Privacy policy for cybroko

This privacy policy explains how cybroko collects, uses, stores, and discloses personal data in connection with software development services, client portals, and our website. It reflects our professional approach to data handling and our commitment to transparency about processing activities. The policy applies to clients, contractors, website visitors, and end users of software solutions we provide in 2026.

2026-02-05 cybroko ขอนแก่น 3065, Sila Sub District, Amphoe Mueang Khon Kaen District, Khon Kaen Province 40000, Thailand [email protected]

Key definitions

For clarity, we define terms used in this policy so readers can easily understand the categories of data and processing activities mentioned throughout.

Personal data refers to any information that can identify an individual directly or indirectly, such as name, contact details, identifiers, or information linked to a device or account used to access cybroko services.
Processing means any operation performed on personal data, including collection, storage, use, transfer, erasure, or modification carried out in the course of providing software development and related services.
User refers to an individual who interacts with cybroko systems, including clients' employees, administrators, or end users of applications we develop and maintain.
Service describes the software development, deployment, maintenance, and support services provided by cybroko to its clients, including web and mobile applications, integration work, and back-office tools.
Cookies are small text files placed on a device by a website to remember preferences, maintain sessions, and assist in analytics and security. cybroko uses cookies to operate the website and improve user experience.

Data we collect

We collect personal data that is necessary to deliver contracted services, support clients, secure systems, and comply with legal obligations. Collection follows principles of data minimization and purpose limitation.

Data provided directly by users

Information users supply when engaging with our services, registering accounts, submitting requests, or communicating with our team.

  • Contact details (name, professional email address, phone number) required to establish and manage client relationships.
  • Company and billing information, including business identification number (for example, Business ID 5577966414708) and invoicing address.
  • Project specifications, technical requirements, and uploaded documents used to design and implement software solutions.
  • Support requests and correspondence content submitted through help channels, including troubleshooting logs provided by users.
  • Account credentials and profile settings necessary to grant access to client portals and development environments.
  • Consent choices and marketing preferences explicitly indicated by the user.

Automatically collected data

When users interact with the website or our hosted applications, we collect certain technical data automatically to secure services, measure performance, and improve functionality.

  • Device and browser identifiers, IP address, and basic system configuration used for security and compatibility checks.
  • Usage metrics such as visited pages, feature usage, timestamps, and session durations to inform product improvements.
  • Crash logs and application diagnostics when users consent to share telemetry for debugging.
  • Authentication logs and access records to support incident contribute and user administration.
  • Cookie data consistent with the cookie policy to enable sessions and analytics.
  • IP-based geolocation approximations to route servers and detect anomalous access patterns.

Data from third parties

We may receive information from third-party providers or integration partners to deliver and operate services, subject to contractual data protection requirements.

  • Payment processors and invoicing platforms supplying transaction confirmations and billing status.
  • Identity providers or single sign-on services that authenticate users and share account identifiers with consent.
  • Cloud service providers and monitoring tools that supply logs and performance metrics used for operation and troubleshooting.

Purposes of processing

Personal data is processed only for clearly stated, legitimate purposes directly related to the provision and improvement of cybroko services.

  • To provide, configure, and maintain software solutions and client portals.
  • To communicate with clients and users about projects, support issues, and scheduled maintenance.
  • To process billing, payments, and contractual obligations tied to delivered services.
  • To protect systems from abuse and to contribute security incidents or suspected fraud.
  • To analyze product usage and operational performance to prioritize engineering work and service improvements.
  • To comply with legal or regulatory requirements and respond to lawful requests from authorities.
  • To manage employment, contractor relationships, and vendor onboarding where applicable.
  • To provide optional marketing communications to subscribers who have explicitly opted in.

Legal bases for processing

Where applicable, cybroko relies on appropriate legal bases to process personal data, such as contractual necessity, legitimate interests, consent, and compliance with legal obligations.

  • Contract performance: processing necessary to fulfill obligations under client agreements and deliver services.
  • Legitimate interests: processing for security, fraud prevention, product development, and business administration where those interests do not override individual rights.
  • Consent: where users have provided clear consent for optional processing such as marketing or diagnostic telemetry.
  • Legal compliance: processing required to comply with statutory duties or lawful requests from public authorities.

Data subject rights (where applicable)

For individuals in jurisdictions where GDPR-like rights apply, cybroko provides mechanisms to exercise standard data subject rights and supports lawful handling of requests.

  • Right of access: you can request a copy of personal data we hold about you relating to service provision.
  • Right to rectification: you may request correction of inaccurate or incomplete personal data.
  • Right to erasure: under certain circumstances, you may request deletion of personal data, subject to contractual and legal retention obligations.
  • Right to restrict processing: you may request that processing be limited where accuracy is contested or processing is unlawful.
  • Right to data portability: where processing is based on consent or contract and is automated, you may request personal data in a commonly used format.
  • Right to object: you can object to processing based on legitimate interests; we will assess and respond in line with applicable law.

