Privacy Policy
Media Network Communication Co., Ltd. (MNC)
- Website covered: https://www.mnc.co.th/
- Effective date: 26 August 2026
- Version: 6.0 (First Public Release)
- Data protection contact:
wutthiphan@mnc.co.th(see Sections 11 and 12 for details)
Table of Contents
- Introduction
- Data We Collect
- Purposes and Legal Bases
- 7.1 Encryption in Transit
- 7.2 Encryption at Rest
- 7.3 Access Control
- 7.4 Network and Web Application Protection
- 7.5 HTTP Security Headers
- 7.6 Access Logging and Audit Trail
- 7.7 Patch Management and Vulnerability Remediation
- 7.8 WordPress Hardening
- 7.9 Incident Response
- 7.10 Responsibility and Review
- 7.11 Backup and Recovery Policy
- Personal data means data about an individual who can be identified, directly or indirectly, but does not include data of the deceased specifically.
- Data Controller means a person or legal entity that determines the purposes and means of processing personal data.
- Data Processor means a person who processes data on behalf of the Data Controller, not the one setting the main purpose.
- Sensitive data means data under law that requires special care, e.g., health, belief, or biometric data.
- Cookies means data files stored by the website or third parties in your browser to remember or track usage, as detailed in Section 8.
- Full name, username, email, phone number, and other contact information you submit
- Company name, job title, and organizational information when you contact us on behalf of a company or indicate so in your message
- Subject and content of your request, e.g., product details, system requirements, project information, or technical questions
- Account data such as username and email used for registration, and data needed for account management. Passwords are stored in a format that allows system verification without exposing the original password
- Product search data, messages submitted via contact forms, email, phone, or chat channels connected from the website
- Order, shipping, or service history data only when MNC enables the relevant functions on the website
- MNC employees and operators with roles in sales, marketing, accounting, technical, security, or customer support, with access limited by job function
- External service providers such as hosting and website management, email or support system providers, website analytics, anti-spam, and security providers
- Manufacturers, distributors, agents, or business partners only when necessary to respond to inquiries, warranty, troubleshooting, or services regarding products/systems you request
- Consultants, auditors, lawyers, or independent professionals when necessary to protect rights, audit, or pursue legal action
- Government agencies, courts, or persons with legal authority when there is an order or legal obligation to disclose
- Successors or asset transferees in case of restructuring, sale, or partial business transfer, only as necessary and lawful
- All website pages use HTTPS with TLS 1.2 or 1.3 (modern encryption protocols) only — TLS 1.0 and 1.1 are rejected as outdated and insecure
- SSL certificates are issued by Let’s Encrypt and auto-renewed every 90 days
- HTTP/2 and HTTP/3 (QUIC) are supported for improved performance and security
- ECDHE is used for Perfect Forward Secrecy — even if a key is compromised in the future, past encrypted traffic cannot be decrypted
- Hostinger (our hosting provider) is certified under ISO/IEC 27001:2022 (international information security management standard) for infrastructure, including at-rest encryption for servers and backup systems
- WordPress user passwords are stored in hashed form (one-way encryption, cannot be reversed to original) per WordPress standards (bcrypt/phpass)
- Payment card data is not retained on MNC’s servers — all payment processing goes through Stripe, which is certified under PCI-DSS (Payment Card Industry Data Security Standard)
- hPanel (hosting control panel) access is limited to designated administrators, with 2FA (Two-Factor Authentication) recommended for all admin accounts
- WordPress admin login uses a custom URL hidden from the default (
/wp-login.php) to reduce brute-force attack risk (automated password guessing) - Database access (phpMyAdmin) is via hPanel only, with session-based authentication
- WordPress user accounts have role-based permissions only (admin / editor / author / subscriber)
- WordPress user list review happens every quarter, with unnecessary accounts removed immediately
- DDoS Protection — defends against attacks that try to overwhelm the website with massive traffic, using Cloudflare-protected nameservers and anti-DDoS traffic analyzer
- Web Application Firewall (WAF) — filters malicious traffic such as SQL injection (database command injection) and XSS (script injection) before reaching the website
- Malware Scanner — scans server files for malware automatically and on demand via hPanel
- BitNinja Server Protection — real-time server defense detecting brute-force attacks, tracking IPs with bad reputation, and scanning for malware
- Patchstack (WordPress) — automatic vulnerability monitoring and alerting for WordPress plugins/themes
- Cloudflare Turnstile — identity verification system protecting login pages (hPanel) from bots and brute-force attacks
- hPanel logs all logins and configuration changes
- WordPress logs admin logins, content changes, and failed login attempts
- Stripe maintains complete transaction audit trail
- WordPress core uses the current version — security patches (minor versions) auto-applied
- Plugins and Themes are reviewed and updated regularly, with Patchstack alerting vulnerabilities automatically
- PHP runtime uses Hostinger-managed version (currently PHP 8.5.7)
- Staging/test environment is used before deploying significant plugin/theme updates
- Hide
/wp-login.php— changed to a different URL to prevent brute-force attacks - Disable XML-RPC (
/xmlrpc.php) — reduces attack surface (area attackers could exploit) - Disable directory listing — prevents access to files in
/wp-includes/,/wp-content/ - Protect
/.env,/wp-config.php.bak,/.git/— block access to configuration files that may leak - Restrict REST API User enumeration — currently
/wp-json/wp/v2/usersexposes admin usernames; P1 fix plan (install “Disable REST API” plugin or restrict via .htaccess) - Investigate and contain — identify event scope, close vulnerabilities, stop unauthorized access
- Assess risk — identify affected data types, number of data subjects, severity
- Notify the Personal Data Protection Committee (PDPC) within 72 hours per Section 37(4) of Thailand’s Personal Data Protection Act B.E. 2562 (unless leaked data does not pose high risk)
- Primary owner: Business owner and designated system administrator (currently: MNC IT/Security team)
- Review cycle: Security measures are reviewed at least annually or upon significant changes (e.g., hosting change, new services, new vulnerabilities)
- Risk assessment: Evaluates data type, access channel, user count, and impact if incident occurs
- Documentation: Audit reports are kept internally as evidence and not disclosed publicly
- Hostinger stores backups separately from the main web server (off-server storage) to reduce risk from events affecting the source server
- Hostinger encrypts backups at rest per ISO/IEC 27001:2022
- Backup access is limited to MNC administrators authorized via hPanel, with 2FA recommended
- No point-in-time recovery — can only restore from snapshots in Hostinger’s automated schedule
- No granular restore — full site restore only
- Restoration may take minutes to hours depending on data size
- Install offsite backup plugin (e.g., UpdraftPlus or Backup by Jetpack) exporting to Google Drive or company NAS (supplementary to Hostinger)
- Manual backup via hPanel before every WordPress core update, major plugin update, or theme change
- Monthly backup status verification in hPanel
- Strictly Necessary Cookies: Required for basic service delivery, security, login retention, cart, and cookie preference storage, e.g.,
moove_gdpr_popup. Should not be disabled as core functions may break. - Analytics/Measurement Cookies: Measure visitor count, popular pages, and website performance, e.g.,
_ga,_gid,_gatfrom Google Analytics. The system found in source code is GA4G-2PZFRZSYLB, with Universal AnalyticsUA-1049102-33also appearing. - Security/Anti-bot Cookies: e.g.,
_GRECAPTCHAfrom Google reCAPTCHA, used to verify human form submissions and prevent spam. - Attribution/Performance Cookies: e.g.,
sbjs_current,sbjs_first,sbjs_session,sbjs_current_add,sbjs_first_add,sbjs_udata,sbjs_migrationsfrom SourceBuster/WooCommerce, used for traffic source analysis. - Website: https://www.mnc.co.th/
- Primary email for data subject rights:
wutthiphan@mnc.co.th(confirmed by management 26 August 2026) — recommended channel for rights under PDPA/GDPR, rights requests, and policy inquiries (see Section 12 for details) - General email: support@mnc.co.th — for general inquiries unrelated to data subject rights
- Phone: 099-629-9460 and 02-005-6587
- LINE Official: @mnc.th
- Tax ID: 0-1055-50115-92-1
- Mailing address: 151/268 Soi Rama II 33, Bang Mot, Chom Thong, Bangkok 10150 (confirmed by management 26 August 2026)
- GDPR Article 27 Representative (if any):
(to be confirmed) - There are changes to the nature or scope of data processing activities
- There is a significant increase in sensitive data processing
- There are changes to applicable laws or guidelines
- Management determines that appointment is appropriate
- Data Protection Coordinator: Business Owner / Managing Director (this role facilitates rights coordination, but is not a “DPO” as defined in Section 41)
