Data We Collect
We may collect your personal data through your use of the GutePOS / GuteStyle system, our website, or your inquiries. This data falls into 4 main categories:
- Identity and contact data: Full name, email address, phone number, shop/salon address, tax identification number (if any)
- Transaction data: Order history, active package details, billing information · We do not store full credit card data — we use only PCI-DSS certified payment gateways
- Service data (as data processor): Employee/stylist data, customer data entered into the system by users, bookings, receipts, payslips, and reports — we act as a Data Processor under the instructions of the system user (Data Controller)
- Technical data: IP address, browser type, OS, cookies, website visit statistics, login logs
Purposes of Data Use
We collect and use your data for the following purposes:
- Service delivery: To enable you to use GutePOS and GuteStyle to their full potential
- Transaction processing: Issuing receipts, tax invoices, invoices, and purchase orders
- Communications: Notifying you of system updates, license renewals, or special benefits
- Analytics and improvement: Improving our products and services to better meet your needs
- Security: Detecting and preventing misuse, account theft, and security breaches
- Legal compliance: To fulfill legal obligations, such as issuing tax invoices (e-Tax Invoice)
Disclosure of Data to Third Parties
We will never sell or rent your personal data to third parties. We may disclose your data only when necessary, in the following cases:
- Cloud infrastructure providers: AWS / Google Cloud / Microsoft Azure (server hosting), all ISO 27001 certified
- Payment Gateway: 2C2P, GBPrimePay, Stripe — all PCI-DSS Level 1 certified
- Communication providers: LINE, SendGrid, Twilio (for notifications)
- Government agencies: Upon an official request under the law or a court order
- Legal/accounting advisors: To the extent necessary for business administration, under confidentiality agreements
Your Rights as a Data Subject
Under the Personal Data Protection Act (PDPA), you have the following rights:
Data Retention Period
We retain your data only as long as necessary to fulfill the purposes for which it was collected:
- User account data: For the lifetime of the account + 90 days after service cancellation
- Transaction data / receipts: 5 years, as required by the Revenue Code
- Login / security log data: 1 year
- Cookies: Depending on cookie type — up to 12 months
- Legally required data: For the period required by law
After these periods, we willdelete the data or render it non-identifiable (anonymize) in accordance with appropriate standards
Cross-Border Data Transfers
By default, we store your data in data centers located in Thailand If data is transferred abroad (e.g., to cloud providers in Singapore or the United States), we will:
- Choose destination countries with data protection standards equivalent to or higher than Thailand's
- Maintain a Data Processing Agreement with overseas service providers
- Use Standard Contractual Clauses (SCCs) in line with international practice
- Notify you and obtain your consent where required
Security Measures
We employ both technical and organizational security measures to protect your data:
- Data encryption: SSL/TLS for data in transit · AES-256 for data at rest
- Authentication: Hashed passwords (bcrypt) + support for 2-Factor Authentication (TOTP)
- Access control: Role-based Access Control (RBAC) · Audit log of every action
- Data backup: Daily backups retained for 30 days · Disaster Recovery Plan
- Security testing: Annual penetration testing · Semi-annual security audits
- Employee training: All employees complete PDPA and Information Security training
Use of Cookies
Our website uses cookies to remember your settings, analyze usage, and deliver relevant content. Our cookies fall into 4 categories:
- Essential Cookies: Essential for the website to function — cannot be disabled
- Analytics Cookies: Google Analytics for usage analytics — can be disabled
- Marketing Cookies: Facebook Pixel, Google Ads for personalized advertising — can be disabled
- Functional Cookies: Remember your language, theme, and personal settings — can be disabled
You can manage your cookie preferences via the Cookie Banner shown on your first visit, or through your own browser settings
Minors' Data
Our services are designed for business operators and are not directed at minors under 20 years of age. We do not knowingly collect data from minors. If we discover that a minor's data has been collected without parental consent, we will delete it immediately
Changes to This Policy
We reserve the right to update this policy to reflect changes in the law or improvements to our services. Material changes will be communicated to you via:
- An announcement on our website
- An email notification to registered users
- An in-system notification via GutePOS / GuteStyle
Continued use after changes take effect constitutes your acceptance of the updated policy
Contact us about personal data
If you have questions or concerns about your privacy, or wish to exercise your rights under the PDPA, please contact our data controller through the channels below: