Skip to content
Ruk-Com Cloud
  • Cloud
    Compute & Platforms
    Cloud IaaSCloud servers for business workloads
    VPS HostingVPS with a hosting control panel
    Private CloudDedicated cloud for your organization
    Cloud PaaSDeploy and scale applications
    Managed KubernetesRun containers on Kubernetes
    Storage & Databases
    Block StorageDisks for cloud servers
    Object StorageFile storage via an S3-compatible API
    Managed DatabasesDatabases with managed operations
    Network & Datacenter
    VPC NetworkingPrivate networking for cloud workloads
    Load BalancersDistribute traffic across backends
    Datacenter & ColocationServer colocation and connectivity
    View all products & services ↗
  • Hosting
    Hosting & WordPress
    Web HostingHosting for business websites
    Managed WordPress HostingManaged hosting for WordPress
    WordPress CareOngoing WordPress care
    WordPress Web DesignDesign and build WordPress websites
    Domains & Business Email
    Domain ManagementDomain registration and DNS
    Enterprise EmailEmail on your business domain
    Google WorkspaceGmail · Drive · Meet
    Microsoft 365Office · Teams · OneDrive
    Content Delivery
    Global CDNDeliver content closer to visitors
    Live StreamingOnline live video delivery
    View all products & services ↗
  • AI & GPU
    AI Infrastructure
    GPU InstancesGPU compute and dedicated servers
    AI & Automation
    Ruk-Com AgentAI assistance for operations and security
    AI / ML ServicesBuild and integrate AI for your business
    View all products & services ↗
  • Security
    Threat Detection
    AI SOC / NOCBring signals together for monitoring
    EASM & Threat IntelExternal exposure and threat intelligence
    VA / Pentest & Red TeamAssess vulnerabilities and test attack objectives
    Website & Network Protection
    Managed WAFWeb request filtering and policy care
    DDoS ProtectionDDoS filtering before your servers
    Malware RemovalClean malware from WordPress websites
    View all products & services ↗
  • Services
    Managed Operations
    Managed ServiceSystem operations within an agreed scope
    Consulting & FDECloud · DevSecOps · Cyber Security
    Migration & ConsultingPlan and migrate with our team
    Monitoring & APM
    Monitoring & AlertsWebsite uptime checks and alerts
    APMApplication performance monitoring
    Engineering & Resources
    Dev SupportHelp diagnose and fix website issues
    DevSecOps SolutionIntegrate security into software delivery
    Software DevelopmentCustom software for organizations
    Knowledge BaseComing SoonTechnical guides and articles
    View all products & services ↗
  • Solutions
    By industry
    SME · E-commerceSmall & mid-size businesses
    EnterpriseLarge organizations
    Governmente-Bidding ready, PDPA
    By role
    Developer · DevOpsCI/CD, K8s, IaC ready
    Agency · Web DevReseller, white-label portal
    StartupStart lean, scale fast
All systems operational
ไทยEN
Contact team
Log in

