Privacy Policy
This policy explains how TRS NextGen ("we," "us") collects, uses, discloses, and protects personal data when you use the OrcaTMS platform — the web dashboard, the OrcaTMS Go driver app, and our marketing pages — in line with Thailand's Personal Data Protection Act B.E. 2562 (PDPA).
01Overview & Data Controller
For your organization's account data (admin name, email, phone) and platform usage data, the data controller is TRS NextGen.
For operational data your organization enters into the system (your customers, your drivers), your organization is the data controller; we act as a data processor on your instructions to provide the Service.
02Data We Collect
a) Account & registration data
- Company name, admin full name, email, phone, and password (stored hashed, never in plain text).
b) Operational data you enter
- Your customers' data (name, address, contact details).
- Driver data (name, phone, employee code, driving license number and expiry).
- Real-time GPS location and trip history of vehicles during active jobs, plus driving-behavior signals (e.g. speed, harsh braking).
- Photos (vehicle condition, fuel gauge) and electronic signatures captured as proof of delivery (POD).
- Financial data — quotations, invoices, payment records, tax data, driver compensation/payroll.
- Dispatch-chat messages between office and drivers, and their attachments.
- The driver app's device ID, IP address, and audit logs, for security purposes.
03Purpose & Legal Basis
| Purpose | Legal basis (PDPA) |
|---|---|
| Providing the core Service (dispatch, tracking, POD, finance, reports) | Performance of a contract |
| System security, fraud/abuse prevention | Legitimate interest |
| Transactional emails/notifications (verification, invoices) | Performance of a contract |
| Accounting and tax records as required by law | Legal obligation |
05Data Retention
- Account and operational data: retained while your subscription is active, and for a further period after cancellation for legal/accounting purposes (Thai law generally requires accounting records to be kept at least 5 years).
- GPS/driving-behavior data: retained for the period configured in the system for reporting and audit lookback.
- Backups: retained per the system backup cycle.
- Once any legally required retention period has passed, we delete the data or render it non-identifiable.
06Security Measures
- Tenant isolation — every request is scoped by organization ID at the application layer.
- All connections encrypted via HTTPS/TLS.
- Passwords stored hashed and non-reversible.
- Role-based access control and audit logging.
- Automatic daily backups.
No system is 100% secure. If you suspect a security incident, please notify us immediately via the contact details below.
07Your Rights
Under the PDPA, you have the following rights over your personal data:
- Right to access and obtain a copy of your data
- Right to rectification
- Right to erasure/deletion
- Right to restrict processing
- Right to data portability
- Right to object to processing or withdraw consent
- Right to lodge a complaint with the Personal Data Protection Committee (PDPC)
An end-user (e.g. a driver, or a customer of one of our customers) who wants to exercise rights over their own data should contact the organization they have a direct relationship with (their data controller), or reach us via the contact details below and we will coordinate as appropriate.
09Children's Data
This Service is designed for business (B2B) use and is not intended for direct use by minors under 20. If you become aware of inappropriate collection of a minor's data, please contact us.
10Changes to this Policy
We may update this policy periodically. Material changes will be announced in advance by email or an in-app notice.
11Contact
For questions about your personal data, or to exercise your PDPA rights, contact: