1. Introduction and Scope
phsk (hereinafter "phsk," "we," "us," or "our") is committed to protecting the privacy and personal data of all users (hereinafter "you," "your," or "User") who access or use our online gaming platform. This Privacy Policy describes our practices concerning the collection, use, disclosure, retention, and protection of personal information in accordance with the Republic Act No. 10173 (Data Privacy Act of 2012), its Implementing Rules and Regulations, National Privacy Commission circulars, and Philippine Amusement and Gaming Corporation (PAGCOR) regulatory requirements.
By creating an account, accessing the phsk platform, or using any of our services, you acknowledge that you have read, understood, and consent to the data processing practices described in this Privacy Policy. If you do not agree with this Privacy Policy, you must immediately discontinue use of our services and refrain from creating an account. This Privacy Policy should be read in conjunction with our Terms & Conditions, which govern your overall use of the platform.
Data Controller: phsk operates as the data controller responsible for determining the purposes and means of processing your personal data. For data protection inquiries, contact our Data Protection Officer at the details provided in Section 12.
2. Personal Information We Collect
phsk collects various categories of personal information necessary to provide gaming services, comply with legal obligations, prevent fraud, and improve user experience. The types of personal information we collect include:
2.1 Account Registration Information
When you create a phsk account, we collect:
- Full legal name as it appears on government-issued identification;
- Date of birth (to verify you meet the minimum age requirement of 21 years);
- Gender;
- Nationality and country of residence;
- Complete residential address (street, barangay, city/municipality, province, postal code);
- Email address;
- Mobile phone number;
- Username and encrypted password;
- Security questions and answers (if applicable);
- Preferred currency (default: Philippine Peso).
2.2 Identity Verification Documents
To comply with Know Your Customer (KYC), anti-money laundering (AML), and PAGCOR verification requirements, we may request and collect copies of:
- Government-issued photo identification (Philippine passport, driver's license, UMID, postal ID, voter's ID, PRC ID, SSS ID, PhilHealth ID, TIN ID);
- Proof of address documents (utility bills, bank statements, government correspondence) dated within the last three (3) months;
- Proof of payment method ownership (bank account statement, screenshot of e-wallet profile showing name and account details);
- Selfie photograph holding identification document ("liveness verification");
- Source of funds documentation for high-value transactions or when required by compliance procedures.
2.3 Financial and Transaction Information
To process deposits, withdrawals, and gaming transactions, we collect:
- Payment method details (GCash mobile number, Maya account identifier, bank account name and number, credit/debit card last four digits and expiry date);
- Transaction history (deposits, withdrawals, transfers, bet placements, winnings, bonus credits);
- Transaction amounts, dates, times, and status;
- Payment processor reference numbers;
- Billing address associated with payment methods.
Note: phsk does not store full credit card numbers or card verification values (CVV/CVC). Card payments are processed through PCI-DSS compliant third-party payment processors who tokenize sensitive payment data.
2.4 Gaming Activity and Behavioral Data
To provide gaming services, detect fraud, and improve platform functionality, we automatically collect:
- Bet history (game type, stake amount, odds, outcome, timestamp);
- Game preferences and favorite games;
- Session duration and frequency;
- Bonus usage and wagering progress;
- Winnings and losses;
- Loyalty program tier and points balance;
- Chat messages sent through customer support channels;
- Responsible gaming settings (deposit limits, self-exclusion status, reality check intervals).
2.5 Technical and Device Information
When you access phsk, our servers automatically log technical data including:
- IP address and geolocation data (city/region level, not precise GPS coordinates);
- Device type, operating system, and browser version;
- Screen resolution and device identifiers;
- Referring website URL;
- Pages visited, clicks, scrolling behavior;
- Access times and session durations;
- Cookies and similar tracking technologies (see Section 9).
2.6 Communications and Support Interactions
When you contact phsk customer support, we retain:
- Email correspondence content and attachments;
- Live chat transcripts;
- Support ticket details (issue description, resolution, timestamps);
- Feedback, complaints, and survey responses;
- Phone call recordings (with prior notice and consent where legally required).
