Information We Collect
Personal Information You Provide
When you interact with our budget categorization platform, we collect information you voluntarily provide to us. This typically happens when you create an account, use our services, or contact our support team.
Automatically Collected Information
Our system automatically collects certain technical information to ensure smooth operation and improve your experience with our platform.
Data Type | Purpose | Retention Period |
---|---|---|
IP Address & Location | Security monitoring, fraud prevention | 90 days |
Device Information | Platform optimization, compatibility | 12 months |
Usage Analytics | Feature improvement, user experience | 24 months |
Session Data | Authentication, security | 30 days |
How We Use Your Data
We process your personal information for specific, legitimate purposes that directly relate to providing and improving our budget categorization services. Here's exactly how we use different types of data:
Primary Service Functions
Your financial data is processed to categorize transactions, generate spending insights, create budget recommendations, and provide personalized financial analysis. We never use this information for marketing to third parties or selling to data brokers.
Account Management & Authentication
We use your account information to verify your identity, maintain your profile, process password resets, and ensure secure access to your dashboard. This includes sending important account notifications and security alerts when unusual activity is detected.
Service Improvement & Analytics
Aggregated, anonymized usage data helps us understand which features are most valuable, identify areas for improvement, and develop new functionality. We analyze patterns in how users categorize expenses to refine our automated suggestions, but this analysis never connects back to individual users.
Communication & Support
When you contact our support team, we use your information to respond to inquiries, troubleshoot technical issues, and follow up on your concerns. We may also use your contact information to send important service updates or security notices.
Data Sharing & Third Parties
We maintain strict control over your personal information and only share data in specific circumstances that are essential for service operation or legally required.
Service Providers & Partners
Legal Requirements & Protection
We may disclose personal information when required by Thai law, court orders, or government regulations. This includes cooperation with law enforcement investigations, compliance with tax reporting requirements, and protection of our legal rights or those of our users.
Important: We never sell, rent, or trade your personal information to marketers, data brokers, or advertising companies. Any data sharing is limited to the specific purposes outlined above and governed by strict contractual protections.
Your Rights & Control
Under Thai Personal Data Protection Act (PDPA) and international privacy standards, you have comprehensive rights regarding your personal information. Here's how you can exercise these rights:
Access & Portability Rights
You can request a complete copy of all personal data we hold about you. This includes your profile information, financial data, usage history, and communication records. We provide this information in a structured, machine-readable format within 30 days of your request.
To request your data, log into your account dashboard and use the "Export My Data" feature, or email our privacy team at info@logical-data-glow.com with the subject line "Data Access Request."
Correction & Update Rights
You can update most of your information directly through your account settings. For data that cannot be self-edited, contact our support team with specific correction requests. We process these updates within 7 business days and notify you once changes are complete.
Deletion & Erasure Rights
You have the right to request deletion of your personal data. Account deletion can be initiated through your profile settings or by contacting our support team. Please note that complete data erasure may take up to 90 days due to backup systems and legal retention requirements.
Objection & Restriction Rights
You can object to specific processing activities or request temporary restrictions on data use. Common reasons include concerns about automated categorization accuracy or objections to marketing communications. Contact our privacy team to discuss your specific concerns and available options.
Security Measures & Protection
Protecting your financial information is fundamental to our operations. We implement multiple layers of security controls designed to prevent unauthorized access, data breaches, and misuse of your personal information.
Technical Security Controls
Operational Security Practices
Our team follows strict security protocols including mandatory privacy training, background checks for employees with data access, and regular security audits. We maintain incident response procedures and work with cybersecurity professionals to stay ahead of emerging threats.
All employees sign confidentiality agreements and receive ongoing training about data protection requirements. Access to customer data is limited to specific roles and monitored through detailed audit logs.
Breach Response Procedures
In the unlikely event of a data breach, we have established procedures to contain the incident, assess the impact, and notify affected users within 72 hours as required by Thai PDPA regulations. We work with law enforcement and regulatory authorities as needed and provide regular updates throughout the resolution process.
Data Retention & Deletion
We retain your personal information only as long as necessary for the purposes it was collected or as required by applicable law. Different types of data have different retention periods based on their function and legal requirements.
Active Account Data
While your account remains active, we retain your profile information, financial data, and usage history to provide ongoing service. You can delete or modify this information at any time through your account settings.
Inactive Account Procedures
If you don't log in for 18 months, we'll send reminder emails about account inactivity. After 24 months of inactivity, we begin the account closure process, which includes a final notification with options to reactivate or confirm deletion.
Data Category | Active Retention | Post-Deletion |
---|---|---|
Profile Information | Duration of account | Immediate deletion |
Financial Transactions | Duration of account | 30 days then deleted |
Support Communications | 3 years | Anonymized after 1 year |
Payment Records | 7 years (tax compliance) | Cannot be deleted early |
Legal Retention Requirements
Thai tax law requires retention of certain financial records for seven years. This applies only to payment and billing information, not to your personal financial data or transaction categorizations. We maintain these records in secure, separate systems with restricted access.
International Data Transfers
While our primary operations are based in Thailand, some of our service providers operate from other countries. We ensure all international data transfers comply with Thai PDPA requirements and include appropriate safeguards for your information.
Transfer Safeguards
All international transfers are governed by standard contractual clauses approved by Thai data protection authorities. Our service providers must implement equivalent security measures and are contractually prohibited from using your data for their own purposes.
We regularly review our international transfer arrangements and update them as data protection laws evolve. You can request specific information about transfers affecting your data by contacting our privacy team.
Privacy Contact & Support
For questions about this privacy policy, data protection practices, or to exercise your privacy rights, our dedicated privacy team is available to help. We respond to most privacy inquiries within 48 hours and provide regular updates on complex requests.
Privacy Request Procedures
To ensure security, privacy requests require identity verification. Please provide your account email address and answer a security question when submitting requests. For complex matters, we may schedule a brief verification call.
Emergency privacy concerns, such as suspected unauthorized access to your account, receive immediate priority. Contact us immediately if you notice unusual account activity or have concerns about data security.
Contact Our Privacy Team
This privacy policy was last updated on January 15, 2025, and is reviewed quarterly to ensure compliance with evolving privacy regulations.