Personal Data Protection Policy (Privacy Policy)

FlowAccount Company Limited (“the Company”) is a provider of accounting software and online business management systems. In carrying out such operations, the Company may need to collect your personal data (“you”). The Company is responsible for maintaining the security of the personal data under its care and is committed to managing data in a secure, safe, and reliable manner.

In placing importance on your privacy and safety, the Company has therefore prepared this Personal Data Protection Policy (the “Policy”), which explains how the Company handles your personal data and sensitive personal data, such as the collection, storage, use, and disclosure thereof, including your various rights, which forms part of the terms of service.

The Company recommends that you read and understand this Policy before using the services. When you begin using the Company's services, in particular when you begin registering to sign up for use of the application or website, or when you communicate with the Company through the designated channels,

each time you use the services, you are deemed to have agreed to and accepted this Policy. If you refuse or do not accept this Policy, the Company reserves the right to refuse to provide various services to you.

1. Definitions
“Personal Data Protection Law” means the Personal Data Protection Act B.E. 2562 (2019) and its subordinate legislation, as well as the guidelines under such law.

“Personal Data” means information relating to a natural person which enables the identification of that person, whether directly or indirectly, but does not include information of deceased persons, information of legal entities, business contact information that does not identify a specific person, anonymous data, or pseudonymous data that can no longer be used to identify a specific person by technical means, and the like.

“Sensitive Personal Data” means data that is sensitive in nature and may pose a risk of unfair discrimination, such as race, ethnicity, political opinions, cult or religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, biometric data, or any other data which affects the data subject in a similar manner, as prescribed by the Personal Data Protection Committee.

“Technical Data” means data relating to the monitoring and maintenance of system security, including the enforcement of device policies.

“Technical Measures” means the technological methods used to monitor, prevent, and enforce the terms of service.

“Processing” means any operation performed on personal data, whether or not by automated means, such as collection, recording, organization, storage, alteration or adaptation, retrieval, consultation, use, disclosure (by transmission, transfer, dissemination, or making available or accessible by any means), alignment, combination, blocking or restriction, erasure, or destruction, and the like.

“Processing for Policy Enforcement” means the processing of personal data in order to comply with the terms of service.

“Data Controller” means a natural person or legal entity having the power and duty to make decisions regarding the collection, use, or disclosure of personal data.

“Data Processor” means a person or legal entity that carries out the collection, use, or disclosure of personal data according to the instructions of or on behalf of the data controller, where such person or legal entity is not the data controller.

“Cookies” means small computer files that temporarily store necessary personal data on the data subject's computer for convenience and speed of communication, which take effect only while the website system is being accessed.

“Data Protection Officer” means a person appointed by the Company to have duties under the Personal Data Protection Law.

“Device Usage Data” means data relating to the identification and verification of the device used to access the services, including the Device ID, IP Address, and other technical data.

“Processing for Security” means the processing of personal data to monitor and prevent unauthorized use in accordance with the Single User per Account device policy.

2. Categories of Data Subjects
The Company processes the personal data of the following data subjects. In this regard, the Company may establish a Privacy Notice for each category of data subject in order to provide the details of the processing to each category of data subject.

2.1 Customers/Service Users
(a) Persons who use the Company's services, who register to sign up for the services and/or sign up to use the Company's applications under the names FlowAccount, FlowPayroll, Autokey, and Mobile POS, including the Company's websites flowaccount.com, flowaccount.com/payroll, and flowaccount.com/autokey (“Applications”), and including related persons, representatives, or persons authorized to act on behalf of customers.
(b) General persons who have a legal relationship with or contact the Company, such as visitors to the Company's website, persons who contact the Company for support and coordination through the Call Centre, LINE Official Account, Facebook, and X, persons who contact the Company to request information, and persons who respond to surveys about the Company's services (all services collectively referred to as the “Services”).
(c) Persons who register for seminars, courses, or tests to pass our assessment criteria.

Please see the Privacy Notice for Customers and Service Recipients.

