Privacy Policy

Last updated 2026-04-27

This Privacy Policy governs how Nattapong Petra, trading as 'Experts Mix', operating as 'PDF BulkX' ('we', 'us'), collects, uses, and protects your personal data. We are the data controller under Thailand's Personal Data Protection Act B.E. 2562 (2019) ('PDPA') and align with GDPR principles where applicable. This Policy applies to all users of the PDF BulkX web service at pdfbulkx.expertsmix.com. Your continued use of the Service is conditioned on the consent you provided at registration; you may withdraw consent at any time via Settings → Data & Privacy.

Data Controller

Data controller: Nattapong Petra, trading as 'Experts Mix', operating the 'PDF BulkX' brand. Controller type: Individual / natural person under PDPA §6. Contact: privacy@expertsmix.com. We do not yet have a designated Data Protection Officer (DPO) under PDPA §41 as our processing scale does not meet the mandatory threshold; the founder acts as the primary privacy contact.

User as Controller, PDFBulkX as Processor

When you upload PDFs containing personal data of third parties (your customers, vendors, employees, etc.), the legal roles change: You are the data controller for that third-party personal data under Thailand's PDPA. You decide what data to process and for what purpose. PDFBulkX is your data processor (PDPA §40). We process the third-party data only as instructed by you — specifically: extracting structured fields from your PDFs, delivering Excel/CSV output, and deleting both the PDF and the result within the retention windows below. Our processor obligations to you include: (a) processing third-party data only on your instructions, never for our own purposes; (b) maintaining security safeguards (encryption at rest and in transit, access control, audit logs); (c) notifying you within 72 hours of any data breach affecting your project's data; (d) assisting you with data-subject rights requests directed at us; (e) deleting or returning third-party data when you delete your project or close your account. Your responsibilities as controller include ensuring you have a lawful basis to process the third-party personal data (e.g., your customer's consent or a contract), providing notice to those data subjects under PDPA §23, and fulfilling your own obligations under PDPA §28 (cross-border transfer), §30–37 (rights), and §37(4) (breach notification to those data subjects). For a Data Processing Addendum (DPA) suitable for your enterprise compliance needs, contact privacy@expertsmix.com.

Data We Collect

We collect the following categories of personal data under the lawful bases specified (PDPA §24): (1) Account data (email address, display name, password hash) — Lawful basis: contract performance (§24(3)), necessary to provide the Service. (2) Uploaded PDF content — Lawful basis: consent (§24(1)) and contract performance (§24(3)). Sample PDFs uploaded during project setup are retained up to 7 days after Save, then auto-deleted. PDFs uploaded for bulk extraction within a saved project are deleted immediately after each run completes. PDFs uploaded via Quick Mode (a one-off extraction without project setup) are retained for up to 24 hours and then automatically deleted, unless you save the extraction as a project within that window — in which case they become project sample files governed by the 7-day rule above. (3) Extraction results (Excel/CSV output) — Lawful basis: contract performance (§24(3)). Retained 24 hours after generation, then automatically and permanently deleted (see Retention Periods section). (4) Usage logs, IP address, user agent, computer traffic data — Lawful bases: (a) legitimate interest (§24(5)) for security, fraud prevention, and service integrity; AND (b) legal obligation (§24(4)) under Section 26 of the Thai Computer Crime Act B.E. 2550, which requires service providers to retain computer traffic data for a minimum of 90 days (extendable up to 2 years on a case-by-case official order). Our actual retention is 365 days — see the Retention Periods section. We may disclose this data to competent officials upon a valid legal order under Section 18 of the same Act. You may object to the legitimate-interest processing at any time; the Computer Crime Act retention is legally mandated. (5) Audit events (login, consent records, data access, deletion requests) — Lawful basis: legal obligation (§24(4)) under PDPA record-keeping and breach investigation requirements. (6) Consent records — Lawful basis: legal obligation (§24(4)), to demonstrate lawful processing per PDPA §39.

