This Data Processing Agreement ("DPA") constitutes a legally binding schedule incorporated into the master Terms of Service between the Customer/Merchant ("Customer", "Data Controller") and Pocketify ("Provider", "Data Processor").
1. Scope & Definitions
This DPA governs the processing of Personal Data collected from End Users in connection with Customer's use of Pocketify's WiFi Marketing, Captive Portal, and subscriber management services under applicable privacy legislation (specifically including Thailand Personal Data Protection Act B.E. 2562 - PDPA).
2. Roles of the Parties
The parties expressly acknowledge and agree to the allocation of roles:
- Customer as Data Controller: The Customer exercises exclusive authority to determine the purposes, legal bases, notice terms, and collection scope for End-User Personal Data gathered via Captive Portals.
- Pocketify as Data Processor: Pocketify acts strictly as a Data Processor executing automated operations, data storage, and analytics under the documented instructions and platform configurations established by the Customer.
3. Ownership of Data
All End-User Personal Data, customer databases, and subscriber lists captured through the Customer's instance of Pocketify remain the sole property and asset of the Customer.
4. Categories of Processed Data
Subject to Customer configurations, Pocketify processes the following categories of data on behalf of Customer:
- Identity Data: Full name, mobile telephone number, email address, LINE User ID, social login profiles.
- Captive Portal Form Responses: Survey inputs, custom field entries, registration preferences.
- Network Telemetry: MAC Address, IP Address, access timestamps, session duration, bandwidth consumption logs.
- Hardware & Technical Metadata: User-Agent strings, operating system, browser model, Access Point identifiers.
- Campaign Engagement Records: Promotional coupon redemptions, campaign interaction logs.
5. Purposes of Processing
Pocketify is authorized to process Customer Personal Data strictly to:
- Operate guest WiFi authentication portals and access management workflows.
- Generate aggregate visitor analytics reports, demographic summaries, and foot-traffic insights for Customer.
- Execute automated communication workflows (e.g., SMS/Email vouchers) commanded by Customer.
- Maintain platform stability, perform data backups, and deliver technical support requested by Customer.
- Comply with legal obligations, computer log compliance requirements, and mandatory court orders.
6. Restrictions on Processor
Pocketify agrees and covenants that it shall not:
- Sell, rent, license, or trade End-User Personal Data.
- Cross-combine subscriber databases between separate Customer accounts to construct cross-merchant profiling.
- Send marketing messages to End Users under Pocketify's own brand without Customer direction.
- Disclose Personal Data to any unauthorized personnel or unapproved third parties.
Pocketify may utilize anonymized, aggregated statistical metrics (non-identifiable metrics) solely to evaluate platform performance and enhance service algorithms.
7. Duties of Data Controller
The Customer warrants and covenants that it shall:
- Provide adequate Privacy Notices and terms to End Users on Captive Portals prior to data collection.
- Establish valid statutory legal bases (e.g., explicit consent, legitimate interest) for all processing activities.
- Obtain all requisite End-User consents for marketing communications under applicable laws.
- Maintain appropriate administrative access controls for Customer dashboard credentials.
- Promptly notify Pocketify of any unauthorized credentials access or suspected data security incidents at Customer's end.
8. Duties of Data Processor
Pocketify covenants and agrees that it shall:
- Process Personal Data strictly in accordance with documented Customer instructions and this DPA.
- Implement state-of-the-art technical and organizational safeguards against accidental destruction, loss, or unauthorized access.
- Enforce strict non-disclosure obligations upon all employees and contractors authorized to handle Personal Data.
- Assist Customer, to a reasonable commercial extent, in responding to statutory Data Subject Rights requests.
- Notify Customer without undue delay upon confirming a verified Personal Data Breach affecting Customer data.
- Return or permanently purge Customer data upon contract expiration or service termination.
9. Authorized Subprocessors
Customer provides general authorization for Pocketify to engage third-party subprocessors (such as AWS/Cloud Infrastructure, SMS Delivery Gateways, Email Providers, and Payment Processors) essential for service delivery. Pocketify shall enforce data protection obligations on all subprocessors no less restrictive than those in this DPA.
10. Security Safeguards
Pocketify maintains comprehensive technical and organizational safeguards:
- HTTPS/TLS 1.3 transport layer encryption for all portal interfaces.
- AES-256 data encryption at rest for database instances and cloud backups.
- Logical Multi-Tenant database isolation ensuring strict segregation of customer data repositories.
- Continuous vulnerability monitoring, automated threat detection, and centralized system audit logs.
11. Staff Access & Confidentiality
Pocketify restricts staff access to Customer databases strictly to a need-to-know basis (e.g., technical support escalation or system maintenance). All access sessions are logged, monitored, and bound by binding non-disclosure agreements.
12. Breach Incident Notification
In the event of a confirmed security incident resulting in unauthorized access, leakage, or loss of Customer Personal Data, Pocketify shall notify Customer without undue delay (aiming within 24-72 hours of confirmation). Notification shall outline the nature of the breach, affected data categories, and remediation measures undertaken.
13. Data Return & Deletion
During the active subscription, Customer may export subscriber databases via the Pocketify dashboard. Upon termination of service, Customer may request complete data export or permanent deletion. Pocketify will execute permanent purging within 30 days of request, retaining copies only as mandated by law (e.g., statutory computer traffic log obligations).
14. Governing Law & Jurisdiction
This DPA is governed by and construed in accordance with the laws of the Kingdom of Thailand (including the Personal Data Protection Act B.E. 2562). Any legal disputes arising hereunder shall be submitted to the exclusive jurisdiction of the competent courts of Thailand.