คุณเลขา KHUNLEKA
ข้อกำหนดความเป็นส่วนตัว

English version below · ฉบับภาษาไทยเป็นฉบับที่มีผลทางกฎหมาย

PRIVACY POLICY

นโยบายความเป็นส่วนตัว

เวอร์ชัน 5 · มีผลตั้งแต่ 11 ตุลาคม 2569

ห้างหุ้นส่วนจำกัด โอที ฟิวเจอร์ (“เรา”) เป็นผู้ควบคุมข้อมูลส่วนบุคคลของบริการคุณเลขา (KhunLeka) ทั้งเว็บไซต์ khunleka.com และแอป app.khunleka.com นโยบายนี้อธิบายว่าเราเก็บข้อมูลใด ใช้เพื่ออะไร เปิดเผยให้ใคร เก็บนานเท่าไร และคุณใช้สิทธิ์ได้อย่างไร ตามพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA)

  1. หลักสำคัญ: พื้นที่ส่วนตัวเข้ารหัส
  2. ข้อมูลที่เราเก็บ
  3. ข้อมูลจาก Google และ Microsoft (บัญชีที่เชื่อมต่อ)
  4. ข้อมูลอ่อนไหว
  5. ข้อมูลของบุคคลอื่นที่คุณบันทึกหรือส่ง
  6. วัตถุประสงค์และฐานทางกฎหมาย
  7. ผู้ประมวลผลที่เราเปิดเผยข้อมูลให้
  8. การส่งข้อมูลไปต่างประเทศ
  9. คุกกี้และสถิติการใช้งาน
  10. ระยะเวลาเก็บรักษา
  11. สิทธิของคุณ
  12. ความปลอดภัย
  13. ผู้เยาว์
  14. การเปลี่ยนแปลงนโยบายและการติดต่อ

1. หลักสำคัญ: พื้นที่ส่วนตัวเข้ารหัส

ข้อมูลชีวิตที่คุณบันทึก (นัดหมาย งาน โน้ต ทรัพย์สิน การเงิน เอกสาร สัตว์เลี้ยง ประวัติแชต อีเมลใน e-docs และข้อมูลที่ซิงก์จากบัญชีที่เชื่อมต่อ) ถูกเข้ารหัสด้วยกุญแจที่คุณถือบนอุปกรณ์ของคุณ ทีมงานและเซิร์ฟเวอร์ของเราเปิดอ่านเนื้อหาที่จัดเก็บไม่ได้ บางฟีเจอร์ต้องให้เซิร์ฟเวอร์เห็นเนื้อหาชั่วขณะเพื่อทำงาน เช่น ส่งข้อความให้ AI ตอบ ส่งอีเมล หรือดึงข้อมูลจาก Google ในกรณีนั้นเนื้อหาถูกประมวลผลในหน่วยความจำเท่านั้น และถูกเข้ารหัสด้วยกุญแจของคุณก่อนจัดเก็บ

แม้เราอ่านเนื้อหาที่เข้ารหัสไม่ได้ เราถือว่าเราเป็นผู้ควบคุมข้อมูลส่วนบุคคลและประมวลผลข้อมูลทั้งหมดนี้ เพราะระบบของเราเป็นผู้จัดเก็บ ส่งต่อ และถอดรหัสข้อมูลบนอุปกรณ์ของคุณ นโยบายนี้และสิทธิ์ทั้งหมดของคุณจึงใช้กับข้อมูลที่เข้ารหัสด้วย

