Privacy Notice for Customers and Service Recipients

FlowAccount Co., Ltd. ("we", "us", "our") respects and values the right to privacy and is committed to protecting the personal data of its customers and service recipients ("Service Users"). We recognize the importance of the personal data that Service Users have entrusted to us. We have therefore prepared this Privacy Notice to assure Service Users that the personal data they provide to us will be used in accordance with their needs, in a lawful manner, and kept secure in accordance with international standards for personal data protection.

1. What personal data do we collect?
We will collect, use, and disclose ("Process") the personal data necessary to provide services to Service Users, which may be in the form of documents or electronic data. We may require Service Users to fill in information in documents or on online platforms that we have designated, including the following data:

1. General information of the Service User, such as title, first name, last name, occupation, national ID card number, contact information (namely email and telephone number), address, workplace, email, and telephone number.

2. Social Media Account information, such as social media account names, Facebook profile, Line ID, Google Account, Apple ID, and the like.

3. Electronic information that can identify the Service User (Online Identifier), namely Username / Password, information about the device that the Service User uses to connect to the application or to contact the Company, such as IP address, device identifier, device type, mobile network information, connection information, browser type, application access logs, application usage behavior (Customer Behavior), including searched data, use of various functions on the application, and information that the Company has collected through cookies or other similar technologies.

In this regard, with respect to the use of cookies, the Service User acknowledges that we have installed "Cookies", which are computer files that store necessary temporary information on the Service User's computer for the convenience of the Service User in using the website (which identifies only the computer, but does not identify the Service User or information relating to the Service User). We may use the information that cookies have recorded or collected for statistical analysis or website activities in order to improve the quality of our services.

4. Usage data that the Service User uses through the application, and device usage data for the enforcement of the Single User per Account device policy, namely:

  • Log-in data
  • Application usage history data
  • Information about the pattern and frequency of service use
  • The volume and type of use of various features in the system
  • Statistics on data access and processing
  • System performance data relating to the Service User's usage
  • Time of visiting and using the website (Access Time)
  • Device ID of the device used to access the service
  • Concurrent login sessions data
  • History of changes to registered devices
  • Data on violations of the device usage policy
  • Any other data necessary for improving service quality and determining the service fee structure

5. Payment information for the use of the Company's services, in particular payments made through the Company's application, whereby the Company may receive payment information and credit card information, including the Service User's payment history, through third-party payment system companies, as well as information appearing on quotations, invoices, tax invoices, receipts, and the like.

6. Search history information, such as browsing data, service request data, responses to our advertisements, including content viewed and links clicked.

7. Information related to study, seminars, and testing, such as answer data, attendance data, enrolled course data, examination score data, training history, training results, training certificates, diplomas, and any other documents that we issue as evidence in support of training and/or examinations, and the like.

8. Information entered on the website and information on participation in activities, such as registration for various campaigns, taking surveys, questionnaires, satisfaction assessment forms, suggestions, and opinion survey data, details regarding the exercise of rights, and complaints regarding services, or other similar items.

9. Interaction data and communication data, including information that the Service User may contact and notify us of through the Call Center, chat system, systems, applications, and our various services, in whatever form or by whatever method, which may be images, moving images, or audio, including but not limited to telephone, email, chat messages, and communications via online social media.

10. Other personal data that the Service User may provide to us, which may include but is not limited to photographs (still images and moving images) of the Service User who may participate in activities or training (Event / Webinar) that we may organize in either Online or Offline formats, testimonial information or opinions of the Service User that the Service User may give regarding the Company and/or other services.

11. Bank account information, such as account number, account name, financial status information, or other information appearing in such bank account, only to the extent necessary to provide the bank data connection service in the event that the Service User chooses to use such service.

12. Information about the work of you or your employees arising from the use of the time attendance service, such as clock-in and clock-out times, leave days, Geolocation, and salary, only to the extent necessary to provide the time attendance service in the event that the Service User chooses to use such service.

