Dextalo
FeaturesPricingAboutGuidesDocs
Sign inGet started
Legal

Privacy Policy

How DxT Corporation Co., Ltd. collects, uses, shares, and protects personal data across the Dextalo platform — and the rights you have under Thai PDPA, GDPR, CCPA/CPRA, and Singapore PDPA.

Last updated: 23 July 2026

On this page

  1. 1. Introduction & Scope
  2. 2. Who We Are — Controller vs Processor
  3. 3. Definitions
  4. 4. Categories of Personal Data We Collect
  5. 5. How We Collect Personal Data
  6. 6. Purposes & Legal Bases
  7. 7. AI Features & Automated Processing
  8. 8. Cookies & Tracking Technologies
  9. 9. How We Share Data & Sub-Processors
  10. 10. International Data Transfers
  11. 11. Data Retention & Deletion
  12. 12. Security Measures
  13. 13. Data Breach Notification
  14. 14. Your Privacy Rights
  15. 15. California Privacy Rights (CCPA/CPRA)
  16. 16. Thailand PDPA-Specific Notes
  17. 17. Singapore PDPA-Specific Notes
  18. 18. Children's Privacy
  19. 19. Third-Party Links & Services
  20. 20. Customer Organization Name, Logo & Marketing Use
  21. 21. Changes to This Policy
  22. 22. Data Protection Officer & How to Contact Us
  23. 23. Customer Responsibilities & Our DPA

This Privacy Policy explains how DxT Corporation Co., Ltd. ("DxT", "we", "us", or "our") collects, uses, discloses, transfers, retains, and protects personal data in connection with Dextalo (formerly "DxT"), our business software platform available at dextalo.com (the "Platform"). Dextalo is delivered as one platform comprising three applications: Projects (translation and localization management), HRM (human-resources management), and Accounting (enterprise resource planning, including CRM and financial records).

We have written this policy to satisfy the disclosure and transparency requirements of the Thailand Personal Data Protection Act B.E. 2562 (2019) ("Thai PDPA"), the EU and UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the Singapore Personal Data Protection Act 2012 ("Singapore PDPA"). Where a specific law grants you rights or imposes obligations that go beyond the general statements below, the law-specific sections of this policy control.

Please read this policy together with any agreement under which you access the Platform. If you are a business customer, your subscription agreement and our Data Processing Addendum ("DPA") govern how we process the personal data you upload to the Platform. If you do not agree with this policy, please do not use the Platform.

1. Introduction & Scope

This policy applies to personal data we process through the Platform, the dextalo.com website, our in-app AI assistants and MCP/AI gateway, our APIs, and any related support, sales, and administrative interactions. "Personal data" (also called "personal information" or "personal data" depending on the jurisdiction) means any information relating to an identified or identifiable natural person.

Dextalo is a business-to-business (B2B) product intended for use by organizations and their authorized personnel. It is not directed to consumers or to children. References to "you" mean the individual whose personal data we process — for example an account administrator, an authorized user, a website visitor, or, where applicable, an individual whose data is contained in content a customer uploads.

This policy does not cover the privacy practices of third parties we do not control, including websites or services that link to or from the Platform, or your own organization's handling of your personal data as your employer or service provider.

2. Who We Are — Controller vs Processor

The entity responsible for the Platform is DxT Corporation Co., Ltd., a company incorporated under the laws of Thailand, with legal entities in Thailand and Singapore and customers worldwide. You can reach our privacy team at privacy@dextalo.com and our Data Protection Officer at dpo@dextalo.com.

Our role under data-protection law depends on the type of data involved, and this distinction matters for your rights:

  • Data controller / data processor ("controller" / "business" under CCPA): For account, administrative, billing, and usage/technical data, we determine the purposes and means of processing and act as a data controller in our own right.
  • Data processor / service provider ("processor" / "service provider" under CCPA): For the content that a customer uploads to the Platform — including their translation projects and translation memory, their HR and employee records, and their financial and accounting records ("Customer Content") — we act as a data processor on behalf of the customer, who is the controller. We process Customer Content only on the customer's documented instructions, as set out in the subscription agreement and our DPA.

If you are an individual whose personal data appears in Customer Content (for example, an employee whose leave records sit in the HRM app, or a customer contact in the Accounting CRM), the organization that uploaded that data is the controller and your first point of contact. We will refer your request to the relevant customer and assist them as their processor.

3. Definitions

To keep this policy readable, we use the following terms. Where a statute defines a term differently, the statutory definition applies for the purposes of that law.

