Privacy Policy overview
This Privacy Policy explains how aitlawex collects, uses, discloses and safeguards personal data in connection with the educational platform and related services available at aitlawex.pro. The policy applies to course participants, trial users, customers and visitors. We present processing purposes, legal bases, retention practices and the rights available to individuals. Our operations are conducted from Thailand and we maintain administrative, technical and organizational measures appropriate to the sensitivity of the data we handle. For questions, contact our privacy team at [email protected] or by mail/phone at the contact details below. The policy is effective as of the date specified and may be updated to reflect operational or legal changes.
Key definitions
This section clarifies terms used throughout the policy to ensure consistent understanding of roles and data categories.
- Personal data means information relating to an identified or identifiable individual, such as name, email address, billing information and usage records linked to an account.
- Processing refers to any operation performed on personal data, including collection, storage, retrieval, use, disclosure and deletion.
- User means any individual who registers for or uses the aitlawex platform, including learners, instructors and administrative users.
- Service refers to the educational platform, courses, learning management features, billing services and related functionality provided at aitlawex.pro.
- Cookies are small text files placed on a device to store preferences, session information and identifiers that facilitate site functionality, analytics and personalization.
Data collection
We collect two main categories of data: information provided directly by users and information collected automatically when users interact with the platform. Collection is limited to what is necessary to deliver the service and meet operational, legal and security requirements.
Data you provide directly
When you register, enroll in courses or communicate with our team, we collect information needed to establish your account, manage course access and process transactions.
- Account identity: full name, display name, email address and profile details.
- Contact and billing: billing address, invoice details and payment confirmation (payment card data are processed by third-party payment providers and are not stored on our servers).
- Course records: enrollment history, course progress, assessment submissions and certifications.
- Support communications: messages platform with our support or instructional staff, including any attachments you submit.
- Employer or organization details if provided as part of a team subscription or enterprise account.
- Optional feedback and survey responses you elect to submit for service improvement.
Automatically collected data
We collect operational and technical data to run the platform, monitor performance and detect misuse. This data is collected through server logs, cookies and third-party analytics.
- Device and browser information, including device type, operating system and browser version.
- IP address, approximate geolocation derived from IP and time zone.
- Usage data: pages visited, features used, timestamps and interaction patterns within the platform.
- Performance and error logs to diagnose technical issues and maintain service availability.
- Cookie and tracking identifiers used for session management and analytics.
- Aggregated engagement metrics used to assess course effectiveness and platform improvements.
Data from third parties
We may receive information about you from authorized third parties as necessary to provide the service or comply with legal requirements.
- Payment processors supplying confirmation of completed transactions and limited billing metadata.
- Identity or authentication services used for single sign-on (SSO) where you choose to link an external account.
- Third-party analytics and learning tool providers that integrate with the platform to support reporting and course delivery.
Purposes of processing
We process personal data for specific and limited purposes necessary for delivery and improvement of our services, operational management and compliance.
- Provision and administration of accounts, course enrollment and learning management.
- Payment processing, billing and fraud prevention through authorized payment partners.
- Personalization of user experience and learning pathways based on progress and preferences.
- Security, abuse detection, contribute and prevention of unauthorized access.
- Service maintenance, performance monitoring, debugging and operational analytics to improve platform reliability.
- Regulatory compliance and response to legal requests or disputes.
- Customer support and communications related to your account, course activity and purchases.
- Research and development to improve curriculum quality and instructional methods using aggregated, de-identified data where possible.
Legal bases for processing
Depending on the processing activity and applicable law, we rely on appropriate legal bases to lawfully process personal data.
- Performance of a contract: processing necessary to provide the platform and fulfill user agreements.
- Legitimate interests: for security, platform integrity, fraud prevention and service improvement, balanced against user privacy.
- Consent: where requested (for example, optional marketing communications or certain cookies), processing occurs with user consent which may be withdrawn.
- Legal obligation: processing required to comply with applicable laws, such as tax or law enforcement requests.
Rights available to users (GDPR-style)
Where applicable, users have specific rights regarding their personal data. We provide mechanisms to exercise these rights promptly and transparently.
- Right of access: obtain a copy of personal data we hold about you.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of data when not required for legitimate purposes.
- Right to restriction: request limits on certain processing activities.
- Right to portability: receive your data in a structured, commonly used format when applicable.
- Right to object: object to processing based on legitimate interests or direct marketing.
Cookies and similar technologies
We use cookies and similar technologies to enable core functionality, remember preferences and measure usage. You can manage cookie settings via the consent banner and browser controls.
Types include essential cookies for session management, preference cookies to store settings and analytics cookies to collect aggregated usage data.
Categories: Essential (required for service), Performance and analytics (used to improve experience), Functional (preferences) and Marketing (third-party advertising where applicable).
You may manage or disable non-essential cookies through the cookie banner on the site and via your browser settings. Disabling certain cookies may affect functionality such as single sign-on or progress tracking.
Cookie policy details
Data sharing and disclosures
We share personal data only with identified categories of recipients to support service delivery, billing, analytics and compliance. Contracts and technical safeguards are used to protect that data.
