Identity Orchestration & Data Protection
This Privacy Policy describes how AuthSys ("we", "us", "our") collects, uses, and protects your personal information when you use our services.
เราเก็บรวบรวมข้อมูลส่วนบุคคลของท่านเท่าที่จำเป็น ภายใต้ฐานทางกฎหมายที่กำหนดไว้ในพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562
| ข้อมูล / Data | ตัวอย่าง / Examples | วัตถุประสงค์ / Purpose | ฐานทางกฎหมาย |
|---|---|---|---|
| Account Data | ชื่อผู้ใช้, อีเมล Username, Email |
สร้างและจัดการบัญชี Account management |
สัญญา |
| Authentication Data | รหัสผ่าน (เข้ารหัส) Password (hashed) |
ยืนยันตัวตน Verification |
สัญญา |
| Technical Data | IP, เบราว์เซอร์ IP, Browser |
ความปลอดภัย Security |
ประโยชน์โดยชอบ |
| Usage Data | เวลาเข้าสู่ระบบ Login timestamp |
ปรับปรุงบริการ Improvement |
ความยินยอม |
| Consent Record | เวลา consent, IP Consent log |
หลักฐาน PDPA Compliance |
กฎหมาย |
เราใช้ข้อมูลของท่านตามวัตถุประสงค์ที่ได้รับความยินยอม หรือมีฐานทางกฎหมายรองรับเท่านั้น
ท่านสามารถถอนความยินยอมได้ทุกเวลา โดยไม่กระทบต่อการใช้บริการหลัก
We use the following types of cookies:
| Cookie Type | Name | Duration | Required |
|---|---|---|---|
| Session | connect.sid |
24 hours | Essential |
| OAuth State | oauth_state |
5 minutes | Essential |
| PKCE Verifier | oauth_code_verifier |
5 minutes | Essential |
| Consent Record | cookie_consent |
365 days | Essential |
Your data may be shared with authorized third-party applications that you explicitly grant access to via our OAuth 2.0 consent screen.
| Data | Retention Period |
|---|---|
| Account data | Until deletion + 30 days |
| Access tokens | 1 hour (JWT expiry) |
| Authorization codes | 10 minutes |
| Consent records | 3 years (legal) |
| Login logs | 90 days |
Under the Personal Data Protection Act (PDPA), you have the right to:
Request a copy of your data
Correct inaccurate data
Request data deletion
Restrict processing
Receive portable data
Object to processing
We implement industry-standard security measures:
For privacy-related requests, contact our Data Protection Officer: