Official Legal Document PDPA Compliance Standard v2.0

Pocketify Privacy Policy

Comprehensive formal terms detailing how personal data is collected, used, protected, and processed across our WiFi Marketing & Captive Portal ecosystem.

Last Updated: June 20, 2026
Effective Date: June 20, 2026

1. Definitions

In this Privacy Policy, the following capitalized terms shall have the meanings ascribed to them below:

  • "Pocketify" (referred to as "we", "us", or "our") refers to the cloud platform, infrastructure, and software services operated by Siamserve, including WiFi Marketing tools, Captive Portal builders, visitor analytics, and subscriber management.
  • "Customer" means any venue operator, merchant, commercial entity, organization, or individual who registers an account to utilize Pocketify services.
  • "End User" means an individual customer, guest, or venue visitor who connects to a guest WiFi network or submits information through a Captive Portal operated via Pocketify.
  • "Personal Data" means any information relating to an identified or identifiable natural person, directly or indirectly, in accordance with applicable data protection legislation (including the Thailand Personal Data Protection Act B.E. 2562 - PDPA).
  • "Data Controller" means the natural or legal person with the authority to make decisions regarding the collection, purpose, use, or disclosure of Personal Data.
  • "Data Processor" means the natural or legal person processing Personal Data on behalf of and under the documented instructions of the Data Controller.

2. Scope of Policy

This Privacy Policy applies to all Personal Data collected directly by Pocketify from Customers, authorized account managers, website visitors, trial registrants, and support inquiries.

Important Role Distinction: For End-User data captured when guests access WiFi at a venue via Pocketify Captive Portals, the Customer acts as the primary Data Controller, while Pocketify operates as the Data Processor under strict instructions provided by the Customer.

3. Data We Collect from Customers

Pocketify collects and processes the following categories of information when Customers register, configure, and maintain accounts:

  1. Account Identification Data: Full name, corporate title, email address, contact telephone number, legal entity name, and encrypted authentication credentials (passwords, API tokens).
  2. Business Profile Information: Venue names, physical branch addresses, logos, branding assets, WiFi network configurations, and merchant profile settings.
  3. System Operational Logs: Access timestamps, administrative audit logs, IP addresses, browser specifications, hardware signatures, and management dashboard activities.
  4. Customer Communications: Support tickets, correspondence records, customer feedback, and technical diagnostic submissions.
  5. Technical Metadata: Session cookies, security tokens, telemetry data, and system performance metrics.

4. Purposes of Data Processing

Pocketify processes collected Personal Data exclusively for legitimate commercial, legal, and operational purposes:

  1. Provisioning, maintaining, and managing Customer user accounts and platform permissions.
  2. Operating the Pocketify engine, Captive Portal framework, and WiFi network authentication workflows.
  3. Verifying identity, enforcing Multi-Tenant data isolation, and preventing unauthorized administrative access.
  4. Delivering technical customer support, service announcements, and platform maintenance updates.
  5. Analyzing service statistics, performance bottlenecks, and system optimization requirements.
  6. Detecting, preventing, and mitigating cybersecurity threats, fraudulent activities, or malicious system access.
  7. Complying with statutory requirements, mandatory law enforcement requests, and regulatory mandates under applicable laws.

5. End-User Data & Processing Roles

When a Customer deploy Pocketify to manage guest WiFi access, End-User credentials (such as telephone numbers, email addresses, LINE Account IDs, connection timestamps, IP addresses, and MAC addresses) are collected according to settings designated by the Customer.

  • The Customer determines all underlying purposes, privacy notices, legal bases, and retention policies applicable to End Users.
  • Pocketify acts strictly as a Data Processor executing automated workflows on behalf of the Customer.
  • Pocketify never sells, rents, monetizes, trades, or re-uses End-User personal data for Pocketify's independent marketing endeavors.

6. Data Disclosure

Pocketify maintains strict confidentiality policies. Personal Data will only be disclosed under limited, legally permissible conditions:

  1. Authorized Subprocessors: Disclosing necessary operational data to verified third-party service infrastructure providers (e.g., Cloud Hosting, SMS Gateways, Email Delivery services).
  2. Customer Directives: Disclosing data explicitly authorized or commanded by the Data Controller.
  3. Legal & Regulatory Mandates: Disclosing information when compelled by valid legal orders, subpoenas, judicial processes, or statutory law enforcement demands.
  4. Corporate Restructuring: In the event of a merger, acquisition, or asset transfer, subject to binding confidentiality and data protection continuity commitments.

7. Third-Party Subprocessors

To ensure high availability and security, Pocketify utilizes tier-one global infrastructure and service providers. All subprocessors undergo security evaluations and are bound by data protection agreements limiting data access to minimal necessary functions.

8. Data Retention & Deletion

Personal Data is retained only for the duration necessary to satisfy active contractual obligations, legitimate business purposes, or legal recordkeeping requirements.

Upon account termination or contract expiration, Pocketify will purge, destroy, or permanently anonymize stored Customer and End-User data in accordance with our data retention schedule, unless extended retention is mandated by law.

9. Data Security Safeguards

Pocketify implements rigorous technical and organizational security controls designed to preserve data confidentiality, integrity, and availability:

  • End-to-end TLS/HTTPS encryption for all data in transit across public networks.
  • AES-256 encryption at rest for sensitive data repositories and database backups.
  • Strict Multi-Tenant database isolation preventing cross-customer data leakage.
  • Role-Based Access Control (RBAC) and mandatory Least-Privilege staff access policies.
  • Continuous security monitoring, centralized audit logging, and regular vulnerability assessments.

10. Data Subject Rights

Under applicable data privacy legislation (including PDPA), natural persons possess enforceable rights regarding their Personal Data, including:

  • The right to request access to and receive copies of Personal Data.
  • The right to request rectification of inaccurate or incomplete records.
  • The right to request erasure, destruction, or permanent anonymization of data.
  • The right to request restriction of data processing or object to processing activities.
  • The right to withdraw previously granted consent at any time.

Where End Users submit data subject requests to Pocketify, we will promptly forward the inquiry to the appropriate Customer Data Controller for handling.

11. Cookies & Tracking Technologies

Pocketify utilizes functional cookies and authentication session identifiers essential for maintaining dashboard login states, security verification, and preferences. Users may control cookie behaviors via browser configuration, though disabling cookies may impede platform functionality.

12. Cross-Border Data Transfers

Where Personal Data is processed or stored via cloud infrastructure located outside Thailand, Pocketify ensures that recipient servers maintain adequate data protection standards compliant with statutory regulations.

13. Minors & Children Data

Pocketify services are structured for commercial entities and venue management. Captive Portals deployed at venues accessible to minors must be configured by the Customer to ensure appropriate parental consent or legal compliance under local law.

14. Policy Amendments

Pocketify reserves the right to revise this Privacy Policy periodically to reflect technological updates or legislative modifications. Revisions become effective upon publication on our platform.

15. Official Contact Details

For inquiries, legal notices, or exercising data subject rights regarding this Privacy Policy, please contact our Data Protection Support team:

Pocketify (Siamserve Team)

Email: siamserve.th@gmail.com

Official Website: https://siamserve.com

Telephone: +66 63 412 9422