2.2 Business Partners

  • Natural persons who are representatives of legal entities, such as directors, authorized signatories, delegates, sub-delegates, operators, staff, and employees of legal entities that have entered into, will enter into, or are considering entering into various transactions with the Company.
  • Persons whose personal data appears in relevant documents, including persons who submit bids to sell goods and/or provide services to the Company, such as service providers, consultants, experts, academics, speakers, business project participants, contracting parties, or those having any other similar relationship with the Company.

2.3 Company Personnel

  • Employees or persons who work or perform any duties for the Company and receive a salary, wages, benefits, or remuneration from the Company, such as executives, managers, staff, personnel, or any other persons of a similar nature.
  • Persons related to the Company's personnel and persons who are data subjects whose personal data appears in various documents relating to the recruitment process, such as family members, father, mother, spouse, and children, persons who can be contacted in case of emergency, reference persons, and beneficiaries, and the like.

2.4 Job Applicants

  • Persons who have submitted a job application/internship application, or any other persons who have sent details of their personal profile to the Company for the purpose of applying for a job/internship as a permanent employee or a contract employee.
  • Employees under the employment of outsourced recruitment service providers/freelance employees/interns who have not yet been selected by the Company, and persons related to the applicant.
  • Persons whose personal data appears in various documents relating to the application, such as family members, reference persons, and persons who can be contacted in case of emergency, and the like.

2.5 Persons Photographed and/or Recorded

  • Male models, female models, presenters, and persons hired or compensated for photography.
  • Company personnel, award recipients, and persons who consent to the Company recording still images or moving images during interviews, training, courses, the atmosphere of events, or group photography.

2.6 Event Participants

  • Participants in the Company's various events or campaigns, or those organized by the Company, or registrants, attendees of training and seminars, including any other persons of a similar nature.

2.7 Visitors to the Company's Website or Application

The Company may use automated technology to collect personal data when you use the website or application via a computer or mobile device, namely the IP Address, the browser used, or the operating system, the web pages visited, and the referring website from which the visitor linked to the website. This automated technology may include the use of cookies or other similar technologies. Please see the Cookies Policy.


3. Privacy Protection
In order to comply with the laws governing personal data protection, the Company has issued a Privacy Notice specifying the collection of personal data, notifying the data subject of the details of the personal data collection electronically, by short message, or by any other method prescribed by the Company. The Company will notify the data subject before or at the time of collecting the personal data of at least the following details, unless the data subject already knows such details.

1. Identifying the categories of persons whose personal data the Company collects.

2. Explaining the purpose and method of collecting the data subject's personal data.

3. Specifying the personal data collected.

4. Specifying the legal basis the Company uses for the collection and processing of personal data.

5. Specifying the retention period of the personal data.

6. Specifying all the rights of the data subject.

7. Specifying how the data subject may exercise their rights, and the withdrawal of consent to the collection of personal data.

8. Specifying all the measures taken to protect the data subject's personal data.

9. Specifying the channels for contacting the data controller or the data protection officer, so that the data subject can make contact, ask further questions, or exercise their rights as a data subject.

10. Specifying the categories of external persons or organizations that may use the personal data, and including the destination countries that may receive the personal data.


4. Collection of Personal Data
In collecting personal data, the Company has established appropriate measures to maintain the security of your personal data, consistent with the maintenance of confidentiality, in order to prevent loss, unauthorized access, destruction, use, alteration, modification, or unlawful disclosure of data. The Company and third parties assigned by the Company will collect your personal data under the following conditions:

4.1 Collection of General Data
The Company will process the personal data you have provided by limiting access rights and using lawful and fair methods in collecting personal data, and will process it only under the purposes specified by the Company. In this regard, before undertaking such action, the Company will notify the data subject of the purpose of such processing electronically, by short message, or by the Company's method, including requesting your consent in cases where the law requires such consent to be obtained.