  • "Personal data" — information relating to an identified or identifiable individual; equivalent to "personal information" under CCPA/CPRA and Singapore PDPA.
  • "Special-category / sensitive data" — data such as health, disability, religion, race or ethnicity, biometric or genetic data, trade-union membership, and government identifiers. The HRM app may process such data about employees on a customer's behalf.
  • "Customer" — the organization that subscribes to the Platform and uploads Customer Content.
  • "Customer Content" — data, files, and records a customer or its authorized users upload to or generate within the Platform, including projects, translation memory, HR/employee records, and financial records.
  • "Authorized User" — an individual a customer permits to access the Platform under the customer's account.
  • "Sub-processor" — a third party we engage to process personal data on our behalf in providing the Platform.
  • "Processing" — any operation performed on personal data, such as collection, storage, use, disclosure, transfer, or deletion.
  • "Controller", "Processor", "Business", "Service Provider", "Data Subject", "Consumer" — have the meanings given under the applicable data-protection law.

4. Categories of Personal Data We Collect

The categories of personal data we collect depend on how you interact with us. We group them as follows.

Account & administrative data

  • Identity and contact data: name, business email address, username, job title, and the organization you belong to.
  • Authentication and credential data: login identifiers, password hashes, multi-factor settings, and single sign-on identifiers (managed through our authentication provider).
  • Role and permission data: your assigned roles, workspace memberships, and access scopes within the customer's tenant.
  • Billing and commercial data: billing contact, plan, subscription history, and tax or invoicing details (we do not store full payment-card numbers).
  • Communications data: support tickets, correspondence with our team, and feedback you submit.

Usage & technical data

  • Device and connection data: IP address, browser type, device and operating-system identifiers, and approximate (city/region-level) location derived from IP.
  • Log and event data: pages and features accessed, actions taken, timestamps, referring URLs, and session identifiers.
  • Diagnostic data: crash reports, performance traces, and error events (collected through our monitoring provider).
  • Cookie and similar-technology data: identifiers stored in cookies, local storage, and pixels (see Section 8).

Customer Content (processed on the customer's behalf)

  • Projects app: source and target text, translation memory, terminology, file attachments, vendor and linguist contact details, and project metadata.
  • HRM app: employee directory records, leave and attendance records, holiday calendars, and related employment data. This may include special-category / sensitive personal data such as health-related leave reasons, disability accommodations, or government identifiers, where the customer chooses to store it.
  • Accounting app: CRM contacts, sales documents, invoices, receipts, general-ledger entries, and other financial records, which may identify individuals.

We do not control and do not require any particular field within Customer Content. The customer, as controller, decides what personal data to upload and is responsible for ensuring it has a lawful basis to do so.

5. How We Collect Personal Data

We collect personal data in the following ways.

  • Directly from you — when you create or administer an account, configure a workspace, contact support, subscribe, or otherwise communicate with us.
  • Automatically — through cookies, server logs, and analytics/monitoring tools when you use the Platform or visit dextalo.com (see Sections 4 and 8).
  • From your organization — when a customer's administrator provisions you as an Authorized User or uploads Customer Content that contains your personal data.
  • From service providers — for example our authentication provider (identity and login events) and our monitoring provider (diagnostic events).
  • From you in the course of using AI features — prompts, instructions, and content you submit to our in-app AI assistants and MCP/AI gateway (see Section 7).

6. Purposes & Legal Bases

We process personal data only where we have a lawful basis. Under the GDPR we rely on the bases in Article 6 (and, for special-category data, Article 9). Under the Thai PDPA we rely on consent, contractual necessity, legitimate interest, or other lawful bases in Sections 24 and 26. The principal purposes and bases are set out below.

