Privacy Policy
At a9piso, your personal data is handled with the same care and seriousness we apply to game security and financial integrity. This Privacy Policy explains exactly what we collect, why we collect it, how we protect it, and what rights you hold as a Filipino data subject under the Data Privacy Act of 2012.
Our Privacy Commitments at a Glance
Data Minimization
a9piso collects only the personal data that is strictly necessary for account operation, identity verification, payment processing, and legal compliance. We do not collect data speculatively or for purposes unrelated to the Platform.
256-bit Encryption
All personal data stored and transmitted by a9piso is protected with 256-bit AES encryption at rest and 256-bit TLS in transit — the same standard used by Philippine banking institutions. Your data is never stored in plain text.
Your Rights Under DPA 2012
As a Filipino data subject, you have statutory rights under Republic Act No. 10173 (Data Privacy Act of 2012), including the right to access, correct, erase, and object to the processing of your personal data. a9piso honors all these rights.
No Unauthorized Sharing
a9piso does not sell, rent, or trade your personal data to third parties for marketing purposes. Data is shared only with service providers directly necessary to operate the Platform and with authorities as required by Philippine law.
NPC-Aligned Compliance
Our data handling practices are aligned with the guidelines of the National Privacy Commission (NPC) of the Philippines, including breach notification requirements, Privacy Impact Assessments, and Data Protection Officer appointment.
Defined Retention Periods
Personal data collected by a9piso is retained only for as long as required to fulfill the purpose for which it was collected or as mandated by Philippine law. Data is securely deleted or anonymized once the retention period expires.
SCOPE OF THIS POLICY. This Privacy Policy applies to all personal data collected and processed by a9piso in connection with the Platform at a9piso.cam, including account registration, KYC verification, payment processing, gameplay, customer support interactions, and marketing communications. By using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, you must discontinue use of the Platform immediately.
01 Data Controller Identity
For the purposes of the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, a9piso is the Personal Information Controller (PIC) in respect of all personal data collected and processed through the Platform at a9piso.cam.
All data processing activities conducted by a9piso are carried out in accordance with the Data Privacy Act of 2012, the guidelines and issuances of the National Privacy Commission (NPC) of the Philippines, PAGCOR's data governance requirements, and the Anti-Money Laundering Act (AMLA) as amended.
Website: a9piso.cam
Contact: [email protected]
Jurisdiction: Republic of the Philippines
02 Data Protection Officer
In compliance with Section 21 of the Data Privacy Act of 2012 and NPC Circular No. 16-01, a9piso has designated a Data Protection Officer (DPO) responsible for ensuring the organization's compliance with applicable data privacy laws and regulations.
The DPO is responsible for: (a) monitoring compliance with the Data Privacy Act and NPC issuances; (b) conducting Privacy Impact Assessments for new data processing activities; (c) serving as the primary point of contact for data subjects exercising their rights; and (d) coordinating with the NPC in the event of a personal data breach.
Players may contact the a9piso Data Protection Officer by writing to [email protected] with the subject line "Data Protection Officer — Privacy Request." All inquiries addressed to the DPO will be acknowledged within three (3) business days and substantively responded to within thirty (30) calendar days.
03 Personal Data We Collect
a9piso collects personal data across several categories depending on the nature of your interaction with the Platform. The following table summarizes the categories of personal data collected and the context in which they are gathered:
| Data Category | Specific Data Points | Collection Context |
|---|---|---|
| Identity Data | Full legal name, date of birth, nationality, government ID type and number, ID document images | Registration & KYC verification |
| Contact Data | Philippine mobile number (+63), email address, residential address (province/city/barangay) | Account registration, account updates |
| Financial Data | GCash number, PayMaya account, bank account name/number (BPI, BDO, UnionBank, Metrobank), transaction history | Deposit and withdrawal processing |
| Gaming Activity | Game session logs, wager amounts, win/loss records, bonus usage, RNG interaction logs | Gameplay on Platform |
| Technical Data | IP address, device type and OS, browser type and version, session tokens, login timestamps | Automatic collection via Platform access |
| Communications Data | Live chat transcripts, email correspondence, support ticket content, SMS OTP logs | Customer support interactions |
| Preference Data | Favorite games, preferred payment methods, language preference, marketing opt-in/out status | Account personalization settings |
a9piso does not collect sensitive personal information as defined under Section 3(l) of the Data Privacy Act (such as racial origin, religious beliefs, health data, or political affiliations) except where an individual's health status is voluntarily disclosed in a responsible gaming context, in which case it is handled with heightened confidentiality.
