Skip to main content
Pcampus Studio LogoPcampus Studio

Privacy Policy

Last updated: 2026-08-25

Who we are

Pcampus Studio Co., Ltd. (“Pcampus Studio,” “Pcampus,” “we,” “our,” or “us”), of 149 Moo 4, Tambon Fangdang, Amphoe Naklang, Nongbualamphu 39170, Thailand, operates the public website at https://pcampus.studio and the Pcampus platform, including Console, Pcampus Identity Platform (PIP), Pcampus Business Context Platform (PBCP / Pulse), Developer documentation, and commercial services such as Mail, Storage, Content OS, Notify, and related billing. This Privacy Policy explains how we collect, use, store, disclose, and protect information when you visit our websites, create an account, use our APIs, enable a service, or hire us for implementation. It is designed to align with Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) and, where applicable, similar principles under other data-protection laws. This policy is written to match how the platform is actually governed: tenant isolation, least privilege, evidence that can be traced (Evidence → Story → Trust), and a split between as-is controls and production-readiness targets. It is not an ISO, SOC, or PDPA certification, and it is not a substitute for independent legal advice on your own processing. Contact: contact@pcampus.studio · https://pcampus.studio

Scope of this policy

This policy covers: - Visitors to pcampus.studio and related marketing pages - Users of Console (console.pcampus.co) and Identity (PIP) - Developers using documentation and API credentials (developers.pcampus.co) - Organizations that send Business Events into PBCP or enable commercial services - Contacts who email, call, or message us about sales or support It does not make us the owner of your organization’s business systems. Customer applications, storefronts, and source databases remain under the customer’s control.

Roles: controller and processor

We distinguish two situations. The role is determined by who decides the purpose and means of processing, not by a product name. Website, accounts, billing, and our own operations. When you visit pcampus.studio, create a Pcampus account, manage an organization, pay invoices, or contact us, Pcampus is typically the Data Controller of that Personal Data. Platform processing of customer business data. When an organization sends Business Events, stores files, sends email, or otherwise uses PBCP and commercial services, that organization is typically the Data Controller. Pcampus is typically the Data Processor: we process Personal Data on the organization’s instructions to provide the service. The organization must have a lawful basis before sending us Personal Data. If a contract, order, or data-processing addendum says otherwise, that document controls for that engagement.

Information we collect

We may collect the following classes of information. We follow data minimization: we do not require Personal Data to be copied into Context when an entity identifier is enough. Account and identity data. Name, email address, password hashes or identity-provider tokens, organization name, role, membership, API keys, and OAuth identifiers if you sign in with Google or GitHub. Billing and commercial data. Organization billing profile, payment-method tokens handled by our payment processor (we do not store full card numbers), invoices, enablement of services, and usage needed to bill. Business Events and platform data. Event identifiers, timestamps, tenant/organization identifiers, actor and source metadata, payloads you send, facts derived from those events, Context and Story records, and Intelligence outputs (scores, recommendations, or similar derived data). Payloads may include Personal Data if your organization includes it. Delivery-service data. Email recipients and content for Mail; object metadata and files for Storage; content and brand materials for Content OS; notification addresses and message content for Notify. Technical and security data. IP address, device and browser type, approximate location derived from IP, logs, cookies, session identifiers, and API request metadata (who called which API, when, for which organization, on which resource, and with what result). Communications. Messages you send to contact@pcampus.studio or through our forms. We do not sell or rent Personal Data.

Data classification we apply

For governance we treat information in four layers: - System metadata (event IDs, timestamps, schema version) — needed to operate the platform - Business data (orders, products, accounts, transactions, business state) — used for Context and Story - Personal Data (name, phone, email, or other identifiers of a natural person) — processed only for a defined purpose, with access, retention, and deletion controls - Derived / Intelligence data (scores, segments, recommendations, risk signals) — decision support, not a substitute for your professional judgment Personal Data should not be treated as interchangeable with Business Context. We design so that Business Facts can remain useful while Personal Data is limited, unlinked, or deleted when the purpose ends, where the product supports that.

How we use information

We use information to: - Create and secure accounts, organizations, roles, and API credentials (PIP) - Provide Console, PBCP (Event → Context → Story → Intelligence), Pulse, and enabled commercial services - Isolate one organization’s data from another (tenant isolation) - Authenticate, authorize, rate-limit, and detect abuse - Bill organizations, prevent fraud, and keep financial records - Improve reliability, documentation, and product quality using aggregated or non-identifying signals where possible - Communicate service, security, and (only with a lawful basis or consent) product updates - Comply with law, enforce these terms, and protect rights, safety, and security - Handle data-subject and customer requests We do not use customer Business Events to train public foundation models as a default product feature. If a future feature would use customer data to improve models, we will describe it and obtain the required agreement or instruction first. Intelligence outputs are generated from Context that itself traces to Evidence. They are decision support. They are not legal, financial, medical, or compliance advice.

