PAMMO — PRIVACY NOTICE
Version 1 — Publication-Ready Pending Final Review Last Updated: 2026-05-18 Effective Date: 15 June 2026
This Privacy Notice describes how Pammo — operated jointly by AEDOWON CO., LTD and AEDOWON SINGAPORE PTE. LTD. (UEN 202612161D) (together, "Pammo", "we", "us", "our") — collects, uses, discloses, retains, and protects your personal data when you access or use the Pammo AI property-workflow service (the "Service").
This Notice is provided in compliance with:
- The Personal Data Protection Act B.E. 2562 (2019) of the Kingdom of Thailand ("Thailand PDPA")
- The Personal Data Protection Act 2012 of the Republic of Singapore ("Singapore PDPA")
- The EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and UK GDPR / DPA 2018
- The California Consumer Privacy Act / California Privacy Rights Act ("CCPA / CPRA") and analogous U.S. state privacy laws (VCDPA, CPA, CTDPA, UCPA, etc.)
- Other applicable data-protection laws
PLAIN-LANGUAGE SUMMARY
- We are a dual-entity operation: a Thai company (AEDOWON CO., LTD) serves Thai residents; a Singapore company (AEDOWON SINGAPORE PTE. LTD., UEN 202612161D) serves everyone else. Together we act as joint data controllers for your account data.
- We collect what we need to provide the Service: account info, payment info, listings you create, audit logs, support correspondence, KYC for the Creator Program, and W-9 / W-8BEN for international Affiliate / Creator payouts.
- We share data only with Sub-Processors (AI providers, Omise, Polar.sh, Supabase, Resend, etc.) listed in our Sub-Processor List and only where necessary.
- You have rights to access, correct, delete, port, object, and withdraw consent — via Account → Privacy or dpo@pammo.co.
- We retain your data only as long as necessary, then delete or anonymize.
- We do not sell or share your personal data for cross-context behavioral advertising except where you have affirmatively opted in (per-network).
- Our optional browser extension sends us a session for your own account, its version number, and a short report of what it did — for each post, the outcome (sent, held, blocked) and whether it could see the post afterwards; for a post that did not go up, also that group's name and link and the reason the extension showed. It never names a group a post went up in, and never sends us anything about your Facebook account, the list of groups you belong to, or what it posted — see §2.6.
1. WHO WE ARE — JOINT CONTROLLERS
Pammo is operated under a dual-entity geo-routed structure (see Pammo-Terms-Conditions-Main-V1 §0):
| Entity | Role | Users | Payment Route |
|---|---|---|---|
| AEDOWON CO., LTD | Joint Controller (TH residents); contracting entity for Thai-Route Users | Thailand-resident Users | Omise |
| AEDOWON SINGAPORE PTE. LTD. (UEN 202612161D) | Joint Controller (Intl residents); contracting entity for International-Route Users; primary controller and primary DPO contact for the joint controllership | Non-Thailand-resident Users | Polar.sh (Merchant of Record) |
Joint-Controller Allocation. Both entities are joint controllers for:
- Account identity and authentication data
- Billing and payment-method metadata (tokenized references)
- Audit and security-event logs
- Compliance and fraud-prevention signals
- Communications with you (support, marketing under §13A/§13B, newsletter)
The entity that contracts with you under §0 of the Main T&C is the primary local-controller for tax-invoice, withholding-tax, refund, and consumer-protection purposes; the other entity is co-responsible under the joint-controller arrangement and bound by the same standard of care.
Primary DPO contact (single channel for both entities): dpo@pammo.co
Singapore registered office: AEDOWON SINGAPORE PTE. LTD. (UEN 202612161D), 8 TEMASEK BOULEVARD, #17-02A, SUNTEC TOWER THREE, SINGAPORE 038988
Thailand registered office: AEDOWON CO., LTD, 250/207 SOI BUDDHAMONDON SAI 2 SOI 32, SALATHAMMASOP, TAWEWATTANA, BANGKOK 10170, THAILAND
Pammo engages personnel located in various jurisdictions (Thailand, Singapore, and others) as authorized agents bound by confidentiality and the technical and organizational measures set out in our Data Processing Addendum.