3. How We Use Your Personal Information
phsk processes personal information for the following purposes, based on lawful grounds under the Data Privacy Act of 2012:
| Processing Purpose | Lawful Basis |
|---|---|
| Account creation and management | Contractual necessity / Consent |
| Identity verification and KYC compliance | Legal obligation (PAGCOR / AMLC requirements) |
| Processing deposits and withdrawals | Contractual necessity |
| Providing gaming services and settling bets | Contractual necessity |
| Fraud prevention and security monitoring | Legitimate interest / Legal obligation |
| Customer support and dispute resolution | Contractual necessity / Legitimate interest |
| Marketing communications (promotional emails, SMS) | Consent (opt-in required) |
| Platform improvement and analytics | Legitimate interest |
| Responsible gaming monitoring and intervention | Legal obligation / Legitimate interest |
| Compliance with court orders and lawful requests | Legal obligation |
3.1 Detailed Processing Activities
Account Administration: We use your registration information to create and maintain your account, authenticate your identity when you log in, provide customer support, and communicate important account-related information such as security alerts, password reset confirmations, and policy updates.
Regulatory Compliance: PAGCOR regulations and Philippine anti-money laundering laws require licensed gaming operators to verify player identity, monitor transactions for suspicious patterns, maintain detailed records, and report certain activities to government agencies. We process your personal data to fulfill these mandatory legal obligations.
Fraud Detection and Platform Security: We analyze betting patterns, transaction histories, device fingerprints, and IP addresses to detect coordinated fraud, account takeovers, bonus abuse, underage gambling attempts, and other prohibited activities. Anomalous behavior triggers automated alerts for manual review by our compliance team.
Personalization and User Experience: We use your gaming preferences, device information, and behavioral data to customize game recommendations, optimize platform performance, display relevant content, and improve interface design. This processing is based on legitimate business interest in providing a quality user experience.
Responsible Gaming Protections: We monitor your gaming activity for patterns that may indicate problem gambling, such as rapid deposit escalation, extended session durations, or chase-loss behavior. If concerning patterns emerge, we may proactively contact you to offer responsible gaming resources, suggest deposit limits, or encourage self-exclusion.
4. Legal Basis for Processing
Under the Data Privacy Act of 2012, personal data processing must be grounded in at least one lawful basis. phsk relies on the following legal bases:
- Consent: You provide explicit consent during account registration and when opting into marketing communications. Consent may be withdrawn at any time by contacting our Data Protection Officer.
- Contractual Necessity: Processing is necessary to perform our obligations under the Terms & Conditions you accepted, including providing gaming services, processing payments, and settling bets.
- Legal Obligation: We are legally required to process personal data to comply with PAGCOR licensing conditions, anti-money laundering laws (RA 9160 as amended by RA 10365 and RA 11521), tax reporting obligations, and court orders.
- Legitimate Interest: We process data to pursue legitimate business interests such as fraud prevention, network security, platform improvement, and business analytics, provided such interests are not overridden by your fundamental rights and freedoms.
5. Data Sharing and Disclosure
phsk does not sell, rent, or trade your personal information to third parties for their marketing purposes. We share personal data only in the following circumstances:
5.1 Service Providers and Processors
We engage third-party service providers to perform functions on our behalf, including:
- Payment Processors: GCash, Maya, Visa/Mastercard acquiring banks, InstaPay/PesoNet networks, and 7-Eleven cash collection partners process financial transactions. These providers have access only to data necessary to perform payment services.
- Identity Verification Services: Specialized KYC providers assist with document verification, facial recognition, and identity validation using secure APIs.
- Cloud Hosting Providers: Our platform infrastructure is hosted on secure cloud servers. Providers have limited access to technical data but do not access customer account contents.
- Customer Support Software: Live chat and ticketing systems process support interactions. Transcripts are encrypted and access-controlled.
- Marketing and Analytics Tools: Email service providers (for sending account notifications and promotional messages to opted-in users) and analytics platforms (for understanding user behavior and platform performance) process aggregated or pseudonymized data where possible.
All service providers are contractually bound by data processing agreements requiring them to handle personal information securely, use it only for specified purposes, and comply with Philippine data protection laws.
5.2 Regulatory and Law Enforcement Authorities
We disclose personal information to Philippine government agencies when legally required, including:
- PAGCOR: For licensing compliance audits, responsible gaming monitoring, and regulatory investigations;
- Anti-Money Laundering Council (AMLC): Suspicious transaction reports and covered transaction reports as mandated by RA 9160;
- Bureau of Internal Revenue (BIR): For tax compliance and withholding tax reporting on winnings exceeding statutory thresholds;
- National Privacy Commission (NPC): In response to data breach notifications or compliance inquiries;
- Law Enforcement: Pursuant to valid court orders, subpoenas, or search warrants in criminal investigations.
