Free Cyber Audit — Limited Time
Schedule a Demo
RedSocs LogoRedSocs
  • Products
    • SpamWardenDLP & Bot Protection EngineFree tier available.
    • BadLinksAutonomous SEO Hijack DiscoveryEnterprise access only.
  • Platform
    • EASM & Discovery
    • Threat Intelligence
    • Autonomous Agents
  • Pricing
  • Support
  • Request Audit Report
  • |
  • Login
Home / Legal

[TH] Legal Documentation

[TH] Privacy Policy, Terms of Service, and Billing Agreement for RedSocs services. All documents governed by the laws of the Kingdom of Thailand.

Last updated: [TH] June 2026
Table of Contents
  • 01
    [TH] Privacy Policy[TH] Data collection, PDPA compliance, retention, processors
  • 02
    [TH] Terms of Service[TH] Acceptable use, SLA, IP ownership, governing law
  • 03
    [TH] Billing Agreement[TH] Payment methods, refunds, government procurement
Jump to
  • [TH] Privacy Policy
  • [TH] Data Collected
  • [TH] PDPA Compliance
  • [TH] Data Retention
  • [TH] Third-Party Processors
  • [TH] Terms of Service
  • [TH] Acceptable Use
  • [TH] Service Availability
  • [TH] IP Ownership
  • [TH] Governing Law
  • [TH] Billing Agreement
  • [TH] Payment Methods
  • Refunds
  • [TH] Gov. Procurement
01

[TH] Privacy Policy

Effective: [TH] June 2026 | Jurisdiction: [TH] Kingdom of Thailand

[TH] RedSocs ("we", "our", "us") is committed to protecting your privacy in accordance with the Personal Data Protection Act B.E. 2562 (PDPA) of the Kingdom of Thailand. This Privacy Policy explains how we collect, use, and protect your data when you use RedSocs products, including SpamWarden, the RedSocs SOC Platform (app.redsocs.com), and this website.

1.1 Data Collected

[TH] SpamWarden — Client-Side Processing: SpamWarden is engineered as a fully client-side engine. All spam signal processing, Naive Bayes classification, and DOM analysis occur within the user's browser. No personally identifiable information (PII) leaves the user's browser during standard SpamWarden operation. The SpamWarden script does not collect names, email addresses, IP addresses (in standard mode), or any data that could identify an individual.

[TH] Key Privacy Principle: SpamWarden's standard (free) tier transmits zero personal data to RedSocs servers. Enterprise telemetry mode sends only anonymized, aggregated threat signals — never individual user data.

[TH] We collect the following categories of data across our services:

Data CategoryWhat We CollectPurposeLawful Basis
[TH] Account Data[TH] Work email, organisation name, contact name[TH] Account creation, service delivery[TH] Contract performance
[TH] Usage Metrics[TH] Aggregate scan counts, feature usage frequency[TH] Platform improvement[TH] Legitimate interest
[TH] Scan Telemetry[TH] Anonymized threat signal hashes, domain names scanned[TH] Threat intelligence corpus[TH] Contract performance / Consent
[TH] Payment Data[TH] Processed by Stripe — RedSocs does not store card detailsBilling[TH] Contract performance
[TH] Communication Data[TH] Emails, support tickets[TH] Customer support[TH] Contract performance

1.2 PDPA Compliance

[TH] RedSocs operates in full compliance with the Personal Data Protection Act B.E. 2562 (PDPA), Thailand's primary data protection legislation. Our compliance measures include:

  • [TH] Lawful Basis: We only process personal data where we have a clear lawful basis — contract performance, legitimate interest (with balancing test), or explicit consent.
  • [TH] Data Minimisation: We collect only the minimum data required to deliver each service function.
  • [TH] Data Subject Rights: You have the right to access, correct, delete, and port your personal data. Requests are fulfilled within 30 days. Contact privacy@redsocs.com.
  • [TH] Cross-Border Transfers: Where data is processed outside Thailand (e.g., via Cloudflare CDN), we apply adequate safeguards consistent with PDPA Chapter 7 requirements.
  • [TH] Consent Management: Where consent is required (e.g., marketing communications, optional telemetry), we obtain explicit opt-in consent and maintain a consent audit log.
  • [TH] Data Breach Notification: In the event of a personal data breach, we notify affected data subjects and the PDPC within 72 hours where required under PDPA Section 37.

