PAMMO — PRIVACY NOTICE
Version 1 — Publication-Ready Pending Final Review Last Updated: 2026-05-18 Effective Date: 15 June 2026
This Privacy Notice describes how Pammo — operated jointly by AEDOWON CO., LTD and AEDOWON SINGAPORE PTE. LTD. (UEN 202612161D) (together, "Pammo", "we", "us", "our") — collects, uses, discloses, retains, and protects your personal data when you access or use the Pammo AI property-workflow service (the "Service").
This Notice is provided in compliance with:
- The Personal Data Protection Act B.E. 2562 (2019) of the Kingdom of Thailand ("Thailand PDPA")
- The Personal Data Protection Act 2012 of the Republic of Singapore ("Singapore PDPA")
- The EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and UK GDPR / DPA 2018
- The California Consumer Privacy Act / California Privacy Rights Act ("CCPA / CPRA") and analogous U.S. state privacy laws (VCDPA, CPA, CTDPA, UCPA, etc.)
- Other applicable data-protection laws
PLAIN-LANGUAGE SUMMARY
- We are a dual-entity operation: a Thai company (AEDOWON CO., LTD) serves Thai residents; a Singapore company (AEDOWON SINGAPORE PTE. LTD., UEN 202612161D) serves everyone else. Together we act as joint data controllers for your account data.
- We collect what we need to provide the Service: account info, payment info, listings you create, audit logs, support correspondence, KYC for the Creator Program, and W-9 / W-8BEN for international Affiliate / Creator payouts.
- We share data only with Sub-Processors (AI providers, Omise, Polar.sh, Supabase, Resend, etc.) listed in our Sub-Processor List and only where necessary.
- You have rights to access, correct, delete, port, object, and withdraw consent — via Account → Privacy or dpo@pammo.co.
- We retain your data only as long as necessary, then delete or anonymize.
- We do not sell or share your personal data for cross-context behavioral advertising except where you have affirmatively opted in (per-network).
1. WHO WE ARE — JOINT CONTROLLERS
Pammo is operated under a dual-entity geo-routed structure (see Pammo-Terms-Conditions-Main-V1 §0):
| Entity | Role | Users | Payment Route |
|---|---|---|---|
| AEDOWON CO., LTD | Joint Controller (TH residents); contracting entity for Thai-Route Users | Thailand-resident Users | Omise |
| AEDOWON SINGAPORE PTE. LTD. (UEN 202612161D) | Joint Controller (Intl residents); contracting entity for International-Route Users; primary controller and primary DPO contact for the joint controllership | Non-Thailand-resident Users | Polar.sh (Merchant of Record) |
Joint-Controller Allocation. Both entities are joint controllers for:
- Account identity and authentication data
- Billing and payment-method metadata (tokenized references)
- Audit and security-event logs
- Compliance and fraud-prevention signals
- Communications with you (support, marketing under §13A/§13B, newsletter)
The entity that contracts with you under §0 of the Main T&C is the primary local-controller for tax-invoice, withholding-tax, refund, and consumer-protection purposes; the other entity is co-responsible under the joint-controller arrangement and bound by the same standard of care.
Primary DPO contact (single channel for both entities): dpo@pammo.co
Singapore registered office: AEDOWON SINGAPORE PTE. LTD. (UEN 202612161D), 8 TEMASEK BOULEVARD, #17-02A, SUNTEC TOWER THREE, SINGAPORE 038988
Thailand registered office: AEDOWON CO., LTD, 250/207 SOI BUDDHAMONDON SAI 2 SOI 32, SALATHAMMASOP, TAWEWATTANA, BANGKOK 10170, THAILAND
Pammo engages personnel located in various jurisdictions (Thailand, Singapore, and others) as authorized agents bound by confidentiality and the technical and organizational measures set out in our Data Processing Addendum.
2. WHAT PERSONAL DATA WE COLLECT
We collect the following categories of personal data:
2.1 Data You Provide Directly
| Category | Examples | When Collected |
|---|---|---|
| Account Identity | Name, email, password (hashed), date of birth, country of residence | At signup |
| Contact | Mobile phone, business name, brokerage / agency affiliation, license number (real-estate professionals) | At signup or upgrade |
| Billing | Payment-method tokens (Omise or Polar tokenization), billing address, Thai Tax ID or international tax ID, withholding-tax documents | At first paid subscription |
| Listing Inventory | Property data you upload — addresses, prices, photos, descriptions, condominium foreign-quota status (only as you supply) | When you create listings |
| User Input | Text prompts, images, audio, documents (title-deed photos for OCR), brand assets, contract drafts, audience / lead lists | When you use the Service |
| AI Output | Generated listing descriptions, ad copy, draft contracts, OCR extractions, matching results | When AI generates content for you |
| Creator Program KYC | Thai National ID image / international passport image, issuing authority, ID number, name, DOB, photo | If you apply to the Creator Program |
| Affiliate / Creator Tax Forms | W-9 / W-8BEN / W-8BEN-E, CRS / FATCA self-certification, TIN, bank / Wise / PayPal payout details | If you enroll as a non-SG/TH-resident Affiliate / Creator |
| Support Correspondence | Email content, in-app chat, screenshots you share | When you contact support |
| Marketing & Consent Preferences | Opt-in to marketing (§13A), per-network ad-platform opt-in (§13B), newsletter (§14) | At consent capture and updates |
2.2 Data Collected Automatically
| Category | Examples |
|---|---|
| Device / Technical | IP address, browser type, OS, device fingerprint hash, screen resolution, language |
| Usage Telemetry | Pages visited, features used, clicks, time spent, errors encountered, credits consumed |
| Cookies / Local Storage | Session ID, preferences, attribution cookies (see Cookie Notice) |
| Fraud-Detection Signals | Payment-method hash, email-domain match, IP / device patterns, conversion rates, velocity signals (per Anti-Fraud Rules AB1–AB7) |
| Quota & Billing Audit Trail | Credits used (general + Discovery), Extra Usage charges, Prepaid balance, Monthly Spending Limit triggers |
2.3 Data Collected from Third Parties
| Source | Data |
|---|---|
| Omise (Opn Payments) — TH Route | Payment authorization status, 3-D Secure result, chargeback notifications, withholding-tax codes |
| Polar.sh — International Route MoR | Payment authorization, tax-jurisdiction validation, chargeback coordination |
| Currenxie / Wise / PayPal — Payout rails (Affiliate / Creator) | Payout status, sanctions-screening result (from the payout provider's regulatory obligations) |
| Identity Verification — Creator KYC (currently manual review by Pammo personnel; third-party vendor TBD) | NID / passport verification results |
| Anti-Fraud Services — built-in screening of Omise / Polar / payout-rail providers | Risk scores, sanctions-list match |
| Advertising Platforms (with your consent) — Meta, Google, TikTok, LINE | Audience-list matching results, ad-attribution data |
2.4 Sensitive Personal Data
We do not require sensitive personal data for ordinary Service use. Where the Service processes sensitive data, we obtain your explicit consent:
(a) Creator NID / passport image (Thailand PDPA §26 sensitive category; Singapore PDPA Schedule 2 — physical-identification document) — collected with verbatim consent at Creator application; used only for identity verification, anti-fraud, and tax-residency confirmation per Pammo-Creator-Program-Terms-V1 §11.
(b) Sensitive data in Your Input or in Property Data you upload. Where User Input or uploaded Property Data contains sensitive data of third parties (e.g., health information of an occupant, religion-related preferences, biometric, criminal-record, political-opinion, sexual-orientation data), you represent that you have obtained the required explicit consent from those data subjects under Thailand PDPA §26, Singapore PDPA Schedule 2, and / or GDPR Art 9. You indemnify Pammo per Main T&C §16 against any claim arising from your failure to do so.
2.5 Children
Pammo is not directed to children under 13 and does not knowingly collect data from children under 13. The minimum age for the Service is 18 (or the higher local age of majority). Where mandatory parental consent permits use by minors (13–17) in specific jurisdictions, separate parental-consent collection applies.