13. Information about your wage and tax payments arising from the use of the Payroll service, such as bank account number, salary rate, tax rate, overtime from the time recording system, personal allowances, and various tax deduction items, only to the extent necessary to provide the Payroll service in the event that the Service User chooses to use such service.

14. Other personal data that we may need to collect in order to perform the Company's duties in accordance with relevant laws, notices, or regulations, including other personal data that the Service User may consent to forward and disclose to us.


2. Do we collect sensitive personal data of Service Users?
In any event, we do not have a policy to collect sensitive personal data of Service Users relating to race, ethnicity, political opinions, cult beliefs, religion or philosophy, sexual behavior, criminal records, health data, disability, genetic data, biometric data, or any other data that similarly affects the Service User, in accordance with the notifications of the Personal Data Protection Committee.

In the event that we ask the Service User to take a photograph of the national ID card, or any other evidence containing information equivalent to that on the national ID card, in order to verify identity, this is merely a step to verify the accuracy and confirm the identity of the Service User for the use of only certain services. We do not intend to collect, gather, or use personal data that is classified as sensitive personal data, such as race, blood group information, or religious information, even though such information may appear on the national ID card.


3. Through which channels do we obtain the personal data of Service Users?
We may obtain the personal data of Service Users from the following sources:

1. Received directly from the Service User, whereby the Service User may register to use the service, enter into a contract, or submit various documents or provide relevant information through the application or other forms that we may prescribe to request the Service User's information, as well as when the Service User participates in marketing activities, events, or other activities that we organize, including the process by which the Service User submits a request to exercise various rights with us, or when the Service User communicates, inquires about information, handles the resolution of complaints and usage problems, gives opinions, or provides feedback, whether in written or oral form, through the website, application, video call, telephone, email, post, in-person meetings, or by any other method.

2. Information obtained while the Service User visits the Company's website, or while the Service User uses the Company's services, which is personal data that we collect and gather from the Service User automatically through various channels, such as the use of cookies or other similar technologies. For further details, see the Cookies Policy.

3. We may obtain the personal data of Service Users from third parties, such as organizations or any other agencies that have the right and duty to disclose information, or we may obtain it from online social media channels, third-party online platforms, including the business partners specified in clause 5.1.

In this regard, in the event that the Service User provides us with the personal data of another person, we shall deem that the Service User represents and warrants that the Service User has the lawful right under the Personal Data Protection Act B.E. 2562 ("Personal Data Protection Act") to forward and disclose the data of each such other person for us to process under the conditions specified in this Policy.

4. For what purposes do we use the personal data of Service Users?
We will process the personal data necessary for our operations, for the following purposes:

#Specified PurposeLegal Basis
1To send information on discounts, promotions, news, and information related to education, and to carry out marketing activities, such as sending messages, public relations, promotions, and marketing activities via email, SMS, and Line account.Basis of consent
2To make contact by telephone or through channels permitted by the Service User, and to recommend suitable services or services that the Service User may be interested in, in order to make targeted advertising based on the Service User's behavior.Basis of consent
3To analyze, conduct research, and compile statistics regarding the behavior of Service Users from their use of the website, application, or other channels for the purpose of development and improvement. This does not include cases covered by purpose No. 6 below.Basis of consent
4For the purpose of complying with laws, rules, and regulations, both domestic and foreign, that are applicable and relevant to our business, finance, and accounting, including compliance with the lawful orders of government agencies and relevant officials, and persons with legal authority, such as court orders, regulatory agencies, or authorized competent officials.Basis of compliance with the law
5To perform our duties under the terms of service, in accordance with the conditions specified in the Terms of Service that we have announced, which include but are not limited to (a) verifying the identity and rights of each individual Service User, by reference to the Service User's account, in order to verify accuracy and to use for confirming or identifying the Service User before using the service; (b) carrying out service fee payment transactions; (c) providing other support services as the Service User may request us to perform, including but not limited to coordinating the use of our application services. In this regard, it is necessary for us to process and collect the personal data of the Service User for such purposes for as long as the Service User still maintains a user account on the application.Basis of contract performance
6For the legitimate interest in managing and developing the Company's business, without unduly affecting the rights of the Service User, the Company needs to process personal data for: Development and improvement of services: - analyzing usage patterns in statistical and anonymized form - developing new features and improving service quality - determining the service structure and appropriate service fee rates - analyzing usage trends for service development planning. Business management: - handling complaints and settling disputes - preparing statistical reports for management and marketing - auditing, controlling, and managing risk - preparing models and analyzing the Portfolio. Protection of legal rights: - enforcing legal and contractual rights - conducting relevant legal proceedings - internal governance and internal audit.Basis of legitimate interest
7To notify of any other news and information relating to the provision of the same type of service that the Service User has with us, which is beneficial to the Service User.Basis of legitimate interest
8To manage orders, deliver, track, ship, exchange, and prepare products and services, notify of benefits that the Service User receives, including managing matters related to the performance of the contract, which, if not carried out, would affect our provision of services or would render us unable to provide services fairly and continuously.Basis of contract performance/
basis of legitimate interest
9To complete transactions, debit accounts, and verify the accuracy of account numbers and credit or debit card numbers, and transactions relating to payments, refunds, and the issuance of receipts, invoices, and tax invoices in accordance with the Revenue Code and any other relevant laws or notifications.Basis of contract performance/
basis of compliance with the law
10Receiving complaints, receiving suggestions, communicating, conducting questionnaires, surveying opinions regarding products and services, carrying out orders and requests, including managing the relationship, such as customer care, satisfaction assessment, providing consultation, providing clarification, and answering queries.Basis of contract performance/
basis of legitimate interest
11For the purpose of establishing legal claims, complying with or exercising legal claims, or defending against legal claims of ours, at various stages under the law, such as investigation, inquiry by state officials, case preparation, litigation, and/or court proceedings, and the like.Basis of legitimate interest
12For collecting payments or outstanding debts, entering into transactions, carrying out the receipt of payments, handling claims and disputes, including dispute resolution proceedings, establishing legal claims, exercising rights, or contesting legal claims, conducting various legal proceedings, as well as taking action to enforce judgments in accordance with the law.Basis of contract performance/
basis of legitimate interest
13To send service usage reminders when the contract period is nearing its end, to create and maintain user accounts, including processing, auditing service usage, and closing user accounts.Basis of contract performance
14For use in a sale, transfer, merger, or similar event, whereby we may disclose or transfer personal data to any one or more third parties involved in that transaction.Basis of legitimate interest
15To prevent security risks, such as monitoring network activity logs, identifying security incidents, conducting data security audits, and any other prevention against malicious, deceptive, fraudulent, or unlawful acts, troubleshooting, developing, providing, operating, testing, and maintaining information technology systems (IT systems).Basis of legitimate interest
16To enhance and develop our products and services, including the lawful use of data to train artificial intelligence systems. This training aims to improve the efficiency and quality of the services we provide to our customers.Basis of legitimate interest
17To audit, control, and manage the use of the service in accordance with the agreements, policies, and conditions specified, including preventing unauthorized use under the terms of service, and preventing inappropriate use or use beyond the specified scope.Basis of contract performance/
basis of legitimate interest
18To audit and report violations of the usage policy, including taking legal action if necessary.Basis of contract performance/
basis of legitimate interest


5. Do we disclose the personal data of Service Users?
In principle, the Company will keep the personal data of Service Users confidential. However, based on the specified purposes of processing personal data, the Company may need to disclose personal data from time to time to external parties, under the condition that the Company will disclose personal data only to the extent necessary. In disclosing the personal data of Service Users to other persons, we will put in place appropriate measures to protect personal data and to comply with the standards prescribed by personal data protection law. We will ensure that such persons keep the personal data secure and confidential and will not use it for purposes other than the scope we have specified. We may disclose the personal data of Service Users to the following persons or organizations:

1. Groups of business partners with whom we have mutual agreements. We will notify Service Users of the names of the groups of business partners in order to support their decision to give consent for the disclosure of data for marketing purposes, such as for sales promotion, public relations, or offering products and services to Service Users.

