Security and Data Protection Policy
Last updated: 17 July 2025
1. Introduction
TH - Dashsecurity (“we”, “our”, “us”) is committed to protecting the privacy, integrity, and security of your personal data in accordance with the Personal Data Protection Act (PDPA) and applicable cybersecurity standards. This policy details how we collect, store, process, and safeguard information across our platform.
2. Data Collection and Purpose
- Identify and authenticate users during session login and authorization.
- Perform statistical telemetry and threat analysis.
- Operate, optimize, and maintain cybersecurity learning services.
- Detect, isolate, and mitigate potential security incidents or technical anomalies.
- Comply with statutory legal obligations under Thailand Cybersecurity Act B.E. 2562.
3. Lawful Basis for Processing
Data processing is conducted based on explicit consent, contractual necessity, or legitimate interests in platform defense under the PDPA framework.
4. Data Protection Measures
- Personal data is encrypted both in transit (TLS 1.3) and at rest (AES-256).
- Access control is restricted strictly to authenticated personnel with audit logging.
- Continuous vulnerability assessments and automated patch monitoring are enforced.
- Incident response plans are established to manage potential security breaches immediately.
5. User Rights
- Access and obtain a copy of registered account information.
- Request data rectification, restricted processing, or erasure where permissible.
- Withdraw consent at any time without affecting historical lawful processing.
6. Responsible Disclosure
If you identify a security vulnerability in our platform or endpoints, please report it immediately to our security team at tigerzaza5678@gmail.com.
7. Contact Information
For inquiries regarding this policy or data management, contact:
Email: security@kpltgroup.com
GitHub: https://github.com/ThemeHackers/