4.2 Exceptions to Consent
The Company will process personal data only as necessary under the lawful purposes notified to the data subject before or at the time of collecting the personal data, and the Company will obtain explicit consent from the data subject, except in the following cases where the Company may collect personal data without obtaining consent:

  • To achieve the purpose of preparing historical documents or archives for the public interest, or in relation to research or statistics, where the Company will provide appropriate safeguards to protect the rights and freedoms of the data subject.
  • To prevent or suppress danger to the life, body, or health of a person.
  • It is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract.
  • It is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Company.
  • It is necessary for the legitimate interests of the Company or of another person or legal entity, unless such interests are overridden by the fundamental rights of the data subject in their personal data.
  • To comply with the law.

4.3 Sensitive Personal Data
For the collection of sensitive personal data, the Company must obtain explicit consent from the data subject before or at the time of collecting such sensitive personal data, in accordance with the criteria prescribed by the Company that are not contrary to law. The Company may collect sensitive personal data to provide certain forms of services when explicit consent has been obtained from you, when you voluntarily disclose the data to the public, or where it is a case prescribed by the personal data protection law, by relying on at least one of the lawful bases prescribed under the personal data protection law, as follows:

  • It is carried out with the explicit consent of the data subject.
  • To prevent or suppress danger to the life, body, or health of a person, where the data subject is incapable of giving consent.
  • For the lawful activities of a foundation, association, or non-profit organization with political, religious, philosophical, or trade union objectives, with appropriate safeguards.
  • It is data disclosed to the public with the explicit consent of the data subject.
  • It is necessary for the establishment of legal claims, compliance with or the exercise of legal claims, or the raising of a defense against legal claims.
  • It is necessary for compliance with the law to achieve the purposes of preventive or occupational medicine, the assessment of the working capacity of employees, public health interests, labor protection, social security, national health security, benefits relating to medical treatment, scientific, historical, or statistical research, or other substantial public interest.

4.4 Collection of Data for Maintaining Usage Security and Policy Enforcement
The Company will collect the technical data necessary to:

  • Maintain the security of systems and data.
  • Prevent unauthorized use.
  • Enforce the policy and terms of service.
  • Maintain fairness in providing services to all users.
Such data covers data identifying the specific characteristics of the device, usage patterns, and system access behavior, with details as specified in the relevant Privacy Notice.

4.5 Related Additional Policies or Notices
In the event that the Company will process your personal data in a manner and/or for a purpose that is not consistent with the specified purposes, the Company will provide additional policies or notices regarding personal data protection, and/or will send a letter to you to explain the processing of data in such manner. You should read the related additional policies or notices together with this Policy, and/or such letter (as the case may be).

5. Artificial Intelligence - Use of Data
The Company may use technology to assist with automated processing, including artificial intelligence (AI), to help read, extract, transform, verify, analyze, search, and summarize data from documents or data that customers import into the system, such as receipts, invoices, tax invoices, bank statements, and other types of financial documents. This is to increase the correctness and accuracy of the data, reduce errors that may arise from human processing, and help make the use of the system, including searching for data in various languages and summarizing data, more efficient.

The Company may use personal data and data that customers import into the system to develop and improve the Company's own artificial intelligence capabilities, including the development of models, algorithms, and various automated processing functions of the system, in order to develop and improve artificial intelligence capabilities to provide more efficient and accurate services to customers, to the extent that such action can be carried out under the personal data protection law, as specified in the Privacy Notice.

In addition, the Company may offer certain types of services that allow customers to choose to use functions that connect with external artificial intelligence service providers, where the connection will be carried out only as necessary in accordance with the Least Privilege Principle and the Know-to-know basis. However, the retention of data, the use of data for training or developing models, and other requirements of the external artificial intelligence service providers will be governed by the policies and terms of the relevant external service providers. You therefore have a duty to study and understand the policies of the external service providers before choosing to use such services.

The Company does not sell or trade customers' personal data, and will not disclose personal data to third parties other than as specified in this Policy.

