Privacy Policy

Zeroboard (Thailand) Co., Ltd. (“Company”, “we”, “us” or “our”) strongly recognizes the importance of protecting personal data.
The Company establishes and maintains a management system for the protection of personal data in relation to each service provided by the Company, including Zeroboard, Zeroboard ESG, Dataseed SAQ and related services (hereinafter collectively referred to as the “Service”), as well as the Company’s business activities. The Company processes personal data appropriately and carefully in accordance with applicable laws and regulations.

Article 1. Compliance with Laws and Regulations

The Company will comply with the Personal Data Protection Act B.E. 2562 (2019), its subordinate regulations and notifications issued thereunder, and other applicable laws and regulations concerning the processing of personal data, where applicable, collectively referred to as “Applicable Personal Data Protection Laws”.
The Company will also keep its personal data protection management system, security and safeguards, current updated and appropriate.

Article 2. Scope of Application

  1. This Privacy Policy (“Policy”) applies to the use of the Service and to the business activities of the Company in Thailand.
  2. This Policy applies to users of the Service, clients, prospective clients, business partners, employees, former employees, job applicants, shareholders, and other stakeholders collectively referred to as “Users”.
  3. If the Company separately stipulates other provisions concerning the processing of personal data on websites operated by the Company, in other privacy policies, service terms, contracts, or other regulations, such provisions shall also apply. If such provisions conflict with this Policy, the separately stipulated provisions shall prevail to the extent of such conflict.
  4. This Policy does not apply to services provided by third parties, including third-party websites, tools, platforms, applications, or external services used in connection with the Service collectively referred to as “External Services”, or the Service that is provided outside of Thailand. Please refer to the privacy policies separately provided by the providers of such External Services or privacy policies for services provided in such countries.

Article 3. Collection of Personal Data and Retention Period

  1. The Company may collect personal data of Users to the extent necessary for the provision of the Service, the Company’s business activities, compliance with laws or contracts, or the legitimate interests of the Company or other persons.
  2. The Company will collect personal data properly and will not collect it by deceit or other wrongful means. The Company will collect, use, or disclose personal data only where the User has given consent, or where the Company is permitted to do so without consent under Applicable Personal Data Protection Laws. Where consent is required, the Company will inform the User of the purposes of collection before or at the time consent is requested.
  3. The Company may collect the following categories of personal data:
    1. Data provided directly by Users
      The Company may collect information such as name, company name, department, position, email address, telephone number, address, country or region, inquiry details, contact details, transaction history, and any other information that Users voluntarily provide to the Company.

      Where certain personal data is necessary for compliance with laws, performance of contracts, or entering into contracts with Users, failure to provide such personal data may result in the Company being unable to provide the Service, enter into a contract, or perform its legal or contractual obligations.
    2. Data collected automatically through the Service
      The Company may collect the following data when Users access or use the Service:
      • terminal or device information;
      • IP address;
      • browser type and version;
      • operating system;
      • access date and time;
      • log data;
      • action history;
      • usage history of the Service;
      • error logs;
      • cookie identifiers;
      • anonymous identifiers;
      • advertising identifiers;
      • other technical information necessary for maintaining, improving, securing, and analyzing the Service.
  4. Cookies and similar technologies
    The Company may use cookies and similar technologies in the Service or on websites operated by the Company. Cookies are technologies that allow a web server to identify a User’s browser or device.Users may disable cookies by changing their browser or device settings. However, if cookies are disabled, Users may not be able to use all or part of the Service.
  5. Data obtained from External Services
    Where the Service is used in connection with External Services, the Company may collect identifiers used by Users in such External Services and information that Users permit the providers of External Services to disclose, in accordance with the privacy settings of such External Services.
  6. Telephone or online meeting records
    The Company may, with prior notification to attendees, record telephone calls, online meetings, inquiries, interviews, business negotiations, or support communications in order to accurately understand requests, improve services, maintain records, provide support, and ensure service quality.
  7. The Company will retain personal data for the period necessary to achieve the purposes for which it was collected. The Company may retain personal data for a longer period where permitted or required by law, where necessary for legal claims, dispute resolution, audits, accounting, compliance, or other legitimate business purposes.After the retention period has expired or the personal data is no longer necessary, the Company will delete, destroy, anonymize, or otherwise appropriately dispose of such personal data.

Article 4. Purposes of Use of Personal Data

The Company will use Users’ personal data for the following purposes, unless otherwise permitted by Applicable Personal Data Protection Laws.

