wisesight logo
messenger icon

Legal & Privacy

Privacy Notice for Our Services

Privacy Notice for Our Services

1. Introduction

This Privacy Notice is issued by Wisesight (Thailand) Co., Ltd. (hereinafter referred to as the "Company" or "Wisesight") to describe the collection, use, and disclosure of personal data arising from the conduct of its business in social media data analytics, the provision of software services (Software-as-a-Service: SaaS), the provision of customer data and communications management services, and the development and provision of artificial intelligence (AI) services and data-driven research.

This is to ensure that data subjects receive the information required under the Personal Data Protection Act B.E. 2562 (2019) (the "PDPA").

This Notice covers the processing of personal data arising through the following products and services:

  • Zocial Eye — social listening analytics software.
  • Warroom — customer relationship management and ticket management software.
  • Omnichannel Solution — a service integrating customers' communication channels.
  • Monitoring & Alert — a service monitoring and alerting on mentions according to conditions defined by the client.
  • Response Service — a service responding to messages on social media.
  • Command Center — a centralised social media situation-monitoring system for clients.
  • Influencer Directory — a database of social media influencers.
  • Brand Scan — a service measuring and ranking the performance of social media accounts/content.
  • Trend — a platform for monitoring public social media data.
  • Virtual Persona — an AI-powered synthetic research service.
  • Wisesight AI — the Company's suite of artificial intelligence products.
  • Research — research and analytical reporting services tailored to client requirements.
  • Other Services — other services that the Company may provide in the future.

2. Relevant Data Subjects

  • Authors of Public Content — means persons who publish information, opinions, posts, images, videos, or any other information publicly on social media platforms, web boards, blogs, news websites, or other public sources, which the Company collects and processes for the purposes of providing social listening and social media analytics services. The collection of data of this group of persons arises from the Company's provision of monitoring and analysis of social media content according to keywords defined by the client, whereby the Company does not have the purpose of identifying or collecting the data of any particular individual on an individualised basis and does not create individual profiles for marketing or surveillance purposes.
  • Influencers / Creators — means persons included in the Company's Influencer Directory database, whom the Company profiles using data publicly disclosed on social media, relying on the Company's lawful basis of legitimate interest in establishing the database for the purposes of analysis and the provision of marketing data services. The Company has determined that such processing is necessary and reasonable and does not unduly affect the rights and freedoms of the data subject, particularly where such data has been made public by the data subject him- or herself.
  • End-users of Customer Organisations — means consumers or customers of the Company's corporate clients whose data the corporate client submits for processing within the various services (Warroom, Omnichannel, Monitoring & Alert, Command Center), or within Zocial Eye where the client specifies search terms directed at a specific individual. For this category of data, the corporate client is the Data Controller and determines the purposes and means of processing the personal data, whereby the Company has no decision-making authority in relation to such processing and acts solely on the instructions of the corporate client.
  • SaaS Platform Users — means persons to whom the Company's corporate clients grant access rights to the Company's SaaS products (such as employees, executives, or contractors of the client organisation) by means of login, in order to use the features and functions of the products. The Company acts as the Data Controller for account data, access data, platform telemetry data, and technical data generated by this group of users through their use.
  • Third Parties Appearing in Content — means persons who are mentioned in, or appear in, content that the Company processes, even where such persons are not the direct authors of the content (for example, persons tagged in posts, persons appearing in images, or persons mentioned in news items). The processing of the data of this group of persons results from the nature of public data or content created by other persons, whose appearance the Company is unable to control or restrict. The Company will process such data only to the extent necessary and consistent with the purposes of the service.

The Company may act as a Data Controller or a Data Processor, depending on the nature of the product or service, as follows:

  • Data Controller — where the Company itself decides the purposes and means of processing personal data and operates its own products, including the processing of the data of SaaS Platform Users.
  • Data Processor — where the Company processes personal data on the instructions of a client who is the Data Controller, such as the handling of customer requests within the Warroom software on the instructions of the corporate client.