- Email for data subject rights matters:
wutthiphan@mnc.co.th(confirmed by management 26 August 2026) - Mailing address for documents: 151/268 Soi Rama II 33, Bang Mot, Chom Thong, Bangkok 10150
- Personal Data Protection Committee (PDPC) — Thailand: https://www.pdpc.or.th/
- Where GDPR applies: The supervisory authority in the EU/EEA member state of your residence, work, or where the alleged breach occurred
7. Security
8. Cookies and Similar Technologies
11. Contacting the Data Controller
13. Glossary
1. Introduction
Media Network Communication Co., Ltd. (“Company”, “MNC”, “we”) provides, distributes, installs, and consults on enterprise communication systems such as IP PBX, VoIP, IP Phone, and IP PA (Public Address) systems for corporate clients and individuals contacting on behalf of organizations. This policy explains how MNC collects, uses, discloses, secures, and deletes or destroys personal data when you use our website, submit information requests or quotation requests, register/log into a user account, contact us by email or other channels linked from the website, and when our cookies operate on the website.
In doing so, MNC acts as Data Controller for data collected from website visitors and individuals contacting us for product or service information. However, when MNC processes data of others on a customer’s instructions (e.g., system maintenance or services related to a customer’s systems), MNC may act as Data Processor, and such processing will be governed by the relevant contract, terms, or data protection notice of that project.
MNC will collect data only as necessary and appropriate for the stated purposes, will not use data outside those purposes, and will put in place appropriate measures so that data subjects can understand, access, correct, object, withdraw consent, or request other actions as provided by law. This policy is based primarily on Thailand’s Personal Data Protection Act B.E. 2562 (PDPA), with additional GDPR-aligned practices where GDPR applies to the processing.
This policy applies to data collected through the website and channels linked from it. If you use a specific service that has its own contract, user manual, or data protection notice for that system, those documents may describe the data, processors, retention period, and contact channels in more detail. In case of conflict, use the document specific to that service or system, and contact MNC for further clarification.
We design our data collection processes around the principles of lawfulness, purpose limitation, data minimization, accuracy, access limitation, and storage limitation. These principles apply from form design, through vendor selection, to auditing and data deletion — so that website usage does not become endless data collection without justification.
For consistent understanding of terms in this policy:
2. Data We Collect
2.1 Data You Provide Directly
We may collect the following data when you contact us or use website functions:
Registration or login may require us to store username, email, encrypted password, account creation date, and account recovery data. If you add products to cart or wishlist, the system may remember such state for convenience. These data are used for account functions and website operation, not to identify individuals outside the website without reason.
Personal data in a B2B context remains personal data when it can identify an individual, even if you use a company email or contact us in a job role.
2.2 Data Collected Automatically
When you open the website or use its functions, the system may collect technical and usage data such as IP address, device and browser type, language, access date/time, pages viewed, referring website, system errors, and cookie identifiers — to operate the website, maintain security, analyze performance, and improve services.
Some data may be stored only temporarily in browser sessions, while other items may be stored persistently to remember settings or states. We may truncate IP data or separate data from names and emails before statistical analysis. Anonymization or pseudonymization is not applied to all data types, and we will not attempt to re-identify individuals from statistical data beyond the stated purposes.
We do not intend to collect full payment card data, biometric data, health data, or criminal history data from general website visits. If additional collection occurs for transactions or specific projects, we will notify you in advance as appropriate and will not use the data for inappropriate advertising.
The website currently uses Google Analytics (both Google Analytics 4 and possibly Universal Analytics settings that may still appear in source code) and SourceBuster/WooCommerce attribution for measurement and traffic source tracking.
