Pammo ← Back to Legal Center
ดูฉบับภาษาไทย →

Effective 15 June 2026 · Updated 18 May 2026

PAMMO — PRIVACY NOTICE

Version 1 — Publication-Ready Pending Final Review Last Updated: 2026-05-18 Effective Date: 15 June 2026

This Privacy Notice describes how Pammo — operated jointly by AEDOWON CO., LTD and AEDOWON SINGAPORE PTE. LTD. (UEN 202612161D) (together, "Pammo", "we", "us", "our") — collects, uses, discloses, retains, and protects your personal data when you access or use the Pammo AI property-workflow service (the "Service").

This Notice is provided in compliance with:

PLAIN-LANGUAGE SUMMARY

  • We are a dual-entity operation: a Thai company (AEDOWON CO., LTD) serves Thai residents; a Singapore company (AEDOWON SINGAPORE PTE. LTD., UEN 202612161D) serves everyone else. Together we act as joint data controllers for your account data.
  • We collect what we need to provide the Service: account info, payment info, listings you create, audit logs, support correspondence, KYC for the Creator Program, and W-9 / W-8BEN for international Affiliate / Creator payouts.
  • We share data only with Sub-Processors (AI providers, Omise, Polar.sh, Supabase, Resend, etc.) listed in our Sub-Processor List and only where necessary.
  • You have rights to access, correct, delete, port, object, and withdraw consent — via Account → Privacy or dpo@pammo.co.
  • We retain your data only as long as necessary, then delete or anonymize.
  • We do not sell or share your personal data for cross-context behavioral advertising except where you have affirmatively opted in (per-network).

1. WHO WE ARE — JOINT CONTROLLERS

Pammo is operated under a dual-entity geo-routed structure (see Pammo-Terms-Conditions-Main-V1 §0):

Entity Role Users Payment Route
AEDOWON CO., LTD Joint Controller (TH residents); contracting entity for Thai-Route Users Thailand-resident Users Omise
AEDOWON SINGAPORE PTE. LTD. (UEN 202612161D) Joint Controller (Intl residents); contracting entity for International-Route Users; primary controller and primary DPO contact for the joint controllership Non-Thailand-resident Users Polar.sh (Merchant of Record)

Joint-Controller Allocation. Both entities are joint controllers for:

The entity that contracts with you under §0 of the Main T&C is the primary local-controller for tax-invoice, withholding-tax, refund, and consumer-protection purposes; the other entity is co-responsible under the joint-controller arrangement and bound by the same standard of care.

Primary DPO contact (single channel for both entities): dpo@pammo.co

Singapore registered office: AEDOWON SINGAPORE PTE. LTD. (UEN 202612161D), 8 TEMASEK BOULEVARD, #17-02A, SUNTEC TOWER THREE, SINGAPORE 038988

Thailand registered office: AEDOWON CO., LTD, 250/207 SOI BUDDHAMONDON SAI 2 SOI 32, SALATHAMMASOP, TAWEWATTANA, BANGKOK 10170, THAILAND

Pammo engages personnel located in various jurisdictions (Thailand, Singapore, and others) as authorized agents bound by confidentiality and the technical and organizational measures set out in our Data Processing Addendum.


2. WHAT PERSONAL DATA WE COLLECT

We collect the following categories of personal data:

2.1 Data You Provide Directly

Category Examples When Collected
Account Identity Name, email, password (hashed), date of birth, country of residence At signup
Contact Mobile phone, business name, brokerage / agency affiliation, license number (real-estate professionals) At signup or upgrade
Billing Payment-method tokens (Omise or Polar tokenization), billing address, Thai Tax ID or international tax ID, withholding-tax documents At first paid subscription
Listing Inventory Property data you upload — addresses, prices, photos, descriptions, condominium foreign-quota status (only as you supply) When you create listings
User Input Text prompts, images, audio, documents (title-deed photos for OCR), brand assets, contract drafts, audience / lead lists When you use the Service
AI Output Generated listing descriptions, ad copy, draft contracts, OCR extractions, matching results When AI generates content for you
Creator Program KYC Thai National ID image / international passport image, issuing authority, ID number, name, DOB, photo If you apply to the Creator Program
Affiliate / Creator Tax Forms W-9 / W-8BEN / W-8BEN-E, CRS / FATCA self-certification, TIN, bank / Wise / PayPal payout details If you enroll as a non-SG/TH-resident Affiliate / Creator
Support Correspondence Email content, in-app chat, screenshots you share When you contact support
Marketing & Consent Preferences Opt-in to marketing (§13A), per-network ad-platform opt-in (§13B), newsletter (§14) At consent capture and updates