Where the Company acts as a Data Processor on the instructions of a client, the personal data processed is subject to the privacy notice and lawful bases of the client in its capacity as Data Controller. If a data subject wishes to exercise rights in respect of such data, please contact the corporate client that is the Data Controller directly, or contact the Company through the designated channels so that the Company may forward the request to the client controller.

4. Collection of Personal Data

  • Public sources — For products in respect of which the Company is the Data Controller, the Company collects personal data from public sources, being collection from sources other than directly from the data subject. Such data includes but is not limited to: (a) posts, comments, and interactions on public social media platforms such as Facebook (public content), X (formerly Twitter), Instagram (public accounts), TikTok, YouTube; (b) threads and comments on public web boards such as Pantip; (c) articles and content on news websites and public websites; (d) data via the public APIs of the above platforms in accordance with the terms and conditions of each platform.
  • Data from clients — personal data submitted to the Company by corporate clients for the Company to process under the various services.
  • Data from use of the SaaS platform — when you access the Company's SaaS products, the Company collects data you provide directly (such as account data and settings) and data generated by the system through your use (such as access logs, product telemetry data, and device data).
  • Data from affiliates and partners — in some cases, data may be collected from affiliated companies or business partners under appropriate arrangements.

The content the Company collects originates from third-party platforms, each of which has its own terms of use and privacy policy. The public disclosure of data on those platforms depends on the privacy settings and terms accepted by the data subject when using the platform's services.

Because the Company collects data from a large volume of public posts each day, across multiple platforms, through automated systems, the Company has regard to the fact that: (a) the data processed is data that the data subject has already made public; (b) the Company has no direct channel of contact with the majority of data subjects; and (c) the Company has published this Privacy Notice publicly through the Company's website, together with channels for exercising rights and making contact.

5. Categories of Personal Data Processed

The Company processes several categories of personal data, which vary according to the product/service and the context of processing. This section details the data the Company may process; it does not mean that every category of data is processed in every activity or every product. The data actually processed depends on: (a) the relevant product/service; (b) the client's instructions (where the Company acts as processor); and (c) the data subject's public disclosure on the Source Platform.

The Company will process personal data only to the extent necessary and relevant to the purposes of the service, in accordance with the principles of Purpose Limitation and Data Minimization; some categories of data identified below may not be processed in every case.

Data Processed in Social Media Analytics and Client Services

Identity and public profile data

  • Username, profile display name, and any other name the user discloses on public platforms.
  • Platform-specific account identifiers (platform user ID / profile ID).
  • Profile picture and cover photo.
  • Public profile URLs (e.g., Facebook page URL, X profile URL, TikTok handle URL).
  • Self-description (bio / about).
  • Publicly visible following/follower status.
  • Cross-platform linkage, where the user discloses that he or she is the same person across multiple platforms (e.g., an Instagram link in a Facebook profile).

Public contact data

  • Email addresses the user has publicly disclosed on a profile or in posts.
  • Telephone numbers the user has publicly disclosed (e.g., on online shops or business pages).
  • Other contact channels (Line ID, WhatsApp, Telegram) to the extent publicly disclosed by the user.
  • Personal website or business page URLs.

Public Content

  • Text (posts, comments, replies, captions, reviews) on social media platforms and public websites.
  • Images the user has published publicly, which may include images of faces, products, places, or screenshots.
  • Videos the user has published publicly (e.g., TikTok, YouTube Shorts, Instagram Reels).
  • Audio embedded in video content (audio track) or audio clips published by the user.
  • Emoji, hashtags, stickers, and other symbols appearing in content.
  • Links (URLs) and content shared by the user.
  • News articles, web board articles (e.g., Pantip), blogs, including the publicly displayed names of article/thread authors.
  • Live-format content or content subsequently deleted (live streams), to the extent the Company collected it while it was publicly available.

