A hotel in Phuket, a villa on Koh Samui or a beach bar in Krabi that offers internet access is a venue the Computer Crime Act has an opinion about. The duty is short to state and easy to get wrong, and Thailand’s PDPA adds the consent rules on top. Set the property to Thailand during setup and the platform follows both.
Any venue offering internet access keeps traffic records for at least ninety days, and an official can order a longer period. The record has to say who was connected and when. A log with the wrong time on it is not a log, which is why the platform and the equipment keep their clocks in step.
Thailand’s Personal Data Protection Act treats a guest’s name, email and device record as personal data. Marketing needs its own consent, given separately from getting online, and a guest can ask what is held and ask for it to go.
The marketing box is separate, un-ticked and per channel. A guest who says no is online at the same speed. Every yes is kept with the wording the guest saw, the page it was on, and when.
This page describes how the product behaves. It is not legal advice, and your own counsel decides what your property must do.
Identifiable session logs kept for ninety days by default, with a longer period available for a property that has been ordered to keep one. Synchronised clocks, so every record carries the right time. Marketing consent as its own tick, recorded with the exact wording. Erasure that deletes the personal data and keeps the logs the Act requires without the identifying details.
The data is held in a single hosting region serving every country today, with the cross-border safeguards in the processing agreement. If the data has to sit in Thailand, say so before signing up. Where the data is →
Retention · ninety days, extendable
Clocks · synchronised, so the time on a record is right
Consent · separate, un-ticked, per channel, recorded
Erasure · personal data deleted, required logs kept without identifying details
Export · a guest’s whole record, free on every plan
Phuket, Koh Samui, Koh Phangan and Krabi are where the guest Wi-Fi gets used hardest and where the internet line is most often shared or metered, so the same setup that keeps the logs also sets the per-guest limits that keep the line usable. Thailand is one of the two markets where most of our installations are, and the ninety-day pack exists because the first properties needed it. Guest Wi-Fi for hotels and resorts → · How much Wi-Fi a resort needs →
At least ninety days of traffic records, under the Computer Crime Act, and longer if an official orders it. The records have to carry the right time, so the clocks on the equipment and the platform are kept in step. Set the property to Thailand and ninety days becomes the default, with a longer period available.
Yes. A name, an email address and a device record are personal data, and marketing needs its own consent, separate from network access. The platform keeps the two apart and records every consent with the wording the guest saw.
Their access is cancelled, their personal data deleted, and identifying details stripped from the records the Computer Crime Act requires the property to keep. Every connected system is told to do the same. A guest can also be given a copy of their whole record, free on every plan.
In a single hosting region serving every country today, with the cross-border safeguards described in the processing agreement. Every property’s data is encrypted with its own key. If data residency in Thailand is a hard requirement, say so before signing up.
No. It describes how the product behaves once a property is set to Thailand. Your own counsel decides what your property must do.