Privacy & Data Protection Policy
1. Introduction and scope
This Privacy and Data Protection Policy (the “Policy”) sets out the basis on which Longevity Property Group Limited, a private company limited by shares incorporated under the laws of the Hong Kong Special Administrative Region (“the Company”, “we”, “us” or “our”), collects, records, holds, uses, discloses, transfers and otherwise processes personal data in connection with the website available at https://longevitysamui.com (the “Website”) and any related enquiry, reservation, brochure-request or communication channels operated by or on behalf of the Company (together, the “Services”). This Policy is issued in accordance with, and is intended to satisfy the information requirements of, Articles 12, 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “General Data Protection Regulation” or “GDPR”), the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (the “PDPO”), the Personal Data Protection Act B.E. 2562 (2019) of the Kingdom of Thailand (the “PDPA”), and any other data protection legislation applicable to the processing activities described herein (together, “Applicable Data Protection Law”).
By accessing or using the Website, submitting an enquiry, requesting marketing or sales documentation, or otherwise communicating with the Company, you acknowledge that you have read and understood this Policy. Where processing is based on your consent, such consent is obtained separately in accordance with Applicable Data Protection Law and may be withdrawn at any time as described in Section 12 below. This Policy does not apply to third-party websites, applications or services that may be linked from the Website, whose privacy practices are governed by their own policies, and for which the Company accepts no responsibility.
2. Identity and contact details of the controller
For the purposes of Applicable Data Protection Law, the data controller responsible for the processing of personal data described in this Policy is:
- Longevity Property Group Limited
- No 5, 17/F, Strand 50, 50 Bonham Strand
- Sheung Wan, Hong Kong
- Email: sales@longevitysamui.com
The Company has not appointed a statutory Data Protection Officer, as it is not required to do so under Article 37 GDPR having regard to the nature, scope and purposes of its processing activities. All data protection enquiries should be directed to the contact point identified above, which serves as the Company’s single point of contact for data subjects and supervisory authorities.
3. Definitions
In this Policy, “personal data”, “processing”, “data subject”, “controller”, “processor”, “consent”, “special categories of personal data” and cognate expressions bear the meanings given to them in the GDPR or, where the context requires, the equivalent concepts under the PDPO or the PDPA. References to statutory provisions include any amendment, re-enactment or replacement thereof from time to time in force.
4. Categories of personal data processed
The Company processes the following categories of personal data, in each case limited to what is adequate, relevant and necessary in relation to the purposes for which it is processed (data minimisation, Article 5(1)(c) GDPR):
- Identity and contact data— first name, surname, email address, telephone number and, where provided, messaging identifiers (including WhatsApp), submitted through the Website’s enquiry, reservation or brochure-request forms or otherwise provided in correspondence;
- Transaction and preference data — the residence type or unit of interest, indicative preferences, and the content of any message or request submitted;
- Marketing attribution data — campaign parameters associated with your visit (including UTM source, medium, campaign, term and content identifiers and equivalent referral codes), the page from which a form was submitted, and the date and time of submission;
- Usage and interaction data — aggregated and event-level records of interactions with the Website (such as page visits, referral domain and interface interactions), collected on a first-party basis without the use of advertising identifiers;
- Technical data — Internet Protocol (IP) address, browser type and version, operating system, device characteristics, language settings and other data generated automatically by web servers, content-delivery infrastructure and security systems in the ordinary course of operating a website;
- Consent records— records of consent given or refused through the Website’s consent-management facility, including the categories consented to and the time of the consent event;
- Communication data — the content and metadata of correspondence between you and the Company by email, telephone, messaging services or otherwise.
The Company does not intentionally collect special categories of personal data within the meaning of Article 9 GDPR, nor personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR, and requests that you do not submit such data through the Services. The Services are not directed at, and are not intended for use by, persons under the age of eighteen (18), and the Company does not knowingly process the personal data of such persons.
5. Sources of personal data
Personal data is obtained (a) directly from you, when you complete a form on the Website, download documentation, or correspond with the Company or its authorised sales representatives; (b) automatically, through the operation of the Website and its hosting, security, analytics and consent-management infrastructure; and (c) from third parties acting on the Company’s behalf or with your authorisation, including marketing and sales intermediaries who refer your enquiry to the Company.
6. Purposes and legal bases of processing
The Company processes personal data for the purposes, and on the legal bases, set out below. Where more than one legal basis is indicated, the applicable basis depends on the specific context of the processing operation concerned.
| Purpose of processing | Legal basis (Art. 6(1) GDPR) |
|---|---|
| Receiving, recording, allocating and responding to enquiries, reservation requests and requests for sales documentation; conducting pre-contractual correspondence and negotiations | Art. 6(1)(b) — performance of a contract or steps at the data subject’s request prior to entering into a contract; Art. 6(1)(f) — legitimate interests |
| Providing the brochure and other requested documentation | Art. 6(1)(a) — consent; Art. 6(1)(b) — pre-contractual steps |
| Maintaining customer-relationship records, including the classification and prioritisation of enquiries and the administration of follow-up activity | Art. 6(1)(f) — legitimate interests in the orderly administration of sales activity |
| Measuring the effectiveness of marketing channels and campaigns by means of attribution parameters associated with enquiries | Art. 6(1)(f) — legitimate interests in evaluating marketing expenditure |
| Operating, monitoring, securing and improving the Website and its infrastructure, including the prevention, detection and investigation of fraud, abuse and security incidents | Art. 6(1)(f) — legitimate interests in network and information security |
| Deploying analytics, measurement and, where applicable, marketing technologies subject to your consent choices | Art. 6(1)(a) — consent, to the extent required by Applicable Data Protection Law |
| Complying with legal, regulatory, tax, accounting and record-keeping obligations to which the Company is subject | Art. 6(1)(c) — legal obligation |
| Establishing, exercising or defending legal claims | Art. 6(1)(f) — legitimate interests |
Where processing is based on the Company’s legitimate interests, the Company has carried out the balancing assessment required by Article 6(1)(f) GDPR and has concluded that such interests are not overridden by the interests or fundamental rights and freedoms of data subjects, having regard in particular to the reasonable expectations of persons who submit commercial property enquiries. Further information regarding any such assessment may be requested via the contact point in Section 2. The Company does not use personal data for automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR, and does not sell personal data.
7. Cookies, consent management and similar technologies
The Website uses strictly necessary storage by default and deploys optional cookies and similar technologies only in accordance with the choices you express through the consent-management facility made available on the Website (operated using the CookieYes consent-management platform, deployed via Google Tag Manager). Tag-management infrastructure provided by Google Tag Manager (Google Ireland Limited / Google LLC) is used to control the deployment of measurement and, where applicable, marketing tags in accordance with your consent state. First-party, cookieless aggregate usage measurement is additionally performed by the Website’s hosting infrastructure. Detailed information on the specific cookies and storage technologies used, their providers, purposes and retention periods is set out in the Company’s Cookie Policy, which forms part of this Policy.
8. Recipients and categories of recipients
Personal data is disclosed, on a need-to-know basis and subject to appropriate contractual safeguards (including, where required, data-processing agreements pursuant to Article 28 GDPR), to the following categories of recipients acting as processors or, in limited cases, as independent controllers:
- Website hosting and infrastructure: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, United States (website hosting, content delivery, security and first-party aggregate analytics);
- Database infrastructure:Neon, Inc. (managed database services used for the Company’s enquiry-management records);
- Customer-relationship management: Zoho Corporation Pvt. Ltd. and its affiliates, as provider of the Zoho Bigin CRM platform, in which enquiry and customer-relationship records are maintained;
- Workflow and integration services:Celonis, Inc. / make.com (Make), used to route form submissions from the Website to the Company’s CRM systems;
- Tag and consent management: Google Ireland Limited / Google LLC (Google Tag Manager) and CookieYes Limited (consent management);
- Communications providers: providers of email and messaging services used to correspond with you, including, where you elect to communicate by WhatsApp, WhatsApp Ireland Limited / Meta Platforms, Inc. as an independent controller of that service;
- Professional advisers and authorities: legal, accounting, audit and other professional advisers, and courts, regulators, supervisory and law-enforcement authorities where disclosure is required or permitted by law;
- Corporate transactions:actual or prospective acquirers, investors, financiers and their advisers in connection with any merger, acquisition, reorganisation, financing or transfer of all or part of the Company’s business or assets, subject to customary confidentiality obligations.
