This Privacy Policy explains how ha77 collects, uses, stores, shares, and protects your personal information. It applies to all players and visitors who interact with the ha77 platform and its related services. ha77 is committed to full compliance with the Philippine Data Privacy Act of 2012 and all applicable PAGCOR data protection requirements.
This Privacy Policy ("Policy") is issued by ha77 ("ha77," "we," "us," or "the Company") and governs all personal data processing activities conducted in connection with the ha77 Platform accessible at ha77.club and all associated pages, services, and communications.
This Policy applies to: (a) registered Account holders who use the ha77 Platform to play casino games, sports betting, bingo, fishing games, Slide, and other entertainment products; (b) prospective users who visit the Platform without registering; (c) individuals who contact ha77 support, subscribe to communications, or interact with ha77 through any channel.
ha77 operates under a license issued by the Philippine Amusement and Gaming Corporation (PAGCOR) and is legally established and operating within the Philippines. This Policy is governed by and construed in accordance with the Philippine Data Privacy Act of 2012 (Republic Act 10173) and its Implementing Rules and Regulations (IRR), as enforced by the National Privacy Commission (NPC).
This Policy should be read in conjunction with ha77's Terms and Conditions and Responsible Gaming Policy, both of which are accessible from the Platform footer. Where any conflict exists between this Policy and a specific contractual arrangement with ha77, the specific arrangement prevails to the extent of the conflict.
For the purposes of the Data Privacy Act of 2012 and its IRR, ha77 is the personal information controller in respect of all personal data processed through the Platform. ha77 determines the purposes and means of processing your personal data and is responsible for ensuring that all such processing is lawful, transparent, and proportionate.
ha77 has designated a Data Protection Officer (DPO) in accordance with the NPC's requirements for personal information controllers processing data at significant scale. The DPO is responsible for overseeing ha77's compliance with the Data Privacy Act, responding to data subject rights requests, and serving as the primary point of contact for the NPC on data protection matters.
ha77 collects only the personal data that is necessary, relevant, and proportionate to the purposes described in this Policy. The categories of personal data we process are as follows:
| Category | Specific Data Elements | When Collected |
|---|---|---|
| Identity Data | Full legal name, date of birth, government ID type and number, nationality, gender | Account registration and KYC verification |
| Contact Data | Philippine mobile number, email address | Account registration |
| Address Data | Residential address, city, province, postal code | KYC verification; enhanced due diligence |
| Financial Data | Payment method details (GCash number, Maya number, bank account details); transaction history; deposit and withdrawal amounts | Cashier transactions; AML compliance |
| Identity Verification Data | Scanned or photographed government ID image; selfie photograph; proof of address document images | KYC process |
| Account & Gaming Data | Username, account preferences, game history, betting history, session duration records, bonus usage, VIP tier and points history | Ongoing Platform use |
| Technical Data | IP address, device type, operating system, browser type and version, device identifiers | Automatic collection during Platform access |
| Usage Data | Pages visited, features accessed, click patterns, session timestamps, referral URLs | Automatic collection via analytics tools |
| Communications Data | Records of support chat conversations, emails, and other correspondence with ha77 | Customer support interactions |
| Marketing Preferences | Opt-in/opt-out status for promotional SMS, email, and push notifications | Account settings; subscription actions |
The majority of personal data ha77 holds is provided directly by you during Account registration, the KYC verification process, Cashier transactions, customer support interactions, and promotional opt-ins. You are in control of what you provide, but certain data (particularly KYC documents) is required by PAGCOR regulation and cannot be waived.
When you access ha77, our servers and analytics infrastructure automatically log technical and usage data. This includes your IP address, device type, browser, the pages you visit within the Platform, and the timestamps of your sessions. This data is collected through standard web server logs, cookies, and third-party analytics tools. See Section 9 for full details on cookies.
ha77 may receive personal data from third parties in limited circumstances: (a) from GCash, Maya, or bank partners to confirm payment transaction details; (b) from identity verification service providers engaged to assist with KYC document validation; (c) from PAGCOR's player exclusion and compliance systems, where ha77 is required to check registering players against exclusion registries; and (d) from fraud prevention and AML screening databases, where ha77 is legally required to perform such checks under the Anti-Money Laundering Act.
Under the Data Privacy Act of 2012, ha77 processes personal data only where a lawful basis exists. The applicable lawful bases and corresponding processing purposes are as follows:
Processing your Identity Data, Contact Data, Account Data, and Financial Data is necessary for ha77 to operate your Account, process your transactions, credit your winnings, and deliver the gaming services you have contracted for. Without this processing, ha77 cannot provide its services to you.
ha77 is required by PAGCOR regulations, the Anti-Money Laundering Act (Republic Act 9160 as amended), the Terrorism Financing Prevention and Suppression Act, and other Philippine law to: verify player identity and age (KYC); monitor transactions for suspicious activity (AML); retain financial records for specified periods; report certain transactions and players to regulators; and cooperate with law enforcement requests supported by lawful authority.
ha77 processes Technical Data and Usage Data on the basis of its legitimate interests in: operating and improving a secure, functional gaming platform; detecting and preventing fraud, cheating, and account takeover; analysing aggregate usage patterns to improve the player experience; and managing its VIP and loyalty programme. ha77 has assessed these interests against your privacy rights and determined they are not overridden by those rights — you may object to processing on this basis at any time (see Section 11).
