Privacy Policy
Effective Date: January 15, 2025
At Flow Surge, we take your privacy seriously. This policy explains how we collect, use, and protect your personal information when you interact with our business activity analysis services.
We operate in accordance with Thailand's Personal Data Protection Act (PDPA) B.E. 2562 and international data protection standards. If you have questions about how we handle your data, we're here to help.
Information We Collect
We collect different types of information depending on how you use our services. Here's what we gather and why:
Information You Provide Directly
When you sign up for our services or contact us, you might share:
- Your name, email address, and phone number
- Company details including business name and industry sector
- Financial data you upload for analysis purposes
- Payment information when you subscribe to our services
- Messages and inquiries you send through our contact forms
Information Collected Automatically
Our systems automatically log certain technical information:
- IP address and general location data
- Browser type, device information, and operating system
- Pages you visit and features you use on our platform
- Time spent on different sections of our website
- Referral sources that brought you to our site
We don't sell your personal information to third parties. Your business data stays confidential and is used only for the analysis services you've requested.
How We Use Your Information
Your data helps us deliver better services and improve your experience. We use what we collect to:
- Provide accurate business activity analysis and financial insights
- Process your payments and manage your account subscriptions
- Send you important updates about our services and your account
- Respond to your questions and support requests promptly
- Improve our platform based on usage patterns and feedback
- Detect and prevent fraudulent activities or security threats
- Comply with legal obligations under Thailand law
We occasionally send marketing emails about new features or services. You can opt out anytime by clicking the unsubscribe link in any email we send.
Legal Basis for Processing (PDPA Compliance)
Under Thailand's PDPA, we process your personal data based on these legal grounds:
| Processing Purpose | Legal Basis |
|---|---|
| Service delivery and account management | Contract performance |
| Payment processing and billing | Contract performance |
| Customer support and communication | Legitimate interest |
| Marketing communications | Your consent |
| Legal compliance and record keeping | Legal obligation |
| Platform security and fraud prevention | Legitimate interest |
Data Sharing and Third Parties
We're careful about who gets access to your information. We only share data when necessary:
Service Providers
We work with trusted companies that help us run our business. These include payment processors, cloud hosting services, and analytics tools. They're contractually required to protect your data and can only use it for the specific services they provide to us.
Legal Requirements
Sometimes we're legally required to share information with Thai government authorities or law enforcement. This happens when we receive valid legal requests or need to comply with regulations.
Business Transfers
If Flow Surge is acquired or merged with another company, your data might be transferred as part of that transaction. We'll notify you before this happens and explain any changes to how your information is handled.
We never share your financial analysis data with other clients or use it for any purpose beyond providing your requested services.
Your Rights Under Thailand PDPA
Thailand's data protection law gives you several important rights. Here's what you can do:
Access Your Data
You can request a copy of all personal information we hold about you. We'll provide this in a commonly used electronic format within 30 days.
Correct Inaccurate Information
If something we have on file is wrong or outdated, let us know. We'll update it promptly.
Delete Your Data
You can ask us to delete your personal information. We'll honor this request unless we're legally required to keep certain records for tax or regulatory purposes.
Restrict Processing
In some situations, you can ask us to temporarily stop processing your data while we resolve a dispute or verify information accuracy.
Data Portability
You have the right to receive your data in a structured format and transfer it to another service provider if you choose.
Withdraw Consent
For processing that requires your consent (like marketing emails), you can withdraw permission at any time. This doesn't affect the lawfulness of processing before you withdrew consent.
Lodge a Complaint
If you're unhappy with how we handle your data, you can file a complaint with Thailand's Personal Data Protection Committee.
Data Security Measures
We've implemented multiple layers of security to protect your information:
- Industry-standard encryption for data transmission and storage
- Regular security audits and vulnerability assessments
- Restricted access controls - only authorized staff can view sensitive data
- Secure backup systems with encrypted storage
- Two-factor authentication for account access
- Regular employee training on data protection practices
While we take security seriously, no system is completely immune to threats. We recommend using strong passwords and keeping your login credentials confidential.
Data Retention Periods
We don't keep your data forever. Here's how long we retain different types of information:
| Data Type | Retention Period |
|---|---|
| Active account information | Duration of your subscription plus 1 year |
| Financial analysis data | 3 years after account closure |
| Payment and billing records | 7 years (Thai tax law requirement) |
| Marketing consent records | Until you withdraw consent |
| Website usage logs | 12 months |
| Customer support communications | 2 years after resolution |
After these periods expire, we securely delete or anonymize your data so it can no longer identify you.
International Data Transfers
Our primary data storage is within Thailand, but some of our service providers operate servers in other countries. When we transfer data internationally, we ensure adequate protection through:
- Standard contractual clauses approved by data protection authorities
- Verification that recipient countries have adequate data protection laws
- Additional security measures for sensitive financial information
We currently use cloud services with data centers in Singapore and the European Union, both of which maintain high data protection standards.
Cookies and Tracking Technologies
Our website uses cookies - small text files stored on your device - to improve your experience. We use:
Essential Cookies
These are necessary for our website to function properly. They handle things like keeping you logged in and remembering your preferences.
Analytics Cookies
These help us understand how visitors use our site so we can make improvements. We use aggregated data that doesn't identify individual users.
Performance Cookies
These measure how our platform performs and help us optimize loading times and functionality.
You can control cookies through your browser settings. Keep in mind that blocking some cookies might affect how well our platform works for you.
Children's Privacy
Our services are designed for businesses and professionals. We don't knowingly collect information from anyone under 20 years old (the age of majority in Thailand). If you're a parent who believes we've accidentally collected data about your child, please contact us immediately so we can delete it.
Changes to This Policy
We update this privacy policy occasionally to reflect changes in our practices or legal requirements. When we make significant changes, we'll notify you by email or through a prominent notice on our website.
The "Effective Date" at the top shows when this version was last updated. We recommend reviewing this policy periodically to stay informed about how we protect your information.
Questions About Your Privacy?
We're happy to answer any questions about how we handle your data.
Email: [email protected]
Phone: +66 3231 4603
Address: 142/69 Rattirom 3, Mahasawat, Bang Kruai, Nonthaburi 11130, Thailand
For formal data protection inquiries or to exercise your PDPA rights, please include "Data Privacy Request" in your email subject line.