Privacy at TIS
Privacy Policy
Thai International School (the “School,” “we,” “us,” or “our”) is committed to protecting your privacy and to collecting, using, and storing personal data in accordance with Thailand’s Personal Data Protection Act B.E. 2562 (PDPA). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you visit our website or contact us regarding our services.
Policy status Current school policy Effective
This notice covers the School website, online forms and communications. The School-wide rules for personal data and responsible AI are set out in the combined policy. Read the Data, Privacy & Responsible AI Policy.
Definitions
- Site
- The School’s website, accessible at thaiinternationalschool.ac.th.
- Service
- All services accessible via the Site, including academic program inquiries, admissions, events, and communications.
- Personal Data
- Information that identifies or can be used to identify an individual, directly or indirectly, as defined under the PDPA.
- You
- You, as a visitor, applicant, parent or guardian, or user of the Site or Service.
By using our Site or Service, you acknowledge this notice. Where consent is a lawful basis, the School asks for it separately and specifically.
Types of personal data we collect
We may collect the following categories of Personal Data:
- Directly Provided Information Your name, email address, telephone number, address, child’s date of birth, and other contact details submitted via inquiry or application forms.
- Visitor Pre-registration Information Visitor category, full name, required email address, optional telephone number and organization, host or department, broad purpose code, intended visit date and time, party size, adult or responsible-adult declaration, and conduct and privacy acknowledgments. Visitors must not enter student names or sensitive information in free-text fields. The email address is retained to match the submission to its record and to respond to privacy questions or rights requests. The visitor-registration system does not automatically email the visitor.
- Automatically Collected Information Browser type, IP address, device type, visit duration, pages viewed, and usage data via cookies or similar technologies.
- Sensitive Personal Data Only when necessary and with explicit consent, such as health information for school services or special needs accommodations.
We collect Personal Data only when necessary and for specific lawful purposes as outlined in Section II.
Purposes and legal basis for processing personal data
We process your Personal Data only when there is a lawful basis under the PDPA, including:
- Consent When a specific activity relies on consent, we request it separately and explain how to withdraw it. Submitting the visitor form acknowledges the notices and is not consent to unrelated uses.
- Contractual Obligations For processing admissions or service-related requests.
- Legal Obligations To comply with applicable laws and regulatory requirements.
- Legitimate Interests To maintain and improve our Site and services, provided that your fundamental rights are not infringed.
Use and disclosure of personal data
Your Personal Data may be used for:
- To respond to inquiries and provide information about our academic programs.
- To facilitate communication regarding admissions, school events, or updates.
- To manage visitor pre-entry screening, campus access, safety, safeguarding and an auditable reception record using an applicable lawful basis, including the School’s legitimate interests where appropriate.
- To notify only the School administrator recipients configured in the website backend when a visitor submits a registration. Each administrator recipient receives a separate TIS-branded HTML notice containing the complete submitted registration, including the reference, visitor name and contact details, organization when provided, visitor category, purpose, host or department, intended visit date and time, party size, form language, required acknowledgments, accepted notice version and submission time. The notice also contains that recipient’s private link to the read-only retained-record summary. No automatic submission email is sent to the visitor. A complete current link can start a 12-hour browser viewing session, so recipients must keep it confidential and must not forward it. Removing a recipient or replacing the private summary links revokes that recipient’s previous link and viewing sessions.
- To analyze and improve our Site and Service.
- To comply with legal or regulatory obligations.
We may share Personal Data with:
- Third-party service providers, such as website hosting, email, SMTP, mail-delivery and mail-log services, under appropriate confidentiality, security and data-processing terms and only for the above purposes. Depending on the School’s configuration, these providers may process or retain notification content and message or delivery metadata.
- Government authorities when legally required.
- Internal school departments for administrative or educational purposes.
- Authorized reception, security and administrative personnel who need visitor details for access control, safety or safeguarding.
We do not sell or rent your personal information to any third party.
An email being accepted by the website’s mail system means only that it was accepted for sending; it does not confirm delivery to a recipient’s inbox.
