AVASA Privacy Policy

Effective date of this version: August 26, 2026

[Important Notes]

We take user privacy very seriously. We understand the importance of personal information to you and are committed to doing everything we can to keep your personal information secure and under control, in accordance with legal and regulatory requirements and with reference to proven industry security standards. To that end, we have created this Privacy Policy for AVASA (this "Policy") so that you can understand in detail how we collect, use, transfer, store and disclose your personal information and what your rights are. Your attention is drawn to the following.

This policy applies to the AVASA software (including but not limited to the web and mobile side), parts of the AVASA features/services that are integrated with third party products or software.

For your convenience, the AVASA Service may contain third party services or links to them. However, as these third parties will collect and process your personal information independently, we have no control over them. Therefore, unless otherwise required by law, we are not responsible for third party services and you should read and refer to the privacy policies of these third parties and use their services at your own discretion.

Please read and thoroughly understand this policy before using the AVASA service, and use the relevant product or service only after confirming that you fully understand and agree to it. By using the AVASA service, you acknowledge that you have fully understood and agreed to this policy. Specifically, you are required to tick/check a box to agree to this policy when you register an AVASA account, and the first time you use the relevant features we will obtain your consent via a pop-up window.

[Policy text]

1. Scope of application of this Agreement

This policy applies to the following usage scenarios: you are using the AVASA service when you are not logged in, requesting a trial account, or logged in to use the AVASA service.

For specific products and services offered on this website, AVASA may have separate privacy policies and service agreements, and if you are registering to use a specific product or service, you should also read the privacy policy and service agreement for that specific product.

2. How we collect your information

1. Personal information refers to various kinds of information recorded electronically or by other means that, alone or in combination with other information, can identify a specific natural person. References in this policy to "your information" mean your personal information. Please note that we currently do not collect sensitive personal information such as biometric data, religious beliefs, specific identity, medical and health information, financial accounts, or whereabouts. If we need to collect such sensitive personal information for business purposes in the future, we will obtain your separate consent in advance.

For your convenience, we summarize the information we collect as follows:

Information typeSpecific contentPurposeRequired
Registration & login informationUsername, password, email/phone numberRegistration, login, verification, notificationRequired
Contact informationEmail, phone numberReceiving verification codes, business notifications and communicationRequired
Enterprise/organization informationSub-account login name, user ID, phone number, passwordEnabling enterprise servicesRequired
Device informationDevice model, OS type and version, app version, push registration IDSecurity protection, push notifications, service operationRequired
Network logsAccess frequency, crash data, error/exception data, system operating statusSecurity operation & maintenanceRequired

The personal information you may need to voluntarily submit to us or authorize us to collect or use when using the AVASA service.This includes both the following:

2.1 Information necessary to provide you with the basic business functions of the AVASA service. If you refuse to provide the appropriate information, you will not be able to use the AVASA service properly.

2.2 Information required to provide you with the additional business features of the AVASA Cloud Web Control Service. If you refuse to provide it, you will not be able to use the relevant additional business functions or achieve the functionality we intend to achieve, but it will not affect your normal use of the basic business functions of the AVASA Service.

Reminder that

2.2.1 The AVASA cloud web management services are provided through different carriers and the specific products/services selected by different users may vary. Accordingly, the basic/additional features and the type and scope of personal information collected and used may vary, so please refer to the specific product/service features.

2.2.2 If the information you submit to us or collect through the AVASA service contains personal information about another person, you must ensure that you have legally obtained the authorization of the relevant subject. If any of the aforementioned information involves personal information about children, you must obtain the prior and separate consent of the corresponding child's guardian.

2.2.3 In order to provide you with a better experience with our products and services, we are constantly working to improve our technology and, as a result, we may from time to time introduce new or optimized features that may require the collection or use of new personal information or change the purposes or manner in which personal information is used. In this regard, we will separately explain to you the purpose, scope and use of the corresponding information through updates to this policy, pop-ups, page prompts, etc., and provide you with the means to choose your own consent, and collect and use it with your express consent.

You can get a quick overview of how we collect and use your personal information by using the AVASA Personal Information Collection Checklist.

