Your privacy matters to cataya. This Privacy Policy explains what personal data we collect when you use the cataya platform, why we collect it, how it is used and protected, who it may be shared with, and what rights you hold as a data subject under the Republic Act No. 10173 — the Philippine Data Privacy Act of 2012.
Six principles that govern how cataya handles your personal data
cataya collects only the personal data that is genuinely necessary to operate your account, verify your identity, process transactions, and fulfill our PAGCOR licensing obligations. We do not collect data speculatively or for purposes unrelated to the cataya platform.
All data transmitted between your device and cataya is encrypted using 256-bit SSL/TLS. Personal data at rest is protected by access controls, encryption, and regular security audits. cataya employs technical and organizational measures to prevent unauthorized access, disclosure, or loss.
cataya does not sell, rent, or trade your personal data to third-party marketers or data brokers. Data sharing with third parties occurs only where required for cataya's operational services, as required by Philippine law, or with your explicit prior consent.
Under the Philippine Data Privacy Act, you have the right to access, correct, delete, and port your personal data held by cataya. You may also object to certain processing activities. cataya has a designated process for handling all data subject rights requests.
cataya retains personal data only for as long as required to fulfill the purpose for which it was collected, or as mandated by Philippine law and PAGCOR regulations — typically five years for transaction and KYC records. Data no longer required is securely deleted or anonymized.
This Privacy Policy is governed by the Republic Act No. 10173 (Data Privacy Act of 2012) and its Implementing Rules and Regulations. cataya's privacy practices comply with the requirements of the National Privacy Commission and PAGCOR's licensing conditions.
About This Policy: This Privacy Policy applies to all personal data processed by cataya in connection with your use of the cataya platform at cataya.club, including registration, account management, gaming activity, payment processing, and customer support interactions. By registering a cataya account or using the platform, you acknowledge that you have read and understood this Privacy Policy.
cataya, operating at cataya.club, is the data controller responsible for the personal data of individuals who register and use the cataya platform. As data controller, cataya determines the purposes and means of processing your personal data and is accountable for ensuring that such processing complies with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and all applicable PAGCOR regulatory requirements.
cataya operates under the PAGCOR licensing framework. cataya's data processing activities are subject to oversight by both the National Privacy Commission (NPC) of the Philippines and PAGCOR's regulatory conditions.
For all privacy-related inquiries, requests, and complaints, cataya has designated a Data Protection Officer (DPO). Contact details for cataya's DPO are provided in Section 14 of this Policy.
cataya collects the following categories of personal data from users of the cataya platform:
| Data Category | Specific Data Points |
|---|---|
| Identity Data | Full legal name, date of birth, nationality, government-issued ID number and document image, selfie or liveness verification image (for KYC) |
| Contact Data | Philippine mobile number, email address (if provided) |
| Account Data | Username, encrypted password, account creation date, login history, device fingerprint |
| Financial Data | GCash or PayMaya account reference, bank account reference (BPI, BDO, Metrobank), deposit and withdrawal history, account balance |
| Gaming Activity Data | Games played, bet amounts, game outcomes, session durations, bonus redemption history, responsible gaming tool usage |
| Device & Technical Data | IP address, device type and operating system, browser type, screen resolution, mobile network provider |
| Location Data | Approximate location derived from IP address; precise location if voluntarily enabled via device settings |
| Communications Data | Records of live chat, email correspondence, and SMS communications with cataya support |
| Responsible Gaming Data | Deposit limits set, self-exclusion requests, session timer settings, any problem gambling flags raised |
cataya does not collect sensitive personal information as defined under the Philippine Data Privacy Act (such as health data, religious beliefs, or political affiliations) except where directly required for responsible gaming purposes — for example, where a player voluntarily discloses health-related grounds for a self-exclusion request.
cataya collects personal data directly from you when you: register a cataya account; complete KYC identity verification; make a deposit or withdrawal; participate in any cataya game; contact cataya customer support; respond to a promotion or survey; or update your account settings.
cataya automatically collects certain technical and device data when you access the cataya platform, including IP address, device identifiers, browser type, operating system, session duration, pages visited, and in-game interaction data. This automated collection is necessary for platform security, fraud prevention, and service optimization.
