policy

Privacy Policy

Identity Orchestration & Data Protection

arrow_back Back
Version 1.0.0 Effective: January 1, 2025
PDPA Compliant

format_list_numbered Table of Contents

  1. Data Controller Information
  2. Data We Collect
  3. How We Use Your Data
  4. Cookies & Tracking
  5. Data Sharing
  6. Data Retention
  7. Your Rights (PDPA)
  8. Security
  9. Contact Us

business Data Controller Information

This Privacy Policy describes how AuthSys ("we", "us", "our") collects, uses, and protects your personal information when you use our services.

info
By registering or using our services, you acknowledge that you have read and understood this Privacy Policy.

database Data We Collect / ข้อมูลที่เราเก็บรวบรวม

เราเก็บรวบรวมข้อมูลส่วนบุคคลของท่านเท่าที่จำเป็น ภายใต้ฐานทางกฎหมายที่กำหนดไว้ในพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562

ข้อมูล / Data ตัวอย่าง / Examples วัตถุประสงค์ / Purpose ฐานทางกฎหมาย
Account Data ชื่อผู้ใช้, อีเมล
Username, Email
สร้างและจัดการบัญชี
Account management
สัญญา
Authentication Data รหัสผ่าน (เข้ารหัส)
Password (hashed)
ยืนยันตัวตน
Verification
สัญญา
Technical Data IP, เบราว์เซอร์
IP, Browser
ความปลอดภัย
Security
ประโยชน์โดยชอบ
Usage Data เวลาเข้าสู่ระบบ
Login timestamp
ปรับปรุงบริการ
Improvement
ความยินยอม
Consent Record เวลา consent, IP
Consent log
หลักฐาน PDPA
Compliance
กฎหมาย
lock
รหัสผ่านถูกเข้ารหัสด้วย bcrypt ก่อนจัดเก็บทุกครั้ง
ไม่มีผู้ใดสามารถอ่านรหัสผ่านของท่านได้
Passwords are always hashed with bcrypt before storage.

settings How We Use Your Data / วัตถุประสงค์การใช้ข้อมูล

เราใช้ข้อมูลของท่านตามวัตถุประสงค์ที่ได้รับความยินยอม หรือมีฐานทางกฎหมายรองรับเท่านั้น

verified

วัตถุประสงค์ที่จำเป็น (Essential)

สัญญา / Contract
  • ให้บริการระบบยืนยันตัวตน (Authentication)
  • สร้างและจัดการบัญชีผู้ใช้
  • ส่งอีเมลที่เกี่ยวข้องกับบัญชี เช่น รีเซ็ตรหัสผ่าน
  • ป้องกันการเข้าถึงโดยไม่ได้รับอนุญาต
analytics

วัตถุประสงค์เพิ่มเติม (Analytics)

ความยินยอม / Consent
  • วิเคราะห์รูปแบบการใช้งานเพื่อปรับปรุงบริการ
  • เก็บสถิติการเข้าสู่ระบบ

ท่านสามารถถอนความยินยอมได้ทุกเวลา โดยไม่กระทบต่อการใช้บริการหลัก

block
เราไม่ขาย ให้เช่า หรือเปิดเผยข้อมูลส่วนบุคคล
เพื่อวัตถุประสงค์ทางการตลาด
We do not sell or disclose your data for marketing purposes.

cookie Cookies & Tracking

We use the following types of cookies:

Cookie Type Name Duration Required
Session connect.sid 24 hours Essential
OAuth State oauth_state 5 minutes Essential
PKCE Verifier oauth_code_verifier 5 minutes Essential
Consent Record cookie_consent 365 days Essential

share Data Sharing

Your data may be shared with authorized third-party applications that you explicitly grant access to via our OAuth 2.0 consent screen.

schedule Data Retention

Data Retention Period
Account data Until deletion + 30 days
Access tokens 1 hour (JWT expiry)
Authorization codes 10 minutes
Consent records 3 years (legal)
Login logs 90 days

gavel Your Rights (PDPA)

Under the Personal Data Protection Act (PDPA), you have the right to:

visibility Access

Request a copy of your data

edit Rectification

Correct inaccurate data

delete Erasure

Request data deletion

pause Restriction

Restrict processing

download Portability

Receive portable data

block Objection

Object to processing

email
To exercise any rights, contact us below.
We respond within 30 days.

security Security

We implement industry-standard security measures:

contact_mail Contact Us

For privacy-related requests, contact our Data Protection Officer: