Data Processing Agreement
← BackVersion 2026-07-25.2 · Nongbokwa (น้องบอกว่า)
This document forms part of the Terms of Service and applies when you use our service to collect or process your customers' personal data.
1. Roles of the parties
We process data only as needed to provide the service. We do not sell it or use it for our own separate purposes.
2. Data processed
- Your customers: name, phone, email, LINE ID, contact history.
- Pets: name, species, breed, and health records to the extent the owner has consented.
- Your appointments, inventory and income/expense records.
- Messages customers send through chat channels you connect.
3. Security measures
All connections encrypted (HTTPS) · data separated per business with permission checks on every request · passwords stored hashed only · every access to health data logged immutably · regular backups.
4. Sub-processors
To deliver the service we send some data to the following providers:
| Provider | Purpose |
|---|---|
| Google (Gemini API) | Processing text so the AI can answer customers and summarise data |
| LINE Corporation | Sending and receiving messages via the shop's LINE OA (when enabled) |
| Google Maps Platform | Place and map data |
| Google (Gmail / SMTP) | Sending system email such as password reset links, receipts and reminders |
5. Data subject rights
- Pet owners can view, correct or delete their own data directly in our app.
- Owners can withdraw consent to health record access at any time, effective immediately.
- If your customer contacts us directly, we will forward the request to you within 7 days.
- We will reasonably assist you in responding to data subject requests.
6. Breach notification
If a personal data breach occurs we will notify you without undue delay once aware, with the information we have, so you can report to the PDPC within the statutory deadline.
7. Retention and deletion
We keep data while you use the service. On termination you may request a copy within 30 days; afterwards we delete or anonymise it, except records we must keep by law such as payment documents.
8. Audit
You may reasonably request information about our security measures with at least 14 days' notice.
⚠️ This document was drafted following Thailand's Personal Data Protection Act B.E. 2562 but has not yet been reviewed by legal counsel — please contact us with any questions before using the service.