Legal
Data Processing Agreement
Effective date: July 29, 2026
1. Roles and scope
The Customer is the Data Controller and AraiHub is the Data Processor for Customer Data submitted to or collected through the Customer's workspaces, widgets, tickets, connected communication channels, and related features. Each party remains responsible for complying with the data protection laws applicable to it, including Thailand's Personal Data Protection Act B.E. 2562 ("PDPA") and, where applicable, the EU General Data Protection Regulation ("GDPR").
For account administration, billing, security, service analytics, and AraiHub's direct relationship with the Customer, AraiHub may act as an independent Data Controller as described in the Privacy Policy.
2. Customer instructions and responsibilities
AraiHub will process Customer Personal Data only on the Customer's documented instructions, including the Customer's configuration and ordinary use of the service, unless processing is required by applicable law. If legally permitted, AraiHub will inform the Customer before processing required by law.
The Customer is responsible for:
- having a lawful basis and providing all required notices and choices;
- ensuring its instructions comply with applicable law;
- configuring access, retention, integrations, and connected channels appropriately;
- not submitting Personal Data that is unnecessary for the intended support purpose; and
- responding to Data Subjects and regulators as the Data Controller.
AraiHub will notify the Customer if, in AraiHub's reasonable opinion, an instruction infringes applicable data protection law and may suspend the affected processing until the parties resolve the issue.
3. AraiHub obligations
AraiHub will:
- limit access to personnel who need it to provide and secure the service;
- ensure authorized personnel are bound by appropriate confidentiality obligations;
- implement appropriate technical and organizational security measures;
- reasonably assist the Customer with Data Subject requests, security incidents, data protection impact assessments, and regulatory consultations;
- maintain records and information reasonably necessary to demonstrate compliance with this DPA; and
- not sell Customer Personal Data or use it for AraiHub's own advertising.
4. Security
Taking into account the state of the art, implementation costs, the nature and risks of processing, AraiHub will maintain safeguards designed to protect Customer Personal Data against unauthorized or unlawful access, disclosure, alteration, loss, or destruction. The measures include, as appropriate:
- encryption in transit and protection of stored credentials and secrets;
- tenant and workspace access controls with role-based authorization;
- logging, monitoring, backup, recovery, and vulnerability management;
- data minimization and retention controls; and
- incident response and business continuity procedures.
The Customer acknowledges that security is a shared responsibility and must protect its accounts, credentials, devices, integrations, and access permissions.
5. Personal Data Breach
AraiHub will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. The notice will include available information reasonably required for the Customer to meet its legal obligations. AraiHub will take reasonable steps to contain, investigate, mitigate, and remediate the incident and will provide material updates as they become available.
AraiHub's notification or response does not constitute an admission of fault or liability. The Customer is responsible for determining whether notification to Data Subjects or authorities is legally required.
6. Data Subject requests
If AraiHub receives a request from a Data Subject concerning Customer Personal Data, AraiHub will direct the requester to the Customer where reasonably possible and will not independently respond unless instructed by the Customer or required by law. Taking into account the nature of processing, AraiHub will provide reasonable technical assistance through available product functionality and support channels. Additional work outside standard functionality may be subject to reasonable fees agreed in advance.
7. Sub-processors
The Customer gives AraiHub general authorization to use Sub-processors to provide infrastructure, storage, communications, authentication, payment, support, and security services. AraiHub will require each Sub-processor that processes Customer Personal Data to protect it under obligations materially consistent with this DPA.
AraiHub will make current Sub-processor information available on request and will provide reasonable notice of a material new Sub-processor where required by law. The Customer may object on reasonable data protection grounds by contacting AraiHub promptly. The parties will work in good faith on a commercially reasonable solution. If none is available, the Customer may stop using the affected feature. AraiHub remains responsible for its Sub-processors to the extent required by law.
Communication platforms or services that the Customer independently connects to AraiHub may process data under their own terms and are not AraiHub Sub-processors when they act independently of AraiHub.
8. International data transfers
AraiHub will process and transfer Customer Personal Data only as necessary to provide the service and in accordance with applicable cross-border transfer requirements. Where legally required, the parties will use an appropriate transfer mechanism, which may include adequacy decisions, binding contractual safeguards, or applicable Standard Contractual Clauses. On request, AraiHub will provide information reasonably necessary for the Customer's transfer assessment.
9. Return, deletion, and retention
During the subscription, the Customer may access, export, or delete Customer Data using available service functionality. After termination or expiry, AraiHub will delete or return Customer Personal Data at the Customer's choice, unless applicable law requires retention. Data may remain in protected backups until overwritten under normal backup cycles, during which it remains protected and is not used for another purpose.
Product-specific retention limits, paid-plan grace periods, deleted content, anti-abuse records, and legal holds may apply as described in the service, applicable plan, and Privacy Policy.
10. Audit and compliance information
On reasonable written request, AraiHub will provide information necessary to demonstrate compliance with this DPA. If that information is insufficient and applicable law requires an audit, the Customer may conduct one no more than once annually through an independent auditor bound by confidentiality, during normal business hours and without disrupting the service. The Customer bears its audit costs unless the audit identifies a material breach by AraiHub.
AraiHub may require reasonable scope, security, and confidentiality conditions and may satisfy an audit request by providing relevant third-party reports or certifications where available.
11. Government and legal requests
Unless prohibited by law, AraiHub will notify the Customer of a legally binding request for Customer Personal Data and will disclose only the data legally required. AraiHub may challenge requests it reasonably believes are unlawful or disproportionate.
12. Term, precedence, and liability
This DPA takes effect when the Customer accepts the agreement governing the AraiHub service and continues while AraiHub processes Customer Personal Data. If this DPA conflicts with the agreement on the protection or processing of Personal Data, this DPA controls. All other contractual terms, including limitations of liability, continue to apply to the fullest extent permitted by law.
The English and Thai versions are intended to have the same meaning. If an inconsistency cannot be resolved, the English version prevails, except where applicable law requires otherwise.
13. Processing details
| Subject matter and purpose | Providing omnichannel customer support, live chat, ticketing, collaboration, automation, storage, analytics, and related AraiHub features configured by the Customer. |
|---|---|
| Duration | For the term of the service and the applicable deletion, backup, grace, and legal-retention periods. |
| Data Subjects | Customer personnel, agents, administrators, visitors, end customers, contacts, and other individuals whose data the Customer submits or connects. |
| Personal Data | Names, contact details, profile and channel identifiers, messages, tickets, files, images, audio/video, conversation metadata, device/browser information, access logs, and Customer-configured fields. |
| Sensitive data | Not intentionally required by AraiHub. It may be processed only when the Customer or a Data Subject submits it, subject to the Customer's lawful instructions and safeguards. |
| Processing operations | Collection, receipt, transmission, organization, storage, retrieval, display, analysis, modification, export, restriction, and deletion as directed through the service. |
14. Contact
DPA, privacy, and security requests may be sent to hello@araihub.com.
- Processor: Tepari Limited (AraiHub)
- Location: Bangkok, Thailand
This public DPA is designed to form part of the AraiHub service agreement. Customers requiring a signed copy, additional transfer clauses, or organization-specific terms may contact AraiHub.