  • Providing and operating the Platform, including provisioning accounts and tenants — GDPR Art. 6(1)(b) performance of a contract; Thai PDPA contractual necessity.
  • Processing Customer Content to deliver the Projects, HRM, and Accounting features — performed as processor on the customer's documented instructions; the customer's own lawful basis applies to the underlying data.
  • Authentication, security, fraud prevention, and protecting the integrity of the service — GDPR Art. 6(1)(f) legitimate interests, and where applicable Art. 6(1)(c) legal obligation; Thai PDPA legitimate interest.
  • Billing, invoicing, and tax/accounting compliance — GDPR Art. 6(1)(b) and Art. 6(1)(c); Thai PDPA contractual necessity and legal obligation.
  • Product analytics, troubleshooting, and improving and developing the Platform — GDPR Art. 6(1)(f) legitimate interests, balanced against your rights; Thai PDPA legitimate interest.
  • Service, transactional, and (where permitted) marketing communications — GDPR Art. 6(1)(f) legitimate interests, or Art. 6(1)(a) consent for marketing where required; Thai PDPA consent where required for marketing.
  • Identifying a Customer organization as a Platform customer using its name and/or logo (for example on dextalo.com marketing pages) as described in Section 20 and in our Terms of Service — this primarily concerns business identity and trademarks, not personal data; where personal data appears in marketing materials (e.g. a named testimonial), GDPR Art. 6(1)(f) legitimate interests or Art. 6(1)(a) consent as applicable; Thai PDPA legitimate interest or consent where required.
  • Complying with legal obligations and responding to lawful requests — GDPR Art. 6(1)(c); Thai PDPA legal obligation.
  • Establishing, exercising, or defending legal claims — GDPR Art. 6(1)(f) legitimate interests.

Where we rely on legitimate interests, we have assessed that those interests are not overridden by your interests or fundamental rights. Where we rely on consent (for example for certain cookies or marketing), you may withdraw it at any time without affecting processing carried out before withdrawal (see Sections 8 and 13). For special-category employee data in the HRM app, the customer-controller is responsible for securing the relevant Article 9 condition or Thai PDPA explicit consent.

7. AI Features & Automated Processing

Dextalo includes an MCP/AI gateway and in-app AI assistants that help you draft, translate, summarize, classify, and analyze content within the Platform. These features are powered by large language models provided by third-party AI vendors (Anthropic, Google, and OpenAI).

To deliver these features, Customer Content and the prompts you submit may be transmitted to and processed by these third-party models. We want to be explicit about the limits we apply.

  • Inputs are processed only to generate the requested output and return it to you within the Platform.
  • We contractually require that your inputs and outputs are NOT used to train or fine-tune the third-party foundation models.
  • AI processing is invoked only when an Authorized User actively uses an AI feature; it is not applied to your data in the background as a default.
  • AI vendors act as our sub-processors for this purpose and are bound by data-protection terms (see Sections 9 and 10).

AI outputs may be inaccurate or incomplete and should be reviewed before reliance. We do not use AI to make decisions that produce legal or similarly significant effects about you without human involvement. If you believe an automated process has materially affected you, you may contact us to request human review, and where the GDPR applies you have the rights described in Article 22.

8. Cookies & Tracking Technologies

We and our service providers use cookies, local storage, and similar technologies to operate the Platform, keep you signed in, remember preferences, secure sessions, and understand product usage.

  • Strictly necessary — authentication, session integrity, security, and load balancing. These are required for the Platform to function and cannot be switched off.
  • Functional — remembering settings and preferences to improve your experience.
  • Analytics & performance — understanding feature usage and diagnosing errors so we can improve the service.

In regions where consent is required (including the EU/UK under the GDPR and ePrivacy rules, and Thailand under the PDPA), we present a cookie banner / consent manager that lets you accept or reject non-essential cookies and change your choices at any time. We will not set non-essential cookies before you consent where consent is legally required. You can also control cookies through your browser settings; disabling some cookies may affect functionality. We honor recognized opt-out preference signals (such as Global Privacy Control) where required by law.

9. How We Share Data & Sub-Processors

We do not sell personal data. We share personal data only as described below and under appropriate contractual protections.

  • Within your organization — Customer Content and account data are accessible to Authorized Users according to the roles and permissions the customer configures.
  • Sub-processors — vetted vendors who process personal data on our behalf to provide the Platform (listed below).
  • Professional advisers and auditors — under confidentiality, where necessary.
  • Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy and applicable law.
  • Legal and safety — where required to comply with law, a lawful request, or to protect rights, safety, or the integrity of the service.

Our sub-processors

  • Cloudflare — hosting, edge compute, object/file storage, and KV storage (global).
  • Neon — managed PostgreSQL database hosting (United States / EU).
  • Clerk — authentication and user identity management (United States).
  • Anthropic, Google, and OpenAI — AI model inference, only when AI features are used (United States).
  • Sentry — error and performance monitoring (United States / EU).

Each sub-processor is engaged under a written agreement that requires it to protect personal data and to process it only for the purposes we specify. A current list of sub-processors is maintained for customers; we provide a mechanism for customers to receive notice of, and where applicable object to, material changes to our sub-processors as set out in our DPA.

