Privacy Notice
1109 Prosper Company Limited
Effective date: 13 September 2026
1109 Prosper Company Limited (the “Company” or “1109”) is committed to protecting your personal data. This Notice explains the categories and sources of personal data the Company collects, the purposes and legal bases for using that data, the persons to whom the Company may disclose it, the applicable retention periods, your rights and how to contact the Company, in accordance with the Personal Data Protection Act B.E. 2562 (2019) and related laws.
1 Purpose and Scope of this Notice
This Notice applies to the collection, use and disclosure of personal data by the Company as a data controller in the course of its digital asset business as a Digital Asset Dealer. It covers service applications, account opening, the purchase, sale or exchange of digital assets, and related products, services and programmes operated by the Company in accordance with the law and within the scope of its authorisation, whether independently or together with counterparties or business partners. This includes Regulatory Sandbox programmes in which the Company participates, regardless of whether you contact the Company or use its services through a website, application, platform or any other channel provided by the Company.
This Notice covers the personal data of Thai and foreign individuals who are customers, counterparties or persons who contact or transact with the Company. It also covers the personal data of individuals associated with Thai or foreign juristic persons that are customers, counterparties or persons who contact or transact with the Company, such as directors, shareholders, ultimate beneficial owners, authorised signatories, attorneys-in-fact, representatives and contact persons of those juristic persons.
Products, services and programmes that the Company provides in the future are covered by this Notice to the extent that the nature and purposes of their data processing are consistent with those described in this Notice. If there is a material change, the Company will update this Notice or provide the relevant information in accordance with Section 12, before the relevant processing begins where prior notification is required by law.
2 Definitions
“You” means an individual whose personal data is processed under this Notice, whether a Thai or foreign national, including an individual associated with a juristic person within the scope of Section 1.
“Personal Data” means information relating to a person that enables that person to be identified, directly or indirectly, but excludes information specifically relating to a deceased person. Information relating to a juristic person is covered by this Notice only to the extent that it constitutes the personal data of an individual.
“Sensitive Personal Data” means personal data afforded special protection by law, such as data concerning racial origin, religion, political opinions, health, criminal records and biometric data used to uniquely identify a person.
“Services” means the Company's products, services and programmes within the scope of Section 1, including related activities before, during and after the provision of Services.
“Partners” means counterparties or business partners that work with the Company to offer, connect or provide Services, such as digital asset business operators, banks, payment service providers, electronic money service providers and participants jointly operating Regulatory Sandbox programmes.
“Processing” means the collection, use or disclosure of personal data.
3 Categories of Personal Data
The Company collects personal data according to the nature of your relationship with the Company, the Services about which you enquire or which you use, and the Company's legal obligations. The Company collects only data that is appropriate and necessary for the purposes set out in Section 5. This may include the following categories of data.
3.1 Identification and contact data: for example, your first name and surname, former names, date of birth, nationality, national identification number, passport number, tax identification number, photograph, signature, address, telephone number, email address, and details or copies of identification documents. Where a Service or programme has requirements relating to travel or residence, this may also include information on entry into the country, length of stay and documents used to verify participants' eligibility.
3.2 Data relating to juristic persons and associated individuals: for example, your position, signing authority or authority to act; personal data appearing in corporate registration certificates; lists of directors and shareholders; ownership and control structures; ultimate beneficial owner information; powers of attorney; and information establishing your relationship with a juristic person that is a customer or counterparty of the Company, including identification documents and contact details of associated individuals.
3.3 Occupational, financial and suitability data: for example, your occupation, place of work, type of business, income, financial standing, source of funds or assets, investment or transaction objectives, knowledge and experience relating to digital assets, investment suitability assessment results, bank or electronic money account information, and evidence of receipts or payments.
3.4 Account and transaction data: for example, customer identifiers, account status, trading orders, agreed prices, the quantity and type of digital assets, fees, transaction dates and times, settlement information, outgoing or incoming transfers, digital asset wallet addresses, blockchain transaction references (Transaction Hashes), the networks used and balances relating to the Services, as well as information on transferors and transferees and supporting transaction documents.
