Legal

Privacy Policy

Last Updated: 15 March 2025

Effective Date: 15 March 2025

This Privacy Policy describes how Oakthorn ("we," "us," "our") collects, uses, stores, and protects personal data provided by visitors to our website and participants in our programs. We are committed to handling personal information with care, transparency, and respect for your rights under applicable law.

Questions or concerns about this policy may be directed to: [email protected]

1. Data We Collect

We collect personal data only when you voluntarily provide it through our website contact form or when you enrol in a program. The categories of data we may collect include:

  • Full name and preferred form of address
  • Email address
  • Phone number (if provided)
  • Message content submitted through our contact form
  • Program enrolment records and session attendance
  • Website usage data collected via cookies (see Section 6)

We do not collect sensitive personal data (such as financial account details, health information, or national identification numbers) through our website.

2. How We Use Your Data

Personal data collected through our website and programs is used for the following purposes:

  • Responding to enquiries: We use contact form submissions to reply to questions about our programs.
  • Program delivery: Enrolment information is used to administer sessions, send program materials, and maintain attendance records.
  • Communication: We may send information relevant to an enrolled participant's program via email.
  • Website improvement: Aggregated, anonymised analytics data helps us understand how the site is used and improve its content.

We do not use personal data for unsolicited marketing. We do not sell, rent, or share your personal information with third parties for commercial purposes.

3. Legal Basis for Processing

We process personal data on the following legal bases under Thailand's Personal Data Protection Act (PDPA) B.E. 2562:

  • Consent: Where you have submitted a contact form or opted into communications, processing is based on your consent.
  • Contract: Where you have enrolled in a program, processing is necessary to perform that educational engagement.
  • Legitimate interest: Website analytics are processed on the basis of our legitimate interest in maintaining and improving the site.

4. Data Retention

Contact form enquiries are retained for a maximum of 12 months from the date of submission. Program enrolment records are retained for 5 years following the completion of a program, after which they are securely deleted. Analytics data is retained in aggregated, anonymised form with no individual retention limit.

5. Data Protection Measures

  • Data transmitted via our website contact form is encrypted using TLS/SSL.
  • Internal access to personal data is restricted to staff who require it for their role.
  • We do not store payment information — payments are processed through third-party providers and are not retained by Oakthorn.
  • In the event of a data breach that affects your rights and freedoms, we will notify affected individuals within 72 hours of becoming aware, in accordance with PDPA requirements.

6. Cookies

Our website uses cookies to improve functionality and collect anonymised usage data. Cookies are categorised as follows:

  • Essential cookies: Required for basic site functionality. Cannot be disabled.
  • Analytics cookies: Help us understand how visitors use the site. Can be declined via our cookie consent settings.
  • Preference cookies: Remember your settings. Can be declined.

For full details, see our Cookie Policy.

7. Third-Party Services

We use a limited number of third-party services in connection with website operations:

  • Google Analytics (optional): Collects anonymised usage data if analytics cookies are accepted. Governed by Google's Privacy Policy.
  • Email service provider: We use a secure email platform for correspondence. Messages are not retained beyond operational need.

We are not responsible for the privacy practices of third-party services. We encourage you to review their policies directly.

8. Your Rights

Under Thailand's PDPA, you have the following rights regarding your personal data:

  • Right to access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your data, subject to legal retention obligations.
  • Right to data portability: Request your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests.
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent.
  • Right to lodge a complaint: Lodge a complaint with the Personal Data Protection Committee (PDPC) of Thailand.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

9. External Links

Our website may contain links to external sites. We are not responsible for the content or privacy practices of those sites. We encourage you to review their privacy policies before providing any personal information.

10. Children's Privacy

Our programs are designed for adults aged 18 and over. We do not knowingly collect personal data from individuals under 18. If we become aware that we have collected data from a minor, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Where changes are material, we will post notice on our website. Continued use of the site following any update constitutes acceptance of the revised policy. The date at the top of this page reflects the most recent revision.

12. Contact

For privacy-related enquiries, please contact:

Oakthorn

88 Wireless Road, Lumphini, Pathum Wan, Bangkok 10330, Thailand

[email protected]