At aaaph, the privacy of every Filipino player matters. This policy explains exactly what personal data we collect, why we collect it, how we use and protect it, and what rights you have over your information — all in plain language, consistent with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173).
This Privacy Policy ("Policy") describes how aaaph Casino ("aaaph," "We," "Us," or "Our"), operator of aaaph.biz, collects, processes, stores, and protects the personal information of registered players, visitors, and other individuals who interact with the platform ("you," "your," or "Data Subject").
aaaph is committed to the responsible and lawful processing of personal data in accordance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and the applicable issuances of the National Privacy Commission (NPC). Where aaaph processes data in connection with its PAGCOR-regulated gaming operations, this Policy also reflects the data processing requirements imposed under PAGCOR's licensing framework.
By registering an account on aaaph.biz or using any service provided by aaaph, you acknowledge that you have read and understood this Policy and consent to the processing of your personal data as described herein. If you do not agree to the terms of this Policy, you should not register an account or use the platform.
1.1 aaaph Casino is the Personal Information Controller (PIC) in respect of personal data collected through aaaph.biz and its associated services. This means aaaph determines the purposes and means by which personal information is processed.
1.2 This Policy applies to all personal data collected from:
1.3 This Policy should be read alongside aaaph's Terms and Conditions and Responsible Gaming Policy, both of which are accessible via the links on aaaph.biz.
2.1 aaaph collects the minimum personal data necessary to operate a licensed online gaming platform and comply with applicable Philippine law. The categories of data we collect include:
| Category | Examples | Purpose |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government ID type and number (UMID, PhilSys, Driver's License, Passport) | KYC verification, age verification, fraud prevention, AMLA compliance |
| Contact Data | Philippine mobile number, email address, residential address (city, province, barangay) | Account management, communications, transaction notifications, support |
| Financial Data | GCash account number, Maya account number, bank account details (BPI, BDO, Metrobank), transaction history, deposit and withdrawal amounts | Payment processing, withdrawal verification, AMLA reporting, fraud detection |
| Gaming Activity Data | Game history, betting patterns, wager amounts, session duration, game preferences, bonus usage | Platform operation, responsible gaming monitoring, product improvement, bonus eligibility |
| Technical Data | IP address, device type and identifier, operating system, browser type, geolocation (approximate), session logs | Security monitoring, fraud detection, platform optimisation, regulatory reporting |
| Communications Data | Support chat transcripts, email correspondence, survey responses, feedback submissions | Dispute resolution, service improvement, quality assurance, regulatory compliance |
| Sensitive Personal Information | Self-exclusion status, responsible gaming flags, KYC document images (as required under AMLA) | Responsible gaming compliance, PAGCOR regulatory reporting, AMLA obligations |
2.2 aaaph does not collect biometric data (fingerprints, facial recognition data) through the platform, except where a player voluntarily uses their device's biometric authentication to access their account — in which case the biometric processing occurs entirely on the player's personal device and is not transmitted to aaaph.
3.1 Directly from you: When you register an account, complete KYC verification, submit a deposit or withdrawal request, contact customer support, respond to a survey, or interact with any feature of aaaph.biz that requires you to provide information.
3.2 Automatically during platform use: aaaph's systems collect technical data automatically as you navigate the platform — including session logs, device information, IP addresses, and clickstream data. This collection occurs through cookies, server logs, and similar technologies described in Section 7.
3.3 From third-party sources: aaaph may receive personal data from the following categories of third parties:
4.1 aaaph processes personal data only for specific, lawful, and declared purposes. The primary purposes for which your data is used include:
5.1 Under the Philippine Data Privacy Act and its Implementing Rules, aaaph relies on the following legal bases for processing personal data:
5.2 For processing of sensitive personal information (as defined under Section 3(l) of RA 10173), aaaph relies on your explicit consent obtained at registration, or on the legal obligation basis where such processing is required under PAGCOR or AMLA frameworks.
6.1 aaaph does not sell, rent, or trade your personal data to third-party marketers or data brokers. Your data is shared only where necessary for the lawful purposes described in this Policy, specifically with:
6.2 All third-party processors engaged by aaaph are required to maintain data security standards consistent with RA 10173 and may only process data for the specific purposes for which they were engaged.
7.1 aaaph.biz uses cookies and similar tracking technologies to operate the platform, maintain your session, and analyse usage patterns. The following categories of cookies are used:
7.2 aaaph does not use third-party advertising or tracking cookies that follow you across unrelated websites. The analytics and tracking technologies used on aaaph.biz are limited to first-party tools and vetted service providers engaged specifically for platform operation.
7.3 You may manage cookie preferences through your browser settings. Disabling strictly necessary cookies will affect your ability to log in and use the platform.
8.1 aaaph retains personal data only for as long as necessary for the purposes described in this Policy, or as required by applicable Philippine law, whichever is longer. The following indicative retention periods apply:
8.2 Upon expiry of the applicable retention period, personal data will be securely deleted or anonymised so that it can no longer be associated with an identifiable individual.
9.1 aaaph implements a layered technical and organisational security programme to protect personal data against unauthorised access, disclosure, alteration, and destruction. Key measures include:
9.2 While aaaph implements robust security measures, no online platform can guarantee absolute security. You can strengthen your own account security by using a strong, unique password, enabling 2FA, and ensuring the security of your registered Philippine mobile number and linked e-wallet accounts.