Choose your service

PortalManage services and your account Cloud PaaSManage your Cloud applications
  • All products
  • Cloud Compute & Platforms
    Cloud IaaSCloud servers for business workloads
    VPS HostingVPS with a hosting control panel
    Private CloudDedicated cloud for your organization
    Cloud PaaSDeploy and scale applications
    Managed KubernetesRun containers on Kubernetes
    Storage & Databases
    Block StorageDisks for cloud servers
    Object StorageFile storage via an S3-compatible API
    Managed DatabasesDatabases with managed operations
    Network & Datacenter
    VPC NetworkingPrivate networking for cloud workloads
    Load BalancersDistribute traffic across backends
    Datacenter & ColocationServer colocation and connectivity
  • Hosting Hosting & WordPress
    Web HostingHosting for business websites
    Managed WordPress HostingManaged hosting for WordPress
    WordPress CareOngoing WordPress care
    WordPress Web DesignDesign and build WordPress websites
    Domains & Business Email
    Domain ManagementDomain registration and DNS
    Enterprise EmailEmail on your business domain
    Google WorkspaceGmail · Drive · Meet
    Microsoft 365Office · Teams · OneDrive
    Content Delivery
    Global CDNDeliver content closer to visitors
    Live StreamingOnline live video delivery
  • AI & GPU AI Infrastructure
    GPU InstancesGPU compute and dedicated servers
    AI & Automation
    Ruk-Com AgentAI assistance for operations and security
    AI / ML ServicesBuild and integrate AI for your business
  • Security Threat Detection
    AI SOC / NOCBring signals together for monitoring
    EASM & Threat IntelExternal exposure and threat intelligence
    VA / Pentest & Red TeamAssess vulnerabilities and test attack objectives
    Website & Network Protection
    Managed WAFWeb request filtering and policy care
    DDoS ProtectionDDoS filtering before your servers
    Malware RemovalClean malware from WordPress websites
  • Services Managed Operations
    Managed ServiceSystem operations within an agreed scope
    Consulting & FDECloud · DevSecOps · Cyber Security
    Migration & ConsultingPlan and migrate with our team
    Monitoring & APM
    Monitoring & AlertsWebsite uptime checks and alerts
    APMApplication performance monitoring
    Engineering & Resources
    Dev SupportHelp diagnose and fix website issues
    DevSecOps SolutionIntegrate security into software delivery
    Software DevelopmentCustom software for organizations
    Knowledge BaseComing SoonTechnical guides and articles
  • Solutions SME · E-commerce Enterprise Government Developer · DevOps Agency · Web Dev Startup
Contact team
Log in

Choose your service

PortalManage services and your account Cloud PaaSManage your Cloud applications
  1. Home
  2. Legal
  3. PDPA Rights and Duties Notice
LEGAL · PDPA notice

PDPA Rights and Duties Notice

Last updated 28 Jun 2026
Contents
  1. About this notice
  2. Definitions
  3. The provider
  4. The customer
  5. Categories of personal data
  6. Information security system
  7. Processing on the customer’s instructions
  8. Sub-processors
  9. Assistance with rights and DPIAs
  10. Data breach notification
  11. Cross-border transfers
  12. Audit and demonstrating compliance
  13. Return and deletion of data
  14. Penalties
  15. Contact and submitting your data list

§ 01About this notice

Ruk-Com Co., Ltd. | Applies to Web Hosting, WordPress Hosting, VPS Hosting, Platform as a Service (PaaS) and Infrastructure as a Service (IaaS)

With reference to the Personal Data Protection Act B.E. 2562, Ruk-Com Co., Ltd. (“the company”) attaches importance to complying with the law and to providing material information to its customers. We therefore give notice of the following.

This document applies to every type of company service — Web Hosting, WordPress Hosting, VPS Hosting, Platform as a Service (PaaS) and Infrastructure as a Service (IaaS). Read the service-specific terms for the service you use (see the table in clause 1) together with the general terms in this document. Detailed conditions in the relationship between data controller and data processor follow the company’s Data Processing Agreement (DPA).

§ 02Definitions

ProviderRuk-Com Co., Ltd.
CustomerA user of the company’s services, whether an individual or a legal entity
End customerA user of the customer’s services (the third-party data subject whose personal data the customer stores)
Sub-processorAnother processor appointed by the company to process personal data on its behalf in order to deliver the service

§ 03The provider

1.1 The company provides the service type the customer selects. The nature of each service is as follows:

ServiceNature of the service
Web Hosting / WordPress HostingHosting the customer’s website on the provider’s servers so that it stays online 24 hours a day. Website files, databases, email and similar data are stored on the web server, which serves website pages to visitors through the domain name at all times.
VPS HostingA virtual private server that the customer administers themselves, so that the customer’s service stays online 24 hours a day.
Platform as a Service (PaaS)A platform for software and application developers where the provider prepares and maintains the infrastructure, operating system and required resources — such as database servers and web applications — so the customer can focus on developing and managing their own applications and data.
Infrastructure as a Service (IaaS)Compute infrastructure delivered as virtual resources — CPU, memory, storage and networking — where the customer installs and manages the operating system, software and applications entirely themselves.

1.2 The provider has the duties and responsibilities of a “data processor” under the Personal Data Protection Act B.E. 2562. The company maintains security measures by service type as follows:

ServiceMeasures provided
Web / WordPress / VPS HostingA Web Application Firewall (WAF) whose rules are updated regularly, and vulnerability assessment at least once a week.
Platform as a Service (PaaS)Security of the servers, operating system/platform, network and connectivity.
Infrastructure as a Service (IaaS)Security of the physical infrastructure, virtualization layer and core network. The customer is responsible for security from the operating system upwards.
All of the company’s services run on enterprise-grade equipment in high-standard data centres located in Thailand and Singapore.

1.3 The company cannot access, view and/or know what the customer has uploaded, imported and/or stored on its servers, and cannot view the confidential, business or commercial data or any other data of the customer’s own end customers, because that data is under the customer’s control. The company does not use such data for other purposes — in particular advertising or marketing — unless the customer consents or the law requires it.

§ 04The customer

2.1 The customer has the duties and responsibilities of a “data controller” under the Personal Data Protection Act B.E. 2562, because the customer decides about the personal data brought into the company’s services for storage or processing. It is therefore the customer’s own duty to comply with the Personal Data Protection Act B.E. 2562 and/or other applicable regulations and laws.

2.2 The customer must control their own end customers’ data and is responsible for maintaining appropriate security standards for the nature of their own service, including but not limited to data classification, encryption, access rights management, data risk assessment, appointing data custodians, and authentication to maintain security.

For VPS Hosting, Platform as a Service (PaaS) and Infrastructure as a Service (IaaS) only: because the customer administers the system themselves, the security standard required depends on how the customer designs their own processes and service procedures.

2.3 The customer must send the company the types and list of data they have brought into the service, identifying the data type by the numbers defined in clause 3, certified by the customer’s data controller.

2.4 The customer warrants that collecting personal data and instructing the company to process it under the service rests on a lawful legal basis, and is responsible for the lawfulness of the instructions given to the company for processing.

§ 05Categories of personal data

Category 1

  • Name, surname, nickname
  • National ID number, passport number, social security number, driving licence number, taxpayer identification number, bank account number, credit card number (including images of ID card copies or other card copies showing personal data)
  • Address, email, phone number

Category 2

  • Device or tool data such as IP address, MAC address, cookie ID
  • Biometric data such as facial images, fingerprints, X-ray films, iris scans, voice identity data and genetic data
  • Data identifying a person’s assets, such as vehicle registration and land title deeds
  • Data that can be linked to the above, such as date of birth, place of birth, ethnicity, nationality, weight, height, location data, medical data, education data, financial data and employment data
  • Reference numbers stored on microfilm
  • Performance appraisals or an employer’s opinions on an employee’s work
  • Records used to track and audit a person’s activity, such as log files
  • Data used to search for other personal data on the internet

Category 3

  • Ethnicity and race
  • Gender
  • Groups, affiliations and demographic groups
  • Family, relatives and friends
  • Physical characteristics
  • Knowledge and beliefs
  • Data or references and preferences
  • Assets and ownership of assets
  • Physical and mental health
  • Financial status
  • Occupation
  • Personal behaviour
  • Activities and associations
  • Sports and recreation
  • Personality
  • Membership of groups, clubs and activities

Category 4 — sensitive personal data

  • Political opinions
  • Cult, religious or philosophical beliefs
  • Sexual behaviour
  • Criminal records
  • Health and disability data such as underlying conditions, vaccinations and medical certificates
  • Trade union data

