Privacy Policy
How AI MEDIADD collects, uses, shares, stores, and protects personal data under Thailand’s PDPA and, where applicable, the GDPR.
Last updated: 10 August 2026 · Policy version 2026-08-101. Controller and contact
AI MEDIADD, operated for ai-mediadd.com by the legal entity identified on your invoice, acts as data controller for account, sales, support, and managed-production data. Privacy requests can be made from Account & security or by email to privacy@ai-mediadd.com. The legal entity name, tax ID, registered address, and privacy contact must be confirmed by the site owner before launch.
2. Data we collect
- Account data: name, email, language, timezone, password hash, security and consent records.
- Billing data: order, invoice, tax and payment references. Card numbers and CVV are entered on GB Prime Pay and are not stored by AI MEDIADD.
- Creative data: briefs, prompts, uploaded images, characters, scripts, generated media, approvals, comments, and delivered files.
- Technical data: security logs, hashed IP address, browser signature, audit events, job diagnostics, and consent choices.
3. Purposes and lawful bases
We process data to perform the service contract, secure accounts, prevent fraud, provide support, meet tax and accounting obligations, improve reliability, and—only when consent applies—send marketing or use optional analytics. AI inputs may be sent to the enabled model providers selected for a job.
4. Processors and international transfers
Data may be processed by hosting/object-storage providers, transactional email services, GB Prime Pay, enabled AI generation providers, and production staff. The administrator must record the actual vendors, regions, contracts, and transfer safeguards before launch. We do not sell personal data.
5. Retention
Generated assets and deliveries are scheduled for deletion one year after the applicable purchase unless a shorter period is displayed. Security logs, financial records, backups, and legally required evidence may follow different restricted retention periods. Expiry reminders are sent before eligible assets are purged.
6. Your rights
Depending on applicable law, you may request information, access, correction, deletion, restriction, portability, objection, or withdrawal of consent and may complain to a competent data-protection authority. Requests are tracked electronically. We may verify identity and may retain data where a legal obligation or legal claim requires it.
7. Security
Controls include password hashing, two-factor authentication for staff, role-based access, CSRF and origin checks, encrypted provider secrets, private signed media URLs, malware scanning, immutable financial snapshots, audit logs, and backup/restore procedures. No internet service can guarantee absolute security.
8. Children and changes
The service is intended for business users aged 18 or older. Material policy changes will be versioned and, where required, notified or presented for renewed consent.