If you have any questions or concerns regarding the use of artificial intelligence technology, please contact the Company using the details specified in Section 13 of this Policy.

6. Use and Disclosure of Personal Data
6.1 Limitations on the Use of Data
The Company will use personal data only for the purposes notified to the data subject. In any case where the Company wishes to collect, use, or disclose additional personal data, or where there is a change in the purpose of collection, use, or disclosure, the Company will notify the data subject before taking action on such personal data, unless it is a case where the law requires or permits such action.

6.2 Service Providers
The Company will use personal data appropriately, and in the event that the Company uses the information services of a third-party service provider, the Company will provide for the maintenance of security and the control of access to, use of, and disclosure of personal data. The Company will oversee its employees, service providers, officers, or operators to ensure that they do not use or disclose your personal data beyond the purposes of the personal data collection specified by the Company, or disclose it to third parties.

6.3 Disclosure of Data to Business Partners
The Company may disclose your personal data that the Company currently stores and will store in the future to partners, business partners, or other persons or legal entities within the scope of a mutual agreement, and that you can reasonably expect.

6.4 Use of Data for Management and Policy Enforcement
6.4.1 Scope of Data Use
The Company will use personal data for system management and policy enforcement. The use of data will be limited only to the parts necessary for:

  • Monitoring compliance with the terms of service.
  • Preventing and resolving usage problems.
  • Maintaining the quality and stability of the services.
  • Creating fairness among service users.

7. Principles of Personal Data Processing
7.1 Accountability

The Company will process personal data, both in its capacity as a data controller and as a data processor, lawfully, fairly, and transparently, taking into account the accuracy of the personal data. In this regard, the determination of the scope of the purposes of personal data processing and the retention period of personal data shall be carried out only as necessary under the lawful purposes and the Company's business operation guidelines.

7.2 Procedures and Controls

The Company will provide procedures and controls to manage personal data at every stage in a manner consistent with the law and the Company's Personal Data Protection Policy.

7.3 Records of Processing Activities (ROPA)

The Company will prepare and maintain Records of Processing Activities (ROPA) to record the lists and various activities relating to the processing of personal data in accordance with the law, and will update the records of processing activities when there is a change in the relevant lists or activities.

7.4 Transparency and Consent

The Company will provide a clear process to ensure that the notification of the purposes of collection and the details of personal data processing (Privacy Notices), and the obtaining of consent from data subjects, are consistent with the law, and will provide measures to oversee and monitor such matters.

7.5 Access Control

The Company provides guidelines for permitting access to personal data only for persons who need to know and access the personal data, in order to enable the Company to perform its duties under the contract with you, or only within the scope of the services. In the event that the Company is a data processor, the Company will process personal data according to written instructions as specified in the contract, and only within the scope of its duties with the data controller, and will comply with the personal data protection law with respect to the duties of a data processor.

7.6 Data Sharing Agreements

In the event that the Company sends, transfers, or allows another person to use personal data, the Company will prepare an agreement regarding the use of such personal data to define the rights and duties in a manner consistent with the law and the Company's Personal Data Protection Policy.

7.7 Cross-Border Data Transfers

The Company may need to send or transfer your personal data to foreign countries for the purposes of providing services, processing data, storing data, supporting the provision of services, or using services from the Company's external service providers, which may be located or have data processing systems in foreign countries. Such destination countries may have personal data protection standards that differ from Thailand, including the United States of America, in cases where the Company uses certain types of automated processing technology or artificial intelligence service providers.

In sending or transferring personal data to foreign countries, the Company will act only as necessary and will provide appropriate personal data protection measures, such as contractual measures, data security measures, restriction of data access rights, and any other measures as required or permitted by the personal data protection law, in order to ensure that your personal data is appropriately protected.

In the event that the sending or transfer of personal data to foreign countries cannot be carried out on the basis of the criteria or protection measures prescribed by law, the Company will obtain consent from you before sending or transferring such personal data, unless it is a case where the law requires or permits such action without obtaining consent.

