Key definitions
To make the policy practical, we define terms used across scenarios and templates so readers can map them to real cases—contractor onboarding, procurement, and support interactions.
This privacy statement explains how omniluxpad collects and processes personal data in connection with its legal services for the IT sector. The text uses concrete examples and scenarios—such as onboarding a software development team, running a beta test, or licensing an API—to illustrate typical data flows and the steps omniluxpad takes to minimize legal and operational risk. We describe categories of data collected, lawful bases for processing, data-sharing cases with processors, and retention practices. This policy reflects practices for our operations in Thailand and, where relevant, cross-border matters involving regional partners.
To make the policy practical, we define terms used across scenarios and templates so readers can map them to real cases—contractor onboarding, procurement, and support interactions.
We collect data necessary to provide legal services and to operate the website. Below we list categories with practical examples from common IT scenarios such as contractor onboarding, beta testing programs, and client intake forms.
Direct data examples relate to intake forms, contract negotiations, and advisory sessions:
When you visit omniluxpad.pro or use our web tools, automated systems may collect technical data to operate the service and analyze usage patterns for product improvements.
We sometimes receive data from partners and service providers to support engagements and integrate tools used in practice scenarios.
We process data to deliver legal services, support site operation, and improve our practical guidance through case studies and scenario testing.
We rely on lawful bases appropriate to specific activities. Below are practical mappings between purposes and lawful grounds commonly used in our IT-focused work.
While omniluxpad operates in Thailand, many clients engage in cross-border activities. We map our practices to common protections found in regional frameworks and adopt practical safeguards accordingly.
Cookies support essential site functions and help us analyze how legal materials are used so we can refine examples and workshops.
We use session cookies for authentication, persistent cookies for preferences, and analytics cookies to collect anonymized usage data during case-study viewing.
Categories include: necessary (site operation), preferences (language), analytics (usage of templates and pages), and marketing (optional announcements about workshops).
You can manage cookie preferences via the cookie settings banner on omniluxpad.pro or adjust your browser settings to block or delete cookies; note that some features may not function correctly if cookies are disabled.
Full cookie policy
Sharing is limited to the needs of a specific legal engagement or to comply with lawful requests. All sharing scenarios are illustrated with concrete examples.
When data is transferred outside Thailand for hosting or professional collaboration, we assess legal requirements and implement reasonable safeguards tailored to the transfer scenario—examples include using EU-standard contractual clauses for transfers involving European entities or contractual protections with regional processors.
Safeguards may include encrypted storage, limited access controls, data-processing agreements with processors, and contractual terms specifying permitted processing activities relevant to the engagement.
Retention is purpose-driven: we retain only what is needed for the matter, compliance, or legitimate business purposes described in the case scenarios below.
Account records and identification details are retained for the duration of an active engagement plus a standard post-engagement period to address follow-up matters, typically aligned with applicable statutory limitation periods.
Communications platform during negotiations or advisory sessions are kept for case management and dispute readiness; where practical they are archived and access is restricted to relevant staff.
System logs, access records, and analytics used for troubleshooting and security are retained for limited periods and anonymized where possible to support ongoing service improvements and incident contribute.
Personal data retention is based on the legal and operational needs of omniluxpad. Client records, contract documents, billing records and case files are retained for periods required by Thai law and industry standards, typically between 3 and 10 years depending on the document type and legal requirement. When data is no longer required, we will securely delete or anonymize it using documented procedures. For deletion requests related to active legal matters we may limit deletion where retention is necessary for case integrity, dispute resolution, regulatory compliance, or to complete a contractual obligation. Examples: in one compliance review scenario we retained audit logs for seven years to satisfy regulatory reporting; in a contract termination case we retained billing and engagement records for five years to respond to potential claims.
omniluxpad applies technical and organizational measures to protect personal and business data handled in legal engagements with IT sector clients. Measures are selected based on risk assessments and include access controls, encryption, incident response procedures and regular security reviews. We prioritize scenario-based controls: for example, for M&A due diligence projects we compartmentalize access to sensitive repositories; for recurring compliance audits we maintain encrypted archives with role-based retrieval.
As a data subject interacting with omniluxpad, you have rights under applicable data protection laws. Below are practical options and step-by-step scenarios illustrating how you can exercise each right, and typical response timelines we follow.
To submit a data rights request, contact our Data Protection Officer at the address or email below. Include your full name, contact details, clear description of the right you wish to exercise, and any supporting identification. For example, a rectification request should include the record to be corrected and documentation supporting the change. We may request additional information to verify identity and scope but will avoid unnecessary delays.
We aim to acknowledge receipt of rights requests within 5 working days and provide a substantive response within 30 calendar days. For complex requests, or where additional verification is required, we will inform you if we need up to an additional 60 days and explain the reasons.
omniluxpad may send informational updates about legal developments, events, and services relevant to the IT sector where you have opted in. Communications are tailored to scenarios such as compliance bulletins for data protection, contract drafting tips for software licensing, or regulatory alerts for fintech clients. We only send marketing that matches your preferences and the scope of our relationship.
To stop marketing communications, follow the unsubscribe link in our emails or contact [email protected]. In practice, unsubscribes are processed within five business days and you will continue to receive transactional messages related to active engagements unless you request otherwise.
omniluxpad does not offer services directed to children and we do not knowingly collect personal data from minors for legal engagements. If we identify data belonging to a child in error during a client matter, we will take steps to limit processing and, where required by law, notify the relevant parties and remove the data when appropriate.
Our website and client portals may link to third-party services or use third-party tools such as cloud storage, analytics, or payment providers. These services have their own privacy policies. In scenario-based outsourcing arrangements, we contractually require third parties to follow confidentiality and data protection standards appropriate for legal work and to process data only on documented instructions.
We periodically review privacy practices to reflect regulatory changes and operational improvements. Any material changes will be published on our site with an effective date. For example, when we introduced a new client portal we published a revision describing new security controls and data flows.
For privacy concerns, rights requests, or questions about data handling, contact: omniluxpad Data Protection Officer, 11/6, Thanon Nakhon In, Bang Khen Sub District, Amphoe Mueang Nonthaburi District, Nonthaburi Province 11000, Thailand. Business ID: 0023228520366. Phone: +66939639395. Email: [email protected]. Office hours: Monday to Friday, 09:00–17:30 ICT. In case of an ongoing legal matter include engagement reference to help expedite handling.