cataya may receive supplementary personal data about you from third-party sources in limited circumstances, including: identity verification service providers used for KYC processing; payment processors (GCash, PayMaya, BPI, BDO, Metrobank) for transaction verification; and fraud prevention and anti-money laundering screening services. Data received from third-party sources is used solely for the purposes described in this Policy.
cataya never purchases personal data lists from data brokers or marketing companies, and does not collect personal data about non-users from social media platforms without direct user consent.
cataya uses the personal data it collects for the following purposes:
Under the Philippine Data Privacy Act, cataya processes your personal data on the following legal bases:
Processing of identity, contact, financial, gaming activity, and account data is necessary for cataya to fulfill its contractual obligations to you as a registered cataya player — specifically, to provide you with access to the cataya platform and process your transactions.
KYC verification, anti-money laundering screening, age verification, and transaction record-keeping are processed on the basis of cataya's legal obligations under PAGCOR licensing conditions, the Anti-Money Laundering Act (Republic Act No. 9160, as amended), and the Data Privacy Act.
Fraud detection, platform security, abuse prevention, and aggregated analytics are conducted on the basis of cataya's legitimate interest in operating a safe, fair, and compliant gaming platform. cataya has assessed that these interests do not override individual data subjects' rights and privacy expectations.
Marketing communications and non-essential cookies are processed on the basis of your explicit, freely given, and informed consent. You may withdraw consent for marketing communications or non-essential cookies at any time without affecting your access to cataya's core services.
cataya shares personal data with carefully selected service providers who assist in operating the cataya platform, including: identity verification and KYC processing providers; payment processors (GCash, PayMaya, BPI, BDO, Metrobank); fraud prevention and anti-money laundering screening services; game studio providers (such as JILI Gaming, Pragmatic Play, Evolution Gaming); cloud hosting and infrastructure providers; and customer support technology platforms. All service providers are contractually bound to process cataya player data only for the specific purpose for which it is shared and in compliance with the Philippine Data Privacy Act.
cataya is required to share certain player data with PAGCOR, the National Privacy Commission, the Anti-Money Laundering Council (AMLC), and other Philippine regulatory authorities as required by law or regulatory direction. cataya will notify affected players of such disclosures where legally permitted to do so.
cataya will disclose personal data to Philippine law enforcement agencies in response to valid legal process, such as a court order, search warrant, or lawful demand from a Philippine law enforcement authority. cataya will not voluntarily disclose player data to foreign law enforcement agencies without proper legal basis under Philippine law.
cataya does not sell, rent, lease, or otherwise commercialize your personal data to third-party marketers, advertisers, or data brokers. This prohibition applies regardless of whether the data is in identifiable or pseudonymized form.
Cross-Border Transfers: Where cataya's service providers operate infrastructure outside the Philippines, personal data transfers are conducted only under binding data transfer agreements that ensure a standard of protection equivalent to or greater than that required by the Philippine Data Privacy Act. cataya does not transfer personal data to jurisdictions without adequate data protection frameworks without appropriate safeguards in place.
cataya uses cookies and similar tracking technologies (including local storage and session storage) on the cataya platform for the following purposes:
You may control non-essential cookies through your browser settings or through cataya's cookie preference center, accessible from the cataya platform. Disabling essential cookies will prevent you from logging in to cataya and accessing the platform. Please review your browser documentation for instructions on managing cookie settings on your specific browser or device.
cataya implements comprehensive technical and organizational security measures to protect your personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction. These measures include:
While cataya takes all reasonable steps to protect your personal data, no internet transmission or electronic storage system is completely secure. cataya cannot guarantee absolute security of data transmitted over public networks.
cataya retains personal data for the following periods, based on the purpose of processing and applicable legal requirements:
| Data Category | Retention Period | Basis |
|---|---|---|
| KYC and Identity Documents | 5 years after account closure | PAGCOR and AMLA requirements |
| Transaction Records | 5 years from transaction date | Philippine Anti-Money Laundering Act |
| Gaming Activity Logs | 3 years from account closure | PAGCOR audit requirements |
| Customer Support Records | 3 years from last interaction | Dispute resolution and legal obligation |
| Marketing Preferences | Until withdrawal of consent + 1 year | Consent record-keeping |
| Security and Fraud Logs | 3 years from log creation | Legitimate interest in platform security |
Upon expiry of the applicable retention period, personal data is securely deleted or irreversibly anonymized. Where data must be retained beyond the standard retention period due to ongoing legal proceedings or regulatory investigation, cataya will extend retention only to the extent necessary and will notify affected data subjects where legally permitted.