7.8 Data Retention and Destruction

The Company will destroy personal data upon the expiration of the retention period, acting in a manner consistent with the law and the Company's business operation guidelines.

7.9 Risk Management

The Company will assess risks and establish measures to mitigate risks and reduce the impact that will arise on the processing of personal data.

7.10 Continuous Improvement

The Company will provide for the regular review and improvement of policies, standards, guidelines, procedures, and other documents relating to personal data protection, in order to keep them up to date and consistent with the law and the circumstances at each period of time.

8. Retention Period of Personal Data
The Company will retain the data subject's data according to the type of activity and the purpose of the personal data processing, as specified in the Privacy Notice on the Company's website.

After the expiration of the aforementioned period, the Company will delete or destroy such personal data from storage in the Company's systems and those of other persons who provide services to the Company (if any), or will render the data subject's personal data unable to identify the data subject, or will take any other action as prescribed by the personal data protection law, in order to make the protection of personal data effective, except where it is a case in which the Company can continue to retain such personal data as prescribed by the personal data protection law or other relevant laws.

  • The Company may retain the data subject's personal data for a period longer than the aforementioned period if permitted by law; or
  • The retention of such personal data is necessary for compliance with the law, or is in compliance with an order of a competent official or relevant government agency; or
  • The retention of such personal data is necessary for the establishment of the Company's legal claims and for business purposes or as lawful.

9. Rights of the Data Subject
The Company grants the data subject the rights prescribed by the personal data protection law, as follows:

9.1 Right to Withdraw Consent

The right to withdraw consent to the processing of personal data throughout the period during which the personal data remains with the Company.

9.2 Right to Access and Obtain a Copy

The right to request access to and obtain a copy of the personal data, and the right to request the disclosure of the acquisition of the personal data.

9.3 Right to Data Portability

The right to obtain personal data in a format that is generally readable or usable, including the right to request that such data be sent or transferred to another data controller.

9.4 Right to Object

The right to object to the processing of personal data at any time.

9.5 Right to Erasure

The right to request that the Company delete, destroy, or render the personal data unable to identify the person who is the data subject.

9.6 Right to Restriction of Processing

The right to request that the Company suspend the use of personal data.

9.7 Right to Rectification

The right to request that the Company take action to ensure that the personal data is accurate, up to date, complete, and not misleading.

9.8 Right to Lodge a Complaint

The right to lodge a complaint in the event that the Company, its employees, or its contractors violate or fail to comply with the personal data protection law, through the Data Processing Complaint Form, or to the Personal Data Protection Committee.

In this regard, the Company respects your privacy and provides you with the opportunity to choose the method of control, or the method by which the Company contacts you, and the Company will comply with what you have requested, in order to help ensure transparency and the quality and accuracy of the data. Any request to exercise your rights as prescribed by law must be made in writing through the electronic system that the Company has provided on the Company's website.


10. Security for Personal Data

The Company recognizes the importance of maintaining the security of your personal data. The Company therefore establishes appropriate measures to prevent loss, unauthorized access, destruction, use, alteration, modification, or unlawful disclosure of personal data, including establishing policies, regulations, guidelines, and various procedures as follows:

10.1 Establishing Policies and Operating Procedures

Establishing clear policies and operating procedures to protect personal data and to manage data securely in accordance with the law.

10.2 Commitment to Data Privacy

Not selling or trading your personal data under any circumstances, and not transferring your personal data to other persons who are not the Company's data processors.

10.3 Access Control

Limiting the rights of the Company's employees to access personal data, and specifying the rights to access or use the personal data of data subjects, in order to maintain the confidentiality and security of the data.

10.4 Technical Protection Measures

Preventing unauthorized access and use of personal data by providing data encryption, identity verification, and virus detection technology, as necessary.

10.5 Security Governing Third Parties

Conducting due diligence on the Company's business partners, requiring business partners that do business with the Company to comply with the criteria under the laws and various regulations on personal data protection, and specifying restrictions on the use of personal data.

