Privacy Policy
Last Updated: March 15, 2025
At currentaflowon, we understand that your business data isn't just information — it's the backbone of your operations. This privacy policy explains how we collect, handle, and protect your data when you use our business activity analysis services. We're based in Thailand and comply with Thai data protection laws, including the Personal Data Protection Act B.E. 2562 (2019).
What Information We Collect
Running a business analysis platform means we need certain information to provide you with meaningful insights. Here's what we gather and why it matters.
Business Account Information
When you create an account with us, we collect basic details that help us identify your business and set up your analytical workspace:
- Company name and registration details
- Primary contact person's name and role
- Business email address and phone number
- Physical business address (which helps us understand your operational context)
- Industry classification and business size
Financial and Operational Data
This is where things get specific to what we do. To analyze your business activity and cash flow patterns, we need access to transaction data and operational metrics. You decide what level of detail to share:
- Transaction records and payment histories
- Cash flow statements and balance information
- Revenue patterns and expense categories
- Operational metrics you choose to integrate
- Banking connection data (encrypted and tokenized)
Technical Information
Like most online platforms, we automatically collect some technical data that helps us keep the service running smoothly and securely:
- IP addresses and device identifiers
- Browser type and operating system details
- Access times and usage patterns
- Feature interactions and navigation paths
- Error logs and performance data
How We Use Your Information
We're not in the business of collecting data for the sake of it. Everything we gather serves a specific purpose in helping you understand your business better.
Purpose | Data Used | Legal Basis |
---|---|---|
Providing analysis services | Financial data, operational metrics | Contract performance |
Account management | Contact information, business details | Contract performance |
Security and fraud prevention | Technical data, access logs | Legitimate interest |
Service improvements | Usage patterns, feedback | Legitimate interest |
Legal compliance | All data categories as needed | Legal obligation |
We analyze your financial data to generate insights about cash flow trends, spending patterns, and business health indicators. This analysis happens on our secure servers, and the results are presented back to you through our dashboard. We don't use your data to train AI models or for purposes unrelated to your service.
Data Storage and Security
Your business data is stored on secure servers located in Thailand, which means it's subject to Thai data protection laws. We've built multiple layers of security into our infrastructure because financial information requires serious protection.
Encryption: All data is encrypted both in transit (using TLS 1.3) and at rest (using AES-256 encryption). Your banking connections use tokenization, so we never store actual banking credentials.
Access Controls: Only authorized team members can access client data, and only when necessary for service delivery or support. All access is logged and monitored.
Infrastructure Security: Our servers are housed in certified data centers with physical security measures, redundant systems, and regular security audits.
Regular Testing: We conduct vulnerability assessments and penetration testing quarterly to identify and fix potential security gaps.
Data Retention Periods
We keep your data for as long as you maintain an active account with us. Here's what happens to different types of information:
- Active account data: Retained while your subscription is current
- Historical analysis data: Kept for up to 7 years (standard business practice in Thailand)
- Transaction logs: Maintained for 3 years for audit purposes
- Technical logs: Stored for 90 days unless needed for security investigations
- Deleted account data: Purged within 30 days (except where legal retention applies)
Sharing and Third-Party Access
We don't sell your data. Period. But running a financial analysis service does require working with some trusted partners. Here's who might see your information and why:
Service Providers
We work with carefully vetted companies that help us deliver our service:
- Cloud hosting providers for server infrastructure
- Payment processors for subscription billing
- Banking API providers for secure financial data connections
- Email service providers for account communications
- Security monitoring services for threat detection
These partners are bound by strict data processing agreements and can only use your data for the specific services they provide to us. They can't use it for their own purposes or share it further.
Legal Disclosures
Sometimes we're legally required to share information. This might happen if we receive a valid court order, need to comply with Thai tax authorities, or must respond to legitimate law enforcement requests. When this occurs, we verify the legal basis and share only what's specifically required.
Business Transfers
If currentaflowon is acquired or merged with another company, your data would be transferred as part of that transaction. We'd notify you beforehand and ensure the new owner commits to similar privacy protections.
