phderm Privacy Policy
At phderm, your privacy is not an afterthought — it is a foundational part of how we operate. This Privacy Policy explains what personal data we collect from players in the Philippines, why we collect it, how we use and protect it, and what rights you have under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173).
How phderm Protects Your Privacy
Here is a plain-language summary of the key privacy commitments phderm makes to every registered player. The full legal text follows below.
phderm complies fully with Republic Act No. 10173 — the Philippine Data Privacy Act of 2012 — and the implementing rules issued by the National Privacy Commission (NPC). Your personal data is handled lawfully, fairly, and transparently at every stage.
All data transmitted between your device and phderm is protected by 256-bit SSL/TLS encryption. Your personal details, financial information, and account credentials are never sent in plaintext — every connection to phderm is secured end-to-end.
Under the Data Privacy Act, you have the right to access, correct, delete, object to, and port your personal data held by phderm. You also have the right to lodge a complaint with the National Privacy Commission if you believe your rights have been violated.
phderm does not sell, rent, or trade your personal data to third parties for their own marketing purposes. Data shared with third-party service providers — such as payment processors — is shared solely to deliver the services you use and is governed by strict data processing agreements.
phderm collects only the personal data that is strictly necessary for the purposes described in this Policy. We do not request information we do not need, and we regularly review our data holdings to delete or anonymise records that are no longer required for operational or legal purposes.
phderm retains your personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal obligations (including PAGCOR and AMLC reporting requirements), or to resolve disputes. Once retention periods expire, data is securely deleted or anonymised.
Who We Are
phderm ("phderm," "we," "us," or "our") is the operator of the phderm online casino and gaming platform, accessible at phderm.net. We are the personal information controller responsible for the personal data of players who register and use our platform in the Philippines and, where applicable, in other jurisdictions.
As a personal information controller under Republic Act No. 10173 (the Philippine Data Privacy Act of 2012, or "DPA") and its Implementing Rules and Regulations, phderm determines the purposes and means of processing your personal data. We have designated a Data Protection Officer ("DPO") who is responsible for overseeing our compliance with data protection obligations. Contact details for our DPO are provided in Section 14 of this Policy.
Personal Data We Collect
phderm collects the following categories of personal data, depending on how you interact with our platform:
| Category | Examples | Collected When |
|---|---|---|
| Identity Data | Full legal name, date of birth, government-issued ID number, nationality | Registration & KYC verification |
| Contact Data | Email address, mobile number, residential address (city, province) | Registration & account updates |
| Financial Data | GCash number, Maya account, bank account name and number (BPI, BDO, Metrobank), transaction history | Deposits, withdrawals & KYC |
| Technical Data | IP address, device type, browser type and version, operating system, session timestamps | Each platform visit |
| Usage Data | Pages visited, games played, bet amounts, session duration, feature interactions | Active use of the platform |
| Communications Data | Live chat transcripts, support emails, feedback submissions | When you contact phderm support |
| Responsible Gaming Data | Self-exclusion status, deposit limits set, cool-off period history | When you use responsible gaming tools |
Special categories of data. phderm does not intentionally collect sensitive personal information as defined under Section 3(l) of the DPA (such as health data, religious beliefs, or political affiliations) unless specifically required by law or provided voluntarily by you in the context of a support interaction. Any such data is handled with heightened care and processed only on the basis of explicit consent or legal obligation.
How We Collect Your Data
phderm collects personal data through the following channels:
- Direct interactions — when you register a phderm account, complete identity verification, make a deposit or withdrawal, contact our support team, or update your account settings.
- Automated technologies — cookies, web beacons, server logs, and similar tracking technologies that operate when you access the phderm website or mobile platform. See Section 7 for full details on our use of cookies.
- Third-party payment providers — confirmation and transaction metadata shared by GCash, Maya, BPI, BDO, Metrobank, and other payment service providers when you initiate a deposit or withdrawal.
- Identity verification providers — data returned by our KYC and AML screening partners when we verify your identity or screen your account against sanctions and watchlists required under Philippine anti-money laundering regulations.
- Publicly available sources — data from public databases, government records, or publicly available social media profiles where relevant to fraud prevention or AML obligations.
Why We Use Your Personal Data
phderm uses your personal data for the following purposes:
- Account management — to create and administer your phderm account, authenticate your identity at login, and provide access to platform features.
- Service delivery — to process your deposits and withdrawals, settle bets, credit bonuses, and deliver the gaming experience you expect from phderm.
- Identity verification & KYC — to verify your age (21+), identity, and address in compliance with PAGCOR licensing requirements and Philippine AML regulations.
