BillBoxLegalbillbox.app
คู่มือการใช้งานนโยบายความเป็นส่วนตัวข้อกำหนดการใช้บริการข้อกำหนด Affiliateการลบข้อมูลการใช้ AI
Public legal pageEnglishภาษาไทย

Privacy Policy

นโยบายความเป็นส่วนตัว

This page publishes both the English and Thai versions on the same URL so customers can read the Thai copy and provider reviewers can inspect the English copy without switching locales.

English

Jump to Thai

Privacy Policy

Effective date: 2026-07-09

BillBox ("BillBox", "we", "us") is an expense document management service operated by Pongvich Gludkhemthong, operating as BillBox. BillBox helps companies collect receipts, tax invoices, and other expense documents, uses AI to extract key data from them, and helps teams review expenses, prepare payment vouchers, and export data for accounting.

This policy explains what data we collect, how we use it, and the choices you have. We have written it to be readable — if anything is unclear, contact us at privacy@billboxapp.com.

1. Information we collect

Account and workspace data

  • Your LINE profile information when you sign in with LINE Login (LINE user ID, display name, and profile picture). LINE is the primary way to sign in to BillBox.
  • An email address and password, if you choose to add them in your account settings as a backup sign-in method for desktop.
  • Company/workspace information you enter: company name, team members, roles, requester names, expense categories, and settings.

Documents and their contents

  • Receipts, tax invoices, bank statements, payment evidence, and other files you or your team submit to BillBox.
  • Data extracted from those documents (by AI or entered manually): amounts, dates, vendor names, tax IDs, categories, currency and exchange information, and similar expense fields.
  • Because these are business documents, they may incidentally contain personal data of third parties (e.g. employee names on payroll-related documents, customer names on invoices). You are responsible for having a lawful basis to process such documents; we process them only to provide the service to you.

Data from connected channels (only if you connect them)

  • Web upload: files you upload directly in the app.
  • LINE / Telegram: images and files sent to your company's connected messaging channel, plus the sender identifier needed to attribute the document.
  • Gmail: if you connect a Gmail account, we access email messages read-only to find expense documents (attachments) based on rules you configure (e.g. sender allowlists, keyword groups). See section 4 for the Google-specific commitments.
  • Microsoft Outlook: same as Gmail, using Microsoft's Mail.Read permission.
  • Google Drive: BillBox archives your documents into folders in your own Google Drive. We use Google's per-file scope (drive.file), which only allows access to files and folders that BillBox itself creates or that you explicitly open with BillBox — we cannot see the rest of your Drive.
  • Google Sheets: BillBox creates and updates BillBox accounting export spreadsheets when you enable Google export features.

Technical data

  • Log data such as IP address, browser type, timestamps, and error reports, used for security and troubleshooting.

Billing and Affiliate data

  • Subscription plan, Workspace usage, credit ledger, payment event identifiers, amounts, tax, discounts, refunds, and chargebacks. Stripe hosts BillBox Checkout and handles payment-card data directly; BillBox stores Stripe customer, subscription, invoice, payment-event, and Checkout identifiers but does not store full card numbers or CVCs.
  • Affiliate identity or entity, tax, address, contact, promotion-channel, bank account or PromptPay details, referral attribution, commission, fraud-review, withholding-tax, and payout evidence.
  • The Affiliate Portal exposes only shortened referral identifiers and commercial status; it does not disclose customer names, documents, or contact details to Affiliates.

2. How we use your data

We use your data only to operate BillBox for you:

  • Receive and store the documents you submit.
  • Extract expense fields from documents using AI so your team does not have to type them (see section 3).
  • Let your team review, correct, approve, and export expense records and payment vouchers.
  • Archive documents to your company's Google Drive when you enable that feature.
  • Provide support, maintain security, prevent abuse, and comply with legal obligations.

We do not sell your data, and we do not use your documents for advertising.

3. AI processing

BillBox uses AI to read documents and suggest expense data (amount, date, vendor, category, etc.). To do this, document images/files and relevant text are sent to our AI provider, currently Google Gemini (via the Gemini API), for processing. A document image may additionally be sent to the Google Cloud Vision API for text detection, used solely to cross-check a vendor name or tax ID already read from that same document.

  • AI output is a suggestion. Your team reviews and confirms data before it becomes an expense record or is exported.
  • We do not use your documents to train our own AI models.
  • Regarding the AI provider: BillBox uses the paid tier of the Gemini API. Under Google's terms for the paid tier, Google does not use data submitted to the Gemini API to train its models. We rely on the provider's terms for this commitment.

See our AI Processing Disclosure for a plain-language explanation.

4. Google user data from Gmail, Google Drive, and Google Sheets

If you connect Google services, our use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Gmail data to find and import expense-related attachments according to the rules you set. We do not use Gmail data for advertising, and we do not sell it.
  • Gmail access is read-only. We never send, label, delete, or modify your email.
  • We use Google Drive to store documents and files that BillBox creates or manages for your company.
  • We use Google Sheets to create and update BillBox accounting export spreadsheets.
  • We only transfer Google user data to service providers as necessary to provide BillBox features (for example, secure application hosting, database services, file processing, and AI document extraction as described in this policy), for security, or to comply with law.
  • Humans at BillBox do not read your Gmail data or documents except (a) with your explicit permission for support or troubleshooting, (b) for security or abuse investigation, or (c) where required by law.
  • Drive access is limited to files BillBox creates or that you open with BillBox (drive.file scope).
  • BillBox does not use raw, derived, aggregated, or anonymized Google Workspace API data for advertising, credit or lending decisions, user profiling unrelated to BillBox’s user-facing features, or any other prohibited purpose.
  • BillBox does not use raw, derived, aggregated, or anonymized Google Workspace API data to develop, improve, or train generalized artificial intelligence or machine-learning models.
  • Google Workspace API data sent to Google Gemini is used only to extract information from the specific documents submitted or imported for the requesting user. BillBox uses a paid Gemini API service under terms that do not permit submitted customer data to be used to train Google’s generalized AI models.
  • BillBox does not transfer raw, derived, aggregated, or anonymized Google Workspace API data to advertisers, data brokers, information resellers, or third-party AI services that use the data to train generalized artificial intelligence or machine-learning models.
  • The use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Google at any time from BillBox settings or from your Google Account permissions page. Disconnecting stops all further access; see our Data Deletion page for how to remove stored data.

5. Third-party processors

We share data only with service providers that help us run BillBox:

ProviderPurpose
SupabaseDatabase, authentication, and file storage
VercelApplication hosting
StripeHosted checkout, subscription billing, one-time credit purchases, receipts, refunds, and payment dispute handling
Google (Gemini API)AI document data extraction
Google (Cloud Vision API)Text detection on document images, to cross-check a vendor name or tax ID read from the same document
Google (Gmail, Drive, Sheets APIs)Email import, Drive archiving, spreadsheet export — only if you connect them
Microsoft (Graph API)Outlook email import — only if you connect it
LINESign-in (LINE Login) and receiving documents sent through your connected LINE channel
TelegramReceiving documents sent through your connected Telegram channel — only if you connect it

Each provider processes data under its own terms and security measures. Some providers store data outside Thailand; by using BillBox you acknowledge this cross-border processing.

6. Data retention and deletion

  • We keep your data while your account is active so your team can use it.
  • You can delete individual documents and records in the app.
  • You can request deletion of your account and company data — see Data Deletion. We aim to complete deletion within 30 days of a verified request.
  • Files archived to your own Google Drive belong to you and remain in your Drive until you delete them there.
  • Residual copies may persist in encrypted backups for a limited period before being cycled out.

7. Your rights (PDPA)

Under Thailand's Personal Data Protection Act (PDPA), you have the right to access, obtain a copy of, correct, delete, restrict, or object to the processing of your personal data, and to withdraw consent where processing is based on consent. To exercise these rights, contact privacy@billboxapp.com. If you believe we have not handled your data properly, you may also lodge a complaint with Thailand's Personal Data Protection Committee (PDPC).