10.1 aaaph's primary data processing infrastructure is located within the Philippines. However, some of aaaph's service providers — including certain game providers, cloud infrastructure providers, and technical support partners — may be located or operate infrastructure outside the Philippines.
10.2 Where personal data is transferred outside the Philippines, aaaph ensures that such transfers are subject to appropriate safeguards consistent with the requirements of Section 21 of RA 10173 and the NPC's guidelines on cross-border data transfers. These safeguards may include:
10.3 Details of aaaph's cross-border transfer mechanisms are available on request from the Data Protection Officer.
11.1 Under the Philippine Data Privacy Act of 2012, you have the following rights in respect of your personal data held by aaaph:
11.2 To exercise any of the above rights, please contact aaaph's Data Protection Officer using the contact details in Section 14. aaaph will acknowledge your request within 5 Philippine business days and respond substantively within 30 days, or within the period required by the NPC's guidelines.
12.1 If aaaph becomes aware that personal data has been submitted by or on behalf of a person under 21 years of age, all such data will be immediately deleted, the account will be closed, and any deposits will be returned to their source. Where aaaph has reason to believe that a minor has been assisted in circumventing age restrictions, the matter may be referred to relevant Philippine authorities.
12.2 If you are a parent or guardian and believe that your child (under 21) has registered on aaaph, please contact us immediately via the support team so the account can be closed and data removed.
13.1 aaaph may update or amend this Privacy Policy from time to time to reflect changes in our data practices, applicable Philippine law, or NPC guidance. The revised Policy will be posted on aaaph.biz with an updated effective date.
13.2 Where changes are material — for example, where we begin processing personal data for a new purpose, or where we change the category of third parties with whom data is shared — aaaph will provide advance notice via a prominent notice on the platform and, where practicable, by email to registered accounts, no less than 7 days before the change takes effect.
13.3 Your continued use of aaaph following notification of a material change constitutes your acknowledgement of the updated Policy. Where the change requires fresh consent, aaaph will seek it explicitly before the new processing begins.
14.1 aaaph has designated a Data Protection Officer (DPO) in accordance with Section 21(c) of RA 10173. The DPO is responsible for overseeing aaaph's data protection programme, acting as a point of contact for data subjects and the NPC, and ensuring compliance with this Policy.
14.2 For any privacy-related queries, requests to exercise your data subject rights, or concerns about aaaph's data practices, please contact:
14.3 If you are not satisfied with aaaph's handling of your privacy concern, you have the right to lodge a complaint with the National Privacy Commission of the Philippines (NPC). The NPC can be contacted through its official government channels.
The Philippine Data Privacy Act gives you real, enforceable rights over your personal information. Here is what each right means for your aaaph account.
You have the right to know exactly what data aaaph holds about you, why it was collected, and what it is being used for — before collection where possible, and at any time upon request.
Request a full copy of the personal data aaaph holds in your account, including transaction records, KYC data, and gaming history. Requests are processed within 30 days of identity verification.
If your name, contact details, or any other information in your aaaph account is incorrect or outdated, you have the right to request a correction. Some changes require KYC re-verification.
Request deletion or blocking of your personal data where it is no longer needed for its original purpose or where processing was unlawful — subject to aaaph's legal retention obligations under AMLA and PAGCOR regulations.
Receive a structured, machine-readable copy of the personal data you've provided to aaaph — useful if you want to migrate your account history or review your data independently.
Object to specific processing activities, withdraw marketing consent at any time, and if unsatisfied with aaaph's response, lodge a formal complaint with the National Privacy Commission (NPC) of the Philippines.
Privacy at aaaph is an operating standard, not a compliance exercise. Here are six ways those commitments show up in practice for Filipino players.
aaaph does not sell, rent, or trade your personal information to third-party marketers or data brokers — ever. The only parties who receive your data are those directly involved in operating your account and processing your transactions, under contractual privacy obligations.
Every connection between your device and aaaph's servers uses SSL 256-bit encryption — the same standard used by Philippine banks and BSP-supervised financial institutions. Your personal data and payment details are encrypted in transit and at rest.
aaaph collects only the personal data necessary to operate a licensed Philippine gaming platform. If a piece of information is not required for account operation, legal compliance, or player safety, aaaph doesn't collect it. No excessive data collection for speculative future uses.
Withdrawing marketing consent in aaaph account settings takes effect immediately. You will stop receiving promotional emails and SMS within one business day. Withdrawing consent has no effect on your ability to use the platform or receive essential account notifications.
aaaph retains your data only for as long as legally required or operationally necessary. Gaming activity logs are deleted after 3 years; support communications after 2 years. KYC and financial data is retained for 5 years as required by Philippine AMLA law, then securely deleted.
aaaph's data protection programme is designed to comply with the Philippine Data Privacy Act (RA 10173) and the National Privacy Commission's guidelines. Disputes are handled under Philippine jurisdiction, giving Filipino players access to familiar legal protections and local regulatory recourse.
Our Data Protection Officer and support team are available 24/7 to help with any privacy query.
Visit aaaph Casino