Interior Architecture
Privacy Policy
PRIVACY POLICY
Kunya Interior
Last Updated: January 24, 2025
Effective Date: January 24, 2025
Version: 1.0
1. Introduction
8KUNYA Interior Co.,Ltd. ("Kunya Interior," "we," "us," or "our") is a professional interior architecture firm based in Bangkok, Thailand. We are committed to protecting your privacy and personal data in accordance with the highest standards of data protection.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you:
-
Use our website
-
Contact us for project inquiries or consultations
-
Engage our services for interior design or architecture projects
-
Visit our office or showroom
-
Interact with our social media accounts and digital platforms (Instagram, Facebook, TikTok, LinkedIn, LINE)
-
Communicate with us through any channel (email, WhatsApp, LINE, phone)
-
Subscribe to our newsletter or promotional materials
-
Attend events, exhibitions, or presentations hosted by us
This Privacy Policy should be read in conjunction with our Terms of Service, which govern your use of our services.
Data Controller:
Kunya Interior
25 Lat Phrao 101 Road, Soi 50
Khlong Chan, Bang Kapi
Bangkok 10240
Thailand
Email: contact@8kunya.com
Data Protection Contact: Data Protection Officer
Email: contact@8kunya.com
2. Legal Basis for Processing
We process your personal data in accordance with the following legal frameworks:
2.1 Primary Legal Framework
-
Thailand Personal Data Protection Act (PDPA) B.E. 2562 (2019) - Our primary governing law as a Thailand-based company
-
Thai Civil and Commercial Code - Governing our contractual relationships with clients and business partners
-
Thai Consumer Protection Act - For consumer rights and protection in service delivery
2.2 International Data Protection Laws
-
EU General Data Protection Regulation (GDPR) - Applicable when:
-
Processing data of EU residents (for international clients)
-
Using EU-based service providers or software platforms (Infomaniak - Switzerland)
-
Sharing client data with partner companies, suppliers, or contractors located in the EU
-
Collaborating with European designers, architects, or brands
-
-
Other applicable international data protection laws - As relevant to our international clients' nationalities and jurisdictions
2.3 Legal Bases for Data Processing
We process your personal data based on one or more of the following legal grounds:
Consent (PDPA Section 19)
-
When you explicitly agree to provide your personal data
-
For marketing communications and newsletters
-
For photography/videography of completed projects
-
For testimonials and case studies
Contract Performance (PDPA Section 24(1))
-
To fulfill our contractual obligations for interior design and architecture services
-
To process payments and manage project deliveries
-
To coordinate with contractors, suppliers, and vendors on your behalf
Legitimate Interests (PDPA Section 24(4))
-
To improve our services and client experience
-
To maintain business records and documentation
-
To ensure security of our premises and digital systems
-
To manage client relationships and project portfolios
Legal Obligations (PDPA Section 24(2))
-
To comply with Thai tax and accounting requirements
-
To respond to legal requests and regulatory requirements
-
To maintain records as required by professional standards
2.4 Client Project Data
Important Note: When you engage our services, you voluntarily provide personal data necessary for project execution. This includes contact information, project requirements, budget details, and site access information. By signing a service agreement with us, you consent to our collection and use of this information for project delivery purposes.
2.5 Cross-Border Data Processing
Given our collaborations with international suppliers, manufacturers, design brands, and contractors, we may process personal data across borders. We ensure compliance with applicable data protection laws when:
-
Sharing project specifications with international furniture or materials suppliers
-
Collaborating with foreign architects, designers, or consultants
-
Using cloud-based design software or project management platforms hosted internationally (Google Workspace, Microsoft Office, Adobe, iCloud)
-
Processing payments through international payment gateways
-
Using international social media platforms (Instagram, Facebook, TikTok, LinkedIn) and communication tools (WhatsApp, LINE)
We implement appropriate safeguards to ensure your data remains protected regardless of where it is processed.
3. What Personal Data We Collect
3.1 Information You Provide Directly
Client Contact & Registration Data:
-
Full name (first name and family name)
-
Email address (personal and/or business)
-
Phone number (mobile and/or office)
-
Mailing address
-
Preferred method and language of communication (LINE, WhatsApp, email, phone)
-
Company name and position (for corporate clients)
-
Profile photograph (optional)
Project & Property Information:
-
Property address and location details
-
Property type (residential, commercial, hospitality, etc.)
-
Property size and specifications
-
Ownership status (owner, tenant, developer)
-
Access information (gate codes, security procedures, key arrangements)
-
Existing conditions and architectural plans
-
Property photographs and documentation
-
Timeline and deadline requirements
Design Preferences & Requirements:
-
Design style preferences and inspiration references
-
Functional requirements and space usage needs
-
Color, material, and finish preferences
-
Furniture and fixture preferences
-
Lifestyle information relevant to design decisions
-
Special requirements (accessibility, pet-friendly, child-safe, etc.)
-
Cultural or religious considerations affecting design
Budget & Financial Information:
-
Project budget range
-
Payment preferences and financial constraints
-
Billing address (if different from property address)
-
Tax identification information (for invoicing)
-
Payment authorization and signature
Contractual Documents:
-
Signed service agreements and contracts
-
Project scope documents and amendments
-
Terms of engagement and acknowledgments
-
Consent forms for site access and photography
Communication & Feedback Data:
-
Messages sent through contact forms or email
-
WhatsApp, LINE, or other messaging app communications
-
Phone call records and meeting notes
-
Site visit reports and consultation notes
-
Feedback, testimonials, and survey responses
-
Before/after project feedback and satisfaction ratings
3.2 Information Collected Automatically
Technical & Website Data:
-
IP address and approximate location data
-
Browser type and version
-
Device information (operating system, device type, screen size)
-
Website usage patterns and navigation data
-
Cookies and similar tracking technologies (via Wix platform)
-
Time stamps and session duration
-
Referral sources (how you found our website)
Analytics Data:
-
Page views and click patterns
-
User journey and behavior on our website
-
Portfolio browsing patterns
-
Contact form interactions
-
Performance metrics and error logs
Social Media Interaction Data:
-
Social media engagement metrics (likes, shares, comments, follows) when you interact with our content on Instagram, Facebook, TikTok, LinkedIn, LINE
-
Note: We do not actively monitor or collect your personal social media activity beyond public interactions with our official accounts
3.3 Project Documentation & Visual Data
Photography & Videography:
-
Progress photos taken during construction/installation
-
Final project photography for portfolio and marketing
-
Video walkthroughs or time-lapse documentation
-
Drone photography (where applicable and consented)
-
Behind-the-scenes content creation
-
Social media content for Instagram, Facebook, TikTok
Design & Technical Documents:
-
Architectural drawings and floor plans
-
3D renderings and visualizations (created with architecture software and Adobe tools)
-
Material specifications and mood boards
-
Product selections and supplier information
-
Installation instructions and technical specifications
-
AI-generated design concepts and variations (created with AI LLMs)
3.4 Payment & Transaction Information
-
Transaction details and payment history
-
Payment method information (processed securely through payment providers)
-
Deposit and milestone payment records
-
Invoices and receipts
-
Refund or adjustment records
-
Note: We do not store complete credit card details on our servers
3.5 Third-Party & Vendor Coordination Data
Information shared for project execution:
-
Contact details shared with contractors, suppliers, and vendors
-
Site access schedules shared with installation teams
-
Delivery addresses shared with furniture and materials suppliers
-
Special instructions for service providers
-
Coordination details with property management or building authorities
3.6 Data Completeness Requirements
Certain information marked as "required" or "mandatory" during our intake process must be provided to:
-
Process your initial inquiry or consultation request
-
Prepare accurate project proposals and quotations
-
Execute design and architecture services effectively
-
Coordinate with contractors, suppliers, and vendors
-
Ensure compliance with building codes and regulations
-
Complete payment processing and invoicing
The mandatory nature of each data field is clearly indicated during the consultation, proposal, and contracting processes.
4. How We Use Your Personal Data
4.1 Client Relationship Management
-
Legal Basis: Performance of contract (PDPA Section 24(1)) and consent (PDPA Section 19)
-
Managing initial inquiries and consultation requests
-
Maintaining client records and project portfolios in our systems
-
Providing personalized design services and recommendations
-
Managing ongoing client relationships and repeat business
-
Maintaining historical records of completed projects
-
Following up on project satisfaction and after-sales support
-
Communicating via your preferred channels (LINE, WhatsApp, email, phone)
4.2 Design & Project Execution
-
Legal Basis: Performance of contract (PDPA Section 24(1)) and legitimate interests (PDPA Section 24(4))
-
Developing design concepts, mood boards, and presentations tailored to your preferences using Adobe Creative Suite and architecture software
-
Creating AI-assisted design variations and explorations using AI LLMs
-
Creating architectural drawings, floor plans, and 3D visualizations
-
Preparing project proposals, quotations, and cost estimates using Microsoft Office and Google Workspace
-
Sourcing and specifying furniture, materials, fixtures, and finishes
-
Coordinating with contractors, suppliers, vendors, and subcontractors for project execution
-
Managing project timelines, milestones, and deliverables
-
Conducting site visits, measurements, and progress inspections
-
Overseeing installation, construction, and final styling
-
Providing project documentation and as-built drawings
-
Arranging final walkthroughs and handover procedures
-
Storing and organizing project files via iCloud and Google Workspace
4.3 Vendor & Contractor Coordination
-
Legal Basis: Performance of contract (PDPA Section 24(1)) and legitimate interests (PDPA Section 24(4))
-
Sharing project specifications with furniture and materials suppliers
-
Coordinating delivery schedules and site access with vendors
-
Providing contractor teams with necessary site information and contact details
-
Managing procurement of custom furniture, fixtures, and finishes
-
Facilitating communication between you and service providers via LINE, WhatsApp, or email
-
Ensuring quality control and compliance with design specifications
4.4 Communication & Updates
-
Legal Basis: Performance of contract (PDPA Section 24(1)), consent (PDPA Section 19), and legitimate interests (PDPA Section 24(4))
-
Sending project updates, progress reports, and milestone notifications via email, LINE, or WhatsApp
-
Responding to inquiries, questions, and support requests
-
Scheduling consultations, site visits, and meetings
-
Sharing design presentations and approval requests
-
Providing payment reminders and invoice notifications
-
Communicating changes, delays, or issues requiring your attention
-
Sending newsletters, design inspiration, and promotional materials (with your consent)
4.5 Payment Processing & Financial Management
-
Legal Basis: Performance of contract (PDPA Section 24(1)) and legal obligation (PDPA Section 24(2))
-
Processing deposits, milestone payments, and final payments
-
Generating invoices, receipts, and tax documents using Microsoft Office and Google Workspace
-
Managing refunds or adjustments where applicable
-
Maintaining financial records for accounting and tax purposes
-
Verifying payment status and resolving payment issues
4.6 Legal Compliance & Documentation
-
Legal Basis: Legal obligation (PDPA Section 24(2)) and legitimate interests (PDPA Section 24(4))
-
Complying with Thai tax laws and accounting requirements
-
Maintaining records as required by professional standards and regulations
-
Responding to legal requests, investigations, and regulatory inquiries
-
Protecting our rights and interests in legal proceedings or disputes
-
Ensuring compliance with building codes, safety regulations, and permits
-
Managing insurance and liability documentation
4.7 Website Operations & Security
-
Legal Basis: Legitimate interests (PDPA Section 24(4))
-
Operating and maintaining our website via Wix platform
-
Managing domain and email services via Infomaniak
-
Ensuring website security and preventing fraud or unauthorized access
-
Managing user accounts and access permissions (if applicable)
-
Troubleshooting technical issues and improving user experience
-
Monitoring system performance and security threats
4.8 Analytics & Service Improvements
-
Legal Basis: Consent (PDPA Section 19) for non-essential analytics; legitimate interests (PDPA Section 24(4)) for aggregated/anonymized analytics
-
Understanding client behavior, preferences, and trends
-
Improving our design services, processes, and client experience
-
Analyzing website usage to optimize navigation and content via Wix analytics
-
Conducting market research and industry analysis
-
Developing new services or design offerings based on client needs
-
Training our team on best practices and client service excellence
4.9 Marketing & Portfolio Development
-
Legal Basis: Consent (PDPA Section 19)
-
Client Approval Required: Any use of project photos, client testimonials, or identifying information for marketing purposes requires explicit prior written approval from the client
-
Creating portfolio content showcasing completed projects (with consent)
-
Publishing case studies or project features on our website or social media (Instagram, Facebook, TikTok, LinkedIn)
-
Preparing award submissions or design competition entries (with consent)
-
Promoting our services to prospective clients using anonymized or consented project examples
-
Participating in design publications, exhibitions, or media features (with consent)
-
Creating before/after transformations and design inspiration content (with consent)
-
Sharing content on social media platforms including Instagram, Facebook, TikTok, and LinkedIn
Important: We will never publish your property photos, address, or personal information publicly without your explicit written consent.