Lawful basis (PDPA)

Depending on the processing, we rely on: - Contract — to provide the account, platform, APIs, and paid services you request - Legitimate interests — security, fraud prevention, service improvement that does not override your rights - Legal obligation — tax, accounting, and lawful requests - Consent — where required (for example certain marketing cookies or optional communications). You may withdraw consent without affecting processing that does not rely on consent When we act as Processor, the customer organization is responsible for its own lawful basis (including notices to its employees, customers, or other data subjects) before it sends Personal Data to Pcampus.

Tenant isolation and access control

Pcampus is a multi-organization platform. One organization must not access another organization’s data. Access is scoped by organization, user, role, service, API credential, and resource. Authentication is provided through PIP. Production changes to authentication, authorization, or tenant boundaries require human approval in our operating process. You must keep credentials secret, assign least-privilege roles inside your organization, and revoke access when people leave.

Security measures

We apply technical and organizational measures appropriate to the risk, including: - HTTPS on public hostnames - Authentication and authorization through PIP - Tenant scoping of events, context, and commercial-service data - Input validation at ingest; events that fail the contract are rejected rather than silently “fixed” - Secrets kept out of source repositories; production secret changes require authorization - Append-only storage of accepted Business Events so evidence can be traced (Evidence → Story → Trust) We do not claim that every datastore currently has independently certified encryption-at-rest, a tested restore drill, or a completed PDPA operating program (records of processing, tested breach playbooks, and field-level retention registries). We work toward those production-readiness controls. Do not treat this policy as an ISO, SOC, or PDPA certification. No method of transmission or storage is perfectly secure. You use the services at your own residual risk and must maintain security on systems you control (source applications, endpoints, and staff devices).

Sharing and subprocessors

We share information only as needed to operate the business: - Infrastructure and hosting providers - Payment processors for organization billing (card data handled by the processor) - Email and transactional-mail infrastructure when Mail or account messages are used - Identity providers you choose (for example Google or GitHub sign-in) - Professional advisers (legal, accounting) under confidentiality - Authorities when required by law - A successor in a merger or asset transfer, with notice where required We do not sell Personal Data. Processors are held to confidentiality and purpose limitation. A current subprocessors list is available on request at contact@pcampus.studio.

International transfers

Infrastructure and subprocessors may process data outside Thailand. Where PDPA requires a transfer mechanism, we use contractual and technical safeguards appropriate to the transfer. By using the services, organizations instruct us to process in the locations needed to deliver the product, as described in the order or DPA if one is signed.

Cookies and similar technologies

Our public website uses essential cookies for security and core behavior. Non-essential cookies are used only if you accept them. See our Cookie Policy at https://pcampus.studio/cookie-policy. Console and platform sessions use cookies or tokens strictly needed to keep you signed in and to protect the account.

Retention and lifecycle

We retain information for as long as needed for the purpose, including: - Account and billing records for the life of the organization relationship plus a period required for tax, dispute, and security logs - Accepted Business Events as evidence (append-only). Deletion of Personal Data in this layer may be implemented as unlinking, redaction, or anonymization so that remaining Business Facts can still be traced without keeping unnecessary identifiers — where the product supports that path - Backup copies until they rotate, which may lag primary deletion - Derived Intelligence only as needed for the service you enabled When an organization closes its account, we stop active processing and delete or anonymize Personal Data within a reasonable period except where law requires retention or where residual backups have not yet expired.

Your rights (PDPA)

If we are the Controller of your Personal Data (for example your Pcampus login email), you may request: - Access and a copy of your Personal Data - Correction of inaccurate or incomplete data - Erasure or restriction where the law allows - Objection to certain processing - Withdrawal of consent where processing is based on consent - Data portability where technically feasible - A complaint to the Personal Data Protection Committee (PDPC) of Thailand Send requests to contact@pcampus.studio. We may need to verify your identity. We will respond within the period required by PDPA. If we are the Processor (your data sits in a customer organization’s tenant), we will direct you to that organization or assist the organization as required by our processor obligations. We cannot lawfully treat a data-subject request as an instruction to wipe another organization’s Business Context without the Controller’s authority.

Children

The platform and studio website are intended for business users. We do not knowingly collect Personal Data from children under 20 years of age (or the age of majority in your jurisdiction, if higher). If you believe we have, contact us and we will delete it.

Customer responsibilities

Organizations using PBCP and commercial services must: - Send only data they are allowed to process - Minimize Personal Data in Event payloads - Configure roles and API keys with least privilege - Not use Intelligence outputs as the sole basis for legally significant decisions about individuals without human review and a lawful basis - Keep their own privacy notices accurate toward their employees, customers, and other data subjects

Third-party sites and sign-in

Links to third-party sites, and sign-in via Google or GitHub, are governed by those parties’ policies. We are not responsible for their practices.

Changes

We may update this Privacy Policy. The “Last updated” date on this page will change. Material changes will be posted here. Continued use after the update constitutes acceptance where permitted by law. If PDPA requires consent again, we will ask for it.

Contact

Privacy and data-protection requests: contact@pcampus.studio Website: https://pcampus.studio Related: Terms of Service at https://pcampus.studio/terms-of-service