PRIVACY POLICY

THAI - FINNISH CHAMBER OF COMMERCE

Last Updated: September 2026

1. Our Commitment

The THAI – FINNISH CHAMBER OF COMMERCE (“TFCC,” “we,” “us,” or “our”) protects your personal data and respects your privacy.

This policy details how we collect, use, disclose, and store your personal data in compliance with: Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) and The European Union’s General Data Protection Regulation (GDPR) (where applicable).

2. Data Controller Identity & Scope

Data Controller

  • Organization: THAI – FINNISH CHAMBER OF COMMERCE
  • Tax ID / Registration: 0108535000029 (Tax ID: 0-1085-35000-02-9)
  • Head Office: Level 2, Summer Point Building, 7 Sukhumvit 69 Road, Phra Khanong
    Nuea, Watthana, Bangkok 10110, Thailand
  • Email: [email protected]
  • Website: https://thaifin.org/

Scope

This policy covers data collected through:

  • Our official main domain and all associated subdomains
  • Our marketing emails, event circulars, and newsletters
  • Our official profiles on LinkedIn, Facebook, Instagram, and Google Business Profile
  • Membership applications, event registrations, community portals, ticketing, and direct
    email inquiries

3. Personal Data We Collect

We collect data across six practical categories:

  • Identity & Professional Data: Name, title, employer, position, nationality, and
    professional biography.
  • Contact Data: Email address, billing address, and social media handles.
  • Financial & Billing Data: Tax ID, corporate billing details, payment receipts, and bank
    transfer slips.
  • Event, Community & Media Data: Attendance history, community engagement
    records, dietary requirements, and photographs or video recordings from chamber events.
  • Email Engagement Data: Open rates, link clicks, and bounce reports from our email broadcasts.
  • Technical Browsing Data: IP addresses, browser types, operating systems, and aggregate visitor analytics collected via cookies.

4. Purposes and Lawful Bases for Processing

Under PDPA Section 24 and GDPR Article 6, we process data only when supported by a
statutory lawful basis:

Purpose Data Categories Lawful Basis (PDPA / GDPR)
Chamber Membership & Community: Processing applications, renewals, member directories, community platforms, and governance. Identity, Professional, Contact, Billing Contractual Necessity (PDPA §24(3) / GDPR Art. 6(1)(b))
Event Ticketing & Badging: Managing guest lists, ticket sales, and venue catering. Identity, Contact, Billing, Dietary Needs Contractual Necessity (PDPA §24(3) / GDPR Art. 6(1)(b))
Tax & Financial Compliance: Issuing tax invoices, receipts, and filing statutory audits. Identity, Billing, Financial Records Legal Obligation under Thai Revenue Code (PDPA §24(6) / GDPR Art. 6(1)(c))
Marketing Emails & Updates: Distributing newsletters, trade briefings, and event alerts. Name, Email, Engagement Metrics Consent (PDPA §19 / GDPR Art. 6(1)(a)) OR Legitimate Interests for active business contacts
Trade Inquiries & Networking: Answering member inquiries and facilitating bilateral trade introductions. Professional, Contact, Inquiry Data Legitimate Interests in bilateral commerce (PDPA §24(5) / GDPR Art. 6(1)(f))
Event Photography & Media: Publishing event photos to document and showcase chamber life. Photos, Video Media Legitimate Interests (PDPA §24(5) / GDPR Art. 6(1)(f)), subject to opt-out and erasure rights

5. Cookies and Web Analytics

  • Strictly Necessary Cookies: Essential for website navigation, session security, and
    basic functions.
  • Performance & Analytics Cookies: Collect aggregate, non-identifiable traffic data to
    help us improve site navigation.
  • Browser Controls: You can block or delete cookies in your browser settings. Disabling
    cookies may limit some interactive features.

6. Sharing Data with Third Parties

We never sell, rent, or trade your personal data. We disclose information strictly on a
need-to-know basis to:

  • Cloud, CRM & Platform Providers: Secure enterprise systems for member databases,
    CRM automation, community collaboration platforms, and email distribution.
  • Authorized Technical & Operational Partners: Vetted professional service partners
    bound by written confidentiality and data processing agreements who assist with
    chamber administration, platform maintenance, and communications.
  • Banks & Auditors: Financial institutions, statutory auditors, and legal counsel for
    payment processing and annual compliance.
  • Event Partners: Co-hosting organizations and institutional partners for joint attendee
    lists.
  • Government Authorities: The Thai Revenue Department and the Department of
    Business Development (DBD) when required by Thai law.

7. International Cloud Transfers

Because TFCC uses secure international cloud infrastructure, your data may transfer to
servers outside Thailand or the European Economic Area. We safeguard all cross-border
data transfers through standard contractual clauses and data processing agreements in
compliance with PDPA Sections 28–29 and GDPR Chapter V.

8. Data Retention Periods

We store personal data only as long as necessary to fulfill its collection purpose or satisfy
legal and accounting standards:

  • Invoices & Billing Records: Retained for 7 to 10 years under the Thai Revenue Code
    and chamber accounting regulations.
  • Marketing Subscribers: Retained until you unsubscribe or withdraw consent.
  • General Inquiries: Retained for up to 2 years after resolving your inquiry.
  • Chamber Archives (Photos & Videos): Retained in historical records unless you
    request erasure.

9. Your Statutory Privacy Rights

Under PDPA (Sections 30–36) and GDPR (Articles 15–22), you hold the following statutory
rights:

  1. Access: Request a copy of the personal data we hold about you.
  2. Correction: Correct inaccurate, incomplete, or outdated data.
  3. Erasure: Request that we delete or destroy your data when retention is no longer
    necessary or lawful.
  4. Restriction: Request that we temporarily suspend data processing under statutory
    conditions.
  5. Portability: Receive your data in a structured, machine-readable format.
  6. Objection: Stop data processing for direct marketing at any time.
  7. Withdraw Consent: Revoke your consent for optional activities (like newsletters)
    without affecting prior processing.

How to Exercise Your Rights

Submit your request in writing to our administrative office (Section 2). We verify your
identity to protect your data and respond within statutory deadlines (30 days).

10. Filing a Complaint

If you believe our data processing violates applicable regulations, you may lodge a
complaint with the relevant supervisory authority:

11. Security Safeguards

We safeguard personal data using access controls, encryption, multi-factor authentication, and confidentiality obligations.

12. Policy Updates & Inquiries

We review and update this Privacy Policy periodically. We post the latest revision at https://thaifin.org/legal/tfcc-privacy-policy/ with the effective “Last Updated” date.

For general inquiries or policy questions, contact our administrative office (Section 2).