Privacy Policy
How MICE Thailand collects, uses, stores, and protects your personal data. Compliant with Thailand’s Personal Data Protection Act (PDPA) B.E. 2562 and the EU General Data Protection Regulation (GDPR) where applicable.
About This Policy
MICE The Thai DMC Co., Ltd. (“MICE Thailand”, “we”, “us”, “our”) is committed to protecting your personal data and respecting your privacy rights. This Privacy Policy outlines how we collect, use, process, store, and protect personal information when you visit micethailand.net, contact us for a proposal, book an event with us, or attend an event we deliver.
We comply with Thailand’s Personal Data Protection Act (PDPA) B.E. 2562 (2019) and, where applicable, the EU General Data Protection Regulation (GDPR). If you are based outside Thailand, local data protection laws may also apply.
Who We Are & Contact Details
Company Information
Legal Name: MICE The Thai DMC Co., Ltd. | Trading As: MICE Thailand
Office Locations
#03-44 130, 132 Witthayu Rd, Lumphini, Pathum Wan, Bangkok 10330, Thailand
180 Moo 1, Cherngtalay, Thalang, Phuket 83110, Thailand
How to Contact Us
Email: connect@micethailand.net
Phone: +66 65 749 5221
Subject: For privacy matters, use subject line “Privacy Request”
What Personal Data We Collect
3.1 Enquiry & Proposal Data
When you submit an online form, call, email, or message us via WhatsApp or social media to enquire about our services, we collect:
- Full name, job title, and company name
- Work email address and phone number
- Event details: type, dates, estimated attendee count, destination(s), budget range, and specific requirements
- Message content and communication history
3.2 Booking & Event Delivery Data
When we deliver an event for your organisation, we process data on your behalf (you as data controller; we as processor):
- Delegate/Attendee Data: names, email addresses, phone numbers, job titles, company affiliations
- Travel & Accommodation: passport/ID details (for visas and transfers), airline preferences, hotel room preferences, check-in dates
- Health & Accessibility: dietary restrictions (vegetarian, vegan, halal, allergies), mobility or accessibility needs, medical alerts relevant to activities
- Financial: payment terms, invoicing contact, PO numbers, billing address
- Event Content: registration data, badge information, session preferences, survey responses
3.3 Website Usage & Analytics Data
When you visit micethailand.net, we automatically collect:
- IP address and approximate geographic location
- Device type, browser, operating system, and language settings
- Pages visited, time spent on each page, links clicked, and referring source
- Search queries and form interactions
3.4 Communication Records
We retain records of all email, phone, WhatsApp, Line, and messaging-app conversations with our team for service continuity, quality assurance, and dispute resolution.
How We Use Your Data
Legal Bases for Processing
Under PDPA and GDPR, we process your data only where we have a lawful basis:
- Contract: preparing proposals, making bookings, delivering events, and customer support
- Legal Obligation: tax records (7-year retention per Thai law), visa support, TCEB licensing, government requests
- Legitimate Interest: website analytics, service improvement, security, fraud prevention, and marketing communications
- Consent: optional communications beyond event delivery (newsletters, promotional materials)
Specific Uses
- Responding to Enquiries: preparing proposals, shortlisting venues, sourcing activities, generating quotations
- Booking & Contracting: confirming availability with venues, hotels, airlines, and providers
- Event Delivery: coordinating transfers, registrations, dietary arrangements, emergency support
- Visa & Travel Support: providing invitation letters, visa documentation, travel insurance coordination
- Payment & Invoicing: generating invoices, processing payments, account reconciliation
- Service Improvement: analysing website usage to identify popular content and improve experience
- Marketing & Communications: sending event recaps, testimonial requests, case study invitations, service updates (opt-out available)
- Legal & Compliance: maintaining tax records, supporting TCEB applications, responding to regulatory enquiries
- Security & Risk: detecting fraud, preventing cyber attacks, protecting system and data security
We do not sell personal data to third parties. We do not use delegate or client data for unsolicited marketing or secondary purposes without your explicit consent.
Who We Share Your Data With
We share personal data only as necessary to deliver your event or meet legal obligations. Recipients include:
Service Providers & Third Parties
- Venues & Hotels: your name, contact details, room requirements, dietary needs, arrival/departure dates
- Airlines & Airports: delegate names, passport details (for manifests and immigration), baggage requests
- Transport Providers: attendee names, pick-up/drop-off locations, mobility requirements, contact numbers
- Activity & Experience Providers: delegate names, group size, dietary/accessibility needs, language preferences
- Event Technology Platforms: registration systems, badge printing, virtual platforms, mobile apps (names, email, session preferences)
- Insurance Providers: event details, delegate count, activity types (for liability and cancellation insurance)
- Government Authorities: visa documentation, event permits, TCEB applications, tax records (as legally required)
- Professional Advisers: accountants, auditors, and legal counsel under confidentiality obligations
- IT Service Providers: website hosting, email systems, CRM software, payment gateways, cloud backup services
All third parties are contractually obligated to handle your data securely and only for specified purposes. Where data transfers outside Thailand, we ensure appropriate safeguards consistent with PDPA and GDPR requirements.
