castis.io / Legal / Privacy policy

Privacy policy

Master policy covering the website, the platform and every Castis application.

1. Who we are

This policy is issued by Castis IO Co., Ltd. (Thailand) and Castis Co., Ltd. (Republic of Korea), together “Castis”, “we” or “us”. Castis Co., Ltd. is the parent company, incorporated in the Republic of Korea. Castis IO Co., Ltd. is the operating company for Asia.

Registered offices: 6–7F K-Tower, 1931 Nambusunhwan-ro, Gwanak-gu, Seoul, Korea. 2 Soi Tiwanon 7/2, Talat Kwan, Mueang Nonthaburi, Nonthaburi 11000, Thailand. 15F Tasco Tower, Pham Hung, Me Tri, Nam Tu Liem, Hanoi, Vietnam.

Company registration numbers: [Korea — to confirm] · [Thailand — to confirm].

Privacy contact: partner@castis.io. Personal Information Protection Officer (Republic of Korea, under PIPA Article 31): [name, title, telephone, e-mail — to confirm before publication].

2. Scope of this policy

This policy applies to the castis.io website, to the Castis platform products (CDN, Backoffice, Playout, Spatio.View, TellyBoard, Biz Console, AI Chatbot, FAST & SSAI, ADvisor, Video Analytics and Observability), and to the Castis applications listed in the application annexes.

It does not apply to third-party services you reach from our products, or to a customer's own privacy practices where that customer is the controller of the data being processed.

3. Controller and processor — which one we are

Castis is the controller for information about our own website visitors, prospective customers, business contacts, applicants and the administrators of customer accounts. We decide why and how that information is used.

Castis is a processor for personal data that a customer places into the platform — hotel guest records, staff records, ticket holders, viewer sessions and similar. The customer is the controller. We process that data only on the customer's documented instructions, under the Data Processing Addendum.

If you are a hotel guest, a staff member or a ticket holder and you want your data corrected or deleted, the fastest route is usually the organisation that operates the venue. We will assist them, and we will also act on a request sent directly to us where the law requires it.

4. Information we collect

Account and contact information. Name, business e-mail, telephone number, employer, job title, and the organisation and workspace you belong to.

Authentication data. Sign-in identifiers, session tokens, multi-factor enrolment state, and the device binding used for authenticator and attendance functions. We do not store your password in readable form.

Usage and device data. Pages and product screens visited, actions taken, IP address, browser and operating system, device model, application version, language setting, time zone, and diagnostic and crash information.

Location data. Where an application uses location — for example, to validate a staff clock-in at a work site — it is collected only while the relevant function is in use, and only where you have granted the permission. We do not track location in the background.

Camera and photo data. Applications that scan device codes or capture proof of task completion access the camera only while you are performing that action. Scan results and completion photographs are stored in the operating organisation's tenant.

Content you provide. Media, schedules, messages, tasks, guest requests, service notes and support correspondence.

Viewing and delivery telemetry. Playback session measurements such as start-up time, rebuffering, bitrate and errors, and device and network health data. Where this can be linked to an identifiable person it is treated as personal data and processed under the customer's instructions.

5. Why we use it, and on what basis

To provide the service — performance of a contract with you or with your employer.

To secure the service — legitimate interest in preventing fraud, abuse and unauthorised access, and compliance with legal obligations.

To support and communicate with you — performance of a contract and legitimate interest in responding to enquiries.

To improve and measure the service — legitimate interest, using aggregated or pseudonymised data wherever it is sufficient for the purpose.

Marketing — consent, or legitimate interest in business-to-business communication where the law allows it. You can withdraw at any time using the unsubscribe link or by writing to partner@castis.io.

Where Thai or Korean law requires consent as the basis for a particular processing activity, we obtain that consent separately and record it.

6. Automated processing and artificial intelligence

Some products generate recommendations — for example, advertising optimisation or operational suggestions. These systems propose; a person approves; the owning system applies the change. We do not make decisions producing legal or similarly significant effects about an individual by automated means alone.

The AI Chatbot answers from a property's own knowledge base. Access is filtered at retrieval, before content reaches the model, so a request cannot return material the requester is not entitled to see. Inference calls are logged with the organisation, workspace and application that made them.

We do not use customer content to train general-purpose models for other customers.

7. Who we share it with

Within the Castis group — between Castis Co., Ltd. and Castis IO Co., Ltd. and their affiliates, for delivery, support and administration.

