Legal
Privacy Policy
How we handle personal data when you browse this site, create an account, contact us, or subscribe to managed SOC monitoring. Last updated: 6 August 2026.
Who we are
SOCGuard (“we”, “us”) provides managed Security Operations Center (SOC) and related cybersecurity monitoring services for businesses in Thailand, Singapore, and other regions. For privacy requests, email [email protected] or use our contact page.
Personal data we collect
- Identity and contact: name, job title, company, email, phone, billing address, and tax identifiers you provide for invoicing.
- Account data: login email, password hash, email verification status, and account activity needed to operate customer billing.
- Orders and billing: selected plan/edition, endpoint quantity, region, payment method references, Stripe customer/subscription identifiers, and invoices.
- Service scoping notes: asset counts, cloud tenants, escalation contacts, and technical details you choose to share so we can onboard monitoring.
- Security telemetry (customers only): endpoint, identity, cloud, and related security logs necessary to deliver the subscribed SOC service, processed as a service provider for your organisation.
- Website usage: IP address, browser type, pages viewed, preferred region cookie, and similar technical data (see Cookies).
Why we use your data
We process personal data to provide quotes and assessments, create and manage accounts, process payments, deliver monitoring and reporting, send service notices, prevent fraud, meet tax and accounting duties, and improve the website. Depending on your location, this is based on your consent, performance of a contract, compliance with law, and other lawful grounds recognised under the Thailand PDPA and the Singapore PDPA (such as legitimate interests where permitted).
Thailand PDPA
If you are in Thailand, the Personal Data Protection Act B.E. 2562 (PDPA) applies. We collect and use personal data for lawful purposes, take appropriate security measures, and honour access, correction, and other rights where applicable. Where consent is required (for example certain marketing), we will ask clearly and you may withdraw consent without affecting services already contracted.
Singapore PDPA
If you are in Singapore, the Personal Data Protection Act 2012 applies. We follow PDPC obligations including consent, purpose limitation, notification, access and correction, protection, and retention limitation. Contact us through the channels above for data protection requests.
Customer security telemetry
When you subscribe, we process security telemetry from systems you authorise (for example endpoints, Microsoft 365 / Entra ID, servers, and cloud workloads in scope). That telemetry may include identifiers such as hostnames, usernames, IP addresses, and file paths necessary for detection and investigation.
We process this data to provide the SOC service to your organisation. You remain responsible for informing your employees and users as required by applicable law and for configuring what systems are in scope. We do not sell telemetry or use it to advertise to your end users.
How we share personal data
We do not sell personal information. We share data only as needed to operate:
- Payment processors (including Stripe): to take payment, manage subscriptions, and prevent fraud under their privacy notices.
- Infrastructure and email providers: hosting, transactional email, and (if enabled) analytics.
- Subprocessors assisting monitoring or support: under contract and only for delivering the service.
- Professional advisers: accountants or lawyers when required for compliance or disputes.
- Authorities: when required by law, court order, or to protect legal rights.
International transfers
Our primary operations are in Thailand. Some providers (for example Stripe or cloud hosting) may process data outside Thailand or Singapore, including the United States or the European Union. Where required, we rely on appropriate safeguards such as contractual clauses or your agreement as part of placing an order.
Data retention
- Sales, invoicing, and tax records: typically at least five (5) years, or longer if required by law or audit.
- Account and subscription records: for the service term plus up to twenty-four (24) months after the last order or support request, unless longer retention is needed for disputes or law.
- Security telemetry and investigation artefacts: retained according to your edition and our operational playbooks, generally only as long as needed for detection, response, reporting, and contractual obligations.
- Website logs and analytics: typically up to thirteen (13) months, then aggregated or deleted.
Your rights
Depending on where you live, you may have rights to access, correct, delete (subject to legal retention), object to or restrict certain processing, and withdraw marketing consent. You may also lodge a complaint with the Office of the Personal Data Protection Committee (Thailand) or the Personal Data Protection Commission (Singapore).
To exercise rights, email [email protected] with enough detail for us to verify your identity. We aim to respond within thirty (30) days, or explain any permitted extension.
Cookies and similar technologies
- Strictly necessary: session, security, and region preference cookies needed to operate the site and checkout.
- Analytics: if Google Analytics / Tag Manager (or similar) is enabled in production, it may measure traffic. We do not use advertising or cross-site profiling cookies as part of the default SOCGuard storefront.
Security
We use HTTPS, access controls, and least-privilege practices for staff and systems handling customer data. No method of transmission over the Internet is fully secure; please use the channels we provide for payment and sensitive attachments.
Children
Our services are directed at businesses and adults purchasing on behalf of an organisation. We do not knowingly collect personal data from children. Under Thailand’s PDPA, a child is generally a person under twenty (20) years of age.
Changes
We may update this policy from time to time. The “Last updated” date above will change when we do. Material changes will be posted on this page.
This page is provided for transparency and is not a substitute for legal advice. For contract negotiations, contact us.