General Privacy Information
koranasy operates personal development programs and collects certain personal data to deliver course content, manage enrollments, and support learners through practical case work. This policy explains what we collect, why we process it, how long we retain it, and how participants can exercise their rights. Examples and scenarios are used across our materials to make data practices transparent and relatable.
Definitions
This section defines commonly used terms in this policy to help participants understand the categories of data and processing activities referenced throughout. Definitions are illustrated with practical cases where relevant.
Data We Collect
We collect data directly from users, automatically via technical logs, and in certain cases from third parties to assist with course delivery, billing, analytics, and support. Examples and scenarios are used to show why each type of data is needed.
Data You Provide Directly
When registering, communicating, or participating in exercises you provide information that helps us deliver personalized course experiences and evaluate practical case outcomes.
- Full name and preferred display name used to identify participants in group scenarios and feedback sessions.
- Email address for account access, course notifications, assignment feedback, and scenario follow-ups.
- Phone number (+66940106346) for urgent course-related communications and administrative notices.
- Payment and billing information submitted when purchasing course access through our payment processor; used solely for transaction processing and record-keeping related to training cases.
- Course-related content such as submitted assignments, reflective journals, and scenario responses used for mentoring and progress review.
- Profile details and preferences including learning goals, prior experience, and consent choices to tailor scenario-driven materials.
Data Collected Automatically
When you interact with our websites and services we automatically collect technical and usage data to improve course delivery and analyze how scenario materials perform.
- IP address and approximate location inferred from the IP to help secure accounts and adapt time of live sessions for regional cohorts.
- Device and browser information to ensure compatibility with interactive scenarios and resource downloads.
- Usage data such as pages visited, time on lesson modules, and interaction with case-study content for analytics and course improvements.
- Performance metrics and error logs to diagnose technical issues that affect delivery of real-time workshops and simulations.
- Cookie identifiers and session vouchers to preserve user preferences and progress through multi-step practical exercises.
- Referral and campaign data used to evaluate the effectiveness of outreach for case-based cohorts.
Data from Third Parties
In some situations we receive data from partner services that help with payments, analytics, or course delivery. We limit such transfers to what is necessary for the related service.
- Payment processors providing transaction confirmations and billing records tied to course enrollments.
- Analytics providers that supply aggregated reports on engagement with scenario modules.
- Support platforms used to handle participant inquiries and case-related troubleshooting.
Purposes of Processing
We process personal data for specific purposes necessary to operate our courses, support participants, and improve learning outcomes through scenario-based methods.
- To register participants and provide access to course content, live workshops, and scenario materials.
- To process payments and maintain billing records for purchased courses and mentoring packages.
- To personalize learning paths and recommend practical case exercises based on participant profiles and past results.
- To deliver communications about course schedules, assignment feedback, and administrative notices.
- To analyze engagement with courses and scenario modules for continuous improvement of teaching methods.
- To detect, prevent, and respond to fraud or abuse affecting course delivery and participant safety.
- To comply with legal obligations or respond to lawful requests affecting koranasy operations.
- To provide aggregated, de-identified case outcome statistics used in training materials and reported internally to refine practical scenarios.
Legal Bases for Processing
Depending on the processing activity, we rely on one or more legal bases such as contractual necessity, consent, legitimate interests, or legal obligations. Below are examples aligned with typical scenarios.
- Performance of a contract: processing necessary to deliver purchased courses and mentoring sessions.
- Consent: where we seek your explicit consent for marketing communications or optional data uses tied to research and aggregated case studies.
- Legitimate interests: to improve services, secure our platforms, and analyze aggregated engagement with scenario modules, balanced against participants' rights.
- Legal obligation: processing required to comply with tax, accounting, or other statutory requirements in Thailand.
Rights Under Applicable Data Protection Law
If applicable under local data protection law, you may have specific rights regarding your personal data. We outline common rights and how to exercise them, illustrated with case examples where relevant.
- Access: request a copy of personal data we hold about you, for example your registration record and submitted scenario responses.
- Rectification: request correction of inaccurate personal data such as a misspelled name shown in a cohort roster.
- Erasure: request deletion of certain personal data, subject to retention needs for legal or contractual reasons.
- Restriction: request that we limit processing of your data while a dispute about accuracy or lawful basis is resolved.
- Portability: where applicable, request a machine-readable copy of data you provided for use in another service.
- Objection: object to certain processing based on legitimate interests, for example direct marketing related to optional study groups.
Sharing and Disclosure
We share personal data only as necessary to provide services, comply with legal obligations, or support data processing partners under contracts. Listed items provide practical examples of typical recipients.
- Payment and billing service providers who process course fees and issue receipts.
- Cloud hosting and infrastructure providers that store learning materials and participant records.
- Analytics and platform vendors that help us measure engagement with case modules and improve course design.
- Customer support platforms used to manage inquiries and resolve issues arising during scenario assignments.
- Legal or regulatory authorities when required to comply with valid legal processes or to protect rights and safety.
- Third-party instructors or partners, only with explicit participant consent, when they are involved in a specific course or case study session.