2.2 Data Collected Automatically

Category Examples
Device / Technical IP address, browser type, OS, device fingerprint hash, screen resolution, language
Usage Telemetry Pages visited, features used, clicks, time spent, errors encountered, credits consumed
Cookies / Local Storage Session ID, preferences, attribution cookies (see Cookie Notice)
Fraud-Detection Signals Payment-method hash, email-domain match, IP / device patterns, conversion rates, velocity signals (per Anti-Fraud Rules AB1–AB7)
Quota & Billing Audit Trail Credits used (general + Discovery), Extra Usage charges, Prepaid balance, Monthly Spending Limit triggers

2.3 Data Collected from Third Parties

Source Data
Omise (Opn Payments) — TH Route Payment authorization status, 3-D Secure result, chargeback notifications, withholding-tax codes
Polar.sh — International Route MoR Payment authorization, tax-jurisdiction validation, chargeback coordination
Currenxie / Wise / PayPal — Payout rails (Affiliate / Creator) Payout status, sanctions-screening result (from the payout provider's regulatory obligations)
Identity Verification — Creator KYC (currently manual review by Pammo personnel; third-party vendor TBD) NID / passport verification results
Anti-Fraud Services — built-in screening of Omise / Polar / payout-rail providers Risk scores, sanctions-list match
Advertising Platforms (with your consent) — Meta, Google, TikTok, LINE Audience-list matching results, ad-attribution data

2.4 Sensitive Personal Data

We do not require sensitive personal data for ordinary Service use. Where the Service processes sensitive data, we obtain your explicit consent:

(a) Creator NID / passport image (Thailand PDPA §26 sensitive category; Singapore PDPA Schedule 2 — physical-identification document) — collected with verbatim consent at Creator application; used only for identity verification, anti-fraud, and tax-residency confirmation per Pammo-Creator-Program-Terms-V1 §11.

(b) Sensitive data in Your Input or in Property Data you upload. Where User Input or uploaded Property Data contains sensitive data of third parties (e.g., health information of an occupant, religion-related preferences, biometric, criminal-record, political-opinion, sexual-orientation data), you represent that you have obtained the required explicit consent from those data subjects under Thailand PDPA §26, Singapore PDPA Schedule 2, and / or GDPR Art 9. You indemnify Pammo per Main T&C §16 against any claim arising from your failure to do so.

2.5 Children

Pammo is not directed to children under 13 and does not knowingly collect data from children under 13. The minimum age for the Service is 18 (or the higher local age of majority). Where mandatory parental consent permits use by minors (13–17) in specific jurisdictions, separate parental-consent collection applies.


3. WHY WE PROCESS YOUR DATA (PURPOSES AND LAWFUL BASES)

Purpose Lawful Basis
Create and operate your account Contract performance (Thailand PDPA §24(3); Singapore PDPA §13; GDPR Art 6(1)(b))
Bill you and process payments via Omise (TH) or Polar (Intl) Contract performance
Deliver Service features (Chat-to-Listing, AI Chat Command, Discovery, OCR, Property Matching, Contract Auto-gen, PANNORA Co-Pilot) Contract performance
Provide customer support Contract performance
Detect fraud, prevent abuse, enforce the AUP and these Terms Legitimate interests (GDPR Art 6(1)(f); Thailand PDPA §24(5)) + legal obligation
Comply with tax, accounting, AML, and sanctions obligations (Thai Revenue Code, SG Income Tax Act, AMLO, OFAC, etc.) Legal obligation
Process Creator KYC (Thailand PDPA §26 sensitive category) Explicit consent + legal obligation (Thai tax / AML)
Train / improve AI models on User Input or Output Consent — opt-in only
Send marketing communications Consent (per §13A) — opt-in only
Share behavioral / inferred-preference data with advertising platforms (Meta, Google, TikTok, LINE) Consent (per §13B) — per-network opt-in only
Send newsletter Consent (per §14) — opt-in only (double opt-in for EEA/UK)
Run FGF / Affiliate / Creator attribution and reward Contract performance + legitimate interest (program operation)
Defend or pursue legal claims Legitimate interests / legal obligation
Respond to data-subject-rights requests Legal obligation

4. WHO WE SHARE YOUR DATA WITH

4.1 Sub-Processors

We engage third-party Sub-Processors to operate the Service. A current list is published in our Sub-Processor List; broad categories include:

We provide at least 30 days' prior notice before engaging any new material Sub-Processor, with a right of objection on reasonable grounds (per Main T&C §12.2A(d) + Pammo-Data-Processing-Addendum-V1 §7).

