Privacy Policy Overview
This Privacy Policy describes how propertydealassist collects, processes and safeguards personal data in the delivery of IT security and digital literacy training. The document outlines the categories of data we handle, purposes for processing, legal bases, data sharing practices, retention periods and security measures. The policy applies to individuals who interact with our website, enroll in training, request information, or otherwise use our services. We adopt an approach that emphasizes limited collection, documented handling procedures and technical controls appropriate to the sensitivity of the data. For questions about this policy or our practices, contact our data protection representative using the contact details provided below.
Key Definitions
For clarity, the following terms are used throughout this policy to describe the types of information processed and the parties involved. Definitions are provided in plain language to assist learners and site visitors in understanding how data is handled in the context of our training services.
Data We Collect
We collect information from users in three primary ways: data provided directly by users, data collected automatically when using our services, and data obtained from third-party partners where necessary to deliver services or comply with legal obligations.
Data You Provide
When you enroll, request information, or communicate with us we collect the following categories of user-provided data to administer accounts, deliver courses and support learning outcomes:
- Full name and professional title
- Email address and billing address
- Telephone number and emergency contact where provided
- Organization name and job role for corporate accounts
- Course enrollment details, assessments, certifications and progress records
- Support requests, feedback, and communication history
Automatically Collected Data
When you interact with our website and learning platforms we automatically collect technical and usage information to maintain security, understand usage patterns and improve service delivery:
- IP address and approximate geolocation derived from network routing
- Device and browser information, operating system and screen resolution
- Usage logs, pages visited, session duration and interactions within the learning platform
- Cookie identifiers and local storage vouchers used for session management
- Analytics data collected to measure course engagement and platform performance
- Error reports and diagnostic information generated by the platform
Data from Third Parties
In certain situations we receive data from trusted third parties to support enrollment, payment processing and platform functionality. We limit such data to what is necessary for the stated purpose:
- Payment processors and invoicing services for billing and refunds
- Analytics and hosting providers that support website performance and reporting
- Identity verification services where required for compliance or certification
Purposes of Processing
We process personal data for specific, legitimate purposes tied to course delivery, administration and legal compliance. Processing is limited to what is necessary to achieve these objectives:
- Account creation, authentication and administration for learners and corporate accounts
- Delivery of course content, assessments, certifications and progress reporting
- Billing, invoicing and business reconciliation with payment service providers
- Customer support, scheduling and communications related to enrolled courses
- Platform maintenance, security monitoring and fraud detection to protect users and systems
- Service improvement, research and analytics to enhance training quality and relevance
- Compliance with legal obligations, regulatory reporting and legitimate business interests such as dispute resolution
- Marketing communications where the user has provided consent to receive such information
Legal Bases for Processing
We rely on one or more lawful bases to process personal data depending on the purpose and jurisdiction. Typical legal bases include:
- Performance of a contract: processing necessary to provide the training services you requested
- Legal obligation: processing required to comply with applicable laws, tax or regulatory requirements
- Legitimate interests: processing for platform security, fraud prevention and internal analytics where those interests are balanced against user rights
- Consent: where processing requires explicit permission, such as marketing communications or optional analytics trackers
Your Data Rights
Where EU data protection rules are applicable, individuals have rights that enable them to control how their personal data is processed. We describe those rights below and how to exercise them.
- Right of access: request a copy of your personal data held by us
- Right to rectification: correct inaccurate or incomplete personal data
- Right to erasure: request deletion of personal data when there is no overriding legal requirement to retain it
- Right to restriction and objection: request limited processing or object to certain processing activities
- Right to data portability: receive personal data in a structured commonly used format where applicable
- Right to withdraw consent: if processing is based on consent you may withdraw it at any time without affecting prior processing
Data Sharing and Processors
We share personal data with trusted processors and partners only to the extent necessary to deliver services, manage payments or comply with legal obligations. Contracts and technical safeguards are used to protect shared data.
- Hosting and infrastructure providers that store and process course content and learner data
- Payment processors and business institutions for processing fees and refunds
- Analytics and email service providers used to monitor platform performance and deliver communications
- Professional advisors and auditors for legal compliance and business reporting
- Certification bodies when users request verifiable course completion records
- Law enforcement or regulators where disclosure is required by law or to protect rights and safety
International Transfers
Personal data collected may be stored and processed in jurisdictions outside Thailand for operational reasons. When transfers occur, we implement appropriate safeguards to ensure an adequate level of protection consistent with applicable law.
