Qlendar.AI

ข้อตกลงการประมวลผลข้อมูลส่วนบุคคล (Data Processing Agreement)

ข้อตกลงฉบับนี้กำหนดคำสั่งที่บันทึกไว้ซึ่งผู้ควบคุมข้อมูลส่วนบุคคลให้ไว้แก่ผู้ประมวลผลข้อมูลส่วนบุคคล ตามมาตรา ๔๐ แห่งพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. ๒๕๖๒ ข้อตกลงนี้มีผลเมื่อผู้ควบคุมข้อมูลส่วนบุคคล กดตอบรับในระบบ และระบบจะบันทึกผู้กดตอบรับ วันเวลา และเวอร์ชันของข้อตกลงไว้เป็นหลักฐาน

1. คู่สัญญาและบทบาท

สตูดิโอผู้ใช้บริการเป็น ผู้ควบคุมข้อมูลส่วนบุคคล ของข้อมูลนักเรียนและผู้ปกครอง ส่วน Qlendar.ai ซึ่งดำเนินการโดย ธนายุ พัฒนภิรมย์ (Thanayu Phatthanaphirom) ในฐานะ ผู้ประกอบการรายบุคคล / sole proprietor เป็น ผู้ประมวลผลข้อมูลส่วนบุคคล ผู้ควบคุมข้อมูลส่วนบุคคลเป็นผู้กำหนดวัตถุประสงค์และวิธีการประมวลผล ผู้ประมวลผลข้อมูลส่วนบุคคลดำเนินการตามคำสั่งเท่านั้น

2. ขอบเขต

ผู้ประมวลผลข้อมูลส่วนบุคคลจะประมวลผลข้อมูลส่วนบุคคลเฉพาะตามคำสั่งที่บันทึกไว้ในตารางที่ ๑ เท่านั้น คู่สัญญารับทราบร่วมกันว่า ตามมาตรา ๔๐ วรรคสอง หากผู้ประมวลผลข้อมูลส่วนบุคคลประมวลผลนอกเหนือจากคำสั่งดังกล่าว ผู้ประมวลผลข้อมูลส่วนบุคคลย่อมถือเป็นผู้ควบคุมข้อมูลส่วนบุคคลสำหรับการประมวลผลนั้นโดยผลของกฎหมาย การประมวลผลที่ผู้ประมวลผลข้อมูลส่วนบุคคลกระทำเพื่อวัตถุประสงค์ของตนเองระบุไว้แยกต่างหากในตารางที่ ๒

3. ตารางที่ ๑ — คำสั่งที่บันทึกไว้

ผู้ควบคุมข้อมูลส่วนบุคคลสั่งให้ผู้ประมวลผลข้อมูลส่วนบุคคลดำเนินการดังต่อไปนี้

  1. สร้างและดูแลบัญชีผู้ใช้และการเข้าสู่ระบบผ่าน LINE Login รวมถึงชื่อที่แสดง รหัสผู้ใช้ LINE และภาษาที่เลือก
  2. รับและจัดการการจอง รายชื่อผู้เข้าเรียน คิวสำรอง และการเช็คอิน
  3. รับชำระเงินค่าคอร์สและแพ็กเกจ ออกรายการเครดิต และกระทบยอดการชำระเงินผ่าน PromptPay บัตรเครดิต และสลิปโอนเงิน
  4. ส่งข้อความแจ้งเตือนถึงนักเรียนผ่านบัญชีทางการ LINE ของผู้ควบคุมข้อมูลส่วนบุคคลเอง
  5. ส่งข้อความการตลาดหรือข้อความกระจายเสียง เฉพาะถึงนักเรียนที่ให้ความยินยอมทางการตลาดไว้ และเฉพาะเมื่อผู้ควบคุมข้อมูลส่วนบุคคลสั่ง
  6. ให้บริการผู้ช่วยอัตโนมัติ (AI assistant) ในช่องทาง LINE ซึ่งรวมถึง การส่งชื่อนักเรียนและบริบทการจองไปยัง Google LLC ในสหรัฐอเมริกา เพื่อสร้างคำตอบ ผู้ควบคุมข้อมูลส่วนบุคคลสามารถปิดการใช้งานผู้ช่วยนี้ได้
  7. บันทึกความยินยอมและดำเนินการตามคำขอใช้สิทธิของเจ้าของข้อมูลส่วนบุคคลตามที่ผู้ควบคุมข้อมูลส่วนบุคคลกำหนด
  8. เก็บรักษาและลบข้อมูลตามตารางที่ ๓
  9. จัดทำสถิติและข้อมูลเชิงลึก ภายในข้อมูลของผู้ควบคุมข้อมูลส่วนบุคคลรายนั้นเท่านั้น
  10. ดำเนินงานเบื้องหลังตามกำหนดเวลา เช่น การกระทบยอดการชำระเงิน การหมดอายุของเครดิต และการลบข้อมูลตามกำหนด งานเหล่านี้ทำงานกับข้อมูลของผู้ควบคุมข้อมูลส่วนบุคคลทุกรายในระบบเดียวกัน แต่ประมวลผลข้อมูลของแต่ละรายแยกจากกัน และถือเป็นการดำเนินการตามคำสั่งข้างต้น