2. WHAT PERSONAL DATA WE COLLECT
We collect the following categories of personal data:
2.1 Data You Provide Directly
| Category | Examples | When Collected |
|---|---|---|
| Account Identity | Name, email, password (hashed), date of birth, country of residence | At signup |
| Contact | Mobile phone, business name, brokerage / agency affiliation, license number (real-estate professionals) | At signup or upgrade |
| Billing | Payment-method tokens (Omise or Polar tokenization), billing address, Thai Tax ID or international tax ID, withholding-tax documents | At first paid subscription |
| Listing Inventory | Property data you upload — addresses, prices, photos, descriptions, condominium foreign-quota status (only as you supply) | When you create listings |
| User Input | Text prompts, images, audio, documents (title-deed photos for OCR), brand assets, contract drafts, audience / lead lists | When you use the Service |
| AI Output | Generated listing descriptions, ad copy, draft contracts, OCR extractions, matching results | When AI generates content for you |
| Creator Program KYC | Thai National ID image / international passport image, issuing authority, ID number, name, DOB, photo | If you apply to the Creator Program |
| Affiliate / Creator Tax Forms | W-9 / W-8BEN / W-8BEN-E, CRS / FATCA self-certification, TIN, bank / Wise / PayPal payout details | If you enroll as a non-SG/TH-resident Affiliate / Creator |
| Support Correspondence | Email content, in-app chat, screenshots you share | When you contact support |
| Marketing & Consent Preferences | Opt-in to marketing (§13A), per-network ad-platform opt-in (§13B), newsletter (§14) | At consent capture and updates |
2.2 Data Collected Automatically
| Category | Examples |
|---|---|
| Device / Technical | IP address, browser type, OS, device fingerprint hash, screen resolution, language |
| Usage Telemetry | Pages visited, features used, clicks, time spent, errors encountered, credits consumed |
| Cookies / Local Storage | Session ID, preferences, attribution cookies (see Cookie Notice) |
| Fraud-Detection Signals | Payment-method hash, email-domain match, IP / device patterns, conversion rates, velocity signals (per Anti-Fraud Rules AB1–AB7) |
| Quota & Billing Audit Trail | Credits used (general + Discovery), Extra Usage charges, Prepaid balance, Monthly Spending Limit triggers |
2.3 Data Collected from Third Parties
| Source | Data |
|---|---|
| Omise (Opn Payments) — TH Route | Payment authorization status, 3-D Secure result, chargeback notifications, withholding-tax codes |
| Polar.sh — International Route MoR | Payment authorization, tax-jurisdiction validation, chargeback coordination |
| Currenxie / Wise / PayPal — Payout rails (Affiliate / Creator) | Payout status, sanctions-screening result (from the payout provider's regulatory obligations) |
| Identity Verification — Creator KYC (currently manual review by Pammo personnel; third-party vendor TBD) | NID / passport verification results |
| Anti-Fraud Services — built-in screening of Omise / Polar / payout-rail providers | Risk scores, sanctions-list match |
| Advertising Platforms (with your consent) — Meta, Google, TikTok, LINE | Audience-list matching results, ad-attribution data |
2.4 Sensitive Personal Data
We do not require sensitive personal data for ordinary Service use. Where the Service processes sensitive data, we obtain your explicit consent:
(a) Creator NID / passport image (Thailand PDPA §26 sensitive category; Singapore PDPA Schedule 2 — physical-identification document) — collected with verbatim consent at Creator application; used only for identity verification, anti-fraud, and tax-residency confirmation per Pammo-Creator-Program-Terms-V1 §11.
(b) Sensitive data in Your Input or in Property Data you upload. Where User Input or uploaded Property Data contains sensitive data of third parties (e.g., health information of an occupant, religion-related preferences, biometric, criminal-record, political-opinion, sexual-orientation data), you represent that you have obtained the required explicit consent from those data subjects under Thailand PDPA §26, Singapore PDPA Schedule 2, and / or GDPR Art 9. You indemnify Pammo per Main T&C §16 against any claim arising from your failure to do so.
2.5 Children
Pammo is not directed to children under 13 and does not knowingly collect data from children under 13. The minimum age for the Service is 18 (or the higher local age of majority). Where mandatory parental consent permits use by minors (13–17) in specific jurisdictions, separate parental-consent collection applies.
2.6 Browser Extension (Pammo — โพสต์ลงกลุ่ม)
We publish an optional Chrome browser extension that posts listings from your Pammo account into the Facebook groups you belong to, from the browser you are already signed in to. It is free, it is optional, and the Service works fully without it.
(a) What the extension sends to us. Three things:
- An authentication session for your Pammo account, created when you connect the extension. It is used to read your own listings and their photos, and to confirm once a day that your account is still active. It is the extension's own session — your browser's Pammo session is never handed over.
