d) PAGCOR or other regulatory bodies pursuant to their lawful authority. In all cases, phparm verifies that third-party sources are authorised to share such data before it is processed.
Under the Philippine Data Privacy Act, phparm processes your personal data on one or more of the following lawful bases, depending on the specific processing activity:
phparm uses your personal data for the following specific purposes:
With your consent, phparm may send you promotional communications about bonuses, new games, tournaments, and platform updates via your registered email address or Philippine mobile number. You may withdraw consent for marketing communications at any time by updating your notification preferences within your phparm account dashboard or by contacting phparm support.
phparm does not sell, rent, or trade your personal data with any third party for commercial gain. phparm discloses personal data only in the following circumstances and only to the extent necessary for the stated purpose:
phparm engages carefully selected third-party service providers who process personal data on phparm's behalf under binding data processing agreements that impose data protection obligations consistent with the DPA. These include: identity verification providers (for KYC processing); payment processors (GCash, Maya, Visa, Mastercard, and linked banking partners); game software providers (for game outcome verification); hosting and cloud infrastructure providers; and customer support platform providers.
phparm will disclose personal data to competent Philippine regulatory or law enforcement authorities — including PAGCOR, the Anti-Money Laundering Council (AMLC), the National Bureau of Investigation (NBI), and the National Privacy Commission (NPC) — where required by law, court order, or regulatory directive. phparm will inform you of such disclosure where legally permitted to do so.
In the event of a merger, acquisition, asset sale, or restructuring of phparm's business, your personal data may be transferred to a successor entity as part of that transaction. phparm will provide reasonable notice of such transfer and ensure that the successor entity assumes equivalent data protection obligations under the DPA.
Where a player activates self-exclusion through the phparm Platform, phparm may register that exclusion with the PAGCOR self-exclusion programme or other applicable industry-wide exclusion registry. This disclosure is made to protect the player's welfare and is authorised under phparm's PAGCOR licensing conditions.
Some of phparm's third-party service providers — particularly game software providers and cloud infrastructure vendors — may be located outside the Philippines. Where personal data is transferred to countries that do not provide an equivalent level of data protection to the Philippines, phparm implements appropriate safeguards to protect your data in accordance with Section 21 of the DPA and the NPC's rules on cross-border data transfers.
These safeguards include: contractual data protection clauses that bind foreign recipients to DPA-equivalent obligations; transfers only to recipients in countries with adequate data protection frameworks as recognised by the NPC; and where required, obtaining your prior consent for specific international transfers.
phparm maintains a register of all cross-border data transfers and will make this register available to the NPC upon request. You may contact the phparm Data Protection Officer (see Section 16) to request information about specific cross-border transfer safeguards applicable to your personal data.
phparm retains personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by Philippine law, whichever is longer. The primary retention periods applied by phparm are as follows:
| Data Category | Retention Period | Legal Basis for Retention |
|---|---|---|
| Account & KYC records | Duration of account plus 5 years after closure | PAGCOR licensing conditions, AMLA record-keeping requirements |
| Financial transaction records | 5 years from transaction date | Anti-Money Laundering Act, BSP regulations, tax law |
| Game activity logs | 12 months from activity date (full detail); aggregate data may be retained longer | PAGCOR reporting obligations, dispute resolution |
| Support communications | 2 years from last interaction | Dispute resolution, quality assurance, legal claims |
| Marketing opt-in records | Duration of consent plus 1 year after withdrawal | Proof of consent under DPA, NPC guidance |
| Security and audit logs | 12 months (rolling) | Fraud prevention, account security, regulatory audit |
At the end of the applicable retention period, phparm will securely delete or anonymise personal data in a manner that prevents reconstruction. Anonymised data that cannot be re-linked to an individual may be retained indefinitely for statistical and platform improvement purposes.
phparm implements a layered, risk-based information security programme designed to protect your personal data against unauthorised access, disclosure, alteration, and destruction. The technical and organisational measures applied by phparm include:
phparm uses cookies and similar tracking technologies on the phparm Platform to provide functionality, maintain your session, protect account security, and (with your consent) analyse Platform usage patterns. A cookie is a small text file placed on your device when you access the Platform.
You may configure your browser to reject non-essential cookies or delete existing cookies at any time. Please note that disabling strictly necessary cookies will impair or prevent your ability to use the phparm Platform, including preventing login. Analytics and marketing cookies can be disabled via your account notification preferences without affecting Platform functionality.
As a Data Subject under the Philippine Data Privacy Act of 2012, you have the following rights in relation to your personal data processed by phparm. phparm will respond to all valid rights requests within the timeframes specified by the DPA and NPC regulations.
Request a copy of the personal data phparm holds about you, along with information on how it is being used, with whom it is shared, and how long it will be retained.
Request correction of any personal data that is inaccurate, incomplete, or outdated. Corrections affecting KYC details require supporting documentation.
Request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to phparm's legal retention obligations under AMLA and PAGCOR regulations.
Object to phparm's processing of your personal data where that processing is based on legitimate interests, including processing for direct marketing purposes.
Request that phparm provide your personal data in a structured, commonly used, and machine-readable format for transfer to another service provider where technically feasible.
