Effective 29 August 2026

ภาษาไทย

Privacy Policy

What Accella ONE processes, on what basis, and what you can ask us to do about it.

01

Scope, and who controls the data

This policy covers Accella ONE, the software Accella Co., Ltd. provides to business customers. It does not cover the corporate website accella.co.th, which has its own separate policy.

Data in Accella ONE falls into two groups with different responsible parties, and the distinction matters:

  • End-customer data — people who contact a business using our software, by chat, form, or online storefront. That business is the data controller; Accella is a processor acting on its instructions.
  • System-user data — owners and staff who sign in to do their work. For this group Accella is the data controller.

If you once messaged a business and want to exercise your rights, that business decides about your data — but you may always write to us at contact@accella.co.th and we will pass the request on.

02

What we process

We process what the service needs in order to work:

  • Account data — name, email, role within the organisation, and sign-in records.
  • Contact data — display name, profile picture, channel identifier, and details a contact gives voluntarily such as phone number, email, or delivery address.
  • Conversation content — messages, images, and attachments exchanged over connected channels, with their timestamps.
  • Transaction data — orders, appointments, bookings, receipts, and payment evidence submitted by contacts.
  • Technical data — application and error logs, used to operate the service and investigate security events.

The service is not designed to hold sensitive personal data as defined by law, and we ask businesses not to enter such data unless separately agreed in writing.

03

Data received from connected platforms

When a business connects its own channels to Accella ONE, we receive from that platform what is needed to receive and answer messages.

From Meta (Facebook Messenger and Instagram), once a Page administrator grants access:

  • The Page's name, id, and picture, and the Instagram account linked to it.
  • A Page access token, stored encrypted and never exposed to a browser.
  • For people who write in — a Page-scoped identifier, display name, profile picture, and the content of messages sent to that Page.

From LINE, when a business connects its Official Account, we receive equivalent information.

We do not use platform data for advertising, do not sell it, and do not combine it with another business's data. Each organisation's data is separated at the database level.

04

Purposes and legal bases

  • To deliver the service under contract — sending and receiving messages, handling orders, appointments, and related work. Basis: performance of a contract.
  • To keep the service secure — detecting abuse, recording changes, and preventing unauthorised access. Basis: legitimate interest.
  • To comply with law — retaining accounting and tax records for the statutory period. Basis: legal obligation.
  • To improve the service — aggregate, non-identifying usage analysis. Basis: legitimate interest.

05

Use of artificial intelligence

A business may enable an automated assistant to answer messages. When enabled, a contact's message and the relevant catalogue information are sent to a language-model provider to compose a reply.

  • We send only what is needed to answer that message.
  • We select providers that do not train models on our data.
  • The assistant cannot alter business records on its own; every change comes from a predefined system routine or from a person.

06

Service providers we use

We rely on the following providers, each with access limited to what its function requires:

  • Supabase — database, authentication, and file storage.
  • Vercel — hosting infrastructure for the web application.
  • OpenRouter — routing to language-model providers for the automated assistant.
  • Meta Platforms — the Facebook Messenger and Instagram channels.
  • LINE — the Official Account channel.

Some providers operate servers outside Thailand. Cross-border transfers are made under the safeguards required by applicable law.

We do not sell, rent, or trade personal data with third parties for marketing purposes.

07

Retention and security

We retain data for as long as the organisation's account is active, and for the period set out in that organisation's service agreement.

On termination we delete or return customer data within 90 days, unless a longer period is required by law.

Our measures include encryption in transit, encryption of secrets such as channel tokens, role-based access control, database-level separation between organisations, and an audit record of every significant change.

08

Your rights

Under Thailand's Personal Data Protection Act you may request access to your data, a copy of it, correction, erasure, restriction of use, objection to processing, portability, and withdrawal of a consent previously given.

Send requests to contact@accella.co.th. We respond within 30 days of receiving a request containing enough information to verify your identity.

Where a request concerns data controlled by a particular business, we forward it to that business and tell you we have done so.

If you believe processing is unlawful, you may complain to Thailand's Personal Data Protection Committee.

09

Deleting your data

How to request deletion, including where you contacted a business through Facebook or Instagram, is set out on a separate page.

See /data-deletion

10

Changes to this policy

When we make a material change we update the effective date above and give business customers reasonable advance notice through our usual channel of contact.

11

Contact us

Accella Co., Ltd.

68/52 Om Kret Sub-district, Pak Kret District, Nonthaburi 11120, Thailand

Email contact@accella.co.th · Telephone 063-204-6870