This policy explains how ENTGROUP ("we") collects, uses and protects personal data when you use Aloha Digital Signage, under Thailand’s Personal Data Protection Act B.E. 2562 (PDPA).
At a glance
We collect only what we need to run the Service, invoice you and keep it secure
We never sell data and use no advertising cookies
Every business gets its own separate database
Marketing emails only with your consent, which you can withdraw any time
Use your PDPA rights by email — we reply within 30 days
This summary is for convenience; the full text below governs.
1. Our role
We are the data controller for account, billing, usage and security logs, enquiries and marketing data.
For personal data inside Customer Content (photos of people, names on boards, wayfinding or announcements) the customer is the controller and we are a processor acting only on its instructions — the customer’s own privacy notice applies.
The Service uses no cameras or face recognition and does not identify people watching screens.
2. What we collect
Accounts: name, email, business and branch name, role, password (stored only as a hash) and two-step verification data.
Billing: taxpayer name, tax ID, address, invoices and transfer slips. Card payments are processed by Stripe; we never store full card numbers.
Usage and devices: IP address, browser, player IDs, online status, play logs, audit logs (who changed what, when) and system logs.
Enquiries: name, company, email, phone, LINE ID and your message from our forms.
Consents and acceptances: document version, time, IP and browser when you mark to accept.
3. Purposes and legal bases
Providing the Service, creating accounts, pairing screens and support — contract.
Invoices, tax invoices and accounting — legal obligation.
Security, fraud prevention, audit logs and Computer Crime Act records — legitimate interest and legal obligation.
Improving the Service from aggregate statistics — legitimate interest.
News, promotions and product updates — consent (separate from sign-up; you can use the Service without it).
Answering enquiries from our forms — pre-contract steps and legitimate interest.
If you do not give the data we need, we may be unable to create your account, provide the Service or issue tax invoices.
4. Who we share with
Service providers acting for us under contract: cloud hosting and databases (such as Vercel and Neon), file storage, email delivery (Resend), payments (Stripe, and banks for PromptPay), and AI and speech providers when you use those features.
Professional advisers, auditors, and authorities where the law requires.
A buyer or successor in a merger or transfer of the business, bound to protect data under this policy.
We do not sell personal data.
5. International transfers
Some cloud providers store or process data outside Thailand, such as in Singapore and the United States. We transfer data under PDPA sections 28–29 and the related PDPC notifications, using standard contractual clauses or other appropriate safeguards, or where the transfer is needed to perform our contract with you.
6. How long we keep data
Account data and content: while you use the Service, then deleted after the 30-day export window that follows cancellation.
Accounting and tax records: for the periods the Revenue Code and accounting law require.
Computer traffic data: at least 90 days, or longer if lawfully ordered.
Records of acceptance and consent: for the life of the contract plus the legal limitation period.
Marketing data: until you withdraw consent. Enquiries that do not become customers: up to 2 years.
7. Security
Encrypted connections (HTTPS), and passwords stored as one-way hashes.
A separate database for each business, role-based permissions, two-step verification and an audit trail of changes.
If a breach poses a risk, we notify the PDPC within 72 hours of becoming aware, and tell affected people without undue delay when the risk is high.
8. Your rights
Access or get a copy of your data, and receive or transfer it in a machine-readable format.
Correct it, have it deleted or anonymised, or restrict its use.
Object to processing (including direct marketing, at any time) and withdraw consent.
Complain to the Office of the Personal Data Protection Committee (PDPC).
Email entgroupchannel@gmail.com. We will verify your identity and reply within 30 days. Some rights have legal limits — for example tax records we must keep.
9. Data we process for customers
If you appear in content on a customer’s screens, please contact that business directly. We help customers respond to requests, process data only on their instructions, keep it confidential, use sub-processors held to the same standard, report breaches to the customer without undue delay, and delete or return data when the service ends.
10. Cookies and browser storage
We use only essential cookies and browser storage — sign-in state, language and display preferences. Players keep a copy of content for offline playback. We use no advertising or cross-site tracking cookies.
11. Minors
The Service is for businesses and not intended for anyone under 20. Customers who display images or data of minors (for example, schools) must have consent from a parent or guardian as the law requires.
12. Changes to this policy
We may update this policy and will tell you by email or in the app about material changes. The current version always shows its date at the top.