MedAi — Privacy Policy Version 2026-09-18 Source: https://meetmedai.com/privacy.html Generated from privacy.html by scripts/gen_legal_text.py. Do not hand-edit: edit the HTML and regenerate, or the copies fall out of step. Headings are marked ##, sub-headings ###, emphasis **bold**, list and table rows with a leading dash. =============================================================================== ENGLISH =============================================================================== **Local records, optional cloud scanning.** Medication records are stored on your device. When you choose AI scanning, the label photo leaves your device for processing by Google. A photo may contain identifying and health information. This notice explains how Varaporn Suwanthevarat, operating as MedAi in Thailand, processes data in the MedAi app and at meetmedai.com. Reading this notice is not consent to optional AI processing. ## 1. Controller and contact **Controller:** Varaporn Suwanthevarat (MedAi). **Contact address:** 39/642 Nichada-Thani, Raveevan, Samakee Road, Bang Talat, Pak Kret, Nonthaburi 11120, Thailand. **Email:** support@meetmedai.com. **Data protection officer.** We have assessed section 41 of the PDPA and have not appointed a DPO, on the basis that MedAi is operated by one person and does not process sensitive personal data on a large scale. We review this as the service grows, and will appoint and publish a DPO if that assessment changes. Privacy questions reach the controller at the address above. ## 2. Information and purposes - **Local health records:** medicine names, doses, schedules, course changes, allergies, notes, photos, stock and dose history support your chosen reminder and recordkeeping functions. Core records use AES-256-GCM encryption; saved medicine photos use ChaCha20-Poly1305 with a key derived from the local storage key. Keys are managed through the operating system’s secure storage. Settings and system alarm/display information are not all covered by this application-level encryption. Names and doses may appear in notifications and on the lock screen; manage their visibility in device settings. - **AI label photos:** after separate consent, the entire selected or captured label image and language are sent through Firebase Cloud Functions in the United States (us-central1) to Google’s Gemini API. The image itself may reveal your name, prescription, pharmacy, birth date or other identifiers. We do not automatically redact it. Cover unnecessary personal details before capture while keeping medicine instructions readable. We do not upload your saved medication list as part of a scan. Photos attached to saved records remain on your device until removed. - **Account and security:** Firebase Authentication creates a pseudonymous installation account. Its UID, App Check attestation and technical request information support access control, fraud prevention and scan quotas. A random UID does not