Legal

Privacy Policy

Last Updated: [●]

CSI Bangkok Co., Ltd. (“CSI Bangkok”, “Company”, “we”, “our”, or “us”) is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how the Company collects, uses, stores, processes, and discloses personal data through the Eagle Eye platform, websites, applications, plugins, AI-powered features, subscriptions, cloud services, and related services (collectively, “Services”) operated by CSI Bangkok.

By accessing, registering, or using the Services, communicating with the Company, or otherwise providing Personal Data to the Company, you acknowledge that your Personal Data may be processed in accordance with this Privacy Policy. This Privacy Policy should be read together with the Company's Terms and Conditions.

Collection of Personal Data

The Company may collect Personal Data through the following channels:

(a) Directly from you when you:

  • register for an account on the Eagle Eye platform;
  • submit information through the website, including the Contact Us page;
  • register for, subscribe to, or purchase applications, packages, or related services; or
  • communicate with the Company through email or other communication channels.

(b) Automatically

When you access or use the Eagle Eye platform, website, applications, or related services through cookies, system logs, machine hardware identifiers, software execution logs, and other automated data collection tools.

(c) Through payment transactions

Processed by authorized third-party payment service providers in connection with subscriptions, purchases, or related services.

(d) Indirectly through integrations

Through integrations with third-party engineering software, plugins, viewers, or related platforms when you choose to upload, import, process, render, share, or view project files, model data, or related information through connected Eagle Eye services or integrations, including integrations with CSI software applications.

The Company may collect, use, store, and process the following categories of personal data (collectively, “Personal Data”):

  • Your full name, gender, address and/or the name of the company, organization, or other juristic person you represent, including information relating to your authority or capacity to act on behalf of such entity. This may also include identification or verification documents where required.
  • Contact information such as telephone number or email.
  • Other personal data you provide when communicating with the Company, including inquiries, requests, feedback, support matters, or other information submitted through communication channels or the Services.
  • In case of communication via the website, may include your technical information such as IP Address, Cookies, including information about your browsing behavior.
  • User-submitted engineering design briefs, project parameters, textual prompt inputs, and associated structural files uploaded to facilitate artificial intelligence (AI) automation and analytical processing.

Collection of Sensitive Personal Data

The Company does not request, require, or intentionally collect, use, or disclose personal data classified as sensitive under applicable data protection laws, including, without limitation, data relating to racial or ethnic origin, religious or philosophical beliefs, criminal records, trade union membership, health information, biometric data, genetic data, or other categories of sensitive personal data (collectively, “Sensitive Personal Data”).

If you choose to provide, or permit others to provide on your behalf, any Sensitive Personal Data through the Services, you do so at your own discretion and responsibility and represent that you have obtained all necessary rights, consents, and authorizations required under applicable law. You further agree not to provide any personal data relating to a third party unless you have fully complied with all applicable legal requirements, including obtaining any necessary consents or permissions.

Collection of Children's Data

The Services are intended for a general audience and are designed for individuals who have reached the minimum legal age required to enter into a legally binding agreement under applicable law. The Company does not knowingly collect Personal Data from children in connection with the Services.

If you become aware that a child has provided Personal Data to the Company without appropriate authorization or in circumstances not permitted by applicable law, please contact us using the contact information provided below. Upon becoming aware of such circumstances, we will take reasonable steps to investigate the matter and, where appropriate, delete the relevant Personal Data or take such other actions as may be required under applicable law.

Storage and Purposes of Processing Personal Data

Personal Data collected by the Company may be stored and processed in Thailand, and in any other jurisdiction where the Company or its affiliates, subsidiaries, or service providers operate facilities.

