Privacy Policy

At coachixza we process personal data to deliver software development and related professional services. This privacy policy explains the categories of data we handle, the purposes of processing, legal bases, data sharing practices, retention periods, and the rights available to data subjects. We adopt industry-standard technical and organisational measures to protect personal data and maintain accountability in our processing activities. This document applies to services provided by coachixza operating from Thailand and to interactions through our website and client engagements.

01-07-2026 coachixza, Business ID 3584247567152, 212/1, Soi Prapokklao, Si Phum Sub District, Amphoe Mueang Chiang Mai District, Chiang Mai Province 50200, Thailand; contact +66968279405 212/1, Soi Prapokklao, Si Phum Sub District, Amphoe Mueang Chiang Mai District, Chiang Mai Province 50200, Thailand [email protected]

Definitions

To ensure clarity, we define terms used throughout this policy related to personal data and processing activities.

Personal data refers to any information that identifies or can reasonably identify an individual, such as name, contact details, job title, or business identifiers when tied to a natural person.
Processing means any operation performed on personal data, including collection, recording, organization, structuring, storage, retrieval, use, disclosure, transmission, erasure or destruction.
User refers to any natural person who interacts with coachixza services or website, including prospective clients, business contacts, employees of client organizations and end users of delivered software.
Service denotes the software development, consultancy and support offerings provided by coachixza, including web applications, APIs, integrations, and managed services.
Cookies are small text files stored on devices to support website functionality, analytics and preference management. We use cookies to operate the website securely and to understand usage patterns for service improvement.

Data Collection

We collect personal data from several sources to provide and improve our services, to manage client relationships and to comply with legal obligations. Collection is limited to information relevant to these purposes and handled with care.

Data You Provide

Information provided directly by clients, prospects or users when contacting us, registering for services, or using delivered applications. Examples include:

  • Contact details: name, business email, telephone number, job title and company name.
  • Project information: technical requirements, specifications, architecture diagrams and configuration details shared for development.
  • Account credentials and access identifiers required to integrate third-party services when authorised by the client.
  • Transactional data such as invoices, billing contact and payment processing details when engaged in commercial activity.
  • Communications and support tickets platform during project delivery, including feedback and documentation.
  • Any other information you explicitly submit to us to support the provision of services.

Automatically Collected Data

Certain data is collected automatically when interacting with our website or services to ensure operation, security and to improve the user experience.

  • Device and browser information (user agent, screen resolution, language settings).
  • IP address and approximate geolocation derived from the IP for security and troubleshooting.
  • Usage data such as pages visited, session duration, referrer and interaction events for analytics.
  • Logs generated by our servers and applications for debugging and performance monitoring.
  • Error reports and crash data from services where enabled.
  • Cookie identifiers used to manage preferences and basic functionality.

Third-party Data Sources

We may receive data from third parties when necessary to perform contractual obligations or at the client's direction. These sources are selected for reliability and compliance.

  • Payment processors providing transaction confirmation and billing details.
  • Cloud infrastructure providers and hosted service vendors supplying operational logs and usage metrics.
  • Identity and access providers when clients choose single sign-on or federated identity integrations.

Purposes of Processing

We process personal data for distinct, listed purposes necessary for service delivery, legal compliance and service improvement. Each purpose is limited to the data strictly required.

  • To deliver contracted software development, integrations and support services.
  • To manage client relationships, billing, and project governance.
  • To ensure security, fraud prevention and incident response for our services.
  • To operate, maintain and troubleshoot infrastructure that hosts or connects to delivered applications.
  • To perform analytics and product improvement using aggregated or anonymized data.
  • To fulfill legal obligations, regulatory reporting or to respond to lawful requests from public authorities.
  • To communicate updates, service notifications and changes relevant to clients and service users.
  • To support training, support ticket resolution and documentation associated with project delivery.

Legal Basis for Processing

Processing is supported by one or more lawful bases depending on the context. We select the appropriate legal basis in line with applicable law and contractual requirements.