ข้อมูลสุขภาพ ข้อมูลการแพ้ และข้อมูลการบาดเจ็บ ไม่อยู่ในคำสั่งนี้ และระบบยังไม่เปิดใช้งานการเก็บข้อมูลดังกล่าว หากจะเปิดใช้งานในอนาคต ต้องมีคำสั่งเพิ่มเติมและความยินยอมโดยชัดแจ้งแยกต่างหาก

4. ตารางที่ ๒ — การประมวลผลที่ Qlendar เป็นผู้ควบคุมข้อมูลส่วนบุคคล

เพื่อความชัดเจนและตรงตามความเป็นจริง การประมวลผลต่อไปนี้ Qlendar กระทำเพื่อวัตถุประสงค์ของตนเอง จึงเป็นผู้ควบคุมข้อมูลส่วนบุคคลสำหรับการประมวลผลนั้น ไม่ใช่การกระทำตามคำสั่งของสตูดิโอ

  1. ข้อมูลบัญชี การเรียกเก็บเงิน และการสมัครใช้บริการของสตูดิโอเอง
  2. ยอดรวมค่าธรรมเนียมแพลตฟอร์มที่คำนวณจากรายการชำระเงิน โดยผลลัพธ์เป็นยอดรวมรายสตูดิโอ ไม่ใช่ข้อมูลรายบุคคล
  3. บันทึกความปลอดภัย บันทึกการตรวจสอบ และการจำกัดอัตราการใช้งานเพื่อป้องกันการใช้งานโดยมิชอบ
  4. ข้อมูลผู้สนใจที่ส่งเข้ามาทางเว็บไซต์ของ Qlendar
  5. การติดต่อเพื่อให้ความช่วยเหลือแก่สตูดิโอ

ฐานทางกฎหมาย คือ ความจำเป็นเพื่อการปฏิบัติตามสัญญาที่ทำกับสตูดิโอ และประโยชน์โดยชอบด้วยกฎหมาย ในการให้บริการและรักษาความมั่นคงปลอดภัยของระบบ

5. ผู้ประมวลผลช่วง

ผู้ประมวลผลข้อมูลส่วนบุคคลใช้ผู้ให้บริการรายอื่นดังต่อไปนี้ และจะแจ้งให้ผู้ควบคุมข้อมูลส่วนบุคคลทราบก่อนเพิ่มรายใหม่

