Legal
Privacy Policy
How we handle your personal data under Thailand's Personal Data Protection Act.
Draft for review — not yet legally binding
This document is an unreviewed draft prepared as a starting point. It must be checked and amended by a Thai lawyer familiar with the Personal Data Protection Act (PDPA) and tourism regulations before Sea Hills Resort relies on it. Items in [square brackets] are placeholders awaiting real details.
Last updated: [date this policy is approved]
Who we are
Sea Hills Resort is a fifteen-room, family-run hotel on the hillside above Patong, Phuket, Thailand. For the purposes of the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), we are the data controller for the personal data described below.
- Operating entity: [registered company name], [company registration number]
- Registered address: [registered company address, Thailand]
- Hotel operating licence number: [hotel licence no.]
- TAT (Tourism Authority of Thailand) registration: [TAT licence no., if applicable]
- Tax ID: [Thai tax identification number]
What data we collect
- Booking and stay details — name, nationality, date of birth, passport or ID details where Thai law requires us to record them, arrival and departure dates, room type, guest numbers, special requests.
- Contact details — email address, telephone/WhatsApp number, postal address, LINE ID.
- Payment information — the amount, currency, method and status of payment. Card numbers are handled by our booking engine and payment providers; we do not store full card numbers on our own systems.
- Correspondence — enquiry form submissions, emails, chat messages with our on-site assistant, and review or feedback you send us.
- Marketing preferences — your email address and language if you join our newsletter, and the fact and time of your consent.
- Website data — with your consent, analytics data such as pages visited, approximate location, device and browser. See our Cookie Policy.
- On-site data — CCTV in public areas of the property [confirm coverage and signage], and any incident records.
Why we use it, and our legal basis
- To provide your stay (contract) — taking and confirming bookings, allocating rooms, billing, answering questions, honouring requests.
- To meet legal duties (legal obligation) — immigration and guest registration reporting required of hotels in Thailand, tax and accounting records, safety records.
- To run and improve the hotel (legitimate interest) — service quality, security of the property, preventing fraud and misuse, defending legal claims.
- Marketing emails and non-essential cookies (consent) — only where you have opted in, and you may withdraw at any time.
- Sensitive data — we ask for dietary, medical, accessibility or allergy information only where you volunteer it so we can look after you, and we use it on the basis of your explicit consent.
Who we share it with
We do not sell personal data. We share only what is needed, with:
- Our channel manager and booking engine provider (WuBook/ZaK), which processes reservations on our behalf.
- Online travel agents you booked through (for example Booking.com, Expedia, Agoda), where the reservation originated with them.
- Payment providers and banks, to take and refund payments.
- Website, email and hosting providers that operate our site and store our records on our instructions.
- Thai government authorities, including immigration and the police, where the law requires us to report guest information.
- Professional advisers, insurers and, if ever necessary, courts, to establish or defend legal claims.
Some of these providers are outside Thailand. Where personal data is transferred abroad, we take steps to ensure an adequate level of protection as required by the PDPA [lawyer to confirm the mechanism used for each provider].
How long we keep it
- Reservation and stay records: [X] years after departure, in line with Thai accounting and tax requirements.
- Guest registration records required by immigration law: [X] years [confirm the statutory period].
- Enquiries that do not become bookings: [X] months.
- Newsletter subscriptions: until you unsubscribe, plus a short record that you did so.
- CCTV footage: [X] days, unless retained for an incident.
- Website analytics: [X] months, and only if you consented.
Your rights
Under the PDPA you may ask us to:
- Access your personal data and receive a copy of it.
- Correct data that is inaccurate, out of date or incomplete.
- Delete data where we no longer have a lawful reason to keep it.
- Restrict or object to certain uses of your data.
- Receive your data in a portable, machine-readable form, or have it sent to another controller where technically feasible.
- Withdraw consent at any time — for marketing emails or analytics cookies — without affecting the lawfulness of what we did before.
- Complain to the Personal Data Protection Committee (PDPC) in Thailand if you believe we have handled your data unlawfully.
Withdrawing consent will not affect a booking already in progress, because we still need your data to give you the stay you have paid for and to meet our legal obligations.
How to contact us about your data
- Data protection contact: [full name], [job title]
- Email: privacy@seahillsresort.com [confirm the real address]
- Telephone: [+66 …]
- Postal: Sea Hills Resort, [exact street address], Patong, Kathu, Phuket 83150, Thailand
- We aim to respond to any request within 30 days.
Security
We use access controls, encrypted connections and staff training to protect guest data, and we limit access to the people who need it to do their job. No system is perfect; if a breach affects your rights we will notify you and the PDPC as the PDPA requires.
Children
We welcome families, but we do not knowingly collect data directly from children. Bookings and the personal data attached to them should be provided by a parent or guardian.
Changes to this policy
We will update this page when our practices change and revise the “last updated” date above. Significant changes affecting consent will be brought to your attention.