3.5 Verification and risk assessment data: for example, information and results relating to identity proofing and verification; know-your-customer and know-your-business checks (KYC/KYB); customer due diligence and enhanced due diligence (CDD/EDD); politically exposed person (PEP) status; results of screening against designated person or sanctions lists; information on mule accounts or fraudulent activity; relevant adverse media; and results of checks on the source of funds or digital assets. This also includes the results of transaction and digital asset wallet analysis, transaction linkages, risk ratings, alerts and findings from investigations into unusual activity.
3.6 Technical and usage data: for example, IP addresses, device identifiers and attributes, operating systems, browsers, network information, approximate location derived from IP addresses, login logs, access and usage history, API connection data, cookies and security event logs. This also includes device analysis data (Device Intelligence) used to detect unusual access or transactions.
3.7 Communications and rights request data: for example, messages and documents you provide to the Company; service records from platforms, chat, email and telephone channels; audio or video recordings of conversations on recorded channels; enquiries, complaints and their outcomes; requests to exercise rights; records of consent or its withdrawal; and your preferences for receiving communications. The Company will notify you when audio or video is recorded through the relevant channel.
3.8 Data relating to Services provided with Partners and programme participation: for example, reference identifiers used to connect with Partners, application or participation status, eligibility and identity verification results, service limits and usage amounts, transaction or payment status, reconciliation results, service disruptions, complaints and information used to monitor or evaluate a programme. This is limited to data relevant to the Company's role in the Service or programme you use or participate in.
4 Sources and Collection of Personal Data
4.1 The Company collects data directly from you when you make an enquiry, apply for Services or open an account, submit documents, verify your identity, use Services, conduct transactions, participate in a programme or exercise your rights. The Company also collects technical data from your use of its systems as described in Sections 3.6 and 11.
4.2 The Company may receive data from customers or persons associated with you, such as a juristic person of which you are a director, shareholder or contact person, a person granting authority to act, a customer introducer or a transaction counterparty. This also includes Partners through whose channels you apply for or use Services.
4.3 To provide Services and carry out checks for the purposes set out in Section 5, the Company may receive data from banks, payment service providers, digital asset business operators, identity proofing and verification service providers, risk screening database and blockchain analytics providers, regulators and government agencies. The Company may also obtain data from publicly available sources, such as corporate registers, designated person lists, relevant news and blockchain networks. The Company may verify and link this data with data it already holds to confirm its accuracy and assess customer or transaction risk.
4.4 Where the Company collects data from other sources, it will provide the required information to you within the period and in the manner prescribed by law, unless a statutory exception applies. If you provide another person's data to the Company, please inform that person of this Notice and ensure that you have the right or an appropriate legal basis to provide that data.
4.5 Certain data is necessary to enter into a contract, provide Services or comply with the law, such as identification data and information required for customer due diligence. If the Company does not receive the necessary data or cannot verify its accuracy, it may be unable to open an account, carry out a transaction or provide the relevant part of the Services, or may need to suspend or terminate Services in accordance with the law and the terms of service. Providing data or consent for marketing purposes is optional and is not a condition of using the core Services.
5 Purposes and Legal Bases for Processing
The Company processes personal data for the following purposes, relying on the legal basis appropriate to each processing activity. Where the Company relies on legitimate interests, it will give particular consideration to the necessity of the processing.
5.1 Applications, account opening and customer relationship management: to receive and assess service applications, verify information and the authority of representatives, prepare contracts, open and manage accounts, assign access rights, assess suitability for investment or use of Services, update customer information and communicate about accounts or terms of service. For these purposes, the Company uses your identification, contact, corporate, occupational, financial and account data.
The Company relies on the necessity of entering into or performing a contract with you and compliance with laws relating to eligibility and customer onboarding. For data relating to representatives or individuals associated with corporate customers, the Company relies on legal obligations and its legitimate interests in verifying authority and managing the relationship with the relevant customer.
5.2 Provision of Services and execution of transactions: to receive and confirm orders, quote or confirm prices, purchase, sell or exchange digital assets, verify ownership of relevant accounts or wallets, settle transactions, transfer or receive funds and digital assets, reconcile records, issue supporting records, collect fees, correct transactions and handle account matters when Services end. This includes connecting these processes with the systems of Partners providing services to you.
