Privacy Policy
mlwin is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains what information we collect, why we collect it, how we use it, and what rights you have under Philippine law.
Data Privacy Act Compliant
mlwin processes your personal data in full compliance with the Philippine Data Privacy Act of 2012 (RA 10173) and its implementing rules.
Bank-Grade Encryption
All personal and financial data transmitted to and from mlwin is protected using TLS 1.3 encryption. Stored data is encrypted at rest using AES-256.
No Data Selling
mlwin does not sell, rent, or trade your personal data to third parties for marketing or commercial purposes â ever.
Your Rights, Respected
You have the right to access, correct, delete, and port your personal data. mlwin provides clear channels to exercise all your data subject rights.
Transparent Cookie Use
mlwin uses cookies only for essential platform functionality, security, and analytics. You can manage your cookie preferences at any time.
NPC Registered
mlwin is registered with the National Privacy Commission (NPC) of the Philippines as required under RA 10173 for personal information controllers.
Table of Contents
- 1. Introduction
- 2. Personal Data We Collect
- 3. How We Collect Your Data
- 4. How We Use Your Data
- 5. Legal Basis for Processing
- 6. Data Sharing & Disclosure
- 7. Data Retention
- 8. Data Security
- 9. Cookies & Tracking
- 10. Your Data Subject Rights
- 11. Minors & Age Restriction
- 12. Cross-Border Data Transfers
- 13. Changes to This Policy
- 14. Contact & DPO Details
1. Introduction
mlwin ("we", "us", "our") operates the online gaming platform accessible at mlwin.net (the "Platform"). As a personal information controller under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173, "DPA"), mlwin is responsible for the personal data you provide to us and the data we collect about you through your use of the Platform.
This Privacy Policy ("Policy") describes in detail how mlwin collects, uses, stores, shares, and protects your personal data. It also explains the rights you have as a data subject under Philippine law and how you can exercise those rights.
This Policy applies to all personal data processed by mlwin in connection with the Platform, including data collected through the mlwin website, mobile applications, customer support channels, and any other services we provide. It should be read together with the mlwin Terms & Conditions and Responsible Gaming Policy.
âšī¸ Your Consent: By registering an account on mlwin or continuing to use the Platform, you acknowledge that you have read and understood this Privacy Policy and consent to the collection and processing of your personal data as described herein. You may withdraw consent at any time, subject to the limitations described in Section 10.
2. Personal Data We Collect
mlwin collects the following categories of personal data from and about you:
2.1 Identity & Contact Data
- Full legal name as it appears on your government-issued identification.
- Date of birth (used for mandatory age verification â players must be 21 years of age or older).
- Philippine mobile number and email address.
- Residential address, city, and province within the Philippines.
- Government-issued identification numbers (e.g., PhilSys ID number, passport number, SSS/GSIS number, driver's licence number) â collected during KYC verification only.
2.2 Account & Transaction Data
- mlwin username and encrypted password credentials.
- Account registration date, login history, and session timestamps.
- Deposit and withdrawal records, including amounts, dates, payment methods, and transaction reference numbers.
- Wagering history, game activity logs, and bonus redemption records.
- Account balance and transaction statements.
2.3 Payment & Financial Data
- GCash mobile number or Maya account details used for transactions.
- Bank account details (bank name, account number) for bank transfer transactions.
- Debit card details (card number is tokenised and never stored in full by mlwin).
- Transaction verification records required under Philippine AML regulations.
2.4 Technical & Usage Data
- IP address and approximate geolocation data.
- Device type, operating system, browser type and version.
- Pages visited, features used, and time spent on the Platform.
- Referral source and marketing attribution data.
- Error logs and crash reports.
2.5 Communications Data
- Records of your communications with mlwin customer support, including live chat transcripts, email correspondence, and call recordings (where applicable).
- Survey responses, feedback submissions, and promotional opt-in preferences.
â ī¸ Sensitive Personal Information: mlwin may collect certain sensitive personal information as defined under the DPA, including government ID numbers and financial account details, solely for the purpose of complying with KYC and AML obligations. This data is handled with the highest level of security and access controls.
3. How We Collect Your Data
mlwin collects your personal data through the following means:
- Direct collection: Information you provide when registering an account, completing KYC verification, making deposits or withdrawals, contacting customer support, or participating in promotions.
- Automated collection: Technical and usage data collected automatically through cookies, web beacons, server logs, and similar tracking technologies when you access and use the Platform.
- Third-party sources: Identity verification data from KYC service providers; fraud and AML screening data from compliance partners; payment confirmation data from GCash, Maya, and banking partners.
- Publicly available sources: Where permitted by law, mlwin may supplement your data with information from publicly available Philippine government databases for identity verification purposes.
4. How We Use Your Personal Data
mlwin uses your personal data for the following purposes:
| Purpose | Data Used |
|---|---|
| Account registration and management | Identity, contact, account data |
| Age and identity verification (KYC) | Identity data, government IDs |
| Processing deposits and withdrawals | Payment and financial data |
| Providing gaming services and personalisation | Account, usage, transaction data |
| Anti-money laundering (AML) compliance | Identity, transaction, financial data |
| Fraud detection and prevention | Technical, transaction, identity data |
| Customer support and dispute resolution | Communications, account, transaction data |
| Responsible gaming monitoring | Account, wagering, usage data |
| Marketing and promotional communications (with consent) | Contact, usage, preference data |
| Platform analytics and improvement | Technical and usage data (anonymised where possible) |
| Legal and regulatory compliance | All categories as required by law |
mlwin will not use your personal data for any purpose that is incompatible with the purposes listed above without first obtaining your explicit consent or as otherwise permitted by the DPA.
5. Legal Basis for Processing
mlwin processes your personal data on the following legal bases as recognised under the Philippine Data Privacy Act of 2012:
- Contractual necessity: Processing required to perform our contract with you, including account management, payment processing, and delivery of gaming services.
- Legal obligation: Processing required to comply with applicable Philippine laws, including the Anti-Money Laundering Act (AMLA), PAGCOR regulatory requirements, and the Data Privacy Act itself.
- Legitimate interests: Processing necessary for mlwin's legitimate business interests, including fraud prevention, platform security, and responsible gaming monitoring, where these interests are not overridden by your rights and freedoms.
- Consent: Processing based on your freely given, specific, informed, and unambiguous consent â primarily for direct marketing communications and non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Vital interests: In exceptional circumstances, processing may be necessary to protect your vital interests or those of another person, such as in a responsible gaming intervention.
âšī¸ Withdrawing Consent: Where processing is based on your consent, you may withdraw it at any time by contacting mlwin's Data Protection Officer (DPO) at the details provided in Section 14. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
6. Data Sharing & Disclosure
mlwin does not sell, rent, or trade your personal data. We may share your data with the following categories of recipients only to the extent necessary for the purposes described in this Policy:
6.1 Service Providers & Processors
- Payment processors: GCash, Maya, and banking partners process transaction data solely to facilitate your deposits and withdrawals.
- KYC and identity verification providers: Third-party verification services that assist mlwin in confirming your identity and age in compliance with Philippine regulations.
- AML screening providers: Compliance technology partners that screen transactions against watchlists and sanctions databases as required by the AMLA.
- Cloud infrastructure providers: Hosting and data storage providers operating under strict data processing agreements that prohibit independent use of your data.
- Customer support platforms: Tools used to manage live chat, email, and support ticket communications.
- Analytics providers: Platform analytics services that receive anonymised or pseudonymised usage data to help mlwin improve the Platform.
All third-party service providers engaged by mlwin are bound by contractual data processing agreements that require them to process your data only on mlwin's instructions and in compliance with the DPA.
6.2 Regulatory & Law Enforcement Authorities
mlwin may disclose your personal data to the following authorities where required or permitted by Philippine law:
- The Anti-Money Laundering Council (AMLC) â for suspicious transaction reporting under the AMLA.
- The Philippine Amusement and Gaming Corporation (PAGCOR) â for regulatory compliance and audit purposes.
- The National Privacy Commission (NPC) â in connection with data breach notifications or regulatory inquiries.
- Philippine law enforcement agencies â where required by a valid court order, subpoena, or other lawful process.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of all or substantially all of mlwin's assets, your personal data may be transferred to the acquiring entity. You will be notified of any such transfer and the privacy practices of the successor entity prior to the transfer taking effect.
â Our Commitment: mlwin will never share your personal data with advertisers, data brokers, or any third party for their own marketing purposes. Your data is used exclusively to operate and improve the mlwin Platform and to comply with our legal obligations.
7. Data Retention
mlwin retains your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable Philippine law. The following retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and identity data | Duration of account + 5 years after closure | AMLA / PAGCOR regulatory requirement |
| Transaction and financial records | 10 years from transaction date | AMLA Section 9 retention obligation |
| KYC verification documents | 5 years after account closure | AMLA implementing rules |
| Customer support communications | 3 years from last interaction | Legitimate interest / dispute resolution |
| Marketing preferences and consent records | Until consent withdrawn + 1 year | DPA consent documentation requirement |
| Technical and usage logs | 13 months from collection | Security and analytics purposes |
| Self-exclusion records | Indefinitely (or as required by PAGCOR) | Responsible gaming regulatory obligation |
Upon expiry of the applicable retention period, mlwin will securely delete or anonymise your personal data in accordance with its data disposal procedures. Where data cannot be immediately deleted due to technical constraints, it will be isolated and protected from further processing until deletion is possible.
8. Data Security
mlwin implements a comprehensive set of technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, loss, or destruction. These measures include:
8.1 Technical Measures
- Encryption in transit: All data transmitted between your device and mlwin servers is encrypted using TLS 1.3 protocol.
- Encryption at rest: Sensitive personal and financial data stored on mlwin servers is encrypted using AES-256 encryption.
- Password security: Account passwords are hashed using industry-standard bcrypt algorithms. mlwin never stores passwords in plain text.
- Two-factor authentication (2FA): mlwin offers optional 2FA for account login to provide an additional layer of security.
- Firewalls and intrusion detection: mlwin's infrastructure is protected by enterprise-grade firewalls and continuous intrusion detection and prevention systems.
- Regular security audits: mlwin conducts periodic penetration testing and vulnerability assessments of its Platform and infrastructure.
8.2 Organisational Measures
- Access to personal data is restricted to mlwin personnel and authorised service providers who require it to perform their duties, on a strict need-to-know basis.
- All mlwin staff with access to personal data undergo mandatory data privacy training and are bound by confidentiality obligations.
- mlwin maintains a documented data breach response plan and will notify affected players and the NPC of any qualifying data breach within the timeframes prescribed by the DPA.
â ī¸ Your Responsibility: While mlwin takes all reasonable steps to protect your data, the security of your account also depends on you. Please use a strong, unique password for your mlwin account, enable 2FA where available, and never share your login credentials with anyone. If you suspect your account has been compromised, contact mlwin support immediately.
9. Cookies & Tracking Technologies
mlwin uses cookies and similar tracking technologies to operate and improve the Platform. A cookie is a small text file placed on your device when you visit a website. The following categories of cookies are used on mlwin.net:
| Cookie Type | Purpose | Can Be Disabled? |
|---|---|---|
| Strictly Necessary | Essential for Platform operation â session management, login authentication, security tokens, and fraud prevention. | No â required for the Platform to function. |
| Functional | Remember your preferences such as language settings, game display options, and responsible gaming limits. | Yes â disabling may affect Platform functionality. |
| Analytics | Collect anonymised data about how players use the Platform to help mlwin identify improvements and fix issues. | Yes â via cookie preference settings. |
| Marketing | Track promotional campaign effectiveness and personalise offers shown to you on the Platform (internal only â no third-party ad networks). | Yes â via cookie preference settings or by withdrawing marketing consent. |
You can manage your cookie preferences through the cookie settings panel available on the Platform. Please note that disabling strictly necessary cookies will prevent you from using core Platform features including account login.
mlwin does not use third-party advertising networks or allow external advertisers to place cookies on your device through the Platform.
10. Your Data Subject Rights
Under the Philippine Data Privacy Act of 2012, you have the following rights with respect to your personal data held by mlwin:
- Right to be informed: The right to know whether mlwin holds personal data about you, and to receive clear information about how it is processed â as provided in this Policy.
- Right of access: The right to request a copy of the personal data mlwin holds about you, along with information about how it is used.
- Right to rectification: The right to request correction of any inaccurate or incomplete personal data mlwin holds about you.
- Right to erasure: The right to request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to mlwin's legal retention obligations.
