ฉบับภาษาอังกฤษอยู่ด้านล่าง — อ่านฉบับภาษาอังกฤษ · หากสองฉบับมีความหมายต่างกัน ให้ยึดฉบับภาษาไทย
BrandOS เป็นพื้นที่ทำงานด้านแบรนด์ ให้บริการโดย บริษัท ซิมพลิซิส จำกัด (“ซิมพลิสิส”, “เรา”) ซึ่งจดทะเบียนในประเทศไทย สำนักงานตั้งอยู่ที่ 126/33 หมู่ 5 ตำบลรัษฎา อำเภอเมืองภูเก็ต จังหวัดภูเก็ต 83000 เลขทะเบียนนิติบุคคล 0825558000140
นโยบายนี้ครอบคลุมเว็บแอปพลิเคชัน BrandOS (รวมถึงเว็บแอปแบบติดตั้งได้) และช่องทาง LINE ที่องค์กรลูกค้าอาจเลือกเชื่อมต่อ โดยอธิบายว่าระบบเก็บข้อมูลส่วนบุคคลอะไรจริง ๆ ใช้เพื่ออะไร ใครเป็นผู้รับข้อมูล เก็บไว้นานเท่าใด และคุณมีสิทธิอะไรบ้างตามพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA)
BrandOS เป็นเครื่องมือสำหรับธุรกิจที่ให้บริการแก่องค์กรลูกค้า ไม่มีการสมัครใช้งานสาธารณะด้วยตนเอง — บัญชีถูกสร้างโดยคำเชิญจากซิมพลิสิสหรือจากผู้ดูแลระบบขององค์กรลูกค้าเท่านั้น
สำหรับเนื้อหาที่องค์กรลูกค้าและพนักงานนำเข้าสู่พื้นที่ทำงานของแบรนด์ — องค์ความรู้ของแบรนด์ สินทรัพย์แบรนด์ เอกสาร งานออกแบบ และข้อความสนทนากับผู้ช่วยของแบรนด์ — องค์กรลูกค้าเป็นผู้กำหนดวัตถุประสงค์และวิธีการใช้ข้อมูลนั้น องค์กรลูกค้าจึงเป็น “ผู้ควบคุมข้อมูลส่วนบุคคล” และซิมพลิสิสเป็น “ผู้ประมวลผลข้อมูลส่วนบุคคล” ซึ่งประมวลผลเพียงเพื่อให้บริการและสนับสนุนบริการตามที่อธิบายไว้ที่นี่
สำหรับข้อมูลที่จำเป็นต่อการดำเนินระบบ BrandOS เอง — บัญชีและโปรไฟล์ของคุณ บันทึกการเป็นสมาชิกองค์กร คำเชิญ บันทึกความยินยอม บันทึกความปลอดภัยและโฮสติ้ง ข้อมูลการใช้งาน และรายงานข้อบกพร่อง — ซิมพลิสิสเป็นผู้ควบคุมข้อมูลส่วนบุคคล
หากคุณเป็นพนักงานขององค์กรลูกค้าและต้องการใช้สิทธิเกี่ยวกับเนื้อหาในพื้นที่ทำงาน เราจะส่งคำขอไปยังองค์กรของคุณและให้ความช่วยเหลือ ส่วนข้อมูลบัญชีและข้อมูลระดับแพลตฟอร์ม คุณติดต่อเราได้โดยตรง (ข้อ 9)
บัญชีและโปรไฟล์: อีเมล ชื่อ รูปโปรไฟล์ (แบบสำเร็จรูปที่เลือกหรือภาพที่อัปโหลด) และข้อมูลรับรองการเข้าสู่ระบบ รหัสผ่านถูกจัดการโดยผู้ให้บริการยืนยันตัวตนของเรา (Supabase Auth) และจัดเก็บในรูปแบบแฮชเท่านั้น เราไม่เห็นรหัสผ่านของคุณ
การเข้าสู่ระบบด้วย Google (ทางเลือก): ในกรณีที่เราเปิดใช้การเข้าสู่ระบบผ่านบัญชีโซเชียลสำหรับ BrandOS และคุณเลือกใช้ Google จะส่งกลับมาให้เรา ได้แก่ อีเมลของบัญชี Google นั้น สถานะว่า Google ยืนยันอีเมลนั้นแล้วหรือไม่ ชื่อของคุณ รูปโปรไฟล์ Google และตัวระบุที่ผูกบัญชี Google นั้นเข้ากับบัญชี BrandOS ของคุณ เราขอจาก Google เพียงชื่อ อีเมล และรูปโปรไฟล์เท่านั้น เราไม่ได้รับรหัสผ่าน Google ของคุณ และไม่ได้รับสิทธิ์เข้าถึง Gmail, Drive หรือบริการอื่นใดของ Google ส่วนสิ่งที่ Google เองรับรู้จากการเข้าสู่ระบบนั้นเป็นไปตามนโยบายความเป็นส่วนตัวของ Google เอง การเข้าสู่ระบบด้วยวิธีนี้ไม่ได้สร้างบัญชีที่ใช้งานได้ขึ้นมาเองโดยลำพัง — ยังต้องมีคำเชิญ และบัญชี Google ที่ไม่มีคำเชิญจะถูกนำออกจากระบบทันทีพร้อมคำอธิบายว่าบัญชีที่นี่สร้างขึ้นอย่างไร ทั้งนี้ผู้ให้บริการยืนยันตัวตนของเรามีการบันทึกความพยายามเข้าสู่ระบบครั้งนั้นไว้ หากคุณไม่เคยได้รับคำเชิญและต้องการให้ลบบันทึกนั้น กรุณาติดต่อตามที่อยู่ในข้อ 15 แล้วเราจะลบให้
การเป็นสมาชิกและคำเชิญ: คุณเป็นสมาชิกองค์กรและแบรนด์ใด และมีบทบาทอะไร คำเชิญจะเก็บอีเมลผู้ถูกเชิญ บทบาทที่กำหนด วันหมดอายุ และค่าแฮชทางเดียว (SHA-256) ของโทเคนคำเชิญ — ตัวโทเคนเองไม่ถูกจัดเก็บ
บันทึกความยินยอม: เมื่อคุณยอมรับเอกสารทางกฎหมายเหล่านี้ เราบันทึกว่าเอกสารใด เวอร์ชันใด เวลาใด และ — เพื่อคุณภาพของพยานหลักฐาน — ที่อยู่ IP และตัวระบุเบราว์เซอร์ (user-agent) ของคำขอที่ยอมรับ
แชท: ข้อความที่คุณสนทนากับผู้ช่วยของแบรนด์ถูกจัดเก็บ (เนื้อหาข้อความ ภาษา เวลา) พร้อมบันทึกการสนทนาซึ่งรวมอีเมลของคุณ ตัวระบุเซสชันแบบแฮช และชื่อหัวข้อการสนทนา
รายงานข้อบกพร่องและข้อเสนอแนะ: เมื่อคุณเลือกส่งรายงาน ระบบจะเก็บคำอธิบายของคุณ อีเมลบัญชี หน้าที่คุณอยู่ บริบททางเทคนิค (user-agent ของเบราว์เซอร์ ขนาดหน้าต่าง เวอร์ชันของแอป) ข้อความ error/warning จากคอนโซลไม่เกิน 25 รายการ (แต่ละรายการตัดทอนที่ 400 ตัวอักษร) และประวัติการโต้ตอบ 30 ครั้งล่าสุดของคุณในแอป (การคลิก การนำทาง คำสั่ง — พร้อมป้ายชื่อองค์ประกอบไม่เกิน 120 ตัวอักษรต่อรายการ)
ส่วนที่ละเอียดที่สุดของรายงานคือตัวระบุองค์ประกอบที่คุณปักหมุด และเราขอระบุให้ครบแทนการสรุปรวบรัด: อาจรวมข้อความที่มองเห็นได้ขององค์ประกอบนั้นไม่เกิน 80 ตัวอักษร และอีกไม่เกิน 80 ตัวอักษรจากองค์ประกอบแม่ที่มีป้ายกำกับใกล้ที่สุด แอตทริบิวต์ HTML ขององค์ประกอบนั้น ผลตรวจลักษณะการแสดงผลขององค์ประกอบนั้นและองค์ประกอบข้างเคียงอีกไม่เกิน 8 รายการ ลำดับชั้นองค์ประกอบแม่ไม่เกิน 12 ระดับที่อธิบายการซ้อนชั้นของหน้าจอ ณ จุดนั้น และการคาดเดาว่าคอมโพเนนต์และไฟล์ต้นฉบับใดเป็นผู้วาดองค์ประกอบนั้น นอกจากนี้รายงานยังเก็บสถานะพื้นที่ทำงาน (เช่น งานออกแบบและเครื่องมือที่ใช้อยู่) และภาพหน้าจอที่คุณแนบ — ไม่เกิน 4 ภาพ จัดเก็บอยู่ภายในตัวรายงานเอง การพิมพ์ด้วยเสียงในหน้าต่างรายงานถูกถอดความบนอุปกรณ์ของคุณ — ไฟล์เสียงไม่ถูกอัปโหลด
