Our Privacy Commitments
Six principles that govern how phh22 handles every piece of personal data — before you read the full policy.
Minimal Collection
phh22 collects only the personal data that is strictly necessary for operating your account, verifying your identity, processing payments, and complying with legal obligations. We do not harvest data for its own sake.
Secure Storage
All personal data stored by phh22 is protected using industry-standard encryption at rest and in transit. Access to personal data within the phh22 organization is restricted to personnel who require it to perform their duties.
No Data Selling
phh22 does not sell, rent, or trade your personal information to third parties for commercial purposes. Your data is used solely to provide you with phh22 services and to meet our legal compliance obligations.
Your Rights Respected
As a data subject under Philippine law, you have the right to access, correct, delete, and object to the processing of your personal data. phh22 provides clear and accessible mechanisms to exercise every one of these rights.
Full Transparency
phh22 tells you exactly what data is collected, why it is collected, how long it is kept, and who can access it. There are no hidden data collection practices, silent tracking agreements, or undisclosed sharing arrangements.
RA 10173 Compliance
phh22 processes personal data in full compliance with Republic Act No. 10173, the Data Privacy Act of 2012 of the Philippines, and its implementing rules. Our practices are aligned with the requirements of the National Privacy Commission.
1 Introduction
This Privacy Policy ("Policy") describes how phh22 ("phh22," "we," "our," or "us") collects, processes, stores, shares, and protects personal information relating to you ("User," "Player," or "you") when you access or use the phh22 online casino and sports betting platform available at phh22.net and its associated subdomains and services (collectively, the "Platform").
phh22 is committed to protecting the privacy and security of the personal information of every player on the Platform. This Policy is written in compliance with Republic Act No. 10173 — the Data Privacy Act of 2012 of the Philippines — and its Implementing Rules and Regulations, as administered by the National Privacy Commission (NPC). Where applicable, phh22 also observes internationally recognized privacy principles.
By creating a phh22 account, logging in to the Platform, or otherwise using any phh22 service, you acknowledge that you have read, understood, and consent to the data practices described in this Policy. If you do not agree with this Policy, you should not use the Platform.
This Policy forms part of phh22's Terms & Conditions. In the event of any conflict between this Policy and the Terms & Conditions concerning data matters, this Policy shall prevail.
2 Data Controller
phh22 acts as the Personal Information Controller (PIC) in respect of the personal data it collects from users of the Platform, as that term is defined under the Data Privacy Act of 2012. phh22 determines the purposes and means of processing personal data collected through the Platform.
In instances where phh22 engages third-party service providers (such as payment processors, KYC verification providers, or cloud infrastructure providers) to process personal data on phh22's behalf, those parties act as Personal Information Processors (PIPs) and are bound by data processing agreements that require them to process personal data only on phh22's documented instructions and in compliance with applicable privacy law.
For all privacy-related queries, requests, or complaints, please use the contact information set out in Section 15 of this Policy.
3 Personal Data We Collect
phh22 collects the following categories of personal information:
3.1 Identity and Registration Data
When you register for a phh22 account, we collect: your full legal name, date of birth, nationality, residential address (including city — such as Manila, Cebu, Davao, Quezon City, or Makati — and province), contact mobile number, and email address. This information is mandatory for account creation.
3.2 Identity Verification (KYC) Data
To comply with PAGCOR and anti-money laundering requirements, phh22 collects copies of government-issued identity documents (such as Philippine National ID, Passport, SSS ID, UMID, Driver's License, or Voter's ID), proof of address documentation, and where required, selfie or biometric verification images. KYC data is processed only for identity verification and regulatory compliance purposes.
3.3 Financial and Transaction Data
We collect records of all deposits, withdrawals, and wagers made on the Platform, including GCash account identifiers, PayMaya wallet identifiers, BPI/BDO/Metrobank account reference information (partial numbers as provided by your bank), and transaction amounts and timestamps. We do not store full credit or debit card numbers on phh22 servers.
