Privacy notice

How this website handles visits, optional analytics and booking enquiries, with controls for your privacy.

Who this notice covers

This draft covers the Doona Resort website. Doona Resort is the public trading name; the full legal operator and controller contact details are awaiting owner confirmation. The existing resort phone and LINE links below can be used to ask who handles privacy enquiries. INSIDEA is the website delivery partner, not the accommodation provider.

Browsing and website delivery

The website is hosted on Vercel. Hosting and network providers may process IP addresses, requested URLs, browser information and security logs to deliver and protect the site. There is no guest account or payment checkout on this website. Provider roles, lawful bases, log retention and international-transfer arrangements need owner review.

Using the stay planner

Dates, guest counts and optional notes stay in this page while you edit them. Search availability opens Booking.com with the selected dates and guest/room counts; notes are not included in that link. The LINE action copies your enquiry, including notes, to your clipboard. You choose whether to paste and send it in LINE. This website does not submit the form to a resort database or send it automatically.

Optional Google Analytics

Analytics is off until you allow it. With consent, Google Analytics receives page visits, limited referral/campaign information, device/browser information and booking, map or contact actions. Analytics identifiers can distinguish visits. Our custom events do not include the stay form, names, phone numbers, payment details or message text. Advertising consent is denied and advertising personalization is disabled. Do not place personal information in campaign links.

Your choice and storage

You can refuse analytics and still use the site. Cookie preferences lets you withdraw or change consent. The choice is saved in this browser for up to 180 days; configured analytics cookies also expire within 180 days, subject to browser limits. Browser storage may remain until cleared even after a choice expires. These durations are not the same as Google Analytics server-side retention, which still needs to be confirmed in the account.

External services and enquiries

Booking.com, LINE, Google Maps and social platforms process data under their own notices when you use them. The resort may receive the information you send through those services to answer an enquiry or arrange a stay. The resort must confirm its enquiry-handling process, recipients, lawful bases, retention and any cross-border safeguards.

Privacy requests

Depending on applicable law, rights may include access, correction, deletion, restriction, objection, portability, withdrawal of consent and a complaint to Thailand’s Personal Data Protection Committee. Some rights have conditions or legal exceptions. Ask the resort through the contact options below to reach its privacy contact. A verified dedicated contact and request-handling procedure must be added before approval.

Before this notice is approved

Owner review must confirm the legal name and address, privacy contact, purposes and lawful bases, required versus optional information and consequences, recipients, retention schedule, international transfers, request process, and effective date. This draft does not cover all on-property guest records, identity checks, payment handling or CCTV. Those practices need their own assessment.

Thai PDPA framework · proposed for adoption

The website behaviour described above has been checked against its implementation. The standards below are recommendations to adopt, not a claim that the resort already follows them. Legal operator details remain pending. Thai legal review is recommended before final publication.

Purpose and legal basis

Proposed bases: consent for optional analytics; steps requested before a booking or performance of a contract for necessary enquiries; legitimate interests for necessary site delivery and security, subject to a rights-balancing assessment. Identify any specific legal obligation separately, rather than using a blanket claim that Thai law requires all processing.

Only the information needed

Browsing requires technical connection data, not an account. Dates and guest/room counts are needed for a useful availability search; notes and analytics are optional. Declining analytics does not prevent booking. Keep passport copies, payment-card details and sensitive health information out of the planner.

Storage, access and deletion

Proposed standard: approved systems, need-to-know staff access, protected accounts, secure transfer and deletion when the documented purpose or applicable legal retention ends. Do not claim a universal Thai retention period. Confirm a separate schedule for enquiries, booking records, identity documents and CCTV before describing those practices publicly.

Providers and overseas processing

Vercel delivers the site and Google provides analytics only after consent. Booking.com and LINE receive information when the guest chooses to use them. Review each provider’s role, locations, contract and applicable Thai transfer safeguards. No Thailand-only storage or completed safeguards assessment is claimed.

Requests and incidents

Proposed procedure: record requests, verify identity proportionately, apply the relevant PDPA deadlines and exceptions, and explain any refusal. Establish incident assessment, escalation and legally required notifications. Do not request identity documents through the public planner. This procedure is not yet verified as operational.

Retention settings: implemented versus pending

Implemented in this website: a 180-day consent-choice lifetime and analytics-cookie configuration, with analytics off before consent. Pending: Google account retention and provider-log schedules. Google distinguishes user/event retention from aggregated reports; the browser setting does not delete every server-side record after 180 days.