For documents your company uploads about other people (employees, vendors), your company is the data controller and BillBox acts as a processor on your company's instructions.

8. Security

We protect your data with encryption in transit, access controls with company-level roles, and OAuth tokens stored server-side. No system is perfectly secure, but we take reasonable measures appropriate for financial documents, and we will notify affected customers of any breach as required by law.

9. Changes to this policy

We will post any changes on this page and update the effective date. For significant changes we will notify you in the app or by email.

10. Contact

  • Support & privacy requests: privacy@billboxapp.com
  • Pongvich Gludkhemthong, operating as BillBox, 2/6 ชั้น 3 คู้บอน 38 แขวงบางชัน เขตคลองสามวา กรุงเทพมหานคร 10510

ภาษาไทย

Jump to English

นโยบายความเป็นส่วนตัว

มีผลบังคับใช้: 2026-07-09

BillBox ("เรา") เป็นบริการจัดการเอกสารค่าใช้จ่ายของบริษัท ดำเนินการโดย Pongvich Gludkhemthong, operating as BillBox BillBox ช่วยรวบรวมใบเสร็จ ใบกำกับภาษี และเอกสารค่าใช้จ่าย ใช้ AI อ่านข้อมูลสำคัญจากเอกสาร และช่วยทีมของคุณตรวจรายการ ทำใบสำคัญจ่าย และ export ข้อมูลส่งบัญชี

นโยบายนี้อธิบายว่าเราเก็บข้อมูลอะไร ใช้อย่างไร และคุณมีสิทธิ์อะไรบ้าง เราตั้งใจเขียนให้อ่านง่าย หากมีข้อสงสัยติดต่อได้ที่ privacy@billboxapp.com

1. ข้อมูลที่เราเก็บ

ข้อมูลบัญชีและ workspace

  • ข้อมูลโปรไฟล์ LINE เมื่อคุณล็อกอินด้วย LINE Login (LINE user ID ชื่อที่แสดง และรูปโปรไฟล์) — LINE เป็นช่องทางหลักในการเข้าใช้ BillBox
  • อีเมลและรหัสผ่าน หากคุณเลือกตั้งไว้ในหน้าตั้งค่าบัญชี เพื่อเป็นช่องทางล็อกอินสำรองบนเดสก์ท็อป
  • ข้อมูลบริษัทที่คุณกรอก เช่น ชื่อบริษัท สมาชิกทีม บทบาท (role) ชื่อผู้เบิก หมวดหมู่ค่าใช้จ่าย และการตั้งค่าต่าง ๆ

เอกสารและข้อมูลในเอกสาร

  • ใบเสร็จ ใบกำกับภาษี statement ธนาคาร หลักฐานการจ่ายเงิน และไฟล์อื่น ๆ ที่คุณหรือทีมส่งเข้า BillBox
  • ข้อมูลที่ดึงจากเอกสาร (โดย AI หรือกรอกเอง) เช่น ยอดเงิน วันที่ ชื่อร้านค้า เลขผู้เสียภาษี หมวดหมู่ สกุลเงินและอัตราแลกเปลี่ยน
  • เอกสารธุรกิจอาจมีข้อมูลส่วนบุคคลของบุคคลอื่นปะปนอยู่ (เช่น ชื่อพนักงานในเอกสารเงินเดือน ชื่อลูกค้าในใบแจ้งหนี้) บริษัทของคุณมีหน้าที่มีฐานทางกฎหมายในการประมวลผลเอกสารเหล่านั้น เราประมวลผลเพื่อให้บริการแก่คุณเท่านั้น

ข้อมูลจากช่องทางที่คุณเชื่อมต่อ (เฉพาะเมื่อคุณเชื่อมต่อเอง)