2. ข้อมูลที่เราเก็บ

  • บัญชี: อีเมล สถานะยืนยันอีเมล รหัสผู้ใช้ เวลาสร้างบัญชีและเข้าสู่ระบบล่าสุด เมื่อเข้าสู่ระบบด้วย Google: ชื่อ อีเมล รูปโปรไฟล์ และรหัสบัญชี Google (เราไม่ได้รับรหัสผ่าน)
  • พื้นที่ส่วนตัว: กุญแจสาธารณะ ลายนิ้วมือกุญแจ ไฟล์กุญแจส่วนตัวที่ล็อกด้วยรหัสกู้คืนของคุณ และเนื้อหาที่เข้ารหัสแล้ว ซึ่งเราอ่านไม่ได้ เราไม่เก็บรหัสกู้คืน
  • แชตกับมายา (เมื่อคุณยินยอม): ข้อความและรูปที่คุณส่งถูกส่งไปให้ Google Vertex AI (Gemini) เพื่อสร้างคำตอบ เซิร์ฟเวอร์ของเราไม่บันทึกเนื้อหา ประวัติแชตเก็บแบบเข้ารหัสในพื้นที่ส่วนตัว เราเก็บบันทึกความยินยอมและจำนวน token เพื่อคิดโควตา
  • อีเมลที่มายาส่งแทนคุณ: ผู้รับ หัวเรื่อง เนื้อหา และไฟล์แนบที่คุณยืนยันจะถูกส่งผ่าน Amazon SES สำเนาเก็บแบบเข้ารหัสใน e-docs คำตอบกลับที่ส่งถึงที่อยู่ตอบกลับของมายาผ่าน Cloudflare Email Routing จะถูกเข้ารหัสเข้า e-docs ทันที ที่อยู่ที่อีเมลตีกลับหรือแจ้งว่าเป็นสแปมเก็บเป็นค่าแฮชเพื่อหยุดส่งซ้ำ
  • อีเมลจากระบบ: ลิงก์เข้าสู่ระบบ อีเมลต้อนรับ และไฟล์กุญแจสำรองที่เข้ารหัสแล้ว ส่งผ่าน Amazon SES และนับจำนวนครั้งที่ขอส่งเพื่อป้องกันการใช้งานผิดปกติ
  • บัญชีที่เชื่อมต่อ (เมื่อคุณเลือก): ดูข้อ 3
  • การแจ้งเตือน: โทเคนอุปกรณ์สำหรับ push และชื่ออุปกรณ์ ข้อความแจ้งเตือนไม่มีรายละเอียดส่วนตัว
  • สถานที่ อากาศ และเวลาเดินทาง (เมื่อคุณถาม): เมืองหรือตำแหน่งที่คุณเลือกหรืออนุญาต ส่งให้ Google Maps Platform (Weather, Air Quality, Places, Routes) เพื่อหาคำตอบ
  • การชำระเงิน (เมื่อเปิดใช้): สถานะแพ็กเกจและใบแจ้งหนี้ ข้อมูลบัตรอยู่กับ Stripe เราไม่เห็นเลขบัตร
  • ข้อมูลทางเทคนิค: IP address และข้อมูลอุปกรณ์เพื่อความปลอดภัยและป้องกันบอท (Google reCAPTCHA Enterprise, Firebase App Check) และบันทึกเหตุการณ์ความปลอดภัย
  • การลงทะเบียนรอเปิดตัว: อีเมลและเบอร์มือถือ เข้ารหัสก่อนจัดเก็บ
  • ในเบราว์เซอร์และสถิติ: ดูหัวข้อคุกกี้และสถิติการใช้งาน เราไม่ใช้คุกกี้โฆษณา

3. ข้อมูลจาก Google และ Microsoft (บัญชีที่เชื่อมต่อ)

  • เมื่อไร: เฉพาะเมื่อคุณกดเชื่อมต่อในการตั้งค่าและเลือกหมวดเอง ไม่เชื่อมต่อก็ใช้งานได้ตามปกติ
  • สิทธิ์ที่ขอจาก Google: ดูรายการปฏิทินของคุณ (อ่านอย่างเดียว) และดู สร้าง แก้ไข และลบนัดหมายในปฏิทิน (calendar.calendarlist.readonly, calendar.events) ดู สร้าง แก้ไข และลบรายชื่อติดต่อ (contacts) ดู สร้าง แก้ไข และลบงาน (tasks) รวมถึงชื่อ อีเมล และรูปโปรไฟล์ของบัญชีนั้น
  • สิทธิ์ที่ขอจาก Microsoft: ปฏิทิน รายชื่อติดต่อ งาน และ OneNote และการอ่านอีเมลเฉพาะเมื่อเปิดให้ใช้และคุณเลือก
  • ใช้ทำอะไร: แสดงนัด รายชื่อ และงานของคุณในคุณเลขา ให้มายาเตือนและตอบคำถามจากข้อมูลเหล่านั้น และเมื่อคุณแก้ไข เพิ่ม หรือลบในคุณเลขา เราจะส่งการเปลี่ยนแปลงกลับไปยังบัญชีต้นทางตามที่คุณสั่ง เราไม่ใช้ข้อมูลนี้เพื่อโฆษณา ไม่ขาย และไม่ใช้ฝึกโมเดล AI
  • จัดเก็บอย่างไร: โทเคนการเข้าถึงถูกเข้ารหัส (AES-256-GCM) บนเซิร์ฟเวอร์และไม่ส่งให้แอป ข้อมูลที่ดึงมาถูกเข้ารหัสด้วยกุญแจของคุณก่อนจัดเก็บ ทีมงานอ่านไม่ได้ ซิงก์ประมาณทุก 30 นาทีหรือเมื่อคุณกดซิงก์ รายการที่ถูกลบที่ต้นทางจะถูกลบที่นี่ด้วย
  • เปิดเผยให้ใคร: ไม่เปิดเผยให้บุคคลภายนอก ยกเว้นผู้ประมวลผลในข้อ 5 และเมื่อคุณถามมายาเรื่องที่ต้องใช้ข้อมูลนั้น ส่วนที่เกี่ยวข้องจะถูกส่งให้ Vertex AI เพื่อสร้างคำตอบตามความยินยอมของคุณ
  • ยกเลิก: กด “ยกเลิกการเชื่อมต่อ” ในการตั้งค่า เราจะเพิกถอนสิทธิ์กับ Google และลบโทเคนทันที และคุณเลือกให้ลบข้อมูลที่ซิงก์มาได้ หรือเพิกถอนเองที่ myaccount.google.com/permissions