The Company may collect, use, store, process, and disclose Personal Data for the following purposes:

  • To validate personal identity as necessary to fulfil the Company contract with you.
  • To create, manage, secure, and maintain your accounts on the Eagle Eye platform.
  • To provide access to the Eagle Eye platform, applications, subscriptions, services, and related functionalities requested by you.
  • To process payments, manage billing activities, verify transactions, prevent fraudulent activity, and maintain financial, accounting, and transaction records relating to the Services.
  • To communicate with you regarding account-related matters, service updates, technical support, inquiries, troubleshooting, customer support, and other matters relating to the use of the Services.
  • To monitor, analyze, improve, develop, maintain, and secure the Eagle Eye platform, websites, applications, Services, system performance, user experience, and related operational functionality.
  • To detect, investigate, prevent, or address security incidents, unauthorized access, fraudulent activity, misuse of the Services, or violations of applicable terms, policies, or laws.
  • To comply with applicable laws, regulations, legal processes, governmental requests, accounting obligations, tax requirements, and regulatory obligations.
  • To establish, exercise, protect, or defend the legal rights, safety, property, or legitimate interests of the Company, its users, or other relevant parties.
  • Subject to your consent where required under applicable laws, to provide marketing communications, newsletters, promotional materials, updates, or other information relating to the Company's Services.

Third Party Services

The Company may engage third-party service providers to support the provision of the Services, including but not limited to providers of integrations, plugins, APIs, model viewers, AI-powered features, payment services, cloud services, or related functionality provided by third-party providers or external Services (collectively as the “Third Party Services”). The Company's service providers may change periodically as its business and operational requirements evolve. The current list of material service providers is available upon request.

Please note that this Privacy Policy applies only to the Personal Data that the Company collects, uses, and discloses through the Services.

Certain third-party service providers may independently collect, receive, store, process, use, or disclose information in connection with the services they provide. Such activities may be governed by the privacy policies and terms of those third parties. To the extent permitted by applicable law, the Company is not responsible for the privacy practices of such third parties, and we encourage you to review their applicable privacy policies and terms.

Transfers or Disclosures of Personal Data to Other Countries

To the extent that the provision of the Services involves the transfer or disclosure of Personal Data to any country in which the Company operates or engages service providers, such transfer or disclosure may include destinations outside your region or country of residence, where data protection laws may differ from those applicable in your country of residence.

In certain circumstances, courts, law enforcement agencies, regulatory authorities, or security authorities in such countries may be entitled to access your Personal Data.

The Company will take appropriate measures to ensure that any overseas recipient applies adequate standards of Personal Data protection, or otherwise that such transfer or disclosure of your Personal Data is carried out in compliance with applicable laws and this Privacy Policy.

You acknowledge that, by providing us with your Personal Data, you consent to such overseas transfer or disclosure. By consenting to such transfer or disclosure, you further acknowledge that, to the extent permitted by applicable law, the Company shall not be liable, and you shall not have any right of action against the Company, in respect of any act or omission of an overseas recipient that results in a breach of your Personal Data.

Retention Period of Personal Data

The Company retains personal data only for as long as necessary to provide the Services, fulfills the purposes described in this Privacy Policy, complies with applicable legal obligations, and resolves disputes where necessary.

Certain integration-related data, including project or model information processed through connected third-party software integrations, may be retained where necessary for platform functionality, security, technical support, legal compliance, dispute resolution, or related operational purposes.

When the Company no longer requires your Personal Data for any of the purposes described above, the Company will erase, destroy, anonymize, or otherwise process such Personal Data in accordance with applicable personal data protection laws to ensure effective protection of Personal Data, unless its retention is required or otherwise permitted under applicable law, including for legitimate business or other lawful purposes.

Disclosure of Personal Data

The Company does not sell or unlawfully disclose your personal data to third parties. However, the Company may disclose personal data where necessary for the purposes described in this Privacy Policy, including but not limited to the following circumstances:

  • To the Third Party Services. Such disclosure will be limited to the extent necessary for the provision of the relevant services.
  • To law enforcement authorities, legal counsel, or other parties where the Company reasonably determines that such disclosure is necessary to: (a) comply with applicable laws, regulations, legal processes, or lawful governmental requests; (b) enforce or apply the Company's terms and conditions; (c) establish, exercise, or defend the rights of the Company, its personnel, customers, or other persons; (d) prevent, investigate, or respond to fraud, security incidents, or unlawful activities; or (e) protect the rights, property, or safety of the Company, its customers, or the public. To government authorities, regulators, law enforcement agencies, courts, tribunals, or other parties where disclosure is required or permitted under applicable laws or legal processes.
  • To other parties where you have provided your consent to such disclosure or have directed the Company to disclose your Personal Data for purposes requested or authorized by you.
  • The Company may also use or share aggregated or de-identified information for analytics, research, service improvement, or business reporting purposes, provided that such information cannot reasonably be used to identify you.

