Specialized legal data handling for cloud companies

Privacy Policy for Cloudtoplex

This Privacy Policy explains how Cloudtoplex collects, uses, shares and safeguards personal data in connection with our legal services for cloud companies. The policy covers visitors to cloudtoplex.link, clients that engage our advisory or contract services, and individuals whose data we process in the course of providing legal and compliance support. We describe data categories, purposes, legal bases, retention practices and the rights available to data subjects. Our approach reflects applicable Thai law and commonly accepted international standards relevant to cloud operations and cross-border processing.

09-02-2026 Cloudtoplex Co., Ltd., Business ID 7961985249315; Thanon Phahon Yothin, Bangkok District, Bangkok 10210, Thailand Thanon Phahon Yothin, Bangkok District, Bangkok 10210, Thailand [email protected]
01

Definitions

For clarity, the following terms are used throughout this policy to describe data types, processing activities and actors involved in providing legal services to cloud companies.

Personal data means information that identifies or can reasonably be used to identify an individual, such as name, contact details, identification numbers, job title and professional contact information. Processing refers to any operation performed on personal data, including collection, recording, organization, structuring, storage, retrieval, consultation, use, disclosure by transmission, erasure and destruction. User refers to any individual who visits cloudtoplex.link, registers for services, or is a contact within an organisation that engages Cloudtoplex for legal services. Service means the legal advisory, contract drafting, compliance assessments, and regulatory liaison provided by Cloudtoplex to cloud industry clients. Cookies are small text files placed on a device to store preferences and track interactions; they enable basic functionality, analytics and performance measurement on cloudtoplex.link.
02

Data We Collect

We collect personal data that is necessary for delivering legal services, managing client relationships, securing our systems and meeting legal obligations. Collection sources include data you provide directly, data captured automatically and information from third parties where permitted.

Data You Provide Directly

When you contact us, register for services, or enter into an engagement, we may collect the following categories of information to perform contractually and legally required tasks.

  • Contact and identity details: full name, job title, corporate email, corporate phone number and company name.
  • Engagement information: scope of services, contract terms, service-level information and documentation relevant to legal advice.
  • Billing and administrative data: billing address, invoicing information and business identification numbers when required for contracting.
  • Communications: emails, meeting notes and correspondence related to legal matters and requests for support.
  • Technical and operational documentation provided by clients for compliance reviews and contract drafting.
  • Explicit consent records where you opt in to newsletters, marketing communications or additional services.

Automatically Collected Data

When you use cloudtoplex.link or interact with our digital services, we automatically gather information needed for security, performance and analytics.

  • Device and browser information, including user agent and screen resolution.
  • Network data such as IP address and approximate geolocation inferred from network routing.
  • Usage logs and timestamps recording pages visited, actions taken and resources accessed.
  • Cookies and similar tracking technologies used for site functionality and analytics.
  • Error reports and diagnostics generated when issues or security events occur.
  • Performance metrics used to measure and improve the delivery of our online content.

Data from Third Parties

We may receive data about you from partners, service providers and public sources where necessary for service delivery and legal compliance.

  • Analytics and technology providers that help us understand site usage and performance.
  • Cloud infrastructure and hosting providers that process data necessary for service delivery.
  • Professional service providers and external counsel engaged to assist with specific client matters.
03

Purposes of Processing

We process personal data for limited, specific purposes aligned to service delivery, compliance and legitimate business needs. Each purpose is documented and supported by a legal basis.

  • Provision and management of legal services, including advice, contract drafting and regulatory engagement.
  • Performance of contracts with clients and potential clients, and fulfilment of pre-contractual obligations.
  • Security, incident response and fraud detection to protect client information and our systems.
  • Regulatory compliance, dispute resolution and responding to lawful requests from authorities.
  • Operational analytics and service improvement, including website analytics and performance measurement.
  • Communications and account administration, including billing, notifications and case management.
  • Marketing communications where individuals have expressly opted in to receive such materials.
  • Evaluations required for mergers, acquisitions or business continuity planning, subject to appropriate safeguards.

Legal Bases for Processing

We rely on established legal bases to process personal data, appropriate to the relevant jurisdiction and the nature of the processing activity.

  • Performance of a contract: processing necessary to provide legal services and fulfil contractual obligations.
  • Legal obligation: processing necessary to comply with applicable laws, regulations and court orders.
  • Legitimate interests: processing for security, fraud prevention, business operations and service improvement when those interests are balanced against individual rights.
  • Consent: where required, we will process personal data on the basis of explicit consent for specific purposes such as marketing.

GDPR and International Standards

For individuals subject to EU data protection law, Cloudtoplex observes GDPR principles where relevant. We implement measures to respect data subject rights and ensure appropriate safeguards for international transfers.

  • Right of access: you may request confirmation of whether we process your data and request a copy.
  • Right to rectification: you may request correction of inaccurate or incomplete personal data.
  • Right to erasure: subject to legal limits, you may request deletion of personal data we hold about you.
  • Right to restriction of processing: you may request restriction for certain processing activities in defined circumstances.
  • Right to data portability: where processing is based on consent or contract, you may request a machine-readable copy of your data.
  • Right to object: you may object to processing based on legitimate interests or direct marketing; we will assess and respond in accordance with applicable law.
04

Cookies and Tracking Technologies

We use cookies and similar technologies to provide site functionality, measure performance and support analytics necessary to maintain a secure and usable website.

Common types include session cookies (temporary), persistent cookies (retain settings) and third-party cookies used by analytics or embedded services.

