This is our promise to you about the information we collect, how we use it, and how you can control it. Under Thailand's Personal Data Protection Act, we owe you a clear, honest explanation - and this document is it.
On this page
- Who we are (the Data Controller)
- What we tell you when we collect data (§23(2))
- What personal data we collect
- Sensitive Personal Data (§26)
- Why we can process your data (lawful bases)
- Who we share your data with
- International data transfers
- How long we keep your data
- Your rights
- How we keep your data safe
- Age restrictions
- Contact and complaints
1. Who we are
Veyya Life (Thailand) Limited
Bangkok, Thailand
Registration No. 0105569069061
We are the Data Controller responsible for the personal data we process through the Veyyā Platform.
Data Protection Officer · dpo@veyya.com
General privacy questions · privacy@veyya.com
2. What we tell you when we collect data
Under PDPA §23(2), we let you know at the point of collection:
- Why we are collecting the data
- What we are collecting and how long we will keep it
- Who we may share it with
- Your rights (see Section 9)
- How to reach us and our DPO
- What happens if you choose not to provide certain data
- Whether the data is required by law or contract
3. What personal data we collect
3.1 Your account and identity
- Legal name, email, phone number
- Date of birth (optional)
- Profile photo (optional)
3.2 Your address
- Registered address and saved service addresses
- We do not collect real-time GPS from your device. We match providers using the saved addresses you give us.
3.3 Your bookings
- Booking history, preferences, saved providers, service frequency
3.4 Your payments
- Payment tokens (last 4 digits, brand, expiry) - your full card details are held by Omise Co., Ltd. (primary) or Stripe Thailand Ltd. (backup), not by us
- Billing address, transaction history, refund records
3.5 Your communications
- Chat messages, support conversations, feedback
3.6 Ratings and reviews
- Your ratings and reviews of providers
- Photos or videos you provide as evidence
4. Sensitive Personal Data (§26)
Under PDPA §26, these categories of information about you are treated as Sensitive Personal Data:
- Health information (any medical conditions you disclose voluntarily)
- Allergy and sensitivity information
- Medication and treatment information
- Disability information
- Pregnancy and reproductive health
- Religion, race, political opinion (only if you voluntarily disclose)
4.1 Health and safety notes shared with providers
When you make a booking, you can share health and safety information with the assigned provider through the booking notes field. Because this is Sensitive Personal Data under §26, we ask for your explicit consent through the separate Customer Sensitive Personal Data Consent Letter, right at the booking step.
Two modes, you choose
Default (per-booking) · notes are shared with the assigned provider for this booking only and deleted when the booking is complete.
Opt-in persistence · notes are stored in your encrypted profile and reused for future bookings until you withdraw consent or 90 days after account closure. You can toggle this any time in Account Settings.
Provider obligations
Providers who receive your Sensitive Personal Data are bound by their Master Services Agreement (COMP-016) and DPA (COMP-018) to use it only for safe service delivery, not screenshot or copy it, not share it with anyone else, and not to retain it beyond 7 days after your booking is complete.
5. Why we can process your data
| Data category | Lawful basis |
|---|---|
| Account and profile data | Contractual necessity (PDPA §24(3)) |
| Saved addresses | Contractual necessity (PDPA §24(3)) |
| Booking history and transactions | Contract + Legal obligation (Revenue Code) |
| Payment tokens and records | Contract + Legal obligation |
| Communications | Contract + Legitimate interest (service quality) |
| Customer Health Notes (per-booking) | PDPA §26 per-booking necessity |
| Customer Health Notes (persistent) | PDPA §26 explicit consent |
| Marketing communications | PDPA §19 consent |
| Basic platform analytics | Legitimate interest (PDPA §24(5)) |
| Behavioural profiling & personalization | PDPA §19 consent |
| Cookies (functional, analytics, marketing) | PDPA §19 consent per category |
| Fraud prevention and security | Legitimate interest (PDPA §24(5)) |
5.1 Two kinds of analytics
Basic platform analytics (aggregated, non-identifying usage data to improve the service) runs under Legitimate Interest (§24(5)). You can object under §33.
Behavioural profiling and personalized recommendations (individual profiles for targeted offers) runs under explicit consent (§19), captured in the in-app consent centre. You can withdraw any time - it does not affect basic Platform functionality.
