UNREVIEWED DRAFT. Not yet checked by a Thai lawyer. Remove before the site goes live.
Legal

Privacy Notice

Effective 2026-09-19Controller: [REGISTERED COMPANY NAME] Co., Ltd.[REGISTERED ADDRESS], Bangkok, Thailand

This notice explains what personal data we handle, why, and what you can do about it. It covers Thailand's Personal Data Protection Act B.E. 2562 (the PDPA) and, where it applies to our processing, the EU and UK General Data Protection Regulation (GDPR).

1. Two very different kinds of data

We handle personal data in two distinct situations, and they work differently, so we treat them separately throughout this notice:

  • Client and prospect data — the business contact details of the people we sell to and work with.
  • Investigation data — publicly available information about websites that appear to impersonate our clients' brands, which sometimes contains personal data about the people who registered or operate them.

We do not receive our clients' customer data. We do not ask for it, we have no use for it, and you should not send it to us. If a victim's details reach us inside a complaint you forward, we will keep them only as long as needed for that case and will tell you so.

2. Client and prospect data

What: name, job title, employer, business email address, business phone number, correspondence with us, the brands and domains you ask us to cover, billing contact details, tax identifiers and invoice records.

Why, and on what legal basis:

PurposeLegal basis
Providing the Service and communicating with you about itPerformance of a contract
Invoicing, payment and tax recordsLegal obligation; performance of a contract
Business-to-business outreach to a named role at a company we believe has this problemLegitimate interests — direct B2B marketing, balanced against your interests, and you can opt out at any time in one reply
Security, fraud prevention and keeping records of what we did and whenLegitimate interests

If you would rather we did not contact you again, reply to any message from us saying so, or write to hello@sylaprotect.com. We will stop, and we will keep the minimum record needed to make sure we do not contact you again by mistake.

We do not sell personal data, and we do not use it for automated decision-making that produces legal effects for anyone.

3. Investigation data about third parties

This is the unusual part of what we do, so we set it out plainly.

What we collect: domain names, DNS records, IP addresses, hosting and network details, page content and screenshots as served to an ordinary visitor, and publicly published domain registration records obtained through RDAP or WHOIS. Those registration records sometimes contain a name, postal address, email address or telephone number. We also record technical identifiers that appear on the pages themselves, such as advertising or analytics identifiers and publicly displayed contact or messaging handles.

How we collect it: only from public sources. We request pages as any visitor would. We do not attempt to access any private system, account or network, we do not bypass access controls, and we do not disrupt any service.

Why, and on what legal basis: our legitimate interests, and the legitimate interests of the rights holder we act for, in detecting and stopping the impersonation of a brand and the consumer fraud that flows from it — together with the public interest in consumers not being defrauded. Under the PDPA we rely on the corresponding legitimate-interest ground, and on the grounds permitting processing for the establishment, exercise or defence of legal claims.

We have assessed this balance and record our reasoning. It is a narrow purpose: we collect only what is needed to establish that a property is impersonating a brand and to identify the parties who can act on it.

What we do with it: include it in reports to the client whose brand is affected, and in abuse or infringement notices submitted — on that client's written instruction — to registries, registrars, hosting and network providers, platforms, reputation services and, where a case qualifies, the relevant authorities.

What we do not do with it: we do not publish it, we do not sell it, and we do not present technical association between websites as an allegation against a named person. Our attribution output is expressed as a confidence level about infrastructure, not as a finding of fact about anybody.

If you believe your personal data appears in our records because a domain was wrongly assessed, contact hello@sylaprotect.com. We will review it promptly and correct or erase what we should not be holding.

4. Website and email data

This website does not set advertising or tracking cookies and does not profile visitors. Our host records standard server logs, including IP address and user agent, for security and reliability.

If you pay by card, our payment provider processes your payment details directly. We receive only a confirmation, the amount, and a partial card reference. We never see or store your full card number.

Emails we send you may record whether you opened them or followed a link, so we know whether to follow up. Tell us if you would prefer we turned that off for your address.

5. Who we share data with

  • Service providers who host our systems, send our email, process payments and keep our accounts. They act on our instructions under a written contract.
  • Recipients of notices — registries, registrars, hosts, network providers, platforms and reputation services — but only the material necessary for that notice, and only where the client has approved that property in writing.
  • Public authorities, where a client instructs us in writing to submit a case file, or where we are required by law to disclose.
  • Professional advisers, and any acquirer of our business, under confidentiality.

A current list of our processors is available on request from hello@sylaprotect.com.

6. International transfers

Some of our providers, and many of the parties we file notices with, are outside Thailand. Where we transfer personal data abroad we do so on one of the bases permitted by the PDPA and, where GDPR applies, under an adequacy decision or standard contractual clauses. Notices filed with a foreign registry or platform are transferred because that is the only way the report can reach the party able to act, which is necessary for the legal claim being pursued.

7. How long we keep it

CategoryRetention
Client contact and account recordsFor the contract, then 2 years
Invoices and accounting recordsAs required by Thai tax law, currently 10 years
Case evidence and filed notices5 years from case closure, so an outcome can be evidenced and a repeat operator recognised
Candidates assessed as benignKept as a suppression record only, so we never re-report them; substantive content deleted within 90 days
Prospect contact data where no relationship begins12 months, or immediately on an opt-out request
Server logs90 days

8. How we protect it

Access is limited to the people who need it. Data is encrypted in transit and at rest with our providers, access to production systems requires multi-factor authentication, and we keep an audit record of every notice submitted, by whom and when. No system is perfectly secure, but we will tell affected people and the regulator about a breach where the law requires it and within the time limits that apply.

9. Your rights

Subject to the conditions and exemptions in the applicable law, you may ask us to: give you access to your personal data; correct it; erase it; restrict or object to how we use it; provide it in a portable form; or withdraw consent where consent was our basis. Where we rely on legitimate interests, you have the right to object, and we will stop unless we have compelling grounds that override your interests — for example an ongoing enforcement matter or the defence of a legal claim.

Write to hello@sylaprotect.com. We respond within 30 days and we do not charge for a reasonable request. We may need to verify your identity first.

10. Children

The Service is sold to organisations. We do not knowingly collect personal data from anyone under 20, and we will delete it if we learn that we have.

11. Changes

We will post any update here with a new effective date, and tell active clients by email where the change is material.

12. Contact and complaints

[REGISTERED COMPANY NAME] Co., Ltd. Bangkok, Thailand hello@sylaprotect.com

If we have not resolved your concern, you may complain to the Office of the Personal Data Protection Committee (PDPC) in Thailand, or to your local supervisory authority where GDPR applies to you.