2.2.3.1 Registration, Login and Authentication

A). When you create an account with AVASA, you must provide us with a username, set and confirm your login password, and provide your home country email (or mobile phone number). The email address (or mobile phone number) you submit will be used to accept the verification code when you register, log in, bind your account, retrieve your password, and as one of the contact details you specify with AVASA to receive notifications (such as changes to AVASA services, various system notifications, etc.), and AVASA may use this contact information to market to you, promote your products, send service notifications or conduct business with you. Beyond that:

A1). After you have registered for your AVASA account, you can continue to improve your information in your personal centre on the web.

A2). If you are connected to the AVASA service in another way, we will obtain your third party account information from the third party based on your authorization.

A3). For services that require a AVASA account to access, we will verify your user identity against the information you provide above to ensure that we are providing the service to you personally.

B). When you create a sub-account as a business/organization administrator and set up the AVASA service for it, you must submit your user login name, user number, mobile phone number and password to us.

You should ensure that you have obtained the prior express consent of the subject of the personal information before uploading the personal information related to the AVASA, and that you have only collected the information necessary to open an account and the AVASA service, and have fully informed the subject of the personal information of the purpose, scope and use of the relevant data collection. If we find that you have collected personal information without the express consent of a third party, or if we receive a complaint or report in this regard, we have the right to make an independent judgment, extract the relevant system records as evidence, and take measures such as immediately deleting the relevant information, suspending or terminating the provision of some or all services to you. The evidence we extract may be used as direct evidence of your violation of the law and may be submitted to the competent authorities or relevant third parties. If you violate your commitment by collecting personal information of third parties in violation of the law, the responsibility arising therefrom shall be borne by you, and we have the right to claim compensation from you if you cause us any damage as a result.

2.2.3.2 Customer Service

We provide customer services such as product and Service Enquiry, support and after-sales service through various means including telephone, email and online systems. In order to contact you and help you resolve your problem as quickly as possible or to record the solution and outcome of the problem, we may collect and maintain records of your correspondence with us and related content (including account information, your contact information, feedback on problems or suggestions) in accordance with this policy

2.2.3.3 Security and O&M services

In order to protect the security of your account and system operation, and to better provide the AVASA service, we will collect information related to your use of the AVASA service. Including:

A). When you use the AVASA software and related services, we will receive and record information about the device you use, such as your mobile phone or computer device model, operating system type and version number, app version number, as well as the push registration ID assigned to the device by the push notification service. Please understand that this information is essential for us to provide our services and to ensure the proper functioning of our products.

B). To help us better understand the operation of the AVASA software and related services in order to ensure the safety of the operation and provision of services, we record network log information, as well as information on the frequency of use of the software and related services, crash data, error reporting or abnormal service data, and system operation status of abnormal devices.

2.2.3.4 Permissions open

The AVASA service may require you to enable certain access permissions in your device in order to enable the collection and use of personal information to which those permissions relate.

3.How we use your information

3.1 We will use your information in accordance with the following rules

3.1.1 We will use them as agreed in this policy and for the purpose of achieving the appropriate product and/or service functionality.

3.1.2 We may integrate the use of your personal information, or other information that we obtain in a lawful manner in connection with your use of our services or products ("Other Information"), to prevent, detect and investigate fraud, infringement, breach of security, illegality or violation of agreements with us or our affiliates.

3.1.3 We may process or combine your personal information with other information for the purposes of maintaining, improving, optimizing and enhancing the user experience of the AVASA service, or share information with partners to enable them to send you information about other ancillary products and services in accordance with this policy.

3.1.4 When you access third party services through the AVASA service, we will share your personal information within the scope of your authorization with the third party service provider in accordance with your authorization.

3.1.5 Other uses with your permission

3.2 All personal information that you provide or authorize us to collect when you use the AVASA service will continue to be authorized for the duration of your use of the AVASA service unless you delete it, refuse to allow us to collect it through your account settings or system settings. When you cancel your account, we will stop using and delete or anonymize your personal information, except where otherwise required by law or regulation.

3.3 We may compile statistics on the use of the AVASA service and may share these statistics with the public or third parties to demonstrate overall usage trends and/or to generate market satisfaction reports, service improvement plans, etc. in connection with the AVASA service. These statistics will not, however, contain any identifying information about you.

