Legal

Terms of Service

Last updated: July 20, 2026

1

Introduction

These Terms of Service ("Terms") govern your access to and use of Inboxly's website, software, and services ("Services") provided by BUNGFAI TECH Co., Ltd., juristic person registration no. 0105569112366, registered office at 245/60 Moo Ban Sin Poem, Pracha Ruam Jai Road, Sai Kong Din Tai, Khlong Sam Wa, Bangkok 10510, Thailand ("the Company", "Inboxly", "we", "us", or "our"). Please read these Terms carefully before using our Services. By creating an account or using our platform, you agree to be bound by these Terms and our Privacy Policy.
2

Acceptance of Terms

By accessing or using the Services, you confirm that you are at least 18 years old, have the legal authority to enter into this agreement, and accept these Terms on behalf of yourself or the organization you represent. If you do not agree to any part of these Terms, you must not use our Services. We reserve the right to update these Terms at any time. Continued use of the Services after changes constitutes acceptance of the revised Terms.
3

Our Services

Inboxly provides a cloud-based omnichannel customer support platform that enables businesses to manage customer communications across multiple channels. LINE and Facebook Messenger are currently available, with additional channels (such as Shopee, Lazada, WhatsApp and email) rolling out over time. We reserve the right to modify, suspend, or discontinue any aspect of the Services at any time with reasonable notice. We are not liable to you or any third party for any modification, suspension, or discontinuation of Services.
4

Account Registration & Responsibilities

To use most features, you must create an account. You agree to: • Provide accurate, current, and complete registration information. • Maintain the security of your account credentials and not share them with unauthorized parties. • Promptly notify us of any unauthorized access to your account. • Take responsibility for all activities that occur under your account. You may not use a false identity or impersonate another person or company. We reserve the right to terminate accounts that violate these requirements.
5

Payment & Billing

Premium is paid in advance as a one-time charge covering a 30-day access period. It does not auto-renew and your payment method is not charged again. You may request a full refund within the first 7 days after payment by contacting [email protected] with your account email; we process these within 3 business days. After that period fees are non-refundable except where required by applicable law. • Prices are listed in Thai Baht (THB) and subject to change with 30 days' notice. • When the 30-day period ends without payment for a further period, the account enters read-only mode for 15 days and is then suspended. Your data is retained for the period stated in our Privacy Policy. • You are responsible for all applicable taxes. The Starter plan is free for as long as you use it and requires no credit card. Because Premium is not an auto-renewing subscription there is nothing to cancel — if you do not pay for a further period, access simply ends.
6

Prohibited Use

You agree not to use the Services to: • Violate any applicable law, regulation, or third-party rights. • Send spam, unsolicited messages, or engage in phishing activities. • Upload or transmit viruses, malware, or any harmful code. • Attempt to gain unauthorized access to any system or network. • Harvest or scrape data from our platform without authorization. • Use the Services to harass, threaten, or harm any individual. • Resell or sublicense the Services without written permission. Violation of these prohibitions may result in immediate account termination without refund.
7

Data Retention & Deletion

Messages and attachments older than 30 days are automatically deleted, across all plans: • Messages: 30 days. • Images and files: 30 days. Deletion runs daily at 10:00 AM Bangkok time (03:00 UTC). Daily aggregate statistics (message counts, conversation totals) are preserved as anonymous rollups before deletion so historical analytics remain functional. Use the "Download data" feature in Billing settings to export all data before deletion. For full details on personal-data retention, see our Privacy Policy.
8

