This Notice explains how Veyya Life (Thailand) Limited processes personal data of Service Providers and Business Providers (including authorised signatories and employees). We take our obligations under Thailand's PDPA seriously - this is our honest, complete statement.
On this page
- Data Controller
- Information provided at collection (§23(2))
- Categories of personal data we collect
- Provider ID card handling
- Sensitive Personal Data (§26)
- Lawful bases
- Location data during active bookings
- Customer personal data you may receive
- Sharing and subprocessors
- International transfers
- Retention
- Your rights
- Security
- Contact
1. Data Controller
Veyya Life (Thailand) Limited
Bangkok, Thailand
Registration No. 0105569069061
We are the Data Controller responsible for Provider personal data processed through the Veyyā Platform.
Data Protection Officer · dpo@veyya.com
2. Information provided at collection (§23(2))
Under PDPA §23(2), we inform Service Providers of the purposes of collection, retention periods, categories of recipients, data subject rights, our contact information, and the consequences of failing to provide data. This is delivered through this Notice, the in-app collection notices at each data entry point, and the sensitive data consent flow.
3. Categories of personal data we collect
3.1 Identity and legal documentation
- Full legal name as registered
- Thai National Identification Number (also serves as Tax ID for individuals)
- Registered address on national records
- Date of birth
- Contact details (phone, email)
3.2 Financial and tax
- Bank account details for payout
- Withholding tax records and Form 50 bis certificates
- Booking and payout history
3.3 Verification data
- Verification outcome (pass/fail + date + reference number)
- Redacted Thai National ID card copy (religion + blood type blacked out)
3.4 Operational data
- Skills, certifications, service categories
- Booking history, ratings, reviews
- Real-time GPS during active bookings (Contract Performance basis)
- In-app communications
4. Provider ID card handling
Because this involves PDPA §26 sensitive fields (religion, blood type on Thai ID card), the handling flow is set out below:
- The Service Provider uploads the Thai National ID card during onboarding through AppMan's secure interface
- AppMan performs identity verification (OCR, DOPA check, biometric matching)
- AppMan redacts the religion field and blood type field on the ID image
- AppMan sends Veyyā: (a) verification outcome, (b) redacted ID card image, (c) verification reference number
- AppMan deletes the raw unredacted ID card image upon verification completion
- Veyyā stores the redacted ID card image + name + Tax ID + address as tax deduction evidence for 10 years
- On offboarding: verification outcome purged after 3-year residue window; redacted ID + Tax ID retained for full 10-year financial retention period
Raw unredacted Thai ID card is NOT retained by anyone.
5. Sensitive Personal Data (§26)
For onboarding, we collect the following Sensitive Personal Data through AppMan under explicit consent captured in the Sensitive Personal Data Consent Letter (COMP-017):
- Biometric data (facial photograph, liveness frames) - not retained by Veyyā
- Background screening results (criminal record, bankruptcy, fraud, adverse media, INTERPOL Red Notice, sanctions) - not retained by Veyyā
Only the verification outcomes (pass/fail + date) are retained by Veyyā, for engagement + 3 years.
6. Lawful bases
| Data category | Lawful basis |
|---|---|
| Identity, name, address, Tax ID | Contractual necessity + Legal obligation (Revenue Code) |
| Redacted ID card copy | Contractual necessity + Legal obligation (tax deduction proof) |
| Biometric verification outcome | PDPA §26 explicit consent (COMP-017) |
| Background check outcome | PDPA §26 explicit consent (COMP-017) |
| Bank details and payouts | Contractual necessity + Legal obligation |
| Real-time GPS during bookings | Contractual necessity (PDPA §24(3)) |
| Skills, certifications, ratings | Contractual necessity + Legitimate interest (platform quality) |
| Communications | Contractual necessity |
| Marketing to providers | PDPA §19 consent |
7. Location data during active bookings
Real-time GPS location during active bookings is processed under Contractual Necessity (PDPA §24(3)) for matching, dispatch, in-service navigation, Customer-facing ETA display, safety monitoring, and dispute resolution. No PDPA consent is captured or required. Device-level location permission (iOS/Android runtime prompt) remains subject to the operating system's permission flow. This is standard operational data flow accepted as part of your Service Provider Agreement, not consent-based.
