TPN (The Property Network) — Privacy Policy

Effective date: 2026-06-29


1. Who we are and the scope of this notice

This Privacy Policy ("Policy") explains how [LEGAL ENTITY NAME — registered controller entity, to be confirmed] (trading as TPN (The Property Network), "TPN", "we", "us", or "our") collects, uses, discloses, transfers, and otherwise processes personal data in connection with the TPN professional property network — a multiple-listing service (MLS) and co-broking network, agency dashboards and staff management, lead generation, a customer-relationship-management (CRM) tool, and related features made available through our website at https://thaipropertiesnetwork.com, our applications, and our application programming interfaces (together, the "Services").

We are the data controller for the personal data described in this Policy in respect of the TPN professional network — that is, the accounts of agents, agency staff and organizations, and the operation of the co-broking network. This Policy is issued under, and intended to comply with, the Personal Data Protection Act B.E. 2562 (2019) of Thailand (the "PDPA").

The Services are intended for licensed real-estate agents and agencies operating in Thailand and the staff users who belong to those organizations. This is a professional, business-to-business service.

A note on shared infrastructure. TPN, the consumer marketplace "BaanMe", and the white-label "Agent Websites" run on one shared technical backend. Where we process personal data on behalf of an organization that operates its own white-label Agent Website, the organization is the controller and we act as its data processor under a separate Data Processing Agreement; that arrangement is described in the Agent Websites documentation and the Terms of Service, not in this TPN Policy.

Contact details of the controller:

  • Controller: [LEGAL ENTITY NAME — registered controller entity, to be confirmed]
  • Registered office: [REGISTERED OFFICE ADDRESS, Bangkok, Thailand]
  • Privacy contact: [PRIVACY CONTACT EMAIL — e.g. [email protected]]
  • Data Protection Officer (DPO): [DPO / DATA-PROTECTION CONTACT EMAIL — e.g. [email protected]] (the appointment of a DPO under PDPA s.41 is [under review by the operator]; see section 14)

2. The personal data we collect

We collect the categories of personal data set out below. The specific data within each category depends on how you use the Services.