5.3 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, personal information may be transferred to the acquiring entity. Users will be notified via email and Platform notification at least thirty (30) days prior to such transfer, and the new entity will be bound by this Privacy Policy or a substantially similar policy.
5.4 Consent-Based Disclosures
We may share your information with third parties when you provide explicit consent for specific purposes, such as participating in co-branded promotions or authorizing data sharing with affiliate partners.
6. International Data Transfers
While phsk primarily processes personal data within the Philippines, certain service providers (cloud infrastructure, payment processors, software-as-a-service tools) may be located outside the Philippines. When personal data is transferred internationally, we implement appropriate safeguards including:
- Ensuring the receiving country provides adequate data protection (as determined by the National Privacy Commission or as recognized under international frameworks);
- Implementing Standard Contractual Clauses (SCCs) or equivalent data transfer mechanisms;
- Conducting vendor due diligence to assess data protection practices;
- Limiting transferred data to the minimum necessary for service delivery.
By using phsk, you acknowledge and consent to the international transfer of your personal data under these safeguards.
7. Data Retention
phsk retains personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our Terms & Conditions. Specific retention periods include:
- Active Account Data: Retained for the duration of your account's active status plus six (6) months following voluntary account closure;
- Transaction Records: Retained for seven (7) years from transaction date to comply with anti-money laundering record-keeping requirements under AMLC regulations;
- Identity Verification Documents: Retained for seven (7) years following account closure or last transaction, whichever is later;
- Marketing Consent Records: Retained until consent is withdrawn, plus three (3) years to demonstrate compliance with consent management obligations;
- Support Communications: Retained for three (3) years to facilitate dispute resolution and service quality monitoring;
- Responsible Gaming Records: Retained for ten (10) years to fulfill duty of care obligations and defend against potential litigation;
- Legal Hold Data: Data subject to pending litigation, regulatory investigation, or valid preservation orders is retained until the matter is resolved and legal obligations expire.
Upon expiry of applicable retention periods, personal data is securely deleted or anonymized such that it can no longer identify individuals.
8. Data Security Measures
phsk implements technical, organizational, and physical security measures to protect personal information against unauthorized access, disclosure, alteration, or destruction:
8.1 Technical Safeguards
- Encryption: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher. Sensitive data at rest (passwords, payment details, identification documents) is encrypted using AES-256 encryption.
- Access Controls: Role-based access controls (RBAC) ensure employees access only the data necessary for their job functions. Multi-factor authentication is required for administrative access.
- Firewalls and Intrusion Detection: Network perimeter security includes firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS) to block malicious traffic.
- Vulnerability Management: Regular security assessments, penetration testing, and vulnerability scans identify and remediate system weaknesses.
- Secure Development Practices: Code undergoes security review, and third-party libraries are monitored for known vulnerabilities.
8.2 Organizational Safeguards
- Employee Training: All staff handling personal data receive mandatory data protection training covering confidentiality obligations, secure data handling procedures, and incident response protocols.
- Confidentiality Agreements: Employees and contractors sign confidentiality agreements prohibiting unauthorized disclosure of personal information.
- Vendor Management: Third-party service providers undergo security assessments before engagement and are contractually required to maintain equivalent security standards.
- Incident Response Plan: We maintain a documented data breach response plan specifying detection, containment, investigation, notification, and remediation procedures.
8.3 Physical Safeguards
- Data centers hosting our infrastructure implement physical access controls including biometric authentication, video surveillance, and 24/7 security personnel;
- Paper documents containing personal data are stored in locked cabinets within access-restricted areas;
- Secure disposal procedures (shredding for paper, degaussing or physical destruction for electronic media) prevent data recovery from discarded materials.
9. Cookies and Tracking Technologies
phsk uses cookies, web beacons, and similar technologies to enhance user experience, analyze platform usage, and deliver personalized content. Cookies are small text files stored on your device that allow us to recognize you across sessions.
9.1 Types of Cookies We Use
- Essential Cookies: Required for platform functionality, including session management, login authentication, and shopping cart persistence. These cannot be disabled without affecting service delivery.
- Performance Cookies: Collect anonymous information about how visitors use the platform, such as most frequently visited pages and error messages. Data is aggregated and used to improve platform performance.
- Functional Cookies: Remember your preferences (language, currency, display settings) to provide enhanced personalization.