2.3 Data from Third Parties
We may receive data from website service providers, data analytics providers, anti-spam providers such as Google reCAPTCHA, hosting providers, or individuals/organizations you have instructed to contact us, such as product referrers, agents, or partner company contacts.
If we receive data from other sources, we will notify you of the purpose and necessary details within the time required by law, unless you already know the data or notification is not possible for legal necessity reasons.
We will record the source, receipt date, and reason for using the data to enable audit traceability, and will not accept third-party data for new purposes without notice or legal basis. If third-party sources are public, we will verify that usage is consistent with the source’s terms and applicable laws.
Data collection from users must have a clear reason and a channel for you to review or correct data as appropriate. We will not request excessive data merely to make a form look complete, and will clearly indicate which data is required, which is optional, and which should not be sent by email or public channels. If we find we have received more data than necessary, we will consider reducing usage scope or deleting unnecessary data promptly.
2.4 Sensitive Data
MNC does not intend to collect sensitive data such as health, political, religious, genetic, biometric, or criminal history data directly through the website. If necessary for specific projects, we will obtain explicit consent or rely on exceptions under Section 26 of PDPA, and will provide further details before or during collection.
3. Purposes and Legal Bases
We will use data for the purposes notified before or during collection, and will not use it in a manner inconsistent with those purposes. Each activity will have at least one legal basis, as follows:
| Activity / Purpose | PDPA Basis | GDPR Basis (when applicable) |
| Responding to inquiries, receiving information or quotation requests, preparing for contracts | Section 24(3): necessary for pre-contractual steps | Article 6(1)(b) |
| Registration, login, account management, or fulfilling orders/contracts | Section 24(3) | Article 6(1)(b) |
| After-sales service, follow-up, issue handling, and fulfilling customer requests | Section 24(3) and/or 24(5) as necessary | Article 6(1)(b) and/or 6(1)(f) |
| Security, fraud prevention, anomaly detection, error correction, and system improvement | Section 24(5): legitimate interests | Article 6(1)(f) with balancing test |
| Website usage analysis and performance measurement | Consent for non-essential cookies/processing, or other verified basis | Article 6(1)(a) for consent-required cookies |
| Marketing, news, promotions, invitations to contact back, or product recommendations | Consent under Section 19 and opt-out right under Section 32 | Article 6(1)(a) or other channel-specific basis |
| Accounting, tax, audit, compliance with court orders, law, or legal exercise | Section 24(6): legal obligation | Article 6(1)(c) and/or 6(1)(f) |
Where certain data is necessary for contract performance or legal compliance, we will inform you of the necessity and possible consequences if you do not provide it. Continued use of the website, form submission, or clicking “accept” does not automatically constitute consent for processing beyond necessary purposes, and we will keep consent requests for marketing or non-essential cookies separate from service terms.
We will identify the legal basis separately for each activity, not use “legitimate interests” as a blanket justification for all data uses. Instead, we will assess how necessary our or others’ interests are and how they affect your rights. If a new purpose arises, we will notify you and request new consent when necessary. Before withdrawing consent, we will explain potential impacts, such as stopping newsletters or canceling personalization features, without withdrawing your right to use core services simply because consent is not given.
4. Data Disclosure
MNC will not disclose personal data beyond what is necessary, and may disclose to the following recipients under the necessary-use rules:
We do not have a policy of selling personal data to advertisers. Recipients must have a clear reason and legal basis to receive data, and if disclosure is for marketing or sharing beyond reasonable expectations, we will request separate consent first, unless the law permits without consent.
We will select reliable service providers and require processors to follow our instructions, maintain confidentiality, apply security measures, and delete or return data when the purpose ends, unless legally required otherwise. If MNC processes data on a customer’s instructions, the role, instructions, security, and customer assistance for rights requests will be detailed in the project contract or DPA.
For each disclosure, we will verify how much data the recipient needs, set usage timeframes, and prohibit use for other purposes. If a recipient violates terms, we will act per contract and applicable law.
Where MNC acts as Data Processor for a customer, we will process per instructions and will not use data for our own activities or marketing unless specifically authorized by the customer. If MNC and the customer jointly determine purposes or means, we will draw up a separate agreement reflecting the actual roles to avoid gaps in notification, rights handling, or breach reporting.
