Legal · Privacy policy

Your data, handled with care.

นโยบายความเป็นส่วนตัว

This page explains what we collect when you visit kaliberstudios.com or work with us, why we collect it, and the rights you have under Thailand's Personal Data Protection Act and, if you are in Europe or the UK, the GDPR. No legalese where plain words will do.

Last updated
22 September 2026
Version
v1.0 · 9 min read
Data controller
Kaliber Studios Co. Ltd.
Questions
sayhi@kaliberstudios.com
01

Who we are

In short
We are a small studio in Thailand. When you give us your details, we are the ones responsible for them, under Thai law and, for people in Europe and the UK, under the GDPR.

Kaliber Studios Co. Ltd. is a creative and digital product studio registered in Thailand, with its office at 18/8 Bang Bao Plaza, Koh Chang, Trat 23170, Thailand. Under the Personal Data Protection Act B.E. 2562 (2019), usually called the PDPA, we are the data controller for the personal data described on this page.

Because we offer our services to people and businesses in the European Union, the European Economic Area and the United Kingdom, the EU General Data Protection Regulation and the UK GDPR also apply to how we treat their data. Where those laws give you more than the PDPA does, you get the more.

Chris Mihelic, our Creative Director, looks after data protection questions. You can reach him at the email address at the bottom of this page. We are not required to appoint a data protection officer.

02

What we collect

In short
Only what you type into our contact form, what you send us while we work together, and the usual technical basics every website sees.

When you use the contact form we receive what you enter: your name, email address, phone number (with country code, if you choose to be contacted by WhatsApp, LINE or a call), how you prefer to be contacted, what you need help with, your budget range if you give one, and your message. While you fill in the form your draft is kept in your own browser's session storage, so it survives a reload; it is cleared when the brief is sent or the tab is closed.

If we go on to work together we will also hold the information needed to run the project: your company details, invoices, contracts, project files, feedback and correspondence.

When you visit the site our hosting provider records technical data such as your IP address, browser and device type, the pages you open, the site that referred you, and approximate location derived from your IP address. This is used in aggregate to keep the site running and to understand how it is used.

Please do not send us sensitive personal data (health, religion, political opinions, biometric data, criminal records and the like). We do not ask for it and we would rather not hold it.

03

Why we use it, and the legal basis

In short
To answer you, to do the work you hire us for, to keep the lights on, and because Thai tax law makes us keep records.

The PDPA and the GDPR both require us to have a lawful basis for each use of your personal data. Ours are:

  • Contract, or steps before one (GDPR Art. 6(1)(b)): replying to your enquiry, preparing proposals, delivering the project and invoicing it.
  • Legitimate interests (Art. 6(1)(f)): keeping the site secure, understanding how it is used through aggregated statistics, improving our services, and managing our client relationships, always balanced against your rights.
  • Legal obligation (Art. 6(1)(c)): keeping accounting and tax records for the periods required by Thai law, and responding to lawful requests from authorities.
  • Consent (Art. 6(1)(a)): sending you occasional studio news, or setting any non-essential cookies. Where we rely on consent you can withdraw it at any time.

We do not use your data for automated decision-making or profiling, and we never sell it.

04

Cookies and analytics

In short
The site sets no cookies. Two small values live in your browser to run the site itself, and visitor counts are anonymous. No advertising networks, so no cookie banner.

The site is built and hosted on Framer. As published, it sets no cookies. Framer's visitor statistics are collected without cookies and without identifying you, and are shown to us only in aggregate. Fonts are served from Framer's own servers, so no font provider sees your visit.

Two small values are stored in your browser by the site itself: one remembers that you have already seen the opening animation, so it does not play again for thirty days, and one carries the page transition from one page to the next within your visit. Neither identifies you or leaves your device, and both fall within the strictly necessary exception, which is why there is no cookie banner.

If we ever add tools that do use cookies or similar tracking, such as advertising pixels, embedded video or a chat widget, we will ask for your consent before they load and update this section.

05

Who we share it with

In short
The services that make the studio run, and only what each one needs. Nobody buys your data from us.

We share personal data with a small set of service providers who process it on our instructions and under written data-processing terms:

  • Framer, which hosts the website.
  • Web3Forms, which delivers contact-form submissions to our inbox.
  • Our email, cloud storage, design and project tools (for example Google Workspace and Figma).
  • WhatsApp or LINE, if you asked to be contacted there.
  • Our accountant, bank and legal advisers, where needed to run the business.
  • Freelance collaborators we bring into your project, who sign confidentiality terms and see only what the work requires.

We may also disclose data when Thai law or a law that applies to you requires it, or to protect our rights, our clients or the public.

06

Transfers between countries

In short
We are in Thailand and some of our tools are in the US. Data moving out of Europe or the UK is covered by standard contractual clauses, or by the contract we have with you.