  1. Account identity and credentials — your name, email address (unique), a hashed password, email-verification status, and internal authentication identifiers (user/session IDs, session tokens, an anonymous-guest flag, a token version).
  2. Federated sign-in (OAuth) data — where you sign in with Google or Apple, the access/refresh/ID tokens, your provider account ID, the granted scopes, and the display name and email derived from your provider profile.
  3. Email-verification and one-time tokens — verification and password-reset tokens, organization staff-invitation tokens, and email-alert confirmation/unsubscribe tokens.
  4. Contact details — phone number, LINE ID, WhatsApp/Telegram identifiers, social or contact-method URLs, and organization phone/website.
  5. Agent / agency professional records — staff role and RBAC permissions (read/create/update/delete), organization membership, legal company name, contact persons, invite codes, organization branding, and subscription plan (free / pro / agency).
  6. Property listings and confidential listing data — listing descriptions, specifications, amenities and images, and confidential fields: the listing owner's identifier, internal notes, source link, and unit number; together with rent/sale pricing, commission, and rental-contract terms.
  7. Enquiries — where a property seeker contacts an agent: sender name, email, phone, LINE ID, free-text message, locale, the source product, and the property of interest.
  8. In-app messaging / conversations — message content (text, images, property cards, viewing requests, contact cards, location cards), the participants, read/delivery watermarks, and last-message previews.
  9. Saved properties, projects and searches — saved listing/project IDs, saved-search query strings, and search-subscription filters.
  10. Search and query logs — search query text, an optional user ID, session ID, user-agent, IP address, results metadata and language.
  11. Leads and sales-CRM contacts — name, phone, email, agency name, role, marketing attribution identifiers (UTM parameters, gclid/fbclid/ttclid), referrer, and CRM pipeline data (stage, notes, follow-up dates, lost reason). This includes leads distributed from the consumer marketplace to TPN agents.
  12. KYC identity-document images — a selfie photo and an ID-card image submitted during agent identity verification, and the submission timestamp. Sensitive data — see section 4.
  13. Passport / machine-readable-zone (MRZ) identity data — first/middle/last name, date of birth, passport number and expiry, sex, nationality, the passport image, and an MRZ-valid flag, used to pre-fill official documents. Sensitive data — see section 4.
  14. Profile and user-uploaded images — profile pictures, property listing images, and blog/content images.
  15. Reviews and ratings — author display name, rating (1–5), structured ratings, the review target (agent/project/region), and any review reports.
  16. Product-analytics event stream — events such as page views, property views, searches and contact-initiated actions, together with an anonymous ID, distinct ID, optional user ID, session ID, path and referrer, app/device/screen/locale/timezone/connection details, raw IP address (and a hashed IP), user-agent (raw and parsed), and approximate geolocation (country/region/city).
  17. Marketing attribution and advertising identifiers — UTM parameters; click identifiers (gclid, fbclid, ttclid, li_fat_id, msclkid, gbraid, wbraid); referrer; first-touch/last-touch attribution; and, in our mobile apps, the device advertising identifier (after you grant App Tracking Transparency permission) and install-attribution context.
  18. Hashed PII for advertising conversions — SHA-256 hashed email, phone, name, city, country and a hashed external user ID, generated to match advertising conversions (see sections 5, 7 and 8).
  19. Consent and opt-out records — your consent-state cookie value (unknown / accepted / rejected), your stored consent state and decision time, analytics opt-out records, and your App Tracking Transparency decision.
  20. Push tokens and notification-delivery records — push notification tokens, platform, app brand and device ID, and a notification ledger (recipient address, channel, status, provider message ID, payload).
  21. Geolocation — precise device location (only where you grant location permission in our mobile apps) and coarse, IP-derived location (country/region/city).
  22. Diagnostics / crash and performance telemetry — crash stack traces, performance traces, app/OS/device details, and request IDs; we may associate this with your identity after you sign in.
  23. AI-derived data — image style embeddings, room/amenity classifications and feedback, property-deduplication match candidates, bill-OCR extracted fields, and passport-MRZ extraction.
  24. PII access audit log — an internal record of staff access to personal data (the user accessed, the reason, a query hash, the row count, and the time).

We collect this data: from you (when you register, create listings, submit enquiries or content, or upload documents); from third parties (your Google/Apple sign-in provider); and automatically (analytics events, logs, cookies, device signals, and IP-derived geolocation).


3. Purposes of processing and lawful basis

Under the PDPA, every purpose must rest on a lawful basis (s.24), with consent (s.19) used for analytics and advertising and explicit consent for sensitive data (s.26). The table below maps our purposes to the categories of data, the lawful basis we rely on, and the retention period. Where a retention period is not yet fixed, it appears as a bracketed placeholder and is an open item for our review (see section 12).

The lawful-basis determinations below are first-draft positions and are subject to confirmation by Thai-qualified counsel. Thailand does not read "legitimate interest" as broadly as some other jurisdictions; where we rely on it we maintain a documented balancing assessment.

