Privacy Notice

This Privacy Notice describes how zenexsm collects, uses, discloses and retains personal information in the course of providing legal and advisory services. Controller: zenexsm. Office address: Khlong Phon Sub District, Amphoe Khlong Thom District, Krabi Province 81170, Thailand. Business ID: 3983179697691. Contact: +66936521902. We collect contact details, engagement-related documents and limited technical data necessary to deliver services. Processing is limited to the purposes described in this notice, retention schedules are defined by service needs and applicable law, and access is restricted to personnel with a legitimate need. Individuals may request access, correction or deletion of their data where permitted by law. For inquiries, use the contact details above.

27-05-2026

zenexsm

Khlong Phon Sub District, Amphoe Khlong Thom District, Krabi Province 81170, Thailand

[email protected]

Definitions

This section defines key terms used throughout this privacy notice to ensure clarity about how zenexsm collects, processes and safeguards personal data in the context of legal services for the IT sector.

Personal data means any information relating to an identified or identifiable natural person, including names, contact details, identity numbers, professional credentials, IP addresses, and other identifiers that may arise in legal intake, contract negotiation or regulatory compliance matters handled by zenexsm.
Processing refers to any operation performed on personal data, whether automated or manual, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, or deletion carried out by or on behalf of zenexsm in connection with the provision of legal services.
User refers to an individual or representative of an organization who interacts with zenexsm, submits personal or company data for legal advice, uses online forms, requests consultations, or otherwise communicates with our team in the course of IT-related legal engagements.
Service means the legal advisory, contract drafting and review, compliance assessment, dispute support, intellectual property counsel, and related professional services provided by zenexsm to clients in the information technology sector.
Cookies are small pieces of data stored on a user's device by a website to enhance functionality, remember preferences, enable analytics, and support secure sessions when interacting with zenexsm platforms.
Data We Collect

zenexsm collects and processes a range of data types strictly necessary for the delivery of legal services to IT clients, for compliance with legal obligations, and to maintain secure communications. We limit collection to information relevant to the engagement and to fulfilling legitimate professional responsibilities.

Data You Provide Directly

When you instruct zenexsm or contact us for services, we will collect information you supply to enable intake, legal analysis and case management. Examples include:

  • Contact information: name, corporate role, email address, postal address, and telephone number necessary for client communication and documentation.
  • Identity and company verification: business registration numbers, tax identifiers, Business ID 3983179697691, copies of identification documents when required for compliance checks.
  • Contractual and transactional details: contracts, project specifications, invoices, payment information and related commercial documentation needed to provide legal advice and perform billing.
  • Case materials: technical reports, IP registrations, source code descriptions, customer lists, incident reports and other documents required to assess and advise on legal matters.
  • Communications: emails, meeting notes, and messages you send to zenexsm as part of case discussions and engagement management.
  • Consents and preferences: opt-ins, marketing preferences and any permissions you communicate related to data usage in the course of our professional relationship.

Data Collected Automatically

When you visit zenexsm websites or use our online tools, we may collect limited technical information automatically to maintain secure and reliable services and to improve user experience while keeping processing strictly necessary.

  • Connection data: IP address, browser type and version, device type and operating system to support secure sessions and troubleshoot connectivity issues.
  • Usage data: pages visited, time spent on pages and navigation paths to understand how visitors use our legal content and to optimize accessibility for professional users.
  • Cookies and similar technologies: identifiers used to maintain sessions, remember language preferences and to facilitate analytics where you have consented to tracking.
  • Security logs: authentication events, access logs and error reports maintained to detect and respond to potential security incidents affecting client information.
  • Device identifiers: device-specific settings and timestamps that assist with fraud prevention and to ensure proper configuration of secure client portals.
  • Performance metrics: anonymized statistics on system uptime and response times used to maintain the availability and performance of client services.

Third-Party Sources

In certain circumstances zenexsm obtains data from trusted third parties to verify information, fulfill legal duties or to support client matters. We only engage third parties that meet our confidentiality and security standards.

  • Professional counterparties and opposing counsel: documents and contact details platform as required by casework or transactional negotiations.
  • Regulatory and public registries: business registration databases and public filings used to validate corporate information and compliance histories.
  • Service providers: secure cloud hosters, payment processors and background check providers engaged under contract to support zenexsm operations.

