Data Privacy Act Compliance: sayaph operates in full compliance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations. Your personal information is processed only for lawful purposes with appropriate safeguards in place as required by the National Privacy Commission (NPC).
By using sayaph services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your personal data as described herein.
Quick Navigation
1. Introduction 2. Data Controller 3. Data We Collect 4. Legal Basis 5. How We Use Your Data 6. Data Sharing 7. Data Retention 8. Security Measures 9. Cookies Policy 10. Your Privacy Rights 11. Minors & Age Policy 12. International Transfers 13. AML Obligations 14. Policy Changes 15. Contact Our DPO1. Introduction
This Privacy Policy governs the collection, use, storage, sharing, and protection of personal information by sayaph ("sayaph," "we," "us," or "our"), the operator of the online casino platform accessible at sayaph.cam.
sayaph is a PAGCOR-licensed online casino platform serving Filipino players across the Philippines. As part of our operations, we necessarily collect and process certain personal data to provide gaming services, verify player identities, process financial transactions, comply with legal obligations, and maintain the security and integrity of our platform.
We recognize that Filipino players entrust us with sensitive personal and financial information. This trust forms the foundation of everything we do. sayaph is committed to processing your data responsibly, transparently, and in strict compliance with:
- Republic Act No. 10173 – Philippine Data Privacy Act of 2012 (DPA)
- National Privacy Commission (NPC) regulations and circulars
- PAGCOR licensing requirements relating to player data
- Republic Act No. 9160 – Anti-Money Laundering Act (AMLA), as amended
This policy applies to all personal data collected through the sayaph website, mobile platform, customer support channels, and any other means by which you interact with sayaph services.
2. Data Controller
For purposes of the Philippine Data Privacy Act, sayaph is the personal information controller (PIC) responsible for your personal data. sayaph determines the purposes and means of processing your personal information in connection with the gaming services we provide.
sayaph has designated a Data Protection Officer (DPO) as required by the DPA and NPC regulations. The DPO is responsible for overseeing sayaph's data protection strategy and compliance program. Contact details for our DPO are provided in Section 15 of this policy.
Where sayaph engages third-party service providers to process personal data on our behalf (such as payment processors, identity verification providers, and game software vendors), those parties act as personal information processors (PIPs) under binding data processing agreements that require them to maintain equivalent data protection standards.
3. Personal Data We Collect
sayaph collects personal data through multiple touchpoints across your relationship with our platform. The categories of data collected are as follows:
3.1 Registration and Identity Data
When you create a sayaph account, we collect your full legal name, date of birth, mobile number, email address, residential address in the Philippines, and the username you select. This information is required to establish your account and verify your identity.
3.2 Identity Verification (KYC) Data
To comply with PAGCOR licensing conditions and Philippine AML requirements, sayaph conducts Know Your Customer (KYC) verification. This process requires submission of:
- Government-issued photo identification (Philippine passport, driver's license, national ID, SSS/GSIS card, or PRC ID)
- Proof of residential address (utility bill, bank statement, or barangay certificate)
- Selfie photograph for facial verification against submitted ID
- Source of funds documentation where required by AML thresholds
3.3 Financial Data
sayaph collects financial information necessary to process deposits and withdrawals, including GCash account numbers, PayMaya account details, Philippine bank account information (account name, account number, bank name), and transaction history on the sayaph platform. We do not store complete credit or debit card numbers; payment card data is handled exclusively by PCI-DSS-compliant payment processors.
3.4 Technical and Usage Data
When you access sayaph, our systems automatically collect technical data including IP address, device type and model, operating system and version, browser type and version, session duration, pages visited, game history, bet amounts and outcomes, and platform interaction logs.
3.5 Communications Data
Records of communications between you and sayaph customer support, including live chat transcripts, email correspondence, and support ticket history, are retained to maintain service quality and resolve disputes.