If data is transferred abroad, e.g., to hosting providers or parent companies abroad , we will follow Sections 28 and 29 of PDPA, including verifying destination country protection standards and applying appropriate safeguards. If GDPR applies, we will use Chapter V mechanisms such as adequacy decisions, Standard Contractual Clauses, or other lawful measures, and will notify you when necessary.
When you choose to use LINE, Facebook Messenger, or other external platforms connected from the website, the conversation or data sent via that platform may also be subject to that platform provider’s policy. This policy covers data MNC collects or processes as Controller, and does not substitute third-party policies.
5. Rights of Data Subjects
Under PDPA, you have the right to access and obtain a copy of personal data, request receipt or transfer of data in a machine-readable format, request correction, deletion, destruction, or anonymization, request restriction of use, object to processing, and withdraw consent at any time. Withdrawal must be as easy as giving consent, and will not affect processing lawfully conducted before withdrawal.
The right to access and copy includes knowing the data source where we received data from other sources and you have a legal right. We may redact data of other persons or data that the law allows to limit disclosure, and will explain reasons in writing when necessary.
Upon receiving a request, we will verify that it pertains to the requester’s data, and may ask you to specify the scope or data type to locate it efficiently. If the request is unclear, we may contact you for clarification without treating it as a complete request until sufficient information is provided. Additional verification of identity must be reasonable and not exceed necessity.
If you are not satisfied with the outcome, we will explain the reasons and channels for appeal or complaint. Contacting us first does not preclude filing with the regulator. If the requested data is corporate or shared among multiple persons, we may ask the authorized person or representative to submit on their behalf to protect other persons’ data.
If GDPR applies, you may have rights under Articles 15–22: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right not to be subject to solely automated decision-making with legal or similarly significant effects.
You may submit requests via email wutthiphan@mnc.co.th or other channels in Sections 11 and 12 (for DPO status and rights under Section 41). We may ask for identity verification as appropriate to prevent access by others, and will handle requests without discrimination. Generally, we will act within 30 days under PDPA, or 1 month under GDPR, and will notify you of the reason and expected timeline when extension is legally allowed.
We may refuse or limit certain rights as permitted by law, e.g., to comply with law, preserve evidence or legal claims, protect others’ rights and freedoms, or when data is necessary for contract performance. If you object to direct marketing, we will stop such processing promptly and make the opt-out channel clear and easy.
We will retain records of requests, receipt date, identity verification, actions taken, and reasons for refusal as necessary, to enable audit and complaint traceability. You are not charged for exercising your rights, unless the law permits charging for repeated or unreasonable requests.
You may file a complaint with the Personal Data Protection Committee (PDPC) via the current channel at https://www.pdpc.or.th/ . If GDPR applies, you may complain to the supervisory authority in the EU/EEA member state of your residence, work, or where the alleged breach occurred.
6. Retention Period
MNC will retain data only as necessary for the purpose, legal basis, legal obligations, and legal exercise, with the following baseline periods or criteria:
| Data Type | Proposed Period / Criteria |
| Inquiry, question, or quotation data from non-customers | Period necessary to respond, plus 12 months after case closure |
| Customer data, contracts, orders, tax invoices, and accounting | Throughout the contract and thereafter per legal requirements or as necessary for claims — propose 5 years after the end of the related matter or item |
| User account data | As long as the account is active, plus 30 days after account closure for system shutdown and recovery |
| Contact and support history | During customer relationship, plus 12 months after relationship ends |
| Marketing data and marketing opt-out records | Until you withdraw consent or object, retaining opt-out evidence as necessary |
| Cookie consent records | Currently set to no more than 365 days |
| Google Analytics and SourceBuster | Per service provider or website setting; propose the shortest necessary period, e.g., 14 months for Analytics |
| Security logs and access/hosting logs | 90 days to 12 months based on risk and security requirements (see Section 7.6 for details) |
| Data retained for legal evidence or exercise | As necessary until the limitation period ends or the legal process concludes |
When the period ends or data is no longer necessary for the purpose, MNC will delete, destroy, or anonymize the data using a method appropriate to its format, unless retention is required for legal compliance, prosecution, filing or defending a case, or other legal necessity.
