In the modern digital entertainment sector, safeguarding personal privacy and securing sensitive data are fundamental responsibilities. When you register an account, submit verification documentation, or execute financial transactions, you entrust us with private personal information. We view the protection of this data as a critical institutional commitment.
This comprehensive Privacy Policy outlines the categories of data we collect, explains our lawful bases for processing information, details the technical safeguards protecting your records, and explains your statutory rights as a data subject under Republic Act 10173 (the Data Privacy Act of 2012 or DPA) and its Implementing Rules and Regulations (IRR) enforced by the National Privacy Commission (NPC).
All data handling practices are conducted in strict alignment with regulatory requirements mandated by PAGCOR pursuant to Presidential Decree 1869, Republic Act 9287, and Republic Act 9160 (Anti-Money Laundering Act).
Statutory Foundations and Regulatory Mandate
Our data protection architecture is structured around Philippine privacy jurisprudence and international information security benchmarks.
| Philippine Data Privacy Statutory Hierarchy |
|---|
v
[Republic Act 10173 (Data Privacy Act)]
Foundational statute governing personal data handling
Enforced nationwide by the National Privacy Commission
v
[National Privacy Commission (NPC)]
Regulatory circulars, advisory opinions, and audits
Mandatory designation of certified Data Protection Officer
v
[PAGCOR & AMLA Statutory Compliance]
Mandatory identity verification under RA 9160
Statutory customer due diligence and 5-year retention
The Data Privacy Act of 2012 (Republic Act 10173)
Republic Act 10173 guarantees the fundamental human right to privacy while ensuring the free flow of information to promote innovation. As an organization processing both personal information and sensitive personal information, we adhere strictly to the general data privacy principles of transparency, legitimate purpose, and proportionality.
Interaction with Anti-Money Laundering Mandates
Under Republic Act 9160 (AMLA), as amended by Republic Act 10927, gaming operators are classified as covered institutions. The collection of customer identity documents and transaction records is not merely an internal operational preference; it is a statutory obligation mandated by Philippine national security and anti-financial crime laws.
Categories of Personal Information We Collect
To provide secure gaming services, verify player eligibility, and comply with regulatory directives, we collect several categories of information:
| Taxonomy of Collected User Data |
|---|
v v
[Basic Personal Information] [Sensitive Personal Data]
- Full legal name - PhilSys / Passport scans
- Date of birth & nationality - Biometric liveness selfies
- Active Philippine mobile number - Tax identification numbers
- Residential address & email - Proof of address documents
v v
[Financial & Transactional Data] [Technical & Telemetry Data]
- E-wallet references (GCash/Maya) - IP addresses & device hashes
- Deposit & withdrawal histories - Browser headers & cookies
- Wagering turnover logs - Geolocation coordinates
Basic Personal Information
| Lawful Processing Basis | Operational Scope | Statutory Authority |
|---|---|---|
| Compliance with Legal Obligations | Verifying player identity (KYC), monitoring for financial crimes, and reporting covered transactions. | Republic Act 9160 (AMLA), Republic Act 10927, and PAGCOR regulatory directives. |
| Performance of Contract | Setting up player profiles, processing deposits and withdrawals, and settling game round outcomes. | Contractual terms of service established upon account registration. |
| Legitimate Interests | Detecting fraud, preventing duplicate accounts, securing server infrastructure, and troubleshooting errors. | Protecting platform integrity and consumer assets against malicious intrusion. |
| Explicit Consent | Delivering promotional newsletters, optional marketing SMS notifications, and participation in voluntary surveys. | Revocable user opt-in provided during account creation or profile management. |
| Information Security Architecture | ||
v
[Layer 1: Network Transport Security]
- TLS 1.3 protocol implementation
- 256-bit AES cryptographic encryption
- Automated DDoS & bot mitigation firewalls
v
[Layer 2: Database Storage Security]
- Database encryption at rest (AES-256)
- Strict cryptographic hashing of all passwords
- Geographically redundant, secure cloud vaults
v
[Layer 3: Human & Operational Controls]
- Role-Based Access Controls (RBAC)
- Mandatory two-factor authentication for staff
- Background checks & confidentiality covenants
Cryptographic Protection
All data transmitted between your device and our servers is secured using Transport Layer Security (TLS 1.3) protocols. Sensitive personal files and identification documents stored within our databases are encrypted at rest using bank-grade AES-256 cryptographic algorithms. Passwords and financial credentials undergo salted cryptographic hashing, ensuring they cannot be read even by internal system administrators.
Role-Based Access Control (RBAC)
Access to sensitive customer records is restricted to authorized compliance officers and financial verification personnel on a strict "need-to-know" basis. Every administrative access event is logged in permanent audit trails to prevent unauthorized internal data browsing.
Certified Data Protection Officer (DPO)
In compliance with National Privacy Commission regulations, we have appointed an independent, certified Data Protection Officer (DPO). The DPO oversees data governance policies, conducts regular privacy impact assessments (PIAs), and acts as the official liaison between players and regulatory bodies.
Third-Party Disclosures and Data Sharing
We maintain a strict policy regarding the sharing of player data. We do not sell, rent, lease, or commercialize your personal information to third-party marketing brokers or independent advertisers under any circumstances.
Disclosures occur strictly within the following authorized channels:
- Government Regulatory Bodies: Providing necessary reports to PAGCOR, the Anti-Money Laundering Council (AMLC) under Republic Act 9160, and law enforcement agencies pursuant to valid court subpoenas or statutory reporting mandates.
