Introduction
This Privacy Policy ("Policy") describes how phdre ("phdre," "we," "us," "our") collects, uses, stores, shares, and protects the personal data of individuals ("you," "Player," "User") who access or use the phdre online gaming platform available at phdre.net and all associated mobile interfaces, applications, and services.
This Policy is intended to be read alongside phdre's Terms and Conditions and Responsible Gaming Policy, all of which collectively govern your relationship with phdre. In the event of any conflict between this Policy and the Terms and Conditions on a privacy-related matter, this Policy shall prevail.
phdre is committed to full compliance with the Data Privacy Act of the Philippines (RA 10173) and its implementing rules and regulations, as administered by the National Privacy Commission (NPC). We process your personal data lawfully, fairly, and transparently — and only for the specific purposes described in this Policy.
If you have any questions about this Policy or your data rights, contact phdre's Data Protection Officer (DPO) at [email protected] at any time.
Who We Are
phd re is an online gaming platform operating under the PAGCOR regulatory framework, providing Filipino players with access to slots, live dealer games, sports betting, bingo, e-sports, and sabong. phdre serves players across the Philippines, including those based in Metro Manila, Cebu, Davao, Quezon City, Makati, and beyond.
For the purposes of the Data Privacy Act of the Philippines, phdre acts as the Personal Information Controller (PIC) with respect to the personal data of its registered players and website visitors. As PIC, phdre determines the purposes and means by which your personal data is processed.
Third-party service providers engaged by phdre — including payment processors, KYC verification providers, and game content suppliers — act as Personal Information Processors (PIP) operating under data processing agreements with phdre. They may only process your data on phdre's documented instructions and in accordance with applicable Philippine data privacy law.
Data We Collect
phdre collects only the personal data necessary for the purposes described in this Policy. The categories of personal data we collect are set out in the table below:
| Category | Examples | Required? |
|---|---|---|
| Identity Data | Full legal name, date of birth, gender, nationality, government-issued ID (PhilSys, passport, driver's license, SSS, GSIS, PRC ID) | Required |
| Contact Data | Email address, mobile number (Smart, Globe, or DITO), residential address (barangay, city, province) | Required |
| Account Data | Username, encrypted password, account ID, registration date, account status, session history | Required |
| Financial Data | GCash mobile number, Maya account details, BPI/BDO/Metrobank account name and number (last 4 digits only), deposit and withdrawal transaction records, wallet balance history | Required |
| Gaming Data | Game session logs, wager history, bet amounts, game outcomes, bonus participation, win/loss records, RTP data | Required |
| KYC & Verification Data | Copies of government-issued IDs, selfie/liveness verification images, proof of address documents, source of funds declarations | Required for withdrawals |
| Device & Technical Data | IP address, device type, operating system, browser type and version, screen resolution, device ID, geolocation (region/province level) | Automatic |
| Usage Data | Pages visited, features used, time spent on platform, click patterns, search queries within the platform | Automatic |
| Communications Data | Live chat transcripts, email correspondence with support, feedback submissions | Where applicable |
| Responsible Gaming Data | Deposit limits set, self-exclusion records, cooling-off periods, session alerts, problem gambling indicators flagged by our monitoring system | Where applicable |
phdre does not collect sensitive personal information such as racial or ethnic origin, religious beliefs, health data (except where directly relevant to responsible gaming assessments), or political affiliation unless specifically required by law.
How We Collect Your Data
phdre collects your personal data through the following channels:
- Direct collection: Information you provide when registering an account, completing KYC verification, making deposits or withdrawals, contacting support, or submitting feedback forms on the phdre platform.
- Automated collection: Technical and usage data collected automatically via cookies, web beacons, server logs, and similar tracking technologies when you access the phdre website or app. See Section 8 for full details on cookies.
- Third-party sources: Identity and fraud verification data received from KYC providers; payment verification data from GCash, Maya, BPI, BDO, Metrobank, and other payment partners; geolocation data from network providers; and publicly available data used for AML/fraud screening purposes.
- PAGCOR and regulatory sources: Information received from PAGCOR or other Philippine regulatory authorities as part of ongoing compliance obligations, including self-exclusion register data.
How We Use Your Data
phdre uses your personal data strictly for the following purposes:
- Account management: Creating and maintaining your phdre account, verifying your identity, managing your login credentials, and communicating account-related updates.
- KYC and age verification: Confirming that you meet the 21+ age requirement under Philippine gambling regulations and verifying your identity as required by PAGCOR and AML legislation.