3.4 Technical and Device Data
When you access the Platform, we automatically collect: IP address, browser type and version, device type and operating system, session duration and pages visited, referring URL, and cookie identifiers. This data is used for security, fraud prevention, and Platform optimization purposes.
3.5 Communications Data
When you contact phh22 support via live chat, email, Messenger, or Viber, we record the content and metadata of those communications. These records are retained for quality assurance, dispute resolution, and compliance purposes.
3.6 Responsible Gaming Data
If you use phh22's responsible gaming tools — such as setting deposit limits, activating self-exclusion, or requesting a Reality Check — we record the details of those choices and their effective dates. This information is used solely to honor your responsible gaming preferences and protect your welfare as a player.
phh22 does not collect sensitive personal information (such as health records, political opinions, or religious beliefs) as part of standard account operations. If such information is incidentally disclosed during a support interaction, it is treated with the highest level of protection.
4 How We Collect Your Data
phh22 collects personal data through the following means:
- Directly from you — when you complete the registration form, submit KYC documents, make deposits or withdrawal requests, contact support, or participate in promotions;
- Automatically from your device — via cookies, session logs, and technical data captured when you access and navigate the Platform;
- From third-party service providers — such as KYC verification platforms (identity confirmation), payment providers (transaction records), and fraud detection services (risk assessments);
- From publicly available sources — where required for AML compliance purposes, phh22 may verify certain information against publicly available Philippine government databases or sanctions lists.
5 How We Use Your Personal Data
phh22 uses personal data for the following specific purposes:
| Purpose | Data Used |
|---|---|
| Account creation and management | Identity & registration data |
| Identity verification and KYC compliance | KYC documents, selfie/biometric data |
| Processing deposits and withdrawals | Financial & transaction data |
| Fraud prevention and security monitoring | Technical, device, and transaction data |
| Regulatory compliance (PAGCOR, AML, NPC) | Identity, KYC, and transaction data |
| Customer support and dispute resolution | Communications and transaction data |
| Responsible gaming monitoring and protection | Gaming behavior and RG preference data |
| Platform improvement and analytics | Aggregated and anonymized technical data |
| Promotional communications (with consent) | Contact data, game preference data |
phh22 does not use personal data for automated decision-making that produces legal or similarly significant effects on players without a human review step, except in cases of immediate fraud or security risk detection where temporary account restriction may be applied pending investigation.
6 Legal Bases for Processing
phh22 processes personal data under the following legal bases as provided under the Data Privacy Act of 2012:
- Consent — for marketing communications, optional analytics, and any processing beyond what is necessary for account operation. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Contractual Necessity — processing necessary to perform the services you have contracted with phh22 by accepting the Terms & Conditions, including account management, payments, and game delivery.
- Legal Obligation — processing required to comply with PAGCOR licensing requirements, AML/CTF obligations under Republic Act No. 9160 (as amended), tax reporting requirements, and the Data Privacy Act itself.
- Legitimate Interests — fraud prevention, Platform security, customer support quality assurance, and responsible gaming monitoring, where phh22's legitimate interests do not override your fundamental rights and freedoms.
7 Sharing of Personal Data
phh22 does not sell your personal data. phh22 may share personal data with the following categories of parties, strictly for the purposes described:
- KYC and identity verification providers — to confirm your identity against submitted documents during account verification;
- Payment processors — GCash (operated by Mynt), PayMaya (Voyager Innovations), and banking partners, to facilitate deposits and withdrawals you have initiated;
- Game software providers — such as Pragmatic Play, PG Soft, Jili Games, and other licensed studios, who receive anonymized game session data necessary to operate the games you play;
- Cloud infrastructure and IT service providers — who host Platform data under contractual data processing agreements obligating them to maintain security and confidentiality standards equivalent to phh22's own;
- Regulatory and law enforcement authorities — PAGCOR, the National Privacy Commission, the Anti-Money Laundering Council (AMLC), and Philippine law enforcement agencies, where disclosure is required by law, court order, or regulatory direction;
- Fraud prevention and security networks — to protect phh22 and its players from fraudulent activity, money laundering, and account compromise.
