Privacy Policy
Effective 25 September 2026
BASC helps students find study programs, apply with the help of our counselors, and follow their applications. It is run by Koipath Co., Ltd., 554 Thanon Asok - Din Daeng, Khwaeng Din Daeng, Din Daeng, Bangkok 10400, Thailand (“we”, “us”). We are responsible for the personal data described here, under Thailand’s Personal Data Protection Act (PDPA).
What we collect
- Your account: your name and email address, and your password, which is stored only in a scrambled form that cannot be read back. If you sign in with Google or Facebook, we receive the name, email address and profile photo of that account, never its password.
- Your profile: details you choose to add, such as your legal name, pronouns, phone number, preferred study country, grade level, GPA and intended major.
- Your applications: the programs you apply to, your target term, the status of each application, notes our counselors write about it, and documents you upload for it.
- Payments: amounts, payment method and status, and payment slips you upload. If you pay by card, your card details go straight to our payment provider; we never see your full card number.
- Security records: your IP address, browser details, and a log of sign-ins and important account actions.
We use one essential cookie to keep you signed in. If you open a staff invitation, your browser also keeps a temporary note of it until you accept it. We use no advertising or analytics cookies.
Google user data
If you choose “Continue with Google”, Google shares only the following with BASC:
- your name and email address, and whether Google has verified that address;
- your Google profile photo;
- an identifier that tells us it is the same Google account the next time you sign in.
- How we use it: only to create your BASC account, sign you in, and show your name on your account. We do not ask for, and have no access to, your Gmail, contacts, files or anything else in your Google account.
- Who we share it with: no one, except Supabase, which stores it as part of your account so you can sign in. We do not sell it, use it for advertising, or transfer it for any other purpose.
- How we protect it: it is sent only over encrypted connections, stored in an encrypted database, and only you and staff whose role needs it can see your account.
- How long we keep it: while your account is open. You can disconnect Google on your profile page at any time, and deleting your account removes it (see how to delete your data).
BASC’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Facebook sign-in works the same way: we receive the same details from Facebook and use them in the same limited way.
Why we use it
- To run your account and the services you ask for: applications, courses and payments.
- To contact you about your account and applications.
- To keep BASC secure and to prevent fraud and misuse.
- To meet our legal obligations, such as keeping accounting records.
We do not sell your personal data or use it for advertising.
Who we share it with
- Our staff, each seeing only what their role needs: counselors work with applications, finance with payments.
- Universities and schools you apply to, when we submit an application for you.
- Companies that run parts of BASC for us: Supabase (database and sign-in), Vercel (website hosting), Resend (email), and Google or Facebook if you choose to sign in with them. Our payment provider, Omise, processes card payments.
- Authorities, when the law requires it.
Where your data is kept
Our database is in Singapore, and some of the companies above process data in other countries, including the United States. When personal data leaves Thailand, we protect it as the PDPA requires, for example through data protection agreements with those companies.
How long we keep it
- Your account and profile: while your account is open, and up to 30 days after you ask us to delete it.
- Applications and payments: as long as accounting and tax law requires.
- Security records: as long as needed to keep BASC secure and to meet legal obligations.
Your rights
Under the PDPA you can ask us to:
- give you access to, or a copy of, your personal data;
- correct it (you can also edit most details on your profile page);
- delete it, or make it anonymous (see how to delete your data);
- stop or limit using it, or object to how we use it;
- send it to you or to another organization in a common format;
- withdraw any consent you have given.
Email privacy@koipath.com and we will reply within 30 days. You can also complain to the Office of the Personal Data Protection Committee (PDPC).
Keeping it safe
Connections to BASC are encrypted, staff access is limited by role, passwords are never stored in a readable form, and important actions are logged.
Students under 20
If you are under 20, please read this policy with a parent or guardian. Where Thai law requires their consent, we will ask for it.
Changes to this policy
If we change this policy, we will update this page and the date above. If a change is significant, we will also tell you by email or in BASC.
Contact us
Koipath Co., Ltd., 554 Thanon Asok - Din Daeng, Khwaeng Din Daeng, Din Daeng, Bangkok 10400, Thailand. Email: privacy@koipath.com.