PESONA.
AboutFAQFor ContributorsFor ClientsTermsPrivacy
CONTENTS1. Who we are and scope2. Definitions and contract relationship3. Personal data we collect - contributors4. Personal data we collect - clients and other users5. How we obtain personal data6. Why we process personal data and legal bases7. Biometric and face data8. AI Processing, digital replicas and composite personas9. Consent preferences, usage briefs, standing licences and withdrawal10. Marketplace visibility, comp cards and client disclosures11. Service providers and subprocessors12. International and cross-border transfers13. Security14. Retention and audit records15. Account closure, withdrawal and deletion16. Your privacy rights17. Age requirement and minors18. Cookies, analytics and platform logs19. Corporate transactions and assignment20. Policy changes, language and order of documents21. Contact, requests and complaints22. Privacy governance, records of processing and impact assessments23. Data minimisation, purpose limitation and privacy by design24. Vendor due diligence, contracts and AI provider controls25. International transfer register and transfer safeguards26. Data-subject request and consent-record procedures27. Personal-data breach response and notification28. Retention schedule, deletion verification and backups29. Automated decisions, profiling and human review30. Accountability, training and access review31. Implementation condition and accuracy of this policy32. Product data matrix33. Country-specific application34. Mobile application data35. Instant licensing processing36. Account deletion and retention37. Mobile providers and store disclosures38. Core contractual authorization and biometric consent39. Setting changes and account deletion40. Version 3.3 consent, story settings and payment events
Legal · Privacy Policy

Privacy Policy

Version 3.3Operated by Fresh Day Production Co., Ltd.Governed by Thai law

How PESONA handles your personal data, including biometric and face data.

This Policy explains how PESONA collects, uses, shares and retains personal data, including the biometric and face data required to operate the platform. It applies alongside the Talent Agreement, Client License Agreement, Usage Brief and Terms of Service.

Section 1

Who we are and scope

PESONA is a consent-first marketplace and technology platform operated by Fresh Day Production Co., Ltd. (“PESONA”, “we”, “us” or “our”). This Privacy Policy explains how PESONA collects, uses, stores, discloses, transfers, protects and deletes personal data in connection with the PESONA platform, Contributor/Talent accounts, Client accounts, Comp Cards, Usage Briefs, AI-generated Outputs, subscriptions, payments, identity verification and related services.

This Policy applies to Contributors, Clients, authorised Client users, website/platform visitors and other individuals whose personal data is processed through PESONA. It is intended to operate consistently with the PESONA Talent Agreement, PESONA Client License Agreement and each applicable Usage Brief. Where a signed data-processing agreement (“DPA”) governs a specific processing relationship, that DPA controls solely for the data-processing matters it expressly covers.

For Contributor personal data, PESONA generally acts as a data controller/data หน้าที่ไว้วางใจ (fiduciary) or equivalent role under Applicable Law. For personal data supplied by a Client about its personnel, campaign contacts or other persons, PESONA’s role may be controller, processor or another legally recognised role depending on the processing context and any applicable DPA.

Section 2

Definitions and contract relationship

Capitalised terms not defined in this Policy have the meanings given in the applicable PESONA Talent Agreement, Client License Agreement or Usage Brief, as relevant. In particular, “Likeness”, “Source Material”, “Biometric Data”, “Consent Preferences”, “Usage Brief”, “Standing Licence”, “Composite Persona”, “Comp Card”, “Output”, “Client Materials” and “License ID” have the meanings used in the applicable PESONA agreement.

This Policy describes PESONA’s personal-data practices. It does not itself expand any Client licence, Contributor consent, Usage Brief scope, Composite Persona permission, Standing Licence term or right to create or use an Output. Licensing rights arise only under the applicable agreements and an activated Usage Brief.

Additional defined terms

“Authorised Final Output” and “Licensed Deliverables” have the meanings given in the applicable Talent Agreement and Client License Agreement.

Section 3

Personal data we collect - contributors

Depending on the features you use, PESONA may collect the following Contributor data: • account and contact data, including legal name, display name, email, telephone number, country and account identifiers; • identity-verification data, including government-issued identification, date of birth, verification results and provider reference identifiers; • Source Material, including photographs, video, audio, speaking video and material from optional linked accounts that you expressly authorise PESONA to access or import; • Biometric Data, including facial scans, facial geometry, facial templates, face references, liveness results and other qualifying biometric identifiers; • profile and Comp Card data, including authorised display information, content tier, rate information and profile visibility settings; • Consent Preferences and related consent records, including media, territory, duration, category, pricing, exclusivity, Composite Persona permissions, Standing Licence permissions and any surviving-generation permission; • licence and transaction data, including Usage Brief references, License IDs, campaign category, territory, duration, payout allocation, Contributor Licence Fee, payment and tax records; • audit and security data, including Agreement Version, Consent Preference Version, Consent Record ID, acceptance timestamps, login records, device/session information and fraud/security logs; and • communications, support requests, disputes and other information you provide to PESONA.

Additional Contributor Data Categories

PESONA may also process Physical Measurements such as height, weight, clothing size and other casting measurements; Evaluation Preview records; Role Signals, derived Role and role-reason records; generation-credit purchase/use records; and Composite similarity or identifiability screening results. Physical Measurements are treated as personal data and are not classified as Biometric Data merely because they describe physical characteristics unless the applicable law or actual processing purpose requires that classification.