How Long We Retain Your Data
| Data Type | Retention Period | Reason |
|---|---|---|
| Enquiry Data (No Booking) | 24 months | Follow-up opportunities; then deleted or anonymised |
| Client & Event Records | 7 years | Thai accounting, tax, and business law requirements |
| Delegate Data (Event Complete) | 90 days | Returned or deleted unless extended with consent (e.g. surveys) |
| Website Analytics | 12-14 months | Aggregated/anonymised after 12 months; individual-level deleted at 14 months |
| Communication Records | 3 years | Service continuity and dispute resolution |
| Legal Holds | As Required | Retained for legal disputes or regulatory enquiries |
Cookies & Tracking Technologies
Types of Cookies We Use
- Essential Cookies: required for site functionality (login, form submission, session management). Cannot be disabled.
- Performance Cookies: collect data on how you use the site (pages visited, time spent, clicks). Helps us understand behavior and improve content. Powered by Google Analytics.
- Preference Cookies: remember your choices (language, theme, saved filters) for a better experience.
No Advertising or Cross-Site Tracking: We do not use advertising cookies, retargeting pixels, or third-party tracking for behavioral advertising.
Your Cookie Control
You can control cookies through your browser settings. Most browsers allow you to refuse cookies or alert you when sent. Blocking essential cookies may affect site functionality. To manage cookies, visit your browser settings or use allaboutcookies.org.
Your Data Protection Rights
Under Thailand’s PDPA and the GDPR (where applicable), you have the following rights:
Your Rights at a Glance
- Right of Access: request a copy of all personal data we hold about you
- Right to Rectification: correct or update inaccurate or incomplete data
- Right to Erasure: request deletion where we have no legal obligation to retain it
- Right to Restrict Processing: limit use of your data during disputes or accuracy contests
- Right to Object: object to processing based on legitimate interest, including marketing
- Right to Data Portability: receive your data in a structured, machine-readable format (CSV, JSON)
- Right to Withdraw Consent: withdraw consent for optional processing at any time
How to Exercise Your Rights
Email connect@micethailand.net with subject “Privacy Request” and specify which right you wish to exercise. Include your name, email, and any relevant event details. We will respond within 30 days. If we cannot fulfill your request, we will explain why in writing.
Right to Lodge a Complaint
If you believe your rights have been violated, you have the right to lodge a complaint with:
- Thailand’s Personal Data Protection Committee (PDPC): pdpc.go.th
- Your local data protection authority (if you are based in the EU or another jurisdiction with a supervisory authority)
How We Protect Your Data
We implement comprehensive security measures to protect your personal data:
Security Measures
- Encryption: all data transmitted over the internet is encrypted using TLS; sensitive data at rest is encrypted
- Access Controls: personal data is accessible only to staff and contractors who need it; access is role-based and logged
- Authentication: staff use strong passwords and multi-factor authentication to access sensitive systems
- Device Security: laptops and mobile devices are password-protected, kept up-to-date with security patches, and monitored
- Confidentiality: all employees and contractors sign confidentiality agreements and receive data protection training
- Secure Disposal: data no longer needed is securely deleted (overwritten or shredded) rather than discarded
- Incident Response: we have a documented incident response plan. If a breach occurs risking your rights, we notify you and relevant authorities within required timeframes
Security Limits: No system is 100% secure. We cannot guarantee absolute security, but we maintain industry-standard protections and respond promptly to suspected breaches.
Additional Information
Third-Party Links & External Services
micethailand.net contains links to external websites (partner venues, tourism boards, social media). We are not responsible for their privacy practices. Review their policies before submitting data.
Children & Minors
Our services are intended for adult business professionals. We do not knowingly collect data from individuals under 18. If you believe we have, contact us immediately at connect@micethailand.net.
Data Processor Relationships
For events we deliver, we act as data processor on behalf of your organisation (data controller). We maintain Data Processing Agreements (DPA) outlining:
- Types and purposes of personal data processed
- Our confidentiality and security obligations
- Your rights to audit and request deletion
- Our commitment to comply with PDPA and GDPR
Request our standard DPA template by emailing connect@micethailand.net.
Policy Updates & Changes
We may update this policy to reflect service, technology, or legal changes. The current version is always at micethailand.net/privacy-policy/ with the revision date at the top. Material changes will be flagged here, and we will notify you via email at least 14 days in advance.