  1. Personal data collected through inquiries, requests for materials, requests for demonstrations, free trials, or contact formsThe Company may use such personal data for the following purposes:
    • responding to inquiries, requests, consultations, and communications;
    • providing information about the Company, the Service, products, events, campaigns, seminars, and related services;
    • sales and marketing activities;
    • analyzing browsing history, inquiry history, behavioral history, email opening status, click history, and other interaction data in order to provide information according to Users’ interests and preferences;
    • improving the content, frequency, and quality of communications;
    • conducting surveys and questionnaires;
    • planning, developing, improving, and promoting the Company’s products and services.
  2. Personal data collected through sales activities, business negotiations, seminars, exhibitions, or eventsThe Company may use such personal data for the following purposes:
    • business communication;
    • confirmation of participation in seminars, exhibitions, meetings, or events;
    • provision of detailed information about the Service and related products or services;
    • sales and marketing activities;
    • management of business negotiations and prospective client information;
    • follow-up communications after meetings, seminars, exhibitions, or events.
  3. Personal data of Service Users
    The Company may use such personal data for the following purposes:
    • identity verification and authentication;
    • provision, operation, maintenance, and improvement of the Service;
    • contract management;
    • billing, payment, and transaction management;
    • user support and response to inquiries;
    • investigation and correction of defects, errors, or technical problems;
    • analysis of usage status;
    • creation and use of statistical data;
    • notification of important information regarding the Service;
    • announcement of updates, maintenance, changes, or suspension of the Service;
    • prevention, detection, and response to unauthorized access, fraud, abuse, security incidents, or violations of terms of use;
    • enforcement of the Company’s terms, policies, contracts, or legal rights;
    • provision of information regarding the Service, related services, other services of the Company, or services of affiliates or partners.
  4. Personal data of clients and business partners
    The Company may use such personal data for the following purposes:
    • management of client and business partner information;
    • business communication;
    • negotiation, execution, and performance of contracts;
    • delivery of products, services, documents, notices, invoices, and other communications;
    • transaction management;
    • accounting, tax, audit, and legal compliance;
    • planning, development, maintenance, and improvement of the Service and business activities.
  5. Personal data of employees and former employeesThe Company may use such personal data for the following purposes:
    • employment management;
    • payroll, benefits, attendance, evaluation, training, and human resources management;
    • internal communication;
    • compliance with labor, tax, social security, and other applicable laws;
    • security management;
    • post-employment communication and legal obligations.
  6. Personal data of job applicantsThe Company may use such personal data for the following purposes:
    • recruitment screening;
    • communication regarding applications, interviews, and selection results;
    • management of recruitment records;
    • consideration for future recruitment opportunities, where permitted by law or consented to by the applicant.
  7. Personal data of shareholders or stakeholdersThe Company may use such personal data for the following purposes:
    • exercise of shareholder or stakeholder rights;
    • performance of the Company’s legal obligations;
    • provision of notices, reports, and other information;
    • management of shareholder or stakeholder records;
    • creation and management of data required by laws and regulations.
  8. Temporary or additional purposes
    If the Company collects personal data for purposes other than those described above, the Company will notify Users of such purposes prior to or at the time of collection, where required by Applicable Personal Data Protection Laws.If the Company wishes to use or disclose personal data for a purpose other than those described above, the Company will notify the User of the new purpose and obtain the User's consent before doing so, unless Applicable Personal Data Protection Laws permit the new purpose without consent.

Article 5. Disclosure of Personal Data

  1. The Company will not disclose or provide personal data to third parties except in the following cases:
    1. where disclosure is required or permitted by laws or regulations;
    2. where it is necessary to prevent or suppress a danger to life, body, or health of a person;
    3. where it is necessary for the performance of a task carried out in the public interest by the Company, or in the exercise of official authority vested in the Company;
    4. where it is necessary for the legitimate interests of the Company or of another person, except where those interests are overridden by the User's fundamental rights in their personal data;
    5. where the User has given prior consent;
    6. where the Company entrusts the processing of personal data to a data processor acting on the Company's instructions and, on its behalf, to the extent necessary for achieving the purposes of use;
  2. The Company may provide or transfer personal data to the following third parties where necessary:
    • Zero board Inc.;
    • cloud service providers;
    • system vendors;
    • payment service providers;
    • professional advisors, including lawyers, accountants, auditors, and consultants;
    • business partners necessary for providing the Service;
    • government agencies, regulators, courts, or other public authorities where required by law.
  3. Cross-border transfer
    The Company may transfer personal data to countries or regions outside Thailand, including but not limited to:
    ・Japan
    Where personal data is transferred outside Thailand, the Company will do so only where:
    1. the User has given consent to the transfer, after being informed that the data protection standard of the destination country has not been determined by the Personal Data Protection Committee to be adequate;
    2. the transfer is made under a data transfer agreement between the Company and the recipient providing appropriate safeguards recognized under Applicable Personal Data Protection Laws, such as the ASEAN Model Contractual Clauses for Cross Border Data Flows, or the Standard Contractual Clauses under the General Data Protection Regulation, under which the User has enforceable rights and effective legal remedies, including the ability to object to the transfer or to the use of personal data beyond the agreed scope;
    3. the transfer is made under a personal data protection policy for the Company's corporate group that has been examined and certified by the Office of the Personal Data Protection Committee; or
    4. the transfer is otherwise permitted without consent under Applicable Personal Data Protection Laws.
  4. Data protection measures taken by recipients
    Where the Company provides or transfers personal data to third parties, the Company will take necessary and appropriate measures to ensure that the recipient processes such personal data in accordance with Applicable Personal Data Protection Laws and appropriate security standards.

