1. Data Controller
For the purposes of the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, the data controller responsible for the personal information of users of the ah333 Casino platform is ah333 Casino, operating under the domain ah333.club ("ah333," "we," "us," "our").
ah333 has designated a Data Protection Officer (DPO) responsible for overseeing compliance with this Privacy Policy and with RA 10173. The DPO may be contacted at the email address specified in Section 14 of this Policy. All data subject rights requests, privacy complaints, and data breach notifications should be directed to the DPO in the first instance.
Regulatory Framework
ah333's data processing activities are governed by: Republic Act No. 10173 (Data Privacy Act of 2012); National Privacy Commission (NPC) Advisory Opinions and Circulars; PAGCOR regulations applicable to licensed online gaming operators; Republic Act No. 9160 as amended (Anti-Money Laundering Act); and Republic Act No. 10175 (Cybercrime Prevention Act of 2012).
2. Personal Data We Collect
ah333 collects the following categories of personal data from users of the platform. In each case, we collect only data that is necessary and proportionate to the purposes described in Section 4 of this Policy.
2.1 Identity and Contact Data
- Full legal name as it appears on a valid Philippine government-issued identification document
- Date of birth (for age verification — 21+ requirement is strictly enforced)
- Residential address in the Philippines (barangay, city/municipality, province)
- Email address
- Philippine mobile number (09XX format)
- Nationality and country of residence
2.2 Identity Verification (KYC) Data
- Copies or images of valid Philippine government-issued photo identification (e.g., PhilSys National ID, passport, driver's licence, SSS/UMID card, voter's ID)
- Proof of address documents (e.g., utility bills, bank statements, barangay certificate dated within 90 days)
- Proof of payment method ownership (e.g., GCash or PayMaya account screenshot showing registered name)
- Selfie or live video verification for identity confirmation, where required
2.3 Financial Data
- Transaction history including deposits and withdrawals in Philippine Peso
- GCash, PayMaya, BPI, BDO, Metrobank, or other payment method identifiers (account numbers or wallet IDs associated with your registered payment methods — full payment credentials are not stored by ah333 and are processed exclusively by the relevant payment provider)
- Bonus and promotional transaction records
2.4 Gaming and Usage Data
- Gaming history including games played, bets placed, and results across all ah333 game categories
- Session data including login timestamps, session duration, and device information
- Responsible gaming tool usage, including deposit limits set, self-exclusion requests, and session reminder preferences
- Customer support interaction records including live chat transcripts and email correspondence
2.5 Technical Data
- IP address and approximate geolocation (city/region level)
- Device type, operating system, and browser information
- Cookies and similar tracking technology data as described in Section 10
- Platform event logs for security monitoring and fraud prevention purposes
3. How We Collect Your Data
ah333 collects personal data through the following means:
- Direct Collection: Data provided by you during account registration, KYC verification, deposit and withdrawal processing, customer support contacts, promotional registrations, and responsible gaming tool configuration
- Automated Collection: Technical data collected automatically as you use the ah333 platform — including via cookies, session tokens, device fingerprinting, and server access logs
- Third-Party Sources: Identity verification data from KYC service providers; fraud and AML screening data from compliance screening services; payment verification data from GCash, PayMaya, and banking partners; and publicly available information where relevant to security or compliance investigations
ah333 does not purchase personal data lists from data brokers or marketing aggregators. We do not obtain personal data from social media platforms without your explicit consent.