Cookies and tracking technologies
We use cookies and similar technologies to enhance user experience and track visitor behavior on our Site. You may adjust your browser settings to refuse or delete cookies. However, some parts of our Site may not function properly without them. After a visitor-form submission, an encrypted, HttpOnly first-party confirmation cookie is retained for up to 30 minutes solely to display, translate, print or save a non-identifying submission confirmation. It contains only the reference, submission time, intended visit date and time, and confirmation status; it is not used for advertising or analytics. For abuse prevention, the visitor form derives a keyed pseudonymous rate identifier from the connection address and does not keep the raw address in its rate table. The identifier stops affecting decisions at the next hourly boundary; expired buckets are removed by scheduled cleanup. Hosting or CDN security logs are governed separately.
Retention and protection of personal data
We retain your Personal Data only as long as necessary for the purposes it was collected or to comply with legal requirements. Your data is stored securely using reasonable administrative, technical, and physical safeguards to protect against loss, misuse, unauthorized access, or disclosure.
Visitor pre-registration records are retained for 90 days by default. An authorized administrator may configure a period from 30 to 365 days; the configured ordinary period cannot exceed 365 days after the scheduled visit. A legal, safeguarding or incident hold may preserve a record in the restricted backend only for as long as the documented need continues.
A complete copy of each submitted visitor record is encrypted at rest using a site-specific key that the visitor system creates and manages automatically. Limited linked operational metadata—including date, time, category, purpose, party size, status, notification state and retention timestamps—may also remain in access-controlled columns of the private table so authorized administrators can operate and audit the service.
The email-linked staff summary reads retained records live and is not a separate archive. A record no longer appears there after an authorized backend deletion or once its recorded retention deadline is reached, and the summary never displays a record beyond 365 days after the scheduled visit. A formal hold may preserve a due record for authorized WordPress managers, but it does not extend visibility in the email-linked summary.
The workflow does not generate a QR code or expose a public check-in bearer token. The printable or savable confirmation is evidence that the form was submitted, not permission to enter. Normal reception identity, safeguarding and entry checks still apply.
Data subject rights under PDPA
You have the following rights regarding your Personal Data:
- Right to Access Request a copy of your personal data.
- Right to Rectify Request corrections to incomplete or inaccurate data.
- Right to Erasure Request deletion of your data when it is no longer necessary.
- Right to Withdraw Consent Withdraw your consent at any time, which will not affect prior processing.
- Right to Object Object to data processing where applicable.
- Right to Data Portability Request transfer of your data to another party.
- Right to Lodge a Complaint Submit complaints to the Personal Data Protection Committee (PDPC) of Thailand.
To exercise your rights, contact us at the email address or phone number provided below.
Children’s privacy
Children receive specific protection. The School applies the consent and parent-or-guardian rules relevant to each activity under the PDPA and, where applicable, other binding law. If you believe a child’s data was collected or used improperly, contact us so we can investigate and take appropriate action.
Third-party links
Our Site may contain links to external websites. We are not responsible for the privacy practices or content of such sites. Please review their privacy policies before engaging with them.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to comply with PDPA or other applicable regulations. Significant changes will be posted on our Site or communicated to you directly when required. Please review this page periodically.
Contact information
If you have any questions or concerns about this Privacy Policy or your personal data, please contact:
Thai International School Email: info@thaiinternationalschool.ac.th Phone: 063 838 9900School visits & Sit-In Program
- This visitor form adjusts to the selected visit type. General visits collect contact details, purpose or event details and dates. Family and event groups provide group counts and the ages, enrolment status, current school and grade of attending children. No child details are collected for groups with no children. Contractors and vendors provide only contact details, purpose, host department and date, with policy acknowledgments. Trial and sit-in applications additionally collect the enabled student, guardian, support, document and fee-choice fields.
- Health, allergy and learning or attention-support information, diagnosed or not, is requested to assess and prepare appropriate support. The form asks separately for authorization to use this information. Families may contact the school about assistance or future consent withdrawal.
- TIS uses your contact, group and visit details to arrange your visit and manage reception. These basic details are sent to the school’s configured notification recipients and are available through their private visitor-summary links. Student identity documents, health and learning-support information remain restricted to authorized school accounts and are not included in these emails or private summaries. Hosting and email providers support this service. Email copies follow the school’s mailbox retention policy and are not removed when website records expire.
- Registration records and uploads are scheduled for deletion 180 days after the visit date or last requested student day, or after submission if dates are not supplied. Separate school enrolment or accounting records follow the school’s retention policies. Contact info@thaiinternationalschool.ac.th to ask about access, correction, deletion, or health-information consent. Required and optional fields are identified on this form; contact the school if you need help providing required information.