Important: By registering an account or using any part of the g0123 platform, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your personal data as described herein. If you do not consent, please do not register or continue using the platform.
1 Introduction
g0123 ("g0123," "we," "us," or "our") operates the online gaming platform accessible at g0123.org ("Platform"). This Privacy Policy ("Policy") sets out how g0123 collects, uses, discloses, retains, and protects the personal information of individuals ("you," "your," or "Player") who register for and use our services.
This Policy is issued in accordance with Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 ("DPA"), and its Implementing Rules and Regulations issued by the National Privacy Commission of the Philippines ("NPC"). It supplements and should be read in conjunction with our Terms & Conditions.
g0123 is committed to processing your personal data lawfully, fairly, and transparently. We collect only what is necessary to provide our services and comply with our regulatory obligations under PAGCOR licensing requirements and Philippine anti-money laundering law.
This Policy applies to all personal data collected through the g0123 Platform, including data submitted during registration, identity verification, payment processing, gameplay, and customer support interactions. It does not apply to third-party websites or services that may be linked from our Platform.
2 Data Controller
For the purposes of the Data Privacy Act of 2012, g0123 is the personal information controller responsible for your personal data processed in connection with the Platform.
g0123 has appointed a Data Protection Officer ("DPO") as required by Section 21 of the DPA. The DPO is responsible for overseeing g0123's data protection compliance, handling data subject requests, and acting as the point of contact with the National Privacy Commission.
You may contact our Data Protection Officer directly for any privacy-related matter at:
- Email: [email protected] (subject line: "Data Privacy — DPO Request")
- Platform: Via the 24/7 live chat feature within your g0123 account dashboard
g0123 is registered with the National Privacy Commission as required under the DPA and its Implementing Rules and Regulations.
3 Personal Data We Collect
g0123 collects the following categories of personal data:
3.1 Identity Data
- Full legal name as it appears on your Philippine government-issued ID;
- Date of birth (for age verification — must confirm 21 or older);
- Gender (where voluntarily provided);
- Nationality and country of residence;
- Copies of government-issued photo identification documents submitted during KYC (passport, driver's license, SSS ID, PhilHealth ID, UMID, postal ID, or PhilSys National ID);
- Selfie photographs submitted during KYC verification.
3.2 Contact Data
- Philippine mobile number (primary contact and OTP delivery);
- Email address;
- Current residential address in the Philippines.
3.3 Account Data
- Username and encrypted password hash;
- Account registration date and timestamps;
- Login history including device type and IP address;
- Account preference settings and responsible gaming limit configurations.
3.4 Financial Data
- GCash account number or mobile number linked to deposits/withdrawals;
- Bank account details for BPI, BDO, or Metrobank transfers (account name and number only — full account credentials are never collected);
- Deposit and withdrawal transaction history including amounts, dates, and payment methods;
- Wallet balance records.
3.5 Gaming Data
- Game session logs including game type, wager amounts, outcomes, and timestamps;
- Loyalty program tier, points balance, and redemption history;
- Bonus and promotion participation records.
3.6 Technical Data
- IP address at time of access;
- Device fingerprint and browser user agent string;
- Geolocation data (country/region level, derived from IP address);
- Session duration and navigation behavior within the Platform;
- Cookie identifiers (see Section 10).
3.7 Communications Data
- Customer support chat transcripts and email correspondence;
- Feedback and survey responses where voluntarily submitted.
4 How We Collect Your Data
g0123 collects personal data through the following means:
- Direct submission: Data you provide when registering an account, completing KYC verification, making a deposit or withdrawal, or contacting customer support;
- Automated collection: Technical data collected automatically when you access and use the Platform, including IP addresses, device identifiers, and session logs via our web analytics infrastructure;
- Cookie and tracking technologies: First-party cookies used to maintain your session, remember preferences, and measure Platform performance (see Section 10);
- Payment processors: Transaction confirmation data received from payment providers such as GCash, PayMaya, BPI, BDO, and Metrobank when you make deposits or withdrawals;
- KYC verification providers: Identity verification data processed through our third-party KYC partners when you submit government ID documents.
