PENTABYTE CO., LTD (company registration 0105564104101), {{COMPANY_ADDRESS}}. Personal-data contact: {{PRIVACY_CONTACT}}
We use the following external providers only as necessary to run the service:
| Sub-processor | Country | Service provided to us | Data it can access |
|---|---|---|---|
| Let's Encrypt (ISRG) | United States | Issues DV certificates via ACME | Domain names and the CSR — no private key |
| Google Trust Services | United States | Issues DV certificates via ACME | Domain names and the CSR — no private key |
| Cloudflare | United States | DNS and email delivery for our domain | DNS records, inbound email metadata |
| Brevo (Sendinblue) | France / European Union | System email (verification, password reset, team invites) | Recipient email address and message content |
| Stripe | United States / Ireland | Payment processing (Stripe checkout page) | Payment-identifying information — we do not store card details |
| MinIO (our infrastructure) | Thailand | Offsite data backup | Encrypted database backup copies |
| Broadcom / VMware (via PROEN) | Thailand | Cloud infrastructure that runs the service | All data at the infrastructure layer |
| Cert Spotter / SSLMate | United States | Monitors certificates issued for your domain names (Certificate Transparency) | Your domain names |
| Google (Sign-in with Google) | United States | Sign-in with a Google account (when you choose it) | Account email and identity |
| Microsoft (Sign-in with Microsoft) | United States | Sign-in with a Microsoft account (when you choose it) | Account email and identity |
No sub-processor ever receives a usable private key. ACME issuance transmits only the Certificate Signing Request.
Some sub-processors are located outside Thailand, as marked in section 4. Such transfers are necessary for the performance of the contract to which you are a party, under section 28 of the Thai Personal Data Protection Act B.E. 2562.
Data transferred outside Thailand is limited to: the recipient's email address (for system email), payment-identifying information (for payment processing), domain names and CSRs (for certificate issuance and Certificate Transparency monitoring), and account sign-in identity (for sign-in with Google or Microsoft, when you choose to use it).
Account and service data are kept for the life of the account and for {{RETENTION_AFTER_CLOSURE}} after closure. Audit logs are kept for {{RETENTION_AUDIT}}. After that, data is deleted or anonymised.
You may request access, rectification, erasure, restriction, portability, object to processing, and withdraw consent. Contact {{PRIVACY_CONTACT}}; we respond within 30 days. You may also complain to Thailand's Personal Data Protection Committee office.
The portal uses browser localStorage to hold your session token, the signed-in user's email and account status, your chosen language, and display preferences (theme and menu collapse state). We use no behavioural-tracking or advertising cookies, and no third-party analytics script runs on the portal.
Material changes are announced by email or in the portal at least 30 days before they take effect, and the version number above is incremented.