Data in backups: Backups stored in Hostinger’s backup system are separated from primary production data and are automatically deleted when the backup retention period ends — currently no more than 30 days (daily) and 30 days (weekly). If backup data has not yet been deleted while the source has been deleted, it will expire in the next backup cycle without additional action. See Section 7.11 Backup and Recovery Policy for full details.
These proposed periods are initial design baselines, not a guarantee that every record will be retained for the full period. If events such as tax audits, disputes, lawsuits, or government orders occur, we may need to retain certain data longer than normal within legal limits. When such events end, we will return to normal deletion/destruction rules.
In setting the retention schedule, we consider data type, sensitivity, service necessity, legal/contractual periods, risk of unauthorized access, and storage limits. We will review periods when services, laws, or technology change. The primary responsible party for reviewing the retention schedule is the business owner and MNC’s IT/Security team, reviewed together with the security controls in Section 7.10 Responsibility and Review (at least annually).
7. Security
MNC applies security measures at both infrastructure and application layers to protect personal data from unauthorized access, modification, destruction, or unlawful disclosure. These measures are evaluated and reviewed regularly based on data risk and characteristics. Technical details are based on the internal website security audit report (signed by the IT/Security team). Technical jargon is explained in Section 13. Glossary.
7.1 Encryption in Transit
Data sent between your browser and our website is encrypted to prevent interception or modification in transit:
Planned improvement: Enabling HSTS (HTTP Strict Transport Security — forces browsers to use HTTPS always, never HTTP) is in the P1 improvement plan.
7.2 Encryption at Rest
Stored data is protected with encryption:
7.3 Access Control
We restrict system and data access to those who need it for their role (Least Privilege principle):
7.4 Network and Web Application Protection
Hostinger provides multiple built-in security layers that our website receives automatically:
7.5 HTTP Security Headers
We audit the HTTP security headers sent by the server to browsers to prevent browser-level attacks. Current status:
| Header | Status | Meaning / Improvement Plan |
Server | ✅ Hidden | Server returns hcdn only, not exposing nginx/apache — reduces attacker information |
Content-Security-Policy | ⚠️ Minimal | Currently only upgrade-insecure-requests — plan stricter CSP to restrict script/style sources |
Strict-Transport-Security (HSTS) | ❌ Not enabled | P1 plan: Enable to force browsers to use HTTPS always |
X-Frame-Options | ❌ Not enabled | P1 plan: Add SAMEORIGIN to prevent clickjacking (tricking users into clicking hidden links) |
X-Content-Type-Options | ❌ Not enabled | P1 plan: Add nosniff to prevent MIME-sniffing (browsers misguessing file types) |
Referrer-Policy | ❌ Not enabled | P2 plan: Add strict-origin-when-cross-origin to limit URL source disclosure |
Permissions-Policy | ❌ Not enabled | P2 plan: Restrict unnecessary browser feature access (e.g., geolocation, microphone, camera) |
7.6 Access Logging and Audit Trail
We log security-related events to enable retrospective audit when anomalies occur:
Log retention: 90 days to 12 months, depending on log type and risk level. These logs are used only for security incident investigation, not disclosed externally.
7.7 Patch Management and Vulnerability Remediation
We keep website software current and close vulnerabilities that could be exploited:
7.8 WordPress Hardening
Beyond Hostinger’s measures, we prevent unintended data disclosure from WordPress configuration specifically:
7.9 Incident Response
In the event of a personal data breach, we will follow these steps:
4. Notify data subjects if the incident poses high risk to their rights and freedoms, with mitigation guidance
5. Document incident in incident log for review and prevention of recurrence
6. Post-incident review to improve processes and technical controls
7.10 Responsibility and Review
7.11 Backup and Recovery Policy
MNC maintains a backup and recovery policy so that the website and data can be restored in case of unexpected events (e.g., hardware failure, malware attacks, or system modification errors).
Backup provider: Hostinger (Business plan or higher) — certified under ISO/IEC 27001:2022 with automated backup and infrastructure-level threat protection.