  • Performance of a contract: processing necessary to provide the requested software services and fulfil contractual obligations.
  • Legitimate interests: processing for security, fraud prevention, infrastructure maintenance and direct business communications where interests are balanced against individual rights.
  • Legal obligation: processing required to meet statutory or regulatory duties.
  • Consent: where specific optional processing (such as marketing communications beyond contractual scope) is based on freely given consent, which can be withdrawn.

Data Subject Rights (GDPR-aligned)

Where GDPR or similar provisions apply, data subjects have rights concerning their personal data. We provide procedures to exercise these rights and respond within applicable timeframes, considering legal and contractual constraints.

  • Right of access: request confirmation of processing and a copy of personal data.
  • Right to rectification: request correction of inaccurate or incomplete data.
  • Right to erasure: request deletion where retention is no longer necessary and no overriding legal basis exists.
  • Right to restrict processing: request limitation of processing in specific situations.
  • Right to data portability: receive personal data in a structured, commonly used, machine-readable format when technically feasible.
  • Right to object: object to processing based on legitimate interests or direct marketing, subject to lawful grounds for continuing processing.

Cookies and Tracking

Our website uses cookies to provide core functionality, remember preferences and collect anonymized analytics. Cookies do not store sensitive personal data unless voluntarily provided during interactions.

We use session cookies for site operation, persistent cookies for preferences, and third-party cookies for anonymized analytics services. Where required by law or best practice, we request consent for non-essential cookies.

Categories include essential (required for operation), performance (analytics), and preferences (language or display settings). Third-party cookies are described in the cookie policy linked below.

Users can manage cookie preferences via their browser settings or the cookie management tools available on our website. Disabling certain cookies may reduce website functionality or affect analytics accuracy.

Full Cookie Policy and Management

Data Sharing

We only share personal data with third parties when necessary to provide services, comply with legal obligations, or with explicit client instruction. Any sharing is governed by contracts and data protection measures.

  • Service providers engaged to host infrastructure, perform backups, or provide analytics on our behalf under data processing agreements.
  • Payment processors and business institutions for billing and transactional purposes.
  • Subcontractors and technical partners when required for specific project tasks and bound by confidentiality and security requirements.
  • Legal or regulatory authorities when required to comply with lawful requests or to protect legal rights.
  • Acquirers or advisors in the event of a corporate transaction, subject to appropriate safeguards and due diligence.
  • Aggregated or anonymized data that cannot reasonably be used to identify any individual may be shared for research or service improvement.

International Transfers

We operate internationally and may transfer personal data to jurisdictions outside the country of collection for operational purposes. Transfers are conducted with appropriate safeguards such as contractual clauses, data processing agreements and where required, legal transfer mechanisms.

Safeguards applied may include standard contractual clauses, vendor assessments, encryption, access controls, and written commitments from service providers to adhere to adequate protection standards.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes set out in this policy, to meet contractual obligations, or to comply with legal retention requirements. Retention periods are determined based on the type of data and the purpose of processing.

Account and contractual records are retained for the duration of the engagement and for a reasonable period thereafter to support warranty, billing inquiries and compliance obligations, typically up to seven years depending on local recordkeeping laws.

Communications, support tickets and project correspondence are retained for the time necessary to support service continuity and to allow for dispute resolution, generally for a minimum of one year after project closure unless otherwise required.

System logs and security-related records are retained for operational troubleshooting and security analysis. Retention duration is balanced between contribute needs and data minimization principles and typically ranges from 90 days to two years based on the type of log and regulatory considerations.

We retain personal data only for the period necessary to fulfill the purposes described in this policy, to comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary by data type: contact and contractual records are kept for up to 7 years for accounting and regulatory compliance, project files are retained for the duration of active engagement plus up to 5 years for reference and support, and anonymized analytics data may be retained longer for product and security improvements. When data is no longer required, coachixza implements secure deletion or irreversible anonymization procedures consistent with industry practice.

