365org
Privacy Policy
Your personal data matters to us. This Privacy Policy explains exactly what information 365org collects, why we collect it, how we use and protect it, and the rights you hold as a data subject under Philippine law.
Notice to Data Subjects: This Privacy Policy is issued by 365org ("the Platform," "We," "Us," or "Our") in accordance with Republic Act No. 10173, known as the Data Privacy Act of 2012 (DPA), and its Implementing Rules and Regulations. By registering an account or using the 365org platform at https://365org.cam, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your personal data as described herein.
1. Introduction
365org is committed to protecting the privacy and personal data of every player who uses our platform. As an operator regulated by the Philippine Amusement and Gaming Corporation (PAGCOR), 365org is required by both gaming regulations and Philippine data protection law to collect, process, and store certain categories of personal information. This Privacy Policy describes in full detail how we fulfill those obligations while respecting your rights as an individual.
This Privacy Policy applies to all personal data collected through the 365org website (https://365org.cam), mobile-optimized web platform, customer support channels, live chat, email correspondence, and any other interaction you have with 365org as a registered player or visitor. It applies whether you access our platform from Metro Manila, Cebu, Davao, Quezon City, or anywhere else in the Philippines.
This Policy should be read alongside the 365org Terms & Conditions and Responsible Gaming policy, both of which govern your overall relationship with the platform. In the event of any conflict, the specific provisions of this Privacy Policy shall govern matters relating to personal data processing.
2. Personal Data We Collect
365org collects several categories of personal data in the course of operating our platform. The categories, specific data points, and the primary purpose for each are set out in the table below:
| Category | Data Points | Primary Purpose |
|---|---|---|
| Identity Data | Full legal name, date of birth, gender, nationality, government-issued ID number | Account registration, KYC verification, age verification (21+), PAGCOR reporting |
| Contact Data | Mobile number (Globe/Smart/DITO), email address, residential address | Account communication, OTP delivery, customer support, withdrawal notifications |
| Financial Data | GCash account reference, PayMaya reference, bank account details (BPI, BDO, Metrobank), transaction history | Deposit and withdrawal processing, AMLA compliance, fraud prevention |
| Gaming Activity Data | Game history, bet amounts, session durations, win/loss records, bonus usage | Platform operation, responsible gaming monitoring, dispute resolution, PAGCOR reporting |
| Technical Data | IP address, device type, browser type, operating system, referral URL, session timestamps | Security, fraud detection, platform optimization, geo-compliance |
| KYC Documents | Government-issued photo ID (e.g., PhilSys ID, passport, driver's license), selfie verification, proof of address | Identity verification, AMLA compliance, PAGCOR regulatory requirements |
| Communication Data | Live chat transcripts, email correspondence, support ticket records | Customer support delivery, dispute resolution, quality assurance |
You are not required to provide all categories of data at the point of registration; however, certain data (particularly identity, contact, and financial data) is required for KYC verification and for the processing of withdrawals. Failure to provide required data may result in limitations on your account.
3. How We Collect Your Data
365org collects personal data through the following means:
- Direct submission: Information you provide when you complete the 365org registration form, submit KYC documents, make a deposit or withdrawal request, contact customer support, or respond to a survey or promotion;
- Automated collection: Technical data collected automatically when you access the platform, including IP address, browser type, device identifiers, and session data, through server logs and standard web technologies;
- Cookies and similar technologies: First-party cookies and session tokens used to maintain your login session, remember your preferences, and support the platform's security features (see Section 9 for full cookie details);
- Third-party verification services: Identity verification data obtained through KYC verification partners during the account verification process, in accordance with PAGCOR and AMLA requirements;
- Payment providers: Transaction reference data shared by GCash, PayMaya, BPI, BDO, Metrobank, and 7-Eleven in connection with deposits and withdrawals you initiate;
- Fraud prevention and security services: Risk signals and device fingerprinting data from security service providers used to detect and prevent unauthorized access and financial fraud.