Character Sheet data

Character Sheet images; Character Sheet generation and modification records; selection or presentation identifiers; consent records; and related marketplace-presentation metadata.

Authorised Final Output records

Authorised Final Outputs; selected Source Material reference IDs; consent and Consent Preference records; metadata-removal and technical-processing records; watermark, License ID and file-hash records; format and resolution details; delivery, download, access and recipient logs; and related Usage Brief and payment/Activation records.

Section 4

Personal data we collect - clients and other users

For Clients and authorised Client users, PESONA may collect: • organisation and account data, including entity name, registration details, country, industry, billing details, account users and business contact information; • identity and authority information about persons accepting agreements or acting for a Client; • Client Materials, prompts, instructions, campaign declarations, brand/product information and contact information contained in those materials; • Usage Brief data, including licensed Persona(s), end brand, Named Campaign Parties, campaign purpose, media, territory, duration, category, fees, exclusivity, licence/persona type and special restrictions; • generation and licence records, including render attempts, approved Outputs, License IDs, watermark/tracking information, validation status and evidence records; • subscription, invoice, payment, refund, chargeback and credit information; • account usage, API, security and audit logs; and • communications, support requests, complaints and dispute records.

Clients must not provide PESONA with personal data they are not authorised to provide. Where Client Materials contain personal data of third parties, the Client remains responsible for having an appropriate legal basis and providing any required notices, except to the extent a signed DPA expressly allocates responsibility differently.

Additional Client/User Data Categories

For role-based licensing, PESONA may collect planned-use answers and supporting campaign facts used as Role Signals, the resulting derived Role, role reason, การอัปเกรด/การปรับยอด (upgrade/true-up) history and related audit evidence. For generation credits, PESONA may process purchase, allocation, promotional grant, usage, balance, refund, chargeback and reconciliation records.

Section 5

How we obtain personal data

PESONA obtains personal data directly from you, from your organisation, from optional accounts or sources you connect and authorise, from authorised administrators acting on your behalf, from Clients in connection with a transaction, and from approved Service Providers such as identity-verification, payment, hosting, security and AI-processing providers.

PESONA or an authorised administrator may import material for a Contributor only where the Contributor has authorised the source/import or PESONA has an independent lawful right to obtain and use the material for the stated purpose. Contributor warranties do not automatically apply to material independently sourced by PESONA without the Contributor’s direction.

Section 6

Why we process personal data and legal bases

PESONA processes personal data only for specified purposes and on a legal basis permitted by Applicable Law. Depending on the data and jurisdiction, the basis may include performance of a contract, steps requested before entering into a contract, compliance with legal obligations, legitimate interests that are not overridden by individual rights, establishment/exercise/defence of legal claims, or consent.

Key purposes include: • creating and administering Contributor and Client accounts; • age, identity, liveness, fraud and duplicate-account verification; • recording Consent Preferences and matching proposed Usage Briefs against those permissions; • creating, validating, delivering and auditing authorised Outputs and licences; • operating Composite Persona and Standing Licence features only within the applicable recorded permissions; • generating and distributing Comp Cards for legitimate casting, selection and licence-evaluation purposes; • processing Contributor payouts, Client billing, subscription fees, taxes, refunds, chargebacks and accounting records; • information security, abuse prevention, watermarking, licence tracking, investigation and enforcement; • customer support, communications and dispute resolution; • platform administration and service analytics; and • compliance with legal, regulatory, tax, accounting and record-retention duties.

Where consent is the legal basis, consent is requested separately where required and may be withdrawn prospectively. Withdrawal does not make prior lawful processing unlawful and does not by itself invalidate an Output or licence already validly created, subject to Applicable Law and Sections 9 and 15 below.

Additional Processing Purposes

PESONA may process personal data to: (i) provide Evaluation Previews where the Contributor has affirmatively enabled that consent class; (ii) derive, validate and audit campaign Roles and corresponding transaction scope/pricing; (iii) administer generation credits and related payment/reconciliation activity; (iv) perform Composite similarity, identifiability, safety or rights-risk screening; and (v) maintain evidence necessary to distinguish evaluation previews from Activated licensed Outputs.

Evaluation Preview processing is not treated as licensed commercial use. Where consent is the required lawful basis, PESONA will not make a Contributor available for that preview class unless the applicable affirmative consent record exists.

Character Sheet purposes and legal basis

Where the Contributor has affirmatively enabled the Character Sheet / Marketplace Presentation Use permission, PESONA processes authorised Likeness, Source Material and necessary face-related data to create, generate, modify, administer, display and distribute authorised Character Sheets and related marketplace presentation materials for bona fide casting, selection, creative evaluation, licence solicitation and licence evaluation. PESONA relies on the recorded permission and other lawful bases applicable to the particular processing; where consent is legally required, PESONA relies on valid explicit consent. No Character Sheet is generated under this purpose without the applicable affirmative permission.

Authorised Final Output purposes and legal bases

Where the Contributor has affirmatively enabled Authorised Final Output Use and Delivery, PESONA processes authorised Source Material and necessary face-related data to select, prepare, copy, technically adjust, remove unnecessary metadata from, protect, watermark, license and deliver a Authorised Final Output; administer the Activated Usage Brief; calculate payments; maintain audit and security records; and investigate misuse. PESONA relies on the recorded permission, performance or administration of the relevant agreements and other lawful bases applicable to each activity. Where explicit consent is required, PESONA relies on valid explicit consent.

Section 7

Biometric and face data

Face images, facial scans, facial geometry, facial templates, face references, liveness information and other qualifying Biometric Data may be sensitive/special-category personal data under Applicable Law. PESONA applies heightened controls to this data.

PESONA processes Biometric Data only to the extent reasonably necessary for authorised purposes such as identity/liveness verification, prevention of duplicate or fraudulent registration, security/protection of a Contributor’s Likeness, and creation or maintenance of technical representations needed to generate authorised Outputs.

Before processing Biometric Data for identity verification, liveness verification or generation-related purposes, PESONA will obtain separate explicit consent where consent is required by Applicable Law. If PESONA relies on another lawful basis permitted by Applicable Law, PESONA will document that basis and any required safeguards.

PESONA does not sell Biometric Data. PESONA does not disclose Contributor Biometric Data to Clients. PESONA does not permit any Service Provider to use Biometric Data, Likeness or Source Material to train a general-purpose or unrelated AI model. Biometric processing by a Service Provider must be subject to appropriate confidentiality, security, purpose-limitation, retention and data-protection obligations.

No biometric entitlement

The visual fidelity of a Authorised Final Output does not entitle a Client to receive or create Biometric Data. A Client must not extract, infer, generate or use facial geometry, templates, embeddings, recognition identifiers or other biometric or technical representations from the image.

Section 8

AI Processing, digital replicas and composite personas

PESONA may use approved AI technology providers as Service Providers to generate or process authorised Outputs. Those providers may process only the data necessary to perform the authorised service and must not use PESONA data for unrelated AI/model training or create independent Digital Replicas except as expressly authorised by PESONA and the affected Contributor under the applicable agreement.

A Composite Persona may be created only where each source Contributor has separately and affirmatively authorised Composite Persona use. PESONA records the relevant source Contributor/Consent Record IDs, licence scope and allocation record. Client access is limited to the authorised Composite Outputs; Clients are not entitled to receive source biometric templates, embeddings, blend components or the identities of source Contributors unless disclosure is separately authorised and necessary for the transaction or required by law.

PESONA does not currently treat a standard Usage Brief as permission to license Contributor Source Material or Biometric Data for third-party AI training, model fine-tuning, dataset creation or independent Digital Replica creation. Any future product involving such processing would require separate legal terms, transparent notice and any additional explicit consent required by Applicable Law.

Composite Identifiability Screening

A Composite Persona or Output may remain personal data if it can reasonably be linked to, inferred from or associated with an identifiable source Contributor. PESONA may use similarity or identifiability screening, source mapping and related technical records to assess this risk. PESONA may reject, quarantine or regenerate candidate Outputs where risk thresholds or contextual review indicate an undue resemblance, misidentification or rights risk. Any numerical threshold is an internal technical/risk-control parameter and may change without amending this Policy, subject to governance and Applicable Law.

Section 9

Consent preferences, usage briefs, standing licences and withdrawal

Contributor permissions must be affirmatively recorded. A default, pre-ticked setting, blank field, inferred preference or system assumption does not constitute consent. Exclusivity, Composite Persona use and Standing Licence permissions are off unless affirmatively enabled.

Before an Output licence activates, PESONA validates the proposed Usage Brief against the applicable Consent Preferences and records any additional consent required. PESONA retains records sufficient to connect the Contributor agreement/version, Consent Preference Version(s), Consent Record ID(s), Usage Brief, License ID and relevant timestamps.

Changes to Consent Preferences apply prospectively to new licences. A valid licence issued before a later preference change generally remains effective until its agreed expiry or earlier termination under its terms, unless Applicable Law requires otherwise.

If a Contributor withdraws from PESONA, PESONA will stop issuing new licences after withdrawal becomes effective. Existing valid Outputs/licences may continue according to their terms. New generation after withdrawal that depends on Biometric Data will stop unless a lawful basis remains. For Composite Persona generation after withdrawal, new generation is permitted only where an express surviving-generation permission was recorded before the licence was issued, the generation remains within the existing licence, and all required lawful bases remain valid.

Evaluation Preview Consent and Standing Licence Renewal

Evaluation Preview permission is a separate affirmative Consent Preference. A blank, default or inferred setting does not authorise it. PESONA records the applicable consent version. Once withdrawal of that permission becomes effective, PESONA will cease future Evaluation Preview generation that depends on that permission, unless and only to the extent another lawful basis and the applicable Contributor agreement expressly permit the processing, subject to lawful retention of evidence.

For Standing Licence renewals, the renewed Role and transaction scope may be re-derived from planned use. Any renewed commercial terms are handled through the applicable licence documents; the privacy record retains the consent and version evidence necessary to validate the renewed scope.

Section 10

Marketplace visibility, comp cards and client disclosures

PESONA limits what Contributor information is shown to Clients. Marketplace/profile information may include an authorised display name or identifier, approved images/video, content tier, licence-eligibility information, selected consent categories, availability and pricing/rate information as configured for the platform. PESONA does not disclose a Contributor’s government identification, payment credentials or Biometric Data to Clients.