การใช้และการส่งต่อข้อมูลที่ได้รับจาก Google API ไปยังแอปอื่นของคุณเลขาจะเป็นไปตาม Google API Services User Data Policy รวมถึงข้อกำหนด Limited Use

4. ข้อมูลอ่อนไหว

ข้อมูลบางอย่างที่คุณเลือกบันทึกอาจเป็นข้อมูลอ่อนไหวตามมาตรา 26 แห่ง PDPA เช่น ข้อมูลสุขภาพในโน้ต แชต หรือเอกสาร และข้อมูลบนบัตรประชาชนหรือหนังสือเดินทาง (เช่น ศาสนาหรือรูปถ่ายใบหน้า) เราประมวลผลข้อมูลเหล่านี้เฉพาะเมื่อคุณให้ความยินยอมโดยชัดแจ้งในแอป ซึ่งแยกจากการยอมรับข้อกำหนด และไม่ใช่เงื่อนไขในการใช้บริการ ก่อนบันทึกบัตรประชาชนหรือหนังสือเดินทางครั้งแรก แอปจะขอความยินยอมเฉพาะเรื่องนั้นอีกครั้ง

คุณถอนความยินยอมได้ทุกเมื่อ โดยลบข้อมูลนั้นหรือแจ้งที่ dpa@khunleka.com, dpa@otfuture.com การถอนไม่กระทบการประมวลผลก่อนหน้า

5. ข้อมูลของบุคคลอื่นที่คุณบันทึกหรือส่ง

คุณอาจบันทึกข้อมูลของบุคคลอื่น เช่น รายชื่อติดต่อ ข้อมูลคนในครอบครัว และสำเนาเอกสาร หรือให้มายาส่งอีเมลถึงผู้อื่น เราประมวลผลข้อมูลเหล่านี้เพื่อให้บริการตามคำสั่งของคุณเท่านั้น โดยจัดเก็บแบบเข้ารหัสด้วยกุญแจของคุณ คุณมีหน้าที่ตรวจว่ามีสิทธิ์บันทึกหรือส่งข้อมูลนั้น

สำหรับผู้รับอีเมลที่มายาส่ง: เราประมวลผลที่อยู่อีเมล ชื่อ และเนื้อหาเพื่อส่งอีเมลและเก็บสำเนาให้ผู้ใช้ เรารับเฉพาะคำตอบกลับจากผู้รับเดิม และอีเมลทุกฉบับมีลิงก์มายังนโยบายนี้ ผู้รับใช้สิทธิ์ตามข้อ “สิทธิของคุณ” ได้ที่ dpa@khunleka.com, dpa@otfuture.com

6. วัตถุประสงค์และฐานทางกฎหมาย

วัตถุประสงค์ฐานทางกฎหมาย
สร้างบัญชี ยืนยันตัวตน และให้บริการตามที่คุณขอ รวมถึงพื้นที่ส่วนตัวและการแจ้งเตือนการปฏิบัติตามสัญญา (ม. 24(3))
เชื่อมต่อและซิงก์บัญชี Google/Microsoft ที่คุณเลือกการปฏิบัติตามสัญญา (ม. 24(3))
ส่งอีเมลที่คุณยืนยันและรับคำตอบกลับการปฏิบัติตามสัญญา (ม. 24(3))
ตอบเรื่องสถานที่ อากาศ และเวลาเดินทางเมื่อคุณถามการปฏิบัติตามสัญญา (ม. 24(3))
ประมวลผลข้อความแชตด้วย AIความยินยอม (ม. 19) — ถอนได้จากห้องแชต
นับ token และจำกัดโควตาตามแพ็กเกจการปฏิบัติตามสัญญา (ม. 24(3))
ส่งคำเชิญทดลองใช้ให้ผู้ลงทะเบียนรอเปิดตัวความยินยอม (ม. 19)
รักษาความปลอดภัย ป้องกันการทุจริตและบอทประโยชน์โดยชอบด้วยกฎหมาย (ม. 24(5))
เรียกเก็บเงิน ออกใบเสร็จ และเก็บหลักฐานทางบัญชีสัญญา และหน้าที่ตามกฎหมาย (ม. 24(3), 24(6))
วัดสถิติการใช้งานด้วย Google Analyticsความยินยอม (ม. 19)
ข้อมูลอ่อนไหว เช่น ข้อมูลสุขภาพที่คุณบันทึกความยินยอมโดยชัดแจ้ง (ม. 26)