Under the Philippine Data Privacy Act of 2012, you have the following rights with respect to your personal data held by cataya. These rights are exercisable by submitting a written request to cataya's Data Protection Officer as described in Section 14.
Request a copy of the personal data cataya holds about you, along with information about how it is being processed and shared.
Request correction of any inaccurate, incomplete, or outdated personal data cataya holds about you, where correction is technically feasible.
Request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to cataya's legal retention obligations under PAGCOR and AMLA requirements.
Object to cataya's processing of your personal data for marketing communications or processing based on legitimate interests. Objection to marketing will be actioned immediately.
Request a copy of the personal data you have provided to cataya in a structured, commonly used, machine-readable format for transfer to another data controller.
File a complaint with cataya's DPO or directly with the National Privacy Commission if you believe cataya has violated your rights under the Philippine Data Privacy Act.
cataya will respond to data subject rights requests within fifteen (15) business days of receipt. In complex cases, cataya may extend this period by a further thirty (30) days and will notify you of the extension with reasons. Requests will be acknowledged within three (3) business days.
The cataya platform is strictly intended for individuals who are 21 years of age or older, as required by PAGCOR regulations. cataya does not knowingly collect, process, or retain personal data from individuals under the age of 21.
cataya employs age verification controls at registration and during KYC processing to prevent underage access. Where cataya discovers that personal data has been collected from an individual under 21, all such data will be deleted immediately, the relevant account will be closed, and deposited funds will be returned.
Parents and guardians who believe a minor has accessed the cataya platform or submitted personal data to cataya should contact cataya's support team or DPO immediately. cataya will treat all such reports with priority and will investigate and resolve all confirmed underage access cases within 48 hours.
The cataya platform may contain references to third-party services — for example, payment providers such as GCash and PayMaya. When you interact with a third-party service in connection with cataya (such as completing a GCash payment), you will be subject to that third party's own privacy policy and terms of service. cataya has no control over and accepts no responsibility for the privacy practices or content of third-party platforms.
cataya recommends that you review the privacy policy of any third-party platform you access in connection with cataya transactions before providing personal data to that platform.
cataya may update this Privacy Policy from time to time to reflect changes in our data practices, applicable law, or PAGCOR regulatory requirements. Where changes are material — meaning they significantly affect how your data is processed or your rights as a data subject — cataya will notify you via the mobile number or email address on your cataya account and display a prominent notice on the platform at least fourteen (14) days before the changes take effect.
Minor updates that do not materially affect data processing (such as clarifications of existing language or correction of typographical errors) may be made without advance notice, though the "Last Updated" date at the top of this Policy will always reflect the most recent revision date.
Your continued use of the cataya platform after the effective date of any updated Privacy Policy constitutes your acknowledgment of the updated terms. If you object to any changes, please contact cataya's DPO or close your account before the effective date of the change.
This Privacy Policy was last reviewed and updated on January 1, 2026. cataya recommends that all registered players review this Policy periodically to remain informed about how their personal data is handled.
For all privacy-related inquiries, data subject rights requests, and complaints, please contact cataya's designated Data Protection Officer through the following channels:
cataya will acknowledge all privacy-related communications within three (3) business days. Complex requests for data access, portability, or erasure will be resolved within fifteen (15) business days, with a possible extension of thirty (30) additional days for particularly complex cases.
If you are not satisfied with cataya's response to a privacy complaint, you have the right to lodge a complaint directly with the National Privacy Commission of the Philippines:
National Privacy Commission (NPC)
3/F Core G, DICT Building, C.P. Garcia Avenue, Diliman, Quezon City
Website: privacy.gov.ph
Contact the NPC directly for complaints that remain unresolved after cataya's internal dispute process.
PAGCOR-licensed, Data Privacy Act compliant, and built for Filipino players. 1,500+ games, GCash payouts, and a team that has your back 24/7.
Log In to cataya