10. International Data Transfers

We operate from Thailand and Singapore and serve customers worldwide, and our sub-processors operate in the United States and the EU, among other locations. As a result, personal data may be transferred to, stored in, and processed in countries other than your own, including countries that may not provide the same level of data protection as your home jurisdiction.

When we transfer personal data internationally, we rely on lawful transfer mechanisms, including:

  • Adequacy decisions or designations, where the destination is recognized as providing an adequate level of protection.
  • Standard Contractual Clauses (SCCs), including the EU SCCs and the UK International Data Transfer Addendum, supplemented by transfer-risk assessments and additional safeguards where needed.
  • For transfers from Thailand under PDPA Sections 28–29, appropriate safeguards such as SCCs aligned with international and ASEAN model clauses, or applicable derogations (for example consent, contractual necessity, or legal obligation), pending publication of a PDPC adequacy list.
  • For transfers from Singapore under the PDPA Transfer Limitation Obligation, contractual and other measures ensuring a comparable standard of protection.

You may request a copy of the relevant safeguards we use for international transfers by contacting privacy@dextalo.com.

11. Data Retention & Deletion

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to provide the Platform, comply with legal, tax, and accounting obligations, resolve disputes, and enforce our agreements.

  • Account & administrative data — retained for the life of the account and for a limited period afterward to meet legal, security, and audit needs.
  • Customer Content — retained for the duration of the subscription and processed according to the customer's instructions; the customer controls retention within the Platform.
  • Usage, log, and diagnostic data — retained for a limited period for security, troubleshooting, and analytics, then deleted or aggregated.
  • Billing and financial records — retained for the period required by applicable tax and accounting law.

Post-termination export window: following termination or expiry of a subscription, we provide a defined window (as set out in the subscription agreement / DPA, typically 30 days) during which the customer may export Customer Content. After that window, we will delete or anonymize Customer Content in accordance with our standard schedules and the DPA, unless retention is required by law. Where you exercise a right to erasure, we will delete or anonymize the relevant personal data unless we have an overriding legal basis to retain it.

12. Security Measures

We implement and maintain technical and organizational measures designed to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures include:

  • Encryption of data in transit (TLS) and at rest.
  • Logical tenant isolation so that each customer's data is segregated from other customers' data.
  • Role-based access control (RBAC) and the principle of least privilege for both customers and our personnel.
  • Audit logging of significant actions and administrative events.
  • Access controls including authentication, multi-factor authentication for privileged access, and managed identity through our authentication provider.
  • Network security, monitoring, and vulnerability management, including continuous error and performance monitoring.
  • Personnel confidentiality obligations and security training.
  • A documented incident-response process, including detection, containment, investigation, and notification.

No method of transmission or storage is completely secure. While we work hard to protect your personal data, we cannot guarantee absolute security, and you are responsible for keeping your credentials confidential and configuring your tenant's roles and permissions appropriately.

13. Data Breach Notification

If we become aware of a personal-data breach affecting personal data we process, we will respond in accordance with our incident-response process and applicable law.

  • Where we act as processor, we will notify the affected customer (controller) without undue delay so the customer can meet its own notification obligations.
  • Where we act as controller and the breach is likely to result in a risk to individuals, we will notify the relevant supervisory authority, and affected individuals where required, within the timeframes set by applicable law — including notifying the Thai PDPC without undue delay and, where feasible, within 72 hours, and meeting the GDPR's 72-hour authority-notification standard.
  • We will provide information about the nature of the breach, the categories and approximate number of individuals and records affected, likely consequences, and the measures taken or proposed.

14. Your Privacy Rights

Subject to applicable law, you have the following rights in relation to your personal data. These rights apply most directly where we act as controller; where we act as processor, we will forward your request to the relevant customer-controller and assist them in responding.

  • Access — to obtain confirmation of whether we process your personal data and a copy of it.
  • Rectification — to have inaccurate or incomplete data corrected.
  • Erasure — to have your personal data deleted in certain circumstances.
  • Restriction — to limit how we process your data in certain circumstances.
  • Portability — to receive certain data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
  • Objection — to object to processing based on legitimate interests, and to object to direct marketing at any time.
  • Withdraw consent — where processing is based on consent, to withdraw it at any time without affecting prior processing.
  • Not to be subject to solely automated decisions — including profiling, that produce legal or similarly significant effects, except as permitted by law.