4.2 Advertising Networks (Opt-In Only)

Where you have affirmatively opted in via §13B of the Main T&C, we share behavioral / inferred-preference data with selected advertising networks on a per-network basis:

You may withdraw any of these per-network consents at any time via Account → Privacy → Ad-Network Sharing.

4.3 Legal / Regulatory Disclosures

We may disclose personal data:

4.4 What We Do NOT Do


5. WHERE YOUR DATA GOES (CROSS-BORDER TRANSFERS)

Your data may be transferred to and processed in jurisdictions outside your country of residence, including Singapore, Thailand, the United States, the European Union, the United Kingdom, Hong Kong, Japan, and other locations where our Sub-Processors operate.

Lawful transfer mechanisms (in order of preference):

(a) Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914) or by the Thailand PDPC — primary basis for routine recurring transfers;

(b) Adequacy decisions recognized by the Thailand PDPC or the European Commission;

(c) Binding Corporate Rules approved by the competent supervisory authority;

(d) Contract necessity for performance of your contract with us (Thailand PDPA §28 ¶2(3); GDPR Art 49(1)(b)) — used where SCC / adequacy is unavailable;

(e) Your explicit consent after being informed of the absence of adequate safeguards — last-resort basis only (Thailand PDPA §28 ¶2(2); GDPR Art 49(1)(a));

(f) Compliance with legal obligation, public interest, vital interests, or legal claims.

A current mapping of each Sub-Processor's jurisdiction and applicable safeguard is published in the Sub-Processor List.


6. HOW LONG WE KEEP YOUR DATA (RETENTION)

Data Category Retention Period
Account profile + billing identity 24 months post-account-termination
User Input (listings, prompts, uploaded documents) and AI Output 24 months post-account-termination, or earlier on User deletion request (subject to legal hold)
Service usage logs / telemetry 12 months
Fraud-detection signals (IP, device fingerprint, payment-method hash, email-domain match, AB1–AB7 audit) 24 months
Support tickets and correspondence 36 months
Chargeback / dispute evidence 7 years (regulatory minimum, both Thai Revenue Code and SG payment-services regulatory norms)
Marketing preferences and consent records Duration of consent + 24 months post-withdrawal
Creator KYC NID / passport verification records 24 months after Creator termination (longer where required by tax / fraud / sanctions / legal hold)
Affiliate / Creator tax-form records (W-9 / W-8BEN / withholding-tax certificates) Minimum 7 years for tax-record-retention compliance
Accounting and tax records (Thai Revenue Code §87/3, Thai Accounting Act B.E. 2543 §14, Singapore Companies Act §199, Singapore Income Tax Act §67) Minimum 5 years

After the applicable retention period, personal data is securely deleted or irreversibly anonymized, with an audit trail.


7. YOUR RIGHTS

You have the following rights regarding your personal data:

7.1 Right Catalog

Right What It Means Where It Lives in Law
Be informed Know what data we collect and why TH PDPA §23 · GDPR Art 13–14 · SG PDPA §20
Access Get a copy of your data TH PDPA §30 · GDPR Art 15 · SG PDPA §21
Portability Receive your data in machine-readable format and transfer to another controller TH PDPA §31 · GDPR Art 20
Rectification Correct inaccurate or incomplete data TH PDPA §§35–36 · GDPR Art 16
Erasure Request deletion ("right to be forgotten") TH PDPA §33 · GDPR Art 17
Restriction Limit processing in certain circumstances TH PDPA §34 · GDPR Art 18
Object Object to processing based on legitimate interests or direct marketing TH PDPA §32 · GDPR Art 21
Withdraw consent Withdraw any time (without affecting prior lawfulness) TH PDPA §19 ¶5 · SG PDPA §16 · GDPR Art 7(3)
Complaint Lodge complaint with supervisory authority TH PDPC · SG PDPC · EU DPA · UK ICO · US state AG
No automated decisions Not be subject to solely automated decision-making with legal effect GDPR Art 22

7.2 How to Exercise Your Rights

Easiest method: Account → Privacy → "Manage My Data" — one-click controls for most rights.

