Privacy & Data Handling

General privacy statement

This privacy statement explains how omniluxpad collects and processes personal data in connection with its legal services for the IT sector. The text uses concrete examples and scenarios—such as onboarding a software development team, running a beta test, or licensing an API—to illustrate typical data flows and the steps omniluxpad takes to minimize legal and operational risk. We describe categories of data collected, lawful bases for processing, data-sharing cases with processors, and retention practices. This policy reflects practices for our operations in Thailand and, where relevant, cross-border matters involving regional partners.

31-07-2026
omniluxpad Co., Ltd., Business ID 0023228520366
11/6, Thanon Nakhon In, Bang Khen Sub District, Amphoe Mueang Nonthaburi District, Nonthaburi Province 11000, Thailand

Key definitions

To make the policy practical, we define terms used across scenarios and templates so readers can map them to real cases—contractor onboarding, procurement, and support interactions.

Personal data means any information that can identify an individual in a professional or consumer context. Examples used in our IT cases include developer names, business emails, IP addresses collected during testing, and billing contact details. Processing includes any operation performed on personal data such as collection, storage, analysis for compliance checks, or transmission to a third-party hosting provider during a product trial scenario. User refers to any individual who interacts with omniluxpad services, requests templates, or participates in a legal intake for a particular IT project. Examples: a CTO requesting a SaaS subscription agreement review or a product manager sharing telemetry for a privacy impact assessment. Service refers to the legal services, templates, compliance audits, and advisory sessions offered by omniluxpad to technology companies and teams operating in Thailand and the region. Cookies are small data files used on omniluxpad.pro to support sessions, website analytics, and preferences. In illustrative scenarios, cookies support login persistence during contract review sessions and anonymous analytics to improve guidance materials.

What data we collect

We collect data necessary to provide legal services and to operate the website. Below we list categories with practical examples from common IT scenarios such as contractor onboarding, beta testing programs, and client intake forms.

Data you provide directly

Direct data examples relate to intake forms, contract negotiations, and advisory sessions:

  • Contact details (name, company, business email, business phone) when requesting a consultation.
  • Company information (legal entity name, Business ID 0023228520366 where applicable, registered address) for drafting contracts and filings.
  • Project-specific details such as scope of work, source code access requests, or test environment credentials provided for limited review purposes.
  • Billing and invoicing information for paid services when entering into a retainer or discrete engagement.
  • Communications and attachments platform during negotiations or dispute handling, including emails and supporting documents.
  • Consent choices and preferences for marketing or newsletters related to legal updates and case studies.

Data collected automatically

When you visit omniluxpad.pro or use our web tools, automated systems may collect technical data to operate the service and analyze usage patterns for product improvements.

  • Device and browser information used when accessing contract templates and case libraries.
  • IP addresses, timestamps, and pages visited to troubleshoot access issues during a contract drafting session.
  • Usage metrics such as download counts for templates and viewing of scenario-based case studies.
  • Cookie identifiers to manage sessions and remember preferences during repeated visits.
  • Error logs and performance data when interactive legal tools are used for tasks like clause comparison.
  • Geo-location approximations derived from IP to comply with regional restrictions and present relevant regulatory guidance.

Third-party sources

We sometimes receive data from partners and service providers to support engagements and integrate tools used in practice scenarios.

  • Payment processors for invoicing and reconciliation in a paid engagement.
  • Hosting and cloud providers that store documents shared for contract review or DPIA exercises.
  • Professional advisors and translation partners when localized legal documents are required for cross-border operations.

Purposes of processing

We process data to deliver legal services, support site operation, and improve our practical guidance through case studies and scenario testing.

  • Provide legal advice, draft and negotiate contracts, and manage client matters for IT sector use cases.
  • Perform compliance reviews and privacy impact assessments for data-intensive products.
  • Manage billing, subscriptions, and retainer arrangements for paid services.
  • Improve services by analyzing anonymized usage of templates and case-study resources.
  • Communicate updates, invitations to workshops, or scenario-based webinars relevant to technology teams.
  • Detect and respond to security incidents affecting stored documents or communications.
  • Fulfil legal or regulatory obligations when required by Thai authorities or applicable cross-border rules.
  • Support dispute resolution and cooperation with professional advisers in specific contract or IP cases.

Legal bases for processing

We rely on lawful bases appropriate to specific activities. Below are practical mappings between purposes and lawful grounds commonly used in our IT-focused work.