3.4 When we display your personal information, we will desensitize your information using methods including content substitution and anonymous processing to protect the security of your information.

3.5 The features and services we provide to you are constantly being updated and developed. If we need to collect and use your personal information for new features or services, we will separately inform you of the type, scope, purpose and rules of use of the information collected and obtain your express consent through page prompts, interactive processes, website announcements, etc.

3.6 In particular, we would like to draw your attention to the fact that information relating to an identified or identifiable self-identified person that has been anonymized is not your personal information within the meaning of the law; where your information can be used to identify you personally, either alone or in combination with other information, or where we use data that cannot be linked to any specific personal information in combination with other personal information about you, such information will be treated and protected as your personal information in accordance with this Privacy Policy for the duration of the combination.

(7) Automated decision-making: We currently do not use your personal information for automated decision-making, user profiling or algorithmic recommendation, nor do we make judgments that may have a significant impact on you based on such information. If such mechanisms are introduced in the future, we will inform you in advance of their operating logic, their impact and how you may refuse or opt out, and will only implement them after obtaining your consent.

4.How we use cookies and similar technologies

4.1 Cookie

4.1.1 A cookie is a mechanism that supports the server (or script) to store and retrieve information on a website or client. When you use the AVASA service, we send one or more small data files called cookies on your computer or mobile device. the cookie assigned to you is unique and can only be read by the web server in the domain that issued the cookie to you. cookies typically contain an identifier, the site name, and a number of numbers and characters. We use cookie technology to simplify the process of repeatedly logging you in, to help determine your login status and to help secure your account or data.

4.1.2 We are committed to using cookie information for the sole purpose of improving the quality of our services/products and optimizing the user experience. We will not use cookies for any purpose other than those described in this policy. You may manage or delete cookies according to your preferences; you can clear all cookies stored on your computer, most web browsers automatically accept cookies, but you can usually modify your browser settings to reject cookies if you wish; alternatively, you can clear all cookies stored within the software, but if you do so, you may need to change your user settings yourself each time you visit the AVASA website or software, and the corresponding information you have previously recorded may be deleted and may have an impact on the security of the services you use.

4.2 Web beacons and pixel tags

In addition to cookies, we may also use other similar technologies on our websites such as web beacons and pixel tags. For example, the email we send you may contain a click-through URL that links to content on our website, and if you click on that link, we track that click to help us understand your product or service preferences and improve customer service. A web beacon is usually a transparent image that is embedded in a website or email. With the help of pixel tags in the email, we can tell if the email has been opened. If you do not want your activity to be tracked in this way, you can unsubscribe from our mailing list at any time.

5.How we store and protect your information

5.1 In accordance with the requirements of applicable laws and regulations, we will store the user information we collect within the Kingdom of Thailand. Please note that the third-party SDKs we have integrated (Aurora Mobile, the push notification service provider, and the WeChat Open Platform) will, as necessary for the provision of their services, transfer device identifier information, push registration IDs, sharing-related data, etc. to their servers located outside Thailand (e.g., China, Singapore). For details, please refer to the third-party SDK list in Section 6 of this policy. Apart from the foregoing, we currently do not involve any other cross-border transfer. If, in the future, it becomes necessary for business purposes to provide your personal information outside the Kingdom of Thailand, we will obtain your separate consent in advance, and will carry out a personal information protection impact assessment and adopt appropriate protection measures (such as standard contractual clauses) as required by the applicable laws of the relevant country/region before implementing such provision.

5.2 We will continue to store information for you for the duration of your use of the AVASA service. If you cancel your account or voluntarily delete information, we will delete or anonymize your information, unless otherwise required by law or regulation.

5.3 To protect your information from accidental, unauthorized and unlawful access, copying, modification, transmission, loss, destruction, processing or use, we have taken and will continue to take steps to protect your information including but not limited to the following.

5.3.1 Our web service adopts encryption technologies such as transmission security protocols and provides browsing services via https and other means to ensure the security of user data during transmission

5.3.2 User information is stored encrypted with encryption technology as we deem necessary and is isolated by segregation technology.