Cookie policy summary

cybroko uses cookies and similar technologies to enable website functionality, remember preferences, and collect analytics. Users can manage cookie settings through their browser or our cookie banner where offered.

Types of cookies we use include session cookies for authentication, persistent cookies for preferences, and analytics cookies for performance measurement.

Categories include essential (required for site operation), performance and analytics (used to improve services), and optional marketing cookies (used only with consent).

You can control cookies through browser settings to refuse or delete cookies. Note that disabling essential cookies may limit certain site functions and access to client portals.

Full cookie policy

How we share data

We limit data sharing to necessary third parties and partners under contractual safeguards. Sharing is carried out only to provide services, comply with legal obligations, or with legitimate operational partners.

  • Service providers engaged to manage hosting, payment processing, analytics, and customer support under data processing agreements.
  • Authorized subcontractors and development partners who require access to project data to deliver contracted work.
  • Legal or regulatory authorities when required by law or to respond to lawful requests.
  • Potential acquirers or advisors in the context of a business transaction, subject to confidentiality and due diligence safeguards.
  • Aggregated or anonymized datasets that do not identify individuals and are used for internal analysis.
  • Emergency disclosures to protect the safety of individuals or the security of systems, limited to relevant information only.

International data transfers

Because cybroko relies on global cloud providers and partners, some processing may occur outside Thailand. Transfers are managed with appropriate contractual safeguards and technical protections to maintain data confidentiality.

We use standard contractual clauses, data processing agreements, and where applicable, data localization measures to ensure transfers meet legal and security requirements.

Data retention

We retain personal data only as long as necessary to fulfill the purposes described, to meet contractual obligations, and to comply with legal retention periods applicable in 2026.

Account information and billing records are typically retained for the duration of the contractual relationship plus a limited period for accounting and legal compliance, normally not exceeding statutory periods required by tax law.

Support correspondence and project communications are retained for as long as necessary to resolve issues and to maintain an audit trail of project decisions.

Technical logs and diagnostic data are retained for operational and security purposes for a defined period, then anonymized or deleted according to retention schedules.

When data is no longer required and no legal reason to retain it exists, we securely delete or anonymize it using industry-standard procedures.

Security measures

cybroko follows a risk-based security program combining technical controls, operational policies, and staff training to protect personal data against unauthorized access, disclosure, alteration, or destruction.

  • Access controls and role-based permissions limiting data access to authorized personnel only.
  • Encryption in transit and at rest for sensitive data, alongside secure key management practices.
  • Regular vulnerability assessments, patch management, and incident response procedures to detect and mitigate threats.

User rights and how to exercise them

If you are an individual whose data we process, you have certain rights to access and control that data. We provide clear channels to exercise these rights and respond in a timely manner consistent with applicable law.

  • To request access, correction, deletion, or transfer of your personal data held by cybroko, contact our privacy team using the contact details below.
  • To object to processing or withdraw consent where processing is based on consent; withdrawal will not affect processing carried out prior to withdrawal.
  • Access: You may request a copy of personal data we hold about you and details on how we process it, including categories of data, purposes, and recipients.
  • Rectification: You can request correction of inaccurate or incomplete personal information so records remain current and reliable for business processing.
  • Erasure: Where applicable under local law, you may request deletion of personal data when retention is no longer necessary or processing lacks a legal basis.
  • Restriction of processing: You can request limits on how we process specific personal data pending verification of accuracy or disputes about processing grounds.
  • Data portability: For data you provided directly, you may request a structured, commonly used, machine-readable copy to transfer to another provider when technically feasible.
  • Object to processing: You may object to processing based on legitimate interests or direct marketing; we will assess and respond according to applicable law and business needs.

How to exercise your rights

To submit a request to access, correct, erase, or restrict processing of your personal data, please contact cybroko at the contact details below. Include sufficient information to identify yourself and describe the request so we can locate relevant records and respond efficiently.

[email protected]

We will acknowledge receipt of your request within 7 business days and aim to provide a substantive response within 30 calendar days. If we need more time, we will notify you, explain the reason, and indicate an estimated response timeframe.

Marketing communications

cybroko may send informational and promotional communications related to software development services, updates, and industry insights. Communications are only sent to users who have opted in, or where permitted by applicable law based on a legitimate interest assessment.

You can opt out of marketing communications at any time using the unsubscribe link in emails, replying with a clear unsubscribe request, or contacting our privacy team. Processing for service-related messages may continue as required to perform contractual obligations.

Children's privacy

Our services are aimed at businesses and professionals. We do not knowingly collect personal data from children under the age specified by local regulation. If we become aware that we have collected data of a minor without appropriate consent, we will take steps to delete it promptly.

Links to third-party services

Our website and services may contain links to external sites or integrate third-party tools. cybroko is not responsible for the privacy practices of external sites. Review third-party privacy notices before sharing personal information with them.

Changes to this privacy policy

We periodically review and update our privacy practices to reflect legal, technical, or operational changes. Material changes will be posted on our site with an updated effective date. Continued use of our services after changes indicates acceptance of the revised policy.