4.10 Quality Control & Risk Management
-
Legal Basis: Legitimate interests (PDPA Section 24(4)) and performance of contract (PDPA Section 24(1))
-
Documenting site conditions and project progress
-
Monitoring quality of workmanship and materials
-
Managing project risks and resolving issues promptly
-
Maintaining records for warranty and after-sales support
-
Ensuring health and safety compliance on project sites
-
Protecting against potential disputes through thorough documentation
5. Data Sharing and Recipients
5.1 Contractors & Construction Teams
Purpose: Project execution, construction, and installation services
Data Shared: Contact details, property address, site access information, project specifications, design drawings, timelines
Legal Basis: Performance of contract and legitimate interests
We share necessary client data with contractors and construction teams for the purpose of:
-
Executing construction, renovation, or installation work
-
Coordinating site access and work schedules
-
Ensuring design specifications are implemented correctly
-
Managing project timelines and deliverables
Contractor Characteristics:
-
Licensed and insured construction professionals
-
Specialized tradespeople (electricians, plumbers, carpenters, painters, etc.)
-
Installation teams for furniture, fixtures, and finishes
-
HVAC, lighting, and smart home system installers
Data Access Scope:
-
Contractors receive only information necessary for their specific scope of work
-
Access to property is limited to agreed project timeframes
-
Contractors are contractually required to maintain confidentiality
-
Once shared, contractors are responsible for protecting the data they receive
-
We require contractors to use client data only for the stated project purpose and to handle it securely
5.2 Furniture & Materials Suppliers
Purpose: Procurement, customization, and delivery of furniture, fixtures, and materials
Data Shared: Contact details, delivery address, product specifications, measurements, special requirements
Legal Basis: Performance of contract and legitimate interests
We share client information with suppliers for:
-
Processing custom furniture orders and specifications
-
Coordinating delivery schedules and logistics
-
Arranging installation or assembly services
-
Managing warranties and after-sales support
-
Facilitating direct communication for product selections
Supplier Types:
-
Furniture manufacturers and showrooms (local and international)
-
Fabric, wallpaper, and materials suppliers
-
Lighting fixture suppliers
-
Hardware and fixture suppliers
-
Custom millwork and joinery workshops
-
Flooring suppliers and installers
Data Protection:
-
Suppliers receive only information necessary for order fulfillment
-
We work with reputable suppliers who maintain professional standards
-
Client contact information is shared only when direct coordination is necessary
5.3 Design Consultants & Specialists
Purpose: Specialized design services and technical expertise
Data Shared: Project requirements, site information, design briefs, technical specifications
Legal Basis: Performance of contract and legitimate interests
We may collaborate with external specialists including:
-
Architects and structural engineers
-
Lighting designers
-
Landscape architects
-
Acoustic consultants
-
Feng Shui or Vastu consultants
-
Art consultants and curators
-
Smart home technology specialists
Confidentiality: All consultants are bound by professional confidentiality agreements
5.4 Service Providers & Technology Platforms
Purpose: Business operations, project management, and service delivery
Data Shared: Varies by service provider; only data necessary for the specific service
Legal Basis: Legitimate interests and performance of contract
Service Provider Categories:
Website & Hosting Services:
-
Wix - Website platform and hosting
-
Location: USA/Global CDN
-
Privacy policy: https://www.wix.com/about/privacy
-
-
Infomaniak - Domain registration and email hosting
-
Location: Switzerland
-
Privacy policy: https://www.infomaniak.com/en/legal/confidentiality-policy
-
Cloud & Productivity Services:
-
Google Workspace - Email, cloud storage, collaboration
-
Location: USA/Global
-
Privacy policy: https://policies.google.com/privacy
-
-
Microsoft Office - Document creation and management
-
Location: USA/Global
-
Privacy policy: https://privacy.microsoft.com
-
-
iCloud - File storage and synchronization
-
Location: USA/Global (Apple)
-
Privacy policy: https://www.apple.com/legal/privacy
-
-
Adobe Creative Cloud - Design and creative software
-
Location: USA/Global
-
Privacy policy: https://www.adobe.com/privacy.html
-
Architecture & Design Software:
-
Various architecture and design software platforms for technical drawings, 3D modeling, and project visualization
-
Data processing typically occurs on local devices with cloud synchronization
AI & Machine Learning Tools:
-
AI LLMs (Large Language Models) - For design assistance, content creation, and project optimization
-
Various providers
-
Used to enhance design concepts and communications
-
No sensitive client data shared without consent
-
Communication Tools:
-
LINE - Client messaging and communication
-
Location: Japan
-
Privacy policy: https://line.me/en/terms/policy
-
-
WhatsApp Business - Client messaging
-
Location: USA (Meta)
-
Privacy policy: https://www.whatsapp.com/legal/privacy-policy
-
-
Zoom/Microsoft Teams - Virtual consultations (if used)
-
Privacy policies: https://zoom.us/privacy, https://privacy.microsoft.com
-
Social Media Platforms:
-
Instagram (Meta) - Business profile and marketing
-
Facebook (Meta) - Business page and client engagement
-
TikTok - Content sharing and marketing
-
LinkedIn - Professional networking and business development
-
Privacy policies available on respective platforms
-
Location: Services may be hosted with providers in Thailand, EU/EEA, USA, Switzerland, Japan, or other jurisdictions with adequate data protection safeguards
Safeguards: Data processing agreements and appropriate technical and organizational measures are in place with all service providers
5.5 Photography & Videography Services
Purpose: Project documentation and marketing content creation
Data Shared: Property address, access arrangements, project details, client name (only if approved for publication)
Legal Basis: Consent (PDPA Section 19)
-
We engage professional photographers/videographers to document completed projects
-
Client Approval Required: Photography for marketing purposes requires your explicit written consent
-
Photographers are bound by confidentiality and usage agreements
-
You control whether your property can be identified or featured publicly
-
Content may be shared on Instagram, Facebook, TikTok, and LinkedIn with your consent
5.6 Delivery & Logistics Companies
Purpose: Transportation and delivery of furniture, materials, and fixtures
Data Shared: Delivery address, contact phone number, special delivery instructions, recipient name
Legal Basis: Performance of contract
-
Local and international shipping companies
-
White-glove delivery services for high-value items
-
Installation and assembly teams affiliated with delivery services
-
Data shared only for delivery coordination and confirmation
5.7 Property Management & Building Authorities
Purpose: Compliance, permits, and building regulations
Data Shared: Property address, project scope, technical drawings, contractor information, timeline
Legal Basis: Legal obligation and performance of contract
Shared with (where applicable):
-
Condominium or building management offices
-
Homeowners' associations (HOA)
-
Local building authorities and permit offices (Bangkok Metropolitan Administration)
-
Fire safety and building inspection departments
Purpose: Obtaining necessary approvals, ensuring compliance with building codes, coordinating building access
5.8 Insurance Providers
Purpose: Professional liability and project insurance coverage
Data Shared: Limited project details, property type, project value (no personal client details unless necessary for claims)
Legal Basis: Legitimate interests and legal obligation
-
Professional indemnity insurance providers
-
Project-specific insurance coverage
-
Liability insurance for contractor coordination
5.9 Legal & Professional Advisors
Purpose: Legal, accounting, and professional services
Data Shared: Contract details, financial records, dispute-related information (as necessary)
Legal Basis: Legal obligation and legitimate interests
Recipients may include:
-
Legal counsel for contract review or dispute resolution
-
Accounting firms for tax and financial compliance
-
Professional associations or regulatory bodies (if applicable)
-
Auditors and compliance consultants
Confidentiality: All professional advisors are bound by professional privilege and confidentiality obligations
5.10 Business Partners & Collaborators
Purpose: Joint projects, referrals, or collaborative design services
Data Shared: Only with your explicit consent; typically limited to contact information and project interests
Legal Basis: Consent (PDPA Section 19)
Examples:
-
Real estate developers for collaborative projects
-
Interior styling services for final touches
-
Furniture rental companies for staging
-
Complementary design services (e.g., garden design, home automation)
Transparency: We will always inform you before sharing your data with business partners
5.11 Legal Authorities & Regulatory Bodies
Purpose: Compliance with legal obligations and protection of rights
Data Shared: Only information required by law or legal process
Legal Basis: Legal obligation (PDPA Section 24(2))
Circumstances where data may be shared:
-
To comply with court orders, subpoenas, or legal processes
-
To respond to requests from government authorities or law enforcement
-
To protect our rights, safety, or property in legal proceedings
-
To prevent fraud, illegal activity, or safety threats
-
To comply with tax, regulatory, or professional licensing requirements
5.12 Data Sharing Principles
Across all recipient categories, we follow these principles:
✓ Minimum Necessary: We share only the data required for the specific purpose
✓ Need-to-Know Basis: Recipients receive information only when necessary for their role in your project
✓ Contractual Protection: Where possible, recipients are bound by data protection and confidentiality agreements
✓ Transparency: We inform you about data sharing that affects your project
✓ Client Control: For marketing or non-essential sharing, we obtain your explicit consent
✓ Secure Transfer: We use secure methods to transmit sensitive information (encrypted email, secure file sharing)
✓ Third-Party Accountability: Once data is shared, recipients become responsible for their own data protection practices
6. International Data Transfers
Some of our service providers, suppliers, and design partners may process your data outside Thailand. When this occurs, we ensure adequate protection through appropriate safeguards as required by the Thailand PDPA and international data protection standards.
