General Privacy Statement

This Privacy Policy explains how exvoramiify (operating at exvoramiify.club) collects, uses and protects personal data in the provision of legal services for the IT sector. We describe categories of data processed, legal bases for processing, retention periods, safeguards for international transfers and the rights available to individuals. The policy applies to visitors, clients and partners in connection with our professional services and website interactions.

17-04-2026 exvoramiify Co., Ltd. — Business ID 2476022665852 Tha Sai Sub District, Amphoe Mueang Nonthaburi District, Nonthaburi Province 11000, Thailand [email protected]

Definitions

To help you understand this policy, we provide clear definitions of key terms used throughout. These definitions reflect the functions and types of information relevant to legal services for technology businesses.

Personal data means any information relating to an identifiable natural person, such as name, contact details, identification numbers, business affiliation, or other information that can be used to identify an individual directly or indirectly.
Processing includes any operation or set of operations performed on personal data, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, erasure or destruction.
User means a visitor to the website, a prospective or existing client, or any individual whose data is processed by exvoramiify in the course of providing legal and advisory services.
Service refers to the professional legal services we deliver to clients in the IT sector, including contract review, IP advisory, data protection assessments, compliance advice and related legal support.
Cookies are small data files stored on a device by the browser at the request of the website. They enable functions like session management, analytics and preferences.

What Data We Collect

We collect personal data necessary to provide professional legal services, to operate the website and to comply with legal obligations. Collection methods include direct submission by users, automatic technical collection and third-party sources where permitted.

Data You Provide Directly

When you engage our services, request information or communicate with us, you may provide the following categories of personal data:

  • Identity and contact information (name, email address, telephone number, company name)
  • Business and professional details (position, company registration, industry sector and business ID)
  • Transactional and billing information (invoices, payment confirmations, billing address)
  • Case and engagement materials (contracts, technical documentation, project descriptions, code samples where relevant)
  • Communications and correspondence provided by you (emails, messages, meeting notes)
  • Consents and preferences provided for marketing or service notifications

Data Collected Automatically

When you use our website or interact with digital services, certain technical data is collected automatically to support functionality, security and analytics:

  • Device and browser information (type, version, operating system)
  • IP address and approximate location derived from network data
  • Usage logs and interaction data (pages visited, time on site, click events)
  • Cookies and similar tracking technologies to remember preferences and measure performance
  • Error and diagnostic data when an application or page fails
  • Analytics identifiers used by analytics platforms to improve site functionality

Data from Third-Party Sources

We may supplement data you provide with information obtained from trusted third parties to perform services and comply with obligations:

  • Payment processors and banks for transaction verification
  • Professional service providers and advisors engaged to support a client matter
  • Publicly available registries and corporate databases for identity and business verification

Purposes of Processing

We process personal data for specific, explicit and legitimate purposes directly related to our legal services and website operation. Processing is limited to what is necessary for each purpose.

  • To provide and manage legal advisory services and execute contractual obligations with clients
  • To perform identity, anti-funds laundering and compliance checks required by law or professional standards
  • To process payments, issue invoices and manage business records
  • To communicate about matters relating to engagements, deliverables, schedules and administrative matters
  • To maintain and improve our website, services and internal operations through analytics and research
  • To protect the security, integrity and availability of our systems and client data
  • To respond to legal requests, enforce agreements and exercise legal rights where necessary
  • To provide marketing communications where you have given consent and to manage your communication preferences

Legal Bases for Processing

We rely on appropriate legal bases for processing personal data. These bases are selected according to the nature of the processing activity and applicable law.

Cookies and Similar Technologies

We use cookies and similar technologies to ensure the website functions correctly, to analyze usage and to remember preferences. Cookies help us deliver a stable and secure experience.

Types of cookies used include session cookies, persistent cookies, and third-party cookies provided by analytics and performance services.

Categories: strictly necessary (site operation), functional (preferences), performance/analytics (usage measurement) and marketing (where applicable and only with consent).

You can manage cookie preferences via your browser settings or through available consent controls on the site. Disabling certain cookies may affect site functionality.

Cookie Policy

When We Share Your Data

We share personal data only when necessary for the operation of services, with contractual partners, or when legally required. Recipients are bound to process data in accordance with this policy and applicable law.

  • Service providers and sub-contractors engaged to deliver or support our legal services (hosting, IT, document management)
  • Payment processors and business institutions for billing and transactional purposes
  • Professional advisors and auditors engaged under confidentiality obligations
  • Regulatory bodies, courts or law enforcement when required by law or to respond to legal claims
  • Prospective buyers, supporter or advisors if there is a corporate transaction involving our business, subject to confidentiality and legal safeguards
  • Analytics and performance service providers to improve website and service delivery under appropriate data processing terms

International Data Transfers

Personal data may be transferred to and processed in jurisdictions outside the country where you reside, including locations where our service providers operate. When transfers occur, we take steps to ensure an adequate level of protection for personal data.