5 Purposes of Data Processing
g0123 processes your personal data for the following specified, legitimate purposes:
- Account management: To create, maintain, and secure your g0123 player account, including authentication and session management;
- Age and identity verification: To verify that you are 21 years of age or older as required by PAGCOR, and to confirm your identity in compliance with anti-money laundering regulations;
- Payment processing: To process deposits, execute withdrawal requests, and maintain accurate wallet balance records;
- Game delivery and platform operation: To operate game sessions, record outcomes, and maintain game integrity;
- Regulatory compliance: To fulfill our legal obligations under PAGCOR licensing conditions, Republic Act No. 9160 (Anti-Money Laundering Act), and the DPA, including mandatory reporting to PAGCOR and the AMLC;
- Fraud prevention and security: To detect, investigate, and prevent unauthorized access, fraudulent activity, money laundering, and other prohibited conduct;
- Customer support: To respond to your inquiries, resolve disputes, and maintain records of support interactions;
- Responsible gaming: To implement deposit limits, session controls, and self-exclusion tools in accordance with PAGCOR responsible gaming requirements;
- Platform improvement: To analyze usage patterns, diagnose technical issues, and improve the Platform's features and user experience;
- Direct communications: To send you account-related notifications (deposit confirmations, withdrawal updates, security alerts, promotional offers) to your registered mobile number or email, subject to your communication preferences.
g0123 does not process your personal data for purposes other than those listed above without first obtaining your explicit consent, except where otherwise permitted or required by Philippine law.
6 Legal Basis for Processing
g0123 processes your personal data on the following legal grounds under the Data Privacy Act of 2012:
- Contractual necessity: Processing is necessary to perform our contract with you (the Terms & Conditions) — specifically, to provide your account, process payments, and deliver gaming services;
- Legal obligation: Processing is required to comply with our obligations under PAGCOR licensing, the Anti-Money Laundering Act (RA 9160), and other applicable Philippine law;
- Legitimate interests: Processing for fraud detection, platform security, and service improvement, where these interests are not overridden by your data protection rights;
- Consent: For marketing communications and optional data uses. You may withdraw consent at any time by updating your notification preferences in your account settings or by contacting our DPO.
7 Data Sharing and Disclosure
g0123 does not sell your personal data. We disclose personal data only in the following circumstances:
7.1 Service Providers
We share data with trusted third-party service providers who process data on our behalf under contractual data processing agreements that require them to implement appropriate security measures and process data only for specified purposes. These include:
- Payment processors (GCash / Mynt, PayMaya, BPI, BDO, Metrobank) — for transaction processing;
- KYC identity verification providers — for document verification;
- Cloud infrastructure providers — for secure data hosting;
- Customer support platform providers — for support ticket management.
7.2 Regulatory and Law Enforcement Authorities
g0123 is legally required to disclose certain personal data to:
- PAGCOR — in connection with our licensing obligations and any investigations;
- The Anti-Money Laundering Council (AMLC) — for mandatory suspicious transaction and covered transaction reporting under RA 9160;
- Philippine law enforcement agencies — where required by lawful court order, subpoena, or official legal process;
- The National Privacy Commission — in connection with data breach notifications or NPC investigations.
7.3 Business Transfers
In the event of a merger, acquisition, or sale of substantially all of g0123's assets, your personal data may be transferred to the acquiring entity. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
Beyond the above, g0123 will not disclose your personal data to any third party without your explicit prior consent.
8 Data Retention
g0123 retains your personal data for as long as is necessary for the purposes for which it was collected, subject to the following minimum retention periods required by Philippine law:
- Account and identity data: Retained for the duration of your active account plus a minimum of 5 years following account closure, as required by PAGCOR and AML regulations;
- Transaction and financial records: Retained for a minimum of 10 years from the date of the transaction, as required by the Anti-Money Laundering Act (RA 9160, as amended by RA 10365);
- KYC documents: Retained for a minimum of 5 years from account closure or last transaction, whichever is later;
- Customer support records: Retained for 3 years from the date of each interaction;
- Technical/log data: Retained for 12 months, after which it is anonymized or deleted.