Metadata

  • Date and time of posting (timestamp).
  • Source platform and the device/client identified in post metadata (e.g., "Tweet from iPhone").
  • Language and locale settings.
  • Volume and details of engagement: number of likes, comments, shares, views, forwards, reactions.
  • Posting history and patterns (posting frequency, time-of-day patterns).
  • Automated platform groupings or tags (e.g., hashtag clusters, trending indicators).

Location data

  • Location data the user states on his or her profile (publicly displayed city, country).
  • Locations tagged in posts (geo-tagged posts, check-ins, location tags).
  • Location data embedded in image metadata (EXIF GPS — to the extent it remains in images as published by the platform).
  • Locations inferred from content (e.g., mentions of places).

Network & Relationship Data

  • Publicly visible relationships between users (follows, disclosed friendships, mentions, replies).
  • Groups, communities, or pages the user publicly belongs to or follows.
  • Network analysis (network graph) constructed from public interactions.
  • Interest groupings inferred from relationships.

Image/Video-derived Data

  • Faces appearing in public images or videos. The Company has no purpose of using biometric data for the identification of any particular individual and will not perform facial recognition or identify individuals from such data.
  • Logos, trademarks, products, or objects appearing in images (brand mentions via vision).
  • Text embedded in images (OCR-extracted text).
  • Image classification labels (e.g., "food", "pets", "landscape").
  • Speech-to-text transcripts from public videos/audio clips.

Customer-Supplied Data

Where the Company acts as a Data Processor on the instructions of a client (Warroom, Omnichannel, Monitoring & Alert, Command Center, or the relevant part of Zocial Eye), the Company may process the following categories of data submitted, or made accessible, by the client:

  • Identity data of the client's end customers: full name, email, telephone number, address.
  • Account/membership data of end customers: member ID, tier, purchase history.
  • Contact/complaint/service-ticket history.
  • Content of conversations through communication channels (Facebook Messenger, Line OA, email, etc.) that the client integrates into the Company's systems.
  • Transaction data (purchase orders, delivery status, payment at summary level), to the extent the client uploads it or connects its systems.
  • Access tokens and credentials of the client's systems necessary for connecting to destination platform APIs.

Derived & Inferred Data

For analysis and reporting, the Company generates new data from the source data above. Such derived or inferred data is used solely for aggregate-level analysis, report preparation, or service-quality improvement, and is not used for automated decisions producing legal effects or similarly significant effects concerning the data subject. It comprises:

  • Sentiment scores: positive/negative/neutral and emotional intensity levels.
  • Topic classification: content categories (politics, products, services, brands).
  • Intent classification: complaint, enquiry, praise, comparison, etc.
  • Influencer scores and attributes: follower size, engagement rate, interest categories, inferred follower demographics.
  • Inferred demographics: age range, gender, language, location, interest groups — generated from public data or behaviour.
  • Embeddings: representations of content used for semantic search and classification.
  • Synthetic personas: synthetic profiles generated from large volumes of public data.
  • Reports and dashboards: aggregate analytical outputs that may reference specific content or users.

Data of SaaS Platform Users

This section applies to users of the Company's SaaS platform, being persons granted access and usage rights to the products by a corporate client by means of login. The Company acts as the Data Controller for the data in this section.

Account Data

  • Full name.
  • Email address (ordinarily an email designated by the corporate client).
  • Telephone number (if provided).
  • Job title, department, and employing organisation.
  • Password (stored as a one-way hash; the Company does not store passwords in readable form).
  • Multi-factor authentication data (MFA/2FA).
  • Roles and permissions in the system.
  • Personal settings: language, time zone, notification settings.
  • Data linking to identity providers (SSO/SAML/OIDC attributes), such as Google Workspace, Microsoft Entra, or the corporate client's SSO system.

