FlowAccount Company Limited (âthe Companyâ) is a provider of accounting software and online business management systems. In carrying out such operations, the Company may need to collect your personal data (âyouâ). The Company is responsible for maintaining the security of the personal data under its care and is committed to managing data in a secure, safe, and reliable manner.
In placing importance on your privacy and safety, the Company has therefore prepared this Personal Data Protection Policy (the âPolicyâ), which explains how the Company handles your personal data and sensitive personal data, such as the collection, storage, use, and disclosure thereof, including your various rights, which forms part of the terms of service.
The Company recommends that you read and understand this Policy before using the services. When you begin using the Company's services, in particular when you begin registering to sign up for use of the application or website, or when you communicate with the Company through the designated channels,
each time you use the services, you are deemed to have agreed to and accepted this Policy. If you refuse or do not accept this Policy, the Company reserves the right to refuse to provide various services to you.
1. Definitions
âPersonal Data Protection Lawâ means the Personal Data Protection Act B.E. 2562 (2019) and its subordinate legislation, as well as the guidelines under such law.
âPersonal Dataâ means information relating to a natural person which enables the identification of that person, whether directly or indirectly, but does not include information of deceased persons, information of legal entities, business contact information that does not identify a specific person, anonymous data, or pseudonymous data that can no longer be used to identify a specific person by technical means, and the like.
âSensitive Personal Dataâ means data that is sensitive in nature and may pose a risk of unfair discrimination, such as race, ethnicity, political opinions, cult or religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, biometric data, or any other data which affects the data subject in a similar manner, as prescribed by the Personal Data Protection Committee.
âTechnical Dataâ means data relating to the monitoring and maintenance of system security, including the enforcement of device policies.
âTechnical Measuresâ means the technological methods used to monitor, prevent, and enforce the terms of service.
âProcessingâ means any operation performed on personal data, whether or not by automated means, such as collection, recording, organization, storage, alteration or adaptation, retrieval, consultation, use, disclosure (by transmission, transfer, dissemination, or making available or accessible by any means), alignment, combination, blocking or restriction, erasure, or destruction, and the like.
âProcessing for Policy Enforcementâ means the processing of personal data in order to comply with the terms of service.
âData Controllerâ means a natural person or legal entity having the power and duty to make decisions regarding the collection, use, or disclosure of personal data.
âData Processorâ means a person or legal entity that carries out the collection, use, or disclosure of personal data according to the instructions of or on behalf of the data controller, where such person or legal entity is not the data controller.
âCookiesâ means small computer files that temporarily store necessary personal data on the data subject's computer for convenience and speed of communication, which take effect only while the website system is being accessed.
âData Protection Officerâ means a person appointed by the Company to have duties under the Personal Data Protection Law.
âDevice Usage Dataâ means data relating to the identification and verification of the device used to access the services, including the Device ID, IP Address, and other technical data.
âProcessing for Securityâ means the processing of personal data to monitor and prevent unauthorized use in accordance with the Single User per Account device policy.
2. Categories of Data Subjects
The Company processes the personal data of the following data subjects. In this regard, the Company may establish a Privacy Notice for each category of data subject in order to provide the details of the processing to each category of data subject.
2.1 Customers/Service Users
(a) Persons who use the Company's services, who register to sign up for the services and/or sign up to use the Company's applications under the names FlowAccount, FlowPayroll, Autokey, and Mobile POS, including the Company's websites flowaccount.com, flowaccount.com/payroll, and flowaccount.com/autokey (âApplicationsâ), and including related persons, representatives, or persons authorized to act on behalf of customers.
(b) General persons who have a legal relationship with or contact the Company, such as visitors to the Company's website, persons who contact the Company for support and coordination through the Call Centre, LINE Official Account, Facebook, and X, persons who contact the Company to request information, and persons who respond to surveys about the Company's services (all services collectively referred to as the âServicesâ).
(c) Persons who register for seminars, courses, or tests to pass our assessment criteria.
Please see the Privacy Notice for Customers and Service Recipients.
2.2 Business Partners
2.3 Company Personnel
2.4 Job Applicants
2.5 Persons Photographed and/or Recorded
2.6 Event Participants
2.7 Visitors to the Company's Website or Application
The Company may use automated technology to collect personal data when you use the website or application via a computer or mobile device, namely the IP Address, the browser used, or the operating system, the web pages visited, and the referring website from which the visitor linked to the website. This automated technology may include the use of cookies or other similar technologies. Please see the Cookies Policy.
3. Privacy Protection
In order to comply with the laws governing personal data protection, the Company has issued a Privacy Notice specifying the collection of personal data, notifying the data subject of the details of the personal data collection electronically, by short message, or by any other method prescribed by the Company. The Company will notify the data subject before or at the time of collecting the personal data of at least the following details, unless the data subject already knows such details.
