Privacy Terms
Privacy Policy
How we collect, use, disclose, and protect your personal information
Last updated: July 31, 2026
Introduction
The Acua group operates through Acua (Thailand) Co., Ltd. ("Acua Thailand"), Acua Co., Ltd. in Japan ("Acua Japan"), and Acua Vietnam Co., Ltd. ("Acua Vietnam") (together, "Acua," "we," "us," or "our"). Thailand is our principal market for the Acua finance-operations platform and related accounting, implementation, support, and operational services. We also provide some products and services in Japan and Vietnam. Acua Vietnam principally supports product development and engineering and may also support local customers and group service delivery. This Privacy Policy explains how the relevant Acua entity collects, uses, discloses, transfers, retains, and protects personal data.
The Acua entity identified in your Order Form, contract, local notice, or other direct relationship is normally the controller for that relationship. Acua entities may act as separate or joint controllers for group activities, or as processors or subprocessors for one another and for customers. This Privacy Policy is a notice and does not itself create consent. Where applicable law requires consent, we request it separately in a clear and specific form and permit withdrawal as required by that law.
Definitions
"Personal data" or "personal information" means information about an identified or identifiable individual under applicable law. "Sensitive personal data" includes the categories treated as sensitive or requiring enhanced protection under applicable law, such as health, biometric, genetic, racial or ethnic, political, religious, sexual-life, criminal-record, government-identifier, financial-account, or precise-location data. The exact definition and protections differ under Thailand's PDPA, Japan's APPI, and Vietnam's Personal Data Protection Law.
"Processing" means any operation performed on personal data, including collection, recording, storage, use, disclosure, transfer, restriction, erasure, or destruction. Acua is a "data controller" when it determines the purposes and means of processing, including for website visitors, prospects, customer contacts, account administration, billing, security, and Acua's own compliance. Acua is a "data processor" when it processes invoices, receipts, expense records, supplier information, employee information, and other customer-controlled data on a customer's instructions; that processing is governed by the Data Processing Addendum.
Data Collection Methods
We collect personal data you or your organization provides to us, including:
β’Identity and business contact data, such as name, job title, company, work email, phone number, and authorized-user details β’Account, subscription, billing, tax, and contract-administration data β’Documents and records submitted through the platform, such as invoices, receipts, purchase orders, expense records, supplier and payee details, bank-account details, approval history, and accounting information β’Integration credentials or identifiers and data imported from accounting, ERP, email, messaging, identity, or other systems that your organization connects β’Support requests, implementation records, survey responses, and communications with us. We record calls or meetings only after providing notice and where legally permitted
We automatically collect certain information when you use our Services:
β’Log files, device identifiers, and IP addresses β’Browser type, operating system, and usage statistics β’Cookies, web beacons, and telemetry data
We may receive personal data from your employer or another Acua customer, authorized users, suppliers and business partners, connected third-party services, Acua group companies, and public business sources. If we obtain personal data from a source other than you, we provide any notice required by applicable law within the required period unless an exception applies, including the notice requirements of the Thailand PDPA where relevant.
Some information is required to create an account, enter into or perform a contract, comply with tax or other legal obligations, secure the Services, or provide requested features. If required information is not provided, we may be unable to create the account, conclude or perform the contract, process a requested transaction, or provide the relevant feature. Fields or requests that are optional will be identified as such where practical.
The Services are not intended for customers to submit sensitive personal data unless it is strictly necessary for a permitted business process and lawful under the rules applicable to that data, including Thailand PDPA section 26 where relevant. Where Acua acts as controller, we process sensitive personal data only with explicit consent or another applicable statutory exception and with additional safeguards. Where Acua acts as processor, the customer is responsible for determining the lawful basis and issuing appropriate instructions.
