brojl Privacy Policy
At brojl, we take your privacy as seriously as we take your security. This Privacy Policy explains exactly what personal data we collect, why we collect it, how we use it, and the rights you hold as a player under Philippine law — including the Data Privacy Act of 2012 (Republic Act No. 10173).
Privacy Principles at brojl
Data Minimisation
brojl only collects the personal data we genuinely need to provide the Service. We do not request information that serves no legitimate operational or regulatory purpose.
Bank-Grade Security
All data is transmitted over 256-bit SSL/TLS encryption and stored in access-controlled environments. Player data is never stored in plaintext and is subject to continuous security monitoring.
No Unauthorised Selling
brojl does not sell, rent, or trade your personal information to third-party advertisers or data brokers. Your data belongs to you — not to marketing companies.
RA 10173 Compliance
brojl operates in full compliance with the Philippine Data Privacy Act of 2012 and adheres to the directives of the National Privacy Commission (NPC) of the Philippines.
Your Rights, Respected
You have the right to access, correct, object to, erase, and port your personal data. brojl provides clear mechanisms for exercising each of these rights without unnecessary friction.
Transparent Processing
Every category of data we collect, every purpose for which it is used, and every type of third party we share it with is documented clearly in this policy — no vague language, no hidden processing.
1. Introduction and Scope
This Privacy Policy ("Policy") is issued by brojl ("we," "us," or "our") and applies to all personal data collected from individuals ("you," "your," or "Data Subject") who access, browse, register on, or otherwise interact with the brojl online gaming platform at brojl.cam (the "Platform").
This Policy is governed by and construed in accordance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, as well as applicable directives issued by the National Privacy Commission (NPC) of the Philippines. By using the Platform, you acknowledge that you have read and understood this Policy and consent to the processing of your personal data as described herein.
Note: This Policy is supplementary to and should be read in conjunction with the Terms & Conditions. In the event of any conflict between the two documents regarding the handling of personal data, this Privacy Policy shall prevail.
2. Personal Data We Collect
brojl collects personal data through multiple channels — directly from you when you register or interact with the Platform, automatically through your use of the Platform, and from third-party sources in limited circumstances. The categories of personal data we collect are as follows:
2.1 Registration and Identity Data
- Full legal name as it appears on your government-issued identification
- Date of birth (for mandatory age verification — you must be 21 years of age or older)
- Gender (optional, collected to personalise promotional communications where applicable)
- Nationality and country of residence
- Residential address, including barangay, city or municipality, province, and ZIP code
2.2 Contact and Account Data
- Email address (used for account verification, transactional communications, and support)
- Philippine mobile number (used for one-time password delivery and account security)
- Username and encrypted password (passwords are stored using industry-standard hashing algorithms and are never accessible in plaintext)
- Security questions and responses (where applicable)
2.3 Identity Verification (KYC) Documents
- Copies of government-issued identification documents (e.g., Philippine National ID, Passport, Driver's License, UMID, SSS ID, Voter's ID)
- Selfie photographs or video verification footage collected for liveness checks
- Proof of address documentation where required for enhanced due diligence
2.4 Financial and Transaction Data
- GCash registered mobile number and account reference numbers
- Maya (PayMaya) account reference numbers
- Bank account names and last four digits of account numbers for BPI, BDO, UnionBank, and Metrobank transactions
- Deposit and withdrawal transaction histories including amounts, timestamps, and payment method used
- Gaming transaction records including bets placed, game results, and account balance changes
brojl does not collect or store full bank account numbers, full credit or debit card numbers, or CVV codes. All payment processing is handled by certified third-party payment processors operating under their own privacy and security frameworks.
