ContentVelo
Log in

Data Protection Policy

How we protect and handle your personal data

Last updated: March 2026

business Data Controller

ContentVelo, operated by NB Digital Co., LTD., is the data controller responsible for your personal data.

NB Digital Co., LTD.

Bangkok, Thailand

Email: [email protected]

gavel Legal Basis for Processing

We process your personal data under the following legal bases as permitted by the PDPA and applicable data protection laws:

  • check_circle Consent — When you explicitly agree to data processing, such as connecting your Facebook Page or opting into marketing communications.
  • check_circle Contractual Necessity — When processing is required to fulfill our service agreement, such as generating AI content and publishing posts.
  • check_circle Legitimate Interest — For platform improvement, security monitoring, and fraud prevention.
  • check_circle Legal Obligation — When required by Thai law, including tax records and regulatory compliance.

shield Data Protection Measures

We implement comprehensive technical and organizational measures to protect your data:

lock Technical Safeguards

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Regular security audits and penetration testing
  • Automated vulnerability scanning

groups Organizational Safeguards

  • Employee data protection training
  • Role-based access controls
  • Data processing agreements with all vendors
  • Incident response procedures

public International Data Transfers

Your data may be processed outside Thailand by our service providers. We ensure adequate protection through:

  • Standard contractual clauses with all international vendors
  • Adequate data protection assessments for recipient countries
  • Compliance with PDPA cross-border transfer requirements
  • Regular review of vendor compliance status

emergency Data Breach Response

In the event of a data breach, we follow a strict response protocol:

  • Immediate containment and investigation within 24 hours
  • Notification to the PDPC within 72 hours as required by law
  • Affected users notified without undue delay
  • Full incident report and remediation plan

mail Contact Our DPO

For data protection inquiries, contact our Data Protection Officer:

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.