Privacy notice
Last updated 2026-07-19
This notice explains what personal data we collect, why, how long we keep it, and what rights you have. It is written to meet both Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) and the UK GDPR, because we are a UK company offering services to people in Thailand and both apply.
Who is responsible for your data
The data controller is SiamRise Ltd, a company registered in England and Wales under company number , with its registered office at London, United Kingdom. You can reach us about anything on this page at privacy@siamrise.com.
What we collect, and why
We only collect what we need to answer you and to run the business. Specifically:
- Enquiry details: your name, the name you would like us to use, your business name, email address, LINE ID, the type of venue you run, what you are looking for, your rough budget, and your message. We use these to reply to your enquiry and to prepare a proposal if you want one.
- Marketing list: if, and only if, you separately tick the optional box, your name and email address, so we can send occasional practical articles. This is never bundled with your enquiry.
- Technical data: your IP address and browser information, held briefly in server logs for security and to diagnose faults. If you accept analytics cookies, we also collect anonymous usage statistics; if you do not, we collect none.
Whether you have to provide it
You are not required by law or by contract to give us anything. But if you do not give us a name and a way to reply, we cannot answer your enquiry. That is the only consequence. Every other field on the form is optional and marked as such.
Our lawful basis
For answering your enquiry, we rely on legitimate interests and on taking steps at your request before entering a contract. You have asked us to get in touch, so consent would be the wrong basis and we do not ask you to tick a box for it. Our legitimate interest is in responding to people who contact us about our services; we have assessed that this does not override your rights, and you can object at any time. For marketing emails and for non-essential cookies, we rely on your consent, which you can withdraw as easily as you gave it.
How long we keep it
Enquiries are deleted 24 months after we receive them, automatically. If you become a client, we keep contract and billing records for as long as UK company and tax law requires, currently six years. Marketing list entries are kept until you unsubscribe. Server logs are kept for 30 days.
Who else sees it
We do not sell your data and we never will. We share it only with the suppliers who help us operate, each under a written data processing agreement:
- our hosting provider, which stores the site and its database
- our email provider, which delivers our messages
- our analytics provider, but only if you accepted analytics cookies
We will also disclose data where the law requires it.
Sending data outside Thailand
Your personal data is transferred to and stored in the United Kingdom. Thailand’s Personal Data Protection Committee has not designated the UK as having adequate data protection standards. We rely on appropriate safeguards under PDPA s.29: your rights under this notice are enforceable against us directly, and against our designated representative in Thailand.
Your rights
Under the PDPA and the UK GDPR you have the right to:
- be informed about how your data is used, which is what this notice is for
- access your data and receive a copy of it
- receive your data in a portable form, or have it sent to another controller
- have inaccurate data corrected
- have your data erased
- restrict how we process your data
- object to processing, including objecting to direct marketing at any time
- withdraw consent at any time, where we relied on consent
- complain to a regulator
To exercise any of these, email privacy@siamrise.com. We will acknowledge within 30 days and will not charge you.
If you are unhappy
Please tell us first at privacy@siamrise.com. We would rather fix it. You can also complain to Thailand’s Personal Data Protection Committee (pdpc.or.th) or, in the UK, to the Information Commissioner’s Office (ico.org.uk). You do not have to come to us first.
How we protect it
The site is served over HTTPS only. Access to enquiry data is limited to the people who need it, protected by multi-factor authentication. We keep backups, and we test that we can restore them. If a breach occurs that risks your rights, we will notify the Personal Data Protection Committee within 72 hours and tell you where the law requires it.
Changes to this notice
If we change anything material, we will update the date at the top and, where the change affects consent you have given, ask you again. The current version is 2026-07-19.1.