Retention · Live during active booking; raw trace 30 days post-completion; aggregate/anonymized thereafter.
8. Customer personal data you may receive
In the course of delivering Services, you may receive personal data from Customers, including:
- Customer first name and approximate location for booking fulfilment
- Customer notes about the service (e.g., parking instructions, preferences)
- Customer health and safety information (e.g., allergies, sensitivities, medical conditions) where the Customer has given explicit consent under PDPA §26 to share this with you for safe service delivery
You act as a Recipient under PDPA §27, bound by obligations in the Service Provider Master Services Agreement and Provider Data Processing Agreement, including: use only for the specific Service booked; no screenshot, copy, export, or third-party sharing; no retention beyond booking completion + 7 days; report any incidents to Veyyā within 24 hours.
9. Sharing and subprocessors
Identity verification service provider · AppMan Co., Ltd. is engaged to perform eKYC and background screening. Veyyā and AppMan are bound by a separate Data Processing Agreement.
Payment service providers · Omise Co., Ltd. (Thailand) primary; Stripe Thailand Ltd. backup.
Cloud infrastructure · [Provider names] for hosting and storage under Data Processing Agreements.
Group companies · Aggregate and specific data may be transferred to Veyya Holdings Limited (UAE) under Standard Contractual Clauses.
10. International transfers
Providers are Thailand-based. International transfers limited to (a) Veyya Holdings Limited (UAE) intra-group transfer under Standard Contractual Clauses, and (b) named subprocessors under equivalent safeguards under PDPA §28-29.
11. Retention
Complete schedule in Annex R (PDPA Retention Schedule v2.1). Highlights:
| Data category | Retention |
|---|---|
| Tax ID, name, address, WHT records | Engagement + 10 years (Tier 1) |
| Redacted ID card copy | Engagement + 10 years (tax deduction evidence) |
| Executed Agreement bundle (MSA, DPA, consents) | Engagement + 10 years (Tier 2) |
| Bank account raw | Deleted 90 days after final settlement |
| Payout / transaction metadata | 10 years |
| Criminal record outcome (pass/fail) | Engagement + 3 years residue |
| Biometric verification outcome | Engagement + 3 years residue |
| Provider verified date (audit reference) | 10 years (Tier 1) |
| Real-time GPS raw trace | 30 days post-booking |
| Ratings and reviews | Active engagement; anonymized on exit |
| Communications | 12 months |
12. Your rights
You have the rights under PDPA to access (§30), portability (§32), object (§33), correction (§34), erasure (§35, subject to statutory retention), and withdraw consent (§19). Contact dpo@veyya.com or use Provider Settings.
13. Security
Under PDPA §37(4), we implement field-level AES-256 encryption for Sensitive Personal Data, at-rest encryption, TLS 1.3+ in transit, role-based access, and audit logging. We maintain a Record of Processing Activities under PDPA §39(7).
14. Contact
- Data Protection Officer · dpo@veyya.com
- Provider support · providers@veyya.com
You may lodge a complaint with the Personal Data Protection Committee (PDPC).
Veyya Life (Thailand) Limited · Bangkok, Thailand
Version history
v3.0 (3 July 2026) - Data Controller name and legal entity fully corrected. §23(2) informed collection section added. Provider ID card 7-step handling flow described. Sensitive-data outcome residue 3 years. Redacted ID card retention 10 years. Location data as Contract Performance basis. Customer sensitive personal data receipt clause. Independent third-party service provider terminology. AppMan classification aligned with DPA framework. Retention synchronized with Annex R v2.1.