Wisible

Privacy Policy

Last updated: 27 August 2026

Wisible Co., Ltd. ("Wisible," "we," "us") provides Wisible CRM.

1. Introduction and scope

This Privacy Policy is issued under the Personal Data Protection Act, B.E. 2562 (“PDPA”). It explains what personal data we collect, use, and disclose, for which purposes, on which legal bases, how long we retain it, who may receive it, your rights, and how to contact our Data Protection Officer (Section 23).

The data controller for this website, Wisible user accounts, and direct communications with the company is Wisible Co., Ltd. (“Wisible,” “we,” “us”), of 1010 Shinawatra Tower III, Room 3227, 32nd Floor, Vibhavadi Rangsit Road, Chatuchak, Bangkok 10900, Thailand. Tel: 02-106-9744.

This Policy covers wisible.com, the Wisible CRM application, and channels through which you contact us directly, such as email, telephone, and Wisible’s LINE Official Account. It does not cover third-party websites or services linked from our site.

2. PDPA roles — controller and processor

Wisible is a B2B sales CRM provided as SaaS. Our legal role therefore splits into two cases. This split determines who must answer a data-subject request.

  • When Wisible is the data controller (Section 6): data of website visitors, demo or trial requesters, Wisible account users (for example a salesperson’s name and login email), and people who contact Wisible sales or support. We decide the purposes and means of processing.
  • When Wisible is the data processor (Sections 6 and 40): data that a customer organisation stores in Wisible CRM — such as their contacts’ names, emails, phone numbers, deals, sales notes, uploaded files, and messages from channels they connect. The customer organisation (tenant owner) is the controller and decides purposes and legal bases. Wisible processes only on documented instructions and the service contract.
  • A juristic person’s name alone is not personal data. A natural person’s name together with an email, phone number, or user identifier (such as a LINE user ID) is personal data.

If you are a data subject whose details sit in a customer’s Wisible CRM, please exercise your rights through that organisation first. They are the controller. We will act on their lawful instructions.

3. Data Protection Officer (DPO)

You may contact our Data Protection Officer about this Policy, our processing of personal data, and PDPA rights requests at:

  • Name: Saroj Ativitavas (สาโรจน์ อธิวิทวัส)
  • Email: saroj@wisible.com

Please send rights requests to this email and say in which capacity you are writing (Wisible user, website visitor, or a person whose data is stored in a customer’s CRM) so we can handle the request correctly.

4. Personal data we collect

“Personal data” means any data about a living natural person that identifies them, directly or indirectly. We collect only what is necessary for the purposes notified (Section 22), as follows.

  • Identity and contact data you share with Wisible: name, job title, organisation, work email, telephone number
  • Account data: login email, access logs, and data needed to perform the service contract
  • Technical data on the website: IP address, browser type, device, cookie ID, and pages viewed
  • Data you submit when requesting a demo, trial, or sales contact
  • Data needed for financial documents, such as name, address, and a juristic person’s tax ID (juristic-person data is not personal data under the PDPA unless it identifies a natural person)
  • When Wisible is a processor: contacts, deals, activity notes, files, and messages that the customer organisation enters or connects into the CRM, as that organisation determines

We do not require a Thai national ID card number to use Wisible CRM in the ordinary course, and we do not collect GPS location unless you grant permission in a relevant app. We do not collect sensitive personal data described in Section 7 as a default.

5. Legal bases (Sections 19 and 24)

Having your email, or visiting the website, is not treated as consent for every purpose. We rely on the following bases where they apply.

  • Contract (Section 24(3)): subscribing, creating and managing accounts, billing, support, and performing the terms of service
  • Legitimate interests (Section 24(5)): securing the system, preventing fraud or misuse, improving the product from de-identified statistics where practicable, and necessary website analytics, balanced against your rights
  • Legal obligation (Section 24(6) and related laws): accounting, tax, and complying with lawful orders
  • Consent (Section 19): optional marketing messages you choose to receive, and cookies or pixels that are not necessary for the website to function. You may withdraw consent at any time, without affecting processing already carried out.