6.1 Transfer Mechanisms and Safeguards
We use recognized transfer safeguards where required, including:
-
Adequacy Decisions: Relying on jurisdictions deemed to have adequate data protection standards
-
Standard Contractual Clauses: Using model contracts approved by data protection authorities
-
Binding Corporate Rules: For multinational suppliers with internal data protection policies
-
Explicit Consent: Obtaining your consent for specific international transfers when required
-
Additional Technical Measures: Encryption, pseudonymization, and secure transfer protocols
6.2 Common International Data Processing Scenarios
Cloud Service Providers:
-
Google Workspace (USA/Global) - email, cloud storage, collaboration
-
Microsoft Office 365 (USA/Global) - productivity software
-
iCloud (USA/Global - Apple) - file storage
-
Adobe Creative Cloud (USA/Global) - design software
-
Infomaniak (Switzerland) - domain and email hosting
-
Wix (USA/Global) - website hosting
International Communication Platforms:
-
WhatsApp (USA - Meta/Facebook)
-
Instagram (USA - Meta/Facebook)
-
Facebook (USA - Meta)
-
TikTok (China/Singapore - ByteDance)
-
LinkedIn (USA - Microsoft)
-
LINE (Japan)
Architecture & Design Software:
-
Various international software providers for CAD, 3D modeling, rendering
AI & Machine Learning Services:
-
AI LLMs and related services (various international providers)
International Suppliers & Brands:
-
European furniture brands and manufacturers (Italy, Germany, Scandinavia)
-
American lighting and fixture suppliers
-
Asian furniture manufacturers (China, Vietnam, Indonesia)
-
Custom manufacturing partners in various countries
Payment Processing:
-
International payment gateways for credit card processing
-
Cross-border transactions for international supplier payments
6.3 Supplier and Partner Data Transfers
-
Limited Scope: International suppliers receive only information necessary for order fulfillment
-
Purpose Limitation: Data shared only for specific project purposes
-
Independent Controllers: Once shared, international partners act as independent data controllers responsible for their own compliance
-
Contractual Obligations: We require partners to protect your data and use it only for agreed purposes
-
Client Awareness: When selecting international suppliers or services, you are informed which companies will receive your data
6.4 Your Rights and Transparency
-
Informed Choices: We inform you when selecting international suppliers or services
-
Right to Object: You may object to international transfers and request alternative solutions where feasible
-
Data Subject Rights: Your PDPA rights apply regardless of where your data is processed
-
Alternative Options: Where possible, we can suggest local alternatives if you prefer to avoid international transfers
6.5 Specific Country Transfers
Switzerland:
-
Infomaniak (domain and email hosting)
-
Swiss suppliers and brands
United States:
-
Google (Workspace, Analytics)
-
Microsoft (Office, Cloud services)
-
Apple (iCloud)
-
Adobe (Creative Cloud)
-
Meta/Facebook (WhatsApp, Instagram, Facebook)
-
LinkedIn
-
TikTok operations
-
Wix (website platform)
-
Various design software providers
-
Some furniture and lighting brands
Japan:
-
LINE (messaging platform)
European Union (EU/EEA):
-
Furniture and materials suppliers
-
Design software and cloud services
-
Some payment processors
China/Singapore:
-
TikTok (ByteDance)
Asia Pacific:
-
Furniture manufacturers (Vietnam, Indonesia, Malaysia)
-
Materials suppliers
-
Regional logistics companies
6.6 Ongoing Compliance Monitoring
We continuously monitor the legal landscape regarding international data transfers, including:
-
PDPA Compliance: Ensuring transfers comply with Thailand's Personal Data Protection Act
-
Adequacy Decisions: Monitoring changes in recognized adequate jurisdictions
-
Enhanced Safeguards: Implementing additional security measures for sensitive data transfers
-
Transfer Impact Assessments: Evaluating risks associated with specific international transfers
-
Vendor Due Diligence: Regular review of international service providers' data protection practices
Note: The regulatory landscape for international data transfers continues to evolve. We are committed to adapting our practices to ensure continued compliance with applicable data protection laws while maintaining the quality and functionality of our design services.
7. Data Retention
7.1 General Retention Principle
We retain personal data only as long as necessary for project execution, client relationship management, and compliance with legal obligations. Once our business relationship ends and all legal retention requirements are satisfied, personal data is deleted or anonymized.
This typically includes:
-
Contact and registration information
-
Project specifications and design documents
-
Communication records
-
Payment and financial records
-
Project photography and documentation (subject to consent and usage rights)
7.2 Specific Retention Periods
Active Client Projects:
-
All project-related data retained throughout the duration of the project
-
Retention continues through warranty periods and after-sales support
-
Data maintained while actively working on your project(s)
Completed Projects:
-
Project files, drawings, and specifications: 5 years after project completion
-
Purpose: Warranty support, future renovation reference, professional liability
-
Client can request earlier deletion after warranty period ends
Financial & Payment Records:
-
7 years after the end of the fiscal year in accordance with Thai Revenue Code requirements
-
This applies regardless of other deletion requests
-
Includes invoices, receipts, contracts, payment records, tax documents
Communication Records:
-
Email and message correspondence (WhatsApp, LINE, email): 3 years after last communication
-
Meeting notes and consultation records: 3 years after project completion
-
Purpose: Reference for disputes, clarifications, or future projects
Marketing & Portfolio Content:
-
Project photography with client consent: Retained indefinitely until consent is withdrawn
-
Client testimonials: Retained indefinitely until consent is withdrawn
-
Case studies: Retained indefinitely until consent is withdrawn
-
Social media content (Instagram, Facebook, TikTok, LinkedIn): Until consent withdrawn
-
Clients may request removal from marketing materials at any time
Website Analytics Data:
-
Wix analytics data: Anonymized after 2 years maximum
-
Cookie data: As specified in cookie settings
-
Aggregate statistics: May be retained indefinitely in anonymized form
Legal Compliance & Dispute Records:
-
Records retained as required by applicable law or pending legal proceedings
-
Typically 10 years for professional liability purposes
-
May be extended if active litigation or disputes exist
Cloud Storage & Backups:
-
iCloud, Google Workspace, Microsoft Office files: Per active project and retention schedules
-
Complete deletion from backups may take up to 90 days after deletion request
Security Logs & Access Records:
-
System logs: 12 months for security and operational purposes
-
Access logs for sensitive projects: 2 years
Inactive Client Accounts:
-
If no activity for 3 years, we may contact you to confirm whether to retain or delete your data
-
Data deleted or anonymized after 5 years of complete inactivity unless legal retention applies
7.3 Data Deletion Process
Client-Initiated Deletion:
-
How to Request: Email us at contact@8kunya.com with subject "Data Deletion Request"
-
Identity Verification: We verify your identity for security purposes
-
Processing Timeline: Requests processed within 30 days of verification
-
Scope of Deletion:
-
All non-legally required data permanently deleted
-
Financial records retained for 7 years as required by law
-
Marketing content removed if consent withdrawn
-
Project files may be anonymized rather than deleted if needed for legal compliance
-
Cloud storage (Google Workspace, iCloud, Microsoft Office) purged
-
Social media content featuring your project removed
-
What Gets Deleted:
-
Contact information and profile data
-
Communication records and correspondence (email, LINE, WhatsApp)
-
Project preferences and notes (unless legally required)
-
Marketing consent and newsletter subscriptions
-
Website usage data and cookies
-
Files stored in Google Workspace, iCloud, Microsoft Office
What May Be Retained (Legal Requirements):
-
Financial records (7 years - Thai Revenue Code)
-
Contracts and legal documents (professional liability period)
-
Anonymized project data for internal analysis
-
Data required for ongoing legal proceedings or disputes
Automatic Deletion:
-
Analytics data automatically anonymized after 2 years
-
Security logs automatically deleted after 12 months
-
Temporary files and cache cleared regularly
-
Cookie data managed per your cookie preferences
-
Cloud backup rotation (90-day cycle)
7.4 Third-Party Data Retention
Contractors, Suppliers, and Service Providers:
-
Once project data is shared with third parties (contractors, suppliers, vendors), they become independent controllers
-
We require contractually that they use data only for project purposes and delete it afterwards
-
Client Rights: To request deletion from third-party systems, you must contact them directly
-
Our Assistance: We can provide you with:
-
List of contractors/suppliers who received your data
-
Contact information for each party
-
Approximate dates when data was shared
-
Guidance on exercising your rights with each party
-
Service Provider Retention:
-
Google Workspace, Microsoft Office, iCloud, Adobe, Wix, Infomaniak: Per their respective retention policies
-
LINE, WhatsApp, Instagram, Facebook, TikTok, LinkedIn: Per platform policies
-
We can assist you in identifying which platforms hold your data
Marketing Photography/Videography:
-
Professional photographers retain raw files per their contracts and industry standards
-
Published content remains available unless you withdraw consent
-
We can facilitate communication with photographers for data deletion requests
7.5 Project Portfolio & Archive Management
Internal Archives:
-
We maintain anonymized project archives for design reference and portfolio development
-
Personal identifiers (names, addresses, contact info) removed after retention period
-
Visual documentation (photos) retained only with explicit ongoing consent
Published Portfolio:
-
Projects published with your consent remain available until you request removal
-
You can withdraw consent for marketing use at any time
-
Removal from website typically within 14 days of withdrawal request
-
Social media content (Instagram, Facebook, TikTok, LinkedIn) removed upon request
-
Third-party publications (magazines, awards) cannot be retroactively removed by us
7.6 Legal and Regulatory Compliance
Thai Revenue Code: Financial records retained for 7 years regardless of deletion requests
Professional Liability: Project documentation may be retained for professional liability purposes even after client requests deletion (typically 5-10 years)
PDPA Compliance: Retention periods align with data minimization principles while respecting legal obligations
Industry Standards: Compliance with Thai architecture and design professional standards
7.7 Secure Deletion Procedures
When data is deleted:
-
Operational Systems: Data permanently deleted from active databases
-
Backups: Data removed from backups through regular rotation cycles (typically within 90 days)
-
Cloud Storage: Data deleted from Google Workspace, iCloud, Microsoft Office, Adobe per their deletion procedures
-
Physical Documents: Securely shredded or destroyed
-
Documentation: Deletion actions documented where appropriate for accountability
-
Legal Holds: Data subject to legal obligations retained in restricted, secure systems
-
Communication Platforms: Message history removed from LINE, WhatsApp, email systems
Note: Complete deletion from all backup systems may take up to 90 days due to backup rotation schedules. However, your data will be immediately inaccessible in operational systems.
7.8 Data Retention Transparency
-
We maintain internal records of retention periods for different data categories
-
Upon request, we can provide information about how long specific data will be retained
-
We review and update retention policies annually to ensure compliance and best practices
Recommendation: Clients should maintain their own copies of important project documents, drawings, and specifications for their records.