Authentication & Access Data

  • Login and logout records — date, time, IP address.
  • Session tokens (session tokens / JWT) — retained while the session remains valid.
  • Device identifiers and browser fingerprints to the extent necessary to detect anomalous logins.
  • Password reset history and security-setting changes.
  • Failed login attempts, and logins from new devices/countries.
  • API keys issued by the Company to users for programmatic connections.

Device & Technical Data

  • IP address (including location inferred from IP — country, province/city).
  • Operating system and version.
  • Browser type, model, and version, or user agent string.
  • Screen size, browser language, time zone.
  • Device type (desktop / mobile / tablet).
  • Cookie identifiers and related identifiers.

Usage & Product Telemetry

  • Feature-usage records: pages visited, buttons clicked, usage paths, time spent on each page.
  • Frequency and patterns of use (session duration, feature adoption rate).
  • Search terms and conditions you set within the products (e.g., searches in Zocial Eye, keyword rules in Monitoring & Alert).
  • Files you upload or download, including reports generated and exported.
  • System performance data (response times, error logs).
  • Dashboards, saved reports, custom configurations, and alert configurations.

User-Generated Content

  • Content you create in the course of using the Company's products, which may constitute your own personal data or that of third parties, comprising: custom dashboards and reports, saved searches, keyword sets, tags, descriptions, notes, team comments and collaboration, files you upload, and automation configurations.
  • Content in this section may contain personal data of third parties for which the corporate client is the Data Controller. Where that is the case, the Company acts as the Data Processor for such third-party data on the instructions of the corporate client.

Integration Data

  • When you connect the Company's products to external systems, the Company may process access tokens (OAuth tokens / API tokens), webhook URLs, destination-system credentials stored in encrypted form, API call logs, and mapping data between users in the Company's systems and users in the destination systems.

Support and communications data

  • Content of contacts with the support function (helpdesk tickets, chat logs, emails).
  • Feedback, reviews, satisfaction surveys.
  • Webinar registrations, training attendance, and product training history.
  • Marketing communications (only where you have given consent or where the communication concerns services you currently use).

Sensitive personal data

The Company has no purpose of systematically collecting sensitive personal data under Section 26 of the PDPA. However, in some cases such data may appear in public content disclosed by the data subject him/herself, which the Company will process only to the extent necessary and under an appropriate lawful basis.

For SaaS platform users, the Company asks that you avoid submitting sensitive data unnecessarily when contacting support.

6. Purposes and Lawful Bases of Processing

  • Collection, storage, and analysis of public data from social media to build the database underpinning the Company's products — legitimate interest.
  • Establishment and provision of Influencer Directory, Brand Scan, Trends — legitimate interest.
  • Development and operation of Virtual Persona and Wisesight AI, including model training — legitimate interest.
  • Processing of data on client instructions in Zocial Eye, Warroom, Omnichannel, Monitoring & Alert, Command Center — the client's legitimate interest (the Company acting as processor).
  • Provision of the SaaS platform to registered users, including account management, authentication, and granting of feature access — performance of a contract / legitimate interest.
  • Maintenance of audit records, security monitoring, and retention of computer traffic data — legal obligation (Computer Crime Act) / legitimate interest.
  • Analysis of product telemetry for improvement and feature development — legitimate interest.
  • Delivery of services under service agreements with clients — the client's legitimate interest (the Company acting as processor).
  • Compliance with applicable law, such as tax and accounting law — legal obligation.
  • Establishment, exercise, or defence of legal claims — legitimate interest.

7. Artificial Intelligence

The Company uses artificial intelligence (AI) as a component of its products and services, including in the Company's back-end data processing operations. This section describes the use of AI as it relates to the processing of personal data.

AI Used by the Company to Process Public Data

The Company uses AI to classify and analyse the public data it collects, in order to generate outputs useful to clients, comprising: sentiment classification, topic classification, intent classification, influencer ranking and attributes, summarisation, inference of demographic attributes, and generation of embeddings for semantic search.

