Your data is safe with ThaiBot
We built ThaiBot with PDPA compliance, encryption, and data privacy at the core — so you can deploy AI with confidence.
PDPA Compliant
ThaiBot is built to comply with Thailand's Personal Data Protection Act (PDPA) B.E. 2562. We process data under lawful bases defined by PDPA Sections 19 and 24, and we respect all data subject rights including access, rectification, erasure, and portability.
Encryption Everywhere
All data is encrypted in transit (TLS/SSL) and at rest (AES-256). Your customer conversations, business data, and personal information are protected at every layer of our infrastructure.
- AES-256 encryption at rest (Supabase)
- TLS 1.2+ on all connections
- Row Level Security on every database table
Your Data Is Never Used for AI Training
We enable Zero Data Retention (ZDR)on our AI routing service. Your prompts and conversations are never stored or used to train AI models. They exist only long enough to generate a response, then they're gone.
- OpenRouter: Zero Data Retention enabled
- Anthropic (Claude): Auto-deleted after 7 days, never trained on
- Google (Gemini): API-only access, not used for training
Trusted Infrastructure
ThaiBot runs on industry-leading infrastructure providers with enterprise-grade security certifications. We don't store payment card data — Stripe handles it all (PCI DSS Level 1).
Vercel
SOC 2 Type 2 • Hosting
Supabase
SOC 2 Type 2 • Database
Stripe
PCI DSS Level 1 • Payments
OpenRouter
ZDR Enabled • AI Routing
Cross-Border Safeguards
Data is stored on US-based servers (Supabase, Vercel). We implement Standard Contractual Clauses (SCCs) with vendors where available and obtain explicit user consent for cross-border transfers as required by PDPA Section 28.
Breach Notification
In the event of a confirmed data breach, we commit to notifying affected parties and the Personal Data Protection Committee (PDPC) within 72 hoursof discovery — exceeding the PDPA notification requirement.
Your Rights
Under PDPA, you have the right to access, correct, delete, restrict, and port your data. You can withdraw consent at any time. Contact privacy@thaibot.aiand we'll respond within 30 days.
Access Controls & Rate Limiting
All API endpoints are rate-limited to prevent abuse. Database access is secured with Row Level Security (RLS) — businesses can only access their own data. Administrative accounts require multi-factor authentication.
What we do — and don't do — with your data
We do
- ✓ Encrypt all data at rest and in transit
- ✓ Isolate each business's data with Row Level Security
- ✓ Delete your data when you ask us to
- ✓ Notify you within 72 hours of any breach
- ✓ Use Zero Data Retention on AI providers
- ✓ Honor all PDPA data subject rights
We never
- ✗ Sell your data to third parties
- ✗ Use your data to train AI models
- ✗ Share data with advertisers or data brokers
- ✗ Store credit card numbers (Stripe handles payments)
- ✗ Access one business's data from another account
- ✗ Retain AI prompts after generating a response
Questions about security?
We're happy to answer any questions about how we handle your data. Reach out to our team or read the full privacy policy.