Who we are
This website is operated by BCIS Co., Ltd. (trading as 1% EVO), company registration number 0105542093468, registered at 11/23 Moo 2, Tha Sa-an, Bang Pakong, Chachoengsao 24130, Thailand.
We are the data controller for the personal data described in this notice under Thailand's Personal Data Protection Act B.E. 2562 (2019), the “PDPA”.
We also handle personal data of visitors and customers in Australia and Singapore. We follow the Thai PDPA as our baseline, and we apply the privacy laws of those countries where they apply to us.
What this notice covers
This notice covers this website, the enquiry form on it, our LINE Official Account once it is live, and the contact details of people we work with at client businesses. It does not cover the documents inside a client's own systems; those are handled under the written agreement for that engagement.
When we process personal data for a customer's own chatbot, booking or CRM system, the customer decides why the data is used and we process it for them under a written data-processing agreement. That data is not covered by this notice; contact that business first.
It also covers our social publishing service and the publishing dashboard behind it (Postiz, at postiz.1percentevo.com), which we host ourselves. Our team uses it for our own Facebook Page, Instagram, TikTok and YouTube accounts, and clients who engage us for content publishing use it to schedule and publish posts to social-media accounts they own. Client users receive their own login from us; there is no public sign-up.
Effective date: 8 October 2026.
What we collect
When you send an enquiry we collect exactly what the form asks for:
- your name and the name of your business;
- the contact channel you choose and its details: a LINE ID, a phone number, or an email address (you can give more than one);
- what you are interested in, chosen from a short list;
- an optional message of up to 500 characters and, optionally, how you heard about us.
When you visit the site our servers and our hosting provider log technical data: IP address, browser type, the pages requested, and the time of the request. We do not collect anything the form does not ask for, and we do not buy or append data about you.
When you send an enquiry we also record the country your connection appears to come from, read from our hosting provider's own connection data — never typed by you — and stored alongside that enquiry.
If you answer our cookie/consent banner, we keep a server-side record of your choice, to be able to prove it if ever asked: which option you picked, which categories that meant, when, a one-way hash of your IP address (never the address itself) that changes every day, and your browser family only (e.g. “Chrome”, never the full browser string). See how long we keep it below, and our cookie policy for what the banner itself stores in your browser.
Social-media accounts connected to our publishing dashboard. We schedule and publish posts through a dashboard we host ourselves (Postiz, at postiz.1percentevo.com): our own marketing posts, and posts for clients who engage us for content publishing. A client user of the dashboard gives us a name and a work email address for their login. When a business account on Facebook, Instagram, TikTok or YouTube is connected, that platform gives the dashboard:
- the account's ID, display name, username and avatar, so we can see which account is connected;
- its follower count and post or video count, for an internal analytics view;
- the list of posts that account has already published, so the tool can confirm a scheduled post went out and avoid publishing it twice;
- an OAuth access token and refresh token, which let the dashboard publish on that account's behalf.
For TikTok, the permissions we request are user.info.basic, user.info.profile, user.info.stats, video.list, video.upload and video.publish. TikTok data is used only to show which account is connected, to publish the posts that account's owner schedules, and to confirm they went out.
This is data about business accounts that we or our clients own and operate, not about the public. The dashboard does not read anyone's profile, posts or interactions beyond the connected account's own published posts, and we do not use it to build a profile of any individual. Tokens and account details are stored in the dashboard's own database on our server; media is stored in our own storage at media.1percentevo.com. The dashboard is reachable only by our team and by client users we have invited, behind an access gateway. We do not sell, rent or share this data.
Disconnecting an account in the dashboard, or revoking the app on the platform (for TikTok: Settings → Security → Manage app permissions), removes its tokens immediately. A client can also ask us to delete everything the dashboard holds about a connected account, including data obtained from TikTok, by writing to privacy@1percentevo.com; we do so within 30 days.
Why we collect it, and the legal basis
Replying to your enquiry and preparing a proposal. This is necessary to take the steps you asked for before entering a contract (PDPA section 24(3)). We do not need your consent for this, and we do not ask for it.
Keeping the site secure and improving it. Technical logs are used to detect abuse and keep the site working. This is our legitimate interest (section 24(5)), balanced against your rights; the logs are not used to profile you.
