Privacy Policy
Last updated: September 1, 2026
Thara is provided by Ngernthongdee Co., Ltd. (“we”, “us”, or “the Company”). This policy explains how we collect, use, and protect your personal data when you use this website, contact us through our form, or use the Thara service as a customer, in accordance with Thailand's Personal Data Protection Act B.E. 2562 (PDPA).
1. Information We Collect
- Contact form data: your name, job title, business email, phone number (if provided), company name, business type, and details about the systems you'd like to connect.
- Minimal technical data required to prevent spam (via Cloudflare Turnstile) when you submit the form.
- For active customers: audit log data on MCP tool usage (who asked, what was asked, when) for security and accountability. We do not retain a permanent copy of your source system data — Thara's architecture is read-only, forwarding requests in real time to the AI assistant you've chosen.
2. How We Use Your Information
- To respond to and follow up on inquiries submitted through our contact form.
- To carry out Discovery and onboarding for customers who move forward with the service.
- To maintain system security, monitor for unusual activity, and produce audit trails required by enterprise customers.
- We do not use your data for advertising. We do not sell, rent, or trade personal data with third parties for marketing purposes.
3. Legal Basis for Processing
- Consent, when you submit our contact form.
- Contractual necessity, for customers actively using the Thara service.
- Legitimate interest, in maintaining system security and preventing misuse.
4. Third-Party Disclosure
- Thara does not sell or rent personal data to third parties for marketing purposes.
- Queries made through a customer's Thara deployment are forwarded only to the AI assistant that customer has chosen to connect (e.g. Claude, ChatGPT, Gemini, or a self-hosted model), per that customer's own configuration. We do not control the privacy practices of those AI providers.
- We use Cloudflare Turnstile to prevent spam on our contact form — a privacy-preserving third-party service that does not use cross-site tracking cookies.
- We may disclose information when required by law, or to protect the rights, property, or safety of the Company and its users.
5. Security Measures
- Read-only architecture — no MCP tool Thara generates can write, update, or delete data in a source system.
- Role-based access control.
- A full audit log of every access.
- Per-tenant data isolation — no cross-business mixing.
- Fields that qualify as personal data are masked before reaching the AI, where applicable to the system.
6. Data Retention
- Contact form data: retained for no more than 24 months from your last contact, unless you become a customer, in which case it's retained per your service agreement.
- Audit logs: retained per the term agreed in each customer's service agreement, for security and accountability purposes.
7. Your Rights Under PDPA
You have the right to:
- Access and request a copy of your personal data.
- Correct inaccurate data.
- Request deletion or destruction of your data.
- Withdraw consent at any time.
- Object to processing in certain circumstances.
- File a complaint with Thailand's Personal Data Protection Committee (PDPC) if you believe your rights have been violated.
8. Cookies
This website does not use cookies for tracking or advertising. We do not deploy third-party behavioral analytics tools. The Cloudflare Turnstile spam protection used on our contact form is designed not to use cross-site tracking cookies.
9. Changes to This Policy
We may update this policy from time to time. Changes take effect immediately upon posting to this page, along with an updated “last updated” date.
10. Contact Us
You may exercise your rights or ask questions about this policy by contacting:
Ngernthongdee Co., Ltd.
Email: chanon@ngernthongdee.co.th