Data Processing Agreement

This section is the data processing agreement between you and us. It is provided so that you, as Data Controller, can discharge your obligation under Section 40 paragraph 3 of Thailand's Personal Data Protection Act B.E. 2562, which requires a Controller to put in place an agreement with its Processor. It takes effect when you accept these Terms. 1. Roles of the parties For the personal data of your end customers that enters the platform through the channels you connect — names, profile pictures, message content and attachments — you are the Data Controller and Inboxly is the Data Processor acting on your behalf. For your own account data (name, email, billing details, usage records), Inboxly is the Data Controller, as described in our Privacy Policy. 2. Scope of processing • Purpose: solely to provide the unified messaging platform described in these Terms. • Categories of data: channel identifiers, names and profile pictures, message content, attachments, and contact details you record yourself. • Data subjects: your customers and contacts. • Duration: for the term of your subscription, subject to the retention period of your plan. 3. Processing on documented instructions We process personal data only on your instructions, as expressed through your use of the platform and these Terms. We do not sell your customers' data, do not use it for advertising, and do not use it to train our own AI models. Where you enable the AI assistant, we access language model providers through commercial APIs whose terms provide that data submitted via the API is not used to train the provider’s models. Where the law requires us to process beyond your instructions, we will tell you first unless the law forbids it. 4. Security measures • TLS 1.2 or higher in transit, with TLS 1.3 preferred; AES-256-GCM at rest for connected-channel credentials and two-factor authentication secrets. • Role-based access control and tenant data isolation enforced in the application layer. • Cryptographic signature verification on inbound messages using each channel’s supported mechanism, rejecting anything that cannot be verified. Channels for which the provider offers no signing mechanism are refused inbound traffic entirely. • Sign-in events and significant changes recorded in an audit log. 5. Personnel Access is limited to those who need it to operate and support the service, under confidentiality obligations that survive the end of their engagement. 6. Sub-processors You authorise us to engage the third-party providers necessary to deliver the service. The complete list is published in our Privacy Policy. We bind each sub-processor to data protection obligations no less protective than those in this section and remain responsible to you for their performance. Before adding or replacing a sub-processor we will give you at least 30 days’ prior notice, by email to your registered address and by updating the Privacy Policy. If you object on reasonable data protection grounds within that period, the parties will discuss in good faith; failing agreement, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees. 7. International transfers Our infrastructure runs on Contabo GmbH in France, and certain sub-processors listed in our Privacy Policy are located outside Thailand. Transfers abroad are made in reliance on Section 28(3) of the Personal Data Protection Act B.E. 2562 — necessity for the performance of a contract to which you are a party — together with data protection contractual clauses we maintain with each sub-processor. Where you configure outbound webhooks in automations, message content is transmitted to endpoints you specify; those transfers are made on your instruction and under your responsibility. 8. Data subject requests If a data subject contacts us directly about data we process on your behalf, we will forward the request to you and will not respond ourselves unless you instruct us to. Account-level export and account deletion tools are built into the platform. For requests concerning an individual data subject, we will provide reasonable assistance to help you respond. 9. Personal data breach notification On becoming aware of a personal data breach affecting data we process on your behalf, we will notify you without undue delay and, where feasible, within 48 hours of becoming aware, so that you retain sufficient time to discharge your own notification duty under Section 37(4). Our initial notice will contain the information available at that time about the nature of the breach, the data affected, and the steps we have taken; we will supplement it as our investigation progresses. Such notice is not an acknowledgement of fault or liability. The obligation to notify the Personal Data Protection Committee and affected data subjects remains yours as Controller. 10. Deletion on termination When you close your account we delete the personal data processed on your behalf, following the process and timeframes set out in our Privacy Policy. You can export your data using the in-product tools before closing. Data we are required by law to retain is excepted. 11. Audit On not less than 30 days’ prior written request, and no more than once per year, we will provide our confidential security measures summary so you can verify compliance with this section. Bespoke questionnaires or verification beyond that document may be charged at our reasonable rates, except where requested following a confirmed personal data breach. Because our infrastructure is operated by third-party providers, we cannot grant data centre access rights. Where an on-site audit is required by law or a regulator, the parties will agree a reasonable scope and method. 12. Record of processing activities We prepare and maintain a record of the personal data processing activities we carry out on your behalf, as required by Section 40(3) of the Personal Data Protection Act B.E. 2562, and will make the portion relevant to you available on reasonable request. 13. Liability Liability under this section is subject to the Limitation of Liability section of these Terms, except where the law does not permit liability to be limited.
9

Termination

Either party may terminate this agreement at any time. You may cancel your account through the account settings page. Upon termination: • Your access to the Services will be disabled immediately (or at end of billing period for paid plans). • Your data remains subject to the retention policy of your last active plan (see the "Data Retention & Deletion" section). • You may request a data export before deletion. We may suspend or terminate your account immediately for material breach of these Terms, non-payment, or activity that poses security or legal risks.
10

Limitation of Liability

To the maximum extent permitted by applicable law, Inboxly and its directors, employees, partners, and agents shall not be liable for any indirect, incidental, special, consequential, or punitive damages — including loss of profits, data, goodwill, or business interruption — arising from your use of or inability to use the Services. Subject to the following paragraph, our total cumulative liability for any claim arising under these Terms shall not exceed the greater of (a) the amount you paid us in the 12 months preceding the claim, or (b) THB 100,000. The above limitation does not apply to: wilful misconduct or gross negligence; breach of confidentiality obligations; liability for death or personal injury; or any other case where the law does not permit liability to be limited. Some jurisdictions do not allow limitation of liability for certain damages; in such cases, our liability is limited to the fullest extent permitted by law.
11

Governing Law

These Terms shall be governed by and construed in accordance with the laws of the Kingdom of Thailand, without regard to conflict-of-law principles. Any dispute arising from or related to these Terms or the Services shall first be subject to good-faith negotiation. If unresolved within 30 days, disputes shall be submitted to the competent courts in Bangkok, Thailand. These Terms are published in both Thai and English. In the event of any conflict or inconsistency between the two versions, the Thai version shall prevail. Notwithstanding the above, Inboxly reserves the right to seek injunctive relief in any jurisdiction to protect its intellectual property rights.
12

Contact Us

If you have questions about these Terms, please contact us: BUNGFAI TECH Co., Ltd. (บริษัท บั้งไฟ เทค จำกัด) operator of the Inboxly platform Juristic person registration no. 0105569112366 245/60 Moo Ban Sin Poem, Pracha Ruam Jai Road Sai Kong Din Tai, Khlong Sam Wa, Bangkok 10510, Thailand Email: [email protected]

Important Notice

By continuing to use Inboxly's services, you acknowledge that you have read, understood, and agreed to these Terms of Service.