Marketing. We do not send marketing email. If we ever offer updates, that will be a separate, unticked choice under section 19, and you can withdraw at any time.
If you are in Australia or Singapore. In plain words: we use your data with your consent where the law requires it, to take the steps you asked for or to perform a contract with you, and for our legitimate interest in keeping the site secure and working. The Thai PDPA references above stay as our baseline.
Whether you have to give us anything
No. Sending the form is voluntary and there is no legal or contractual obligation to do so. If you leave out a working contact channel the only consequence is that we cannot reply.
How long we keep it
- Enquiries that do not become a client engagement: 12 months from our last contact with you.
- Client contact details and project records: 5 years, measured from the end of the engagement.
- Email and chat correspondence: 3 years from the last message in the thread.
- Technical server logs: 30 days, unless a specific log is needed to investigate abuse.
- Invoices and tax records, including those for customers in Australia and Singapore: for as long as Thai tax and accounting law requires us to keep them.
- Consent/cookie-banner records: 12 months from when you answered.
- Connection tokens and account details for social-media accounts connected to our publishing dashboard (ours or a client's): for as long as the account stays connected; removed when it is disconnected, or within 30 days of a deletion request.
When a period ends we delete the data or make it anonymous.
Who we share it with
We never sell personal data. We share it only with the people and providers we need to run the business, under written agreements:
- Hosting and delivery: Cloudflare, Inc. (United States) — Cloudflare Workers and Cloudflare's content delivery network; pages are served from the Cloudflare data centre nearest to you, normally inside Thailand for visitors in Thailand, and the application runs on Cloudflare's global network rather than in one fixed country.
- Enquiry delivery: the form is sent over an encrypted, signed connection to our own intake service, which we run on a virtual server we rent from DigitalOcean, LLC (a United States company), running in its Singapore data centre alongside our self-hosted CRM; no third-party form or CRM vendor receives the enquiry, which delivers it to the team.
- Analytics: Cloudflare Web Analytics, provided by Cloudflare, Inc. (United States) — aggregate page-traffic and performance measurement with no cookies and no browser storage; Cloudflare states that it does not store visitor IP addresses. PostHog, provided by PostHog, Inc., hosted in the European Union (Frankfurt) — heatmaps and session recording, loaded only after an affirmative opt-in on the consent banner, with all text and all form fields masked in the browser before anything is sent and the enquiry form excluded entirely; recordings are deleted after 30 days; it sets no cookie. Google Analytics 4, provided by Google LLC (United States) — visit measurement, loaded only after an affirmative opt-in on the consent banner, with advertising storage denied and your IP address anonymised before Google sees it; it sets the _ga and _ga_<container> cookies for up to 2 years. Microsoft Clarity, provided by Microsoft Corporation (United States) — heatmaps and masked session recording, loaded only after an affirmative opt-in on the consent banner, with the enquiry form and your name on the confirmation page masked in the browser before anything is sent and advertising storage denied so no advertising cookie is ever set; it sets the _clck cookie for up to 1 year and the _clsk cookie for up to 1 day on this site's own domain, and Microsoft sets a third cookie, CLID, for up to 1 year on its own domain (www.clarity.ms), which a withdrawal cannot erase because it is neither ours to read nor ours to delete.
- LINE: if you contact us through our LINE Official Account (opens in a new tab) (@1percentevo), LY Corporation processes that conversation under its own terms. Launch date: September 2026.
- AI tooling used on client work: Anthropic, PBC (United States), OpenAI (United States) and Google LLC (United States); whether any of them may see a client's documents, and for which tasks, is agreed in writing with each client before a build starts.
- Payments: where you pay by card, Stripe, our card-payment provider, processes the payment under its own terms and privacy policy, and may do so outside your country.
- Social-media platforms: when we publish a post from our publishing tool, that post and its media go to the platform it is published on — Meta Platforms (Facebook and Instagram), TikTok, or Google (YouTube) — and are then handled under that platform's own terms. The connection tokens described in section 03 are used only for that.
- Professional advisers, and public authorities where the law requires it.
Where a provider above handles personal data on our behalf, it does so as our service provider (sub-processor). For a customer's own chatbot, booking or CRM system, the providers that may handle that data are listed in the data-processing agreement for that engagement.