This processing involves account, transaction, financial and identification data and necessary reference information. The Company relies on performance of its contract with you and its legal obligations. For data relating to transferors, transferees or other persons who are not parties to a contract with the Company, the Company relies on legal obligations or its legitimate interests in properly executing and verifying transactions.
5.3 Know-your-customer checks and anti-money laundering: to carry out identity proofing and verification, KYC/KYB and CDD/EDD; check ultimate beneficial owners, PEPs, designated or sanctioned persons, mule account information, adverse media and the source of funds or digital assets; assign and review risk ratings; examine suspicious transactions; and prepare or submit reports relating to anti-money laundering and countering the financing of terrorism (AML/CFT).
The Company uses the data described in Sections 3.1 to 3.5 and relevant supporting verification information, relying on compliance with laws governing digital asset businesses, anti-money laundering laws and rules applicable to the Company. Risk checks beyond those required by law are based on the Company's legitimate interests in preventing its Services from being used for fraud or unlawful activity, within a scope proportionate to the relevant risks.
5.4 Transaction monitoring, fraud prevention and security: to trace digital assets and identify linkages using Blockchain Analytics and know-your-transaction (KYT) checks; monitor transaction patterns; detect impersonation, unauthorised account access, the use of high-risk devices or networks and cyber threats; investigate unusual activity; conduct retrospective reviews; and preserve evidence.
The Company processes transaction data, digital asset wallet data, risk assessment results, device data, system logs and relevant communications data, relying on its legal obligations relating to business regulation and security and its legitimate interests in protecting accounts, assets, systems and users of the Services.
Analytical results may inform risk ratings, requests for additional information or decisions to suspend or reject transactions in accordance with the law and the terms of service. If you believe that information used in making an assessment is inaccurate, you may contact the Company to request a review or correction in accordance with Section 9.
5.5 Services provided with Partners and programmes under regulatory supervision: to assess eligibility and admit participants, connect accounts or transactions across service providers, verify entitlements and limits, track transaction completion and manage the joint provision of Services. This includes system testing, resolving disruptions, handling complaints, evaluating service delivery and preparing reports under the conditions of programmes in which the Company participates, such as TouristDigiPay or pilot programmes involving digital asset services and connections with financial services under the supervision of the Office of the Securities and Exchange Commission, the Bank of Thailand or other relevant competent authorities.
The Company uses eligibility and identification data, account status, verification results, transaction data and programme information according to its role, relying on entering into or performing a contract with you, legal obligations or legally binding conditions of authorisation, and its legitimate interests in connecting Services, verifying outcomes and managing programme risks. For testing or evaluation that does not require individuals to be identified, the Company will use aggregated or anonymised data. Where an activity requires consent, the Company will obtain it before proceeding.
Details of data exchanges with Partners and relevant authorities are set out in Section 6. This Notice applies only to those parts of a Service or programme for which you apply, which you use or in which you are involved.
5.6 Customer service, complaints and the exercise of rights: to respond to enquiries, provide assistance, verify instructions and service delivery, resolve complaints or disputes, review service quality and assess requests to exercise personal data rights. The Company uses contact data, communications records, account and transaction data and relevant evidence, relying on performance of its contract with you, its legal obligations concerning complaint handling and personal data protection, and its legitimate interests in investigating and resolving service issues.
5.7 Business administration and legal compliance: to maintain accounting and tax records, prepare reports, conduct internal and external audits, comply with lawful orders or requests from courts, regulators and government agencies, establish, exercise or defend legal claims, and undertake activities relating to a restructuring or transfer of business. The Company uses data relevant to the matter concerned, relying on legal obligations or its legitimate interests in administering and auditing its business and protecting its rights, as applicable.
5.8 Service development and marketing communications: the Company may use usage data, feedback and complaints to analyse performance, remedy deficiencies and improve Services, relying on its legitimate interests in improving service quality. The Company uses aggregated data where identifying details are not necessary for the analysis.