4. Purposes of Processing
ah333 processes personal data for the following specific, legitimate purposes:
- Account Management: Creating and maintaining your ah333 account; authenticating your identity at login; and communicating essential account-related information
- Age Verification: Verifying that all registered users are at least 21 years of age as required by PAGCOR and Philippine gaming regulations
- KYC and AML Compliance: Meeting our legal obligations under the Anti-Money Laundering Act (RA 9160 as amended) and PAGCOR requirements, including customer due diligence and transaction monitoring
- Payment Processing: Processing deposits and withdrawals via GCash, PayMaya, BPI, BDO, Metrobank, and other approved Philippine payment channels
- Game Provision: Enabling access to and operation of all ah333 game categories including slots, live casino, sports betting, e-sabong, and bingo
- Responsible Gaming: Monitoring gaming patterns to identify potential problem gambling indicators; operating deposit limits, self-exclusion, and other responsible gaming tools; and complying with PAGCOR's responsible gaming requirements
- Security and Fraud Prevention: Detecting, investigating, and preventing unauthorised access, fraud, collusion, cheating, and other prohibited activities on the platform
- Customer Support: Responding to your enquiries, complaints, and requests; resolving disputes; and improving our support services
- Legal Compliance: Meeting our obligations under Philippine law including RA 10173, RA 9160, RA 10175, PAGCOR regulations, and any order of a competent Philippine court or regulatory authority
- Marketing (Opt-in Only): Sending promotional communications about ah333 bonuses, game launches, events, and offers — only where you have provided separate, explicit consent and have not subsequently withdrawn that consent
5. Legal Basis for Processing
Under the Data Privacy Act of 2012, ah333 processes personal data on the following legal bases:
- Contractual Necessity: Processing required to perform the contract between ah333 and you as a registered user (account management, game access, payment processing)
- Legal Obligation: Processing required to comply with applicable Philippine laws including RA 10173, RA 9160 (AMLA), and PAGCOR regulatory requirements (KYC, age verification, AML transaction monitoring)
- Legitimate Interests: Processing for fraud prevention, security monitoring, responsible gaming oversight, and platform improvement — where such interests do not override your fundamental rights and freedoms
- Consent: Processing for optional marketing communications — where your separate, freely given, specific, informed, and unambiguous consent has been obtained. You may withdraw marketing consent at any time without affecting the lawfulness of prior processing or your continued use of ah333
6. Data Sharing & Disclosure
ah333 does not sell, rent, or trade your personal data to third parties for their independent marketing purposes. We share personal data only in the following circumstances and only to the extent strictly necessary:
- Game Providers: Personal data necessary for game operation is shared with licensed game providers including JILI, PG Soft, Pragmatic Play, Evolution Gaming, and Ezugi, under contractual data processing agreements consistent with RA 10173
- Payment Processors: Financial and identity data required to process deposits and withdrawals is shared with GCash, PayMaya, BPI, BDO, Metrobank, and other approved payment providers, each bound by their own applicable data protection obligations
- KYC and Compliance Service Providers: Identity documents and verification data shared with contracted KYC verification and AML screening services operating under data processing agreements with ah333
- Regulatory Authorities: ah333 is required by law to disclose certain personal data to PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), and other competent Philippine regulatory authorities upon lawful request
- Law Enforcement: ah333 will disclose personal data to Philippine law enforcement authorities (e.g., NBI, PNP) pursuant to a valid court order, search warrant, or other legally compelled disclosure
- Corporate Transactions: In the event of a merger, acquisition, or sale of substantially all assets of ah333, personal data may be transferred to the relevant successor entity, subject to the same privacy protections as set out in this Policy
All third-party recipients of ah333 user data are required to implement security measures appropriate to the sensitivity of the data received and to process such data only for the specific purposes for which it was disclosed.
7. International Data Transfers
Some of ah333's game providers, technology vendors, and operational service providers are located outside the Philippines. Where personal data is transferred to a country that does not have data protection laws providing a level of protection equivalent to RA 10173, ah333 implements appropriate safeguards including:
- Contractual clauses in data processing agreements that impose data protection obligations on overseas recipients equivalent to those under Philippine law
- Transfers only to recipients in jurisdictions with adequate data protection frameworks as assessed by the National Privacy Commission
- Technical security measures including encryption in transit and at rest for all transferred data
By registering an ah333 account and using the platform, you acknowledge and consent to the transfer of your personal data to overseas recipients in the limited circumstances described above, subject to the safeguards set out in this Section.