4. Legal Basis for Processing
Under the Data Privacy Act of 2012 and its Implementing Rules and Regulations, 365org processes your personal data on one or more of the following legal bases:
- Contractual necessity: Processing required to perform the contract between you and 365org — including account management, game delivery, deposit and withdrawal processing, and customer support;
- Legal obligation: Processing required to comply with applicable Philippine laws and regulations, including the Anti-Money Laundering Act (AMLA), PAGCOR licensing conditions, and the Data Privacy Act itself;
- Legitimate interests: Processing necessary for the legitimate interests of 365org, including fraud prevention, platform security, responsible gaming monitoring, and improvement of our services — where those interests are not overridden by your rights;
- Consent: For processing activities not covered by the above grounds — including marketing communications and certain analytics — we rely on your freely given, specific, and informed consent, which you may withdraw at any time without affecting the lawfulness of processing carried out prior to withdrawal.
5. How We Use Your Personal Data
365org uses the personal data we hold about you for the following purposes:
- To create, verify, and manage your 365org player account;
- To process deposits and withdrawals via GCash, PayMaya, and Philippine banking partners;
- To verify your identity and age (minimum 21 years) in compliance with PAGCOR requirements and the AMLA;
- To deliver the games and services you access on the 365org platform;
- To administer bonuses, promotions, and loyalty programs in accordance with their published terms;
- To operate responsible gaming tools including deposit limits, session timers, and self-exclusion features, and to monitor gaming patterns that may indicate problem gambling;
- To detect, investigate, and prevent fraudulent transactions, money laundering, and unauthorized account access;
- To respond to your customer support inquiries and resolve disputes;
- To fulfill mandatory reporting obligations to PAGCOR, the Anti-Money Laundering Council (AMLC), and other Philippine government authorities as required by law;
- To send you transactional communications, including deposit confirmations, withdrawal notifications, and security alerts;
- To send promotional communications about 365org offers and new games — only where you have provided consent or opted in, and subject to your right to unsubscribe at any time;
- To improve, test, and develop the 365org platform and user experience through aggregated and anonymized analytics.
Marketing Opt-Out: If you no longer wish to receive promotional communications from 365org, you may update your communication preferences at any time from your account settings or contact our support team directly. Opting out of marketing will not affect your ability to receive essential transactional messages relating to your account.
6. Sharing Your Personal Data
365org does not sell, rent, or trade your personal data to any third party for their own marketing purposes. We share your data only in the following limited and controlled circumstances:
- PAGCOR and Philippine government authorities: 365org shares player data with PAGCOR as required under our operating license, and with the AMLC and other relevant agencies as required by the AMLA and other applicable laws;
- KYC and identity verification partners: Trusted third-party service providers engaged to perform identity document verification and age verification as part of our regulatory compliance obligations;
- Payment service providers: GCash, PayMaya, BPI, BDO, Metrobank, and 7-Eleven receive the minimum data necessary to process your deposits and withdrawals — typically a transaction reference and your account identifier;
- Game content providers: Game providers (such as Pragmatic Play, Evolution Gaming, PG Soft, and others) receive a pseudonymous player identifier and session token to deliver their games — they do not receive your full identity or financial data;
- IT and security service providers: Third-party providers of cloud hosting, cybersecurity, fraud detection, and platform infrastructure services, all of whom are contractually bound to process your data only on our instructions and in compliance with applicable data protection law;
- Professional advisers: Legal, accounting, and auditing professionals where necessary for the conduct of our business, under strict confidentiality obligations;
- Law enforcement: Where disclosure is required by a court order, subpoena, or other lawful demand from Philippine law enforcement or a competent regulatory authority.
No Unauthorized Disclosure: 365org will never share your full name, identification number, financial account details, or contact information with any unauthorized third party. Any third party that receives your data is bound by data processing agreements consistent with the requirements of the Data Privacy Act of 2012.