Where a Contributor has authorised Comp Card use, PESONA may create, display, provide, download or share a Comp Card for bona fide marketplace, casting, selection and licence-evaluation purposes. A Comp Card is not a commercial campaign licence. PESONA seeks to limit Comp Card content to information reasonably necessary for those purposes and may use access controls, watermarking, expiry controls or audit logging where appropriate.

PESONA may provide an affected Contributor with a limited licence notification such as category, territory, duration and applicable rate without disclosing confidential Client/campaign information. Full campaign information may be subject to an NDA or other confidentiality condition. Where a valid Usage Brief falls within already-recorded Consent Preferences, privacy notification does not create an additional approval right unless the applicable agreement, a special condition or Applicable Law requires it.

Character Sheets and disclosures

PESONA may display, provide or permit authorised download or sharing of an authorised Character Sheet to eligible or prospective Clients, agencies and authorised casting or selection participants solely for bona fide marketplace, casting, selection, creative-evaluation, licence-solicitation and licence-evaluation purposes. A Character Sheet is not a commercial campaign licence. Disclosure of a Character Sheet does not authorise disclosure of raw Source Material or Biometric Data, or any use for advertising, public distribution, AI training, dataset creation, profiling, resale or creation of a Digital Replica, unless separately and lawfully authorised under the applicable PESONA documents and Applicable Law.

Disclosure after Activation

After payment or approved credit conditions and Activation, PESONA may deliver a Authorised Final Output to the Client and Authorised Campaign Parties identified or permitted under the Usage Brief. This is a limited authorised disclosure and does not constitute disclosure of raw Source Material. Before delivery, PESONA may remove unnecessary metadata and apply invisible watermarking, License ID, file hashing, access controls and audit logging. The image may be used only within the Usage Brief and must not be used for AI training, dataset creation, biometric extraction, unrelated profiling, resale or creation of a Digital Replica. A Character Sheet may accompany delivery, subject to its stated reference-only or licensed status.

Section 11

Service providers and subprocessors

PESONA may use third-party Service Providers to operate the platform. Categories may include identity/KYC and liveness verification, cloud/application hosting, database and storage, cybersecurity, email/communications, payment and payout processing, analytics, customer support, AI generation/processing and professional advisers.

As of the date of this Policy, PESONA’s operating environment includes, where the relevant function is used, Sumsub for identity/KYC verification, Stripe or another approved processor for Client billing/payment services, Vercel for application hosting, Neon for database infrastructure, and approved AI-generation/processing providers including MiniPi where deployed. Provider roles and infrastructure may change as PESONA evolves. PESONA will maintain a current subprocessor/service-provider list or privacy notice identifying material providers where required by Applicable Law.

PESONA requires Service Providers to process personal data only for authorised purposes and subject to contractual confidentiality, security, purpose-limitation, retention, deletion and data-protection obligations appropriate to the service. AI providers must be restricted from unrelated model training or independent reuse of PESONA Source Material, Likeness or Biometric Data.

Section 12

International and cross-border transfers

PESONA operates a cross-border digital service and its Service Providers may process personal data in countries other than the country where the data was collected. Cross-border processing may occur for hosting, database services, identity verification, payment processing, cybersecurity, AI processing, support and other platform operations.

Where Applicable Law imposes cross-border transfer requirements, PESONA will use a legally recognised transfer mechanism or other appropriate safeguards, which may include contractual transfer clauses, processor agreements, transfer-risk assessments, adequacy mechanisms, consent where legally appropriate, or another mechanism permitted by Applicable Law.

Biometric Data and other sensitive data are subject to additional safeguards. If Applicable Law requires localisation or additional approval for particular data, PESONA will apply those requirements before the relevant transfer or processing.

Section 13

Security

PESONA uses technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss, misuse or destruction. Measures may include encryption in transit and at rest where appropriate, role-based access controls, least-privilege permissions, separated access to sensitive data, authentication controls, audit logging, monitoring, secure development practices, vendor due diligence and incident-response procedures.

Access to identity, Source Material and Biometric Data is restricted to authorised personnel and systems with a legitimate operational need. Clients are not given access to Contributor legal identity documents or Biometric Data. Security controls are reviewed and updated as the platform and risks evolve.

No system can guarantee absolute security. If a personal-data breach occurs, PESONA will assess the incident, take reasonable containment/remediation steps and make notifications to affected persons or authorities where required by Applicable Law.

Section 14

Retention and audit records

PESONA retains personal data only for as long as reasonably necessary for the purposes described in this Policy, the applicable agreements, legal obligations, legitimate enforcement/audit needs and dispute resolution. Retention periods may differ by data type and jurisdiction.

Indicative retention principles are: • Source Material and Biometric Data: while reasonably necessary for an active Contributor account, authorised generation and active licences, plus any required withdrawal/closure period; then deleted, destroyed or anonymised unless a lawful retention basis remains; • identity/KYC records: raw identity documents may be held by the KYC provider under its retention rules; PESONA may retain verification results, reference IDs and limited legally required information; • executed agreements, consent records, Usage Brief snapshots/hashes, licence evidence and dispute records: retained for the period required by Applicable Law and PESONA’s applicable record-retention policy, taking account of limitation periods, audit and evidence needs; • transaction, tax, accounting, invoice, subscription, payout and chargeback records: retained for applicable statutory/accounting periods; • security, login, API and platform logs: retained for periods reasonably necessary for security, fraud prevention, troubleshooting and compliance, then deleted or anonymised where appropriate.

