Last updated: 2 September 2026
This notice applies to the ORDIS Co., Ltd. market (ocatis.ai) under the Thailand Personal Data Protection Act B.E. 2562 (2019) and is maintained in English — the working language of that Act for an international customer base. Customers in the European Union are covered by the GDPR privacy notice of itcv GmbH.
The data controller for the ocatis.ai market is ORDIS Co., Ltd., Phayathai Plaza, 128/196 Phayathai Road, Ratchathewi, Bangkok 10400, Thailand; e-mail: info@ordis.co.th, telephone: +66 2 1072512.
Data-subject requests under this notice are handled by ORDIS Co., Ltd. For customers inside the European Union the contract partner is itcv GmbH, Frankfurt am Main, and a separate privacy notice under the EU GDPR applies (see clause 15).
Under Section 6 of the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), “personal data” means information relating to a natural person which enables that person’s identification, directly or indirectly, excluding information of deceased persons in particular. A “data controller” is the person or juristic person having power and duties to make decisions regarding the collection, use or disclosure of personal data; a “data processor” acts pursuant to the orders of the controller and is not itself the controller.
This notice is written under the PDPA. It is not a GDPR notice: the PDPA differs from the EU GDPR in its lawful bases, duties and rights, and the two documents govern different markets.
Except where Section 24 PDPA or another law permits processing without consent, we collect, use or disclose personal data only with your consent given prior to or at the time of the processing (Section 19). Consent requests are made in writing or by clear electronic means, in easily accessible and plain language, separated from other matters, and are freely given — entering a contract is never made conditional on consent to data that is not necessary for that contract.
You may withdraw consent at any time; withdrawal is as easy as giving consent and takes effect for the future, without affecting the lawfulness of processing already carried out. Where withdrawing consent would affect you, we will inform you of the consequences.
We collect personal data only for the purposes notified to you at or before collection (Section 21) and rely on: consent (Section 19); performance of a contract with you, or steps taken at your request prior to entering into a contract (Section 24(3)); legitimate interests, unless overridden by your fundamental rights (Section 24(5)); and compliance with applicable law (Section 24(6)). The other bases of Section 24 — public archives, research and statistics (Section 24(1)), vital interests (Section 24(2)) and public-interest or official-authority tasks (Section 24(4)) — are not used in our operations.
Visiting this site processes technically necessary access data — a truncated IP address, timestamp, requested page, referrer and browser identification — so the site can be delivered and operated securely.
The site sets one cookie, NEXT_LOCALE, which stores your chosen language (“en” or “de”). It is a session cookie with no expiry (removed when the browser closes), path “/”, SameSite “Lax”, not HttpOnly. It is set or refreshed server-side when a page is requested in a language differing from the previously stored choice (including first visits), and client-side when you use the language selector; no cookie appears when the stored preference already matches.
Two values are kept in your browser’s local storage: ocatis-theme (light or dark design) and ocatis-market-seen (a flag that the notice about the other market was shown). The language itself is not stored in local storage; it travels in the URL path.
There are no marketing, advertising or tracking cookies, and the site loads no third-party scripts or measurement beacons. These entries exist only so the site can provide the service you asked for — your language, your design, without repeating notices — and are treated as necessary for that provision; consent under Section 19 PDPA is not required for them, and no consent banner is used.
We do not currently run any analytics or tracking tooling on this site. If the planned self-hosted, cookie-free reach measurement is activated, this notice will be updated beforehand.
The contact form processes name, e-mail address, company, topic and message; the demo form adds optional role, organisation size and preferred date. We use these to handle and answer your enquiry (Section 24(3) PDPA; consent under Section 19 where applicable).
For the 14-day Business trial we process first name, last name, business e-mail address, company name and the password you set — stored only as an Argon2id hash, never in plain text — to create your tenant and deliver access through a single-use activation link (Section 24(3) PDPA).
Without conversion to a paid subscription, the trial tenant becomes read-only on day 14 and is deactivated on day 44; its data is preserved for 30 days after the trial ends and then deleted, unless a retention obligation applies. One self-service owner trial per global identity per market.
We send no marketing e-mail without your separate consent — the forms contain no pre-settled option to give it. You may object to any direct marketing at any time under Section 32 PDPA, and withdraw consent under Section 19.
For in-app conversion we collect a billing profile (invoice address, contact data, tax identification, billing period, currency and seat count). It is stored and processed in our own billing portal, operated by ORDIS Co., Ltd. on its own infrastructure in the EU; checkout, payment methods, invoices, receipts and cancellation run through that portal with separate portal credentials.
Card and direct-debit payments are handled by Stripe Payments Europe Ltd., Dublin, with payment data processed only as required for the transaction. Billing records are kept for the periods required under applicable Thai accounting and revenue law (Section 24(6) PDPA).
This website does not collect personal data of the types listed in Section 26 PDPA (for example racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual behaviour or orientation, health, disability, biometric, genetic or criminal-record data). Please do not include such data in form messages.
Conversations inside a customer’s ocatis deployment may contain such categories depending on what the customer’s users enter; for that content the customer organisation is the controller and must secure its own lawful basis, normally explicit consent under Section 26.
The website, demo and trial signup are directed at business users, not minors. Where we do become aware of a data subject under 10 years of age, consent is obtained from the holder of parental responsibility (Section 20(2) PDPA); for minors aged 10 up to majority, consent of the holder of parental responsibility is also required for any act the minor may not perform alone under the Civil and Commercial Code (Section 20(1) PDPA).