2. Service providers and personal data processors that provide services supporting our provision of services, whom we have assigned or engaged to manage or process personal data in providing various services, including those acting on behalf of the Company or jointly with the Company, in order to carry out the relevant purposes specified in this Notice, and who need to receive your personal data, which may include but is not limited to artificial intelligence (AI) system service providers, information technology system service providers, payment service providers, accounting providers, or consultants, for the business operations and functioning of the application or any other service of the Company, or relating to the Company's business operations, where it is reasonably necessary to disclose your personal data in order to achieve the Company's business purposes.

3. Government agencies that have a legal supervisory duty, or that request the disclosure of personal data by virtue of legal authority, or that are permitted under relevant laws.

4. Banks, service providers, government agencies, or any other organizations, subject to your consent.

6. Do we send or transfer the personal data of Service Users abroad?
We may need to send or transfer your personal data abroad for the purposes of providing services, processing data, storing data, supporting the provision of services, or using services from our external service providers, which may be located or have data processing systems abroad. Such destination countries may have personal data protection standards that differ from Thailand, including the United States, in cases where the Company uses certain types of automated processing technology or artificial intelligence service providers.

In sending or transferring personal data abroad, we will do so only to the extent necessary and will put in place appropriate personal data protection measures, such as contractual measures, data security measures, restriction of data access rights, and any other measures prescribed or permitted by personal data protection law, in order to ensure that your personal data is appropriately protected.

In the event that sending or transferring personal data abroad cannot be carried out on the basis of the criteria or protective measures prescribed by law, we will obtain your consent prior to such sending or transfer of personal data, unless it is a case where the law prescribes or permits it to be carried out without obtaining consent.

7. How long do we retain the personal data of Service Users?
We will retain the personal data of Service Users for the period necessary to achieve the specified purposes of processing that personal data. The retention period of personal data will depend on the specified purposes of processing the personal data, as follows:

1. In the case where we obtain data from registration or membership sign-up, we will retain the Service User's data for as long as necessary to provide services to the Service User, and for as long as the Service User remains a member, and will continue to retain it for a further 5 (five) years following the year in which the membership status ends or the relationship ends.

2. In the case of a request to exercise the rights specified in this Notice, we will retain evidence of the history of exercising rights under the personal data protection law for 1 (one) month following the month in which the Company completes its consideration of the request.

3. In the case where you sign up to use the KCC+ Connection Service or other similar services, we will retain evidence of your consent to use the service and to send your personal data to the bank service provider for a period of 10 (ten) years from the date on which your membership status ends or your relationship with us ends, or from the date on which you have withdrawn such consent, whichever event occurs first.

4. In other cases, we will retain the personal data of Service Users for as long as reasonably necessary to achieve the purposes specified in this Notice. In this regard, in the event that the retention period of personal data cannot be clearly determined, we will retain the data for the period that can be anticipated in accordance with the standard of collection (for example, the maximum civil prescription period under the law of 10 years). In this regard, if there are court proceedings, the personal data of Service Users may be retained until the end of such proceedings, including any period of time in carrying out the actions necessary to achieve the purpose, after which the Service User's data will be deleted or retained as permitted by law.

4.1 In the case of device usage data for the Single User per Account device policy

  • Device ID data: retained throughout the period of service use, and for 2 years after the end of the provision of service.
  • Login logs and Session data: retained for 1 year from the date of collection.
  • Data on policy violations and appeal data: retained for 3 years as evidence and to prevent repeat violations.

Upon the expiration of the specified period, we will delete, destroy, or render such personal data unable to identify the person who is the owner of the personal data, or take any other action as prescribed by the law on personal data protection, in order to make the protection of personal data effective. However, we may retain certain data for longer than specified above if it is necessary to comply with the law, or for an audit relating to copyright matters, or to comply with the orders of competent officials or state agencies having relevant authority, and for business purposes or purposes lawful under the law, such as for security, for the prevention of infringement or misconduct, or for the keeping of financial records, and the like.

