[TH] Legal Documentation
[TH] Privacy Policy, Terms of Service, and Billing Agreement for RedSocs services. All documents governed by the laws of the Kingdom of Thailand.
[TH] Privacy Policy
Effective: [TH] June 2026 | Jurisdiction: [TH] Kingdom of Thailand
[TH] RedSocs ("we", "our", "us") is committed to protecting your privacy in accordance with the Personal Data Protection Act B.E. 2562 (PDPA) of the Kingdom of Thailand. This Privacy Policy explains how we collect, use, and protect your data when you use RedSocs products, including SpamWarden, the RedSocs SOC Platform (app.redsocs.com), and this website.
1.1 Data Collected
[TH] SpamWarden — Client-Side Processing: SpamWarden is engineered as a fully client-side engine. All spam signal processing, Naive Bayes classification, and DOM analysis occur within the user's browser. No personally identifiable information (PII) leaves the user's browser during standard SpamWarden operation. The SpamWarden script does not collect names, email addresses, IP addresses (in standard mode), or any data that could identify an individual.
[TH] We collect the following categories of data across our services:
| Data Category | What We Collect | Purpose | Lawful Basis |
|---|---|---|---|
| [TH] Account Data | [TH] Work email, organisation name, contact name | [TH] Account creation, service delivery | [TH] Contract performance |
| [TH] Usage Metrics | [TH] Aggregate scan counts, feature usage frequency | [TH] Platform improvement | [TH] Legitimate interest |
| [TH] Scan Telemetry | [TH] Anonymized threat signal hashes, domain names scanned | [TH] Threat intelligence corpus | [TH] Contract performance / Consent |
| [TH] Payment Data | [TH] Processed by Stripe — RedSocs does not store card details | Billing | [TH] Contract performance |
| [TH] Communication Data | [TH] Emails, support tickets | [TH] Customer support | [TH] Contract performance |
1.2 PDPA Compliance
[TH] RedSocs operates in full compliance with the Personal Data Protection Act B.E. 2562 (PDPA), Thailand's primary data protection legislation. Our compliance measures include:
- [TH] Lawful Basis: We only process personal data where we have a clear lawful basis — contract performance, legitimate interest (with balancing test), or explicit consent.
- [TH] Data Minimisation: We collect only the minimum data required to deliver each service function.
- [TH] Data Subject Rights: You have the right to access, correct, delete, and port your personal data. Requests are fulfilled within 30 days. Contact privacy@redsocs.com.
- [TH] Cross-Border Transfers: Where data is processed outside Thailand (e.g., via Cloudflare CDN), we apply adequate safeguards consistent with PDPA Chapter 7 requirements.
- [TH] Consent Management: Where consent is required (e.g., marketing communications, optional telemetry), we obtain explicit opt-in consent and maintain a consent audit log.
- [TH] Data Breach Notification: In the event of a personal data breach, we notify affected data subjects and the PDPC within 72 hours where required under PDPA Section 37.
1.3 Data Retention
| Data Type | Retention Period | Deletion Mechanism |
|---|---|---|
| [TH] Aggregate usage metrics | [TH] 12 months from collection | [TH] Automated purge |
| [TH] Anonymized scan telemetry | [TH] 24 months (threat intelligence corpus) | [TH] Automated purge |
| [TH] Account data | [TH] Duration of contract + 90 days | [TH] Manual deletion on request |
| [TH] Payment records | [TH] 7 years (Thai accounting law requirement) | [TH] Retained by Stripe; reference IDs only in RedSocs systems |
| [TH] Support communications | [TH] 3 years from last interaction | [TH] Archived then purged |
[TH] All data is deleted upon written request to privacy@redsocs.com, subject to the legal retention obligations noted above.
1.4 Third-Party Data Processors
- [TH] Cloudflare, Inc. — Content Delivery Network, DDoS mitigation, DNS. Data processed: server logs, IP addresses (anonymized). Cloudflare processes data under a Data Processing Agreement with GDPR-equivalent safeguards applicable to cross-border contexts.
- [TH] Stripe, Inc. — Payment processing. Stripe is a PCI-DSS Level 1 certified processor. RedSocs does not store cardholder data. Stripe's privacy policy applies to all payment data.
[TH] We do not sell, rent, or share your personal data with third parties for marketing purposes.
1.5 Contact
For all privacy enquiries, data subject rights requests, or PDPA-related questions:
Email: [TH] privacy@redsocs.com
Address: [TH] Bangkok, Thailand
Response time: [TH] Within 30 days of receipt
[TH] Terms of Service
Effective: [TH] June 2026 | Jurisdiction: [TH] Kingdom of Thailand
[TH] By accessing or using RedSocs services, you agree to be bound by these Terms of Service. If you do not agree, you must not use our services. These terms constitute a legally binding agreement between you (or your organisation) and RedSocs.
2.1 Acceptable Use
[TH] You agree to use RedSocs services for lawful purposes only. Prohibited activities include, but are not limited to:
- [TH] Using RedSocs scanning tools against systems you do not own or have explicit written permission to scan.
- [TH] Reverse engineering, decompiling, or disassembling any RedSocs software, including SpamWarden, rcortex, or the BadLinks browser extension.
- [TH] Attempting to circumvent, disable, or interfere with RedSocs security mechanisms or audit logging systems.
- [TH] Using RedSocs services to facilitate any activity that constitutes a criminal offence under Thai law or international law.
- [TH] Submitting false scan requests, fraudulent government .go.th email addresses, or misrepresenting your organisation's identity.
- [TH] Reselling, sublicensing, or white-labelling RedSocs services without a written reseller agreement.
[TH] Violation of acceptable use terms may result in immediate account suspension without refund and reporting to relevant authorities.
2.2 Service Availability
[TH] RedSocs commits to the following service availability targets:
- [TH] Enterprise SOC Platform (app.redsocs.com): 99.5% monthly uptime SLA. Scheduled maintenance windows are excluded and communicated at least 72 hours in advance.
- [TH] SpamWarden CDN: 99.9% availability target. Served via Cloudflare global network. No SLA guarantee on the free tier.
- [TH] EASM Scanning Service: Best-effort delivery. Scan completion targets stated at the time of order. Delays caused by target domain rate-limiting are excluded from SLA.
- [TH] Critical Incident Response (Enterprise): Priority SLA — acknowledged within 7 business days for critical-severity findings. P1 security incidents responded to within 4 business hours.
[TH] SLA credits are available for Enterprise customers. Credits are calculated as a percentage of the affected monthly fee, proportional to downtime duration exceeding the committed threshold. Maximum credit: 30% of monthly fee.
2.3 Intellectual Property Ownership
[TH] Client-Owned Outputs[TH] All scan results, vulnerability reports, EASM data, BadLinks findings, and NCSA audit reports generated by RedSocs for your domain(s) are your property. You own all findings data. RedSocs retains no commercial rights to your specific scan outputs.
[TH] RedSocs IP[TH] The RedSocs platform, including rcortex, SpamWarden, the BadLinks bot network, the Thai spam corpus, and all proprietary algorithms, remain the exclusive intellectual property of RedSocs. No licence is granted to copy, modify, or distribute these components outside the scope of normal service use.
[TH] Feedback and Contributions[TH] If you provide feature suggestions or feedback to RedSocs, you grant us a non-exclusive, royalty-free licence to implement such feedback in our products without obligation or compensation.
2.4 Governing Law and Dispute Resolution
[TH] These Terms of Service are governed by and construed in accordance with the laws of the Kingdom of Thailand. Any disputes arising from or related to these terms shall be subject to the exclusive jurisdiction of the competent courts located in Bangkok, Thailand.
[TH] Prior to initiating formal legal proceedings, the parties agree to attempt resolution through good-faith negotiation for a period of 30 days from the date of written notice of the dispute.
2.5 Termination
- [TH] Customer Termination: You may terminate your RedSocs subscription with 30 days written notice to hello@redsocs.com. Service continues during the notice period.
- [TH] RedSocs Termination for Cause: RedSocs may terminate your account immediately for material breach of these terms, including acceptable use violations, without refund.
- [TH] Effect of Termination: Upon termination, your access to app.redsocs.com is deactivated. Your scan result data remains available for download for 30 days post-termination, after which it is permanently deleted.
[TH] Billing Agreement
Effective: [TH] June 2026 | Jurisdiction: [TH] Kingdom of Thailand
3.1 Payment Methods
[TH] RedSocs accepts the following payment methods:
[TH] Stripe — Credit / Debit Card
[TH] All major credit and debit cards accepted. Currencies: Thai Baht (THB) and US Dollar (USD). Stripe is PCI-DSS Level 1 compliant. RedSocs does not store card data.
[TH] Wire Transfer / Bank Transfer
[TH] Available for government procurement and Enterprise annual contracts. Bank details provided via encrypted email upon invoice issuance. THB and USD accepted.
For government agencies, we issue formal tax invoices (ใบกำกับภาษี) compliant with Thai Revenue Department requirements.
3.2 Refund Policy
- [TH] Enterprise — Pro-rated cancellation: Enterprise customers who cancel within 14 days of the start of a new billing cycle are entitled to a pro-rated refund for unused days. Cancellations after 14 days in a billing cycle receive no refund for that period.
- [TH] Annual contracts: Annual Enterprise subscriptions cancelled before the end of the term receive a pro-rated refund for unused full months, minus a 10% early-termination administrative fee.
- [TH] Government procurement: Refund terms for government procurement contracts are negotiated at contract formation and stated in the MOU / procurement agreement. Standard commercial refund terms do not automatically apply.
- [TH] Free tier (SpamWarden CDN): No billing applies. No refund is applicable.
- [TH] One-time scan fees: Non-refundable once the scan has commenced (scan commencement is defined as the point at which the EASM engine begins active scanning of the target domain).
[TH] To request a refund, contact hello@redsocs.com with your invoice number and account email.
3.3 Government Procurement
RedSocs services are available for procurement by Thai government agencies under the พระราชบัญญัติการจัดซื้อจัดจ้างและการบริหารพัสดุภาครัฐ B.E. 2560 (Government Procurement and Supplies Administration Act B.E. 2560).
- [TH] Procurement enquiries should be directed to pichit@redsocs.com or initiated via the official audit request flow at /request-cyber-audit.
- RedSocs can provide Tor Tor Dong (ทต.) documentation, price comparison sheets, and company registration certificates as required for government procurement processes.
- [TH] MOU (Memorandum of Understanding) drafts are available for ministry-level engagements upon request.
- For procurement under direct negotiation methods (วิธีเฉพาะเจาะจง), documentation is available within 5 business days of request.
3.4 Billing Cycle
[TH] RedSocs subscriptions are billed on the following cycles:
- [TH] Monthly billing: Charged on the same calendar date each month as the initial subscription date. Pro-rated for the first partial month.
- [TH] Annual billing: Charged upfront for 12 months. Annual subscribers receive the equivalent of 2 months free compared to monthly billing.
- [TH] Government procurement: Invoiced per the terms of the procurement contract. Typically project-based or annual.
[TH] Invoices are emailed to the account billing email address. Duplicate or corrected invoices can be requested via <a href="mailto:hello@redsocs.com">hello@redsocs.com</a>.
Legal Documentation
Privacy Policy, Terms of Service, and Billing Agreement for RedSocs services. All documents governed by the laws of the Kingdom of Thailand.
Privacy Policy
Effective: June 2026 | Jurisdiction: Kingdom of Thailand
RedSocs ("we", "our", "us") is committed to protecting your privacy in accordance with the Personal Data Protection Act B.E. 2562 (PDPA) of the Kingdom of Thailand. This Privacy Policy explains how we collect, use, and protect your data when you use RedSocs products, including SpamWarden, the RedSocs SOC Platform (app.redsocs.com), and this website.
1.1 Data Collected
SpamWarden — Client-Side Processing: SpamWarden is engineered as a fully client-side engine. All spam signal processing, Naive Bayes classification, and DOM analysis occur within the user's browser. No personally identifiable information (PII) leaves the user's browser during standard SpamWarden operation. The SpamWarden script does not collect names, email addresses, IP addresses (in standard mode), or any data that could identify an individual.
We collect the following categories of data across our services:
| Data Category | What We Collect | Purpose | Lawful Basis |
|---|---|---|---|
| Account Data | Work email, organisation name, contact name | Account creation, service delivery | Contract performance |
| Usage Metrics | Aggregate scan counts, feature usage frequency | Platform improvement | Legitimate interest |
| Scan Telemetry | Anonymized threat signal hashes, domain names scanned | Threat intelligence corpus | Contract performance / Consent |
| Payment Data | Processed by Stripe — RedSocs does not store card details | Billing | Contract performance |
| Communication Data | Emails, support tickets | Customer support | Contract performance |
1.2 PDPA Compliance
RedSocs operates in full compliance with the Personal Data Protection Act B.E. 2562 (PDPA), Thailand's primary data protection legislation. Our compliance measures include:
- Lawful Basis: We only process personal data where we have a clear lawful basis — contract performance, legitimate interest (with balancing test), or explicit consent.