Service providers — the categories and named providers are published on the Subprocessors page. Each is bound by written terms no less protective than this policy.

Your organisation — if you use the platform through an employer or venue operator, that organisation's administrators can see your account and activity within their tenant.

Legal and safety — where required by law, court order or a lawful request from a competent authority, or to protect rights, safety and property.

Business transfers — in connection with a merger, acquisition or sale of assets, subject to this policy continuing to apply.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

8. International transfers

We operate in Korea, Thailand, Vietnam and other markets in Asia. Personal data may be transferred between these countries and to service providers located elsewhere.

Transfers out of Thailand rely on the mechanisms permitted under the Personal Data Protection Act B.E. 2562, including adequacy, appropriate safeguards, binding corporate rules or your explicit consent, as applicable.

Transfers out of Korea are made in accordance with the Personal Information Protection Act, and the recipient, purpose, categories, retention period and country are disclosed in the Korean-language annex to this policy.

9. How long we keep it

Account and contract records: for the life of the relationship and then as required by tax, accounting and corporate law.

Security and audit logs: typically twelve months, longer where an investigation or legal obligation requires it.

Support correspondence: twenty-four months from closure.

Customer-controlled data: for the term of the customer's subscription, then deleted or returned under the Data Processing Addendum.

Marketing contact data: until you withdraw consent or object.

Where a specified period expires, data is deleted or irreversibly anonymised. Backup copies are removed on the ordinary backup expiry cycle.

10. How we protect it

Encryption in transit and at rest, tenant isolation enforced at the database layer, role-scoped access with least privilege, multi-factor authentication for administrative access, logging of consequential actions, and periodic review of access rights. Further detail is on the Security page.

No system is perfectly secure. If a breach affecting your personal data occurs, we will notify the relevant authority and affected individuals within the periods required by applicable law.

11. Your rights

Subject to local law, you may request access to your personal data, correction, deletion, restriction of processing, portability, and objection to processing based on legitimate interest or used for direct marketing. You may withdraw a consent you have given, without affecting processing carried out before withdrawal.

Write to partner@castis.io. We will respond within thirty days, or within the shorter period local law requires. We may need to verify your identity before acting.

If you are dissatisfied you may complain to the Office of the Personal Data Protection Committee in Thailand, or to the Personal Information Protection Commission in the Republic of Korea.

12. Thailand — PDPA

For individuals in Thailand, this policy serves as the notice required under section 23 of the Personal Data Protection Act B.E. 2562. It states the purpose, the legal basis, the categories of data, the recipients, the retention period, your rights and our contact details.

We do not process sensitive personal data under section 26 unless you have given explicit consent or another statutory exception applies.

A Data Protection Officer is appointed where section 41 requires it, and the appointment details are published here when applicable.

13. Republic of Korea — PIPA

For individuals in Korea, the Korean-language Personal Information Processing Policy (개인정보처리방침) is published separately and takes precedence in the event of any inconsistency with this English text.

That notice states the items of personal information collected, the purpose and retention period for each, the procedure and method of destruction, any provision to third parties, any consignment of processing and the consignee, the rights of the data subject and how to exercise them, the measures taken to secure personal information, and the identity and contact details of the Personal Information Protection Officer.

Where personal information is destroyed, electronic files are deleted by a method that prevents recovery and printed material is shredded or incinerated.

14. Children

The platform and our applications are business tools and are not directed to children. We do not knowingly collect personal data from a child below the age at which consent can be given in the relevant jurisdiction. Where a guest-facing surface may be used by a minor, the venue operator is the controller and is responsible for obtaining any consent required.

If you believe a child's data has been collected, write to partner@castis.io and we will delete it.

15. Cookies

The website uses cookies and similar technologies. See the Cookie notice for the categories, the specific cookies set, and how to control them.

16. Application annexes

Each Castis application collects a different set of data for a different purpose. The application annexes state, for each application, what is collected, why, which device permissions are requested, and how to delete an account. They form part of this policy.

17. Changes

We will post any change on this page and update the effective date. Where a change is material we will give notice before it takes effect, by e-mail or in the product.

Effective date: [to confirm on publication]. Last updated: [to confirm on publication].

Draft for counsel review. These documents are prepared to cover the disclosures required by Thai PDPA, Korean PIPA, the Apple App Store and Google Play. They must be reviewed and signed off by qualified legal counsel in each contracting jurisdiction, and every [bracketed] placeholder completed, before publication. Castis is not providing legal advice through this page.
데모 신청문의하기