At the end of the applicable retention period, personal data is securely deleted or irreversibly anonymized. Data subject to active legal proceedings, regulatory investigations, or unresolved disputes will be retained until those matters are concluded.
9 Data Security
g0123 implements a comprehensive set of technical and organizational security measures to protect your personal data against unauthorized access, loss, alteration, or disclosure:
- Encryption: All data in transit is protected by TLS 1.3. All data at rest is encrypted using AES-256;
- Access controls: Personal data access within g0123 is restricted on a strict need-to-know basis. Staff with access undergo background screening and receive regular data privacy training;
- Two-factor authentication: Player accounts are protected by optional 2FA via SMS OTP, and all administrative access to g0123 systems requires multi-factor authentication;
- Regular security audits: g0123 conducts periodic penetration testing and vulnerability assessments on its Platform infrastructure;
- Secure KYC processing: Identity documents are processed in an isolated, access-controlled environment and are not accessible to general Platform operations staff;
- Incident response: g0123 maintains a documented data breach response procedure aligned with NPC requirements (see Section 14).
Notwithstanding these measures, no internet-based system can guarantee absolute security. You are encouraged to use a strong, unique password for your g0123 account and to enable two-factor authentication for additional protection.
10 Cookies and Tracking Technologies
g0123 uses first-party cookies and similar technologies on the Platform for the following purposes:
- Essential cookies: Required for the Platform to function. These include session authentication tokens (to keep you logged in), security cookies (to detect unauthorized login attempts), and load balancing cookies. These cannot be disabled without preventing core Platform functionality;
- Preference cookies: Store your Platform settings such as language preferences and responsible gaming limit configurations;
- Analytics cookies: First-party analytics cookies that collect anonymized data about how you navigate the Platform, which pages are visited, and how long sessions last. This data is used solely to improve Platform performance and is not shared with third-party advertising networks;
- Security cookies: Device fingerprinting cookies used for fraud detection and to identify unusual login patterns.
g0123 does not use third-party advertising cookies, retargeting cookies, or cross-site tracking technologies. You may manage non-essential cookies through your browser settings. Please note that disabling cookies may affect Platform functionality.
11 Your Data Subject Rights
Under the Data Privacy Act of 2012 and its Implementing Rules, you have the following rights with respect to your personal data held by g0123:
- Right to be informed: The right to know that your personal data is being collected and processed, and the purposes for which it is used — which is the purpose of this Policy;
- Right to access: The right to request a copy of the personal data we hold about you, and information about how it is processed. Requests will be fulfilled within 15 working days;
- Right to rectification: The right to request correction of inaccurate or incomplete personal data. You may update most account information directly from your account settings. For KYC-related data, contact our DPO;
- Right to erasure / right to be forgotten: The right to request deletion of your personal data where it is no longer necessary for the purposes collected, subject to our legal retention obligations (see Section 8). Data retained for AML compliance purposes cannot be erased during the mandatory retention period;
- Right to object: The right to object to processing of your personal data based on legitimate interests, including for marketing communications. Objections to mandatory regulatory processing (AML, KYC) cannot be upheld as they are required by law;
- Right to data portability: The right to receive a structured, machine-readable copy of personal data you provided to g0123, for transfer to another service provider;
- Right to lodge a complaint: The right to file a complaint with the National Privacy Commission (NPC) at privacy.gov.ph if you believe g0123 has violated your data privacy rights.
To exercise any of the above rights, submit a written request to our Data Protection Officer at [email protected] with the subject line "Data Subject Rights Request" and include your full name, registered email address, and a description of the right you wish to exercise. We may require identity verification before processing your request.