7. ผู้ประมวลผลที่เราเปิดเผยข้อมูลให้

เราไม่ขายข้อมูลส่วนบุคคล เราเปิดเผยข้อมูลเฉพาะผู้ประมวลผลที่จำเป็นต่อการให้บริการ ภายใต้สัญญาที่กำหนดให้รักษาความปลอดภัย

  • Google LLC — Firebase (Authentication, Hosting, Firestore, Storage, Functions, Cloud Messaging), Google Sign-In, Vertex AI (Gemini), Google Maps Platform, reCAPTCHA Enterprise / Firebase App Check, Google Analytics (เมื่อยินยอม) และ Google Calendar / People / Tasks API (เมื่อคุณเชื่อมต่อ)
  • Microsoft Corporation — Microsoft Graph (เมื่อคุณเชื่อมต่อ)
  • Amazon Web Services, Inc. — Amazon SES (ภูมิภาคสิงคโปร์) ส่งอีเมลจากระบบและอีเมลที่มายาส่งแทนคุณ
  • Cloudflare, Inc. — รับอีเมลตอบกลับที่ส่งถึงมายาและส่งต่อเข้าระบบของเรา
  • Stripe — เมื่อเปิดการชำระเงิน
  • ผู้ช่วย AI ภายนอกที่คุณเชื่อมต่อเองผ่าน MCP — เฉพาะข้อมูลที่คุณอนุญาต เนื้อหาที่เข้ารหัสยังอ่านไม่ได้
  • หน่วยงานรัฐ — เฉพาะเมื่อกฎหมายหรือคำสั่งที่ชอบด้วยกฎหมายกำหนด

8. การส่งข้อมูลไปต่างประเทศ

ผู้ประมวลผลข้างต้นอาจจัดเก็บหรือประมวลผลข้อมูลนอกประเทศไทย เช่น สิงคโปร์ สหรัฐอเมริกา และภูมิภาคอื่นที่ผู้ให้บริการ AI ใช้ประมวลผล เราเลือกผู้ให้บริการที่มีมาตรการคุ้มครองข้อมูลที่เหมาะสม เช่น ข้อสัญญามาตรฐาน ตามมาตรา 28–29 แห่ง PDPA

9. คุกกี้และสถิติการใช้งาน

เราใช้คุกกี้และพื้นที่เก็บข้อมูลในเบราว์เซอร์ 2 ประเภท คุกกี้วิเคราะห์จะไม่ถูกโหลดเลยจนกว่าคุณจะกด “ยอมรับ” คำตอบของคุณใช้ร่วมกันทั้ง khunleka.com และ app.khunleka.com

ชื่อประเภทและวัตถุประสงค์อายุ
leka_consentจำเป็น — จำคำตอบเรื่องคุกกี้ของคุณ13 เดือน
สถานะเข้าสู่ระบบของ Firebaseจำเป็น — ให้คุณอยู่ในระบบ (เก็บในเบราว์เซอร์)จนออกจากระบบหรือปิดแท็บ
khunleka-vault (IndexedDB)จำเป็น — กุญแจใช้งานของพื้นที่ส่วนตัวบนอุปกรณ์นี้ ส่งออกจากเครื่องไม่ได้จนกด “ลืมอุปกรณ์นี้” หรือล้างข้อมูลเบราว์เซอร์
leka.loginEmail, leka.lastLoginMethodจำเป็น — ช่วยยืนยันลิงก์อีเมล และแสดงป้าย “ใช้ล่าสุด”ปิดแท็บ / จนล้างข้อมูลเบราว์เซอร์
_ga, _ga_<รหัส>วิเคราะห์ (ต้องยินยอม) — Google Analytics ใช้แยกผู้เข้าชมด้วยรหัสสุ่ม13 เดือน