2.5 Technical and Usage Data
When you access the Platform, the following data is automatically collected by our systems:
| Data Type | Examples | Purpose |
|---|---|---|
| Device data | Device type, operating system, browser type and version, screen resolution | Platform optimisation and fraud detection |
| Network data | IP address, approximate geolocation (city/region level), ISP name | Jurisdictional eligibility checks, fraud prevention |
| Session data | Login timestamps, session duration, pages visited, features accessed | Security monitoring, responsible gaming, UX improvement |
| Cookies and similar | Session cookies, preference cookies, analytics identifiers | Authentication persistence, analytics, personalisation |
2.6 Communications Data
When you contact brojl support via live chat or email, we retain records of your communications, including the content of your messages, timestamps, and the resolution of any issues raised. This data is retained for quality assurance, dispute resolution, and regulatory compliance purposes.
3. Legal Basis and Purposes for Processing
brojl processes your personal data only when a lawful basis for processing exists under the Data Privacy Act of 2012. The applicable legal bases and corresponding processing purposes are:
- Contractual necessity: Processing required to enter into and perform the contract between you and brojl — including account registration, identity verification, payment processing, game delivery, and dispute resolution.
- Legal obligation: Processing required to comply with PAGCOR licensing conditions, the Anti-Money Laundering Act (AMLA), the Anti-Terrorism Financing Act, and directives from the NPC, PAGCOR, or other competent Philippine regulatory authorities.
- Legitimate interests: Processing necessary for fraud prevention, platform security, responsible gaming enforcement, and improving the quality of the Service, where such interests are not overridden by your rights and freedoms.
- Consent: Where we send optional promotional communications (e.g., bonus offers, newsletters), we do so based on your explicit consent, which you may withdraw at any time.
4. Cookies and Tracking Technologies
4.1 What Cookies We Use
brojl uses the following categories of cookies on the Platform:
- Strictly Necessary Cookies: Essential for the Platform to function. These enable authentication, session management, and security features. They cannot be disabled without impairing the Service.
- Functional Cookies: Remember your language preferences, display settings, and other personalisation choices to enhance your experience.
- Analytics Cookies: Collect aggregated and anonymised data about how players use the Platform — which pages are visited most, where users drop off, and how features perform. This data informs product improvements.
- Responsible Gaming Cookies: Track session duration and gaming activity to power the real-time responsible gaming alerts and session time reminders available in your account settings.
4.2 Managing Cookies
You may manage cookie preferences through your browser settings at any time. Please note that disabling strictly necessary cookies will prevent you from logging in to your brojl account. Disabling functional or analytics cookies will not affect your ability to play but may reduce the personalisation of your experience.
5. Sharing Your Personal Data
brojl does not sell your personal data. We may share your data only with the following categories of recipients and only to the extent strictly necessary:
- Payment Processors: GCash (Globe Fintech Innovations), Maya Philippines, BPI, BDO, UnionBank, and other licensed Philippine payment service providers — to process deposits and withdrawals on your behalf.
- KYC and Identity Verification Providers: Third-party identity verification service providers engaged to conduct document verification and liveness checks in compliance with PAGCOR KYC requirements.
- Game Content Providers: Licensed game studios and live dealer platform providers whose games are made available through the Platform. These providers receive anonymised or pseudonymised game session data only.
- Regulatory Authorities: PAGCOR, the Anti-Money Laundering Council (AMLC), the National Privacy Commission (NPC), and other Philippine government bodies when required by law or in response to a valid legal demand.
- Technology and Infrastructure Providers: Cloud hosting, cybersecurity, and platform analytics providers operating under binding data processing agreements that prohibit them from using your data for any purpose other than providing services to brojl.
All third parties with whom brojl shares personal data are contractually required to maintain appropriate security standards and to process your data only for the specific purposes for which it was shared.
6. International Data Transfers
Some of brojl's technology and service providers may process your data in jurisdictions outside the Philippines. Where such transfers occur, brojl ensures that adequate safeguards are in place as required by the Data Privacy Act of 2012, including the use of binding data processing agreements incorporating standard contractual clauses or transfers to jurisdictions deemed to provide an adequate level of protection.
7. Data Retention
brojl retains your personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law. The following general retention periods apply:
- Account and identity data: Retained for the duration of your account and for a minimum of 5 years following account closure, as required by PAGCOR regulations and the Anti-Money Laundering Act.
