Your privacy choices

KU Spark uses cookies carefully

Essential cookies keep sign-in and security working. Optional cookies stay off until you choose them. Read the Cookie Policy.

KU SparkBack to KU Spark

Effective 28 July 2026

Privacy Policy

How KU Spark collects, uses, shares, protects, and removes personal data, and how you can exercise your rights under Thailand’s Personal Data Protection Act (PDPA).

Version
2026-07-28
Language
English
On this page
  1. Who controls your data
  2. Data we collect
  3. Why we use data and our lawful bases
  4. Required and optional data
  5. Sensitive personal data
  6. Who receives data
  7. International transfers
  8. Retention and deletion
  9. Your PDPA rights
  10. Security and breaches
  11. Changes and contact
01

Who controls your data

The data controller is the person or juristic entity operating this KU Spark deployment (the “Operator”). The Operator’s legal name, address, and privacy contact must be configured in the service information shown below before public launch. KU Spark is a student community service and does not claim to be an official Kasetsart University service unless the Operator expressly states otherwise.

You can contact the Operator about privacy through Feedback and Request in the app. If a data protection officer has been appointed, their contact details are shown in the service information below.

02

Data we collect

  • Account and verification data: name, KU email, password credentials stored by the authentication system, verification status, account role, sessions, and account timestamps.
  • Profile and discovery data: display name, date of birth or age, gender, faculty, study year, campus, graduation status, biography, interests, relationship goal, discovery filters, visibility, likes, passes, matches, blocks, and profile interactions.
  • Content: profile photos, messages, message media, GIF references, reports, safety evidence, feedback posts, comments, votes, and support correspondence.
  • Technical and security data: IP address, user agent, request time, method, host, path, protocol, pseudonymous session identifier, authentication events, upload metadata, and administrator audit records. Traffic records exclude message bodies and URL query strings.
  • Governance data: the legal document version you accepted or acknowledged, cookie choices, privacy requests, legal holds, and lawful authority requests.
  • Data from others: reports about you, messages sent to you, interaction records involving you, and content another user chooses to share with the service.
03

Why we use data and our lawful bases

  • Contract: create and authenticate your account; provide profiles, discovery, matching, messaging, uploads, settings, and support you request.
  • Legitimate interests: prevent fraud and abuse, keep the community safe, moderate reports, secure and improve service reliability, maintain necessary audit evidence, and defend legal claims. The Operator must assess these interests against your rights before relying on them.
  • Legal obligation: retain required computer traffic data, respond to valid legal process, handle PDPA rights requests, and meet security and accountability duties.
  • Consent: store or read optional preference, analytics, or marketing cookies; and process optional data that requires consent, including sensitive personal data where applicable. Consent is separate from accepting the Terms and can be withdrawn without affecting earlier lawful processing.
  • Vital interests: act where reasonably necessary to prevent a serious danger to a person’s life, body, or health.
04

Required and optional data

A valid @ku.th email, account credentials, minimum eligibility information, and technical data necessary to authenticate and secure requests are required to provide the service. If you do not provide them, KU Spark cannot create or operate your account. Profile fields marked optional and all optional cookies may be refused. Refusing optional cookies does not block core service access.

05

Sensitive personal data

Profile choices, discovery preferences, free-text content, photos, and reports may reveal sexual behaviour, health, disability, religion, ethnicity, political opinions, biometric characteristics, or other sensitive matters. KU Spark does not use profile photos for facial recognition. Where the service intentionally asks for or uses sensitive personal data, it must present a separate, explicit purpose-specific consent or identify another condition permitted by section 26 of the PDPA. Do not post another person’s sensitive data without a lawful basis.

06

Who receives data

  • Other users receive the profile and content you make visible to them, subject to your settings and matching state.
  • Service providers may process data only to operate the service, including Supabase/PostgreSQL for structured data, Cloudflare R2 for private media storage, Resend for transactional email, and GIPHY when you choose its GIF search or media.
  • Authorized moderators and administrators receive only the access needed for support, safety, security, legal, and governance work; sensitive actions are audited.
  • Courts, regulators, police, or other authorities receive data only when a request has a valid legal basis or disclosure is otherwise required or permitted by law.
  • A successor may receive necessary data during a merger, reorganization, or transfer of the service, subject to law and appropriate notice.
07

International transfers

Some service providers may process data outside Thailand. Before production use, the Operator must document each processing location and use a transfer mechanism and safeguards permitted by the PDPA. Contact the Operator to ask for current transfer details.

08

Retention and deletion

  • Incomplete or unattached uploads are scheduled for deletion after 1 day once lifecycle enforcement is enabled.
  • When you replace, delete, or detach media, KU Spark queues the database record and R2 object for verified deletion rather than leaving an untracked object.
  • Computer traffic records are kept for at least 90 days under the applicable Thai computer-traffic retention rules, and may be preserved longer only under a documented lawful order or legal hold.
  • Expired sessions and one-time verification credentials are removed after they are no longer needed. User content follows the account, conversation, report, feedback, and safety retention rules in the live retention registry.
  • Reports, moderation actions, administrator audit records, privacy-request evidence, legal acceptance evidence, and legal claims material may be retained after account deletion where law or a defensible legal need requires it. Identifiers should be minimized or anonymized when full identification is no longer necessary.
  • The governance dashboard is the source of truth for approved retention periods. Policies remain disabled until the Operator completes its legal review and explicitly enables enforcement.
09

Your PDPA rights

Submit a request from Settings → Privacy or Feedback and Request. KU Spark records the request, verifies identity where necessary, and targets a response within 30 days for access requests. A request may be limited or refused only where the law permits; the reason and complaint route will be recorded and explained.

  • Ask for access to and a copy of your personal data, and information about data obtained without your consent.
  • Ask for portable data where the legal conditions apply; correct inaccurate data; or ask that incomplete data be completed.
  • Object to processing, request restriction, or request erasure, destruction, or anonymization where the legal conditions apply.
  • Withdraw consent at any time as easily as you gave it. Withdrawal does not make earlier lawful processing unlawful.
  • Complain to Thailand’s Personal Data Protection Committee if you believe the Operator has not complied with the PDPA.
10

Security and breaches

KU Spark uses private object storage, authenticated access, least-privilege administration, append-only governance logs, deletion verification, rate limits, and retention controls. No system is risk-free. The Operator will assess personal-data breaches and notify the PDPC Office without delay and, where feasible, within 72 hours when required; affected people will also be notified without delay when a breach is likely to create a high risk.

11

Changes and contact

Material changes receive a new version and effective date. Where a change requires new consent, KU Spark will ask before the new processing begins. Questions and rights requests can be sent through Feedback and Request or the privacy contact in the service information below.

Service information

Operator and privacy contact

Data controller / Operator
-
Address
-
Privacy contact
-
Data protection officer
-
Open Feedback and Request
Privacy PolicyTerms of ServiceCommunity GuidelinesCookie Policy