Privacy at a Glance
Six Core Privacy Commitments
These cards summarise the most important aspects of 35ph's approach to data privacy. They are provided for convenience and do not replace the full legal text below, which governs the 35ph–player data relationship in its entirety.
Data Collected Only as Needed
35ph collects only the personal data necessary to operate your account, comply with PAGCOR licensing requirements, process your payments, and deliver customer support. We do not collect data speculatively or sell it to third-party advertisers.
Philippine Data Privacy Act Compliant
35ph's data handling practices comply with Republic Act No. 10173 — the Data Privacy Act of 2012 — and its Implementing Rules and Regulations. Your rights as a data subject, including the right to access, correct, and erase your data, are protected and honoured.
No Sale of Personal Data
35ph does not sell, rent, or trade your personal data to third parties for their own marketing purposes. Data shared with third parties is limited to what is required to deliver the 35ph service — game providers, payment processors, and regulatory bodies — under strict data processing agreements.
256-bit SSL Encryption
All data transmitted between your browser and 35ph servers is encrypted using 256-bit SSL/TLS. Sensitive data at rest — including payment details and ID documents submitted for KYC — is stored using industry-standard encryption, with access restricted on a strict need-to-know basis among 35ph staff.
Full Transparency on Data Use
This Privacy Policy provides a complete, plain-language account of how 35ph uses your personal data. There are no hidden data practices. If our practices change in any material way, we will notify registered players in advance by email or platform notice before the changes take effect.
Your Rights Are Actionable
Your data rights under RA 10173 — including the right to be informed, access your data, correct inaccuracies, object to processing, and request erasure — are exercisable at any time by contacting the 35ph Data Privacy Officer via the contact details provided at the end of this Policy.
Table of Contents
- 1. Introduction & Scope
- 2. Data Controller Information
- 3. Data We Collect
- 4. How We Collect Your Data
- 5. Purposes & Legal Bases for Processing
- 6. Sharing Your Data with Third Parties
- 7. International Data Transfers
- 8. Data Retention
- 9. Cookies & Tracking Technologies
- 10. Security Measures
- 11. Your Data Subject Rights
- 12. Children's Privacy
- 13. Responsible Gaming & Data
- 14. Changes to This Policy
- 15. Contact & Complaints
This Privacy Policy ("Policy") describes how 35ph ("35ph," "we," "us," or "our") — the operator of the online gaming platform at https://35ph.cam — collects, processes, stores, shares, and protects personal data relating to registered players, prospective players, and visitors to the 35ph website. This Policy is issued in accordance with Republic Act No. 10173 (the Data Privacy Act of 2012, "DPA"), its Implementing Rules and Regulations, and the guidelines issued by the National Privacy Commission of the Philippines.
By creating a 35ph account or using the platform's services, you acknowledge that you have read and understood this Policy and consent to the processing of your personal data as described herein. This Policy should be read alongside the 35ph Terms & Conditions and Responsible Gaming Policy.
1. Introduction & Scope
This Policy applies to all personal data collected by 35ph in connection with your use of the 35ph platform, including account registration, gameplay, financial transactions, customer support interactions, and the use of responsible gaming tools. It applies to all players located in the Philippines and to Filipino nationals accessing the platform from abroad.
This Policy does not apply to third-party websites or services that may be linked from the 35ph platform. 35ph is not responsible for the privacy practices of external sites, including those operated by game providers. You should review the privacy policies of any third-party service you access independently.
2. Data Controller Information
35ph is the data controller responsible for your personal data collected through the platform. As data controller, 35ph determines the purposes and means of processing your personal data and is accountable for ensuring that processing is lawful, transparent, and consistent with this Policy.
35ph has appointed a Data Privacy Officer (DPO) as required under the DPA. The DPO is responsible for ensuring 35ph's ongoing compliance with RA 10173 and can be contacted using the details provided in Section 15 of this Policy. All data subject rights requests and privacy-related complaints should be directed to the DPO in the first instance.
3. Data We Collect
The following categories of personal data may be collected and processed by 35ph:
| Category | Examples | When Collected |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government ID number (PhilSys, UMID, SSS, GSIS, passport, driver's licence) | Registration & KYC verification |
| Contact Data | Email address, Philippine mobile number, residential address (city, province) | Registration & account updates |
| Financial Data | GCash account number, PayMaya number, bank account details (BPI, BDO, Metrobank), transaction history, deposit and withdrawal amounts | Deposits, withdrawals, KYC |
| Gaming Data | Game history, bet amounts, session duration, wagering patterns, win/loss records, bonus usage | Ongoing gameplay |
| Technical Data | IP address, device type, browser type and version, operating system, cookies, session identifiers | Each platform visit or session |
| Communications Data | Records of live chat conversations, email exchanges, and support ticket content | Customer support interactions |
| Responsible Gaming Data | Self-exclusion status, deposit or loss limit settings, cooling-off period records | When tools are activated or modified |
35ph does not intentionally collect special categories of personal data (such as health data, religious beliefs, or political opinions) unless this is strictly necessary for a compliance purpose — for example, where a player provides health information in connection with a problem gambling support request. Such data is handled with additional safeguards.
