Privacy Policy for Cloudtoplex
This Privacy Policy explains how Cloudtoplex collects, uses, shares and safeguards personal data in connection with our legal services for cloud companies. The policy covers visitors to cloudtoplex.link, clients that engage our advisory or contract services, and individuals whose data we process in the course of providing legal and compliance support. We describe data categories, purposes, legal bases, retention practices and the rights available to data subjects. Our approach reflects applicable Thai law and commonly accepted international standards relevant to cloud operations and cross-border processing.
Definitions
For clarity, the following terms are used throughout this policy to describe data types, processing activities and actors involved in providing legal services to cloud companies.
Data We Collect
We collect personal data that is necessary for delivering legal services, managing client relationships, securing our systems and meeting legal obligations. Collection sources include data you provide directly, data captured automatically and information from third parties where permitted.
Data You Provide Directly
When you contact us, register for services, or enter into an engagement, we may collect the following categories of information to perform contractually and legally required tasks.
- Contact and identity details: full name, job title, corporate email, corporate phone number and company name.
- Engagement information: scope of services, contract terms, service-level information and documentation relevant to legal advice.
- Billing and administrative data: billing address, invoicing information and business identification numbers when required for contracting.
- Communications: emails, meeting notes and correspondence related to legal matters and requests for support.
- Technical and operational documentation provided by clients for compliance reviews and contract drafting.
- Explicit consent records where you opt in to newsletters, marketing communications or additional services.
Automatically Collected Data
When you use cloudtoplex.link or interact with our digital services, we automatically gather information needed for security, performance and analytics.
- Device and browser information, including user agent and screen resolution.
- Network data such as IP address and approximate geolocation inferred from network routing.
- Usage logs and timestamps recording pages visited, actions taken and resources accessed.
- Cookies and similar tracking technologies used for site functionality and analytics.
- Error reports and diagnostics generated when issues or security events occur.
- Performance metrics used to measure and improve the delivery of our online content.
Data from Third Parties
We may receive data about you from partners, service providers and public sources where necessary for service delivery and legal compliance.
- Analytics and technology providers that help us understand site usage and performance.
- Cloud infrastructure and hosting providers that process data necessary for service delivery.
- Professional service providers and external counsel engaged to assist with specific client matters.
Purposes of Processing
We process personal data for limited, specific purposes aligned to service delivery, compliance and legitimate business needs. Each purpose is documented and supported by a legal basis.
- Provision and management of legal services, including advice, contract drafting and regulatory engagement.
- Performance of contracts with clients and potential clients, and fulfilment of pre-contractual obligations.
- Security, incident response and fraud detection to protect client information and our systems.
- Regulatory compliance, dispute resolution and responding to lawful requests from authorities.
- Operational analytics and service improvement, including website analytics and performance measurement.
- Communications and account administration, including billing, notifications and case management.
- Marketing communications where individuals have expressly opted in to receive such materials.
- Evaluations required for mergers, acquisitions or business continuity planning, subject to appropriate safeguards.
Legal Bases for Processing
We rely on established legal bases to process personal data, appropriate to the relevant jurisdiction and the nature of the processing activity.
- Performance of a contract: processing necessary to provide legal services and fulfil contractual obligations.
- Legal obligation: processing necessary to comply with applicable laws, regulations and court orders.
- Legitimate interests: processing for security, fraud prevention, business operations and service improvement when those interests are balanced against individual rights.
- Consent: where required, we will process personal data on the basis of explicit consent for specific purposes such as marketing.
GDPR and International Standards
For individuals subject to EU data protection law, Cloudtoplex observes GDPR principles where relevant. We implement measures to respect data subject rights and ensure appropriate safeguards for international transfers.
- Right of access: you may request confirmation of whether we process your data and request a copy.
- Right to rectification: you may request correction of inaccurate or incomplete personal data.
- Right to erasure: subject to legal limits, you may request deletion of personal data we hold about you.
- Right to restriction of processing: you may request restriction for certain processing activities in defined circumstances.
- Right to data portability: where processing is based on consent or contract, you may request a machine-readable copy of your data.
- Right to object: you may object to processing based on legitimate interests or direct marketing; we will assess and respond in accordance with applicable law.
Data Sharing and Disclosure
We share personal data only as necessary for service delivery, legal compliance or with your consent. Third-party recipients are selected for their ability to meet contractual and security requirements.
- Affiliates and group entities that support service delivery and administrative functions.
- Service providers such as cloud hosts, analytics vendors, communication platforms and payment processors.
- Professional advisors and external counsel engaged to provide subject-matter expertise.
- Governmental or regulatory bodies where disclosure is required by law or to protect legal rights.