ข้อมูลการใช้งานเชิงวิเคราะห์ (เฉพาะเมื่อคุณยินยอม — ข้อ 11): เหตุการณ์ผลิตภัณฑ์ที่มีชื่อกำกับ เช่น “ใช้ฟีเจอร์” พร้อมองค์กร แบรนด์ ตัวระบุเซสชันสุ่มรายแท็บ รหัสผู้ใช้ภายใน ภาษา ประเภทอุปกรณ์อย่างหยาบ (มือถือ/แท็บเล็ต/เดสก์ท็อป) และช่องทาง คุณสมบัติของเหตุการณ์ถูกจำกัดให้เป็นค่าง่าย ๆ จำกัดขนาด และอีเมลถูกลบทิ้งก่อนจัดเก็บ เหตุการณ์วิเคราะห์ไม่รวมที่อยู่ IP ลายนิ้วมือเบราว์เซอร์ หรือข้อความใด ๆ ที่คุณพิมพ์ — ชื่อคุณสมบัติที่จะพาข้อความที่คุณพิมพ์เข้ามาได้ เช่น คำค้น คำถาม หรือคำสั่ง ถูกปฏิเสธโดยตัวบันทึกบนอุปกรณ์ของคุณเอง ก่อนที่เหตุการณ์จะถูกส่งออกไปที่ใด และถูกปฏิเสธซ้ำอีกครั้งโดยเซิร์ฟเวอร์ของเราเมื่อได้รับ เพราะบริการที่รับเหตุการณ์ผ่านอินเทอร์เน็ตย่อมสันนิษฐานไม่ได้ว่าผู้ส่งได้กรองข้อมูลมาแล้ว เหตุการณ์ที่เซิร์ฟเวอร์ของเราบันทึกอยู่ภายใต้ความยินยอมเดียวกันกับเหตุการณ์ที่บันทึกในเบราว์เซอร์ หากคุณไม่ได้เลือก “ยอมรับทั้งหมด” จะไม่มีการบันทึกเหตุการณ์ใดของคุณเลย
ช่องทาง LINE (เฉพาะเมื่อองค์กรของคุณเชื่อมต่อและคุณใช้งาน): LINE user ID ของคุณ และหากมี ชื่อที่แสดงและรูปโปรไฟล์ LINE พร้อมการเชื่อมโยงระหว่างตัวตน LINE นั้นกับบัญชี BrandOS ของคุณ เนื้อหาข้อความ LINE ถูกประมวลผลเพื่อตอบคุณแต่ไม่ถูกจัดเก็บโดย BrandOS — เก็บเพียงบันทึกทางเทคนิคอายุสั้น (รายการกันเหตุการณ์ซ้ำ เก็บราว 7 วัน และโทเคนเชื่อมบัญชีแบบแฮชใช้ครั้งเดียว)
บันทึกโฮสติ้งและความปลอดภัย: ผู้ให้บริการโฮสติ้งของเรา (Vercel) เก็บบันทึกคำขอมาตรฐานซึ่งรวมที่อยู่ IP เป็นส่วนหนึ่งของการดำเนินโครงสร้างพื้นฐาน ภายในแอปพลิเคชัน ที่อยู่ IP ถูกบันทึกเฉพาะในบันทึกความยินยอม (ข้างต้น) และเป็นกุญแจจำกัดอัตราแบบอายุสั้นตอนเชื่อมบัญชี LINE เท่านั้น
ไม่มีตัวติดตามโฆษณาและไม่มีเครื่องมือวิเคราะห์ของบุคคลที่สาม: BrandOS ไม่โหลด Google Analytics ไม่มีพิกเซลโซเชียล ไม่มีสคริปต์วัดผลของบุคคลที่สาม ข้อมูลการใช้งานเป็นของเราเอง ต้องได้รับความยินยอมก่อน และจัดเก็บในฐานข้อมูลของเราเอง
ไม่มีเนื้อหาดิบในข้อมูลวิเคราะห์: ระบบวัดการใช้งานเก็บค่าที่สรุปแล้ว (ชื่อเหตุการณ์ ช่วงค่า จำนวน) ไม่เก็บข้อความคำสั่ง คำค้น หรือเอกสารของคุณ มีข้อความเดียวที่เราเก็บไว้โดยเจตนา คือข้อความแจ้งข้อผิดพลาดทางเทคนิค เช่น “HTTP 500 on /api/chat” เพราะเป็นข้อความที่โค้ดของเราเขียนขึ้นเอง ไม่ใช่ข้อความที่คุณพิมพ์ และหากไม่มีข้อความนี้ก็ไม่อาจวินิจฉัยข้อขัดข้องได้
ไม่อัปโหลดเสียงเพื่อการพิมพ์ด้วยเสียงหรือคำบรรยาย: การถอดเสียงเป็นข้อความทำงานในเบราว์เซอร์บนอุปกรณ์ของคุณทั้งหมด และเสียงของคุณไม่ออกจากเครื่อง — ใน BrandOS ไม่มีจุดให้บริการถอดเสียงฝั่งเซิร์ฟเวอร์อยู่เลย สิ่งที่ถูกดาวน์โหลดคือตัวซอฟต์แวร์รู้จำเสียงเอง ได้แก่ ไฟล์น้ำหนักโมเดลจาก CDN ของ Hugging Face และตัวรันไทม์จาก CDN ของ jsDelivr ทั้งสองเป็นการดาวน์โหลดไฟล์ตามปกติ CDN แต่ละรายจึงเห็นเพียงที่อยู่ IP ของคำขอ ไม่มีข้อมูลอื่น และทั้งสองรายอยู่ในรายชื่อข้อ 7 ตัวโมเดลมีขนาดใหญ่ — ราว 200 MB — และถูกดาวน์โหลดครั้งเดียวเมื่อคุณเปิดแอปครั้งแรก โดยมีแถบแสดงความคืบหน้าให้เห็น จากนั้นเบราว์เซอร์จะเก็บไว้ในแคช และจะข้ามการดาวน์โหลดทั้งหมดหากอุปกรณ์ของคุณแจ้งว่าอยู่ในโหมดประหยัดเน็ตหรือเครือข่ายแบบคิดค่าปริมาณ
เราไม่เก็บข้อมูลส่วนบุคคลอ่อนไหวตาม PDPA ม.26 โดยเจตนา และขอให้คุณอย่าอัปโหลดข้อมูลดังกล่าวเข้าสู่พื้นที่ทำงานของแบรนด์
สร้างและดำเนินการบัญชีของคุณ ให้บริการพื้นที่ทำงาน แชท งานออกแบบ และช่องทางต่าง ๆ — การปฏิบัติตามสัญญา (ม.24(3))
สร้างคำตอบ งานออกแบบ และสื่อด้วย AI จากข้อมูลแบรนด์ขององค์กรคุณ — การปฏิบัติตามสัญญา (ม.24(3))
ความปลอดภัย การป้องกันการใช้งานในทางที่ผิด การจำกัดอัตราการใช้ และการวิเคราะห์ปัญหาของระบบ (รวมถึงรายงานข้อบกพร่องที่คุณเลือกส่ง) — ประโยชน์โดยชอบด้วยกฎหมาย (ม.24(5))
บันทึกการยอมรับเอกสารเหล่านี้และความยินยอมตาม PDPA ของคุณ — หน้าที่ตามกฎหมายและประโยชน์โดยชอบด้วยกฎหมายในการมีพยานหลักฐานความยินยอม (ม.24(1), ม.24(5))
การวิเคราะห์การใช้งานผลิตภัณฑ์ — ความยินยอม (ม.19) ซึ่งคุณให้หรือปฏิเสธได้ในแบนเนอร์คุกกี้ และถอนได้ (ข้อ 11)
การปฏิบัติตามกฎหมายไทย รวมถึงหน้าที่ทางภาษีและบัญชีสำหรับการเรียกเก็บเงินเชิงพาณิชย์ (ดำเนินการนอกผลิตภัณฑ์) — หน้าที่ตามกฎหมาย (ม.24(6))
เมื่อคุณใช้ผู้ช่วยแชท สิ่งต่อไปนี้ถูกส่งไปยังผู้ให้บริการโมเดล AI ของเราเพื่อสร้างคำตอบ: ข้อความของคุณ บทสนทนาก่อนหน้าในการสนทนาเดียวกัน และส่วนที่เกี่ยวข้องขององค์ความรู้แบรนด์ที่ผ่านการกำกับดูแล ความจำของแบรนด์ และข้อความจากเอกสารที่ถูกค้นคืน
เพื่อให้เนื้อหาแบรนด์ค้นหาได้ ข้อความเอกสารและคำอธิบายสินทรัพย์ถูกส่งไปยังผู้ให้บริการประเภทเดียวกันเพื่อคำนวณ embeddings (ตัวแทนเชิงตัวเลข) และเพื่ออธิบาย/จัดหมวดสินทรัพย์ที่อัปโหลด ภาพของสินทรัพย์ถูกวิเคราะห์โดยโมเดลวิชัน
ผู้ให้บริการโมเดลปัจจุบันของเราสำหรับแชท embeddings และวิชันคือ OpenAI (api.openai.com) ประมวลผลในสหรัฐอเมริกา ตามข้อกำหนด API ของ OpenAI (ตรวจสอบเมื่อ 10 ส.ค. 2026) ข้อมูลที่ส่งผ่าน API จะไม่ถูกใช้ฝึกโมเดลของ OpenAI เว้นแต่ลูกค้าเลือกยินยอมเอง — เราไม่ได้เลือกยินยอม — และ OpenAI เก็บอินพุต/เอาต์พุตของ API เพื่อเฝ้าระวังการใช้งานในทางที่ผิดไม่เกิน 30 วัน เว้นแต่กฎหมายกำหนดให้นานกว่า
ฟีเจอร์เสียงใน Studio (แปลงข้อความเป็นเสียง การแปลงเสียง เอฟเฟกต์เสียง การโคลนเสียง) ส่งข้อความหรือเสียงที่เกี่ยวข้องไปยัง ElevenLabs (สหรัฐอเมริกา) เพื่อสร้างผลลัพธ์ ข้อกำหนดความเป็นส่วนตัวของ ElevenLabs เองกำกับการเก็บและการใช้ข้อมูลนั้น หากองค์กรของคุณไม่ต้องการให้อินพุตเสียงถูกประมวลผลโดย ElevenLabs โปรดอย่าใช้ฟีเจอร์เสียง