make all associated data anonymous. These services can start before you use AI. - **Purchases:** Apple or Google handles payments. RevenueCat processes app-user identifiers, purchase and entitlement information; Firebase stores subscription status and scan counters. We do not receive your card number. Store and provider records have their own retention obligations. - **Updates and operations:** Shorebird distributes app patches. Providers may process app/build versions, operating-system information, device identifiers, IP addresses, timestamps and diagnostic information to deliver and secure their services. We do not promise that IP addresses are masked. - **Support and website:** if you email us, we receive your address and message. Avoid sending unnecessary medical information. Hosting and external font services may receive IP addresses and browser/request information. The website uses local storage for language and text-size preferences and session storage for navigation. - **Consent records:** the app stores the AI notice version, choice, language, time and age/guardian confirmation locally. A scan request includes the consent version. This is self-attestation, not identity verification. - **No analytics or advertising:** MedAi contains no advertising network, no analytics or attribution SDK and no behavioural tracking, and we do not sell or share personal data for advertising. The website sets no advertising or analytics cookies. The AI reads a label and returns a transcription for you to check; it is not used to profile you, score you, or make any decision about you. ## 3. Legal bases and your choices Optional cloud processing of health-related photos uses explicit consent under PDPA sections 19 and 26. Declining does not prevent manual medication entry or local reminders. Withdraw consent for future uploads in **Settings > Privacy > Withdraw AI photo consent**. This cannot recall requests already sent. Other processing necessary to provide requested services relies, where applicable, on contract performance; service security relies on legitimate interests, and required records on legal obligations. These bases do not replace the additional requirements for sensitive health data. ## 4. Providers and overseas processing Firebase/Google Cloud, Google Gemini, RevenueCat, Apple/Google stores, Shorebird and Zoho (which hosts our support mailbox) process the categories above. Cloud processing can take place outside Thailand, including the United States and other countries where providers operate. Their protections may differ from Thailand’s. The AI consent notice explains overseas processing; where transfer consent is relied upon, PDPA section 28(2) applies. Applicable processor agreements and other lawful safeguards must also be maintained; encryption alone is not a transfer mechanism. Provider information: Google privacy, Gemini terms, RevenueCat privacy, Shorebird privacy, Zoho privacy. ## 5. Retention and