Data Protection

Privacy Policy

Information regarding data collection, processing standards, user privacy rights, and compliance under Thai PDPA and international standards.

Last Updated: August 2026

At Glow Vertex Point Co., Ltd. (“we”, “us”, or “our”), respecting the privacy and data security of our website visitors and consulting clients is fundamental to our practice. This Privacy Policy details how we collect, process, retain, and safeguard personal information in compliance with Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA) and international privacy principles (including GDPR where applicable).


1. Data Controller Details


2. Information We Collect

We collect information through two primary channels:

A. Information You Provide Directly

  • Inquiry Details: When you submit a diagnostic inquiry or contact form on our website, we collect your full name, work email address, company/app name, selected service interest, project scope details, and inquiry message.
  • Client Engagement Data: When entering into a consulting agreement, we collect business billing addresses, tax registration numbers, and authorized contact information.

B. Technical and Browsing Information

  • Standard Web Logs: IP addresses, browser types, operating systems, referring URLs, and timestamps collected via standard web server logs.
  • Cookie Data: Information collected through necessary session cookies and optional aggregate analytics cookies (subject to your consent).

We process personal data solely for the following legitimate purposes:

  1. Fulfilling Inquiries & Proposals: To respond to your requests for diagnostic scopes and prepare commercial proposals (Legal Basis: Contractual Necessity / Legitimate Interest).
  2. Delivering Advisory Services: To execute telemetry audits, cohort analyses, and executive reporting under signed service agreements (Legal Basis: Contractual Performance).
  3. Legal & Financial Compliance: To maintain accounting and taxation records under Thai commercial law (Legal Basis: Legal Obligation).
  4. Site Optimization & Security: To protect our digital infrastructure against fraudulent activity or cyber threats (Legal Basis: Legitimate Interest).

4. Client Telemetry & Analytics Data Processing

During client engagements, we examine client-provided application event logs. We adhere to the following principles:

  • No Direct Consumer Tracking: We do not market to or track individual end-users of our clients’ applications.
  • Anonymized & Pseudonymized Analysis: We require and recommend that all client event logs use hashed pseudonyms (e.g., user_id_hash) devoid of unencrypted Personally Identifiable Information (PII) such as payment card details, government IDs, or sensitive health data.
  • Strict Read-Only Access: We operate via secure read-only credentials or exports and delete temporary local analytical working files within 30 days of engagement completion.

5. Data Retention Periods

  • Website Inquiries: Retained for up to 24 months to support ongoing advisory conversations and historical context, after which records are deleted.
  • Contractual & Invoicing Records: Retained for 7 years in accordance with Thai statutory accounting requirements.
  • Analytics Working Files: Purged within 30 calendar days of final report sign-off.

6. International Data Transfers

As an advisory firm based in Phuket, Thailand serving global clients, data may be transferred to and stored on secure cloud servers located in recognized data centers. When transferring personal data outside Thailand, we ensure appropriate safeguards (such as standard contractual clauses and robust encryption) are in place.


7. Your Statutory Rights

Under applicable data protection laws (including Thai PDPA and GDPR), you possess the following rights regarding your personal information:

  • Right of Access: Request copies of personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete information.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data where retention is no longer necessary.
  • Right to Restrict or Object to Processing: Object to or limit how your data is processed under specific circumstances.
  • Right to Data Portability: Request transfer of your data in a structured, machine-readable format.
  • Right to Withdraw Consent: Withdraw cookie or marketing consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact our privacy desk at info@glowvertexpoint.click.


8. Updates to This Policy

We may update this Privacy Policy periodically to reflect changes in our advisory practices or legal obligations. The latest version will always be published on this page with an updated effective date.