ผู้ให้บริการ / Providerได้รับข้อมูลใด / What it receivesที่ตั้ง / Location
Neonฐานข้อมูล PostgreSQL — ข้อมูลส่วนบุคคลทั้งหมดสหรัฐอเมริกา
Vercelโฮสติ้ง การประมวลผล และบันทึกคำขอสหรัฐอเมริกา และเครือข่ายทั่วโลก
Google LLC (Gemini API)ข้อความสนทนา บริบทของนักเรียนที่ส่งเข้าไป และกฎที่สตูดิโอกำหนดเองสหรัฐอเมริกา
Stripeการเรียกเก็บค่าบริการรายเดือนของสตูดิโอสหรัฐอเมริกา และทั่วโลก
Omiseการชำระเงินของนักเรียน (PromptPay และบัตร)ประเทศไทย
EasySlipภาพสลิปโอนเงินทั้งภาพ ซึ่งมีชื่อผู้โอน เลขบัญชี และจำนวนเงินประเทศไทย
Sentryข้อมูลข้อผิดพลาดของระบบ ซึ่งอาจมีตัวระบุตัวตนปะปนสหรัฐอเมริกา
Upstashตัวนับสำหรับจำกัดอัตราการใช้งานและงบประมาณ AIสิงคโปร์
LINEการเข้าสู่ระบบและการส่งข้อความ ซึ่งเนื้อหาข้อความมีชื่อนักเรียนญี่ปุ่นและสิงคโปร์

ณ วันที่จัดทำข้อตกลงฉบับนี้ ข้อตกลงการประมวลผลข้อมูลส่วนบุคคลกับผู้ให้บริการข้างต้น ยังไม่ได้ลงนาม ผู้ประมวลผลข้อมูลส่วนบุคคลจะแจ้งความคืบหน้าให้ผู้ควบคุมข้อมูลส่วนบุคคลทราบ

6. มาตรการรักษาความมั่นคงปลอดภัย

ผู้ประมวลผลข้อมูลส่วนบุคคลจัดให้มีมาตรการดังนี้ การแบ่งแยกข้อมูลของแต่ละสตูดิโอในทุกคำสั่งค้นข้อมูล การเข้ารหัสข้อมูลลับของสตูดิโอขณะจัดเก็บ การเข้ารหัสข้อมูลระหว่างการรับส่ง การบันทึกการกระทำของผู้ดูแลระบบ และการจำกัดอัตราการใช้งานเพื่อป้องกันการใช้งานโดยมิชอบ

7. ข้อห้าม

ผู้ประมวลผลข้อมูลส่วนบุคคลจะไม่กระทำการดังต่อไปนี้ (๑) นำข้อมูลส่วนบุคคลของนักเรียนไปใช้ฝึกฝนแบบจำลองปัญญาประดิษฐ์ใด ๆ (๒) วิเคราะห์ข้อมูลส่วนบุคคลของนักเรียนข้ามสตูดิโอเพื่อวัตถุประสงค์ของผู้ประมวลผลข้อมูลส่วนบุคคลเอง (๓) เปิดเผยข้อมูลส่วนบุคคลแก่บุคคลอื่นนอกเหนือจากผู้ประมวลผลช่วงที่ระบุไว้ในข้อ ๕ และ (๔) ขายข้อมูลส่วนบุคคล

8. การแจ้งเหตุละเมิดข้อมูลส่วนบุคคล

เมื่อผู้ประมวลผลข้อมูลส่วนบุคคลทราบถึงเหตุละเมิดข้อมูลส่วนบุคคล จะแจ้งให้ผู้ควบคุมข้อมูลส่วนบุคคลทราบตามมาตรา ๔๐ (๒) โดยแจ้งผ่านระบบเป็นประกาศที่ปิดไม่ได้จนกว่าผู้ดูแลของสตูดิโอจะกดรับทราบ ซึ่งระบบจะบันทึกผู้กดรับทราบและวันเวลาไว้ และจะติดต่อทางช่องทางอื่นเพิ่มเติมพร้อมบันทึกการติดต่อนั้นไว้ด้วย การแจ้งสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคลและการแจ้งเจ้าของข้อมูลส่วนบุคคลเป็นหน้าที่ของผู้ควบคุมข้อมูลส่วนบุคคลตามมาตรา ๓๗ (๔) ผู้ประมวลผลข้อมูลส่วนบุคคลจะไม่ดำเนินการดังกล่าวแทน

9. การช่วยเหลือเรื่องสิทธิของเจ้าของข้อมูลส่วนบุคคล

ผู้ประมวลผลข้อมูลส่วนบุคคลจัดให้มีช่องทางรับคำขอใช้สิทธิของเจ้าของข้อมูลส่วนบุคคล และส่งต่อให้ผู้ควบคุมข้อมูลส่วนบุคคลพิจารณา โดยระบบกำหนดกรอบเวลาตอบสนอง ๓๐ วัน การตัดสินใจว่าจะอนุมัติหรือปฏิเสธคำขอเป็นของผู้ควบคุมข้อมูลส่วนบุคคล