สิ่งที่ส่งให้ Google Analytics: ที่อยู่หน้าเว็บโดยไม่มีพารามิเตอร์ใน URL, ข้อมูลอุปกรณ์และเบราว์เซอร์, ตำแหน่งโดยประมาณที่ได้จาก IP (Google Analytics ไม่บันทึก IP) และเหตุการณ์การใช้งาน เราไม่ส่งอีเมล ชื่อ เบอร์โทร รหัสผู้ใช้ หรือข้อมูลในพื้นที่ส่วนตัวของคุณ และปิด Google signals กับการปรับโฆษณาให้ตรงตัวบุคคล

ถอนความยินยอมได้ทุกเมื่อที่ปุ่ม “ตั้งค่าคุกกี้” ด้านล่างของทุกหน้า ระบบจะหยุดเก็บสถิติและลบคุกกี้ _ga บนโดเมนของเรา ข้อมูลที่ส่งไปก่อนหน้าจะถูกลบตามระยะเวลาเก็บรักษา

10. ระยะเวลาเก็บรักษา

  • ข้อมูลบัญชี: ตลอดที่บัญชียังใช้งาน และ 90 วันหลังบริการสิ้นสุดหรือขอลบ
  • ข้อมูลในพื้นที่ส่วนตัว รวมกุญแจสาธารณะและไฟล์กุญแจที่เข้ารหัส: จนกว่าคุณจะลบ หรือ 90 วันหลังลบบัญชี
  • โทเคนของบัญชีที่เชื่อมต่อ: จนยกเลิกการเชื่อมต่อหรือลบบัญชี ข้อมูลที่ซิงก์มา: จนลบที่ต้นทาง ยกเลิกการเชื่อมต่อพร้อมเลือกลบ หรือลบบัญชี
  • ที่อยู่ตอบกลับของอีเมลมายา: 90 วันนับจากส่ง
  • โทเคนอุปกรณ์สำหรับ push: จนปิดการแจ้งเตือนหรือโทเคนหมดอายุ
  • ข้อมูลลงทะเบียนรอเปิดตัว: จนกว่าจะส่งคำเชิญ หรือ 12 เดือน หรือจนกว่าคุณจะขอลบ แล้วแต่ว่าอย่างใดถึงก่อน
  • บันทึกความปลอดภัย: 1 ปี
  • จำนวน token ที่ใช้รายเดือนและบันทึกความยินยอม AI: ตลอดที่บัญชียังใช้งาน (บันทึกความยินยอมลบทันทีเมื่อถอนความยินยอม)
  • ตัวนับการขอส่งอีเมลและการลงทะเบียน: ลบอัตโนมัติภายใน 2 วัน
  • สถิติการใช้งานใน Google Analytics: ไม่เกิน 14 เดือน และคุกกี้วิเคราะห์หมดอายุใน 13 เดือน
  • หลักฐานการชำระเงินและภาษี: ตามที่กฎหมายบัญชีและภาษีกำหนด
  • ข้อมูลสำรอง: ลบตามรอบหมุนเวียนของระบบสำรอง

11. สิทธิของคุณ

คุณมีสิทธิ์ขอเข้าถึงหรือขอสำเนาข้อมูล ขอรับหรือโอนข้อมูล คัดค้าน ขอลบหรือทำให้ไม่สามารถระบุตัวตนได้ ขอระงับการใช้ ขอแก้ไขให้ถูกต้อง และถอนความยินยอมได้ทุกเมื่อ การถอนความยินยอมไม่กระทบการประมวลผลที่ทำไปก่อนหน้า

ส่งคำขอได้ที่ privacy@khunleka.com หรือ dpa@khunleka.com, dpa@otfuture.com เราจะตอบภายใน 30 วัน และอาจต้องยืนยันตัวตนก่อน สำหรับข้อมูลที่เข้ารหัสด้วยกุญแจของคุณ เราจะลบได้ แต่ส่งเนื้อหาเป็นข้อความอ่านได้ให้ไม่ได้ โดยคุณส่งออกเองได้จากแอป หากรหัสกู้คืนและอุปกรณ์ที่ปลดล็อกไว้หายทั้งหมด เราไม่สามารถกู้ข้อมูลที่เข้ารหัสให้ได้

หากเห็นว่าเราปฏิบัติไม่ถูกต้อง คุณร้องเรียนต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส.) ได้