PurposeData categoriesLawful basisRetention
Create and secure your account; authenticate you; manage sessions; password reset; link guest data to your accountAccount identity & credentials; OAuth data; verification/one-time tokensPerformance of a contract (s.24)Until account deletion; soft-deleted then hard-deleted after a 30-day recovery window; tokens expire at their TTL
Operate the agency dashboard, staff management and RBAC; maintain agent/agency professional recordsAgent/agency professional records; contact detailsPerformance of a contract; legitimate interest (operating the professional network)For the life of the organization account; then per [ORGANIZATION-RECORD RETENTION PERIOD — to be confirmed]
Listing management and co-broking shared-inventory display across the networkProperty listings & confidential listing data; profile/uploaded imagesPerformance of a contract; legitimate interest (operating the co-broking network)[LISTING RETENTION PERIOD — to be confirmed]
Deliver enquiries to the listing agent/organization; in-app messaging; BaanMe→TPN lead distribution and CRM follow-upEnquiries; in-app messaging; leads & CRM contacts; contact detailsPerformance of a contract; legitimate interest (connecting seekers and agents)[ENQUIRY / MESSAGE / LEAD RETENTION PERIOD — to be confirmed]
Saved searches and new-match alert subscriptionsSaved properties/projects/searches; push tokens; contact details; consent recordsPerformance of a contract; consent (for the alert channel)Until you unsubscribe or delete your account
Search quality, relevance, analytics and debuggingSearch & query logsLegitimate interest (operating and improving search)[SEARCH-LOG RETENTION PERIOD — to be confirmed]
First-party product analytics and funnel/conversion measurementProduct-analytics event stream; marketing attribution; consent recordsConsent (s.19) for non-essential analytics[ANALYTICS-EVENT RETENTION PERIOD — to be confirmed; events are monthly-partitioned, lifecycle undefined in code]
Advertising conversion measurement via Meta, Google and TikTokHashed PII for advertising conversions; marketing attributionConsent (s.19)Forwarded to the advertising platforms (separate controllers); retained by us per [AD-EVENT RETENTION PERIOD — to be confirmed]
Agent identity verification (KYC)KYC identity-document imagesExplicit consent (s.26); supported by contract / legal-compliance considerations (to be confirmed)[KYC IMAGE RETENTION PERIOD — to be confirmed]
Passport scan to pre-fill official documents (e.g. visa forms, rental contracts)Passport / MRZ identity dataExplicit consent (s.26) — captured at the time of each writeUntil the first of: your deletion of the passport, deletion of your account, or expiry of the configured maximum retention period. The stored image is purged before the record is deleted; a storage failure leaves deletion retryable.
Reviews and ratings of agents, projects and regionsReviews & ratingsPerformance of a contract; legitimate interest (reputation in the network)[REVIEW RETENTION PERIOD — to be confirmed]
Push and multi-channel notifications, alerts and digestsPush tokens & notification-delivery records; contact details; consent recordsConsent; performance of a contract; legitimate interestPush tokens until revoked; notification ledger per [NOTIFICATION-LOG RETENTION PERIOD — to be confirmed]
Nearby-property search and default region detectionGeolocationConsent (precise location); legitimate interest (coarse IP geo)Not stored beyond the request, except geo recorded in analytics events
Error monitoring, debugging and performanceDiagnostics / crash & performance telemetryLegitimate interest (service reliability and security)[DIAGNOSTICS RETENTION PERIOD — to be confirmed]
AI features: gallery grouping, similar-listing search, deduplication, document pre-fillAI-derived data; and the underlying listing/bill/passport dataLegitimate interest; consent / explicit consent where the underlying data is consent-based or sensitiveTied to the underlying records
Recording and honouring consent / opt-outConsent & opt-out recordsLegal obligation; consent record-keepingConsent cookie 1 year; consent state retained on your account record
Internal audit of staff access to personal dataPII access audit logLegal obligation; legitimate interest (security and accountability)[AUDIT-LOG RETENTION PERIOD — to be confirmed]
Operational awareness (a new-signup notification sent to an internal Telegram channel containing the new user's name and email)Account identity & credentials[Legitimate interest — under review; see section 8 and the open-items disclosure]Held in the third-party messaging history

Where a basis is contract, providing the data is necessary to use the relevant feature, and you cannot use that feature without it. Where a basis is consent, providing the data is optional and you may decline or withdraw without losing access to the core Services (you will simply not receive the optional feature, such as analytics or advertising measurement).