3.6 Sensitive Personal Information
Under certain circumstances, sayaph may collect sensitive personal information as defined by the DPA, including information about your financial standing when required for AML compliance. Such sensitive data is subject to heightened protection measures and is processed only when strictly necessary for a lawful purpose.
| Data Category | Examples | Collection Point |
|---|---|---|
| Identity Data | Full name, date of birth, address | Account registration |
| KYC Documents | Government ID, selfie, proof of address | Verification process |
| Financial Data | GCash number, bank account, transaction history | Deposits & withdrawals |
| Technical Data | IP address, device info, session logs | Platform access |
| Gameplay Data | Bet history, game sessions, win/loss records | Game activity |
| Communications | Support transcripts, emails | Customer support |
4. Legal Basis for Processing
Under the Philippine Data Privacy Act, sayaph processes your personal data on the following lawful bases:
- Contractual Necessity: Processing required to perform our contract with you - providing gaming services, processing payments, managing your account, and fulfilling our obligations under the sayaph Terms & Conditions.
- Legal Obligation: Processing required to comply with applicable Philippine laws including the Data Privacy Act, Anti-Money Laundering Act, PAGCOR licensing conditions, and National Privacy Commission regulations.
- Legitimate Interest: Processing necessary for sayaph's legitimate business interests including fraud prevention, platform security, dispute resolution, and service improvement, where these interests are not overridden by your privacy rights.
- Consent: Processing based on your freely given, specific, informed consent - particularly for marketing communications and optional personalization features. You may withdraw consent at any time.
5. How sayaph Uses Your Personal Data
sayaph uses collected personal data for the following specific purposes:
5.1 Account Management and Service Delivery
Creating and maintaining your sayaph account, authenticating your identity at login, processing deposits and withdrawals, recording gaming activity, providing access to all platform features, and responding to your support requests.
5.2 Identity Verification and Regulatory Compliance
Verifying your identity in accordance with PAGCOR KYC requirements, confirming your age eligibility (21 years and older as required by Philippine gambling regulations), monitoring transactions for AML compliance, filing mandatory regulatory reports with PAGCOR and the Anti-Money Laundering Council (AMLC) where required by law.
5.3 Security and Fraud Prevention
Detecting and preventing unauthorized account access, identifying fraudulent transactions and bonus abuse, monitoring for multi-accounting violations, maintaining audit logs for security investigations, and protecting the integrity of sayaph's gaming environment.
5.4 Responsible Gaming
Monitoring gameplay patterns that may indicate problem gambling behavior, administering self-exclusion and deposit limit programs, communicating responsible gaming information, and complying with PAGCOR's responsible gaming requirements.
5.5 Platform Improvement
Analyzing anonymized usage patterns to improve platform performance, identifying technical issues, optimizing the gaming experience for Philippine network conditions, and developing new features that serve Filipino players better.
5.6 Marketing Communications (With Consent)
Sending promotional offers, bonus notifications, and platform updates via email and SMS - only where you have given explicit consent to receive such communications. You can opt out of marketing messages at any time through your account settings or by contacting support.
6. Data Sharing and Disclosure
sayaph does not sell your personal data to third parties. We share personal data only in the following limited circumstances:
6.1 Service Providers and Processors
sayaph engages carefully vetted third-party processors who assist in delivering our services. These include payment processors (GCash, PayMaya, InstaPay partners), identity verification providers, game software vendors, cloud infrastructure providers, and customer support platforms. All processors are bound by data processing agreements requiring them to handle your data exclusively in accordance with sayaph's instructions and applicable Philippine law.
6.2 Regulatory Authorities
sayaph is legally required to disclose certain player data to PAGCOR and the Anti-Money Laundering Council (AMLC) as part of our licensing and AML compliance obligations. Such disclosures are made only as required by law and within the scope of applicable reporting requirements.
6.3 Law Enforcement
sayaph may disclose personal data to Philippine law enforcement agencies, courts, or other government bodies when legally compelled to do so by valid legal process (subpoena, court order, or equivalent legal instrument), or when disclosure is necessary to prevent imminent harm or fraud.