5.3.3 When using personal information, such as the display of personal information and the calculation of personal information associations, we use various data desensitization techniques, including content replacement and encryption desensitization, to enhance the security of personal information in use.

5.3.4 Establish a strict data use and access system, using strict data access rights control and multiple authentication techniques to protect user information and avoid unauthorized use of data

5.4 Please use complex passwords when using the AVASA service to help us keep your account secure. It is important that you keep your account number and password secure. When you use our services, we will identify you by your account number, password and other elements. If you disclose the aforementioned information, you may suffer losses and it may be used to your disadvantage. If you become aware that an account number, password or other element of your identity may be or has been compromised, you should contact us immediately so that we can take prompt action to avoid or mitigate the relevant damage.

Where there are situations where we share your information with third parties, our web services employ encryption technologies such as transmission security protocols. Transmission services are provided via https etc. to ensure the security of user data during transmission.

5.5 After the unfortunate occurrence of an information security incident, we will, in accordance with the requirements of laws and regulations, promptly inform you of: the basic situation of the security incident and its possible impact, the disposal measures we have taken or will take, the suggestions you can independently prevent and reduce the risk, and the remedial measures for you, etc. We will also keep you informed of the incident by email, letter, telephone, push notification, etc. When it is difficult to inform the information subjects individually, we will take reasonable and effective ways to make announcements. At the same time, we will also take the initiative to report on the handling of personal information security incidents in accordance with the requirements of the regulatory authorities. If your legitimate rights and interests are damaged, we will bear the corresponding legal responsibility.

The internet environment is not 100% secure and we will do our best to ensure the security of any information you send us based on our normal business endeavours.

6. How we commission, share, transfer and publicly disclose your information

6.1 Commissioning

In order to improve the efficiency of information processing, reduce the cost of information processing, or improve the accuracy of information processing, we may entrust our affiliated companies or other professional organisations who are competent to process information on our behalf. We will require the entrusted company to comply with strict confidentiality obligations and adopt effective confidentiality measures through written agreements, and prohibit them from using such information for purposes not authorised by you. The entrusted party's data protection level is not lower than our own. When the entrustment relationship is terminated, we will require them to delete your personal information immediately.

6.2 Sharing

6.2.1 We will not share your information with third parties, except in the following circumstances

6.2.1.1 We have obtained your express authorization or consent to share your information with third parties in accordance with the scope of your authorization.

6.2.1.2 We may share your personal information with external parties as required by law and regulation, litigation, dispute resolution, or as required by law by administrative or judicial authorities.

6.2.1.3 Disposal of infringement complaints: In the event that you are the subject of a complaint by another person about infringement of intellectual property rights or other legal rights, you are required to disclose to the complainant the information necessary for the complaint to be processed.

6.2.1.4 Sharing with Authorized Partners: We may engage authorized partners to provide certain services to you or perform functions on our behalf, including providing infrastructure technical services, messaging services, data processing services for our services. We will only share your information for purposes that are legal, legitimate, necessary, specific and explicit as stated in this policy, and authorized partners will only have access to the information they need to perform their duties and will not use this information for any other purpose.

6.2.2 In order to enable you to use our services, SDKs or other similar applications from authorized partners are embedded in our software. We conduct strict security monitoring of the application programming interfaces (APIs) and software tool development kits (SDKs) from which our authorized partners obtain the relevant information, and we agree with our authorized partners on strict data protection measures so that they handle personal information in accordance with the purposes of our engagement, our service descriptions and this privacy policy.

6.2.3 We will provide you with a list of the names of the third party SDKs we access and a link to their privacy agreements so that you can be more aware of how your personal information is used and protected.

Third-Party SDKProviderPurposeData CollectedPrivacy Policy
JPush SDKAurora MobilePush notifications & crash reportingDevice identifiers (Android ID/IDFV/OAID), device model, OS version, network type, IP address, push registration ID, crash logshttps://jpush.cn/en/license/privacy
WeChat OpenSDKTencentContent sharing to WeChatDevice info, app signature, sharing activity datahttps://weixin.qq.com/cgi-bin/readtemplate?t=weixin_agreement&s=privacy&lang=en

6.2.4 Our products (services) may also have access to services provided by third parties. When you use the services provided by these third parties, they may collect and use your personal information for the purpose of providing their services, so we remind you to read the relevant terms and policies provided by the third parties carefully before using these services.