Processing Purposes
We process personal data for the following purposes:
β’Providing, configuring, and administering the Services; authenticating users; processing documents; enabling approvals, integrations, exports, and customer-requested workflows β’Managing contracts, subscriptions, billing, tax documentation, customer relationships, implementation, support, and service communications β’Securing accounts and systems; detecting abuse, fraud, duplicate or anomalous transactions, and security incidents; maintaining audit logs and business continuity β’Complying with tax, accounting, corporate, employment, court, regulatory, and other legal obligations applicable to the relevant Acua entity in Thailand, Japan, Vietnam, or another country, and establishing, exercising, or defending legal claims β’Improving reliability, usability, and features using telemetry and aggregated or de-identified information β’Sending product updates, event invitations, and marketing where permitted by law and honoring opt-out or withdrawal requests β’Managing corporate transactions, audits, and internal governance β’Other specific purposes notified to you and supported by an applicable legal basis
Legal Bases
Depending on the country, relationship, and data involved, we rely on consent or another basis permitted by applicable law, including:
β’Contract or pre-contract steps: providing requested products, accounting or operational services, administering accounts and subscriptions, and communicating about performance β’Legal obligation: tax, accounting, corporate, employment, court, regulatory, and record-keeping requirements applicable to the relevant Acua entity β’Legitimate or lawful interests where recognized: securing and improving the Services, preventing fraud and misuse, administering business relationships, maintaining audit evidence, and protecting legal rights, after the required balancing β’Consent: optional marketing, non-essential cookies, recordings, sensitive data, or another activity where consent is required β’Protection of life or health, public interest, legal claims, or another statutory exception. For Thailand, these bases include PDPA sections 24 and 26; Japan and Vietnam apply their own statutory requirements.
Data Sharing
Acua does not sell personal data. We disclose personal data only as reasonably necessary for the stated purposes and applicable legal basis, including to:
β’Cloud hosting, authentication, AI-assisted document processing, communications, support, security, analytics, and other service providers acting under contract β’Acua Thailand, Acua Japan, and Acua Vietnam for product development, engineering, local customer delivery, accounting services, support, finance, legal, security, and administration. Access is role-based and limited to the relevant function β’Accounting, ERP, email, messaging, banking, or other integration providers when your organization enables or directs an integration β’Customers or authorized users that control the relevant workspace or business record β’Tax, court, law-enforcement, regulatory, or other competent authorities in Thailand, Japan, Vietnam, or another relevant country where required or permitted by law β’Professional advisers, auditors, insurers, investors, and transaction counterparties subject to confidentiality and necessity β’A successor in a merger, reorganization, financing, or sale of relevant assets β’Other recipients at your direction, with valid consent, or as otherwise permitted by law
For a current list of Acua affiliate and third-party subprocessors, their roles, and processing regions, see our Subprocessors page.
International Transfers
Our production application and primary database are hosted in Thailand. Personal data may also be accessed or processed by Acua Japan for local service delivery and group administration, by Acua Vietnam principally for product development, engineering, support, and some local service delivery, and by subprocessors in the locations listed on our Subprocessors page. Remote access from another country is treated as cross-border processing where applicable. Access by each Acua entity is limited by role, business need, confidentiality duties, and technical controls.
We apply the cross-border rules of the country from which data is transferred. Transfers from Thailand are handled under PDPA sections 28 and 29 and applicable PDPC notifications. Transfers from Japan are handled under the APPI, including the rules for provision to foreign third parties and supervision of service providers. Transfers from or involving Vietnam are handled under Law No. 91/2025/QH15 on Personal Data Protection and Decree No. 356/2025/ND-CP, including transfer-impact documentation and regulatory filings where required. Safeguards may include intra-group and vendor data-transfer agreements, ASEAN Model Contractual Clauses or other appropriate terms, transfer-risk review, data minimization, encryption, logging, and access controls.
Security Measures
We maintain technical and organizational security measures appropriate to the nature and risk of the processing, informed by recognized information-security frameworks. Measures include role- and permission-based access controls, multi-factor authentication where supported, encryption in transit and at rest, tenant isolation, managed network controls, logging and monitoring, backup and recovery, secure development practices, personnel confidentiality, incident response, and periodic security review.