6.4 Business Transfers
In the event of a merger, acquisition, or sale of sayaph's business assets, personal data may be transferred to the acquiring entity as part of the transaction. Players will be notified of any such transfer and the privacy policy of the acquiring entity prior to the transfer taking effect, in accordance with DPA requirements.
6.5 With Your Consent
sayaph will not share your personal data with any other third party without your explicit prior consent, except as described in this section.
7. Data Retention
sayaph retains personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by applicable Philippine law.
7.1 Active Account Data
Personal data associated with active sayaph accounts is retained throughout the duration of the account relationship and for a minimum period following account closure to comply with legal obligations.
7.2 Post-Closure Retention
Following account closure, sayaph retains account and transaction records for a minimum of five (5) years as required by Philippine AML regulations and PAGCOR licensing conditions. KYC documentation is retained for the same period.
7.3 Legal Hold
Where personal data is subject to an active legal dispute, regulatory investigation, or legal hold order, retention is extended until the matter is fully resolved regardless of the standard retention period.
7.4 Marketing Data
Marketing consent records and preferences are retained for the duration of your account and for three (3) years following account closure, to demonstrate compliance with consent requirements.
7.5 Data Deletion
Upon expiry of applicable retention periods, sayaph securely destroys or anonymizes personal data in accordance with NPC guidelines. Technical and system logs may be anonymized and retained for statistical purposes without identifying individual players.
8. Security Measures
sayaph employs comprehensive technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Our security program includes:
8.1 Technical Safeguards
- Encryption: All data transmitted between your device and sayaph servers is encrypted using TLS 1.3 or higher. Sensitive stored data including KYC documents and financial records is encrypted at rest using AES-256 encryption.
- Access Controls: Strict role-based access controls limit employee access to personal data on a need-to-know basis. All access to sensitive data is logged and audited.
- Authentication: Multi-factor authentication is required for all sayaph staff accessing player data systems. Players are encouraged to enable 2FA on their accounts.
- Intrusion Detection: Automated intrusion detection and prevention systems monitor sayaph's infrastructure 24/7 for unauthorized access attempts.
- Penetration Testing: sayaph's systems undergo regular independent security assessments including penetration testing and vulnerability scanning.
8.2 Organizational Safeguards
- All sayaph employees with access to personal data are bound by confidentiality obligations and undergo mandatory data privacy training.
- A documented data breach response plan is maintained and tested regularly, with NPC notification procedures in place as required by the DPA.
- Third-party processors are subject to security assessments before engagement and periodic re-assessment during the contract period.
8.3 Data Breach Notification
In the event of a personal data breach that poses a real risk of serious harm, sayaph will notify the National Privacy Commission within 72 hours of discovery as required by the DPA, and will notify affected players as promptly as practicable with information about the breach and recommended protective actions.
9. Cookies and Tracking Technologies
9.1 What Are Cookies
Cookies are small text files stored on your device when you visit sayaph. They help us recognize you, remember your preferences, maintain your session security, and understand how you use our platform.
9.2 Types of Cookies sayaph Uses
- Strictly Necessary Cookies: Essential for the platform to function - maintaining your login session, preserving security tokens, and enabling core gaming functions. These cannot be disabled without breaking the service.
- Functional Cookies: Remember your language preferences, game display settings, and other personalization choices. Disabling these may reduce platform functionality.
- Analytics Cookies: Collect anonymized data about how players navigate sayaph, which features are most used, and where technical issues occur. This data helps us improve the platform.
- Security Cookies: Support fraud detection and account security by identifying unusual access patterns across sessions.
9.3 Managing Cookies
You can control cookie settings through your browser preferences. Note that disabling strictly necessary cookies will prevent you from logging into or using sayaph. Analytics and functional cookies can be disabled without affecting core service availability. sayaph does not use third-party advertising cookies or behavioral tracking cookies for external advertising purposes.
