Version 1.0 · Effective date: 20 September 2026 · UK legal review required
Privacy Policy
1. Controller and contact
Mark Prime trading as Prime Cognito is the controller for ThaiYinda. Contact hello@primecognito.com, use Get in Touch, or write to c/o 8 Springhill Road, Burntwood, Staffordshire, WS7 4UL, United Kingdom.
2. Scope and age
ThaiYinda is strictly for people aged 18 or over and is not directed to children. Under-18 accounts are not permitted. A parent or guardian can report suspected child data through Get in Touch. We will proportionately investigate, restrict access, preserve only necessary safeguarding evidence, and delete or review the data under the applicable law. We do not knowingly profile or advertise to children.
3. Information we handle
We handle account and contact details, eligibility and date of birth, profiles and preferences, Community posts and interactions, ordinary and Lounge messages and photographs, calls and connection metadata, blocks, reports, appeals, support and privacy cases, translation requests, membership and provider references, notification endpoints, device/security records, cookies and local storage.
At first successful verified sign-in, we use Cloudflare’s trusted two-letter connection-country value once to classify Thailand-included or paid-market access. We retain the limited country code, decision, source and time for entitlement and audit purposes; it is not nationality proof or detailed location history.
ThaiYinda does not record voice-call audio. Full payment-card details remain with the configured hosted payment provider.
4. Purposes and legal bases
We process data to perform the account contract; provide profiles, discovery, content, messaging, translation, calls and support; secure the service; prevent fraud and protect members; moderate and preserve necessary evidence; respond to rights requests; and comply with law. Depending on the activity, the proposed Article 6 basis is contract, legitimate interests, legal obligation, vital interests in a genuine emergency, or consent. Optional preferences that reveal special-category data require a valid Article 9 condition, normally explicit consent.
5. Translation and automated tools
Fixed legal copy is authored in English and Thai. Member text selected for translation may be sent to the configured protected translation service. Identifiers are masked where the protected workflow applies. Machine translations may be inaccurate and never replace the exact original. Automated safety signals support, but do not replace, proportionate human review for significant decisions.
6. Sharing, processors and recipients
Cloudflare supplies hosting, D1, R2, security and configured Workers AI processing; Resend supplies email when configured; Stripe supplies hosted billing when configured. We may share the minimum required information with professional advisers, authorities, recipients or processors where lawful. International processing uses the applicable adequacy decision or contractual safeguards.
7. Retention, evidence and backups
We keep information only for a documented purpose and appropriate period. The exact period depends on the record, the operator’s approved schedule, legal obligations, safety and fraud needs, accounting requirements and legal claims. A restricted retention decision must identify its purpose, legal basis, minimum fields, access owner and review or deletion date. We do not use encryption as a reason for indefinite retention. Deleted material in immutable backups is put beyond use until the verified backup expiry cycle.
8. Pause and erasure requests
Signed-in members can use Settings → Account and privacy after password re-authentication. Pausing is reversible: it hides the account and stops ordinary use and future renewal while retaining data for possible reactivation. Reactivation never restarts billing automatically. An erasure request immediately restricts access and begins a one-calendar-month review. Erasure is not absolute; a narrowly necessary record may be restricted and retained for a specific lawful reason. Pass 1 records and reviews the request; it does not claim that erasure has already occurred.
9. Identity, outcomes and complaints
A signed-in account plus fresh password verification will normally be sufficient identity evidence. We request more only where a genuine recorded doubt makes it necessary and proportionate. Extensions, partial outcomes and refusals require a specific explanation. You may complain to the Information Commissioner’s Office and seek a judicial remedy.
10. Your rights — Articles 15 to 21
Subject to the law and circumstances, Article 15 provides access; Article 16 rectification; Article 17 erasure; Article 18 restriction; Article 19 notification to recipients; Article 20 portability; and Article 21 objection. You may also withdraw consent without affecting earlier lawful processing and object to direct marketing. Requests are reviewed by a human and ordinarily answered within one calendar month.
11. Security and member choices
We use access controls, private object storage, encryption in transit, restricted Admin permissions, session revocation, audit chronology and anti-abuse controls. No service can guarantee absolute security. Members can manage profile visibility, notifications, consents, blocks, sessions and account closure through the available controls.
12. Changes and related documents
Material changes receive reasonable notice. Read the Terms of Use, Community Standards and Membership Policy. Version 1.0 requires final review by an appropriately qualified UK legal/data-protection professional; publication is not a claim of legal certification.