- Payment and billing partners for transaction authorization and invoicing.
- Cloud hosting and infrastructure providers that store and process platform data.
- Analytics and learning analytics providers that process engagement metrics on our behalf.
- Third-party content or tool providers integrated into specific courses when you choose to use such integrations.
- Legal, audit and compliance advisors when required to respond to lawful requests or obligations.
- Affiliates or subcontractors under contract who perform services on our behalf and are bound to process data consistent with this policy.
International data transfers
Because we operate internationally and rely on global cloud services, personal data may be transferred to, stored and processed in countries outside Thailand. Transfer decisions are made with care and in accordance with applicable law.
When transfers occur, we apply safeguards such as contractual data transfer agreements, standard contractual clauses or equivalent protections. We assess service providers and implement technical controls to maintain an appropriate level of protection.
Data retention
We retain personal data only as long as necessary to provide services, fulfill legal obligations and resolve legitimate business needs. Retention periods vary by data type and purpose.
Account data and enrollment history are retained for the duration of the account and for a limited period afterward to handle billing, support and compliance matters.
Support communications and user-submitted content are retained for the period necessary to resolve requests and to maintain records of interactions.
System logs and diagnostic data are retained for operational troubleshooting and security monitoring for a limited period consistent with industry practice.
When retention periods expire or upon valid deletion requests, we securely delete or anonymize personal data unless retention is required by law or legitimate business purposes.
Security measures
We maintain administrative, technical and physical controls designed to protect personal data against unauthorized access, disclosure, alteration and destruction. Security practices are reviewed and updated to reflect evolving threats and operational changes.
- Encryption of data in transit using industry-standard TLS and encrypted storage for sensitive records where appropriate.
- Access controls, role-based permissions and regular access reviews to limit data access to authorized personnel only.
- Ongoing monitoring, vulnerability scanning and incident response procedures to detect and remediate security events.
User rights
You have rights to control your personal data. We provide straightforward mechanisms to exercise these rights and will respond within applicable timeframes.
- Access your personal data and receive a copy of records held about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of personal data where there is no lawful reason for continued processing.
- Request restriction of processing in certain circumstances.
- Request portability of data provided in a structured, commonly used format.
- Object to processing based on legitimate interests or for direct marketing.
- Withdraw consent to processing where consent is the legal basis and no other basis applies.
- Lodge a complaint with a supervisory authority if you consider your rights have been infringed.
How to exercise your rights
To exercise your rights or ask questions about this policy, contact our privacy team by email at [email protected] or by post/phone: aitlawex, 137/149, Muban Bo Din Laksa 3 Soi 4, Bang Khen Sub District, Bangkok District, Bangkok 10220, Thailand; phone +66933943224. Please provide sufficient information to verify your identity and the request. We will respond to verified requests in accordance with applicable law and our internal procedures.
Requests to exercise privacy rights received via the designated channels will be acknowledged within 10 business days. Detailed responses, including verification steps and any required follow-up, will typically be provided within 30 calendar days of verification. If a request requires additional time due to complexity, you will receive a clear explanation of the delay and an estimated completion timeframe.
Marketing Communications
We may send email or messenger updates about new courses, policy changes, and professional resources relevant to AI education and responsible chatbot operation. Communications are tailored to stated user preferences and subscription selections. Marketing messages will be informational, focused on learning opportunities, regulatory updates, and best-practice workshops rather than promotional exaggeration.
You can opt out of marketing communications at any time using the unsubscribe link in emails or by contacting our privacy team. Opt-out requests are processed within a reasonable timeframe and will not affect transactional messages related to your account or enrolled courses.
Children and Minors
aitlawex does not target services to children under the age required by applicable law in Thailand. We do not knowingly collect personal data from children for training or account creation. If we become aware that we have collected personal data from an individual under the applicable age threshold without appropriate parental consent, we will take steps to delete the data as required by law and notify the parent or guardian when feasible.
Third-Party Links and Services
Certain pages and learning modules may link to or embed third-party platforms that provide tools or supplementary content. Those third parties maintain their own privacy practices. Review third-party privacy policies before providing personal data. aitlawex does not assume responsibility for third-party data handling beyond integration points we explicitly control.
Changes to This Privacy Notice
We periodically review and update our privacy practices to reflect changes in law, technology, and our educational offerings. Material changes will be communicated through the website and via email to registered users where required. The date of last revision is displayed at the top of this notice.
Contact and Data Requests
For privacy inquiries, data access requests, or to exercise other rights, contact: Data Protection Officer, aitlawex, 137/149, Muban Bo Din Laksa 3 Soi 4, Bang Khen Sub District, Bangkok District, Bangkok 10220, Thailand. Phone: +66933943224. Business ID: 1876767487261. Email inquiries may be submitted via the contact form on aitlawex.pro.
- +66933943224
- [email protected]
- 137/149, Muban Bo Din Laksa 3 Soi 4, Bang Khen Sub District, Bangkok District, Bangkok 10220, Thailand