4. How We Collect Your Data
35ph collects personal data through the following means:
- Direct submission: Information you provide when registering, completing KYC verification, making deposits or withdrawals, contacting support, or updating your account settings.
- Automated collection: Technical data collected automatically when you access the platform, including IP address, device identifiers, and browser metadata, through server logs and cookies.
- Platform activity: Gaming data generated as a record of your gameplay, bets, sessions, and financial transactions on the 35ph platform.
- Third-party sources: Identity verification data obtained from document verification service providers during KYC processing; payment confirmation data from GCash, PayMaya, and banking partners.
- Regulatory sources: Information received from PAGCOR or law enforcement authorities in connection with compliance or investigation requirements.
5. Purposes & Legal Bases for Processing
35ph processes your personal data only where there is a lawful basis for doing so under the DPA. The following table sets out the primary purposes for which we process personal data and the corresponding legal basis:
| Purpose | Legal Basis (RA 10173) |
|---|---|
| Account creation, maintenance, and authentication | Performance of contract; consent |
| KYC identity and age verification (21+ compliance) | Legal obligation (PAGCOR requirements); consent |
| Processing deposits, withdrawals, and transaction records | Performance of contract; legal obligation (AMLA) |
| Fraud detection, security monitoring, and account protection | Legitimate interests; legal obligation |
| Anti-money laundering (AML) monitoring and reporting | Legal obligation (AMLA, PAGCOR) |
| Responsible gaming monitoring and intervention | Legal obligation (PAGCOR); legitimate interests; consent |
| Customer support and dispute resolution | Performance of contract; legitimate interests |
| Platform improvement and analytics | Legitimate interests (aggregated and anonymised data) |
| Marketing communications (where opted in) | Consent |
| Regulatory reporting and audit cooperation | Legal obligation (PAGCOR, NPC) |
6. Sharing Your Data with Third Parties
35ph does not sell your personal data. Data is shared with third parties only to the extent necessary to deliver the 35ph service and meet regulatory obligations, and only under data processing agreements that require those parties to handle your data in accordance with RA 10173 and this Policy. Third parties who may receive your personal data include:
- Game providers (e.g., JILI, Pragmatic Play, PG Soft, Evolution Gaming) — receive session identifiers and bet data necessary to deliver game services. These providers do not receive your full identity or financial data.
- Payment processors (GCash, PayMaya, BPI, BDO, Metrobank) — receive transaction data necessary to process deposits and withdrawals. Payment data is transmitted over encrypted channels.
- KYC and identity verification providers — receive copies of government-issued IDs and selfies to verify your identity and age during the KYC process.
- PAGCOR and Philippine regulatory authorities — receive compliance reports, AML disclosures, and other information as required by law.
- Law enforcement agencies — may receive data in response to lawful requests, court orders, or where 35ph is legally obligated to disclose.
- Technology service providers — cloud infrastructure, cybersecurity, and customer support platform providers who process data on 35ph's behalf under strict contractual obligations.
7. International Data Transfers
Some of the third-party service providers used by 35ph — including certain game providers and cloud infrastructure services — may be located outside the Philippines. Where personal data is transferred outside the Philippines, 35ph ensures that appropriate safeguards are in place, including contractual data processing agreements that require the recipient to apply data protection standards equivalent to those required under RA 10173.
35ph will not transfer your personal data to countries or organisations that do not provide an adequate level of data protection without first obtaining your explicit consent or implementing appropriate contractual safeguards as required by the National Privacy Commission.
8. Data Retention
35ph retains your personal data for as long as is necessary to fulfil the purposes described in this Policy, or as required by applicable law. The following general retention periods apply:
- Account and identity data: Retained for the duration of your account and for a minimum of five (5) years following account closure, as required by PAGCOR regulations and Philippine AML obligations.
- Financial transaction records: Retained for a minimum of five (5) years from the date of the transaction, in compliance with AMLA record-keeping requirements.
- Gaming activity data: Retained for five (5) years to support dispute resolution, fraud investigation, and regulatory audit requirements.
- Customer support communications: Retained for three (3) years from the date of the interaction.
- Marketing consent records: Retained until consent is withdrawn and for one (1) year thereafter as an audit trail.
- Responsible gaming records (self-exclusion): Retained indefinitely where required by PAGCOR to prevent re-registration during an active exclusion period.
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in a manner that prevents re-identification.
9. Cookies & Tracking Technologies
35ph uses cookies and similar tracking technologies to operate the platform, maintain session continuity, detect fraud, and improve the player experience. The types of cookies used by 35ph include:
- Strictly necessary cookies: Required for the platform to function. These include session authentication tokens and security cookies. These cannot be disabled without breaking core platform functionality.
- Functional cookies: Store your preferences (language, game display settings) to personalise your experience. Disabling these may reduce functionality.
- Analytics cookies: Collect anonymised data about how players use the platform to help 35ph identify technical issues and improve the interface. No personally identifiable information is included in analytics data shared with analytics service providers.