Data security and handling

coachixza treats security as an operational priority. We apply a layered approach to protect personal data throughout its lifecycle: controlled access, encryption in transit and at rest where applicable, routine vulnerability assessments, and incident response planning. Our security measures are designed to reduce the risk of unauthorized access, disclosure, alteration, or destruction of personal data while allowing lawful processing necessary for providing software development and business services.

  • Access control and least-privilege principle for employee and contractor accounts; multi-factor authentication for administrative access.
  • Encryption of data in transit using TLS and selective encryption of sensitive data at rest; secure key management practices.
  • Regular patching, vulnerability scanning, code reviews, and periodic backups stored with access restrictions and integrity checks.

Your privacy rights

Depending on applicable law, individuals have certain rights in respect of their personal data processed by coachixza. We respond to requests to exercise these rights in a timely manner and with documentation. To submit a request, see the contact section below.

  • Right of access — you can request confirmation of whether we process your data and request a copy of personal data we hold.
  • Right to rectification — you may request correction of inaccurate or incomplete personal data.
  • Right to erasure — where lawful grounds permit, you may request deletion of personal data we no longer need for the purposes collected.
  • Right to restriction of processing — you can request restriction of processing in certain circumstances, for example while a dispute about accuracy is resolved.
  • Right to data portability — where applicable, you may request a machine-readable copy of your personal data for transfer to another service provider.
  • Right to object — you may object to certain processing activities, such as direct marketing, and coachixza will stop processing unless we demonstrate compelling legitimate grounds.
  • Right to withdraw consent — where processing is based on consent, you may withdraw consent at any time without affecting processing performed prior to withdrawal.
  • Right to lodge a complaint with a supervisory authority if you consider our processing violates applicable data protection laws.

How to make a rights request

To submit a request to access, correct, delete, or otherwise exercise your data protection rights, please contact coachixza using the contact details below. Provide your name, contact details, the nature of the request, and any information that helps us verify your identity. We may request additional information to confirm your identity and the scope of the request.

[email protected]

We aim to respond to verifiable requests within 30 calendar days. Where requests are complex or numerous, we will inform you of any extension and the reasons for the delay. If we refuse a request, we will provide a reasoned explanation and information about available remedies.

Direct marketing and communications

We may use contact details to send transactional and service-related communications about your projects, account status, invoices, and important product updates. With your consent, we may also send promotional messages about coachixza services, new offerings, and events. All marketing communications include a clear means to opt out.

You may unsubscribe from marketing emails at any time by following the unsubscribe link in the message or by contacting [email protected]. Unsubscribing will not prevent service-related communications necessary for the performance of contracts and project delivery.

Data concerning minors

coachixza’s services are intended for businesses and professionals. We do not intentionally collect personal data from children under the age of 13. If we become aware that we have collected personal data of a child without appropriate parental consent, we will take steps to delete the information as soon as practicable.

Links to third-party websites

Our website and communications may contain links to third-party websites, services, or platforms. coachixza is not responsible for the privacy practices or content of those third parties. We recommend reviewing the privacy policies of any third-party site you visit before providing personal data.

Policy changes

We may update this privacy policy to reflect changes in our practices, legal requirements, or service offerings. When material changes occur, we will publish a revised policy at coachixza.digital and indicate the effective date. Continued use of our services after changes are published constitutes acceptance of the updated policy.

Contact and data controller information

Data controller: coachixza (Business ID 3584247567152). Registered contact: coachixza, 212/1, Soi Prapokklao, Si Phum Sub District, Amphoe Mueang Chiang Mai District, Chiang Mai Province 50200, Thailand. For privacy inquiries and rights requests, email [email protected] or call +66968279405 during business hours. For postal correspondence use the registered address above.

  • +66968279405
  • [email protected]
  • 212/1, Soi Prapokklao, Si Phum Sub District, Amphoe Mueang Chiang Mai District, Chiang Mai Province 50200, Thailand