Data Subject Rights

The Company respects your rights as a data subject under applicable laws. Subject to applicable legal conditions and limitations, you may contact the Company through the designated channels to exercise the following rights:

  • the right to withdraw consent at any time, where processing is based on consent; provided that such withdrawal shall not affect the lawfulness of processing carried out prior to the withdrawal of consent;
  • the right to access your personal data and obtain information regarding the collection, use, and disclosure of your Personal Data, as permitted by law;
  • the right to request a copy of your Personal Data, subject to applicable legal restrictions;
  • the right to request correction of inaccurate, incomplete, misleading, or outdated Personal Data;
  • the right to request data portability, including the transfer of your Personal Data to another data controller, where technically feasible and where required by applicable law;
  • the right to request the deletion, destruction, or anonymization of your Personal Data where there is no lawful basis for continued processing or where such right is otherwise available under applicable law;
  • the right to request restriction or suspension of the processing of your Personal Data in circumstances prescribed by applicable law; and
  • the right to lodge a complaint with the relevant supervisory authority or other competent authority if you believe that the Company's processing of your Personal Data violates applicable law.

The Company reserves the right to refuse a request to exercise any of the above rights where permitted or required by applicable law, where compliance with the request would prevent or materially affect the performance of the Company's contractual obligations, where compliance would adversely affect the rights and freedoms of others, where compliance would be contrary to applicable law or the Company's information security requirements, or where compliance is not reasonably practicable due to technical limitations. The Company will record any such refusal together with the reasons therefor, as required by applicable law.

Please note that certain rights may be subject to limitations where the relevant Personal Data is necessary for the Company to comply with its legal obligations, maintain the security of its operations, or protect its assets.

Security Measures

The Company implements reasonable technical, organizational, and administrative security measures designed to protect Personal Data against unauthorized access, use, disclosure, alteration, loss, destruction, or other unlawful processing. The Company may review and update its security measures from time to time in accordance with operational, technical, and legal requirements.

The Company takes reasonable steps to limit access to Personal Data to those employees, contractors, agents, and authorized personnel who have a legitimate need to access such information in order to perform their assigned duties. The Company also limits the collection of Personal Data to that which is reasonably necessary for the provision of the Services.

Personal Data Breach

In the event of a Personal Data Breach, the Company will promptly investigate the incident, implement appropriate remedial measures, and notify the relevant authorities and affected individuals where required under applicable law.

Governing Law

This Privacy Policy and any disputes arising out of or relating to the Services shall be governed by and construed in accordance with the laws of the Kingdom of Thailand, without regard to conflict of law principles.

To the maximum extent permitted under applicable laws, any dispute, claim, or legal proceeding arising out of or relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the competent courts located in Bangkok, Thailand.

Amendments to this Privacy Policy

The Company reserves the right to amend, review, or update this Privacy Policy from time to time. Any such amendments, revisions, or updates shall become effective upon publication without prior notice.

The Company makes such changes to ensure that this Privacy Policy remains appropriate and effective in connection with the provision of the Services. Accordingly, the Company recommends that you review this Privacy Policy each time you visit or use the Services or the Company's website to ensure that you are aware of the current version.

Cookies

The Company uses cookies and similar technologies to operate, maintain, improve, and secure the Services. For more information about how the Company uses cookies and the choices available to you, please refer to the Company's Cookie Policy.

Company Contact Information

Data Protection Officer

Name: Ms. Suthathip Thanakorn

Address: BOI Science and Technology Park, Asian Institute of Technology, 58 Moo 9, Klongnueng, Klongluang, Pathumthani 12120, Thailand

Email: [email protected]

Phone: +66-638247272