Backup Schedule:
| Type | Frequency | Maximum Retention |
| Daily backup | Daily, automated | Up to 30 days |
| Weekly backup | Weekly, automated | Up to 30 days |
| Manual backup | On-demand via hPanel | As needed |
| Offsite backup | Recommended weekly via WordPress plugin | Per destination (NAS / Google Drive / S3) |
Storage Location and Encryption:
Recovery Objectives:
| Metric | Target | Meaning |
| RPO (Recovery Point Objective) | 24 hours | Maximum acceptable data loss equals the daily backup window |
| RTO (Recovery Time Objective) | 4 hours | Maximum acceptable downtime to restore the website after a data loss event |
Restore Testing: MNC performs restore testing at least once per quarter to confirm backups can be successfully restored, measure actual restoration time (MTR — Mean Time to Restore), verify data integrity, and verify access rights remain functional. Test results are documented.
Backup System Limitations: As MNC uses shared hosting, the backup system has limitations users should know:
Compensating Controls:
Data Loss Notification: In the event of accidental or unintended loss/deletion of personal data that may affect data subject rights, MNC will act per Section 37 of Thailand’s Personal Data Protection Act B.E. 2562, notifying the Personal Data Protection Committee (PDPC) within 72 hours of becoming aware, and notifying data subjects if the incident poses high risk.
8. Cookies and Similar Technologies
Cookies are small data files that websites or service providers may store in your browser to remember settings, login status, cookie preferences, and certain usage analytics. Common categories:
Non-essential cookies should be set or activated after you provide separate consent per category, where required by law. You may opt out without affecting basic website use, and may change your mind via the “Settings” bar on the website or browser settings. Blocking some cookie types may cause certain functions, such as login or cart, to not work fully.
9. Children and Minors Policy
This website is primarily a business contact channel for organizational product/service information and does not intend to serve or collect data directly from children or persons under 20 years of age. If a user is a minor under Thai law, consent, notification, rights exercise, or complaints will be handled per Section 20 of PDPA, and may require consent or action from the legal guardian depending on the minor’s legal capacity.
For minors aged 10 and above who may perform certain legal acts by law, consent requests may not always require the guardian, but we will consider capacity and legal basis for each activity first. If unclear, contact the DPO/Coordinator for guidance and avoid excessive data collection.
If we learn that we have received data from a minor without proper basis or action, we will investigate, delete, destroy, or anonymize the data per law. If GDPR applies to services aimed at children, Article 8 and the age laws of relevant member states must be assessed. This policy should not substitute age verification or child protection measures appropriate to the actual service.
The website is not designed to profile minors or offer personalized content to them. If guardians or those with authority notify us that minor data was collected inappropriately, we will investigate and act promptly on the request.
10. Changes to This Policy
MNC may review and update this policy periodically to align with changes in services, laws, and security standards. We will announce the effective version, effective date, and summary of material changes on the website. If changes affect your rights or involve new purposes requiring consent, we will notify you and request new consent before processing begins for the new purpose.
We will not apply revised policy retroactively to expand processing purposes without legal basis, unless the law allows otherwise. You may review previous versions from archived documents (to be confirmed).
11. Contacting the Data Controller
Data Controller: Media Network Communication Co., Ltd.
For exercising rights under PDPA Section 41 or other PDPA/GDPR rights: Please use wutthiphan@mnc.co.th or the channels listed in Section 12 (DPO appointment status and data protection contact). If you have questions about this policy, please include your name, contact email, and the matter you want us to act on — without sending passwords or other security data via email.
12. DPO Appointment Status and Data Protection Contact
12.1 Data Protection Officer (DPO) Appointment Status
As of the date of this policy, MNC has not appointed a Data Protection Officer (DPO) under Section 41 of Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) and/or Article 37 of GDPR (where GDPR applies). The “not yet appointed” status was confirmed by company management on 26 August 2026.
The absence of a DPO does not reduce data subjects’ rights under Section 41 or other provisions of PDPA in any way. Data subjects retain all rights specified in Section 5 and may exercise those rights by contacting the Data Controller directly through the channels listed in Section 12.2 below.
