Privacy Policy Overview
This privacy policy explains how nunusala collects, uses, discloses, and protects personal data in the provision of AI software development, AI integration, and related professional services. It applies to visitors of nunusala.digital and to clients who engage our services. The policy describes categories of data processed, lawful bases for processing, data recipients, retention practices, security measures, and the rights available to data subjects. The approach reflects applicable data protection principles and seeks to support transparent handling of personal information in project delivery and ongoing support activities.
Definitions
Terms used in this document are defined to clarify the scope and meaning of processing activities described below. Definitions reflect common data protection terminology adapted to our services in AI software development and integration.
- Personal data means any information relating to an identified or identifiable natural person, including contact details, business identifiers, and technical identifiers collected in the course of providing services.
- Processing refers to any operation performed on personal data, such as collection, storage, use, disclosure, transmission, and deletion, whether automated or manual.
- User refers to any individual who accesses nunusala.digital, requests information, or is a contact person at a client organization engaged with our services.
- Service means the professional activities provided by nunusala, including AI software design, development, deployment, model integration, technical consulting, and maintenance.
- Cookies are small text files stored on a device by a web browser at the request of a website, used to recognize returning visitors and support site functionality and analytics.
Data Collection
We collect data necessary to provide professional services, operate the website, comply with legal obligations, and maintain administrative records. Data collection varies by interaction type: browsing the site, contacting us, or engaging in a client project.
Data Provided by Users
Data that users or client representatives provide directly when contacting nunusala or engaging our services. Such data is used to establish engagement, perform services, and communicate about projects.
- Contact details: name, business email address, phone number, job title, and organization name.
- Project information: project descriptions, business requirements, technical specifications, and any materials supplied for development or integration.
- Account and billing details: company billing address, tax or business ID (for example Business ID 5691688271061), invoicing information, and payment details where required.
- Support communications: messages platform with our team including troubleshooting logs, meeting notes, and feedback.
- Recruitment and HR data: CVs, candidate contact information, and references when applying for roles with nunusala.
- Consents and preferences: language preferences, marketing opt-in choices, and service-specific consents.
Automatically Collected Data
When users visit nunusala.digital or use online components of our service, the site may automatically collect technical and usage data to support operation, security, and analytics.
- Device and browser information such as user agent, screen resolution, and supported features.
- IP address and approximate geographic location for security, logging, and regional service routing.
- Usage data including pages visited, duration of visits, navigation paths, and error reports.
- Performance and diagnostic data to monitor uptime, optimize response times, and contribute incidents.
- Technical logs related to API calls, authentication attempts, and service integrations for security and audit purposes.
- Cookie identifiers and similar storage vouchers used to maintain session state and user preferences.
Data from Third Parties
In some cases, nunusala may receive data about a user from third-party sources, where that data is necessary to provide services or to comply with legal obligations.
- Service providers and partners that assist in payment processing, hosting, analytics, or communication.
- Publicly available sources such as company registries, professional directories, and business databases for due diligence.
- Client organizations that share contact and project information for the purposes of service delivery.
Purposes of Processing
We process personal data for the following legitimate, specified purposes necessary for service delivery, compliance, and operational management.
- To provide AI software development, deployment, integration, and maintenance services requested by clients.
- To communicate with prospective and existing clients regarding proposals, contracts, project status, and support.
- To manage billing, invoicing, and business records associated with contracted services.
- To maintain website functionality, perform usage analysis, and improve user experience.
- To ensure security, detect and respond to incidents, and maintain operational integrity of systems.
- To comply with legal obligations, regulatory requests, and to establish, exercise, or defend legal claims.
- To process recruitment applications and manage employment-related administration.
- To send administrative messages, service updates, and transactional communications related to client engagements.
Legal Basis for Processing
Where applicable, processing of personal data is based on one or more lawful bases, including contractual necessity, legitimate interests, consent, and legal obligations.
- Contract performance: processing necessary to perform services agreed with a client.
- Legitimate interests: processing for operational needs such as security, fraud prevention, and system maintenance, balanced against data subject rights.
- Consent: where individuals voluntarily provide consent for specific processing activities such as marketing communications.
- Legal compliance: processing required to comply with applicable laws, regulations, or official requests.
Data Subject Rights (GDPR-style Reference)
Although nunusala operates in Thailand, we recognize privacy principles similar to those in international frameworks. Relevant rights are outlined below to support transparent handling of personal data.
- Right to access: individuals may request confirmation whether personal data is being processed and obtain a copy of such data.
- Right to rectification: individuals can request correction of inaccurate or incomplete personal data.
- Right to erasure: in certain circumstances, individuals may request deletion of personal data that is no longer necessary for the purposes collected.
- Right to restriction of processing: individuals may request limitation of processing where accuracy or lawfulness is in question.
- Right to data portability: where technically feasible and applicable, individuals may request transfer of their personal data in a structured, commonly used format.
- Right to object: individuals may object to processing based on legitimate interests or direct marketing where applicable.
Cookies and Similar Technologies
nunusala.digital uses cookies and similar technologies to enable core website functionality, improve performance, and collect analytics. Users may control cookie settings via their browser and available on-site tools.
