Privacy Policy
Siam Property Management International Co., Ltd. is committed to protecting the personal data of our website users, customers, tenants, and property owners.
- Effective date:
- 1 May 2026
- Last updated:
- 17 July 2026
Siam Property Management International Co., Ltd. (hereinafter referred to as “Company”, “we”, “us”, or “our”), acting as the “Data Controller”, highly values the privacy of your personal data. This Privacy Policy is formulated in compliance with Thailand’s Personal Data Protection Act B.E. 2562 (PDPA) to explain how we collect, use, disclose, transfer, and protect your personal data, as well as your legal rights.
1. Personal Data We Collect
We will collect your personal data strictly to the extent necessary for lawful purposes. The categories include:
- Identity Data: Name, surname, passport copy (with visa page), ID card copy, house registration copy.
- Contact Data: Phone number, email address, current address, or mailing address.
- Financial Data: Credit card details (16-20 digits, CVV, expiry date), bank account details, and bank statements (past 3-6 months).
- Property Data (For Owners): Title deed copy or Condominium Ownership Certificate (Or.Chor. 2) copy.
- Technical Data: IP address, log files, browser type, time zone settings, and Cookies.
- Transaction Data: Booking details, payment history, and lease agreement details.
- Sensitive Data: Religion and Blood Type (only as they appear on identity documents such as ID cards or passports).
- Disclaimer regarding Sensitive Data: The Company has no intention or necessity to collect your sensitive data. You are requested to cross out or redact the religion and blood type information before submitting any documents. If you fail to do so, we will consider that you have explicitly consented to the Company retaining such documents solely as proof of identity, and such sensitive data will not be processed for any other purpose.
Minors: If you are under 20 years of age or have legal capacity restrictions, we may collect, use, or disclose your personal data. We may require consent from your parent or legal guardian, or as permitted by law. If we become aware that personal data has been collected from a minor without the required consent from a parent or guardian, we will delete that data from the Company's servers.
2. Sources of Personal Data
We may obtain your personal data through the following channels:
- Directly from you: When you register on our website (siampropertymanagement.com), fill out booking forms, make inquiries, or sign contracts.
- From Third Parties or Business Partners: Through Online Travel Agency (OTA) platforms including Agoda, Airbnb, Booking.com, Trip.com, Rednote, and Vrbo, as well as Payment Gateways including Stripe, Omise, and 2C2P.
3. Purposes and Lawful Basis for Processing
We collect, use, and disclose your personal data based on the following legal grounds:
Contract Basis
- To process bookings, draft lease agreements, and manage your stay.
- To process rental payments, service fees, and security deposits.
- To provide after-sales service, mediate disputes, and assess property damages.
Legal Obligation
- To prepare accounting records, issue tax invoices, and comply with tax laws.
- To report the residence of foreigners (TM.30) in accordance with the Immigration Act.
Legitimate Interest
- To maintain network and website security (e.g., maintaining Log files pursuant to the Computer Crime Act).
- To detect, prevent, and handle fraud or illegal activities.
- To analyze usage and improve the quality of our website and services.
Consent
- To send marketing communications, news, and promotional offers (only when explicit consent is provided).
4. Disclosure and Transfer of Personal Data
We will not disclose your data to third parties unless necessary to fulfill the stated purposes. Your data may be shared with:
- Contractual Parties: For contractual and legal compliance, the Company will provide only the passport and/or ID card copy of the tenant/guest to the Property Owner and the Condominium Juristic Person for the lease agreement annex and TM.30 reporting. The Company reserves the right strictly not to disclose the tenant's contact information, such as phone numbers or emails, to these parties.
- Third-Party Service Providers: Such as Payment Gateways (Stripe, Omise, 2C2P), Cloud Computing providers, and Data Analytics service providers.
- Government Authorities: Such as the Immigration Bureau, Revenue Department, or law enforcement agencies when legally requested.
Cross-Border Data Transfer: Your data may be transferred to or stored on servers located outside Thailand (e.g., Cloud systems or Payment Gateways). We will ensure that the destination country or the service provider maintains adequate data protection standards in accordance with the law.
5. Data Retention Period
- We will retain your personal data for a period of 10 years from the date our service ends, the lease agreement expires, or the last transaction occurs. This is for accounting and tax auditing purposes, and to serve as evidence in the event of legal disputes.
- Upon the expiration of this period, the Company will securely delete, destroy, or anonymize your personal data with appropriate security standards.
6. Data Subject Rights
Under the PDPA, you have the following rights regarding your personal data:
- Right to Access: Request access to and obtain a copy of your personal data.
- Right to Rectification: Request correction of inaccurate, incomplete, or outdated data.
- Right to Erasure: Request the deletion, destruction, or anonymization of your data (unless legal retention obligations apply).
- Right to Restriction of Processing: Request the suspension of the use of your data.
- Right to Data Portability: Request the transfer of your data to another Data Controller.
- Right to Object: Object to the processing of your personal data.
- Right to Withdraw Consent: Withdraw your consent at any time (this does not affect the lawfulness of processing based on consent before its withdrawal).
- Right to Lodge a Complaint: File a complaint with the Personal Data Protection Committee if you believe the Company has violated the PDPA.
7. Cookies and Tracking Technologies
Our website uses cookies to remember your preferences, enhance your user experience, and gather traffic statistics. You can manage or disable cookies through your browser settings.
8. Security Measures
The Company has implemented appropriate security measures (Administrative, Technical, and Physical safeguards) to prevent the unauthorized or unlawful loss, access, use, alteration, or disclosure of personal data.
Notification of Personal Data Breach: In the event of a personal data breach, we will notify the Office of the Personal Data Protection Committee without delay and within 72 hours of becoming aware of the breach, to the extent possible. If the breach poses a high risk of affecting your rights and freedoms, we will notify you of the breach along with remedial measures without delay through channels such as our website, SMS, email, telephone, letter, etc.
9. Changes to the Privacy Policy
We may review and update this policy periodically to reflect changes in our business practices and legal requirements. Significant changes will be communicated through our website.
10. Contact Information
If you have any questions about this policy or wish to exercise your data subject rights, please contact:
Data Controller: Siam Property Management International Co., Ltd. (Tax ID: 0105569054200)
Address: 39 Soi Ramkhamhaeng 46 (Thai Land Fund), Hua Mak, Bang Kapi, Bangkok 10240, Thailand