สรุปดี AI · เอกสารสำหรับฝ่ายไอทีและฝ่ายกฎหมาย
ความปลอดภัยของข้อมูล
ปรับปรุง 20 กันยายน 2569 · ผู้ให้บริการ: บริษัท ทริปดีดี-ธีร์ จำกัด · หน้านี้พิมพ์เป็น PDF ส่งต่อได้
สรุปให้สั้นที่สุด
- เนื้ออีเมลและข้อความจากไฟล์แนบ เข้ารหัสขณะจัดเก็บ ด้วย AES-256-GCM กุญแจเก็บแยกจากฐานข้อมูล
- อ่านอีเมลได้เฉพาะเจ้าของกล่อง · หัวหน้าในบริษัทเห็นแค่ตัวเลขนับ · พนักงานของเราไม่มีหน้าจอให้เปิดอ่าน
- ข้อมูลของคุณไม่ถูกนำไปฝึกหรือปรับแต่งแบบจำลอง AI ทั้งของเราและของผู้ให้บริการ AI ที่เราใช้
- ข้อรักษาความลับมีผลอัตโนมัติตั้งแต่เริ่มใช้ ไม่ต้องขอและไม่ต้องเซ็นเพิ่ม (เงื่อนไขการใช้บริการ ข้อ 8)
1. การเข้ารหัส
- ขณะจัดเก็บ เนื้ออีเมลและข้อความที่อ่านได้จากไฟล์แนบ เข้ารหัสด้วย AES-256-GCM (มีการตรวจความถูกต้องของข้อมูลในตัว) กุญแจ 256 บิตเก็บไว้ในค่าตั้งของเซิร์ฟเวอร์ ไม่ได้อยู่ในฐานข้อมูลและไม่ได้อยู่ในไฟล์สำรอง
- ขณะรับส่ง เข้ารหัสด้วย TLS ทุกช่องทาง
- สิ่งที่ไม่ได้เข้ารหัส หัวเรื่อง ชื่อและอีเมลผู้ส่ง และหัวข้อสรุป เพราะต้องใช้ค้นหาและแสดงรายการ — เราแจ้งข้อนี้ไว้ตรง ๆ เพื่อให้ประเมินความเสี่ยงได้ครบ
- ผลที่ได้จริง สำเนาฐานข้อมูลหรือไฟล์สำรองที่หลุดออกไป อ่านเนื้ออีเมลไม่ได้
2. ใครอ่านข้อมูลได้บ้าง
- เจ้าของกล่อง อ่านอีเมลของตัวเองได้ · ทุกคำขอตรวจสิทธิ์ที่ระดับฐานข้อมูล ไม่ใช่ตรวจทีหลัง คนที่ไม่ใช่เจ้าของได้ผลลัพธ์ "ไม่พบ" แม้จะรู้รหัสอ้างอิงของอีเมลนั้น
- หัวหน้าและเจ้าของบริษัท เห็นใบเสนอราคาของทีม ผลอนุมัติ และจำนวนอีเมลของแต่ละคน · ไม่เห็นเนื้ออีเมลของสมาชิก
- พนักงานของผู้ให้บริการ ระบบหลังบ้านไม่มีหน้าจอใดที่แสดงเนื้ออีเมลของลูกค้า
- สมาชิกใหม่ เข้าบริษัทได้เมื่อยืนยันอีเมลโดเมนของบริษัทด้วยรหัสเท่านั้น (ถ้าบริษัทเปิดการจำกัดโดเมน)
- บันทึกการเข้าถึง ทุกการกระทำในบริษัทถูกบันทึก ลบจากหน้าเว็บไม่ได้ และส่งออกเป็นไฟล์เองได้
3. ปัญญาประดิษฐ์
- เราใช้บริการ AI แบบเสียค่าบริการ ซึ่งผู้ให้บริการระบุว่าไม่นำคำสั่งและคำตอบไปปรับปรุงผลิตภัณฑ์ของตน และเก็บบันทึกไว้ชั่วคราวเพื่อตรวจการใช้งานที่ผิดนโยบายเท่านั้น
- เราไม่นำข้อมูลของคุณไปฝึกหรือปรับแต่งแบบจำลองใด ๆ ของเราเอง ข้อนี้ผูกพันตามสัญญา
- อีเมลประเภทรหัสผ่านชั่วคราว (OTP) อีเมลธนาคาร และอีเมลรีเซ็ตรหัสผ่าน ถูกคัดออกตั้งแต่ทางเข้า ไม่เก็บเนื้อหาและไม่ส่งให้ AI
- ข้อจำกัดที่เราไม่ปิดบัง การสรุปด้วย AI จำเป็นต้องถอดรหัสเนื้ออีเมลเพื่ออ่าน เราจึงไม่อาจรับรองว่า "อ่านไม่ได้ในทางเทคนิค" การคุ้มครองอาศัยการไม่มีช่องทางใช้งานให้พนักงานอ่าน การเข้ารหัสขณะจัดเก็บ และข้อผูกพันตามสัญญาประกอบกัน
4. ที่เก็บ การสำรอง และการลบ
- ระบบและฐานข้อมูลทำงานบนผู้ให้บริการคลาวด์ที่มีศูนย์ข้อมูลอยู่ต่างประเทศ · ฐานข้อมูลเป็นของเราเอง ไม่ได้ฝากไว้กับผู้ให้บริการฐานข้อมูลรายอื่น
- สำรองข้อมูลอัตโนมัติทุกวัน เก็บย้อนหลัง 30 วัน · ไฟล์สำรองมีเฉพาะฐานข้อมูล ไม่มีกุญแจถอดรหัสรวมอยู่ด้วย
- บริษัทกำหนดระยะเวลาเก็บอีเมลเองได้ จากหน้าแดชบอร์ด (สั้นกว่าค่าของระบบได้) ครบกำหนดแล้วระบบลบอัตโนมัติ
- เมื่อเลิกใช้บริการ ลบหรือส่งคืนข้อมูลภายใน 30 วันนับแต่ได้รับแจ้งเป็นลายลักษณ์อักษร
5. บัญชีและการเข้าสู่ระบบ
- เข้าสู่ระบบด้วยโทเคนที่มีวันหมดอายุ · เจ้าของบัญชีสั่ง ออกจากระบบทุกเครื่อง ได้เอง ซึ่งทำให้โทเคนเดิมทั้งหมดใช้ไม่ได้ทันที
- ลิงก์ใบเสนอราคาที่ส่งให้ลูกค้ามีวันหมดอายุตามที่บริษัทตั้ง และยกเลิกได้ทันที · เอกสารมีลายน้ำชื่อผู้เปิด
- ที่อยู่กล่องรับอีเมลเป็นค่าสุ่มยาว เดาไม่ได้ · ผู้ที่ทราบที่อยู่ส่งอีเมลเข้ามาได้แต่อ่านของในกล่องไม่ได้ · บริษัทปิดรับกล่องใดก็ได้ทันที
6. เอกสารและการแจ้งเหตุ
- ข้อรักษาความลับมีผลอัตโนมัติ ตั้งแต่เริ่มใช้บริการ และต่อไปอีก 3 ปีหลังเลิกใช้ (เงื่อนไขการใช้บริการ ข้อ 8)
- ต้องการ NDA หรือ ข้อตกลงประมวลผลข้อมูล (DPA) ฉบับลงนามไว้เข้าแฟ้ม ขอได้ฟรีจากหน้าทีมและบริษัท
- แจ้งเหตุละเมิดข้อมูลภายใน 48 ชั่วโมง นับแต่ทราบเหตุ · แจ้งล่วงหน้า 30 วันก่อนเปลี่ยนผู้ให้บริการช่วง
- รายชื่อผู้ให้บริการช่วงทุกราย อยู่ในนโยบายความเป็นส่วนตัว
ติดต่อเรื่องความปลอดภัย
พบช่องโหว่หรือมีคำถามที่หน้านี้ไม่ได้ตอบ ส่งมาที่ [email protected] เราตอบทุกฉบับ
SarupDee AI · for your IT and legal teams
Data security
Updated 20 September 2026 · Provider: TripDeDee-THEE Co., Ltd. · This page prints to PDF for forwarding
The short version