No security measure can eliminate all risk. When an Acua entity acts as controller, it assesses and reports a personal data breach to the competent authority and affected individuals within the period and risk threshold required by applicable law. This includes Thailand's risk-based PDPC notice under PDPA section 37 and applicable notification duties under Japan's APPI and Vietnam's Personal Data Protection Law and Decree No. 356/2025/ND-CP. Where Acua acts as processor, we notify the relevant customer controller without undue delay and assist it under the Data Processing Addendum.
Data Retention
We retain personal data only for the period reasonably necessary for the stated purpose, taking account of contractual requirements, tax and accounting record-keeping rules applicable to the responsible Acua entity, applicable limitation periods, security needs, disputes, and legal holds. In general:
β’Customer-controlled content is retained during the subscription and, unless early deletion is requested or law requires otherwise, for 90 days after termination before deletion or anonymization from the active production environment; backups expire through the normal backup cycle β’Account, contract, billing, tax, audit, and transaction records are retained for the period required by applicable law in Thailand, Japan, Vietnam, or another relevant country and reasonably necessary for claims or audit β’Support and security logs are retained for a limited operational period based on risk and troubleshooting needs β’Marketing data is retained until opt-out, withdrawal of consent, or expiry under our retention schedule When data is no longer required, we delete, destroy, or anonymize it using measures appropriate to the data and system.
Your Rights
Subject to applicable law, you may have the following rights regarding your personal information:
β’Access: request a copy of the personal information we hold about you β’Correction: request that we correct inaccurate or incomplete data β’Deletion: request that we delete your personal information under certain circumstances β’Restriction: request that we restrict the processing of your information β’Objection: object to our processing of your information based on legitimate interests β’Portability: request that we transfer your data to another service provider β’Withdrawal of consent: withdraw your consent at any time where processing is based on consent
To exercise a right, contact privacy@acua.ai and describe your relationship with Acua and the request. We may verify identity and authority before acting and may request only the information reasonably necessary for verification. For a valid PDPA access request that is not subject to a lawful exception, we respond without delay and no later than 30 days after receipt. Other requests are handled within the period required by applicable law. If we refuse or limit a request, we will explain the lawful reason where required and record the decision. If the request concerns data controlled by an Acua customer, we will ordinarily refer the request to that customer and assist it as processor.
Regional Provisions
This section supplements the rest of this Privacy Policy with jurisdiction-specific information. Where there is a conflict between this section and the rest of the Privacy Policy for a data subject located in a named jurisdiction, this section prevails for that data subject.
Japan (APPI). For products or services contracted from or local activities conducted by Acua Co., Ltd., that Japanese entity is the personal information handling business operator for its own purposes. Its office is MIEUX Shibuya Building 8F, 5-3 Maruyamacho, Shibuya-ku, Tokyo 150-0044, Japan. Acua Japan also supports group administration and may provide or receive development, support, and service-delivery assistance under appropriate supervision and cross-border safeguards. Individuals may request notification of purpose, disclosure, correction, cessation of use, deletion, or cessation of third-party provision where available under the APPI, and may contact Japan's Personal Information Protection Commission.
European Economic Area and United Kingdom (GDPR / UK GDPR). Data subjects in the EEA or UK have the rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent described in this Privacy Policy. You also have the right to lodge a complaint with your local data protection supervisory authority.
Thailand (PDPA). For processing described in this Policy that relates to our Thailand operations, the controller is Acua (Thailand) Co., Ltd., HQ, Room 204, 2nd Floor, No. 31, Soi Sukhumvit 26 Yaek, Sukhumvit Road, Khlong Tan, Khlong Toei, Bangkok 10110, Thailand. Acua acts as controller or processor depending on the activity, as explained above. Data subjects have the rights provided by PDPA sections 19 and 30β36, subject to statutory conditions and exceptions. Requests and concerns may be sent to privacy@acua.ai. You may lodge a complaint with the Personal Data Protection Committee or its Office in Thailand.
