Privacy Policy
Last Updated: February 15, 2025NextGenFileHub takes your privacy seriously. We're a financial reporting platform serving investors throughout Thailand, and we understand that your financial data deserves the highest level of protection.
This policy explains what information we collect, why we collect it, and what choices you have. We've tried to keep the legal language minimal and make this as straightforward as possible.
1 Information We Collect
Account Information
When you register for NextGenFileHub, we collect basic details needed to create and manage your account. This includes your name, email address, phone number, and company information if you're representing an organization.
Financial Data You Upload
Our platform is built for financial reporting. That means you'll be uploading documents, spreadsheets, and other files containing financial information. We store this data securely on encrypted servers located in Thailand and Singapore.
Important: We never access your financial documents unless you specifically request support assistance or we're required to by Thai law. Your files remain private to you and anyone you choose to share them with.
Usage Information
Like most online platforms, we collect information about how you use our service. This includes things like when you log in, which features you use most often, and what types of reports you generate. We use this to improve the platform and understand what's working well.
- IP addresses and device information
- Browser type and operating system
- Pages visited and features accessed
- Time spent on different sections
- Search queries within the platform
- Report generation frequency and types
Payment Information
When you subscribe to a paid plan, we work with payment processors to handle transactions. We don't store your complete credit card numbers on our servers. Instead, we receive a secure token from our payment partner that allows us to process future charges to your card.
2 How We Use Your Information
We're pretty straightforward about this. Your information helps us run the service and make it better. Here's what we do:
Purpose | What This Means |
---|---|
Service Delivery | Processing your reports, storing your files, and keeping your account running smoothly |
Communication | Sending you updates about your account, responding to support requests, and notifying you about important changes |
Security | Detecting unusual activity, preventing unauthorized access, and protecting against fraud |
Improvement | Understanding how people use the platform so we can add features that actually matter |
Legal Compliance | Meeting our obligations under Thai law and financial regulations |
We don't sell your data to third parties. Period. That's not our business model, and it's not something we'll ever consider.
3 Data Sharing and Third Parties
Running a secure financial platform requires working with some trusted partners. Here's who might see your information and why:
Service Providers
We work with companies that help us run our infrastructure. This includes cloud hosting providers, email services, and payment processors. These partners only get access to the information they need to do their job, and they're bound by strict confidentiality agreements.
- Cloud storage providers for secure file hosting
- Email service providers for transactional messages
- Payment processors for billing and subscriptions
- Analytics tools to understand platform usage
- Customer support software for ticket management
Legal Requirements
Sometimes we're required by law to share information with Thai authorities. This could happen if there's a court order, a regulatory investigation, or a legitimate legal request. We'll always review these requests carefully and only share what's legally required.
Business Transfers
If NextGenFileHub is acquired or merged with another company, your information would be part of that transaction. We'd notify you beforehand and give you options about your data.
4 Your Rights and Choices
Under Thailand's Personal Data Protection Act (PDPA), you have several rights regarding your personal information. We take these seriously and have built systems to make exercising them straightforward.
Access Your Data
You can download a complete copy of your account data at any time. Just go to Settings → Privacy → Export Data. You'll receive a link to download everything within 48 hours.
Correct Information
Found something wrong in your profile? You can update most information directly through your account settings. For changes that require verification, contact our support team.
Delete Your Account
You can close your account whenever you want. When you do, we'll delete your personal information and uploaded files within 30 days. We might keep some transaction records for accounting and legal purposes, but these are stored separately from your personal data.
Heads up: Once you delete your account, there's no going back. Make sure you've downloaded any reports or files you want to keep before proceeding.
Object to Processing
You can ask us to stop processing your data for certain purposes. For example, if you don't want to receive marketing emails, you can opt out through your email preferences or by clicking unsubscribe in any message we send.
Data Portability
Want to move your data to another service? We'll provide your information in a standard format that other platforms can read. Most data exports happen automatically, though large accounts might take a bit longer.
5 Security Measures
Financial data security isn't something we take lightly. We've invested heavily in protection systems and follow industry best practices.
Encryption
All data transmitted to and from our servers uses TLS 1.3 encryption. Your files are encrypted at rest using AES-256 encryption. These are the same standards used by banks and financial institutions worldwide.