4. Sensitive personal data (PDPA s.26)

Some processing involves sensitive personal data, which the PDPA protects with heightened requirements. On TPN this includes:

  • Agent KYC verification images — the selfie photo and ID-card image you submit during agent identity verification. We rely on your explicit consent for this processing (the precise s.26 basis and whether the facial image is treated as biometric data are open items for counsel — see section 14). When you submit, the ID image is processed by our OCR partner (OpenRouter / Qwen vision models) to read the name and document number, which an administrator then confirms. We delete the ID and selfie images once your verification is reviewed, and keep only the confirmed name and document number — encrypted — as a minimal verification record (see section 12).
  • Passport / MRZ identity data — collected only with your explicit consent, captured at the time of each submission, to pre-fill official documents.

Safeguards specific to these documents. Sensitive images (KYC selfie/ID and passport images) are stored in a separate, private object-storage bucket; they are never made public and never processed into public image variants. Internal access is routed through an access-controlled proxy that serves them with private, no-store caching, behind a restricted internal network. You may withdraw your consent and request deletion of these documents at any time (see sections 11 and 12).

We do not intentionally collect other special categories of data (such as racial or ethnic origin, political opinions, religious beliefs, health, sexual behaviour, or trade-union membership). Please do not submit such data in free-text fields, listings, messages or reviews.


5. Cookies and similar tracking technologies

We use cookies and similar technologies. Non-essential trackers do not fire before you give consent.

Strictly necessary (always on; no consent required):

  • Session cookie — keeps you signed in (signed; SameSite=Lax; Secure in production; host-only).
  • OAuth state cookies — protect the Google/Apple sign-in flow against cross-site request forgery.
  • Consent cookie (pl_consent) — stores your analytics/advertising consent decision (unknown / accepted / rejected) for up to 1 year.

Non-essential (only after you accept; you can decline or withdraw):

  • Anonymous-ID and attribution cookies — used for analytics identity stitching and first-/last-touch marketing attribution.
  • Product-analytics SDK (PostHog) — first-party product analytics; the analytics client is constructed in a disabled state and only activates on an explicit "accept", and events are dropped on "reject".
  • Advertising / consent-mode tags (Google Consent Mode v2 wiring; advertising-platform measurement) — default to denied until consent is granted.
  • Mobile install-attribution SDK and the device advertising identifier — in our mobile apps, install-attribution tracking and the advertising identifier are gated behind the iOS App Tracking Transparency (ATT) prompt and equivalent controls; they do not run unless you allow tracking.

You can change or withdraw your consent at any time using the consent controls in the app/site (which reset the pl_consent decision), the in-app analytics opt-out, and — on iOS — your device's tracking settings.


6. Automated processing and profiling

We use automated processing in the following ways:

  • Advertising conversion matching and retargeting (profiling; consent-based) — when you have consented, hashed identifiers and certain behavioural events are shared with Meta, Google and TikTok to measure advertising conversions and, through those platforms, to build audiences and retarget. You may object to this at any time by withdrawing consent (section 11).
  • AI image classification and embeddings — listing images are automatically classified by room/amenity and embedded to power similar-listing search and gallery grouping. This does not produce legal or similarly significant effects on you.
  • Property deduplication — a multi-stage matcher (image, geolocation, unit number, style-embedding plus a model adjudicator) identifies likely-duplicate listings.
  • Lead distribution — consumer leads are broadcast to eligible organizations on a region-scoped basis and atomically claimed by the first responding agent.
  • OCR / MRZ extraction — bill and passport images are read by optical-character-recognition and MRZ parsing to pre-fill fields, which you confirm before use.

None of the operational automation above makes a decision that produces a legal or similarly significant effect on you without human involvement; the advertising profiling is the principal profiling activity and is consent-gated and objectionable. We also generate an aggregate, cookieless daily visitor hash for visitors who have not consented to analytics, which is used only for aggregate counting and does not identify you individually.


