Nested / Privacy Notice

Privacy Notice

Last updated 1 October 2026 Nested Company Limited

Nested Company Limited (“the Provider” or “we”) takes the protection of personal data seriously. This Notice explains how we collect, use, disclose and look after personal data.

1. Our Roles

In providing the services, we may act in different roles depending on the nature of the data and the purposes of processing.

Where we act as a data controller (Data Controller)

For example, the data of primary contacts, service applicants and system users, and data necessary for the provision of the services, communications, billing, security and legal compliance.

Where we act as a data processor (Data Processor)

For personal data that the Customer enters into the system for the conduct of its business, such as data of the Customer's employees, customers, business partners or contacts, where the Customer determines the purposes and means of processing and we process the data on the Customer's instructions under the Data Processing Addendum (DPA).

2. Personal Data We Collect

As a data controller, we may collect the following data:

  1. Name and surname
  2. Email address and telephone number
  3. Company name and job title
  4. User account information
  5. IP address and technical information
  6. System usage data and logs
  7. Support contact information and support tickets
  8. Payment information and information necessary for issuing accounting or tax documents

For data that the Customer enters into the system, we will process it in accordance with our role and the Customer's instructions as set out in Clause 1.

3. Purposes and Legal Bases

We may process personal data for the following purposes:

Providing the services and managing user accounts Legal basis: Performance of a contract, or taking steps at the data subject's request prior to entering into a contract
Billing and the preparation of accounting/tax documents Legal basis: Compliance with a legal obligation, or performance of a contract, as the case may be
Maintaining security, preventing fraud and administering the system Legal basis: Legitimate interests, or another basis permitted by law
Analysing and improving the services Legal basis: Legitimate interests, or another basis permitted by law
Marketing communications Legal basis: Consent, where the law requires consent to be obtained

4. Disclosure of Data

We may disclose or transfer personal data, only to the extent necessary, to:

  1. Cloud and infrastructure service providers
  2. IT system and security service providers
  3. Payment service providers or related service providers
  4. Service providers or business partners necessary for the provision of the services
  5. Advisers or contractors necessary for our operations
  6. Government agencies or other persons where required or permitted by law

The list of sub-processors used in relation to the data in the Customer's system is set out in Annex C of the DPA (currently Microsoft Azure, INET for e-Tax Invoice, Intuit Mailchimp for email delivery, Crisp for support chat, and Google Workspace).

Such persons or service providers will receive only the data necessary for the relevant purposes, and where they act as a data processor, we will require them to process the data within the defined scope and under appropriate protective measures.

5. Cross-Border Data Transfers

We use the cloud infrastructure services of Microsoft Azure, which stores and processes data primarily in data centres in the Singapore region. In some cases, data may be accessed or processed from other countries by the relevant service providers.

Where personal data is sent or transferred abroad, we will comply with the conditions and data protection measures required by law, including measures concerning international data transfers under the Personal Data Protection Act.

6. Data Retention

We will retain personal data only for as long as necessary for the purposes of collection, or as required by law, with the following approximate retention periods:

  1. Business data entered into the system by the Customer (for which we act as processor): will be deleted or returned after the 60-day data export period following termination of the services, unless otherwise required by law or instructed by the Customer.
  2. User account and contact data: retained for no more than 5 years from the end of the relationship, for the establishment of legal claims or the defence of claims.
  3. Accounting and tax documents: retained for 5 years under the Revenue Code and related laws (which may be extended as required by law).
  4. Computer traffic data and system logs: retained for no more than 1 year, for security and audit purposes.
  5. Backup data (Backup): will be deleted in accordance with the ordinary backup cycle within 90 days.
  6. Marketing data relying on consent: until consent is withdrawn.

Upon expiry of such periods, we will delete, destroy or anonymise the data.

7. Security Measures

We maintain appropriate technical and organisational measures to prevent the loss of, and unauthorised access to, use, alteration or disclosure of, personal data.

In the event of a personal data breach, we will notify the Office of the Personal Data Protection Committee without delay and, where feasible, within 72 hours of becoming aware of the breach, and will notify data subjects where the law requires such notification.

8. Rights of Data Subjects

Subject to the conditions and exceptions provided by law, data subjects may have the following rights:

  1. To request access to and obtain a copy of the data
  2. To request the transfer of the data to another data controller (data portability) as provided by law
  3. To request rectification of the data
  4. To request erasure or destruction of the data
  5. To request suspension of the use of the data
  6. To object to processing in certain cases
  7. To withdraw consent where the processing relies on consent

Data subjects may exercise their rights by contacting us through the channels set out in Clause 10. We will consider and respond to a request within 30 days of receiving a request containing sufficient information, which period may be extended as permitted by law where necessary. The exercise of certain rights may be subject to limitations under the law.

9. Cookies

Our website and platform may use cookies or similar technologies to enable the services to function properly, remember settings and analyse usage. For cookies that are not necessary for the functioning of the system, we will obtain prior consent as required by law. Users can manage their cookie settings through their browser or through the channels we provide. Disabling certain types of cookies may affect the use of certain functions.

10. Contact

If you have any questions regarding personal data protection, or wish to exercise data subject rights, you may contact:

Nested Company Limited

Email: privacy@nested.co.th

11. Amendments to this Notice

We may update this Notice from time to time to reflect changes in our services, technology or the law, The updated version takes effect when published on this website, and the last-updated date is shown at the top of this Notice. For material changes, we will in addition give advance notice by email to the contact designated in the user account.

Contact us about personal dataNested Company Limited · email privacy@nested.co.th
For the processing of data that the Customer enters into the system, see the Data Processing Addendum (DPA)
Language: This English version is provided for convenience only. Where it differs from the Thai version, the Thai version prevails.