10. Your Privacy Rights Under Philippine Law
The Philippine Data Privacy Act grants you the following rights with respect to your personal data held by sayaph. You may exercise any of these rights by contacting our Data Protection Officer as described in Section 15.
Your Data Rights Under RA 10173
The Philippine Data Privacy Act gives you meaningful control over your personal information at sayaph. Here's what you're entitled to.
Right to Be Informed
You have the right to know whether sayaph holds personal data about you, what data we hold, and how it is being processed. This Privacy Policy fulfills our notification obligation.
Right to Access
You may request a copy of the personal data sayaph holds about you, including information on how it has been processed and with whom it has been shared.
Right to Correction
If any personal data sayaph holds about you is inaccurate, incomplete, or outdated, you have the right to request correction. We will update your records as promptly as possible.
Right to Erasure
You may request deletion of your personal data where it is no longer necessary for the purpose collected, or where processing was based on consent that you have withdrawn. Legal retention obligations may limit this right.
Right to Object
You may object to processing of your personal data for direct marketing purposes at any time. You may also object to processing based on legitimate interest where your individual circumstances warrant.
Right to Data Portability
Where technically feasible, you may request your personal data in a structured, commonly used, machine-readable format for transfer to another service provider.
How to Exercise Your Rights: Submit a written request to sayaph's Data Protection Officer at [email protected] with the subject line "Data Privacy Request." Include your full name, account username, and a description of your request. sayaph will respond within fifteen (15) business days. If you are not satisfied with sayaph's response, you have the right to file a complaint with the National Privacy Commission at privacy.gov.ph.
11. Minors and Age Restriction Policy
sayaph services are intended exclusively for individuals aged 21 years and older, in compliance with Philippine gambling regulations enforced by PAGCOR. sayaph does not knowingly collect personal data from individuals under the age of 21.
Age verification is a mandatory component of sayaph's KYC process. Where age verification reveals that a Player is under 21 years of age, sayaph will:
- Immediately suspend the account pending investigation.
- Return any deposits made by the underage individual to the original payment source after deducting any costs incurred.
- Permanently close the account and delete collected personal data to the extent permitted by law.
- Report the incident to PAGCOR as required by licensing conditions.
If you are a parent or guardian and believe that a minor in your care has registered a sayaph account, please contact our support team immediately. We take underage gambling seriously and will act on such reports without delay.
12. International Data Transfers
As part of delivering our services, sayaph may transfer personal data to third-party processors located outside the Philippines. Such transfers occur when engaging cloud infrastructure providers, game software vendors, or specialist technical services that operate internationally.
All international data transfers are conducted in compliance with the DPA's requirements for cross-border data transfers. Specifically, sayaph ensures that:
- Transfers are made only to countries with adequate data protection standards, or
- Appropriate contractual safeguards (standard contractual clauses or equivalent) are in place with the receiving party, or
- The transfer is necessary to perform the contract with you and no alternative means of processing is available.
sayaph does not transfer personal data internationally for purposes beyond those described in this Privacy Policy, and all international processors are prohibited from using your data for their own independent purposes.
13. Anti-Money Laundering Obligations
As a PAGCOR-licensed casino operator, sayaph is a covered person under the Philippine Anti-Money Laundering Act (RA 9160, as amended by RA 10365 and RA 11521). This status imposes mandatory data collection and reporting obligations that affect how we handle certain categories of player information.
13.1 Mandatory Collection
sayaph is legally required to collect and verify identity information, maintain detailed transaction records, and monitor transactions for suspicious activity patterns. These obligations exist independently of your consent and cannot be waived by individual players.
13.2 Mandatory Reporting
sayaph is legally required to file Covered Transaction Reports (CTRs) with the Anti-Money Laundering Council (AMLC) for single cash transactions exceeding ₱500,000, and Suspicious Transaction Reports (STRs) where transactions exhibit characteristics identified in AMLC regulations as potentially linked to money laundering or terrorism financing. These reports are filed without your knowledge or consent, as required by Philippine law.