Not shared: phh22 never shares personal data with third-party marketers, data brokers, social media platforms, or advertising networks without your explicit, separately obtained consent.
8 Cookies and Tracking Technologies
phh22 uses cookies and similar tracking technologies on the Platform to enable core functionality, improve the user experience, and detect fraudulent or abusive activity. The following cookie categories are used:
- Strictly Necessary Cookies: Required for Platform operation — session management, login state maintenance, and security functions. These cannot be disabled without impairing Platform functionality.
- Functional Cookies: Remember your preferences such as language settings and display options. These persist between sessions to improve convenience.
- Analytics Cookies: Collect anonymized and aggregated data about how players navigate the Platform, which pages are most visited, and where technical errors occur. This data is used solely for Platform improvement and is not linked to individual identities.
- Security Cookies: Detect and prevent fraudulent login attempts, automated bot activity, and account takeover patterns.
You can manage cookie preferences through your browser settings. Disabling analytics or functional cookies may reduce Platform convenience but will not prevent you from accessing core services. Disabling strictly necessary cookies will prevent login and game access.
9 Data Retention
phh22 retains personal data for as long as is necessary to fulfill the purpose for which it was collected, or as required by applicable law. The following general retention periods apply:
- Account and identity data: Retained for the duration of your account and for a minimum of five (5) years following permanent account closure, in compliance with AML record-keeping requirements under Philippine law;
- Transaction records: Retained for a minimum of five (5) years from the date of each transaction, in accordance with AMLC and PAGCOR recordkeeping rules;
- KYC documents: Retained for the periods required by PAGCOR and AMLC regulations, typically five (5) years from the end of the business relationship;
- Support communications: Retained for two (2) years from the date of the interaction, unless the communication relates to an ongoing dispute or regulatory matter;
- Technical and device data: Retained in identifiable form for up to twelve (12) months, after which it is aggregated and anonymized.
Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymized using industry-standard methods.
10 Data Security
phh22 employs a comprehensive set of technical and organizational security measures to protect personal data against unauthorized access, loss, destruction, alteration, or disclosure. These measures include:
- 256-bit Transport Layer Security (TLS/SSL) encryption for all data transmitted between your device and phh22 servers;
- Encryption at rest for all sensitive personal and financial data stored on phh22 infrastructure;
- Role-based access controls ensuring that only authorized phh22 personnel with a documented operational need can access personal data categories;
- Multi-factor authentication requirements for all phh22 staff accessing systems containing personal data;
- Regular security vulnerability assessments and penetration testing conducted by qualified security professionals;
- Formal incident response procedures for detecting, containing, and reporting personal data breaches in accordance with NPC notification requirements.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of affected players, phh22 will notify the National Privacy Commission within 72 hours of becoming aware of the breach, and will notify affected players as required by applicable law.
Your role in security: While phh22 maintains strong server-side security, you are responsible for keeping your phh22 login credentials confidential. Never share your password or OTP with anyone — phh22 staff will never ask for these details.
11 Your Data Subject Rights
Under the Data Privacy Act of 2012 of the Philippines, you have the following rights with respect to your personal data processed by phh22. These rights may be exercised by contacting phh22 using the details in Section 15.
Right to Access
Request a copy of the personal data phh22 holds about you and information on how it is processed.
Right to Correction
Request correction of inaccurate or incomplete personal data we hold about you.
Right to Erasure
Request deletion of your personal data where there is no overriding legal basis for continued retention.
Right to Object
Object to processing of your personal data where phh22 relies on legitimate interests as the legal basis.
Right to Portability
Receive a copy of your personal data in a structured, commonly used machine-readable format.
