1 Introduction
dbx77 ("dbx77," "we," "us," or "our") is committed to protecting the personal data and privacy of every Filipino player who uses our online casino and sports betting platform at dbx77.app. We recognize that privacy is a fundamental right under Philippine law, and we take our obligations as a data controller seriously.
This Privacy Policy describes how dbx77 collects, processes, stores, discloses, and protects your personal data in compliance with the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, the directives of the National Privacy Commission (NPC), and PAGCOR's applicable data governance requirements.
This Policy applies to all personal data we collect through:
- Registration and use of your dbx77 Account;
- Deposits, withdrawals, and payment processing via GCash, PayMaya, BPI, BDO, Metrobank, and other payment providers;
- Your interactions with dbx77's customer support team;
- Your use of our website, mobile platform, and any related services; and
- Your participation in promotions, bonuses, and loyalty programs.
Plain language summary: We collect certain personal information about you to run your account, process your payments, keep you and our platform safe, and comply with Philippine law. We do not sell your data to third parties. You have legal rights over your data, and this Policy explains exactly how to exercise them.
2 Data Controller
For the purposes of the Data Privacy Act of 2012 and this Privacy Policy, dbx77 is the Personal Information Controller in respect of personal data collected through the dbx77.app Platform and associated services.
dbx77 determines the purpose and means of processing personal data obtained from players, applicants, and visitors to the Platform. In cases where dbx77 engages third-party service providers to process personal data on our behalf, those providers act as Personal Information Processors and are bound by written data processing agreements that require equivalent data protection standards.
Our designated Data Protection Officer (DPO) is responsible for ensuring dbx77's compliance with RA 10173 and for responding to data-related queries and complaints from players. Contact details for our DPO are provided in Section 16.
3 Personal Data We Collect
dbx77 collects the following categories of personal data, depending on how you interact with our Platform:
| Category | Data Types | Purpose |
|---|---|---|
| Identity Data | Full name, date of birth, gender, nationality, government ID type and number (e.g., PhilSys, passport, driver's license, UMID) | Account registration, KYC verification, age verification (21+), AML compliance |
| Contact Data | Philippine mobile number (+63), email address, residential address (city/province) | Account communications, OTP delivery, support correspondence, regulatory notifications |
| Financial Data | GCash number, PayMaya number, bank account details (BPI, BDO, Metrobank), transaction history, deposit and withdrawal records | Payment processing, AML compliance, fraud prevention, PAGCOR reporting obligations |
| Gaming Data | Game session logs, bet amounts, win/loss records, game history, bonus participation, wagering activity | Game integrity, dispute resolution, responsible gaming monitoring, PAGCOR reporting |
| Technical Data | IP address, device identifiers, browser type, operating system, session timestamps, geolocation data | Security monitoring, fraud detection, geographic access control, platform optimization |
| Behavioral Data | Pages visited, features used, session duration, click patterns, support interactions | Platform improvement, personalized experience, responsible gaming pattern detection |
| Communication Data | Live chat transcripts, support emails, feedback submissions | Quality assurance, dispute resolution, service improvement, training |
Sensitive Personal Information: Government-issued ID information and financial account data fall within the definition of sensitive personal information under RA 10173. dbx77 processes such data only to the extent strictly necessary for KYC verification and compliance purposes, using enhanced security safeguards as described in Section 9.
4 How We Collect Your Personal Data
dbx77 collects personal data through the following means:
4.1 Direct Collection
Data you provide directly to dbx77 when you register an Account, complete identity verification, make deposits or withdrawal requests, contact customer support, participate in promotions, or update your Account profile. This includes all information entered into forms on the dbx77.app Platform.
4.2 Automated Collection
Technical data collected automatically when you access or use the Platform, including through cookies, log files, pixel tags, and similar tracking technologies as described in Section 10. This includes your IP address, device type, browser information, session data, and approximate geographic location.