Alternative: Email dpo@pammo.co with:

We may ask for additional verification to confirm your identity.

7.3 Response Timeline

We respond to verified requests within 30 calendar days of receipt, extendable by a further 60 days for complex or high-volume requests (with prior notice and reasons given within the original 30-day period). This is in accordance with Thailand PDPA §32, Singapore PDPA §21(2), and GDPR Art 12(3).

7.4 No Charge

We respond to data-subject requests free of charge, except where requests are manifestly unfounded, excessive, or repetitive — in which case we may charge a reasonable administrative fee or refuse.

7.5 U.S. State Privacy Rights

If you are a U.S.-resident User, you additionally have rights under CCPA / CPRA / VCDPA / CPA / CTDPA / UCPA:

To exercise these rights, contact privacy@pammo.co or use the in-app "Do Not Sell or Share My Personal Information" control. We do not currently "sell" or "share" your personal information for cross-context behavioral advertising except where you have opted in via §13B of the Main T&C.

7.6 Withdrawal of Consent — One-Click

You may withdraw any consent at any time using one-click in-app controls (Account → Privacy → "Withdraw consent") or by emailing dpo@pammo.co. Withdrawal mechanisms are at least as easy as the original consent action. We process valid withdrawal requests within 7 calendar days. Withdrawal does not affect the lawfulness of prior processing.


8. SECURITY

We implement administrative, technical, and physical safeguards consistent with industry standards and PDPA / GDPR / SG PDPA security requirements:

Full Technical and Organizational Measures (TOMs) are documented in Data Processing Addendum Annex II.


9. BREACH NOTIFICATION

In the event of a personal-data breach, we notify regulators and affected individuals in accordance with the following statutory clocks:

Jurisdiction Clock
Thailand PDPC (Thailand PDPA §39) + EU / EEA Supervisory Authority (GDPR Arts 33–34) 72 hours from awareness
Singapore PDPC (PDPA §§26B–26D + Notifiable Data Breaches Regulations 2021) 3 calendar days from credible assessment
UK ICO 72 hours per UK GDPR Art 33
U.S. state authorities Per applicable state breach-notification statutes

Affected individuals are notified where the breach is likely to result in significant harm or high risk to rights and freedoms.


10. COOKIES AND TRACKING

The Service uses cookies, local storage, and similar technologies as described in our Cookie Notice. Non-essential cookies — including analytics, retargeting, and the 60-day Affiliate / Creator / FGF attribution cookie — are set only with your affirmative consent via our cookie banner. We honor Global Privacy Control (GPC) and "Do Not Track" signals where legally required.


11. THIRD-PARTY LINKS

The Service may contain links to third-party websites or services (e.g., DDproperty, condominium-portal listings, embedded map services). We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy notices.


12. AUTOMATED DECISION-MAKING

We use automated processes for:

These do not produce legal effects on you without human review where required by GDPR Art 22. Affiliate / Creator commission decisions involving forfeiture, escrow hold, or termination are reviewed by Pammo staff before being finalized (per the 14-day challenge + 30-day mediation window in Pammo-Program-Rules-V1 §8.4).


13. CHILDREN

The Service is not directed to and may not be used by children under 13 in any circumstance. The minimum age is 18 or the local age of majority. See Main T&C §1.5 + §3.1 for full age-eligibility rules.


14. CHANGES TO THIS NOTICE

We may update this Privacy Notice from time to time. Material changes will be notified by email and in-app banner at least 30 days before they take effect; non-material clarifications take effect immediately upon posting. The "Last Updated" date at the top of this Notice reflects the most recent change. Prior versions are available on request to dpo@pammo.co.


15. CONTACT US

Data Protection Officer (DPO — joint controllers): dpo@pammo.co General Privacy Inquiries: privacy@pammo.co U.S. State Privacy Rights: privacy@pammo.co

Supervisory Authorities:

You may also lodge a complaint with the supervisory authority of your habitual residence or place of alleged infringement.


END OF PAMMO PRIVACY NOTICE — V1 (PUBLICATION-READY PENDING FINAL REVIEW) Last Updated: 2026-05-18