1.3 Data Retention

Data TypeRetention PeriodDeletion Mechanism
[TH] Aggregate usage metrics[TH] 12 months from collection[TH] Automated purge
[TH] Anonymized scan telemetry[TH] 24 months (threat intelligence corpus)[TH] Automated purge
[TH] Account data[TH] Duration of contract + 90 days[TH] Manual deletion on request
[TH] Payment records[TH] 7 years (Thai accounting law requirement)[TH] Retained by Stripe; reference IDs only in RedSocs systems
[TH] Support communications[TH] 3 years from last interaction[TH] Archived then purged

[TH] All data is deleted upon written request to privacy@redsocs.com, subject to the legal retention obligations noted above.

1.4 Third-Party Data Processors

  • [TH] Cloudflare, Inc. — Content Delivery Network, DDoS mitigation, DNS. Data processed: server logs, IP addresses (anonymized). Cloudflare processes data under a Data Processing Agreement with GDPR-equivalent safeguards applicable to cross-border contexts.
  • [TH] Stripe, Inc. — Payment processing. Stripe is a PCI-DSS Level 1 certified processor. RedSocs does not store cardholder data. Stripe's privacy policy applies to all payment data.

[TH] We do not sell, rent, or share your personal data with third parties for marketing purposes.

1.5 Contact

For all privacy enquiries, data subject rights requests, or PDPA-related questions:

[TH] RedSocs Privacy Team
Email: [TH] privacy@redsocs.com
Address: [TH] Bangkok, Thailand
Response time: [TH] Within 30 days of receipt
02

[TH] Terms of Service

Effective: [TH] June 2026 | Jurisdiction: [TH] Kingdom of Thailand

[TH] By accessing or using RedSocs services, you agree to be bound by these Terms of Service. If you do not agree, you must not use our services. These terms constitute a legally binding agreement between you (or your organisation) and RedSocs.

2.1 Acceptable Use

[TH] You agree to use RedSocs services for lawful purposes only. Prohibited activities include, but are not limited to:

  • [TH] Using RedSocs scanning tools against systems you do not own or have explicit written permission to scan.
  • [TH] Reverse engineering, decompiling, or disassembling any RedSocs software, including SpamWarden, rcortex, or the BadLinks browser extension.
  • [TH] Attempting to circumvent, disable, or interfere with RedSocs security mechanisms or audit logging systems.
  • [TH] Using RedSocs services to facilitate any activity that constitutes a criminal offence under Thai law or international law.
  • [TH] Submitting false scan requests, fraudulent government .go.th email addresses, or misrepresenting your organisation's identity.
  • [TH] Reselling, sublicensing, or white-labelling RedSocs services without a written reseller agreement.

[TH] Violation of acceptable use terms may result in immediate account suspension without refund and reporting to relevant authorities.

2.2 Service Availability

[TH] 99.5%[TH] Monthly SLA — Enterprise Tier

[TH] RedSocs commits to the following service availability targets:

  • [TH] Enterprise SOC Platform (app.redsocs.com): 99.5% monthly uptime SLA. Scheduled maintenance windows are excluded and communicated at least 72 hours in advance.
  • [TH] SpamWarden CDN: 99.9% availability target. Served via Cloudflare global network. No SLA guarantee on the free tier.
  • [TH] EASM Scanning Service: Best-effort delivery. Scan completion targets stated at the time of order. Delays caused by target domain rate-limiting are excluded from SLA.
  • [TH] Critical Incident Response (Enterprise): Priority SLA — acknowledged within 7 business days for critical-severity findings. P1 security incidents responded to within 4 business hours.

[TH] SLA credits are available for Enterprise customers. Credits are calculated as a percentage of the affected monthly fee, proportional to downtime duration exceeding the committed threshold. Maximum credit: 30% of monthly fee.

