นโยบายความเป็นส่วนตัว
Last updated: 13 พฤษภาคม 2026 · Version 1.0
1. ใครคือ Data Controller
บริษัท เบสท์ อินเวสติเกชั่น จำกัด (Best Investigation Co., Ltd.)
เลขประจำตัวผู้เสียภาษี: 0-4055-38000-09-1
เป็นผู้ให้บริการ NirvaDeploy (nirvadeploy.com) และเป็น Data Controller ตามนิยามของ พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA)
Data Protection Officer (DPO): [email protected]
2. ข้อมูลที่เราเก็บ
เราเก็บข้อมูลต่อไปนี้เมื่อคุณใช้บริการ:
- Account data: email, ชื่อ, รูป profile (จาก Line/Google OAuth)
- Billing data: Stripe customer ID, ประวัติการชำระเงิน, tax ID (ถ้านิติบุคคล), ที่อยู่สำหรับใบกำกับภาษี
- Engine credentials: Railway/Dokploy access token (encrypted at rest ด้วย AES-256)
- Usage data: projects, services, deployments, environment variables (เนื้อหา code ของคุณเก็บอยู่ที่ engine — เรา proxy ผ่านเท่านั้น)
- Audit log: destructive actions (delete, scale-to-zero, etc.) + IP address + user agent
- Affiliate data: referral slug, click tracking, commission records, payout details (PromptPay phone / bank account)
- Communication: email correspondence ที่คุณส่งมาเรา
3. เก็บเพื่ออะไร (Lawful basis)
เราใช้ข้อมูลของคุณตามวัตถุประสงค์ที่ระบุไว้เท่านั้น:
- Contract performance (PDPA §24(3)) — ให้บริการตาม Terms of Service ที่คุณ accept
- Legal obligation (PDPA §24(6)) — ออกใบกำกับภาษี, เก็บข้อมูลบัญชี 7 ปีตามกฎหมายภาษีไทย
- Legitimate interest (PDPA §24(5)) — ปรับปรุงบริการ, detect abuse / fraud, audit log สำหรับ security
- Consent (PDPA §24) — marketing emails (ยกเลิกได้ใน settings)
4. แชร์ข้อมูลกับใคร
เราแชร์ข้อมูลเฉพาะกับ data processors ที่จำเป็นต่อการให้บริการ:
- Railway (United States) — engine ใต้ระบบ Phase 1-3. ข้อมูล code + deployments ของคุณ. (Phase 4 จะย้ายไป Hetzner Singapore — ดู docs/phase4-dokploy-spec.md)
- Stripe Thailand — payment processing. ข้อมูลการชำระเงิน + tax ID
- Anthropic (United States) — Claude API สำหรับ premium templates (slip parser, bank statement parser). เฉพาะเนื้อหาที่คุณส่งให้ template ประมวลผล
- Resend / SendGrid — transactional emails (รวมส่งใบกำกับภาษี ภ.พ.30 · ใบกำกับ generate ในระบบเราเอง ไม่ผ่าน 3rd party)
- Cloudflare — DNS, DDoS protection, R2 storage (encrypted backups)
- Sentry / Datadog (Phase 4+) — error monitoring (no PII)
เรา ไม่ ขายข้อมูลของคุณให้ใคร และ ไม่ แชร์เพื่อ ad targeting / data brokering
5. โอนข้ามชาติ (Cross-border transfer)
ข้อมูลบางส่วนเก็บที่ US (Railway, Stripe, Anthropic) และ EU (Hetzner ตอน Phase 4). การโอนข้ามชาติเป็นไปตาม PDPA §28 — adequate level of data protection หรือ Standard Contractual Clauses
สำหรับ Enterprise tier (Phase 5): มี option ให้เลือก Thailand-only data residency (BYOC) เพื่อ compliance ของลูกค้าภาครัฐ/ธนาคาร
6. สิทธิ์ของคุณ (PDPA §30-37)
คุณมีสิทธิ์ดังต่อไปนี้:
- Right of access (§30) — ขอ copy ของข้อมูลที่เราเก็บไว้
- Right to rectification (§31) — ขอแก้ไขข้อมูลที่ไม่ถูกต้อง
- Right to erasure (§33) — ขอลบบัญชี + ข้อมูลทั้งหมด ("Right to be forgotten")
- Right to portability (§31) — ขอ export ข้อมูลในรูปแบบที่ machine-readable
- Right to object (§34) — คัดค้านการประมวลผลที่ไม่จำเป็น
- Right to withdraw consent (§19) — ยกเลิก consent ที่เคยให้
📨 ส่งคำขอใช้สิทธิ์: [email protected] — เราจะตอบกลับภายใน 30 วัน
7. การเก็บข้อมูล (Retention)
- Account data: ตลอดอายุบัญชี + 1 ปีหลังลบบัญชี (กรณีต้องการ reactivate)
- Billing + tax records: 7 ปี (กฎหมายภาษีไทย)
- Engine credentials: ตลอดอายุบัญชี (revoke ได้ทุกเวลาใน settings)
- Audit log: 90 วัน hot + 5 ปี cold storage
- Code logs: 7 วัน (Free), 30 วัน (Hobby+), 90 วัน (Business)
- Marketing email opt-out: ทันที (ใน settings)
8. ความปลอดภัย
- Encryption at rest (AES-256) สำหรับ DB + engine credentials
- Encryption in transit (TLS 1.3) สำหรับทุก API call
- OAuth-only login (ไม่มี password-based)
- Audit log สำหรับ destructive actions
- DDoS protection ผ่าน Cloudflare
- Backup ทุก 6 ชม. → encrypted R2 (30-day retention)
ดูรายละเอียดเต็มที่ /security
9. Cookies
เราใช้ cookies น้อยที่สุดเท่าที่จำเป็น:
next-auth.session-token— JWT session (HTTP-only, 30 วัน)_nd_ref— affiliate referral cookie (90 วัน) ถ้ามาจาก referral linkNEXT_LOCALE— language preference (th/en)
เราไม่ใช้ third-party tracking cookies (Google Analytics ฯลฯ). อนาคต: ถ้าจะเพิ่มเราจะขอ consent ผ่าน cookie banner ตามที่ PDPA กำหนด
รายละเอียดเต็มของ cookies ทุกตัว (purpose, lifetime, opt-out) /cookie-policy
10. เด็ก
NirvaDeploy ไม่ได้ออกแบบมาเพื่อผู้ใช้อายุต่ำกว่า 13 ปี. ถ้าเราพบว่าเก็บข้อมูลของเด็กโดยไม่ได้รับ parental consent — เราจะลบทันที. รายงาน: [email protected]
11. การเปลี่ยนแปลงนโยบายนี้
เราอาจปรับปรุงนโยบายนี้เป็นระยะ. การเปลี่ยนแปลงสำคัญ — เราจะแจ้ง email ล่วงหน้า 30 วัน. ปรับเล็กน้อย (typo, clarification) — อัพเดต "Last updated" ด้านบน
12. ติดต่อ
- DPO: [email protected]
- Security: [email protected]
- General: [email protected]
ร้องเรียน: ถ้าไม่พอใจกับการจัดการของเรา ติดต่อ สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส.) ที่ pdpc.or.th
เอกสารฉบับนี้เขียนเป็น ภาษาไทย ตามกฎหมายไทย. ในกรณี discrepancy กับ English version — ภาษาไทย prevail