While no DPO is appointed, MNC will review this status at least annually, or when:
If a DPO is appointed in the future, this will be announced and the policy will be updated in the next version.
12.2 Data Protection Contact (While No DPO Is Appointed)
While no DPO is appointed by law, you may contact the Data Controller directly to exercise all rights under PDPA Section 41 and other rights specified in Section 5 through the following channels:
Clarification on role designation: The “Data Protection Coordinator” designation in this document is solely for contact facilitation and does not constitute appointment of a DPO under Section 41 of PDPA, nor does it create any additional rights or obligations beyond what the law provides.
12.3 Supervisory Authorities
If you wish to file a complaint or consult about personal data protection, you may contact the supervisory authorities at:
13. Glossary
Technical terms used in this policy, explained for readers without a technical background.
| Term | Meaning |
| HTTPS | Communication protocol encrypting data between browser and website, visible as a padlock icon in the URL bar |
| TLS (Transport Layer Security) | Encryption protocol used in HTTPS. Versions 1.2 and 1.3 are secure today (1.0 and 1.1 are outdated) |
| SSL Certificate | Digital certificate that confirms website identity. We use Let’s Encrypt, auto-renewed every 90 days |
| HTTP/2, HTTP/3 (QUIC) | Modern web protocols that are faster and more secure than HTTP/1.1 |
| ECDHE | Key exchange method ensuring that even if a key is compromised later, past traffic cannot be decrypted (Perfect Forward Secrecy) |
| HSTS (HTTP Strict Transport Security) | Header that forces browsers to use HTTPS always, not accept HTTP, reducing downgrade risk |
| X-Frame-Options | Header preventing clickjacking (tricking users into clicking hidden links in frames) |
| X-Content-Type-Options | Header preventing MIME-sniffing (browsers guessing file types wrong and running unintended scripts) |
| Referrer-Policy | Header controlling how much URL origin the browser sends to destination sites |
| Permissions-Policy | Header restricting browser feature access, e.g., geolocation, microphone, camera |
| Content-Security-Policy (CSP) | Header controlling which sources the browser may load scripts, styles, images from, preventing XSS |
| 2FA (Two-Factor Authentication) | Two-step identity verification, e.g., password + OTP from mobile. Reduces risk when password leaks |
| DDoS (Distributed Denial of Service) | Attack sending massive traffic to make a website crash or slow |
| WAF (Web Application Firewall) | Application-level firewall filtering malicious traffic, e.g., SQL injection, XSS |
| Brute-Force Attack | Attack automatically guessing passwords until one works |
| Malware | Harmful software, e.g., viruses, ransomware |
| SQL Injection | Attack embedding SQL commands via input fields to access or modify databases |
| XSS (Cross-Site Scripting) | Attack embedding malicious scripts in web pages to steal user data or hijack sessions |
| XML-RPC | Old WordPress protocol for pingback and remote posting. Disabled because it’s an attack vector |
| PCI-DSS | Payment Card Industry Data Security Standard |
| ISO/IEC 27001:2022 | International information security management standard |
| RPO (Recovery Point Objective) | Maximum acceptable data loss period, e.g., RPO 24 hours = max 24h of data loss before the event |
| RTO (Recovery Time Objective) | Maximum time to restore the system to working order |
| MTR (Mean Time to Restore) | Average actual restoration time, measured after tests or real events |
| Shared Hosting | Hosting service sharing a server with other users, with some limitations (e.g., no SSH) compared to VPS or dedicated servers |
| hPanel | Hostinger’s hosting control panel name |
| phpMyAdmin | MySQL/MariaDB database management tool via web interface |
| Patchstack | WordPress plugin/theme vulnerability alerting and remediation service |
| BitNinja | Real-time server protection detecting brute-force, bad-reputation IPs, malware |
| Cloudflare Turnstile | Identity verification system replacing CAPTCHA, protecting login pages from bots |
| Offsite Backup | Backing up data to another location, e.g., Google Drive, NAS, S3, to reduce risk from events affecting the source server |
| Point-in-Time Recovery | Recovering data at any specific point in time, e.g., “restore database as of 14:30 yesterday” |
| Granular Restore | Restoring a single file/record instead of the whole site |