Purposes of Processing

zenexsm processes personal data for well-defined professional and operational reasons aligned with providing legal services to IT sector clients, meeting regulatory obligations and maintaining a secure service environment.

  • To provide legal advice, draft and review agreements, prepare regulatory filings and support dispute resolution matters for IT businesses.
  • To verify client identity and conduct required client due diligence, including anti-funds laundering and Know Your Client checks when applicable.
  • To perform contract management, billing, and collections necessary for the administration of legal engagements.
  • To communicate securely with clients and third parties about case progress, strategy, deadlines and required actions.
  • To maintain and improve zenexsm digital services, including secure client portals and documentation repositories.
  • To detect, prevent and respond to security incidents, fraud or misuse of our platforms and to maintain system integrity.
  • To meet legal and regulatory obligations, including responding to lawful requests from competent authorities.
  • To manage records retention and ensure appropriate archival or secure deletion of client data in accordance with professional standards.

Legal Bases for Processing

We rely on legitimate and recognized legal bases to process personal data. The applicable legal basis depends on the specific processing activity and relevant law.

  • Performance of a contract: processing necessary to provide legal services and fulfill contractual obligations with clients.
  • Compliance with a legal obligation: processing required to satisfy regulatory, tax or professional reporting duties.
  • Legitimate interests: processing necessary for the administration of our practice, fraud prevention, direct communications about client matters, and improvement of services, balanced against individual rights.
  • Consent: where required by law or where we seek permission for optional processing such as marketing communications or non-essential analytics.

European Data Protection (GDPR) Considerations

Although zenexsm operates from Thailand, we recognize the importance of GDPR principles when handling data of EU/EEA residents. We apply data protection practices consistent with international standards and offer assistance to clients seeking GDPR-aligned processing.

  • Rights facilitation: we will respond to requests from EU/EEA residents regarding access, rectification, erasure and other data subject rights within applicable timeframes.
  • Lawful transfer mechanisms: where data is transferred from the EU/EEA we implement appropriate safeguards such as standard contractual clauses or other permitted measures.
  • Data minimization: we limit collection to what is necessary for the specified purposes and retain data for no longer than required for professional and legal obligations.
  • Accountability and documentation: zenexsm maintains records of processing activities and can provide relevant information to demonstrate compliance with applicable data protection requirements.
  • Security measures: appropriate organizational and technical measures are in place to protect data handled on behalf of EU/EEA data subjects.
  • Point of contact: EU/EEA residents may contact our privacy representative using the details provided in this policy to exercise rights or raise concerns.

Cookies and Tracking

Cookies on zenexsm websites are used to provide essential functionality, to remember preferences, and, where consent is given, to collect analytics. We avoid unnecessary profiling and provide controls for cookie consent.

We use session cookies for secure logins, persistent cookies to remember settings, and optional analytics cookies that collect aggregated usage data when you consent to such tracking.

Cookie categories include strictly necessary cookies, performance and analytics cookies (consent-based), and functional cookies to maintain user preferences and language settings.

You can manage cookie preferences through the cookie banner displayed on our site and via your browser settings. Disabling non-essential cookies may limit some site features required for client portals.

Full Cookie Policy

Sharing and Disclosure

zenexsm shares personal data only with parties necessary to deliver legal services or as required by law. Any sharing is governed by confidentiality commitments and data protection safeguards.

  • External advisors and expert witnesses: engaged on a need-to-know basis to provide technical or sector-specific expertise in legal matters.
  • Service providers: cloud hosting, document management, secure communications and payment processors who operate under contract and confidentiality obligations.
  • Regulators and courts: where disclosure is required by judicial order, regulatory request or to comply with applicable law.
  • Counterparties and opposing counsel: information platform as part of transactional negotiations or litigation, limited to relevant case materials.
  • Acquirers or business partners: in the event of a merger, acquisition or sale of assets where personal data is part of transferred assets and subject to confidentiality and contractual protections.
  • Aggregated and anonymized data: statistical information that does not identify individuals and may be used for service improvement and internal reporting.

