Overview
This Privacy Policy explains how kalimiora collects, uses, discloses and protects personal data when providing legal services to businesses and their representatives. It applies to visitors and clients who interact with our website kalimiora.pro, engage our services, or communicate with our team. We document processing activities to maintain accountability and to support lawful, transparent handling of personal data in line with applicable Thai law and relevant international norms.
Key definitions
For clarity, the following terms are used in this policy: personal data means any information relating to an identifiable individual; processing covers any use of data; controller refers to kalimiora when we determine how and why data is processed; service means the legal and advisory services we provide to business clients.
What data we collect
We collect data necessary to deliver legal services, comply with professional obligations, and communicate with clients. Collection is limited to information required for the specific service or regulatory requirement.
Data you provide directly
Information supplied voluntarily during engagement or correspondence, required to perform legal work and to meet compliance checks.
- Contact details and professional identity: full name, work email, business phone number, job title and employer information.
- Company and registration details: business registration number, registered address, tax identification where necessary for compliance and filings.
- Case materials and documents: contracts, corporate minutes, commercial agreements, transaction records and other documents needed to provide legal advice.
- Verification information: copies of identification documents, proof of authority or power of attorney when required by law or to establish client identity.
- Communications and instructions: emails, meeting notes, engagement letters and documented instructions relevant to the provision of services.
- Billing and payment information: invoicing details, corporate billing instructions and other data required to process payments and maintain business records.
Data collected automatically
When you visit kalimiora.pro, we collect technical and usage information needed to operate and secure the site and to understand service use trends.
- Device and browser information such as IP address (may be pseudonymised immediately), browser type and version, and operating system.
- Usage data including pages visited, time spent on pages, navigation paths and interactions with site features for analytics and performance improvement.
- Referral and campaign data indicating how visitors arrive at the site, useful for legitimate marketing and performance measurement.
- Cookie identifiers and similar local storage vouchers used to remember preferences and session state.
- Security logs and access records maintained to detect and contribute unauthorized access attempts and to protect client records.
- Error reports and diagnostic data captured when faults or exceptions occur on the site to aid troubleshooting and service reliability.
Third-party sources
We may receive data about you from third parties when necessary for service delivery, vetting or to comply with a legal process. Such sources are used only for legitimate, documented purposes.
- Professional intermediaries and legal representatives who submit documents or communications on behalf of a client.
- Public registers and corporate databases used to verify company registration and director details as part of due diligence.
- Payment processors and management partners that provide transactional data required for billing and recordkeeping.
Purposes of processing
We process personal data for specific operational, regulatory and contractual reasons aligned to the services we provide. Processing is limited to what is necessary for each purpose.
- To deliver legal advice, draft and manage contracts, and perform tasks expressly requested by our clients.
- To verify client identity and conduct due diligence required by professional and regulatory obligations.
- To communicate with clients and prospective clients regarding service delivery, engagement status and administrative matters.
- To manage billing, collect fees, and maintain accurate business records for audits and tax compliance.
- To improve our website, perform analytics, and maintain security and operational stability of kalimiora.pro.
- To respond to legal requests, protect legal rights, and cooperate with lawful contribute or regulatory authorities when required.
- To store client records in accordance with professional retention obligations and to maintain historical case files necessary for ongoing representation.
- To provide training and quality oversight within kalimiora, using de-identified material where practicable to protect privacy.
Lawful bases for processing
We rely on one or more lawful bases for processing personal data depending on the activity. Those bases may include performance of a contract, compliance with legal obligations, legitimate interests and consent where required.
- Performance of a contract: processing necessary to provide contracted legal services and to carry out client instructions.
- Legal obligation: processing required to comply with applicable laws, professional rules and regulatory reporting requirements.
- Legitimate interests: processing for security, fraud prevention, business administration and improvement of our services when these interests are not overridden by individual rights.
- Consent: where we rely on consent for specific marketing communications or optional processing, individuals may withdraw consent at any time.
Data subject rights and international standards
Although kalimiora is based in Thailand, we recognize internationally recognised data subject rights and provide mechanisms to exercise rights where applicable to the services we deliver and to the extent required by law.
- Access: request a copy of personal data we hold about you and information about processing activities.
- Rectification: request correction of inaccurate or incomplete personal data.
- Erasure: request deletion of personal data where retention is no longer necessary and processing is not required by law.
- Restriction and objection: request limits on processing or object to processing on grounds relating to your particular situation where relevant.
- Data portability: where technically feasible, request a structured, commonly used, machine-readable copy of data you provided.
- Complaint rights: the right to lodge a complaint with a supervisory authority if you consider our processing is not lawful.
Data sharing and disclosure
We disclose personal data only for the purposes described in this policy and under appropriate safeguards. Sharing is limited to necessary recipients and governed by contractual, legal or professional requirements.
- Service providers: third parties engaged to perform processing on our behalf, such as secure hosting, analytics providers and payment processors, under data processing agreements.
- Professional advisors: external consultants, auditors or legal advisers engaged for compliance, quality assurance or specialized advice.
- Regulatory and law enforcement authorities when disclosure is required by law, court order or to respond to lawful requests.
- Counterparties and advisors in the context of a specific matter where disclosure is necessary to represent a client or to negotiate and execute transactions.
- Acquirers or supporter in the event of a merger, acquisition or sale of business assets, subject to confidentiality protections and due diligence safeguards.
- Aggregated or anonymized information that cannot reasonably be used to identify an individual and that we may use for reporting or service improvement.
International data transfers
Personal data may be transferred to jurisdictions outside Thailand in the course of delivering services or using global service providers. Transfers are conducted with appropriate contractual and technical safeguards to protect data subject rights.
When we transfer personal data internationally we implement safeguards such as contractual clauses, data processing agreements and technical protections. Transfers are assessed on a case-by-case basis to maintain an adequate level of protection.
Data retention
We retain personal data only for as long as necessary to fulfill the purposes set out in this policy, to comply with legal and professional retention obligations, and to defend or exercise legal claims.
Client account information and engagement records are retained for the period required by professional conduct rules and tax regulations, typically several years following the end of an engagement.
Communications and correspondence are retained for the duration necessary to manage matters effectively and to meet record-keeping obligations; retention periods vary by matter and legal requirement.
Security logs, access records and diagnostic data are retained for a limited period necessary for incident contribute and service maintenance, after which logs are archived or deleted.
When retention periods expire or when deletion is requested and permitted by applicable law, personal data is securely deleted or anonymized in accordance with documented procedures.
Security measures
kalimiora implements administrative, technical and physical safeguards to protect personal data against unauthorized access, disclosure, alteration and destruction. Security measures are regularly reviewed to reflect risk and technology changes.
- Access control and role-based permissions limiting access to client data to personnel with a documented need.
- Encryption of data in transit and at rest where appropriate, and secure storage of sensitive documents.
- Regular backups, vulnerability assessments and incident response procedures to detect, contain and remediate security events.
Your rights
You may exercise the rights described in this policy by contacting us. We will respond in a timely manner and provide guidance on required identity verification and the scope of any request.
- Right to access: request confirmation of whether we process your personal data and obtain a copy of such data.
- Right to rectification: request correction of inaccurate or incomplete personal data we hold.
- Right to erasure and restriction: request deletion or limitation of processing where legally permitted and not contrary to retention obligations.
- Right to object and opt-out: object to certain types of processing including direct marketing and withdraw consent where previously given.
- How to exercise rights: contact kalimiora at the address or email below with sufficient details to process your request; we may require identity verification to protect privacy.
- Right to data portability: receive a copy of the personal data you provided in a structured, commonly used and machine-readable format when applicable.
- Right to restrict processing: request limitation of processing of your personal data while a dispute about accuracy or lawfulness is resolved.
- Right to lodge a complaint with a supervisory authority in Thailand if you believe your data protection rights have been breached.
Exercising your privacy rights
To exercise any of the privacy rights described here, submit a written request through the contact form on kalimiora.pro or by post to our office at Thanon Pattaya Sai Song, Na Kluea Sub District, Amphoe Bang Lamung District, Chon Buri Province 20150, Thailand. Include sufficient details to identify yourself, the specific right you are invoking, and documents verifying your identity and authority if you act on behalf of a business. Where appropriate, provide examples of the personal data and the processing activity you wish to address.
We aim to acknowledge receipt of valid requests promptly and provide a substantive response within 30 calendar days. Complex requests or those requiring verification may take up to 60 calendar days. If we need additional time or information we will inform you of reasons for the delay and expected timeline.
Marketing communications
We may send information about services, events, and publications relevant to business legal needs where we have a lawful basis to do so. Where required by law we rely on consent; otherwise communications are based on our legitimate interest in offering legal services to businesses in Thailand. Marketing messages will clearly indicate the sender and the reason you received the communication.
To stop receiving marketing communications, use the unsubscribe link in any electronic message from kalimiora, adjust your preferences via the contact form at kalimiora.pro, or contact us by phone at +66986389781. We will process opt-out requests without undue delay.
Children's data
Our services are designed for businesses and adult representatives. We do not knowingly collect personal data of children under 18. If we become aware that we have collected such data inadvertently, we will take steps to delete it promptly upon verification and notification.
Third-party links
Our website may contain links to third-party websites, services, and legal resources. Those third parties operate under their own privacy policies and kalimiora is not responsible for their content, practices, or compliance. We recommend reviewing third-party privacy notices before providing personal information.
Changes to this privacy policy
We periodically update this privacy policy to reflect operational, legal, or regulatory changes. The effective date is indicated at the top of the policy. Material changes will be posted on kalimiora.pro and, where appropriate, notified to affected contacts using available contact information.