1. Introduction
Pensora ("we", "our", "us") operates as a pension education and information resource based at 305 Silom Road, Suriyawong, Bangkok 10500, Thailand. We provide group workshops, document organisation tools, and HR communication advisory services — all educational and informational in nature.
This Privacy Policy applies to personal data collected through our website at pensoras.club, our contact forms, and our direct service engagements. By using our website or getting in touch with us, you acknowledge that you have read and understood this policy.
If you have any questions about how we handle your data, please reach out to us at [email protected] before proceeding.
2. Personal Data We Collect
We only collect personal data that is reasonably necessary to respond to your enquiries and deliver our services. The categories of data we may collect include:
- Contact details: Full name, email address, and phone number when submitted through our contact form or provided directly by email.
- Organisation details (B2B only): Company name, HR contact name, and company size for enquiries about our HR Communication Advisory service.
- Workshop participation records: Attendance records for group sessions, including the name and contact details provided at registration.
- Website usage data: Browser type, referring page, pages visited, session duration, and approximate location (country/city level), collected via analytics tools.
- Cookie data: Functional and analytical cookies as described in our Cookie Policy.
We do not collect sensitive personal data such as financial account numbers, identification documents, or health information. We do not knowingly collect data from individuals under the age of 18.
3. How We Collect Data
We collect personal data through the following means:
- Contact form submissions on our website — name, email, and message content.
- Direct email or phone enquiries — where you choose to contact us directly.
- Workshop registration — details provided when booking a place on a session.
- Cookies and analytics — passive collection of browsing behaviour data when you visit our site. You may adjust your preferences via our cookie banner.
4. Legal Basis for Processing
Under Thailand's Personal Data Protection Act B.E. 2562 (PDPA), we rely on the following lawful bases when processing your personal data:
- Consent: When you submit our contact form or opt in to receive communications from us. You may withdraw consent at any time.
- Legitimate interests: For internal analytics and website improvement, where such interests are not overridden by your rights.
- Contractual necessity: When data is needed to fulfil a booked service, such as confirming your place on a workshop.
- Legal compliance: Where we are required to retain records under applicable Thai law.
5. How We Use Your Data
We use the personal data we collect for the following purposes:
- Responding to enquiries and service requests submitted through our contact form or by other means.
- Confirming bookings and sending service-related correspondence (e.g. workshop schedules, toolkit delivery instructions).
- Sending follow-up messages where you have consented to receive them. You may unsubscribe at any time by replying to any such message.
- Improving our website through aggregated, anonymised analytics data.
- Complying with our legal obligations under Thai law.
We do not use your data for automated decision-making or profiling. We do not sell, rent, or trade your personal data with third parties for marketing purposes.
6. Data Sharing with Third Parties
We share personal data only where necessary and under appropriate safeguards:
- Website analytics provider: We use an analytics service (such as Google Analytics) to understand how visitors use our site. This service may process your IP address and browsing data. Data is processed under the provider's own terms and privacy policies.
- Email service provider: We use a third-party provider to manage and deliver email correspondence. Only your name and email address are shared for this purpose.
- Legal obligations: We may disclose personal data to Thai regulatory authorities or law enforcement agencies where required to do so by law.
All third-party processors we work with are required to maintain appropriate security measures and may only use your data for the purposes we specify.
7. Data Retention
We retain personal data only for as long as it is needed:
- Contact form enquiries: Up to 12 months from the date of your last interaction with us, unless a service relationship is ongoing.
- Workshop attendance records: Up to 3 years for administrative and record-keeping purposes.
- Financial and billing records (B2B): Up to 7 years to comply with Thai accounting and tax regulations.
- Website analytics data: Retained in aggregated or anonymised form after 26 months.
Once data is no longer required, it is securely deleted or anonymised.
8. How We Protect Your Data
We take reasonable technical and organisational steps to keep your personal data secure:
- Our website is served over HTTPS with TLS encryption to protect data in transit.
- Access to stored personal data is restricted to staff members who require it to carry out their duties.
- We use reputable third-party hosting and email services that maintain their own security certifications and controls.
- In the event of a data breach that is likely to affect your rights and interests, we will notify the relevant supervisory authority and, where required, affected individuals within the timeframes set out under Thai PDPA regulations.
While we take these steps carefully, no system of data transmission over the internet can be entirely risk-free. We encourage you to use a secure connection when contacting us.
9. Cookies
Our website uses cookies — small text files stored on your device — to support basic site functionality and to understand how visitors navigate our pages. The types of cookies we use include:
- Strictly necessary cookies: Required for the website to function. These cannot be disabled.
- Analytical cookies: Used to gather anonymised data on page visits and session duration. These are only activated with your consent.
You can manage your cookie preferences through the banner displayed on your first visit to our site, or by adjusting your browser settings at any time. For full details, please read our Cookie Policy.
10. Your Rights Under Thai PDPA
Thailand's Personal Data Protection Act gives you a number of rights over your personal data. You may contact us at any time to exercise any of the following:
- Right to access: Request a copy of the personal data we hold about you.
- Right to rectification: Ask us to correct inaccurate or incomplete data.
- Right to erasure: Request that we delete your personal data, subject to any legal obligations we have to retain it.
- Right to restrict processing: Ask us to pause the use of your data in certain circumstances.
- Right to data portability: Receive your data in a structured, commonly used format where technically feasible.
- Right to object: Object to our processing of your data where we rely on legitimate interests as the lawful basis.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, please write to us at [email protected]. We will aim to respond within 30 days. We may need to verify your identity before acting on a request.
If you believe we have not handled your data correctly, you have the right to raise a concern with the Personal Data Protection Committee (PDPC) of Thailand, the relevant supervisory authority.
11. External Links
Our website may contain links to external websites — for example, links to official Thai government resources or public pension scheme information pages. These sites are not operated by us, and we are not responsible for their content or privacy practices. We encourage you to read the privacy policy of any external site before sharing your personal data with it.
12. Age Restriction
Our services are intended for adults aged 18 and over. We do not knowingly collect or process personal data from individuals under the age of 18. If you believe a minor has submitted data through our website, please contact us at [email protected] so we can arrange its prompt deletion.
13. International Data Transfers
Your data is primarily stored and processed in Thailand. In some cases, third-party service providers (such as cloud hosting or analytics platforms) may process data on servers located outside Thailand. Where this occurs, we take steps to ensure that those providers offer an appropriate level of data protection consistent with Thai PDPA requirements, including through contractual clauses or equivalent safeguards.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, service offerings, or applicable regulations. Any updates will be published on this page with a revised "Last updated" date at the top. Where changes are significant, we may also notify you by email if you have an active correspondence with us.
We encourage you to review this page periodically to stay informed about how we handle your information.
15. Contact Information
If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle personal data, please contact our data point of contact:
We will aim to acknowledge your enquiry within 5 working days and provide a full response within 30 days.