- Payment processing: Facilitating GCash, Maya, QR Ph, GrabPay, BPI, BDO, and Metrobank deposits and withdrawals, verifying payment account ownership, and maintaining accurate financial records.
- Gaming and platform operations: Delivering game content, calculating game outcomes, managing bonuses and promotions, and maintaining accurate game session records.
- Regulatory compliance: Meeting phdre's obligations under PAGCOR regulations, the Anti-Money Laundering Act (RA 9160), and other applicable Philippine law, including filing Suspicious Transaction Reports (STRs) where required.
- Responsible gaming: Monitoring player activity for signs of problem gambling, enforcing deposit limits and self-exclusion orders, and fulfilling obligations under PAGCOR's responsible gaming framework.
- Fraud prevention and security: Detecting, investigating, and preventing fraudulent transactions, account takeovers, bonus abuse, and other prohibited conduct on the phdre platform.
- Customer support: Responding to your inquiries, resolving disputes, and maintaining records of support interactions for quality assurance purposes.
- Platform improvement: Analyzing usage patterns and player feedback to improve the phdre platform, optimize game performance, and develop new features — using aggregated and anonymized data where possible.
- Marketing communications: Sending you promotional offers, bonus notifications, and platform updates via email or SMS — only where you have consented to receive such communications. You may withdraw consent at any time by contacting support.
Legal Basis for Processing
Under the Data Privacy Act of the Philippines, phdre processes your personal data on the following legal bases:
- Contractual necessity: Processing your identity, contact, account, financial, and gaming data is necessary to perform our contract with you — namely, providing you access to the phdre platform and gaming services.
- Legal obligation: Processing your KYC, AML-related, and responsible gaming data is necessary to comply with PAGCOR regulations, the Anti-Money Laundering Act, the Data Privacy Act, and other applicable Philippine law.
- Legitimate interests: Processing device, technical, and usage data for fraud prevention, platform security, and service optimization, where these interests do not override your fundamental data privacy rights.
- Consent: Processing your data for direct marketing communications, and for any optional data collection activities that go beyond what is strictly necessary for platform operations. You may withdraw consent at any time without affecting the lawfulness of processing that occurred before withdrawal.
Data Sharing & Third Parties
phdre does not sell, rent, or trade your personal data to third parties for their own marketing purposes. We share your data only in the circumstances described below, and only to the extent necessary for each specific purpose:
- Payment processors: GCash (GXI), Maya Philippines, GrabPay, BPI, BDO, Metrobank, and other payment partners receive transaction-specific data necessary to process your deposits and withdrawals. These partners are subject to their own privacy policies and BSP regulations.
- KYC and identity verification providers: Third-party verification services receive copies of your identity documents and biometric verification data for the sole purpose of confirming your identity and age. These providers operate under data processing agreements with phdre.
- Game content providers: Game suppliers may receive anonymized session and wager data necessary to deliver game content, calculate outcomes, and maintain game integrity. No directly identifiable personal data is shared with game providers beyond what is technically required.
- Regulatory authorities: PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), and other competent Philippine authorities may receive your data where required by law, court order, or regulatory direction. phdre will cooperate fully with any lawful request from these bodies.
- Fraud prevention services: Fraud detection and cybersecurity providers may receive technical and transactional data for the purpose of identifying and preventing unauthorized or fraudulent activity on the platform.
- Group entities: Where phdre operates as part of a corporate group, data may be shared with group entities for consolidated compliance, risk management, and operational purposes — under the same data protection standards that apply to phdre.
Cookies & Tracking Technologies
phdre uses cookies and similar tracking technologies on the phdre.net website and associated platform interfaces. Cookies are small text files stored on your device that help phdre recognize you across sessions, personalize your experience, and understand how the platform is used.
phdre uses the following categories of cookies:
- Essential cookies: Strictly necessary for the platform to function — including session management, login authentication, and security tokens. These cannot be disabled without breaking core platform functionality.
- Functional cookies: Remember your preferences such as language settings, preferred payment method, and display options. Disabling these may reduce your platform experience but will not prevent you from logging in.
- Analytics cookies: Collect anonymized usage data — such as which pages are visited most frequently and how players navigate the platform — to help phdre improve its services. phdre uses first-party analytics tools for this purpose.
- Security cookies: Support fraud detection and bot prevention systems by identifying unusual patterns in device behavior or session activity.
You may manage your cookie preferences through your browser settings. Note that disabling essential cookies will prevent you from accessing your phdre account. phdre does not use third-party advertising cookies or cross-site tracking cookies for behavioral advertising purposes.
Data Retention
phdre retains your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable Philippine law. The following retention periods apply:
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Account and identity data | Duration of account + 5 years after closure | PAGCOR regulations, AML Act |
| Financial transaction records | 5 years from transaction date | Anti-Money Laundering Act (RA 9160) |
| KYC and verification documents | 5 years after account closure | PAGCOR KYC requirements, AMLC rules |
| Game session and wagering logs | 3 years from session date | Regulatory compliance, dispute resolution |
| Support communications | 2 years from last interaction | Legitimate interest (service quality) |
| Marketing consent records | Until consent is withdrawn + 1 year | Data Privacy Act compliance |
| Self-exclusion records | Permanent (as required by PAGCOR) | PAGCOR responsible gaming framework |
| Device and technical logs | 12 months from collection | Fraud prevention, security |
Upon expiry of the applicable retention period, phdre will securely delete or anonymize your personal data. Where anonymization is applied, the resulting anonymized data may be retained indefinitely for statistical and platform improvement purposes, as it no longer constitutes personal data under the Data Privacy Act.
Data Security
phdre implements technical and organizational security measures designed to protect your personal data against unauthorized access, loss, alteration, disclosure, or destruction. These measures include:
- 256-bit SSL/TLS encryption: All data transmitted between your device and phdre servers is encrypted using industry-standard TLS 1.2 or higher protocols.
- Encryption at rest: Sensitive personal data — including identity documents and financial account details — is stored in encrypted form on phdre's secure servers.
- Access controls: Access to personal data within phdre's systems is restricted on a strict need-to-know basis using role-based access controls. All staff with data access undergo regular privacy and security training.
- Two-factor authentication (2FA): phdre supports optional SMS OTP-based 2FA for player accounts and mandates 2FA for all internal staff accounts with data access privileges.
- Regular security assessments: phdre conducts periodic vulnerability assessments and penetration tests to identify and remediate security weaknesses before they can be exploited.
- Incident response: phdre maintains a documented data breach response procedure. In the event of a personal data breach, phdre will notify the National Privacy Commission and affected players within 72 hours of becoming aware of the breach, as required by the Data Privacy Act.
While phdre takes all reasonable measures to protect your data, no internet-based platform can guarantee absolute security. You are responsible for maintaining the confidentiality of your own login credentials and for notifying phdre immediately if you suspect unauthorized access to your account.
Your Data Rights
Under the Data Privacy Act of the Philippines, you have the following rights with respect to your personal data held by phdre. These rights may be exercised by contacting phdre's Data Protection Officer at [email protected] or via 24/7 live chat:
phdre will respond to all verified data rights requests within fifteen (15) business days of receipt. Where a request is complex or involves a large volume of data, phdre may extend this period by a further fifteen (15) business days, with prior written notice to you.
Minors & Age Verification
phdre strictly prohibits access to its platform by individuals under 21 years of age, in accordance with Philippine gambling regulations. phdre does not knowingly collect personal data from persons under 21.
Age verification is a mandatory step in the phdre registration and KYC process. Players must confirm their date of birth during registration and must provide a valid government-issued Philippine ID confirming they are 21 or older during KYC verification. Any account found to belong to a person under 21 will be immediately closed and all associated data will be securely deleted, except where retention is required by law.
Policy Updates
phdre may update this Privacy Policy from time to time to reflect changes in our data practices, applicable Philippine law, or PAGCOR regulatory requirements. When we make changes, the revised Policy will be published on this page with an updated effective date displayed at the top.
For material changes that significantly affect how your personal data is processed, phdre will provide advance notice via email to your registered address or through an in-platform notification. Where required by the Data Privacy Act, phdre will seek fresh consent before implementing material changes to processing activities that are consent-based.
Your continued use of the phdre platform after the publication of a revised Policy constitutes your acknowledgment of the updated terms. If you do not agree with the revised Policy, you may contact phdre to exercise your right to close your account and request data deletion, subject to applicable retention obligations.
Contact & DPO
For any questions, concerns, or requests relating to this Privacy Policy or phdre's data practices, you may contact phdre's Data Protection Officer through the following channels:
- 24/7 Live Chat: Available directly within the phdre platform for immediate assistance at any time.
- Email (DPO): [email protected] — mark your subject line with "Privacy / DPO Request" for priority routing.
If you are not satisfied with phdre's response to your data rights request, or if you believe that phdre has processed your personal data in violation of the Data Privacy Act, you have the right to lodge a complaint with the National Privacy Commission of the Philippines (NPC) through their official channels.