Request that phparm suspend processing of your personal data in certain circumstances — such as during a dispute about the accuracy of your data — pending resolution.
Under Section 16(f) of the DPA, you may claim compensation for damages suffered due to inaccurate, incomplete, outdated, or unlawfully obtained personal data processed by phparm.
Lodge a complaint with the National Privacy Commission (NPC) of the Philippines if you believe phparm has violated your rights under the DPA, after first attempting resolution with phparm's DPO.
To exercise any of these rights, submit your request in writing to phparm's Data Protection Officer at [email protected], clearly identifying your registered phparm account, the right you are exercising, and supporting information. phparm will verify your identity before processing any rights request and will respond within 15 business days. Complex requests may require up to 30 days with notice of the extension.
The phparm Platform is strictly restricted to individuals aged 21 years and above. phparm does not knowingly collect personal data from anyone under the age of 21. The Platform's age verification and KYC processes are designed to identify and reject any registration attempt by a person under 21 years of age.
If phparm discovers or has reasonable grounds to believe that personal data has been collected from a person under 21 years of age — whether through circumvention of age verification or other means — phparm will immediately: (a) restrict the relevant account; (b) conduct an investigation; (c) delete all personal data associated with the underage user, except to the extent required by law; and (d) refund any deposited funds to their source in accordance with applicable Philippine gaming regulations.
Parents or guardians who believe that phparm may have inadvertently collected personal data from a minor in their care are encouraged to contact the phparm Data Protection Officer immediately at [email protected].
The phparm Platform integrates with third-party services — including game providers, payment gateways, and identity verification systems — whose own privacy practices are separate from and independent of this Policy. phparm has entered into data processing agreements with all such third-party service providers to ensure they process your data only as directed by phparm and in accordance with DPA-equivalent standards.
phparm is not responsible for the privacy practices of GCash, Maya, Visa, Mastercard, BPI, BDO, Metrobank, or any other payment provider you use to make deposits to or withdrawals from your phparm account. Transactions processed through those providers are subject to their own privacy policies, which you should review independently.
The phparm Platform does not contain outbound links to third-party websites. Where phparm refers players to resources such as the National Council on Problem Gambling Philippines (NCPG-PH) or PAGCOR for responsible gaming support, those organisations operate under their own privacy frameworks independent of phparm.
phparm reserves the right to update this Privacy Policy to reflect changes in applicable Philippine law, NPC regulations, phparm's data processing activities, or best practice standards. The effective date at the top of this Policy reflects the date of the most recent revision.
Where amendments are material — meaning they significantly affect your rights or how your personal data is processed — phparm will notify you by email to your registered address and post a prominent notice on the phparm Platform at least 14 days before the amended Policy takes effect. Minor corrections and clarifications that do not change the substance of your rights may be published without advance notice.
Your continued use of the phparm Platform after the effective date of any amendment constitutes your acknowledgement of the updated Policy. If you do not accept material amendments, you should stop using the Platform and may request account closure as described in the phparm Terms & Conditions. phparm will process any real-money balance in accordance with those Terms regardless of your decision not to accept the amended Policy.
For any questions, concerns, or requests relating to this Privacy Policy or phparm's data processing activities, please contact the phparm Data Protection Officer:
Data Protection Officer — phparm
Email: [email protected]
Subject Line: DPA Rights Request or Privacy Policy Enquiry
Response Time: phparm acknowledges all DPO enquiries within 5 business days. Full responses to rights requests are provided within 15 business days, extendable to 30 days for complex requests with prior notice.
Support Hours: 24 hours a day, 7 days a week
If you are not satisfied with phparm's response to your privacy concern, you have the right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines — the supervisory authority for data protection in the Philippines.
A plain-language summary of what phparm commits to in terms of your personal data — no legalese, just the essentials.
phparm does not sell, rent, or trade your personal information to any third party for commercial purposes — ever. Your name, contact details, game history, and financial data are used exclusively to operate your phparm account and comply with Philippine law.
phparm is registered with the National Privacy Commission of the Philippines under the Data Privacy Act of 2012. A dedicated Data Protection Officer oversees compliance and is available to address any privacy concern from Filipino players directly.
Your personal data is protected by 256-bit SSL/TLS encryption in transit and encrypted at rest — the same standard used by BPI, BDO, and Metrobank. Passwords are hashed using one-way algorithms that cannot be reversed even by phparm staff.
You have the right to access, correct, delete, and port your personal data held by phparm. You can withdraw marketing consent, adjust notification preferences, and request account closure — all directly from your phparm dashboard or by contacting the DPO.
This Privacy Policy is written in plain English for Filipino players — not buried in impenetrable legal language. phparm publishes the exact categories of data collected, the specific purposes it is used for, and the retention periods that apply to each category.
In the event of a personal data breach that could cause harm to Filipino players, phparm commits to notifying the NPC within 72 hours and informing affected players promptly — in full compliance with NPC Circular No. 16-03 and the DPA's breach notification requirements.
Play with confidence knowing your personal information is protected by Philippine data privacy law, PAGCOR-mandated security standards, and phparm's own commitment to transparent, fair data practices.
21+ only · PAGCOR Regulated · DPA Compliant · NPC Registered