DexoTH

DexoTH Privacy Policy

Version 1 · Effective 8 August 2026

This Privacy Policy explains how Dexo TH Technology Co., Ltd. collects, uses, discloses and protects personal data of platform users under the Personal Data Protection Act B.E. 2562 (2019) ("PDPA"). It covers your PLATFORM ACCOUNT data, for which DexoTH is the Data Controller. Workforce data inside a client company's workspace is governed by that company's own privacy notice (the company is the Data Controller; DexoTH processes it as Data Processor).

11. Data Controller

Dexo TH Technology Co., Ltd. (บริษัท เด็กซ์โซ ทีเอช เทคโนโลยี จำกัด), registration no. 0205569040330, headquartered in Chonburi, Thailand.

Contact for data protection matters: tanawat@dexoth.com

22. Personal data we collect

• Account data — name, work email, password (stored as a secure hash), optional profile photo, language preference.

• Workspace membership data — the tenants you belong to, your role, and your linked employee record where your company links one.

• Usage and security data — sign-in events, device/browser information, IP address, and activity logs kept for security and support.

• Billing contact data — for workspace owners and billing contacts: company, tax ID, billing address and contact details.

• Legal records — your acceptance of the Terms of Service and this Policy (version, date and time), kept as evidence of the agreement.

33. Purposes and lawful bases

• To create and operate your account and provide the Service — performance of a contract (PDPA s.24(3)).

• To secure the platform, prevent fraud and abuse, and keep audit logs — legitimate interests (s.24(5)) and legal obligation (s.24(6)).

• To issue invoices and tax documents — legal obligation.

• To communicate service announcements and support responses — performance of a contract / legitimate interests.

• Marketing communications, if any, are sent only with your consent, which you may withdraw at any time.

We do not use your personal data for automated decision-making that produces legal effects on you, and we do not sell personal data.

44. Controller and Processor roles on this platform

Platform account data (this Policy): DexoTH is the Data Controller.

Customer workforce data inside a client workspace (employee records, training, discipline, performance, etc.): the client company is the Data Controller and DexoTH is the Data Processor acting on its instructions under a Data Processing Agreement. For that data, please refer to your company's workforce privacy notice, available in the platform's PDPA module.

55. Disclosure of personal data

We disclose personal data only to: (a) infrastructure service providers (sub-processors) that host and operate the platform under contracts carrying data-protection obligations — a managed cloud database, authentication and storage provider, and a managed application-hosting provider; (b) professional advisers, auditors, and competent authorities where the law requires; (c) a successor entity in a merger or business transfer, under equivalent protection. A current list of sub-processor categories is available on request.

66. Cross-border transfer

Platform data is hosted on managed cloud infrastructure located in Singapore, with application delivery via a global content-delivery network. Transfers are made under the PDPA's cross-border provisions with appropriate safeguards, including contractual data-protection obligations with our hosting providers and industry-standard encryption in transit and at rest.

77. Retention

Account data is kept for as long as your account is active. After account closure we retain data only as long as necessary for legal obligations, dispute resolution and enforcement of agreements — generally no longer than 10 years for records connected to legal claims, and materially shorter for routine logs.

Terms-acceptance records are retained for the life of the account plus the legal limitation period, as evidence of the agreement.

88. Security measures

We apply appropriate technical and organizational measures: encryption in transit (TLS) and at rest, hashed passwords, role-based access control, tenant isolation, least-privilege administrative access, audit logging and routine backups. Access to personal data is limited to personnel who need it to operate the Service.

99. Your rights under the PDPA

You have the rights to: access and obtain a copy of your data; rectify inaccurate data; erase or anonymize data; restrict or object to processing; data portability; withdraw consent (where processing is based on consent); and lodge a complaint with the Personal Data Protection Committee (PDPC).

To exercise these rights, contact tanawat@dexoth.com. We will respond within 30 days of a verifiable request. Exercising your rights does not affect the lawfulness of processing already carried out.

1010. Cookies and similar technologies

The platform uses strictly necessary cookies and browser storage for sign-in sessions, security, and preferences (such as language). These are required for the Service to function and do not track you across other websites.

1111. Changes to this Policy

We may update this Policy as the Service or the law evolves. The current version and effective date are always published on the platform; material changes will be re-presented for acknowledgement at your next sign-in.