Category 5 — data that is not personal data

  • Company registration numbers
  • Business contact details that do not identify an individual — for example work phone and fax numbers, office addresses, work email and company email such as [email protected]
  • Anonymous data, pseudonymous data and data technically rendered no longer able to identify an individual
  • Data about deceased persons
  • Data about legal entities

§ 06Information security system

Security and legal compliance are a shared responsibility between the company and the customer, divided as follows:

Security OF the cloudSecurity IN the cloud
The provider is responsible for operating, managing and controlling the hosting operating system, the network, the control systems for customers, and the physical security of the data centre.The customer is responsible for managing their own virtual machines and/or containers, including the operating system running on them (updates and security patches), software and applications, firewall and security configuration, connections to their own IT systems, and compliance with applicable law.

The scope of responsibility at each layer differs by service type, as shown below (R = provider responsibility, C = customer responsibility):

LayerWeb / WordPressVPSPaaSIaaS
Data and content in the system/database²CCCC
ApplicationCCCC
Runtime / Middleware / Database Engine³RCRC
Operating system (OS)RC¹RC
VirtualizationRRRR
NetworkRRRR
Physical infrastructureRRRR
Notes: ¹ For VPS Hosting the customer manages the operating system, unless they purchase a Managed add-on (such as DirectAdmin), in which case the provider helps within the agreed scope. ² Data and content in the database that the customer creates or imports (tables, records, data structures and the data itself) is the customer’s responsibility across every service type. ³ The database engine means the database software/service (such as MySQL/MariaDB) that keeps the system running, including installation, updates and patching — for Managed services (Web/WordPress/PaaS) the provider keeps “the service working”, while the data inside remains the customer’s under note ². In summary, the more the customer controls the system (VPS, IaaS), the more security responsibility falls on the customer.

The security measures the company provides include:

4.1 Web Application Firewall (WAF) — for Web / WordPress / VPS Hosting

A standard system for filtering traffic, monitoring and blocking anomalous HTTP/HTTPS traffic sent to the customer’s web application, and for preventing data leaking out of the application. It works as a reverse proxy so that threatening traffic cannot reach the internal data of the web application server.

Exception for VPS Hosting: where the customer chooses to install only an operating system, has not purchased the DirectAdmin add-on from the provider, and/or accesses or changes the VPS configuration themselves with the highest system privileges (root), WAF protection may not apply.
Note: a Web Application Firewall only provides baseline protection rules and cannot guarantee 100% protection against attacks, because each customer’s application differs — including but not limited to the development team, how it works, the system design and third-party components such as CMS, frameworks, plugins, themes and libraries, as well as different usage patterns.

4.2 Vulnerability assessment

An initial risk assessment of vulnerabilities found in the operating system, software or network/security devices — identifying which vulnerabilities exist and how severe they are, so they can be fixed and closed.

4.3 Restricting employee access

Access to data is tiered according to each employee’s duties, with confidentiality agreements in place. The personnel involved have a duty of confidentiality that continues after they leave, and receive training so they are aware of their duty to protect personal data.

4.4 The information security team

The company has staff holding the ICDL Personal Data Protection certificate from the International Computer Driving Licence, referenced to European Union standards, namely:

  • Data Protection Officer (DPO) — the officer who oversees and protects all personal data in the organisation, both internal and external, with duties from preparing, controlling, auditing, collecting and storing data under the law to coordinating with the Personal Data Protection Committee when issues arise.
  • Data Processor — the officer who processes personal data solely under the instructions of, or on behalf of, the data controller.

4.5 Standards and management framework

The company’s technical and organisational measures align with an Information Security Management System (ISMS) and a Privacy Information Management System (PIMS), referencing ISO/IEC 27001 and ISO/IEC 27017 / 27018 / 27701. These cover at least access control and authentication (including multi-factor authentication for privileged access), encryption in transit and at rest as appropriate, segregation of each customer’s data in shared environments, logging and monitoring, vulnerability and patch management, backup and recovery, and business continuity management. The company reviews and improves these measures periodically so they remain appropriate to changing risks.