These outputs are used for aggregate-level analysis and report preparation, and are not used for automated decisions producing legal effects or similarly significant effects concerning the data subject.

AI Invoked Directly by SaaS Platform Users

The Company provides AI features that SaaS platform users may invoke directly, comprising:

  • Wisesight AI Assistant — the user types a command or question (prompt) for the AI to assist with analysis, answer questions, or generate outputs as instructed.
  • Virtual Persona — a tool with which the user may create simulated consumer groups (synthetic personas) for research and hypothesis testing.
  • AI Summary — summarisation of content, reports, or threads selected by the user.
  • AI Translation — translation of text between languages.
  • AI Insights — conclusions and recommendations generated by the AI from the context of the data the user is viewing.

When you use the AI features above, the Company will process your prompts, search terms, input content, and relevant context in order to generate the outputs you request.

External AI Providers

In some cases, the Company uses AI model services of external providers acting as data processors (such as OpenAI, Anthropic, Google). The Company will select a service tier (enterprise tier) under which the provider is bound not to use data submitted by the Company via API to train the provider's general models.

Compliance with Source Platform Data Policies

Where the Company uses data from Google API Services (including the YouTube Data API), the Company complies with the Google API Services User Data Policy, including the Limited Use requirements, and does not use data from Google Workspace APIs to develop, improve, or train general AI models.

Limitations of AI

Outputs from AI systems may contain inaccuracies, bias, or fabricated content (hallucination). The Company evaluates and improves its models on an ongoing basis; nonetheless, users should exercise judgement and verify outputs before relying on them for significant decisions.

8. Data Recipients and External Data Processors

Data Recipients

  • The Company's corporate clients — for the delivery of analytical results and contracted services, whereby clients use the Company's systems to view public data matching their search terms, build dashboards and reports, and identify influencer groups with whom they wish to work.
  • Your corporate client organisation (for SaaS platform users) — if you are a platform user granted rights by an organisation, the corporate client and administrators designated by it may access your account data, login status, usage frequency, features used, and content you create in the system, for the purpose of managing the usage of users within their organisation.
  • Affiliates or partners (such as Another Dot Co., Ltd., Robolingo Co., Ltd., eTailligence Co., Ltd., TechMatrix Corporation) — for joint service delivery, intra-group management, technical support, and business operations, under appropriate data sharing/processing arrangements.
  • Cloud and infrastructure providers — for the storage and processing of data in the Company's systems.
  • External technology and software providers (including providers of artificial intelligence models) — for the provision of the Company's products, including AI functions, analytics, email delivery, and data visualisation.
  • Data Providers and partners — for the enrichment and verification of data collected by the Company, including access to Source Platform APIs.
  • Channel Partners and Resellers — for marketing and sales support of the Company's products in designated territories.
  • Professional advisers (auditors, legal advisers, tax advisers, insurers) — for the performance of professional duties and legal compliance.
  • Government authorities and law enforcement agencies — where there is a lawful order or where the Company is required to comply with the law, including court warrants, administrative orders, or requests from competent authorities.
  • Counterparties to corporate transactions (prospective purchasers, investors, advisers) — in the event of a merger, acquisition, asset sale, or corporate restructuring, subject to the recipient being bound to use the data in accordance with the purposes announced.

Sub-Processors

  • Cloud infrastructure — Amazon Web Services, Inc. (and its affiliates) — for cloud data storage and processing, being the location of the Company's primary Region in Singapore.
  • External AI model providers — OpenAI, Anthropic, Google — for the provision of artificial intelligence functions, whereby the Company will ensure that data sent to such providers is limited to what is necessary and is not used for other purposes unrelated to the provision of services to the Company.
  • Web and platform analytics provider — Microsoft PowerBI — to support data analysis, visualisation, and system operations.
  • Email delivery and communications provider — Mailchimp.

9. Cross-Border Transfer of Personal Data

Most processing and storage takes place in the cloud systems of Amazon Web Services and Google located in the Republic of Singapore.