4.3 Third-Party Sources
Data received from third-party service providers as part of our verification, payment processing, and fraud prevention operations. This may include identity verification status from KYC providers, payment transaction data from GCash, PayMaya, and Philippine banks, and risk assessments from AML screening services.
4.4 Publicly Available Sources
In limited circumstances related to AML compliance and fraud prevention, dbx77 may reference publicly available information from Philippine government databases, court records, or other lawful public sources to verify player identity or assess risk.
5 How We Use Your Personal Data
dbx77 processes your personal data for the following specific, legitimate, and declared purposes:
- Account administration: Creating and maintaining your dbx77 Account, authenticating your identity at login, managing your Wallet balance, and providing access to platform features.
- Age and identity verification: Confirming that all players meet the mandatory 21+ age requirement under PAGCOR regulations, and conducting KYC checks required by Philippine law.
- Payment processing: Processing deposits via GCash, PayMaya, BPI, BDO, Metrobank, and other approved Philippine payment channels, and executing withdrawal requests to your registered payment instruments.
- Legal and regulatory compliance: Meeting dbx77's obligations under PAGCOR licensing conditions, RA 9160 (Anti-Money Laundering Act) and its amendments, RA 10175 (Cybercrime Prevention Act), RA 10173 (Data Privacy Act), and all other applicable Philippine laws and regulations.
- Fraud prevention and security: Detecting, investigating, and preventing fraudulent activity, unauthorized Account access, bonus abuse, collusion, and other security threats to the Platform.
- Customer support: Responding to your queries, processing complaints, resolving disputes, and providing platform assistance via live chat, email, and other support channels.
- Responsible gaming: Monitoring gaming patterns to identify potential problem gambling behavior, administering player-requested deposit limits and self-exclusion, and fulfilling PAGCOR responsible gaming obligations.
- Platform improvement: Analyzing aggregated usage data to improve the dbx77 Platform's performance, features, and user experience for Filipino players.
- Marketing communications: Sending promotional offers, bonus notifications, and platform updates to players who have opted in to receive such communications. You may opt out of marketing communications at any time via your Account settings or by contacting support.
dbx77 does not sell, rent, or trade your personal data to third parties for their own marketing or commercial purposes. This is an absolute commitment, not subject to exception.
6 Legal Basis for Processing
Under the Data Privacy Act of 2012, dbx77 processes your personal data on the following legal grounds:
- Contractual necessity: Processing required to perform our contract with you — i.e., to operate your Account, process payments, and provide gaming services in accordance with our Terms & Conditions.
- Legal obligation: Processing necessary to comply with dbx77's obligations under PAGCOR regulations, the Anti-Money Laundering Act, the Data Privacy Act, and other applicable Philippine law. Such processing cannot be refused even if you object.
- Legitimate interests: Processing necessary for dbx77's legitimate business interests, including fraud prevention, platform security, and responsible gaming monitoring, where such interests are not overridden by your privacy rights.
- Consent: For marketing communications and certain cookie uses, where we are required to obtain your explicit consent. You may withdraw consent at any time as described in Section 11.
7 Sharing of Personal Data
dbx77 may share your personal data with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate data protection safeguards:
7.1 Regulatory Authorities
PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), and other Philippine government agencies as required by law or valid legal process. dbx77 cannot refuse or delay such disclosures where they are legally mandated.
7.2 Payment Service Providers
GCash, PayMaya, BPI, BDO, Metrobank, InstaPay, PESONet, and other payment partners, strictly to the extent required to process your deposit and withdrawal transactions. These providers process payment data under their own privacy policies and applicable Philippine law.
7.3 Identity Verification and KYC Providers
Third-party KYC and AML service providers engaged by dbx77 to verify player identities and screen against relevant watchlists, as required by Philippine AML regulations. Such providers act as Personal Information Processors bound by data processing agreements.
7.4 Technology and Platform Providers
Game software providers (such as JILI, PG Soft, Pragmatic Play, and CQ9), cloud infrastructure providers, cybersecurity service providers, and other technology partners who process technical and gaming data solely to deliver Platform functionality. All such providers operate under contractual data protection obligations.