Vietnam (Personal Data Protection Law). Acua Vietnam Co., Ltd., The Hive District 1, 2F, 26 Huynh Khuong Ninh, Da Kao Ward, District 1, Ho Chi Minh City 71007, Vietnam, principally performs product development and engineering for the Acua group and may also provide products, support, or other services locally. It acts as controller for its own local contracting, workforce, office, and customer-relationship purposes, and as processor or subprocessor when handling data on documented instructions from another Acua entity or customer. Processing involving individuals in Vietnam is governed by Law No. 91/2025/QH15 on Personal Data Protection, effective 1 January 2026, Decree No. 356/2025/ND-CP, and other applicable Vietnamese law. Individuals have the rights provided by that law, including to be informed, consent or withdraw consent where applicable, access, correct, request deletion or restriction, object, and complain to the competent authority, subject to statutory conditions.
California (CCPA / CPRA). California residents have the rights to know, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information, as described in the California Consumer Privacy Act as amended by the California Privacy Rights Act. Acua does not sell personal information. To exercise your rights, contact privacy@acua.ai.
Cookies & Tracking
We use strictly necessary cookies and local storage to provide security, authentication, language, and core website functions. We use analytics, preference, or marketing technologies only on an applicable legal basis and, where required in Thailand, Japan, Vietnam, or another relevant country, after obtaining consent through available cookie controls. You may reject or withdraw consent for non-essential technologies without losing access to core website functions. Browser settings may also be used, but blocking necessary storage can prevent sign-in or other essential features.
Children's Privacy
Our Services are business-to-business services and are not directed to minors. We do not knowingly invite minors to create accounts or submit personal data for their own use. If processing involving a minor requires consent or authorization, we obtain it from the minor and/or parent, guardian, or person with parental authority as required by the law of Thailand, Japan, Vietnam, or another applicable country. If you believe a minor has provided personal data improperly, contact privacy@acua.ai.
Policy Updates
We may update this Privacy Policy from time to time. When we make changes, we will revise the "Last Updated" date at the top of this page. For material changes, we will provide a more prominent notice, such as an in-product notification or email, or obtain your renewed consent where required by law.
Contact Information
For questions, rights requests, complaints, or concerns, contact privacy@acua.ai and identify your country, organization, relationship with Acua, and request. General inquiries may be sent to contact@acua.ai.
Thailand β Acua (Thailand) Co., Ltd., HQ, Room 204, 2nd Floor, No. 31, Soi Sukhumvit 26 Yaek, Sukhumvit Road, Khlong Tan, Khlong Toei, Bangkok 10110, Thailand
Japan β Acua Co., Ltd., MIEUX Shibuya Building 8F, 5-3 Maruyamacho, Shibuya-ku, Tokyo 150-0044, Japan
Vietnam β Acua Vietnam Co., Ltd., The Hive District 1, 2F, 26 Huynh Khuong Ninh, Da Kao Ward, District 1, Ho Chi Minh City 71007, Vietnam
The central privacy address routes the request to the responsible Acua entity and, where applicable, its data protection officer or qualified data-protection function. You may also contact the competent authority identified in the Regional Provisions.
Thailand β Acua (Thailand) Co., Ltd., HQ, Room 204, 2nd Floor, No. 31, Soi Sukhumvit 26 Yaek, Sukhumvit Road, Khlong Tan, Khlong Toei, Bangkok 10110, Thailand
Japan β Acua Co., Ltd., MIEUX Shibuya Building 8F, 5-3 Maruyamacho, Shibuya-ku, Tokyo 150-0044, Japan
Vietnam β Acua Vietnam Co., Ltd., The Hive District 1, 2F, 26 Huynh Khuong Ninh, Da Kao Ward, District 1, Ho Chi Minh City 71007, Vietnam
The central privacy address routes the request to the responsible Acua entity and, where applicable, its data protection officer or qualified data-protection function. You may also contact the competent authority identified in the Regional Provisions.