Data Processing Agreement
Effective date:
This is a translation of the Thai original. If the two versions conflict, the Thai version governs.
Why this document exists
Section 40, paragraph three of the Personal Data Protection Act B.E. 2562 requires a Data Controller to put in place a written agreement with its Data Processor, to govern the Processor's activities.
This document is that agreement. It forms part of the Terms of Service. By agreeing to use the service, you agree to this document.
1. Parties and roles
Data Controller (the "Controller") The legal entity or person who subscribes to TMS and creates an organization in the system.
Data Processor (the "Processor") , company registration number , .
1.1 Scope
This agreement applies to personal data the Controller enters into or generates in the system to run its own transport operations.
It does not apply to data for which the Processor is itself the Controller — registration data, billing data, support correspondence, and security logs — which are governed by the Privacy Policy.
1.2 Division of responsibility
| Matter | Controller (Customer) | Processor (Us) |
|---|---|---|
| Deciding what data to collect and why | ✅ | ❌ |
| Giving PDPA s.23 notice to data subjects | ✅ | ❌ |
| Establishing a valid legal basis | ✅ | ❌ |
| Configuring access permissions internally | ✅ | ❌ |
| Responding to data subject requests | ✅ (we provide tooling) | Assists |
| Securing the infrastructure | ❌ | ✅ |
| Securing their own user accounts | ✅ | ❌ |
| Notifying the PDPC and data subjects of a breach | ✅ | Notifies Controller within 48 h |
2. Details of processing
(Mandatory annex under PDPC guidance)
2.1 Purpose
Providing transport management software to the Controller under the Terms of Service — managing work orders, dispatch planning, assigning work to drivers, recording operational proof, and reporting.
2.2 Nature of processing
Collection, recording, storage, organisation, alteration, retrieval, use, internal transmission, backup, restriction, and deletion.
2.3 Categories of personal data
| Group | Items |
|---|---|
| Identity and contact | Name, email, telephone number, profile picture, address |
| Account and permissions | User ID, role, status, organization membership history |
| Official document data | Driving licence class, licence number, expiry date, licence document image |
| Financial data | Bank name, bank account number, account holder name, PromptPay ID, per-trip pay |
| Location data | Latitude and longitude captured when recording proof, checking a vehicle in or out, or changing a job status |
| Images and signatures | Pickup and delivery photographs, odometer photographs, vehicle condition photographs, and recipients' electronic signatures |
| Operational data | Work orders, routes, requested times, status history, delivery failure reasons |
Sensitive data under PDPA section 26 — the system is not designed to hold sensitive data and has no dedicated fields for it. The Controller agrees not to enter sensitive data into the system. If it does so in breach of this clause, the Controller bears sole responsibility for the consequences.
2.4 Categories of data subjects
- The Controller's back-office users (administrators, dispatchers)
- Drivers and vehicle assistants
- The Controller's customer contacts
- Shippers and consignees
- Individuals who may incidentally appear in proof photographs
2.5 Duration
The term of the service agreement, plus the deletion period in clause 10.
3. Processor obligations
The Processor agrees that it will:
3.1 Process only on instructions
Process personal data only on the Controller's documented instructions. The Controller's normal use of the system constitutes those instructions.
The sole exception is where Thai law compels processing, in which case the Processor will inform the Controller beforehand unless the law prohibits it.
If the Processor considers an instruction to breach the PDPA, it will inform the Controller immediately and may suspend that instruction until the matter is resolved.
3.2 Not use data for its own benefit
Not sell, rent, use for its own marketing, or use to train artificial intelligence models, whether its own or a third party's.
The Processor may use anonymised aggregate statistics to improve the service, provided they cannot be traced back to the Controller or any data subject.
3.3 Maintain confidentiality
Restrict access to personnel who need it, and bind all personnel to confidentiality obligations that survive the end of their engagement.
3.4 Implement security measures
Maintain appropriate measures under PDPA section 37(1) and the PDPC Notification on Security Measures B.E. 2565, as set out in Annex B.
3.5 Assist the Controller
Provide reasonable assistance with:
- Responding to data subject requests
- Data protection impact assessments
- Breach notification to the regulator and data subjects
- Consultations with the regulator
Where a request requires disproportionate engineering effort, the Processor may charge its actual cost, having first provided an estimate and obtained approval.
3.6 Forward requests received directly
If a data subject contacts the Processor directly to exercise rights over data the Controller controls, the Processor will not respond to the substance of the request. It will forward the request to the Controller within 7 days and tell the data subject where it was sent.
4. Controller obligations
The Controller represents and warrants that:
- It has a valid legal basis for collecting and processing every item of personal data entered into the system.
- It has given complete PDPA section 23 notice to data subjects, including notice that this Processor is engaged.
- For driver location data, it has clearly informed drivers and, where relying on legitimate interest, has documented a Legitimate Interest Assessment in writing.
- For recipients' signatures and photographs, it has informed those individuals that the records are captured and for what purpose.
- It will not enter sensitive data under section 26 into the system.
- It will configure and periodically review access permissions within its own organization, and revoke access for departing users without undue delay.
- It will keep its user accounts secure and will not permit account sharing.
The Controller agrees to indemnify the Processor against claims or fines arising from its failure to comply with items 1 to 5 above.
5. Sub-processors
5.1 General authorisation
The Controller gives general authorisation for the Processor to engage the sub-processors listed in Annex A.
5.2 Adding or changing sub-processors
The Processor will give at least 30 days' prior notice before adding or changing a sub-processor.
The Controller may object on reasonable data protection grounds within 30 days. The parties will then discuss in good faith; if no resolution is found, the Controller may terminate and receive a pro-rata refund of unused prepaid fees.