3. WHY WE PROCESS YOUR DATA (PURPOSES AND LAWFUL BASES)
| Purpose | Lawful Basis |
|---|---|
| Create and operate your account | Contract performance (Thailand PDPA §24(3); Singapore PDPA §13; GDPR Art 6(1)(b)) |
| Bill you and process payments via Omise (TH) or Polar (Intl) | Contract performance |
| Deliver Service features (Chat-to-Listing, AI Chat Command, Discovery, OCR, Property Matching, Contract Auto-gen, PANNORA Co-Pilot) | Contract performance |
| Provide customer support | Contract performance |
| Detect fraud, prevent abuse, enforce the AUP and these Terms | Legitimate interests (GDPR Art 6(1)(f); Thailand PDPA §24(5)) + legal obligation |
| Comply with tax, accounting, AML, and sanctions obligations (Thai Revenue Code, SG Income Tax Act, AMLO, OFAC, etc.) | Legal obligation |
| Process Creator KYC (Thailand PDPA §26 sensitive category) | Explicit consent + legal obligation (Thai tax / AML) |
| Train / improve AI models on User Input or Output | Consent — opt-in only |
| Send marketing communications | Consent (per §13A) — opt-in only |
| Share behavioral / inferred-preference data with advertising platforms (Meta, Google, TikTok, LINE) | Consent (per §13B) — per-network opt-in only |
| Send newsletter | Consent (per §14) — opt-in only (double opt-in for EEA/UK) |
| Run FGF / Affiliate / Creator attribution and reward | Contract performance + legitimate interest (program operation) |
| Defend or pursue legal claims | Legitimate interests / legal obligation |
| Respond to data-subject-rights requests | Legal obligation |
4. WHO WE SHARE YOUR DATA WITH
4.1 Sub-Processors
We engage third-party Sub-Processors to operate the Service. A current list is published in our Sub-Processor List; broad categories include:
- AI model providers — Anthropic, OpenAI, Google (Gemini), Stability AI, Replicate, and successor providers
- Payment / payout processors — Omise (TH Route), Polar.sh (International Route MoR), Currenxie (international banking + Affiliate / Creator payouts), Wise (reserved future activation), PayPal (Affiliate / Creator payouts)
- Hosting / infrastructure — Supabase, Vercel, Cloudflare
- Email transport — Resend (transactional + transport for in-house marketing emails)
- LINE OA — broadcast (with consent for marketing)
- Customer support — Dabby (an AI chatbot operated by Pammo itself — internal tool, not a third-party Sub-Processor)
- Web-aggregation infrastructure for Property Discovery — bounded to Pammo's own infrastructure stack on Supabase + Vercel, no third-party scraping-as-a-service vendor at launch
We provide at least 30 days' prior notice before engaging any new material Sub-Processor, with a right of objection on reasonable grounds (per Main T&C §12.2A(d) + Pammo-Data-Processing-Addendum-V1 §7).
4.2 Advertising Networks (Opt-In Only)
Where you have affirmatively opted in via §13B of the Main T&C, we share behavioral / inferred-preference data with selected advertising networks on a per-network basis:
- Meta (Facebook / Instagram)
- Google (Google Ads / YouTube)
- TikTok
- LINE Ads
- Others listed in the Sub-Processor List
You may withdraw any of these per-network consents at any time via Account → Privacy → Ad-Network Sharing.
4.3 Legal / Regulatory Disclosures
We may disclose personal data:
- To comply with applicable law, court order, subpoena, or regulator request
- To the Thailand Personal Data Protection Committee (PDPC), the Singapore PDPC, EU supervisory authorities, the UK ICO, or US state AGs in response to lawful requests
- To protect rights, property, or safety of Pammo, our Users, or others
- To Thai Revenue Department, Singapore IRAS, Thai AMLO, US OFAC, EU FCA, UK OFSI, or other competent regulator for tax / AML / sanctions purposes
- In connection with merger, acquisition, sale of assets, or insolvency, subject to notice and successor-assumption-of-obligations per Main T&C
- To enforce or defend legal claims
4.4 What We Do NOT Do
- We do NOT sell personal data for monetary consideration.
- We do NOT share personal data for cross-context behavioral advertising as defined under CCPA / CPRA, VCDPA, CPA, CTDPA, or UCPA, except where you have affirmatively opted in (§4.2 above).
- We do NOT disclose your User Input or AI Output as identifiable to you without your consent, except as required by law.
- We do NOT train AI models on your User Input or AI Output without your separate opt-in consent (Account → Privacy → AI Training).
- We do NOT share Property Data you upload with competitors of Pammo.
5. WHERE YOUR DATA GOES (CROSS-BORDER TRANSFERS)
Your data may be transferred to and processed in jurisdictions outside your country of residence, including Singapore, Thailand, the United States, the European Union, the United Kingdom, Hong Kong, Japan, and other locations where our Sub-Processors operate.
Lawful transfer mechanisms (in order of preference):
(a) Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914) or by the Thailand PDPC — primary basis for routine recurring transfers;
(b) Adequacy decisions recognized by the Thailand PDPC or the European Commission;
(c) Binding Corporate Rules approved by the competent supervisory authority;
(d) Contract necessity for performance of your contract with us (Thailand PDPA §28 ¶2(3); GDPR Art 49(1)(b)) — used where SCC / adequacy is unavailable;
(e) Your explicit consent after being informed of the absence of adequate safeguards — last-resort basis only (Thailand PDPA §28 ¶2(2); GDPR Art 49(1)(a));
(f) Compliance with legal obligation, public interest, vital interests, or legal claims.
