General Privacy Statement

Dealtoplegal operates with professional confidentiality standards applicable to legal services. This privacy statement explains how we collect, use, disclose and retain personal data in connection with corporate transaction work and website interactions. We limit processing to information necessary for delivering legal advice, participating in negotiations, conducting due diligence and fulfilling contractual and regulatory obligations. The policy outlines data subject rights and contact points for questions or requests related to personal data. Our practices reflect industry expectations for security, discretion and legal compliance in Thailand and, where applicable, cross-border matters.

08-01-2026 Dealtoplegal Soi Muban Baan Suan Pruksa the Master, Tha Tum Sub District, Amphoe Si Maha Phot District, Prachin Buri Province 25140, Thailand [email protected]

Definitions

This section clarifies the meaning of terms used throughout the privacy policy so that readers understand the scope of processing and rights.

Personal data means any information that relates to an identifiable individual, including name, contact details, identification numbers, role within a company, transaction records and any other information that can reasonably identify a person in the context of our services.
Processing refers to any operation performed on personal data, whether automated or manual, such as collection, storage, use, disclosure, retention, deletion and transport in the course of providing legal services.
User refers to any visitor to the website, client, prospective client, counterparty representative or third party whose personal data Dealtoplegal processes in connection with company deals or related communications.
Service denotes the legal advisory and transactional support provided by Dealtoplegal to corporate clients, including document drafting, due diligence, negotiation support and regulatory liaison.
Cookies are small data files stored on a device to enable website functionality, analytics and session management. We use cookies to improve site performance and user experience while minimizing data collection to what is necessary.

Data Collection

We collect data that is necessary for the provision of legal services, for client onboarding, and for operating the website. Collection methods include information provided directly by users, automated collection during website use, and receipt of information from third parties when needed for a transaction.

Data You Provide

When engaging with Dealtoplegal or using our contact forms, we may request or record the following categories of information:

  • Contact information such as name, company name, role, email address and telephone number.
  • Identification and business registration details, including business ID (e.g. 4206389544333) and company address.
  • Transaction-related documents and information including contracts, term sheets, business summaries and due diligence materials.
  • Communications and instructions relevant to the legal engagement, including email content and meeting notes.
  • Billing and payment details necessary to process invoices and manage accounts where applicable.
  • Any additional information you choose to provide to support legal advice and case handling.

Automatic Data

When you visit our website or interact with online tools we collect limited technical data to maintain and improve our services.

  • IP address and general location data for security and analytics purposes.
  • Device and browser information including screen resolution and browser type.
  • Usage data such as pages visited, time on site and navigation paths for website optimization.
  • Cookie identifiers used to manage session state and preferences.
  • Error and performance logs to monitor stability and diagnose technical issues.
  • Analytics data aggregated to understand service patterns without identifying individuals except where authentication is required.

Third-Party Data

In certain situations we may receive information about individuals from third parties to facilitate transaction work, compliance checks or when acting on behalf of clients.

  • Information from counterparties or their advisors relevant to a transaction or negotiation.
  • Publicly available registries and corporate databases used for verification of corporate status and beneficial ownership.
  • Third-party service providers such as payment processors or document hosting platforms acting on our instructions.

Purposes of Processing

We process personal data only for legitimate purposes necessary to provide legal services, comply with law, and maintain operations in a professional manner.

  • To assess, negotiate and execute corporate transactions and related contracts.
  • To perform due diligence, compliance checks and risk assessments required by law or client instruction.
  • To communicate with clients, counterparties and regulators regarding transaction matters.
  • To prepare and maintain records, invoices and project documentation for legal representation.
  • To improve website functionality, provide secure access and troubleshoot technical or security incidents.
  • To satisfy legal obligations such as anti-funds laundering checks and tax reporting where applicable.
  • To manage client relationships, including conflict checks and conflict resolution processes.
  • To process requests related to data subject rights and regulatory inquiries.

Legal Bases for Processing

Processing is supported by one or more lawful bases appropriate to the activity and jurisdictional context, listed below.

  • Performance of a contract: processing necessary to provide legal services and fulfill contractual commitments to clients.
  • Legal obligation: processing required to comply with applicable laws, regulations and professional obligations.
  • Legitimate interests: processing necessary for our business operations, security, fraud prevention and service improvements when such interests are balanced against individual rights.
  • Consent: where specific processing requires consent, we will request clear and documented consent and provide means to withdraw it.

Data Subject Rights

Where applicable under GDPR-style frameworks, individuals have rights regarding their personal data. We outline the typical rights and how to exercise them.

  • Right of access: individuals may request confirmation of processing and access to their personal data.
  • Right to rectification: individuals can request correction of inaccurate or incomplete data.
  • Right to erasure: in limited circumstances, individuals may request deletion of personal data where retention is no longer necessary.
  • Right to restriction and objection: individuals may request restriction of processing or object to certain processing activities, subject to overriding legal or contractual requirements.
  • Right to data portability: where processing is based on consent or contract and is automated, individuals may request a portable copy of their data.
  • How to exercise rights: submit a request using the contact details below; we will verify identity and respond within applicable timeframes.

Cookies and Similar Technologies

We use cookies to support core site functions, analytics and minimal personalization. Cookies help maintain sessions and improve security and performance.

Types include essential cookies for site operation, analytical cookies for aggregated usage statistics, and functional cookies for user preferences. We do not rely on profiling cookies for legal advice delivery.

Category examples: Essential (session management), Analytics (usage measurement) and Functional (preferences). You may block non-essential cookies through your browser settings.

To manage cookies, use browser controls or device settings. Disabling certain cookies may affect website functionality; essential cookies remain necessary for secure sessions and forms.