Cookies fall into necessary (site functionality), performance (analytics), functional (preferences) and targeting categories; only non-essential cookies are used with consent where required.

You can manage cookie preferences through your browser settings and opt-out tools provided via the website. Disabling certain cookies may affect site functionality.

Cookie Policy and preferences

Data Sharing and Disclosure

We share personal data only as necessary for service delivery, legal compliance or with your consent. Third-party recipients are selected for their ability to meet contractual and security requirements.

  • Affiliates and group entities that support service delivery and administrative functions.
  • Service providers such as cloud hosts, analytics vendors, communication platforms and payment processors.
  • Professional advisors and external counsel engaged to provide subject-matter expertise.
  • Governmental or regulatory bodies where disclosure is required by law or to protect legal rights.
  • Third parties in connection with business transactions such as mergers or asset transfers, subject to due diligence and confidentiality safeguards.
  • Recipients that provide security, monitoring and incident response services to protect client data and infrastructure.

International Data Transfers

Cloudtoplex may transfer personal data to jurisdictions outside Thailand, including locations where our service providers operate. Transfers are necessary for cloud service support, legal research and multi-jurisdictional regulatory engagement.

Where transfers occur, we implement appropriate safeguards such as data processing agreements, standard contractual clauses, technical controls and encryption to maintain a level of protection consistent with applicable law.

Data Retention

We retain personal data only for the period necessary to fulfil the purposes described, to meet legal or regulatory obligations and to resolve disputes or enforce agreements.

Account and client engagement records are retained for the duration of the engagement and for up to seven years after closure when required for regulatory compliance and recordkeeping in legal matters.

Communications and case-related correspondence are retained for the duration of the matter and commonly for up to two years after matter closure to support potential follow-up and compliance checks.

Security logs and access records are generally retained for up to one year to support incident response, monitoring and forensic analysis, subject to regulatory or operational exceptions.

When personal data is no longer required, we securely delete or anonymize it. Deletion requests are processed in accordance with legal obligations; residual copies may persist in backups for operational reasons for a limited time.

Security of Personal Data

Protecting personal data is a core component of our legal service offering. We apply technical and organizational measures designed to protect confidentiality, integrity and availability of data appropriate to the risks involved.

  • Encryption in transit and at rest for sensitive data and secure channels for all client communications.
  • Access controls, role-based permissions and least-privilege principles applied to internal systems and document repositories.
  • Regular security assessments, vulnerability scanning and incident response protocols supported by third-party audits where appropriate.
05

Your Rights

Depending on jurisdiction and applicable law, you may have rights regarding access, correction, deletion and portability of your personal data. We provide mechanisms to exercise those rights in a transparent manner.

  • To exercise your data rights or make inquiries, contact our privacy team at [email protected] or by mail to Thanon Phahon Yothin, Bangkok District, Bangkok 10210, Thailand. For urgent matters you may call +66956990187.
  • If you are unsatisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority, such as the Personal Data Protection Committee in Thailand or the appropriate regulator for your jurisdiction.
  • Right to rectification: You may request correction of inaccurate or incomplete personal data we hold about you.
  • Right to erasure: You can request deletion of personal data when retention is no longer necessary or processing lacks lawful basis.
  • Right to restriction of processing: You may request that processing be limited while accuracy or lawful basis is verified.
  • Right to data portability: Where applicable, you can request a structured, commonly used, machine-readable copy of personal data you provided.
  • Right to object: You may object to processing based on legitimate interests or for direct marketing; we will review and respond to reasonable objections.
  • Right to lodge a complaint: If you are not satisfied with our response, you may contact the relevant supervisory authority in Thailand or pursue other legal remedies.

Exercising Your Privacy Rights

To exercise any of the privacy rights listed above, submit a request to Cloudtoplex through the contact channels below. Include your name, Business ID or company identifier where relevant, a description of the data or processing you wish to address, and proof of identity or authorization when acting on behalf of an organization. We will verify requests to prevent unauthorized disclosures. Requests related to business records should reference Cloudtoplex services at cloudtoplex.link and include sufficient detail to locate the information.

[email protected]

Cloudtoplex aims to acknowledge and respond to valid privacy requests promptly. In most cases we will provide an initial response within 30 days of receipt; complex requests may require additional time, during which we will inform you of any reasonable extension.

Marketing Communications

Cloudtoplex may use contact details you provide to send information about services, events, updates to legal frameworks that affect cloud companies, and invitations to webinars. Marketing communications are relevant to legal, compliance, and commercial matters for cloud businesses operating in Thailand and the region.

You may opt out of marketing communications at any time by following the unsubscribe link in any marketing message or by contacting Cloudtoplex via the details below. Unsubscribing will not affect transactional communications about services you receive.

Children and Minors

Our services are directed to businesses and professionals. Cloudtoplex does not knowingly collect personal data from persons under the age of majority in Thailand. If we become aware that we have collected such data without appropriate parental or guardian consent, we will take steps to delete it as required by law.

Third-Party Links and Services

Cloudtoplex may link to third-party websites, tools, and service providers, including cloud infrastructure vendors, analytics providers, and legal research platforms. We do not control those third parties and are not responsible for their privacy practices. Review the privacy notices of any third-party site before providing personal information.

Changes to This Privacy Notice

We periodically review and may update this privacy policy to reflect changes in our services, legal obligations, or business practices. The effective date for the current version is 09-03-2026. Material changes will be published at cloudtoplex.link and notified as appropriate to affected contacts.