Safeguards include standard contractual clauses, data processing agreements with subprocessors, encryption in transit and at rest, and limiting access to personnel who require the data to perform their duties.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this policy, to meet legal or regulatory requirements, and to resolve disputes. Retention periods are defined according to data category and purpose.
Account records and enrollment history are retained for the duration of the customer relationship and subsequently archived for tax and compliance purposes for a limited statutory period determined by applicable law.
Support communications, requests and transactional emails are retained for a period necessary to respond to inquiries and maintain an audit trail, typically no longer than two years unless required otherwise.
System logs, access records and security-related telemetry are retained for operational security and incident contribute for periods aligned with our security policy and legal obligations.
When data is no longer required we securely delete or anonymize it. Individuals can request deletion in accordance with local law, subject to exceptions for legal and contractual retention requirements.
Security Measures
We apply a combination of organizational, technical and physical measures to protect personal data from unauthorized access, disclosure, alteration and destruction. Security controls are periodically reviewed and updated in line with recognized standards and evolving threats.
- Encryption of data in transit and at rest, using up-to-date encrypted protocols
- Role-based access control, multifactor authentication for administrative accounts and least-privilege principles
- Regular security assessments, vulnerability scanning, backups and an incident response plan maintained by trained personnel
How to Exercise Your Rights
As a data subject interacting with propertydealassist services, you have specific rights regarding the collection, use and management of your personal data. We describe those rights below and explain how you can exercise them in a clear, verifiable manner in accordance with applicable Thai data protection practice and our internal procedures.
- Right of access — You may request confirmation whether we process your personal data and request a copy of the personal data we maintain about you, including processing purposes and categories of data.
- Right to rectification — If personal data we hold about you is inaccurate or incomplete, you may request correction or completion of that data.
- Right to erasure (right to be forgotten) — Subject to legal and operational limits, you may request deletion of personal data that is no longer necessary for the purpose for which it was collected.
- Right to restriction of processing — You may request temporary suspension of processing where the accuracy or lawfulness of processing is contested while we verify the issue.
- Right to data portability — Where processing is based on consent or contract and carried out by automated means, you can request a copy of personal data in a structured, commonly used and machine-readable format.
- Right to object — You may object to processing based on legitimate interests or direct marketing; we will review such objections and take appropriate measures where required by law.
- Right to withdraw consent — If processing is based on consent you previously provided, you may withdraw consent at any time; withdrawal applies prospectively and will not affect prior lawful processing.
- Right to lodge a complaint — If you consider our handling of your personal data not in compliance with applicable law, you may lodge a complaint with the competent supervisory authority in Thailand or contact our privacy team for internal review.
How to submit a data rights request
To exercise any of the rights above, submit a written request to our Data Protection Officer by email or postal mail. Include your full name, a description of the request, and any documents required to verify your identity. Where appropriate, identify the specific processing activity or data fields involved to help us locate the information promptly.
We review requests upon receipt and aim to respond within 30 calendar days. Complex requests or requests requiring additional verification may take up to 60 calendar days; we will notify you if an extension is necessary and explain the reason for any delay.
Marketing communications and profiling
We may use contact details you provide to send service updates, course announcements and relevant IT security guidance. Marketing communications are limited to topics for which you have opted in or where there is a legitimate interest that is not overridden by your rights. We do not use automated profiling for high-impact decisions without explicit consent.
You can opt out of marketing communications at any time by using the unsubscribe link in emails, by visiting your account settings on propertydealassist, or by sending an unsubscribe request to [email protected]. Unsubscribing will not affect transactional messages related to your account or course enrollment.
Protection of minors and children’s data
Our services are designed for adults and professionals. We do not knowingly collect personal information from children under the age of 15. If we become aware that we have inadvertently collected data from a minor, we will take steps to remove the data as required under applicable law and our procedures.
Third-party links and integrations
propertydealassist may include links to third-party websites, services and learning partners. These external sites operate under their own privacy policies and practices. We recommend reviewing third-party privacy statements before submitting personal information. We are not responsible for third-party content or their data handling.
Changes to this privacy information
We periodically review and may update our privacy practices. Material changes that affect how we process your personal data will be communicated through propertydealassist notifications, the privacy policy page, or direct message to affected users. The effective date of the latest version will be published on the privacy policy page.