- The extension's version number, on each request, so that we can refuse versions we no longer support.
- A short report of what the extension did, so that we can support it and see that it works. For each post it makes: the outcome (sent, held for the group's approval, could not post, failed, blocked, or stopped by a Facebook identity check), whether the extension could see the post in the group afterwards and how it found the post's link, the time, and the extension's version. The posts of one campaign are grouped under a random key, and a campaign made from the onboarding sample listing is marked as such. Once a day it also reports the extension's version and build, how many Facebook groups your account belongs to (the number only), and how many campaigns it holds. When a post does not go up, or the extension cannot tell whether it did, the report also includes that group's name and link and the one-line reason the extension showed, so that we can see why and help you. The report never includes the name, address or identity of a group a post went up in, the text or photos of any post, which listing a campaign was made from, or anything about your Facebook account.
(b) What the extension keeps on your device and never sends to us. Your saved group selections, your campaign history with the group and link of each post, and listing photos while a campaign is running. These are held in your browser's own storage on your computer. They are not transmitted to Pammo and we cannot read them; only the report in (a) reaches us — which, for a post that did not go up, names that group.
(c) What the extension never does.
- It never sends us your Facebook account details, the list of groups you belong to, or what it posted. The only group it ever names is the group of a post that did not go up, as described in (a).
- It never sees or stores your Facebook password. You sign in to Facebook in a Facebook window, exactly as you normally would, and the extension operates only within the session your browser already holds.
- Pammo is not connected to Facebook or Meta Platforms, Inc., has no agreement with them, and receives no data from them.
(d) Deleting it. Removing the extension from your browser deletes everything it stored on your device. Pressing disconnect inside the extension ends its session with us. Reports already sent under (a) stay with your Pammo account and are deleted with it. Neither action affects the other data in your Pammo account, which is governed by the rest of this Notice.
(e) Your responsibility for posting. Posting into Facebook groups is subject to Facebook's own terms and is the account holder's responsibility, as stated on the extension's download page and in our Acceptable Use Policy.
3. WHY WE PROCESS YOUR DATA (PURPOSES AND LAWFUL BASES)
| Purpose | Lawful Basis |
|---|---|
| Create and operate your account | Contract performance (Thailand PDPA §24(3); Singapore PDPA §13; GDPR Art 6(1)(b)) |
| Bill you and process payments via Omise (TH) or Polar (Intl) | Contract performance |
| Deliver Service features (Chat-to-Listing, AI Chat Command, Discovery, OCR, Property Matching, Contract Auto-gen, PANNORA Co-Pilot) | Contract performance |
| Provide customer support | Contract performance |
| Detect fraud, prevent abuse, enforce the AUP and these Terms | Legitimate interests (GDPR Art 6(1)(f); Thailand PDPA §24(5)) + legal obligation |
| Comply with tax, accounting, AML, and sanctions obligations (Thai Revenue Code, SG Income Tax Act, AMLO, OFAC, etc.) | Legal obligation |
| Process Creator KYC (Thailand PDPA §26 sensitive category) | Explicit consent + legal obligation (Thai tax / AML) |
| Train / improve AI models on User Input or Output | Consent — opt-in only |
| Send marketing communications | Consent (per §13A) — opt-in only |
| Share behavioral / inferred-preference data with advertising platforms (Meta, Google, TikTok, LINE) | Consent (per §13B) — per-network opt-in only |
| Send newsletter | Consent (per §14) — opt-in only (double opt-in for EEA/UK) |
| Run FGF / Affiliate / Creator attribution and reward | Contract performance + legitimate interest (program operation) |
| Defend or pursue legal claims | Legitimate interests / legal obligation |
| Respond to data-subject-rights requests | Legal obligation |
4. WHO WE SHARE YOUR DATA WITH
4.1 Sub-Processors
We engage third-party Sub-Processors to operate the Service. A current list is published in our Sub-Processor List; broad categories include:
- AI model providers — Anthropic, OpenAI, Google (Gemini), Stability AI, Replicate, and successor providers
- Payment / payout processors — Omise (TH Route), Polar.sh (International Route MoR), Currenxie (international banking + Affiliate / Creator payouts), Wise (reserved future activation), PayPal (Affiliate / Creator payouts)
- Hosting / infrastructure — Supabase, Vercel, Cloudflare
- Email transport — Resend (transactional + transport for in-house marketing emails)
- LINE OA — broadcast (with consent for marketing)
- Customer support — Dabby (an AI chatbot operated by Pammo itself — internal tool, not a third-party Sub-Processor)
- Web-aggregation infrastructure for Property Discovery — bounded to Pammo's own infrastructure stack on Supabase + Vercel, no third-party scraping-as-a-service vendor at launch
We provide at least 30 days' prior notice before engaging any new material Sub-Processor, with a right of objection on reasonable grounds (per Main T&C §12.2A(d) + Pammo-Data-Processing-Addendum-V1 §7).
