Privacy Policy
This policy explains how Zentr collects, uses, discloses and protects personal data under Thailand's Personal Data Protection Act B.E. 2562 (PDPA). Please read it alongside the service agreement you hold with us.
- Our role in relation to your data
- What we collect
- Why we use it, and on what legal basis
- Who we share it with
- International transfers
- How long we keep it
- Your rights
- Cookies and usage measurement
- How we protect it
- Children's data
- Changes to this policy
- Contact us
Our role in relation to your data
Zentr acts in two distinct roles, and your rights differ depending on which applies.
- Data controller — for the data of salon owners and staff who sign up to Zentr: name, email, phone number and billing details. We decide how that data is used.
- Data processor — for end-customer data the salon brings into the system: customer names, booking history and conversations. The salon is the controller of that data; we process it only on the salon's instructions.
If you are a customer of a salon that uses Zentr and want to exercise your rights, please contact that salon first. We will support them in carrying out the request.
What we collect
Data you give us directly
- Account details — name, email, phone number, salon name and address
- Billing details — handled through a certified payment provider; we do not store full card numbers on our systems
- Data the salon imports — customer lists, schedules, service history and price lists
- Correspondence — messages you send us by email, chat or support channels
Data generated through use
- Conversations between customers and the AI assistant, and the bookings that result
- Product usage such as pages opened, time spent and features used
- Technical data such as IP address, device type, browser and operating system
Data from third parties
- Basic profile data from chat channels you connect — LINE Official Account, Facebook or Instagram — within the scope you have authorised that platform to share
Why we use it, and on what legal basis
We use data only as far as necessary for the purposes below, on the legal basis noted against each.
- Delivering the service — answering chat, managing bookings, keeping customer records and producing reports (contract)
- Billing and invoicing (contract and legal obligation)
- Keeping the system secure — preventing misuse and fraud (legitimate interest)
- Improving the product — analysing aggregate usage to develop the service (legitimate interest)
- Marketing communications — only where you have consented, and you may withdraw at any time (consent)
- Meeting legal requirements such as accounting and tax record keeping (legal obligation)
We do not sell personal data. We do not use one salon's conversation content to train models for the benefit of another salon without permission.
International transfers
Primary data is held on servers in Thailand. Some providers may process data outside Thailand. Where that happens we put appropriate safeguards in place as required by the PDPA, such as standard contractual clauses.
How long we keep it
- Account and usage data — for the life of the subscription, plus two years after closure
- Accounting and tax records — as required by law, generally no less than five years
- Conversations and booking history — as determined by the salon acting as controller, deleted on their instruction or on account closure
- System access logs — no more than 90 days, unless needed for a security investigation
Your rights
Under the PDPA you have the following rights. To exercise any of them, contact us using the details at the end of this page.
- Access — see and obtain a copy of the data we hold about you
- Rectification — have inaccurate or outdated data corrected
- Erasure — have data deleted or anonymised
- Restriction — have us pause our use of your data
- Objection — object to collection or use in certain circumstances
- Portability — receive your data in a machine-readable form, or have it sent to another controller
- Withdrawal of consent — withdraw at any time, without affecting processing already lawfully carried out
- Complaint — lodge a complaint with the Personal Data Protection Committee if you believe we are not meeting our obligations
We respond to rights requests within 30 days of receiving a complete request. If we need longer, we will explain why.
How we protect it
- Encryption in transit (TLS) and at rest
- Role-based access separation, reviewed periodically
- Access logging for after-the-fact audit
- Regular backups with restore testing
If a personal data breach occurs that poses a risk to individuals' rights and freedoms, we will notify the Personal Data Protection Committee within 72 hours of becoming aware, and notify affected individuals as required by law.
Children's data
This service is intended for businesses and is not designed for minors. If we learn we have received a minor's data without valid parental consent, we will delete it promptly.
Changes to this policy
We may update this policy from time to time. Where changes are material, we will give notice by email or in-product at least 30 days before they take effect. The last updated date appears at the top of this page.
Contact us
For questions about this policy, or to exercise your rights, contact us at:
- Email — zentr-info@arisecorpn.com
- Data controller — Arise Corporation Co., Ltd.
- Registered address — 5/37 Thetsaban Songkhro Road, Lat Yao Sub-district, Chatuchak District, Bangkok 10900, Thailand
- Data Protection Officer — Mr. Theeraphat Khammueangchai (theeraphat@arisecorpn.com)
This policy is issued under Thailand's Personal Data Protection Act B.E. 2562. For questions or to exercise your rights, you may contact our Data Protection Officer directly.
