Definitive code of ethics
For NexStudio — headquarters: Bangkok, Thailand. Version 1.0, effective from 21 April 2026. Internal and external document: principles, obligations and operating procedures for anyone working with the Company.
Version 1.0 · Effective from: 21 April 2026
Summary index
- Preamble
- Scope of application
- Core values and principles
- Regulatory compliance (by perimeter: platform, legal, healthcare)
- Protection of personal and sensitive data
- Information security and operational resilience
- Software quality, clinical validation and user risk
- Intellectual property and use of external components
- Responsible use of AI/ML and automation
- Conflicts of interest and commercial integrity
- Operating lines: development, release and vulnerability management
- Governance, roles and responsibilities
- Onboarding, training and certification
- Reporting, whistleblower protection and investigations
- Handling of violations and sanctions
- Monitoring, audit and continuous improvement
- Mandatory documentation and registers
- Annexes and forms
- Approval and useful contacts
1. Preamble
This Code of Ethics sets out the principles, duties and rules of conduct that all parties involved in NexStudio (hereinafter the “Company”) must observe in the development, marketing and management of SaaS solutions, organized by lines (shared platform, legal domain, healthcare domain) and, in concrete terms, with particular reference to LexAura (Legal Tech) and MediAura (Health Tech). If the offering expands or evolves, new highly regulated lines shall be described under the same scheme (platform + domain perimeter), via annexes or text revision, without mixing criteria across verticals. It aims to ensure regulatory compliance, privacy protection, security, technical quality, protection of user rights and professional accountability.
2. Scope of application
It applies to: founders, executives, employees (full-time, part-time), external collaborators, consultants, contractors and suppliers. It covers all activities: analysis, design, development, testing, release, maintenance, support, marketing, sales and research.
3. Core values and principles
- Integrity, honesty and transparency.
- Respect for human dignity, inclusion and non-discrimination.
- Technical-professional responsibility and service quality.
- Confidentiality and protection of personal and sensitive data.
- Security and operational resilience.
- Legal and regulatory compliance.
- Continuous improvement and accountability.
4. Specific regulatory compliance
The references below are grouped: horizontal obligations for all SaaS offerings, distinct references for the Legal Tech / LexAura perimeter and for Health Tech / MediAura (each line may expand or diversify by product and market, without improper mixing with other perimeters). Product-line summary: LexAura (Legal Tech) and MediAura (Health Tech) .
4.1 Platform and SaaS offering (horizontal obligations)
Common references for all processing activities and all subscription lines, regardless of the end customer’s domain.
- Thailand Personal Data Protection Act (PDPA).
- General Data Protection Regulation (GDPR), where applicable for users or services in the European Union.
4.2 Legal domain (Legal Tech / LexAura)
Measures and references for software and flows used by law firms and regulated professions, including activity attributable to LexAura or evolutions in the same domain.
- Professional rules and professional secrecy for legal practice; respect for professional privileges (e.g. attorney–client privilege) where applicable; fairness and correctness toward counterparties and third parties, within the limits of law and professional ethics.
4.3 Healthcare domain (Health Tech / MediAura)
Data, risks and, where applicable, regulatory classifications attributable to Health Tech and MediAura (and products within the same perimeter).
- Relevant local or international healthcare regulations and standards (requirements for clinical data management, relevant ISO standards, care continuity where touched by the software).
- Requirements for medical devices or software for medical purposes (e.g. EU MDR, local regulations) if features fall within the definition of a medical device or equivalent for the chosen market.
- Rules and good practices on secrecy and confidentiality in healthcare (e.g. relations with practitioners) and, where applicable: HIPAA (United States) in addition to horizontal requirements (GDPR, PDPA) for transfers.
The Company carries out DPIAs (Data Protection Impact Assessments) for high-risk processing and consults authorities or regulatory counsel when needed, with references for each processing activity to the relevant perimeter (platform, legal, healthcare).
5. Protection of personal and sensitive data
Yes, role division must be explained: the Code sets what we expect from each party, without replacing the privacy notice or contracts. Below, in summary, who processes patient and client data relative to the firms and with which duties (Company, subscribers, data subjects).
5.1 Patients, firm clients and subscription: roles and processing
NexStudio (provider / service operator). The Company processes personal data and, where present, special categories (e.g. health, legal situation) only to provide, protect and improve the platforms, for support, security, billing, legal compliance and, where contractually provided, to assist the controller in honouring data subject rights. Staff working for the Company are prohibited from incompatible uses, from reselling data for purposes unrelated to the service, and from accessing professional content beyond what is technically necessary or for authorized support. Exact legal qualifications (e.g. processor under Art. 28 GDPR, or another scheme under PDPA) are defined in writing in the DPA and privacy documents.