deletion Our scan function does not save image payloads or AI responses in a database, and prompt storage is switched off in our Google project for the API method the app calls, so no copy of your scan is kept there. This is separate from provider retention: Google documents **55-day retention** of prompts, context and outputs for abuse monitoring, with authorized review of flagged content. We use the paid tier, whose terms state that Google does not use prompts or responses to improve its products. See Google’s abuse-monitoring policy. We do not promise immediate erasure at every provider. Local records remain until you remove them. **Settings > Delete All Data** first attempts cloud account-data deletion and requires connectivity. If that fails, local records remain so you can retry. The app then removes reminders, photos, encryption keys and preferences and attempts Firebase account deletion. Partial failures are reported. Continuing to use the app may create a new pseudonymous account. Deletion does not cancel a store subscription or automatically erase provider security logs, purchase records, emails, or copies you saved elsewhere. Contact us for assistance with these records. Lawful retention beyond the periods in the table may continue only where a dispute or a statutory duty requires it, and only for as long as that reason lasts. Device backups and copies outside the app are controlled by the device owner and their provider; we cannot promise their removal through the app. The periods below apply. Where a period depends on a provider rather than on us, that is stated rather than implied. - **Data** — Retention period - **Medication records, schedules, dose history, allergies, photos, stock and your AI consent record** — Held on your device until you delete them or use Settings > Delete All Data. No automatic expiry. Finished courses move to History and remain until deleted from there. - **AI label image and the model’s response** — Not stored by us — prompt storage is disabled in our Google project. Google documents up to 55 days’ retention for its own abuse monitoring. - **Account record (pseudonymous UID, plan, monthly scan counter, subscription status)** — While the installation account exists; deleted when you use Delete All Data. - **Cloud Functions operational logs (timestamps, status codes, UID, IP)** — 30 days, the configured Google Cloud Logging period. - **Support email** — Held in our Zoho mailbox for as long as that mailbox exists. **We do not run an automatic deletion schedule for support mail**, so a message you send us stays until it is deleted by hand. You can ask us to delete your correspondence at any time under section 7, and we will do so within 30 days unless a legal obligation or an active dispute requires us to keep it. A deleted message may remain recoverable at Zoho for a short period set by that provider. - **Purchase and entitlement records at Apple, Google and RevenueCat** — Set by those providers under their own terms and accounting obligations; deleting your MedAi data does not remove them. **Change of operator.