12. ความปลอดภัย

เราใช้การเชื่อมต่อแบบเข้ารหัส (HTTPS) จำกัดสิทธิ์การเข้าถึงของทีมงาน เข้ารหัสข้อมูลลงทะเบียน และออกแบบพื้นที่ส่วนตัวให้เข้ารหัสฝั่งอุปกรณ์ หากเกิดเหตุละเมิดข้อมูลที่มีความเสี่ยง เราจะแจ้ง สคส. ภายใน 72 ชั่วโมง และแจ้งคุณโดยไม่ชักช้าเมื่อมีความเสี่ยงสูง

13. ผู้เยาว์

บริการนี้ไม่ได้ออกแบบสำหรับผู้มีอายุต่ำกว่า 20 ปี หากเราทราบว่าได้เก็บข้อมูลของผู้เยาว์โดยไม่มีความยินยอมจากผู้ใช้อำนาจปกครอง เราจะลบข้อมูลนั้น

14. การเปลี่ยนแปลงนโยบายและการติดต่อ

เราจะแจ้งการเปลี่ยนแปลงที่สำคัญทางอีเมลหรือในแอปก่อนมีผล ประวัติเวอร์ชัน: เวอร์ชัน 1 (9 ตุลาคม 2569) → เวอร์ชัน 2 (9 ตุลาคม 2569) เพิ่มคุกกี้วิเคราะห์ Google Analytics แบบขอความยินยอม → เวอร์ชัน 3 (10 ตุลาคม 2569) เพิ่มข้อมูลกุญแจของพื้นที่ส่วนตัว → เวอร์ชัน 4 (10 ตุลาคม 2569) เพิ่มแชตกับมายาด้วย AI, อีเมลจากระบบผ่าน Amazon SES และการป้องกันบอทด้วย reCAPTCHA / App Check → เวอร์ชัน 5 (11 ตุลาคม 2569) ปรับข้อมูลที่เก็บให้ตรงกับฟีเจอร์ที่เปิดแล้ว เพิ่มบัญชีที่เชื่อมต่อ Google/Microsoft และข้อกำหนด Limited Use อีเมลที่มายาส่งและรับ การแจ้งเตือน สถานที่และอากาศ MCP และฉบับภาษาอังกฤษ ผู้ควบคุมข้อมูล: ห้างหุ้นส่วนจำกัด โอที ฟิวเจอร์ 222/16 หมู่ 2 ซอยวิภาวดี-รังสิต 60 แยก 18 แขวงตลาดบางเขน เขตหลักสี่ กรุงเทพมหานคร 10210 · อีเมล privacy@khunleka.com ติดต่อฝ่ายคุ้มครองข้อมูลส่วนบุคคลได้ที่ dpa@khunleka.com, dpa@otfuture.com

This English translation is provided for convenience. The Thai version above is the legally binding version.

PRIVACY POLICY · ENGLISH

Privacy Policy

Version 5 · Effective 11 October 2026

OT Future Limited Partnership (“we”) is the data controller for KhunLeka (khunleka.com and app.khunleka.com). This policy explains what we collect, why, who we share it with, how long we keep it and your rights under Thailand's Personal Data Protection Act B.E. 2562 (PDPA).

  1. Our core principle: an encrypted private space
  2. Information we collect
  3. Data from Google and Microsoft (connected accounts)
  4. Sensitive data
  5. Other people's data you record or send
  6. Purposes and legal bases
  7. Processors we share data with
  8. International transfers
  9. Cookies and analytics
  10. Retention
  11. Your rights
  12. Security
  13. Children
  14. Changes and contact

1. Our core principle: an encrypted private space

The life data you record (appointments, tasks, notes, assets, finances, documents, pets, chat history, e-docs emails and data synced from connected accounts) is encrypted on your device with a key you hold. Our staff and servers cannot read stored content. Some features need the server to see content briefly to work, such as sending your message to the AI, sending an email or fetching data from Google. In those cases content is processed in memory only and encrypted with your key before it is stored.

Even though we cannot read encrypted content, we treat ourselves as the data controller processing all of this data, because our system stores, transfers and decrypts it on your device. This policy and all your rights therefore apply to encrypted data too.

