Legal
Privacy Policy
What personal data Eden Technologies collects through this website, why, who else sees it, how long we keep it, and the rights you hold over it under the Personal Data Protection Act B.E. 2562 (2019).
Last updated 5 August 2026
Identity of the Data Controller
This Privacy Policy is issued by Eden Technologies Co., Ltd. (“the Company”, “we”, “us” or “our”), a limited company incorporated under the laws of the Kingdom of Thailand, tax identification number 0845567002524, having its registered office at 35/4 Moo 1, Taling Ngam, Koh Samui, Suratthani 84140, Thailand.
For the purposes of the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), the Company is the Data Controller in respect of the Personal Data described in this Policy. Where the General Data Protection Regulation (EU) 2016/679 or the UK GDPR applies to a particular data subject, the Company is the controller for those purposes also.
The Company has appointed a Data Protection Officer in accordance with section 41 of the PDPA. The Data Protection Officer may be contacted at dpo@edentechnologies.ai, by telephone on +66(0)81-089-0333, or in writing at the registered office above marked for the attention of the Data Protection Officer. In accordance with section 42 of the PDPA, the Data Protection Officer advises the Company on its compliance, monitors its processing operations, and is the point of contact for data subjects and for the Office of the Personal Data Protection Committee. General data protection enquiries and requests to exercise your rights may also be sent to privacy@edentechnologies.ai.
Scope
This Policy applies to Personal Data collected through the website at edentechnologies.ai and through correspondence arising from it.
This Policy does NOT apply to: (a) Personal Data processed by the Company as Data Processor on behalf of a client under a signed engagement, which is governed by the data protection provisions of that engagement and any accompanying data processing agreement; or (b) any third-party website, platform or service reached from a link on this website, each of which operates under its own privacy policy.
Where any provision of a signed engagement between the Company and a client conflicts with this Policy in relation to that engagement, the engagement prevails.
Definitions
“Personal Data” means any information relating to a natural person which enables the identification of that person, whether directly or indirectly, but excluding information of deceased persons in particular.
“Sensitive Personal Data” means Personal Data of the categories listed in section 26 of the PDPA, namely data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade union information, genetic data, biometric data, or any other data affecting the data subject in the same manner.
“Processing” means any operation performed on Personal Data, including collection, use, disclosure, storage, transfer, erasure and destruction.
“Data Subject” means the natural person to whom Personal Data relates.
Personal Data We Collect
4.1 Data you provide to us directly.
If you submit the enquiry form on the website, we collect: your name; the organisation you represent; your email address; your telephone number together with the country dialling code you select; the category of assistance you select; and the content of the message you write. Each of these fields is mandatory in order to submit the form.
If you contact us by email or telephone, we collect the contact details you use and the content of the communication.
4.2 Data collected automatically.
When you access the website, the following are received automatically: your IP address; approximate geographic location derived from that IP address; the type, version and language settings of your browser and operating system; the device type; the pages you request and the time of each request; and the referring page or source.
4.3 Data collected by the anti-automation check.
When you submit the enquiry form, Google reCAPTCHA collects device, browser and interaction information in order to assess whether the submission originates from a human being or an automated script, and receives your IP address for that purpose. The scope of that assessment is determined by Google and not by the Company.
4.4 Data collected for measurement.
The website uses Google Analytics (property G-XJ9TTM2QLW) to measure usage. Details are set out in the Cookies Policy.
4.5 What we do not collect.
We do not purchase Personal Data from data brokers. We do not compile behavioural profiles for advertising purposes. We do not knowingly collect Sensitive Personal Data through this website, and you are asked not to submit it.
Purposes and Legal Bases for Processing
We process Personal Data only where a legal basis under section 24 of the PDPA applies. The bases we rely upon are set out below.
- To respond to your enquiry, to prepare and issue a quotation or proposal, and to negotiate an engagement. Legal basis: necessity for the performance of a contract to which you are a party, or for taking steps at your request prior to entering into a contract (section 24(3)). Without your contact details we cannot reply.
- To maintain a record of correspondence, quotations and agreed scope. Legal basis: our legitimate interests (section 24(5)), namely the ability to evidence what was requested, quoted and agreed.
- To protect the enquiry form and our systems against automated abuse, spam and unauthorised access. Legal basis: our legitimate interests (section 24(5)) in maintaining a functioning and secure contact channel; and, in relation to logging, compliance with law (section 24(6)).
- To measure and improve use of the website. Legal basis: your consent (section 19), obtained through the cookie consent mechanism described in the Cookies Policy.
- To comply with obligations imposed on us by law, including the retention of accounting records under the Accounting Act B.E. 2543 and the Revenue Code, and the retention of computer traffic data under section 26 of the Computer Crime Act B.E. 2550. Legal basis: compliance with a legal obligation (section 24(6)).