2.3 Intellectual Property Ownership

[TH] Client-Owned Outputs

[TH] All scan results, vulnerability reports, EASM data, BadLinks findings, and NCSA audit reports generated by RedSocs for your domain(s) are your property. You own all findings data. RedSocs retains no commercial rights to your specific scan outputs.

[TH] RedSocs IP

[TH] The RedSocs platform, including rcortex, SpamWarden, the BadLinks bot network, the Thai spam corpus, and all proprietary algorithms, remain the exclusive intellectual property of RedSocs. No licence is granted to copy, modify, or distribute these components outside the scope of normal service use.

[TH] Feedback and Contributions

[TH] If you provide feature suggestions or feedback to RedSocs, you grant us a non-exclusive, royalty-free licence to implement such feedback in our products without obligation or compensation.

2.4 Governing Law and Dispute Resolution

[TH] These Terms of Service are governed by and construed in accordance with the laws of the Kingdom of Thailand. Any disputes arising from or related to these terms shall be subject to the exclusive jurisdiction of the competent courts located in Bangkok, Thailand.

[TH] Prior to initiating formal legal proceedings, the parties agree to attempt resolution through good-faith negotiation for a period of 30 days from the date of written notice of the dispute.

2.5 Termination

  • [TH] Customer Termination: You may terminate your RedSocs subscription with 30 days written notice to hello@redsocs.com. Service continues during the notice period.
  • [TH] RedSocs Termination for Cause: RedSocs may terminate your account immediately for material breach of these terms, including acceptable use violations, without refund.
  • [TH] Effect of Termination: Upon termination, your access to app.redsocs.com is deactivated. Your scan result data remains available for download for 30 days post-termination, after which it is permanently deleted.
03

[TH] Billing Agreement

Effective: [TH] June 2026 | Jurisdiction: [TH] Kingdom of Thailand

3.1 Payment Methods

[TH] RedSocs accepts the following payment methods:

💳

[TH] Stripe — Credit / Debit Card

[TH] All major credit and debit cards accepted. Currencies: Thai Baht (THB) and US Dollar (USD). Stripe is PCI-DSS Level 1 compliant. RedSocs does not store card data.

🏦

[TH] Wire Transfer / Bank Transfer

[TH] Available for government procurement and Enterprise annual contracts. Bank details provided via encrypted email upon invoice issuance. THB and USD accepted.

For government agencies, we issue formal tax invoices (ใบกำกับภาษี) compliant with Thai Revenue Department requirements.

3.2 Refund Policy

  • [TH] Enterprise — Pro-rated cancellation: Enterprise customers who cancel within 14 days of the start of a new billing cycle are entitled to a pro-rated refund for unused days. Cancellations after 14 days in a billing cycle receive no refund for that period.
  • [TH] Annual contracts: Annual Enterprise subscriptions cancelled before the end of the term receive a pro-rated refund for unused full months, minus a 10% early-termination administrative fee.
  • [TH] Government procurement: Refund terms for government procurement contracts are negotiated at contract formation and stated in the MOU / procurement agreement. Standard commercial refund terms do not automatically apply.
  • [TH] Free tier (SpamWarden CDN): No billing applies. No refund is applicable.
  • [TH] One-time scan fees: Non-refundable once the scan has commenced (scan commencement is defined as the point at which the EASM engine begins active scanning of the target domain).

[TH] To request a refund, contact hello@redsocs.com with your invoice number and account email.

3.3 Government Procurement

RedSocs services are available for procurement by Thai government agencies under the พระราชบัญญัติการจัดซื้อจัดจ้างและการบริหารพัสดุภาครัฐ B.E. 2560 (Government Procurement and Supplies Administration Act B.E. 2560).

  • [TH] Procurement enquiries should be directed to pichit@redsocs.com or initiated via the official audit request flow at /request-cyber-audit.
  • RedSocs can provide Tor Tor Dong (ทต.) documentation, price comparison sheets, and company registration certificates as required for government procurement processes.
  • [TH] MOU (Memorandum of Understanding) drafts are available for ministry-level engagements upon request.
  • For procurement under direct negotiation methods (วิธีเฉพาะเจาะจง), documentation is available within 5 business days of request.