Right to Withdraw Consent
Withdraw previously given consent for optional data processing at any time, without affecting prior lawful processing.
phh22 will respond to all data subject requests within thirty (30) days of receipt. In complex cases, this period may be extended by an additional thirty (30) days with written notice and explanation. Please note that some rights are subject to limitations under applicable law — for example, the right to erasure does not apply where phh22 has a legal obligation to retain data under AML or PAGCOR regulations.
12 Children's Privacy
The phh22 Platform is not directed at, and is not intended for use by, individuals under the age of 21 years. phh22 does not knowingly collect personal data from persons under 21 years of age. In compliance with PAGCOR's minimum age requirements for casino-style online gaming in the Philippines, all account registrations require age verification and any account found to belong to an underage individual will be immediately and permanently closed.
If phh22 becomes aware that it has collected personal data from a person under the age of 21 without appropriate consent, phh22 will take immediate steps to delete that data and close the associated account. If you believe phh22 may have collected data from a minor, please contact us immediately using the details in Section 15.
Age enforcement: The minimum age for a phh22 account is 21 years old. This is enforced during KYC verification and through ongoing monitoring. phh22 does not make exceptions to this requirement under any circumstances.
13 International Data Transfers
phh22 operates primarily within the Philippines and stores core personal data on servers located in or near the Philippine jurisdiction. In some cases, the use of third-party service providers (such as cloud infrastructure, KYC verification platforms, or game software providers operating internationally) may involve transfers of personal data to servers or processors located outside the Philippines.
Where personal data is transferred outside the Philippines, phh22 ensures that such transfers are conducted: (a) to countries recognized by the NPC as providing adequate levels of data protection; or (b) under contractual safeguards — including binding data processing agreements incorporating standard contractual clauses — that require the recipient to protect personal data to a standard equivalent to Philippine law.
phh22 does not transfer personal data to jurisdictions known to have inadequate data protection standards without implementing enhanced contractual and organizational safeguards to mitigate associated risks.
14 Updates to This Privacy Policy
phh22 may update this Privacy Policy from time to time to reflect changes in our data practices, legal obligations, regulatory requirements, or Platform features. The effective date of the most recent version is displayed at the top of this page.
When material changes are made — meaning changes that significantly affect how your personal data is processed or your rights as a data subject — phh22 will notify you by email to your registered address and/or by a prominent notice on the Platform before the changes take effect.
Your continued use of the Platform after the effective date of any updated Privacy Policy constitutes your acceptance of the revised practices. If you do not accept the changes, you should stop using the Platform and request account closure before the effective date of the revision.
15 Contact Us and Privacy Complaints
For any questions, concerns, or requests related to this Privacy Policy or the processing of your personal data by phh22, please contact our Data Protection Officer (DPO) through the following channels:
- Email: [email protected] (Subject: Privacy Request — [your name])
- Live Chat: 24/7 support available from any page on the phh22 Platform
- Messenger & Viber: Via phh22's official pages
- Response Language: English and Filipino (Tagalog)
phh22 will acknowledge receipt of all privacy requests within five (5) business days and will endeavor to resolve requests within thirty (30) days.
If you are not satisfied with phh22's response to a privacy complaint, you have the right to lodge a formal complaint with the National Privacy Commission (NPC) of the Philippines. The NPC is the supervisory authority responsible for enforcing the Data Privacy Act of 2012 and accepts complaints from data subjects whose rights have not been adequately addressed by the personal information controller.
National Privacy Commission (Philippines): The NPC is the relevant data protection supervisory authority for phh22's processing of personal data in the Philippines. Contact the NPC via their official government channels if you believe your data privacy rights have been violated.
Your Data Is Safe at phh22
phh22 is built on trust. Your personal data is protected, your identity is secured, and your winnings are yours. Play with confidence on the Philippines' most trusted online casino platform.
Must be 21 years or older. Play responsibly. phh22 complies with RA 10173 — the Data Privacy Act of 2012 of the Philippines.