12 Children's Privacy and Age Restriction
The g0123 Platform is strictly for adults aged 21 years and above as required by PAGCOR. g0123 does not knowingly collect personal data from individuals under 21 years of age.
Where g0123 discovers that an account has been registered by an individual under 21 — whether through KYC verification, age inconsistency detection, or third-party notification — the following actions will be taken:
- The account will be immediately suspended and access to the Platform disabled;
- All personal data collected in connection with the underage account will be deleted within 30 days, except for records required to be retained for legal or regulatory purposes;
- The incident will be reported to PAGCOR as required by licensing conditions.
If you have reason to believe that a minor has registered on the g0123 Platform, please notify us immediately at [email protected].
13 Cross-Border Data Transfers
g0123's primary data processing operations are conducted within the Philippines. In certain circumstances, your personal data may be processed by service providers operating in other jurisdictions — for example, cloud infrastructure providers or KYC processing partners.
Where personal data is transferred outside the Philippines, g0123 ensures that such transfers comply with Section 21 of the Data Privacy Act of 2012 and the NPC's rules on cross-border data flows. Specifically, g0123:
- Ensures that the receiving jurisdiction provides an adequate level of data protection, or;
- Implements appropriate contractual safeguards with the receiving party through Data Transfer Agreements that impose obligations equivalent to those under Philippine law;
- Does not transfer personal data to jurisdictions that the NPC has determined to offer inadequate data protection without implementing additional technical and contractual safeguards.
You may request information about the specific jurisdictions to which your personal data may be transferred by contacting our DPO.
14 Data Breach Response Protocol
g0123 maintains a documented personal data breach response procedure in accordance with NPC Circular 16-03 on Security of Personal Data in Government Agencies and the requirements of the Data Privacy Act.
In the event of a personal data breach that poses a real risk of serious harm to affected data subjects, g0123 will:
- Internal detection: Identify and contain the breach within our Security Incident Response Team within the first 24 hours of discovery;
- NPC notification: Notify the National Privacy Commission within 72 hours of discovering a notifiable breach, in the form required by NPC Circular 16-03;
- Player notification: Notify affected players directly via their registered email address and/or SMS within 72 hours (or sooner where feasible), including a description of the nature of the breach, the types of data affected, the measures taken, and the steps you can take to protect yourself;
- Post-incident review: Conduct a full root cause analysis and implement remediation measures to prevent recurrence.
g0123 maintains a breach register as required by the NPC and cooperates fully with any NPC investigation arising from a notified breach.
15 Amendments to This Policy
g0123 reserves the right to modify this Privacy Policy at any time to reflect changes in our data processing practices, applicable law, or regulatory requirements. When material changes are made:
- The updated Policy will be published at g0123.org/privacy-policy with a revised "Last Updated" date;
- Registered Players will be notified via SMS or email to their registered contact details at least 7 days before changes take effect, except where immediate amendments are required by law or NPC directive;
- For significant changes that materially affect your rights, g0123 will seek fresh consent where required by the DPA.
We encourage you to review this Policy periodically. Continued use of the g0123 Platform after the effective date of any amendment constitutes acknowledgment of the updated Policy.
16 Contact and Data Protection Officer
For all data privacy inquiries, data subject rights requests, or complaints regarding g0123's handling of your personal data, please contact our Data Protection Officer:
- Email: [email protected] (subject: "Data Privacy — DPO Request")
- Live Chat: Available 24/7 within your g0123 account dashboard
- Response Time: Data subject rights requests are acknowledged within 2 business days and fulfilled within 15 working days from receipt of complete information.
If you are not satisfied with our response to your data privacy concern, you have the right to lodge a complaint with the National Privacy Commission of the Philippines. The NPC handles complaints related to violations of the Data Privacy Act of 2012 and may be reached through their official government channels.
This Privacy Policy was prepared in accordance with Republic Act No. 10173 (Data Privacy Act of 2012), its Implementing Rules and Regulations, and applicable NPC Circulars and Advisories. It is effective as of June 5, 2026.