Article 6. Proper Protection of Personal Data

The Company will take appropriate technical and organizational measures to process personal data accurately, securely, and properly in accordance with Applicable Personal Data Protection Laws and this Policy.

The Company will implement necessary and appropriate security measures to prevent loss of, and unauthorized or unlawful access to, use, alteration, correction, or disclosure of, personal data, and to maintain the confidentiality, integrity, and availability of personal data at a level appropriate to the risk.

The Company may implement the following measures:

  1. Basic policy
    The Company establishes basic policies and internal rules concerning information security and personal data protection.
  2. Rules for processing of personal data
    The Company establishes internal rules concerning the collection, use, storage, transfer, deletion, and disposal of personal data.
  3. Organizational security measures
    The Company appoints a person or team responsible for personal data protection and information security.The responsible person or team supervises the processing of personal data, confirms compliance with internal rules, implements improvements where necessary, and establishes reporting procedures in the event of incidents such as leakage or unauthorized access.The Company may conduct regular audits, reviews, or checks of its personal data processing system.
  4. Human security measures
    The Company provides employees, officers, contractors, and relevant personnel with training or guidance on the proper processing and protection of personal data.The Company also requires personnel who process personal data to comply with confidentiality obligations.
  5. Physical and technical security measuresThe Company may implement physical and technical measures including:
    • access control, including identity proofing, authentication, and authorization on a need-to-know and least-privilege basis;
    • user authentication;
    • password management;
    • user access management, including registration and de-registration of users, provisioning and review of access rights, and removal or adjustment of access rights;
    • encryption;
    • device management;
    • account management;
    • restriction of access rights;
    • deletion of accounts of employees or contractors who leave or change roles;
    • prevention of unauthorized removal of data;
    • management of external storage media;
    • remote wipe or mobile device management where applicable;
    • firewall, WAF, IPS/IDS, anti-malware, monitoring, logging, vulnerability management, and other security measures;
    • audit trails enabling subsequent verification of access to, alteration, correction, or deletion of, personal data;
    • secure disposal of equipment and electronic media.
  6. Review of security measures
    The Company will review its security measures where necessary or where technology changes, so that they remain effective. Where a personal data breach occurs, the Company will treat that as a circumstance requiring review, unless the breach poses no risk to the rights and freedoms of persons.
  7. Personal Data Breach
    In the event of a personal data breach, the Company will notify the Office of the Personal Data Protection Committee without delay and, where feasible, within 72 hours of becoming aware of the breach, unless the breach poses no risk to the rights and freedoms of persons. Where the breach carries a high risk to the rights and freedoms of persons, the Company will also notify the affected Users, together with the remedial measures available to them, without delay. The Company will also take necessary measures to prevent similar incidents from occurring or recurring.