- To establish, exercise or defend legal claims, and to respond to a lawful order of a court or competent authority. Legal basis: our legitimate interests (section 24(5)) and compliance with a legal obligation (section 24(6)).
Where we rely on legitimate interests, we have assessed that interest against your rights and freedoms and concluded that the processing is proportionate. You may object to such processing under section 32 of the PDPA, and we will cease unless we can demonstrate a compelling legitimate ground.
Sensitive Personal Data
We do not seek and have no need for Sensitive Personal Data through this website. Please do not include it in the enquiry form or in correspondence.
If Sensitive Personal Data is submitted to us unsolicited, we will delete it as soon as reasonably practicable unless we are required to retain it by law, and we will not use it for any purpose. Submitting such data unsolicited does not constitute the explicit consent required by section 26 of the PDPA, and we do not treat it as such.
Minors
This website is directed at businesses and at persons acting in a professional capacity. It is not directed at children.
In accordance with section 20 of the PDPA, where consent is required and the Data Subject is a minor who has not attained majority under section 19 of the Civil and Commercial Code and whose act is not one a minor may perform independently, consent must be obtained from the holder of parental responsibility. Where the Data Subject is under ten years of age, consent must be obtained from the holder of parental responsibility.
We do not knowingly collect Personal Data from minors through this website. If you believe that a minor has provided Personal Data to us, please contact privacy@edentechnologies.ai and we will delete it.
Cookies and Similar Technologies
The website uses cookies and similar technologies. The categories used, the identity of each cookie, its purpose and its duration are set out in the Cookies Policy, which forms part of this Policy.
Cookies which are strictly necessary for the website to function and to be secure are set on the basis of our legitimate interests. All other cookies, including analytics cookies, are set only where you have given consent, and you may withdraw that consent at any time by the means described in the Cookies Policy.
Disclosure of Personal Data
We do not sell Personal Data. We do not disclose Personal Data to third parties for their own marketing purposes. We disclose Personal Data only as follows.
- To service providers acting as Data Processors on our behalf, including providers of website hosting, email, and customer relationship management. Each is engaged under a written agreement imposing obligations consistent with section 40 of the PDPA, including obligations of confidentiality, security, and processing only on our instructions.
- To Google LLC and its affiliates, in their capacity as providers of Google reCAPTCHA and Google Analytics, in accordance with their own terms and privacy policy.
- To our professional advisers, including lawyers, accountants and auditors, where necessary for them to advise us and subject to duties of confidentiality.
- To a court, regulator, law enforcement agency or other competent authority, where we are required to disclose by law or by lawful order, or where disclosure is necessary to establish, exercise or defend legal claims.
- To a purchaser or prospective purchaser in connection with a sale, merger, reorganisation or transfer of all or part of our business, subject to appropriate confidentiality undertakings.
Cross-Border Transfer
The Company is established in Thailand. Certain of our service providers, including Google, process Personal Data outside Thailand, including in the United States and in other jurisdictions.
Where Personal Data is transferred outside Thailand, we do so in accordance with sections 28 and 29 of the PDPA and the relevant notifications of the Personal Data Protection Committee, relying on one or more of the following: that the destination country or international organisation has adequate data protection standards; that appropriate safeguards are in place together with enforceable rights and effective legal remedies, including standard contractual clauses adopted by the recipient; that the transfer is necessary for the performance of a contract with you or at your request; or that you have given consent having been informed of the inadequate standards of the destination.
You may request information about the safeguards applicable to a particular transfer by writing to privacy@edentechnologies.ai.
Retention
We retain Personal Data only for as long as necessary for the purposes for which it was collected, and thereafter only where retention is required by law.
| Category of data | Retention period |
|---|---|
| Enquiry submitted through the website, and related correspondence | For the duration of the enquiry and for twenty-four (24) months following our last communication with you, after which it is deleted. |
| Correspondence forming part of an engagement | For the duration of the engagement and for the limitation period applicable to claims arising from it |
| Accounting and tax records | Not less than five (5) years, as required by the Accounting Act B.E. 2543, extended where the Revenue Code requires a longer period |
| Computer traffic data and server logs | Not less than ninety (90) days, as required by section 26 of the Computer Crime Act B.E. 2550, and not longer than two (2) years |
| Analytics data | As configured in Google Analytics, and in no case longer than fourteen (14) months for event-level data |
| Records of consent and of the exercise of rights | For the period necessary to evidence our compliance, and for not less than the applicable limitation period |
Where Personal Data is no longer required, we erase, destroy or anonymise it such that the Data Subject can no longer be identified.
Security Measures
In accordance with section 37(1) of the PDPA, we maintain appropriate security measures to prevent loss, and unauthorised or unlawful access, use, alteration, correction or disclosure of Personal Data.