To send offers, promotions or marketing communications, the Company uses your contact details and interests that you have indicated or that relate to your use of Services, obtaining consent where required by law. Where the Company relies on legitimate interests, it will limit communications to existing customers about services similar to those they already use and within their expectations. You may opt out of direct marketing at any time through the channel provided in the communication or as described in Section 13, without affecting your use of the core Services. The Company will provide data to Partners for their own marketing only with your consent.
6 Disclosure and Exchange of Personal Data
The Company may transmit, link, exchange or disclose data for the purposes and on the legal bases set out in Section 5. The categories and level of detail of the data will be limited to what is appropriate to the recipient's role and the relevant activity, as follows.
6.1 Persons or entities that may receive data
(a) Partners and transaction service providers, including digital asset business operators, banks, payment service providers, electronic money service providers and entities jointly operating programmes, to connect Services, verify identities and accounts, execute or confirm transactions, make or receive transfers, reconcile records and resolve related issues. This also includes service providers of transferors or transferees that are required by law to receive information accompanying transactions.
(b) Identity proofing and risk screening service providers, including providers of KYC/KYB services, risk databases on individuals, AML/CFT screening, blockchain analytics, KYT, fraud prevention and security services, to carry out checks and report the results to the Company for the purposes set out in Sections 5.3 and 5.4.
(c) Operational support service providers, including providers of information technology systems, APIs, cloud services, data storage or backup, communications, access authentication, customer support and document storage or destruction, to support the functions assigned to them by the Company.
(d) Advisers and auditors, including financial auditors, systems auditors, legal and tax advisers and other professional advisers, to provide advice, conduct audits or handle legal claims, subject to the relevant confidentiality obligations.
(e) Regulators, government agencies and persons with statutory authority, including the Office of the Securities and Exchange Commission (SEC Office), the Bank of Thailand, the Anti-Money Laundering Office (AMLO), the Office of the Personal Data Protection Committee, the Revenue Department, courts, the police and other relevant authorities, to submit reports, provide information for regulatory supervision or investigations, and comply with lawful orders or requests. This also includes programme reporting and evaluation within each authority's statutory remit.
(f) Persons involved in a restructuring or transfer of business, such as transferees of the business or rights, parties to a merger and their advisers, limited to data necessary for due diligence and completion of the transaction and subject to appropriate confidentiality and data protection safeguards.
(g) Persons whom you request or authorise to receive data, such as an attorney-in-fact or a service provider to whom you ask the Company to send data, after verification of the relevant authority and the scope of the request.
6.2 Scope of data exchanges in joint Services and Sandbox programmes: when you use Services connected with Partners, the Company may send data to and receive data from Partners through APIs, electronic systems or channels used to operate the programme. The data exchanged depends on the stage of the Service, as follows.
(a) Application and eligibility verification: identification data, customer reference identifiers, identity proofing results and status, eligibility verification results, and information or supporting documents necessary for the recipient's checks. Full documents or biometric data will be transmitted only where necessary and where there is a legal basis for the relevant category of data.
(b) Connection and execution of transactions: linked account or wallet identifiers, transferor or transferee information, reference numbers, amounts of money or digital assets, transaction dates and times, limits, usage amounts and processing status, to enable each party to carry out its part of the transaction, confirm the outcome and reconcile records.
(c) Risk checks and issue resolution: verification results or alerts relating to a customer or transaction, reasons for further checks, details of unusual activity, complaints and outcomes, to enable the relevant parties to investigate and address the same matter. Disclosure is subject to legal restrictions, including the confidentiality of suspicious transaction reports.
(d) Programme monitoring and closure: participant status, transaction outcomes, information on disruptions and their resolution, and data required for reporting, evaluation, retrospective reviews, the return of funds or assets, and the closure or termination of service connections under the programme conditions. Identifiable data will be used only where necessary for the relevant activity or review.
For example, if you use Services under the TouristDigiPay programme in which the Company participates, the Company may exchange identification data, eligibility verification results, account identifiers, information on the sale of digital assets for Thai baht and the status of transfers of funds into the electronic money system with the relevant service providers, to connect transactions and verify that Services are used within the programme limits and conditions. Any spending data the Company receives from an electronic money service provider will be limited to what is necessary for the Company's role and the programme requirements.
