Legal document · PN-PP-2026-001
Privacy Policy
นโยบายความเป็นส่วนตัว
- Version
- 1.0
- Effective date
- 8 ตุลาคม 2569 / 8 October 2026
- Issuer
- Prospera Nexus Company Limited
- Controlling language
- Thai
The Thai text is legally controlling. This English version is a convenience translation only; if there is any conflict, the Thai text prevails.
Prospera Nexus Company Limited
Version 1.0, effective 8 October 2026. Thai language controls.
1. Data controller
Prospera Nexus Company Limited, registration no. 0105569181481.
Address: No. 25, Alma Link Building, Room 808, 17th Floor, Soi Chidlom, Ploenchit Road, Lumpini, Pathum Wan, Bangkok, Thailand.
General email: cs@prosperanexus.com Tel. 093-737-3482 (+66 93 737 3482).
Data Protection Officer (DPO): dpo@prosperanexus.com, same address.
This policy is issued under section 23 of the Personal Data Protection Act B.E. 2562 (2019) and related laws.
2. Scope
Applies to the website www.prosperanexus.com, the official Prospera Nexus app (once launched), customer service channels and performance of loan agreements. This website does not collect copies of ID cards; loan applications are made only in the app.
3. Data we collect
3.1 Identity data: full name, date of birth, nationality, national ID number, registered address, contact address, electronic signature.
3.2 Contact data: phone number, email.
3.3 Financial data: self-declared income, bank account, borrowing and repayment history with the company, outstanding balance, instalments.
3.4 KYC data: live face capture taken in the app (liveness) and an image of the ID card taken with the in-app camera at that moment.
3.5 Device data needed to provide the service: device model, operating system, app version, notification token, IP address, security logs.
3.6 Support data: the content of messages sent to cs@.
4. Data we do not collect and permissions the app will never request
Prohibited and never requested: phone book / contacts (READ_CONTACTS), photo or video gallery (READ_MEDIA_IMAGES / READ_MEDIA_VIDEO), external storage (READ/WRITE_EXTERNAL_STORAGE), precise location (ACCESS_FINE_LOCATION), SIM phone number (READ_PHONE_NUMBERS), list of all installed apps (QUERY_ALL_PACKAGES), SMS messages, call logs, and continuous microphone access unrelated to the service.
Identity verification uses only the live in-app camera; the photo album is never opened.
5. Purposes and legal bases (section 24; consent under section 19)
5.1 Entering into the contract and providing credit — contract / pre-contractual steps. Without this data the company cannot assess or grant a loan.
5.2 Identity verification and prevention of impersonation and fraud — legitimate interests and contract. Face/ID data is sensitive or limited biometric data; additional explicit consent under section 26 is obtained where required by law.
5.3 Account administration, payment requests, receipts and lawful collection — contract and legal obligation (Debt Collection Act).
5.4 Accounting and financial record-keeping — legal obligation.
5.5 System security and prevention of computer crime — legitimate interests.
5.6 Customer service and complaints — contract / legitimate interests.
5.7 Marketing (email / promotional notifications) — consent only, withdrawable at any time without affecting the core service.
5.8 Compliance with court orders or competent authorities — legal obligation.
6. Sources
Directly from the data subject, from the device when using the app, and from payment processors (e.g. the receiving bank). The company does not obtain data from the National Credit Bureau while this policy is in effect; if it does so in future, a new policy will be issued and lawful consent obtained first.
7. Recipients
The company does not sell personal data.
- Employees and directors on a need-to-know basis.
- Data processors (cloud hosting in Thailand or in countries with adequate safeguards, KYC liveness providers, transactional email/SMS providers, payment providers) under contracts compliant with section 40.
- Legal advisers and auditors.
- Assignees of claims under the loan agreement (if any), who must protect data to a standard no lower than this policy.
- Government authorities, courts and officials under warrant or law.
8. Cross-border transfers
Core systems are intended to process data in Thailand. If a transfer abroad is required, standard contractual clauses or consent under the cross-border transfer provisions will be used, and the category of destination country will be disclosed on this page when it actually occurs.
9. Retention
At the end of the period the company deletes or anonymises the data.
- Website visitor data / non-essential cookies: per the cookie policy, or until consent is withdrawn.
- Applications not approved: no more than 24 months.
- Customer and contract data: the life of the contract plus 5 years, or longer where accounting, tax or limitation-period law requires.