Where ha77 sends direct marketing communications — promotional SMS, marketing emails, or push notifications about offers, tournaments, or new game launches — such communications are sent only where you have given freely-given, specific, informed, and revocable consent at Account settings or during registration. You may withdraw consent at any time without penalty by updating your notification preferences in Account Settings or contacting support.
ha77 retains personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The general retention schedule is as follows:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account registration & identity data | Duration of Account + 5 years post-closure | PAGCOR and AMLA requirements |
| KYC documents (ID images, selfies) | Duration of Account + 5 years post-closure | AMLA record-keeping obligations |
| Financial transaction records | Duration of Account + 5 years post-closure | AMLA; Bureau of Internal Revenue requirements |
| Game and betting history | Duration of Account + 2 years post-closure | Dispute resolution; PAGCOR audit requirements |
| Customer support communications | 3 years from last interaction | Legitimate interests; dispute resolution |
| Technical and usage logs | 12 months rolling | Security monitoring; fraud prevention |
| Marketing preference records | Until consent withdrawn + 1 year | Consent record-keeping |
Upon expiry of the applicable retention period, ha77 securely deletes or anonymises personal data in a manner that renders re-identification impossible. Where data must be retained beyond normal periods due to active legal proceedings, regulatory investigations, or court orders, ha77 retains only the data strictly necessary and for only as long as the relevant proceeding requires.
ha77 does not sell, rent, or trade your personal data to any third party for their independent marketing or commercial use. We share personal data only in the following circumstances:
ha77 engages third-party service providers who process personal data on ha77's behalf and under ha77's instructions. These include: payment processing partners (GCash, Maya, BPI, BDO); KYC and identity verification platforms; cloud hosting and data storage providers; customer support software platforms; fraud detection and AML screening services; and game content delivery infrastructure providers. All such processors are bound by written data processing agreements that require them to process personal data only on ha77's documented instructions and to maintain appropriate security measures.
ha77 discloses personal data to PAGCOR, the Anti-Money Laundering Council (AMLC), the National Bureau of Investigation, the Philippine National Police, or any other competent government authority where required by applicable law, regulation, court order, or lawful regulatory demand. ha77 will, where legally permissible, notify affected players of such disclosures.
In the event of a merger, acquisition, asset sale, or corporate restructuring involving ha77, personal data held by ha77 may be transferred to the acquiring or successor entity as part of that transaction. Players will be notified in advance of any such transfer and of any changes to the applicable privacy policy that result from the transaction.
ha77 may disclose personal data where necessary to protect the safety, rights, or property of ha77, its players, or third parties — for example, where fraud, identity theft, or a threat to personal safety is identified and disclosure to appropriate authorities is warranted.
Some of ha77's service providers — including cloud infrastructure partners and game content delivery networks — may be located outside the Philippines. Where personal data is transferred outside the Philippines, ha77 ensures such transfers comply with the requirements of the Data Privacy Act of 2012, specifically Section 21 and the NPC's rules on cross-border data flows.
ha77's safeguards for international transfers include: (a) ensuring the recipient country provides an adequate level of data protection as recognised by the NPC; (b) implementing standard contractual clauses approved by the NPC; or (c) obtaining your explicit consent where required. ha77 does not transfer personal data to jurisdictions with inadequate data protection frameworks without appropriate safeguards in place.
ha77 uses cookies and similar tracking technologies to operate the Platform, remember your preferences, maintain your login session, prevent fraud, and analyse usage patterns. The types of cookies used are:
You may manage cookie preferences through your browser settings. Blocking strictly necessary cookies will impair or prevent Platform functionality. Blocking analytics cookies will not affect your ability to use ha77 but will limit ha77's ability to improve the Platform based on usage data.
ha77 does not use advertising cookies or permit third-party advertising networks to place tracking cookies on the Platform for purposes unrelated to ha77's own security and analytics.
ha77 implements technical and organisational security measures designed to protect personal data against unauthorised access, disclosure, alteration, loss, or destruction. These measures include, but are not limited to:
Under the Data Privacy Act of 2012 and its IRR, you have the following rights in respect of your personal data held by ha77. To exercise any of these rights, contact ha77's Data Protection Officer at [email protected] with the subject line "Data Subject Rights Request."
You may request a copy of all personal data ha77 holds about you, together with information about the purposes of processing, the categories of data concerned, and the recipients to whom data has been disclosed.
You may request that ha77 correct inaccurate or incomplete personal data held about you. Certain data (such as your registered name) requires identity re-verification before correction can be processed.
You may request deletion of your personal data where processing is no longer necessary, where consent has been withdrawn, or where processing is unlawful — subject to ha77's overriding legal retention obligations under AMLA and PAGCOR regulations.
You may object to processing based on legitimate interests. If you object, ha77 will cease processing unless it can demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for legal claims.
You may request that ha77 restrict active processing of your data — for example, while the accuracy of data is contested, or while an objection is being assessed — even if the data is not deleted.