A current mapping of each Sub-Processor's jurisdiction and applicable safeguard is published in the Sub-Processor List.
6. HOW LONG WE KEEP YOUR DATA (RETENTION)
| Data Category | Retention Period |
|---|---|
| Account profile + billing identity | 24 months post-account-termination |
| User Input (listings, prompts, uploaded documents) and AI Output | 24 months post-account-termination, or earlier on User deletion request (subject to legal hold) |
| Service usage logs / telemetry | 12 months |
| Fraud-detection signals (IP, device fingerprint, payment-method hash, email-domain match, AB1–AB7 audit) | 24 months |
| Support tickets and correspondence | 36 months |
| Chargeback / dispute evidence | 7 years (regulatory minimum, both Thai Revenue Code and SG payment-services regulatory norms) |
| Marketing preferences and consent records | Duration of consent + 24 months post-withdrawal |
| Creator KYC NID / passport verification records | 24 months after Creator termination (longer where required by tax / fraud / sanctions / legal hold) |
| Affiliate / Creator tax-form records (W-9 / W-8BEN / withholding-tax certificates) | Minimum 7 years for tax-record-retention compliance |
| Accounting and tax records (Thai Revenue Code §87/3, Thai Accounting Act B.E. 2543 §14, Singapore Companies Act §199, Singapore Income Tax Act §67) | Minimum 5 years |
After the applicable retention period, personal data is securely deleted or irreversibly anonymized, with an audit trail.
7. YOUR RIGHTS
You have the following rights regarding your personal data:
7.1 Right Catalog
| Right | What It Means | Where It Lives in Law |
|---|---|---|
| Be informed | Know what data we collect and why | TH PDPA §23 · GDPR Art 13–14 · SG PDPA §20 |
| Access | Get a copy of your data | TH PDPA §30 · GDPR Art 15 · SG PDPA §21 |
| Portability | Receive your data in machine-readable format and transfer to another controller | TH PDPA §31 · GDPR Art 20 |
| Rectification | Correct inaccurate or incomplete data | TH PDPA §§35–36 · GDPR Art 16 |
| Erasure | Request deletion ("right to be forgotten") | TH PDPA §33 · GDPR Art 17 |
| Restriction | Limit processing in certain circumstances | TH PDPA §34 · GDPR Art 18 |
| Object | Object to processing based on legitimate interests or direct marketing | TH PDPA §32 · GDPR Art 21 |
| Withdraw consent | Withdraw any time (without affecting prior lawfulness) | TH PDPA §19 ¶5 · SG PDPA §16 · GDPR Art 7(3) |
| Complaint | Lodge complaint with supervisory authority | TH PDPC · SG PDPC · EU DPA · UK ICO · US state AG |
| No automated decisions | Not be subject to solely automated decision-making with legal effect | GDPR Art 22 |
7.2 How to Exercise Your Rights
Easiest method: Account → Privacy → "Manage My Data" — one-click controls for most rights.
Alternative: Email dpo@pammo.co with:
- Your full name and email associated with the account
- The right you wish to exercise
- Any relevant context (e.g., specific data to delete)
We may ask for additional verification to confirm your identity.
7.3 Response Timeline
We respond to verified requests within 30 calendar days of receipt, extendable by a further 60 days for complex or high-volume requests (with prior notice and reasons given within the original 30-day period). This is in accordance with Thailand PDPA §32, Singapore PDPA §21(2), and GDPR Art 12(3).
7.4 No Charge
We respond to data-subject requests free of charge, except where requests are manifestly unfounded, excessive, or repetitive — in which case we may charge a reasonable administrative fee or refuse.
7.5 U.S. State Privacy Rights
If you are a U.S.-resident User, you additionally have rights under CCPA / CPRA / VCDPA / CPA / CTDPA / UCPA:
- Right to know the categories and specific pieces of personal information we collect, sell, or share
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt out of any future "sale" or "sharing" for cross-context behavioral advertising
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising privacy rights
To exercise these rights, contact privacy@pammo.co or use the in-app "Do Not Sell or Share My Personal Information" control. We do not currently "sell" or "share" your personal information for cross-context behavioral advertising except where you have opted in via §13B of the Main T&C.