6. Who we share your data with
6.1 Your assigned provider
When you book, we share with the assigned provider:
- Your first name and last initial
- Your service address for the booking
- Your booking specifics (service, time, price)
- Your masked phone number (after assignment, for communication)
- Customer Health Notes (only if you have consented under §26)
6.2 Payment service providers
Omise Co., Ltd. (primary) and Stripe Thailand Ltd. (backup) process card payments. Both are bound by DPAs.
6.3 Identity verification service provider
We work with AppMan Co., Ltd. to verify providers (not customers). Your data is not sent to AppMan in the normal course of business.
6.4 Group companies
Data may flow to Veyya Holdings Limited (United Arab Emirates), our group holding company, for consolidated operations, financial reporting, and strategic management - under Standard Contractual Clauses substantially equivalent to those approved under GDPR Article 46.
6.5 Authorities
We may disclose personal data where Thai law, a court order, or a competent regulator requires it (including the Revenue Department, DOPA, or PDPC).
7. International data transfers
Our service providers are currently based in Thailand. International transfers are limited to:
- Group company transfers to Veyya Holdings Limited (UAE) under Standard Contractual Clauses in our Intra-Group Data Transfer Agreement
- Named subprocessors (Omise, Stripe, cloud infrastructure) where limited data may be processed outside Thailand under equivalent safeguards under PDPA §28-29
8. How long we keep your data
The complete retention schedule lives in Annex R (PDPA Retention Schedule v2.1). Here are the highlights for your data:
| Data category | Retention |
|---|---|
| Identity, profile, contact | Active account + 90 days |
| Saved addresses | Life of account + 90 days |
| Booking history - operational fields | Active + 2 years, then anonymized |
| Booking history - financial fields, transactions | 10 years (Revenue Code §87/3, Accounting Act §14, CCC §193/30-31) |
| Payment tokens | Until account closure or card expiry |
| Communications | 12 months from closure |
| Customer Health Notes (default) | Deleted on booking completion |
| Customer Health Notes (opt-in persistence) | Until withdrawal or account closure + 90 days |
| Marketing consent records | Until withdrawal + 3 years (PDPA §78) |
| Traffic logs | 90 days (Computer Crime Act §26) |
| Cookies (functional / analytics / marketing) | 12 mo / 12 mo / 6 mo |
9. Your rights
9.1 Right to access (§30(1))
Ask for a copy of your data any time. We respond within 30 days.
9.2 Right to portability (§32)
Ask for your data in a machine-readable format, or to have it transmitted to another controller. 30 days.
9.3 Right to object (§33)
Object to processing based on Legitimate Interest, direct marketing, or automated decisions.
9.4 Right to correction (§34)
Ask us to correct inaccurate or incomplete data.
9.5 Right to erasure (§35)
Ask us to delete or anonymize your data. Statutory retention (like tax records for 10 years) still applies.
9.6 Right to withdraw consent (§19)
Where processing is based on your consent, withdraw any time - with the same ease as giving it - in Account Settings › Privacy and Consent.
9.7 How to exercise your rights
Email our Data Protection Officer. You can also use the in-app tools in Account Settings › Privacy and Consent › Data Subject Rights.
10. How we keep your data safe
10.1 Technical and organizational measures
Under PDPA §37(4), we implement field-level AES-256 encryption for Sensitive Personal Data, at-rest encryption for all databases, TLS 1.3+ in-transit encryption, role-based access control, and audit logging.
10.2 Record of Processing Activities (§39(7))
We maintain a Record of Processing Activities available for the Personal Data Protection Committee on request, and available to you on a redacted basis on written request.
11. Age restrictions
Veyyā is for adults. You must be at least 18 to have an account. We do not knowingly collect data from anyone under 18. If we discover an underage account, we suspend it, delete the data, and notify the individual or a parent or guardian.
To report a suspected underage account, email dpo@veyya.com.
12. Contact and complaints
- Data Protection Officer · dpo@veyya.com
- Privacy team · privacy@veyya.com
If our response does not satisfy you, you can lodge a complaint with the Personal Data Protection Committee (PDPC).
Veyya Life (Thailand) Limited · Bangkok, Thailand
Version history
v3.0 (3 July 2026) - Data Controller name corrected. PDPA §23(2) informed collection section added. Customer Health Notes §26 opt-in persistence section added with COMP-017B reference. Behavioural profiling split into Legitimate Interest (basic) and Consent (personalization). Payment retention 10 years. International transfers narrowed to HoldCo + named subprocessors. Age at 18+. Independent third-party service provider terminology.