You may request that ha77 provide your personal data in a structured, commonly-used, machine-readable format — applicable to data you have provided to ha77 that is processed by automated means on the basis of contract or consent.
Where processing is based on consent (such as marketing communications), you may withdraw that consent at any time through Account Settings or by contacting support, without affecting the lawfulness of processing prior to withdrawal.
If you believe ha77 has violated your data privacy rights, you may lodge a complaint with the National Privacy Commission (NPC) — the Philippine government authority responsible for enforcing the Data Privacy Act.
ha77 will respond to all rights requests within fifteen (15) calendar days. Where a request is complex or numerous, this period may be extended by up to thirty (30) days, with notice provided to you of the extension and reason.
All registering players are required to complete identity and age verification through KYC, which includes submission of a government-issued ID confirming date of birth. Any Account found to belong to an individual under 21 years of age will be immediately suspended, all data will be retained only as legally required for regulatory reporting purposes, and the matter will be reported to PAGCOR.
If you believe a person under the age of 21 has registered an Account on ha77, please contact our Data Protection Officer immediately at [email protected].
ha77 sends promotional communications — including information about bonuses, new game launches, tournaments, and platform updates — only to players who have given their consent to receive such communications at registration or through Account Settings.
Marketing communications are sent via: (a) email to your registered email address; (b) SMS to your registered Philippine mobile number; and (c) in-Platform notifications within your ha77 Account dashboard. Each communication includes a clear unsubscribe mechanism.
You can manage your marketing preferences at any time through Account Settings → Notification Preferences, or by contacting ha77 support. Opting out of marketing communications does not affect your ability to receive transactional communications — such as deposit confirmations, withdrawal receipts, security alerts, and account verification messages — which are sent as a necessary part of the Account service regardless of marketing preferences.
ha77 does not pass your contact details to any third party for their independent marketing purposes. We do not engage in cold calling. ha77 employees and support agents will never call you unsolicited to promote offers or request payment.
The ha77 Platform may contain references to third-party service providers — such as GCash and Maya payment platforms — in the context of payment instructions. ha77 does not maintain external links to third-party websites from the Platform beyond what is necessary for payment and regulatory compliance navigation.
Where you access third-party platforms (such as your GCash app or bank's online portal) to initiate a deposit or withdrawal transaction, the privacy practices of those platforms are governed by their own privacy policies. ha77 is not responsible for the privacy practices of third-party platforms and recommends that you review their policies before use. The ha77 Privacy Policy applies solely to data processed by ha77 through the ha77 Platform.
ha77 reviews and updates this Privacy Policy periodically to reflect changes in our data processing practices, applicable law, NPC guidance, or PAGCOR requirements. Material changes — those that significantly affect your rights or how we process your data — will be communicated to registered Account holders via email to the registered address or via an in-Platform notification at least seven (7) calendar days before taking effect.
Non-material updates (such as corrections to typographical errors or minor clarifications that do not change the substance of the Policy) may be made without prior notice, but will be reflected in an updated "Last Updated" date at the top of this page.
The current version of this Policy is the version published at ha77.club/privacy-policy. Continued use of the Platform after the effective date of any update constitutes acceptance of the revised Policy. If you do not accept an update, you may close your Account pursuant to the Account closure process described in the Terms and Conditions before the effective date.
For any questions, concerns, or formal requests relating to this Privacy Policy or ha77's data processing activities, please contact:
ha77 is committed to resolving all privacy-related concerns promptly, fairly, and in full compliance with the Data Privacy Act of 2012 and NPC regulations. Our Data Protection Officer engages with all formal requests personally — your concerns are not handled by automated systems or deflected to scripted responses.
A plain-English summary of the data protection commitments in this Privacy Policy — for players who want the key points at a glance.
ha77 is governed by the Philippine Data Privacy Act of 2012 — not an offshore privacy framework with weak enforcement. Your rights as a Filipino data subject are protected by the NPC, a real government body with enforcement powers and a complaints process.
Every connection to ha77 — login, deposit, withdrawal, KYC upload — is protected by 256-bit TLS encryption. Your data in transit cannot be intercepted. Sensitive data at rest is encrypted with AES-256. The padlock in your browser confirms the connection is secure.
ha77 does not sell, rent, or trade your personal data to third parties for their independent marketing or commercial purposes — full stop. Your data is shared only with service providers who process it under ha77's instructions, and regulators where required by law.
You have real, enforceable rights to access, correct, restrict, and request deletion of your personal data under the Data Privacy Act. ha77 responds to all formal rights requests within 15 calendar days. These rights are not just policy language — they are legally enforceable in the Philippines.
ha77 collects only the data necessary to operate your Account, comply with PAGCOR and AMLA obligations, and keep the platform secure. We do not build advertising profiles. We do not share your gaming history with marketers. Data collected for KYC stays in KYC systems.
ha77 does not keep your data indefinitely. Each data category has a defined retention schedule — typically 5 years post-account closure for identity and financial data (AMLA requirement), 12 months for technical logs, and 3 years for support records. Data is securely deleted when retention periods expire.