D PROMPT ACCOUNTING (operated by The Rich Consultant Co., Ltd., "we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website dpromptaccounting.com or engage our services.
This policy is issued in compliance with Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA") and the EU General Data Protection Regulation ("GDPR") where applicable.
1. Who We Are (Data Controller)
The Rich Consultant Co., Ltd. (operating as D PROMPT ACCOUNTING) is the data controller of your personal data.
- Address: 25 Alma Link Building, 17th Floor, Soi Chidlom, Ploenchit Road, Lumpini, Pathumwan, Bangkok 10330
- Email: dpo@dpromptaccounting.com (Data Protection Officer)
- Phone: 083-048-2999
2. Personal Data We Collect
2.1 Information you provide
- Identity data: Name, nationality, passport details (for visa/registration services).
- Contact data: Email, phone, LINE ID, postal address, company name.
- Financial data: Bank details, tax identification numbers (for accounting clients only).
- Engagement data: Service interest, business stage, free-form messages submitted via forms.
2.2 Information we collect automatically
- Technical data: IP address, browser type, device type, operating system.
- Usage data: Pages visited, time on page, referrer URL, click events.
- Marketing attribution: UTM parameters from advertising campaigns.
2.3 Information from third parties
- LinkedIn or referrer information when you click an ad or referral link.
- Public records and regulatory databases (DBD, Revenue Department) when conducting due diligence on engaged clients.
3. How We Use Your Personal Data
| Purpose | Lawful Basis |
| Respond to consultation requests | Consent + Legitimate interest |
| Deliver contracted professional services | Contract performance |
| File regulatory documents on your behalf | Legal obligation + Contract |
| Send service updates and invoices | Contract performance |
| Send marketing newsletters | Consent (you may unsubscribe anytime) |
| Improve our website & services | Legitimate interest |
| Comply with anti-money-laundering laws | Legal obligation |
| Defend or pursue legal claims | Legitimate interest |
4. Cookies and Tracking
We use the following categories of cookies. You can change your preferences at any time via the cookie banner.
- Essential cookies (always active): Required for site functionality, including session management and form submission.
- Analytics cookies (consent required): Google Analytics 4 — anonymized usage statistics.
- Marketing cookies (consent required): Meta Pixel and LinkedIn Insight Tag for advertising performance measurement.
Read our full Cookie Policy for details.
5. How We Share Your Personal Data
We do not sell your personal data. We share it only with:
- Thai government authorities: DBD, Revenue Department, BOI, Immigration Bureau, Social Security Office, Ministry of Labour — strictly to perform our contracted services.
- Service providers: Cloud hosting (Vercel, Cloudflare), email delivery (SendGrid), CRM (HubSpot), automation (n8n) — bound by data processing agreements.
- Professional partners: Audit firms, banks, and partner law firms — only with your prior consent.
- Legal authorities: When required by law or court order.
6. International Transfers
Some of our service providers (HubSpot, Vercel, Cloudflare) are located outside Thailand, primarily in the United States and European Union. Where we transfer your data outside Thailand, we rely on the EU Standard Contractual Clauses or equivalent legal mechanisms approved by the Personal Data Protection Committee of Thailand.
7. Data Retention
- Inquiry-only data (no engagement): 24 months from last contact.
- Active client data: Duration of the engagement plus 10 years (Thai legal retention requirement for accounting/tax records).
- Analytics data: 14 months (Google Analytics default).
- Marketing data: Until you unsubscribe, or 36 months of inactivity.
8. Your Rights
Under PDPA and GDPR, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Request deletion of your data (subject to our legal retention obligations).
- Restriction: Limit how we process your data.
- Portability: Receive your data in a machine-readable format.
- Objection: Object to processing for marketing or legitimate-interest purposes.
- Withdraw consent: Where processing is based on consent.
- Lodge a complaint: With Thailand's Personal Data Protection Committee or your local supervisory authority.
To exercise any right, email dpo@dpromptaccounting.com. We will respond within 30 days.
9. Data Security
We implement industry-standard technical and organizational safeguards including:
- TLS 1.3 encryption for all data in transit.
- AES-256 encryption for data at rest.
- Role-based access control with multi-factor authentication.
- Regular security audits and penetration testing.
- Mandatory PDPA training for all staff.
Despite these measures, no internet transmission is 100% secure. We cannot guarantee absolute security.
10. Children's Privacy
Our services are intended for adult business use. We do not knowingly collect personal data from individuals under 20 years of age (Thai legal age of majority).
11. Changes to This Policy
We may update this policy periodically. Material changes will be communicated via email (for active clients) or website banner notice. The "Last updated" date at the top reflects the most recent revision.
12. Contact
Questions, concerns, or requests regarding this Privacy Policy:
- Email: dpo@dpromptaccounting.com
- Post: Data Protection Officer, D PROMPT ACCOUNTING, 25 Alma Link Building, 17F, Soi Chidlom, Bangkok 10330, Thailand