Legal
VEDA Workspace Privacy Policy
This policy explains how Verion handles personal data in connection with VEDA Workspace, and what rights you have.
- Effective date
- Last updated
- Version
- 1.1
1. About this policy
VEDA Workspace is a business workspace provided by Verion, a technology company based in Thailand. This policy covers personal data handled in connection with the VEDA Workspace service, including account creation, signing in, subscription administration, support, and the data your organization works with inside its workspace.
The data controller is VERION TECHNOLOGY CO., LTD. (บริษัท เวริออน เทคโนโลยี จำกัด), taxpayer identification number 0125569024157, registered at 331/12 Bang Rak Phatthana, Bang Bua Thong, Nonthaburi 11140, Thailand. Naming the registered entity matters here rather than only the trading name, because the rights described below are exercised against a specific legal person.
Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA") is our primary reference for this policy. Where other data protection laws apply to your organization, we address them through the agreement with that organization.
Requests under this policy can be made using the contact address in the Contact section and will be handled by VERION TECHNOLOGY CO., LTD..
2. Who is responsible for personal data
Responsibility depends on the processing activity, and it is important to distinguish two situations.
Where Verion decides the purpose — we act as the data controller. This covers, for example:
- creating and administering user accounts and organization workspaces;
- authenticating users and protecting accounts;
- administering subscriptions, trials, invoices, and billing records;
- operating, securing, monitoring, and supporting the service;
- detecting and preventing fraud and abuse;
- meeting our own legal and accounting obligations.
Where your organization decides the purpose — we act on its instructions, as a service provider or processor. This covers the business content inside the workspace, for example:
- customer, supplier, and contact records;
- accounting, invoicing, and financial records;
- employee and HR records, where those modules are in use;
- documents and files uploaded to the workspace;
- other operational records your organization creates.
If you are an employee, customer, supplier, or other contact of an organization that uses VEDA Workspace, that organization decides what data about you is held in its workspace and why. Please direct requests about that data to the organization in the first instance. We will support them in responding, and we will help you reach them if you contact us.
3. Personal data we handle
Depending on how you interact with the service, this may include:
- Identity and profile data — name, the details you add to your user profile, and your language or display preferences.
- Business contact data — work email address, organization name, role, and similar business details.
- Account and security data — credentials in protected form, email verification and password reset state, session and sign-in records, and consent records showing what you agreed to and when.
- Organization and workspace data — the workspace your account belongs to, its companies, your role and permissions, and invitation records.
- Subscription and billing metadata — subscription status, trial and billing period dates, plan and module entitlements, invoice records, and identifiers issued by our payment provider.
- Limited payment method metadata — the card brand, the last four digits, the expiry month and year, and the provider's reference for the payment method. We do not receive or store full card numbers or security codes.
- Support and correspondence data — messages you send us and our replies, and records of requests you make under this policy.
- Technical, log, and security data — IP address, device and browser information, timestamps, actions recorded in audit logs, and diagnostic records generated when something fails.
- Workspace content — the business records your organization puts into the workspace, which may contain personal data about its customers, suppliers, employees, and other contacts.
- Uploaded documents — files your organization uploads, and text or values extracted from them where document processing is used.
- AI interaction data — the prompts, workspace context, and results involved when AI-assisted features are used, where those features are enabled.
We do not ask for special-category or sensitive personal data in order to provide the core service. Where your organization chooses to place such data in its workspace, it is responsible for having a lawful basis to do so.
4. Why we use personal data
- To provide the service — create and run workspaces, deliver the modules your organization has purchased, and make the product work.
- To authenticate and protect accounts — verify identity, maintain sessions, and detect unauthorised access.
- To administer organizations — manage members, roles, invitations, and companies within a workspace.
- To administer subscriptions and payments — manage trials, subscriptions, renewals, invoices, and payment status.
- To provide support — respond to your questions and investigate problems you report.
- To keep the service secure and reliable — monitor for abuse and fraud, diagnose faults, and maintain audit records.
- To improve the service — understand how the product is used and where it fails, in a way that is proportionate and, where required, based on your consent.
- To provide AI-assisted features — where those features are enabled for your organization and invoked by a user.
- To send service communications — transactional messages such as verification, trial and subscription notices, invoices, security alerts, and important product changes.
- To comply with legal obligations — including accounting, tax, and record-keeping requirements, and lawful requests from competent authorities.
5. Legal bases
Under the PDPA, and under other data protection laws where they apply, we rely on the basis appropriate to each activity. Consent is not our universal basis, and we do not treat acceptance of the Terms of Service as consent to unrelated processing.
- Performance of a contract, or steps taken at your request before entering one — to provide the service, run your account and workspace, and administer your subscription.
- Legal obligation — to keep accounting and tax records and to respond to lawful requests.
- Legitimate interests — to secure the service, prevent fraud and abuse, maintain audit records, diagnose faults, and improve the product, where those interests are not overridden by your rights and freedoms.
- Consent — where consent is actually required, such as optional analytics cookies and marketing communications. Where we rely on consent you may withdraw it at any time, and withdrawal does not affect processing carried out before withdrawal.
For personal data inside your organization's workspace, the legal basis is determined by that organization as the party deciding the purpose of the processing.
6. Payment data
Online payments are processed by Stripe, our payment provider. When you enter payment details at checkout or in a payment form, those details are transmitted to and handled by Stripe. We do not receive, and do not store, your full card number or card security code.