Those measures include: transmission of the website and of form submissions over HTTPS using current transport encryption; restriction of access to Personal Data to those personnel who require it in order to perform their duties; contractual confidentiality obligations binding personnel and processors; review of access rights upon a change of role or departure; and periodic review of these measures.
No method of transmission over the internet and no method of electronic storage is completely secure. We therefore do not and cannot warrant absolute security, and we state this expressly rather than imply the contrary.
Personal Data Breach
In the event of a Personal Data breach, we will notify the Office of the Personal Data Protection Committee without delay and, where feasible, within seventy-two (72) hours of becoming aware of it, in accordance with section 37(4) of the PDPA.
Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you and describe the remedial measures taken, without delay.
Your Rights as a Data Subject
Subject to the conditions, exceptions and refusal grounds set out in the PDPA, you have the following rights.
- Right of access and to obtain a copy (section 30). To be informed whether we hold Personal Data relating to you, to access it, to obtain a copy, and to be informed of the source where it was not obtained from you.
- Right to data portability (section 31). To receive Personal Data in a machine-readable format and to have it transmitted to another controller, where the processing is by automated means and is based on your consent or on contractual necessity.
- Right to object (section 32). To object to processing based on legitimate interests or carried out for the purposes of direct marketing, scientific, historical or statistical research.
- Right to erasure or destruction (section 33). To have Personal Data erased, destroyed or anonymised where it is no longer necessary, where you withdraw consent, or where the processing is unlawful.
- Right to restriction of processing (section 34). To require that processing be suspended, including while the accuracy of data or the lawfulness of processing is being verified.
- Right to rectification (section 35). To have inaccurate Personal Data corrected and incomplete Personal Data completed, and to have it kept up to date.
- Right to withdraw consent (section 19, paragraph five). To withdraw consent at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right to lodge a complaint (section 73). To complain to the Office of the Personal Data Protection Committee where you believe that we or our processors have contravened the PDPA.
Where we refuse a request, we will record the reason for refusal and inform you of it, as required by the PDPA.
How to Exercise Your Rights
To exercise any right, write to privacy@edentechnologies.ai, or to the Company at the registered office stated above, marked for the attention of the data protection contact point.
We may request information reasonably necessary to verify your identity, in order to avoid disclosing Personal Data to a person not entitled to receive it. We will not use that information for any other purpose.
We will respond within thirty (30) days of receipt of a valid request, in accordance with section 30 of the PDPA. Where a request is complex or numerous, we may extend that period and will inform you of the extension and the reason for it within the initial period.
No fee is charged for a first request. A reasonable fee reflecting administrative cost may be charged for a repeated request for the same data made within a short interval, or for additional copies.
Consequences of Not Providing Personal Data
The fields in the enquiry form are mandatory because each is necessary in order for us to identify the enquirer, to reply, and to understand what is being asked. If you do not provide them, the form cannot be submitted and we will be unable to respond to you. There is no other consequence, and no service is otherwise withheld.
Automated Decision-Making and Profiling
We do not take decisions concerning you based solely on automated processing, and we do not carry out profiling. Every enquiry is read by a person.
The anti-automation check on the enquiry form assesses whether a submission is automated. It does not assess you as a person and does not produce a decision about you; where it is not satisfied, the form offers a further verification step rather than rejecting the submission. If the Company later introduces automated triage or scoring of enquiries, this clause must be amended and, where applicable, the requirements of section 24 and section 32 of the PDPA addressed.
Marketing
We do not operate a newsletter and we do not send marketing communications on the basis of an enquiry alone. If we introduce marketing communications, we will obtain your separate, freely given consent, which will not be a condition of any service, and every such communication will contain a means of withdrawing consent.
Amendment of this Policy
We may amend this Policy from time to time. The version number and effective date appear at the end of the document.
Where an amendment materially affects the processing of Personal Data we already hold, we will take reasonable steps to notify affected Data Subjects directly, and will not rely upon publication of the amended Policy alone. Where an amendment requires consent, we will obtain it before the amendment takes effect in relation to you.
Complaints
If you are dissatisfied with how we have handled your Personal Data or your request, please contact privacy@edentechnologies.ai in the first instance so that we may attempt to resolve the matter.
You may at any time complain to the Office of the Personal Data Protection Committee, Ministry of Digital Economy and Society, Kingdom of Thailand. If you are located in the European Economic Area or the United Kingdom, you may instead complain to the supervisory authority of your country of residence or place of work.
Governing Law and Language
This Policy is governed by and construed in accordance with the laws of the Kingdom of Thailand.
This Policy is issued in Thai and in English. In the event of any discrepancy or inconsistency between the two versions, the Thai version shall prevail.