13.3 Record Keeping
Transaction records maintained for AML compliance are retained for a minimum of five (5) years from the date of the transaction, overriding standard retention schedules. These records may be disclosed to the AMLC, PAGCOR, or law enforcement agencies pursuant to lawful authority.
14. Changes to This Privacy Policy
sayaph reserves the right to update or modify this Privacy Policy at any time to reflect changes in our data practices, applicable law, or regulatory requirements. The "Last Updated" date at the top of this page reflects the most recent revision.
For material changes that significantly affect your privacy rights or the way we use your personal data, sayaph will provide advance notice via registered email and in-platform notification at least seven (7) days before the changes take effect. For minor clarifications or non-material updates, changes may take effect immediately upon publication.
Your continued use of sayaph services following the effective date of any Privacy Policy revision constitutes your acknowledgment of the updated policy. If you do not agree with material changes to this policy, you should discontinue use of sayaph services and contact support to request account closure.
The current version of this Privacy Policy is always accessible at sayaph.cam/privacy-policy. We recommend reviewing this page periodically to stay informed of how sayaph protects your personal data.
15. Contact Our Data Protection Officer
For any privacy-related inquiries, requests to exercise your data rights, concerns about sayaph's data practices, or to report a potential privacy issue, please contact sayaph's Data Protection Officer:
- Email: [email protected] (subject line: "Data Privacy Request" or "DPO Inquiry")
- Live Chat: Available 24/7 via the sayaph platform — ask to be connected to the data privacy team
- Response Time: sayaph's DPO will acknowledge receipt within 48 hours and respond substantively within 15 business days
- Languages: English and Filipino (Tagalog)
If you believe sayaph has not adequately addressed your privacy concern, you have the right to lodge a complaint directly with the National Privacy Commission of the Philippines (NPC). The NPC is the independent government body responsible for enforcing the Data Privacy Act and protecting the privacy rights of Filipino citizens.
How sayaph Protects Your Data
Privacy at sayaph isn't just a legal checkbox. Here's what we actually do to keep your information safe every single day.
AES-256 Encryption at Rest
All personal data stored on sayaph's servers is encrypted using AES-256 - the same standard used by Philippine government agencies and international financial institutions. Your KYC documents, financial records, and account information are unreadable without the encryption keys, which are themselves protected by hardware security modules.
DPA-Compliant Data Program
sayaph's data protection program was built from the ground up to meet RA 10173 requirements. We have a registered Data Protection Officer, a documented Privacy Management Program, and regular NPC compliance reviews. This isn't reactive compliance - it's how we've operated since day one.
Staff Privacy Training
Every sayaph employee who handles personal data completes mandatory privacy training before accessing player systems. Access is role-limited, logged, and audited. No employee can access your full data profile without a legitimate operational reason that is recorded and reviewable by our DPO.
Independent Security Audits
sayaph's systems undergo independent penetration testing and security audits on a regular schedule. Identified vulnerabilities are remediated under tracked timelines. Audit results inform our continuous improvement program - not filed away and forgotten.
72-Hour Breach Notification
If a data breach affecting your personal information occurs, sayaph is required under the DPA to notify the National Privacy Commission within 72 hours. Affected players receive direct notification as promptly as possible, along with clear guidance on protective steps you can take.
Binding Processor Agreements
Every third-party vendor that touches sayaph player data signs a binding data processing agreement requiring them to meet DPA standards, prohibiting them from using your data for their own purposes, and making them directly accountable for breaches caused by their systems.
Play at sayaph - Your Privacy is Protected
Over 150,000 Filipino players trust sayaph with their personal and financial data. Our PAGCOR-licensed platform, DPA-compliant data program, and Manila-based support team ensure your information stays private, secure, and under your control.
21+ only. PAGCOR Licensed. Play responsibly.