§ 07Processing on the customer’s instructions

5.1 The company processes the personal data the customer brings into the service only on the customer’s written instructions (including instructions set out in the service contract and the data processing agreement) and only for the purposes of providing the service, unless required by law — in which case the company informs the customer beforehand unless the law prohibits such notice.

5.2 The company does not process personal data for its own purposes and does not use it for marketing or advertising, unless instructed or explicitly consented to by the customer, or required by law.

5.3 If the company considers that an instruction from the customer may conflict with data protection law, it informs the customer without delay and may suspend that instruction until it receives written confirmation or a corrected instruction. Responsibility for the lawfulness of the instruction remains with the customer as data controller.

§ 08Sub-processors

6.1 To deliver the service, the company may appoint sub-processors to process personal data on its behalf. The company contracts with sub-processors in writing, imposing data protection duties equivalent to its own, and remains liable to the customer for the acts or omissions of its sub-processors as if they were its own.

6.2 The list of approved sub-processors at present is:

No.Sub-processorService / productData locationCertifications / transfer mechanism
1Microsoft Corporation (EEA: Microsoft Ireland Operations Ltd)Microsoft 365 — email / files / collaborationGlobal / region selectableISO 27001/27017/27018/27701; SOC 1/2/3; SCCs in the DPA
2Google LLC (EEA: Google Ireland Ltd)Google Workspace — email / files / collaborationGlobal / data regions US, EUISO 27001/27017/27018/27701; SOC 2/3; SCCs in the DPA
3Ruk-Com Co., Ltd.Cloud Hosting / Email / VPS (as actually used)Thailand / SingaporeISO 27001; DPA
Note: the list above is current as at the date of preparation and may be updated from time to time.

6.3 Where the company wishes to add or change a sub-processor, it notifies the customer at least 30 (thirty) days in advance. The customer may object to the change on reasonable data protection grounds by giving written notice within 14 (fourteen) days of being notified. If the parties cannot reach a resolution, the customer may suspend or terminate the affected part of the service under the conditions of the service contract.

§ 09Assistance with rights and DPIAs

7.1 If a data subject (the customer’s own end customer) submits a rights request directly to the company, the company forwards it to the customer without delay and does not respond to it itself, unless instructed by the customer or required by law.

7.2 The company provides the customer with reasonable assistance through appropriate technical and organisational measures so the customer can meet data subject rights requests (such as access, rectification, erasure, objection and portability) within the time limits set by law.

7.3 The company provides the customer with reasonable assistance in preparing Data Protection Impact Assessments (DPIAs) and in consulting the Office of the Personal Data Protection Committee, taking into account the nature of the processing and the information available to the company.

§ 10Data breach notification

8.1 When the company becomes aware of a personal data breach involving the customer’s data, the company as data processor notifies the customer (the data controller) without delay and no later than 48 (forty-eight) hours after becoming aware, so that the customer can notify the Office of the Personal Data Protection Committee within 72 hours under section 37(4) of the Personal Data Protection Act B.E. 2562.

8.2 The notification includes the necessary information known to the company — for example the nature of the incident, the approximate categories and volume of data and data subjects, the possible impact, and the measures taken or proposed. The company cooperates with the customer in investigating and remediating the incident.

§ 11Cross-border transfers

9.1 Personal data may be stored or processed in data centres in Thailand and abroad (for example Singapore), according to the region the customer chooses to use. The customer determines and acknowledges the location of that data.

9.2 Where data is stored or processed abroad, the company puts in place appropriate protection measures under section 28 of the Personal Data Protection Act B.E. 2562 — for example Standard Contractual Clauses (SCCs) or another legally recognised mechanism — and discloses the destination country on request.