How We Process Your Data

Logic Mode

Logic Mode has two phases: project setup (one-time) and bulk extraction runs (every batch). During setup, PDFs are briefly sent to Google Gemini for column detection and extraction-logic generation — see the AI Extract Mode section below for full cross-border details and consent gates. Once setup is complete, Logic Mode runs happen on our infrastructure in Singapore. Processing is local, pattern-matching based, and deterministic — no PDF content leaves our infrastructure during a typical Logic Mode run. AI fallback for scanned PDFs: if a Logic Mode run encounters scanned (image-only) PDFs that pattern-matching cannot read, you can optionally enable AI fallback for those specific files. When enabled, those scanned files are sent to Google Gemini for AI-based extraction — same cross-border safeguards as AI Extract Mode (see below). AI fallback is opt-in per run; if you skip it instead, scanned files are excluded from the run.

AI Extract Mode

PDF content you upload is sent to Google LLC (Gemini API) in the United States at several stages: (a) column detection during project setup, (b) extraction-logic generation for Logic Mode, (c) result preview, (d) AI Extract Mode bulk processing if you enable that mode, and (e) per-file AI fallback within a Logic Mode run when you opt in for scanned/unreadable PDFs. All of these constitute cross-border transfer of personal data under PDPA §28. Safeguards in place: (1) Explicit consent captured before any Gemini call via the first-upload consent dialog (PDPA §28(1) — consent of the data subject). (2) An additional, stronger consent captured before AI Extract Mode bulk runs specifically. (3) Google Cloud Data Processing Addendum with Standard Contractual Clauses (PDPA §28(2) — adequate protection measures). (4) Gemini paid-tier zero-retention policy — Google does not retain or use your content for model training. You may withdraw these consents at any time from Settings → Data & Privacy; withdrawal disables all AI-dependent features. For the full list of third parties involved, see the Sub-Processors section below.

Retention Periods

We retain personal data only as long as necessary for the stated purpose: (1) Sample PDFs uploaded during project setup — retained for up to 7 days after you finalize project setup ('Save' action), then automatically and permanently deleted, in line with the PDPA §37(3) duty to erase or destroy personal data when the retention period expires, when the data is irrelevant, or when it is beyond what is necessary for the purpose of collection. The grace window lets you iterate on refinement prompts without re-uploading. Re-saving (refinement re-upload flow) restarts the 7-day clock for the new sample files. (2) Bulk extraction & Quick Mode PDFs — PDFs uploaded for bulk extraction within a saved project are deleted immediately after each extraction run completes; never persisted across runs. PDFs uploaded via Quick Mode (a one-off extraction without project setup) are retained for up to 24 hours, then automatically and permanently deleted in line with the PDPA §37(3) duty to erase or destroy personal data when the retention period expires, when the data is irrelevant, or when it is beyond what is necessary for the purpose of collection, unless you save the extraction as a project within that window — in which case they become project sample files governed by the 7-day rule in (1). (3) Extracted data (Excel/CSV results) — 24 hours after generation, then automatically and permanently deleted. (4) Generated extraction logic — retained until you delete the project; you control deletion. (5) Account data (name, email, preferences) — retained until your account deletion request is processed; 15-day soft-delete grace period during which you may reverse the request; hard-deleted at the 15-day mark. A small identification tombstone (email, display name, account creation date) survives in audit logs for 365 days after hard-deletion as required by Section 26 ¶2 of the Thai Computer Crime Act B.E. 2550 (which mandates retention of user-identification data for at least 90 days from end-of-use); thereafter it is purged with the rest of the audit log. (6) Audit logs (login, consent, data access events, computer traffic data) — 365 days, satisfying both PDPA breach investigation requirements and the 90-day minimum under Section 26 of the Thai Computer Crime Act B.E. 2550. (7) Consent records — retained for the lifetime of the account plus 90 days after account deletion, to demonstrate lawful processing per PDPA §39. (8) Invoice and payment records — Stripe (our payment processor) issues a payment receipt (ใบเสร็จรับเงิน) for each transaction and retains transaction records per their standard retention policy. We also keep exported copies for at least 5 years to support Thai tax compliance (personal income tax filing now; Section 83 of the Revenue Code's VAT-record retention will additionally apply once we register for VAT). We do not yet issue Thai tax invoices (ใบกำกับภาษี) as we are below the VAT registration threshold.