- Advertising Cookies: Track your browsing activity to deliver relevant promotional content. Used only if you opt into marketing communications.
9.2 Managing Cookie Preferences
Most browsers allow you to control cookies through settings. You can block or delete cookies, though doing so may impair platform functionality. Note that disabling essential cookies will prevent you from logging into your account.
10. Your Privacy Rights
Under the Data Privacy Act of 2012, you have the following rights regarding your personal information:
10.1 Right to Access
You may request confirmation of whether phsk processes your personal data and obtain a copy of such data. We will provide the requested information within thirty (30) days of receiving a valid request, subject to identity verification.
10.2 Right to Rectification
You may update inaccurate or incomplete personal information through your account settings or by contacting customer support. We will correct verified inaccuracies without undue delay.
10.3 Right to Erasure ("Right to be Forgotten")
You may request deletion of your personal data when it is no longer necessary for the purposes collected, consent is withdrawn, or processing is unlawful. This right is subject to exceptions where retention is required by law (e.g., anti-money laundering record-keeping) or for legitimate legal interests (e.g., defending against claims).
10.4 Right to Object
You may object to processing based on legitimate interest grounds. Upon receipt of an objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests or processing is necessary for legal claims.
10.5 Right to Data Portability
You may request a structured, commonly used, machine-readable copy of personal data you provided to phsk, and request that we transmit such data directly to another controller where technically feasible.
10.6 Right to Withdraw Consent
Where processing is based on consent (e.g., marketing communications), you may withdraw consent at any time by clicking "unsubscribe" in promotional emails or contacting our Data Protection Officer. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.
10.7 Exercising Your Rights
To exercise any of these rights, submit a written request to our Data Protection Officer at the contact details in Section 12. We may request additional information to verify your identity before fulfilling requests.
11. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, phsk will notify the National Privacy Commission within seventy-two (72) hours of becoming aware of the breach, as required by NPC Circular No. 16-03. If the breach poses a high risk, we will also notify affected individuals without undue delay via email or Platform notification, providing information about the nature of the breach, potential consequences, and measures taken to mitigate harm.
12. Contact Information and Complaints
For questions, concerns, or requests related to this Privacy Policy or your personal data, please contact our Data Protection Officer:
- Data Protection Officer Email: [email protected]
- Customer Support Email: [email protected]
- Response Time: We aim to respond to privacy inquiries within five (5) business days and fulfill data subject rights requests within thirty (30) days.
If you believe phsk has violated your privacy rights or applicable data protection laws, you have the right to lodge a complaint with the National Privacy Commission (NPC). Contact details for the NPC are available at privacy.gov.ph.
13. Children's Privacy
phsk services are intended exclusively for individuals aged twenty-one (21) years or older. We do not knowingly collect personal information from minors. If we become aware that personal data has been collected from an individual under 21 without verifiable parental consent, we will take immediate steps to delete such information and terminate the account.
14. Changes to This Privacy Policy
phsk reserves the right to modify this Privacy Policy at any time to reflect changes in legal requirements, business practices, or data processing activities. Material changes will be communicated via email to your registered email address and through prominent Platform notification at least thirty (30) days prior to the effective date. Your continued use of phsk services following the effective date of an amended Privacy Policy constitutes acceptance of the revised terms. If you do not agree to changes, you may close your account in accordance with our Terms & Conditions.
Acknowledgment: By using the phsk platform, you acknowledge that you have read, understood, and agree to the data processing practices described in this Privacy Policy.
Data Protection Standards
How phsk Protects Your Privacy
AES-256 Encryption
Military-grade encryption protects all sensitive data at rest and in transit. Your personal information is unreadable to unauthorized parties.
Strict Access Controls
Role-based permissions ensure only authorized personnel access your data, and all access is logged for audit trails.
Data Privacy Act Compliant
Full adherence to RA 10173 and National Privacy Commission guidelines. Your rights as a data subject are legally protected.
No Third-Party Selling
We never sell, rent, or trade your personal information to advertisers or data brokers. Your privacy is not for sale.
Transparent Data Retention
Clear retention schedules with automatic deletion once legal requirements expire. We don't hoard data indefinitely.
Your Rights, Respected
Easy exercise of access, rectification, erasure, and portability rights. We respond to requests within 30 days.
Privacy Questions or Data Requests?
Our Data Protection Officer is available to address your concerns, fulfill data subject rights requests, or clarify how your information is handled. We're here to help.