4.2 Advertising Networks (Opt-In Only)
Where you have affirmatively opted in via §13B of the Main T&C, we share behavioral / inferred-preference data with selected advertising networks on a per-network basis:
- Meta (Facebook / Instagram)
- Google (Google Ads / YouTube)
- TikTok
- LINE Ads
- Others listed in the Sub-Processor List
You may withdraw any of these per-network consents at any time via Account → Privacy → Ad-Network Sharing.
4.3 Legal / Regulatory Disclosures
We may disclose personal data:
- To comply with applicable law, court order, subpoena, or regulator request
- To the Thailand Personal Data Protection Committee (PDPC), the Singapore PDPC, EU supervisory authorities, the UK ICO, or US state AGs in response to lawful requests
- To protect rights, property, or safety of Pammo, our Users, or others
- To Thai Revenue Department, Singapore IRAS, Thai AMLO, US OFAC, EU FCA, UK OFSI, or other competent regulator for tax / AML / sanctions purposes
- In connection with merger, acquisition, sale of assets, or insolvency, subject to notice and successor-assumption-of-obligations per Main T&C
- To enforce or defend legal claims
4.4 What We Do NOT Do
- We do NOT sell personal data for monetary consideration.
- We do NOT share personal data for cross-context behavioral advertising as defined under CCPA / CPRA, VCDPA, CPA, CTDPA, or UCPA, except where you have affirmatively opted in (§4.2 above).
- We do NOT disclose your User Input or AI Output as identifiable to you without your consent, except as required by law.
- We do NOT train AI models on your User Input or AI Output without your separate opt-in consent (Account → Privacy → AI Training). See §4.5 for exactly what that setting does when you turn it on.
- We do NOT share Property Data you upload with competitors of Pammo.
4.5 AI Training (Account → Privacy → AI Training) — OFF by default
This setting is off unless you turn it on. While it is off, nothing described in this section is collected — not collected-and-excluded, not collected-and-deleted: the records are never created.
What is collected when you turn it on. When Pammo's AI extracts a listing from something you paste and you correct a field before saving, we keep that correction as a pair: what the AI proposed, and what you changed it to. Your edit is the ground truth that tells us the AI was wrong and what the right answer was.
What is never collected, even when it is on:
- Contact details are excluded outright — no phone number, email, LINE ID, contact name or agent name, whether or not you corrected them. The fields worth measuring are price, property type, area, bedrooms, zone and similar.
- Fields you did not change. If you accepted what the AI produced, there is no correction to keep.
- The conversation itself. We keep the two values for a field, not your messages.
What it is used for. Measuring and improving Pammo's own extraction accuracy — finding the fields the AI most often gets wrong and fixing them. It is not sent to the AI providers in §1 of the Sub-Processor List for their model training; those providers are engaged on training-opt-out terms independently of this setting.
Retention and withdrawal. Corrections are kept for 24 months, then deleted. You can turn the setting off at any time; collection stops immediately, and you can request deletion of everything already collected via privacy@pammo.co or Account → Privacy. Turning it off is not retroactive on its own — ask us to delete if that is what you want.
5. WHERE YOUR DATA GOES (CROSS-BORDER TRANSFERS)
Your data may be transferred to and processed in jurisdictions outside your country of residence, including Singapore, Thailand, the United States, the European Union, the United Kingdom, Hong Kong, Japan, and other locations where our Sub-Processors operate.
Lawful transfer mechanisms (in order of preference):
(a) Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914) or by the Thailand PDPC — primary basis for routine recurring transfers;
(b) Adequacy decisions recognized by the Thailand PDPC or the European Commission;
(c) Binding Corporate Rules approved by the competent supervisory authority;
(d) Contract necessity for performance of your contract with us (Thailand PDPA §28 ¶2(3); GDPR Art 49(1)(b)) — used where SCC / adequacy is unavailable;
(e) Your explicit consent after being informed of the absence of adequate safeguards — last-resort basis only (Thailand PDPA §28 ¶2(2); GDPR Art 49(1)(a));
(f) Compliance with legal obligation, public interest, vital interests, or legal claims.