2. Information we collect

  • Account: email, verification status, user ID, sign-up and last sign-in time. With Google Sign-In: name, email, profile photo and Google account ID (we never receive your password).
  • Private space: your public key, key fingerprint, your private key file locked with your recovery code, and encrypted content we cannot read. We do not store your recovery code.
  • Chat with Maya (with your consent): messages and photos you send are processed by Google Vertex AI (Gemini) to produce a reply. Our servers do not log the content. Chat history is stored encrypted in your private space. We keep your consent record and monthly token counts for quotas.
  • Emails Maya sends for you: the recipients, subject, body and attachments you confirm are sent through Amazon SES, and an encrypted copy is kept in e-docs. Replies to Maya's reply address arrive through Cloudflare Email Routing and are encrypted into e-docs immediately. Addresses that bounced or reported spam are kept as a keyed hash so we stop sending to them.
  • System emails: sign-in links, welcome emails and your encrypted key backup are sent through Amazon SES; we count send requests to prevent abuse.
  • Connected accounts (if you choose): see section 3.
  • Notifications: a device token for push and a device name. Notifications never show private details.
  • Places, weather and travel time (when you ask): the city or location you choose or allow is sent to Google Maps Platform (Weather, Air Quality, Places, Routes).
  • Payments (when enabled): plan status and invoices. Card details stay with Stripe; we never see your card number.
  • Technical: IP address and device data for security and bot protection (Google reCAPTCHA Enterprise, Firebase App Check), and security event logs.
  • Pre-launch registration: email and mobile number, encrypted before storage.
  • Browser storage and analytics: see Cookies and analytics. We do not use advertising cookies.

3. Data from Google and Microsoft (connected accounts)

  • When: only when you connect an account in Settings and choose which categories. Everything works without connecting.
  • Google permissions requested: see your list of calendars (read-only) and see, create, edit and delete events (calendar.calendarlist.readonly, calendar.events); see, create, edit and delete contacts (contacts); see, create, edit and delete tasks (tasks); plus the account's name, email and profile photo.
  • Microsoft permissions requested: calendars, contacts, tasks and OneNote, and reading mail only where enabled and you choose it.
  • How we use it: to show your events, contacts and tasks in KhunLeka, let Maya remind you and answer questions about them, and — when you edit, add or delete something in KhunLeka — send that change back to the source account as you asked. We do not use this data for advertising, do not sell it, and do not use it to train AI models.
  • How we store it: access and refresh tokens are encrypted (AES-256-GCM) on our servers and never sent to the app. Fetched data is encrypted with your key before it is stored; our staff cannot read it. Data syncs about every 30 minutes or when you tap sync; items deleted at the source are deleted here.
  • Sharing: we do not share it with third parties except the processors in section 5. When you ask Maya about something that needs this data, the relevant part is sent to Vertex AI to answer, under your AI consent.
  • Revoking access: tap “Disconnect” in Settings — we revoke our access with Google, delete the tokens immediately, and you can choose to delete the synced data. You can also revoke access at myaccount.google.com/permissions.

KhunLeka's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Sensitive data

Some data you choose to record may be sensitive data under section 26 of the PDPA, such as health information in notes, chats or documents, and details on ID cards or passports (for example religion or a face photo). We process it only with your explicit consent given in the app, which is separate from accepting the Terms and is not a condition of using the service. Before you save your first ID card or passport, the app asks for consent for that again.

You can withdraw consent at any time by deleting that data or by writing to dpa@khunleka.com, dpa@otfuture.com. Withdrawal does not affect earlier processing.

5. Other people's data you record or send

You may record other people's data, such as contacts, family members' details and document copies, or have Maya email other people. We process this data only to provide the service on your instructions, stored encrypted with your key. You are responsible for making sure you may record or send it.

For recipients of emails Maya sends: we process the email address, name and content to deliver the email and keep a copy for the user. We accept replies only from the original recipients, and every email links to this policy. Recipients can exercise the rights in “Your rights” at dpa@khunleka.com, dpa@otfuture.com.

6. Purposes and legal bases

PurposeLegal basis
Creating your account, verifying you and providing the service you ask for, including the private space and notificationsContract (s. 24(3))
Connecting and syncing the Google/Microsoft accounts you chooseContract (s. 24(3))
Sending emails you confirm and receiving repliesContract (s. 24(3))
Answering place, weather and travel questions when you askContract (s. 24(3))
Processing chat messages with AIConsent (s. 19) — withdraw any time from the chat
Counting tokens and applying plan quotasContract (s. 24(3))
Sending trial invitations to pre-launch registrantsConsent (s. 19)
Security and preventing fraud and botsLegitimate interests (s. 24(5))
Billing, receipts and accounting recordsContract and legal obligation (s. 24(3), 24(6))
Usage analytics with Google AnalyticsConsent (s. 19)
Sensitive data such as health information you recordExplicit consent (s. 26)

7. Processors we share data with

We do not sell personal data. We share data only with processors needed to provide the service, under contracts that require security.