We are based in Thailand, and several of the providers above run their servers in the United States or elsewhere. Personal data therefore crosses borders in two directions.

Data leaving Thailand: we rely on the conditions the PDPA allows. The destination has adequate data protection standards, the transfer is needed to perform our contract with you, appropriate safeguards such as contractual protections are in place, or you have consented.

Data leaving the EU, EEA or UK: Thailand and the United States are not covered by an adequacy decision, so these transfers rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) in our agreements with our providers, and, for the data you send directly to us, on the fact that the transfer is necessary to perform the contract between us or to take steps at your request before entering into one (GDPR Art. 49(1)(b)). You can ask us for a copy of the safeguards we rely on.

07

How long we keep it

In short
Enquiries: about a year. Client records: the project plus the years Thai tax law requires. Then it goes.
  • Enquiries that do not lead to a project: up to 12 months from our last exchange, so we can pick the conversation back up if you return.
  • Client records, contracts and invoices: for the life of the project and then for the period required by Thai accounting and tax law, generally at least five years from the end of the relevant financial year.
  • Project files and design work: as long as needed to support you and to keep our portfolio accurate, unless you ask us to delete them earlier.
  • Marketing contact details: until you unsubscribe or ask us to stop.
  • Technical logs: short periods set by our hosting provider.

When data is no longer needed we delete it or anonymise it so it can no longer identify you.

08

Keeping it safe

In short
Encryption in transit, two-factor logins, access on a need-to-know basis. If something goes wrong, we tell you and the regulator.

The site is served over HTTPS, our accounts use two-factor authentication, and only the people working on your project can see your data. No method of storage or transmission is completely secure, so we cannot promise absolute safety, but we take reasonable measures and review them.

If a data breach is likely to affect your rights, we will notify the Office of the Personal Data Protection Committee in Thailand within 72 hours of becoming aware of it, notify the relevant European or UK supervisory authority within the same 72 hours where the GDPR applies, and tell you without undue delay.

09

Your rights

In short
See it, copy it, fix it, move it, limit it, delete it, or object to it. Email us and we will act within 30 days.

Under the PDPA and the GDPR you have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Have it corrected if it is inaccurate or incomplete.
  • Receive it in a commonly used, machine-readable format, or have it sent to another controller where technically possible.
  • Object to processing based on legitimate interests, and to direct marketing at any time.
  • Ask us to delete, destroy or anonymise it.
  • Ask us to restrict how we use it.
  • Withdraw any consent you have given, without affecting what was done before you withdrew it.
  • Not be subject to decisions based solely on automated processing (we make none).
  • Lodge a complaint with a regulator: in Thailand the Office of the Personal Data Protection Committee (PDPC); in the EU or EEA the supervisory authority of the country you live or work in, for example AZOP in Croatia or the AEPD in Spain; in the UK the Information Commissioner's Office (ICO).

To use any of these rights, email us. We may need to confirm your identity first. We aim to respond within 30 days (the GDPR allows one month, extendable in complex cases, and we will tell you if we need longer) and there is no charge unless a request is clearly excessive.

10

If you are in the EU, EEA or UK

In short
The GDPR applies to you in full. Here is the extra detail it asks us to give, in one place.

Controller: the company named at the top of this page, contactable through the details at the bottom. We have not appointed a representative in the EU or the UK under Article 27, because our processing of European and UK data is occasional, does not involve special categories of data on any scale, and is unlikely to put your rights at risk. We will appoint one if that changes.

What we process and why is set out above; the lawful basis for each purpose is listed in the section on why we use it. The only source of your data is you, and the people you authorise to write to us on your behalf.

Providing your details is not a legal requirement, but we cannot reply to an enquiry or run a project without a name and a way to reach you.

Transfers outside the EU, EEA and UK, and the safeguards we rely on, are described in the section on transfers between countries. Your rights, and where to complain, are in the section above.

11

Children

In short
The studio works with businesses. We do not knowingly collect data from anyone under 20 without a parent or guardian.

Our services are aimed at businesses and adults. Thailand's age of majority is 20, and we do not knowingly collect personal data from anyone younger without the consent of a parent or legal guardian where the PDPA requires it; in Europe and the UK we apply the same rule to anyone under 16. If you believe a minor has sent us their data, tell us and we will remove it.

12

Changes to this policy

In short
When it changes, the date at the top changes. Big changes get a note on the site.

We may update this policy as the studio, the law or our tools change. The version and date at the top of the page tell you when it was last revised. If a change materially affects how we use your data we will say so on the site or contact you directly.

Talk to a human

Questions about your data, or a request to exercise a right? Write to us. A person reads every message.

Kaliber Studios Co. Ltd.
18/8 Bang Bao Plaza, Koh Chang, Trat 23170, Thailand
sayhi@kaliberstudios.com

Create a free website with Framer, the website builder loved by startups, designers and agencies.