7. Data Retention
365org retains your personal data for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable Philippine law, whichever is longer. The following general retention periods apply:
- Account and identity data: Retained for the duration of your account and for a minimum of five (5) years following account closure, in accordance with PAGCOR licensing conditions and AMLA record-keeping requirements;
- Transaction and financial data: Retained for a minimum of five (5) years following each transaction, consistent with AMLA obligations;
- KYC documents: Retained for a minimum of five (5) years following submission, or longer if required by a specific PAGCOR or AMLC directive;
- Gaming activity data: Retained for a minimum of three (3) years for responsible gaming monitoring and dispute resolution purposes;
- Customer support records: Retained for three (3) years following the resolution of the relevant support interaction;
- Technical and device data: Retained for twelve (12) months for security and fraud detection purposes.
Upon the expiry of applicable retention periods, personal data is securely deleted or anonymized in a manner that prevents reconstruction of identifiable information.
8. Security Measures
365org implements appropriate technical and organizational security measures to protect your personal data against unauthorized access, accidental loss, destruction, disclosure, or alteration. These measures include, but are not limited to:
- 256-bit SSL/TLS encryption for all data transmitted between your device and the 365org platform;
- Encryption of sensitive data fields (including passwords and financial data) at rest using industry-standard algorithms;
- Role-based access controls limiting employee access to personal data strictly to those with a legitimate business need;
- Multi-factor authentication requirements for administrative access to systems holding player data;
- Regular penetration testing and vulnerability assessments conducted by independent cybersecurity specialists;
- Real-time fraud detection and anomaly monitoring systems to identify and respond to suspicious activity;
- Incident response procedures consistent with the Data Privacy Act's requirements for breach notification to the National Privacy Commission (NPC) and affected data subjects.
While 365org takes all reasonable steps to protect your data, no system is entirely immune to risk. You also play an important role in account security: we strongly recommend using a unique, strong password for your 365org account and enabling two-factor authentication (2FA) in your account settings.
9. Cookies & Tracking Technologies
365org uses cookies and similar tracking technologies on its platform. Cookies are small data files stored on your device that help us deliver a functional and secure user experience. The following categories of cookies are used:
- Strictly necessary cookies: These cookies are essential for the platform to function. They maintain your authenticated session after login, preserve your security tokens, and enable core features such as the game lobby and account dashboard. These cookies cannot be disabled without impairing platform functionality;
- Functional cookies: These cookies remember your preferences — such as language settings and responsible gaming limit configurations — to provide a more personalized experience between sessions;
- Analytics cookies: First-party analytics cookies collect aggregated, anonymized data about how players navigate the platform, which pages are most visited, and how features are used. This data is used solely to improve the 365org platform and is not shared with external analytics services;
- Security cookies: Short-lived cookies used by our fraud detection systems to identify unusual access patterns and protect against session hijacking and cross-site request forgery (CSRF) attacks.
You may control cookie settings through your browser's preferences. Note that disabling strictly necessary cookies will affect your ability to log in and use the platform. 365org does not use third-party advertising cookies or behavioral tracking cookies for cross-site advertising.
10. Your Rights as a Data Subject
Under the Data Privacy Act of 2012, you have the following rights with respect to your personal data held by 365org. You may exercise any of these rights by contacting our Data Protection Officer (see Section 13):
- Right to be informed: The right to be told when your personal data is being collected and how it will be used — which is fulfilled by this Privacy Policy;
- Right of access: The right to request a copy of the personal data 365org holds about you, along with information about how it is processed;
- Right to rectification: The right to request correction of inaccurate, incomplete, or outdated personal data in your account. Many fields can be updated directly from your account settings;
- Right to erasure: The right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to overriding legal retention obligations under PAGCOR licensing conditions and the AMLA;
- Right to object: The right to object to the processing of your personal data for direct marketing purposes. Upon receipt of a valid objection, 365org will cease sending promotional communications;
- Right to data portability: The right to receive personal data you have provided to 365org in a structured, commonly used, machine-readable format, where technically feasible;
- Right to lodge a complaint: The right to file a complaint with the National Privacy Commission (NPC) of the Philippines if you believe 365org has processed your personal data in violation of the Data Privacy Act. Information on how to contact the NPC is available from its official government website.
365org will respond to all valid data subject requests within fifteen (15) business days of receipt. In complex cases, this period may be extended by an additional fifteen (15) business days, with notice provided to you. Identity verification may be required before we can process a data subject request to protect against unauthorized access to another person's data.
11. Minors and Age Restrictions
365org is strictly restricted to persons aged 21 years and above. We do not knowingly collect personal data from persons under the age of 21. If 365org discovers that an account has been created by a person under 21, the account will be immediately suspended, all balances will be frozen pending investigation, and the matter will be reported to PAGCOR in accordance with regulatory requirements. If you are a parent or guardian and believe a minor has registered on our platform, please contact our support team immediately.
Age verification is a mandatory step in the 365org account registration process. We use KYC document verification to confirm that each new player meets the minimum age requirement of 21 years before their account is fully activated for gameplay and deposits.
12. Changes to This Privacy Policy
365org may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, PAGCOR requirements, or business operations. When we make material changes — for example, changes to the categories of data we collect, the purposes for which we use it, or your rights as a data subject — we will notify registered players by email to the address on their account and/or by posting a prominent notice on the 365org platform.
Non-material changes, such as typographical corrections or clarifications that do not alter the substance of our data processing activities, will be reflected in this Policy with an updated "Last Updated" date without separate notification. We encourage you to review this Privacy Policy periodically to stay informed of how 365org protects your data.
Continued use of the 365org platform after the effective date of any updated Privacy Policy constitutes your acknowledgment of the changes.
13. Contact & Data Protection Officer
365org has designated a Data Protection Officer (DPO) in accordance with the requirements of the Data Privacy Act of 2012 and the National Privacy Commission's guidelines on DPO designation. If you have any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, you may contact the 365org DPO through the following channels:
Customer Support (24/7): Available via live chat directly on the 365org platform. For privacy-specific inquiries, please indicate "Data Privacy Request" in your opening message so your query can be routed directly to the appropriate team.
Email: For written data subject requests, you may send your request to our support email address: [email protected]. Please include "Data Privacy Request" in the subject line and provide your registered account email address or mobile number to enable us to verify your identity.
We aim to acknowledge all privacy inquiries within two (2) business days and to provide a substantive response within the fifteen (15) business day period prescribed by the Data Privacy Act.
How 365org Keeps Your Information Safe
Beyond the legal text, here is what data protection at 365org looks like in practice for every Filipino player on our platform.
256-Bit SSL Encryption
Every piece of data transmitted between your device and the 365org platform is encrypted using 256-bit SSL/TLS — the same standard used by major Philippine banks. Your login credentials, payment details, and personal information are never sent in plain text.
DPA 2012 Compliant
365org processes your data in full compliance with Republic Act No. 10173, the Data Privacy Act of 2012. Our Data Protection Officer ensures that all data handling practices meet the standards set by the National Privacy Commission of the Philippines.
No Data Selling — Ever
365org does not sell, rent, or trade your personal data to any third party for their own marketing use. Period. Your information is used only to operate your 365org account and meet our legal obligations — nothing else.
Your Data Subject Rights
Access your data, request corrections, ask for deletion, or object to marketing — all of these are enforceable rights under Philippine law that 365org is legally required to honor. Submit a request via live chat or email and we'll respond within 15 business days.
Regular Security Audits
365org conducts regular penetration testing and security assessments with independent cybersecurity specialists. Vulnerabilities are patched promptly, and our incident response procedures ensure rapid action in the unlikely event of a data breach.
Defined Data Retention
365org doesn't hold onto your data indefinitely. Retention periods are clearly defined — typically five years for financial and identity data as required by AMLA — and data is securely deleted or anonymized once those periods expire.
🎰 Play at 365org with Confidence
Your Data Is Safe at 365org
Now you know exactly how 365org handles your personal data — transparently, securely, and in full compliance with Philippine law. Join thousands of Filipino players who trust 365org every day. Players must be 21 years or older to register.