International Transfers
koranasy may transfer personal data to service providers or partners located outside Thailand to support operations such as hosting, analytics, and payment processing. Transfers are limited to what is necessary for the relevant service.
When data is transferred internationally, we use appropriate safeguards such as data processing agreements, standard contractual clauses where available, and technical protections like encryption to protect personal data.
Data Retention
We retain personal data only for as long as needed to provide services, meet legal obligations, resolve disputes, and improve educational offerings based on scenario outcomes.
Account information and enrollment records are retained for the period necessary to provide continued access to courses and to meet tax and accounting requirements, typically a minimum of the current year plus relevant statutory periods.
Communications such as support tickets and instructor feedback are retained for case continuity and quality assurance for a period consistent with operational needs, unless a deletion request is approved and applicable retention requirements are met.
Technical logs and analytics data are retained in aggregated or pseudonymized form for analysis of course engagement and platform performance, then deleted or anonymized according to our retention schedule.
When retention periods expire or deletion is requested and permitted, we delete or anonymize personal data securely. Some data required for legal compliance may be retained longer in a restricted form.
Security Measures
We implement administrative, technical, and physical measures to protect personal data against unauthorized access, disclosure, alteration, and destruction. Security practices are reviewed periodically and adjusted based on operational risks observed in practical scenarios.
- Encryption of data in transit and at rest for sensitive records such as payment confirmations and participant profiles.
- Access controls and role-based permissions to limit data access to staff and instructors who require it for course delivery and support.
- Regular audits, vulnerability scans, and incident response procedures to identify and remediate potential threats affecting platform reliability and participant data.
How to Exercise Your Rights
You can exercise your data protection rights by contacting us. Requests will be reviewed and handled in accordance with applicable law and the practical considerations of ongoing course delivery and legal obligations.
- To submit a request for access, rectification, deletion, or restriction of processing, contact our data protection point of contact with details of the request and any relevant account identifiers.
- We may request additional information to verify your identity and clarify the scope of the request. We will respond within applicable timeframes and provide explanations if any request is limited by legal obligations.
- Request portability: You may request a copy of personal data we hold about you in a commonly used, machine-readable format to transfer it to another provider. Example scenario: a participant asked for course enrollment history to import into a corporate LMS; we provided a CSV export within the timeframe described below.
- Withdraw consent: Where processing is based on consent, you can withdraw that consent at any time. Practical case: a user who previously opted into marketing emails chose to withdraw; we updated preferences and stopped emails for that account within 48 hours.
- Request rectification: If your personal data is inaccurate or incomplete, you can request updates. Case example: a participant found an error in their certification name after a course; we corrected the record after verification and issued an updated certificate.
- Request erasure: You can ask us to delete personal data where legal grounds allow. Scenario: an alumnus requested removal of their profile and course progress; we removed personal identifiers while retaining anonymized aggregate data for statistical purposes.
- Object to processing: You may object to certain processing activities, such as direct marketing or profiling. Example: a person objected to targeted promotion of an advanced workshop and we ceased targeted messaging for that account.
- Lodge a complaint: If you believe your rights have been breached, you can file a complaint with the relevant supervisory authority in Thailand. We also review complaints internally and report outcomes to the complainant when appropriate.
How to exercise your rights
To exercise any data subject rights, contact our privacy team with a clear description of the request and any supporting evidence needed to verify your identity. Provide your full name, email used with koranasy, and the nature of the request. Include course names or transaction references where relevant to speed processing. We handle requests with documented cases and step-by-step updates so you can follow progress.
Response timeframe: We aim to acknowledge requests within 5 business days and to provide a substantive response within 30 calendar days. For complex requests requiring additional verification or coordination with third parties, we will notify you and may extend the response period by up to 60 days with an explanation.
Marketing and communications
koranasy may send newsletters, course announcements, and event invitations based on preferences you set. Communications are tailored using enrollment records and stated interests. Example practice: after completing a resilience workshop, participants may receive invitations to related scenario-based sessions unless they opt out. We minimize marketing frequency and base content on practical case relevance rather than broad assumptions.
Unsubscribe: Every marketing message includes an unsubscribe link. You can also update communication preferences in your account settings or contact support to stop promotional messages. Changes take effect within 48 hours in most cases.
Children and youth
koranasy courses are designed for adult learners. We do not knowingly collect personal data from individuals under 16 without verifiable parental consent. If we become aware that we have inadvertently collected data from a minor without consent, we will take steps to delete the data after verifying the report. Example: when a parent reported an underage registration, we verified and removed the account upon confirmation.
Third-party links and services
Our site and course materials may include links to third-party tools, content platforms, and payment processors. These services have separate privacy policies. Case in point: if a workshop uses a third-party video conferencing provider, that provider may process participant names and attendance data. We recommend reviewing linked providers' privacy statements before sharing personal information.
Updates to this policy
We periodically update our privacy practices to reflect operational or regulatory changes. Revisions are posted on koranasy.pro with the effective date. When changes materially affect previously collected personal data, we will notify registered users by email and highlight differences using practical examples of how processing will change.