7. How and why we disclose personal data

We disclose personal data to the categories of recipients below, only as needed for the purposes in section 3.

  • Other agents in the co-broking network. This is core to TPN. Listings you make available for co-broking — and the associated professional information — are visible to other agents in the network so they can present a shared inventory to clients. Confidential listing fields (owner identifier, internal notes, source link, unit number) are subject to confidentiality controls and are not part of the openly co-broked display; see also the Terms of Service.
  • Property seekers and counterparties you communicate with through enquiries, messaging and lead distribution receive the contact and message data necessary to that interaction.
  • Service providers (data processors) acting on our instructions — see section 8.
  • Advertising platforms (separate controllers) — Meta, Google and TikTok, and (in mobile) Branch — receive hashed identifiers and conversion/attribution data only where you have consented (section 8).
  • Operational messaging — at present, a new-signup notification containing the new user's name and email is sent to an internal Telegram channel for operational awareness. We disclose this transparently; it is an open item under review, and we are evaluating restricting or discontinuing it (see section 14).
  • Authorities, legal and corporate — we may disclose personal data where required by law, to respond to lawful requests, to protect our rights or the safety of others, or in connection with a corporate transaction, in each case as permitted by the PDPA.

We do not sell your personal data.


8. Service providers, advertising recipients and other third parties

We engage the third parties below. For each, we work towards a written Data Processing Agreement where the party is our processor; the existence and status of each agreement is an open item we are confirming (section 14). Several recipients are located outside Thailand — see section 9.

Processors (acting on our instructions):

  • Cloudflare — object storage (including the private bucket for sensitive images), bot-protection (Turnstile), IP-based geolocation, and content delivery.
  • PostHog (United States) — first-party product analytics; receives analytics events including IP and approximate geolocation (for consented users).
  • Resend (United States) — transactional email (verification, password reset, alerts, notifications).
  • Sentry — crash diagnostics, traces and performance monitoring; may include identity after sign-in.
  • Expo Push (United States) — push-notification delivery.
  • DashScope / Alibaba Cloud — Qwen models (China) — text and image embeddings.
  • OpenRouter (United States gateway) — LLM gateway for listing descriptions, alt text, image embeddings and identity-document OCR (extracting the name and document number from the ID image you submit for agent verification, via Qwen vision models).
  • z.ai / Zhipu — GLM (China) — website-builder chat and blog/SEO generation.
  • Anthropic / OpenAI (United States) — AI tooling and operational assistants (read-only operational queries that may incidentally touch personal data).
  • Slack (United States) — optional internal operations tooling.
  • MapLibre / MapTiler / PMTiles — map rendering and tiles.

Separate controllers (govern your data under their own privacy policies; consent-gated where applicable):

  • Meta (Conversions API), Google Ads (Enhanced Conversions), TikTok (Events API) — receive SHA-256 hashed email/phone/name/location, a hashed external user ID, click identifiers and conversion events, only where you have consented, for advertising conversion measurement and audiences.
  • Google (Sign-In, Maps/geocoding, Consent Mode/GA wiring) and Apple (Sign in with Apple) — for the features you choose to use.
  • Branch (United States) — mobile install attribution and deep linking; the device advertising identifier is shared only after ATT permission.
  • Telegram, LINE / WhatsApp — messaging channels (Telegram is also used for the operational signup notification described in section 7; LINE/WhatsApp for notification channels and agent–client contact).

Other third parties: an external subscriptions/billing provider processes organization-subscription billing (provider [BILLING PROVIDER — to be confirmed]); and SEO data sources used in our back-office tooling do not process RealtyTable-user personal data.


9. International transfers of personal data

Operating the Services involves transferring personal data outside Thailand, including to:

  • the United States (Cloudflare, PostHog, Meta, Google, Apple, TikTok, Sentry, Expo, OpenRouter, Anthropic/OpenAI, Resend, Slack, Branch);
  • China (DashScope/Alibaba — Qwen — for embeddings; z.ai/Zhipu); and
  • Singapore, Thailand and other regions (LINE).

