PCB manufacturing in Thailand · Buyers worldwide← ← MPBxChange Home

Privacy Policy

Effective 2026-09-25 · PDPA B.E. 2562 (2019)

The English version of this policy is the authoritative text. Translations are provided for convenience; in case of any discrepancy, the English version prevails.

1. Who is the data controller

MPBxChange, operated by The Northeastern Consultants Company Limited (Thai DBD registration 0105562014156), Bangkok, is the Data Controller for personal data processed through the platform. Contact: dpo@mpbxchange.com (privacy contact).

2. What data we collect

The platform collects the following categories of personal data:

  • Identity: name, email, phone, employer, job title.
  • Authentication: hashed password, MFA factors, session tokens, IP address, user-agent.
  • KYC documents: business registration, tax ID, bank account proof, beneficial-owner declaration, ISO/IATF/IEC/UL/FDA certifications, factory licences, etc. — uploaded for the purpose of trust verification.
  • Transactional: listings posted, RFQs sent, quotes received, contracts signed, milestones advanced, disputes raised, comments posted.
  • Audit log: every action (create, update, sign, advance, comment) timestamped with IP address and user-agent.
  • Payment metadata: transfer references and payment status reported by the parties (we do not store card numbers; buyers pay factories directly and MPBxChange holds no user funds).
  • Cookies: see §9 — categorical consent.

3. Lawful basis (PDPA §24-§25)

We process personal data on the following lawful bases:

ActivityLawful basis
Account creation, login, contract executionContractual necessity §24(3)
KYC verification, sanctions screeningLegitimate interests in preventing fraud and protecting platform access (PDPA §24(5)); a legal obligation is relied on only where it applies.
Trust score, transaction history displayLegitimate interest §24(5) — platform integrity
Audit logging for regulatory + dispute purposesLegitimate interest §24(5) + Legal obligation §24(6)
Marketing emails, product announcementsConsent under PDPA §19 (withdrawable)
Cookies (analytics + marketing)Consent under PDPA §19

4. Who we share data with (processors)

The providers below support platform operations. Applicable processor agreements and transfer safeguards are required where the law requires them. Contact the platform operator for details of the arrangements applying to your data.

ProcessorPurposeLocation
Supabase Inc.Database, storage, authenticationUnited States (Singapore region)
Vercel Inc.Application hosting + CDNUnited States
Resend Inc.Transactional + system emailsUnited States
Sanctions-screening providerAML / sanctions list checkingEU / SG (TBA)
Vemaps.comThailand outline SVG (no PII)EU

We do not sell personal data to advertisers or data brokers. We do not share personal data outside this list of processors except: (a) when ordered by a competent court or regulator; (b) when required to honour AMLA reporting obligations; (c) when a successor entity acquires MPBxChange.

5. Cross-border data transfers (PDPA §28)

Some providers process data outside Thailand. A cross-border transfer requires an applicable legal mechanism under PDPA §§28–29, such as adequate protection, appropriate safeguards or a specific statutory exception. Accepting the general terms or privacy notice alone is not specific informed consent for a transfer that requires it. Ask the platform operator for the providers, destinations and safeguards relevant to your data.

6. How long we keep data (retention)

DataRetention period
Account profile + login credentialsUntil account closure + 90 days
KYC documents5 years post account closure (AMLA §22 requirement)
Trade contracts + signed PDFs + audit logs10 years (Civil and Commercial Code limitation period)
Payment metadata5 years (AMLA + Revenue Code)
Marketing-consent records3 years from latest interaction or until withdrawn
Cookie-consent records1 year, then re-prompt
Audit logs (security, login events)2 years rolling

7. Your rights as a data subject (PDPA §30-§35)

You have the following rights with respect to your personal data:

  • Right of access (§30) — request a copy of all data we hold about you.
  • Right to rectification (§35) — correct inaccurate or incomplete data.
  • Right to erasure (§33) — request deletion of your data, subject to overriding legal retention duties (AMLA, tax). You can delete your account yourself under Profile, Delete account: it closes at once and your personal data is erased 14 days later, unless you reopen it with the emailed link.
  • Right to restrict processing (§34) — pause processing while a dispute is resolved.
  • Right to object (§32) — object to processing on legitimate-interest basis.
  • Right to data portability (§31) — receive your data in a machine-readable format.
  • Right to withdraw consent (§19) — at any time, with no effect on past lawful processing.
  • Right to complain (§73-§76) — to the Personal Data Protection Committee (PDPC) of Thailand.