6.3 Protection of disclosed data: service providers processing data on the Company's instructions or behalf must do so under agreements specifying the scope of work, confidentiality obligations and data protection measures required by law. Partners or recipients that determine their own processing purposes and means have obligations as data controllers for that processing. Details of how those persons use data and how to exercise rights with them are available in the relevant recipients' privacy notices.
Data exchanges for the joint provision of Services are limited to purposes related to your Services. Any use for another purpose must have a legal basis and be accompanied by notification or the obtaining of consent as required by law.
6.4 Data on blockchain networks: blockchain transactions may cause digital asset wallet addresses, asset amounts, timestamps and transaction reference data to be recorded on the network and accessible to others, depending on the nature of that network. This information may constitute personal data where it can be linked to you. Technical limitations may affect the amendment or deletion of data recorded on the network. The Company will consider rights requests concerning data under its control in accordance with the law and to the extent that it is able to act on them.
7 Cross Border Transfers of Personal Data
7.1 The use of Partners, cloud providers, identity verification systems, risk analysis systems or other support service providers may involve transmitting, storing or backing up data abroad, or allowing access to data from abroad, whether by those providers directly or by their relevant subcontractors, for the purposes set out in this Notice.
7.2 Where these activities constitute a cross-border transfer of data under the law, the Company will comply with the applicable requirements. This may involve transferring data to a country or international organisation with adequate data protection standards, providing appropriate safeguards with enforceable rights and effective remedies, including contractual data protection provisions recognised by law, or relying on a statutory exception applicable to the circumstances.
7.3 Where it is necessary to rely on consent for a transfer to a destination that does not have adequate data protection standards, the Company will inform you of that lack of adequate protection and obtain your consent before the transfer. You may contact the Company using the details in Section 13 to enquire about transfers and safeguards relating to your data.
8 Retention of Personal Data
8.1 The Company retains data in paper or electronic form for as long as necessary for the purposes for which it was collected, taking into account the duration of the Services, statutory retention obligations, the need to verify transactions, complaint handling and the limitation periods for relevant legal claims.
8.2 For data subject to anti-money laundering laws, the Company retains identification records for five years from the date of account closure or termination of the customer relationship, and transaction details and records of facts for five years from the date of the transaction or the recording of those facts. Customer due diligence records are retained for ten years from the date of account closure or termination of the customer relationship. Longer retention may be required under a lawful order or other laws applicable to the same data.
8.3 Account data and records of the provision of Services that are subject to digital asset business regulations, accounting or tax laws, or legally binding programme conditions will be retained for the periods specified by those requirements. Where more than one requirement applies to the same data, the Company will apply a retention period that enables it to fulfil all applicable legal obligations.
8.4 Where no fixed statutory retention period applies, the Company uses the following criteria
(a) Data relating to prospective customers or applicants who have not begun using Services is retained to assess and communicate about their applications until that process is complete, unless it is necessary to retain evidence of checks, customer rejection or fraud prevention in light of applicable law or relevant risks.
(b) System usage logs and security data are retained for the period necessary to detect and investigate unusual activity, maintain security and conduct retrospective reviews, taking into account the type of log and system risks.
(c) Communications and complaints data is retained until the matter is resolved and thereafter to the extent necessary as evidence of the outcome or for related legal claims.
(d) Marketing data is retained until you withdraw consent or object, or the Company ceases to use the data for that purpose. The Company may retain data to the extent necessary to record your marketing opt-out and respect your preferences.
8.5 Where data relates to an investigation, dispute, legal proceedings or an order of a competent authority, the Company may retain the relevant data until the matter is concluded and there is no longer a legal need to retain it. Once the retention period expires and there is no reason for further retention, the Company will delete, destroy or anonymise the data. Data in backup systems will be handled in accordance with the systems' backup and deletion cycles.
9 Your Rights as a Data Subject
You have the following rights under personal data protection law. The exercise of each right is subject to the conditions and exceptions prescribed by law.
9.1 Withdrawal of consent: you may withdraw consent at any time for processing based on consent, without affecting the lawfulness of processing carried out before its withdrawal. If withdrawal affects any part of the Services, the Company will inform you of the consequences. Withdrawal of marketing consent does not affect your use of the core Services.