10. บันทึกรายการกิจกรรมการประมวลผล

ผู้ประมวลผลข้อมูลส่วนบุคคลจัดทำและรักษาบันทึกรายการกิจกรรมการประมวลผลของตนตามมาตรา ๔๐ (๓) และจะจัดส่งให้ผู้ควบคุมข้อมูลส่วนบุคคลเมื่อได้รับการร้องขอ

11. ตารางที่ ๓ — การเก็บรักษาและการลบ

ระบบบังคับใช้กำหนดเวลาต่อไปนี้ตามที่เขียนไว้จริงในโปรแกรม

  • โปรไฟล์ผู้ใหญ่ที่ถูกเก็บเข้าคลัง เก็บต่ออีก ๓ ปี
  • โปรไฟล์ผู้เยาว์ที่ถูกเก็บเข้าคลัง เก็บต่ออีก ๑ ปี
  • ข้อมูลทางการเงินและภาษี เก็บอย่างน้อย ๕ ปี ตามหน้าที่ตามกฎหมาย

ปัจจุบันระบบ ยังไม่มีกลไกอัตโนมัติสำหรับการนับอายุข้อมูลทางการเงิน การลบข้อมูลทางการเงินเมื่อครบกำหนดจึงเป็นการดำเนินการด้วยมือ

12. หน้าที่ของผู้ควบคุมข้อมูลส่วนบุคคล

ผู้ควบคุมข้อมูลส่วนบุคคลมีหน้าที่แจ้งนโยบายความเป็นส่วนตัวแก่นักเรียนและผู้ปกครอง ขอความยินยอมตามที่กฎหมายกำหนด และแจ้งเหตุละเมิดต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคลเมื่อมีหน้าที่ต้องแจ้ง

13. ระยะเวลา เวอร์ชัน และการตอบรับ

ข้อตกลงฉบับนี้เป็นเวอร์ชัน 2026-08-11 มีผลตลอดระยะเวลาที่ผู้ควบคุมข้อมูลส่วนบุคคลใช้บริการ เมื่อมีการแก้ไขเป็นเวอร์ชันใหม่ ผู้ควบคุมข้อมูลส่วนบุคคลต้องกดตอบรับเวอร์ชันใหม่นั้นอีกครั้ง การตอบรับแต่ละครั้งจะถูกบันทึกไว้พร้อมชื่อผู้กดตอบรับ วันเวลา และเวอร์ชัน

Data Processing Agreement

This agreement sets out the documented instructions given by the Controller to the Processor under section 40 of the Personal Data Protection Act B.E. 2562. It takes effect when the Controller accepts it in the product, and the product records who accepted it, when, and which version.

1. Parties and roles

The studio using the service is the Controller of its students' and guardians' personal data. Qlendar.ai, operated by ธนายุ พัฒนภิรมย์ (Thanayu Phatthanaphirom) as ผู้ประกอบการรายบุคคล / sole proprietor, is the Processor. The Controller determines the purposes and means of processing; the Processor acts only on instructions.

2. Scope

The Processor processes personal data only on the documented instructions in Schedule 1. The parties record that, under section 40 paragraph 2, a processor that processes outside those instructions is deemed the controller for that processing by operation of law. Processing the Processor carries out for its own purposes is stated separately in Schedule 2.

3. Schedule 1 — the documented instructions

The Controller instructs the Processor to carry out the following.