- Fraud prevention & security — to detect, investigate, and prevent fraudulent transactions, account takeovers, bonus abuse, collusion, and other prohibited activities.
- Legal compliance — to meet our obligations under the DPA, AMLA, PAGCOR regulations, Bureau of Internal Revenue requirements, and other applicable Philippine laws.
- Responsible gaming — to monitor gameplay patterns, enforce self-exclusion and deposit limits, and proactively reach out to players who may be exhibiting signs of problem gambling.
- Customer support — to respond to your queries, complaints, and support requests in a timely and effective manner.
- Marketing communications — to send you promotional offers, bonus notifications, and platform updates by email or SMS, where you have given consent or where we have a legitimate interest to do so. You may opt out at any time.
- Platform improvement — to analyse aggregated usage patterns, conduct A/B testing, and improve the phderm user experience based on how players interact with our platform.
Legal Bases for Processing
Under the Philippine Data Privacy Act, phderm processes your personal data on one or more of the following legal bases:
- Contractual necessity — processing is necessary to perform the contract between you and phderm (i.e., the Terms and Conditions you accepted at registration), including account creation, payment processing, and game delivery.
- Legal obligation — processing is required to comply with a legal obligation applicable to phderm, including AML reporting to the Anti-Money Laundering Council (AMLC), age verification obligations, and PAGCOR regulatory requirements.
- Legitimate interests — processing is necessary for phderm's legitimate interests, including fraud prevention, platform security, and improving our services, provided those interests are not overridden by your rights and interests.
- Consent — for marketing communications and certain non-essential cookies, phderm relies on your freely given, specific, informed, and unambiguous consent. You may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
Sharing Your Personal Data
phderm does not sell or rent your personal data. We may share your data with the following categories of recipients, strictly for the purposes described in this Policy:
- Payment service providers — GCash, Maya, GrabPay, BPI, BDO, Metrobank, and other payment processors receive the data required to authenticate and complete your financial transactions.
- KYC and AML partners — identity verification and screening providers receive identity documents and related data to fulfil our regulatory obligations.
- Game software providers — game studios and live dealer operators receive session and gameplay data necessary to deliver and audit game outcomes. All such providers are bound by contractual data protection obligations.
- Regulatory authorities — phderm may be required to disclose personal data to PAGCOR, the AMLC, the National Privacy Commission, the Bureau of Internal Revenue, or other Philippine government bodies upon lawful request.
- Law enforcement — where required by a valid court order, subpoena, or other legal process, phderm may disclose personal data to law enforcement agencies in the Philippines.
- Professional advisers — lawyers, auditors, and accountants engaged by phderm may access personal data to the extent necessary to provide their professional services, subject to confidentiality obligations.
- Business transfers — in the event of a merger, acquisition, or sale of all or part of phderm's business, personal data may be transferred to the acquiring entity, subject to equivalent privacy protections.
All third-party processors engaged by phderm are required to process personal data only on documented instructions from phderm, to implement appropriate security measures, and to comply with applicable data protection laws.
Cookies & Tracking Technologies
phderm uses cookies and similar technologies to operate the platform, enhance your experience, and gather analytics data. The categories of cookies we use are as follows:
- Strictly necessary cookies — essential for the platform to function. These include session authentication cookies, security tokens, and load-balancing cookies. They cannot be disabled without affecting platform functionality.
- Analytics cookies — used to understand how players navigate the phderm platform, which pages are visited most, and where errors occur. Data collected is aggregated and anonymised where possible. These cookies are activated only with your consent.
- Functional cookies — used to remember your preferences, such as language settings and responsible gaming limits. These improve usability but are not strictly necessary.
- Marketing cookies — used to deliver relevant promotional content based on your interests. These are only activated where you have provided consent and can be withdrawn at any time.
You can manage your cookie preferences through your browser settings. Note that disabling strictly necessary cookies will impair your ability to access and use the phderm platform. For detailed guidance on managing cookies in your specific browser, refer to your browser's help documentation.
Data Security
phderm implements a comprehensive set of technical, organisational, and physical security measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure. Key measures include:
- 256-bit SSL/TLS encryption for all data in transit between your device and phderm servers.
- Encryption of sensitive data at rest, including financial records and identity documents.
- Role-based access controls ensuring that staff can only access personal data necessary for their specific function.
- Multi-factor authentication requirements for administrative access to systems holding personal data.
- Regular penetration testing, vulnerability assessments, and security audits conducted by independent third parties.
- Incident response procedures that include prompt notification to the National Privacy Commission and affected data subjects in the event of a data breach, in accordance with NPC Circular 16-03.
