Data Protection

Privacy Policy

How Dev Cascade Base Co., Ltd. collects, processes, protects, and handles personal and technical data in compliance with Thailand PDPA and global standards.

Last Updated: August 2026

Dev Cascade Base Co., Ltd. (“Dev Cascade Base,” “we,” “us,” or “our”) is committed to protecting your privacy and handling your data with rigorous technical discipline. This Privacy Policy describes our practices regarding the collection, processing, storage, and transfer of information through our website (dev-cascadebase.click) and our professional consulting communications.


1. Data Controller Information

The data controller responsible for the processing of personal data collected under this policy is:

Dev Cascade Base Co., Ltd.
Office 7, 73 Test Street, Nakhon Ratchasima 00000, Thailand
Telephone: +66 44 000 329
Email: info@dev-cascadebase.click
Data Protection Inquiries: privacy@dev-cascadebase.click


2. Categories of Information We Collect

A. Information You Provide Directly

When you submit an audit scoping brief, schedule a consultation, or communicate with us via email, we may collect:

  • Contact Details: Full name, corporate email address, phone number, and company/organization name.
  • Technical Project Information: Application stack specifications (e.g. Swift, Kotlin, React Native), approximate user scale (MAU), and technical problem descriptions.
  • Billing Details: Corporate legal name, registered tax ID, and billing address for contract invoicing.

B. Information Collected Automatically

When you navigate our public website, our servers and lightweight client telemetry scripts may automatically record:

  • Technical Log Data: IP address (anonymized at ingestion), browser user-agent string, operating system type, referring URL, and timestamps.
  • Aggregate Navigation Metrics: Page view sequences, session durations, and interaction timestamps (collected solely on an aggregate basis if cookie consent is granted).

In compliance with the Personal Data Protection Act (PDPA) B.E. 2562 (2019) of Thailand and the EU General Data Protection Regulation (GDPR), we process your personal data under the following lawful bases:

  1. Performance of a Contract: Processing required to evaluate project scope, draft Statements of Work, deliver consulting reports, and manage invoicing.
  2. Legitimate Interests: Processing required to maintain server security, prevent fraudulent bot traffic, and optimize technical website performance.
  3. Consent: Processing of aggregate measurement cookies where you have explicitly opted in via our cookie consent banner.
  4. Legal Compliance: Retention of financial records and corporate communications as mandated by Thai statutory taxation and accounting laws.

4. Data Retention Periods

We maintain personal and technical data only for as long as strictly necessary:

  • Inquiry & Scoping Submissions: Retained for twenty-four (24) months following the last communication if no consulting contract is executed.
  • Client Project Files & Sanitized Schemas: Retained for thirty-six (36) months following project completion to support warranty verification and technical handover questions, after which data is securely purged.
  • Statutory Financial Records: Retained for five (5) to seven (7) years in accordance with Thai corporate tax legislation.
  • Server Access Logs: Automatically overwritten or permanently deleted every ninety (90) days.

5. User Rights Under PDPA & GDPR

As a data subject, you hold specific statutory rights regarding your personal data:

  • Right to Access: Request confirmation of whether we hold your personal data and obtain a copy.
  • Right to Rectification: Request correction of inaccurate or incomplete personal information.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data where retention is no longer legally justified.
  • Right to Restriction of Processing: Request temporary suspension of data processing during dispute resolution.
  • Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format.
  • Right to Object / Withdraw Consent: Withdraw previously granted consent at any time without affecting the lawfulness of processing prior to withdrawal.

To exercise any of these rights, contact our Data Protection team at privacy@dev-cascadebase.click or via physical mail to our Nakhon Ratchasima office.


6. International Data Transfers

As an engineering practice based in Thailand serving global clients, technical communications may be routed through secure cloud service providers with data centers located in the European Union, Singapore, or the United States. We ensure all international data transmissions are protected through standard contractual clauses (SCCs) and robust TLS 1.3 encryption.


7. Security Safeguards

We implement strict technical and organizational safeguards to protect data against unauthorized access, loss, alteration, or disclosure, including:

  • Mandatory TLS encryption across all web traffic.
  • Strict least-privilege role-based access controls for consulting personnel.
  • Regular security reviews and strict non-disclosure obligations for all technical team members.

8. Updates to This Policy

We may periodically revise this Privacy Policy to reflect evolving technical practices or regulatory requirements. Any updates will be published on this page with an updated revision date.