8. Your Rights Under Data Protection Law
Under the Thailand Personal Data Protection Act (PDPA) and international data protection laws (where applicable), you have the following rights:
8.1 Right of Access (PDPA Section 30)
What you can request:
-
Confirmation of whether we are processing your personal data
-
Information about how we process your data (purposes, categories, recipients)
-
A copy of all personal data we hold about you
-
Details about data retention periods
-
Information about data sources (if not collected directly from you)
-
Information about automated decision-making (if applicable)
How to access your data:
-
Request by Email: Contact us at contact@8kunya.com for a complete data access report
-
Data Format: We provide data in the most relevant format:
-
PDF for contracts and correspondence
-
Excel/CSV for structured data
-
ZIP file for design documents and images
-
Original formats for technical drawings and Adobe files
-
What we provide:
-
Contact and profile information
-
Project details and specifications
-
Communication history (email, LINE, WhatsApp messages)
-
Payment and financial records
-
Design documents and approvals
-
List of third parties who received your data (contractors, suppliers, cloud services)
-
Consent records and preferences
-
Files stored in Google Workspace, iCloud, Microsoft Office
Timeline: We respond within 30 days of your request (may be extended by 30 days for complex requests with notification)
8.2 Right to Rectification (PDPA Section 31)
Correcting inaccurate or incomplete data:
-
Request Corrections: Email us at contact@8kunya.com to correct:
-
Incorrect personal details
-
Outdated project information
-
Inaccurate records or documentation
-
Incomplete information
-
Our Process:
-
We verify the correction request
-
Update our systems within 30 days
-
Notify relevant third parties of corrections where necessary
-
Confirm completion of updates to you
Important: For project-related technical information (specifications, measurements), corrections must be verified to ensure accuracy and safety.
8.3 Right to Erasure / "Right to be Forgotten" (PDPA Section 32)
When you can request deletion:
-
Personal data no longer necessary for the purpose collected
-
You withdraw consent (for consent-based processing)
-
You object to processing and no overriding legitimate grounds exist
-
Personal data processed unlawfully
-
Legal obligation requires deletion
How to request deletion:
-
Email: contact@8kunya.com
-
Subject: "Data Deletion Request - [Your Name]"
-
Include: Full name, project details, email address used
What gets deleted:
-
Contact information and profile data
-
Communication records (email, LINE, WhatsApp)
-
Marketing preferences and subscriptions
-
Non-essential project documentation
-
Website usage and analytics data (Wix)
-
Files in cloud storage (Google Workspace, iCloud, Microsoft Office)
-
Social media content featuring your project (Instagram, Facebook, TikTok, LinkedIn)
What may be retained (Legal Limitations):
-
Financial records: 7 years (Thai Revenue Code requirement)
-
Contracts: Professional liability period (5-10 years)
-
Legal documents: Required for compliance or ongoing disputes
-
Anonymized data: Statistical and analytical data with identifiers removed
Third-Party Data:
-
For data held by contractors, suppliers, vendors, or cloud service providers (Google, Microsoft, Apple, Adobe, etc.), we provide contact information
-
You must request deletion directly from third parties
-
We can assist by providing necessary contact details and guidance
Timeline: Processing within 30 days (immediate removal from operational systems; backup rotation may take up to 90 days)
8.4 Right to Restrict Processing (PDPA Section 33)
When you can request restriction:
-
You contest the accuracy of personal data (until we verify accuracy)
-
Processing is unlawful but you prefer restriction over deletion
-
We no longer need the data, but you need it for legal claims
-
You object to processing (pending verification of our legitimate grounds)
What restriction means:
-
Data stored but not actively processed
-
Limited use only for:
-
Legal claims or proceedings
-
Protection of rights of others
-
Important public interests
-
With your explicit consent
-
How to request:
-
Email us at contact@8kunya.com with specific reasons for restriction
-
We evaluate each request case-by-case
-
Restriction implemented within 30 days if approved
Example scenarios:
-
Disputing billing or project records during investigation
-
Legal proceedings requiring data preservation
-
Transitional period while resolving complaints
8.5 Right to Data Portability (PDPA Section 34)
What you can receive:
-
Personal data you provided to us
-
In structured, commonly used, machine-readable format
-
Only for data processed based on consent or contract
Included data:
-
Contact and profile information (CSV, JSON, or Excel)
-
Project specifications and requirements (PDF, Excel)
-
Communication records (PDF or text format)
-
Preferences and selections (CSV or JSON)
-
Uploaded documents and images (original formats)
-
Design files (original formats from Adobe, architecture software)
Excluded data:
-
Data generated by us (internal notes, evaluations)
-
Third-party proprietary information
-
Data affecting rights of others
Transmission options:
-
Direct download from secure link
-
Email transfer (encrypted if sensitive)
-
Cloud storage link (Google Drive, iCloud, OneDrive)
-
Direct transmission to another provider (where technically feasible)
Timeline: Provided within 30 days of request
8.6 Right to Object (PDPA Section 35)
Processing you can object to:
-
Marketing communications and direct marketing
-
Processing based on legitimate interests
-
Profiling and automated decision-making
-
Use of data for purposes beyond original consent
Absolute Right to Object:
-
Direct Marketing: You can opt out at any time, no questions asked
-
Effect: We immediately stop sending marketing materials (email, LINE messages, social media)
Conditional Right to Object:
-
Legitimate Interest Processing: We must stop unless we demonstrate compelling legitimate grounds
-
Essential Processing: We cannot stop processing necessary for contract performance or legal compliance
How to object:
-
Marketing: Unsubscribe link in emails, or contact us at contact@8kunya.com
-
Other Processing: Email with specific objection and reasons
-
Selective Objection: Object to specific uses while continuing the relationship
Timeline: Marketing opt-outs processed immediately; other objections evaluated within 30 days
8.7 Right to Withdraw Consent (PDPA Section 19)
When consent can be withdrawn:
-
For any processing based solely on your consent
-
At any time, for any reason
-
Withdrawal does not affect lawfulness of prior processing
Consent-based processing areas:
-
Newsletter and promotional communications
-
Marketing photography and portfolio use
-
Social media sharing of project content (Instagram, Facebook, TikTok, LinkedIn)
-
Optional data collection (beyond contract requirements)
-
Non-essential cookies and tracking (Wix analytics)
-
Testimonials and case studies
-
AI-assisted design explorations (if optional)
How to withdraw consent:
-
Email: contact@8kunya.com
-
Subject: "Withdraw Consent - [Specific Purpose]"
-
Unsubscribe Links: In marketing emails
-
Cookie Settings: Via website cookie banner (Wix)
-
Written Notice: For marketing photo/content usage
Effect of withdrawal:
-
Immediate cessation of consent-based processing
-
Removal from marketing materials within 14 days
-
Social media content removal upon request
-
No impact on contract-based services
-
No penalties or negative consequences
Note: Withdrawing consent for essential project communications may affect our ability to complete your project.
8.8 Right to Lodge a Complaint (PDPA Section 78)
If you believe we have not adequately addressed your data protection concerns:
Thailand:
-
Personal Data Protection Committee (PDPC)
-
Website: https://www.pdpc.or.th
-
Email: pdpc@mdes.go.th
-
Phone: +66 (0) 2141 6993
-
Address: Office of the Personal Data Protection Committee Ministry of Digital Economy and Society 120 Moo 3, Government Complex, Chaengwattana Road Laksi, Bangkok 10210 Thailand
EU (for EU residents):
-
Your local data protection authority
-
List available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
Before filing a complaint:
-
We encourage you to contact us first so we can address your concerns directly
-
Many issues can be resolved through direct communication
-
We take data protection concerns seriously and respond promptly
8.9 Rights of Children and Minors
-
We do not knowingly collect data from individuals under 20 years old without parental consent (as per Thai law)
-
Parents/guardians can exercise rights on behalf of minors
-
Special care taken with family residential projects involving children
8.10 Assistance with Third-Party Rights Requests
For data held by contractors, suppliers, vendors, or service providers:
Our support:
-
Provide contact information for relevant third parties
-
Share details of when and what data was transferred
-
Provide documentation of data sharing
-
Offer guidance on exercising your rights with each party
-
Facilitate communication upon request
What we can provide:
-
Complete list of contractors/suppliers who received your data
-
List of service providers (Google, Microsoft, Apple, Adobe, Wix, Infomaniak, LINE, WhatsApp, etc.)
-
Project timeline and data sharing dates
-
Copies of data sharing agreements (where applicable)
-
Templates for rights requests to third parties
Note: Third parties are independent data controllers responsible for their own compliance. We cannot control their response times or decisions, but we will assist you in contacting them.
9. How to Exercise Your Rights
9.1 Contact Information for Rights Requests
Email: contact@8kunya.com
Subject Line: "Data Protection Request - [Your Name] - [Specific Right]"
Postal Address: Kunya Interior 25 Lat Phrao 101 Road, Soi 50 Khlong Chan, Bang Kapi Bangkok 10240 Thailand
Communication Channels:
-
Email (preferred): contact@8kunya.com
-
LINE: [Your LINE Official Account if applicable]
-
WhatsApp: [Your WhatsApp Business number if applicable]
9.2 Required Information for Requests
To process your request efficiently and securely, please provide:
Essential Information:
-
Your full name (as provided to us)
-
Email address and/or phone number on file
-
Project name or reference number (if applicable)
-
Specific right you wish to exercise
-
Clear description of your request
Identity Verification:
-
Copy of ID card or passport (for security purposes)
-
Additional verification may be required for sensitive requests
-
We may ask security questions to confirm your identity
Optional but Helpful:
-
Approximate dates of our business relationship
-
Specific data categories you're inquiring about
-
Preferred format for data delivery (for access requests)
-
Preferred communication channel (email, LINE, WhatsApp)
9.3 Response Timeline
Standard Timeframe:
-
30 days from receiving a valid request
-
If verification or clarification needed, the clock starts once we have complete information
Extensions:
-
For complex requests, we may extend by an additional 30 days
-
We will notify you within the initial 30 days if extension is needed
-
We will explain the reason for any delay
Urgent Requests:
-
Marketing opt-outs: Immediate (within 24 hours)
-
Security or safety concerns: Priority handling
-
Consent withdrawal: Immediate cessation of affected processing
9.4 Fees and Charges
Generally Free:
-
First request for each right: No charge
-
Reasonable requests: No charge
-
Standard data formats: No charge
Fees May Apply:
-
Manifestly unfounded requests: Administrative fee may apply
-
Excessive requests: Repeated requests within short timeframe
-
Large-volume data exports: Complex requests requiring significant resources
-
Physical copies: Printing and shipping costs for physical document requests
Fee Notification:
-
We notify you before applying any fee
-
You can withdraw or modify your request before incurring charges
-
Fees are reasonable and reflect actual costs
9.5 Request Evaluation Process
Upon receiving your request:
-
Acknowledgment: We confirm receipt within 3 business days
-
Verification: We verify your identity for security
-
Evaluation: We assess the request for validity and scope
-
Processing: We gather and prepare the requested information or action
-
Response: We provide complete response with explanation
-
Follow-up: We ensure your satisfaction with the resolution
9.6 Reasons We May Decline Requests
We may refuse or limit requests if:
-
Identity cannot be verified: Security concerns prevent processing
-
Legal obligations prevent deletion: Required retention periods apply (e.g., 7-year financial records)
-
Manifestly unfounded or excessive: Repeated unreasonable requests
-
Rights of others affected: Your request impacts privacy of others
-
Legal proceedings: Active litigation requires data preservation
-
Public interest: Important public health or safety reasons
If we decline:
-
We explain the specific reason for refusal
-
We provide information about complaint mechanisms (PDPC contact)
-
We suggest alternative solutions where possible
9.7 Format and Delivery of Information
Data Access Requests:
Electronic Delivery (Preferred):
-
Secure download link (password-protected)
-
Encrypted email attachment
-
Google Drive, OneDrive, or iCloud shared link
-
WeTransfer or similar secure file sharing
Physical Delivery:
-
Printed documents sent by registered mail (fees may apply)
-
USB drive sent by courier (for large digital files)
-
Available upon specific request
Data Formats:
-
Structured data: CSV, Excel, JSON (machine-readable)
-
Documents: PDF (for contracts, correspondence)
-
Images: Original formats (JPG, PNG, RAW)
-
Technical drawings: Original CAD formats (DWG, SKP) or PDF
-
Design files: Adobe formats (PSD, AI, INDD) or PDF
-
Mixed content: ZIP archive with organized folders
9.8 Language and Accessibility
-
Requests can be made in Thai or English
-
Responses provided in the language of the request
-
Alternative formats available for accessibility needs
-
Large print or simplified language upon request
9.9 Designated Contact Person
Data Protection Officer Email: contact@8kunya.com Subject: "Attention: Data Protection Officer"
For complex data protection inquiries, you may request direct communication with our Data Protection Officer.