Access Controls
Our internal team has strict access limits. Only employees who genuinely need access to certain systems get it, and all access is logged and reviewed regularly. We use two-factor authentication for all administrative accounts.
- Role-based access control for staff members
- Regular security audits by external firms
- Automated monitoring for suspicious activity
- Incident response procedures with 24-hour notification
- Regular penetration testing of our systems
- Secure coding practices and code review processes
Data Centers
We use certified data centers in Thailand and Singapore that meet international security standards. These facilities have physical security, redundant power, and backup systems to keep your data safe and accessible.
Despite our best efforts, no online service is 100% secure. If we ever experience a data breach that affects your information, we'll notify you within 72 hours as required by Thai law.
6 Data Retention
We keep your information for as long as your account is active, plus a reasonable period afterward to handle any potential issues or questions.
Active Accounts
While you're using NextGenFileHub, we maintain all your data so you can access it whenever needed. There's no automatic deletion of files or reports unless you specifically request it.
Closed Accounts
After you close your account, we delete most personal information within 30 days. Financial transaction records are kept for seven years to comply with Thai accounting regulations. These records are stored separately and can't be linked back to your personal profile.
Backup Copies
We maintain encrypted backups of our database for disaster recovery. These backups are automatically deleted after 90 days. If you delete your account, your information will be purged from backups as they expire naturally.
7 International Transfers
While our primary servers are in Thailand and Singapore, some of our service providers operate internationally. This means your data might occasionally be processed in other countries.
When data leaves Thailand, we make sure adequate protections are in place. This usually means working with companies in countries that the Thai government recognizes as having strong privacy laws, or using standard contractual clauses approved by Thai regulators.
The European Union's General Data Protection Regulation (GDPR) also applies to any EU residents using our service. We maintain compliance with both Thai PDPA and EU GDPR standards.
8 Cookies and Tracking
We use cookies and similar technologies to keep you logged in and remember your preferences. Here's what's running on our site:
Essential Cookies
These are necessary for the platform to work. They handle things like keeping you logged in, remembering your language preference, and maintaining security. You can't opt out of these without breaking the service.
Analytics Cookies
We use analytics to understand how people use NextGenFileHub. This helps us figure out what features are useful and where people get stuck. You can disable these in your account settings if you prefer not to be tracked.
- Page views and navigation patterns
- Feature usage and engagement metrics
- Error tracking and performance monitoring
- A/B testing for new features
We don't use advertising cookies or share your browsing data with ad networks. We're a subscription service, not an advertising platform.
9 Children's Privacy
NextGenFileHub is designed for business and investment use. Our service isn't intended for anyone under 18 years old, and we don't knowingly collect information from children.
If we discover that someone under 18 has created an account, we'll delete it immediately and remove any associated data. If you're a parent or guardian and believe your child has provided us with personal information, please contact us right away.
10 Changes to This Policy
We update this privacy policy occasionally to reflect changes in our practices or legal requirements. When we make significant changes, we'll notify you via email and display a prominent notice on the platform.
Minor updates like clarifications or formatting changes might happen without notification. We recommend checking back every few months to stay informed about how we protect your data.
You'll always find the most current version on this page, with the update date clearly shown at the top. If you disagree with any changes, you can close your account before the new policy takes effect.
11 Thai PDPA Compliance
NextGenFileHub fully complies with Thailand's Personal Data Protection Act, which came into full effect in 2022. As a Thai-based company, we follow all requirements set by the Personal Data Protection Committee.
Legal Basis for Processing
We process your personal data based on several legal grounds recognized under Thai law:
- Contractual necessity: We need your information to provide the services you've signed up for
- Consent: You've given us permission to process certain types of data
- Legal obligation: Thai law requires us to maintain certain records
- Legitimate interests: We process some data to improve our service and prevent fraud
Filing Complaints
If you believe we've mishandled your personal data, you have the right to file a complaint with Thailand's Personal Data Protection Committee. You can also contact us directly first, and we'll do our best to resolve any concerns.
Contact Us About Privacy
Questions about this privacy policy or how we handle your data? We're happy to help.
We typically respond to privacy inquiries within three business days. For urgent matters, please call us directly during business hours (Monday-Friday, 9:00-18:00 Thailand time).