Full cookie details and settings

Data Sharing

We share personal data only where necessary for service delivery, compliance, or as required by law. Providers engaged are contractually bound to protect the data.

  • External advisors and counterparties involved directly in a transaction (law firms, accountants, banks).
  • Service providers such as secure document hosts, IT infrastructure vendors and payment processors acting under confidentiality obligations.
  • Regulatory and law enforcement authorities when disclosure is required by statute or formal request.
  • Professional advisors and insurers for risk management and claims handling in connection with legal services.
  • Potential buyers, supporter or partners in a transaction scenario, where client instruction permits such sharing.
  • Where necessary to comply with legal processes, subpoenas or equivalent orders within relevant jurisdictions.

International Transfers

Cross-border transfers occur when data is shared with service providers, counterparties or advisors located outside Thailand. We take steps to ensure appropriate safeguards are in place, such as contractual protections and vetting of recipient safeguards, in line with applicable legal requirements.

Safeguards can include standard contractual clauses, data processing agreements, and careful selection of recipients with suitable security controls and clear contractual obligations to protect personal data.

Data Retention

Retention periods reflect the nature of the data and legal or operational requirements. We retain data only as long as necessary to fulfill the purpose or to meet statutory retention obligations.

Client account records and engagement files are retained for a period consistent with legal and professional rules applicable to legal services in Thailand, typically several years after the conclusion of a matter.

Communications and case-specific correspondence are kept as part of the client file for as long as required to address legal, regulatory and archival needs.

Technical logs and analytics data are retained in aggregated or anonymized form for a limited period to support security monitoring and service improvement.

When retention periods expire or upon verified deletion requests where lawful, Dealtoplegal will securely delete or anonymize personal data in line with documented procedures.

Security Measures

Dealtoplegal maintains administrative, technical and physical measures designed to protect personal data against unauthorized access, alteration, disclosure or destruction. Controls include access restrictions, encrypted storage where appropriate, regular security reviews and training for staff handling confidential client information. We review practices periodically and update measures in response to evolving risks and legal requirements.

  • Access to sensitive client files is restricted to authorized legal staff via individual credentials and multi-factor authentication; role-based access controls ensure team members see only the information necessary for their duties.
  • Data at rest and in transit is protected using industry-standard encryption protocols; regular vulnerability scans and periodic third-party security assessments are performed to identify and remediate risks.
  • Secure backups are maintained on geographically separated storage with strict retention policies; incident response procedures are documented and tested to minimize disruption and protect client confidentiality.

Your Data Rights

Dealtoplegal recognizes the rights of individuals regarding their personal information. The following outlines the principal rights available to data subjects and the practical steps to exercise them in the context of our legal services in Thailand.

  • Right to access: request a copy of personal information we hold about you and receive a clear explanation of how it is processed.
  • Right to rectification: ask us to correct inaccurate or incomplete personal data relating to you.
  • Right to erasure: request deletion of personal data where retention is no longer justified under applicable law or legitimate business needs.
  • Right to restriction of processing: request limits on how your data is used while a dispute about accuracy or lawful basis is resolved.
  • Right to data portability: request transfer of your data to another controller in a commonly used, machine-readable format where applicable.
  • Right to object: object to certain types of processing, such as direct marketing or where processing is based on our legitimate interests.
  • Right to withdraw consent: when processing is based on consent, you may withdraw that consent at any time without affecting prior lawful processing.
  • Right to lodge a complaint: if you believe your rights have been violated, you may raise the issue with Dealtoplegal or the competent supervisory authority in Thailand.

How to Submit a Rights Request

To exercise any of the rights above, contact our Data Protection Officer with a clear description of your request and any relevant identifiers. Include the email or postal address associated with your matter and sufficient information to locate your records. We may request identity verification to protect your data from unauthorized disclosure.

[email protected]

We will acknowledge receipt within 7 business days and aim to respond substantively within 30 calendar days. If additional time is required due to the complexity of the request, we will notify you with an explanation and a revised timeframe.

Marketing and Communications

Dealtoplegal may send informational communications about legal developments, events, or services relevant to company transactions. Marketing communications are based on your consent or our legitimate interest where permitted. Messages will be professional, relevant to corporate legal matters, and respectful of your communication preferences.

You may opt out of marketing messages at any time using the unsubscribe link contained in emails or by contacting Dealtoplegal directly. Opting out will not affect transactional messages related to active engagements or legal matters you retain us to handle.

Children's Data

Dealtoplegal does not provide services to children and does not knowingly collect personal data from minors for marketing or legal engagement purposes. If we become aware that we have inadvertently collected personal information of a minor, we will take steps to delete it in accordance with applicable law.

Third-Party Links and Services

Our website may include links to third-party resources or tools. Dealtoplegal is not responsible for the privacy practices or content of external sites. Before providing personal information to any third party, please review their privacy policy and terms of use.

Changes to This Policy

We periodically review and may update our privacy practices. Material changes will be reflected on the Dealtoplegal website with an updated effective date. Minor clarifications or formatting updates may be made without prior notice where they do not materially affect how we process personal data.

Contact Information

For privacy inquiries or to exercise your rights, contact Dealtoplegal's privacy officer at: Soi Muban Baan Suan Pruksa the Master, Tha Tum Sub District, Amphoe Si Maha Phot District, Prachin Buri Province 25140, Thailand. Business ID: 4206389544333. For general inquiries about corporate legal services, call +66947333132 or visit dealtoplegal.link.

  • +66947333132
  • [email protected]
  • Soi Muban Baan Suan Pruksa the Master, Tha Tum Sub District, Amphoe Si Maha Phot District, Prachin Buri Province 25140, Thailand
Senior Legal Advisor
Available
Hello. I am a Dealtoplegal transactions specialist. Please describe your deal and any immediate legal concerns so I can advise on next steps.