8. Data Retention
ah333 retains personal data for as long as necessary to fulfil the purposes for which it was collected, as required by applicable Philippine law, or as permitted by the legitimate interests of ah333 as described in this Policy. The following general retention periods apply:
- Account Data: For the duration of your active ah333 account plus five (5) years following account closure, as required for AML and regulatory audit purposes under Philippine law
- KYC Documents: Five (5) years from the date of submission or from the date of account closure, whichever is later, as required by RA 9160 (Anti-Money Laundering Act)
- Financial Transaction Records: Five (5) years from the date of each transaction
- Gaming History: Three (3) years from the date of each gaming session, unless retention is required for longer for dispute resolution or compliance purposes
- Customer Support Records: Three (3) years from the date of the relevant interaction
- Technical and Log Data: Ninety (90) days for routine access logs; longer retention for logs related to identified security incidents or investigations
- Marketing Consent Records: Until withdrawal of consent plus three (3) years for evidentiary purposes
Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymised. Where data must be retained for a longer period due to active legal proceedings, regulatory investigation, or dispute resolution, retention will be extended accordingly.
9. Security Measures
ah333 implements a layered set of technical and organisational security measures designed to protect your personal data against unauthorised access, disclosure, alteration, loss, or destruction. These measures include:
- TLS/SSL encryption for all data transmitted between your device and the ah333 platform
- AES-256 encryption at rest for sensitive personal data stored in ah333 databases
- Multi-factor authentication for ah333 administrative systems access
- Role-based access controls limiting employee access to personal data to the minimum necessary for their specific job function
- Regular security vulnerability assessments and penetration testing of the ah333 platform
- 24/7 security event monitoring and anomaly detection on platform infrastructure
- Incident response procedures for rapid containment and notification in the event of a data breach, consistent with NPC breach notification requirements
Notwithstanding these measures, no data security system is impenetrable. In the event of a personal data breach affecting your ah333 account data, we will notify you and the NPC in accordance with the notification timelines prescribed by RA 10173 and NPC Circular 16-03.
10. Cookies & Tracking Technologies
ah333 uses cookies and similar technologies (session tokens, local storage, and device fingerprinting) on the ah333 platform. These technologies serve the following purposes:
- Essential Cookies: Required for the basic operation of the ah333 platform — maintaining your login session, preserving your game state, and ensuring platform security. These cookies cannot be disabled without affecting your ability to use ah333.
- Functional Cookies: Storing your language preference, responsible gaming settings, and other personalisation choices to improve your experience across sessions.
- Analytics Cookies: Collecting anonymised or pseudonymised data about how users interact with the ah333 platform — including pages visited, features used, and session duration — to improve platform design and performance. No personally identifiable information is included in analytics reports.
- Security Cookies: Device fingerprinting and session integrity tokens used to detect and prevent account takeover attempts, unusual login patterns, and other fraudulent activity.
You may configure your browser to block or delete cookies. Please note that blocking essential or security cookies will prevent you from logging in to or using your ah333 account. For functional and analytics cookies, you may opt out via your browser settings without affecting core platform functionality.
11. Your Rights Under RA 10173
As a data subject under the Data Privacy Act of 2012, you have the following rights with respect to your personal data processed by ah333. Requests to exercise any of these rights should be directed to ah333's Data Protection Officer at the contact details in Section 14.
Right to Be Informed
The right to be informed of the purposes, scope, and manner of processing of your personal data prior to its collection. This Privacy Policy fulfils ah333's notification obligation under Section 16(a) of RA 10173.
Right to Access
The right to request a copy of your personal data held by ah333 — including the categories of data, sources, recipients, and processing purposes. ah333 will respond to verified access requests within 15 business days.
Right to Rectification
The right to request correction of any inaccurate or incomplete personal data ah333 holds about you. Where possible, corrections to account data (name, address, contact details) may be made directly in your account settings.