In some cases, data may be transferred to other countries for the provision of services by external data processors, in which case the Company will ensure appropriate protection mechanisms as required by law.

10. Retention of Personal Data

The Company retains your personal data only to the extent necessary, for as long as the data continues to serve a lawful business purpose in relation to the purposes of processing.

When your personal data is no longer used for the above purposes, the Company will delete, destroy, or anonymise your personal data in accordance with its data destruction standards. However, in the event of a dispute, exercise of rights, or legal proceedings concerning your personal data, the Company reserves the right to retain such data until a final order or judgment is received.

11. Data Protection Officer (DPO)

The Company has appointed a Data Protection Officer pursuant to Section 41 of the PDPA to provide advice, monitor compliance with the law, coordinate with the Office of the Personal Data Protection Committee (PDPC), and receive complaints from data subjects.

DPO contact details:

  • Email: dpo@wisesight.com
  • Address: 123 Suntowers Building B, 33rd Floor, Unit B3301–3304, Vibhavadi Rangsit Road, Chomphon Sub-district, Chatuchak District, Bangkok 10900
  • Telephone: 022741299

12. Rights of Data Subjects

Under the PDPA, data subjects have the following rights; the details and procedures for exercising each right appear in the relevant privacy notice:

  • Right to be informed. The Company will provide a "Privacy Notice" containing clear details of the purposes of processing, together with a "Cookie Policy" setting out the categories of cookie technologies the Company uses and the purposes of using such cookie technologies; and in the event that the Company processes data other than in accordance with those purposes, or outside the scope of any consent given, the Company will notify and/or seek consent from the data subject before processing personal data outside such purposes.
  • Right to withdraw consent. The data subject may withdraw consent previously given to the Company at any time.
  • Right of access. The data subject may request access to his or her personal data and a copy of the personal data processing activities, and may request that the Company disclose how such data was obtained.
  • Right to rectification. The data subject may request the correction of inaccurate personal data so that such data is accurate, up to date, and not misleading.
  • Right to erasure. The data subject may request that the Company delete or destroy personal data, or render personal data anonymous such that the data subject can no longer be identified.
  • Right to data portability. Where the Company's data systems support reading or use by generally available automated tools or devices, and the personal data can be used or disclosed by automated means, the data subject may request a copy of his or her personal data, request the automatic transfer of such data to another data controller, and request to receive the personal data so sent or transferred.
  • Right to restriction of processing. The data subject has the right to request that the Company restrict the use of personal data.
  • Right to object. The data subject may object to the processing of personal data.

Channels for Exercising Rights

Data subjects may exercise the above rights through the following channels:

13. Complaints and Contact Channels

  • Internal channel — data subjects may lodge complaints with the Company directly through the DPO via the channels specified.
  • Government channel — where a data subject is dissatisfied with the Company's handling of a matter, or wishes to lodge a complaint directly with a government authority, the data subject may contact: Office of the Personal Data Protection Committee (PDPC). Address: 7th Floor, Ratthaprasasanabhakti Building, The Government Complex, 120 Moo 3, Chaengwattana Road, Thung Song Hong Sub-district, Lak Si District, Bangkok 10210. Telephone: 02-142-1033. Email: saraban@pdpc.or.th. Website: https://www.pdpc.or.th

14. Review and Amendment

  • Review — The Company will review this Policy at least once a year, or upon a change in law, in PDPC guidance, or a material change in the business.
  • Amendment — The Company will announce amendments to employees and affected data subjects through the Company's website and appropriate internal channels.
  • Effectiveness — Amendments take effect on the date of announcement or the date specified in the announcement, whichever occurs later.

We use cookies

We use three types of cookies; necessary cookies, functional cookies, and analytics cookies to improve your website browsing experience, but these cookies are not directly identifiable you as a person. To receive the most relevant offers and benefit, please click the "allow" button for targeting cookies. Learn more about our Cookie Policy.