Subscription subscribers (law firms, physicians, organizations, enrolled teams). Subscribers are, as a rule, controllers or joint controllers of the processing of data they enter or cause to be entered on the platform: in particular patients or care recipients (Health Tech) and clients, counterparties or third parties involved in files or matters (Legal Tech), as well as their own staff data. They must: have an adequate legal basis and notices toward their patients, clients and care recipients; respect professional duties (secrecy, confidentiality, record-keeping); map purposes and retention; give documented instructions to the provider where a processor appointment is needed; and respond in the first instance to access, rectification, erasure and objection requests from data subjects, cooperating with NexStudio when technical tools or logs are needed.
Patients and clients (data subjects). They exercise privacy rights primarily toward the firm, organization or professional that processes their data. NexStudio, except where direct exercise is provided by law or a specific channel, forwards or supports exercise through the controller, within the timelines and methods of the contract and product.
Operational details (categories, timelines, processing table, sub-processors, extra-EU transfers, notice texts addressed to patients or clients of the parties) are in the Privacy policy, cookie notice, DPA, terms of use and annexes, which can be updated without rewriting the entire Code when only the legal annex changes.
In day-to-day operations, the Company and collaborators adhere to the following operating principles (complementary to the roles above):
- Minimization: collect only necessary and relevant data.
- Legal basis: document the legal basis for every processing activity (consent, contract performance, legal obligation, assessed legitimate interest).
- Notice and consent: provide clear notices and obtain consent when required; manage consent in a verifiable way.
- Classification: define categories (PII, health data, privileged legal information) and apply differentiated measures.
- Retention and deletion: documented retention policies; anonymization or deletion at the end of the purposes.
- International transfers: assess legal bases (standard contractual clauses, adequacy decisions, technical measures) for transfers outside Thailand.
- Data subject rights: procedures for access, rectification, erasure, restriction, portability and objection, with documented timelines and logs.
- Sub-processors: contracts imposing equivalent security measures, breach notification obligations and prohibitions on further unauthorized sub-processing.
6. Information security and operational resilience
- Security by design and privacy by design: integration of security and privacy into the product lifecycle.
- Access controls: least-privilege principle, mandatory MFA for access to sensitive resources, centralized identity management.
- Encryption: encryption at rest and in transit with up-to-date algorithms; secure key management.
- Logging and monitoring: immutable logs for access and operations on sensitive data and production environments.
- Vulnerability management: automated scans, periodic penetration tests, patching process and responsible disclosure or bug bounty program.
- Business continuity and disaster recovery: regularly tested plans with defined RTO/RPO.
- Incident management: documented playbook (identification, containment, eradication, recovery, post-mortem), roles and internal/external notification timelines.
7. Software quality, clinical validation and user risk
- Development standards: readable code, automated tests, mandatory code reviews, secure CI/CD.
- Testing and coverage: define minimum coverage for critical components; integration, performance and security tests.
- Validation (legal perimeter) : for features that support choices or activities in the legal domain, validation with legal experts, pilot studies, documentation of limits and warnings, as provided for LexAura or equivalents in Legal Tech.
- Validation (healthcare perimeter) : for features that assist clinical decisions or healthcare activities, validation with clinical experts, pilot studies, warnings, as provided for MediAura or equivalents in Health Tech.
- Risk classification: assess impact on health or rights and apply proportionate mitigation measures.
- No substitution of the professional: the platform provides support and informational tools; it does not present itself as a substitute for professional advice without explicit professional supervision and endorsement.
- Registers and evidence: maintain documentation of clinical tests, risk assessments and regulatory approvals.
8. Intellectual property and use of external components
- Contributions by employees and consultants relating to software, documentation and know-how are owned by the Company, unless otherwise agreed in writing.
- Open source: maintain an SBOM (Software Bill of Materials), verify license compatibility, respect disclosure obligations and patch updates.
- Prohibition of unauthorized use of third-party code or intellectual property; management of IP contamination risks.
9. Responsible use of AI/ML and automation
- Document training datasets, provenance, pre-processing and known limits.
- Bias assessment: conduct analyses to identify and mitigate biases that may discriminate or cause harm.
- Human oversight: for decisions affecting health, legal proceedings or fundamental rights, provide human oversight and clear notices on system limits.
- Explainability and accountability: provide understandable information on how models support decisions and on performance and reliability.
- Post-release monitoring: measure production performance and correct drift or unexpected behaviour.
10. Conflicts of interest and commercial integrity
- Mandatory declaration of actual or potential conflicts (investments, relationships with suppliers or customers).
- Anti-corruption and anti-bribery policies compliant with national and international laws.
- Truthful commercial communications; do not mislead about capabilities, regulatory approvals or results.
- Contractual transparency: clear and accessible SLAs, liability limitations and terms of use.
