Legal
Privacy Policy
Last updated: 15 February 2025 | Withaya, Chiang Mai, Thailand
1. Introduction
Withaya ("we", "us", "our") is committed to handling the personal information of course participants and website visitors with care and transparency. This policy explains what data we collect, how we use it, who we may share it with, and what rights you have in relation to it.
If you have questions about this policy or how we handle your data, please contact us at [email protected].
2. Data We Collect
We collect personal data through the following means:
- Enquiry forms: Name, email address, and phone number when you contact us about a course.
- Course enrolment: Name, contact details, and any information you share during the enrolment process.
- Session participation: Notes and feedback collected during or after course sessions (stored securely and not attributed publicly).
- Website analytics: Aggregate, anonymised data about how visitors use our website, via cookies (see Section 7).
We do not collect sensitive financial data beyond what participants choose to share within course sessions, and this is handled as described in Section 4.
3. Legal Basis for Processing
We process personal data under the following legal bases, consistent with Thailand's Personal Data Protection Act B.E. 2562 (PDPA):
- Consent: For marketing emails and analytics cookies, where you have provided consent.
- Contractual necessity: For processing your enrolment and delivering course services.
- Legitimate interests: For following up with past participants about course feedback, where it is reasonable to expect this.
4. How We Use Your Data
- To respond to enquiries about our courses
- To process enrolments and coordinate session schedules
- To send course materials and follow-up communications
- To collect feedback and improve course content
- To send relevant updates about upcoming courses (only where you have given consent)
- To comply with applicable legal requirements
Any financial information you share during sessions is used solely to support your participation in that course. It is not stored in our main database, not shared with third parties, and not used for any purpose beyond the course itself.
5. Data Sharing
We do not sell personal data. We do not share personal data with third parties for their marketing purposes. We may share data in limited circumstances:
- Service providers: Trusted providers who support our website or communications infrastructure, bound by data processing agreements.
- Legal requirements: Where disclosure is required by Thai law or by order of a competent authority.
6. Data Retention
We retain personal data for the following periods:
- Enquiry data (no enrolment): 12 months from last contact
- Participant records: 3 years from the date of course completion
- Financial session notes: Destroyed after each course concludes
- Analytics data: Aggregate only, retained for 24 months
7. Cookies
Our website uses cookies to understand how visitors use the site and to maintain basic session functions. For full details of the cookies we use and how to manage your preferences, please see our Cookie Policy.
8. Your Rights
Under the PDPA and applicable data protection principles, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data, subject to lawful retention requirements
- Object to processing based on legitimate interests
- Withdraw consent at any time (where processing is based on consent)
- Request data portability in a commonly used format
- Lodge a complaint with the Office of the Personal Data Protection Committee (PDPC) of Thailand
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.
9. Data Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. Access to participant data is restricted to staff who need it to carry out their role. Our website uses HTTPS encryption.
10. Third-Party Links
Our website may contain links to external resources. We are not responsible for the privacy practices of third-party websites and recommend reviewing their privacy policies before submitting any personal information.
11. Children's Privacy
Our courses are designed for adults aged 18 and over. We do not knowingly collect personal data from individuals under 18. If you believe a minor has submitted data to us, please contact us and we will remove it promptly.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated to enrolled participants by email. The updated policy will also be available on this page with a revised "Last Updated" date.
13. Contact
Data Controller: Withaya
Address: 56 Chiang Mai-Lampang Road, Mueang, Chiang Mai 50000, Thailand
Email: [email protected]