Privacy Policy

Appexbots.com by SIAM GEKKO CO., LTD.

Version 1.0 · Effective from 20 July 2026

1. Introduction

This Privacy Policy (the "Policy") explains how SIAM GEKKO CO., LTD., a limited liability company incorporated under the laws of the Kingdom of Thailand under Company Registration Number 0505565016342, having its registered office at 252/49, Moo 2, Mae Sa Sub-district, Mae Rim District, Chiang Mai Province, Kingdom of Thailand (hereinafter "Appexbots.com", "we", "us", or "our"), collects, uses, stores, discloses, and protects personal data in connection with your use of the Appexbots.com platform, our website appexbots.com, our Telegram bots and mini-applications, mobile applications, APIs, and any related services (collectively, the "Service").

We are committed to protecting the privacy and personal data of individuals in accordance with applicable data protection laws, including the Personal Data Protection Act B.E. 2562 (2019) of the Kingdom of Thailand (the "PDPA"), the EU General Data Protection Regulation 2016/679 (the "GDPR"), the UK Data Protection Act 2018, and any other applicable data protection laws.

By using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with the terms of this Policy, please do not use the Service.

2. Our Role and the Role of Our Customers (Merchants)

Appexbots.com is a Software-as-a-Service (SaaS) platform that provides technical tools enabling our customers (hereinafter "Merchants") — including online shops, restaurants, service providers, and other business users — to interact with their own end-customers through Telegram-based mini-applications and bots.

It is important to distinguish two different capacities in which we process personal data:

(a) When we process personal data of our own website visitors, account holders, and prospective Merchants, we act as an independent data controller. This Policy governs such processing.

(b) When we process personal data of the Merchant's end-customers (for example, individuals who place orders through a Merchant's Telegram bot), we act as a data processor on behalf of the Merchant, who acts as the data controller. In such cases, the Merchant is responsible for determining the purposes and means of processing, obtaining lawful consents, providing appropriate notices, and complying with applicable data protection laws in respect of its end-customers.

2.1. Products and services sold by Merchants. Appexbots.com provides only the technical software platform. We do not sell, manufacture, ship, deliver, or otherwise participate in the goods, food, services, or content offered for sale by Merchants through the Service. The Merchant alone is responsible for the quality, safety, legality, description, pricing, availability, delivery, warranty, refund, and after-sale service of any products or services offered through the Service. Any complaint or dispute concerning goods or services purchased through a Merchant's bot must be addressed directly to that Merchant.

2.2. We are not a party to the sale-and-purchase contract between a Merchant and its end-customer, and we do not act as an intermediary, agent, or fiduciary in such transactions.

2.3. If you are an end-customer of a Merchant and have questions about how your personal data is used for the Merchant's business purposes, please contact the Merchant directly. For questions about how Appexbots.com stores such data as a technical processor, you may still contact us using the details in Section 15 below.

3. Personal Data We Collect

Depending on how you interact with the Service, we may collect the following categories of personal data:

3.1. Data you provide directly to us:

  • contact details such as name, email address, and telephone number;
  • Telegram username and Telegram user identifier;
  • company name, business address, and tax identification number (for business Merchants);
  • billing and payment information (processed by third-party payment providers);
  • correspondence and communications you send us;
  • login credentials for your account.

3.2. Data collected automatically:

  • technical data such as IP address, browser type and version, device type, operating system, and time-zone setting;
  • usage data such as pages visited, features accessed, time spent, actions taken, and referral source;
  • cookies and similar tracking technologies (see Section 8 below);
  • log files and server records.

3.3. Data received from third parties:

  • payment confirmation data from Skrill, Stripe, PayPal, or other payment processors;
  • authentication data from Telegram (via Telegram Login);
  • order and catalog synchronization data from third-party integrations (e.g., Grab, DHL, HubSpot, Zoho CRM), where you have connected them;
  • information from public sources, where relevant to verify the identity or eligibility of a business Merchant.

3.4. Data of your end-customers (for Merchants).

When Merchants use the Service to interact with their own end-customers, personal data of such end-customers (such as names, phone numbers, Telegram identifiers, order histories, chat messages) may be transmitted through and stored within the Service. As explained in Section 2, we process such data as a data processor on behalf of the Merchant, and the Merchant is responsible for the lawful basis, notices, and consents required for such processing.