** If MedAi is transferred to a company or another operator, this notice and your choices transfer with it, and we will tell you before any change of controller takes effect. Where the law requires fresh consent, we must obtain it. ## 6. Security and incidents **Organisational measures.** MedAi is operated by one person, who is the only individual with access to the backend console and provider accounts. Those accounts use multi-factor authentication. No employee, contractor or support agent has access to your records, and we do not have any means of reading the medication data held on your device. Provider access is reviewed when the set of providers changes. We use encrypted core local storage, HTTPS transport, access controls and backend attestation. HTTPS is not end-to-end encryption against the processing provider: Google must process readable images. No system is risk-free. We assess suspected breaches and make required notifications to the PDPC and affected people under applicable law, including the applicable 72-hour regulatory notification requirement. ## 7. Your rights Subject to the PDPA’s conditions and exceptions, you may request access, correction, erasure, restriction, objection and portability, withdraw consent, or complain to the PDPC. You can view and edit local records in the app. Email support for other requests; we may request proportionate verification and will respond **within 30 days**, as section 30 of the PDPA requires, telling you if a permitted extension applies. We cannot retrieve local records that you have deleted. Privacy contact: Varaporn Suwanthevarat at the address and email above. You may also complain to the Office of the Personal Data Protection Committee (PDPC), 7th Floor, The Government Complex, Chaeng Watthana Road, Thung Song Hong, Lak Si, Bangkok 10210, Thailand — pdpc.or.th. ## 8. Age and updates Users under 20 who are not sui juris need the consent of the holder of parental power, as section 20 of the PDPA requires, together with their supervision in using the app. AI scanning is restricted to users who confirm they are at least 18; those aged 18–19 must also confirm guardian consent. This does not verify age. We do not intend AI scanning for children. If a child’s data has been submitted without appropriate authorization, contact us. When AI processing materially changes, the consent notice version will change and the app will ask again before uploading. Check this page for other notice updates. =============================================================================== ไทย (THAI) =============================================================================== **บันทึกในเครื่อง เลือกสแกนผ่านคลาวด์ได้** บันทึกยาอยู่ในอุปกรณ์ของคุณ หากเลือกสแกน AI รูปฉลากจะถูกส่งไปให้ Google ประมวลผล รูปอาจมีข้อมูลระบุตัวบุคคลและข้อมูลสุขภาพ นโยบายนี้อธิบายการใช้ข้อมูลโดยวราภรณ์ สุวรรณเทวรัตน์ ผู้ดำเนินงาน MedAi ในประเทศไทย สำหรับแอปและ meetmedai.com การอ่านนโยบายนี้ไม่ใช่การให้ความยินยอมใช้ AI ## 1. ผู้ควบคุมข้อมูลและช่องทางติดต่อ **ผู้ควบคุมข้อมูล:** วราภรณ์ สุวรรณเทวรัตน์ (MedAi) **ที่อยู่ติดต่อ:** 39/642 นิชดาธานี รวีวรรณ ถนนสามัคคี ตำบลบางตลาด อำเภอปากเกร็ด จังหวัดนนทบุรี 11120 ประเทศไทย **อีเมล:** support@meetmedai.com **เจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล** เราได้ประเมินตามมาตรา 41 แห่ง PDPA แล้ว และยังไม่ได้แต่งตั้ง DPO โดยเห็นว่า MedAi ดำเนินงานโดยบุคคลเดียวและไม่ได้ประมวลผลข้อมูลอ่อนไหวในขนาดใหญ่ เราจะทบทวนเมื่อบริการเติบโตขึ้น และจะแต่งตั้งพร้อมประกาศ DPO หากผลการประเมินเปลี่ยนไป คำถามด้านความเป็นส่วนตัวติดต่อผู้ควบคุมข้อมูลตามที่อยู่ข้างต้น ## 2. ข้อมูลและวัตถุประสงค์ - **ข้อมูลสุขภาพในเครื่อง:** ชื่อยา ขนาดยา ตาราง การเปลี่ยนแผน ประวัติแพ้ยา หมายเหตุ รูป จำนวนยาคงเหลือ และประวัติการกิน ใช้สำหรับบันทึกและเตือนตามที่คุณเลือก บันทึกหลักเข้ารหัส AES-256-GCM รูปยาที่บันทึกเข้ารหัส ChaCha20-Poly1305 ด้วยกุญแจที่สร้างจากกุญแจข้อมูลในเครื่อง กุญแจจัดการผ่านที่เก็บข้อมูลปลอดภัยของระบบปฏิบัติการ การตั้งค่าและข้อมูลที่ใช้แสดงการเตือนบางส่วนไม่ได้อยู่ภายใต้การเข้ารหัสระดับแอปนี้ ชื่อและขนาดยาอาจแสดงในการแจ้งเตือนหรือหน้าจอล็อก คุณจัดการการแสดงผลได้ในการตั้งค่าอุปกรณ์ - **รูปฉลากสำหรับ AI:** หลังให้ความยินยอมแยกต่างหาก รูปฉลากทั้งหมดและภาษาจะถูกส่งผ่าน Firebase Cloud Functions ในสหรัฐอเมริกา (us-central1) ไปยัง Gemini รูปอาจมีชื่อ ใบสั่งยา ร้านยา วันเกิด หรือข้อมูลอื่น เราไม่ปิดบังข้อมูลในรูปโดยอัตโนมัติ กรุณาปิดบังข้อมูลส่วนตัวที่ไม่จำเป็นก่อนถ่าย โดยคงคำสั่งใช้ยาให้อ่านได้ชัดเจน การสแกนไม่ส่งรายการยาที่บันทึกไว้ รูปที่แนบกับบันทึกยังอยู่ในเครื่องจนกว่าจะถูกลบ - **บัญชีและความปลอดภัย:** Firebase Authentication สร้างบัญชีด้วยรหัสนามแฝง UID ข้อมูลรับรอง App Check และข้อมูลคำขอทางเทคนิค ใช้ควบคุมสิทธิ ป้องกันการใช้ผิด และนับโควตาสแกน รหัสสุ่มไม่ได้ทำให้ข้อมูลทั้งหมดไม่ระบุตัวบุคคล บริการเหล่านี้อาจเริ่มทำงานก่อนใช้ AI - **การซื้อ:** Apple หรือ Google จัดการชำระเงิน RevenueCat ประมวลผลรหัสผู้ใช้ รายการซื้อและสิทธิสมาชิก Firebase เก็บสถานะสมาชิกและจำนวนสแกน เราไม่ได้รับหมายเลขบัตรของคุณ ผู้ให้บริการมีหน้าที่เก็บข้อมูลของตนเอง - **อัปเดตและการทำงาน:** Shorebird ส่งแพตช์แอป ผู้ให้บริการอาจใช้รุ่นแอป ระบบปฏิบัติการ รหัสอุปกรณ์ IP เวลา และข้อมูลวินิจฉัยเพื่อให้บริการและรักษาความปลอดภัย เราไม่รับรองว่า IP ถูกปิดบัง - **การติดต่อและเว็บไซต์:** หากส่งอีเมล เราได้รับอีเมลและข้อความของคุณ กรุณาไม่ส่งข้อมูลสุขภาพที่ไม่จำเป็น ผู้ให้บริการโฮสต์และฟอนต์ภายนอกอาจได้รับ IP และข้อมูลเบราว์เซอร์/คำขอ เว็บไซต์ใช้ local storage เก็บภาษาและขนาดตัวอักษร และ session storage สำหรับการนำทาง - **บันทึกความยินยอม:** แอปเก็บรุ่นคำอธิบาย ตัวเลือก ภาษา เวลา และการยืนยันอายุ/ผู้ปกครองในเครื่อง คำขอสแกนส่งรุ่นความยินยอมด้วย เป็นการยืนยันด้วยตนเอง ไม่ใช่การตรวจสอบตัวตน - **ไม่มีการวิเคราะห์การใช้งานหรือโฆษณา:** MedAi ไม่มีเครือข่ายโฆษณา ไม่มี SDK วิเคราะห์การใช้งานหรือติดตามที่มา และไม่มีการติดตามพฤติกรรม เราไม่ขายหรือแบ่งปันข้อมูลส่วนบุคคลเพื่อการโฆษณา