ThaiBot for your business — get started for free
Trust & Security

Your data is safe with ThaiBot

We built ThaiBot with PDPA compliance, encryption, and data privacy at the core — so you can deploy AI with confidence.

PDPA Compliant

ThaiBot is built to comply with Thailand's Personal Data Protection Act (PDPA) B.E. 2562. We process data under lawful bases defined by PDPA Sections 19 and 24, and we respect all data subject rights including access, rectification, erasure, and portability.

Read our full Privacy Policy →

Encryption Everywhere

All data is encrypted in transit (TLS/SSL) and at rest (AES-256). Your customer conversations, business data, and personal information are protected at every layer of our infrastructure.

  • AES-256 encryption at rest (Supabase)
  • TLS 1.2+ on all connections
  • Row Level Security on every database table

Your Data Is Never Used for AI Training

We enable Zero Data Retention (ZDR)on our AI routing service. Your prompts and conversations are never stored or used to train AI models. They exist only long enough to generate a response, then they're gone.

  • OpenRouter: Zero Data Retention enabled
  • Anthropic (Claude): Auto-deleted after 7 days, never trained on
  • Google (Gemini): API-only access, not used for training

Trusted Infrastructure

ThaiBot runs on industry-leading infrastructure providers with enterprise-grade security certifications. We don't store payment card data — Stripe handles it all (PCI DSS Level 1).

Vercel

SOC 2 Type 2 • Hosting

Supabase

SOC 2 Type 2 • Database

Stripe

PCI DSS Level 1 • Payments

OpenRouter

ZDR Enabled • AI Routing

Cross-Border Safeguards

Data is stored on US-based servers (Supabase, Vercel). We implement Standard Contractual Clauses (SCCs) with vendors where available and obtain explicit user consent for cross-border transfers as required by PDPA Section 28.

Breach Notification

In the event of a confirmed data breach, we commit to notifying affected parties and the Personal Data Protection Committee (PDPC) within 72 hoursof discovery — exceeding the PDPA notification requirement.

Your Rights

Under PDPA, you have the right to access, correct, delete, restrict, and port your data. You can withdraw consent at any time. Contact privacy@thaibot.aiand we'll respond within 30 days.

Access Controls & Rate Limiting

All API endpoints are rate-limited to prevent abuse. Database access is secured with Row Level Security (RLS) — businesses can only access their own data. Administrative accounts require multi-factor authentication.

What we do — and don't do — with your data

We do

  • Encrypt all data at rest and in transit
  • Isolate each business's data with Row Level Security
  • Delete your data when you ask us to
  • Notify you within 72 hours of any breach
  • Use Zero Data Retention on AI providers
  • Honor all PDPA data subject rights

We never

  • Sell your data to third parties
  • Use your data to train AI models
  • Share data with advertisers or data brokers
  • Store credit card numbers (Stripe handles payments)
  • Access one business's data from another account
  • Retain AI prompts after generating a response

Questions about security?

We're happy to answer any questions about how we handle your data. Reach out to our team or read the full privacy policy.