4. How We Use Personal Data

We use personal data for the following purposes:

  • to create, maintain, and manage your account;
  • to provide, operate, and improve the Service;
  • to process payments and issue invoices;
  • to communicate with you regarding your account, updates, technical notices, security alerts, and support requests;
  • to enforce our Terms of Service and prevent fraud, abuse, or illegal use of the Service;
  • to comply with applicable legal obligations, including tax, accounting, and regulatory requirements;
  • to analyze usage patterns and improve the Service (typically using aggregated or anonymized data);
  • to send marketing communications, where you have consented to receive them (you can withdraw consent at any time).

5. Legal Bases for Processing

We rely on one or more of the following legal bases to process personal data:

  • performance of a contract with you (or steps taken at your request prior to entering into a contract);
  • compliance with a legal obligation to which we are subject;
  • our legitimate interests (such as securing our Service, preventing fraud, improving our platform), provided these interests are not overridden by your fundamental rights and freedoms;
  • your explicit consent, where required by applicable law (for example, for marketing communications or optional cookies).

6. Sharing Personal Data with Third Parties

We do not sell personal data. We may share personal data with the following categories of recipients, only to the extent necessary and under appropriate safeguards:

6.1. Service providers and sub-processors:

  • cloud-hosting and infrastructure providers (such as OVHcloud, Amazon Web Services, Google Cloud Platform, or comparable providers);
  • payment processors (Skrill, Stripe, PayPal, cryptocurrency processors, and local gateways);
  • email and messaging service providers;
  • analytics providers (such as Google Analytics — where enabled);
  • customer-relationship-management and support tools;
  • professional advisers (lawyers, accountants, auditors) bound by confidentiality obligations.

6.2. Integrations at your request:

Where you enable integrations with third-party services (such as Grab, DHL, HubSpot, Zoho CRM, Google Workspace, Stripe, or similar platforms), we transmit the personal data necessary for such integrations to operate. Your use of those third-party services is governed by their own privacy policies, over which we have no control and for which we accept no responsibility.

6.3. Business transfers:

In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, personal data may be transferred as part of the business assets, provided the acquiring party is bound by equivalent privacy commitments.

7. Compliance with Legal Requirements and Cooperation with Competent Authorities

As a responsible business operating internationally, Appexbots.com is committed to compliance with applicable law. We may disclose personal data to competent governmental, judicial, regulatory, or law-enforcement authorities in the following limited circumstances:

  • when required to do so by a valid subpoena, court order, or written legal request issued by a competent authority in a jurisdiction where we are legally bound to respond;
  • when disclosure is necessary to comply with a legal obligation to which we are subject (including tax, anti-money-laundering, and consumer-protection obligations);
  • when disclosure is necessary to protect the rights, property, or safety of Appexbots.com, our users, our Merchants, our Merchants' end-customers, or the public;
  • when disclosure is necessary to investigate, prevent, or take action regarding suspected illegal activity, fraud, security breaches, or breaches of our Terms of Service;
  • when we act, in good faith, at the request of law-enforcement authorities in connection with the detection, prevention, or investigation of a criminal offence.

Where legally permitted, we will make reasonable efforts to notify the affected user of any such disclosure before it occurs. Where we are legally prohibited from providing such notification, we will refrain from doing so.

We carefully review each request from an authority for its legal validity and disclose only the minimum data necessary to satisfy the request. We do not provide direct or bulk access to any government to our systems or databases in the absence of a valid legal process.

This approach reflects our respect for both the rule of law and the fundamental rights of our users to privacy and due process.

8. Cookies and Similar Technologies

The Service uses cookies and similar technologies to ensure proper functioning, enhance user experience, analyze usage, and improve the quality of the services provided. Cookies are small pieces of data stored on your device when you access the Service.

8.1. Types of cookies we use:

  • Strictly necessary (essential) cookies — required for the operation of the Service; you cannot opt out of these;
  • Functional cookies — remember your preferences (language, region, interface settings);
  • Analytical cookies — collect anonymized information about how the Service is used (pages visited, session duration, referral source);
  • Marketing cookies — help us measure the effectiveness of marketing campaigns and, where permitted, display relevant offers.

8.2. On your first visit, we ask for your consent to non-essential cookies through an interface (banner) that allows you to accept or reject categories. You may change or withdraw your consent at any time via the cookie preferences page at https://appexbots.com/cookie-settings or through your browser settings.