Thailand has no published adequacy ("white") list. We therefore do not rely on an adequacy decision. Instead, for each transfer we rely on an appropriate lawful mechanism under PDPA ss.28–29, which may include: your informed consent after being told that the destination may not provide a level of protection equivalent to Thailand's; necessity for the performance of a contract with you or in your interest; or appropriate safeguards such as standard contractual clauses (based on the ASEAN or EU model clauses, adapted with Thai-specific obligations, including 72-hour breach reporting by the data importer) or binding corporate rules.

The specific mechanism per destination/vendor — and any overlap with the EU/UK GDPR (for EU/UK data subjects) or China's PIPL (for the China-hosted AI vendors and for any mainland-China users) — is an open item we are confirming with counsel (section 14). Transfers to China of bill/identity-adjacent and listing data are treated as high-attention.

You may request more detail about the mechanism applicable to a particular transfer using the contact in section 16.


10. How we protect personal data

We apply organisational and technical measures appropriate to the risk, including:

  • hashed passwords and signed session tokens;
  • host-only session cookies scoped per brand, Secure in production;
  • SHA-256 hashing of personal identifiers before transmission to advertising platforms;
  • a separate private object-storage bucket for sensitive images (KYC, passport, bills) that is never public and never processed into public variants, served only through an access-controlled proxy with private, no-store caching behind a restricted internal network;
  • an analytics database view that excludes raw IP and raw user-agent, with the default analytics-reader role limited to that view;
  • a daily-rotating, salted, cookieless visitor hash for non-consented analytics, with raw IP/user-agent not stored for those events;
  • an internal PII access audit log;
  • bot-protection (Cloudflare Turnstile) on email sign-in/sign-up;
  • double opt-in for email alert subscriptions;
  • application-level rate limiting;
  • payment-webhook signature verification and idempotency, with return-URL parameters never trusted (server-to-server confirmation);
  • soft-delete plus a scheduled hard-delete worker for account erasure; and
  • encryption in transit (HTTPS) for external vendor calls.

We describe only the measures we have verified. We do not currently assert encryption-at-rest or multi-factor authentication for our datastores; the status of those controls, and the physical hosting region of our databases and storage, are open items (section 14). We will update this section as those controls are confirmed.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.


11. Your rights under the PDPA

Subject to the conditions and exceptions in the PDPA, you have the right to:

  1. Access your personal data and obtain a copy.
  2. Rectify inaccurate, out-of-date or incomplete data.
  3. Erase, destroy or anonymise your data.
  4. Restrict processing.
  5. Data portability — receive certain data in a machine-readable form and have it transmitted where technically feasible.
  6. Object to processing, including direct marketing and advertising profiling.
  7. Withdraw consent at any time, as easily as you gave it.
  8. Lodge a complaint with the Office of the Personal Data Protection Committee (PDPC) in Thailand.

How these work in practice today:

  • Erasure is implemented: deleting your account triggers a soft-delete followed by a hard-delete after a 30-day recovery window, which cascades to dependent personal data; your passport data can be deleted independently.
  • Objection / withdraw consent is implemented through the consent controls, the analytics opt-out, and iOS App Tracking Transparency; advertising forwarding is gated on accepted consent.
  • Rectification is available by editing your profile and records.
  • Access, portability and restriction are not yet self-service. To exercise these — or any right above — contact us at [PRIVACY CONTACT EMAIL] and we will handle your request through our privacy team.

We will respond without undue delay, normally within 30 days. We may need to verify your identity before acting. Exercising a right is free unless a request is manifestly unfounded or excessive.