9.10 Third-Party Assistance
-
You may authorize a representative to make requests on your behalf
-
Written authorization required with clear scope
-
We may contact you directly to verify authorization
-
Legal representatives (lawyers, family members) accepted with proper documentation
10. Cookies and Tracking Technologies
10.1 What Are Cookies?
Cookies are small text files stored on your device when you visit our website. They help us provide you with a better experience and understand how our website is used.
10.2 Types of Cookies We Use
Essential Cookies
-
Purpose: Required for basic website functionality via Wix platform
-
Examples:
-
Session management and security
-
Website functionality and navigation
-
Load balancing and performance
-
-
Legal Basis: Legitimate interests (necessary for service provision)
-
Can you opt-out? No - these are required for the website to function
-
Duration: Session cookies (deleted when browser closes) or up to 1 year
Analytics Cookies
-
Purpose: Understand website usage and improve user experience
-
What they track:
-
Page views and navigation patterns
-
Time spent on pages
-
Click behavior and interactions
-
Device and browser information
-
Geographic location (country/city level)
-
-
Services used:
-
Wix Analytics
-
Google Analytics (if enabled)
-
-
Legal Basis: Consent - analytics cookies are only activated if you accept via cookie banner
-
Can you opt-out? Yes - decline via cookie banner or opt-out directly with providers
-
Duration: Up to 2 years
-
Privacy safeguards: IP anonymization enabled, no personal identification
Functional Cookies
-
Purpose: Enhanced website features and personalization
-
Examples:
-
Language preferences (Thai/English)
-
Contact form pre-fill
-
Accessibility settings
-
-
Legal Basis: Legitimate interests
-
Can you opt-out? Yes - via cookie settings, but may affect user experience
-
Duration: 30 days to 1 year
Marketing Cookies (If applicable)
-
Purpose: Show relevant content and advertisements
-
Examples:
-
Facebook Pixel (Meta) - for Instagram and Facebook advertising
-
TikTok Pixel
-
LinkedIn Insight Tag
-
Google Ads remarketing (if used)
-
-
Legal Basis: Consent - only activated if you accept
-
Can you opt-out? Yes - decline via cookie banner
-
Duration: Up to 1 year
-
What they track:
-
Pages visited on our website
-
Services viewed
-
Source of traffic
-
10.3 Third-Party Cookies
Wix Platform:
-
Our website is built on Wix, which sets various cookies for functionality and analytics
-
Wix Privacy Policy: https://www.wix.com/about/privacy
Social Media Plugins:
-
Facebook, Instagram, LINE buttons may set cookies
-
TikTok, LinkedIn integration
-
Controlled by respective social media companies
Embedded Content:
-
YouTube video players (if embedded)
-
Google Maps (if embedded)
-
Third-party design portfolio viewers
Note: We do not control third-party cookies. Please review their privacy policies:
-
Facebook/Meta: https://www.facebook.com/privacy
10.4 Managing Cookies
Via Our Website:
-
Cookie Banner: When you first visit, you'll see a cookie consent banner (Wix)
-
Accept All: Enables all cookies for optimal experience
-
Reject Non-Essential: Only essential cookies will be used
-
Customize: Choose which cookie categories to accept
-
Change Anytime: Access cookie settings in website footer
Via Your Browser:
Google Chrome:
-
Settings > Privacy and Security > Cookies and other site data
Safari:
-
Preferences > Privacy > Manage Website Data
Firefox:
-
Options > Privacy & Security > Cookies and Site Data
Edge:
-
Settings > Cookies and site permissions
Mobile Browsers:
-
Similar settings in app preferences
Note: Blocking all cookies may affect website functionality (e.g., contact forms may not work properly).
10.5 Opt-Out Tools for Analytics
Google Analytics Opt-Out:
-
Browser add-on: https://tools.google.com/dlpage/gaoptout
-
Effect: Prevents Google Analytics from tracking you across all websites
Wix Analytics:
-
Managed through cookie consent banner on our website
-
Or through browser cookie settings
10.6 Do Not Track (DNT)
-
We respect "Do Not Track" browser settings where technically feasible
-
Note: DNT is not universally supported by all tracking technologies
-
For strongest privacy, combine DNT with cookie restrictions and opt-outs
10.7 Cookie Duration and Refresh
Session Cookies:
-
Deleted automatically when you close your browser
-
Used for temporary functionality during your visit
Persistent Cookies:
-
Remain on your device for specified duration
-
Shortest duration: 30 days (functional preferences)
-
Typical duration: 1 year (analytics, social media)
-
Longest duration: 2 years (aggregate analytics)
-
Automatically deleted when expired
10.8 Social Media Tracking
Facebook/Instagram (Meta) Pixel:
-
May track your visit even if you don't interact
-
Used for targeted advertising on Instagram and Facebook
-
Control via cookie settings
TikTok Pixel:
-
May track website visits for TikTok advertising
-
Control via cookie settings
LinkedIn Insight Tag:
-
May track visits for LinkedIn marketing
-
Control via cookie settings
LINE Official Account Integration:
-
May set cookies for LINE platform integration
-
Control via cookie settings
10.9 Pixel Tags and Web Beacons
-
Small transparent images embedded in emails or web pages
-
Used to track email opens and engagement
-
Can be blocked by disabling images in email client
-
Used for analytics and marketing effectiveness measurement
10.10 Local Storage and Similar Technologies
HTML5 Local Storage:
-
More persistent than cookies
-
Used by Wix platform for richer features
-
Can be cleared via browser settings
Flash Cookies / LSOs:
-
We do not use Flash technology
10.11 Cross-Site Tracking
-
We do not sell your data to third parties
-
Third-party cookies (e.g., Facebook, Google, TikTok) may track you across sites
-
Control via cookie settings and browser privacy features
-
We use tracking only to improve our services and relevant marketing
10.12 Cookie Policy Updates
-
We may update our cookie usage as technology and services evolve
-
Material changes communicated via website notice
-
Regular review and optimization of cookie practices
10.13 Contact About Cookies
Questions about our cookie practices?
Email: contact@8kunya.com Subject: "Cookie Inquiry"
We'll respond with detailed information about specific cookies and how to manage them.
11. Data Security
We implement comprehensive technical and organizational measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction.
11.1 Technical Security Measures
Encryption:
-
Data in Transit: SSL/TLS encryption (HTTPS) for all website communications via Wix
-
Data at Rest: Encrypted storage for sensitive client information
-
File Transfers: Secure protocols (encrypted email, secure cloud sharing via Google Drive, OneDrive, iCloud)
-
Backup Encryption: Encrypted backup systems
-
Database Encryption: Sensitive fields encrypted in databases
-
Cloud Storage: Encrypted storage in Google Workspace, Microsoft Office, iCloud, Adobe Creative Cloud
Access Controls:
-
Authentication: Strong password requirements for all systems
-
Multi-Factor Authentication (MFA): Enabled for Google Workspace, Microsoft Office, iCloud, Adobe
-
Role-Based Access: Team members access only data necessary for their role
-
Least Privilege Principle: Minimum necessary access rights assigned
-
Access Logs: All data access logged and monitored
-
Automatic Logout: Sessions expire after inactivity period
Infrastructure Security:
-
Secure Hosting: Wix platform with security certifications, Infomaniak for domain/email
-
Firewalls: Network-level and application-level firewalls
-
Intrusion Detection: Real-time monitoring for suspicious activity
-
DDoS Protection: Defense against denial-of-service attacks via Wix
-
Regular Updates: Security patches applied promptly to all systems
-
Vulnerability Scanning: Regular automated security scans
-
Penetration Testing: Periodic security assessments by professionals
Network Security:
-
Wifi Security: WPA3 encryption on office networks
-
Network Segmentation: Sensitive systems isolated
-
Guest Network: Separate network for visitors
-
VPN Access: Secure remote access when needed
Secure Development:
-
Security Testing: Testing for common vulnerabilities
-
Secure APIs: Authentication and rate limiting on API endpoints
-
Input Validation: Protection against malicious input
11.2 Organizational Security Measures
Staff Training:
-
Data Protection Training: Mandatory training for all team members
-
Onboarding Security: Security briefing for new hires
-
Regular Updates: Ongoing training on emerging threats
-
Phishing Awareness: Training to recognize social engineering attacks
-
Confidentiality Agreements: All staff sign confidentiality agreements
Access Management:
-
Need-to-Know Basis: Data access limited to essential personnel
-
Access Reviews: Regular audit of who has access to what data
-
Offboarding Process: Immediate access revocation when employees leave
-
Contractor Management: Third-party contractors bound by security requirements
-
Visitor Controls: Physical access controls for office visitors
Data Handling Procedures:
-
Clear Desk Policy: Sensitive documents secured when not in use
-
Secure Disposal: Shredding of physical documents, secure deletion of digital files
-
Document Classification: Sensitivity levels assigned to documents
-
Transfer Protocols: Standardized procedures for data sharing (encrypted email, secure cloud links)
-
Client File Management: Organized, secure storage of project files in Google Workspace, iCloud, Microsoft Office
Data Processing Agreements:
-
Vendor Contracts: Data protection clauses with all service providers (Wix, Infomaniak, Google, Microsoft, Adobe, etc.)