Common types of cookies used include session cookies to maintain navigation state, persistent cookies for user preferences, and third-party cookies for analytics and service integrations.
Cookie categories typically include necessary cookies for site operation, preferences cookies for storing language or interface choices, analytics cookies for usage measurement, and marketing cookies for third-party integrations if enabled.
Users can manage cookies by adjusting browser settings to block or delete cookies, or by using the site cookie settings if provided. Disabling certain cookies may affect site functionality.
Detailed cookie information and management options
Data Sharing and Disclosure
nunusala shares personal data only with entities necessary to provide services, fulfill contractual obligations, or meet legal requirements. Any sharing is accompanied by appropriate safeguards.
- Service providers engaged for hosting, cloud services, analytics, and payment processing under data processing agreements.
- Professional advisors such as auditors, accountants, and legal advisors where required for business operations.
- Client-designated parties and subcontractors engaged to deliver specific project tasks as instructed by the client.
- Authorities and regulators when disclosure is required by law or to respond to lawful requests.
- Third parties in connection with a corporate reorganization, merger, sale of assets, or transfer of all or part of the business, subject to confidentiality and transition arrangements.
- Aggregated or anonymized data that does not identify individuals may be shared for research, reporting, or internal analysis.
International Data Transfers
Data processed by nunusala may be transferred to, stored in, or accessed from locations outside the country of origin to support cloud services, third-party providers, or remote project teams. Transfers are managed with appropriate contractual and technical safeguards.
When transferring data internationally, nunusala relies on standard contractual clauses, data processing agreements, and technical controls such as encryption to protect personal data consistent with applicable law.
Data Retention
Personal data is retained only as long as necessary to fulfill the purposes for which it was collected, to satisfy contractual obligations, or to meet legal and regulatory requirements.
Client account records and contractual documents are retained for the period necessary to provide services and for statutory record-keeping obligations, typically no less than the period required by applicable accounting and tax rules.
Communications, support tickets, and project correspondence are retained for the duration of the engagement and for a reasonable period afterwards to address follow-up support and historical reference needs.
System logs and technical diagnostics may be retained for a defined period to support security monitoring and incident response; retention periods are limited and reviewed periodically.
When retention periods expire, data is securely deleted or anonymized unless further retention is required by law or legitimate business need documented by nunusala.
Security Measures
nunusala implements organizational, technical, and physical measures appropriate to the nature of the data and the processing risks. Controls are designed to protect confidentiality, integrity, and availability of personal data used in AI development and hosting environments.
- Access controls and role-based permissions limiting data access to authorized personnel only.
- Encryption of data in transit and, where appropriate, at rest to protect sensitive information during storage and transmission.
- Operational controls including regular audits, vulnerability management, and incident response procedures to detect and address security events.
User Rights
Individuals may exercise applicable rights with respect to their personal data. Requests will be processed in accordance with legal requirements and may require verification of identity.
- Request access to personal data processed by nunusala relating to the requester.
- Request correction of inaccurate or incomplete personal data.
- Request deletion or restriction of processing where applicable under law.
- Object to processing based on legitimate interests, unless overriding lawful grounds apply.
- Request data portability where processing is based on consent or contract and the data is processed by automated means.
- Withdraw consent for processing where consent was the legal basis, without affecting the lawfulness of prior processing.
- Lodge a complaint with a supervisory authority if an individual considers nunusala's processing contrary to applicable data protection laws.
- Obtain information about international transfers and the safeguards applied to protect transferred data.
How to Submit Rights Requests
You may request access to, correction of, restriction of processing of, portability of, or deletion of personal data that nunusala holds about you. To submit a request, provide your name, contact details, and a clear description of the request. We may ask for additional information to verify your identity before processing requests. Responses are provided in accordance with applicable law and our internal verification procedures.
Requests will be acknowledged within 7 calendar days. We aim to respond to validated requests within 30 calendar days of verification. If we need additional time due to complexity or volume, we will inform you of an estimated timeframe and reasons for the extension.
Marketing Communications
With your consent, nunusala may send informational emails, newsletters, and updates about product developments, events, and services related to AI software development and business AI adoption. Marketing communications will include clear information on the topics covered and the sender identity. You may manage your preferences or opt out at any time.
To unsubscribe from marketing communications, use the unsubscribe link included in any marketing email, or visit https://nunusala.digital/unsubscribe. You may also contact our privacy team using the contact details below to update communication preferences.
Children's Privacy
nunusala does not offer services targeted at children under 13 years of age and does not knowingly collect personal data from children under that age. If we become aware that we have collected personal data from a child under 13 without appropriate consent, we will take steps to delete the data as required by applicable law.
Third-Party Links
The site may contain links to third-party sites, services, or tools that are not operated by nunusala. We are not responsible for the privacy practices or content of those third parties. Review the privacy policies of any third-party services before providing personal data to them.
Changes to This Privacy Notice
We may update this privacy notice to reflect changes in our practices, regulatory requirements, or services. Material changes will be posted on our website with an updated effective date. Continued use of our services after changes indicates acceptance of the updated notice.