04 How We Collect Personal Data
a9piso collects personal data through the following channels and mechanisms:
- Direct submission: Information you provide when registering an account, completing KYC verification, making a deposit or withdrawal, contacting customer support, or updating your account profile.
- Automated technical collection: IP addresses, device identifiers, browser fingerprints, session data, and behavioral analytics are collected automatically when you access the Platform through standard web technologies including cookies, pixel tags, and server logs.
- Payment processors: Transaction confirmation data, payment reference numbers, and payer identity confirmations are received from GCash, PayMaya, BPI, BDO, UnionBank, Metrobank, and other integrated payment partners in connection with your financial transactions.
- Identity verification providers: Confirmation of identity document authenticity may be processed via third-party KYC verification service providers operating under data processing agreements with a9piso.
- Regulatory bodies: Where required by law, a9piso may receive or be required to share data with PAGCOR, the Anti-Money Laundering Council (AMLC), or other competent Philippine regulatory authorities.
05 Purpose of Processing & Legal Basis
Under the Data Privacy Act of 2012, all personal data processing must rest on a legitimate criterion. The following table sets out the purposes for which a9piso processes your personal data and the corresponding legal basis for each purpose:
| Processing Purpose | Legal Basis (DPA 2012) |
|---|---|
| Account registration and maintenance | Performance of a contract (Sec. 12[b]) |
| KYC identity verification and age confirmation (21+) | Legal obligation (Sec. 12[c]) — PAGCOR / AMLA requirements |
| Processing deposits and withdrawals via GCash, PayMaya, bank transfers | Performance of a contract (Sec. 12[b]) |
| Anti-money laundering monitoring and suspicious transaction reporting to AMLC | Legal obligation (Sec. 12[c]) — AMLA and PAGCOR directives |
| Responsible gaming monitoring: deposit limits, self-exclusion, problem gambling detection | Legal obligation (Sec. 12[c]) + Legitimate interests (Sec. 12[f]) |
| Fraud prevention, security monitoring, account integrity | Legitimate interests (Sec. 12[f]) |
| Customer support communication | Performance of a contract (Sec. 12[b]) |
| Promotional and marketing communications (where opted in) | Consent (Sec. 12[a]) |
| Platform analytics and user experience improvement | Legitimate interests (Sec. 12[f]) |
| Legal proceedings and regulatory compliance | Legal obligation (Sec. 12[c]) + Vital interests (Sec. 12[e]) |
06 Data Sharing & Disclosure
a9piso does not sell, rent, or trade your personal data to third parties. Personal data is disclosed only in the following circumstances:
6.1 Service Providers (Personal Information Processors)
a9piso engages third-party service providers who process personal data on our behalf under written Data Processing Agreements (DPAs) that bind them to confidentiality and data protection obligations equivalent to those applicable to a9piso. These include: payment gateway operators (GCash, PayMaya, BPI), KYC identity verification providers, cloud infrastructure providers hosting Platform servers, game software providers, and customer support platform vendors.
6.2 Regulatory and Legal Disclosure
a9piso is required by Philippine law to disclose player data to: PAGCOR upon regulatory request; the Anti-Money Laundering Council (AMLC) in connection with covered and suspicious transaction reports under the AMLA; courts and law enforcement agencies pursuant to valid legal process; and the National Privacy Commission in the context of breach notifications or regulatory investigations.
6.3 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of substantially all of a9piso's assets, your personal data may be transferred to the acquiring entity, provided that the acquiring entity is bound by data protection obligations no less stringent than those set out in this Privacy Policy. a9piso will provide notice of any such transfer through the Platform.
a9piso will never disclose your personal data to third-party marketers, data brokers, or any entity for advertising purposes without your explicit written consent. If you receive unsolicited communications purportedly from a9piso, please contact support immediately to report the incident.
07 International Data Transfers
Certain third-party service providers engaged by a9piso — particularly cloud infrastructure providers and game software studios — may process or store data on servers located outside the Philippines. Where such transfers occur, a9piso ensures that:
- The receiving country or organization provides an adequate level of data protection comparable to the standards of the Data Privacy Act of 2012;
- Appropriate contractual safeguards, including standard data protection clauses, are in place between a9piso and the recipient;
- The transfer is limited to the minimum data necessary for the specific processing purpose; and
- Players are informed of any material changes to the cross-border transfer arrangements that affect the security of their personal data.