8. How do we keep the personal data of Service Users secure?
In order to maintain the security of the personal data of Service Users, we establish a data control policy and a policy to maintain the confidentiality, accuracy, and availability of all personal data that we may need to process, by specifying and restricting the rights to access personal data, to disclose, and to carry out actions concerning personal data only to the extent necessary. We also establish additional measures to maintain the security of the system and personal data, in order to protect all personal data from destruction or intrusion by malicious persons or persons who do not have the right to access the data, by using advanced data security standards in accordance with industry standards, and by requiring the website to have SSL encryption for security in transmitting data between the website and the database system. The Company also requires regular auditing and risk assessment of the security of the operating systems, which is consistent with the information security policies and practices and the Privacy Policy.

9. How do we handle the personal data of third parties?
In the event that the Service User provides us with the personal data of another person who is not the Service User, we shall deem that the Service User represents and warrants that the Service User has the lawful right under the Personal Data Protection Act to forward and disclose the data of such person for us to process under the conditions specified in this Policy. In this regard, such person has the rights as a data subject as specified above.

10. What rights do Service Users have under the personal data protection law?
We respect the legal rights of Service Users as data subjects over such personal data that is under our control. Therefore, we allow data subjects to exercise various rights under the provisions of the law. Such rights are as follows:

(1) Right to withdraw consent: If the Service User has given consent to the processing of personal data (whether the consent was given by the Service User before or after the effective date of the personal data protection law), the Service User has the right to withdraw consent at any time throughout the period that the Service User's personal data is with us. The withdrawal of consent does not affect the processing of personal data to which the Service User has lawfully given consent, unless there is a restriction of that right by law, or the consent cannot by its nature be withdrawn, or there is a contract between the Service User and us that provides a benefit to the Service User, or it may result in our being unable to carry out some or all of the purposes specified in this document.

In this regard, the withdrawal of the Service User's consent may affect the Service User in relation to the use of various services; for example, the Service User will not receive benefits, promotions, or new offers, will not receive services that meet the Service User's needs, or will not receive beneficial news and information, and the like. For the benefit of the Service User, the Service User should therefore study and inquire about the effects before exercising the right to withdraw consent.

(2) Right to access personal data: The Service User has the right to request access to the Service User's personal data that is under our responsibility, and to request that we make a copy of such data for the Service User, including requesting that we disclose how we obtained the Service User's personal data, except in cases where we have the legal right to refuse the Service User's request, or by court order, or in cases where the Service User's request would have an effect that may cause harm to the rights and freedoms of other persons.

(3) Right to data portability: The Service User has the right to request the transfer of the Service User's personal data in the case where we have made such personal data available in a format that can be read or used by automated tools or devices, and that can be used or disclosed by automated means. The Service User also has the right to request that we send or transfer personal data in such format to another data controller where it can be done by automated means, and has the right to obtain personal data directly from another data controller to whom we send or transfer personal data in such format, except where it cannot be done for technical reasons.

(4) Right to object: The Service User has the right to object to the processing of the Service User's personal data at any time, if the processing of the Service User's personal data is carried out for necessary operations under our legitimate interests, or those of another person or juristic person, without exceeding the scope that the Service User can reasonably anticipate, or in order to carry out a task for public interest, or for marketing purposes, or for the purpose of scientific, historical, or statistical research.

If the Service User files an objection, we will continue to process the Service User's personal data only where we can demonstrate legal grounds that are more important than the fundamental rights of the Service User, or where it is for the establishment of legal claims, compliance with the law, or defense against legal claims, as the case may be.

(5) Right to request erasure or destruction of data: The Service User has the right to request the deletion or destruction of the Service User's personal data, or to render the personal data unable to identify the Service User, if the Service User believes that the Service User's personal data has been processed unlawfully under the relevant law, or considers that it is a case where we no longer have a need to retain it for the relevant purposes in this Notice, or when we consider that we can comply with the Service User's exercise of the right to withdraw consent or the right to object as notified above.