Article 7. User Rights and Procedures

  1. Users have the following rights under Applicable Personal Data Protection Laws:
    • right to access personal data;
    • right to obtain a copy of personal data;
    • right to request disclosure of the source from which personal data was obtained, where the User did not consent to its collection;
    • right to request correction of inaccurate or incomplete personal data;
    • right to request addition or update of personal data;
    • right to request deletion, destruction, or anonymization of personal data;
    • right to request suspension or restriction of use;
    • right to withdraw consent;
    • right to data portability;
    • right to object to the collection, use, or disclosure of personal data. Where the Company collects, uses, or discloses personal data for direct marketing purposes, the User may object to that processing at any time, and the Company will stop such processing without requiring the User to give reasons;
    • right to lodge a complaint with the relevant authority, including the Expert Committee under the Personal Data Protection Act B.E. 2562 (2019).
  2. Users may exercise these rights by submitting a request to the Company by e-mail, by post, or in person at the Company's office, using the contact information set out in Article 12. The request should specify the nature of the request and the manner in which the User wishes to receive the requested information. The Company will require verification of the User's identity before acting on a request, and written authorization where a request is submitted on the User's behalf.
  3. The Company will respond to a request within 30 days of receipt and will notify the User where an extension of up to a further 30 days is necessary, together with the reason for such extension. No fee will be charged where the Company is able to fulfil the request electronically. In other cases, the Company may charge a reasonable fee not exceeding its actual cost, and will inform the User of the applicable fee before the request is processed. The Company may reduce or waive the fee at its discretion.
  4. The Company may decline a request where permitted or required by law, where the request is repetitive or unfounded, or where compliance would adversely affect the rights and freedoms of others. The Company will inform the User of the reason for declining.

Article 8. Outsourcing Contractors

The Company may entrust all or part of the processing of personal data to outsourcing contractors to the extent necessary for achieving the purposes of use.

In such cases, the Company will appropriately select outsourcing contractors, require confidentiality and data protection obligations by contract, and conduct necessary and appropriate supervision to ensure that personal data is processed securely.

Where outsourcing contractors act as data processors under Applicable Personal Data Protection Laws, the Company will enter into a written data processing to ensure that such contractors process personal data only on the Company's instructions, implement appropriate security measures, delete or return personal data on the Company's instruction, maintain a record of processing activities, and notify the Company of any personal data breach without delay and in accordance with this Policy and Applicable Personal Data Protection Laws.

Article 9. Disclaimer

The Company assumes no responsibility for the collection of personal data by third parties in the following cases:

  1. where Users disclose personal data to third parties by using functions of the Service or by other means;
  2. where an individual becomes identifiable through information entered, uploaded, posted, transmitted, or otherwise disclosed by Users through the Service;
  3. where Users access External Services or third-party websites through links or integrations provided in or in connection with the Service.

Nothing in this Article limits the Company's liability to the extent that such liability cannot be limited or excluded under Applicable Personal Data Protection Laws.

Article 10. Use of Statistical Data

The Company may create statistical data based on personal data collected from Users, provided that such data is processed so that specific individuals can no longer be identified, whether directly or indirectly.
The Company may use such statistical data for analysis, service improvement, research, development, marketing, reporting, or other business purposes

Article 11. Use of Cookies and Similar Technologies

When Users access websites operated by the Company, use the Service, agree to this Policy, register personal data, or access a URL included in an email or similar communication sent by the Company, the Company may associate cookies and similar technologies with Users’ personal data.
Where cookies or similar technologies are associated with personal data, the Company will manage such data as personal data in accordance with this Policy and Applicable Personal Data Protection Laws.
The Company may use cookies and similar technologies for the following purposes:

  • operation of websites and the Service;
  • user authentication;
  • security;
  • prevention of unauthorized access;
  • analysis of website or Service usage;
  • improvement of user experience;
  • marketing and advertising;
  • measurement of advertising effectiveness;
  • personalization of content.

The Company will place cookies and similar technologies that are not strictly necessary for the operation of the Service only with the User's consent, obtained through the cookie consent tool available on the Company's websites. Users may change or withdraw their cookie preferences at any time using that tool. Users may also disable cookies through their browser settings, although disabling strictly necessary cookies may affect the availability or functionality of all or part of the Service.

Article 12. Inquiry Regarding Personal Data

For inquiries, requests, or complaints regarding the processing of personal data, please contact the Company using the contact information below.

Zeroboard (Thailand) Co., Ltd.

Personal Data Protection Contact
E-mail: info@zeroboard.co.th
Address: 5 , TPA29 Building , Room No. 2, Floor 3, Soi Sukhumvit 29, Sukhumvit Road, Khlong Toei Nuea, Watthana, Bangkok 10110 Thailand

Article 13. Revision of this Policy

The Company may revise this Policy from time to time.
In the event of a significant change to this Policy, the Company will notify Users in an easy-to-understand manner by posting on the Company’s website, sending email, displaying notice within the Service, or by other appropriate means. Where a revision introduces a new purpose or a new basis requiring consent, the Company will obtain the User's consent before applying the revision to that User's personal data.

Article 14. Language

This Policy may be prepared in multiple languages. In the event of any inconsistency or conflict between different language versions, the ENGLISH version shall prevail, unless otherwise required by applicable law.