N
NYC Legal
Notary · Translation
← EN home

Privacy Policy

Effective 16 July 2026 · PDPA B.E. 2562 · GDPR-aligned · replaces all prior versions.

1. Data controller

NYC Language Institute Co., Ltd., 92/25 Sathon Nuea Rd, Silom, Bang Rak, Bangkok 10500 acts as the data controller for all information you submit through this website, LINE @nycli, email, or physical intake.

2. Lawful basis

We process personal data on four bases: (a) performance of a translation / legalization contract you request; (b) our legitimate interest in fraud prevention and service-quality auditing; (c) legal obligation (KYC for notarial acts, accounting retention under Thai Revenue Code s.87); (d) your explicit consent for marketing.

3. Categories of data

Identity data (name, passport / Thai ID number), contact data (email, phone, LINE ID), document content (birth certificate, marriage certificate, criminal record — treated as sensitive personal data), payment metadata (bank slip reference — we never store card PANs), and technical logs (IP, user-agent, page path).

4. Retention

Translation project files: 7 years after delivery (per Thai Revenue audit window). Notarial records: 10 years (Lawyers Council rule). Marketing lists: until you unsubscribe. Server access logs: 180 days rolling. Sensitive document scans are purged from working folders within 30 days of collection and moved to encrypted cold storage.

5. Recipients

We share data only with (a) Thai MFA Legalization Division when apostille is requested, (b) destination embassy when embassy legalization is part of your order, (c) certified translators bound by NDA, (d) payment processors (SCB, Kbank), (e) cloud infrastructure (Cloudflare, Supabase EU region). We do not sell data, ever.

6. Your rights (PDPA s.30–36 / GDPR Art. 15–22)

You may request access, correction, erasure, restriction, portability, and objection at dpo@nyclanguageinstitute.com. Response within 30 days. You may also lodge a complaint with the Thai Personal Data Protection Committee (PDPC) at pdpc.or.th.

7. Cross-border transfers

When a translation is delivered to an overseas embassy or apostille destination (e.g., Germany, Australia), the recipient country's data-protection regime applies to that copy. We rely on adequacy decisions (EU, UK, JP, KR) or Standard Contractual Clauses (US, other).

8. Security

TLS 1.3 in transit; AES-256 at rest; role-based access on production databases with quarterly audit; MFA required for all staff logins; no personal data on removable media; physical documents in a fireproof safe until pickup.

9. Cookies

Strictly necessary cookies only by default. Analytics and marketing pixels load only after you accept via the cookie banner. See the cookie table on /en/legal/cookies for the full inventory.

10. Changes

We publish material changes 30 days before they take effect. The current version is 2026-07-16.

Data-subject requests: dpo@nyclanguageinstitute.com · Thai version: /privacy

Explore related services