การลบพื้นหลังภาพใน Studio เมื่อเปิดใช้งาน จะส่งภาพที่กำลังแก้ไขไปยังบริการลบพื้นหลังภายนอกเพื่อสร้างภาพตัดพื้นหลัง — ไม่ Adobe Firefly/Photoshop API ก็ผู้ให้บริการทางเลือกที่ตั้งค่าไว้สำหรับการติดตั้งนั้น ปัจจุบันยังไม่ได้เปิดใช้งาน: ไม่มีการตั้งค่าผู้ให้บริการรายใดไว้ จึงไม่มีภาพใดถูกส่งออกไป และฟีเจอร์จะรายงานว่าใช้งานไม่ได้ ที่ระบุไว้ตรงนี้ก็เพื่อให้การเปิดใช้งานเป็นการเปลี่ยนแปลงที่บันทึกไว้ในนโยบาย ไม่ใช่การเปลี่ยนอย่างเงียบ ๆ
ผู้ให้บริการ AI อาจเปลี่ยนแปลงได้ตามพัฒนาการของบริการ รายชื่อในข้อ 7 คือรายชื่อปัจจุบันที่ถือเป็นทางการ การเปลี่ยนแปลงที่สำคัญจะแจ้งผ่านนโยบายเวอร์ชันใหม่ ซึ่งระบบจะขอให้คุณยอมรับก่อนใช้งานต่อ (ข้อ 14)
Supabase, Inc. — ฐานข้อมูล การยืนยันตัวตน และพื้นที่จัดเก็บไฟล์สำหรับข้อมูลพื้นที่ทำงานและบัญชีทั้งหมด — โฮสต์ในประเทศออสเตรเลีย (ภูมิภาคเอเชียแปซิฟิก ซิดนีย์)
Vercel, Inc. — โฮสต์แอปพลิเคชัน การส่งเนื้อหา และบันทึกคำขอ — สหรัฐอเมริกาและเครือข่าย edge ทั่วโลก
OpenAI (OpenAI, L.L.C. / OpenAI Ireland Ltd) — การสร้างข้อความ embeddings และการเข้าใจภาพด้วย AI สำหรับฟีเจอร์ในข้อ 6 — สหรัฐอเมริกา
ElevenLabs, Inc. — การสร้างเสียงด้วย AI สำหรับฟีเจอร์เสียงใน Studio — สหรัฐอเมริกา
Google LLC — “เข้าสู่ระบบด้วย Google” เฉพาะเมื่อคุณเลือกเข้าสู่ระบบด้วยวิธีนี้ — สหรัฐอเมริกา Google รับรู้ว่ามีการเข้าสู่ระบบมายังแอปพลิเคชันของเรา ส่วนเราได้รับชื่อ อีเมล และรูปโปรไฟล์ของคุณ การเข้าสู่ระบบด้วย Microsoft และ Meta นั้นซอฟต์แวร์รองรับแต่ยังไม่ได้เปิดใช้: ปัจจุบันมีเพียง Google เท่านั้น และการเปิดใช้รายอื่นเท่ากับเพิ่มผู้รับข้อมูล ซึ่งต้องออกนโยบายเวอร์ชันใหม่ก่อน
Adobe Inc. (Firefly / Photoshop API) — การลบพื้นหลังภาพใน Studio — สหรัฐอเมริกา ปัจจุบันยังไม่ได้เปิดใช้งาน (ข้อ 6): ไม่มีการตั้งค่าผู้ให้บริการลบพื้นหลังไว้ จึงไม่มีภาพใดไปถึง
LY Corporation (LINE) — แพลตฟอร์มรับส่งข้อความ เฉพาะเมื่อองค์กรของคุณเชื่อมต่อช่องทาง LINE — ญี่ปุ่น/ไทย ภายใต้ข้อกำหนดของ LINE เอง
Hugging Face (CDN) — ส่งมอบไฟล์น้ำหนักโมเดลรู้จำเสียงสำหรับใช้บนอุปกรณ์เท่านั้น ได้รับที่อยู่ IP ของคำขอดาวน์โหลด และไม่มีข้อมูลส่วนบุคคลอื่น
jsDelivr (ดำเนินการโดย Prospect One) — CDN โค้ดสาธารณะ ส่งมอบตัวรันไทม์ของการรู้จำเสียงบนอุปกรณ์ — สหภาพยุโรป บนเครือข่าย edge ทั่วโลก ได้รับที่อยู่ IP ของคำขอดาวน์โหลด และไม่มีข้อมูลส่วนบุคคลอื่น
ผู้ให้บริการเหล่านี้ตั้งอยู่นอกประเทศไทย ข้อมูลส่วนบุคคลจึงถูกโอนระหว่างประเทศ คณะกรรมการคุ้มครองข้อมูลส่วนบุคคลยังไม่ได้ประกาศรายชื่อประเทศที่มีมาตรฐานเพียงพอ เราจึงอาศัยมาตรการคุ้มครองที่เหมาะสมตาม PDPA ม.29 — ผู้ให้บริการแต่ละรายประมวลผลข้อมูลภายใต้ข้อสัญญาคุ้มครองข้อมูล (DPA) ที่ผูกพันให้คุ้มครองข้อมูลและใช้เพียงเพื่อให้บริการแก่เรา — ประกอบกับความจำเป็นของการโอนเพื่อการปฏิบัติตามสัญญากับคุณ (ม.28(5)) นโยบายนี้คือหนังสือแจ้งการโอนข้อมูลดังกล่าวถึงคุณ
เราจะปรับรายชื่อนี้ให้เป็นปัจจุบัน และแจ้งการเปลี่ยนแปลงที่สำคัญผ่านนโยบายเวอร์ชันใหม่ที่ต้องยอมรับอีกครั้ง
ข้อมูลบัญชี โปรไฟล์ และการเป็นสมาชิก: ตลอดอายุบัญชี จากนั้นถูกลบผ่านกระบวนการในข้อ 10
กรอบเวลาการเก็บรักษาถูกกำหนดไว้ในซอฟต์แวร์แล้ว: ข้อความแชท 24 เดือน เหตุการณ์การใช้งานเชิงวิเคราะห์ 24 เดือน และรายงานข้อบกพร่อง/ข้อเสนอแนะ 12 เดือน — แต่ละรายการเป็นกรอบแบบหมุนเวียน ปรับค่าได้ แต่ไม่สั้นกว่า 30 วัน
เราต้องระบุสถานะของกรอบเวลาเหล่านั้นให้ชัด เพราะอ่านผ่าน ๆ อาจเข้าใจว่าเป็นคำสัญญาที่ทำอยู่แล้ว ความจริงคืองานลบตามกำหนดเวลายังไม่ทำงาน: ส่วนประกอบของฐานข้อมูลที่งานนั้นต้องใช้ยังไม่ได้ติดตั้ง จึงยังไม่มีข้อมูลใดถูกลบตามตารางนี้เลย และยังไม่มีข้อมูลใดมีอายุถึงกรอบดังกล่าวด้วย เพราะ BrandOS เพิ่งเริ่มเก็บข้อมูลเหล่านี้ในปี 2569 ระหว่างที่ตารางยังไม่เดิน การลบเกิดขึ้นเมื่อได้รับคำขอ (ข้อ 9) และผ่านการลบบัญชี (ข้อ 10) เราจะปรับข้อนี้เมื่อระบบเริ่มทำงานจริง แทนที่จะบรรยายกลไกที่คุณยังพึ่งพาไม่ได้ในขณะนี้
บันทึกการสนทนา (ชื่อหัวข้อและเมทาเดทา) เก็บไว้จนกว่าจะถูกลบผ่านข้อ 10 หรือเมื่อได้รับคำขอ
คำเชิญ: ลิงก์คำเชิญหมดอายุใน 14 วัน บันทึกคำเชิญ (อีเมลผู้ถูกเชิญ บทบาท สถานะ) คงอยู่ในบันทึกการบริหารขององค์กร หากภายหลังบุคคลนั้นขอลบบัญชี BrandOS อีเมลที่เก็บไว้จะถูกแทนที่ด้วยค่าแฮชทางเดียว
บันทึกความยินยอมและการยอมรับ: เก็บไว้ตลอดอายุบัญชีของคุณ ในฐานะหลักฐานว่าคุณยอมรับอะไรและเมื่อใด บันทึกเหล่านี้ผูกอยู่กับบัญชีของคุณ การลบบัญชีจึงลบบันทึกเหล่านี้ไปด้วย (ข้อ 10) นโยบายเวอร์ชันก่อนหน้าระบุในข้อนี้ว่าบันทึกดังกล่าวคงอยู่หลังการลบบัญชี ซึ่งขัดกับข้อ 10 และเป็นข้อความที่ผิด — ข้อ 10 คือข้อที่ถูกต้อง สิ่งที่คงอยู่หลังการลบคือบันทึกคำขอลบเอง ซึ่งเก็บอีเมลของคุณไว้เป็นค่าแฮชทางเดียวเท่านั้น มากพอจะจับคู่คำขอได้ โดยไม่ต้องเก็บตัวอีเมลไว้
บันทึกทางเทคนิคของ LINE: รายการกันเหตุการณ์ซ้ำถูกลบหลังราว 7 วัน โทเคนเชื่อมบัญชีใช้ครั้งเดียวและหมดอายุ
เอกสารเชิงพาณิชย์และภาษี (เก็บนอกผลิตภัณฑ์): ตามที่กฎหมายบัญชีและภาษีของไทยกำหนด
เนื้อหาพื้นที่ทำงานของแบรนด์ (องค์ความรู้ สินทรัพย์ งานออกแบบ): เก็บไว้จนกว่าองค์กรของคุณจะลบหรือปิดพื้นที่ทำงาน กรณีการยุติบริการ ดูข้อกำหนดในการให้บริการ