How to exercise your rights: email privacy@dextalo.com or our DPO at dpo@dextalo.com. We may need to verify your identity before acting on a request. We will respond within the timeframe required by applicable law — generally within 30 days under the Thai PDPA and within one month under the GDPR (extendable for complex requests), and within 45 days under the CCPA/CPRA. We do not charge a fee unless your request is manifestly unfounded, excessive, or repetitive. You may use an authorized agent where the law permits.

15. California Privacy Rights (CCPA/CPRA)

This section provides additional disclosures for California residents under the CCPA/CPRA. When we handle Customer Content, we act as a service provider and process that information only on the customer's behalf under a written contract.

Categories collected and disclosed

In the past 12 months we have collected the following statutory categories of personal information for the business purposes described in this policy: identifiers (e.g., name, email, account and device identifiers, IP address); commercial information (e.g., subscription and billing records); internet/network activity (e.g., usage and log data); geolocation data (approximate, from IP); professional or employment-related information; and, within Customer Content uploaded by customers, potentially sensitive personal information. We disclose these categories to our sub-processors and service providers (Section 9) for business purposes, and to legal/governmental recipients where required.

Your California rights

  • Right to know — the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of third parties to whom it is disclosed.
  • Right to delete — your personal information, subject to legal exceptions.
  • Right to correct — inaccurate personal information.
  • Right to limit — the use and disclosure of sensitive personal information to what is necessary to provide the service.
  • Right to opt out — of any sale or sharing of personal information (see below).
  • Right to non-discrimination — we will not discriminate against you for exercising your rights.

We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. Because we do not sell or share, there is no need to opt out of sale or sharing; we nonetheless honor recognized opt-out preference signals where applicable. We do not use or disclose sensitive personal information for purposes beyond those permitted by the CCPA/CPRA. To exercise these rights, contact privacy@dextalo.com; we will verify and respond as described in Section 14.

16. Thailand PDPA-Specific Notes

As a controller established in Thailand, we comply with the Thai PDPA in respect of the personal data we control. The following notes supplement the rest of this policy.

  • Legal bases — we rely on consent, contractual necessity, legitimate interest, legal obligation, vital interest, or public-task bases under Sections 24 and 26 of the PDPA, as applicable.
  • Sensitive data — special-category data (e.g., health, disability, religion, biometric, criminal-record data) is processed only with explicit consent or another Section 26 exemption; in the HRM context, the customer-controller is responsible for securing this basis.
  • Consent — where we rely on consent, it is freely given, specific, and informed, and you may withdraw it at any time. Withdrawing consent does not affect prior lawful processing.
  • Data subject rights — you have rights of access, rectification, erasure, restriction, portability, objection, and to withdraw consent, and we will respond within 30 days as the PDPA requires.
  • Cross-border transfers — we apply appropriate safeguards under Sections 28–29 (such as SCCs aligned with international/ASEAN models) or applicable derogations, given that the PDPC has not yet published an adequacy list.
  • Complaints — you may lodge a complaint with the Office of the Personal Data Protection Committee (PDPC) of Thailand.

17. Singapore PDPA-Specific Notes

For individuals in Singapore, we comply with the Singapore PDPA in respect of personal data we control. We collect, use, and disclose personal data for the purposes notified in this policy and, where required, with your consent or on another lawful basis such as legitimate interests or business improvement.

  • You may withdraw consent on reasonable notice, request access to and correction of your personal data, and ask about how it has been used or disclosed.
  • We protect personal data through reasonable security arrangements (Section 12) and limit retention to what is necessary (Section 11).
  • For overseas transfers, we ensure a comparable standard of protection consistent with the PDPA's Transfer Limitation Obligation.
  • You may contact our DPO at dpo@dextalo.com and, if unsatisfied, complain to the Personal Data Protection Commission (PDPC) of Singapore.

18. Children's Privacy

Dextalo is a B2B product intended for organizations and their authorized personnel. It is not directed to, and we do not knowingly collect personal data from, children. Under the GDPR we do not knowingly process the personal data of children under 16, and consistent with Thai law we do not target individuals under 20 without appropriate parental or guardian consent.

If you believe a child has provided us personal data without appropriate consent, please contact privacy@dextalo.com and we will take reasonable steps to delete it. Customers are responsible for ensuring that any personal data of minors contained in Customer Content (for example in HR records) is processed with the appropriate legal basis.