A current mapping of each Sub-Processor's jurisdiction and applicable safeguard is published in the Sub-Processor List.
6. HOW LONG WE KEEP YOUR DATA (RETENTION)
| Data Category | Retention Period |
|---|---|
| Account profile + billing identity | 24 months post-account-termination |
| User Input (listings, prompts, uploaded documents) and AI Output | 24 months post-account-termination, or earlier on User deletion request (subject to legal hold) |
| Service usage logs / telemetry | 12 months |
| Fraud-detection signals (IP, device fingerprint, payment-method hash, email-domain match, AB1–AB7 audit) | 24 months |
| Support tickets and correspondence | 36 months |
| Chargeback / dispute evidence | 7 years (regulatory minimum, both Thai Revenue Code and SG payment-services regulatory norms) |
| Marketing preferences and consent records | Duration of consent + 24 months post-withdrawal |
| Creator KYC NID / passport verification records | 24 months after Creator termination (longer where required by tax / fraud / sanctions / legal hold) |
| Affiliate / Creator tax-form records (W-9 / W-8BEN / withholding-tax certificates) | Minimum 7 years for tax-record-retention compliance |
| Accounting and tax records (Thai Revenue Code §87/3, Thai Accounting Act B.E. 2543 §14, Singapore Companies Act §199, Singapore Income Tax Act §67) | Minimum 5 years |
After the applicable retention period, personal data is securely deleted or irreversibly anonymized, with an audit trail.
7. YOUR RIGHTS
You have the following rights regarding your personal data:
7.1 Right Catalog
| Right | What It Means | Where It Lives in Law |
|---|---|---|
| Be informed | Know what data we collect and why | TH PDPA §23 · GDPR Art 13–14 · SG PDPA §20 |
| Access | Get a copy of your data | TH PDPA §30 · GDPR Art 15 · SG PDPA §21 |
| Portability | Receive your data in machine-readable format and transfer to another controller | TH PDPA §31 · GDPR Art 20 |
| Rectification | Correct inaccurate or incomplete data | TH PDPA §§35–36 · GDPR Art 16 |
| Erasure | Request deletion ("right to be forgotten") | TH PDPA §33 · GDPR Art 17 |
| Restriction | Limit processing in certain circumstances | TH PDPA §34 · GDPR Art 18 |
| Object | Object to processing based on legitimate interests or direct marketing | TH PDPA §32 · GDPR Art 21 |
| Withdraw consent | Withdraw any time (without affecting prior lawfulness) | TH PDPA §19 ¶5 · SG PDPA §16 · GDPR Art 7(3) |
| Complaint | Lodge complaint with supervisory authority | TH PDPC · SG PDPC · EU DPA · UK ICO · US state AG |
| No automated decisions | Not be subject to solely automated decision-making with legal effect | GDPR Art 22 |
7.2 How to Exercise Your Rights
Easiest method: Account → Privacy → "Manage My Data" — one-click controls for most rights.
Alternative: Email dpo@pammo.co with:
- Your full name and email associated with the account
- The right you wish to exercise
- Any relevant context (e.g., specific data to delete)
We may ask for additional verification to confirm your identity.
7.3 Response Timeline
We respond to verified requests within 30 calendar days of receipt, extendable by a further 60 days for complex or high-volume requests (with prior notice and reasons given within the original 30-day period). This is in accordance with Thailand PDPA §32, Singapore PDPA §21(2), and GDPR Art 12(3).
7.4 No Charge
We respond to data-subject requests free of charge, except where requests are manifestly unfounded, excessive, or repetitive — in which case we may charge a reasonable administrative fee or refuse.
7.5 U.S. State Privacy Rights
If you are a U.S.-resident User, you additionally have rights under CCPA / CPRA / VCDPA / CPA / CTDPA / UCPA:
- Right to know the categories and specific pieces of personal information we collect, sell, or share
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt out of any future "sale" or "sharing" for cross-context behavioral advertising
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising privacy rights
To exercise these rights, contact privacy@pammo.co or use the in-app "Do Not Sell or Share My Personal Information" control. We do not currently "sell" or "share" your personal information for cross-context behavioral advertising except where you have opted in via §13B of the Main T&C.