Sending data outside Thailand, and outside your country
Some of the providers above, and the social-media platforms we publish our own content to (Meta, TikTok and Google/YouTube), are outside Thailand, including in the United States. For visitors and customers in Australia and Singapore, that also means outside your country. The PDPA does not currently recognise any country as automatically adequate, so when we transfer personal data abroad we rely on contractual safeguards equivalent to standard contractual clauses (section 29), or on one of the exceptions in section 28, such as the transfer being necessary to perform what you asked us to do.
Status of those safeguards: in place through the data-processing terms in our agreements with each provider named above; where a transfer is not yet covered by such terms we rely on the section 28 exceptions, in particular that the transfer is necessary to perform what you asked us to do. You can ask us for details of the safeguard that applies to your data at any time.
If you are in Australia, where the Privacy Act 1988 applies to us we take reasonable steps in line with Australian Privacy Principle 8 before disclosing your data to overseas providers. If you are in Singapore, where the Singapore PDPA applies to us we take steps to ensure a comparable standard of protection (the PDPA's transfer limitation).
Client documents are a separate matter: which AI tools may see them, and from which country, is agreed in writing with each client before a build starts.
How we protect it
The site is served over HTTPS. Enquiries travel over an encrypted connection that is signed so that a tampered message is rejected. Access is limited to the people who need it to reply to you, and every provider that handles personal data for us is bound by a written agreement. We do not claim controls we do not operate.
If something goes wrong
If a personal-data breach is likely to put your rights at risk, we will notify the Office of the Personal Data Protection Committee without undue delay and, where feasible, within 72 hours of becoming aware of it, and we will tell you directly where the risk to you is high. For personal data of people in Australia or Singapore, where the law of those countries requires it we will also notify the Office of the Australian Information Commissioner (OAIC) or Singapore's Personal Data Protection Commission (PDPC Singapore), and the people affected.
Your rights under Thailand’s PDPA, and if you live elsewhere
สิทธิของท่านตามพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562
You have the right to:
- withdraw consent, where consent is the basis (section 19);
- access and obtain a copy of your personal data (section 30);
- receive it in a portable format, where it was collected with consent or under a contract (section 31);
- object to processing (section 32);
- have it erased or anonymised (section 33);
- restrict its use (section 34);
- have it corrected (section 36);
- complain to the Office of the Personal Data Protection Committee (section 73) if you believe we have not handled your data lawfully.
Requests are free. We respond within 30 days, and we will tell you if we need longer and why.
If you live elsewhere. Where the laws of Australia or Singapore apply to us, you can also:
- ask for access to your personal data and for it to be corrected (in Australia, Australian Privacy Principles 12 and 13; in Singapore, the access and correction rights in Singapore's PDPA);
- withdraw your consent, where consent is the basis for using your data;
- complain: contact us first at privacy@1percentevo.com. If you are in Australia you may then complain to the OAIC (www.oaic.gov.au (opens in a new tab)); if you are in Singapore, to PDPC Singapore (www.pdpc.gov.sg (opens in a new tab)).
How to exercise them
Write to privacy@1percentevo.com, for the attention of the Managing Director. We may ask you to confirm your identity before acting on a request, so that we do not release your data to someone else.
Children
This site is for business owners and managers and is not directed at anyone under 20, or under the age of majority where you live. We do not knowingly collect personal data from minors; if you believe we have, contact us and we will remove it.
Changes to this notice
We may update this notice. Material changes are posted here with a new effective date, and earlier versions are available on request.
Contact and complaints
BCIS Co., Ltd., 11/23 Moo 2, Tha Sa-an, Bang Pakong, Chachoengsao 24130, Thailand. Privacy questions: privacy@1percentevo.com. If you are not satisfied with our answer, you may complain to the Office of the Personal Data Protection Committee (PDPC), Thailand. If you are in Australia, you may complain to the OAIC (www.oaic.gov.au (opens in a new tab)) after contacting us; if you are in Singapore, to PDPC Singapore (www.pdpc.gov.sg (opens in a new tab)).
Language
This notice is published in English, with a Thai translation. Where the two differ, the prevailing version is: English.