PENTABYTE CO., LTD (ทะเบียนนิติบุคคลเลขที่ 0105564104101) สำนักงานตั้งอยู่ที่ {{COMPANY_ADDRESS}}
ช่องทางติดต่อเรื่องข้อมูลส่วนบุคคล: {{PRIVACY_CONTACT}}
เราใช้ผู้ให้บริการภายนอกเท่าที่จำเป็นต่อการให้บริการ ดังนี้
| ผู้ประมวลผลช่วง | ประเทศ | บริการที่ให้เรา | ข้อมูลที่เข้าถึงได้ |
|---|---|---|---|
| Let's Encrypt (ISRG) | สหรัฐอเมริกา | ออกใบรับรอง DV แบบ ACME | ชื่อโดเมนและ CSR — ไม่มี private key |
| Google Trust Services | สหรัฐอเมริกา | ออกใบรับรอง DV แบบ ACME | ชื่อโดเมนและ CSR — ไม่มี private key |
| Cloudflare | สหรัฐอเมริกา | DNS และการรับส่งอีเมลของโดเมนเรา | ระเบียน DNS, เมทาดาทาอีเมลขาเข้า |
| Brevo (Sendinblue) | ฝรั่งเศส / สหภาพยุโรป | อีเมลระบบ (ยืนยันตัวตน/รีเซ็ตรหัส/เชิญทีม) | อีเมลผู้รับและเนื้อหาข้อความ |
| Stripe | สหรัฐอเมริกา / ไอร์แลนด์ | รับชำระเงิน (หน้า checkout ของ Stripe) | ข้อมูลระบุตัวผู้ชำระเงิน — เราไม่เก็บข้อมูลบัตร |
| MinIO (โครงสร้างพื้นฐานของเรา) | ประเทศไทย | สำรองข้อมูลนอกสถานที่ | สำเนาฐานข้อมูลที่เข้ารหัสแล้ว |
| Broadcom / VMware (ผ่าน PROEN) | ประเทศไทย | โครงสร้างพื้นฐานคลาวด์ที่รันระบบ | ข้อมูลทั้งหมดในชั้นโครงสร้างพื้นฐาน |
| Cert Spotter / SSLMate | สหรัฐอเมริกา | ตรวจสอบใบรับรองที่ออกในชื่อโดเมนของท่าน (Certificate Transparency) | ชื่อโดเมนของท่าน |
| Google (Sign-in with Google) | สหรัฐอเมริกา | การเข้าสู่ระบบด้วยบัญชี Google (เมื่อท่านเลือกใช้) | อีเมลและข้อมูลระบุตัวตนของบัญชี |
| Microsoft (Sign-in with Microsoft) | สหรัฐอเมริกา | การเข้าสู่ระบบด้วยบัญชี Microsoft (เมื่อท่านเลือกใช้) | อีเมลและข้อมูลระบุตัวตนของบัญชี |
ไม่มีผู้ประมวลผลช่วงรายใดได้รับ private key ที่ใช้งานได้ การขอใบรับรองผ่าน ACME ส่งเฉพาะคำขอลงนาม (CSR) ซึ่งไม่มีกุญแจส่วนตัวอยู่ภายใน
ผู้ประมวลผลช่วงบางรายอยู่นอกราชอาณาจักร ตามที่ระบุประเทศไว้ในตารางข้อ 4 การโอนข้อมูลดังกล่าวเป็นไปเพื่อการปฏิบัติตามสัญญาที่ท่านเป็นคู่สัญญา ตาม พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 มาตรา 28
ข้อมูลที่โอนออกนอกประเทศจำกัดเฉพาะอีเมลผู้รับ (สำหรับอีเมลระบบ) ข้อมูลระบุตัวผู้ชำระเงิน (สำหรับการรับชำระ) ชื่อโดเมนและ CSR (สำหรับการออกใบรับรองและการตรวจสอบ Certificate Transparency) และข้อมูลระบุตัวตนบัญชีสำหรับการเข้าสู่ระบบ (สำหรับการเข้าสู่ระบบผ่าน Google หรือ Microsoft เมื่อท่านเลือกใช้)
เราเก็บข้อมูลบัญชีและข้อมูลการใช้บริการตลอดอายุการใช้งานของบัญชี และเก็บต่ออีก {{RETENTION_AFTER_CLOSURE}} นับแต่วันปิดบัญชี
บันทึกการใช้งาน (audit log) เก็บเป็นระยะเวลา {{RETENTION_AUDIT}} เพื่อรองรับการตรวจสอบด้านความมั่นคงปลอดภัย
เมื่อพ้นกำหนด เราจะลบหรือทำให้ข้อมูลไม่สามารถระบุตัวบุคคลได้
ท่านมีสิทธิขอเข้าถึง ขอรับสำเนา ขอแก้ไขให้ถูกต้อง ขอลบ ขอระงับการใช้ ขอให้โอนย้ายข้อมูล คัดค้านการประมวลผล และเพิกถอนความยินยอม
ติดต่อใช้สิทธิได้ที่ {{PRIVACY_CONTACT}} เราจะดำเนินการภายใน 30 วันนับแต่ได้รับคำขอ หากท่านไม่พอใจผลการดำเนินการ ท่านมีสิทธิร้องเรียนต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส.)
พอร์ทัลใช้พื้นที่จัดเก็บในเบราว์เซอร์ (localStorage) เพื่อเก็บโทเคนการเข้าสู่ระบบ อีเมลและสถานะบัญชีของผู้ใช้ที่เข้าสู่ระบบ ภาษาที่เลือก และการตั้งค่าการแสดงผล (ธีมและการย่อ/ขยายเมนู) เราไม่ใช้คุกกี้เพื่อการติดตามพฤติกรรมหรือการโฆษณา และไม่มีสคริปต์วิเคราะห์การใช้งานของบุคคลที่สามบนพอร์ทัล
หากมีการแก้ไขในสาระสำคัญ เราจะแจ้งให้ทราบทางอีเมลหรือประกาศในพอร์ทัล ล่วงหน้าไม่น้อยกว่า 30 วันก่อนวันมีผล และจะปรับหมายเลขเวอร์ชันที่แสดงด้านบน