This policy summarizes how TM3P TECH Co., Ltd. handles your data. Full legal detail lives in the PDPA notice.
Our principles
- Collect only what we need to deliver the service
- Encrypt sensitive identifiers (Thai national ID, passport) at the column level
- Isolate every clinic’s data with Postgres row-level security
- Do not sell data to third parties
- Erase PII on request, retaining only what the law requires us to keep
Security
HTTPS in transit; Supabase TLS + at-rest encryption; column-level encryption for ID numbers; clinic-level isolation enforced by row-level security policies.
Your rights at a glance
You may request access, correction, deletion, or object to processing. Send requests to dpo@tm3p.tech. See the PDPA notice for the full version.