- Security logs: no more than 12 months, unless needed as evidence in a case.
10. Your rights
Submit requests to dpo@prosperanexus.com or to the head office address. The company will respond within 30 days unless the law permits an extension.
- Withdraw consent (section 19).
- Access and obtain a copy (section 30).
- Rectification (section 31).
- Erasure or destruction where the law allows (section 33).
- Restriction of processing (section 34).
- Object to collection, use or disclosure (section 32).
- Receive data in a machine-readable format and have it transmitted to another controller where the law supports it (section 31 transfer provisions / data portability under PDPC guidance).
- Complain to the Personal Data Protection Committee (section 73).
11. Security
Encryption in transit (HTTPS/TLS), restricted access rights, access logging, and staff confidentiality obligations. In the event of a breach posing a high risk to rights, the company will notify the PDPC and data subjects as required by law without undue delay (72-hour guideline where the threshold is met).
12. Children and minors
The credit service is for persons aged 20 or over. We do not knowingly collect data of persons under 20; if found, it will be deleted unless retention is needed to evidence the refusal of service.
13. Cookies
See https://www.prosperanexus.com/cookies. Non-essential cookies are used only with consent.
14. Changes to this policy
New versions are published on the website with a version number. Material changes of purpose will be notified in advance, and consent obtained where the law requires.
15. Contact for personal data matters
dpo@prosperanexus.com / cs@prosperanexus.com / 093-737-3482
ต้นฉบับภาษาไทย (ฉบับที่มีผลบังคับ)
นโยบายความเป็นส่วนตัว
บริษัท พรอสเพอร่า เน็กซัส จำกัด
เวอร์ชัน 1.0 มีผล 8 ตุลาคม 2569
ข้อ 1 ผู้ควบคุมข้อมูลส่วนบุคคล
บริษัท พรอสเพอร่า เน็กซัส จำกัด เลขทะเบียน 0105569181481
ที่อยู่: เลขที่ 25 อาคารอัลมา ลิงค์ ห้อง 808 ชั้น 17 ซอยชิดลม ถนนเพลินจิต แขวงลุมพินี เขตปทุมวัน กรุงเทพมหานคร
อีเมลทั่วไป: cs@prosperanexus.com โทร 093-737-3482
เจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (DPO): dpo@prosperanexus.com ที่อยู่เดียวกัน
นโยบายนี้จัดทำตาม พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 มาตรา 23 และกฎหมายที่เกี่ยวข้อง
ข้อ 2 ขอบเขต
ใช้กับเว็บไซต์ www.prosperanexus.com แอป Prospera Nexus อย่างเป็นทางการ (เมื่อเปิดให้บริการ) ช่องทางบริการลูกค้า และการปฏิบัติตามสัญญาเงินกู้ เว็บไซต์นี้ไม่เก็บสำเนาบัตรประชาชน หากสมัครสินเชื่อจะดำเนินการในแอปเท่านั้น
ข้อ 3 ข้อมูลที่เก็บ
3.1 ข้อมูลระบุตัวตน: ชื่อ-นามสกุล วันเดือนปีเกิด สัญชาติ เลขประจำตัวประชาชน ที่อยู่ตามบัตร ที่อยู่ติดต่อ ลายมือชื่ออิเล็กทรอนิกส์
3.2 ข้อมูลการติดต่อ: เบอร์โทร อีเมล
3.3 ข้อมูลทางการเงิน: รายได้โดยผู้กู้ให้เอง บัญชีธนาคาร ประวัติการกู้และชำระกับบริษัท ยอดหนี้ ค่างวด
3.4 ข้อมูล KYC: ภาพถ่ายใบหน้าแบบถ่ายสดในแอป (liveness) ภาพบัตรประชาชนที่ผู้ใช้ถ่ายผ่านกล้องในแอป ณ เวลานั้น
3.5 ข้อมูลอุปกรณ์ที่จำเป็นต่อการให้บริการ: รุ่นเครื่อง ระบบปฏิบัติการ เวอร์ชันแอป โทเค็นแจ้งเตือน ที่อยู่ IP บันทึกความปลอดภัย
3.6 ข้อมูลการสนับสนุน: เนื้อหาที่ติดต่อมาที่ cs@
ข้อ 4 ข้อมูลที่บริษัทไม่เก็บและแอปจะไม่ขอสิทธิ์
ห้ามและจะไม่ขอ: สมุดโทรศัพท์/รายชื่อผู้ติดต่อ (READ_CONTACTS) คลังรูปภาพหรือวิดีโอ (READ_MEDIA_IMAGES / READ_MEDIA_VIDEO) ที่เก็บข้อมูลภายนอก (READ/WRITE_EXTERNAL_STORAGE) ตำแหน่งที่ตั้งแบบละเอียด (ACCESS_FINE_LOCATION) หมายเลขโทรศัพท์ในซิม (READ_PHONE_NUMBERS) รายการแอปทั้งหมดในเครื่อง (QUERY_ALL_PACKAGES) ข้อความ SMS บันทึกการโทร ไมโครโฟนต่อเนื่องโดยไม่เกี่ยวกับบริการ
การพิสูจน์ตัวตนใช้กล้องถ่ายภาพสดในแอปเท่านั้น ไม่เปิดอัลบั้มรูป
ข้อ 5 วัตถุประสงค์และฐานกฎหมาย (มาตรา 24 และความยินยอมมาตรา 19)
5.1 ทำสัญญาและให้สินเชื่อ — ฐานสัญญา / ขั้นตอนก่อนทำสัญญา หากไม่ให้ข้อมูล บริษัทไม่อาจพิจารณาหรือให้กู้ได้
5.2 พิสูจน์ตัวตน ป้องกันการสมมติบุคคลและทุจริต — ฐานประโยชน์โดยชอบด้วยกฎหมายและฐานสัญญา ข้อมูลใบหน้า/บัตรเป็นข้อมูลอ่อนไหวหรือข้อมูลชีวมิติจำกัด ใช้ความยินยอมโดยชัดแจ้งเพิ่มเติมตามมาตรา 26 เมื่อกฎหมายกำหนด
5.3 บริหารบัญชี เรียกชำระ ออกใบเสร็จ ทวงถามตามกฎหมาย — ฐานสัญญาและฐานกฎหมาย (พ.ร.บ.การทวงถามหนี้)
5.4 บัญชีและการรักษาบันทึกทางการเงิน — ฐานหน้าที่ตามกฎหมาย
5.5 ความมั่นคงของระบบ ป้องกันอาชญากรรมทางคอมพิวเตอร์ — ฐานประโยชน์โดยชอบด้วยกฎหมาย
5.6 บริการลูกค้าและร้องเรียน — ฐานสัญญา / ประโยชน์โดยชอบด้วยกฎหมาย
5.7 การตลาด (อีเมล/การแจ้งเตือนโปรโมชัน) — เฉพาะความยินยอม และถอนได้ทุกเมื่อ ไม่กระทบบริการหลัก
5.8 ปฏิบัติตามคำสั่งศาลหรือหน่วยงานรัฐที่มีอำนาจ — ฐานหน้าที่ตามกฎหมาย
ข้อ 6 แหล่งที่มา
ได้จ���กเจ้าของข้อมูลโดยตรง จากอุปกรณ์เมื่อใช้แอป จากผู้ประมวลผลที่จ่ายเงิน (เช่น ธนาคารผู้รับโอน) บริษัทไม่ดึงข้อมูลจากสำนักงานข้อมูลเครดิตแห่งชาติในขณะที่นโยบายนี้มีผล หากจะดึงในอนาคต จะออกนโยบายใหม่และขอความยินยอมตามกฎหมายก่อน
ข้อ 7 ผู้ที่อาจได้รับข้อมูล
บริษัทไม่ขายข้อมูลส่วนบุคคล
- พนักงานและกรรมการที่จำเป็นต้องรู้
