Privacy Policy

How DeeMED Consulting collects, uses, and protects your personal data under Thailand's Personal Data Protection Act (PDPA, B.E. 2562 / 2019).

Overview

This Privacy Policy describes how DeeMED Consulting Co., Ltd. (referred to as "we," "our," or "the Company") handles personal data collected through this website and through our consulting intake process. It is issued in compliance with the Personal Data Protection Act, B.E. 2562 (2019) (the "PDPA"), which entered full enforcement on June 1, B.E. 2565 (2022) and applies to the collection, use, disclosure, and transfer of personal data relating to individuals in Thailand.

This Policy applies to visitors to this website, prospective clients who make inquiries, and contacts who communicate with us for consulting purposes. It does not apply to the personal data of our employees or contractors, which is governed by separate internal policies.

Last updated: July 23, B.E. 2569 (2026).

Data Controller

DeeMED Consulting Co., Ltd. is the data controller for personal data collected through this website and through pre-engagement communications. As data controller, we determine the purposes for which and the means by which your personal data is processed, and we are responsible for ensuring that processing complies with the PDPA.

Our principal place of business is in Bangkok, Thailand. For privacy inquiries or to exercise your rights under the PDPA, please contact us via WhatsApp or email. We will respond to data subject requests within 30 days of receipt, in accordance with the PDPA.

Personal Data We Collect

We collect personal data only to the extent necessary to respond to inquiries, provide consulting services, and operate this website. The categories of personal data we may collect include:

  • Identity data: your name and job title or role.
  • Contact data: your business email address, telephone or WhatsApp number, and country of operation.
  • Business data: your company name, product type, regulatory history, and market-entry objectives, provided voluntarily during an inquiry or consultation.
  • Technical data: your IP address, browser type and version, time zone, operating system, and pages visited, collected automatically when you use this website.
  • Communication data: the content of messages you send us via WhatsApp, email, or our scheduling tool.

We do not intentionally collect sensitive personal data as defined under PDPA Section 26 (including health data, racial or ethnic origin, political opinions, religious beliefs, or biometric data) through this website. If sensitive data is incidentally disclosed to us during a consulting engagement, it is processed only with your explicit consent and only to the extent necessary to perform the service you have requested.

We do not collect personal data from individuals under the age of 18 through this website. Our services are directed at business professionals and organizations, not consumers.

Lawful Basis for Processing

Under PDPA Section 24, we process your personal data on one or more of the following lawful bases:

  • Contractual necessity (Section 24(3)): processing is necessary to take steps at your request prior to entering into a consulting agreement, or to perform a consulting agreement to which you or your organization is a party.
  • Legitimate interests (Section 24(5)): processing is necessary for our legitimate interests in operating and improving this website, responding to inquiries, managing our business relationships, and maintaining records, provided those interests are not overridden by your fundamental rights and freedoms.
  • Legal obligation (Section 24(2)): processing is necessary to comply with a legal obligation under Thai law, including obligations under the Revenue Code, Anti-Money Laundering Act, or other applicable legislation.
  • Consent (Section 19): where we rely on consent, for example for analytics cookies or optional communications, we will seek your explicit consent and you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

How We Use Your Data

We use personal data we collect for the following purposes, each consistent with the lawful basis identified above:

  • Responding to inquiries and requests submitted through this website or by direct communication.
  • Assessing your regulatory needs and preparing preliminary pathway assessments or engagement proposals.
  • Communicating with you about the scope, timeline, and progress of consulting services.
  • Issuing and managing consulting agreements, invoices, and payment records.
  • Complying with legal and regulatory obligations applicable to our business in Thailand.
  • Analyzing aggregate, anonymized website usage data to improve the content and functionality of this website.

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

Cookies and Tracking Technologies

This website uses cookies, which are small text files stored on your device by your browser. We use the following categories of cookies:

  • Strictly necessary cookies: required for the website to function and to remember your cookie preferences. These cannot be disabled without affecting core website functionality.
  • Analytics cookies: we use Google Analytics 4 to collect anonymized data about how visitors interact with this website, including pages visited, time on site, and referral source. These cookies are only placed after you accept our cookie consent notice. No personally identifiable information is transmitted to Google Analytics. Data collected is used solely to understand website performance and is not sold or disclosed to third parties for marketing purposes.

A cookie consent notice is displayed on your first visit to this website. Analytics cookies are only placed once you click Accept; strictly necessary cookies are placed regardless of preference, as they are required for the website to operate. You may also manage cookies through your browser settings at any time; disabling cookies may affect the functionality of certain features.

