Privacy Policy
Effective 2026-09-25 · PDPA B.E. 2562 (2019)
1. Who is the data controller
MPBxChange, operated by The Northeastern Consultants Company Limited (Thai DBD registration 0105562014156), Bangkok, is the Data Controller for personal data processed through the platform. Contact: dpo@mpbxchange.com (privacy contact).
2. What data we collect
The platform collects the following categories of personal data:
- Identity: name, email, phone, employer, job title.
- Authentication: hashed password, MFA factors, session tokens, IP address, user-agent.
- KYC documents: business registration, tax ID, bank account proof, beneficial-owner declaration, ISO/IATF/IEC/UL/FDA certifications, factory licences, etc. — uploaded for the purpose of trust verification.
- Transactional: listings posted, RFQs sent, quotes received, contracts signed, milestones advanced, disputes raised, comments posted.
- Audit log: every action (create, update, sign, advance, comment) timestamped with IP address and user-agent.
- Payment metadata: transfer references and payment status reported by the parties (we do not store card numbers; buyers pay factories directly and MPBxChange holds no user funds).
- Cookies: see §9 — categorical consent.
3. Lawful basis (PDPA §24-§25)
We process personal data on the following lawful bases:
| Activity | Lawful basis |
|---|---|
| Account creation, login, contract execution | Contractual necessity §24(3) |
| KYC verification, sanctions screening | Legitimate interests in preventing fraud and protecting platform access (PDPA §24(5)); a legal obligation is relied on only where it applies. |
| Trust score, transaction history display | Legitimate interest §24(5) — platform integrity |
| Audit logging for regulatory + dispute purposes | Legitimate interest §24(5) + Legal obligation §24(6) |
| Marketing emails, product announcements | Consent under PDPA §19 (withdrawable) |
| Cookies (analytics + marketing) | Consent under PDPA §19 |
5. Cross-border data transfers (PDPA §28)
Some providers process data outside Thailand. A cross-border transfer requires an applicable legal mechanism under PDPA §§28–29, such as adequate protection, appropriate safeguards or a specific statutory exception. Accepting the general terms or privacy notice alone is not specific informed consent for a transfer that requires it. Ask the platform operator for the providers, destinations and safeguards relevant to your data.
6. How long we keep data (retention)
| Data | Retention period |
|---|---|
| Account profile + login credentials | Until account closure + 90 days |
| KYC documents | 5 years post account closure (AMLA §22 requirement) |
| Trade contracts + signed PDFs + audit logs | 10 years (Civil and Commercial Code limitation period) |
| Payment metadata | 5 years (AMLA + Revenue Code) |
| Marketing-consent records | 3 years from latest interaction or until withdrawn |
| Cookie-consent records | 1 year, then re-prompt |
| Audit logs (security, login events) | 2 years rolling |
7. Your rights as a data subject (PDPA §30-§35)
You have the following rights with respect to your personal data:
- Right of access (§30) — request a copy of all data we hold about you.
- Right to rectification (§35) — correct inaccurate or incomplete data.
- Right to erasure (§33) — request deletion of your data, subject to overriding legal retention duties (AMLA, tax). You can delete your account yourself under Profile, Delete account: it closes at once and your personal data is erased 14 days later, unless you reopen it with the emailed link.
- Right to restrict processing (§34) — pause processing while a dispute is resolved.
- Right to object (§32) — object to processing on legitimate-interest basis.
- Right to data portability (§31) — receive your data in a machine-readable format.
- Right to withdraw consent (§19) — at any time, with no effect on past lawful processing.
- Right to complain (§73-§76) — to the Personal Data Protection Committee (PDPC) of Thailand.
Exercise any of these rights at /privacy/my-data We handle requests without undue delay and within the applicable legal deadline. Access requests under PDPA §30 must be handled within 30 days. Other rights follow their applicable requirements.
8. Breach notification
We assess personal-data breaches and document the response. Where notification is required under PDPA §37(4), we notify the PDPC without delay and, where feasible, within 72 hours of becoming aware. If a breach is likely to result in high risk, affected people must also be notified without delay with remedial measures.
8A. Private requests, NDA signatures, encryption and inspections
NDA signatures. When a person signs an NDA on the platform we keep: the company details entered, the signer's name, position, stated authority and email address, the full text signed, the time, a masked network address and a keyed hash of the full address, the browser description, and the fact that a one-time code was confirmed. The one-time code itself is stored only as a one-way hash, works for ten minutes, and is deleted within a day. We keep this record to evidence the agreement for the parties (performance of a contract and our legitimate interest in keeping a reliable record, PDPA sections 24(3) and 24(5)). Both parties to the NDA receive a copy that names the signers.
Access records. For a request with private details we record who signed, who approved or declined, and when private details or files were opened or downloaded, and we show this record to the buyer who published the request.
Time-stamps. To time-stamp a signature record we send only its SHA-256 fingerprint, which contains no personal data, to an independent RFC 3161 time-stamp authority (currently DigiCert, with GlobalSign, Sectigo and FreeTSA as alternatives). The authority returns a signed time; we keep it with the record.
End-to-end encryption. We store each user's public keys, a security code derived from them, and a backup of the private keys sealed under the user's passphrase. We never receive the passphrase and cannot open the backup. Encrypted messages and files are stored only in encrypted form; we cannot read them or disclose their content to anyone. We still process who belongs to an encrypted room or request, when items were sent, their sizes and fingerprints, and search tokens derived from words, which show repeats but not the words.
Inspection records. When a lot inspection is recorded we keep the values entered, the report uploaded, who recorded, confirmed or disputed it, and when. Inspection reports can contain photographs; the party uploading one is responsible for leaving out personal data that the inspection does not need.
Retention. These records are kept with the request or contract they belong to, under section 6, and signature and inspection records for at least as long as the law requires for evidence of a contract. Encrypted content a user removes is deleted from storage; its fingerprint stays in the record.
10. Children
The platform is for B2B use by registered legal entities. We do not knowingly collect data from children under 20 (the age of majority in Thailand).
11. Changes to this Policy
Material changes (additions to processor list, change in retention period, changes to lawful basis) require re-consent via the platform login flow, recorded against your auth_consents row. Non-material updates take effect on publication.
12. Contact
Privacy contact: dpo@mpbxchange.com
Alternative contact for privacy requests and complaints: than@mpbxchange.com. Reporting instructions
Postal: The Northeastern Consultants Company Limited (DBD 0105562014156), Bangkok, Thailand
Complaint regulator: Personal Data Protection Committee (PDPC) — pdpc.or.th