6.2.5 Third-party service providers may offer products or services to you through the AVASA web pages or terminals, and you may choose whether to use the third-party services and when to terminate or cancel your use of the third-party services. In the course of your use, the third party service provider may collect, use and store data or information about you. You should fully understand the third party service provider's personal information and privacy policies before deciding whether to use such services.

6.3 Transfer

We will not transfer your information to any company, organization or individual, except for the following.

6.3.1 When your express consent is obtained.

6.3.2 In the event of a merger, acquisition or insolvency involving the transfer of information, we will require the new company or organization holding your information to continue to be bound by this policy before we will require that company or organization to seek your authorized consent again.

6.4 Public Disclosure

6.4.1 We will only disclose your information publicly in following situation

6.4.1.1 We may disclose your personal information publicly with your explicit consent or based on your voluntary choice.

6.4.1.2 Disclosure based on law: We may disclose your information publicly if compelled to do so by law, legal process, litigation or governmental authority.

6.4.1.3 For purposes reasonably necessary to enforce the relevant service agreement or this policy, to safeguard the public interest, to deal with complaints/disputes, to protect the safety of persons and property or the legitimate interests of our customers, our or our affiliates', other users or employees.

6.4.2 If we disclose your information for any of the above reasons, we will inform you promptly in compliance with the relevant provisions of laws and regulations and this policy.

6.5 Exceptions to prior authorized consent for sharing, transfer, and public disclosure of personal information

In accordance with relevant laws, regulations and national standards, we may share, transfer and publicly disclose your personal information without your consent in accordance with the law in the following circumstances.

6.5.1 Related to the fulfillment of obligations under laws, regulations and industry authorities.

6.5.2 Directly related to national security and defence security

6.5.3 Directly related to public safety, public health, and significant public interest.

6.5.4 Directly related to the investigation, prosecution, trial and enforcement of sentences for crimes.

6.5.5 where it is difficult to obtain your consent for the protection of your or another person's life, property or other significant legal interests

6.5.6 Personal information that you disclose to the public at your own discretion.

6.5.7 Personal information collected from legitimate public disclosures, e.g. legitimate news reports, government information disclosure and other sources.

In addition, in accordance with the aforementioned regulations, the provision of de-identified personal information to the public and ensuring that the recipient of the data is unable to recover and re-identify the subject of the personal information will not require separate notification to you or your consent.

7. How you can access and manage your information

In accordance with the relevant laws, regulations and standards of your country and the common practices of other countries and regions, we protect you in exercising the following rights with respect to the information you provide.

7.1 Access or correct the information you have provided

7.1.1 You have the right to access and update some of your information by following the specific instructions on the service page you have accepted. You can view or update your registration information on the Personal Centre or similar pages, view or update your device information on the Device page, etc. Before you can do so, we may ask you to verify your identity in order to protect the security of your information.

7.1.2 In addition to the information listed above, we are unable to provide you with access to or correct some of your personal information, mainly information about your device collected to enhance your user experience and ensure the security of your transactions, and personal information necessary to ensure the proper functioning of the business functions you have selected. This information will be used within the scope of your authorization and cannot be accessed or corrected, but you may contact us for deletion or anonymisation .

7.2 Delete your information

7.2.1 Some of your information can be deleted directly by you, subject to the actual display of the service page

7.2.2 You can make a request to us to delete information in the following cases.

7.2.2.1 If we process information in violation of laws and regulations.

7.2.2.2 If we collect and use your information without your consent.

7.2.2.3 If we process information in breach of our agreement with you.

7.2.2.4 If your account is cancelled or recalled.

7.2.2.5 If we terminate our services and operations.

7.2.3 If we decide to respond to your request for deletion, we will also simultaneously notify the entities from whom we have obtained your information that they are required to delete it promptly, unless otherwise required by law or regulation, or unless these entities have your independent authorization.

7.2.4 Once you or we have assisted you in removing the relevant information, we may not be able to remove the appropriate information from the backup system immediately because of applicable laws and security technology, but will remove it when the backup is updated or as soon as it is reasonable to do so.