3.4 Billing Cycle

[TH] RedSocs subscriptions are billed on the following cycles:

  • [TH] Monthly billing: Charged on the same calendar date each month as the initial subscription date. Pro-rated for the first partial month.
  • [TH] Annual billing: Charged upfront for 12 months. Annual subscribers receive the equivalent of 2 months free compared to monthly billing.
  • [TH] Government procurement: Invoiced per the terms of the procurement contract. Typically project-based or annual.

[TH] Invoices are emailed to the account billing email address. Duplicate or corrected invoices can be requested via <a href="mailto:hello@redsocs.com">hello@redsocs.com</a>.

Home / Legal

Legal Documentation

Privacy Policy, Terms of Service, and Billing Agreement for RedSocs services. All documents governed by the laws of the Kingdom of Thailand.

Last updated: June 2026
Table of Contents
  • 01
    Privacy PolicyData collection, PDPA compliance, retention, processors
  • 02
    Terms of ServiceAcceptable use, SLA, IP ownership, governing law
  • 03
    Billing AgreementPayment methods, refunds, government procurement
Jump to
  • Privacy Policy
  • Data Collected
  • PDPA Compliance
  • Data Retention
  • Third-Party Processors
  • Terms of Service
  • Acceptable Use
  • Service Availability
  • IP Ownership
  • Governing Law
  • Billing Agreement
  • Payment Methods
  • Refunds
  • Gov. Procurement
01

Privacy Policy

Effective: June 2026 | Jurisdiction: Kingdom of Thailand

RedSocs ("we", "our", "us") is committed to protecting your privacy in accordance with the Personal Data Protection Act B.E. 2562 (PDPA) of the Kingdom of Thailand. This Privacy Policy explains how we collect, use, and protect your data when you use RedSocs products, including SpamWarden, the RedSocs SOC Platform (app.redsocs.com), and this website.

1.1 Data Collected

SpamWarden — Client-Side Processing: SpamWarden is engineered as a fully client-side engine. All spam signal processing, Naive Bayes classification, and DOM analysis occur within the user's browser. No personally identifiable information (PII) leaves the user's browser during standard SpamWarden operation. The SpamWarden script does not collect names, email addresses, IP addresses (in standard mode), or any data that could identify an individual.

Key Privacy Principle: SpamWarden's standard (free) tier transmits zero personal data to RedSocs servers. Enterprise telemetry mode sends only anonymized, aggregated threat signals — never individual user data.

We collect the following categories of data across our services:

Data CategoryWhat We CollectPurposeLawful Basis
Account DataWork email, organisation name, contact nameAccount creation, service deliveryContract performance
Usage MetricsAggregate scan counts, feature usage frequencyPlatform improvementLegitimate interest
Scan TelemetryAnonymized threat signal hashes, domain names scannedThreat intelligence corpusContract performance / Consent
Payment DataProcessed by Stripe — RedSocs does not store card detailsBillingContract performance
Communication DataEmails, support ticketsCustomer supportContract performance

1.2 PDPA Compliance

RedSocs operates in full compliance with the Personal Data Protection Act B.E. 2562 (PDPA), Thailand's primary data protection legislation. Our compliance measures include:

  • Lawful Basis: We only process personal data where we have a clear lawful basis — contract performance, legitimate interest (with balancing test), or explicit consent.
  • Data Minimisation: We collect only the minimum data required to deliver each service function.
  • Data Subject Rights: You have the right to access, correct, delete, and port your personal data. Requests are fulfilled within 30 days. Contact privacy@redsocs.com.
  • Cross-Border Transfers: Where data is processed outside Thailand (e.g., via Cloudflare CDN), we apply adequate safeguards consistent with PDPA Chapter 7 requirements.
  • Consent Management: Where consent is required (e.g., marketing communications, optional telemetry), we obtain explicit opt-in consent and maintain a consent audit log.
  • Data Breach Notification: In the event of a personal data breach, we notify affected data subjects and the PDPC within 72 hours where required under PDPA Section 37.