ภายใต้ข้อจำกัดของ PDPA คุณมีสิทธิ: ขอเข้าถึงและขอสำเนาข้อมูลส่วนบุคคลของคุณ ขอแก้ไขข้อมูลที่ไม่ถูกต้อง ขอลบหรือทำให้ไม่สามารถระบุตัวตน ขอระงับการประมวลผล คัดค้านการประมวลผล ขอโอนย้ายข้อมูลที่คุณให้ไว้ในรูปแบบที่เครื่องอ่านได้ และถอนความยินยอมได้ตลอดเวลา (โดยไม่กระทบการประมวลผลที่ชอบด้วยกฎหมายก่อนหน้า)
วิธีใช้สิทธิ: ส่งอีเมลถึง thoetphong@simplisisdesign.com หรือสำหรับการลบบัญชี ใช้เมนู การตั้งค่า → ความเป็นส่วนตัวและข้อมูล → ขอลบข้อมูล ในผลิตภัณฑ์ คำขอเข้าถึงและโอนย้ายข้อมูลปัจจุบันดำเนินการโดยเจ้าหน้าที่ของเราแบบแมนวล — ยังไม่มีปุ่มส่งออกข้อมูลด้วยตนเอง — และเราตอบภายใน 30 วันนับจากคำขอที่ยืนยันตัวตนแล้ว
กรณีข้อมูลเป็นของพื้นที่ทำงานขององค์กรคุณ (ข้อ 2) เราจะส่งคำขอไปยังองค์กรของคุณซึ่งเป็นผู้ควบคุมข้อมูลผู้มีอำนาจตัดสิน และเราจะช่วยองค์กรในการตอบคุณ
คุณมีสิทธิยื่นเรื่องร้องเรียนต่อคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส. / PDPC) หากเห็นว่าสิทธิของคุณตาม PDPA ถูกละเมิด
คุณขอลบบัญชีได้ทุกเมื่อจาก การตั้งค่า → ความเป็นส่วนตัวและข้อมูล คำขอถูกจัดคิวพร้อมกำหนดวันครบ และเจ้าหน้าที่ของเราดำเนินการลบให้เสร็จภายใน 30 วัน
การลบจะลบออกทั้งหมด: บัญชีเข้าสู่ระบบของคุณ โปรไฟล์ (ชื่อ อีเมล และรูปโปรไฟล์ รวมถึงไฟล์ภาพที่คุณอัปโหลด) การเป็นสมาชิกองค์กร และบันทึกการยอมรับเอกสารเหล่านี้ของคุณ
การลบจะขูดข้อมูลออกแทนการลบทั้งแถว สำหรับรายงานข้อบกพร่อง/ข้อเสนอแนะที่คุณส่ง: ทุกอย่างที่เป็นของคุณในรายงานถูกลบ — อีเมล การอ้างอิงบัญชี หัวข้อและคำอธิบายที่คุณเขียน ข้อความจากคอนโซล ประวัติการโต้ตอบ รายละเอียดเบราว์เซอร์และหน้าต่าง และภาพหน้าจอทั้งหมด สิ่งที่เหลือคือโครงทางวิศวกรรมเท่านั้น ได้แก่ รหัสเคส สถานะ พื้นที่ เส้นทางหน้า เวอร์ชันของแอป และผลการแก้ไข เพราะรหัสเหล่านี้ถูกอ้างอิงอยู่ทั่วบันทึกการแก้ไขของเรา การลบทั้งแถวจะทำให้ประวัติที่ไม่ได้บอกอะไรเกี่ยวกับตัวคุณแล้วขาดวิ่น มีร่องรอยหนึ่งที่เราขอบอกไว้ตรงนี้แทนที่จะปล่อยให้คุณไปพบเอง: อักษรสี่ตัวแรกของรหัสเคสมาจากส่วนหน้าของอีเมลคุณ เมื่อบัญชีและคอลัมน์อีเมลทุกคอลัมน์ถูกลบแล้ว ก็ไม่มีสิ่งใดเหลือให้นำไปจับคู่ได้ จึงเก็บไว้เป็นเพียงรหัสอ้างอิงงาน
การลบจะแทนที่ค่าแทนการลบ ใน 4 จุด: อีเมลที่เก็บอยู่ในบันทึกการสนทนาแชทของคุณถูกล้างเป็นค่าว่าง; อีเมลบนคำเชิญที่ส่งถึงคุณ และบนคำขอลบเอง ถูกแทนที่ด้วยค่าแฮชทางเดียว; และตัวระบุของคุณบนเหตุการณ์การใช้งานเชิงวิเคราะห์ถูกแทนที่ด้วยนามแฝงสุ่มหนึ่งค่า ซึ่งสร้างขึ้น ณ เวลาที่ลบและไม่ถูกเก็บไว้ที่ใดอีก — เพื่อให้ข้อเท็จจริงว่า “เหตุการณ์ชุดนี้เป็นของคนคนเดียว” ยังคงอยู่ ในขณะที่ทุกเส้นทางที่จะย้อนกลับไปว่าคนนั้นคือใครถูกตัดขาด
การลบจะทำให้ไม่ระบุตัวตนแทนการลบ สำหรับงานขององค์กร: เนื้อหาที่คุณสร้างให้องค์กร (งานออกแบบ ไฟล์อัปโหลด การอนุมัติ) ยังคงอยู่กับองค์กร — เป็นข้อมูลขององค์กร — โดยการอ้างอิงตัวผู้สร้างถูกลบออก การลบข้อมูลของบุคคลต้องไม่ทำลายงานของนายจ้างเขา
สิ่งเดียวที่การลบเก็บไว้โดยเจตนา: บันทึกคำขอลบ ในฐานะหลักฐานว่าเราได้ทำตามที่คุณขอ โดยเก็บอีเมลของคุณไว้เป็นค่าแฮชตามที่อธิบายข้างต้นเท่านั้น
ข้อมูลสำรองและบันทึกที่ผู้ให้บริการโครงสร้างพื้นฐานถือครอง จะหมุนเวียนหมดไปตามรอบของผู้ให้บริการนั้น ๆ หลังการลบจากระบบหลัก
ก่อนใช้งานครั้งแรก คุณจะถูกขอให้ยอมรับข้อกำหนดในการให้บริการ นโยบายฉบับนี้ และคำแถลงความยินยอมตาม PDPA ที่ครอบคลุมการโอนข้อมูลระหว่างประเทศตามข้อ 7 การยอมรับแต่ละครั้งถูกบันทึกพร้อมรหัสเอกสาร เวอร์ชันที่ยอมรับ เวลา และที่อยู่ IP กับตัวระบุเบราว์เซอร์ของคำขอ — เพื่อให้สามารถระบุภายหลังได้ว่าคุณยินยอมต่อสิ่งใด
การวิเคราะห์การใช้งานทำงานเฉพาะเมื่อคุณเลือก “ยอมรับทั้งหมด” ในแบนเนอร์คุกกี้ ตัวเลือกของคุณถูกบันทึกไว้สองที่ และทั้งสองที่มีความหมาย: บนอุปกรณ์ของคุณ ซึ่งเป็นตัวหยุดไม่ให้เบราว์เซอร์ส่งเหตุการณ์ออกไป และในบัญชีบันทึกแบบเพิ่มอย่างเดียวชุดเดียวกับความยินยอมอื่น ๆ ของคุณ — พร้อมเวอร์ชันของคำแถลง เวลา และที่อยู่ IP กับตัวระบุเบราว์เซอร์ของคำขอ — ซึ่งเป็นสิ่งที่เซิร์ฟเวอร์ของเราอ่านก่อนบันทึกสิ่งใดก็ตาม การถอนความยินยอมถูกเขียนเป็นรายการใหม่ ไม่ใช่การลบรายการที่เคยให้ไว้ ประวัติว่าคุณตัดสินใจอย่างไรและเมื่อใดจึงยังครบถ้วน
คุณเปลี่ยนตัวเลือกได้ทุกเมื่อที่ การตั้งค่า → ความเป็นส่วนตัวและข้อมูล และมีผลทันทีทั้งสองทิศทาง: เบราว์เซอร์หยุดหรือเริ่มส่งทันที และเหตุการณ์ถัดไปที่เซิร์ฟเวอร์ของเราจะบันทึกก็อ่านการตัดสินใจใหม่ การปฏิเสธเป็นผลลัพธ์ที่สมบูรณ์ในตัวเอง — เราไม่นำกลับมาถามซ้ำเป็นเงื่อนไขของการใช้ BrandOS ต่อ
หากคุณใช้ BrandOS ผ่านช่องทาง LINE ที่เชื่อมต่อไว้เพียงอย่างเดียว คุณจะไม่เห็นแบนเนอร์นี้ จึงไม่มีความยินยอมด้านการวิเคราะห์สำหรับคุณ — ซึ่งหมายความว่าไม่มีการบันทึกเหตุการณ์การใช้งานเชิงวิเคราะห์ของคุณเลย
เมื่อเอกสารมีการเปลี่ยนแปลงที่สำคัญ หมายเลขเวอร์ชันจะถูกปรับขึ้น และระบบจะขอให้คุณยอมรับเวอร์ชันใหม่ก่อนใช้งาน BrandOS ต่อ คำแถลงเรื่องคุกกี้กำหนดเวอร์ชันด้วยหลักเดียวกัน แต่เนื่องจากการปฏิเสธการวิเคราะห์ต้องไม่ขัดขวางการทำงานของคุณ ระบบจึงไม่นำเวอร์ชันใหม่มาเป็นด่านกั้น — แต่คำตอบเดิมของคุณจะสิ้นผล และแบนเนอร์จะถามใหม่ โดยการวิเคราะห์ปิดอยู่จนกว่าคุณจะตอบ นั่นคือภาระทั้งหมดที่เกิดขึ้น และเป็นเหตุผลว่าทำไมคำตอบที่ให้ไว้กับเวอร์ชันเก่าจึงไม่ถูกอ่านเป็นการยอมรับเวอร์ชันใหม่
