Privacy aware — bizdyyx

General privacy overview

At bizdyyx we prioritize respectful handling of personal data collected in the course of arranging accommodation, wellness services, and care coordination for pensioners. This document describes typical scenarios, what data is collected in each case, how it is used to deliver services, and how individuals can exercise their rights.

01-01-2026 bizdyyx, 110/9, Soi Hua Hin 142, Nong Kae Sub District, Amphoe Hua Hin District, Prachuap Khiri Khan Province 77110, Thailand. Business ID: 1711644574847. Contact phone: +66976537674. Website: bizdyyx.click. 110/9, Soi Hua Hin 142, Nong Kae Sub District, Amphoe Hua Hin District, Prachuap Khiri Khan Province 77110, Thailand [email protected]
01

Key definitions

This section explains terms used in the policy and provides short practical examples of each type of data and processing activity in real service scenarios.

Personal data means any information that identifies or can be used to identify an individual. Practical case: reservation details that include a guest's full name, date of birth and emergency contact to enable check-in and care coordination. Processing covers any operation performed on personal data, such as collection, storage, retrieval, sharing, or deletion. Example: compiling a weekly dietary plan from a guest's allergy and preference data to prepare meals. User refers to an individual who accesses services via bizdyyx.click or receives services at our facility, such as a pensioner booking a stay or a family member arranging care. Service means the booking and delivery of sanatorium accommodations, wellness programs, and associated coordination with healthcare and family contacts. Example case: a coordinated discharge program combining transport arrangements and light therapy sessions. Cookies are small data files stored on a device to support site functionality, remember preferences, and analyze usage patterns. Example: remembering language preference on subsequent visits to bizdyyx.click.
02

What data we collect

We collect data relevant to delivering hospitality and care services, ensuring safety and improving guest experience. Below are typical categories with practical examples based on common scenarios.

Data you provide directly

Examples of user-provided data collected during booking, admission, and ongoing service delivery.

  • Identity and contact details: name, date of birth, postal address, email, and phone number used to create reservations and emergency contacts.
  • Health-related information volunteered for care planning: allergies, dietary restrictions, mobility limitations, and medication lists provided during intake assessments.
  • Payment and billing information supplied to complete transactions and issue invoices, such as card details provided via secure payment processors.
  • Preferences and special requests entered when booking (room type, assistance requirements, activity interests) used to personalize a guest's schedule.
  • Communications and correspondence content such as messages to our support team regarding reservations or care coordination.
  • Feedback and reviews submitted after a stay or program, used to improve practical service delivery and scheduling.

Automatically collected data

Data collected automatically when users interact with bizdyyx.click or when facility systems log activity. Typical cases and the purpose of each collection are described below.

  • Log information such as access times, IP addresses, and pages viewed, used to troubleshoot access issues and improve site navigation.
  • Device and browser details to ensure compatibility and present the booking interface correctly on commonly used devices.
  • Usage analytics showing which packages or content pages are most accessed, informing scheduling adjustments and resource planning.
  • Performance and error reports from facility systems used to maintain reliable service delivery (example: resolving a booking confirmation email delivery failure).
  • Cookie identifiers used to remember session state and preferences for returning users.
  • Location approximations (when enabled by the user) to suggest nearby transfer options and local emergency contacts relevant to the Hua Hin area.

Data from third parties

In some scenarios we receive data from partners to coordinate care or complete bookings. Examples and typical uses are listed below.

  • Referral information from healthcare providers or case managers sent to arrange a transitional stay or follow-up rehabilitation sessions.
  • Payment processors that provide transaction confirmations and anonymized fraud signals necessary for billing reconciliation.
  • Travel agencies and booking platforms that supply guest details needed to confirm arrival logistics and special assistance requests.
03

Why we collect data (purposes)

We use personal data for clear operational purposes tied to service delivery and legal obligations. Below are common purposes with scenario-based explanations.

  • Provision of contracted services: using reservation and health preference data to prepare rooms, meals, and activity schedules tailored to a guest's mobility and dietary needs.
  • Billing and payments: processing payments and issuing invoices in cooperation with payment partners for completed stays or services.
  • Safety and medical coordination: sharing essential health and contact details with on-site clinical staff to manage day-to-day care and respond to emergencies.
  • Customer support: responding to booking requests and complaints, with examples such as changing arrival dates or updating care plans after an assessment.
  • Service improvement: analyzing anonymized usage patterns to adjust activity schedules and staffing levels based on observed peak participation.
  • Legal and regulatory compliance: retaining records requested by authorities or needed to comply with contractual and statutory obligations.
  • Communications and marketing (where consented): sending service updates, care reminders, and occasional newsletters describing practical case studies and scheduling tips.
  • Fraud prevention and security: using transaction and device data to detect suspicious activity and protect guest accounts.