เว็บไซต์ไม่ใช้คุกกี้โฆษณาหรือคุกกี้วิเคราะห์การใช้งาน AI อ่านฉลากและส่งคำถอดความกลับมาให้คุณตรวจสอบ ไม่ได้ใช้สร้างโปรไฟล์ ให้คะแนน หรือตัดสินใจใด ๆ เกี่ยวกับตัวคุณ ## 3. ฐานกฎหมายและทางเลือก การส่งรูปที่มีข้อมูลสุขภาพไปยัง AI เป็นทางเลือกและใช้ความยินยอมโดยชัดแจ้งตาม PDPA มาตรา 19 และ 26 การปฏิเสธไม่ขัดขวางการเพิ่มยาเองหรือการเตือนในเครื่อง ถอนความยินยอมสำหรับการส่งครั้งต่อไปได้ที่ **การตั้งค่า > ความเป็นส่วนตัว > ถอนความยินยอมการสแกน AI** ไม่สามารถเรียกคืนคำขอที่ส่งไปแล้ว การประมวลผลอื่นที่จำเป็นต่อบริการใช้ฐานสัญญาตามที่เกี่ยวข้อง ความปลอดภัยใช้ประโยชน์โดยชอบด้วยกฎหมาย และบันทึกที่กฎหมายกำหนดใช้ฐานหน้าที่ตามกฎหมาย ฐานเหล่านี้ไม่แทนข้อกำหนดเพิ่มเติมสำหรับข้อมูลสุขภาพอ่อนไหว ## 4. ผู้ให้บริการและการส่งต่างประเทศ Firebase/Google Cloud, Gemini, RevenueCat, ร้านค้า Apple/Google, Shorebird และ Zoho (ผู้ให้บริการอีเมลสนับสนุนของเรา) ประมวลผลข้อมูลตามข้างต้น ข้อมูลอาจถูกประมวลผลนอกประเทศไทย รวมถึงสหรัฐอเมริกาและประเทศที่ผู้ให้บริการดำเนินงาน การคุ้มครองอาจแตกต่างจากไทย คำอธิบายความยินยอม AI แจ้งการส่งต่างประเทศ หากใช้ฐานความยินยอมในการโอน ให้พิจารณามาตรา 28(2) ต้องจัดให้มีข้อตกลงผู้ประมวลผลและมาตรการที่ชอบด้วยกฎหมายตามที่เกี่ยวข้อง การเข้ารหัสเพียงอย่างเดียวไม่ใช่ฐานการโอน ข้อมูลผู้ให้บริการ: Google, Gemini, RevenueCat, Shorebird, Zoho ## 5. ระยะเวลาเก็บและการลบ ฟังก์ชันสแกนของเราไม่บันทึกรูปหรือผล AI ลงฐานข้อมูล และเราได้ปิดการจัดเก็บพรอมต์ในโปรเจกต์ Google ของเราสำหรับวิธีเรียก API ที่แอปใช้ จึงไม่มีสำเนาการสแกนของคุณเก็บไว้ที่นั่น แต่ผู้ให้บริการมีการเก็บต่างหาก Google ระบุว่าเก็บพรอมต์ บริบท และผลลัพธ์ **55 วัน** เพื่อตรวจสอบการละเมิดนโยบาย และเจ้าหน้าที่ที่ได้รับอนุญาตอาจตรวจข้อมูลที่ถูกตั้งข้อสังเกต เราใช้บริการแบบชำระเงิน ซึ่งเงื่อนไขระบุว่า Google จะไม่ใช้พรอมต์และผลลัพธ์เพื่อพัฒนาผลิตภัณฑ์ของ Google ดู นโยบายตรวจสอบการใช้งานของ Google เราไม่รับรองว่าผู้ให้บริการทุกรายลบทันที บันทึกในเครื่องอยู่จนกว่าจะลบ **การตั้งค่า > ลบข้อมูลทั้งหมด** พยายามลบข้อมูลบัญชีบนคลาวด์ก่อนและต้องใช้อินเทอร์เน็ต หากไม่สำเร็จ ข้อมูลในเครื่องยังอยู่เพื่อให้ลองใหม่ จากนั้นแอปลบการเตือน รูป กุญแจเข้ารหัส และการตั้งค่า แล้วพยายามลบบัญชี Firebase ระบบแจ้งหากลบได้บางส่วน การใช้งานต่ออาจสร้างบัญชีใหม่ การลบไม่ยกเลิกสมาชิกและไม่ลบบันทึกความปลอดภัยของผู้ให้บริการ รายการซื้อ อีเมล หรือสำเนาที่คุณเก็บไว้นอกแอปโดยอัตโนมัติ ติดต่อเราเพื่อขอความช่วยเหลือ การเก็บข้อมูลเกินระยะเวลาในตารางข้างต้นทำได้เฉพาะเมื่อมีข้อพิพาทหรือหน้าที่ตามกฎหมายกำหนด และเก็บเท่าที่เหตุนั้นยังคงอยู่ สำรองข้อมูลและสำเนานอกแอปอยู่ภายใต้การควบคุมของเจ้าของอุปกรณ์และผู้ให้บริการ เราไม่รับรองว่าแอปลบสำเนาเหล่านั้นได้ ระยะเวลาเก็บข้อมูลเป็นดังนี้ กรณีที่ระยะเวลาขึ้นกับผู้ให้บริการ ไม่ใช่เรา เราระบุไว้อย่างชัดเจน - **ข้อมูล** — ระยะเวลาเก็บ - **บันทึกยา ตาราง ประวัติการกิน ประวัติแพ้ยา รูป จำนวนคงเหลือ และบันทึกความยินยอม AI** — เก็บในอุปกรณ์ของคุณจนกว่าคุณจะลบ หรือใช้ การตั้งค่า > ลบข้อมูลทั้งหมด ไม่มีการหมดอายุอัตโนมัติ ยาที่กินครบแล้วจะย้ายไปที่ประวัติ และอยู่จนกว่าจะลบจากประวัติ - **รูปฉลากที่ส่งให้ AI และผลลัพธ์จากโมเดล** — เราไม่จัดเก็บ และปิดการจัดเก็บพรอมต์ในโปรเจกต์ Google ของเราแล้ว ส่วน Google ระบุการเก็บไม่เกิน 55 วันเพื่อตรวจสอบการใช้งานที่ละเมิดนโยบายของ Google เอง - **ข้อมูลบัญชี (รหัสนามแฝง แผน จำนวนสแกนรายเดือน สถานะสมาชิก)** — เก็บตราบที่บัญชียังอยู่ และลบเมื่อคุณใช้ ลบข้อมูลทั้งหมด - **บันทึกการทำงานของ Cloud Functions (เวลา รหัสสถานะ รหัสผู้ใช้ IP)** — 30 วัน ตามที่ตั้งค่าไว้ใน Google Cloud Logging - **อีเมลติดต่อ** — เก็บในกล่องจดหมาย Zoho ของเราตราบเท่าที่กล่องจดหมายนั้นยังอยู่ **เราไม่ได้ตั้งระบบลบอีเมลสนับสนุนโดยอัตโนมัติ** อีเมลที่คุณส่งมาจึงอยู่จนกว่าจะมีการลบด้วยตนเอง คุณขอให้เราลบอีเมลโต้ตอบของคุณเมื่อใดก็ได้ตามข้อ 7 และเราจะดำเนินการภายใน 30 วัน เว้นแต่มีหน้าที่ตามกฎหมายหรือข้อพิพาทที่ยังไม่ยุติซึ่งทำให้ต้องเก็บไว้ อีเมลที่ลบแล้วอาจยังกู้คืนได้ที่ Zoho ในช่วงเวลาสั้น ๆ ตามที่ผู้ให้บริการกำหนด - **รายการซื้อและสิทธิสมาชิกที่ Apple, Google และ RevenueCat** — เป็นไปตามเงื่อนไขและหน้าที่ทางบัญชีของผู้ให้บริการเหล่านั้น การลบข้อมูล MedAi ไม่ได้ลบรายการเหล่านี้ **การเปลี่ยนผู้ดำเนินงาน** หาก MedAi ถูกโอนไปยังบริษัทหรือผู้ดำเนินงานรายอื่น นโยบายนี้และตัวเลือกของคุณจะโอนไปด้วย และเราจะแจ้งคุณก่อนการเปลี่ยนผู้ควบคุมข้อมูลมีผล หากกฎหมายกำหนดให้ขอความยินยอมใหม่ เราต้องดำเนินการ ## 6. ความปลอดภัยและเหตุละเมิด **มาตรการเชิงองค์กร** MedAi ดำเนินงานโดยบุคคลเดียว ซึ่งเป็นผู้เดียวที่เข้าถึงระบบหลังบ้านและบัญชีผู้ให้บริการ บัญชีเหล่านั้นใช้การยืนยันตัวตนหลายขั้นตอน ไม่มีพนักงาน ผู้รับจ้าง หรือเจ้าหน้าที่สนับสนุนรายใดเข้าถึงข้อมูลของคุณ และเราไม่มีช่องทางอ่านข้อมูลยาที่เก็บอยู่ในอุปกรณ์ของคุณ สิทธิการเข้าถึงของผู้ให้บริการจะทบทวนเมื่อมีการเปลี่ยนผู้ให้บริการ เราใช้การเข้ารหัสบันทึกหลักในเครื่อง HTTPS การควบคุมสิทธิ และการรับรองคำขอ HTTPS ไม่ใช่การเข้ารหัสที่ซ่อนข้อมูลจากผู้ประมวลผล Google ต้องอ่านรูปเพื่อประมวลผล ไม่มีระบบใดปราศจากความเสี่ยง เราประเมินเหตุที่สงสัยและแจ้ง สคส. กับผู้ได้รับผลกระทบตามที่กฎหมายกำหนด รวมถึงข้อกำหนดการแจ้งหน่วยงานภายใน 72 ชั่วโมงที่เกี่ยวข้อง ## 7. สิทธิของคุณ ภายใต้เงื่อนไขและข้อยกเว้นของ PDPA คุณอาจขอเข้าถึง แก้ไข ลบ จำกัด คัดค้าน หรือโอนย้ายข้อมูล ถอนความยินยอม และร้องเรียนต่อ สคส. ดูและแก้ไขบันทึกในเครื่องผ่านแอป ติดต่ออีเมลสำหรับคำขออื่น เราอาจขอยืนยันตัวตนอย่างเหมาะสม และจะตอบ**ภายใน 30 วัน**ตามมาตรา 30 แห่ง PDPA โดยจะแจ้งหากมีการขยายเวลาตามที่กฎหมายอนุญาต เราไม่สามารถเรียกคืนข้อมูลในเครื่องที่ลบแล้ว ผู้ติดต่อความเป็นส่วนตัวคือวราภรณ์ สุวรรณเทวรัตน์ ตามที่อยู่และอีเมลข้างต้น คุณสามารถร้องเรียนต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส.) ชั้น 7 อาคารศูนย์ราชการฯ ถนนแจ้งวัฒนะ แขวงทุ่งสองห้อง เขตหลักสี่ กรุงเทพฯ 10210 — pdpc.or.th ## 8. อายุและการปรับปรุง ผู้ใช้อายุต่ำกว่า 20 ปีที่ยังไม่บรรลุนิติภาวะต้องได้รับความยินยอมจากผู้ใช้อำนาจปกครองตามมาตรา 20 แห่ง PDPA พร้อมการดูแลในการใช้งานแอป การสแกน AI จำกัดเฉพาะผู้ยืนยันว่าอายุอย่างน้อย 18 ปี ผู้มีอายุ 18–19 ปีต้องยืนยันความยินยอมของผู้ปกครองด้วย ระบบไม่ได้ตรวจสอบอายุ เราไม่ได้มุ่งให้เด็กใช้การสแกน AI หากมีการส่งข้อมูลเด็กโดยไม่ได้รับอนุญาตอย่างเหมาะสม กรุณาติดต่อเรา หากการประมวลผล AI เปลี่ยนสาระสำคัญ จะเปลี่ยนรุ่นคำอธิบายและขอความยินยอมใหม่ก่อนส่งรูป ดูการปรับปรุงอื่นได้ในหน้านี้