Privacy Notice Overview
This Privacy Notice explains how techlawai collects, processes, and stores personal data in connection with training offerings, case workshops, and communications. We describe the types of information received, the purposes for processing, legal bases relied upon, and the rights available to individuals. Practical examples and scenarios in this text illustrate typical data flows — for instance, registration details collected to manage cohorts, or anonymized case notes used for learning materials. We aim for clarity about choices and retention rather than broad claims about outcomes.
Key Definitions
To make the policy actionable, we define terms used throughout. These explanations are accompanied by short scenarios showing how the term matters in practice — for example, how 'processing' occurs when a registration form is saved to our secure platform.
What Data We Collect
Data collection is limited to what is necessary for the services. We present typical collection instances with concrete examples: registration for an intensive, submission of a company case study, or newsletter sign-up.
Data You Provide Directly
These are items users submit when they interact with our services. Scenarios show why the data is needed and how it is used operationally.
- Full name and job title — used to create participant lists and tailor scenarios to executive roles.
- Corporate email and organization name — used for billing, cohort grouping, and verification of professional status.
- Phone number — used only for program logistics and urgent event updates.
- Case materials and anonymized company data submitted for workshops — used to build practical exercises and shared only with consent or in anonymized form.
- Payment and billing details — handled by our payment processor and retained to manage receipts and refunds.
- Feedback and survey responses — used to improve materials and inform future scenarios; shared internally with trainers.
Data Collected Automatically
Some information is collected automatically when you use our website or interact with emails. We provide examples of what is collected and why, and how it informs site stability and program design.
- IP address and device type — used for basic security and to ensure site compatibility across devices.
- Browsing behavior on techlawai.pro — aggregated to improve navigation and prioritize resources that directors use most.
- Cookie identifiers and session vouchers — support login persistence and basic preferences during a booking.
- Referrer and clickstream data — used to understand how visitors find our pages and which case studies attract engagement.
- Email open and click metrics for program announcements — used to improve timing and relevance of communications.
- Crash reports or performance logs — used by technical staff to resolve issues and maintain a reliable service.
Data from Third Parties
In some cases, we receive data from trusted third parties. We document examples and limits on use, and we describe how those data link into practical program delivery.
- Payment processors providing transaction confirmations and billing records for enrollment management.
- Corporate referees or partner organizations that nominate participants for cohort spots; used only to verify eligibility.
- Authorized learning platforms that host course content and provide anonymized usage statistics to improve curriculum.
Purposes of Processing
We process personal data for a limited set of operational purposes. Each purpose is illustrated with a short scenario so a director can see how their data is used in practice.
- Program administration: managing registrations, attendance, and logistics for workshops.
- Communication: sending confirmations, schedules, and relevant program updates.
- Curriculum improvement: analyzing anonymized feedback to refine case studies and scenarios.
- Billing and accounting: processing payments, issuing invoices, and maintaining receipts.
- Security and fraud prevention: detecting and responding to suspicious activity to protect participants.
- Legal compliance: retaining records and cooperating with lawful requests from authorities.
- Research and development: using aggregated insights to develop new modules without identifying individuals.
- Alumni engagement: informing past participants about follow-on clinics and events where they opted in to receive updates.
Legal Bases for Processing
We rely on appropriate legal bases depending on the context. Below are typical bases with concrete examples so leaders understand the rationale.
- Contract performance — to fulfill the terms of enrollment and deliver training services.
- Legitimate interests — for operational needs such as security, fraud prevention, and internal analytics, balanced against individual rights.
- Consent — for optional uses like marketing communications and sharing case anecdotes beyond anonymized learning materials.
- Legal obligation — to retain business records or respond to lawful requests by authorities.
Rights Under GDPR-Like Frameworks
Where applicable, individuals have rights to access, correct, restrict, or object to processing. We include practical steps for submitting requests and examples of what to expect during resolution.
- Right to access — request a copy of personal data we hold related to your program participation.
- Right to rectification — ask us to correct inaccurate or incomplete data used in cohort administration.
- Right to erasure — request removal of personal data where processing is not otherwise required for legal or contractual reasons.
- Right to restriction — request temporary limits on processing while a dispute or accuracy review is resolved.
- Right to data portability — where technically feasible, request your data in a structured, machine-readable format.
- Right to object — object to certain processing based on legitimate interests, subject to review and potential operational constraints.
Sharing and Disclosure
We share personal data only when necessary and with safeguards. This section lists common sharing scenarios and protective steps we take.
- With service providers: payment processors, learning platform hosts, and email services under contracts limiting use to our instructions.
- With professional advisers: auditors or legal counsel when required for compliance or dispute resolution.
- With partners: when a partner co-hosts an event and participants have consented to joint administration.
- In aggregated form: anonymized summaries of participant outcomes used to illustrate program impact without identifying individuals.
- For legal reasons: to comply with lawful requests by authorities or to protect rights and safety.
- With explicit consent: when participants agree to share case materials or testimonials for publication.
International Data Transfers
techlawai may transfer data to service providers located outside Thailand for hosting, analytics, or payment processing. Transfers are governed by contractual safeguards and appropriate technical and organizational measures to protect data.