9.2 Access and copies: you have the right to request access to and a copy of your personal data for which the Company is responsible, and to request disclosure of how data obtained without your consent was acquired.
9.3 Rectification: you have the right to request that your data be accurate, up to date, complete and not misleading, and to provide supporting information or evidence for the Company to verify.
9.4 Erasure or anonymisation: you have the right to request that data be deleted, destroyed or anonymised, for example where it is no longer necessary, has been unlawfully processed, or where you withdraw consent and there is no other legal basis for continued retention. The Company may nevertheless need to retain data as required by law or for legal claims recognised by law.
9.5 Objection: you have the right to object to processing based on legitimate interests or another legal basis in respect of which the law provides a right to object. The Company will act in accordance with the requirements governing that right. You may object to direct marketing at any time, and the Company will stop using your data for that direct marketing.
9.6 Restriction of use: you have the right to request restriction of the use of your data in the circumstances prescribed by law, for example while its accuracy is being verified, while an objection is being considered, or where you wish the data to be retained for legal claims instead of being erased.
9.7 Data portability: you have the right to receive data in a format readable or usable by automated tools or equipment, and to request that it be sent or transferred to another data controller where this can be done by automated means. This right applies to data and processing that meet the legal requirements, such as automated processing based on consent or contract.
9.8 Complaints: you have the right to lodge a complaint with an Expert Committee under personal data protection law if you believe that the Company, a data processor or relevant personnel have breached or failed to comply with the law. You may contact the Office of the Personal Data Protection Committee to access its complaint channels.
You may submit a request using the channels in Section 13, specifying the right you wish to exercise and providing relevant information to enable the Company to verify the request. The Company may request additional information to the extent necessary to verify the identity or authority of the person making the request, and will act within the statutory time limit. For access and copy requests that cannot lawfully be refused, the Company will act without delay and no later than 30 days from receipt of the request.
Where there are grounds to refuse or limit action on a request, such as statutory retention obligations or an impact on the rights and freedoms of others, the Company will inform you of the reasons to the extent permitted by law. Closing an account or terminating Services may therefore not result in the immediate deletion of all data.
10 Security of Personal Data
The Company implements organisational and technical measures appropriate to the nature and risks of the data to prevent loss and unauthorised or unlawful access, use, alteration, modification or disclosure. These include role-based access rights, user authentication, controls over data transmission and storage, and security event monitoring, as well as confidentiality obligations for personnel and data protection requirements for relevant service providers.
The Company reviews these measures when necessary or when technology and risks change, and handles personal data breaches, including notification to the Office of the Personal Data Protection Committee and affected data subjects, in accordance with the conditions and time limits prescribed by law.
11 Cookies and Similar Technologies
The Company may use cookies and similar technologies to enable its website or applications to function, authenticate logins, maintain security and remember necessary settings. For usage analytics or advertising that requires consent, the Company will obtain consent before using the relevant technology.
You may view details and manage your preferences through the cookie management options displayed in the relevant Services or through your browser or device settings. Disabling necessary cookies may prevent parts of the Services from functioning fully.
12 Updates to this Notice and Your Information
12.1 The Company may update this Notice to reflect changes in its Services, operations or the law. The updated Notice and its effective date will be published on the Company's website or service channels, and material changes will be communicated through channels appropriate to the Company's relationship with you.
12.2 Where a new Service or programme involves processing that differs materially from what has been notified, the Company will provide details of the changes before the relevant processing begins, either in this Notice or during the application for or use of that Service. Where data is to be used for a new purpose that requires consent, the Company will obtain consent before proceeding, unless the law permits it to proceed without consent.
12.3 To enable the Company to contact you and provide Services accurately, please notify the Company of changes to your information through the relevant service channels, such as changes to your contact details, identification documents or a representative's authority.
13 Contact Details
If you have questions about this Notice, wish to enquire about your data or would like to exercise your rights, you may contact the Company or its Data Protection Officer as follows.
1109 Prosper Company Limited
Office address: 67/1 Soi Sukhumvit 39 (Phrom Phong), Sukhumvit Road, Khlong Tan Nuea Subdistrict, Watthana District, Bangkok
Data Protection Officer
Email: DPO@1109x.net