7.6 Withdrawal of Consent — One-Click
You may withdraw any consent at any time using one-click in-app controls (Account → Privacy → "Withdraw consent") or by emailing dpo@pammo.co. Withdrawal mechanisms are at least as easy as the original consent action. We process valid withdrawal requests within 7 calendar days. Withdrawal does not affect the lawfulness of prior processing.
8. SECURITY
We implement administrative, technical, and physical safeguards consistent with industry standards and PDPA / GDPR / SG PDPA security requirements:
- Encryption of personal data at rest (AES-256 or equivalent) and in transit (TLS 1.2+, TLS 1.3 preferred)
- Role-based access control with least-privilege grants and quarterly access review
- Multi-factor authentication for all administrative, production, payment, and DPO tooling
- Logging of security-relevant events for at least 12 months
- Backup with tested restore (quarterly minimum)
- Vendor risk management for Sub-Processors (annual review + 30-day prior-notice on additions)
- Documented incident-response procedure
- Periodic security audits and penetration testing
Full Technical and Organizational Measures (TOMs) are documented in Data Processing Addendum Annex II.
9. BREACH NOTIFICATION
In the event of a personal-data breach, we notify regulators and affected individuals in accordance with the following statutory clocks:
| Jurisdiction | Clock |
|---|---|
| Thailand PDPC (Thailand PDPA §39) + EU / EEA Supervisory Authority (GDPR Arts 33–34) | 72 hours from awareness |
| Singapore PDPC (PDPA §§26B–26D + Notifiable Data Breaches Regulations 2021) | 3 calendar days from credible assessment |
| UK ICO | 72 hours per UK GDPR Art 33 |
| U.S. state authorities | Per applicable state breach-notification statutes |
Affected individuals are notified where the breach is likely to result in significant harm or high risk to rights and freedoms.
10. COOKIES AND TRACKING
The Service uses cookies, local storage, and similar technologies as described in our Cookie Notice. Non-essential cookies — including analytics, retargeting, and the 60-day Affiliate / Creator / FGF attribution cookie — are set only with your affirmative consent via our cookie banner. We honor Global Privacy Control (GPC) and "Do Not Track" signals where legally required.
11. THIRD-PARTY LINKS
The Service may contain links to third-party websites or services (e.g., DDproperty, condominium-portal listings, embedded map services). We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy notices.
12. AUTOMATED DECISION-MAKING
We use automated processes for:
- Fraud detection (cohort fraud monitoring, IP / device matching, anomalous-pattern flagging — AB1–AB7)
- Affiliate tier promotion (automated lifetime-referral-count threshold check per Pammo-Program-Rules-V1 §4.4)
- Credit allocation (monthly reset on the 1st at 00:00 ICT; signup-anchored drip for Yearly plans)
- Property Matching (vector-search ranking)
- Cohort fraud monitor (5% threshold over 20-active-cohort floor)
These do not produce legal effects on you without human review where required by GDPR Art 22. Affiliate / Creator commission decisions involving forfeiture, escrow hold, or termination are reviewed by Pammo staff before being finalized (per the 14-day challenge + 30-day mediation window in Pammo-Program-Rules-V1 §8.4).
13. CHILDREN
The Service is not directed to and may not be used by children under 13 in any circumstance. The minimum age is 18 or the local age of majority. See Main T&C §1.5 + §3.1 for full age-eligibility rules.
14. CHANGES TO THIS NOTICE
We may update this Privacy Notice from time to time. Material changes will be notified by email and in-app banner at least 30 days before they take effect; non-material clarifications take effect immediately upon posting. The "Last Updated" date at the top of this Notice reflects the most recent change. Prior versions are available on request to dpo@pammo.co.
15. CONTACT US
Data Protection Officer (DPO — joint controllers): dpo@pammo.co General Privacy Inquiries: privacy@pammo.co U.S. State Privacy Rights: privacy@pammo.co
Supervisory Authorities:
- Thailand: Personal Data Protection Committee (PDPC), Ministry of Digital Economy and Society — pdpc.or.th
- Singapore: Personal Data Protection Commission of Singapore — pdpc.gov.sg
- EU / EEA: your local Data Protection Authority
- UK: Information Commissioner's Office (ICO) — ico.org.uk
You may also lodge a complaint with the supervisory authority of your habitual residence or place of alleged infringement.
END OF PAMMO PRIVACY NOTICE — V1 (PUBLICATION-READY PENDING FINAL REVIEW) Last Updated: 2026-05-18