- Regulated Payment Service Providers: Transmitting transaction data across encrypted APIs to authorized Philippine financial institutions, including GCash and Maya, solely to execute deposits and withdrawals.
- Certified Game Software Developers: Sharing anonymized player session tokens with licensed software studios (such as Pragmatic Play or JILI) to load games and calculate payouts, with zero sharing of real identity documents.
- Cloud Infrastructure Providers: Utilizing secure, enterprise cloud hosting providers operating under strict data processing agreements that guarantee adherence to Philippine privacy standards.
Statutory Rights of Data Subjects Under Republic Act 10173
Under the Data Privacy Act of 2012, every player registered on our platform holds explicit statutory rights as a data subject. You may exercise these rights at any time by contacting our Data Protection Officer:
| Statutory Data Subject Rights (RA 10173) |
|---|
v v
[Right to be Informed] [Right to Object]
Transparent disclosure of data handling Opt out of commercial marketing
v v
[Right to Access] [Right to Rectification]
Request copies of personal records Correct inaccurate or outdated data
v v
[Right to Erasure / Blocking] [Right to Damages]
Request data removal (post-retention) Compensation for proven privacy harms
Detailed Breakdown of Your Privacy Rights
- Right to be Informed: You have the right to know whether personal data pertaining to you is being collected, stored, or processed, alongside the purpose and extent of processing.
- Right to Access: You may request reasonable access to your personal data, transaction history, and account records held in our systems.
- Right to Rectification: You have the right to dispute any inaccuracy or error in your personal data and have the operator correct it immediately upon providing supporting documentation.
- Right to Erasure or Blocking: You may request the suspension, withdrawal, or removal of your personal information from our active databases, provided that the data is no longer necessary for statutory AMLA compliance or legal proceedings.
- Right to Object: You have the right to withhold consent or object to the processing of your personal data for direct marketing, promotional profiling, or automated decision-making.
- Right to Data Portability: Where processing is conducted via electronic means, you may obtain a copy of your personal data in an electronic or structured format for transfer to another entity.
- Right to File a Complaint: If you believe your personal data has been mishandled or your rights violated, you possess the statutory right to file a formal complaint directly with the National Privacy Commission (NPC).
Data Retention and Secure Disposal
Under standard circumstances, personal data should only be kept as long as necessary to fulfill its operational purpose. However, in the regulated gaming sector, statutory retention mandates take precedence over immediate deletion requests:
- Mandatory 5-Year AMLA Retention: In accordance with Republic Act 9160 and PAGCOR regulatory guidelines, customer identification files, verification records, and transaction histories must be securely preserved for a period of five (5) years following the formal closure of an account.
- Secure Destruction Protocols: Once the statutory five-year retention window expires, all digital records are permanently expunged utilizing certified cryptographic wiping standards, and physical copies (if any) are destroyed via secure industrial shredding.
Responsible Gaming Integration and Welfare Protections
Data privacy tools also serve to protect player health. If a player submits a request for self-exclusion under the National Voluntary Exclusion Program managed by PAGCOR, their identity details are securely flagged to restrict further gameplay while preserving absolute confidentiality regarding their medical or psychological status.
For players seeking assistance with gambling-related distress or looking to understand responsible gaming practices, resources are accessible through Gamblers Anonymous and Gambling Therapy.
Frequently Asked Questions
Can I request that the casino delete all my identification documents immediately after closing my account?
Under standard circumstances, data subjects have the right to erasure. However, Section 12 of Republic Act 10173 and Republic Act 9160 (AMLA) mandate that covered institutions preserve customer identification files and transaction records for five (5) years following account closure. After this statutory period expires, your data is permanently deleted.
Does the platform share my personal phone number with third-party SMS marketing spammers?
No. We adhere to a strict anti-spam policy. Your mobile number is used exclusively for account authentication (SMS OTPs), security notifications, and critical operational updates. We never sell or share contact details with external marketing telemarketers.
How do I update my registered name or residential address if my information changes?
To update your personal details, contact our customer support desk or Data Protection Officer with updated official documentation (such as a newly issued PhilSys ID, updated Driver's License, or marriage certificate) to ensure compliance with KYC standards.
Is my facial biometric data from the liveness check shared with external databases?
No. Biometric liveness data captured during the onboarding verification process is processed in an encrypted format solely to confirm that you are the rightful owner of the submitted ID card. It is never shared with external commercial facial recognition databases.
Who can I contact if I have concerns about how my data is being handled?
You may contact our designated Data Protection Officer (DPO) via email at `dpo@` platform domain. If your concern is not satisfactorily resolved, you possess the statutory right under Republic Act 10173 to submit a formal complaint to the National Privacy Commission.
How does the website protect transactions processed through GCash and Maya?
Financial transactions are conducted through encrypted APIs adhering to PCI-DSS standards. We never receive or store your personal GCash or Maya MPIN or banking passwords; payment authorization takes place entirely within the financial provider's secure banking interface.
Connected Resources and Platform Portals
- Filbet Main Gaming Portal
- Filbet Account Setup and Verification Procedures
- GCash and Maya Deposit and Withdrawal Manual
- Digital Slot Game Features and Auditing Standards
- Live Dealer Studio Integrity and Video Streams
- Philippine Perya Games and Classic Wagering Rules
- Responsible Gaming Policies and Exclusion Framework
Official Member Access and Registration
To access real-money gaming tables, practice slot mechanics, or claim verified promotional credits, visit the official Filbet Portal on mobile or desktop.