Contents
- 1. Introduction & Scope
- 2. Data Controller
- 3. Data We Collect
- 4. How We Collect Data
- 5. Legal Basis for Processing
- 6. How We Use Your Data
- 7. Sharing Your Data
- 8. Cookies & Tracking
- 9. Data Retention
- 10. Data Security
- 11. Your Rights
- 12. Minors
- 13. Cross-Border Transfers
- 14. Policy Updates
- 15. Contact & DPO
1. Introduction & Scope
This Privacy Policy ("Policy") describes how ph2220 ("the Company", "we", "us", "our"), operator of the online gaming platform at ph2220.net ("the Platform"), collects, uses, stores, shares, and protects the personal data of individuals who register as members, visit the Platform, or otherwise interact with our services ("you", "the Data Subject").
This Policy applies to all personal data processing activities carried out by ph2220 in connection with the Platform, including account registration, identity verification, financial transactions, gameplay, customer support, and marketing communications. It applies regardless of the device or method used to access the Platform.
This Policy should be read alongside our Terms and Conditions, which govern your use of the Platform as a whole. By registering a ph2220 account or using the Platform, you acknowledge that you have read and understood this Policy and consent to the processing of your personal data as described herein.
2. Data Controller
ph2220 is the data controller in respect of all personal data collected through the Platform. As data controller, ph2220 determines the purposes and means by which your personal data is processed. ph2220 operates under the regulatory framework of the Philippine Amusement and Gaming Corporation (PAGCOR) and is subject to the data protection obligations imposed by the National Privacy Commission (NPC) of the Philippines.
ph2220 has appointed a Data Protection Officer (DPO) to oversee compliance with the Data Privacy Act of 2012 and to serve as the primary point of contact for all data-related enquiries and complaints. Contact details for the DPO are provided in Section 15 of this Policy.
3. Data We Collect
ph2220 collects the minimum amount of personal data necessary to provide, operate, and improve the Platform in compliance with our regulatory obligations. The categories of personal data we collect are set out below.
| Category | Examples | Purpose |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government ID number | Account registration, KYC verification, age verification (21+) |
| Contact Data | Email address, mobile number, residential address | Account management, notifications, support communications |
| Financial Data | Bank account details, GCash/PayMaya account number, transaction history | Deposits, withdrawals, fraud prevention, AML compliance |
| Technical Data | IP address, device type, browser type, operating system, session logs | Platform security, fraud detection, service improvement |
| Usage Data | Game history, bet amounts, session duration, pages visited | Personalisation, responsible gaming monitoring, platform analytics |
| Communications Data | Live chat transcripts, support emails, survey responses | Customer support quality assurance, dispute resolution |
| Verification Media | ID document scans, selfie images submitted during KYC | Identity verification, fraud prevention, regulatory compliance |
4. How We Collect Data
ph2220 collects personal data through the following means:
4.1 Directly From You
The majority of your personal data is collected directly when you register a ph2220 account, complete KYC verification, make a deposit or withdrawal, contact our customer support team, respond to a survey, or participate in a promotion. You are under no statutory obligation to provide this data, but failure to do so may prevent you from accessing certain features of the Platform.
4.2 Automatically During Platform Use
When you access the Platform, ph2220's systems automatically collect certain technical and usage data, including your IP address, device identifiers, browser type, session timestamps, and in-platform activity logs. This data is collected through server logs, cookies, and similar tracking technologies as described in Section 8.
4.3 From Third Parties
In certain circumstances, ph2220 may receive personal data about you from third parties, including:
- Identity verification and KYC service providers who cross-check your submitted documents against government and commercial databases
- Payment processors and e-wallet providers (GCash, PayMaya, BPI, BDO, Metrobank) in connection with transaction processing
- Fraud prevention and anti-money laundering screening services
- PAGCOR and other regulatory bodies in connection with regulatory enquiries
5. Legal Basis for Processing
Under the Data Privacy Act of 2012, ph2220 must have a valid legal basis for processing your personal data. We rely on the following bases depending on the specific processing activity:
- Contractual Necessity: Processing required to perform our contract with you under the Terms and Conditions — including account management, payment processing, and game delivery.
- Legal Obligation: Processing required to comply with our obligations under Philippine law, including PAGCOR regulations, Republic Act No. 9160 (Anti-Money Laundering Act), and tax reporting requirements.
- Legitimate Interests: Processing necessary for ph2220's legitimate business interests, such as fraud prevention, platform security, and service improvement, provided these interests are not overridden by your rights and interests.
- Consent: Processing based on your freely given, specific, and informed consent — primarily in connection with direct marketing communications and the use of non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.
