K KOVA A Siam Communications Company
  • How It Works
  • What's Included
  • Pricing
  • FAQ
Get Started — $97/mo →
Legal

Privacy Policy

Last updated: 20 August 2026 Effective: 20 August 2026 Controller: Siam Communications Co., Ltd.

On this page

  • 1. Who we are
  • 2. What we collect
  • 3. Your site credentials
  • 4. Why we use it
  • 5. Legal basis
  • 6. Who we share it with
  • 7. International transfers
  • 8. How long we keep it
  • 9. Security
  • 10. Your rights
  • 11. Cookies
  • 12. Children
  • 13. Changes
  • 14. Contact us

This policy explains what personal information Kova collects, why we collect it, who we share it with, and what control you have over it. We have written it in plain language rather than legal boilerplate, because you should be able to understand it without a lawyer.

1. Who we are

Kova is a WordPress maintenance service operated as a division of Siam Communications Co., Ltd., a company registered in Thailand and based in Bangkok. In data protection terms, Siam Communications Co., Ltd. is the data controller for the information described in this policy.

Throughout this policy, "we", "us" and "Kova" mean Siam Communications Co., Ltd. "You" means a customer, a prospective customer, or a visitor to this website.

2. What we collect

Information you give us directly

  • Account and billing details — your name, email address, and business name, collected when you subscribe.
  • Onboarding form data — first and last name, business name, contact email for reports, phone number (optional), your primary domain and any additional domains you want monitored, your hosting provider, and details of any known issues with your site.
  • Website access credentials — see section 3, which covers this separately because it deserves its own explanation.
  • Correspondence — the content of emails and support requests you send us.

Information collected automatically

  • Payment information — processed entirely by Stripe. We receive confirmation of payment, the amount, and your billing email. We never see or store your full card number.
  • Email engagement — whether our emails to you were delivered and opened, via Brevo.
  • Technical data about your website — uptime status, plugin and theme versions, update history, backup status and security scan results, collected by our management tooling.

3. Your site credentials

This is the most sensitive data we hold.

To maintain your WordPress site we require administrative access to it. During onboarding you provide a WordPress admin URL, username and password through our secure intake form.

We want to be direct about how this works:

  • Credentials are collected through a form, never by email, and we ask that you never send them to us by email or chat.
  • Access is used solely to perform the maintenance work you are paying for — updates, backups, security configuration, and any work you request under your monthly development hour.
  • Access is restricted to Kova personnel who need it to deliver the service.
  • We will never use your credentials to alter your content, install anything you have not agreed to, or access customer data held on your site beyond what is necessary to diagnose a fault.
  • You can revoke our access at any time by changing the password or removing our administrator account. If you do so while your membership is active, please tell us, or we will be unable to maintain your site.

When your membership ends, we delete our stored copy of your credentials. We also strongly recommend that you change your WordPress administrator password yourself at that point — this is the only way you can be certain that access has been revoked, and we would rather you rely on your own action than on our assurance.

4. Why we use it

PurposeData used
Delivering the serviceOnboarding details, site credentials, technical site data
Billing and subscriptionsName, email, payment confirmation from Stripe
Service communicationsName, email — welcome messages, monthly reports, dev hour reminders, incident alerts
SupportCorrespondence, site details
Legal and accounting obligationsTransaction records

We do not sell your personal data. We do not share it with advertisers. We do not use it to build marketing profiles, and we do not send you marketing about unrelated products.

5. Legal basis for processing

Where the Thailand Personal Data Protection Act B.E. 2562 (PDPA) applies, and where the EU/UK General Data Protection Regulation (GDPR) applies to customers located in those regions, we rely on the following grounds:

  • Performance of a contract — to provide the maintenance service you have subscribed to.
  • Legitimate interests — to secure and improve our service, and to communicate with you about your account.
  • Legal obligation — to keep accounting and tax records as required under Thai law.
  • Consent — where you have optionally given it, such as for a testimonial. You may withdraw consent at any time.

6. Who we share it with

We use a small number of third-party providers to run the service. Each processes data on our behalf under its own terms and privacy policy.

ProviderPurposeData shared
StripePayment processing and subscriptionsName, email, payment details
BrevoTransactional and service emailName, email
TallySecure onboarding formAll onboarding form responses
GoogleMember records and backup storageAccount details, onboarding data, site backups
GlowSite management, monitoring and reportingSite technical data, access credentials
RailwayHosting our internal automationAccount and onboarding data in transit

We may also share information with our parent agency, Bangkok Web Development, where you have asked for work that falls outside your membership — for example, malware remediation quoted separately. We will tell you before this happens.

We may disclose information where required by law, court order, or a lawful request from a competent authority.

7. International transfers

We are based in Thailand. Several of our providers are based in the United States or the European Union, so your data will be transferred outside Thailand and may be processed in countries whose data protection laws differ from your own. Where required, we rely on the providers' contractual safeguards, including standard contractual clauses, to protect that data.

8. How long we keep it

  • Account and onboarding records — for the duration of your membership, and for up to 12 months afterwards in case you return.
  • Site credentials — deleted when your membership ends.
  • Site backups — retained on a rolling 30-day window, then overwritten.
  • Billing and tax records — retained as long as Thai accounting law requires, currently five years.
  • Correspondence — retained while it remains relevant to supporting you.

9. Security

We limit access to your data to the people who need it, use reputable providers with their own security programmes, transmit data over encrypted connections, and collect credentials through a form rather than email.

No system is perfectly secure, and we will not claim otherwise. If a breach occurs that affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant authority as required by law, without undue delay.

10. Your rights

Depending on where you live, you may have the right to:

  • Ask what personal data we hold about you, and get a copy of it.
  • Have inaccurate data corrected.
  • Have your data deleted, where we have no overriding legal reason to keep it.
  • Object to or restrict how we use it.
  • Receive your data in a portable format.
  • Withdraw consent where our use was based on consent.
  • Lodge a complaint with a supervisory authority — in Thailand, the Personal Data Protection Committee.

To exercise any of these, email us at kova@siamcomm.com. We will respond within 30 days. We may need to verify your identity first.

11. Cookies

This website uses only what is necessary to display the page and load our fonts from Google Fonts, which may log your IP address as part of serving that request. We do not run advertising trackers or third-party analytics profiling on this site.

When you proceed to checkout, Stripe sets its own cookies necessary for payment and fraud prevention. Those are governed by Stripe's privacy policy.

12. Children

Kova is a business service and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to this policy

If we change this policy we will update the date at the top of this page. Where a change materially affects how we handle your data, we will email active members rather than rely on you noticing.

14. Contact us

Questions about this policy, or about the data we hold on you:

kova@siamcomm.com

Siam Communications Co., Ltd. (Head Office)
Tax ID: 0105561201459
19/125 Sukhumvit Suite Building, 13th Floor
Sukhumvit 13 Alley, Sukhumvit Road
Klong Toey Nua, Wattana, Bangkok 10110
Thailand

K KOVA A Siam Communications Company

WordPress maintenance for small businesses. Updates, security, backups and a dev hour every month.

  • How It Works
  • What's Included
  • Pricing
  • FAQ
  • Privacy Policy
  • Terms

© 2026 Siam Communications Co., Ltd.
Tax ID 0105561201459
19/125 Sukhumvit Suite Building, 13th Floor,
Sukhumvit 13 Alley, Sukhumvit Road,
Klong Toey Nua, Wattana,
Bangkok 10110, Thailand

kova@siamcomm.com
KOVA · WordPress maintenance, handled.
All rights reserved.