10.6 Website Monitoring

Monitoring the Company's website through agencies with expertise in personal data protection and security.

10.7 Employee Training

Requiring the Company's employees to undergo training on personal data protection and data security.

10.8 Regular Audits

Evaluating the guidelines on personal data protection, data management, and the maintenance of appropriate technical, physical, and administrative data security, including reviewing security measures when necessary or when technology changes.

10.9 Data Deletion Process

Providing an audit system to carry out the deletion or destruction of personal data upon the expiration of the retention period, or where it is irrelevant or beyond what is necessary for the purpose of collecting that personal data.

10.10 Data Breach Reporting

Providing a system for notifying the Office of the Personal Data Protection Committee of personal data breaches within 72 (seventy-two) hours from becoming aware of the incident, to the extent that it can be done, unless such breach does not pose a risk of affecting the rights and freedoms of persons.


11. Links to Third-Party Websites and Services

11.1 Third-Party Websites and User Data

The Company's website and applications may contain links to third-party applications and websites, which those third parties may use to collect certain data about the use of services and personal data. The Company cannot be responsible for the security or privacy of any data collected by such third-party applications and websites.

Data subjects should exercise caution and carefully review the personal data protection policies of those third-party applications and websites before using such third-party applications and websites, as follows:

  • When exporting such data, you may be disclosing user data to other persons or other organizations responsible for the operation and maintenance of the third-party applications and/or websites.
  • Other persons who view or use those applications and websites may be able to access your data.
  • The Company does not own or manage the applications and websites you connect to. The Company therefore recommends that you exercise caution regarding the disclosure of personal data in this manner.
  • You should review the privacy policy of that application and website to ensure that users are satisfied with the way those applications and websites use the data you provide to them.

11.2 Exporting User Data to Other Persons or Organizations

The Company provides you with the option to export data to third-party applications and websites, including social network websites. When you do this, you may be disclosing your data to other persons or other organizations.

  • The Company does not own or control third-party applications and websites.
  • The Company therefore recommends that data subjects exercise caution in disclosing personal data when using those features.
  • Please review the privacy policies of these third-party applications and websites to ensure that you are satisfied with the way those websites use the data you provide to them.

11.3 Data Analytics

The Company uses services for data analytics, such as Google Analytics and Growthbook, for the purpose of developing and improving the experience of using the platform, such as browsing data, device data, country of residence, and your approximate location.

  • The Company uses this data to improve the platform and deliver advertisements that match your interests.
  • The Company does not disclose such data to any other person outside of internal use within the Company.

Opting Out of Data Analytics Services If you do not want Google Analytics to be able to access your usage data, you can choose to disable the recording of usage through Google's tool at https://marketingplatform.google.com/about/analytics/

Learn More About Growthbook You can find further details about Growthbook on the website https://www.growthbook.io/legal/privacy-policy/01-01-2020

12. Use of Personal Data for the Original Purpose
In the event that the Company collected your personal data before the date on which the personal data protection law relating to the collection, use, or disclosure of personal data came into force, the Company will continue to collect and use your personal data for the original purpose. You have the right to withdraw your consent at any time by contacting the Company through filling in the Consent Withdrawal Request Form.


13. Contact Channels
The Company has assigned Mr. Warodom Kasiolarn as the coordinator regarding the Company's personal data protection. In the event that the data subject has any questions or wishes to exercise the rights specified in this Policy, they may do so through the following channels:

Data Protection Officer

  • Email: dpo@flowaccount.com
  • Address: 141/12 Floor 11, Unit 12B, Sakulthai Surawong Tower Condominium, Surawong Road, Suriyawong Subdistrict, Bang Rak District, Bangkok

14. Review of the Policy
The Company may improve, change, or amend this privacy policy from time to time in order to comply with the criteria prescribed by law. The Company will announce and notify you of the changes through the channels of the Company's website and/or platform.

Currently, the Personal Data Protection Policy was last reviewed on 17 July 2026.