This Data Processing Agreement sets out how you, as a Provider, handle personal data belonging to Veyyā and its Customers. It applies alongside your Service Provider Agreement or Business Provider Agreement, and is required by Thailand's PDPA.
On this page
- Parties and scope
- Definitions
- Roles under PDPA
- Provider Tax Compliance Data
- Identity Verification Service Provider (AppMan)
- Customer Sensitive Personal Information received via Platform
- Data handling obligations
- Security measures
- Data subject rights support
- Sub-processing
- Breach notification
- Retention
- Audit and inspection
- Cross-border transfers
- Term and termination
- General
1. Parties and scope
This Data Processing Agreement ("DPA") is between:
- Veyya Life (Thailand) Limited ("Veyyā", "we"), Registration No. 0105569069061, Bangkok, Thailand; and
- The Provider - the individual Service Provider under COMP-016 or the Business Service Provider under COMP-019.
This DPA supplements your Master Services Agreement (COMP-016 or COMP-019) and governs the processing of personal data under Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA").
2. Definitions
Terms used here have the meanings given in the PDPA or, where relevant, in your Master Services Agreement. "Customer Personal Data" means personal data of Veyyā Customers received through the Platform for the purpose of service delivery. "Customer Sensitive Data" means §26 sensitive personal data of Veyyā Customers shared with the Provider via the Platform for safe service delivery (e.g., health notes).
3. Roles under PDPA
Veyyā · Data Controller of Customer Personal Data and Provider Personal Data.
Provider · Independent Recipient of Customer Personal Data received through the Platform under PDPA §27, and Data Subject of the Provider's own personal data collected by Veyyā.
Regardless of PDPA characterization, the Provider is contractually bound by the obligations in this DPA in respect of Customer Personal Data received through the Platform.
4. Provider Tax Compliance Data
Veyya Life (Thailand) Limited retains the following categories of Provider data for tax compliance:
- Full legal name, Thai Tax ID (= Thai National ID number), registered address
- Bank account details for payout
- Redacted Thai National ID card copy (religion + blood type blacked out by AppMan)
- Form 50 bis Withholding Tax Certificate issuance details
Basis · Legal Obligation (PDPA §24(6); Revenue Code §50, §50 bis, §87/3; Accounting Act B.E. 2543 §14) + Contractual Necessity (PDPA §24(3)).
Retention · Engagement + 10 years.
5. Identity Verification Service Provider (AppMan)
Veyyā engages AppMan Co., Ltd. as a third-party identity verification service provider to perform eKYC and background screening for Providers during onboarding.
The Provider submits identity documents directly through AppMan's secure interface. AppMan performs document authentication, biometric matching, and background screening. AppMan redacts the religion field and blood type field on the Thai ID card image before sending the redacted image to Veyyā. AppMan deletes the raw unredacted image upon verification completion.
AppMan returns to Veyyā:
- Verification outcome (pass/fail + date)
- Verification reference number
- Redacted Thai National ID card image
Raw biometric data (facial photograph, liveness frames) and raw background check reports are processed and retained by AppMan under its own retention and security policies and are NOT stored in Veyyā's systems.
Veyyā and AppMan are bound by a separate Data Processing Agreement governing PDPA obligations and handling of personal data during the verification flow.
6. Customer Sensitive Personal Information received via Platform
6.1 Nature of the data
In the course of providing Services, the Provider may receive from Customers, via the Veyyā Platform, information relating to health, allergies, sensitivities, medical conditions, disabilities, or other matters constituting Sensitive Personal Data under PDPA §26 ("Customer Sensitive Data").
Customer Sensitive Data is collected by Veyyā from the Customer under the Customer's explicit §26 consent (captured at the point of entry) and transmitted to the Provider solely for the purpose of enabling safe and appropriate delivery of the specific Service booked.
