Skip to main content
BACK TO HOME

Privacy Policy

PHYGITAL AGENCY COMPANY LIMITED

Contents / TABLE OF CONTENTS▼

Key Takeaways What you should know about how PHYGITAL AGENCY handles data:

  • A clear role: We separate being the "Data Controller" for our own business from being the "Data Processor" when we serve clients.
  • International standards: This policy follows Thailand's Personal Data Protection Act (PDPA), the EU GDPR, and the UN Guiding Principles on Business and Human Rights (UNGPs), which treat privacy as a basic human right.
  • AI data protection: We protect your confidential data strictly and never use client data to train public artificial intelligence (AI) systems.

PHYGITAL AGENCY COMPANY LIMITED recognises that in the digital economy data is the most valuable asset, and that privacy is a basic human right that must be protected, in line with the UN Guiding Principles on Business and Human Rights (UNGPs).

This policy explains to our employees, partners, clients and consumers how we collect, store, use, disclose and protect personal data, in line with Thailand's Personal Data Protection Act B.E. 2562 (2019) (PDPA) and, where relevant, the European Union's General Data Protection Regulation (GDPR).

Our Legal Roles

Understanding our legal role is where transparency starts. PHYGITAL AGENCY handles data in two capacities:

  • As a "Data Controller": when we collect data to run the agency itself, such as employee data, job applicant data, data of people who enquire about our services, or client billing data.
  • As a "Data Processor": when we provide digital marketing services to a client, such as using the client's customer list to build a Custom Audience on social media, managing a CRM database, or running lead generation for the client's brand. In this case we process data only on the client's (the Data Controller's) written instructions.

Data We Collect

We keep only the data our work needs:

  • Personal and contact details: name, phone number, email, address and social media accounts.
  • Technical and usage data: IP address, browser type and website browsing behaviour, collected through cookies and tracking pixels.
  • Sensitive data: we have no policy of collecting sensitive data (such as race, religion, biometric or health data), except employee data required by labour law or data given with explicit consent.

Purpose of Processing

We process personal data under a lawful basis: contract, consent, legitimate interest or legal obligation, for these purposes:

  • To communicate, coordinate, propose services and enter into contracts.
  • To plan strategy and run media buying within the agreed scope of work.
  • To analyse and improve the performance of websites and marketing campaigns.
  • To manage human resources, pay and benefits.

AI Data Training Policy

As artificial intelligence grows, PHYGITAL AGENCY states its position on protecting your data:

  • Zero-Trust Public AI Training: a client's personal data, the client's customer database and any business-confidential information will never be input into or used to train public generative AI systems (such as open versions of ChatGPT, Midjourney, or platforms that use data to develop their models).
  • Enterprise AI only: when the agency needs AI to help with data analytics, we use only enterprise-grade systems with a clear Data Processing Agreement (DPA) and a Zero-Data Retention policy (data is not kept for training), to guarantee the highest level of security.

Data Sharing & Cross-Border Transfer

As a digital agency we need global tools. Your data may be sent to or processed by:

  • Advertising platforms and partners: such as Meta (Facebook/Instagram), Google, TikTok, LINE Official Account and CRM platforms.
  • Cloud and data storage providers: such as Google Workspace, Amazon Web Services (AWS) and Microsoft Azure.

We make sure the destination country or platform has an adequate data protection standard under Sections 28–29 of the PDPA, or is covered by Standard Contractual Clauses (SCCs).

Data Security Measures

  • We use technical and organisational measures such as encryption, role-based access control, and two-factor authentication (2FA) on every account that can reach client data.
  • Data Breach Protocol: if a breach occurs, we contain it immediately and notify the data subjects and Thailand's Personal Data Protection Committee (PDPC) within 72 hours, as the law requires.

Data Subject Rights

Everyone has the full rights given by the PDPA (and the GDPR):

1. The right to access and obtain a copy of their personal data
2. The right to have data corrected and kept up to date

3. The right to have data deleted or destroyed (Right to be Forgotten)

4. The right to restrict or object to processing (especially direct marketing)

5. The right to receive or transfer their data (Data Portability)

6. The right to withdraw consent at any time

PHYGITAL INSIGHT

“At PHYGITAL AGENCY we see PDPA compliance not as paperwork but as a competitive advantage. Modern digital marketing has to be built on respect for human rights and for consumers' own decisions. Campaigns that are transparent and treat customer data with respect build more lasting brand loyalty than the old "creepy tracking" techniques.”

Frequently Asked Questions (FAQ)

Never. Your customer data is a top business secret. When it is uploaded to build a Custom Audience on an advertising platform, it is used for your work only and is deleted or destroyed from PHYGITAL AGENCY's systems as soon as the campaign or the contract ends.

We use strictly necessary cookies so the website works, and analytics/marketing cookies to show content that suits you better. You can "Reject" or change your cookie choices at any time through the cookie banner on the website.

When the contract ends or is terminated, PHYGITAL AGENCY, as the Data Processor, deletes, destroys or returns all personal data to the client (the Data Controller) within the period agreed in the contract, except data the law requires us to keep for accounting and tax, which is anonymised or kept under strictly limited access.

Email our Data Protection Officer (DPO) at hello@phygital.co.th. Data subjects can ask for access, a copy, correction, deletion or withdrawal of consent at any time, and we act on the request within 30 days, as the law requires. Requests in English are welcome.

Only as long as the contract requires. When it ends, we delete, destroy or return the data to the client within the agreed period, except data that accounting and tax law requires us to keep, which is stored with restricted access.

Digital marketing needs trust (Trust in the Digital Age)

Let us help you plan a transparent, privacy-friendly strategy for your business. Work with a partner that understands both the technology and data protection, and let PHYGITAL AGENCY grow your business safely, without legal worries.

Add us on LINE