Data Sharing and Disclosure

We do not sell your personal data. We do not share personal data with third parties for their own marketing purposes. We may share personal data in the following circumstances:

  • Service providers: we engage third-party providers for website hosting, email delivery, scheduling (Calendly), and analytics (Google Analytics). These providers process personal data only on our documented instructions and are contractually required to maintain confidentiality and implement appropriate security measures consistent with the PDPA.
  • Regulatory authorities and Thai government agencies: where we are legally required to disclose personal data to a competent authority, court, or regulatory body under applicable Thai law, we will comply with that requirement. Where legally permissible, we will notify you of such a requirement before disclosure.
  • Professional advisors: our legal and accounting advisors may access personal data to the extent necessary to provide professional services to us, subject to professional confidentiality obligations.
  • Business transfers: if DeeMED Consulting undergoes a merger, acquisition, or transfer of business assets, personal data may be transferred to the successor entity, subject to equivalent privacy protections and notice to affected individuals.

International Data Transfers

DeeMED Consulting operates in Thailand and serves clients internationally. Some of our service providers, including cloud infrastructure, scheduling, and analytics platforms, are located or process data outside Thailand. Under PDPA Section 28, transfers of personal data to countries outside Thailand are permitted only where the destination country has been determined by the Personal Data Protection Committee (PDPC) to provide an adequate level of personal data protection, or where appropriate safeguards are in place, such as standard contractual clauses approved by the PDPC.

Where we transfer personal data internationally, we take steps to ensure that the transfer is conducted under one of the lawful mechanisms recognized by the PDPA and that your data receives a level of protection equivalent to the protections provided under Thai law.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable Thai law. Our general retention periods are as follows:

  • Inquiry data (no engagement entered into): up to 12 months from the date of the last communication, unless you request earlier deletion.
  • Client engagement records: for the duration of the engagement and for a period of 5 years following its conclusion, consistent with the applicable limitation period under the Civil and Commercial Code of Thailand (B.E. 2468 / 1925) and obligations under the Revenue Code.
  • Financial and accounting records: 5 years from the end of the tax year to which they relate, as required under the Revenue Code B.E. 2481 (1938) and the Accounting Act B.E. 2543 (2000).
  • Website analytics data: in aggregated, anonymized form with no defined retention limit; individual session data is retained by Google Analytics for no longer than 26 months.

When personal data is no longer needed, we securely delete or anonymize it so that it can no longer be associated with you.

Your Rights Under the PDPA

As a data subject under the PDPA, you have the following rights with respect to personal data we hold about you:

  • Right of access (Section 30): the right to request a copy of the personal data we hold about you and information about how it is processed.
  • Right to rectification (Section 34): the right to request that we correct any inaccurate, incomplete, or misleading personal data we hold about you.
  • Right to erasure (Section 33): the right to request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, where you have withdrawn consent and no other lawful basis applies, or where it has been unlawfully processed. This right is subject to legal retention obligations.
  • Right to data portability (Section 32): the right to receive personal data you provided to us in a structured, commonly used, and machine-readable format, where technically feasible and where processing is based on contract or consent.
  • Right to object (Section 35): the right to object to processing carried out on the basis of legitimate interests, including objection to direct marketing.
  • Right to restriction (Section 36): the right to request that we restrict processing of your personal data in defined circumstances, such as while a rectification request is being assessed.
  • Right to withdraw consent (Section 19): where processing is based on your consent, the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before withdrawal.

To exercise any of these rights, please contact us via WhatsApp or email. We will respond within 30 days. We may need to verify your identity before processing a request. There is no charge for making a request, although we reserve the right to charge a reasonable fee for requests that are manifestly unfounded or excessive in frequency.

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Personal Data Protection Committee (PDPC), the supervisory authority responsible for enforcement of the PDPA in Thailand.

Data Security

We implement technical and organizational measures appropriate to the nature of the personal data we process and the risk of a personal data breach. These measures include access controls limiting data access to personnel with a legitimate business need, encrypted transmission of data in transit, and secure storage practices for client records and correspondence.

In the event of a personal data breach that is likely to result in risk to the rights and freedoms of affected individuals, we will notify the PDPC within 72 hours of becoming aware of the breach, in accordance with PDPA Section 37(4). Where the breach is likely to result in high risk to the affected individuals, we will also notify those individuals without undue delay.

No transmission of data over the internet and no storage system is completely secure. We cannot guarantee absolute security, but we are committed to maintaining safeguards consistent with the requirements of the PDPA and with reasonable industry practice for a business of our type.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, in the requirements of Thai law, or in guidance issued by the PDPC. The "Last updated" date at the top of this Policy reflects the date of the most recent revision. Where changes are material, we will take reasonable steps to bring them to your attention, which may include a notice on this website or direct communication where we hold your contact details.

Continued use of this website or our services after a revised Policy has been published constitutes acceptance of the changes, subject to any additional consent required under the PDPA for material changes to the basis on which we process your data.

Contact

For privacy-related questions, to exercise your rights under the PDPA, or to raise a concern about how we handle your personal data, please reach us directly:

WhatsApp →  |  Email →

If you prefer to communicate by post, you may write to us at our registered office in Bangkok, Thailand. We will respond to all privacy requests in English within 30 days of receipt.

To file a complaint with the supervisory authority, contact the Office of the Personal Data Protection Committee (PDPC), which operates under the Ministry of Digital Economy and Society of Thailand.