Cookies

PDF BulkX uses only strictly necessary cookies, all set by us, all `HttpOnly` and `Secure` where applicable, and none used for advertising or cross-site tracking. • `next-auth.session-token` — keeps you signed in; cleared on sign-out or expiry. • `next-auth.csrf-token` — protects sign-in forms against cross-site request forgery. Anonymous traffic statistics are provided by Cloudflare Web Analytics, which is cookie-free and collects only aggregate page-view counts and Core Web Vitals — no personal data, no fingerprinting, no opt-out needed because no personal data is collected. If you proceed to checkout, the Stripe-hosted page on stripe.com may set its own cookies for fraud prevention; those are governed by Stripe's privacy policy and are not within our control.

Your Rights Under PDPA

Under Thailand's PDPA B.E. 2562, you have the following rights regarding your personal data: (§30 Right of access) — Request a copy of all personal data we hold about you. Exercise via Settings → Export Data (aligned with GDPR Art. 15). (§31 Right to data portability) — Receive your data in a structured, machine-readable format (JSON for account export; Excel/CSV for extraction outputs). Exercise via Settings → Export Data (aligned with GDPR Art. 20). (§32 Right to object / withdraw consent) — Withdraw consent for AI processing at any time via Settings → Data & Privacy. Two consent gates exist independently: (a) the first-upload consent that authorizes any Gemini call (used for column recommendation, extraction-logic generation, result preview, and bulk extraction); (b) the AI Extract consent that additionally authorizes per-file Gemini extraction in AI Extract Mode and the per-file AI fallback in Logic Mode runs. Withdrawing the first-upload consent disables ALL AI features. Withdrawing only the AI Extract consent leaves Logic Mode setup available but disables AI Extract Mode runs and the per-file AI fallback. (§33 Right to restrict processing) — If you have an active annual subscription, you can pause all processing via Settings → Pause Account. Your data is preserved, no extractions can run while paused, the subscription is paused (no billing accrues), and your prepaid term is extended by the pause duration on resume so you don't lose paid time. Monthly subscribers can stop processing by cancelling via Settings → Plan & Billing → Manage Subscription; cancellation takes effect at the end of the current billing period. For 7-day cooling-off cancellation requests, email support@expertsmix.com. For more comprehensive restriction requests under PDPA §34 (e.g. data accuracy contested, unlawful processing claim, restriction during objection verification), email privacy@expertsmix.com — we will respond within 30 days (aligned with GDPR Art. 18). (§34 Right to rectification) — Correct inaccurate personal data via Settings (name, email, password) (aligned with GDPR Art. 16). (§35 Right to erasure) — Delete your account permanently via Settings → Danger Zone. This triggers a 15-day soft-delete grace period during which you can cancel the deletion. After the grace period, your account, projects, files, and other personal data are erased from our active systems. Some records are retained as required by law and disclosed in the Retention Periods section above: audit logs for 365 days, a minimal account-deletion tombstone (email, name, account-creation timestamp) for CCA §26 ¶2, payment records retained by Stripe and per Revenue Code §83 where applicable, and rolling backup copies until they are overwritten in normal rotation (aligned with GDPR Art. 17). (§36 Right to be informed of transfers) — Cross-border transfers are disclosed in the AI Extract Mode section and the Sub-Processors section. We will notify you by email at least 30 days before any material change to sub-processors or transfer mechanisms. (§37 Right to complain) — If you believe we have violated your rights, contact privacy@expertsmix.com first; we will respond within 30 days. If unresolved, you may lodge a complaint with Thailand's Personal Data Protection Committee (PDPC) at pdpc.or.th.

No AI Training on Your Data

We do not use your documents, extracted data, or any other personal data to train AI models, and we do not authorize any third party to do so. Google's Gemini API is used on the paid tier, which means: (a) Google does not retain your prompts or outputs for training; (b) data is not used to improve Google's products; (c) the Gemini API Terms of Service for paid usage apply, not the consumer-facing Gemini app terms. This is contractually governed by the Google Cloud Data Processing Addendum listed in the Sub-Processors section.