- Security and fraud prevention cookies: Help 35ph detect unusual login patterns, identify bot activity, and protect against account takeover attempts.
You can manage cookie preferences through your browser settings. Please note that disabling strictly necessary cookies will prevent you from using the 35ph platform. For more information on specific cookies used, contact the 35ph Data Privacy Officer.
10. Security Measures
35ph implements a layered approach to data security that includes both technical and organisational measures proportionate to the sensitivity of the personal data processed. Security measures include:
- 256-bit SSL/TLS encryption for all data in transit between your browser and 35ph servers
- Encryption at rest for sensitive data fields including payment details and KYC document storage
- Role-based access controls limiting staff access to personal data on a strict need-to-know basis
- Multi-factor authentication requirements for all 35ph staff accessing systems containing player data
- Regular security audits, penetration testing, and vulnerability assessments conducted by independent cybersecurity professionals
- Incident response procedures aligned with NPC reporting requirements under RA 10173
- Staff training on data privacy and security obligations under Philippine law
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, 35ph will notify the National Privacy Commission and affected players in accordance with the notification timelines required under RA 10173 — within seventy-two (72) hours of becoming aware of the breach where feasible.
11. Your Data Subject Rights
As a data subject under the Philippine Data Privacy Act, you have the following rights with respect to your personal data held by 35ph:
To exercise any of these rights, submit a written request to the 35ph Data Privacy Officer using the contact details in Section 15. 35ph will acknowledge your request within five (5) business days and provide a substantive response within fifteen (15) business days, extendable to thirty (30) days where the complexity of the request warrants it.
Please note that some rights are subject to limitations where processing is required to fulfil legal obligations — for example, 35ph cannot erase financial transaction records that must be retained under AMLA requirements, even if you request erasure of your account data. In such cases, 35ph will explain the specific limitation clearly.
Where your consent is the legal basis for processing, you may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Certain withdrawals may affect your ability to use 35ph services — for example, withdrawing consent for KYC processing will prevent withdrawal of funds until verification is completed.
12. Children's Privacy
The 35ph platform is strictly intended for adults aged twenty-one (21) years and above in compliance with PAGCOR regulations. 35ph does not knowingly collect personal data from individuals under 21. If you are under 21, you must not use the 35ph platform or provide any personal data to 35ph.
If 35ph becomes aware that personal data has been collected from a person under 21, that account will be permanently closed, the personal data will be deleted from active systems, and the matter will be reported to PAGCOR as required by its licensing conditions. If you are a parent or guardian and believe your minor child has provided data to 35ph, contact the Data Privacy Officer immediately.
13. Responsible Gaming & Data
35ph processes gaming activity data — including session duration, bet frequency, deposit patterns, and loss amounts — not only as a transaction record but also to fulfil its responsible gaming obligations under PAGCOR regulations. This data is analysed to identify accounts that may be exhibiting indicators of problem gambling behaviour, enabling proactive outreach and the application of protective measures.
Self-exclusion requests and responsible gaming limit settings are recorded and retained as described in Section 8. This data is used to enforce exclusion periods and to meet PAGCOR's reporting requirements. 35ph does not use responsible gaming data for marketing profiling. For detailed information about the responsible gaming tools available on 35ph and the data they involve, visit the Responsible Gaming page.
14. Changes to This Policy
35ph may update this Privacy Policy from time to time to reflect changes in our data practices, technological developments, or changes in applicable law. Material changes — those that significantly affect how your personal data is processed or your rights as a data subject — will be communicated to registered players via email at least fourteen (14) days before the changes take effect.
The "Last Updated" date at the top of this Policy indicates when the most recent revision was made. Your continued use of the 35ph platform after the effective date of any revision constitutes your acceptance of the updated Policy. If you do not accept the revised Policy, you must close your account before the effective date of the changes.
15. Contact & Complaints
For any questions, concerns, or requests relating to this Privacy Policy or your personal data held by 35ph, contact the Data Privacy Officer through the following channels:
- Live Chat: Available 24/7 directly on the 35ph platform — mark your message clearly as a "Privacy / Data Subject Request" for priority routing to the DPO
- Email: [email protected] — Subject line: "Data Privacy Request – [Your Registered Name]"
If you are not satisfied with 35ph's response to a privacy concern, you have the right to lodge a complaint with the National Privacy Commission of the Philippines (NPC). Details of the NPC's complaint process are available through the NPC's official channels. 35ph cooperates fully with NPC investigations and will provide all required information within applicable timelines.
Age Verification and Data Privacy Go Hand in Hand at 35ph
The KYC data 35ph collects during identity verification — including your government-issued ID and date of birth — serves a dual purpose: it confirms you are who you say you are, and it confirms you are at least 21 years old as required by PAGCOR regulations. This data is stored securely and is never used for purposes beyond those described in this Privacy Policy.
If you have questions about how your personal data is used or want to exercise your rights under the Data Privacy Act, contact the 35ph Data Privacy Officer at any time via live chat. For responsible gaming resources available to Filipino players, visit the Responsible Gaming page.