Typical safeguards include data processing agreements, standard contractual clauses where applicable, and selection of providers with strong security practices. We document a specific case: using an international learning platform that stores anonymized usage data in a secure European host under a data processing agreement.
Data Retention
Retention periods are purpose-driven. Operational data needed to manage programs is retained for a defined period; aggregated learning materials are retained longer if anonymized.
Participant account information and billing records are typically retained for up to seven years for accounting and compliance, while anonymized case libraries are retained indefinitely to support future program design. If you request deletion, we will remove personal identifiers unless retention is required by law or a legitimate operational need.
We retain direct messages, coaching notes and workshop attendance logs for a limited period to support case studies, follow-up coaching and quality review. Typical retention periods are 2 years for routine workshop notes and up to 5 years for documented agreements tied to paid services. Example: a director who completed a six-month cohort will have coaching summaries stored for the cohort duration plus 18 months for outcome analysis and compliance needs.
System logs and access records are kept to support security contribute and service continuity. Logs used in operational incident reviews are anonymized where possible and retained for up to 12 months. In practical scenarios, log retention enabled us to trace an account access issue back to a misconfigured third-party integration and provide a factual report to the affected executive client.
When you request deletion of personal data, we follow a documented workflow: verification, removal from active systems, and scheduling of backups for eventual overwrite. Example case: after a participant requested removal, we removed direct personal identifiers from coaching files within 14 days and scheduled archival deletion in accordance with retention rules. Deleted data may persist in backups for operational reasons up to the retention window, then be purged.
Data security and practical safeguards
Security measures combine administrative controls, technical protections and operational practices tailored for executive clients. We design scenarios where sensitive workshop materials are compartmentalized: for instance, board-level case studies are stored with restricted access and two-person approval for exports. Security choices reflect risk assessments conducted before onboarding directors or business clients.
- Access controls with role-based permissions and multi-factor authentication for administrative and trainer accounts.
- Encrypted storage for personal data and encrypted channels for data in transit; periodic key rotation and audit trails for exports.
- Operational policies such as least-privilege access, scheduled security reviews, and scenario-based incident response exercises modeled on real case studies.
Your rights over personal data
As a participant or client you have rights to access, correct, restrict or request deletion of personal data we hold. Below are practical steps and typical timelines illustrated with examples relevant to executives and business accounts.
- Right to access: request a copy of personal data and case notes collected during training and coaching.
- Right to rectification: request corrections to inaccurate workshop attendance records or profile details; for example, correcting a company title in a cohort roster.
- Right to erasure: request removal of personal identifiers from participant files where retention rules permit.
- Right to restrict processing: ask that your data be excluded from future research analyses or aggregated case studies.
- Right to data portability: request export of personal profile and participation records in a common machine-readable format.
- Right to objection: object to direct marketing communications or processing based on legitimate interests; we will review and respond with a case example if applicable.
- Right not to be subject to automated decisions: we do not rely on fully automated profiling to make final decisions affecting access to services for directors; manual review and context-based scenarios are applied.
- Right to lodge a complaint: you may escalate unresolved concerns to supervisory authorities; we document each complaint scenario and the corrective actions taken.
How to make a rights request
Submit a request describing the right you wish to exercise and include a copy of a government-issued ID or corporate authorization if you represent a business account. Typical supporting examples: signed company letter for a business director or an identity scan for individual account verification. Requests are logged and handled according to the process below.
We aim to respond to rights requests within 30 calendar days. Complex requests that require additional verification or coordination with third parties will include a status update and a completion estimate, illustrated by previous cases where extended verification was necessary.
Marketing communications
We may send occasional information about upcoming cohorts, executive retreats and case-study publications relevant to directors and business leaders. Marketing is tailored using consent and preference signals; examples include targeted invitations to scenario-based sessions for CEOs and sector-specific briefings for CFOs.
You can opt out of marketing at any time by using the unsubscribe link in emails or by contacting our data protection team. Example: a director unsubscribed mid-year and retained access to course materials while stopping promotional invites within 48 hours.
Children and minors
Our programs are designed for adults and business professionals. We do not target or knowingly collect data from children under 18. If we become aware of personal data from a minor, we will take steps to remove it. Scenario: an account created using a minor's email was reviewed and access restricted pending verification.
Links to third-party services
Our site and resources may link to partner tools and publications. These external services have their own privacy practices. In case studies we document how data flows between techlawai and partners, including what minimal data is shared for scheduling or invoicing and the contractual safeguards applied.
Changes to this policy
We review privacy practices periodically and may update this policy to reflect operational or legal changes. Major updates are communicated to registered participants and clients with examples of what changes mean in practice, such as an amended data retention schedule for archived cohort materials.
Contact and data protection officer
For questions about privacy or to exercise your rights, contact techlawai at: Lang Soon Rachakarn Road, Nai Mueang Sub District, Amphoe Mueang Khon Kaen District, Khon Kaen Province 40000, Thailand. Phone: +66920192975. Business ID: 8420518403370. For formal requests, include your name, role (if acting for a business) and a description of the records you seek; example requests and required documentation are accepted via phone or written contact.
- +66920192975
- [email protected]
- Lang Soon Rachakarn Road, Nai Mueang Sub District, Amphoe Mueang Khon Kaen District, Khon Kaen Province 40000, Thailand