- Third parties in connection with business transactions such as mergers or asset transfers, subject to due diligence and confidentiality safeguards.
- Recipients that provide security, monitoring and incident response services to protect client data and infrastructure.
International Data Transfers
Cloudtoplex may transfer personal data to jurisdictions outside Thailand, including locations where our service providers operate. Transfers are necessary for cloud service support, legal research and multi-jurisdictional regulatory engagement.
Where transfers occur, we implement appropriate safeguards such as data processing agreements, standard contractual clauses, technical controls and encryption to maintain a level of protection consistent with applicable law.
Data Retention
We retain personal data only for the period necessary to fulfil the purposes described, to meet legal or regulatory obligations and to resolve disputes or enforce agreements.
Account and client engagement records are retained for the duration of the engagement and for up to seven years after closure when required for regulatory compliance and recordkeeping in legal matters.
Communications and case-related correspondence are retained for the duration of the matter and commonly for up to two years after matter closure to support potential follow-up and compliance checks.
Security logs and access records are generally retained for up to one year to support incident response, monitoring and forensic analysis, subject to regulatory or operational exceptions.
When personal data is no longer required, we securely delete or anonymize it. Deletion requests are processed in accordance with legal obligations; residual copies may persist in backups for operational reasons for a limited time.
Security of Personal Data
Protecting personal data is a core component of our legal service offering. We apply technical and organizational measures designed to protect confidentiality, integrity and availability of data appropriate to the risks involved.
- Encryption in transit and at rest for sensitive data and secure channels for all client communications.
- Access controls, role-based permissions and least-privilege principles applied to internal systems and document repositories.
- Regular security assessments, vulnerability scanning and incident response protocols supported by third-party audits where appropriate.
Your Rights
Depending on jurisdiction and applicable law, you may have rights regarding access, correction, deletion and portability of your personal data. We provide mechanisms to exercise those rights in a transparent manner.
- To exercise your data rights or make inquiries, contact our privacy team at [email protected] or by mail to Thanon Phahon Yothin, Bangkok District, Bangkok 10210, Thailand. For urgent matters you may call +66956990187.
- If you are unsatisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority, such as the Personal Data Protection Committee in Thailand or the appropriate regulator for your jurisdiction.
- Right to rectification: You may request correction of inaccurate or incomplete personal data we hold about you.
- Right to erasure: You can request deletion of personal data when retention is no longer necessary or processing lacks lawful basis.
- Right to restriction of processing: You may request that processing be limited while accuracy or lawful basis is verified.
- Right to data portability: Where applicable, you can request a structured, commonly used, machine-readable copy of personal data you provided.
- Right to object: You may object to processing based on legitimate interests or for direct marketing; we will review and respond to reasonable objections.
- Right to lodge a complaint: If you are not satisfied with our response, you may contact the relevant supervisory authority in Thailand or pursue other legal remedies.
Exercising Your Privacy Rights
To exercise any of the privacy rights listed above, submit a request to Cloudtoplex through the contact channels below. Include your name, Business ID or company identifier where relevant, a description of the data or processing you wish to address, and proof of identity or authorization when acting on behalf of an organization. We will verify requests to prevent unauthorized disclosures. Requests related to business records should reference Cloudtoplex services at cloudtoplex.link and include sufficient detail to locate the information.
Cloudtoplex aims to acknowledge and respond to valid privacy requests promptly. In most cases we will provide an initial response within 30 days of receipt; complex requests may require additional time, during which we will inform you of any reasonable extension.
Marketing Communications
Cloudtoplex may use contact details you provide to send information about services, events, updates to legal frameworks that affect cloud companies, and invitations to webinars. Marketing communications are relevant to legal, compliance, and commercial matters for cloud businesses operating in Thailand and the region.
You may opt out of marketing communications at any time by following the unsubscribe link in any marketing message or by contacting Cloudtoplex via the details below. Unsubscribing will not affect transactional communications about services you receive.
Children and Minors
Our services are directed to businesses and professionals. Cloudtoplex does not knowingly collect personal data from persons under the age of majority in Thailand. If we become aware that we have collected such data without appropriate parental or guardian consent, we will take steps to delete it as required by law.
Third-Party Links and Services
Cloudtoplex may link to third-party websites, tools, and service providers, including cloud infrastructure vendors, analytics providers, and legal research platforms. We do not control those third parties and are not responsible for their privacy practices. Review the privacy notices of any third-party site before providing personal information.
Changes to This Privacy Notice
We periodically review and may update this privacy policy to reflect changes in our services, legal obligations, or business practices. The effective date for the current version is 09-03-2026. Material changes will be published at cloudtoplex.link and notified as appropriate to affected contacts.