11. Operating lines: development, release and vulnerability management
- Development: branch strategy, mandatory code review, merge only with green CI, pre-release checklist (security, privacy, compliance).
- Test environment: use of synthetic or anonymized data; access to real data only on a minimal authorized basis, in isolated environments.
- Deployment: standardized CI/CD with rollback plan and gradual releases for critical features.
- Vulnerability management: public or private reporting channel (bug bounty or dedicated security@ address), acknowledgement within 72 hours, remediation plan with estimated timelines.
- Patch management: patch release timelines defined by severity.
- Release documentation: changelog, known impacts and operational recommendations.
12. Governance, roles and responsibilities
- Board / founders: approve policies, define strategy and resources.
- CEO: overall responsibility for compliance and governance.
- CTO: technical quality, architecture and development practices.
- CISO / security lead: operational security, incident response, vulnerability management.
- DPO / privacy lead: PDPA and GDPR compliance, DPIA, handling of data subject requests.
- Legal & compliance: legal oversight, contracts and regulatory assessments.
- HR: training, code of conduct and disciplinary management.
- Team lead / PM: apply operating policies and ensure day-to-day compliance.
- Ethics committee (recommended): multidisciplinary group to assess complex cases (clinical or legal impacts, conflicts), with periodic and on-request meetings.
13. Onboarding, training and certification
- Mandatory onboarding on: information security, privacy (PDPA and GDPR), sensitive data handling, requirements and documentation for each product line (today: LexAura (Legal Tech) and MediAura (Health Tech) ; extend the curriculum when the list grows), responsible AI use, secure coding practices.
- Mandatory annual training and additional training for critical roles (see Training plan annex).
- Recording and retention of training records according to the register in the plan.
Open the Training plan (90 days + annual) →
14. Reporting, whistleblower protection and investigations
- Channels: at least one confidential internal channel (e.g. ethics@nexstudio.com ), external anonymous platform or third-party service; contact for independent escalation.
- Protection: prohibition of retaliation; disciplinary measures for proven retaliation.
- Investigations: conducted impartially, documented and with defined timelines; communication of outcomes to the reporter and interested parties, within the limits of confidentiality.
15. Handling of violations and sanctions
- Actions proportionate to severity: corrective training, reprimand, reassignment, suspension, termination of the contractual relationship, legal action if necessary.
- Register of infringements and actions taken; right of defence of the person concerned.
16. Monitoring, audit and continuous improvement
- Regular internal and external audits on security, privacy, compliance and quality control.
- KPIs (examples): number of incidents, average remediation time, test coverage percentage, training completion percentage, average response time to reports.
- Code review: at least annually or upon regulatory, technological or market changes.
17. Mandatory documentation and registers
The Company maintains and updates, among other things:
- records of processing and DPIAs;
- SBOM and component inventory (open source);
- access logs and audit trail;
- incident and data breach register;
- contracts with vendors and sub-processors;
- training records and Code adhesion declarations.
18. Annexes and forms (included)
Download and browse all operational templates on the dedicated page →
- Personal declaration of adhesion to the Code (to be signed at onboarding).
- NDA template and minimum clauses for vendors and sub-processors.
- Pre-release checklist (security and privacy).
- Incident management flowchart and notification template.
- Simplified DPIA model and completed example.
- Privacy notice model and consent form for users or patients.
- SBOM template.
- Data retention policy (timelines and justifications).
- AI/ML impact assessment template.
- Training plan — 90-day onboarding and annual refresh.
19. Approval and useful contacts
- Approved by: competent body / managing director (full name at signature).
- Update owner: Legal & compliance, with support from DPO and CISO.
- Review: at least annually or upon material changes.
Contacts
- DPO / privacy lead: privacy@nexstudio.com
- Security / incident response: security@nexstudio.com
- Confidential reports: ethics@nexstudio.com (or link to a dedicated anonymous platform)
- Legal: legal@nexstudio.com
- HR: hr@nexstudio.com
Final adhesion clause (to be signed at onboarding)
I declare that I have read and understood the Code of Ethics of NexStudio and I commit to respecting its principles and procedures. I also commit to reporting, in good faith, any violations of which I become aware.
Signature: · Date:
Practical notes and recommended next steps
- Customize the document with the official company name (if different from the operating brand), signatures and local legal references in Bangkok.
- Attach the listed templates as separate documents and implement technical channels for reporting and bug bounty.
- Apply the Training plan (operational annex): 90-day onboarding and annual refresh; HR keeps the completion register.
- Perform DPIAs for critical processing for each perimeter (especially high-criticality healthcare or legal processing), documenting the link to the product lines involved.
- For the Health Tech / MediAura line or equivalents, verify whether parts of the product fall within the definition of a medical device or software for medical purposes, for registration or approval according to the chosen market and classification.