PDPA Compliance · 2562

Privacy Policy

We respect and value the privacy of all our users — this document explains how GutePOS and GuteStyle collect, use, disclose, and safeguard your data in accordance with the Personal Data Protection Act B.E. 2562 (2019)

Updated: May 2026 Version 2.0 Thai / English
SECTION 1

Data We Collect

We may collect your personal data through your use of the GutePOS / GuteStyle system, our website, or your inquiries. This data falls into 4 main categories:

  • Identity and contact data: Full name, email address, phone number, shop/salon address, tax identification number (if any)
  • Transaction data: Order history, active package details, billing information · We do not store full credit card data — we use only PCI-DSS certified payment gateways
  • Service data (as data processor): Employee/stylist data, customer data entered into the system by users, bookings, receipts, payslips, and reports — we act as a Data Processor under the instructions of the system user (Data Controller)
  • Technical data: IP address, browser type, OS, cookies, website visit statistics, login logs
Important Note
We do not collect Sensitive Personal Data such as race, religion, or health information, except where necessary for a specific service (e.g., hair dye/chemical allergy information in salons, voluntarily provided by customers)
SECTION 2

Purposes of Data Use

We collect and use your data for the following purposes:

  • Service delivery: To enable you to use GutePOS and GuteStyle to their full potential
  • Transaction processing: Issuing receipts, tax invoices, invoices, and purchase orders
  • Communications: Notifying you of system updates, license renewals, or special benefits
  • Analytics and improvement: Improving our products and services to better meet your needs
  • Security: Detecting and preventing misuse, account theft, and security breaches
  • Legal compliance: To fulfill legal obligations, such as issuing tax invoices (e-Tax Invoice)
SECTION 3

Disclosure of Data to Third Parties

We will never sell or rent your personal data to third parties. We may disclose your data only when necessary, in the following cases:

  • Cloud infrastructure providers: AWS / Google Cloud / Microsoft Azure (server hosting), all ISO 27001 certified
  • Payment Gateway: 2C2P, GBPrimePay, Stripe — all PCI-DSS Level 1 certified
  • Communication providers: LINE, SendGrid, Twilio (for notifications)
  • Government agencies: Upon an official request under the law or a court order
  • Legal/accounting advisors: To the extent necessary for business administration, under confidentiality agreements
SECTION 4

Your Rights as a Data Subject

Under the Personal Data Protection Act (PDPA), you have the following rights:

Right of Access Request access to and a copy of your personal data
Right to Rectification Request that your data be corrected, completed, and kept up to date
Right to Erasure Request deletion or destruction of your data (Right to be Forgotten)
Right to Restriction Request a temporary suspension of the use of your data
Right to Withdraw Consent Withdraw previously given consent at any time
Right to Data Portability Request your data in a machine-readable format
Right to Object Object to the collection, use, or disclosure of your data
Right to Lodge a Complaint File a complaint with the Office of the Personal Data Protection Committee
Response Time
We will respond to your rights request within 30 days from the date the request is received · Submit requests via email dpo@gutepos.com or LINE Official @gutepos
SECTION 5

Data Retention Period

We retain your data only as long as necessary to fulfill the purposes for which it was collected:

  • User account data: For the lifetime of the account + 90 days after service cancellation
  • Transaction data / receipts: 5 years, as required by the Revenue Code
  • Login / security log data: 1 year
  • Cookies: Depending on cookie type — up to 12 months
  • Legally required data: For the period required by law

After these periods, we willdelete the data or render it non-identifiable (anonymize) in accordance with appropriate standards

SECTION 6

Cross-Border Data Transfers

By default, we store your data in data centers located in Thailand If data is transferred abroad (e.g., to cloud providers in Singapore or the United States), we will:

  • Choose destination countries with data protection standards equivalent to or higher than Thailand's
  • Maintain a Data Processing Agreement with overseas service providers
  • Use Standard Contractual Clauses (SCCs) in line with international practice
  • Notify you and obtain your consent where required
SECTION 7

Security Measures

We employ both technical and organizational security measures to protect your data:

  • Data encryption: SSL/TLS for data in transit · AES-256 for data at rest
  • Authentication: Hashed passwords (bcrypt) + support for 2-Factor Authentication (TOTP)
  • Access control: Role-based Access Control (RBAC) · Audit log of every action
  • Data backup: Daily backups retained for 30 days · Disaster Recovery Plan
  • Security testing: Annual penetration testing · Semi-annual security audits
  • Employee training: All employees complete PDPA and Information Security training
SECTION 8

Use of Cookies

Our website uses cookies to remember your settings, analyze usage, and deliver relevant content. Our cookies fall into 4 categories:

  • Essential Cookies: Essential for the website to function — cannot be disabled
  • Analytics Cookies: Google Analytics for usage analytics — can be disabled
  • Marketing Cookies: Facebook Pixel, Google Ads for personalized advertising — can be disabled
  • Functional Cookies: Remember your language, theme, and personal settings — can be disabled

You can manage your cookie preferences via the Cookie Banner shown on your first visit, or through your own browser settings

SECTION 9

Minors' Data

Our services are designed for business operators and are not directed at minors under 20 years of age. We do not knowingly collect data from minors. If we discover that a minor's data has been collected without parental consent, we will delete it immediately

SECTION 10

Changes to This Policy

We reserve the right to update this policy to reflect changes in the law or improvements to our services. Material changes will be communicated to you via:

  • An announcement on our website
  • An email notification to registered users
  • An in-system notification via GutePOS / GuteStyle

Continued use after changes take effect constitutes your acceptance of the updated policy

SECTION 11

Contact us about personal data

If you have questions or concerns about your privacy, or wish to exercise your rights under the PDPA, please contact our data controller through the channels below:

Data Controller · GutePOS / GuteStyle

dpo@gutepos.com @gutepos 02-XXX-XXXX Monday–Friday 9:00–18:00
External Complaints
If you are not satisfied with our response, you may file a complaint with the Office of the Personal Data Protection Committee (PDPC) at pdpc.or.th