Privacy Policy
What we collect when you enquire about a residence, why we hold it, who else sees it, and how to have it back or deleted.
This policy applies to longevitysamui.com and to any enquiry you send through it. It is written to satisfy both the EU/UK General Data Protection Regulation, Hong Kong’s Personal Data (Privacy) Ordinance and Thailand’s Personal Data Protection Act B.E. 2562 (2019). The company is registered in Hong Kong, the development is in Thailand, and most of the people who write to us are in Europe, so all three apply at once.
1. Who is responsible
The controller of your personal data is:
- Longevity Property Group Limited
- Registered in Hong Kong SAR
- Company number 80416491
- Data protection contact: privacy@longevitysamui.com
The company decides why and how your data is used, and answers for it. We have not appointed a Data Protection Officer, and are not required to: we do not monitor people at scale and we hold no special-category data. The address above reaches the people responsible.
Because the company is established outside the European Union and offers residences to people inside it, we have designated a representative in the Union under Art. 27 GDPR. You may address our representative instead of us, on anything to do with your data, and so may a supervisory authority:
- Szűcs Máté, representative in the Union
- 1039 Budapest, Attila u. 92, Hungary
- privacy@longevitysamui.com
Writing to the representative has the same effect as writing to us. It does not limit our own responsibility, and it does not stop you bringing an action against the company itself.
2. What we collect, why, and for how long
We collect what you type into a form and the minimum needed to run and measure the site. We do not buy lists and we do not enrich your record from third-party data brokers.
| What | Why | Legal basis | Kept for |
|---|---|---|---|
| Name, email, WhatsApp number, message | To answer your enquiry and, if you go further, to prepare a reservation | Steps taken at your request before a contract (GDPR Art. 6(1)(b); PDPA s.24(3)) | Three years from the last time you got in touch with us, then anonymised: your name, contact details and messages are removed |
| Email address given for the brochure | To send you the brochure you asked for, and the follow-up e-mails described in section 6 | Consent (GDPR Art. 6(1)(a); PDPA s.19) | Three years from the last time you got in touch with us, or until you withdraw |
| Which page you enquired from, and any campaign tag in the link | So the person replying knows what you were reading | Legitimate interest in answering usefully (GDPR Art. 6(1)(f)) | With the enquiry |
| Pages viewed, device, approximate location from IP | To see which parts of the site are read and which are not | Consent, through the cookie banner | Up to 14 months (Google Analytics default) |
| Your cookie choices | To stop asking you the same question | Legal obligation to record consent | 12 months |
| Contract, payment and ownership records, if you buy | To complete and administer the purchase | Contract and legal obligation | Seven years after the transaction, which is what Hong Kong company law requires of accounting records, and as long as the Thai Land Office requires of the lease registration |
Two invisible checks run on every form: a hidden field no person can see, and a minimum time between the form opening and being sent. Both exist only to stop automated spam. Neither profiles you and neither is stored.
3. Who else sees it
Your enquiry goes straight into our own CRM. We do not route it through a third-party sales platform, a lead marketplace or a marketing automation service. Beyond that, only the following processors touch your data, each under a written agreement limiting them to acting on our instructions:
| Processor | What it does | Where |
|---|---|---|
| Google (Tag Manager, Analytics) | Site measurement, only after you accept analytics cookies | EU / US |
| WhatsApp (Meta Platforms Ireland) | Carries our reply, if you gave a WhatsApp number | EU / US |
| Meta Platforms Ireland (Pixel) | Records that an enquiry or a page view happened, so an advertisement can be attributed. It receives the event, not what you wrote | EU / US |
| Vercel | Serves the website, runs our CRM, and counts page views without cookies | EU / US |
| Neon | Stores our CRM records, including your enquiry | EU / US |
| Resend | Sends our e-mails to you, and alerts to our team when you write | EU (Ireland) |
| Google Workspace | Our mailboxes, which receive your replies and our backups | EU / US |
| Anthropic | Reads your messages, and the notes our team writes about them, to help us answer and decide whom to call first. It may not use them to train its models | US |
We do not sell your data and we do not pass it to other developers or agencies. The one advertising network involved is Meta, named above: it is told that an enquiry or a page view happened so that we can tell which advertisement brought you here. The content of your enquiry is never sent to it. If a Thai lawyer, notary or land office needs your details to complete a purchase you have chosen to make, they receive them as independent controllers under their own obligations.
4. Where your data goes
An enquiry written in Europe reaches a company in Hong Kong and a sales team in Thailand, while the website and its records sit on servers in the EU and the US. Neither Hong Kong nor Thailand is covered by a European Commission adequacy decision, so those movements need a safeguard of their own.
- EU/UK → Hong Kong and Thailand. Transfers rely on the EU Standard Contractual Clauses. Where you have written to us yourself and the transfer is necessary to answer you, Art. 49(1)(b) GDPR also applies.
- Thailand → abroad. Transfers are made under s.28–29 PDPA, using the Standard Contractual Clauses or the ASEAN Model Contractual Clauses, or with your consent where neither applies.
- Hong Kong → abroad. The PDPO’s cross-border section (s.33) is not yet in force. We apply the Privacy Commissioner’s recommended model clauses to transfers out of Hong Kong as a matter of practice.
You can ask us for a copy of the safeguards that cover a specific transfer.
5. Your rights
Both regimes give you the same core rights, and you exercise them the same way , by writing to the address in section 1. We answer within 30 days, free of charge.
- Access: a copy of what we hold about you.
- Rectification: correction of anything wrong.
- Erasure: deletion, unless we are required to keep it.
- Restriction: we hold it but stop using it while something is disputed.
- Portability: your data in a machine-readable file.
- Objection: to any processing we base on legitimate interest.
- Withdrawal of consent: at any time, without affecting what was lawful before.
We take no decision about you by automated means alone that has legal or similarly significant effects. To decide whom to call back first, our CRM sorts enquiries into hot, warm and cold, from what you told us and how recently we spoke; a person always decides what happens next. You can object to this at any time. If you think we have handled your data badly, tell us first: but you may also complain to your national supervisory authority in the EU, to the Information Commissioner’s Office in the UK, to Thailand’s Personal Data Protection Committee, or to the Office of the Privacy Commissioner for Personal Data in Hong Kong.
6. Follow-up e-mails
When you enquire or ask for a brochure, we send you a short series of e-mails about the residences: the first straight away, then about 3, 10, 24, 45 and 60 days later, and nothing after that. The series stops as soon as you reply, as soon as someone from our team has spoken with you, or when you use the unsubscribe link that is in every one of them. We send it because you asked us about the residences (legitimate interest, GDPR Art. 6(1)(f)), and you can object with that one click.
The document links and buttons in these e-mails tell us when you open a document we sent or click a button, so that we know who is still interested. We do not use tracking pixels to see whether you opened the e-mail itself. We do not run a newsletter, and we never add you to anyone else’s list.
7. Security
The site is served over HTTPS only. Enquiries travel encrypted and are held in access-controlled systems. Only the people who need to answer you can see them.
No system is perfect. If a breach ever put you at risk, the three regimes ask for different things and we would do all of them. Under the GDPR we would report it to the lead supervisory authority within 72 hours of becoming aware, and tell you directly without undue delay where the risk to you is high. Under the Thai PDPA the same 72-hour report goes to the Personal Data Protection Committee. Hong Kong does not yet make notification compulsory; we would follow the Privacy Commissioner’s guidance and notify anyway.
8. Children
This site is for adults buying property. We do not knowingly collect data from anyone under 20, which is the Thai threshold and the stricter of the ones that apply to us; the GDPR sets 16, or lower in some member states. If you believe a child has sent us data, write to us and we will delete it.
9. Cookies
What runs on the site, what each cookie is for and how to change your mind is in the Cookie Policy.
10. Changes
We update this policy when what we do changes. The date at the top is the date of the current version. Material changes affecting enquiries already with us will be sent to the address we hold.