For a customer’s ocatis instance, the customer is the data controller of the content it generates — conversation content, messages, file attachments, usage and token statistics, and its own end-user accounts. ORDIS Co., Ltd. does not make its own use of that content.
In a managed deployment operated by us, we act as data processor under Section 40 PDPA: we collect, use or disclose instance data only pursuant to the controller’s instructions, maintain security measures and notify the controller of any breach, and keep records of our processing. For self-hosted installations we are not involved at all, and there is no remote access without the customer’s explicit enablement.
ocatis is a bring-your-own-key platform: the customer contracts with the AI providers it uses, and tenant administrators choose which providers are available in the instance. Prompts and context data may therefore reach providers seated in the United States (for example OpenAI, Anthropic, Google); responsibility for that disclosure and its Section 28 safeguards sits with the customer. Local inference endpoints (Ollama, LM Studio) involve no cross-border transfer at all.
Recipients are Hetzner Online GmbH as hosting provider for this website and managed instances (European data centres, including Germany and Finland), our own billing portal and Stripe Payments Europe Ltd. as payment processor, plus professional advisers bound to confidentiality, and state authorities where disclosure is required by law.
Where personal data is sent or transferred outside Thailand, the destination country or international organisation must have an adequate data protection standard under the rules prescribed by the Personal Data Protection Committee pursuant to Section 28 PDPA, unless one of its exceptions applies: compliance with the law; the data subject’s consent given after being informed of the inadequate standards in the destination; necessity for a contract with the data subject or steps taken at their request before entering into it; necessity for a contract made in the data subject’s benefit between the controller and another person; protection of vital interests where the data subject cannot consent; or substantial public interest.
Section 29 PDPA additionally permits transfers under appropriate data protection measures, or under personal data protection policies certified for intra-group transfers.
Our own transfers on this website and our billing stack go to the recipients named in clause 9, which operate in jurisdictions we assess under the Section 28 standard; where a customer enables a foreign AI provider, the transfer occurs under the customer’s own provider contract.
We retain personal data only for the purposes stated in this notice. We maintain an examination system that erases or destroys personal data when the retention period ends, when the data is no longer relevant or necessary for the purpose it was collected for, when a data subject successfully requests deletion, or when consent is withdrawn and no other basis applies, consistent with Section 37(3) PDPA.
Enquiry and demo data is deleted once the enquiry is concluded; billing and accounting records are kept for the periods required by applicable Thai law. For content in a customer instance, retention follows the settings and deletion schedules the customer configures in that instance.
We implement security measures appropriate to prevent unauthorised or unlawful loss, access, use, alteration or disclosure of personal data, consistent with Section 37(1) PDPA: TLS encryption in transit, AES-256-GCM encryption of stored secrets with a tenant-bound key hierarchy, Argon2id password hashing, role-based access control, strict tenant isolation, and logging of administrative actions.
In the event of a personal data breach we notify the Office of the Personal Data Protection Committee without delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to risk the rights and freedoms of affected persons. Where the breach is likely to result in high risk, we also notify affected data subjects without delay together with remedial measures (Section 37(4) PDPA). Customers of a managed deployment are informed without undue delay so they can meet their own obligations as controllers.
Access and copy: you may request access to and obtain a copy of your personal data under our responsibility, and disclosure of how it was obtained without your consent; we fulfil requests without delay, but no later than thirty days from receipt (Section 30 PDPA).
Machine-readable copy: where your data was processed based on consent or on Section 24(3), you may receive it in a format readable by automated means and have it sent to another controller where technically feasible (Section 31 PDPA; this right does not cover public-interest or legal-obligation processing).
Correction: you may ask us to correct incomplete, inaccurate or misleading data; we are under a standing duty to keep personal data accurate, up to date, complete and not misleading (Section 35 PDPA), and where we do not grant a correction request we record the request with our reasons in the Section 39 record, with the complaint route of Section 36 in connection with Section 34 available to you.
Erasure or destruction: you may request erasure, destruction or anonymisation of your personal data where it is no longer necessary, where consent is withdrawn without another basis, after a successful objection, or where it was collected unlawfully (Section 33 PDPA, subject to its statutory carve-outs).
Restriction: you may request restriction of the use of your personal data in the situations listed in Section 34 PDPA — for example while a correction request is examined or where deletion is sought and retention is needed for legal claims.
Objection: you may object at any time to collection, use or disclosure based on legitimate interests (Section 24(5)) or for direct marketing purposes (Section 32 PDPA).
Withdrawal: consent-based processing can be stopped by withdrawing consent at any time (Section 19 PDPA).
Requests and their handling are recorded together with rejections and reasons in our Section 39 records. For personal data held in a customer’s own instance, direct the request to the customer as controller; the customer administers access, correction and deletion of its end users through its ocatis instance.
If you believe this notice or our processing violates the PDPA, you have the right to lodge a complaint with the Expert Committee (Section 73 PDPA). Please contact us first — we would rather fix the problem directly.
Where ocatis output reaches end users subject to Regulation (EU) 2024/1689, AI-generated content is labelled as required and users are informed of the AI nature of interactions where not obvious from context; the product’s current transparency scope is described on our data-protection page.
This notice applies to the ORDIS Co., Ltd. market under ocatis.ai and the Thailand PDPA. Customers in the European Union contract with itcv GmbH, whose processing is governed by a separate EU GDPR notice: Privacy policy.
Detailed technical description of the processing: Data Protection.