  • อัปโหลดผ่านเว็บ: ไฟล์ที่คุณอัปโหลดในแอปโดยตรง
  • LINE / Telegram: รูปและไฟล์ที่ส่งเข้าช่องทางแชทของบริษัทคุณ พร้อมข้อมูลผู้ส่งเท่าที่จำเป็นเพื่อระบุว่าเอกสารมาจากใคร
  • Gmail: ถ้าคุณเชื่อมต่อ Gmail เราเข้าถึงอีเมลแบบอ่านอย่างเดียว เพื่อค้นหาไฟล์แนบเอกสารค่าใช้จ่ายตามกติกาที่คุณตั้งเอง (เช่น รายชื่อผู้ส่งที่อนุญาต กลุ่มคีย์เวิร์ด) ดูข้อ 4 สำหรับข้อผูกพันเฉพาะของ Google
  • Microsoft Outlook: เหมือน Gmail โดยใช้สิทธิ์ Mail.Read ของ Microsoft
  • Google Drive: BillBox เก็บเอกสารเข้าโฟลเดอร์ใน Google Drive ของคุณเอง เราใช้สิทธิ์แบบรายไฟล์ (drive.file) ซึ่งเข้าถึงได้เฉพาะไฟล์/โฟลเดอร์ที่ BillBox สร้างเอง หรือที่คุณเปิดให้ BillBox เท่านั้น — เรามองไม่เห็นไฟล์อื่นใน Drive ของคุณ
  • Google Sheets: BillBox สร้างและอัปเดตไฟล์ spreadsheet สำหรับส่งออกข้อมูลบัญชีของ BillBox เมื่อคุณเปิดใช้ฟีเจอร์ export ผ่าน Google

ข้อมูลทางเทคนิค

  • ข้อมูล log เช่น IP address ชนิดเบราว์เซอร์ เวลาใช้งาน และรายงานข้อผิดพลาด เพื่อความปลอดภัยและการแก้ไขปัญหา

ข้อมูล Billing และ Affiliate

  • แพ็กสมาชิก การใช้โควตาใน Workspace บัญชีเครดิต รหัสเหตุการณ์ชำระเงิน ยอดเงิน ภาษี ส่วนลด refund และ chargeback โดย Stripe เป็นผู้โฮสต์ Checkout และรับข้อมูลบัตรโดยตรง BillBox เก็บเฉพาะรหัสอ้างอิงลูกค้า subscription invoice เหตุการณ์ชำระเงิน และ Checkout ของ Stripe แต่ไม่เก็บเลขบัตรเต็มหรือ CVC
  • ข้อมูลตัวตนหรือนิติบุคคลของ Affiliate ภาษี ที่อยู่ ติดต่อ ช่องทางโปรโมต บัญชีธนาคารหรือ PromptPay การผูก Referral ค่าคอม การตรวจ fraud ภาษีหัก ณ ที่จ่าย และหลักฐาน payout
  • Affiliate Portal แสดงเพียง Referral ID แบบย่อและสถานะทางการค้า ไม่เปิดเผยชื่อลูกค้า เอกสาร หรือข้อมูลติดต่อแก่ Affiliate

2. เราใช้ข้อมูลเพื่ออะไร

เราใช้ข้อมูลเพื่อให้บริการ BillBox แก่คุณเท่านั้น:

  • รับและจัดเก็บเอกสารที่คุณส่งเข้ามา
  • ใช้ AI อ่านข้อมูลค่าใช้จ่ายจากเอกสาร เพื่อให้ทีมไม่ต้องพิมพ์เอง (ดูข้อ 3)
  • ให้ทีมของคุณตรวจ แก้ไข อนุมัติ และ export รายการค่าใช้จ่ายและใบสำคัญจ่าย
  • เก็บเอกสารเข้า Google Drive ของบริษัทคุณเมื่อคุณเปิดใช้ฟีเจอร์นี้
  • ให้บริการ support ดูแลความปลอดภัย ป้องกันการใช้งานผิดวัตถุประสงค์ และปฏิบัติตามกฎหมาย

เราไม่ขายข้อมูลของคุณ และไม่ใช้เอกสารของคุณเพื่อการโฆษณา

3. การประมวลผลด้วย AI

BillBox ใช้ AI อ่านเอกสารและเสนอข้อมูลค่าใช้จ่าย (ยอดเงิน วันที่ ร้านค้า หมวดหมู่ ฯลฯ) โดยไฟล์เอกสารและข้อความที่เกี่ยวข้องจะถูกส่งไปประมวลผลกับผู้ให้บริการ AI ของเรา ปัจจุบันคือ Google Gemini (ผ่าน Gemini API) ในบางกรณี รูปภาพเอกสารอาจถูกส่งไปยัง Google Cloud Vision API เพิ่มเติมเพื่ออ่านตัวอักษร ใช้เพียงเพื่อตรวจทานชื่อผู้ขายหรือเลขประจำตัวผู้เสียภาษีที่อ่านได้จากเอกสารฉบับเดียวกันนั้น

  • ผลจาก AI เป็นเพียงข้อเสนอ ทีมของคุณต้องตรวจและยืนยันก่อนข้อมูลจะกลายเป็นรายการจริงหรือถูก export
  • เราไม่นำเอกสารของคุณไป train โมเดล AI ของเราเอง
  • ในส่วนของผู้ให้บริการ AI: BillBox ใช้ Gemini API แบบเสียเงิน (paid tier) ซึ่งตามเงื่อนไขของ Google ข้อมูลที่ส่งผ่าน API แบบเสียเงินจะไม่ถูกนำไปใช้ train โมเดลของ Google เราอ้างอิงตามเงื่อนไขของผู้ให้บริการในเรื่องนี้

อ่านคำอธิบายฉบับเข้าใจง่ายได้ที่ การใช้ AI อ่านเอกสาร

4. ข้อมูลผู้ใช้ Google จาก Gmail, Google Drive และ Google Sheets

หากคุณเชื่อมต่อบริการของ Google การใช้ข้อมูลที่ได้จาก Google API ของเราเป็นไปตาม Google API Services User Data Policy รวมถึงข้อกำหนด Limited Use กล่าวคือ:

  • เราใช้ข้อมูล Gmail เพื่อค้นหาและนำเข้าไฟล์แนบที่เป็นเอกสารค่าใช้จ่ายตามกติกาที่คุณตั้งเท่านั้น ไม่ใช้เพื่อโฆษณา และไม่ขายข้อมูล
  • การเข้าถึง Gmail เป็นแบบอ่านอย่างเดียว เราไม่ส่ง ไม่ติดป้าย ไม่ลบ และไม่แก้ไขอีเมลของคุณ
  • เราใช้ Google Drive เพื่อจัดเก็บเอกสารและไฟล์ที่ BillBox สร้างหรือจัดการให้บริษัทของคุณ
  • เราใช้ Google Sheets เพื่อสร้างและอัปเดตไฟล์ spreadsheet สำหรับส่งออกข้อมูลบัญชีของ BillBox
  • เราส่งต่อข้อมูลผู้ใช้ Google ให้ผู้ให้บริการเท่าที่จำเป็นต่อการให้บริการ BillBox เท่านั้น (เช่น hosting แอป ฐานข้อมูล การประมวลผลไฟล์ และการอ่านเอกสารด้วย AI ตามที่ระบุในนโยบายนี้) เพื่อความปลอดภัย หรือเมื่อกฎหมายกำหนด
  • พนักงานของ BillBox จะไม่อ่านข้อมูล Gmail หรือเอกสารของคุณ ยกเว้น (ก) ได้รับอนุญาตจากคุณอย่างชัดเจนเพื่อการ support หรือแก้ปัญหา (ข) เพื่อตรวจสอบด้านความปลอดภัยหรือการใช้งานผิดวัตถุประสงค์ หรือ (ค) เมื่อกฎหมายกำหนด
  • การเข้าถึง Drive จำกัดเฉพาะไฟล์ที่ BillBox สร้างหรือที่คุณเปิดให้ BillBox (drive.file scope)
  • BillBox ไม่ใช้ข้อมูลดิบ ข้อมูลที่ประมวลผลต่อ ข้อมูลแบบรวม หรือข้อมูลที่ไม่สามารถระบุตัวบุคคลได้จาก Google Workspace API เพื่อการโฆษณา การพิจารณาสินเชื่อ การให้เครดิต การสร้างโปรไฟล์ผู้ใช้นอกเหนือจากฟีเจอร์ที่ผู้ใช้ร้องขอ หรือวัตถุประสงค์ต้องห้ามอื่นใด
  • BillBox ไม่ใช้ข้อมูลดิบ ข้อมูลที่ประมวลผลต่อ ข้อมูลแบบรวม หรือข้อมูลที่ไม่สามารถระบุตัวบุคคลได้จาก Google Workspace API เพื่อพัฒนา ปรับปรุง หรือฝึกโมเดลปัญญาประดิษฐ์หรือแมชชีนเลิร์นนิงแบบทั่วไป
  • ข้อมูลจาก Google Workspace API ที่ส่งไปยัง Google Gemini ใช้เฉพาะเพื่อสกัดข้อมูลจากเอกสารที่ผู้ใช้รายนั้นส่งหรืออนุญาตให้นำเข้าเท่านั้น BillBox ใช้บริการ Gemini API แบบชำระเงินภายใต้เงื่อนไขที่ไม่อนุญาตให้นำข้อมูลลูกค้าที่ส่งเข้าไปใช้ฝึกโมเดล AI ทั่วไปของ Google
  • BillBox ไม่ส่งต่อข้อมูลดิบ ข้อมูลที่ประมวลผลต่อ ข้อมูลแบบรวม หรือข้อมูลที่ไม่สามารถระบุตัวบุคคลได้จาก Google Workspace API ให้แก่ผู้ลงโฆษณา นายหน้าข้อมูล ผู้ค้าข้อมูล หรือบริการ AI ภายนอกที่นำข้อมูลดังกล่าวไปใช้ฝึกโมเดลปัญญาประดิษฐ์หรือแมชชีนเลิร์นนิงแบบทั่วไป
  • การใช้ข้อมูลดิบหรือข้อมูลที่ได้จากการประมวลผลซึ่งได้รับจาก Google Workspace API เป็นไปตาม Google API Services User Data Policy รวมถึงข้อกำหนด Limited Use

คุณถอนการเชื่อมต่อ Google ได้ทุกเมื่อจากหน้าตั้งค่าใน BillBox หรือจาก หน้าจัดการสิทธิ์ของบัญชี Google เมื่อถอนแล้วเราจะเข้าถึงข้อมูลเพิ่มไม่ได้อีก ดูวิธีลบข้อมูลที่เก็บไว้ที่ หน้าการลบข้อมูล

5. ผู้ประมวลผลข้อมูลภายนอก (third-party processors)

เราแชร์ข้อมูลเฉพาะกับผู้ให้บริการที่ช่วยให้ BillBox ทำงานได้:

ผู้ให้บริการวัตถุประสงค์
Supabaseฐานข้อมูล ระบบล็อกอิน และที่เก็บไฟล์
Vercelโฮสต์ตัวแอป
Stripeโฮสต์ Checkout รับค่าสมาชิกและเครดิตเติม ออกใบเสร็จ จัดการ refund และข้อโต้แย้งการชำระเงิน
Google (Gemini API)ใช้ AI อ่านข้อมูลจากเอกสาร
Google (Cloud Vision API)อ่านตัวอักษรจากรูปภาพเอกสาร เพื่อตรวจทานชื่อผู้ขายหรือเลขผู้เสียภาษีที่อ่านได้จากเอกสารฉบับเดียวกัน
Google (Gmail, Drive, Sheets API)นำเข้าอีเมล เก็บเอกสารเข้า Drive และ export spreadsheet — เฉพาะเมื่อคุณเชื่อมต่อ
Microsoft (Graph API)นำเข้าอีเมลจาก Outlook — เฉพาะเมื่อคุณเชื่อมต่อ
LINEการล็อกอิน (LINE Login) และรับเอกสารที่ส่งผ่านช่องทาง LINE ที่คุณเชื่อมต่อ
Telegramรับเอกสารที่ส่งผ่านช่องทาง Telegram — เฉพาะเมื่อคุณเชื่อมต่อ