While phderm takes all reasonable steps to protect your data, no online platform can guarantee absolute security. You also bear responsibility for maintaining the confidentiality of your phderm account credentials. Please contact phderm support immediately if you suspect your account has been compromised.
Data Retention Periods
phderm retains personal data for different periods depending on the category of data and the purpose for which it was collected. Our general retention principles are as follows:
- Account and identity data — retained for the duration of your active phderm account and for a period of five (5) years following account closure, in compliance with PAGCOR and AMLC record-keeping requirements.
- Transaction and financial data — retained for a minimum of five (5) years from the date of each transaction, consistent with AMLA obligations.
- Communications and support data — retained for three (3) years from the date of last interaction, to allow for dispute resolution and quality assurance.
- Technical and usage data — retained in identifiable form for up to twelve (12) months, after which it is aggregated or anonymised for analytics purposes.
- Responsible gaming data — self-exclusion records are retained for the full duration of the exclusion period and for five (5) years thereafter, to prevent re-registration during an active exclusion.
Upon expiry of the applicable retention period, personal data is securely deleted, destroyed, or anonymised in a manner that prevents reconstruction of the original data.
Your Data Subject Rights
Under the Philippine Data Privacy Act and its Implementing Rules, you have the following rights with respect to your personal data held by phderm:
- Right to be informed — to know what personal data phderm holds about you, the purposes for which it is processed, and your rights under the DPA.
- Right of access — to request a copy of the personal data phderm holds about you, together with information on how it is processed.
- Right to rectification — to request correction of inaccurate or incomplete personal data. You may also update basic profile information directly through your phderm account settings.
- Right to erasure — to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to phderm's legal retention obligations.
- Right to object — to object to the processing of your personal data on grounds of legitimate interest, including profiling for direct marketing purposes.
- Right to data portability — to receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller where technically feasible.
- Right to lodge a complaint — to file a complaint with the National Privacy Commission (NPC) if you believe phderm has violated your rights under the DPA. The NPC can be reached via the official NPC website.
To exercise any of the above rights, please contact phderm's Data Protection Officer using the contact details in Section 14. phderm will respond to all verified data subject requests within fifteen (15) business days of receipt. We may require you to verify your identity before processing your request.
Children's Privacy
The phderm platform is strictly restricted to individuals aged 21 years and above, in accordance with PAGCOR regulations. phderm does not knowingly collect personal data from anyone under the age of 21. If we become aware that personal data has been collected from a person under 21, we will immediately suspend the associated account, delete the data, and refund any deposits made, in accordance with our Terms and Conditions.
If you believe a minor has registered a phderm account, please contact our support team immediately via live chat or at the support email address listed in Section 14. We take underage access extremely seriously and will act promptly on all such reports.
Cross-Border Data Transfers
Some of phderm's third-party service providers — including game software providers, cloud infrastructure partners, and cybersecurity vendors — may be located outside of the Philippines. Where personal data is transferred to a country that has not been assessed as providing an adequate level of data protection equivalent to the DPA, phderm ensures that appropriate safeguards are in place, including:
- Contractual clauses in data processing agreements that bind the recipient to equivalent data protection standards.
- Assessment of the data protection practices of the recipient organisation prior to transfer.
- Transfer only of the minimum data necessary for the specific purpose of the transfer.
By using the phderm platform, you acknowledge that your personal data may be processed in countries outside the Philippines, subject to the safeguards described above.
Updates to This Privacy Policy
phderm may update this Privacy Policy from time to time to reflect changes in our data practices, applicable law, or regulatory guidance from the National Privacy Commission. When we make material changes — meaning changes that affect how your personal data is collected, used, or shared in a significant way — we will notify you by email to your registered address or via a prominent notice on the phderm platform before the changes take effect.
The "Last Updated" date at the top of this Policy indicates when the most recent revision was made. We encourage you to review this Policy periodically. Your continued use of phderm after the effective date of any revised Policy constitutes your acceptance of the changes.
Contact Us & Data Protection Officer
If you have any questions, concerns, or requests relating to this Privacy Policy or the way phderm handles your personal data, you may contact our Data Protection Officer directly. All data subject requests and privacy-related inquiries are handled by the DPO.
phderm Data Protection Officer
Email: [email protected]
(Please copy and paste this address into your email client — it is displayed as plain text and is not a clickable link.)
You also have the right to escalate any unresolved privacy complaint to the National Privacy Commission of the Philippines. The NPC is the independent supervisory authority responsible for enforcing the Data Privacy Act. Information on how to file a complaint is available on the official NPC website.
Questions about your data? Our support team is available around the clock. Ready to play? Explore everything phderm Casino has to offer — slots, live dealers, bingo, and more.
Explore phderm Casino Responsible Gaming