Privacy Policy — Subata Villas
Effective Date: January 1, 2026
Subata Villas ("we", "our", "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, make a booking, or interact with us.
This policy is designed in accordance with the Thailand Personal Data Protection Act B.E. 2562 (PDPA) and, where applicable, other relevant data protection regulations.
1. Consent
By accessing our website, submitting your information, or engaging with our services, you consent to the collection, use, and disclosure of your personal data as described in this Privacy Policy.
Where required by law, we will obtain explicit consent before processing sensitive personal data.
2. Information We Collect
Personal Information
- Full name
- Email address
- Phone number and WhatsApp contact
- Nationality and residency status
Booking and Stay Information
- Check-in and check-out details
- Number of guests
- Special requests or preferences
Identity and Compliance Data
- Passport copies and identification details
- Arrival and departure information required for Thai immigration reporting (TM30)
Certain identification data, such as passport details, may be processed as required for legal compliance under Thai immigration regulations. This data is collected solely for this purpose and handled with the highest level of care.
Payment and Transaction Data
- Booking platform references (such as Airbnb confirmations)
- Records of additional charges (electricity, water, services)
Technical Data
- IP address
- Browser type and device information
- Website usage data for analytics and performance
3. Purpose of Processing
- To manage bookings and provide your stay experience
- To communicate with you before, during, and after your stay
- To comply with Thai legal and regulatory requirements, including TM30 reporting
- To arrange concierge services and third-party experiences at your request
- To improve our website and services
- To send relevant marketing updates where you have provided explicit consent. You may withdraw marketing consent at any time by contacting us at enquiry@subatavillas.com
4. Lawful Basis for Processing
- Contractual necessity
- Legal obligation
- Legitimate interest
- Consent
5. Data Sharing and Disclosure
We do not sell your personal data. We may share your data only with the following categories of recipients, and only to the extent necessary:
- Our property management and operations team
- Third-party service providers engaged at your request (such as transportation, tours, or catering)
- Thai government authorities where required by law (including immigration authorities for TM30 reporting)
- Cloud hosting and website infrastructure providers
- Booking platform operators (such as Airbnb) where your booking originates from their platform
- Website analytics providers used to improve site performance
All third-party providers are required to handle your data in compliance with applicable data protection laws.
6. Cross-Border Data Transfers
Your personal data may be processed or stored outside of Thailand by our cloud hosting or technology service providers. Where such transfers occur, we ensure appropriate safeguards are in place, including contractual protections equivalent to Standard Contractual Clauses, or we will obtain your explicit consent prior to the transfer where required under PDPA Chapter 7.
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, and in compliance with applicable legal obligations. Specifically:
- Booking records, identity documents, and guest information are retained for a minimum of 5 years in compliance with Thai tax, accounting, and legal obligations
- TM30 immigration data is retained for the period required by Thai immigration law
- Website analytics data is retained for up to 24 months
- Marketing communication records are retained until consent is withdrawn
After the applicable retention period, data is securely deleted or anonymised.
8. Your Rights
Under the Thailand PDPA, you have the following rights with respect to your personal data:
- Right of access — to request a copy of your personal data we hold
- Right to correction — to request correction of inaccurate or incomplete data
- Right to deletion — to request erasure of your data, subject to legal obligations
- Right to withdraw consent — at any time, without affecting the lawfulness of prior processing
- Right to object — to processing based on legitimate interest
- Right to data portability — to receive your data in a structured, commonly used format where technically feasible
- Right to restriction of processing — to request that we limit how we use your data in certain circumstances
- Right to lodge a complaint — if you believe your rights have been violated, you may file a complaint with Thailand's Personal Data Protection Committee (PDPC)
To exercise any of the above rights, contact us at enquiry@subatavillas.com. We will acknowledge your request within 7 days and resolve it within 30 days as required under the PDPA.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include secure hosting environments, restricted internal access controls, and encrypted data transmission where applicable.
While we implement these safeguards, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. We will take all reasonable steps to protect your data but cannot warrant complete security against all possible threats.
In the event of a personal data breach that is likely to affect your rights and freedoms, we will notify affected individuals and report the incident to the PDPC without undue delay, as required under the PDPA.
10. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you. All material decisions relating to your booking or stay are made by our team directly.
11. Cookies
We use cookies on our website. Cookies are categorised as follows:
- Strictly necessary cookies — required for the website to function and cannot be disabled
- Analytics cookies — used to understand how visitors interact with our site, helping us improve performance. These are only activated with your consent
- Marketing cookies — used to deliver relevant content. These are only activated with your explicit consent
You can manage or withdraw your cookie consent at any time through your browser settings or our cookie consent tool.
12. Children's Privacy
Our services are intended for individuals aged 18 and above. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal information, please contact us immediately and we will delete it.
13. Contact and Data Controller
For any privacy-related questions, rights requests, or complaints, please contact us:
Email: enquiry@subatavillas.com
WhatsApp: +66 657 311 044
Data Controller
Data Controller: Subata Villas (operated by Subata Holding Company Limited / บริษัท ซูบาตา โฮลดิ้ง จำกัด)
Registered Address: 80 Moo 11, Tambon Thepkrasattri, Amphoe Thalang, Phuket 83110, Thailand
Company Registration / Tax ID: 0105565188996
VAT Registration Number: 0105565188996 (registered under ภ.พ.20, effective 30 March 2026)
We will acknowledge your request within 7 days and resolve it within 30 days.
14. Jurisdiction
This Privacy Policy is governed by the laws of the Kingdom of Thailand. Any disputes arising in connection with this policy shall be subject to the jurisdiction of the courts of Phuket, Thailand.