6. Purposes (Section 21) and minimisation (Section 22)

We use personal data only as needed for the purposes notified. We do not use it for incompatible purposes without a further notice or a lawful basis.

  • Providing Wisible CRM under contract, including syncing channels the customer organisation connects (such as that organisation’s email or LINE)
  • Creating, verifying, and managing user accounts, and contacting you about the service
  • Improving product quality from statistics that do not identify a person, where practicable
  • Securing the system, keeping necessary event logs, and preventing unauthorised access
  • Complying with law and lawful orders
  • Wisible marketing only where a lawful basis or consent under Section 5 applies

When Wisible is a processor, we do not use a customer’s CRM contact list as Wisible’s own marketing list, and we do not use customer content to train a third-party AI model.

7. Sensitive personal data (Section 26)

We do not intend to collect, use, or disclose sensitive personal data under Section 26, including racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade-union information, genetic data, and biometric data used to uniquely identify a person (such as fingerprints, iris, or facial templates).

If such data appears in text brought into the system, we ask customer organisations and users not to record it in CRM notes for completeness. In-app assistants are designed not to copy this data into notes when it is not needed. Sensitive data would be processed only where the law allows and a clear basis exists.

8. Collection from other sources (Section 25)

CRM contact data often does not come from a Wisible form. It comes from the customer organisation entering, importing, or connecting its own channels, such as email or LINE. In that case the customer organisation, as controller, is responsible for notifying data subjects. Wisible does not use that data for Wisible’s own purposes.

9. Who may receive personal data

We disclose personal data only as needed for the purposes above, on a need-to-know basis. Recipients may include:

  • Wisible employees and contractors who need the data to provide the service, support, or operate systems
  • Infrastructure and cloud providers that host or back up data (Amazon Web Services)
  • Amazon Bedrock, when in-app assistants are used, as described in Section 11
  • Website analytics providers: Google Analytics 4 and PostHog
  • Advertising providers: Meta Pixel, when used on the website
  • LINE, if you contact us via Wisible’s LINE Official Account
  • Payment, accounting, or professional advisers needed to run the business, under confidentiality duties
  • Public authorities, courts, or third parties with a legal right
  • Counterparties in a merger, acquisition, or business transfer, as permitted by law

For in-app assistants, we may send minimised data to an AI sub-processor as described in Section 11.

10. Cross-border transfers (Sections 28–29)

Some providers we use operate systems outside Thailand — for example website analytics that may be processed in the United States, and cloud AI services in Southeast Asia (Singapore). When personal data is transferred outside Thailand, we use appropriate PDPA measures, such as contracts and the provider’s safeguards, and we prefer providers with a policy of not using customer data to train models where that is available.

11. In-app assistants and AI processors

Wisible may offer in-app assistants that help summarise or propose CRM records. These features process only what is needed for your request or the customer organisation’s request, on these principles:

  • Only minimised data is sent; full emails or chat transcripts are not sent when they are not needed
  • Sensitive data under Section 26 is not written into CRM notes for completeness
  • Assistant-driven CRM writes require user approval; the system does not write automatically in the user’s place
  • The primary model provider is Amazon Bedrock in Wisible’s AWS account in Southeast Asia (Singapore). Traffic stays on AWS infrastructure and is not sent through the model maker’s public consumer API
  • Data sent to Amazon Bedrock is not used to train foundation models, under AWS Bedrock terms
  • We do not log raw model prompts in application logs

12. Retention (Section 37(3))

We retain personal data only as long as needed for the stated purposes.