1. Identifying the categories of persons whose personal data the Company collects.
2. Explaining the purpose and method of collecting the data subject's personal data.
3. Specifying the personal data collected.
4. Specifying the legal basis the Company uses for the collection and processing of personal data.
5. Specifying the retention period of the personal data.
6. Specifying all the rights of the data subject.
7. Specifying how the data subject may exercise their rights, and the withdrawal of consent to the collection of personal data.
8. Specifying all the measures taken to protect the data subject's personal data.
9. Specifying the channels for contacting the data controller or the data protection officer, so that the data subject can make contact, ask further questions, or exercise their rights as a data subject.
10. Specifying the categories of external persons or organizations that may use the personal data, and including the destination countries that may receive the personal data.
4. Collection of Personal Data
In collecting personal data, the Company has established appropriate measures to maintain the security of your personal data, consistent with the maintenance of confidentiality, in order to prevent loss, unauthorized access, destruction, use, alteration, modification, or unlawful disclosure of data. The Company and third parties assigned by the Company will collect your personal data under the following conditions:
4.1 Collection of General Data
The Company will process the personal data you have provided by limiting access rights and using lawful and fair methods in collecting personal data, and will process it only under the purposes specified by the Company. In this regard, before undertaking such action, the Company will notify the data subject of the purpose of such processing electronically, by short message, or by the Company's method, including requesting your consent in cases where the law requires such consent to be obtained.
4.2 Exceptions to Consent
The Company will process personal data only as necessary under the lawful purposes notified to the data subject before or at the time of collecting the personal data, and the Company will obtain explicit consent from the data subject, except in the following cases where the Company may collect personal data without obtaining consent:
4.3 Sensitive Personal Data
For the collection of sensitive personal data, the Company must obtain explicit consent from the data subject before or at the time of collecting such sensitive personal data, in accordance with the criteria prescribed by the Company that are not contrary to law. The Company may collect sensitive personal data to provide certain forms of services when explicit consent has been obtained from you, when you voluntarily disclose the data to the public, or where it is a case prescribed by the personal data protection law, by relying on at least one of the lawful bases prescribed under the personal data protection law, as follows:
4.4 Collection of Data for Maintaining Usage Security and Policy Enforcement
The Company will collect the technical data necessary to:
4.5 Related Additional Policies or Notices
In the event that the Company will process your personal data in a manner and/or for a purpose that is not consistent with the specified purposes, the Company will provide additional policies or notices regarding personal data protection, and/or will send a letter to you to explain the processing of data in such manner. You should read the related additional policies or notices together with this Policy, and/or such letter (as the case may be).
5. Artificial Intelligence - Use of Data
The Company may use technology to assist with automated processing, including artificial intelligence (AI), to help read, extract, transform, verify, analyze, search, and summarize data from documents or data that customers import into the system, such as receipts, invoices, tax invoices, bank statements, and other types of financial documents. This is to increase the correctness and accuracy of the data, reduce errors that may arise from human processing, and help make the use of the system, including searching for data in various languages and summarizing data, more efficient.
The Company may use personal data and data that customers import into the system to develop and improve the Company's own artificial intelligence capabilities, including the development of models, algorithms, and various automated processing functions of the system, in order to develop and improve artificial intelligence capabilities to provide more efficient and accurate services to customers, to the extent that such action can be carried out under the personal data protection law, as specified in the Privacy Notice.
In addition, the Company may offer certain types of services that allow customers to choose to use functions that connect with external artificial intelligence service providers, where the connection will be carried out only as necessary in accordance with the Least Privilege Principle and the Know-to-know basis. However, the retention of data, the use of data for training or developing models, and other requirements of the external artificial intelligence service providers will be governed by the policies and terms of the relevant external service providers. You therefore have a duty to study and understand the policies of the external service providers before choosing to use such services.
The Company does not sell or trade customers' personal data, and will not disclose personal data to third parties other than as specified in this Policy.
If you have any questions or concerns regarding the use of artificial intelligence technology, please contact the Company using the details specified in Section 13 of this Policy.
6. Use and Disclosure of Personal Data
6.1 Limitations on the Use of Data
The Company will use personal data only for the purposes notified to the data subject. In any case where the Company wishes to collect, use, or disclose additional personal data, or where there is a change in the purpose of collection, use, or disclosure, the Company will notify the data subject before taking action on such personal data, unless it is a case where the law requires or permits such action.
6.2 Service Providers
The Company will use personal data appropriately, and in the event that the Company uses the information services of a third-party service provider, the Company will provide for the maintenance of security and the control of access to, use of, and disclosure of personal data. The Company will oversee its employees, service providers, officers, or operators to ensure that they do not use or disclose your personal data beyond the purposes of the personal data collection specified by the Company, or disclose it to third parties.