ผู้ให้บริการแต่ละรายประมวลผลข้อมูลตามเงื่อนไขและมาตรการความปลอดภัยของตน บางรายจัดเก็บข้อมูลนอกประเทศไทย การใช้ BillBox ถือว่าคุณรับทราบการประมวลผลข้ามพรมแดนนี้

6. การเก็บรักษาและการลบข้อมูล

  • เราเก็บข้อมูลตราบเท่าที่บัญชีของคุณยังใช้งานอยู่
  • คุณลบเอกสารและรายการทีละรายการได้ในแอป
  • คุณขอลบบัญชีและข้อมูลทั้งบริษัทได้ — ดู การลบข้อมูล เราตั้งเป้าดำเนินการให้เสร็จภายใน 30 วัน หลังยืนยันตัวตน
  • ไฟล์ที่ถูก archive เข้า Google Drive ของคุณเอง เป็นของคุณ และจะยังอยู่ใน Drive จนกว่าคุณจะลบเอง
  • สำเนาข้อมูลอาจคงอยู่ใน backup แบบเข้ารหัสชั่วระยะหนึ่งตามรอบ retention ก่อนถูกลบถาวร

7. สิทธิ์ของคุณตาม PDPA

ตาม พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล (PDPA) คุณมีสิทธิ์ขอเข้าถึง ขอสำเนา ขอแก้ไข ขอลบ ขอจำกัดหรือคัดค้านการประมวลผลข้อมูลส่วนบุคคลของคุณ และถอนความยินยอมในกรณีที่การประมวลผลอาศัยความยินยอม ใช้สิทธิ์ได้โดยติดต่อ privacy@billboxapp.com และหากเห็นว่าเราจัดการข้อมูลไม่ถูกต้อง คุณมีสิทธิ์ร้องเรียนต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส.)

สำหรับเอกสารที่บริษัทของคุณอัปโหลดซึ่งมีข้อมูลของบุคคลอื่น (พนักงาน คู่ค้า) บริษัทของคุณเป็นผู้ควบคุมข้อมูล และ BillBox เป็นผู้ประมวลผลข้อมูลตามคำสั่งของบริษัทคุณ

8. ความปลอดภัย

เราปกป้องข้อมูลด้วยการเข้ารหัสระหว่างรับส่ง ระบบสิทธิ์ตามบทบาทในบริษัท และเก็บ OAuth token ไว้ฝั่งเซิร์ฟเวอร์ ไม่มีระบบใดปลอดภัยสมบูรณ์แบบ แต่เราใช้มาตรการที่เหมาะสมกับเอกสารการเงิน และจะแจ้งลูกค้าที่ได้รับผลกระทบหากเกิดเหตุข้อมูลรั่วไหลตามที่กฎหมายกำหนด

9. การเปลี่ยนแปลงนโยบาย

เราจะประกาศการเปลี่ยนแปลงบนหน้านี้พร้อมอัปเดตวันที่มีผล หากเป็นการเปลี่ยนแปลงสำคัญ เราจะแจ้งในแอปหรือทางอีเมล

10. ติดต่อเรา

  • Support และคำขอด้านข้อมูลส่วนบุคคล: privacy@billboxapp.com
  • Pongvich Gludkhemthong, operating as BillBox, 2/6 ชั้น 3 คู้บอน 38 แขวงบางชัน เขตคลองสามวา กรุงเทพมหานคร 10510