Data Privacy

bm555 Privacy Policy — How We Handle Your Personal Information

At bm555, protecting the personal data of every Filipino member is a legal obligation and a core operational commitment. This Privacy Policy explains in plain terms how we collect your information, what we use it for, who we may share it with, and how you can exercise your rights under Philippine data protection law.

Effective Date: 1 January 2026 Last Reviewed: 1 January 2026 Law: RA 10173 (Data Privacy Act 2012) Jurisdiction: Philippines
Your Data Rights Are Protected Under Philippine Law

bm555 processes personal data of Filipino members in compliance with Republic Act No. 10173, the Data Privacy Act of 2012, and its Implementing Rules and Regulations. You have enforceable rights over your personal data — including the right to access, correct, delete, and port your data — as described in Section 10 of this Policy.

bm555 & the Philippine Data Privacy Act

Republic Act No. 10173 gives Filipino data subjects specific, enforceable rights. Here's how each one applies to your bm555 account.

Your Right
Access Your Data

You can request a copy of all personal data bm555 holds about you — identity records, transaction history, gaming logs, and support records. Requests are fulfilled within 15 business days. Contact the DPO with your registered account details to exercise this right.

RA 10173
Correct Inaccurate Data

If any personal data bm555 holds about you is inaccurate or outdated, you have the right to have it corrected. Minor updates (like contact number changes) can be made directly in your account settings. Name or ID corrections require KYC re-verification.

Protected
Request Data Erasure

Where bm555 no longer needs your data for the purposes it was collected, you may request its deletion. Note that AML and PAGCOR regulations require bm555 to retain certain records for 5 years after account closure regardless of erasure requests — we will explain any applicable exception when responding to your request.

Your Choice
Object to Processing

You can object to bm555 using your data for marketing purposes at any time — reply STOP to any SMS, click unsubscribe in any email, or update preferences in your account settings. Objection to marketing takes effect within 3 business days and does not affect your account access.

Portability
Port Your Data

You have the right to receive your personal data in a structured, machine-readable format (such as JSON or CSV), allowing you to take your data history with you. Data portability requests are fulfilled within 15 business days subject to identity verification. Contact the DPO to initiate a portability request.

21+ Only
Zero Minor Data Collection

bm555 does not knowingly collect data from individuals under 21. Mandatory KYC age verification at the point of registration and prior to first withdrawal is the structural enforcement mechanism. Any account found to belong to an underage user is immediately closed and all data deleted.

How bm555 Protects Your Information Every Day

Legal commitments are only meaningful when backed by technical and operational practice. These are the measures bm555 applies to every member account, every day.

TLS 1.3 + AES-256 Encryption

Data in transit between your device and bm555 servers uses TLS 1.3 — the current gold standard in transport encryption. Sensitive data at rest is encrypted with AES-256. The same dual-layer approach used by Philippine banks and government systems.

Role-Based Access Controls

bm555 staff access personal data only where their job function requires it, enforced through role-based access control systems. Every data access event is logged and regularly audited. No bm555 employee can access Member financial or identity data without a documented operational need.

Breach Notification Protocol

bm555 maintains a documented data breach response plan compliant with the NPC's breach notification requirements. In the event of a breach affecting Member data, bm555 will notify the National Privacy Commission within 72 hours of discovery and affected Members without undue delay.

Your Data. Your Rights. Your bm555 Account.

bm555 processes your data to operate the Platform you use — not to profit from it. Every data point collected has a defined purpose, a defined retention period, and is protected by the measures described in this Policy. Questions? Contact our Data Protection Officer anytime.

RA 10173 Compliant
NPC Registered
TLS 1.3
AES 256-bit
AMLC Aligned
21+ Enforced

Explore related documents: Terms & Conditions, Responsible Gaming, and FAQ. To access your bm555 account, visit the bm555 Login page. bm555 is for adults 21 years and older only.