6. How We Use Your Data
ph2220 uses your personal data for the following purposes:
- Creating and managing your ph2220 account and member profile
- Verifying your identity and age (21+) as required by PAGCOR and the Data Privacy Act
- Processing deposits, withdrawals, and other financial transactions in Philippine Peso (PHP)
- Detecting and preventing fraud, money laundering, and other prohibited activities
- Monitoring gameplay activity for responsible gaming purposes, including identifying problem gambling indicators
- Providing customer support and resolving disputes or complaints
- Sending transactional communications essential to your account (e.g., verification emails, withdrawal confirmations, security alerts)
- Sending promotional communications about ph2220 offers, where you have provided consent to receive such communications
- Improving the Platform through analytics and user experience research
- Complying with regulatory reporting obligations to PAGCOR, the Anti-Money Laundering Council (AMLC), and the National Privacy Commission (NPC)
7. Sharing Your Data
ph2220 does not sell your personal data to third parties for their own commercial purposes. We share your data only in the limited circumstances described below.
7.1 Service Providers
ph2220 engages trusted third-party service providers to assist in delivering and improving the Platform. These include KYC verification providers, payment processors, cloud hosting providers, analytics platforms, and customer support tools. All service providers are contractually required to process your data only on ph2220's instructions and in compliance with the Data Privacy Act of 2012.
7.2 Game Providers
Where necessary for the delivery of specific games, limited technical data (such as a session token or anonymised player identifier) may be shared with licensed third-party game providers. These providers do not receive your full identity data and are bound by their own data protection obligations as licensed gaming operators.
7.3 Regulatory & Law Enforcement Authorities
ph2220 is legally required to share certain data with regulatory and law enforcement bodies in the Philippines, including PAGCOR, the AMLC, the Bureau of Internal Revenue (BIR), and law enforcement agencies, where required by applicable law, court order, or regulatory directive. ph2220 will notify you of such disclosures where legally permitted to do so.
7.4 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of all or part of ph2220's business, your personal data may be transferred to the relevant successor entity, provided that the successor entity agrees to honour the commitments made in this Privacy Policy and complies with applicable Philippine data protection law.
8. Cookies & Tracking Technologies
ph2220 uses cookies and similar tracking technologies (such as pixel tags and local storage) to operate the Platform, recognise returning members, and collect usage analytics. The types of cookies we use are as follows:
- Strictly Necessary Cookies: Required for the Platform to function. These include session authentication cookies and security tokens. They cannot be disabled without disrupting the Platform.
- Functional Cookies: Remember your preferences (e.g., language settings, responsible gaming tool configurations) to improve your experience. Disabling these may reduce Platform functionality.
- Analytics Cookies: Collect aggregated, anonymised data about how members use the Platform to help us improve performance and user experience. These are activated only with your consent.
- Marketing Cookies: Used to deliver relevant ph2220 promotional content within the Platform. These are activated only with your consent and can be withdrawn at any time through your account cookie preferences.
You can manage your cookie preferences through the cookie settings panel accessible in your ph2220 account. Note that disabling strictly necessary cookies will prevent you from logging in to the Platform.
9. Data Retention
ph2220 retains personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable Philippine law and regulatory obligations. The following general retention periods apply:
- Account Data: Retained for the duration of your active account and for a minimum of five (5) years following permanent account closure, as required by PAGCOR and AMLC regulations.
- Financial Transaction Records: Retained for a minimum of five (5) years in compliance with Republic Act No. 9160 (Anti-Money Laundering Act) and BIR record-keeping requirements.
- KYC Documents: Retained for the duration of the account relationship and for five (5) years post-closure, or longer if required by an ongoing regulatory investigation.
- Customer Support Communications: Retained for two (2) years from the date of the interaction, or longer if the communication relates to an unresolved dispute.
- Analytics & Technical Logs: Retained for up to twelve (12) months, after which they are anonymised or deleted.
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with ph2220's data destruction procedures.
10. Data Security
ph2220 implements a comprehensive set of technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. These measures include:
- 256-bit SSL/TLS encryption for all data transmitted between your device and the ph2220 Platform
- Encryption at rest for sensitive data stored on ph2220 servers, including KYC documents and financial records
- Role-based access controls ensuring that only authorised ph2220 personnel with a legitimate need can access personal data
- Regular penetration testing and vulnerability assessments conducted by independent security specialists
- Multi-factor authentication requirements for internal system access by ph2220 staff
- Staff training on data protection obligations under the Data Privacy Act of 2012
- Incident response procedures aligned with NPC notification requirements in the event of a personal data breach
In the event of a personal data breach that is reasonably likely to result in a real risk of serious harm to you, ph2220 will notify the National Privacy Commission within seventy-two (72) hours of becoming aware of the breach, and will notify affected members as soon as practicable thereafter, in compliance with NPC Circular No. 16-03.
11. Your Rights as a Data Subject
Under the Data Privacy Act of 2012 and its Implementing Rules and Regulations, you hold the following rights in respect of your personal data held by ph2220. You may exercise any of these rights by contacting our Data Protection Officer as described in Section 15.