  • Contract performance: processing necessary to prepare, negotiate, and execute client agreements.
  • Legal obligation: processing required to comply with statutory requests or reporting duties in Thailand.
  • Legitimate interests: processing to maintain security of services, manage client relationships, and improve offerings subject to impact assessments where needed.
  • Consent: when collecting optional marketing preferences or sharing case-study materials where personal data would be disclosed beyond anonymized examples.

Regional data protections and standards

While omniluxpad operates in Thailand, many clients engage in cross-border activities. We map our practices to common protections found in regional frameworks and adopt practical safeguards accordingly.

  • Data minimization: when performing assessments we limit collection to information necessary for the specific legal task, illustrated by a redaction workflow used for sensitive code samples.
  • Purpose limitation: data collected for contract drafting is not reused for unrelated profiling or marketing without consent.
  • Access controls and role-based permissions for staff handling client documents during negotiation exercises.
  • Incident response playbook describing steps taken in a breach scenario, including notification procedures to affected parties when required.
  • Data protection by design in template development: example clauses and default settings that reduce unnecessary data exposure.
  • Cross-border transfer assessments and standard contractual clauses or equivalent safeguards used in specific engagements with overseas processors.

Cookies and similar technologies

Cookies support essential site functions and help us analyze how legal materials are used so we can refine examples and workshops.

We use session cookies for authentication, persistent cookies for preferences, and analytics cookies to collect anonymized usage data during case-study viewing.

Categories include: necessary (site operation), preferences (language), analytics (usage of templates and pages), and marketing (optional announcements about workshops).

You can manage cookie preferences via the cookie settings banner on omniluxpad.pro or adjust your browser settings to block or delete cookies; note that some features may not function correctly if cookies are disabled.

Full cookie policy

When we share data

Sharing is limited to the needs of a specific legal engagement or to comply with lawful requests. All sharing scenarios are illustrated with concrete examples.

  • With service providers hosting documents necessary for a contract review or DPIA, subject to contractual data-processing terms.
  • With payment processors to complete billing for paid retainer services.
  • With professional advisors (accountants, translators, local counsel) engaged for a specific project, under confidentiality terms.
  • With authorities when disclosure is required by Thai law or by a valid legal process.
  • With prospective acquirers or partners in the event of a reorganization, limited to information necessary for due diligence and guarded by NDAs.
  • Aggregated or anonymized data used for internal analysis or public case studies where individual identities are removed.

International transfers

When data is transferred outside Thailand for hosting or professional collaboration, we assess legal requirements and implement reasonable safeguards tailored to the transfer scenario—examples include using EU-standard contractual clauses for transfers involving European entities or contractual protections with regional processors.

Safeguards may include encrypted storage, limited access controls, data-processing agreements with processors, and contractual terms specifying permitted processing activities relevant to the engagement.

Data retention

Retention is purpose-driven: we retain only what is needed for the matter, compliance, or legitimate business purposes described in the case scenarios below.

Account records and identification details are retained for the duration of an active engagement plus a standard post-engagement period to address follow-up matters, typically aligned with applicable statutory limitation periods.

Communications platform during negotiations or advisory sessions are kept for case management and dispute readiness; where practical they are archived and access is restricted to relevant staff.

System logs, access records, and analytics used for troubleshooting and security are retained for limited periods and anonymized where possible to support ongoing service improvements and incident contribute.

Personal data retention is based on the legal and operational needs of omniluxpad. Client records, contract documents, billing records and case files are retained for periods required by Thai law and industry standards, typically between 3 and 10 years depending on the document type and legal requirement. When data is no longer required, we will securely delete or anonymize it using documented procedures. For deletion requests related to active legal matters we may limit deletion where retention is necessary for case integrity, dispute resolution, regulatory compliance, or to complete a contractual obligation. Examples: in one compliance review scenario we retained audit logs for seven years to satisfy regulatory reporting; in a contract termination case we retained billing and engagement records for five years to respond to potential claims.

Data Security and Operational Controls

omniluxpad applies technical and organizational measures to protect personal and business data handled in legal engagements with IT sector clients. Measures are selected based on risk assessments and include access controls, encryption, incident response procedures and regular security reviews. We prioritize scenario-based controls: for example, for M&A due diligence projects we compartmentalize access to sensitive repositories; for recurring compliance audits we maintain encrypted archives with role-based retrieval.

