For ABAC Nursing Native Open House · effective from publication · privacy-policy-v1.4
This notice explains how Assumption University collects, uses, discloses and protects the personal data of people who register for and attend the event, under Thailand’s Personal Data Protection Act B.E. 2562 (PDPA). Please read it before you register and before you attend.
Assumption University, through the Bernadette de Lourdes School of Nursing Science, which hosts the event and administers registration.
Address: Martin de Tours Hall (M Building), 2nd Floor, 592/3 Soi Ramkhamhaeng 24, Hua Mak, Bang Kapi, Bangkok 10240
Data Protection Officer (DPO): School of Nursing Science, Assumption University — abacnurse@au.edu, (+66) 2783 2222 ext. 3505
We use data only for the purposes below. Before using it for any other purpose we will tell you and, where required, ask for consent (section 21).
| Purpose | Lawful basis (PDPA) |
|---|---|
| Registration, bookings, check-in, issuing and verifying certificates, contacting you about attending | Necessary to provide what you asked for (s. 24(3)) |
| Internal analysis to plan student admissions and improve programmes and the event, presented as aggregate statistics | The university’s legitimate interests (s. 24(5)); you may object under s. 32 |
| Recording general photographs, video and audio of the event for reporting and the university archive | Legitimate interests (s. 24(5)) and archival purposes (s. 24(1)) |
| Using photographs, video or audio in which you are clearly identifiable in publicity and advertising | Consent (s. 19) — chosen at registration, changeable in your profile |
| Sending news about programmes and future events | Consent (s. 19) |
| Catering and assistance based on the dietary and accessibility needs you give | Explicit consent (s. 26) |
| System security, fraud prevention and system logs | Legitimate interests (s. 24(5)) and legal obligation (s. 24(6)), including the Computer Crime Act |
| Analytics cookies | Consent (s. 19) — off by default |
This system runs on cloud services, so your data is stored or processed on servers outside Thailand — in Singapore, Japan, the United States and Germany, as the table shows. Transfers follow sections 28 and 29 and the related notifications of the Personal Data Protection Committee: each provider is bound by a data processing agreement with appropriate safeguards, data is encrypted in transit and at rest, and access is restricted.
| Provider | Used for | Data involved | Server location |
|---|---|---|---|
| Supabase (PostgreSQL on AWS) | Main database | All registration data (phone numbers field-encrypted) | Singapore (ap-southeast-1) |
| Cloudflare R2 | File storage | Certificates, event photographs and video | Asia-Pacific (APAC) — Cloudflare does not guarantee the city |
| Upstash Redis (on AWS) | Rate limiting and seat locks | Hashed IP addresses, temporary user ids | Singapore (ap-southeast-1) |
| Resend | Email delivery | Email, name, one-time passcodes | Sent from Tokyo, Japan (ap-northeast-1); account data and delivery logs stored in the United States |
| Sentry | Error monitoring (when enabled) | Technical data with personal data removed | Frankfurt, Germany (EU) |
| Vercel | Serving the website, processing requests and deriving approximate location from IP addresses | Data passing through the website, IP addresses | Processed in Singapore (sin1); pages delivered through Vercel’s global network |
| Data | Retention |
|---|---|
| Name, email, phone, profile photo and the details you gave | Deleted automatically 12 months after the event; only the registration code and check-ins remain, as statistics no longer linked to a name or contact details |
| Dietary and accessibility needs | Deleted automatically 30 days after the event, or at once if you withdraw consent |
| Issued certificates (with the recipient name as printed on them) | Kept beyond 12 months so that you, and anyone you show a certificate to (a school, for example), can verify it — until you ask for erasure; after that it can no longer be verified |
| Website usage logs (analytics cookie) | 180 days |
| Security and audit logs | At least 90 days under the Computer Crime Act, and as long as audit requires |
| IP address, approximate location and device in the audit and usage logs | 180 days, then deleted automatically; audit entries remain without them. Deleted at once if your data is erased on request |
| Records of consent given or withdrawn, and of deletion requests | As long as needed to demonstrate compliance, including after erasure, with no name, email or phone number |
| Event photographs, video and audio | Kept in the university archive; publicity use ends when you withdraw consent |
Registrants under 20 are minors under section 19 of the Civil and Commercial Code and must give the name and phone number of a parent or guardian who is aware of and consents to the registration, as PDPA section 20 requires. A guardian may exercise the rights in section 9 on the minor’s behalf. To inform guardians as section 25 requires, a minor receives a link to the “notice for parents and guardians” (the /guardian-notice page) on screen and in the confirmation email, to forward by LINE or SMS.
TLS in transit, encryption at rest, and field-level encryption for values such as phone numbers; row-level security in the database; an append-only record of every consequential access; automatic sign-out when idle. If a breach occurs we notify the PDPC Office within 72 hours of becoming aware of it, and notify you without delay if it poses a high risk to your rights (s. 37).
We may update this notice. The version in force is shown at the top, and each consent records the version you gave it under. For a material change we will tell you and ask for consent again where required.