มาตรการที่มีอยู่จริง: การรับส่งข้อมูลทั้งหมดเข้ารหัสระหว่างทาง (HTTPS/TLS พร้อม HSTS) ข้อมูลที่จัดเก็บอยู่กับผู้ให้บริการที่เข้ารหัสพื้นที่จัดเก็บ รหัสผ่านถูกแฮชโดยผู้ให้บริการยืนยันตัวตน ทุกการอ่าน/เขียนฐานข้อมูลถูกจำกัดขอบเขตตามองค์กรของคุณด้วย row-level security ที่ตรวจสอบฝั่งเซิร์ฟเวอร์ ตารางที่อ่อนไหวเป็นพิเศษ (สิทธิการใช้งาน ข้อมูลช่องทาง รายงานข้อบกพร่อง) ถูกล็อกให้เข้าถึงได้เฉพาะฝั่งเซิร์ฟเวอร์ ไม่มีเส้นทางตรงจากไคลเอนต์ ข้อมูลรับรองช่องทาง LINE เข้ารหัสระดับแอปพลิเคชันด้วย AES-256-GCM โทเคนคำเชิญและโทเคนเชื่อมบัญชีถูกเก็บเป็นแฮชทางเดียวเท่านั้น จุดเชื่อมต่อสำคัญมีการจำกัดอัตราการเรียก และมีการตั้งค่าการป้องกันมาตรฐานของเบราว์เซอร์ (frame, content-type, referrer)
การเข้าถึงโดยเจ้าหน้าที่ซิมพลิสิส: บัญชีปฏิบัติการของซิมพลิสิสจำนวนจำกัดตามรายชื่ออนุญาต ซึ่งถูกตรวจสอบฝั่งเซิร์ฟเวอร์ทุกคำขอ สามารถบริหารพื้นที่ทำงานของลูกค้าข้ามองค์กรเพื่อจัดตั้งและสนับสนุนบริการ การเข้าถึงของเจ้าหน้าที่เป็นหน้าที่งานบริการ ไม่ใช่สิทธิใช้ข้อมูล — เจ้าหน้าที่ปฏิบัติภายใต้นโยบายนี้และหน้าที่รักษาความลับของเรา
ไม่มีระบบใดปลอดภัยสมบูรณ์ และเราไม่กล่าวอ้างใบรับรองที่เราไม่ได้ถือครอง หากเกิดการละเมิดข้อมูลส่วนบุคคลที่มีความเสี่ยงต่อสิทธิของคุณ เราจะแจ้ง สคส. โดยไม่ชักช้าและภายใน 72 ชั่วโมงนับแต่ทราบเหตุ และแจ้งผู้ใช้ที่ได้รับผลกระทบตามที่ PDPA กำหนด
จำเป็นอย่างยิ่ง: คุกกี้เซสชันการยืนยันตัวตนจาก Supabase Auth ทำให้คุณอยู่ในระบบ และถูกต่ออายุระหว่างใช้งาน มีอายุตามเซสชันและรอบต่ออายุ ไม่สามารถปฏิเสธได้ขณะใช้บริการ
การจัดเก็บบนอุปกรณ์ (localStorage และ session storage — ไม่ถูกส่งไปเซิร์ฟเวอร์เพื่อติดตาม): ธีม ภาษาอินเทอร์เฟซ ภาษาเอกสารกฎหมาย ตัวเลือกความยินยอมคุกกี้ และค่ากำหนดอินเทอร์เฟซอื่น ๆ เช่น ขนาดการแสดงผลและเครื่องมือที่ใช้ล่าสุด
อีกสิ่งที่อยู่บนอุปกรณ์ของคุณ และเราขอระบุแยกไว้เพราะเป็นสิ่งที่เป็นส่วนตัวที่สุดในนั้น: เพื่อให้ประวัติการสนทนาเปิดได้ทันที ระบบเก็บสำเนารายการสนทนาและเนื้อหาข้อความของคุณไว้บนเครื่อง ภายใต้กุญแจของบัญชีคุณเอง สำเนานี้อยู่บนอุปกรณ์เท่านั้น ไม่ใช่สำเนาชุดที่สองสำหรับเรา และจะถูกลบเมื่อคุณล้างข้อมูลเว็บไซต์นี้ในเบราว์เซอร์ หากใช้เครื่องร่วมกับผู้อื่น การออกจากระบบไม่ได้ลบสำเนานี้ — หากเป็นเรื่องสำคัญสำหรับคุณ ให้ล้างข้อมูลเว็บไซต์
การวิเคราะห์: เมื่อคุณยินยอม เหตุการณ์การใช้งานของเราเอง (first-party) ถูกบันทึกโดยใช้ตัวระบุเซสชันสุ่มรายแท็บ (ข้อ 3) BrandOS ไม่ตั้งคุกกี้ของบุคคลที่สามหรือคุกกี้โฆษณาใด ๆ ทั้งสิ้น
วิดีโอฝังตัว: การ์ดในคลังแบรนด์อาจฝังตัวเล่นวิดีโอของ YouTube หรือ Vimeo เราโหลดตัวเล่นเหล่านี้จากปลายทางแบบรักษาความเป็นส่วนตัวของผู้ให้บริการ — youtube-nocookie.com และ Vimeo แบบร้องขอไม่ให้ติดตาม (do-not-track) — เพื่อให้วิดีโอบนหน้าไม่ฝังคุกกี้โฆษณาลงบนตัวคุณ อย่างไรก็ตาม ผู้ให้บริการยังคงเห็นคำขอ รวมถึงที่อยู่ IP ของคุณ เมื่อการ์ดที่มีวิดีโอถูกแสดงผล นอกจากนี้ผู้ดูแลระบบยังสามารถวางที่อยู่ตัวเล่นวิดีโอจากผู้ให้บริการรายอื่นได้ด้วย หากทำเช่นนั้น ตัวเล่นนั้นจะถูกโหลดตามที่ระบุไว้ และเราไม่อาจให้คำมั่นข้างต้นเกี่ยวกับคุกกี้ของผู้ให้บริการรายนั้นได้
เมื่อนโยบายนี้เปลี่ยนแปลงอย่างมีนัยสำคัญ เราจะเผยแพร่เวอร์ชันใหม่พร้อมวันที่มีผลใหม่ และผลิตภัณฑ์จะกำหนดให้คุณยอมรับเวอร์ชันใหม่ก่อนใช้งานต่อ — เราไม่ใช้กลไก “ใช้งานต่อถือว่ายอมรับ” เงียบ ๆ สำหรับการเปลี่ยนแปลงที่สำคัญ
บันทึกการเปลี่ยนแปลง (ข้อ 16) ระบุว่าแต่ละเวอร์ชันเปลี่ยนอะไร
ผู้ประสานงานคุ้มครองข้อมูล: นายเทอดพงษ์ หรรษทานสถิต (กรรมการ) บริษัท ซิมพลิซิส จำกัด, 126/33 หมู่ 5 ตำบลรัษฎา อำเภอเมืองภูเก็ต จังหวัดภูเก็ต 83000, +66 89 176 5252 (สำนักงาน 076-608865), thoetphong@simplisisdesign.com
นโยบายนี้จัดทำเป็นภาษาไทยและภาษาอังกฤษ หากสองฉบับมีความหมายแตกต่างกัน ให้ยึดฉบับภาษาไทยเป็นหลัก
13 ส.ค. 2026 (เวอร์ชันนี้ ฉบับร่าง): การตรวจสอบนโยบายฉบับนี้เทียบกับระบบที่ทำงานจริงพบข้อความ 4 ข้อที่ไม่ตรงกับระบบ และทุกข้อได้รับการแก้ที่ตัวซอฟต์แวร์ ไม่ใช่การผ่อนถ้อยคำในเอกสาร (1) ระบบวิเคราะห์ไม่รับข้อความที่พิมพ์ในช่องค้นหาของคลังแบรนด์อีกต่อไป และตัวบันทึกปฏิเสธคุณสมบัติใด ๆ ที่จะพาข้อความที่พิมพ์เข้ามา — คำสัญญาในข้อ 3 และข้อ 4 เป็นเท็จมาตั้งแต่ช่องค้นหานั้นเริ่มใช้งาน และคำค้นเหล่านั้นยังถูกนำไปแสดงเป็น “หัวข้อ” ในหน้า Insights ขององค์กรผู้ใช้เองด้วย (2) เหตุการณ์ที่เซิร์ฟเวอร์ของเราบันทึกปฏิบัติตามแบนเนอร์คุกกี้แล้ว จากเดิมที่แบนเนอร์กำกับเฉพาะเบราว์เซอร์ของคุณ (3) ปุ่มถอนความยินยอมตามที่อธิบายในข้อ 11 มีอยู่จริงในหน้าการตั้งค่าแล้ว จากเดิมที่การถอนทำได้ทางเดียวคือล้างข้อมูลเว็บไซต์ในเบราว์เซอร์ (4) ตัวเล่นวิดีโอฝังตัวย้ายไปใช้ปลายทางแบบไม่ติดตามของผู้ให้บริการ แก้ไขในเนื้อความ: ข้อการเก็บรักษา ซึ่งเดิมระบุว่าไม่มีกำหนดลบอัตโนมัติ ทั้งที่ซอฟต์แวร์มีกรอบเวลาแล้วแต่ยังทำงานไม่ได้; ความขัดแย้งระหว่างข้อ 8 กับข้อ 10 ว่าบันทึกความยินยอมคงอยู่หลังการลบบัญชีหรือไม่ (คำตอบคือไม่คงอยู่); คำอธิบายที่ต่ำกว่าความจริงว่าการลบบัญชีลบอะไรบ้าง; และคำอธิบายที่ต่ำกว่าความจริงว่ารายงานข้อบกพร่องเก็บอะไรบ้าง เพิ่มเติม: “เข้าสู่ระบบด้วย Google” พร้อมผู้รับข้อมูลที่เกี่ยวข้อง, CDN ของ jsDelivr และผู้ให้บริการลบพื้นหลังที่ยังไม่ได้เปิดใช้งาน
การตรวจสอบรอบที่สองในวันเดียวกันพบเพิ่มอีก และมีสามข้อที่เราขอระบุตรง ๆ แทนการรวบไว้ในรายการข้างต้น หนึ่ง: เหตุการณ์เชิงวิเคราะห์ 6 รายการที่บันทึกไว้ก่อนวันนี้ยังคงเก็บข้อความที่พิมพ์ในช่องค้นหาของคลังแบรนด์ รวมถึงคำที่พิมพ์ค้างกลางคัน การหยุดเก็บเพิ่มไม่ได้ทำให้ข้อมูลเดิมหายไป เราจึงลบข้อความเหล่านั้นออกจากฐานข้อมูล สอง: การปฏิเสธข้อความที่พิมพ์เกิดขึ้นบนอุปกรณ์ของคุณเองก่อนที่เหตุการณ์จะถูกส่งออกไป ไม่ใช่เกิดขึ้นเมื่อมาถึงเซิร์ฟเวอร์ของเราเท่านั้น ถ้อยคำเดิมกล่าวอ้างอย่างแรก ทั้งที่ความจริงมีเพียงอย่างหลัง สาม: คำแถลงเรื่องคุกกี้มีการกำหนดเวอร์ชัน แต่ก่อนหน้าวันนี้การปรับเวอร์ชันไม่มีผลใด ๆ เพราะระบบอ่านคำตอบที่คุณเก็บไว้โดยไม่ตรวจว่าเป็นคำตอบต่อเวอร์ชันใด ความยินยอมที่ให้ไว้กับข้อตกลงที่แคบกว่าจึงถูกอ่านเป็นความยินยอมต่อข้อตกลงที่กว้างกว่า ข้อ 11 อธิบายวิธีจัดการเรื่องนี้แล้ว และซอฟต์แวร์ทำงานตามที่อธิบายไว้ นอกจากนี้ยังแก้ไข: นโยบายฉบับก่อนระบุว่าองค์กรของคุณเป็นผู้เปิดใช้การเข้าสู่ระบบผ่านบัญชีโซเชียล ทั้งที่ผู้เปิดใช้คือเรา; ระบุว่าการเข้าสู่ระบบโดยไม่มีคำเชิญถูกปฏิเสธเฉย ๆ โดยไม่ได้บอกว่าผู้ให้บริการยืนยันตัวตนของเรายังบันทึกความพยายามนั้นไว้; และข้อ 13 ไม่ได้ระบุว่ามีสำเนาประวัติการสนทนาของคุณเก็บอยู่บนอุปกรณ์ของคุณเอง
10 ส.ค. 2026 (ฉบับร่าง): เขียนใหม่ทั้งฉบับโดยตรวจทานทุกบรรทัดกับระบบที่ใช้งานจริง — แก้ไขรายชื่อผู้ประมวลผลช่วง (OpenAI เป็นผู้ให้บริการโมเดล AI; ElevenLabs สำหรับเสียง; ฐานข้อมูลอยู่ออสเตรเลีย) อธิบายกระบวนการลบจริงและสิ่งที่ยังคงอยู่ พฤติกรรมการเก็บรักษาจริง บัญชีบันทึกความยินยอม และตัดข้อกล่าวอ้างที่ระบบไม่ได้ทำจริงออก
19 ก.ค. 2026 (ฉบับร่าง): โครงร่างสองภาษาฉบับแรก
The Thai version is above and governs where the two versions diverge.
BrandOS is a brand workspace operated by Simplisis Co., Ltd. (“Simplisis”, “we”, “us”), a company established in Thailand, registered office 126/33 Moo 5, Ratsada Sub-district, Mueang Phuket District, Phuket 83000, Thailand, company registration no. 0825558000140.
This policy covers the BrandOS web application (including the installable web app) and the optional LINE messaging channel a customer organisation may connect. It describes what personal data the system actually collects, what it is used for, who receives it, how long it is kept, and the rights you have under Thailand’s Personal Data Protection Act B.E. 2562 (PDPA).
BrandOS is a business tool provided to client organisations. There is no self-serve public signup: accounts are created by invitation from Simplisis or from a client organisation’s administrator.
For the content a client organisation and its staff put into their brand workspace — brand knowledge, brand assets, documents, designs, and the text of chat conversations held with the brand assistant — the client organisation decides why and how that data is used. For that data the client organisation is the data controller and Simplisis is the data processor, processing it only to provide and support the service as described here.
For the data needed to run BrandOS itself — your account and profile, workspace membership records, invitations, consent records, security and hosting logs, usage analytics, and bug reports — Simplisis is the data controller.
If you are a member of a client organisation’s staff and want to exercise rights over workspace content, we will route your request to your organisation and assist it; for account and platform data you can come to us directly (section 9).
Account and profile: your email address, name, avatar (a chosen preset or an uploaded image), and your authentication credentials. Passwords are handled by our authentication provider (Supabase Auth) and stored only in hashed form; we never see them.
Signing in with Google (optional): where we have enabled social sign-in for BrandOS and you use it, Google returns to us the email address of that Google account, whether Google has verified that address, your name, your Google profile picture, and the identifiers that tie the Google account to your BrandOS account. We ask Google for nothing beyond your name, email address and profile picture; we never receive your Google password, and we are granted no access to Gmail, Drive, or any other Google service. What Google itself learns from the sign-in is governed by Google’s own privacy policy. Signing in this way does not by itself create a usable account — an invitation is still required, and a Google account with no invitation is signed out again and shown how accounts here are created. Our authentication provider does record that sign-in attempt; if you were never invited and want that record erased, write to the address in section 15 and we will remove it.