- Email bodies and attachment text are encrypted at rest with AES-256-GCM; the key is held outside the database.
- Only the mailbox owner can read their email. Managers see counts only. Our staff have no screen that opens it.
- Your data is never used to train or tune AI models — neither ours nor our AI provider's.
- Confidentiality applies automatically from day one. Nothing to request, nothing extra to sign (Terms of Service, clause 8).
1. Encryption
- At rest — email bodies and text extracted from attachments are encrypted with AES-256-GCM (authenticated encryption). The 256-bit key lives in server configuration, not in the database and not in backups.
- In transit — TLS on every channel.
- Not encrypted — subject, sender name and address, and the summary headline, because search and list views need them. We state this plainly so you can assess the real risk.
- What this buys you — a leaked database copy or backup cannot be read.
2. Who can read what
- The mailbox owner reads their own email. Authorisation is part of the database query, not a check applied afterwards: anyone else gets "not found" even with the exact record id.
- Managers and company owners see team quotations, approvals and counts per person — never a member's email content.
- Our staff — the admin system has no page that displays customer email content.
- New members join only after verifying a company-domain email with a code, where the company enables domain restriction.
- Activity log — every action inside your company is recorded, cannot be deleted from the interface, and you can export it yourself.
3. Artificial intelligence
- We use the paid tier of our AI provider, which states it does not use prompts or responses to improve its products and logs them only briefly to detect policy abuse.
- We do not use your data to train or tune any model of our own. This is a contractual commitment.
- OTP, bank and password-reset emails are filtered out at the door: their content is never stored and never sent to the AI.
- A limit we do not hide — AI summarising has to decrypt the mail to read it, so we cannot claim it is "technically impossible" for us to read. Protection comes from the absence of any staff-facing path, encryption at rest, and contractual obligation together.
4. Storage, backup and deletion
- The system and database run on a cloud provider whose data centres are outside Thailand. The database is ours; it is not handed to a third-party database provider.
- Automatic daily backups, 30 days retained. Backups contain the database only — never the decryption key.
- You set how long email is kept from your dashboard (shorter than our default is allowed); the system then deletes it automatically.
- On termination, data is deleted or returned within 30 days of written notice.
5. Accounts and sign-in
- Sign-in uses expiring tokens, and the account owner can sign out everywhere, which invalidates all existing tokens immediately.
- Customer quotation links expire as the company sets them and can be revoked at once; documents carry the viewer's name as a watermark.
- Inbox addresses are long random values. Knowing one lets somebody send mail in, never read what is there, and the company can pause any mailbox instantly.
6. Paperwork and incident notice
- Confidentiality applies automatically from the start and for 3 years after you stop (Terms of Service, clause 8).
- Need a signed NDA or Data Processing Agreement for your files? Request one free from the Team & company page.
- Breach notification within 48 hours of becoming aware · 30 days' notice before any sub-processor change.
- Every sub-processor is listed in the Privacy Policy.
Security contact
Found a vulnerability, or have a question this page does not answer? Write to [email protected] — we answer every one.