1.3 Data Retention

Data TypeRetention PeriodDeletion Mechanism
Aggregate usage metrics12 months from collectionAutomated purge
Anonymized scan telemetry24 months (threat intelligence corpus)Automated purge
Account dataDuration of contract + 90 daysManual deletion on request
Payment records7 years (Thai accounting law requirement)Retained by Stripe; reference IDs only in RedSocs systems
Support communications3 years from last interactionArchived then purged

All data is deleted upon written request to privacy@redsocs.com, subject to the legal retention obligations noted above.

1.4 Third-Party Data Processors

  • Cloudflare, Inc. — Content Delivery Network, DDoS mitigation, DNS. Data processed: server logs, IP addresses (anonymized). Cloudflare processes data under a Data Processing Agreement with GDPR-equivalent safeguards applicable to cross-border contexts.
  • Stripe, Inc. — Payment processing. Stripe is a PCI-DSS Level 1 certified processor. RedSocs does not store cardholder data. Stripe's privacy policy applies to all payment data.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

1.5 Contact

For all privacy enquiries, data subject rights requests, or PDPA-related questions:

RedSocs Privacy Team
Email: privacy@redsocs.com
Address: Bangkok, Thailand
Response time: Within 30 days of receipt
02

Terms of Service

Effective: June 2026 | Jurisdiction: Kingdom of Thailand

By accessing or using RedSocs services, you agree to be bound by these Terms of Service. If you do not agree, you must not use our services. These terms constitute a legally binding agreement between you (or your organisation) and RedSocs.

2.1 Acceptable Use

You agree to use RedSocs services for lawful purposes only. Prohibited activities include, but are not limited to:

  • Using RedSocs scanning tools against systems you do not own or have explicit written permission to scan.
  • Reverse engineering, decompiling, or disassembling any RedSocs software, including SpamWarden, rcortex, or the BadLinks browser extension.
  • Attempting to circumvent, disable, or interfere with RedSocs security mechanisms or audit logging systems.
  • Using RedSocs services to facilitate any activity that constitutes a criminal offence under Thai law or international law.
  • Submitting false scan requests, fraudulent government .go.th email addresses, or misrepresenting your organisation's identity.
  • Reselling, sublicensing, or white-labelling RedSocs services without a written reseller agreement.

Violation of acceptable use terms may result in immediate account suspension without refund and reporting to relevant authorities.

2.2 Service Availability

99.5%Monthly SLA — Enterprise Tier

RedSocs commits to the following service availability targets:

  • Enterprise SOC Platform (app.redsocs.com): 99.5% monthly uptime SLA. Scheduled maintenance windows are excluded and communicated at least 72 hours in advance.
  • SpamWarden CDN: 99.9% availability target. Served via Cloudflare global network. No SLA guarantee on the free tier.
  • EASM Scanning Service: Best-effort delivery. Scan completion targets stated at the time of order. Delays caused by target domain rate-limiting are excluded from SLA.
  • Critical Incident Response (Enterprise): Priority SLA — acknowledged within 7 business days for critical-severity findings. P1 security incidents responded to within 4 business hours.

SLA credits are available for Enterprise customers. Credits are calculated as a percentage of the affected monthly fee, proportional to downtime duration exceeding the committed threshold. Maximum credit: 30% of monthly fee.

2.3 Intellectual Property Ownership

Client-Owned Outputs

All scan results, vulnerability reports, EASM data, BadLinks findings, and NCSA audit reports generated by RedSocs for your domain(s) are your property. You own all findings data. RedSocs retains no commercial rights to your specific scan outputs.

RedSocs IP

The RedSocs platform, including rcortex, SpamWarden, the BadLinks bot network, the Thai spam corpus, and all proprietary algorithms, remain the exclusive intellectual property of RedSocs. No licence is granted to copy, modify, or distribute these components outside the scope of normal service use.

Feedback and Contributions

If you provide feature suggestions or feedback to RedSocs, you grant us a non-exclusive, royalty-free licence to implement such feedback in our products without obligation or compensation.

2.4 Governing Law and Dispute Resolution

These Terms of Service are governed by and construed in accordance with the laws of the Kingdom of Thailand. Any disputes arising from or related to these terms shall be subject to the exclusive jurisdiction of the competent courts located in Bangkok, Thailand.

