PRIVACY POLICY
THAI - FINNISH CHAMBER OF COMMERCE
1. Our Commitment
The THAI – FINNISH CHAMBER OF COMMERCE (“TFCC,” “we,” “us,” or “our”) protects your personal data and respects your privacy.
This policy details how we collect, use, disclose, and store your personal data in compliance with: Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) and The European Union’s General Data Protection Regulation (GDPR) (where applicable).
2. Data Controller Identity & Scope
Data Controller
- Organization: THAI – FINNISH CHAMBER OF COMMERCE
- Tax ID / Registration: 0108535000029 (Tax ID: 0-1085-35000-02-9)
- Head Office: Level 2, Summer Point Building, 7 Sukhumvit 69 Road, Phra Khanong
Nuea, Watthana, Bangkok 10110, Thailand - Email: [email protected]
- Website: https://thaifin.org/
Scope
This policy covers data collected through:
- Our official main domain and all associated subdomains
- Our marketing emails, event circulars, and newsletters
- Our official profiles on LinkedIn, Facebook, Instagram, and Google Business Profile
- Membership applications, event registrations, community portals, ticketing, and direct
email inquiries
3. Personal Data We Collect
We collect data across six practical categories:
- Identity & Professional Data: Name, title, employer, position, nationality, and
professional biography. - Contact Data: Email address, billing address, and social media handles.
- Financial & Billing Data: Tax ID, corporate billing details, payment receipts, and bank
transfer slips. - Event, Community & Media Data: Attendance history, community engagement
records, dietary requirements, and photographs or video recordings from chamber events. - Email Engagement Data: Open rates, link clicks, and bounce reports from our email broadcasts.
- Technical Browsing Data: IP addresses, browser types, operating systems, and aggregate visitor analytics collected via cookies.
4. Purposes and Lawful Bases for Processing
Under PDPA Section 24 and GDPR Article 6, we process data only when supported by a
statutory lawful basis:
| Purpose | Data Categories | Lawful Basis (PDPA / GDPR) |
|---|---|---|
| Chamber Membership & Community: Processing applications, renewals, member directories, community platforms, and governance. | Identity, Professional, Contact, Billing | Contractual Necessity (PDPA §24(3) / GDPR Art. 6(1)(b)) |
| Event Ticketing & Badging: Managing guest lists, ticket sales, and venue catering. | Identity, Contact, Billing, Dietary Needs | Contractual Necessity (PDPA §24(3) / GDPR Art. 6(1)(b)) |
| Tax & Financial Compliance: Issuing tax invoices, receipts, and filing statutory audits. | Identity, Billing, Financial Records | Legal Obligation under Thai Revenue Code (PDPA §24(6) / GDPR Art. 6(1)(c)) |
| Marketing Emails & Updates: Distributing newsletters, trade briefings, and event alerts. | Name, Email, Engagement Metrics | Consent (PDPA §19 / GDPR Art. 6(1)(a)) OR Legitimate Interests for active business contacts |
| Trade Inquiries & Networking: Answering member inquiries and facilitating bilateral trade introductions. | Professional, Contact, Inquiry Data | Legitimate Interests in bilateral commerce (PDPA §24(5) / GDPR Art. 6(1)(f)) |
| Event Photography & Media: Publishing event photos to document and showcase chamber life. | Photos, Video Media | Legitimate Interests (PDPA §24(5) / GDPR Art. 6(1)(f)), subject to opt-out and erasure rights |
5. Cookies and Web Analytics
- Strictly Necessary Cookies: Essential for website navigation, session security, and
basic functions. - Performance & Analytics Cookies: Collect aggregate, non-identifiable traffic data to
help us improve site navigation. - Browser Controls: You can block or delete cookies in your browser settings. Disabling
cookies may limit some interactive features.
6. Sharing Data with Third Parties
We never sell, rent, or trade your personal data. We disclose information strictly on a
need-to-know basis to:
- Cloud, CRM & Platform Providers: Secure enterprise systems for member databases,
CRM automation, community collaboration platforms, and email distribution. - Authorized Technical & Operational Partners: Vetted professional service partners
bound by written confidentiality and data processing agreements who assist with
chamber administration, platform maintenance, and communications. - Banks & Auditors: Financial institutions, statutory auditors, and legal counsel for
payment processing and annual compliance. - Event Partners: Co-hosting organizations and institutional partners for joint attendee
lists. - Government Authorities: The Thai Revenue Department and the Department of
Business Development (DBD) when required by Thai law.
7. International Cloud Transfers
Because TFCC uses secure international cloud infrastructure, your data may transfer to
servers outside Thailand or the European Economic Area. We safeguard all cross-border
data transfers through standard contractual clauses and data processing agreements in
compliance with PDPA Sections 28–29 and GDPR Chapter V.
8. Data Retention Periods
We store personal data only as long as necessary to fulfill its collection purpose or satisfy
legal and accounting standards:
- Invoices & Billing Records: Retained for 7 to 10 years under the Thai Revenue Code
and chamber accounting regulations. - Marketing Subscribers: Retained until you unsubscribe or withdraw consent.
- General Inquiries: Retained for up to 2 years after resolving your inquiry.
- Chamber Archives (Photos & Videos): Retained in historical records unless you
request erasure.
9. Your Statutory Privacy Rights
Under PDPA (Sections 30–36) and GDPR (Articles 15–22), you hold the following statutory
rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Correct inaccurate, incomplete, or outdated data.
- Erasure: Request that we delete or destroy your data when retention is no longer
necessary or lawful. - Restriction: Request that we temporarily suspend data processing under statutory
conditions. - Portability: Receive your data in a structured, machine-readable format.
- Objection: Stop data processing for direct marketing at any time.
- Withdraw Consent: Revoke your consent for optional activities (like newsletters)
without affecting prior processing.
How to Exercise Your Rights
Submit your request in writing to our administrative office (Section 2). We verify your
identity to protect your data and respond within statutory deadlines (30 days).
10. Filing a Complaint
If you believe our data processing violates applicable regulations, you may lodge a
complaint with the relevant supervisory authority:
- Thailand:
Office of the Personal Data Protection Committee (PDPC)
Website: https://www.pdpcthailand.com/ | Email: [email protected] | Phone: +66 (0) 2
142 1000 - European Union / Finland:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
Website: https://tietosuoja.fi/ | Email: [email protected] | Phone: +358 (0) 29 566 6700
(Or the data protection authority in your EU Member State of residence or
employment.)
11. Security Safeguards
We safeguard personal data using access controls, encryption, multi-factor authentication, and confidentiality obligations.
12. Policy Updates & Inquiries
We review and update this Privacy Policy periodically. We post the latest revision at https://thaifin.org/legal/tfcc-privacy-policy/ with the effective “Last Updated” date.
For general inquiries or policy questions, contact our administrative office (Section 2).