Data Privacy

Privacy Policy

Privacy policy detailing data collection, processing standards, retention protocols, and data subject rights under applicable laws at Think Harbor Base.

Last Updated: August 2026

Think Harbor Base Co., Ltd. (“Think Harbor Base,” “we,” “us,” or “our”) is dedicated to protecting the privacy and confidentiality of our clients, website visitors, and engineering partners. This Privacy Policy outlines how we collect, process, retain, and safeguard personal and technical diagnostic data in compliance with the Personal Data Protection Act of Thailand (PDPA), the EU General Data Protection Regulation (GDPR), and applicable international standards.


1. Data Controller Identity

The designated data controller responsible for personal and operational data processed through this website and our diagnostic practice is:

Think Harbor Base Co., Ltd.
Office 9, 42 Example Avenue, Pattaya 00000
Telephone: +66 38 000 652
Email: info@thinkharborbase.click


2. Information We Collect

A. Information You Provide Voluntarily

  • Contact & Scoping Details: Name, job title, corporate email address, phone number, and organization name submitted via our diagnostic intake forms.
  • Diagnostic Briefs: High-level descriptions of application architecture, crash signatures, and stability requirements.

B. Technical Diagnostic Data (Under SOW/NDA Only)

When clients engage us for audits, we may receive sanitized technical artifacts, including:

  • Obfuscated and de-obfuscated stack traces.
  • dSYM symbol files, ProGuard/R8 mapping files, and unstripped .so binaries.
  • Device metadata (OS version, device model, memory limits) and ANR thread dump logs.

We strictly advise clients to sanitize and scrub any Personally Identifiable Information (PII) before transmitting telemetry dumps.


3. Lawful Basis & Purposes of Processing

We process personal and diagnostic data under the following legal bases:

  1. Performance of a Contract: Fulfilling diagnostic audits, delivering code remediation diffs, and providing stability retainer services.
  2. Legitimate Interests: Responding to scoping inquiries, securing our digital infrastructure, and preventing fraudulent submissions.
  3. Legal Compliance: Fulfilling statutory tax and corporate accounting obligations in Thailand.

4. Data Retention & Destruction Policies

  • Inquiry Communications: Retained for up to 12 months following the last communication, after which they are deleted.
  • Client Project Artifacts: Crash dumps, symbol archives, and code samples are permanently and cryptographically purged within 30 days of audit sign-off, or immediately upon client request.
  • Invoicing & Accounting Records: Retained for the statutory period required by Thai corporate tax law (typically 5–7 years).

5. International Data Transfers

When diagnostic telemetry or client communications are processed across international borders, Think Harbor Base ensures appropriate safeguards, including standard contractual clauses (SCCs) and encrypted storage at rest and in transit.


6. Your Data Subject Rights

Under applicable data protection laws, you possess the right to:

  • Access: Request a copy of the personal data we hold concerning you.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure (“Right to be Forgotten”): Request deletion of your personal data where retention is no longer justified.
  • Restriction & Objection: Object to or restrict specific processing operations.
  • Data Portability: Receive your structured personal data in a commonly readable format.

To exercise any of these rights, please contact our data privacy officer at info@thinkharborbase.click.