- Data Minimisation: We collect only the minimum data required to deliver each service function.
- Data Subject Rights: You have the right to access, correct, delete, and port your personal data. Requests are fulfilled within 30 days. Contact privacy@redsocs.com.
- Cross-Border Transfers: Where data is processed outside Thailand (e.g., via Cloudflare CDN), we apply adequate safeguards consistent with PDPA Chapter 7 requirements.
- Consent Management: Where consent is required (e.g., marketing communications, optional telemetry), we obtain explicit opt-in consent and maintain a consent audit log.
- Data Breach Notification: In the event of a personal data breach, we notify affected data subjects and the PDPC within 72 hours where required under PDPA Section 37.
1.3 Data Retention
| Data Type | Retention Period | Deletion Mechanism |
|---|---|---|
| Aggregate usage metrics | 12 months from collection | Automated purge |
| Anonymized scan telemetry | 24 months (threat intelligence corpus) | Automated purge |
| Account data | Duration of contract + 90 days | Manual deletion on request |
| Payment records | 7 years (Thai accounting law requirement) | Retained by Stripe; reference IDs only in RedSocs systems |
| Support communications | 3 years from last interaction | Archived then purged |
All data is deleted upon written request to privacy@redsocs.com, subject to the legal retention obligations noted above.
1.4 Third-Party Data Processors
- Cloudflare, Inc. — Content Delivery Network, DDoS mitigation, DNS. Data processed: server logs, IP addresses (anonymized). Cloudflare processes data under a Data Processing Agreement with GDPR-equivalent safeguards applicable to cross-border contexts.
- Stripe, Inc. — Payment processing. Stripe is a PCI-DSS Level 1 certified processor. RedSocs does not store cardholder data. Stripe's privacy policy applies to all payment data.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
1.5 Contact
For all privacy enquiries, data subject rights requests, or PDPA-related questions:
Email: privacy@redsocs.com
Address: Bangkok, Thailand
Response time: Within 30 days of receipt
Terms of Service
Effective: June 2026 | Jurisdiction: Kingdom of Thailand
By accessing or using RedSocs services, you agree to be bound by these Terms of Service. If you do not agree, you must not use our services. These terms constitute a legally binding agreement between you (or your organisation) and RedSocs.
2.1 Acceptable Use
You agree to use RedSocs services for lawful purposes only. Prohibited activities include, but are not limited to:
- Using RedSocs scanning tools against systems you do not own or have explicit written permission to scan.
- Reverse engineering, decompiling, or disassembling any RedSocs software, including SpamWarden, rcortex, or the BadLinks browser extension.
- Attempting to circumvent, disable, or interfere with RedSocs security mechanisms or audit logging systems.
- Using RedSocs services to facilitate any activity that constitutes a criminal offence under Thai law or international law.
- Submitting false scan requests, fraudulent government .go.th email addresses, or misrepresenting your organisation's identity.
- Reselling, sublicensing, or white-labelling RedSocs services without a written reseller agreement.
Violation of acceptable use terms may result in immediate account suspension without refund and reporting to relevant authorities.
2.2 Service Availability
RedSocs commits to the following service availability targets:
- Enterprise SOC Platform (app.redsocs.com): 99.5% monthly uptime SLA. Scheduled maintenance windows are excluded and communicated at least 72 hours in advance.
- SpamWarden CDN: 99.9% availability target. Served via Cloudflare global network. No SLA guarantee on the free tier.
- EASM Scanning Service: Best-effort delivery. Scan completion targets stated at the time of order. Delays caused by target domain rate-limiting are excluded from SLA.
- Critical Incident Response (Enterprise): Priority SLA — acknowledged within 7 business days for critical-severity findings. P1 security incidents responded to within 4 business hours.
SLA credits are available for Enterprise customers. Credits are calculated as a percentage of the affected monthly fee, proportional to downtime duration exceeding the committed threshold. Maximum credit: 30% of monthly fee.