5.3 Liability
The Processor must bind sub-processors to obligations no less protective than this agreement, and remains liable to the Controller for their acts as if they were its own.
6. International transfers
The Processor may transfer data to sub-processors outside Thailand as listed in Annex A, complying with PDPA sections 28 and 29 and the PDPC Notification on Criteria for Cross-Border Transfer of Personal Data B.E. 2566.
The safeguard relied on is Standard Contractual Clauses signed with each sub-processor. The Controller may request copies of the evidence at .
7. Personal data breaches
7.1 Notification
The Processor will notify the Controller without undue delay and no later than 48 hours after becoming aware of a breach affecting the Controller's data.
The 48-hour window is deliberately shorter than the statutory 72 hours, so that the Controller retains enough time to notify the PDPC under PDPA section 37(4).
7.2 Contents of the notification
So far as known at the time: the nature of the breach, the categories and approximate volume of data affected, the categories of data subjects affected, likely consequences, measures already taken, and a contact point for further information.
Where details are incomplete, the Processor will notify what it knows and follow up. It will not wait for complete information before notifying.
7.3 Cooperation
The Processor will cooperate in investigating, containing, and documenting the breach, and will supply information needed to notify data subjects.
The Processor will not notify data subjects directly or make a public statement without the Controller's prior agreement, unless the law compels it.
8. Audit
8.1 Documentation
The Processor will supply information reasonably necessary to demonstrate compliance — a summary of security measures, summary penetration test results, or third-party audit reports where available.
8.2 On-site audit
Where clause 8.1 is insufficient, the Controller may audit no more than once per year, on at least 30 days' notice, during normal business hours, with auditors bound by confidentiality.
The Controller bears the cost, unless the audit finds a material failure by the Processor to comply with this agreement, in which case the Processor bears it.
The frequency limit does not apply where an actual breach has occurred or a regulator directs an audit.
9. Records of processing activities
The Processor will maintain records of processing activities under PDPA section 40(3) and provide them to the Controller or the regulator on request.
10. Return and deletion of data
On termination of the service agreement for any reason:
| Timing | What happens |
|---|---|
| Termination date | System access suspended; data retained |
| Within 30 days | Controller may export data through the system's export functions, or request delivery in machine-readable form |
| Within 90 days | Processor deletes all data from production systems |
| Within 180 days | Data removed from backups, following the backup rotation cycle |
Exception — the Processor may retain data where Thai law requires, such as computer traffic data under Computer Crime Act section 26 and accounting records under the Revenue Code. Retained data is access-restricted and used only for that statutory purpose.
The Processor will issue written confirmation of deletion on request.
11. Liability
Liability under this agreement is subject to the limitation of liability in clause 11 of the Terms of Service, except where the law does not permit limitation.
Where both parties are liable to a data subject or regulator, each bears liability in proportion to its responsibility under clause 1.2.
12. Conflicts
Where this agreement conflicts with the Terms of Service or Privacy Policy on a data protection matter, this agreement prevails.
Annex A — Sub-processors
Last updated:
| Provider | Service | Data processed | Processing location | Transfer mechanism |
|---|---|---|---|---|
| Amazon Web Services, Inc. | System and database hosting, transactional email (SES) | All system data, email addresses, OTP codes | ap-southeast-1 (Singapore) | Standard Contractual Clauses (AWS DPA) |
| Cloudflare, Inc. | File storage (R2) and network services | Proof photographs, documents, signatures | Global / auto |
Standard Contractual Clauses (Cloudflare DPA) |
| Google LLC | OAuth login and Maps Platform | Email, name, profile picture, searched addresses and coordinates | United States | Standard Contractual Clauses (Google Cloud DPA) |
| LINE Corporation | LINE login | LINE user ID, name, profile picture | Japan / Thailand | Standard Contractual Clauses |
| ThaiBulkSMS | SMS OTP delivery | Telephone number | Thailand | No cross-border transfer |
| Expo, Inc. | Mobile app distribution and updates | Device data and app version | United States | Standard Contractual Clauses |
Note for the document owner: before publishing, verify that a DPA has actually been signed with every provider in this table and that the evidence is retained. If not, the "Transfer mechanism" column states something untrue — a legal and reputational risk.
Annex B — Security measures
Under the PDPC Notification on Security Measures B.E. 2565
B.1 Organizational measures
- Access granted on the principle of least privilege
- Personnel and contractors bound by confidentiality agreements
- Periodic review of access rights; immediate revocation when personnel depart
- A defined breach response process with named responsibility
B.2 Technical measures
Access control
- Authentication using time-limited tokens with a separate refresh mechanism
- Two-step verification by SMS or email OTP at defined points
- Role-based access control enforced at the endpoint level
- Tenant isolation between organizations at the database level
Encryption
- Data encrypted in transit using TLS
- Passwords stored as bcrypt hashes; never stored in recoverable form
- In the mobile app, tokens stored in OS-encrypted storage (iOS Keychain / Android Keystore)
File storage
- Object storage is not publicly accessible
- File access requires a digitally signed link that expires within 15 minutes
Abuse prevention
- Per-user and per-IP rate limiting
- Input validation at every entry point
Logging and audit
- Access logging with trace identifiers
- Computer traffic data retained for at least 90 days under Computer Crime Act section 26
Availability
- Regular backups with periodic restoration testing
B.3 Review
The Processor reviews these measures at least annually and on any significant system change.
Measures may be improved at any time, but will not be reduced below the level stated in this Annex.
Execution
The Controller's acceptance of the Terms of Service and commencement of use constitutes acceptance of this agreement; no separate signature is required.
If your organization requires a counter-signed copy, contact .
This document exists in Thai and English. If they conflict, the Thai version governs.