Your Data Rights
The Data Privacy Act of 2012 gives every ph2220 member clear, enforceable rights over their personal data.
Right to Be Informed
You have the right to know what personal data ph2220 holds about you, how it is being used, and with whom it is shared — before and during processing.
Right to Access
You may request a copy of the personal data ph2220 holds about you at any time. We will respond to access requests within fifteen (15) business days.
Right to Rectification
If any personal data we hold about you is inaccurate or incomplete, you have the right to request that it be corrected without undue delay.
Right to Erasure
You may request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to our legal retention obligations.
Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes. Objections to marketing will be actioned immediately.
Right to Data Portability
Where technically feasible, you may request a copy of your personal data in a structured, commonly used, machine-readable format for transfer to another service.
Right to Withdraw Consent
Where processing is based on your consent (e.g., marketing emails), you may withdraw that consent at any time. Withdrawal does not affect prior lawful processing.
Right to Lodge a Complaint
If you believe ph2220 has violated your data rights, you may file a complaint with the National Privacy Commission (NPC) of the Philippines.
12. Minors
The ph2220 Platform is strictly for individuals aged 21 years and above, as required by PAGCOR regulations. ph2220 does not knowingly collect or process personal data from individuals under the age of 21. If we become aware that personal data has been collected from a person under 21 years of age, we will immediately close the associated account, delete the data, and take any further action required by law.
If you are a parent or guardian and believe that a minor has registered a ph2220 account or submitted personal data to us, please contact our Data Protection Officer immediately at the address provided in Section 15.
13. Cross-Border Data Transfers
ph2220's primary data processing infrastructure is located within the Philippines. However, certain service providers — including KYC verification partners and cloud infrastructure providers — may process your data in jurisdictions outside the Philippines.
Where such cross-border transfers occur, ph2220 ensures that appropriate safeguards are in place as required by the Data Privacy Act of 2012, including contractual data processing agreements that impose equivalent data protection standards on the receiving party. ph2220 does not transfer personal data to jurisdictions that do not provide an adequate level of data protection without implementing such safeguards.
14. Policy Updates
ph2220 reviews and updates this Privacy Policy periodically to reflect changes in our data practices, legal obligations, or regulatory requirements. The "Last updated" date at the top of this page indicates when the most recent revision was published.
Where material changes are made to this Policy, ph2220 will notify registered members via email at least fourteen (14) days before the changes take effect, except where immediate amendment is required by law or a regulatory directive. Your continued use of the Platform after the effective date of any revision constitutes your acknowledgement of the updated Policy.
We encourage you to review this Policy periodically. The current version is always accessible at ph2220.net/privacy-policy.
15. Contact & Data Protection Officer
For any questions, concerns, or requests relating to this Privacy Policy or the exercise of your data subject rights, please contact the ph2220 Data Protection Officer (DPO):
ph2220 Data Protection Officer
Email: [email protected]
Subject line: Data Privacy Request — [Your Full Name]
ph2220 will acknowledge your request within three (3) business days and aim to resolve it within fifteen (15) business days. Complex requests may require additional time, in which case we will keep you informed of the progress.
If you are not satisfied with ph2220's response, you have the right to escalate your complaint to the National Privacy Commission (NPC) of the Philippines, which is the statutory body responsible for enforcing the Data Privacy Act of 2012.
How ph2220 Keeps Your Data Safe
Privacy at ph2220 is not an afterthought — it is built into how we operate from day one.
256-Bit SSL Encryption
Every data exchange between your device and the ph2220 Platform is protected by industry-standard 256-bit SSL/TLS encryption. Your personal and financial details travel securely, every single time.
DPA 2012 Compliant
ph2220 processes all member data in full compliance with Republic Act No. 10173, the Data Privacy Act of 2012. Our DPO is registered with the National Privacy Commission and oversees every aspect of our data handling.
No Data Selling
ph2220 will never sell your personal data to third-party marketers or data brokers. Your information is used exclusively to deliver and improve ph2220 services and meet our regulatory obligations.
You Control Your Data
From your ph2220 account settings, you can update your profile data, manage marketing preferences, adjust cookie settings, and submit data access or deletion requests — all without needing to contact support.
Opt-Out Anytime
Marketing communications from ph2220 are always opt-in. If you change your mind, unsubscribing is immediate and straightforward — one click in any email or a quick toggle in your account notification settings.
Defined Retention Periods
ph2220 does not hold your data indefinitely. Clear retention schedules — aligned with PAGCOR, AMLC, and NPC requirements — govern how long each category of data is kept before secure deletion or anonymisation.
Play with Confidence on ph2220
Your privacy is protected, your data is secure, and your rights are respected. Explore the ph2220 platform knowing your personal information is in safe hands.
21+ only. Play responsibly. PAGCOR regulated. Data protected under RA 10173.