  • Google LLC — Firebase (Authentication, Hosting, Firestore, Storage, Functions, Cloud Messaging), Google Sign-In, Vertex AI (Gemini), Google Maps Platform, reCAPTCHA Enterprise / Firebase App Check, Google Analytics (with consent) and the Google Calendar / People / Tasks APIs (when you connect)
  • Microsoft Corporation — Microsoft Graph (when you connect)
  • Amazon Web Services, Inc. — Amazon SES (Singapore region) for system emails and emails Maya sends for you
  • Cloudflare, Inc. — receiving replies to Maya's emails and forwarding them to our system
  • Stripe — when payments are enabled
  • External AI assistants you connect yourself via MCP — only what you allow; encrypted content stays unreadable
  • Public authorities — only where required by law or a lawful order

8. International transfers

These processors may store or process data outside Thailand, such as in Singapore, the United States and other regions the AI provider uses for processing. We choose providers with appropriate safeguards, such as standard contractual clauses, under sections 28–29 of the PDPA.

9. Cookies and analytics

We use two kinds of cookies and browser storage. Analytics cookies are not loaded at all until you tap “Accept”. Your choice applies to both khunleka.com and app.khunleka.com.

NameType and purposeLifetime
leka_consentNecessary — remembers your cookie choice13 months
Firebase sign-in stateNecessary — keeps you signed in (browser storage)Until you sign out or close the tab
khunleka-vault (IndexedDB)Necessary — your private-space working key on this device; it cannot be exportedUntil “Forget this device” or clearing browser data
leka.loginEmail, leka.lastLoginMethodNecessary — completes email sign-in links and shows the “last used” labelTab close / until browser data is cleared
_ga, _ga_<id>Analytics (consent needed) — Google Analytics tells visitors apart with a random ID13 months

What we send to Google Analytics: the page address without URL parameters, device and browser details, approximate location derived from IP (Google Analytics does not store IP addresses) and usage events. We never send your email, name, phone number, user ID or private-space data, and Google signals and ad personalisation are turned off.

You can withdraw consent at any time with “Cookie settings” at the bottom of every page; we then stop collecting analytics and delete the _ga cookies on our domains.

10. Retention

  • Account data: while your account is active and 90 days after the service ends or you ask for deletion
  • Private-space content, including your public key and encrypted key file: until you delete it, or 90 days after account deletion
  • Connected-account tokens: until you disconnect or delete your account. Synced data: until deleted at the source, until you disconnect and choose to delete it, or until account deletion
  • Maya's reply addresses: 90 days after sending
  • Push device tokens: until you turn notifications off or the token expires
  • Pre-launch registration: until we send your invitation, 12 months, or until you ask us to delete it, whichever comes first
  • Security logs: 1 year
  • Monthly token counts and AI consent records: while your account is active (the consent record is deleted as soon as you withdraw)
  • Email and registration rate counters: deleted automatically within 2 days
  • Google Analytics data: up to 14 months; analytics cookies expire after 13 months
  • Payment and tax records: as required by accounting and tax law
  • Backups: deleted on the backup rotation schedule

11. Your rights

You may request access to or a copy of your data, portability, objection, deletion or anonymisation, restriction, and correction, and you may withdraw consent at any time. Withdrawal does not affect processing done before it.

Send requests to privacy@khunleka.com or dpa@khunleka.com, dpa@otfuture.com. We reply within 30 days and may need to verify your identity. We can delete data encrypted with your key but cannot hand over its readable content; you can export it yourself from the app. If your recovery code and every unlocked device are lost, we cannot recover encrypted data.

If you believe we have not complied, you may complain to Thailand's Personal Data Protection Committee (PDPC).

12. Security

We use encrypted connections (HTTPS), limit staff access, encrypt registration data and designed the private space to be encrypted on your device. If a data breach poses a risk, we will notify the PDPC within 72 hours and notify you without undue delay when the risk is high.

13. Children

KhunLeka is not designed for people under 20. If we learn we have collected a minor's data without consent from a parent or guardian, we will delete it.

14. Changes and contact

We will tell you about important changes by email or in the app before they take effect. Version 5 (11 October 2026) brings the policy in line with features now live and adds connected Google/Microsoft accounts with the Limited Use requirements, emails Maya sends and receives, notifications, places and weather, MCP, and this English translation. Controller: OT Future Limited Partnership, 222/16 Moo 2, Soi Vibhavadi-Rangsit 60 Yaek 18, Talat Bang Khen, Lak Si, Bangkok 10210, Thailand · privacy@khunleka.com. Data protection contact: dpa@khunleka.com, dpa@otfuture.com.

กลับไปหน้าเข้าสู่ระบบ
© 2026 KHUNLEKA ข้อกำหนดความเป็นส่วนตัว