9. International transfers of personal data
The Company is established in Hong Kong and the development to which the Website relates is located in the Kingdom of Thailand; accordingly, personal data is by necessity processed in, and transferred between, jurisdictions outside the European Economic Area (“EEA”) and the United Kingdom, including Hong Kong, Thailand, the United States and India. Where personal data of data subjects located in the EEA or the United Kingdom is transferred to a country that has not been recognised by the European Commission (or, as applicable, the UK Secretary of State) as ensuring an adequate level of protection, the Company relies on appropriate safeguards within the meaning of Article 46 GDPR — in particular the European Commission’s Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), supplemented where necessary by additional technical and organisational measures — or, in the absence thereof, on the derogations of Article 49 GDPR (including performance of a contract concluded at the data subject’s request). Certain providers listed in Section 8 participate in the EU-U.S. Data Privacy Framework, on which the Company may additionally rely. A copy of the relevant safeguards may be requested via the contact point in Section 2.
10. Retention of personal data
Personal data is retained only for as long as is necessary for the purposes for which it was collected, and thereafter deleted, anonymised or placed beyond use, subject to any longer period required or permitted by law. Without prejudice to the foregoing: enquiry and customer-relationship records are retained for the duration of the sales dialogue and for a reasonable subsequent period reflecting the long procurement cycle customary in residential property transactions; records evidencing consent are retained for as long as the related processing continues and thereafter to the extent necessary to demonstrate compliance; documents subject to statutory retention obligations (including accounting and tax records) are retained for the periods prescribed by the applicable legislation; and server, security and interaction logs are retained for short, rolling periods appropriate to their purpose. Criteria used to determine retention periods include the nature and sensitivity of the data, the purposes of processing, applicable limitation periods for legal claims, and statutory requirements.
11. Security of processing
The Company implements appropriate technical and organisational measures, within the meaning of Article 32 GDPR, designed to ensure a level of security appropriate to the risk, including encryption of data in transit, access controls and authentication on administrative systems, segregation of environments, the engagement of reputable infrastructure providers maintaining recognised security certifications, and the limitation of access to personal data to persons who require it for the purposes described in this Policy. No method of transmission or storage is entirely secure, and the Company cannot guarantee absolute security; in the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, the Company will comply with its notification obligations under Articles 33 and 34 GDPR and any equivalent obligations under Applicable Data Protection Law.
12. Rights of data subjects
Subject to the conditions and limitations of Applicable Data Protection Law, you are entitled: (a) to request access to, and a copy of, the personal data held about you (Article 15 GDPR); (b) to request rectification of inaccurate or incomplete personal data (Article 16); (c) to request erasure of personal data (Article 17); (d) to request restriction of processing (Article 18); (e) to receive personal data provided by you in a structured, commonly used and machine-readable format and to transmit it to another controller (Article 20); (f) to object, on grounds relating to your particular situation, to processing based on legitimate interests, and to object at any time to processing for direct-marketing purposes (Article 21); and (g) where processing is based on consent, to withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3)). Equivalent rights may be available under the PDPO and the PDPA.
Requests may be submitted to the contact point identified in Section 2. The Company may require reasonable verification of your identity before acting on a request and will respond within the periods prescribed by Applicable Data Protection Law (in the case of the GDPR, in principle within one month, extendable in accordance with Article 12(3)). You further have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement (Article 77 GDPR), with the Office of the Privacy Commissioner for Personal Data in Hong Kong, or with the Personal Data Protection Committee of Thailand, as applicable.
13. Obligation to provide data
You are under no statutory or contractual obligation to provide personal data to the Company; however, the provision of the data requested in the Website’s forms is necessary for the Company to respond to your enquiry or provide the requested documentation, and failure to provide such data will render the Company unable to do so.
14. Amendments to this Policy
The Company reserves the right to amend this Policy from time to time to reflect changes in its processing activities, service providers or legal requirements. The version published on this page, together with its “last updated” date, is the version in force. Material changes will be indicated by an updated date; continued use of the Services following publication constitutes acknowledgement of the amended Policy. This Policy was last reviewed on the date stated at the head of this page.
15. Contact
All questions, requests and complaints concerning this Policy or the Company’s processing of personal data should be addressed to Longevity Property Group Limited, No 5, 17/F, Strand 50, 50 Bonham Strand, Sheung Wan, Hong Kong, or by email to sales@longevitysamui.com.