6.3 Disclosure of Data to Business Partners
The Company may disclose your personal data that the Company currently stores and will store in the future to partners, business partners, or other persons or legal entities within the scope of a mutual agreement, and that you can reasonably expect.
6.4 Use of Data for Management and Policy Enforcement
6.4.1 Scope of Data Use
The Company will use personal data for system management and policy enforcement. The use of data will be limited only to the parts necessary for:
7. Principles of Personal Data Processing
7.1 Accountability
The Company will process personal data, both in its capacity as a data controller and as a data processor, lawfully, fairly, and transparently, taking into account the accuracy of the personal data. In this regard, the determination of the scope of the purposes of personal data processing and the retention period of personal data shall be carried out only as necessary under the lawful purposes and the Company's business operation guidelines.
7.2 Procedures and Controls
The Company will provide procedures and controls to manage personal data at every stage in a manner consistent with the law and the Company's Personal Data Protection Policy.
7.3 Records of Processing Activities (ROPA)
The Company will prepare and maintain Records of Processing Activities (ROPA) to record the lists and various activities relating to the processing of personal data in accordance with the law, and will update the records of processing activities when there is a change in the relevant lists or activities.
7.4 Transparency and Consent
The Company will provide a clear process to ensure that the notification of the purposes of collection and the details of personal data processing (Privacy Notices), and the obtaining of consent from data subjects, are consistent with the law, and will provide measures to oversee and monitor such matters.
7.5 Access Control
The Company provides guidelines for permitting access to personal data only for persons who need to know and access the personal data, in order to enable the Company to perform its duties under the contract with you, or only within the scope of the services. In the event that the Company is a data processor, the Company will process personal data according to written instructions as specified in the contract, and only within the scope of its duties with the data controller, and will comply with the personal data protection law with respect to the duties of a data processor.
7.6 Data Sharing Agreements
In the event that the Company sends, transfers, or allows another person to use personal data, the Company will prepare an agreement regarding the use of such personal data to define the rights and duties in a manner consistent with the law and the Company's Personal Data Protection Policy.
7.7 Cross-Border Data Transfers
The Company may need to send or transfer your personal data to foreign countries for the purposes of providing services, processing data, storing data, supporting the provision of services, or using services from the Company's external service providers, which may be located or have data processing systems in foreign countries. Such destination countries may have personal data protection standards that differ from Thailand, including the United States of America, in cases where the Company uses certain types of automated processing technology or artificial intelligence service providers.
In sending or transferring personal data to foreign countries, the Company will act only as necessary and will provide appropriate personal data protection measures, such as contractual measures, data security measures, restriction of data access rights, and any other measures as required or permitted by the personal data protection law, in order to ensure that your personal data is appropriately protected.
In the event that the sending or transfer of personal data to foreign countries cannot be carried out on the basis of the criteria or protection measures prescribed by law, the Company will obtain consent from you before sending or transferring such personal data, unless it is a case where the law requires or permits such action without obtaining consent.
7.8 Data Retention and Destruction
The Company will destroy personal data upon the expiration of the retention period, acting in a manner consistent with the law and the Company's business operation guidelines.
7.9 Risk Management
The Company will assess risks and establish measures to mitigate risks and reduce the impact that will arise on the processing of personal data.
7.10 Continuous Improvement
The Company will provide for the regular review and improvement of policies, standards, guidelines, procedures, and other documents relating to personal data protection, in order to keep them up to date and consistent with the law and the circumstances at each period of time.
8. Retention Period of Personal Data
The Company will retain the data subject's data according to the type of activity and the purpose of the personal data processing, as specified in the Privacy Notice on the Company's website.
After the expiration of the aforementioned period, the Company will delete or destroy such personal data from storage in the Company's systems and those of other persons who provide services to the Company (if any), or will render the data subject's personal data unable to identify the data subject, or will take any other action as prescribed by the personal data protection law, in order to make the protection of personal data effective, except where it is a case in which the Company can continue to retain such personal data as prescribed by the personal data protection law or other relevant laws.
9. Rights of the Data Subject
The Company grants the data subject the rights prescribed by the personal data protection law, as follows:
9.1 Right to Withdraw Consent
The right to withdraw consent to the processing of personal data throughout the period during which the personal data remains with the Company.
9.2 Right to Access and Obtain a Copy
The right to request access to and obtain a copy of the personal data, and the right to request the disclosure of the acquisition of the personal data.
9.3 Right to Data Portability
The right to obtain personal data in a format that is generally readable or usable, including the right to request that such data be sent or transferred to another data controller.
9.4 Right to Object
The right to object to the processing of personal data at any time.
9.5 Right to Erasure
The right to request that the Company delete, destroy, or render the personal data unable to identify the person who is the data subject.