19. Third-Party Links & Services

The Platform and dextalo.com may contain links to, or integrations with, third-party websites and services that we do not operate or control. This policy does not apply to those third parties. We are not responsible for their content or privacy practices, and we encourage you to review their own privacy policies before providing personal data to them.

20. Customer Organization Name, Logo & Marketing Use

When an organization creates a Customer account and accepts our Terms of Service, that organization may grant DxT a limited contractual license to use the Customer’s name, trade name, and logo to identify the Customer as a customer of the Platform (for example on the dextalo.com landing page or other marketing materials). That grant is a commercial trademark license set out in the Terms of Service (Intellectual Property — Publicity; Customer name and logo). It is not created by this Privacy Policy.

Company names, trade names, and logos are typically trademarks of the Customer organization. They are business-identity assets and are not, by themselves, personal data about a natural person. This Privacy Policy therefore does not, and cannot, replace the Terms of Service as the legal basis for displaying a Customer’s logo or corporate name on our marketing site.

Where marketing materials also include personal data — for example a named individual’s photo, job title, or quote in a testimonial or case study — we process that personal data only with an appropriate lawful basis (typically consent or legitimate interests for B2B communications), as described in Section 6. We do not treat logo-wall or “customers include” displays of organization marks alone as processing of personal data under this policy.

  • Organization name and logo on marketing materials — governed by the Terms of Service publicity license; the Customer organization may revoke that license by written notice as described in the Terms (contact legal@dextalo.com or support@dextalo.com).
  • Personal data in testimonials or case studies — governed by this Privacy Policy and applicable data-protection law; individuals may contact privacy@dextalo.com to exercise their rights under Section 14.
  • Enterprise customers — a signed Order Form or Enterprise agreement may exclude or modify logo and name use; that negotiated agreement controls to the extent of any conflict.

If you are an individual and believe personal data about you appears in our marketing without an appropriate basis, contact privacy@dextalo.com. If you represent a Customer organization and wish to withdraw permission for display of the organization’s name or logo, follow the revocation process in the Terms of Service rather than a personal-data erasure request under this policy (unless personal data is also involved).

21. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, the Platform, or legal requirements. When we make material changes, we will update the "Last updated" date at the top and, where appropriate, provide additional notice (for example by email or an in-app notice).

Your continued use of the Platform after an update takes effect constitutes acceptance of the revised policy, except where additional consent is required by law, in which case we will seek that consent.

22. Data Protection Officer & How to Contact Us

We have appointed a Data Protection Officer (DPO) to oversee compliance with this policy and applicable data-protection law.

  • Privacy team: privacy@dextalo.com
  • Data Protection Officer: dpo@dextalo.com
  • Controller: DxT Corporation Co., Ltd. (incorporated in Thailand)

If you have a concern about how we handle your personal data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with a supervisory authority — including the Office of the Personal Data Protection Committee (PDPC) of Thailand, the Personal Data Protection Commission of Singapore, or, if you are in the EU/UK, your local data-protection supervisory authority. Where we act as a processor for Customer Content, please also contact the relevant customer-controller, whose privacy notice governs that data.

23. Customer Responsibilities & Our DPA

Where a customer uploads Customer Content, the customer acts as the controller and we act as the processor. The customer is responsible for ensuring that it has a valid legal basis to collect and process the personal data it uploads (including any special-category employee data in the HRM app), for providing required privacy notices to its own data subjects, for configuring roles and permissions appropriately, and for responding to data-subject requests relating to that data.

  • We process Customer Content only on the customer's documented instructions and as needed to provide the Platform.
  • We maintain confidentiality, security, and sub-processor commitments as described in this policy and the DPA.
  • We assist the customer, as far as reasonably possible, with data-subject requests, security, breach notification, and data-protection impact assessments.
  • We delete or return Customer Content at the end of the engagement, subject to the export window and legal-retention exceptions (Section 11).

A Data Processing Addendum (DPA), incorporating EU/UK Standard Contractual Clauses and equivalent transfer safeguards, is available to customers and, once executed, forms part of the subscription agreement. To request the DPA or the current sub-processor list, contact privacy@dextalo.com.

Dextalo

One platform for localization, people, and finance. Run projects, HR, and accounting from a single workspace.

Product

  • Features
  • Pricing
  • Docs

Company

  • About
  • Guides
  • Press kit
  • Careers

Legal

  • Privacy Policy
  • Terms of Service
© 2026 DxT Corporation Co., Ltd. All rights reserved. Dextalo is a product of DxT Corporation Co., Ltd.