Legal Information
How Tivolin collects, uses, and protects your personal data
Last updated: 10 January 2025 | Effective: 10 January 2025
At Tivolin, we handle personal data with the same care and attention we bring to financial education. This policy explains exactly what information we collect, why we collect it, who we may share it with, and what rights you have over your own data.
We comply with Thailand's Personal Data Protection Act B.E. 2562 (PDPA). If you have questions at any point, reach us at privacy@thhappynode.
This Privacy Policy applies to all personal data collected by Tivolin ("we," "us," or "our"), a financial education provider operating at 9/4 Rat-U-Thit 200 Pee Road, Patong, Kathu, Phuket 83150, Thailand. Tivolin is the data controller responsible for your personal data.
This policy covers:
We do not knowingly collect data from individuals under the age of 18. Our educational programs are intended for adults aged 18 and above.
When you complete our contact form, enquire about a program, or communicate with us directly, we may collect:
If you enrol in a program, we may additionally collect information relevant to the educational content, such as your general financial situation, employment type, and household composition — only where you choose to share these voluntarily as part of the program sessions.
When you visit our website, certain technical data is collected automatically via cookies and analytics tools:
This data is used in aggregate form and is not linked to your identity unless you have also submitted a contact form.
We may receive limited data from advertising platforms such as Meta and Microsoft Bing if you click on one of our advertisements. This typically includes a click identifier used to measure whether our advertising resulted in a website visit or enquiry. We do not purchase contact lists or acquire personal data from data brokers.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Responding to enquiries and contact form submissions | Name, email, phone, message | Legitimate interests / pre-contract steps |
| Providing and delivering our educational programs | Name, email, program information | Performance of a contract |
| Sending program updates and relevant communications | Name, email | Consent (you may withdraw at any time) |
| Improving our website and understanding user behaviour | Analytics data (anonymised) | Consent (via cookie banner) / Legitimate interests |
| Measuring advertising campaign effectiveness | Ad click identifiers, anonymised visit data | Consent (via cookie banner) |
| Complying with legal obligations | Any data required by law | Legal obligation |
| Protecting against fraud and maintaining site security | Technical data, IP address | Legitimate interests |
We do not use your personal data for automated decision-making or profiling that produces legal or significant effects.
Under Thailand's PDPA, we rely on the following legal bases to process personal data:
Where we rely on legitimate interests, we have balanced these against your interests and rights and are satisfied that our legitimate interests do not override your fundamental rights and freedoms.
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Our standard retention periods are:
| Data Type | Retention Period | Reason |
|---|---|---|
| Enquiry form submissions (not converted) | 12 months from submission | To allow follow-up within a reasonable period |
| Participant records (enrolled programs) | 3 years from program completion | To provide references and follow-up support |
| Marketing consent records | Until consent is withdrawn, plus 3 years | Legal requirement to demonstrate consent |
| Website analytics data | 26 months (GA4 default) | Trend analysis and service improvement |
| Cookie consent logs | 13 months | Evidence of consent preferences |
When data reaches the end of its retention period, it is securely deleted or anonymised so it can no longer be linked to an individual.
We take the security of personal data seriously and implement appropriate technical and organisational measures to protect against unauthorised access, alteration, disclosure, or destruction. These include:
While we take every reasonable precaution, no method of electronic transmission or storage is 100% secure. In the unlikely event of a personal data breach that poses a risk to your rights, we will notify relevant authorities within 72 hours and inform affected individuals without undue delay, in line with PDPA requirements.
Under Thailand's PDPA, you have the following rights in relation to your personal data. To exercise any of these rights, contact us at privacy@thhappynode.
You may request a copy of the personal data we hold about you, along with information about how it is used and with whom it is shared.
If any of your personal data is inaccurate or incomplete, you may request that we correct or update it.
You may request deletion of your personal data where there is no longer a lawful reason for us to hold it, or where you have withdrawn consent and no other legal basis applies.
In certain circumstances, you may request that we restrict how we use your data while a query or objection is being resolved.
Where processing is based on consent or a contract, you may request a copy of your data in a structured, machine-readable format to transfer to another provider.
You may object to processing based on legitimate interests or direct marketing at any time. We will stop processing unless we can demonstrate compelling legitimate grounds.
Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
If you believe we have not handled your data correctly, you may lodge a complaint with the Personal Data Protection Committee (PDPC), the Thai supervisory authority for data protection matters.
We aim to respond to all data rights requests within 30 days. Complex or multiple requests may take up to 90 days, in which case we will notify you of the extension and reason.
Our website may contain links to external websites — for example, references to financial institutions, government resources, or educational bodies. We are not responsible for the privacy practices of those sites. We recommend reviewing the privacy policy of any third-party website you visit.
Our programs and website are directed at adults aged 18 and above. We do not knowingly collect personal data from individuals under 18. If you believe a minor has provided us with personal data, please contact us at privacy@thhappynode and we will delete that data promptly.
We may update this Privacy Policy periodically to reflect changes in our practices, services, or applicable law. When we make changes, we update the "Last updated" date at the top of this page. For significant changes, we will provide more prominent notice — such as a banner on our website or an email to participants — before the changes take effect.
We encourage you to review this page periodically. Continued use of our website or services after a policy update constitutes acknowledgement of the updated terms.
For all privacy-related questions, to exercise your data rights, or to report a concern, please reach us through any of the following channels. We aim to acknowledge your message within 5 business days.
Address
9/4 Rat-U-Thit 200 Pee Road
Patong, Kathu, Phuket 83150
Thailand
Privacy Email
privacy@thhappynode