6.2 Role allocation
- Veyyā is the Data Controller responsible for collecting and obtaining §26 consent from the Customer
- The Provider receives Customer Sensitive Data as a Recipient under PDPA §27, bound by the obligations in this DPA
- The Provider shall not act as a Data Controller for Customer Sensitive Data for any purpose beyond delivering the booked Service
6.3 Provider obligations
The Provider undertakes that:
- It shall use Customer Sensitive Data only for delivering the specific Service booked
- It shall not screenshot, photograph, copy, transcribe, export, or otherwise reproduce Customer Sensitive Data outside the Veyyā Platform
- It shall not share, disclose, sell, or transfer Customer Sensitive Data to any third party
- It shall not retain Customer Sensitive Data after booking completion plus 7 days (access is automatically revoked)
- It shall apply security measures consistent with PDPA §37(4) to protect Customer Sensitive Data during the period it has access
- It shall report any actual or suspected unauthorized access, use, or disclosure to Veyyā within 24 hours of becoming aware
- It shall indemnify Veyyā for any breach of this clause, including any regulatory fines, claims by affected Customers, or third-party actions arising from the breach
6.4 Customer withdrawal of consent
The Customer may withdraw §26 consent at any time. Upon withdrawal:
- Veyyā will cease transmitting new Customer Sensitive Data to the Provider for that Customer
- The Provider may retain Customer Sensitive Data already received for the booking in which it was used, for the standard 7-day post-booking window
- The Provider shall not retain or use Customer Sensitive Data beyond that window
6.5 Breach consequence
Violation of any obligation in this clause shall constitute a material breach of this Agreement entitling Veyyā to immediate suspension of the Provider's account, removal from the Platform, and recovery of any losses, damages, regulatory fines, or claims arising from the breach.
7. Data handling obligations
The Provider shall:
- Process personal data only for lawful and defined purposes tied to service delivery
- Comply with Veyyā's documented instructions in relation to Customer Personal Data
- Ensure personnel authorized to process personal data are bound by confidentiality obligations
- Implement appropriate technical and organizational measures under PDPA §37(4)
- Not transfer personal data internationally without Veyyā's prior written approval
- Cooperate with Veyyā in responding to Data Subject rights requests
8. Security measures
The Provider shall implement:
- Access control - personnel only, on a need-to-know basis
- Device security - encrypted device storage, screen locks, remote wipe on loss
- Physical security for any printed materials (which should not exist for Customer Sensitive Data per Section 6)
- Regular training for personnel on PDPA obligations
9. Data subject rights support
Where a Data Subject exercises rights (access, portability, correction, erasure, objection) in respect of data held or processed by the Provider, the Provider shall notify Veyyā within 5 business days and support Veyyā in responding within the PDPA statutory timeline.
10. Sub-processing
The Provider shall not engage any sub-processor to handle Customer Personal Data without Veyyā's prior written consent. Personnel of the Provider (employees or sub-contractors of a Business Provider) are treated as Provider personnel bound under this DPA.
11. Breach notification
The Provider shall notify Veyyā within 24 hours of becoming aware of any actual or suspected personal data breach involving Customer Personal Data, including:
- Nature and scope of the breach
- Categories and volume of data affected
- Immediate remediation steps taken
- Any communication with affected Data Subjects
12. Retention
All personal data retention aligns with Annex R (PDPA Retention Schedule v2.1). Key rules for Provider handling of Customer data:
- Customer Sensitive Data · 7 days post-booking maximum (automatic access revocation)
- General Customer data received (name, address, service specifics) · limited to service delivery period; not for retention
- Booking transaction financial data · 10 years (retained by Veyyā, not Provider)
- Communications through Platform · 12 months
13. Audit and inspection
Veyyā may audit the Provider's compliance with this DPA on reasonable notice. The Provider shall cooperate with such audits, including making available records of processing, security measures, personnel training records, and incident logs. Veyyā may audit for cause without notice where a suspected breach requires immediate investigation.
14. Cross-border transfers
The Provider shall not transfer Customer Personal Data outside Thailand without Veyyā's prior written approval and appropriate cross-border transfer safeguards under PDPA §28-29.
15. Term and termination
This DPA runs concurrent with the Master Services Agreement. Obligations survive termination for the period necessary to complete data return or destruction, plus the retention periods in Section 12.
Upon termination, the Provider shall return or destroy all Customer Personal Data in its possession within 30 days, except as required by law.
16. General
Governing law · Laws of Thailand.
Precedence · Where any inconsistency arises between this DPA and the Master Services Agreement, this DPA prevails on matters of personal data processing.
Amendments · Material amendments require 30 days' written notice.
Veyya Life (Thailand) Limited · Bangkok, Thailand
Version history
v4.0 (3 July 2026) - AppMan section restored with DPA-in-place framing (redacted ID handling clarified). Customer Sensitive Personal Information section added with 7-day access window and role allocation. Provider Tax Compliance section retention aligned to 10 years. Sensitive-data outcome residue 3 years. Independent third-party service provider terminology. Annex R reference clause added.