7.6 Withdrawal of Consent — One-Click
You may withdraw any consent at any time using one-click in-app controls (Account → Privacy → "Withdraw consent") or by emailing dpo@pammo.co. Withdrawal mechanisms are at least as easy as the original consent action. We process valid withdrawal requests within 7 calendar days. Withdrawal does not affect the lawfulness of prior processing.
8. SECURITY
We implement administrative, technical, and physical safeguards consistent with industry standards and PDPA / GDPR / SG PDPA security requirements:
- Encryption of personal data at rest (AES-256 or equivalent) and in transit (TLS 1.2+, TLS 1.3 preferred)
- Role-based access control with least-privilege grants and quarterly access review
- Multi-factor authentication for all administrative, production, payment, and DPO tooling
- Logging of security-relevant events for at least 12 months
- Backup with tested restore (quarterly minimum)
- Vendor risk management for Sub-Processors (annual review + 30-day prior-notice on additions)
- Documented incident-response procedure
- Periodic security audits and penetration testing
Full Technical and Organizational Measures (TOMs) are documented in Data Processing Addendum Annex II.
9. BREACH NOTIFICATION
In the event of a personal-data breach, we notify regulators and affected individuals in accordance with the following statutory clocks:
| Jurisdiction | Clock |
|---|---|
| Thailand PDPC (Thailand PDPA §39) + EU / EEA Supervisory Authority (GDPR Arts 33–34) | 72 hours from awareness |
| Singapore PDPC (PDPA §§26B–26D + Notifiable Data Breaches Regulations 2021) | 3 calendar days from credible assessment |
| UK ICO | 72 hours per UK GDPR Art 33 |
| U.S. state authorities | Per applicable state breach-notification statutes |
Affected individuals are notified where the breach is likely to result in significant harm or high risk to rights and freedoms.
10. COOKIES AND TRACKING
The Service uses cookies, local storage, and similar technologies as described in our Cookie Notice. Non-essential cookies — including analytics, retargeting, and the 60-day Affiliate / Creator / FGF attribution cookie — are set only with your affirmative consent via our cookie banner. We honor Global Privacy Control (GPC) and "Do Not Track" signals where legally required.
11. THIRD-PARTY LINKS
The Service may contain links to third-party websites or services (e.g., DDproperty, condominium-portal listings, embedded map services). We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy notices.
12. AUTOMATED DECISION-MAKING
We use automated processes for:
- Fraud detection (cohort fraud monitoring, IP / device matching, anomalous-pattern flagging — AB1–AB7)
- Affiliate tier promotion (automated lifetime-referral-count threshold check per Pammo-Program-Rules-V1 §4.4)
- Credit allocation (monthly reset on the 1st at 00:00 ICT; signup-anchored drip for Yearly plans)
- Property Matching (vector-search ranking)
- Cohort fraud monitor (5% threshold over 20-active-cohort floor)
These do not produce legal effects on you without human review where required by GDPR Art 22. Affiliate / Creator commission decisions involving forfeiture, escrow hold, or termination are reviewed by Pammo staff before being finalized (per the 14-day challenge + 30-day mediation window in Pammo-Program-Rules-V1 §8.4).
13. CHILDREN
The Service is not directed to and may not be used by children under 13 in any circumstance. The minimum age is 18 or the local age of majority. See Main T&C §1.5 + §3.1 for full age-eligibility rules.
14. CHANGES TO THIS NOTICE
We may update this Privacy Notice from time to time. Material changes will be notified by email and in-app banner at least 30 days before they take effect; non-material clarifications take effect immediately upon posting. The "Last Updated" date at the top of this Notice reflects the most recent change. Prior versions are available on request to dpo@pammo.co.
15. CONTACT US
Data Protection Officer (DPO — joint controllers): dpo@pammo.co General Privacy Inquiries: privacy@pammo.co U.S. State Privacy Rights: privacy@pammo.co
Supervisory Authorities:
- Thailand: Personal Data Protection Committee (PDPC), Ministry of Digital Economy and Society — pdpc.or.th
- Singapore: Personal Data Protection Commission of Singapore — pdpc.gov.sg
- EU / EEA: your local Data Protection Authority
- UK: Information Commissioner's Office (ICO) — ico.org.uk
You may also lodge a complaint with the supervisory authority of your habitual residence or place of alleged infringement.
END OF PAMMO PRIVACY NOTICE — V1 (PUBLICATION-READY PENDING FINAL REVIEW) Last Updated: 2026-05-18