Privacy Policy
§ 01Overview
Ruk-Com Co., Ltd. ("Ruk-Com", "we") values your privacy. This policy explains what personal data we collect, how we use it, who we share it with, and your rights under Thailand's Personal Data Protection Act B.E. 2562 (PDPA).
It applies to ruk-com.cloud, our portal, mobile app, API and related services.
§ 02Data We Collect
2.1 Data You Provide Directly
- Account: name, email, phone, address, tax ID (for businesses).
- Payment: card numbers (via PCI-DSS Level 1 gateways · never stored by us), bank accounts, transfer slips.
- Uploaded content: files, databases, email, logs — retained per service.
- Communication: ticket messages, LINE chats, calls (not recorded).
2.2 Data Collected Automatically
- IP, device, browser, OS, referrer, timestamp.
- Usage: data volume, request counts, resource usage.
- Cookies, sessions, analytics (Google Analytics, Facebook Pixel).
- Security events: login attempts, API calls, file access.
2.3 What We Do NOT Collect
- We do not read customer email/file/database content — except for: (1) court orders (2) automated malware/spam scanning (3) help you explicitly request.
§ 03How We Use Data
We use your data to:
- Provide subscribed services — setup, delivery, monitoring, support.
- Bill, invoice and prevent fraud.
- Notify you of service events: maintenance, downtime, security alerts, renewals.
- Improve services: usage analytics, A/B testing, UX refinement.
- Marketing (opt-in only): newsletters, promos — unsubscribe anytime.
- Comply with law: security logs per Computer Crime Act and PDPA.
§ 04Legal Basis
We process data under these PDPA legal bases:
- Contract: to fulfill our service contract.
- Legal Obligation: taxation, log retention.
- Legitimate Interest: security, fraud prevention, service improvement.
- Consent: marketing, analytics cookies — withdrawable.
§ 05Third-Party Sharing
We share data with third parties only as necessary:
- Payment processors: WHMCS, 2C2P, Omise, Stripe (PCI-DSS).
- Infrastructure: Cloudflare (CDN/WAF), Google (Workspace reseller), Microsoft (M365 CSP).
- Analytics: Google Analytics 4, Facebook Pixel (anonymized).
- Government: per court order or legal requirement.
§ 06Data Location and Transfer
Customer personal data and content are primarily stored in our Bangkok Data Center.
Some services offer Singapore DC as an option — disclosed and chosen by the customer.
Cross-border transfers occur only when necessary (e.g., CDN delivery, anti-spam) and only to destinations with PDPA-equivalent protection.
§ 07Data Retention
- Account data: lifetime of service + 30 days post-termination (recoverable).
- Financial/tax records: 10 years per Accounting Act.
- System logs: 365 days per Computer Crime Act.
- Content backups: 90 days, then auto-deleted.
- Marketing data: until consent is withdrawn.
§ 08Your Rights
Under PDPA you have the right to:
- Access — request a copy of your data.
- Rectification — correct inaccurate data.
- Erasure ("right to be forgotten") — subject to legal limits.
- Restriction — temporarily limit processing.
- Objection — object to certain processing.
- Portability — receive data in machine-readable form.
- Withdraw consent — for marketing and analytics.
Send requests to [email protected]. We respond within 30 days.
§ 09Cookies
We use three cookie types:
- Essential: session, login, security · cannot be disabled.
- Analytics: Google Analytics · disable in cookie banner.
- Marketing: Facebook Pixel, Google Ads · disable in cookie banner.
Manage via our cookie banner or your browser settings.
§ 10Security
We protect data per ISO 27001 · ISO 20000-1 · CSA STAR Level 1, audited annually by external auditors.
- Encryption at rest (AES-256) and in transit (TLS 1.3).
- 2FA for admin access · rotating API keys.
- Network segmentation · firewall · WAF · DDoS protection.
- 24/7 SIEM monitoring · incident response team.
- Daily backups · off-site DR.
- Background checks + NDAs for all staff.
§ 11GDPR Addendum (EU/EEA)
EU/EEA customers have additional GDPR rights, including the right to lodge a complaint with your national Supervisory Authority.
Our Data Protection Officer: [email protected].
§ 12Data Breach Notification
If a breach may affect customers, we notify within 72 hours per PDPA — via email and portal — with incident details, impact and remediation steps.
§ 13Privacy Contact
Data Protection Officer (DPO)
Email: [email protected]
Phone: 02-105-4385
Address: 304 Phaholyothin Rd., Samsen Nai, Phaya Thai, Bangkok 10400, Thailand
If unsatisfied, you may file a complaint with Thailand's Personal Data Protection Committee (PDPC) at pdpc.or.th.