NOLAPSE

Privacy Policy

นโยบายความเป็นส่วนตัว

Version 0.1 · Effective 2026-08-23 · PENTABYTE CO., LTD (Reg. 0105564104101)

1. Data controller

PENTABYTE CO., LTD (company registration 0105564104101), {{COMPANY_ADDRESS}}. Personal-data contact: {{PRIVACY_CONTACT}}

2. Data we collect

  • Account — email, organisation role, password hash (never stored in readable form)
  • Organisation — the organisation name you provide
  • Service data — domain names you add, certificate metadata (Common Name, SANs, serial, validity dates), agent inventory (name, OS, last seen)
  • Audit log — significant actions with timestamp and actor

3. Purposes and lawful basis

  • Performance of contract — issuing, renewing and deploying certificates
  • Legitimate interest — platform security, abuse prevention, incident investigation
  • Legal obligation — accounting and tax records

4. Sub-processors

We use the following external providers only as necessary to run the service:

Sub-processorCountryService provided to usData it can access
Let's Encrypt (ISRG)United StatesIssues DV certificates via ACMEDomain names and the CSR — no private key
Google Trust ServicesUnited StatesIssues DV certificates via ACMEDomain names and the CSR — no private key
CloudflareUnited StatesDNS and email delivery for our domainDNS records, inbound email metadata
Brevo (Sendinblue)France / European UnionSystem email (verification, password reset, team invites)Recipient email address and message content
StripeUnited States / IrelandPayment processing (Stripe checkout page)Payment-identifying information — we do not store card details
MinIO (our infrastructure)ThailandOffsite data backupEncrypted database backup copies
Broadcom / VMware (via PROEN)ThailandCloud infrastructure that runs the serviceAll data at the infrastructure layer
Cert Spotter / SSLMateUnited StatesMonitors certificates issued for your domain names (Certificate Transparency)Your domain names
Google (Sign-in with Google)United StatesSign-in with a Google account (when you choose it)Account email and identity
Microsoft (Sign-in with Microsoft)United StatesSign-in with a Microsoft account (when you choose it)Account email and identity

No sub-processor ever receives a usable private key. ACME issuance transmits only the Certificate Signing Request.

5. International transfers

Some sub-processors are located outside Thailand, as marked in section 4. Such transfers are necessary for the performance of the contract to which you are a party, under section 28 of the Thai Personal Data Protection Act B.E. 2562.

Data transferred outside Thailand is limited to: the recipient's email address (for system email), payment-identifying information (for payment processing), domain names and CSRs (for certificate issuance and Certificate Transparency monitoring), and account sign-in identity (for sign-in with Google or Microsoft, when you choose to use it).

6. Security measures

  • Imported private keys and the Private CA root key are encrypted at rest with AES-256 envelope encryption; the master key is not stored in the database
  • TLS in transit; agent connections support mTLS, with a bearer-token fallback for legacy agents
  • Hash-chained, verifiable audit log
  • Role-based access control; mandatory two-factor authentication for administrators

7. Retention

Account and service data are kept for the life of the account and for {{RETENTION_AFTER_CLOSURE}} after closure. Audit logs are kept for {{RETENTION_AUDIT}}. After that, data is deleted or anonymised.

8. Your rights

You may request access, rectification, erasure, restriction, portability, object to processing, and withdraw consent. Contact {{PRIVACY_CONTACT}}; we respond within 30 days. You may also complain to Thailand's Personal Data Protection Committee office.

9. Cookies

The portal uses browser localStorage to hold your session token, the signed-in user's email and account status, your chosen language, and display preferences (theme and menu collapse state). We use no behavioural-tracking or advertising cookies, and no third-party analytics script runs on the portal.

10. Changes

Material changes are announced by email or in the portal at least 30 days before they take effect, and the version number above is incremented.