What we hold in our own systems is limited to what we need to run your subscription:
- the customer, subscription, invoice, and payment identifiers issued by the payment provider;
- subscription and payment status, billing period dates, amounts, currency, and invoice records;
- payment method metadata — type, card brand, last four digits, and expiry month and year;
- any tax identifier your organization supplies for invoicing, and its verification status.
Stripe processes payment data as an independent controller for its own compliance and fraud-prevention purposes, in addition to acting for us. Stripe's own privacy notice describes that processing. Emails confirming a payment, an invoice, or a refund may be sent by the payment provider as well as by us.
7. AI-assisted features
Where AI-assisted features are enabled for your organization and a user invokes them, the request and the workspace context needed to answer it are processed to generate the result. The purpose is to produce the assistance the user asked for.
- AI features run within the same access controls as the rest of the workspace. A request is limited by the entitlements your organization holds and by the permissions of the user making it.
- Depending on how the service is configured, AI processing may be carried out by infrastructure we operate or by a third-party model provider acting as our service provider under an agreement with us.
- We do not sell workspace content, and we do not make it available to third parties for their own independent purposes.
- We do not make claims here about model training or provider-side retention, because those depend on the provider configuration in force. If your organization needs a written commitment on that point for a specific deployment, contact us and we will confirm the position that applies to you in writing.
- AI-generated output can be inaccurate. It is assistance for a person to review, not an automated decision that produces legal or similarly significant effects for you without human involvement.
8. Access control inside your workspace
Who can see what inside a workspace is controlled by your organization:
- administrators decide who is invited, what role each person holds, and when access is removed;
- which modules exist in the workspace depends on the subscription the organization holds;
- within that, individual permissions further limit what each user can see and do;
- actions taken in the workspace are recorded in audit records so the organization can review them.
Our own staff access to workspace content is restricted to what is needed to operate the service and to support your organization — for example investigating a fault you have reported — and is subject to internal controls.
10. Where personal data is processed
The service runs on cloud infrastructure, and some of our service providers operate internationally. Personal data may therefore be processed on servers outside Thailand, or accessed from outside Thailand by a provider supporting the service.
Where personal data is transferred across borders, we rely on providers that offer recognised contractual and organisational safeguards for international transfers, and we transfer only what is needed for the purpose. If your organization needs confirmation of the processing locations that apply to its deployment, contact us and we will confirm them in writing.
11. How long we keep personal data
We keep personal data for as long as it is needed for the purpose it was collected for, and then delete it or de-identify it. We do not publish a single fixed period here, because different records are governed by different obligations and a made-up number would be misleading.
In practice, how long we keep something is determined by:
- how long your organization holds an active workspace, trial, or subscription;
- how long we need the record to provide and support the service;
- security and audit needs — for example retaining sign-in and audit records long enough to investigate an incident;
- legal, accounting, and tax obligations that require certain records, including invoices, to be retained for a defined period;
- whether the record is needed to establish, exercise, or defend a legal claim.
A trial ending, a subscription being cancelled, or a payment being refunded changes access and billing state — none of those events by itself deletes your workspace data. Where you ask us to delete data, we do so subject to the obligations above, and we will tell you if something must be retained and why.
12. Your rights
Subject to the conditions and exceptions in applicable law, including the PDPA, you may:
- be informed about how your personal data is collected, used, and disclosed;
- request access to your personal data and a copy of it;
- request a copy in a portable electronic form, or ask us to transmit it, where that right applies;
- ask us to correct data that is inaccurate, incomplete, or out of date;
- ask us to delete or de-identify your personal data;
- ask us to restrict how we use your personal data;
- object to certain processing, including processing based on legitimate interests;
- withdraw consent where we rely on consent;
- lodge a complaint with the competent data protection authority.
To make a request, write to hello@verion.one and tell us what you are asking for. We may need to verify your identity before acting, and we will respond within the period required by applicable law.
If your request concerns data held inside an organization's workspace, that organization decides the purpose of the processing. We will forward your request to it and support it in responding.
13. Security
We take technical and organisational measures appropriate to the risk. These include:
- encryption of data in transit;
- authentication controls, including email verification and protected credential storage;
- role-based access control and separation between organizations' workspaces;
- audit records of actions taken in the workspace;
- restricted internal access to production systems on a need-to-know basis;
- monitoring and logging to detect and investigate faults and suspicious activity;
- agreements with the service providers that process data on our behalf.
No system can be guaranteed completely secure. We do not currently claim any third-party security certification, and we will not imply one we do not hold. If you believe you have found a vulnerability, please report it to us at the contact address below rather than disclosing it publicly.
15. Communications
Service communications are part of the product and are sent because you hold an account. These include email verification, trial and subscription notices, invoices and payment messages, security alerts, and notices about material changes to the service or these documents. You cannot opt out of these while you hold an account, because they are necessary to operate it.
Marketing communications are separate. We ask for consent for marketing separately from acceptance of the Terms of Service, and accepting the Terms does not subscribe you to marketing. If you have opted in, you can withdraw at any time using the unsubscribe link or by contacting us, and doing so does not affect your service communications.
16. Children
VEDA Workspace is business software intended for organizations and their workers. It is not directed at children and we do not knowingly create accounts for them. If you believe a child has been given an account, contact us and we will address it.
17. Changes to this policy
We update this policy as the service and our obligations change. The version and the effective and last-updated dates are shown at the top of this page. Where a change materially affects how we handle your personal data, we will give notice before it takes effect — in the product, by email, or both.
18. Contact
For any privacy question or request under this policy:
- Privacy, data protection, legal, and security: hello@verion.one
- Billing and payment records: billing@verion.one
Please state clearly that your message is a personal data request, and describe what you are asking for, so that we can route and handle it properly.