Safeguards for international transfers may include standard contractual clauses, data processing agreements with approved protections, and technical measures such as encryption to protect data in transit and at rest.

Data Retention

We retain personal data for as long as necessary to fulfill the purposes described in this policy, to meet legal and regulatory obligations, and to maintain records consistent with professional standards.

Account and client files are retained for the duration of the engagement plus a reasonable archival period determined by legal and regulatory requirements and professional best practice.

Communications and case notes are retained for periods aligned with client matter lifecycle and applicable retention schedules, then archived or securely deleted.

System logs and technical monitoring data are retained for operational and security reasons for defined periods and are subject to secure deletion policies.

On termination of services or when data is no longer necessary, we securely delete or anonymize personal data except where retention is required by law or for legitimate business purposes such as dispute resolution.

Security of Personal Data

We implement technical and organizational measures proportionate to the risks associated with processing activities. Measures include administrative policies, encrypted communications, access controls, regular security reviews and staff training to protect data confidentiality and integrity.

  • Encryption of data in transit using industry-standard protocols and encryption of sensitive data at rest where appropriate
  • Role-based access controls, multi-factor authentication for privileged systems and least-privilege principles for staff access
  • Regular vulnerability assessments, patching practices and incident response procedures to detect and address security events

Your Privacy Rights

Depending on applicable law, individuals may have rights in relation to their personal data. We provide mechanisms to exercise those rights and will respond in accordance with legal requirements.

  • Right to access personal data we hold about you and details of processing
  • Right to request correction of inaccurate or incomplete personal data
  • Right to request deletion of personal data where processing is no longer necessary and no legal basis to retain it exists
  • Right to request restriction of processing in certain circumstances
  • Right to data portability where processing is based on consent or contract and technically feasible
  • Right to object to processing based on legitimate interests or for direct marketing purposes
  • Right to withdraw consent at any time for processing activities based on consent, without affecting processing prior to withdrawal
  • Right to lodge a complaint with a relevant data protection authority if you consider your rights have been infringed

How to Exercise Your Rights

If you wish to exercise your data rights, including access, correction, deletion, or portability, submit a request describing the specific information you need. We will verify your identity and process the request in accordance with applicable law and our internal policies. Requests should include: your full name, email address used with exvoramiify, a description of the records sought, and a copy of an ID when required for verification.

[email protected]

We aim to acknowledge receipt of privacy rights requests promptly and to complete routine requests within a reasonable time frame. Complex requests may require additional time for verification and review; we will communicate any expected extension and the reasons for it. If more information is needed to process your request, we will ask for it and pause the timeline until we receive a response.

Data Subject Rights and GDPR-related Principles

Although exvoramiify operates in Thailand, we follow internationally recognized data protection practices inspired by GDPR principles where applicable to cross-border processing and EU subjects. We process personal data lawfully, transparently and for specified purposes relevant to delivering legal services to IT sector clients. This section explains key rights and how to exercise them.

  • Right of access: You may request a copy of personal data we hold about you and information on how it is processed.
  • Right to rectification: You may request correction of inaccurate or incomplete personal data.
  • Right to erasure: Subject to legal and contractual retention obligations, you may request deletion of personal data that is no longer necessary for the purposes collected.
  • Right to restriction and objection: You may request restriction of processing or object to processing based on legitimate interests, direct marketing, or profiling under certain conditions.
  • Right to data portability: Where processing is based on consent or contract and carried out by automated means, you may request a structured, commonly used, machine-readable copy of your data.
  • Right not to be subject to automated decisions: You have rights regarding automated profiling or decision-making; we employ human oversight for client intake and legal advice where appropriate.

If you are resident in a jurisdiction with a supervisory authority overseeing data protection, you may contact that authority about our processing activities in addition to contacting us directly. We will cooperate with authorized supervisory inquiries to the extent required by applicable law.

Marketing Communications

We may send service-related notices, administrative messages and, where you have opted in, relevant newsletters about legal developments for the IT sector. Marketing communications are limited to information that helps clients manage legal risk, regulatory compliance and commercial transactions in technology and software industries.

To stop receiving promotional emails, follow the unsubscribe link included in the message or contact our privacy team at [email protected]. We will process unsubscribe requests promptly; service-related communications, such as contractual or billing notices, cannot be unsubscribed.

Children's Information

exvoramiify does not knowingly collect personal data from minors for client intake or legal services. If we learn that we have collected personal data from a child without appropriate consent where required by law, we will take steps to delete the data unless retention is necessary for compliance or legal obligations.

Third-Party Links and Services

Our website may contain links to third-party sites or services operated by partners, regulators or technology providers. These third parties maintain their own privacy practices and are responsible for their compliance. We recommend reviewing third-party privacy notices before providing personal information.

Changes to This Privacy Notice

We periodically review and update our privacy practices to reflect legal, technical and business developments. Material changes will be posted on exvoramiify.club with an updated effective date. Continued use of our services after changes implies acceptance of the revised terms.