7.5 Professional Advisers
Legal counsel, auditors, and compliance advisers, where disclosure is necessary in connection with legal proceedings, regulatory investigations, or the exercise of legal rights.
What dbx77 will NEVER do: We will never sell, rent, lease, or otherwise transfer your personal data to unaffiliated third parties for their own commercial, advertising, or marketing purposes. Any request purporting to be from dbx77 asking you to provide personal data to a third party for unrelated purposes should be treated as fraudulent.
8 Data Retention
dbx77 retains personal data only for as long as necessary to fulfill the purposes for which it was collected, or for as long as required by applicable Philippine law and regulatory obligations, whichever is longer.
- Account data and gaming records: Retained for a minimum of five (5) years from the date of Account closure, as required by PAGCOR licensing conditions and Philippine AML regulations.
- Financial and transaction data: Retained for a minimum of five (5) years from the date of each transaction, in compliance with RA 9160 (Anti-Money Laundering Act) requirements.
- KYC and identity verification documents: Retained for the duration of the Account relationship and for five (5) years thereafter, or as otherwise required by PAGCOR and AMLC regulations.
- Support and communication records: Retained for three (3) years from the date of the communication, or until resolution of any associated dispute, whichever is later.
- Marketing preferences and consent records: Retained for the duration of the Account relationship and for one (1) year following Account closure.
- Cookie and technical data: Retained as described in Section 10, typically for session duration or up to 12 months for analytics cookies.
Upon expiry of applicable retention periods, personal data is securely deleted or anonymized in accordance with dbx77's data disposal procedures.
9 Data Security
dbx77 implements a comprehensive set of technical and organizational security measures designed to protect your personal data against unauthorized access, disclosure, alteration, loss, or destruction. Our security framework includes:
- 256-bit SSL/TLS encryption: All data transmitted between your device and the dbx77 Platform is encrypted using industry-standard 256-bit SSL/TLS — the same encryption used by Philippine banks including BPI, BDO, and Metrobank.
- Encryption at rest: Sensitive personal data stored in dbx77's databases, including government ID information and financial account details, is encrypted at rest using AES-256 encryption.
- Access controls: Access to personal data is restricted to dbx77 personnel and authorized third-party processors on a strict need-to-know basis, using role-based access controls and multi-factor authentication.
- Intrusion detection and monitoring: Continuous security monitoring, intrusion detection systems, and real-time alerts for anomalous access patterns or potential data breaches.
- Regular security audits: Periodic penetration testing, vulnerability assessments, and security audits conducted by qualified cybersecurity professionals.
- Incident response: A documented data breach response plan, including notification procedures to the NPC within 72 hours of discovery of a breach involving sensitive personal information, as required by the Data Privacy Act and NPC Circular 16-03.
While dbx77 takes all reasonable precautions to secure your data, no internet transmission or electronic storage system is 100% secure. Players are encouraged to safeguard their own Account credentials, enable Two-Factor Authentication (2FA), and report any suspected unauthorized Account access immediately.
10 Cookies & Tracking Technologies
dbx77 uses cookies and similar tracking technologies on the dbx77.app Platform to improve functionality, personalize your experience, and analyze platform usage. Cookies are small text files stored on your device when you visit the Platform.
10.1 Types of Cookies Used
- Strictly necessary cookies: Required for the Platform to function, including session management, login authentication, and security features. These cannot be disabled without impairing Platform functionality.
- Functional cookies: Remember your preferences such as language settings, display preferences, and responsible gaming limits. Stored for the duration of your session or up to 12 months.
- Analytics cookies: Collect anonymized data about how players use the Platform, which pages are visited, and how long sessions last — used to improve the Platform. Data is aggregated and does not identify individual players.
- Security cookies: Help detect and prevent fraudulent activity, account takeover attempts, and unusual access patterns.
