This Privacy Policy explains how Inorise Co., Ltd., the company that operates Box (“Box”, “we”, “us”), collects and uses personal data when you visit our website, create an account, and use our S3-compatible storage. We handle personal data in line with Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”).
1. Who is responsible
Inorise Co., Ltd., a company registered in Thailand, is the data controller for the account, billing, and website data described in this policy. You can reach us about privacy at privacy@inorise.co.th.
The files you store with Box are different: for those, you are the data controller and we act on your behalf. Section 11 explains how.
2. What we collect
- Account details. Your email address, your organisation’s name, and your password. We store the password only as a secure one-way hash, so we cannot read it.
- Sign-in sessions. When you sign in to the dashboard, we give your browser a session cookie. We keep only a hash of the session token and its expiry time.
- Access keys. The access key IDs you create, with their secret keys stored encrypted.
- Usage records. For each storage request we record the time, your account, the bucket, the type of request (such as an upload, download, or listing), the number of bytes, whether it was served from our cache, and a random request ID. We need these to bill you and to show your usage. They do not include your IP address or the names or contents of your files.
- Billing records. Your credit balance, charges, and invoices, including VAT.
- Operational logs. Our servers write short technical logs for troubleshooting. These can include request IDs and bucket or object names.
- Messages. Anything you send us when you contact us.
We do not store IP addresses or browser details in our databases, we do not use analytics or advertising trackers, and we do not buy or sell data about you.
3. Why we use it
| Purpose | Legal basis under the PDPA |
|---|---|
| Creating your account, signing you in, storing and returning your files, and showing your usage | Performing our contract with you |
| Calculating charges, issuing invoices, and keeping accounting and tax records | Performing our contract, and our legal obligations |
| Keeping the Service secure and preventing abuse or fraud | Our legitimate interests |
| Telling you about your account, security issues, and changes to our terms | Performing our contract with you |
| Responding to lawful requests from authorities | Our legal obligations |
We do not sell your personal data, and we will not send you marketing emails without your consent.
4. Cookies and local storage
- This website sets no cookies. If you switch language, your browser remembers that choice in its local storage (
box-lang). It stays on your device and is never sent to us. - The dashboard uses one cookie,
box_session, to keep you signed in. It is strictly necessary, cannot be read by scripts on the page, and expires 30 days after you last use the dashboard. Signing out deletes the session straight away. The dashboard also remembers your light or dark theme in local storage. - The dashboard loads fonts from Google Fonts, so Google receives your IP address and browser details when you open it. Google’s use of that data is covered by Google’s Privacy Policy.
5. Who we share it with
- Storage providers. Your files are stored by us and independent storage providers, but only as encrypted pieces. Those providers cannot read your files and do not receive your account details. You can ask us for the current list of providers.
- Our hosting provider. Our servers, including the databases that hold the data in section 2, run on a hosting provider in Thailand.
- Payment providers. We do not take card or PromptPay payments online yet. Before we do, we will update this policy to name the payment provider and explain what it receives.
- Authorities, when the law requires us to share data.
- A new owner, if Box or Inorise Co., Ltd. is merged or sold. This policy would continue to protect your data.
6. Data stored outside Thailand
Your account, usage, and billing data is stored on our servers in Thailand. Encrypted pieces of your files may be stored by providers outside Thailand. Those providers receive only encrypted data and no account details. We transfer the data as needed to provide the Service you signed up for, as the PDPA allows.
7. How long we keep it
- Account details for as long as your account is open. We delete them after the account is closed, apart from anything the law requires us to keep.
- Usage and billing records for at least five years, as Thai accounting and tax law requires.
- Sessions until you sign out or they expire. Expired sessions are cleared every hour.
- Your files until you delete them. After you delete a file, its encrypted pieces are erased from our storage providers in the background, usually within a day.
- Operational logs only for as long as we need them to investigate problems.
8. How we protect it
- Every file is encrypted with AES-256 before it is stored, using a separate key for each object. Those keys are themselves encrypted with a master key that never leaves our servers.
- Connections to Box use TLS. Passwords are securely hashed, session tokens are stored only as hashes, and secret access keys are stored encrypted.
- Our staff do not access the contents of your files or raw data. Even when helping with a support request upon your instruction, staff only inspect necessary technical logs and metadata, and never view your raw file contents unless the law strictly requires it.
No system is perfectly secure. If a breach puts your personal data at risk, we will notify the Office of the Personal Data Protection Committee and, where required, you, within the time the PDPA requires.
9. Your rights
Under the PDPA, you can ask us to:
- give you access to, or a copy of, your personal data;
- send your personal data to you or to another organisation in a commonly used format;
- correct personal data that is wrong or incomplete;
- delete or anonymise your personal data;
- restrict how we use your personal data, or stop using it where we rely on our legitimate interests; and
- withdraw any consent you have given us.
To make a request, email privacy@inorise.co.th. We may need to confirm your identity first, and we will reply within 30 days. Some rights have limits; for example, we must keep billing records for as long as tax law requires. You can also complain to the Office of the Personal Data Protection Committee.
10. Children
Box is a service for businesses and developers. It is not intended for anyone under 20, and we do not knowingly collect their personal data.
11. Files you store with Box
If the files you store contain personal data about other people, you are the data controller for that data and we process it on your behalf. That means we:
- use it only to provide the Service to you, following your instructions;
- keep it encrypted and confidential;
- help you respond to requests from the people the data is about, where we can; and
- delete it when you delete it or when your account is closed.
If someone contacts us about personal data in your files, we will refer them to you.
12. Changes to this policy
We may update this policy from time to time. If a change materially affects you, we will tell you by email or in the dashboard before it takes effect. The date at the top shows when the policy last changed.
13. Contact
Inorise Co., Ltd., Thailand. For privacy questions or requests, email privacy@inorise.co.th. For questions about our terms, see our Terms of Service.
Also readTerms of Service