-
Contractor Agreements: Security requirements for contractors
-
Supplier Standards: Evaluation of third-party security practices
-
Regular Audits: Compliance verification with contract terms
Incident Response:
-
Response Plan: Documented procedures for security incidents
-
Incident Team: Designated personnel for incident response
-
Communication Plan: Protocols for notifying affected parties
-
Post-Incident Review: Analysis and improvement after incidents
-
Business Continuity: Plans for maintaining operations during incidents
Governance and Compliance:
-
Privacy by Design: Security considered from project inception
-
Data Protection Officer: Designated responsibility for data protection
-
Regular Audits: Internal reviews of security practices
-
Compliance Monitoring: Ongoing PDPA compliance verification
-
Documentation: Maintained records of security measures
11.3 Physical Security
Office Security:
-
Access Control: Secure building access at 25 Lat Phrao 101 Road
-
Secure Storage: Locked cabinets for sensitive physical documents
-
Visitor Management: Sign-in procedures for office visitors
-
After-Hours Security: Alarm systems and security protocols
Device Security:
-
Laptop Encryption: Full-disk encryption on company devices
-
Mobile Device Management: Security policies for mobile devices
-
Lost/Stolen Protocols: Remote wipe capability for lost devices
-
Secure Disposal: Professional destruction of old hardware
-
BYOD Policy: Security requirements for personal devices used for work
11.4 Cloud and Backup Security
Cloud Storage Security:
-
Reputable Providers: Certified cloud services
-
Google Workspace (Google Drive, Gmail)
-
Microsoft Office (OneDrive, Outlook)
-
iCloud (Apple)
-
Adobe Creative Cloud
-
Wix (website)
-
Infomaniak (domain and email)
-
-
Access Controls: Restricted and monitored cloud access
-
Encryption: Data encrypted in cloud storage
-
Two-Factor Authentication: Enabled on all cloud accounts
-
Geographic Location: Data stored in secure data centers
-
Compliance: Cloud providers meeting international security standards (ISO 27001, SOC 2)
Backup and Recovery:
-
Regular Backups: Automated daily backups of critical data
-
Encrypted Backups: Backup files encrypted
-
Cloud Backups: Stored across Google Drive, OneDrive, iCloud
-
Off-Site Storage: Backups stored in geographically separate cloud locations
-
Backup Testing: Regular verification of backup restoration
-
Retention Policy: Backups retained according to retention schedule (90-day rotation)
-
Disaster Recovery: Documented procedures for data recovery
11.5 Email and Communication Security
Email Protection:
-
Infomaniak Email Hosting: Secure email infrastructure in Switzerland
-
Google Workspace: Additional email accounts with advanced security
-
Spam Filtering: Advanced spam and malware filtering
-
Encryption: Encrypted email for sensitive communications (when requested)
-
Phishing Protection: Tools to detect and block phishing attempts
Communication Tools:
-
Secure Platforms: Use of reputable, encrypted communication tools
-
WhatsApp Business: End-to-end encrypted messaging
-
LINE Official Account: Secure messaging platform
-
Video Conferencing: Secure Zoom/Teams with waiting rooms and passwords (if used)
11.6 Payment Security
-
PCI DSS Compliance: Payment processing follows Payment Card Industry standards
-
No Card Storage: We never store complete credit card numbers
-
Secure Gateways: Third-party certified payment processors
-
Fraud Detection: Monitoring for suspicious transactions
-
Invoice Security: Secure delivery via email or cloud links
11.7 Data Breach Prevention and Detection
Prevention Measures:
-
Security Monitoring: Continuous monitoring of critical systems
-
Threat Intelligence: Staying informed about emerging threats
-
Anomaly Detection: Automated alerts for unusual access patterns
-
User Behavior Analytics: Identifying suspicious user behavior
-
Regular Updates: Timely application of security patches to all platforms
Detection Measures:
-
Log Analysis: Regular review of security logs
-
Incident Alerts: Real-time notifications of potential breaches
-
Cloud Platform Security: Leveraging security features of Google, Microsoft, Apple, Adobe
11.8 Data Breach Notification
In the event of a personal data breach affecting your data:
Our Response:
-
Internal Assessment: Immediate investigation and containment within 24 hours
-
Authority Notification: Report to Personal Data Protection Committee (PDPC) within 72 hours if required by law
-
Client Notification: Inform affected individuals without undue delay if high risk to rights and freedoms
-
Documentation: Comprehensive documentation of breach and response
-
Remediation: Immediate steps to prevent further breaches
What We Will Tell You:
-
Nature of the breach and data affected
-
Likely consequences and potential risks
-
Measures taken to address the breach
-
Recommendations for protecting yourself
-
Contact point for further information (contact@8kunya.com)
Your Actions:
-
Follow any specific guidance we provide
-
Monitor for unusual activity (if financial data affected)
-
Consider changing passwords if credentials compromised
-
Report suspicious activity to us immediately
11.9 Employee and Contractor Security
Background Checks:
-
Reference verification for new hires (where legally permitted)
-
Professional credential verification
Confidentiality Obligations:
-
Non-disclosure agreements (NDAs) with all staff
-
Confidentiality clauses in contractor agreements
-
Clear policies on data handling and confidentiality
Separation Procedures:
-
Immediate access revocation upon termination
-
Return of all company devices and documents
-
Exit interviews covering confidentiality obligations
11.10 Platform-Specific Security
Wix Platform Security:
-
Website hosted on Wix with enterprise-grade security
-
SSL certificates and HTTPS encryption
-
Regular security updates by Wix
-
DDoS protection and firewall
Infomaniak Security:
-
Swiss-based hosting with strong data protection
-
GDPR compliant
-
ISO 27001 certified
Google Workspace Security:
-
Enterprise-grade security and encryption
-
Advanced threat protection
-
Two-factor authentication
-
Data loss prevention
Microsoft Office 365 Security:
-
Enterprise security features
-
Advanced threat protection
-
Multi-factor authentication
iCloud Security:
-
Apple's security infrastructure
-
End-to-end encryption for sensitive data
-
Two-factor authentication
Adobe Creative Cloud Security:
-
Secure cloud storage
-
Access controls and encryption
-
Regular security updates
11.11 Continuous Improvement
Security Practices:
-
Regular Reviews: Annual comprehensive security audits
-
Industry Standards: Alignment with ISO 27001, NIST frameworks
-
Threat Landscape: Continuous monitoring of security trends
-
Vulnerability Management: Prompt remediation of identified vulnerabilities
-
Platform Updates: Keeping all cloud services and software up to date
Investment in Security:
-
Ongoing investment in security tools and training
-
Subscription to enterprise-grade security features
-
Consultation with security experts
-
Adoption of emerging security technologies
11.12 Security Limitations and User Responsibilities
What We Cannot Control:
-
Security of your personal devices
-
Strength of your passwords
-
Your email account security
-
Physical security of your location
-
Social engineering attacks targeting you directly
-
Security of your home WiFi network
Your Responsibilities:
-
Strong Passwords: Use unique, complex passwords for email and cloud accounts
-
Device Security: Keep your devices updated and protected
-
Phishing Awareness: Be cautious of suspicious emails, LINE messages, WhatsApp messages
-
Secure Networks: Avoid public WiFi for sensitive communications
-
Physical Security: Protect physical documents we provide
-
Report Incidents: Notify us immediately of security concerns via contact@8kunya.com
11.13 Security Questions?
For security-related inquiries:
Email: contact@8kunya.com Subject: "Security Inquiry"
To report a security concern: Email: contact@8kunya.com Subject: "URGENT: Security Incident Report"
12. Third-Party Links and Services
12.1 Third-Party Websites and Links
Our website and communications may contain links to external websites and services not operated by Kunya Interior. This Privacy Policy does not apply to third-party sites.
Examples of third-party links:
-
Supplier and manufacturer websites
-
Furniture brand catalogs
-
Design inspiration platforms (Pinterest, Houzz, etc.)
-
Social media profiles (Instagram, Facebook, TikTok, LinkedIn)
-
Review platforms
-
Industry associations
-
Blog references and resources
Important:
-
We are not responsible for privacy practices of third-party websites
-
Third-party sites have their own privacy policies
-
We encourage you to review privacy policies before providing personal information
-
Links do not imply endorsement of third-party privacy practices
12.2 Third-Party Services We Use
Website & Hosting Services:
Wix
-
Purpose: Website platform, hosting, and content management
-
Location: USA/Global CDN
-
Data collected: Website analytics, visitor behavior, form submissions
-
Privacy policy: https://www.wix.com/about/privacy
-
Opt-out: Cookie settings on our website
Infomaniak
-
Purpose: Domain registration and email hosting
-
Location: Switzerland (GDPR compliant)
-
Data collected: Domain registration info, email communications
-
Privacy policy: https://www.infomaniak.com/en/legal/confidentiality-policy
-
Security: ISO 27001 certified, Swiss data protection
Cloud & Productivity Services:
Google Workspace
-
Purpose: Email (Gmail), cloud storage (Google Drive), collaboration (Google Docs, Sheets)
-
Location: USA/Global data centers
-
Data collected: Email communications, stored documents, calendar data
-
Privacy policy: https://policies.google.com/privacy
-
Security: Enterprise-grade encryption, ISO 27001, SOC 2
-
Opt-out: Not possible for essential business operations
Microsoft Office / Office 365
-
Purpose: Document creation (Word, Excel, PowerPoint), cloud storage (OneDrive)
-
Location: USA/Global data centers
-
Data collected: Documents, email (if Outlook used), cloud files
-
Privacy policy: https://privacy.microsoft.com
-
Security: Enterprise-grade encryption, ISO 27001
-
Opt-out: Not possible for essential business operations
iCloud
-
Purpose: File storage, synchronization, backup
-
Location: USA/Global (Apple)
-
Data collected: Files, photos, documents
-
Privacy policy: https://www.apple.com/legal/privacy
-
Security: End-to-end encryption (for certain data types)
-
Opt-out: Not possible for business file management
Adobe Creative Cloud
-
Purpose: Design software (Photoshop, Illustrator, InDesign), cloud storage
-
Location: USA/Global
-
Data collected: Creative files, project data
-
Privacy policy: https://www.adobe.com/privacy.html
-
Security: Cloud encryption, access controls
-
Opt-out: Not possible for design operations
Architecture & Design Software:
Various architecture software platforms (e.g., AutoCAD, SketchUp, Revit, etc.)
-
Purpose: Technical drawings, 3D modeling, project visualization
-
Location: Varies by software (USA, Europe)
-
Data collected: Design files, project specifications
-
Privacy policies: Available on respective software websites
-
Security: Industry-standard encryption and access controls
AI & Machine Learning Services:
AI LLMs (Large Language Models)
-
Purpose: Design assistance, content creation, project optimization, communication drafting
-
Providers: Various AI service providers
-
Location: Varies (primarily USA)
-
Data collected: Text prompts, design queries, communication drafts
-
Important: We do not share sensitive client personal data with AI services without consent
-
Privacy: Each AI service has its own privacy policy
-
Usage: AI is used as a tool to enhance creativity and efficiency, not replace human judgment
Communication & Messaging Tools:
LINE Official Account
-
Purpose: Client messaging, project updates, customer service
-
Location: Japan
-
Data collected: Messages, contact information, interaction history
-
Privacy policy: https://line.me/en/terms/policy
-
Encryption: End-to-end encrypted messages
-
Opt-out: You can stop using LINE and use email instead
WhatsApp Business
-
Purpose: Client messaging, quick updates, media sharing
-
Location: USA (Meta/Facebook)
-
Data collected: Messages, phone numbers, media files
-
Privacy policy: https://www.whatsapp.com/legal/privacy-policy
-
Encryption: End-to-end encrypted
-
Opt-out: You can choose not to use WhatsApp
Social Media Platforms:
Instagram (Meta/Facebook)
-
Purpose: Portfolio showcase, client engagement, marketing
-
Location: USA
-
Data collected: Posts, interactions, engagement metrics, DM communications
-
Privacy policy: https://help.instagram.com/519522125107875
-
Business tools: Instagram Business account features
-
Opt-out: Don't follow or interact with our Instagram page
Facebook (Meta)
-
Purpose: Business page, client community, event announcements
-
Location: USA
-
Data collected: Page interactions, likes, comments, messages
-
Privacy policy: https://www.facebook.com/privacy
-
Facebook Pixel: May be used for advertising (with consent)
-
Opt-out: Don't follow or interact with our Facebook page
TikTok
-
Purpose: Design content, project showcases, marketing
-
Location: China/Singapore (ByteDance)
-
Data collected: Video views, interactions, engagement metrics
-
Privacy policy: https://www.tiktok.com/legal/privacy-policy
-
TikTok Pixel: May be used for advertising (with consent)
-
Opt-out: Don't follow or interact with our TikTok account
-
Purpose: Professional networking, B2B marketing, project showcases
-
Location: USA (Microsoft)
-
Data collected: Professional profile interactions, company page engagement
-
Privacy policy: https://www.linkedin.com/legal/privacy-policy
-
LinkedIn Insight Tag: May be used for analytics (with consent)
-
Opt-out: Don't follow or connect with our LinkedIn page
Payment Processing:
[Thai payment processors - e.g., 2C2P, Omise, Kasikorn Bank payment gateway]
-
Purpose: Secure payment processing
-
PCI DSS compliant: Yes
-
Data collected: Transaction details, payment method
-
Data storage: We do not store complete card numbers
-
Privacy policy: [Link to processor's policy]
Analytics & Tracking:
Wix Analytics
-
Built into Wix platform
-
Website usage statistics, visitor behavior
-
Privacy policy: https://www.wix.com/about/privacy
Google Analytics (if enabled)
-
Website traffic analysis
-
Privacy policy: https://policies.google.com/privacy
12.3 Data Processing Agreements
For all third-party service providers processing personal data on our behalf:
-
Contractual Protection: Terms of service and data processing agreements
-
PDPA Compliance: Services selected for data protection standards
-
Security Standards: Minimum security requirements verified
-
Purpose Limitation: Use restricted to specified purposes
-
Confidentiality: Confidentiality obligations in terms of service
-
International Standards: ISO 27001, SOC 2, GDPR compliance where applicable
12.4 International Service Providers
Many services we use are provided by international companies:
United States:
-
Google (Workspace, Analytics, Drive)
-
Meta/Facebook (WhatsApp, Instagram, Facebook)
-
Microsoft (Office 365, OneDrive, Teams)
-
Adobe (Creative Cloud)
-
Wix (website platform)
-
Various AI LLM providers
-
Various architecture software providers
Switzerland:
-
Infomaniak (domain and email)
Japan:
-
LINE (messaging platform)
China/Singapore:
-
TikTok (social media - ByteDance)
Safeguards:
-
Standard contractual clauses where applicable
-
Adequacy decisions (e.g., Switzerland)
-
Encryption and additional security measures
-
Enterprise-grade service agreements
-
Regular security audits of providers
12.5 Social Media Integrations
Embedded Social Media Content:
-
Facebook Like/Share buttons
-
Instagram feed embeds
-
TikTok embeds
-
LinkedIn sharing buttons
What this means:
-
These plugins may set cookies even if you don't click them
-
Social media companies may track your visit to our website
-
Control via cookie settings and browser privacy features
Our Social Media Pages:
When you interact with our official social media pages (Instagram, Facebook, TikTok, LinkedIn):
-
Your interactions governed by social media platform's privacy policy
-
We may see basic analytics (engagement metrics, demographics)
-
We do not collect additional data beyond platform-provided analytics
-
Direct messages are stored by the platform per their retention policies
12.6 Supplier and Manufacturer Portals
When we coordinate orders on your behalf:
-
Some suppliers require registration or data entry
-
We may create accounts using your information (with permission)
-
Supplier privacy policies apply to data they hold
-
We recommend reviewing terms if you interact directly with suppliers
Examples:
-
International furniture brand websites
-
Custom manufacturing portals
-
Materials specification databases
12.7 Cloud Storage and File Sharing
Google Drive
-
Sharing project files, design documents, client presentations
-
Privacy policy: https://policies.google.com/privacy
Microsoft OneDrive
-
File sharing and collaboration
-
Privacy policy: https://privacy.microsoft.com
Apple iCloud
-
File storage and synchronization
-
Privacy policy: https://www.apple.com/legal/privacy
Adobe Cloud
-
Creative files and project assets
-
Privacy policy: https://www.adobe.com/privacy.html
WeTransfer / Large File Transfer Services (if used)
-
Temporary sharing of large design files
-
Files typically deleted after 7 days
-
Privacy policy: Available on service website
12.8 Your Control Over Third-Party Data
You can:
-
Disable cookies to limit third-party tracking
-
Opt out of analytics services directly
-
Review and delete data held by third parties
-
Close accounts with third-party services
-
Exercise rights directly with service providers (Google, Microsoft, Apple, Adobe, Meta, LINE, TikTok, LinkedIn)
We can:
-
Provide information about which services we use
-
Assist in identifying relevant third parties for your data requests
-
Consider alternative services if you have privacy concerns
12.9 Changes to Third-Party Services
-
We may add, remove, or change service providers as needed for business operations
-
Material changes to key services will be reflected in Privacy Policy updates
-
We evaluate new services for privacy and security before adoption
12.10 Questions About Third-Party Services?
Email: contact@8kunya.com Subject: "Third-Party Service Inquiry"
We'll provide detailed information about specific services and their data practices.
13. Updates to This Privacy Policy
13.1 Why We May Update This Policy
We may revise this Privacy Policy from time to time to reflect:
-
Changes in Services: New services, features, or business practices
-
Legal Requirements: Updates to Thai PDPA, GDPR, or other applicable laws
-
Technology Changes: New tools, platforms, or data processing methods (e.g., new cloud services, AI tools)
-
Security Improvements: Enhanced data protection measures
-
Industry Best Practices: Adoption of improved privacy standards
-
Business Structure: Changes to our organization or ownership
-
User Feedback: Improvements based on client input
13.2 Types of Changes
Material Changes:
Changes that significantly affect your rights or how we use your data, such as:
-
New purposes for data processing
-
Sharing data with new categories of recipients
-
International transfers to new jurisdictions
-
Significant changes to data retention periods
-
Changes to legal bases for processing
-
New types of personal data collected
-
Major changes to third-party services (e.g., switching from Google to Microsoft)
Non-Material Changes:
Minor updates that don't significantly affect your rights, such as:
-
Clarifications or rephrasing for better understanding
-
Updated contact information
-
Corrections of typographical errors
-
Formatting improvements
-
Updates to third-party service names/links (e.g., new URLs)
-
Addition of examples or explanations
-
Minor platform updates (e.g., Wix platform upgrades)
13.3 How We Notify You of Changes
Material Changes - Active Notification:
-
Email Notification: Direct email to registered clients at least 14 days before changes take effect
-
Website Banner: Prominent notice on our website homepage (Wix)
-
Pop-up Notice: Alert when you visit our website after update
-
Social Media: Announcement on Instagram, Facebook, TikTok, LinkedIn
-
LINE/WhatsApp: Direct message to active clients (if you use these channels)
-
In-Person Notification: For active projects, during meetings or consultations
Email notification will include:
-
Summary of key changes
-
Effective date of new policy
-
Link to full updated policy
-
Information about your rights and options
-
How to contact us with questions (contact@8kunya.com)
Non-Material Changes - Passive Notification:
-
Updated "Last Updated" date at top of Privacy Policy
-
Changes log or revision history (if maintained)
-
No direct notification required
-
Available for review on our website
13.4 Effective Date of Changes
Material Changes:
-
Become effective 14 days after notification
-
Grace period allows time to review and ask questions
-
Continued use of services after effective date constitutes acceptance
Non-Material Changes:
-
Become effective immediately upon posting
-
No waiting period required
13.5 Your Options When Policy Changes
If you disagree with material changes:
Option 1: Contact Us
-
Discuss your concerns directly
-
We may be able to address specific issues
-
Email: contact@8kunya.com
-
LINE or WhatsApp: [if applicable]
Option 2: Withdraw Consent
-
Opt out of affected processing activities
-
May limit certain services but preserve basic relationship
Option 3: Request Data Deletion
-
Exercise your right to erasure
-
End business relationship if changes are unacceptable
-
We'll process per Section 8.3 (Right to Erasure)
Option 4: Lodge Complaint
-
Contact Personal Data Protection Committee (PDPC)
-
File complaint with relevant supervisory authority
13.6 Continued Use and Acceptance
By continuing to use our services after changes become effective, you:
-
Acknowledge you've been notified of changes
-
Had opportunity to review the updated Privacy Policy
-
Accept the new terms and conditions
-
Consent to updated data processing practices (where consent is the legal basis)
Important: If you continue an active project after policy changes, we interpret this as acceptance of the updated policy for that project.
13.7 Version Control and History
Current Policy:
-
Date prominently displayed at top of document
-
Version number: 1.0 (or subsequent versions)
-
Clear indication this is the current active policy
Previous Versions (If Available):
-
Archived versions may be available upon request
-
Historical comparison for transparency
-
Contact us if you need prior versions for reference
13.8 Frequency of Reviews
We review this Privacy Policy:
-
Annually: Comprehensive review at least once per year
-
Legislative Changes: Immediate review when laws change (PDPA updates)
-
Business Changes: Review when services or practices evolve
-
Technology Changes: Review when adopting new platforms (e.g., new cloud services, AI tools)
-
Incident Response: Review after any data breach or security incident
-
Continuous Improvement: Ongoing monitoring of privacy best practices
13.9 How to Stay Informed
To ensure you're aware of updates:
-
Subscribe to Newsletter: Receive notifications of important updates
-
Check Website: Review policy periodically at our website
-
Follow Social Media: Announcements on Instagram, Facebook, TikTok, LinkedIn
-
LINE Official Account: Updates via LINE messages
-
Contact Us: Ask if policy has been updated since your last review (contact@8kunya.com)
13.10 Specific Policy Sections Subject to Change
More likely to change:
-
Third-party services and integrations (Section 12) - as we adopt new tools
-
Cookie practices (Section 10) - as Wix updates features
-
International data transfers (Section 6) - as regulations evolve
-
Contact information
-
Social media platforms we use
Less likely to change:
-
Your fundamental rights (Section 8)
-
Legal bases for processing (Section 2)
-
Core principles of data protection
-
Thai law retention requirements (7 years for financial records)
13.11 Multi-Language Policy Updates
If policy is available in multiple languages:
-
All language versions updated simultaneously
-
English version is authoritative in case of conflicts
-
Thai translation provided for convenience
-
Notification in your preferred language (if known)
13.12 Questions About Policy Changes?
Before changes take effect:
-
Email questions to: contact@8kunya.com
-
Subject: "Privacy Policy Change Inquiry"
-
LINE or WhatsApp: [if applicable]
-
We'll respond before effective date
After changes take effect:
-
We remain available to discuss any concerns
-
Can explain rationale for changes
-
Will consider reasonable accommodation requests
13.13 Grandfather Provisions
For existing clients when policy changes:
-
Active Projects: May be subject to terms agreed at project start (unless material changes require updated consent)
-
Completed Projects: Historical data processing remains valid under original policy
-
Future Services: New policy applies to new projects or services
Clarification: We'll communicate clearly which version applies to your specific situation.
13.14 Emergency or Urgent Changes
In rare circumstances requiring immediate changes:
-
Security vulnerabilities requiring urgent action
-
Legal mandate with immediate compliance deadline
-
Critical business continuity situations
-
Platform security updates (e.g., Wix, Google, Microsoft emergency patches)
In such cases:
-
Changes may be effective immediately
-
Notification as soon as reasonably possible
-
Explanation of urgent circumstances
-
Retroactive notice within 48 hours
13.15 Your Responsibility to Review
We encourage you to:
-
Review this Privacy Policy periodically
-
Note the "Last Updated" date
-
Read notifications we send carefully
-
Ask questions if anything is unclear (contact@8kunya.com)
-
Exercise your rights if you disagree with changes
14. Contact Information
14.1 General Inquiries
Kunya Interior
Address: 25 Lat Phrao 101 Road, Soi 50 Khlong Chan, Bang Kapi Bangkok 10240 Thailand
Email: contact@8kunya.com
Business Hours: Monday - Friday: 9:00 AM - 6:00 PM (Bangkok time) Saturday: By appointment Sunday: Closed
Communication Channels:
-
Email: contact@8kunya.com (preferred for formal inquiries)
-
LINE Official Account: [Your LINE ID if applicable]
-
WhatsApp Business: [Your WhatsApp number if applicable]
-
Instagram: [@8kunya / @kunyainterior]
-
Facebook: [Your Facebook page]
-
TikTok: [Your TikTok handle]
-
LinkedIn: [Your LinkedIn page]
Website: [www.8kunya.com or www.kunyainterior.com]
14.2 Data Protection and Privacy Inquiries
For specific questions about how we handle your personal data:
Data Protection Officer
Email: contact@8kunya.com
Subject Line for Email: "Data Protection Inquiry - [Your Name]"
Alternative Contact:
-
LINE: [Your LINE Official Account]
-
WhatsApp: [Your WhatsApp Business number]
Response Time: We typically respond within 3-5 business days for general inquiries, and within 30 days for formal rights requests.
14.3 Formal Data Subject Rights Requests
To exercise your rights under Thailand PDPA (access, rectification, erasure, etc.):
Email: contact@8kunya.com
Subject Line: "Data Subject Rights Request - [Specific Right] - [Your Name]"
Required Information:
-
Your full name
-
Email address and/or phone number on file
-
Project reference number (if applicable)
-
Specific right you wish to exercise
-
Clear description of your request
-
Copy of ID for verification
Postal Address for Written Requests: Data Protection Officer Kunya Interior 25 Lat Phrao 101 Road, Soi 50 Khlong Chan, Bang Kapi Bangkok 10240 Thailand
14.4 Emergency or Security Concerns
For urgent security or data breach concerns:
Email: contact@8kunya.com
Subject Line: "URGENT: Security Incident Report"
Alternative:
-
LINE: [Immediate message for urgent matters]
-
WhatsApp: [For immediate response during business hours]
What constitutes an emergency:
-
Suspected data breach affecting your information
-
Unauthorized access to your project data
-
Lost or stolen documents containing your personal data
-
Suspicious communications claiming to be from us
-
Phishing attempts using our name
14.5 Project and Service Inquiries
For new project inquiries or consultations:
Email: contact@8kunya.com
Communication Channels:
-
LINE Official Account: [Your LINE ID]
-
WhatsApp Business: [Your WhatsApp number]
-
Instagram DM: [@8kunya / @kunyainterior]
-
Facebook Messenger: [Your Facebook page]
Website: Contact form at [your website URL]
14.6 Marketing and Communications Preferences
To manage your communication preferences:
Unsubscribe from Newsletter:
-
Click "Unsubscribe" link at bottom of any email
-
Email: contact@8kunya.com with subject "Unsubscribe"
Opt-Out of Marketing:
-
Email: contact@8kunya.com
-
Subject: "Opt-Out Request - [Your Name]"
Update Contact Preferences:
-
Email: contact@8kunya.com
-
Subject: "Update Communication Preferences"
-
Specify preferred channels (email, LINE, WhatsApp, none)
Social Media:
-
Unfollow our Instagram, Facebook, TikTok, LinkedIn pages
-
Block our accounts if you don't want to see content
14.7 Complaints and Feedback
Client Service Feedback:
Email: contact@8kunya.com Subject: "Feedback - [Your Name]"
We welcome:
-
Service improvement suggestions
-
Privacy practice feedback
-
Policy clarification requests
-
General comments or concerns
-
Suggestions for better communication
14.8 Supervisory Authority Contact
If you believe we have not adequately addressed your data protection concerns, you may contact:
Thailand:
Personal Data Protection Committee (PDPC)
-
Website: https://www.pdpc.or.th
-
Email: pdpc@mdes.go.th
-
Phone: +66 (0) 2141 6993
-
Address: Office of the Personal Data Protection Committee Ministry of Digital Economy and Society 120 Moo 3, Government Complex, Chaengwattana Road Laksi, Bangkok 10210 Thailand
European Union (for EU residents):
-
Your local data protection authority
-
Directory: https://edpb.europa.eu/about-edpb/about-edpb/members_en
Before filing a complaint:
-
We encourage you to contact us first so we can address your concerns directly
-
Many issues can be resolved through direct communication
-
We take data protection concerns seriously and respond promptly
14.9 Social Media and Online Presence
Official Accounts:
Instagram: [@8kunya or @kunyainterior]
-
Portfolio showcase, project updates, design inspiration
-
Direct messages for quick inquiries
Facebook: [Your Facebook page name/URL]
-
Business page, community engagement, events
TikTok: [Your TikTok handle]
-
Design content, behind-the-scenes, creative process
LinkedIn: [Your LinkedIn page URL]
-
Professional updates, B2B communication, industry insights
LINE Official Account: [Your LINE ID]
-
Direct client communication, project updates
Website: [Your website URL]
Note: Be cautious of imposter accounts. Our official accounts are the only ones using our verified brand name. We will never ask for sensitive personal information (passwords, full credit card numbers, ID numbers) via social media direct messages or LINE/WhatsApp.
14.10 Partners and Affiliates
For inquiries about our partners, suppliers, or contractors:
-
We can provide contact information for third parties who received your data
-
Assistance with exercising rights with third parties
-
List of current contractors and suppliers upon request
-
Information about cloud service providers (Google, Microsoft, Apple, Adobe)
Email: contact@8kunya.com Subject: "Third-Party Contact Information Request"
14.11 Media and Press Inquiries
For media, publications, or press inquiries:
Email: contact@8kunya.com Subject: "Media Inquiry - [Publication Name]"
Note: Any use of client project information for media requires explicit client consent. Media inquiries do not override privacy obligations.
14.12 Language Support
Communication Languages:
-
Thai (ภาษาไทย) - Full support
-
English - Full support
We can assist in:
-
Responding to inquiries in your preferred language
-
Providing translations of key documents
-
Bilingual consultations and project management
14.13 Response Times and Service Standards
Our Commitments:
-
General Inquiries: 3-5 business days
-
Data Subject Rights Requests: 30 days (may extend to 60 days for complex requests with notification)
-
Security Incidents: Immediate acknowledgment, full response within 24-48 hours
-
Complaint Resolution: Initial response within 5 business days
-
Urgent Matters: Same-day acknowledgment during business hours
-
LINE/WhatsApp Messages: Typically within 24 hours during business days
14.14 Mailing Address for Legal Notices
For formal legal communications, notices, or service of process:
Legal Department Kunya Interior 25 Lat Phrao 101 Road, Soi 50 Khlong Chan, Bang Kapi Bangkok 10240 Thailand
Attention: Data Protection Officer / Legal Representative
14.15 Accessibility Support
If you need assistance accessing this Privacy Policy or our services:
-
Large print versions available upon request
-
Alternative formats for accessibility needs
-
In-person consultations to explain privacy practices (at our office)
-
Simplified language explanations available
-
Visual aids and diagrams if helpful
Contact: contact@8kunya.com Subject: "Accessibility Assistance Request"
14.16 Office Visits
Visit us by appointment:
Address: 25 Lat Phrao 101 Road, Soi 50 Khlong Chan, Bang Kapi Bangkok 10240 Thailand
To Schedule:
-
Email: contact@8kunya.com
-
LINE: [Your LINE ID]
-
WhatsApp: [Your WhatsApp number]
-
Call during business hours
What to expect:
-
Design consultations and project discussions
-
Portfolio review
-
Material samples viewing
-
Privacy policy explanations in person
Parking: [Information about parking if available, or nearest parking]
Public Transport:
-
[Nearest BTS/MRT station if applicable]
-
[Bus routes if applicable]
-
[Directions from major landmarks]
14.17 After-Hours Contact
For existing clients with urgent project matters:
-
We may provide dedicated contact information for active projects
-
Emergency contact for time-sensitive issues
-
Generally, use LINE or WhatsApp for quickest response
Regular business inquiries:
-
Please email contact@8kunya.com
-
We respond on the next business day
Effective Date and Governing Language
Last Updated: January 24, 2025
Effective Date: January 24, 2025
Version: 1.0
Governing Language: This Privacy Policy is provided in English with Thai translation available upon request. In case of any conflict between language versions, the English version shall prevail.
Thai Version: [ไทย] available upon request at contact@8kunya.com
Acknowledgment
By using our services, visiting our website, communicating with us via email, LINE, WhatsApp, or social media, or providing us with your personal information, you acknowledge that you have read, understood, and agree to this Privacy Policy.
If you do not agree with this Privacy Policy, please do not use our services or provide us with your personal information.
For questions or concerns about this Privacy Policy, please contact us:
Email: contact@8kunya.com Address: 25 Lat Phrao 101 Road, Soi 50, Khlong Chan, Bang Kapi, Bangkok 10240, Thailand
Kunya Interior Creating beautiful spaces with privacy and trust
© 2025 Kunya Interior. All rights reserved.