Privacy Policy

Last Updated: January 15, 2026

1. Introduction

nexxoolitha ("we," "us," or "our") is committed to protecting the privacy and personal data of individuals who interact with our services. This Privacy Policy explains how we collect, use, store, and share personal information in connection with our website and consulting services.

This policy applies to visitors of our website hosted at https://nexxoolithsa.life and to individuals who engage with us through our contact forms, workshops, engineering services, and governance programs.

For questions about this policy, please contact us at [email protected].

2. Data We Collect

We collect the following categories of personal data:

Information you provide directly: When you submit a contact form, request a consultation, or communicate with us via email or phone, we may collect your name, email address, phone number, company name, job title, and the content of your message.

Information collected automatically: When you visit our website, we may collect technical data such as your IP address, browser type, device type, pages visited, and time spent on the site through cookies and analytics tools.

Engagement-related data: During the course of a consulting engagement, we may receive business data, operational data, or technical documentation necessary to deliver our services. The handling of such data is governed by separate engagement agreements and NDAs.

3. How We Use Your Data

We use the information we collect for the following purposes:

Service delivery: To respond to inquiries, schedule consultations, and deliver our consulting services including workshops, pipeline engineering, and governance programs.

Communication: To send relevant information about our services, respond to your questions, and provide follow-up support after engagements.

Website improvement: To analyze site usage patterns and improve the functionality and content of our website.

Legal compliance: To comply with applicable laws, regulations, and legal obligations, including the Thai Personal Data Protection Act (PDPA).

4. Legal Basis for Processing

Under the Thai PDPA and applicable data protection frameworks, we process personal data based on the following legal grounds: your explicit consent (provided through form submissions or cookie preferences), the necessity to perform a contract or take pre-contractual steps, our legitimate interests in operating and improving our services, and compliance with legal obligations.

5. Data Sharing and Third Parties

We do not sell your personal data to third parties. We may share data with trusted service providers who assist us in operating our website and delivering services, such as hosting providers, analytics platforms (e.g., Google Analytics), and email service providers. All third-party processors are required to handle data in accordance with applicable privacy laws.

6. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this policy. Contact form submissions are retained for up to 24 months. Engagement-related data is retained for the duration of the engagement plus an additional 36 months for reference and legal compliance. Website analytics data is retained for up to 14 months.

7. Data Protection Measures

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit and at rest, access controls limiting data access to authorized personnel, regular security reviews, and secure storage practices aligned with industry standards.

8. Cookies

Our website uses cookies to enhance your browsing experience and gather analytics data. For detailed information about the types of cookies we use and how to manage your preferences, please see our Cookie Policy.

9. Your Rights

Under the Thai PDPA, you have the right to access your personal data that we hold, request correction of inaccurate data, request deletion of your data (subject to legal retention requirements), object to certain types of data processing, withdraw consent at any time (where processing is based on consent), request data portability, and lodge a complaint with the relevant supervisory authority in Thailand.

To exercise any of these rights, please contact us at [email protected].

10. Third-Party Links

Our website may contain links to external websites. We are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any third-party sites you visit.

11. Children's Privacy

Our services are intended for individuals aged 18 and above. We do not knowingly collect personal data from individuals under 18 years of age. If we become aware that we have inadvertently collected data from a minor, we will take steps to delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. When we make material changes, we will update the "Last Updated" date at the top of this page. We encourage you to review this policy periodically.

13. Contact Information

Data Controller: nexxoolitha

Address: 56 Sukhumvit Soi 24, Khlong Toei, Bangkok 10110, Thailand

Email: [email protected]

Phone: +66 2-392-5847