All financial transaction data related to Philippine payment methods (GCash, PayMaya, BPI, BDO, etc.) is processed and stored within Philippine-based payment infrastructure in compliance with Bangko Sentral ng Pilipinas (BSP) data localization requirements applicable to payment system operators.
08 Data Retention
a9piso retains personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable Philippine law. The following retention periods apply:
Financial Transaction Records → 5 years (AMLA / BIR requirements)
Gaming Activity Logs → 2 years from session date
Customer Support Records → 3 years from last interaction
Marketing Consent Records → Until consent is withdrawn + 1 year
Technical / Server Logs → 90 days rolling retention
Cookie Data (analytics) → 13 months maximum
Upon expiry of the applicable retention period, personal data is securely deleted using industry-standard data destruction methods, or anonymized such that re-identification is not reasonably possible. Certain data may be retained beyond stated periods where required by a valid legal hold, ongoing legal proceedings, or specific regulatory directive from PAGCOR or the NPC.
09 Security Measures
a9piso implements a layered technical and organizational security framework to protect personal data against unauthorized access, disclosure, alteration, or destruction. Key security measures include:
- Encryption: 256-bit AES encryption for data at rest; TLS 1.3 for all data in transit between your device and a9piso servers.
- Access controls: Role-based access control (RBAC) with principle of least privilege; multi-factor authentication required for all staff accessing production data systems.
- Network security: Web Application Firewall (WAF), DDoS mitigation, intrusion detection and prevention systems (IDS/IPS), and regular penetration testing by independent security firms.
- Physical security: Data hosted in Tier III/IV certified data centers with 24/7 physical access controls, CCTV monitoring, and biometric entry systems.
- Employee controls: All a9piso employees with access to personal data are subject to background checks, confidentiality agreements, and regular data privacy training aligned with NPC guidelines.
- Vulnerability management: Regular security audits, patch management, and vulnerability assessments are conducted to identify and remediate risks to personal data.
Notwithstanding these measures, no system of data transmission or storage can be guaranteed to be 100% secure. Players are encouraged to use strong, unique passwords, enable two-factor authentication on their a9piso accounts, and immediately notify support of any suspected unauthorized account access.
10 Cookies & Tracking Technologies
a9piso uses cookies and similar tracking technologies (pixel tags, local storage objects) to operate and improve the Platform. The following categories of cookies are used:
You may manage your cookie preferences through your browser settings. Note that disabling cookies categorized as "Strictly Necessary" will impair your ability to log in to and use the Platform. Optional cookie categories can be declined without affecting core Platform access.
11 Your Data Subject Rights
Under the Data Privacy Act of 2012, you have the following rights with respect to personal data that a9piso holds about you. To exercise any of these rights, contact the a9piso Data Protection Officer at [email protected] with subject line "Data Subject Rights Request."
Right to be Informed
The right to be informed of the existence of processing, the identity of the PIC, the purposes of processing, and the scope of data being processed — fulfilled by this Privacy Policy.
Right to Access
The right to request a copy of your personal data held by a9piso, information on how it is used, and with whom it has been shared. a9piso responds to access requests within 30 calendar days.
Right to Correction
The right to dispute inaccuracy or error in your personal data and have it corrected or completed. Corrections to account information can also be initiated through your account settings or via support.
Right to Erasure
The right to suspend, withdraw, or request blocking, removal, or destruction of your personal data where the processing was unlawful, the purpose has expired, or consent has been withdrawn. Subject to legal retention obligations.
Right to Object
The right to object to processing based on legitimate interests, particularly direct marketing processing. a9piso will cease processing for direct marketing upon receipt of a valid objection.
Right to Portability
The right to obtain a structured, commonly used, machine-readable copy of personal data you provided to a9piso for portability to another service, where technically feasible.
Right to Damages
The right to be indemnified for damages sustained due to inaccurate, incomplete, outdated, false, unlawfully obtained, or unauthorized use of personal data by a9piso, in accordance with applicable law.
Right to Complain to NPC
If you believe a9piso has not handled your personal data in accordance with the Data Privacy Act, you have the right to file a complaint with the National Privacy Commission of the Philippines.
Requests to exercise data subject rights must be submitted in writing with sufficient information to identify your account. a9piso may request additional proof of identity before processing a rights request to protect against fraudulent access to another person's data. a9piso will not charge a fee for processing reasonable rights requests.