PESONA may preserve specific data longer where reasonably necessary for a legal hold, regulatory request, tax/accounting requirement, fraud prevention, dispute, licence audit or establishment/exercise/defence of legal claims. Data retained for these purposes is restricted to those purposes.

Evaluation Preview, Role and Credit Retention

Evaluation Preview images or other preview content are retained only for the limited evaluation period stated in PESONA’s applicable retention schedule or product notice and are then deleted or rendered inaccessible, subject to backup and legal-hold rules. PESONA may retain separate audit metadata for a longer period where reasonably necessary for consent evidence, security, fraud prevention, dispute resolution or legal compliance. Such metadata may include a Preview/Audit ID, Contributor and Client references, prompt or generation instruction, timestamp and consent-record reference, and need not contain a commercial License ID.

Role Signals, derived-role records, true-up history, credit transaction records and Composite screening records are retained according to the applicable internal retention schedule based on transaction, audit, fraud, legal and dispute purposes. This Policy does not promise indefinite retention of any such record.

Retention of delivery records

PESONA may retain Authorised Final Outputs and related consent, watermark, file-hash, delivery and Usage Brief records for the licence term and thereafter as reasonably necessary for audit, payment, dispute, enforcement, security and legal-compliance purposes. Raw Source Material retention is assessed separately under the stated retention criteria and Applicable Law.

Section 15

Account closure, withdrawal and deletion

A Contributor may withdraw from PESONA in accordance with the Talent Agreement. Withdrawal and privacy deletion are related but not identical processes. PESONA will stop new licensing after the effective withdrawal date and will delete, destroy or anonymise personal data when the applicable processing purpose and lawful retention basis end.

Deletion does not necessarily occur immediately if data remains reasonably necessary to administer an active licence, preserve rights in an existing valid Output, complete payment/tax/accounting obligations, investigate misuse, maintain evidence, resolve a dispute or comply with Applicable Law. Existing valid Outputs and licences may remain effective according to their terms even after the Contributor account closes.

A Contributor may separately withdraw consent for Biometric Data processing where permitted by Applicable Law. PESONA will stop future processing that depends on that consent unless another lawful basis applies. Existing Outputs/licences validly created before withdrawal are not automatically invalidated. If continued generation under an active licence would require Biometric Data processing for which no lawful basis remains, PESONA may suspend future generation while preserving rights in Outputs already validly generated, subject to Applicable Law and the applicable licence terms.

Clients may request account closure, but PESONA may retain transaction, billing, subscription, Usage Brief, License ID and evidence records for the periods described in Section 14.

Section 16

Your privacy rights

Subject to Applicable Law, you may have rights to request access to your personal data, obtain a copy, correct inaccurate data, request deletion, request restriction of processing, object to certain processing, receive portable data, withdraw consent, and lodge a complaint with a competent data-protection authority.

Some rights are not absolute. PESONA may need to verify your identity before acting on a request and may lawfully refuse or limit a request where data must be retained for legal obligations, security/fraud prevention, active licence administration, legal claims, tax/accounting or another lawful ground.

Withdrawing a Contributor licensing permission or Consent Preference is governed by the Talent Agreement and applies prospectively as described there. Exercising a privacy right does not by itself enlarge or cancel a commercial licence except where Applicable Law or the applicable agreement requires that result.

Requests may be sent to privacy@pesona.ai or through any privacy-rights tool made available in the PESONA account. PESONA will respond within the period required by Applicable Law.

Section 17

Age requirement and minors

The current PESONA Contributor programme is available only to individuals aged 18 or older who are legally capable of entering into the Talent Agreement. No parent or guardian may create or operate a current PESONA Contributor account on behalf of a person under 18.

PESONA may request evidence of age during identity verification. If PESONA discovers that a Contributor account was created by, for or on behalf of a person under 18, PESONA may suspend or terminate the account and handle the related personal data in accordance with Applicable Law.

PESONA may introduce a separate programme for minors in the future only under separate terms and privacy safeguards addressing parental/guardian authority, child protection, payments, Biometric Data and any additional consent requirements. This Policy does not by itself authorise such a programme.

Section 18

Cookies, analytics and platform logs

PESONA may use cookies, local storage, session technologies and similar tools to operate the platform, authenticate users, maintain sessions, protect security, prevent fraud, remember settings and understand service performance.

Essential technologies required for login, security, licensing and payment functions may operate without optional consent where permitted by Applicable Law. Non-essential analytics or similar technologies will be subject to consent or opt-out controls where required.

PESONA does not use Contributor Biometric Data for advertising profiling and does not sell platform usage data to data brokers. If PESONA introduces advertising or materially different tracking technologies, this Policy and any applicable cookie notice will be updated before such processing begins.

Section 19

Corporate transactions and assignment

If PESONA undergoes a bona fide financing, corporate reorganisation, merger, acquisition, sale or transfer of all or part of the PESONA business, personal data and associated licence/consent records may be disclosed or transferred to an affiliate, successor, parent company, acquirer or transferee where reasonably necessary for the transaction and permitted by Applicable Law.