- ผู้ประมวลผลข้อมูล (โฮสติ้งคลาวด์ในประเทศไทยหรือประเทศที่มีมาตรการคุ้มครองเหมาะสม ผู้ให้บริการ KYC liveness ผู้ให้บริการอีเมล/SMS แบบธุรการ ผู้ให้บริการชำระเงิน) ภายใต้สัญญาตามมาตรา 40
- ที่ปรึกษากฎหมาย ผู้สอบบัญชี
- ผู้รับโอนสิทธิเรียกร้องตามสัญญาเงินกู้ (ถ้ามี) ซึ่งต้องคุ้มครองข้อมูลในมาตรฐานไม่ต่ำกว่านี้
- หน่วยงานรัฐ ศาล เจ้าหน้าที่ตามหมายหรือกฎหมาย
ข้อ 8 การส่งข้อมูลข้ามประเทศ
ระบบหลักตั้งใจให้ประมวลผลในประเทศไทย หากต้องส่งออก จะใช้ข้อสัญญามาตรฐานหรือความยินยอมตามหมวดการส่งข้อมูลไปนอกราชอาณาจักร และแจ้งประเภทประเทศในหน้านี้เมื่อเกิดขึ้นจริง
ข้อ 9 ระยะเวลาเก็บ
เมื่อครบกำหนด บริษัทจะลบหรือทำให้ระบุตัวตนไม่ได้
- ข้อมูลผู้เยี่ยมชมเว็บไซต์/คุกกี้ที่ไม่จำเป็น: ตามนโยบายคุกกี้ หรือจนกว่าจะถอนความยินยอม
- ข้อมูลคำขอที่ไม่ผ่านการอนุมัติ: ไม่เกิน 24 เดือน
- ข้อมูลลูกค้าและสัญญา: อายุสัญญาบวก 5 ปี หรือนานกว่านั้นหากกฎหมายบัญชี/ภาษี/อายุความฟ้องร้องกำหนด
- บันทึกความมั่นคง: ไม่เกิน 12 เดือน เว้นแต่เป็นหลักฐานคดี
ข้อ 10 สิทธิของเจ้าของข้อมูล
ยื่นคำขอที่ dpo@prosperanexus.com หรือที่อยู่สำนักงานใหญ่ บริษัทจะตอบภายใน 30 วัน เว้นแต่มีเหตุตามกฎหมายให้ขยาย
- ถอนความยินยอม (มาตรา 19)
- เข้าถึงและขอสำเนา (มาตรา 30)
- ให้ทำให้ข้อมูลถูกต้อง (มาตรา 31)
- ลบหรือทำลายเมื่อกฎหมายให้นับได้ (มาตรา 33)
- ระงับการใช้ (มาตรา 34)
- คัดค้านการเก็บรวบรวม ใช้ เปิดเผย (มาตรา 32)
- ขอรับข้อมูลในรูปแบบที่อ่านได้ด้วยเครื่องมือและส่งต่อไปยังผู้ควบคุมรายอื่นเมื่อกฎหมายรองรับ (มาตรา 31 วรรคที่เกี่ยวกับการส่งข้อมูล / data portability ตามแนวปฏิบัติ PDPC)
- ร้องเรียนต่อคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (มาตรา 73)
ข้อ 11 ความมั่นคงปลอดภัย
เข้ารหัสขณะส่ง (HTTPS/TLS) จำกัดสิทธิเข้าถึง บันทึกการเข้าถึง พนักงานผูกพันรักษาความลับ หากเกิดเหตุละเมิดที่เสี่ยงสูงต่อสิทธิ บริษัทจะแจ้ง PDPC และเจ้าของข้อมูลตามกฎหมายโดยไม่ชักช้า (แนว 72 ชั่วโมงเมื่อเข้าเกณฑ์)
ข้อ 12 เด็กและผู้เยาว์
บริการสินเชื่อสำหรับผู้มีอายุ 20 ปีขึ้นไป ไม่เจตนาเก็บข้อมูลของผู้มีอายุต่ำกว่า 20 ปี หากพบจะลบ เว้นแต่ต้องเก็บเพื่อพิสูจน์การปฏิเสธบริการ
ข้อ 13 คุกกี้
ดู https://www.prosperanexus.com/cookies คุกกี้ที่ไม่จำเป็นใช้เมื่อยินยอมเท่านั้น
ข้อ 14 การแก้ไขนโยบาย
ประกาศฉบับใหม่บนเว็บไซต์พร้อมเลขเวอร์ชัน หากเปลี่ยนวัตถุประสงค์เป็นสาระสำคัญจะแจ้งล่วงหน้าและขอความยินยอมเมื่อกฎหมายกำหนด
ข้อ 15 ช่องทางติดต่อเรื่องข้อมูลส่วนบุคคล
dpo@prosperanexus.com / cs@prosperanexus.com / 093-737-3482
PN-PP-2026-001 · Version 1.0 · 8 ตุลาคม 2569 / 8 October 2026 · บริษัท พรอสเพอร่า เน็กซัส จำกัด / Prospera Nexus Company Limited · Registration no. 0105569181481