ที่ดินไทย

Government and law enforcement requests for user data

Applies to 45 INTELLIGENCE Company Limited, operator of teedinthailand.com.

Public authorities, law enforcement and regulators sometimes ask us for the personal data of our users. This document sets out the process we follow for every such request, whoever it comes from, so that we never disclose more about a user than the law requires.

1. Legality review comes first

We disclose nothing until the request has been reviewed and found lawful. Every request is checked for at least the following:

  • Verification of the requesting authority and official, through that authority's own published contact channels — never the contact details supplied in the request itself.
  • That the request is in writing, states its legal basis, and is signed by an authorised official.
  • That the authority has jurisdiction over us and over the data sought.
  • That the scope of the data sought is connected to the matter actually being pursued.

Requests arriving by telephone, chat or unsupported email are not acted on. We ask for a written request through official channels first.

2. Challenging unlawful requests

We do not comply with a request that fails the review above, or that:

  • states no legal basis, or a basis that does not cover the data sought;
  • is overbroad — for example, bulk user data, or data not tied to identified individuals;
  • conflicts with data-protection law or with users' fundamental rights.

In those cases we require written clarification, ask for the request to be narrowed, take legal advice, and object or challenge through whatever channels the law provides. Declining an unlawful request is our normal practice, not an exception.

3. Data minimisation

  • We disclose only the specific items named in the request, and add nothing further.
  • We never grant a third party access to our database, administrative systems, or any form of continuing access, under any circumstances.
  • Where a request covers a period or a group of people wider than necessary, we ask for it to be narrowed before responding.
  • We redact unrelated third-party data that happens to appear in the same records.

4. Documentation

We keep an internal record of every request, containing:

  • date received, requesting authority, and the official who signed it;
  • the legal basis cited and the scope of data requested;
  • the outcome of our legality review and the reasoning behind the decision;
  • exactly what was disclosed, or the grounds on which we refused;
  • who inside the company decided, and the date we responded.

Records are retained for no less than three years so that any response can be audited.

5. Notifying users

We notify the user whose data is sought, unless we are prohibited by law or court order, or unless notice would obstruct a lawful investigation. Where such a prohibition is time-limited, we notify the user once it expires.

6. Emergencies

Where there are reasonable grounds to believe a person faces an imminent risk of death or serious physical harm, we may disclose the minimum data necessary to prevent it without waiting. Such disclosures are recorded in full under section 4 and reviewed afterwards in every case.

7. Responsibility

Every request is decided by an authorised director of 45 INTELLIGENCE Company Limited. No employee, administrator or external service provider has authority to disclose user data to a public authority on their own.

Formal requests should be sent to sorasak.b@45int.co.th with the documentation described in section 1.

Questions about this policy: sorasak.b@45int.co.th