D SCAPE Privacy

Privacy policy

Last updated: 1 September 2026

This policy explains how D SCAPE collects, uses, discloses, retains, and protects personal data when you use this website, contact us, or register for an event. It applies together with any specific notice shown at the point of collection.

1. Controller and contact

D SCAPE Co., Ltd. (“D SCAPE”, “we”, “us”), based in Bangkok, Thailand, is the personal-data controller for the activities described here. For questions or rights requests, contact privacy@dscape.co.th.

2. Data, purposes, and legal bases

Activity and dataPurposeLegal basis
Contact enquiries
Name, email, company, topic, message, language, and email-delivery status.
Respond, prepare an assessment, send confirmation, and manage the request.Steps requested by you, the consent provided in the form, and legitimate interests in administering the enquiry.
Event registration
Name, nickname, company, position, phone, email, dietary choice, allergy details, photography choice, language, and event details.
Reserve a seat, administer the event, communicate with attendees, support safety and catering, and handle post-registration rights.Requested service/contract; explicit consent for allergy information; separate consent for identifiable photography or video.
Cookie choices
Random identifier, selected categories, language, notice version, action, and timestamp.
Remember choices and demonstrate consent or withdrawal.Necessity for remembering the choice, and consent for analytics or marketing cookies.
First-party website analytics
Random visitor and session IDs, page views, journeys, engaged time, scrolling, click positions, source, language, approximate country, and device category.
Measure content performance, user experience, and conversion without recording form values.Consent, which can be withdrawn at any time through Cookie settings.
Security and website operation
IP address, request metadata, technical logs, anti-abuse tokens, and form rate-limit counters.
Deliver the website, prevent spam, fraud, and unauthorised access, and investigate incidents.Legitimate interests in security and availability, and applicable legal obligations.
Administration area
Organisation account, user identifier, sign-in records, and administrative actions.
Authenticate staff, control access, and maintain internal accountability.Legitimate interests in administering and securing our systems.

Where information is required to answer a request or reserve a seat, we may be unable to provide that function if it is not supplied. We do not use this website for solely automated decisions producing legal or similarly significant effects.

3. Sources

We generally obtain data directly from you through forms, cookie settings, email, or communication with our team. Some technical data is received automatically from your device, browser, hosting provider, and anti-abuse systems.

4. Recipients and processors

Access is limited to authorised D SCAPE personnel who need the data for the purposes above. Contracted providers include Microsoft Azure for hosting, database, email, and administrator authentication, and Cloudflare Turnstile for anti-spam and abuse prevention. Where necessary, we may disclose data to professional advisers, venue or event-service providers, or public authorities when legally required.

We do not sell personal data or provide it to advertisers for their own marketing without an appropriate legal basis.

5. International transfers

Cloud and security providers may process data in Thailand or other countries. Where data is transferred to a country with different protections, we use safeguards required by applicable law, such as data-protection agreements, standard contractual clauses, or another valid transfer mechanism.

6. Retention

  • Event registration: until 90 days after the event ends, or no more than 180 days after registration if no event date is set, followed by operational deletion.
  • Contact enquiries: while handling the request and afterwards only as needed for service follow-up, legal or accounting obligations, or legal claims, subject to purpose-based review.
  • Form rate-limit data: used for the short anti-abuse window. Hosting and security logs follow provider retention settings and incident-investigation needs.
  • Cookie-choice evidence: retained as needed to demonstrate consent or withdrawal and meet accountability duties; device cookies last 180 days.
  • Website analytics: event and session data is retained for no more than 90 days. The device visitor ID lasts up to 180 days and is removed when consent is withdrawn or absent.

7. Your rights

Subject to applicable law, you may have rights to access and receive a copy, rectify, erase, restrict or object to processing, receive or transfer data, withdraw consent, and complain to a supervisory authority. Withdrawal does not affect processing lawfully carried out beforehand. Some rights depend on the legal basis and statutory exceptions.

Send requests to privacy@dscape.co.th. We may request information needed to verify your identity. You may complain to Thailand’s Personal Data Protection Committee and—where the GDPR applies—to the data-protection authority where you live or work.

8. Security

We use proportionate technical and organisational safeguards, including access controls, organisation authentication, encrypted connections, request throttling, anti-abuse controls, restricted database permissions, and activity records. No transmission or storage method is completely secure.

9. Cookies, external sites, and social media

Cookie details and preference controls are in our cookie policy. Links to external websites or social platforms are governed by those providers’ policies once you leave the D SCAPE website.

10. Children’s data

This website serves organisations and professionals and is not intended to collect children’s personal data. If you are a parent or guardian and believe a child submitted personal data without permission, contact privacy@dscape.co.th so we can investigate and take appropriate action.

11. Changes to this policy

We may update this policy when our services, data-processing activities, providers, or applicable laws change. The latest revision date appears at the top of this page. If a change materially affects your rights or how we use your data, we will provide additional notice through an appropriate channel.