Legal bases for processing

For residents and visitors from jurisdictions with identifiable legal frameworks, we rely on appropriate lawful bases tied to each processing purpose. Below are typical bases and examples.

  • Performance of a contract: processing reservation and payment details to fulfill booking agreements and provide requested services.
  • Legal obligation: retaining records required for tax, safety, or regulatory reporting related to hospitality and care services.
  • Consent: when individuals opt in to receive marketing communications or allow specific data uses not necessary for service delivery.
  • Legitimate interests: for operational needs such as improving site usability, preventing fraud, and securing systems, balanced against individual privacy considerations.

EU data subject rights (GDPR-related guidance)

For individuals covered by the GDPR, we describe common rights and how they are exercised in practice, with examples of typical response times and documentation requirements.

  • Access: individuals may request a copy of their personal data. Practical case: a guest requests past invoices and care notes from a three-month stay; we provide a secure export within a defined response period.
  • Rectification: correcting inaccurate data such as a misspelled name or incorrect medication listed in intake forms.
  • Erasure (where applicable): in routine scenarios we can delete non-essential data after contractual obligations end, subject to retention requirements for billing or legal records.
  • Restriction of processing: an individual may request limited use of their data while a dispute is resolved; for example, pausing marketing messages during a complaint.
  • Data portability: providing structured data exports used to transfer basic reservation and contact records to another provider upon request.
  • Right to object: individuals may object to certain processing such as direct marketing; we document the objection and stop the relevant processing unless another legal basis applies.
04

Cookies and tracking technologies

Cookies and similar technologies help make bizdyyx.click functional and user-friendly. Below we summarize the types used and management options with practical examples.

Types include session cookies for basic navigation, preference cookies to remember language settings, analytics cookies to measure page usage, and essential cookies for booking form stability.

Categories: strictly necessary (booking sessions), functional (preferences), analytics (usage patterns), and marketing (only with consent). Example: a returning visitor sees previously selected room preferences saved.

Users can manage cookie settings via the site banner and browser controls. Practical step-by-step: adjust preferences in the cookie banner or use browser privacy settings to block third-party cookies.

Read our full cookie policy on bizdyyx.click/cookie-policy

When we share data

We share personal data only for operational needs, safety coordination, or with consent. Below are concrete third-party categories and examples of why sharing occurs.

  • Service providers: third-party booking engines and payment processors are used to complete reservations and payments; example: sending booking details to a payment gateway to confirm a transaction.
  • Healthcare partners: with consent or under necessary circumstances, we share limited health-related information with local clinics or emergency services to deliver safe care.
  • Transport and logistics providers: sharing arrival times and mobility needs with transfer services to ensure appropriate assistance at arrival.
  • Legal and regulatory authorities: disclosing records when required by law or to respond to lawful requests.
  • Analytics and service improvement vendors: sharing anonymized or pseudonymized usage data to inform operational adjustments and staffing scenarios.
  • Marketing partners (only with consent): sharing contact details for co-promotions when a guest explicitly opts in.

International transfers

Personal data may be transferred to service providers or partners located outside Thailand for operational reasons. In each transfer scenario we implement safeguards appropriate to the risk and legal requirements.

Safeguards include contractual data protection clauses, restricted access policies, and verification of partner security practices. Example: payment processor contracts require encrypted transmission and limited retention.

Data retention

We retain personal data only as long as necessary to fulfill the purpose of collection or to meet legal, regulatory, or contractual requirements. Retention periods vary by data type and scenario.

Account and reservation records: retained for the duration needed to manage bookings and for a reasonable period after checkout to allow for queries, typically aligned with tax and billing requirements.

Communications: inquiry and support messages are retained as long as necessary to resolve the matter and for a short period afterward to document case outcomes.

System and access logs: kept for operational troubleshooting and security monitoring for a limited period consistent with industry practice.