- KYC documents: Retained for a minimum of 5 years from the date of collection or from the date of the last transaction, whichever is later.
- Transaction records: Retained for a minimum of 5 years from the date of each transaction.
- Support communications: Retained for 2 years from the date of the last communication, unless the matter is subject to ongoing legal or regulatory proceedings.
- Analytics and usage data: Retained in anonymised or aggregated form for up to 3 years.
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with our internal data disposal procedures.
8. Your Rights as a Data Subject
Under the Philippine Data Privacy Act of 2012, you have the following rights with respect to your personal data held by brojl:
- Right to be Informed: The right to know whether your data is being processed, the purposes of processing, and how it is used — as set out in this Policy.
- Right to Access: The right to obtain a copy of the personal data we hold about you and information about how it is processed.
- Right to Rectification: The right to have inaccurate or incomplete personal data corrected without undue delay.
- Right to Erasure (Right to be Forgotten): The right to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to overriding legal obligations.
- Right to Object: The right to object to processing based on legitimate interests, including the use of your data for direct marketing purposes.
- Right to Data Portability: The right to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Lodge a Complaint: The right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines if you believe your data has been processed in violation of the Data Privacy Act.
To exercise any of these rights, please contact us at [email protected] with the subject line "Data Privacy Request." We will respond to all verifiable requests within 15 business days. We may require you to verify your identity before processing any request.
9. Security Measures
brojl implements a comprehensive set of technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, destruction, alteration, or disclosure:
- 256-bit SSL/TLS encryption for all data transmitted between your device and the Platform
- AES-256 encryption for all sensitive data stored at rest
- Password hashing using bcrypt with a minimum cost factor of 12
- Two-factor authentication (2FA) available to all registered players
- Role-based access controls limiting staff access to personal data on a strict need-to-know basis
- Continuous intrusion detection and real-time security monitoring
- Regular penetration testing and vulnerability assessments conducted by independent security firms
- Documented incident response procedures aligned with NPC breach notification requirements
Despite these measures, no online platform can guarantee absolute security. In the event of a data breach that poses a real risk to your rights and freedoms, brojl will notify the National Privacy Commission and affected users within the timeframe required by law.
10. Children's Privacy
The brojl Platform is strictly intended for individuals aged 21 years and above. We do not knowingly collect personal data from anyone under the age of 21. If you are a parent or guardian and believe that a minor has provided personal data to brojl, please contact us immediately at [email protected]. Upon verification, we will take prompt steps to delete the minor's data and close the associated account.
11. Third-Party Links
The Platform may, on occasion, reference or link to third-party services (such as payment processors' own portals). brojl is not responsible for the privacy practices or content of any third-party website or service. We encourage you to review the privacy policies of any third-party services you access before providing them with your personal data.
12. Changes to This Privacy Policy
brojl reserves the right to update this Policy at any time to reflect changes in our data processing practices, legal requirements, or regulatory guidance. Material changes will be communicated to registered players via email at least 7 days before taking effect. The updated Policy will be posted on this page with a revised "Last Updated" date. Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the revised Policy.
13. Contact and Data Protection Queries
If you have any questions, concerns, or complaints regarding this Privacy Policy or the handling of your personal data by brojl, please contact us:
- Email: [email protected]
- Subject Line: "Data Privacy Request" or "Privacy Complaint"
- Response Time: Within 15 business days of receipt
- Support Hours: 24 hours a day, 7 days a week
If your concern is not resolved to your satisfaction, you have the right to escalate the matter to the National Privacy Commission of the Philippines, the competent supervisory authority for data protection in the Philippines.
Your Privacy is Protected. Enjoy brojl Worry-Free.
With industry-leading encryption, full RA 10173 compliance, and no data selling — ever — brojl is the online gaming platform Filipino players can trust. Over 3,500 games are waiting.
Must be 21 years of age or older to register. Play responsibly. PAGCOR regulated.