1. Who is responsible for the data
Pontia is a business communication service owned and provided by KON Global Co., Ltd. (company registration no. 0105568137772), with its registered office at 748, 5th Floor, Soi Sukhumvit 30/1, Sukhumvit Road, Khlong Tan, Khlong Toei, Bangkok, Thailand. Responsibility depends on why the data is handled.
- The business decides why and how it communicates with customers and manages customer, appointment, order, industry-specific, and conversation information. For that information, the business is normally the data controller. KON Global handles the data to provide Pontia to the business and may use service providers acting under KON Global’s instructions.
- KON Global decides how Pontia accounts, authentication, platform security, support, and service administration data are handled. For those activities, KON Global acts as a data controller.
If you are a customer, the business you contacted is the first point of contact for requests about your conversation or related customer record.
2. Data Pontia may handle
- Business and team information, including names, work contact details, roles, and account status.
- Authentication and security information, including phone-based login records, session data, and audit events.
- Channel identifiers and customer contact information supplied by connected services.
- Conversation content, attachments, delivery status, internal notes, assignments, and tags.
- Customer context and industry-specific records entered by a business, which may include order, appointment, or pet information.
- Technical information needed to operate and secure the service, including error, access, and delivery records.
Businesses choose what they enter into Pontia. They should not add information that is unnecessary for customer communication or business operations.
3. Why the data is used
Pontia handles data to:
- authenticate business team members and enforce business-account access controls;
- receive, organize, assign, display, and send messages through connected channels;
- store attachments and provide business staff with relevant customer and industry-specific context;
- provide optional translation, search, and AI-assisted reply features when a business enables them;
- prevent abuse, investigate errors, maintain audit records, and protect the service;
- provide support and administer the business’s service agreement; and
- comply with applicable law and enforce legal rights.
The applicable legal basis depends on the activity and the business’s relationship with the person. It may include performance of a contract, compliance with law, legitimate interests that do not override individual rights, or consent where consent is required. Businesses remain responsible for selecting and documenting the basis for their customer communications.
4. Service providers and connected channels
KON Global may use service providers for hosting, database, authentication, file storage, delivery, monitoring, and support. Connected communication providers may include LINE, Meta services such as Facebook, Instagram, and WhatsApp, and a business’s email provider.
When an optional feature is enabled, relevant content may also be processed by the selected AI, translation, or search provider, which may include Anthropic, Moonshot AI (Kimi), Google, or Voyage AI. Pontia sends only the information required to perform the enabled function and does not give an AI system authority to make business or professional decisions.
Some providers process data outside Thailand. KON Global and the business must use appropriate contractual and operational safeguards for international transfers where required. Connected providers process data under their own terms and privacy notices as well.
5. Retention and deletion
Data is kept only while it is needed to provide Pontia, meet the business’s documented instructions, protect the service, resolve disputes, or comply with law. Different records require different retention periods. Business conversation retention, account closure handling, backup expiry, and mandatory audit retention are governed by the applicable service agreement, retention schedule, and legal obligations.
Images and videos that customers send to a business through connected messaging channels are kept in Pontia for 90 days after they are received and are then permanently deleted. Deleted images and videos cannot be restored, and the conversation shows that the file was deleted. This rule does not apply to the text of conversations, files such as documents, or media that the business sends.
A deletion request may be limited where data must be retained for a legal obligation, security investigation, dispute, or other lawful reason. See the data deletion instructions.
6. Security
Pontia uses business-account access controls, role-based permissions, encryption for sensitive channel credentials, signed access for stored media, webhook verification, audit records, and operational monitoring. No system is completely secure, and businesses must manage staff access and connected channel credentials responsibly.
7. Individual rights and requests
Subject to applicable law, a person may ask to access, correct, receive, restrict, object to, or delete personal data, or withdraw consent where processing relies on consent. Identity and authority may need to be verified before a request is completed.
Customers should contact the business through the same channel used for the conversation. Business team members should contact their account administrator or the KON Global contact named in the business’s service agreement. For requests concerning KON Global’s own controller activities, contact support@pontia.app.
8. Changes to this notice
This notice may be updated when Pontia’s features, providers, or legal obligations change. The current version will show its last-updated date. Material changes should also be communicated to affected businesses through an appropriate service channel.