- Right to object: The right to object to the processing of your personal data for direct marketing purposes or where processing is based on legitimate interests.
- Right to data portability: The right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller where technically feasible.
- Right to withdraw consent: Where processing is based on consent, the right to withdraw that consent at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: The right to lodge a complaint with the National Privacy Commission (NPC) of the Philippines if you believe your data rights have been violated.
10.1 How to Exercise Your Rights
To exercise any of the rights listed above, please contact mlwin's Data Protection Officer using the details provided in Section 14. mlwin will respond to all data subject requests within fifteen (15) calendar days of receipt, as required by the DPA. In complex cases, this period may be extended by a further fifteen (15) days with prior notice to you.
mlwin may request proof of your identity before processing a data subject request to ensure that personal data is not disclosed to unauthorised parties.
âšī¸ Limitations: Certain rights may be limited where mlwin is required to retain or process your data to comply with a legal obligation (e.g., AMLA transaction records), to defend a legal claim, or where the exercise of your rights would adversely affect the rights and freedoms of others.
11. Minors & Age Restriction
The mlwin Platform is strictly intended for persons who are at least 21 years of age, in accordance with the minimum legal gambling age in the Philippines. mlwin does not knowingly collect personal data from individuals under 21 years of age.
Age verification is a mandatory step in the mlwin registration and KYC process. Where mlwin discovers that personal data has been collected from a person under 21, that data will be deleted immediately and the associated account will be permanently closed.
If you are a parent or guardian and believe that a minor has registered on the mlwin Platform, please contact our support team immediately so that we can take appropriate action.
đ 21+ Only: mlwin is for adults aged 21 and above only. Gambling is addictive. Know when to stop. If you or someone you know may have a gambling problem, please visit our Responsible Gaming page for support resources.
12. Cross-Border Data Transfers
mlwin primarily stores and processes your personal data within the Philippines. In certain circumstances, your data may be transferred to and processed in countries outside the Philippines â for example, where mlwin uses cloud infrastructure providers or technology partners with operations in other jurisdictions.
Where such transfers occur, mlwin ensures that appropriate safeguards are in place to protect your personal data to a standard equivalent to that required under the Philippine DPA. These safeguards may include:
- Contractual clauses in data processing agreements that impose DPA-equivalent obligations on the recipient.
- Transfers to countries that the NPC has determined provide an adequate level of data protection.
- Binding corporate rules where the recipient is part of the same corporate group as mlwin.
You may request information about the specific safeguards applicable to any cross-border transfer of your data by contacting the mlwin DPO.
13. Changes to This Privacy Policy
mlwin reserves the right to update or amend this Privacy Policy at any time to reflect changes in our data processing practices, applicable Philippine law, or regulatory requirements. The date of the most recent revision is displayed at the top of this page.
Where changes are material â meaning they significantly affect your rights or how your data is used â mlwin will notify you by email to your registered address or through a prominent notice on the Platform at least fourteen (14) days before the changes take effect. For non-material changes, the updated Policy will be published on this page with an updated revision date.
Your continued use of the mlwin Platform following the effective date of any revised Policy constitutes your acceptance of the changes. If you do not agree to the revised Policy, you should cease using the Platform and may request account closure in accordance with the mlwin Terms & Conditions.
14. Contact & Data Protection Officer
mlwin has appointed a Data Protection Officer (DPO) responsible for overseeing compliance with the Philippine Data Privacy Act and this Privacy Policy. If you have any questions, concerns, or requests relating to your personal data or this Policy, please contact the mlwin DPO using the details below:
Data Protection Officer â mlwin
Email: [email protected]
General Support: [email protected]
Response time: Within 15 calendar days of receipt, as required by the Philippine Data Privacy Act of 2012.
If you are not satisfied with mlwin's response to your data privacy concern, you have the right to lodge a complaint with the National Privacy Commission of the Philippines:
National Privacy Commission (NPC)
3rd Floor, Core G, GSIS Headquarters, Financial Center, Roxas Boulevard, Pasay City, Metro Manila, Philippines
Website: privacy.gov.ph | Email: [email protected]
Your Privacy Is Our Priority at mlwin
Now that you know how mlwin protects your data, you can play with confidence. Join the mlwin community â where security, fairness, and your privacy come first.
đ For players aged 21 and above only. Please play responsibly.