(6) Right to request restriction of use of data: The Service User has the right to request the temporary restriction of the use of personal data in the case where we are in the process of verifying, pursuant to the Service User's request to exercise the right to correct personal data or to object, or in any other case where we no longer have a need for it and must delete or destroy the Service User's personal data under the relevant law, but the Service User requests that we restrict the use of the personal data instead.

(7) Right to request correction of data: If the Service User considers that the Service User's personal data is not accurate as it truly is, the Service User may notify us to correct or change the Service User's personal data to be accurate, or to supplement the data so that it is current, complete, and does not give rise to misunderstanding.

In this regard, if the Service User wishes to request the correction of data concerning images, we will correct only the data items concerning the Service User's images so that they are accurate, in accordance with our lawful necessity. In the event that carrying out the request incurs expenses, we may charge such expenses. In the event that we have grounds to refuse the Service User's request, we will also prepare a record of the refusal of the request together with the reasons as evidence.

(8) Right to complain: The Service User has the right to complain to us through the website channel by selecting the Data Processing Complaint Form, or to complain to the Personal Data Protection Committee if the Service User believes that the processing of personal data or any action by the service provider is carried out in a manner that violates or fails to comply with the laws relating to personal data protection.

(9) Rights specific to device usage data: The Service User has the following specific rights:

  • to view the list of currently registered devices
  • to request to view usage history for the past 60 days
  • to request to correct inaccurate device data (once per year)
  • to file an appeal

11. How can Service Users exercise their rights under the personal data protection law?

1. In the event that the Service User wishes to withdraw the consent that the Service User has given, the Service User can fill in the Consent Withdrawal Request Form through our website channel; or in the event that the Service User wishes to exercise other rights as specified in clause 10, the Service User can fill in the Data Subject Rights Request Form through our website channel. We will consider and notify the result of the consideration of the Service User's request within 30 (thirty) days from the date we receive such request. However, we may refuse to exercise the Service User's rights under the conditions prescribed by law. In this regard, if we are unable to comply with the Service User's request, we will record the refusal of the request together with the reasons.

2. We will do our utmost, in accordance with the capabilities of the relevant systems, to facilitate and carry out the Service User's request, unless it appears as a matter of fact that carrying out the request risks infringing the rights and freedoms of other Service Users, or is contrary to the law or the security policy of the system, or in the case where it is impractical to carry out the request due to technical reasons.

3. In some situations, we may ask the Service User to prove the Service User's identity before exercising rights, for the Service User's own safety. Sometimes there may be certain limitations on the Service User's request to exercise rights, or expenses may be incurred, which we will clarify to the Service User if we are unable to comply with the Service User's request to exercise rights, or we will notify the Service User if we need to charge expenses relating to carrying out the actions requested by the Service User.

12. How can Service Users contact us for further information?
We have assigned our Data Protection Officer, Mr. Warodom Kasiolan, to be the coordinator regarding our personal data protection. In the event that the Service User considers that the processing of personal data is not in accordance with the Personal Data Protection Act B.E. 2562, or has any suggestions or doubts, or wishes to inquire about the details of the collection, use, and/or disclosure of personal data, including requesting to exercise rights under this Notice, the Service User can contact us to make inquiries or complaints through the following channels:

FlowAccount Co., Ltd.

141/12, 11th Floor, Unit 12B, Sakulthai Surawong Tower Condominium, Surawong Road, Suriyawong Sub-district, Bangrak District, Bangkok

Telephone: 02-026-8989

Data Protection Officer

For inquiries, or to make contact to request the exercise of various rights of the data subject, you can contact us directly via email at dpo@flowaccount.com

13. Will the Privacy Notice be amended or changed?
We reserve the right to amend and update this Notice from time to time, as appropriate for the processing of the personal data of Service Users, to be consistent with the Company's provision of services, as well as to be consistent with relevant laws. The Company will notify Service Users of any changes by communicating the updated Notice through the Company's various contact channels, with effect immediately upon announcement.

Currently, this Privacy Notice was last amended on 17 July 2026.