1. Introduction & Data Controller
The website xamathi.com and its affiliated software products (including the KeyXamathi macOS desktop application) are operated and developed by Mr. Burapa Jaiwat as the Data Controller under Thailand's Personal Data Protection Act B.E. 2562 (2019) (PDPA), the General Data Protection Regulation (GDPR - EU), and the California Consumer Privacy Act (CCPA/CPRA - USA).
We build with strict adherence to Privacy by Design and Data Minimization principles. We believe privacy is an architectural guarantee, not an optional setting.
Data Protection & Legal Rights Requests: [email protected]
General Support & Inquiries: [email protected]
Jurisdiction & Location: Bangkok, Kingdom of Thailand
2. Personal Data We Collect
We only collect personal data when strictly necessary to fulfill your orders, provide customer support, or when you explicitly give your consent:
A. Purchase & Payment Data
When you purchase a Pro License Key or submit proof of payment:
- Full Name or Buyer Name
- Email address (for digital license delivery and transaction receipts)
- Phone number (optional, provided voluntarily)
- Bank transfer proof / Payment slip (account name, timestamp, and amount transferred)
B. Communication & Feedback Data
When you contact us via email or submit dictionary word suggestions:
- Sender email address and name
- Message content, support inquiry, or submitted vocabulary suggestions
C. Technical & Infrastructure Logs
When you visit xamathi.com, traffic is processed through Cloudflare's edge infrastructure:
- Anonymized web visit metrics (Cloudflare Web Analytics without tracking cookies)
- IP addresses are securely salted and hashed for automated DDoS/Spam rate-limiting; raw IP addresses are never permanently tied to your personal identity
- Browser type, operating system version, and preferred UI language
🚫 What We NEVER Collect
- Zero Keystroke Logging: KeyXamathi operates 100% locally. Text processing occurs entirely within temporary RAM on your Mac. No keystrokes or typed words are ever sent to remote servers.
- No Cross-Site Behavioral Tracking: We do not deploy third-party advertising trackers, Facebook Pixels, or Google Ad retargeting tags.
- No Credit Card Storage: Direct payment is handled via secure bank transfer/PromptPay. We do not handle, collect, or store payment card credentials.
3. Lawful Basis & Processing Purposes
We process your personal information strictly under recognized legal bases pursuant to Section 24 of the Thai PDPA and Article 6 of the EU GDPR:
| Purpose | Data Categories | Lawful Basis |
|---|---|---|
| Verifying payments and delivering Pro License Keys via email | Email, payment slip, account name | Contractual Necessity (PDPA Sec. 24(3) / GDPR Art. 6(1)(b)) |
| Order record keeping and compliance with tax/accounting laws | Transaction record, email, timestamp | Legal Obligation (PDPA Sec. 24(6) / GDPR Art. 6(1)(c) - Thai Revenue Code) |
| Network security, anti-abuse, spam mitigation & fraud prevention | Hashed IP, technical request headers | Legitimate Interests (PDPA Sec. 24(5) / GDPR Art. 6(1)(f) & Thai Computer Crime Act) |
| Customer support, troubleshooting, and license reactivation | Email, inquiry text, license key | Contract & Legitimate Interest (Serving customer inquiries) |
| Stability Reports and optional diagnostic crash logs | Diagnostic report ID, non-identifying counters | Explicit Consent (PDPA Sec. 19 / GDPR Art. 6(1)(a) - User-initiated only) |
4. Data Retention Periods
We retain personal data strictly for the period necessary to satisfy legal, tax, and operational obligations:
- Purchase and Financial Records: Retained for 5 years from the transaction date to comply with Thai tax and statutory accounting regulations.
- System Access & Traffic Logs: Retained for a minimum of 90 days in compliance with the Thai Computer Crime Act B.E. 2550 (2007) and amendments.
- Stability Reports: Retained for a maximum of 90 days, after which they are permanently and automatically purged from our encrypted databases.
- Once retention periods expire, data is securely erased, destroyed, or irreversibly anonymized.
5. Third-Party Disclosures & Cross-Border Transfers
No Sale of Personal Data: We never sell, lease, rent, or trade your personal data to third parties for commercial or marketing purposes, in full compliance with the California Consumer Privacy Act (CCPA/CPRA).
We share data only with necessary infrastructure processors under strict security and data processing terms:
- Cloudflare, Inc. (USA / Global Network): Content Delivery Network (CDN), Web Application Firewall (WAF), and Cloudflare D1/Workers edge database under Standard Contractual Clauses (SCCs) ensuring international data transfer protection.
- Law Enforcement & Legal Authorities: Disclosed only upon presentation of a valid court order, subpoena, or legally binding governmental warrant under applicable law.
6. Your Legal Rights (Data Subject Rights)
Under the PDPA and GDPR, you are entitled to the following rights regarding your personal information:
Exercising Your Rights: You may submit requests to [email protected]. We will verify your identity and fulfill valid requests within 30 days of receipt without charge, except where requests are manifestly unfounded or excessive.
7. Cookies & Browser Local Storage
Our website utilizes local storage technologies strictly for essential operational convenience:
- Strictly Necessary Cookies: We do not deploy user tracking or behavioral profiling cookies.
- Browser Local Storage: Used exclusively to store interface preferences on your local machine, such as language selection (
th,en,lo) and announcement banner dismissal states. This data remains on your device and is not transmitted back to our servers. - Cookie Management: You can clear or disable cookies and local storage anytime via your browser settings.
8. Data Security Measures
We maintain comprehensive technical and organizational safeguards to protect your personal data:
- End-to-end transport encryption via modern TLS 1.3 / HTTPS protocols.
- Restricted, least-privilege database access policies on Cloudflare D1 with encrypted backups.
- Mandatory Multi-Factor Authentication (MFA) across all administrative access channels.
9. Policy Updates
We may update this Privacy Policy from time to time to reflect operational changes or legal requirements. Any modifications will take effect upon posting with an updated revision date at the top of this document.