§ 12Audit and demonstrating compliance

10.1 The company provides the information reasonably necessary to demonstrate compliance with its data processor duties — for example standards certifications or assessment reports from independent assessors.

10.2 The customer may audit the company’s compliance no more than once a year, with at least 30 days’ written notice, subject to confidentiality, during business hours, and without affecting the data or systems of the company’s other customers — unless a significant breach occurs or the law provides otherwise.

10.3 The company prepares and maintains records of the personal data processing activities carried out on the customer’s behalf, and makes them accessible to the customer on reasonable request.

§ 13Return and deletion of data

11.1 All data and content the customer uploads to or stores on the company’s systems remains the customer’s property. The company claims no ownership of it and accesses it only as necessary to provide the service, maintain the system or comply with the law.

11.2 At the end of the service, the company returns or deletes and destroys the personal data, including copies, on the customer’s instructions within 30 (thirty) days, unless the law requires continued retention. On request, the company issues written confirmation that the data has been destroyed.

§ 14Penalties

Breaching or failing to comply with the Personal Data Protection Act B.E. 2562 carries criminal, civil and administrative penalties as provided by law. Each party agrees to bear the administrative fines or liability arising from its own actions.

§ 15Contact and submitting your data list

If you have questions or want to ask for more information, contact us by email at [email protected] between 9:00 and 18:00.

You may notify and update the data categories under clauses 2.3 and 3 yourself through the company’s portal at https://portal.ruk-com.cloud/ or by email to [email protected] within 30 days of receiving this document. If you do not do so within that period, the company treats the categories of personal data brought into the service as not yet specified and protects the data under its standard measures as far as it is aware. Responsibility for the accuracy and completeness of the data categories rests with the customer as data controller. This does not affect either party’s duties and responsibilities under the law.

Other policies and terms

  • Service terms and conditions
  • Migrating from another web host
  • Service resource usage limits
  • Domain registration agreement
  • Refund terms and process
  • Personal data protection policy
  • Privacy notice for customers and counterparties
  • HR privacy notice for job applicants
  • CCTV privacy notice
  • Affiliate programme terms
  • Service Level Agreement (SLA)
  • Shared responsibility model
Here to support you, 24/7 24/7 hotline · 02-105-4385
Need a hand? Our support team is here to help, 24/7.
02-105-4385Call us LINE @rukcomChat with our team Email us[email protected]
Ruk-Com Cloud

The Thai-grown cloud platform — domains, web design, hosting, cloud and enterprise security, all in one place.

Vanit Place Ari (Building A), Unit 2703, 27th Floor
304 Phaholyothin Rd., Samsen Nai, Phaya Thai, Bangkok 10400
Tax ID · 0105557156771
View all services →

Cloud & AI

  • Cloud IaaS
  • Cloud PaaS
  • Managed Kubernetes
  • GPU Instances
  • Ruk-Com Agent

Hosting

  • Web Hosting
  • Managed WordPress Hosting
  • WordPress Web Design
  • Domain Management
  • Enterprise Email

Security

  • AI SOC / NOC
  • VA / Pentest & Red Team
  • Managed WAF
  • DDoS Protection
  • Malware Removal

Services

  • Managed Service
  • Consulting & FDE
  • Software Development
  • Monitoring & Alerts
  • APM

Standards & trust

  • ISO27001
    ISO 27001Information security
  • ISO27701
    ISO 27701Privacy management
  • ISO20000
    ISO 20000-1IT service management
  • ISO29110
    ISO 29110Software engineering
  • CSASTAR
    CSA STARCloud security
  • PDPA
    PDPAPersonal data protection
© 2026 RUK-COM CLOUD CO., LTD. All rights reserved.
  • Home
  • Contact
  • Terms
  • Privacy
  • SLA
  • PDPA
24 hours · BANGKOK · SINGAPORE