Membership and invitations: which organisations and brands you belong to and your role in each. An invitation stores the invited email address, the intended role, an expiry date, and a one-way (SHA-256) hash of the invite token — the token itself is not stored.
Consent records: when you accept these legal documents, we record which document, which version, the time of acceptance, and — for evidence quality — the IP address and browser identifier (user-agent) of the accepting request.
Chat: the messages you exchange with the brand assistant are stored (message text, language, timestamps), together with conversation records that include your email address, a hashed session identifier, and conversation titles.
Bug and feedback reports: when you choose to send a report, it captures your description, your account email, the page you were on, technical context (browser user-agent, window size, the app version), up to 25 recent console error or warning messages (each truncated to 400 characters), and a trail of your last 30 interactions in the app (clicks, navigation, commands — with element labels of up to 120 characters each).
The most detailed part of a bug report is the descriptor of the element you pinned, and we would rather set it out in full than summarise it: it can include up to 80 characters of that element’s visible text and up to 80 more from its nearest labelled ancestor, the element’s HTML attributes, a rendered-appearance probe covering it and up to 8 neighbouring elements, a chain of up to 12 ancestors describing how the page is layered at that point, and a best guess at which interface component and source file drew it. A report also carries the workspace state (for example which design and tool were active) and any screenshots you attach — up to four, stored inside the report record itself. Voice dictation in the report widget is transcribed on your device; the audio is never uploaded.
Usage analytics (only with your consent — section 11): named product events such as “feature used”, with the organisation, brand, a random per-tab session identifier, your internal user ID, language, coarse device class (mobile/tablet/desktop) and channel. Event properties are restricted to simple values, capped in size, and email addresses are redacted before storage. Analytics events do not include your IP address, your browser fingerprint, or the text of anything you typed: property names that would carry typed text — a search term, a query, a prompt — are refused by the recorder on your own device, before an event is sent anywhere, and refused again by our servers on arrival, because a service that accepts events over the internet can never assume the sender cleaned them. Events recorded by our servers are subject to the same consent as events recorded in your browser; if you have not chosen “Accept all”, no event is recorded for you at all.
LINE channel (only if your organisation connects one and you use it): your LINE user ID and, where available, your LINE display name and avatar, plus the link between that LINE identity and your BrandOS account. The text of LINE messages is processed to answer you but is not stored by BrandOS; only short-lived technical records (webhook deduplication entries, kept about 7 days, and hashed single-use linking tokens) are kept.
Hosting and security logs: our hosting provider (Vercel) keeps standard request logs, which include IP addresses, as part of operating the infrastructure. Inside the application, IP addresses are recorded only in the consent ledger (above) and as a short-lived rate-limit key when linking a LINE account.
No advertising trackers and no third-party analytics: BrandOS loads no Google Analytics, no social pixels, no third-party measurement scripts. Usage analytics is first-party, consent-gated, and stored in our own database.
No raw content in analytics: usage telemetry stores derived values (event names, buckets, counts), never the text of your prompts, your searches, or your documents. One text field is deliberately kept — the message of a technical error, for example “HTTP 500 on /api/chat” — because it is written by our own code rather than typed by you, and without it a fault cannot be diagnosed.
No audio uploads for dictation or subtitles: speech-to-text runs entirely in your browser on your device and your audio never leaves your machine — there is no server transcription endpoint in BrandOS at all. What is downloaded is the recognition software itself: the model weights from the Hugging Face CDN and the runtime from the jsDelivr CDN. Those are ordinary file downloads, so each CDN sees the IP address of the request and nothing else; both are listed in section 7. The model is large — roughly 200 MB — and is fetched once when you first open the app, with a visible progress badge, then cached by your browser; it is skipped entirely if your device reports a metered or data-saver connection.
We do not intentionally collect special-category (sensitive) personal data as defined by PDPA §26, and we ask that you do not upload it into brand workspaces.
Creating and operating your account, providing the workspace, chat, design, and channel features — performance of a contract (§24(3)).
Generating AI answers, designs, and media from your organisation’s brand data — performance of a contract (§24(3)).
Security, abuse prevention, rate limiting, and service diagnostics (including bug reports you choose to send) — legitimate interest (§24(5)).
Recording your acceptance of these documents and your PDPA consent — legal obligation and legitimate interest in evidencing consent (§24(1), §24(5)).
Product usage analytics — consent (§19), which you may give or refuse in the cookie banner and may withdraw (section 11).
Complying with Thai law, including tax and accounting obligations for commercial billing (handled outside the product) — legal obligation (§24(6)).
When you use the chat assistant, the following is sent to our AI model provider to generate the answer: your message, the recent turns of the same conversation, and the relevant parts of your organisation’s governed brand knowledge, brand memory, and retrieved document passages.
To make brand content searchable, document text and asset descriptions are sent to the same class of provider to compute embeddings (numerical representations). To describe and classify uploaded brand assets, asset images are analysed by a vision model.
Our current model provider for chat, embeddings, and asset vision is OpenAI (api.openai.com), processed in the United States. Under OpenAI’s API terms (checked 2026-08-10), API data is not used to train OpenAI’s models unless the customer opts in — we have not opted in — and API inputs and outputs are retained by OpenAI for abuse monitoring for up to 30 days unless law requires longer.
Voice features in Studio (text-to-speech, voice transformation, sound effects, voice cloning) send the relevant text or audio to ElevenLabs (United States) to generate the output. ElevenLabs’ own privacy terms govern its retention and use of that data; if your organisation does not want voice inputs processed by ElevenLabs, do not use the voice features.
Background removal in Studio, where it is enabled, sends the image being edited to an external background-removal service to produce the cut-out — either Adobe’s Firefly/Photoshop API or an alternative provider configured for the deployment. It is not enabled today: no such provider is configured, so no image is sent to one and the feature reports itself unavailable. It is named here so that switching it on is a documented change to this policy rather than a silent one.
AI providers may change as the service evolves. The list in section 7 is the authoritative current list; a material change is notified through a new version of this policy, which you will be asked to accept before continuing to use BrandOS (section 14).
Supabase, Inc. — database, authentication, and file storage for all workspace and account data — hosted in Australia (Asia-Pacific region, Sydney).
Vercel, Inc. — application hosting, content delivery, and request logs — United States and a global edge network.
OpenAI (OpenAI, L.L.C. / OpenAI Ireland Ltd) — AI text generation, embeddings, and image understanding for the features in section 6 — United States.
ElevenLabs, Inc. — AI voice generation for Studio voice features — United States.
Google LLC — “Sign in with Google”, and only if you choose to sign in that way — United States. Google learns that a sign-in to our application took place; we receive your name, email address and profile picture. Microsoft and Meta sign-in are supported by the software but are not switched on: Google is the only social sign-in available today, and enabling another one adds a recipient, which requires a new version of this policy first.
Adobe Inc. (Firefly / Photoshop API) — background removal for images in Studio — United States. Not enabled today (section 6): no background-removal provider is configured, so no image reaches one.
LY Corporation (LINE) — messaging platform, only where your organisation connects a LINE channel — Japan/Thailand, under LINE’s own terms.
Hugging Face (CDN) — delivery of the on-device speech-recognition model weights only. It receives the IP address of the download request and no other personal data.
jsDelivr (operated by Prospect One) — public code CDN delivering the on-device speech-recognition runtime — European Union, on a global edge network. It receives the IP address of the download request and no other personal data.
These providers are located outside Thailand, so personal data is transferred internationally. Thailand’s PDPC has not yet designated an adequacy list; we rely on appropriate safeguards under PDPA §29 — each provider processes data under its contractual data-protection terms (data processing agreements/addenda) binding it to protect the data and use it only to provide its service to us — together with the necessity of the transfer for performing our contract with you (§28(5)). This policy is our notice to you of these transfers.
We will keep this list current and notify material changes through a new version of this policy requiring re-acceptance.
Account, profile, and membership data: for the life of the account, then removed through the deletion process in section 10.
Retention windows are set in the software: chat messages 24 months, usage analytics events 24 months, and bug and feedback reports 12 months — each a rolling window, each configurable but never shorter than 30 days.
We have to be exact about the status of those windows, because it would be easy to read them as a promise already being kept. The scheduled job that enforces them is not yet running: the database component it depends on is not installed, so nothing has been deleted on that schedule to date. Nor has anything reached those ages — BrandOS only began holding this data in 2026. Until the schedule runs, deletion happens on request (section 9) and through account deletion (section 10). We will update this section when it starts running, rather than describe a mechanism you cannot presently rely on.
Conversation records (titles and metadata) are kept until deleted through section 10 or on request.
Invitations: invite links expire after 14 days; the invitation record (the invited email address, the role, and the status) remains in the organisation’s administration records. If that person later has their BrandOS account erased, the stored address is replaced by a one-way hash.
Consent and acceptance records: kept for as long as your account exists, as the evidence of what you accepted and when. They are attached to your account, so erasing the account removes them with it (section 10). An earlier version of this policy said in this section that they survived deletion, which contradicted section 10 and was wrong; section 10 was the correct one. What does survive an erasure is the deletion record itself, which stores your email address only as a one-way hash — enough to match a request to it, without keeping the address.