2.3 Intellectual Property Ownership
Client-Owned OutputsAll scan results, vulnerability reports, EASM data, BadLinks findings, and NCSA audit reports generated by RedSocs for your domain(s) are your property. You own all findings data. RedSocs retains no commercial rights to your specific scan outputs.
RedSocs IPThe RedSocs platform, including rcortex, SpamWarden, the BadLinks bot network, the Thai spam corpus, and all proprietary algorithms, remain the exclusive intellectual property of RedSocs. No licence is granted to copy, modify, or distribute these components outside the scope of normal service use.
Feedback and ContributionsIf you provide feature suggestions or feedback to RedSocs, you grant us a non-exclusive, royalty-free licence to implement such feedback in our products without obligation or compensation.
2.4 Governing Law and Dispute Resolution
These Terms of Service are governed by and construed in accordance with the laws of the Kingdom of Thailand. Any disputes arising from or related to these terms shall be subject to the exclusive jurisdiction of the competent courts located in Bangkok, Thailand.
Prior to initiating formal legal proceedings, the parties agree to attempt resolution through good-faith negotiation for a period of 30 days from the date of written notice of the dispute.
2.5 Termination
- Customer Termination: You may terminate your RedSocs subscription with 30 days written notice to hello@redsocs.com. Service continues during the notice period.
- RedSocs Termination for Cause: RedSocs may terminate your account immediately for material breach of these terms, including acceptable use violations, without refund.
- Effect of Termination: Upon termination, your access to app.redsocs.com is deactivated. Your scan result data remains available for download for 30 days post-termination, after which it is permanently deleted.
Billing Agreement
Effective: June 2026 | Jurisdiction: Kingdom of Thailand
3.1 Payment Methods
RedSocs accepts the following payment methods:
Stripe — Credit / Debit Card
All major credit and debit cards accepted. Currencies: Thai Baht (THB) and US Dollar (USD). Stripe is PCI-DSS Level 1 compliant. RedSocs does not store card data.
Wire Transfer / Bank Transfer
Available for government procurement and Enterprise annual contracts. Bank details provided via encrypted email upon invoice issuance. THB and USD accepted.
For government agencies, we issue formal tax invoices (ใบกำกับภาษี) compliant with Thai Revenue Department requirements.
3.2 Refund Policy
- Enterprise — Pro-rated cancellation: Enterprise customers who cancel within 14 days of the start of a new billing cycle are entitled to a pro-rated refund for unused days. Cancellations after 14 days in a billing cycle receive no refund for that period.
- Annual contracts: Annual Enterprise subscriptions cancelled before the end of the term receive a pro-rated refund for unused full months, minus a 10% early-termination administrative fee.
- Government procurement: Refund terms for government procurement contracts are negotiated at contract formation and stated in the MOU / procurement agreement. Standard commercial refund terms do not automatically apply.
- Free tier (SpamWarden CDN): No billing applies. No refund is applicable.
- One-time scan fees: Non-refundable once the scan has commenced (scan commencement is defined as the point at which the EASM engine begins active scanning of the target domain).
To request a refund, contact hello@redsocs.com with your invoice number and account email.
3.3 Government Procurement
RedSocs services are available for procurement by Thai government agencies under the พระราชบัญญัติการจัดซื้อจัดจ้างและการบริหารพัสดุภาครัฐ B.E. 2560 (Government Procurement and Supplies Administration Act B.E. 2560).
- Procurement enquiries should be directed to pichit@redsocs.com or initiated via the official audit request flow at /request-cyber-audit.
- RedSocs can provide Tor Tor Dong (ทต.) documentation, price comparison sheets, and company registration certificates as required for government procurement processes.
- MOU (Memorandum of Understanding) drafts are available for ministry-level engagements upon request.
- For procurement under direct negotiation methods (วิธีเฉพาะเจาะจง), documentation is available within 5 business days of request.
3.4 Billing Cycle
RedSocs subscriptions are billed on the following cycles:
- Monthly billing: Charged on the same calendar date each month as the initial subscription date. Pro-rated for the first partial month.
- Annual billing: Charged upfront for 12 months. Annual subscribers receive the equivalent of 2 months free compared to monthly billing.
- Government procurement: Invoiced per the terms of the procurement contract. Typically project-based or annual.
Invoices are emailed to the account billing email address. Duplicate or corrected invoices can be requested via <a href="mailto:hello@redsocs.com">hello@redsocs.com</a>.
RedSocs