  • Access control and least-privilege scenarios: role-based accounts, multi-factor authentication for privileged users and logging of access to sensitive case files in vendor and client matters.
  • Encryption at rest and in transit for client data and case materials. In a practical case involving source-code escrow review, full-disk encryption and encrypted file transfers were used to prevent unauthorized exposure.
  • Operational processes: periodic vulnerability scans, third-party security assessments on infrastructure supporting client portals, and incident response procedures tested with tabletop exercises based on real-case attack simulations.

Your Privacy Rights

As a data subject interacting with omniluxpad, you have rights under applicable data protection laws. Below are practical options and step-by-step scenarios illustrating how you can exercise each right, and typical response timelines we follow.

  • Right of access — you may request a copy of personal data we hold about you. In a practitioner scenario we provide a data export in a commonly used format and an explanation of processing purposes.
  • Right to rectification — if information is inaccurate or incomplete, submit supporting documentation and we will update records within the scope of the engagement and notify relevant parties where appropriate.
  • Right to erasure — you may request deletion where data is no longer necessary, subject to legal or contractual retention needs; in practice deletions for closed non-regulated matters are completed after verification of identity.
  • Right to restriction of processing — you can ask us to limit processing while a dispute about accuracy is resolved. For example, we can freeze access to a contested document during a compliance review.
  • Right to data portability — where applicable, we can provide a structured, machine-readable copy of personal data we process if the processing is based on consent or a contract.
  • Right to object — you may object to certain processing activities related to direct marketing or profiling; we will assess each case and provide a response with operational next steps.
  • Right to lodge a complaint — if you consider our processing unlawful you may submit an internal complaint; we will contribute and provide an outcome and you may also contact local supervisory authorities.
  • Rights in relation to automated decisions — where legally applicable, you can request human review of automated decision-making affecting you; we document contexts in which automated tools are used and provide manual appeal routes.

How to Submit a Rights Request

To submit a data rights request, contact our Data Protection Officer at the address or email below. Include your full name, contact details, clear description of the right you wish to exercise, and any supporting identification. For example, a rectification request should include the record to be corrected and documentation supporting the change. We may request additional information to verify identity and scope but will avoid unnecessary delays.

[email protected]

We aim to acknowledge receipt of rights requests within 5 working days and provide a substantive response within 30 calendar days. For complex requests, or where additional verification is required, we will inform you if we need up to an additional 60 days and explain the reasons.

Marketing Communications

omniluxpad may send informational updates about legal developments, events, and services relevant to the IT sector where you have opted in. Communications are tailored to scenarios such as compliance bulletins for data protection, contract drafting tips for software licensing, or regulatory alerts for fintech clients. We only send marketing that matches your preferences and the scope of our relationship.

To stop marketing communications, follow the unsubscribe link in our emails or contact [email protected]. In practice, unsubscribes are processed within five business days and you will continue to receive transactional messages related to active engagements unless you request otherwise.

Children's Privacy

omniluxpad does not offer services directed to children and we do not knowingly collect personal data from minors for legal engagements. If we identify data belonging to a child in error during a client matter, we will take steps to limit processing and, where required by law, notify the relevant parties and remove the data when appropriate.

Third-Party Links and Services

Our website and client portals may link to third-party services or use third-party tools such as cloud storage, analytics, or payment providers. These services have their own privacy policies. In scenario-based outsourcing arrangements, we contractually require third parties to follow confidentiality and data protection standards appropriate for legal work and to process data only on documented instructions.

Changes to This Privacy Policy

We periodically review privacy practices to reflect regulatory changes and operational improvements. Any material changes will be published on our site with an effective date. For example, when we introduced a new client portal we published a revision describing new security controls and data flows.

Contact Information

For privacy concerns, rights requests, or questions about data handling, contact: omniluxpad Data Protection Officer, 11/6, Thanon Nakhon In, Bang Khen Sub District, Amphoe Mueang Nonthaburi District, Nonthaburi Province 11000, Thailand. Business ID: 0023228520366. Phone: +66939639395. Email: [email protected]. Office hours: Monday to Friday, 09:00–17:30 ICT. In case of an ongoing legal matter include engagement reference to help expedite handling.

+66939639395
11/6, Thanon Nakhon In, Bang Khen Sub District, Amphoe Mueang Nonthaburi District, Nonthaburi Province 11000, Thailand