LINE technical records: webhook deduplication entries are pruned after about 7 days; linking tokens are single-use and expire.
Commercial and tax records (kept outside the product): as required by Thai accounting and tax law.
Brand workspace content (knowledge, assets, designs): kept until your organisation deletes it or the workspace is closed; on termination see the Terms of Service.
Subject to the limits in the PDPA you may: request access to and a copy of your personal data; have inaccurate data corrected; request erasure or anonymisation; request restriction of processing; object to processing; request portability of data you provided in a machine-readable form; and withdraw consent at any time (without affecting processing already done lawfully).
How to exercise them: email thoetphong@simplisisdesign.com, or for deletion use Settings → Privacy & data → Request deletion inside the product. Access and portability requests are currently fulfilled manually by our staff — there is no self-serve export button — and we respond within 30 days of a verified request.
Where the data belongs to your organisation’s workspace (section 2), we will route the request to your organisation, which as controller decides on it, and we will assist it in answering you.
You have the right to lodge a complaint with Thailand’s Personal Data Protection Committee (PDPC) if you believe your rights under the PDPA have been violated.
You can request deletion at any time from Settings → Privacy & data. The request is queued with a due date, and our staff complete the purge within 30 days.
Deletion removes outright: your login account; your profile (name, email, and avatar, including any avatar file you uploaded); your organisation memberships; and your recorded acceptances of these documents.
Deletion strips rather than removes, for bug and feedback reports you sent: everything of yours in the report goes — your email address, your account reference, the title and description you wrote, the console messages, the interaction trail, the browser and window details, and any screenshots. What is left is the engineering skeleton: the case code, status, area, route, app version, and how it was resolved, because those references are woven through our repair records and deleting the row would tear holes in a history that no longer says anything about you. One residue we would rather state than leave for you to find: the first four letters of a case code are derived from the local part of your email address. With the account and every email column erased there is nothing left to match them against, so it is kept as a bare ticket reference.
Deletion replaces rather than removes, in four places: the email address held on your chat conversation records is cleared; the address on any invitation to you, and on the deletion request itself, is replaced by a one-way hash; and your identifier on usage analytics events is replaced by a single random pseudonym, generated at the moment of erasure and stored nowhere else — so that “these events belong to one person” survives while every link to who that person was is severed.
Deletion anonymises rather than deletes, for the organisation’s work: content you authored for your organisation (designs, uploads, approvals) stays with the organisation — it is the organisation’s data — with your authorship reference removed. Erasing a person must not destroy their employer’s work.
Deletion keeps one thing on purpose: the deletion request record, as the evidence that we did what you asked, with your email held only as the hash described above.
Backups and logs held by our infrastructure providers cycle out on those providers’ own schedules after deletion from the live system.
Before first use you are asked to accept the Terms of Service, this Privacy Policy, and a PDPA consent statement covering the international transfers in section 7. Each acceptance is recorded with the document key, the exact version accepted, a timestamp, and the IP address and browser identifier of the request — so what you consented to can be identified later.
Usage analytics runs only after you choose “Accept all” in the cookie banner. Your choice is recorded in two places, and both matter: on your device, which is what stops your browser from sending events, and in the same append-only ledger as your other consents — with the statement version, a timestamp, and the IP address and browser identifier of the request — which is what our own servers read before recording anything. A withdrawal is written as its own entry rather than erasing the earlier grant, so the record of what you decided, and when, stays intact.
You can change the choice at any time in Settings → Privacy & data, and either direction takes effect immediately: your browser stops or starts sending on the spot, and the next event our servers would record reads the new decision. Declining is a first-class outcome — it is never re-asked as a condition of continuing to use BrandOS.
If you reach BrandOS only through a connected LINE channel, you are not shown this banner, so no analytics consent exists for you — which means no product analytics event is recorded for you at all.
When a document materially changes, its version number is raised and you will be asked to accept the new version before continuing to use BrandOS. The cookie statement is versioned the same way: because declining analytics must never block your work, a new version of it is not put in front of you as a barrier — instead your earlier answer stops counting and the banner asks again, with analytics off until you answer. That is the whole of the imposition, and it is why an answer given to an older version is never read as agreement to a newer one.
Measures actually in place: all traffic is encrypted in transit (HTTPS/TLS with HSTS); data at rest is stored with providers that encrypt storage; passwords are hashed by our authentication provider; every database read and write is scoped to your organisation through row-level security verified server-side; especially sensitive tables (entitlements, channel data, bug reports) are locked to server-only access with no direct client path; LINE channel credentials are encrypted at the application layer with AES-256-GCM; invite and account-linking tokens are stored only as one-way hashes; key endpoints are rate-limited; and standard browser protections (frame, content-type, referrer policies) are set.
Access by Simplisis staff: a small allowlist of Simplisis operator accounts, verified server-side on each request, can administer client workspaces across organisations to set up and support the service. Operator access is a service function, not a data-use right — operators act under this policy and our confidentiality obligations.
No system is perfectly secure and we do not claim certifications we do not hold. If a personal-data breach occurs that is likely to pose a risk to your rights, we will notify the PDPC without undue delay and within 72 hours of becoming aware of it, and affected users where the PDPA requires.
Strictly necessary: authentication session cookies from Supabase Auth keep you signed in and are refreshed as you use the app; they exist for your session and its refresh window and cannot be declined while using the service.
On-device storage (localStorage and session storage, never sent to a server as tracking): your theme, interface language, legal-document language, cookie-consent choice, and other interface preferences such as display size and recently used tools.
Also on your device, and worth naming separately because it is the most personal thing there: so that your chat history opens instantly, a copy of your conversation list and the text of your messages is held locally under your own account’s key. It stays on the device, it is not a second copy for us, and it is removed when you clear this site’s data in your browser. On a shared computer, signing out does not erase it — clear the site’s data if that matters to you.
Analytics: with your consent, first-party usage events are recorded keyed by a random per-tab session identifier (section 3). BrandOS sets no third-party or advertising cookies of any kind.
Embedded video: a brand library card may embed a YouTube or Vimeo player. We load these from the providers’ privacy-preserving endpoints — youtube-nocookie.com, and Vimeo with do-not-track requested — so that a video on the page does not plant advertising cookies on you. The provider still sees the request, including your IP address, when a card containing a video is displayed. An administrator can also paste an embed address from some other provider; if they do, that player is loaded as given, and the promise above cannot be made about its cookies.
When this policy materially changes we publish a new version with a new effective date, and the product requires you to accept the new version before continued use — silent “continued use means acceptance” is not our mechanism for material changes.
The changelog (section 16) records what changed in each version.
Data protection contact: เทอดพงษ์ หรรษทานสถิต, Director, Simplisis Co., Ltd., 126/33 Moo 5, Ratsada Sub-district, Mueang Phuket District, Phuket 83000, Thailand, +66 89 176 5252 (office 076-608865), thoetphong@simplisisdesign.com. (The director’s name is shown in Thai script, which is the form registered with the Department of Business Development.)
This policy is provided in Thai and English. If the two versions diverge in meaning, the Thai version governs.
2026-08-13 (this version, draft): a full audit of this policy against the running system found four statements that were not true of it. Each was fixed in the software rather than softened here. (1) Analytics no longer receives the text typed into the Library search box, and the recorder now refuses any property that would carry typed text — the promise in sections 3 and 4 had been false since that search box shipped, and those terms were additionally being shown as “topics” on the organisation’s own Insights page. (2) Events recorded by our servers now obey the cookie banner, which until now governed only your browser. (3) The consent withdrawal control described in section 11 now exists in Settings; previously the only way to withdraw was to clear the site’s browser data. (4) Embedded video players moved to their providers’ no-tracking endpoints. Corrected in the text: the retention section, which claimed no schedule existed while the software had one that cannot yet run; the contradiction between sections 8 and 10 over whether consent records survive account deletion (they do not); an understated account of what deletion removes; and an understated account of what a bug report captures. Added: “Sign in with Google” and the recipients it involves, the jsDelivr CDN, and the not-yet-enabled background-removal provider.
A second review of that same day went further, and three of its findings are worth stating plainly rather than folding into the list above. First: six analytics events recorded before this date still held text typed into the Library search box — including partly-typed words — and stopping new collection would not have removed them, so that text was deleted from the database. Second: the refusal of typed text now happens on your own device, before an event is sent, and not only on arrival at our servers; the earlier wording claimed the former when only the latter was true. Third: the cookie statement is versioned, and until this date raising that version changed nothing, because your stored answer was read without checking which version it answered — so an agreement given to a narrower arrangement was being read as agreement to a wider one. Section 11 now describes how that is handled, and the software does what it describes. Also corrected: this policy said your organisation enables social sign-in, when in fact we do; it described an uninvited sign-in as simply refused, without saying that our authentication provider still records the attempt; and section 13 did not mention that a copy of your chat history is kept on your own device.
2026-08-10 (draft): complete rewrite verified line-by-line against the implemented system — corrected the sub-processor list (OpenAI as the AI model provider; ElevenLabs for voice; database region Australia), described the real deletion path and what it leaves, the real retention behaviour, the consent ledger, and removed claims the system does not implement.
2026-07-19 (draft): first bilingual scaffold.