Record of Processing Activities
GDPR & PDPA Compliance — Siam Visa Pro
This document constitutes the Record of Processing Activities (RoPA) of the Siam Visa Pro platform, in accordance with Article 30 of the GDPR (European General Data Protection Regulation) and the requirements of the PDPA (Thailand Personal Data Protection Act).
🏢 Identity of the Data Controller
📋 Processing Activities Register
Eligibility Qualification and Pre-Audit (AI & OCR)
Automated analysis of the financial and administrative viability of a visa application file via our proprietary algorithm and AI document analysis.
- Siam Visa Pro administrators and audit agents.
- Gemini Enterprise Protocol API (isolated instance, no global training on user data).
- Raw financial proofs: Automatically deleted from active memory after data extraction (OCR) and validation (ephemeral lifetime of 24 hours).
- Qualified lead profile: Kept for 3 years from the last contact with the user, unless early deletion is requested.
Document Space Management (File Assembly)
Secure upload and storage of supporting documents required for the official consular visa submission.
- Certified "Senior Audit" experts only (role-based access control in the Admin Panel).
- Google Cloud Platform cloud hosting (GCP Region Europe-West / Belgium).
- Official documents (passport scans, proof of address) are purged at the latest 6 months after the finalization of the visa application or in case of prolonged account inactivity of 12 months.
Customer Support Management (Chat, Calls & Scheduling)
Real-time support exchanges via instant messaging, scheduling phone or video audit appointments, and transcripts of exchanges for the continuous improvement of the visa application file.
- Customer support team and audit agents.
- Third-party technical solution providers (VoIP/Chat routing solutions) and Firestore database (GCP Belgium).
- Chat history and text transcripts: Retained for 1 year for evidence purposes and tracking of the consular visa file, then anonymized or deleted. Raw call audio files are destroyed immediately after transcription validation.
Billing and Payment
Collection of compliance audit fees and visa preparation packages.
- Internal finance/accounting department of CIM Visas.
- Stripe secure payment gateway (PCI-DSS certified).
- 10 years from the closing of the financial year (legal retention period for accounting records).
🔒 Security & International Transfers
To ensure the integrity and confidentiality of the data listed in this register, the following technical, organizational, and legal measures are implemented:
Regulation of Cross-Border Flows
- The primary storage and processing servers are located within the European Union (GCP Belgium).
- Data flows required for operations between Thailand (operational headquarters / immigration authorities) and the European Union are strictly regulated by EU Standard Contractual Clauses (SCCs) and comply with the cross-border transfer adequacy mechanisms of the Thai PDPA, ensuring a mirrored level of protection.
Data Encryption
- In transit: Mandatory TLS 1.3 protocol site-wide with HSTS policy.
- At rest: Firestore database encrypted by default via Google Cloud Key Management System (KMS).
Network Protection & Proxy
- Cloudflare encrypted tunnel to hide the application server's origin IP address.
- Cloudflare WAF (Web Application Firewall) active against injections, scans, and DDoS attacks.
AI Data Protection
- Gemini Enterprise Protocol AI instance isolated from public servers.
- No training: Contractual prohibition on using Siam Visa Pro data to train global AI models.
- Ephemeral sessions: Automatic audit context purge after 24 hours of inactivity.
Strict Access Control (RBAC)
- Restricted access based on role (client, agent, admin). Passports and bank statements are only accessible to 'Senior Audit' or 'Admin' accounts.
⚖️ Rights of Data Subjects
Each Siam Visa Pro user benefits from the following rights, which they can exercise by contacting info@siamvisapro.com:
Right of access and rectification
Direct consultation of their profile in their personal account space and real-time correction.
Right to erasure ("Right to be forgotten")
Complete deletion of supporting documents and the user account (excluding Stripe billing and regulatory financial transaction recording obligations).
Right to restriction of processing
Possibility to temporarily freeze data processing during a dispute or application file audit.
Right to object and withdraw consent
Possibility to refuse or withdraw consent for automated AI processing of documents. The analysis is then fully transferred to a human agent within 48h.