International Data Transfers

zenexsm may transfer personal data internationally for operational reasons, including to service providers located outside Thailand or the EU/EEA. Transfers are conducted only under appropriate safeguards to maintain protection levels.

When transferring data across borders we apply contractual safeguards, assess third-party security practices, and where necessary use recognized transfer mechanisms such as standard contractual clauses or other lawfully available measures.

Data Retention

We retain personal data only as long as necessary for the purposes described, for professional obligations, and to meet legal retention periods applicable to legal records and client files.

Client account records, engagement letters and files are retained for periods consistent with professional practice rules and applicable Thai regulations, typically for a minimum period necessary to address potential claims and compliance requirements.

Communications such as email correspondence and consultation notes are retained for case management and may be archived according to recordkeeping policies that reflect legal and professional standards.

Technical logs and security records are maintained for a limited time to support incident response and system integrity; retention periods are set to balance forensic needs and privacy considerations.

Data no longer required for casework, regulatory or contractual reasons will be securely deleted or anonymized in a manner consistent with professional confidentiality obligations and applicable law.

Security of Your Data

Protecting client information is a core professional obligation for zenexsm. We combine administrative, technical and physical measures proportionate to the sensitivity of the data processed, regularly reviewing controls to address emerging risks.

  • Access controls: role-based access and multi-factor authentication for systems containing client information.
  • Encryption: encryption of data in transit and at rest for client portals and sensitive documents.
  • Operational safeguards: regular security assessments, staff training on confidentiality, and contractual security obligations for third-party providers.

Your Rights

Subject to applicable law and professional duties, individuals have rights regarding their personal data. zenexsm facilitates reasonable requests in line with legal constraints and the need to preserve client confidentiality.

  • Right of access: request confirmation of whether we process your data and receive a copy of relevant information.
  • Right to rectification: request correction of inaccurate or incomplete personal data.
  • Right to erasure: request deletion of data where processing is no longer necessary and deletion is not inconsistent with legal or ethical obligations.
  • Right to restriction: request limitation of processing in certain circumstances while disputes are resolved.
  • Right to data portability: where applicable, request portability of data in a structured, commonly used and machine-readable format.
  • Right to object: object to processing based on legitimate interests or for direct marketing when applicable.
  • Right to withdraw consent: withdraw any consent given for processing where consent is the legal basis without affecting prior lawful processing.
  • Right to lodge a complaint: contact a relevant supervisory authority if you consider your rights under data protection laws have been infringed.

How to Exercise Your Rights

To exercise any data subject right, contact zenexsm using the contact details below. We will verify your identity and respond to legitimate requests in accordance with applicable legal timeframes and professional duties.

[email protected]

We aim to respond to verified requests without undue delay and within statutory deadlines where applicable. Complex requests may require additional time; we will communicate timelines and any lawful reasons for extension.

Marketing Communications

We may communicate about services relevant to IT sector legal needs only where we have a legitimate interest or consent. Marketing is targeted to professional audiences and limited to information about services, events or publications from zenexsm.

Recipients may opt out of marketing communications at any time using the unsubscribe link in messages or by contacting our privacy team. Opt-outs are processed promptly and without affecting service-related communications.

Children's Privacy

zenexsm does not provide services or knowingly collect personal data from children under 16. If we become aware that we have collected such data without appropriate consent, we will take steps to delete it unless retention is required by law.

Third-Party Links

Our website may contain links to third-party sites. zenexsm is not responsible for the privacy practices of external sites. We recommend reviewing the privacy policies of any site you visit from links on our pages.

Changes to this Policy

This privacy notice may be updated to reflect changes in legal requirements, professional standards or our services. The effective date of the current policy is 03-05-2026. Significant changes will be communicated through our website and, where appropriate, directly to clients.

Contact and Data Protection Officer

For privacy enquiries, data subject requests or to discuss data processing related to legal services, contact zenexsm at: Khlong Phon Sub District, Amphoe Khlong Thom District, Krabi Province 81170, Thailand. Phone: +66936521902. Business ID: 3983179697691. Email: [email protected].

  • +66936521902
  • [email protected]
  • Khlong Phon Sub District, Amphoe Khlong Thom District, Krabi Province 81170, Thailand