12 Minors & Age Policy
The a9piso Platform is strictly intended for individuals who are 21 years of age or older, as required by PAGCOR regulations and Philippine law. a9piso does not knowingly collect personal data from individuals under the age of 21.
Age verification is conducted as part of the mandatory KYC process required before withdrawal privileges are activated. Where a9piso discovers that an account has been registered by or used by a person under the age of 21, all associated personal data will be deleted and the account will be permanently closed, with any balance held subject to investigation and forfeiture as required by applicable law.
If you have reason to believe that a minor has registered an account on the Platform, please notify the a9piso Data Protection Officer immediately at [email protected].
13 Marketing Communications
With your consent, a9piso may send you promotional communications via SMS to your registered Philippine mobile number, email to your registered address, and push notifications via the Platform. These communications may include: welcome bonus offers, reload promotions, tournament announcements, VIP reward updates, and seasonal campaign notifications relevant to the Philippine gaming calendar.
You may withdraw consent for marketing communications at any time by: (a) using the unsubscribe link in any marketing email; (b) replying STOP to any marketing SMS; (c) updating your communication preferences in your a9piso account settings; or (d) contacting the support team. Marketing opt-out requests are processed within five (5) business days. Withdrawal of marketing consent does not affect the lawfulness of processing based on consent before its withdrawal, nor does it prevent a9piso from sending transactional communications required for account operation (such as security alerts, withdrawal confirmations, and account notices).
14 Personal Data Breach Protocol
In the event of a personal data breach that poses a real risk of serious harm to affected data subjects, a9piso will: (a) notify the National Privacy Commission within seventy-two (72) hours of becoming aware of the breach, in accordance with NPC Circular No. 16-03; and (b) notify affected data subjects within seventy-two (72) hours of determining that notification is required under applicable NPC guidelines.
Breach notifications to data subjects will be delivered via registered email address and, where the breach poses an imminent risk of harm, via SMS to the registered Philippine mobile number. The notification will describe: the nature of the breach; the categories and approximate number of data subjects affected; the likely consequences of the breach; the measures taken or proposed to address the breach; and the contact details of the a9piso Data Protection Officer.
a9piso maintains an incident response plan and a breach register as required by NPC Circular No. 16-03. Internal breach assessments are conducted by the Data Protection Officer in coordination with the a9piso information security team within 24 hours of a potential breach being identified.
15 Changes to This Privacy Policy
a9piso reserves the right to update this Privacy Policy from time to time to reflect changes in data processing practices, applicable law, or regulatory guidance. Material changes — defined as changes that significantly affect the scope of data collection, new purposes of processing, new categories of data sharing, or material reductions in your rights — will be communicated to registered players via email to their registered address and via a prominent notice on the Platform at least fourteen (14) days before the changes take effect.
Non-material changes (such as corrections of typographical errors, clarifications of existing practices, or updates to contact information) may be made without advance notice and will be effective from the date of publication on the Platform. The "Effective Date" displayed at the top of this page will be updated to reflect the most recent revision date. Your continued use of the Platform following the effective date of any change constitutes your acknowledgment of the revised Privacy Policy.
16 Contact & NPC Complaints
For all privacy-related inquiries, data subject rights requests, or concerns about a9piso's handling of your personal data, please contact:
Email: [email protected]
Subject Line: "DPO Privacy Request" or "Data Subject Rights Request"
Response Time: Acknowledgment within 3 business days; substantive response within 30 calendar days
If you are not satisfied with a9piso's response to a privacy concern or data subject rights request, you have the right to file a complaint directly with the National Privacy Commission (NPC) of the Philippines through official NPC channels. a9piso cooperates fully with all NPC inquiries and investigations.
This Privacy Policy was drafted in compliance with Republic Act No. 10173 (Data Privacy Act of 2012), its Implementing Rules and Regulations, and relevant issuances of the National Privacy Commission of the Philippines. This document is reviewed annually by the a9piso Data Protection Officer and updated as required to reflect changes in law, regulation, and data processing practice.
Your Privacy Is Protected — Play with Confidence at a9piso
Your personal data is secure, your rights are protected under Philippine law, and your transactions are encrypted end-to-end. Explore 1,000+ games with instant GCash payouts. 21+ only. Play responsibly.
Explore All Games Member Login21+ Only · PAGCOR-Compliant · DPA 2012 Compliant · NPC-Registered