Exercise any of these rights at /privacy/my-data We handle requests without undue delay and within the applicable legal deadline. Access requests under PDPA §30 must be handled within 30 days. Other rights follow their applicable requirements.

8. Breach notification

We assess personal-data breaches and document the response. Where notification is required under PDPA §37(4), we notify the PDPC without delay and, where feasible, within 72 hours of becoming aware. If a breach is likely to result in high risk, affected people must also be notified without delay with remedial measures.

8A. Private requests, NDA signatures, encryption and inspections

NDA signatures. When a person signs an NDA on the platform we keep: the company details entered, the signer's name, position, stated authority and email address, the full text signed, the time, a masked network address and a keyed hash of the full address, the browser description, and the fact that a one-time code was confirmed. The one-time code itself is stored only as a one-way hash, works for ten minutes, and is deleted within a day. We keep this record to evidence the agreement for the parties (performance of a contract and our legitimate interest in keeping a reliable record, PDPA sections 24(3) and 24(5)). Both parties to the NDA receive a copy that names the signers.

Access records. For a request with private details we record who signed, who approved or declined, and when private details or files were opened or downloaded, and we show this record to the buyer who published the request.

Time-stamps. To time-stamp a signature record we send only its SHA-256 fingerprint, which contains no personal data, to an independent RFC 3161 time-stamp authority (currently DigiCert, with GlobalSign, Sectigo and FreeTSA as alternatives). The authority returns a signed time; we keep it with the record.

End-to-end encryption. We store each user's public keys, a security code derived from them, and a backup of the private keys sealed under the user's passphrase. We never receive the passphrase and cannot open the backup. Encrypted messages and files are stored only in encrypted form; we cannot read them or disclose their content to anyone. We still process who belongs to an encrypted room or request, when items were sent, their sizes and fingerprints, and search tokens derived from words, which show repeats but not the words.

Inspection records. When a lot inspection is recorded we keep the values entered, the report uploaded, who recorded, confirmed or disputed it, and when. Inspection reports can contain photographs; the party uploading one is responsible for leaving out personal data that the inspection does not need.

Retention. These records are kept with the request or contract they belong to, under section 6, and signature and inspection records for at least as long as the law requires for evidence of a contract. Encrypted content a user removes is deleted from storage; its fingerprint stays in the record.

9. Cookies

We use cookies in four categories. You can change your preferences any time through the cookie banner or below.

  • Strictly necessary — session ID, CSRF token, language preference. Always on.
  • Functional — remembers your active vertical, last viewed listings. Off by default.
  • Analytics — aggregated, anonymised platform-usage stats. Off by default.
  • Marketing — for outbound product news. Off by default; requires explicit opt-in.

Manage cookie preferences from the banner that appears on first visit, or email dpo@mpbxchange.com to reset.

10. Children

The platform is for B2B use by registered legal entities. We do not knowingly collect data from children under 20 (the age of majority in Thailand).

11. Changes to this Policy

Material changes (additions to processor list, change in retention period, changes to lawful basis) require re-consent via the platform login flow, recorded against your auth_consents row. Non-material updates take effect on publication.

12. Contact

Privacy contact: dpo@mpbxchange.com
Alternative contact for privacy requests and complaints: than@mpbxchange.com. Reporting instructions
Postal: The Northeastern Consultants Company Limited (DBD 0105562014156), Bangkok, Thailand
Complaint regulator: Personal Data Protection Committee (PDPC) — pdpc.or.th

See also: Terms of Service · Manage my data & rights →