Deletion requests are handled case-by-case: non-essential personal data is removed when contractual and legal retention obligations have ended, with clear examples provided on request.

Security practices

We apply reasonable technical and organizational measures to protect personal data against unauthorized access, alteration or loss. Measures are chosen based on scenario risks and operational needs rather than absolute guarantees.

  • Access controls and role-based permissions for staff to limit exposure of guest records in routine care and booking scenarios.
  • Encryption of payment data in transit and at rest through established payment processors, with periodic security reviews.
  • Regular backups, monitored logs, and incident response procedures to restore operations and explain practical steps taken in the event of a breach.
05

How to exercise your rights

Individuals have rights over their personal data. Below are the most relevant rights, explained through practical steps and examples for how to submit requests.

  • How to request access, correction or deletion: submit a request via the privacy contact below with sufficient identification and details about the data and timeframe. Example: requesting copies of last year's invoices or correcting an intake form entry.
  • Right to request correction: You may ask bizdyyx to correct inaccurate or incomplete personal data we hold about you. Example scenario: a guest updates their emergency contact after a family move; our team provides a step-by-step correction case record and confirms the update within our processing window.
  • Right to deletion (right to be forgotten) in specific situations: If retention is no longer necessary or processing is unlawful, you can request deletion. Practical case: a former guest requests removal of marketing consents and non-essential notes from their profile; we retain transactional records required by law but remove optional items.
  • Right to restrict processing: You can request limits on how we use your data while a dispute is resolved. Example: during an identity verification dispute, we place a restriction flag on the account to prevent non-essential processing until verification concludes.
  • Right to data portability where applicable: When data was provided by you and processed automatically, you may request a copy in a commonly used, machine-readable format. Case example: a guest requests a copy of their booking history to transfer to another service; we provide a CSV or JSON extract where feasible.
  • Right to object to processing for direct marketing: If you object to receiving promotional messages, we process the request and update your marketing preferences. Scenario: after a promotional campaign, a retiree opts out via the unsubscribe link and receives confirmation of suppression.
  • Right to withdraw consent: Where we rely on consent for processing (e.g., marketing), you may withdraw it at any time without affecting lawfully processed prior actions. Practical example: a resident withdraws consent for photos used in non-essential publicity; we mark future usage restrictions.
  • Right to lodge a complaint with a supervisory authority: If you believe bizdyyx has not handled your personal data in accordance with applicable law, you may file a complaint with the relevant data protection regulator in Thailand. We document such cases and provide cooperation in contribute.

How to exercise your privacy rights

To exercise any of the rights above, contact our privacy team with a clear description of the request and identity verification. Provide practical details (booking reference, email, dates) to help us process the request more efficiently. Typical cases include correcting contact details after a move, requesting deletion of marketing consents, or asking for a copy of booking records for personal archiving.

[email protected]

Response time: We aim to acknowledge requests within 7 calendar days and to complete standard requests within 30 calendar days. In complex scenarios or where legal checks are required, we may extend processing up to a reasonable additional period and will notify you of any extension and its reasons.

Marketing communications and preferences

bizdyyx may send promotional offers, event notices, and practical program updates about senior-focused services at our Hua Hin location. Marketing is based on your consent or legitimate interest where permitted. Case example: subscribers receive targeted newsletters about seasonal wellness workshops; participation remains optional and linked to clear consent settings.

Unsubscribe options: Each marketing email includes an unsubscribe link. You can also change preferences in your account settings or contact our team to update consent records. Example scenario: a guest who attended a trial program unsubscribes and receives confirmation that they will no longer receive promotional emails.

Children and guardians

Our services are primarily designed for older adults and seniors. We do not knowingly collect personal data from children under 18 for program bookings. If a parent or guardian manages information on behalf of a dependent, please contact us to clarify responsibilities and data handling. Case scenario: a family member books an accompanied stay and provides necessary health information with parental or guardian consent.

Links to third-party sites

Our website and communications may include links to partner services (transport, local medical providers, insurance). Each link leads to third-party sites with separate privacy policies. Practical case: when a guest books airport transfer via a partner link, that partner becomes responsible for any data submitted on their platform.

Changes to this privacy notice

We update this privacy notice to reflect legal changes, operational updates, or improvements based on case reviews. We publish the revision date and, where changes materially affect data use, we notify registered users. Example: after adopting a new booking platform, we updated the notice and provided a summary of changes to active members.