Legal framework

    Data Governance Pack

    Business terms for lawful B2B data collection, imports, enrichment, evidence processing, marketplace coordination, audit/QMS workflows and cross-border transfers across Thailand, EU/EEA and UK use cases.

    1. Data Processing Addendum baseline

    For customer-controlled business data, CannaWorld can act as processor and the customer remains controller. Processing is limited to platform operation, support, evidence workflows, compliance readiness, security, audit logs, notifications and documented customer instructions.

    Processor duties include confidentiality, role-based access, reasonable technical and organizational measures, subprocessors under written terms, incident escalation, return/deletion support and assistance with data-subject requests where legally required.

    2. Data import and enrichment policy

    Imports must be lawful, proportionate and connected to B2B cannabis, pharmaceutical, laboratory, logistics, QP, importer, wholesaler, pharmacy, auditor or compliance workflows.

    Allowed sources include user uploads, customer-approved files, public company/register data, professional directories, event or trade lists with lawful access, inbound leads and manually researched business information. Unlawful scraping, access-control bypassing, paywall circumvention, ToS-violating harvesting and ignored opt-outs are not allowed.

    3. Marketplace, trade-case and lead data

    Marketplace listings, trade cases, buyer requirements, seller documents, contact data and lead-enrichment data may be used to qualify counterparties, route opportunities, suppress unsuitable contacts, verify business status, maintain audit trails and support lawful B2B communications.

    Opt-out, suppression and correction requests must be honored in operational systems before new outreach or enrichment runs are started.

    4. Evidence, audit and QMS records

    Evidence packs may include licenses, CoAs, batch records, SOPs, facility files, inspection notes, CAPA records, training records, images, video, signatures and communications. These records are used for readiness, traceability, internal QMS and counterparty review.

    CannaWorld does not convert uploaded evidence into official certification. Auditors, labs, QPs and authorities remain responsible for their own decisions.

    5. AI and automated review boundaries

    AI may classify, extract, summarize, translate, compare and score evidence. AI outputs are advisory and must be checked by competent humans before regulatory, commercial, QP, laboratory, legal or authority reliance.

    AI must not be represented as releasing batches, issuing official certificates, replacing a QP, replacing legal advice or guaranteeing import approval.

    6. Cookie and consent policy

    Necessary storage supports login, language, security, session continuity and consent state. Optional analytics or marketing technologies require consent where applicable.

    Consent logs should record status, timestamp, source, policy version and withdrawal where feasible.

    7. EU/EEA/UK addendum

    EU/EEA/UK workflows should apply GDPR/UK GDPR principles: purpose limitation, minimization, accuracy, storage limitation, security, accountability, transfer safeguards and data-subject rights handling.

    Where CannaWorld processes personal data for a customer, execute a DPA and document subprocessors, transfer tools, retention and role allocation.

    8. Thailand PDPA addendum

    Thailand workflows should apply PDPA notice, lawful basis, security, retention, data-subject rights and cross-border transfer requirements. Sensitive data and government-license data should be minimized and access-controlled.

    Cannaworld Co., Ltd. remains the Thailand operator unless a signed order document identifies another contracting entity.

    Legal context: this pack describes general data-governance controls. Mandatory law and the signed DPA, order form or service agreement govern the actual processing arrangement.