8.3. Third-party analytics services (such as Google Analytics) may set their own cookies and process data according to their own privacy policies. We do not control and are not responsible for the practices of such third parties.

8.4. Restricting or disabling cookies may impact the functionality of certain features. Instructions for managing cookies are available in your browser's help materials.

9. International Transfers of Personal Data

Appexbots.com operates internationally and may transfer personal data across borders, including to servers located in the Kingdom of Thailand, the European Union, the United States, and other jurisdictions where our cloud-service providers operate.

When transferring personal data to jurisdictions that do not provide an adequate level of protection under applicable law, we implement appropriate safeguards, which may include:

  • standard contractual clauses approved by the European Commission (for transfers subject to GDPR);
  • binding corporate rules or other approved transfer mechanisms;
  • additional technical and organizational measures.

By using the Service, you acknowledge that your personal data may be transferred, stored, and processed in countries other than your country of residence.

10. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.

Typical retention periods:

  • account and contact information — for the duration of your account, plus 3 years after account closure;
  • billing and tax records — 7 years, or the period required by applicable law;
  • chat messages and order history — as configured by the Merchant, but not more than 3 years after last activity, unless the Merchant instructs otherwise;
  • cookies — as described in the cookie management interface, typically from a single session up to 24 months;
  • backup archives — up to 90 days after primary deletion.

After the applicable retention period, personal data is securely deleted or anonymized.

11. Your Rights

Subject to applicable law, you have the following rights in relation to your personal data:

  • Right of access — to request confirmation of whether we process your data and, if so, to obtain a copy;
  • Right to rectification — to request correction of inaccurate or incomplete data;
  • Right to erasure ("right to be forgotten") — to request deletion of your data in certain circumstances;
  • Right to restriction of processing — to request that we temporarily stop processing your data;
  • Right to data portability — to receive your data in a structured, commonly used, machine-readable format;
  • Right to object — to object to processing based on legitimate interests, including direct marketing;
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing;
  • Right to lodge a complaint — with your local data protection supervisory authority.

To exercise any of these rights, please contact us using the details in Section 15. We will respond to your request within the timeframe required by applicable law (typically within 30 days). We may need to verify your identity before acting on your request.

If you are an end-customer of a Merchant and wish to exercise these rights in relation to data processed on behalf of the Merchant, please contact the Merchant directly. We will provide reasonable assistance to Merchants in responding to such requests.

12. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction. Such measures include, without limitation:

  • encryption of data in transit (TLS/HTTPS) and, where feasible, at rest;
  • access controls based on the principle of least privilege;
  • regular backups and disaster-recovery procedures;
  • regular security assessments and monitoring;
  • confidentiality agreements with personnel and sub-processors.

However, no method of transmission or storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security. In the event of a personal-data breach affecting your data, we will notify you and the relevant supervisory authority as required by applicable law.

13. Children's Privacy

The Service is intended for use by business users and by individuals aged 18 or over. We do not knowingly collect personal data from children under the age of 16 (or such other minimum age as applicable local law may require). If you become aware that a child has provided personal data to us, please contact us and we will take steps to delete such data.

14. Changes to This Privacy Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The updated version will be published on our website with a revised "Effective Date". If the changes are material, we will provide a more prominent notice (such as by email or an in-Service notification).

Your continued use of the Service after the effective date of the updated Policy constitutes acceptance of the changes.

15. How to Contact Us

If you have any questions, comments, or requests regarding this Privacy Policy or our processing of personal data, please contact us at:

SIAM GEKKO CO., LTD.
Trading as: Appexbots.com
Registered office: 252/49, Moo 2, Mae Sa Sub-district, Mae Rim District, Chiang Mai Province, Kingdom of Thailand
Company Registration Number: 0505565016342
Email (privacy inquiries): appexbots@gmail.com
Website: https://appexbots.com

Please include "Privacy Inquiry" or "Data Subject Request" in the subject line of your email so we can direct your message appropriately.

16. Governing Language and Law

This Policy is issued in English. Where translated into other languages, the English version shall prevail in case of any discrepancy. This Policy is governed by the laws of the Kingdom of Thailand, without prejudice to mandatory local data protection laws that apply to individuals in their jurisdiction of residence.

— END OF PRIVACY POLICY —