Your Rights and Control
Under Thai data protection law, you have several rights regarding your personal and business data. We've built tools into our platform to make exercising these rights straightforward.
Access and Portability
You can download your data at any time through your account dashboard. This includes all financial records, analysis reports, and account information in machine-readable formats. Most exports are available immediately; larger data sets might take up to 48 hours to prepare.
Correction and Updates
Found an error in your data? You can correct most information directly through your account settings. For changes to historical financial data that affects past analyses, contact our support team — we need to maintain audit trails for such modifications.
Deletion and Restriction
You can request deletion of your account and data by contacting us at [email protected]. We'll process deletion requests within 30 days, though we may need to retain certain records for legal compliance (like tax documentation for the required retention period).
If you want to restrict processing rather than delete everything, you can pause data collection while maintaining your historical records. This is useful if you're temporarily not using the service but want to preserve your analysis history.
Objection and Withdrawal
You can object to specific data processing activities, particularly those based on legitimate interest rather than contractual necessity. For marketing communications, there's an unsubscribe link in every email. For broader objections, reach out to our team and we'll work through your concerns.
Response Times: We respond to rights requests within 30 days as required by Thai law. Complex requests might need an extension, but we'll let you know if that's the case and explain why.
Verification: To protect your data from unauthorized access, we verify your identity before processing rights requests. This usually involves confirming details from your account.
Cookies and Tracking
Our platform uses cookies and similar technologies to function properly and provide a better experience. Here's what we use and why:
Essential Cookies
These are necessary for the platform to work. They handle your login session, remember your preferences, and maintain security. You can't opt out of these if you want to use our service, but they don't track you across other websites.
Analytics Cookies
We use analytics to understand how people use our platform so we can make it better. This includes tracking which features are most popular, where people get stuck, and how long different tasks take. You can opt out of analytics through your account settings.
Performance Cookies
These help us optimize load times and system performance by remembering your preferences and caching certain elements. They make the platform faster and more responsive to your specific usage patterns.
International Data Transfers
Your data is primarily stored and processed in Thailand. However, some of our service providers operate globally, which means your data might occasionally be processed in other countries. When this happens, we ensure adequate protection through:
- Standard contractual clauses approved by Thai authorities
- Verification that the receiving country has adequate data protection laws
- Additional security measures for sensitive financial data
- Regular audits of our international service providers
If you have concerns about international transfers for your specific data, contact us and we can discuss alternative arrangements.
Children's Privacy
Our service is designed for businesses and is not intended for individuals under 18 years old. We don't knowingly collect personal information from minors. If you believe we've inadvertently collected such information, contact us immediately and we'll delete it.
Changes to This Policy
Business needs and regulations evolve, so we might update this privacy policy occasionally. When we make significant changes, we'll notify you via email and through a notice on the platform. The "Last Updated" date at the top of this page shows when we last revised the policy.
If changes affect how we handle existing data, we'll give you at least 30 days notice and, where required by law, ask for your renewed consent. You can always review the current policy at currentaflowon.com/gdpr-policy.html.
Complaints and Regulatory Contact
If you're not satisfied with how we've handled your privacy concerns, you have the right to lodge a complaint with Thailand's Personal Data Protection Committee. Contact details:
Personal Data Protection Committee
Office of the Personal Data Protection Committee
Ministry of Digital Economy and Society
120 Moo 3, Government Complex, Chaengwattana Road
Laksi, Bangkok 10210, Thailand
Before going that route, we'd appreciate the chance to address your concerns directly. Most issues can be resolved through conversation.
Questions About This Policy?
If anything in this privacy policy is unclear, or if you have specific questions about how we handle your data, we're here to help. Our team reviews every privacy inquiry personally.
Email: [email protected]
Phone: +66 2 903 1398
Mail: currentaflowon
97/4 ม.11 ต.คลองแห คลองแห
Hat Yai District, Songkhla 90110
Thailand
Our support team is available Monday through Friday, 9:00 AM to 6:00 PM Thailand time. We typically respond to privacy inquiries within one business day.