  • Account and service data: for the life of the service, and after the contract ends only as needed for accounting or tax law, disputes, or legal claims; then we delete or de-identify it
  • Website and cookie data: for the life of the cookie or the analytics tool’s configured period
  • CRM data of a customer organisation (when Wisible is processor): as that organisation determines, and on its instructions to close the account, delete, or export
  • Security logs: for a short period needed to maintain security

13. Your rights (Sections 30–36)

Subject to the Act’s conditions and exceptions, you have the right to:

  • Access and obtain a copy of your personal data (Section 30)
  • Data portability in a machine-readable format, where applicable (Section 31)
  • Object to collection, use, or disclosure (Section 32)
  • Request erasure, destruction, or de-identification (Section 33)
  • Request restriction of use (Section 34)
  • Request rectification so data is accurate, up to date, and not misleading (Section 35)
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with the Office of the Personal Data Protection Commission if you believe we have not complied with the law

Send requests to the DPO in Section 3. We may ask you to verify your identity. We may refuse a request only where the law allows, for example where the request is manifestly unfounded or would affect another person’s rights. For data in a customer’s CRM, submit the request to that organisation as controller first.

14. Security (Section 37)

We implement appropriate security measures under Section 37 to prevent unauthorised access, use, alteration, or disclosure. These cover the web application, cloud, compute, data management, and in-app assistants.

  • Connections use 256-bit TLS with certificate verification, URL access restrictions, encrypted session cookies, session timeouts, and necessary activity logs
  • Hosting on Amazon Web Services (AWS) in a Virtual Private Cloud that holds ISO 27001 certification at the infrastructure-provider level, with production isolated from development and test environments
  • Port and IP restrictions via AWS Security Groups, role-based access control, and API access keys
  • Each customer organisation has a separate database and a separate access subdomain, so one customer’s data is not mixed with another’s
  • Personal data in each organisation’s database is encrypted (for example names, emails, phone numbers, and notes); user credentials and access/refresh tokens are encrypted with AES-256; EBS volumes use server-side encryption; access is limited to authorised application servers
  • In-app assistants send only minimised data to Amazon Bedrock in Wisible’s AWS account; we do not log raw model prompts, and customer content is not used to train foundation models

15. Personal-data breaches

If a personal-data breach occurs that is likely to affect data subjects’ rights and freedoms, we will act under Section 37(4), including notifying the Office of the Personal Data Protection Commission within 72 hours of becoming aware of the incident where that duty applies, and notifying data subjects when the law requires. When Wisible is a processor, we will notify the customer organisation (the controller) without undue delay.

16. Cookies and site tools

The website uses cookies and similar technologies so the site can function, so we can measure use, and so we can improve content.

  • Necessary cookies: required for the site to work as you request
  • Analytics: Google Analytics 4 and PostHog, to understand site use in aggregate
  • Marketing: Meta Pixel, when used, to measure and improve Wisible communications

You can block or delete cookies in your browser. Some site functions may not work fully if you block necessary cookies.

17. Marketing

We may send information about Wisible products or services to people who have a business relationship with us, or who have given consent. You may opt out at any time via the unsubscribe link in an email or by writing to saroj@wisible.com. Opting out does not affect messages needed to perform the service contract.

18. External links and fraudulent sites

The site or app may link to third-party services with their own privacy policies. We do not control those sites. Wisible will not ask for your password, card details, or national ID number via untrustworthy email or phone numbers. If you suspect a fake site, go directly to wisible.com and contact us under Section 3.

19. Changes to this Policy

We may update this Policy to reflect changes in law, our services, or our processors. The latest version will be posted on this page with an updated date. If a change is material to you, we will provide additional notice through an appropriate channel.

Data Protection Officer (DPO)

Saroj Ativitavas (สาโรจน์ อธิวิทวัส)

Email: saroj@wisible.com

Wisible Co., Ltd., 1010 Shinawatra Tower III, Room 3227, 32nd Floor, Vibhavadi Rangsit Road, Chatuchak, Bangkok 10900, Thailand. Tel: 02-106-9744

Chat