PDPA & Global Privacy Compliance

Privacy Policy

Last updated: September 4, 2026 · Effective immediately

1. Introduction & Data Controller

The website xamathi.com and its affiliated software products (including the KeyXamathi macOS desktop application) are operated and developed by Mr. Burapa Jaiwat as the Data Controller under Thailand's Personal Data Protection Act B.E. 2562 (2019) (PDPA), the General Data Protection Regulation (GDPR - EU), and the California Consumer Privacy Act (CCPA/CPRA - USA).

We build with strict adherence to Privacy by Design and Data Minimization principles. We believe privacy is an architectural guarantee, not an optional setting.

Data Controller Contact Details:
Data Protection & Legal Rights Requests: [email protected]
General Support & Inquiries: [email protected]
Jurisdiction & Location: Bangkok, Kingdom of Thailand

2. Personal Data We Collect

We only collect personal data when strictly necessary to fulfill your orders, provide customer support, or when you explicitly give your consent:

3. Lawful Basis & Processing Purposes

We process your personal information strictly under recognized legal bases pursuant to Section 24 of the Thai PDPA and Article 6 of the EU GDPR:

4. Data Retention Periods

We retain personal data strictly for the period necessary to satisfy legal, tax, and operational obligations:

  • Purchase and Financial Records: Retained for 5 years from the transaction date to comply with Thai tax and statutory accounting regulations.
  • System Access & Traffic Logs: Retained for a minimum of 90 days in compliance with the Thai Computer Crime Act B.E. 2550 (2007) and amendments.
  • Stability Reports: Retained for a maximum of 90 days, after which they are permanently and automatically purged from our encrypted databases.
  • Once retention periods expire, data is securely erased, destroyed, or irreversibly anonymized.

5. Third-Party Disclosures & Cross-Border Transfers

No Sale of Personal Data: We never sell, lease, rent, or trade your personal data to third parties for commercial or marketing purposes, in full compliance with the California Consumer Privacy Act (CCPA/CPRA).

We share data only with necessary infrastructure processors under strict security and data processing terms:

  • Cloudflare, Inc. (USA / Global Network): Content Delivery Network (CDN), Web Application Firewall (WAF), and Cloudflare D1/Workers edge database under Standard Contractual Clauses (SCCs) ensuring international data transfer protection.
  • Law Enforcement & Legal Authorities: Disclosed only upon presentation of a valid court order, subpoena, or legally binding governmental warrant under applicable law.

6. Your Legal Rights (Data Subject Rights)

Under the PDPA and GDPR, you are entitled to the following rights regarding your personal information:

1. Right of Access Request a copy of your personal data held by us.
2. Right to Data Portability Receive your personal data in a structured, commonly used machine-readable format.
3. Right to Object Object to the processing of your personal data on legitimate interest grounds.
4. Right to Erasure ("To Be Forgotten") Request the permanent deletion or anonymization of your personal data.
5. Right to Restriction Request the temporary restriction of processing your personal data.
6. Right to Rectification Request the correction of inaccurate or incomplete information.
7. Right to Withdraw Consent Withdraw your previously granted consent at any time.
8. Right to Lodge a Complaint File a formal complaint with the Personal Data Protection Committee (PDPC) in Thailand or your local supervisory authority.

Exercising Your Rights: You may submit requests to [email protected]. We will verify your identity and fulfill valid requests within 30 days of receipt without charge, except where requests are manifestly unfounded or excessive.

7. Cookies & Browser Local Storage

Our website utilizes local storage technologies strictly for essential operational convenience:

  • Strictly Necessary Cookies: We do not deploy user tracking or behavioral profiling cookies.
  • Browser Local Storage: Used exclusively to store interface preferences on your local machine, such as language selection (th, en, lo) and announcement banner dismissal states. This data remains on your device and is not transmitted back to our servers.
  • Cookie Management: You can clear or disable cookies and local storage anytime via your browser settings.

8. Data Security Measures

We maintain comprehensive technical and organizational safeguards to protect your personal data:

  • End-to-end transport encryption via modern TLS 1.3 / HTTPS protocols.
  • Restricted, least-privilege database access policies on Cloudflare D1 with encrypted backups.
  • Mandatory Multi-Factor Authentication (MFA) across all administrative access channels.

9. Policy Updates

We may update this Privacy Policy from time to time to reflect operational changes or legal requirements. Any modifications will take effect upon posting with an updated revision date at the top of this document.