Prior to initiating formal legal proceedings, the parties agree to attempt resolution through good-faith negotiation for a period of 30 days from the date of written notice of the dispute.

2.5 Termination

  • Customer Termination: You may terminate your RedSocs subscription with 30 days written notice to hello@redsocs.com. Service continues during the notice period.
  • RedSocs Termination for Cause: RedSocs may terminate your account immediately for material breach of these terms, including acceptable use violations, without refund.
  • Effect of Termination: Upon termination, your access to app.redsocs.com is deactivated. Your scan result data remains available for download for 30 days post-termination, after which it is permanently deleted.
03

Billing Agreement

Effective: June 2026 | Jurisdiction: Kingdom of Thailand

3.1 Payment Methods

RedSocs accepts the following payment methods:

💳

Stripe — Credit / Debit Card

All major credit and debit cards accepted. Currencies: Thai Baht (THB) and US Dollar (USD). Stripe is PCI-DSS Level 1 compliant. RedSocs does not store card data.

🏦

Wire Transfer / Bank Transfer

Available for government procurement and Enterprise annual contracts. Bank details provided via encrypted email upon invoice issuance. THB and USD accepted.

For government agencies, we issue formal tax invoices (ใบกำกับภาษี) compliant with Thai Revenue Department requirements.

3.2 Refund Policy

  • Enterprise — Pro-rated cancellation: Enterprise customers who cancel within 14 days of the start of a new billing cycle are entitled to a pro-rated refund for unused days. Cancellations after 14 days in a billing cycle receive no refund for that period.
  • Annual contracts: Annual Enterprise subscriptions cancelled before the end of the term receive a pro-rated refund for unused full months, minus a 10% early-termination administrative fee.
  • Government procurement: Refund terms for government procurement contracts are negotiated at contract formation and stated in the MOU / procurement agreement. Standard commercial refund terms do not automatically apply.
  • Free tier (SpamWarden CDN): No billing applies. No refund is applicable.
  • One-time scan fees: Non-refundable once the scan has commenced (scan commencement is defined as the point at which the EASM engine begins active scanning of the target domain).

To request a refund, contact hello@redsocs.com with your invoice number and account email.

3.3 Government Procurement

RedSocs services are available for procurement by Thai government agencies under the พระราชบัญญัติการจัดซื้อจัดจ้างและการบริหารพัสดุภาครัฐ B.E. 2560 (Government Procurement and Supplies Administration Act B.E. 2560).

  • Procurement enquiries should be directed to pichit@redsocs.com or initiated via the official audit request flow at /request-cyber-audit.
  • RedSocs can provide Tor Tor Dong (ทต.) documentation, price comparison sheets, and company registration certificates as required for government procurement processes.
  • MOU (Memorandum of Understanding) drafts are available for ministry-level engagements upon request.
  • For procurement under direct negotiation methods (วิธีเฉพาะเจาะจง), documentation is available within 5 business days of request.

3.4 Billing Cycle

RedSocs subscriptions are billed on the following cycles:

  • Monthly billing: Charged on the same calendar date each month as the initial subscription date. Pro-rated for the first partial month.
  • Annual billing: Charged upfront for 12 months. Annual subscribers receive the equivalent of 2 months free compared to monthly billing.
  • Government procurement: Invoiced per the terms of the procurement contract. Typically project-based or annual.

Invoices are emailed to the account billing email address. Duplicate or corrected invoices can be requested via <a href="mailto:hello@redsocs.com">hello@redsocs.com</a>.

  • PRODUCTS & SOLUTIONS
  • SpamWarden.js
  • BadLinks Engine
  • External Attack Surface Mgmt
  • Threat Intelligence Feeds
  • Autonomous AI Swarm Agents
  • SERVICES & FRAMEWORKS
  • On-Demand Perimeter Auditing
  • NCSA Web Standard 1.0 Hub
  • OFFICE
  • Contact
  • Inquiries: hello[at]redsocs.com
© 2026 RedSocs Security Platform. All rights reserved. Powered by rcortex Elixir Engine.
  • Privacy Policy
  • Terms of Service
  • Billing Agreement
  • Report Abuse Link