12. Data retention

We keep personal data only as long as necessary for the purposes in section 3, after which we delete or anonymise it. Concrete periods we currently apply:

  • Account data — until deletion; soft-deleted then hard-deleted after a 30-day recovery window.
  • Agent KYC verification record (TPN agents, partners and developers) — the ID/passport and selfie images are deleted once your verification is reviewed. The confirmed name and document number are kept encrypted as a minimal verification record and are retained even after you delete your account, to prevent fraud and re-registration by barred agents, partners and developers (lawful basis: our legitimate interest in fraud prevention and platform integrity). BaanMe consumer accounts have no such record and are fully erased.
  • Consent decisionpl_consent cookie up to 1 year; consent state retained on your account record.
  • Session and verification tokens — until they expire (token TTL).
  • Push tokens — until revoked (logout or de-registration).
  • Passport / MRZ data — until the first of your deletion of the passport, deletion of your account, or expiry of the configured maximum retention period; storage is purged before the record and failures remain retryable.

For other categories — listings, enquiries, messages, leads/CRM, reviews, search and query logs, diagnostics, the audit log, and the analytics event stream (which is monthly-partitioned with a lifecycle not yet fixed) — we have not yet finalised a retention schedule. These appear as bracketed placeholders in the section 3 table and are an open item we are completing with counsel (section 14). Where no period is fixed, we retain data for as long as your account is active and the purpose persists, and review periodically.


13. Children

The Services are intended for professional users — licensed real-estate agents and agency staff — and are not directed to children. We propose a minimum age of [18 — to be confirmed] for a professional account, and we do not knowingly collect personal data from children below the applicable age without the consent of a parent or guardian where the PDPA requires it. The minimum-age position and whether any age-verification step is required are open items for counsel (section 14). If you believe a child has provided us personal data, contact us and we will take appropriate steps.


14. Open items under review

In the interest of transparency, the following are not yet finalised and are being confirmed with qualified Thai counsel. They do not reduce your rights:

  • the registered legal entity / controller name, registered address, privacy contact, and DPO appointment under PDPA s.41 (given large-scale behavioural monitoring and sensitive-data processing);
  • the sensitive-data (s.26) basis and classification for KYC ID/selfie images (including whether facial images are biometric) and passport/MRZ data;
  • the cross-border transfer mechanism for each US, China and Singapore destination, and any GDPR/UK GDPR or PIPL overlap;
  • retention periods for most data categories and the analytics-event partition lifecycle;
  • encryption-at-rest status for our datastores, multi-factor authentication, and the physical hosting region;
  • the external subscriptions billing provider;
  • the minimum-age / children position and whether an age gate is needed;
  • the existence and scope of Data Processing Agreements with each vendor; and
  • the operational Telegram signup notification of name and email — whether to restrict (e.g. internal-only, minimised) or discontinue it.

15. Data breaches

If a personal-data breach occurs, we will act in line with PDPA s.37(4): we will notify the PDPC without undue delay and, where feasible, within 72 hours of becoming aware of it (and, where that deadline cannot be met for unavoidable reasons, no later than the period the PDPA allows, with justification). Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay and describe the mitigation steps.


16. Contact us and complaints

For any privacy question or to exercise your rights:

  • Privacy contact: [PRIVACY CONTACT EMAIL — e.g. [email protected]]
  • Data Protection Officer: [DPO / DATA-PROTECTION CONTACT EMAIL]
  • Controller: [LEGAL ENTITY NAME — registered controller entity, to be confirmed]
  • Registered office: [REGISTERED OFFICE ADDRESS, Bangkok, Thailand]

You also have the right to lodge a complaint with the Office of the Personal Data Protection Committee (PDPC), Thailand, if you believe our processing infringes the PDPA.


17. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new effective date and, where the changes are material, take reasonable steps to notify you (for example by email or an in-app notice). Your continued use of the Services after an update takes effect constitutes acknowledgement of the updated Policy, to the extent permitted by law; where the law requires fresh consent, we will obtain it.

Effective date: 2026-06-29