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you without undue delay and within 72 hours of becoming aware of the breach, per PDPA §37(4). Our notification will include: (a) the nature of the breach and categories of data affected; (b) the likely consequences of the breach; (c) the mitigation measures we have taken or propose to take; and (d) steps you can take to protect yourself. We will also report to Thailand's Personal Data Protection Committee (PDPC) within the same 72-hour window where legally required (PDPA §37(4) — controllers report to the PDPC; high-risk breaches additionally trigger user notification, per the PDPC Notification on Personal Data Breach Notification B.E. 2565). Breach notifications are sent to the email address registered to your account. We retain audit logs of access events for 365 days (PDPA §39 + CCA §26), which support breach investigation and forensic timeline reconstruction.

Sub-Processors

We use the following third parties to operate PDF BulkX. Each has its own data protection commitments. Contact privacy@expertsmix.com for copies of the data processing agreements. Material changes (additions or replacements) are notified by email at least 30 days before taking effect, per the Changes to This Privacy Policy section. All cross-border transfers to these sub-processors rely on Standard Contractual Clauses (SCCs) as the adequate-safeguard mechanism under PDPA §28(2). The same SCCs additionally satisfy GDPR Chapter V transfer requirements where applicable. • Google LLC (United States) — Gemini API for AI extraction (column detection, extraction-logic generation, result preview, AI Extract Mode bulk runs, per-file AI fallback). Governed by the Google Cloud Data Processing Addendum with SCCs. Zero-retention per Gemini paid-tier terms; no data used for training. • Resend, Inc. (United States) — transactional email delivery (account verification, credit-confirmation emails which are separate from Stripe's legal receipt, deletion confirmations, breach notifications). Resend DPA includes SCCs. • Railway Corp. (US-incorporated; data hosted in Railway's Singapore region, asia-southeast1) — application hosting and managed PostgreSQL. Data encrypted at rest (AES-256) and in transit (TLS 1.2+). Railway DPA includes SCCs. • Cloudflare, Inc. (United States) — DNS, CDN, email routing (catch-all on expertsmix.com), cookie-free anonymous traffic analytics (Web Analytics), and R2 object storage for uploaded PDFs, extraction results, and user data exports (data hosted in APAC region, S3-compatible). Analytics collect aggregate page-view counts and Core Web Vitals only; no cookies, no fingerprinting, no personal data. Traffic terminates TLS at the Cloudflare edge. Cloudflare DPA includes SCCs. • Microsoft Corporation (United States) — Microsoft Clarity product-analytics (session recordings and heatmaps) used to understand navigation patterns and improve the Service's user experience. Sensitive inputs (passwords, payment fields, email fields) are masked at the strictest level before any capture, and IP-address collection is disabled. No personal data is intentionally collected. Governed by Microsoft's data protection terms including SCCs; see https://www.microsoft.com/privacy. • Stripe Payments (Stripe, Inc., United States / Stripe Singapore Holdings Pte. Ltd., Singapore) — payment processing for top-up credits and subscription billing (Lite, Pro, Business tiers; monthly and annual). PCI DSS Level 1 certified; card and bank data never touch our servers (Stripe Checkout is hosted on stripe.com). Stripe's global DPA includes SCCs.

Contact

Data Protection contact: privacy@expertsmix.com. The data controller is Nattapong Petra, trading as 'Experts Mix' (see Controller section above). We respond to privacy inquiries — access, correction, deletion, objection, restriction, withdrawal of consent — within 30 days per PDPA §30-37. For information about your rights under PDPA or to contact the regulator directly, see the Personal Data Protection Committee (PDPC) at pdpc.or.th.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes — including new sub-processors, changes to lawful basis, new cross-border transfers, or expanded data collection — will be notified by email at least 30 days before taking effect, giving you the opportunity to withdraw consent or delete your account before the change applies. Non-material changes (clarifications, typo corrections, formatting updates, version metadata) will be published with an updated 'Last updated' date without prior email notice. Your continued use of the Service after the effective date of any change constitutes your acceptance of the updated Policy. You retain the right to withdraw consent or delete your account at any time, regardless of changes.