Any recipient of personal data must handle it in accordance with Applicable Law and the material privacy obligations applicable to the transferred data. A corporate transaction does not by itself expand a Contributor’s Consent Preferences or a Client’s licence rights.

Section 20

Policy changes, language and order of documents

PESONA may update this Policy to reflect changes in law, platform features, Service Providers, security practices or data-processing activities. Where a change materially affects personal-data processing, particularly Biometric Data, Composite Persona processing or another processing activity that requires consent, PESONA will provide notice and obtain fresh or additional consent where required by Applicable Law.

The English text is the master version and the Thai text is a corresponding version intended to mirror the English text in substance. If the two versions are inconsistent, the English version prevails to the extent permitted by Applicable Law.

This Policy governs privacy disclosures and PESONA’s handling of personal data. It does not override the Talent Agreement or Client License Agreement on licensing, Consent Preferences, Contributor payments, Usage Brief scope, liability allocation or enforcement. A signed DPA governs data-processing matters it expressly covers. A Usage Brief may specify transaction data and licence scope but may not waive mandatory data-protection obligations or authorise prohibited biometric/AI processing.

Durable Product Change Mechanics

Operational details that may change frequently - such as quotas, rate-card amounts, credit prices, feature names, technical controls and routine storage windows - may be updated prospectively through the relevant product notice, retention schedule or commercial disclosure. A material change to the purpose, nature or scope of consent-based or otherwise legally significant processing will be notified and will require fresh or additional consent where required by Applicable Law. Version and acceptance/consent evidence will be maintained as described in this Policy.

Section 21

Contact, requests and complaints

Controller: Fresh Day Production Co., Ltd. (Head Office), 2 Soi Nonthaburi 52, Tha Sai Subdistrict, Mueang Nonthaburi District, Nonthaburi 11000, Thailand, Tax ID 0-1255-67021-436. Privacy: privacy@pesona.ai. Legal: legal@pesona.ai. Policy Version: 3.2. Users may exercise applicable access, correction, deletion, restriction, objection, portability and consent-withdrawal rights through these channels and the in-app controls.

Section 22

Privacy governance, records of processing and impact assessments

PESONA maintains a privacy-governance programme proportionate to the nature, scale and sensitivity of its processing. This includes records of processing activities, data-flow and system inventories, identification of controllers/processors and recipients, legal-basis records, retention rules, access controls, vendor/subprocessor records, and records of material privacy decisions.

Before introducing or materially changing processing that is likely to create a high risk to individuals - particularly new biometric identification, facial-template processing, Composite Persona processing, large-scale profiling, new AI uses, new sensitive-data combinations or material cross-border data flows - PESONA will conduct and document an appropriate privacy/data-protection impact assessment or equivalent risk assessment where required by Applicable Law or reasonably appropriate to the risk. Where an assessment is required by Applicable Law, PESONA will complete it and implement any measures required by law before production use. For additional controls identified through a voluntary or risk-based assessment, PESONA will implement measures reasonably appropriate to the risk or document a lawful risk-acceptance decision by an authorised owner, provided that no such decision may override a mandatory legal requirement.

PESONA will review this governance programme periodically and after material incidents, product changes or regulatory developments.

Section 23

Data minimisation, purpose limitation and privacy by design

PESONA will collect and process only personal data that is reasonably necessary, relevant and proportionate for the disclosed purpose. Access to Source Material, identity data and Biometric Data will be designed on a need-to-know and least-privilege basis. Where practical, PESONA will use pseudonymisation, tokenisation, segregation, derived references or other techniques that reduce direct identification and unnecessary exposure.

A new purpose that is incompatible with the purpose previously disclosed will not be introduced merely because the data is technically available. PESONA will identify an appropriate legal basis, update the relevant notice and obtain fresh or additional consent where required before the incompatible processing begins. Product and engineering teams must consider privacy requirements when designing new features and material changes.

Section 24

Vendor due diligence, contracts and AI provider controls

Before a Service Provider receives personal data, PESONA will conduct risk-based due diligence appropriate to the service and data involved. Where the provider acts as a processor or subprocessor, PESONA will put in place a written data-processing agreement or equivalent terms addressing documented instructions, confidentiality, security, assistance with individual rights and incidents, subprocessor controls, international transfers, return/deletion and audit or assurance rights as required by Applicable Law.

For AI, face, liveness or biometric providers that process sensitive or high-risk personal data, PESONA will require contractual or equivalent enforceable protections appropriate to the processing before such data is made available to the provider. Those protections will address, as applicable, prohibitions or restrictions on unrelated model training, independent reuse, sale, creation of independent Digital Replicas, and retention beyond the authorised service except where legally required. PESONA will document the provider and material upstream providers where reasonably necessary to understand the data flow. If a provider cannot provide protections adequate for the proposed sensitive processing, PESONA will not use that provider for that processing until the risk is lawfully remediated.

Section 25

International transfer register and transfer safeguards

In addition to Section 12, PESONA will maintain a reasonable record of material international transfers, including the data categories, purpose, exporter/importer or relevant provider, destination or processing location where known, transfer mechanism and material safeguards. PESONA will assess whether supplementary measures are appropriate for sensitive or biometric data and will update the assessment when the provider, location, law or processing materially changes.

Consent will not be used as a routine substitute for appropriate cross-border safeguards where Applicable Law requires another transfer mechanism. Where a transfer cannot lawfully proceed, PESONA will suspend or redesign the affected transfer or processing.

Section 26

Data-subject request and consent-record procedures

PESONA will maintain procedures to receive, authenticate, record, route and respond to privacy-rights requests within the period required by Applicable Law. PESONA will record the request, identity-verification steps, decision, response date and any lawful reason for refusal, restriction or extension. Requests involving active licences, legal holds or third-party rights will be reviewed so that PESONA preserves only data it is lawfully entitled or required to retain.

Where processing relies on consent, PESONA will maintain evidence reasonably sufficient to show what the individual was told, the specific purpose and scope, the affirmative action used to consent, the applicable policy/consent version, timestamp and any later withdrawal or change. Withdrawal must be as practicable as giving consent, subject to identity verification and lawful retention requirements.

Section 27

Personal-data breach response and notification

PESONA maintains an incident-response process for suspected or confirmed personal-data breaches. PESONA will promptly contain and investigate the incident, preserve relevant evidence, assess affected data and individuals, evaluate the likelihood and severity of harm, document the decision and notify competent authorities and affected individuals within the timeframe and in the circumstances required by Applicable Law.

Service Providers must be contractually required, where appropriate, to notify PESONA without undue delay of security incidents affecting PESONA personal data and to provide information and cooperation reasonably required for PESONA to meet its legal obligations. PESONA will maintain a breach/incident register and conduct post-incident remediation where appropriate.

Section 28

Retention schedule, deletion verification and backups

PESONA will maintain an internal retention schedule assigning retention rules to material data categories and systems. The schedule will distinguish, where appropriate, live production data, Source Material, Biometric Data, identity/KYC results, consent and licence evidence, financial/tax records, support/dispute records, security logs and backups. Retention will be tied to a stated purpose, legal requirement, limitation/evidence need or other documented lawful basis rather than indefinite storage.

When deletion is due, PESONA will delete, destroy, irreversibly anonymise or place data beyond ordinary production use as appropriate to the system. Backup copies may persist for a limited backup cycle where immediate deletion is not technically feasible, provided they remain protected, are not restored to ordinary use except for disaster recovery, and are deleted or overwritten in the ordinary backup lifecycle. PESONA will maintain reasonable verification or audit records showing that material scheduled-deletion controls are designed, configured and periodically checked to operate as intended, taking account of the relevant system and reasonable technical limitations.

New Data Types in Retention Schedule

The internal retention schedule must expressly cover at least Evaluation Preview content and preview audit metadata; Physical Measurements; Role Signals and derived-role records; role การอัปเกรด/การปรับยอด (upgrade/true-up) evidence; generation-credit purchase/use/refund records; and Composite similarity/identifiability screening records. Retention periods must reflect actual production behaviour and be reviewed when the processing changes materially.

Section 29

Automated decisions, profiling and human review

PESONA may use automated tools for fraud detection, duplicate-account checks, content moderation, matching, security, eligibility validation or operational prioritisation. PESONA will not intentionally make a solely automated decision that produces legal or similarly significant effects on an individual where Applicable Law prohibits that practice or requires additional safeguards, unless a lawful exception applies.

Where Applicable Law requires, PESONA will provide meaningful information about the relevant automated processing and an available method to request human review, express a view or contest a materially adverse decision. Biometric matching or AI-generated confidence scores will not be treated as infallible and may be subject to human or secondary review where appropriate to the risk.

Section 30

Accountability, training and access review

Personnel with access to personal data must be subject to appropriate confidentiality obligations and privacy/security training relevant to their role. PESONA will periodically review privileged and sensitive-data access and remove or adjust access that is no longer required. Material privacy controls, including consent capture, vendor restrictions, retention/deletion and incident procedures, will be assigned to responsible owners and reviewed periodically.

Where Applicable Law requires appointment or registration of a data protection officer, representative or other privacy contact, PESONA will make the appointment/registration and publish the required contact information. Nothing in this Policy limits mandatory accountability obligations imposed by Applicable Law.

Section 31

Implementation condition and accuracy of this policy

This Policy is intended to describe PESONA's material personal-data processing accurately. PESONA will use reasonable efforts not to state that a control, provider restriction, deletion practice, transfer safeguard or technical measure is implemented unless PESONA has a reasonable basis to believe it is implemented, or the statement clearly describes a future commitment. Before this Policy becomes effective, PESONA will reasonably verify material data flows, named providers, processing locations, retention practices, consent interfaces and material security statements against the production environment.

If actual processing materially differs from this Policy, PESONA will without undue delay take appropriate steps to remediate the processing, update the applicable notice, or obtain any additional consent or lawful basis required before continuing where Applicable Law requires. Contracts and privacy notices do not replace mandatory data-protection compliance or make unlawful processing lawful.

September Production-Alignment Gate

Before this Policy becomes effective, PESONA should verify that production consent defaults, exclusivity defaults, Evaluation Preview consent gating, preview storage and deletion, preview audit retention, Role/media derivation, generation-credit flows, Physical Measurement display, Composite screening and document versions match this Policy and the applicable agreements. Where production differs, PESONA should remediate the processing or update the legally required notice/consent before continuing the affected processing.