  1. Create and maintain user accounts and LINE Login sessions, including display name, LINE user id and language preference.
  2. Take and manage bookings, class rosters, waitlists and check-in.
  3. Take payment for courses and packages, issue credit ledger entries, and reconcile payments made by PromptPay, card and bank-transfer slip.
  4. Send notification messages to students through the Controller's own LINE Official Account.
  5. Send marketing or broadcast messages only to students who have given marketing consent, and only when the Controller instructs it.
  6. Operate the automated assistant in the LINE channel, which includes sending student names and booking context to Google LLC in the United States in order to generate replies. The Controller may switch the assistant off.
  7. Record consent and process data-subject rights requests as directed by the Controller.
  8. Retain and delete data in accordance with Schedule 3.
  9. Compute insights and analytics within that Controller's own data only.
  10. Run scheduled background jobs such as payment reconciliation, credit expiry and scheduled deletion. These jobs run across every Controller's data in one system but process each Controller's data separately, and they are within the instructions above.

Health, allergy and injury data is not within these instructions and the product does not collect it. Enabling it in future requires a further instruction and separate explicit consent.

4. Schedule 2 — where Qlendar is the controller

Stated plainly and accurately: the following processing is carried out for Qlendar's own purposes, so Qlendar is the controller for it. It is not done on the studio's instructions.

  1. The studio's own account, billing and subscription data.
  2. The platform-fee total computed from payment records. The output is a per-studio total, not individual-level data.
  3. Security logs, audit logs and rate limiting to prevent abuse.
  4. Enquiries submitted through Qlendar's own website.
  5. Support correspondence with the studio.

The legal basis is necessity for performance of the contract with the studio, and legitimate interest in operating and securing the service.

5. Sub-processors

The Processor uses the following sub-processors, and will notify the Controller before adding another.

ผู้ให้บริการ / Providerได้รับข้อมูลใด / What it receivesที่ตั้ง / Location
NeonPostgreSQL database — all personal dataUnited States
VercelHosting, compute and request logsUnited States and global edge
Google LLC (Gemini API)Chat text, injected student context and the studio's own custom rulesUnited States
StripeThe studio's own subscription billingUnited States and global
OmiseStudent payments (PromptPay and card)Thailand
EasySlipFull bank-slip images, including payer name, account number and amountThailand
SentryError payloads, which may carry identifiersUnited States
UpstashRate-limit and AI budget countersSingapore
LINELogin and message delivery; message text contains student namesJapan and Singapore

As at the date of this version, data processing agreements with the providers above are not yet executed. The Processor will keep the Controller informed.

6. Security measures

The Processor maintains the following measures: separation of each studio's data on every query, encryption at rest of studio secrets, encryption in transit, admin action logging, and rate limiting to prevent abuse.

7. Prohibitions

The Processor will not (1) use students' personal data to train any artificial-intelligence model, (2) analyse students' personal data across studios for the Processor's own purposes, (3) disclose personal data to anyone other than the sub-processors listed in clause 5, or (4) sell personal data.

8. Breach notification

On becoming aware of a personal data breach, the Processor notifies the Controller under section 40(2) by an in-product notice that cannot be dismissed until a studio administrator acknowledges it, recording who acknowledged it and when, and additionally makes contact by another channel and records that contact. Notifying the Office of the Personal Data Protection Committee and notifying data subjects are the Controller's own duties under section 37(4). The Processor will not do either on the Controller's behalf.

9. Assisting with data-subject rights

The Processor provides an intake channel for data-subject rights requests and passes them to the Controller, with a 30-day response window in the product. The decision to grant or refuse a request is the Controller's.

10. Records of processing

The Processor keeps its own record of processing activities under section 40(3) and will provide it to the Controller on request.

11. Schedule 3 — retention and deletion

The product enforces the following, as actually implemented.

  • Archived adult profile: kept for a further 3 years.
  • Archived minor profile: kept for a further 1 year.
  • Financial and tax records: kept for at least 5 years, as a statutory floor.

The product does not currently have an automated mechanism for ageing financial records. Deleting them when the period expires is a manual step.

12. The Controller's own duties

The Controller is responsible for giving students and guardians a privacy notice, obtaining consent where the law requires it, and notifying the Office of the Personal Data Protection Committee of a breach where it is required to do so.

13. Term, version and acceptance

This is version 2026-08-11. It applies for as long as the Controller uses the service. When a new version is issued, the Controller accepts the new version again. Each acceptance is recorded with the acceptor's name, the time, and the version.

© 2026 Qlendar.AI. All rights reserved.