9.6 Right to Restriction of Processing
The right to request that the Company suspend the use of personal data.
9.7 Right to Rectification
The right to request that the Company take action to ensure that the personal data is accurate, up to date, complete, and not misleading.
9.8 Right to Lodge a Complaint
The right to lodge a complaint in the event that the Company, its employees, or its contractors violate or fail to comply with the personal data protection law, through the Data Processing Complaint Form, or to the Personal Data Protection Committee.
In this regard, the Company respects your privacy and provides you with the opportunity to choose the method of control, or the method by which the Company contacts you, and the Company will comply with what you have requested, in order to help ensure transparency and the quality and accuracy of the data. Any request to exercise your rights as prescribed by law must be made in writing through the electronic system that the Company has provided on the Company's website.
10. Security for Personal Data
The Company recognizes the importance of maintaining the security of your personal data. The Company therefore establishes appropriate measures to prevent loss, unauthorized access, destruction, use, alteration, modification, or unlawful disclosure of personal data, including establishing policies, regulations, guidelines, and various procedures as follows:
10.1 Establishing Policies and Operating Procedures
Establishing clear policies and operating procedures to protect personal data and to manage data securely in accordance with the law.
10.2 Commitment to Data Privacy
Not selling or trading your personal data under any circumstances, and not transferring your personal data to other persons who are not the Company's data processors.
10.3 Access Control
Limiting the rights of the Company's employees to access personal data, and specifying the rights to access or use the personal data of data subjects, in order to maintain the confidentiality and security of the data.
10.4 Technical Protection Measures
Preventing unauthorized access and use of personal data by providing data encryption, identity verification, and virus detection technology, as necessary.
10.5 Security Governing Third Parties
Conducting due diligence on the Company's business partners, requiring business partners that do business with the Company to comply with the criteria under the laws and various regulations on personal data protection, and specifying restrictions on the use of personal data.
10.6 Website Monitoring
Monitoring the Company's website through agencies with expertise in personal data protection and security.
10.7 Employee Training
Requiring the Company's employees to undergo training on personal data protection and data security.
10.8 Regular Audits
Evaluating the guidelines on personal data protection, data management, and the maintenance of appropriate technical, physical, and administrative data security, including reviewing security measures when necessary or when technology changes.
10.9 Data Deletion Process
Providing an audit system to carry out the deletion or destruction of personal data upon the expiration of the retention period, or where it is irrelevant or beyond what is necessary for the purpose of collecting that personal data.
10.10 Data Breach Reporting
Providing a system for notifying the Office of the Personal Data Protection Committee of personal data breaches within 72 (seventy-two) hours from becoming aware of the incident, to the extent that it can be done, unless such breach does not pose a risk of affecting the rights and freedoms of persons.
11. Links to Third-Party Websites and Services
11.1 Third-Party Websites and User Data
The Company's website and applications may contain links to third-party applications and websites, which those third parties may use to collect certain data about the use of services and personal data. The Company cannot be responsible for the security or privacy of any data collected by such third-party applications and websites.
Data subjects should exercise caution and carefully review the personal data protection policies of those third-party applications and websites before using such third-party applications and websites, as follows:
11.2 Exporting User Data to Other Persons or Organizations
The Company provides you with the option to export data to third-party applications and websites, including social network websites. When you do this, you may be disclosing your data to other persons or other organizations.
11.3 Data Analytics
The Company uses services for data analytics, such as Google Analytics and Growthbook, for the purpose of developing and improving the experience of using the platform, such as browsing data, device data, country of residence, and your approximate location.
Opting Out of Data Analytics Services If you do not want Google Analytics to be able to access your usage data, you can choose to disable the recording of usage through Google's tool at https://marketingplatform.google.com/about/analytics/
Learn More About Growthbook You can find further details about Growthbook on the website https://www.growthbook.io/legal/privacy-policy/01-01-2020
12. Use of Personal Data for the Original Purpose
In the event that the Company collected your personal data before the date on which the personal data protection law relating to the collection, use, or disclosure of personal data came into force, the Company will continue to collect and use your personal data for the original purpose. You have the right to withdraw your consent at any time by contacting the Company through filling in the Consent Withdrawal Request Form.
13. Contact Channels
The Company has assigned Mr. Warodom Kasiolarn as the coordinator regarding the Company's personal data protection. In the event that the data subject has any questions or wishes to exercise the rights specified in this Policy, they may do so through the following channels:
Data Protection Officer
14. Review of the Policy
The Company may improve, change, or amend this privacy policy from time to time in order to comply with the criteria prescribed by law. The Company will announce and notify you of the changes through the channels of the Company's website and/or platform.
Currently, the Personal Data Protection Policy was last reviewed on 17 July 2026.