Section 32

Product data matrix

Character Sheet and Module B Closed - No Source Material Delivery may process authorised Source Material, Likeness, consent, watermark and delivery records. Studio may process prompts, previews, access and expiry records. Identity Monitoring may process authorised reference material, candidate matches and human-review decisions. Voice Products may process recordings, scripts, approvals and Outputs. Research may process authorised images, approved attributes and de-identified results. API and Reseller Products may process Partner, End User, acceptance, authentication and audit records. Processing occurs only when the applicable permission, lawful basis and operational gate are recorded.

Section 33

Country-specific application

Thailand. Biometric data used for unique identification and other sensitive data will be processed only on a basis permitted by Thai law, with specific consent where required. Malaysia. Where Malaysian law applies, PESONA will apply applicable sensitive-data, controller, processor, data-protection-officer, breach and transfer requirements. Indonesia. Before relevant launch, PESONA will document the applicable role, lawful basis, consent, rights, impact assessment, breach, transfer and local-representative requirements. Country-specific mandatory law prevails only to the extent it cannot lawfully be varied.

Section 34

Mobile application data

When a user chooses the relevant feature or grants device permission, PESONA may receive selected photos or media, camera-captured images or video, microphone audio, device and operating-system information, app version, diagnostics, session and authentication records, push-notification token and settings, and Apple or Google identity-provider identifiers. PESONA does not access an entire photo library, camera or microphone merely because the app is installed. Permissions may be changed in device settings, although a related feature may then be unavailable. Unless separately disclosed and consented where required, PESONA does not use advertising identifiers for cross-app tracking and does not sell personal data.

Section 35

Instant licensing processing

PESONA processes agreement versions, Consent Preferences, Standing Authorization parameters, Usage Brief fields, validation outcomes, payment and account status, risk flags, exception decisions, Licence and Certificate identifiers, timestamps and audit evidence to match requests, prevent out-of-scope licensing, activate or refuse a Licence, administer payments, resolve disputes and demonstrate compliance. Legal bases are applied by activity and jurisdiction and may include contract performance, steps requested before contract, legitimate interests, legal obligations and explicit consent where required for biometric or other sensitive data. A Privacy Policy is not itself a licence.

Section 36

Account deletion and retention

Users may initiate account deletion within the app and, where provided, through the published web route. PESONA will authenticate the request, explain material consequences, disable access and delete or de-identify data not required for an active Licence, outstanding payment, dispute, fraud/security investigation, legal claim or mandatory recordkeeping. If an active Licence or outstanding payment remains, PESONA retains only data necessary to administer it until completion and retains records required by law. Deletion of the account does not retrospectively invalidate a Licence lawfully activated before the effective deletion or withdrawal date. Backup deletion follows the documented cycle and access remains restricted.

Section 37

Mobile providers and store disclosures

Data may be obtained from the user, the device and operating system, Apple or Google identity services, APNs or FCM notification services, payment providers and authorised processors. PESONA shall keep this Policy, in-app permission prompts, account-deletion disclosures and App Store or Google Play data-safety declarations materially consistent with actual app behaviour and shall update them before a material new collection or use begins.

Section 38

Core contractual authorization and biometric consent

Marketplace matching, Character Sheets, Composite Personas and Evaluation Previews are governed by the applicable core contractual authorization. Any processing of Biometric Data that requires consent is separately governed by PESONA Biometric Consent Version 3.3. Core authorization does not override a withdrawn or invalid Biometric Consent. PESONA blocks new affected biometric processing immediately after an authenticated withdrawal request, completes operational deactivation within 24 hours, and deletes or irreversibly de-identifies affected data within 30 days, subject to lawful retention and isolated backup schedules.

Section 39

Setting changes and account deletion

Commercial preferences take effect after 48 hours and may be changed once per seven-day period; the prior settings remain operative during that window. Pausing availability, withdrawing Biometric Consent and requesting deletion are always available and are not counted toward that limit. Deletion does not invalidate prior lawful processing or an existing Activated Licence; PESONA retains only data needed for that Licence, payment, dispute, fraud, security, audit, tax or legal duties.

Section 40

Version 3.3 consent, story settings and payment events

PESONA records each required panel confirmation, Story and genre selection, sensitive-content choice, project-only or future permission, withdrawal, agreement/privacy version, language, text hash, timestamp, account, IP/device and relevant Authorization Record. Story and commercial permissions are contractual settings and are not Biometric Consent. Biometric Consent remains separate and unticked.

If a Contributor becomes unavailable during payment, PESONA may record the payment-start, unavailability and completion timestamps, cancel or refund the affected portion and tell the Client only that the Contributor became unavailable, without disclosing whether the cause was a pause, biometric withdrawal or deletion request. Retention and deletion remain subject to active-Licence, legal, dispute and isolated-backup requirements.

PESONA.

The consent-first marketplace for AI face licensing. Built in Thailand. Launching across Southeast Asia, 2026.

Platform

  • Contributors
  • Clients
  • About
  • AI face licensing
  • License your likeness
  • AI marketplace for Southeast Asia
  • FAQ

Company

  • hello@pesona.ai

Legal

  • Terms
  • Privacy
  • Talent Agreement
  • Delete your account
  • DPO
© 2026 Fresh Day Production Co., Ltd.v0.1.5