10.2 Managing Cookies
You can configure your browser to refuse or delete non-essential cookies. However, disabling strictly necessary cookies may impair your ability to use the Platform, including logging in to your Account. dbx77 does not use cookies to serve third-party advertising.
11 Your Data Rights Under RA 10173
As a data subject under the Data Privacy Act of 2012, you have the following rights in respect of your personal data held by dbx77. To exercise any of these rights, contact our Data Protection Officer as described in Section 16.
dbx77 will respond to verified data rights requests within 30 calendar days of receipt. We may request proof of identity before actioning any data rights request. Note that certain rights are subject to overriding legal obligations — for example, we cannot delete data that we are required to retain under PAGCOR or AML regulations.
12 Children's Privacy — Strict 21+ Policy
🔞 STRICT AGE RESTRICTION: The dbx77 Platform is exclusively for individuals aged 21 years or older, as required by PAGCOR regulations. dbx77 does not knowingly collect personal data from anyone under 21. If we discover that personal data has been collected from an individual below the age of 21, that Account will be immediately suspended, all data will be deleted (subject to any mandatory retention for regulatory reporting of the violation), and the matter will be reported to PAGCOR as required.
If you believe a person under 21 years of age has created or is using a dbx77 Account, please notify our Data Protection Officer immediately at [email protected]. dbx77 takes underage gambling and associated data privacy violations extremely seriously.
13 Cross-Border Data Transfers
dbx77 primarily processes and stores personal data within the Philippines. However, certain third-party technology partners and service providers (including game software providers and cloud infrastructure providers) may be located outside the Philippines, which may result in your personal data being transferred to and processed in jurisdictions outside the Philippines.
Where such transfers occur, dbx77 ensures that appropriate safeguards are in place to protect your personal data, including:
- Contractual clauses requiring overseas processors to apply data protection standards equivalent to those under RA 10173;
- Transfer only to jurisdictions recognized as providing adequate data protection standards; and
- Data processing agreements incorporating NPC-approved standard contractual clauses where applicable.
By using the dbx77 Platform, you acknowledge that your personal data may be transferred outside the Philippines as described in this section, subject to the safeguards outlined above.
14 Third-Party Services & Linked Content
The dbx77 Platform may include references to third-party payment providers and game software brands. When you interact with third-party payment services (such as GCash or PayMaya), you are subject to those providers' own privacy policies in addition to this Policy. dbx77 is not responsible for the privacy practices of third-party services.
dbx77 does not include third-party advertising networks, social media tracking pixels, or affiliate tracking technologies that would share your personal data with unaffiliated marketing parties without your consent.
15 Updates to This Privacy Policy
dbx77 reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable Philippine law, PAGCOR requirements, or NPC guidance. The revised Policy will be published on the dbx77.app Platform with an updated effective date.
Where changes are material — meaning they significantly affect how we process your personal data or your privacy rights — dbx77 will provide advance notice to registered players via email to your registered address or via a prominent notice on the Platform, at least 14 days before the revised Policy takes effect.
Your continued use of the Platform following the effective date of any revised Privacy Policy constitutes your acknowledgment of the changes. We recommend reviewing this Policy periodically. The current version is always accessible at dbx77.app/privacy-policy.
16 Contact & Data Protection Officer
For any privacy-related queries, to exercise your data rights under RA 10173, or to report a potential data privacy concern, please contact dbx77's designated Data Protection Officer:
Data Protection Officer — dbx77
Email: [email protected]
General Support: [email protected]
Live Chat: Available 24/7 on dbx77.app
Response time: Within 10 business days for DPO inquiries; within 30 calendar days for formal data rights requests.
If you are not satisfied with dbx77's response to your privacy concern, or if you believe your data rights under RA 10173 have been violated, you have the right to lodge a formal complaint with the National Privacy Commission of the Philippines (NPC), the regulatory body responsible for enforcing the Data Privacy Act of 2012.
This Privacy Policy was last updated: January 1, 2026. It supersedes all previous versions. © 2026 dbx77. All rights reserved.