7.3 Change the scope of your authorized consent or withdraw your authorization

7.3.1 You may change the extent to which you authorize us to continue collecting information or withdraw your authorization by deleting the information, turning off the functionality of the device or service, etc. You may also withdraw all authorization for us to continue to collect information from you by canceling your account.

7.3.2 When you withdraw your consent or authorization, we will no longer be able to provide you with the services for which you have withdrawn your consent or authorization and will no longer process your information. However, your decision to withdraw your consent or authorization will not affect the processing of information that was previously based on your authorization.

7.4 Cancel your account

When a user of your business/organization cancels their AVASA account, we will anonymize or delete your personal information from that organization. Cancellation of your business/organization account with AVASA is only available to administrators, once you have canceled your business/organization account, it cannot be restored, so please proceed with caution. After you have voluntarily canceled your personal account with AVASA, we will cease to provide you with AVASA products or services and will delete or anonymize your personal information as required by applicable law.

7.5 In response to your request above

7.5.1 If you are unable to access, correct or delete your information in the ways described above, or if you need to access, correct or delete other information generated by your use of the AVASA service, or if you believe that we have violated any laws or regulations or agreements with you regarding the collection or use of information, you may contact us by sending an email to info@rltechnet.com. For security purposes, we may require you to provide a written request or otherwise prove your identity, and we will generally respond to your request within 15 days of receiving your feedback and verifying your identity.

7.5.2 In principle, we do not charge a fee for reasonable requests, but we will charge a cost fee for repeated requests that exceed reasonable limits, as appropriate. We may refuse requests that are unnecessarily repetitive, require excessive technical means (e.g. requiring the development of new systems or fundamental changes to current practice), pose a risk to the legal rights of others or are highly impractical (e.g. involving the backing up of information stored on tape).

7.5.3 We will not be able to respond to your request, as required by law or regulation, in the following circumstances.

7.5.3.1 Related to national security and defence security

7.5.3.2 Related to public safety, public health and vital public interests

7.5.3.3 Related to crime investigation, prosecution, trial and execution of judgments, etc.

7.5.3.4 Where there is sufficient evidence of subjective malice or abuse of your rights

7.5.3.5 Where responding to your request will result in serious damage to the legitimate rights and interests of you or other individuals or organizations.

7.5.3.6 Where trade secrets are involved.

8.How we handle the personal information of minors

8.1 Our products, websites and services are primarily intended for adults. Children should not create their own personal data subject accounts without the consent of their parents or guardians. If you are a minor, we ask that you ask your parent or guardian to read this policy and to use our services or provide us with information with the consent of your parent or guardian.

8.2 Where personal information is collected from a minor with the consent of a parent or legal guardian, we will only use or publicly disclose this information as permitted by law, with the express consent of the parent or guardian, or as necessary to protect the minor.

8.3 If we discover that we have collected personal information from a minor without prior verifiable parental or guardian consent, we will seek to delete the relevant data as soon as possible.

9. Amendments to this policy

9.1 We will update this policy in due course in the event of any of the following material changes.

9.1.1 Changes in our basic situation, e.g. change of ownership due to mergers, acquisitions, reorganizations.

9.1.2 Changes in the scope, purpose, and rules for collecting, storing, and using personal information.

9.1.3 Change in the object, scope, and purpose of providing personal information to the public.

9.1.4 Changes in the way you access and manage personal information.

9.1.5 Changes in data security capabilities and information security risks.

9.1.6 Changes in the channels and mechanisms for user enquiry and complaints, as well as external dispute resolution agencies and contact information.

9.1.7 Other changes that may have a significant impact on your personal information rights.

9.2 If this policy is updated, we may notify you by one or more of the relevant service page alerts, AVASA website announcements, web alerts, email, mobile phone text messages, regular mail delivery, and internal mail. In order for you to receive timely notification, we recommend that you notify us when your contact details are updated.

10. Contact Us

If you have any questions, comments or suggestions about this Privacy Policy, or wish to exercise your rights regarding your personal information, please contact us using the details below:

Data Controller: RLTech Global PTE LTD

Email: info@rltechnet.com

We will respond to your request within 15 days after verifying your identity.