Right to Erasure
The right to request deletion of your personal data where processing is no longer necessary or lawful. Note that this right is subject to ah333's legal obligations under RA 9160 (AMLA) and PAGCOR regulations which may require retention of certain data regardless of erasure requests.
Right to Object
The right to object to the processing of your personal data for marketing purposes or for processing based on ah333's legitimate interests. Objections to marketing may be exercised at any time via your account notification settings or by contacting the DPO.
Right to Complain (NPC)
The right to lodge a complaint with the National Privacy Commission of the Philippines if you believe ah333 has violated your rights under RA 10173. NPC complaints may be filed at privacy.gov.ph. Please contact ah333's DPO first to attempt resolution before escalating to the NPC.
12. Children's Privacy
ah333 Casino does not knowingly collect, process, or store personal data from individuals under the age of 21 years. The platform enforces a strict 21+ age restriction as required by PAGCOR. Age is verified at registration via government-issued Philippine identification, and any account found to belong to a person under 21 years will be immediately closed.
If you are a parent or guardian and believe that a person under 21 in your care has provided personal data to ah333 or created an ah333 account without your knowledge, please contact ah333's Data Protection Officer at [email protected] immediately. ah333 will investigate and, where confirmed, will delete the relevant personal data and close the account without delay.
13. Amendments to This Policy
ah333 reserves the right to update this Privacy Policy at any time to reflect changes in our data processing practices, applicable Philippine law, NPC guidance, or regulatory requirements. When material changes are made, we will notify you by: (a) displaying a prominent notice on the ah333 homepage; (b) sending a notification to your registered email address; and/or (c) updating the "Last Updated" date at the top of this document.
Your continued use of ah333 following the effective date of any amended Privacy Policy constitutes acceptance of the revised Policy. If you do not accept the amended Policy, you must cease using ah333 and may request account closure in accordance with Section 12 of the Terms and Conditions.
14. Contact & Data Protection Officer
For any question, concern, or formal request relating to this Privacy Policy or the processing of your personal data by ah333, please contact our Data Protection Officer:
Data Protection Officer — ah333 Casino
Email:
[email protected] (plain text — not a clickable link)
Subject line: "Data Privacy Request – [Your Registered Name]"
Platform: ah333.club
Response time: Within 15 Philippine business days of a verified request
For responsible gaming-related requests including self-exclusion and gaming limit adjustments, please include "Responsible Gaming Request" in the subject line. All data privacy and responsible gaming requests are handled with strict confidentiality.
For complaints that cannot be resolved through ah333's internal process, you may escalate your complaint to the National Privacy Commission of the Philippines — the competent supervisory authority for RA 10173 compliance in the Philippines.
Our Privacy Commitments at a Glance
RA 10173 Compliant
ah333's data processing practices are fully aligned with the Data Privacy Act of 2012 and NPC implementing regulations. Our DPO oversees ongoing compliance and handles all data subject rights requests from Filipino users.
AES-256 Encryption
All sensitive personal data stored in ah333's systems is encrypted at rest using AES-256. All data in transit between your device and the ah333 platform is protected by TLS/SSL encryption. Your GCash and bank credentials are never stored by ah333.
No Data Sales
ah333 does not sell, rent, or trade your personal data to third-party marketers or data brokers. Your data is shared only with contracted service providers and regulatory authorities as described in Section 6 of this Policy — never for commercial gain.
Opt-in Marketing Only
ah333 sends promotional communications only to users who have explicitly opted in. You can withdraw marketing consent at any time — via your account settings or by contacting support — without any effect on your ability to use ah333.
Your Rights Respected
ah333 respects all data subject rights under RA 10173 — access, rectification, erasure, objection, and the right to lodge a complaint with the NPC. The DPO responds to verified rights requests within 15 Philippine business days.
Defined Retention Periods
ah333 retains personal data only for as long as legally required and operationally necessary. Retention periods are set in compliance with RA 9160 (AMLA) and PAGCOR requirements. Data is securely deleted or anonymised upon expiry of the applicable retention period.