Key Definitions
This section defines the main terms used in the policy to make it easier to follow practical cases and examples throughout the document.
- Personal data means any information that identifies or could reasonably identify an individual, such as name, email, phone number, position, company affiliation, billing information and other registration details provided when enrolling in a course or requesting information.
- Processing refers to any operation performed on personal data, including collection, recording, organization, storage, retrieval, use, disclosure, transmission, anonymization and deletion. We outline processing steps with illustrative scenarios in workshop documentation.
- User describes any visitor to the website, registered participant in a training program, prospective client who requests information, or an individual whose data is otherwise handled in the course of delivering our services.
- Service encompasses the educational programs, workshops, online content, newsletters and customer support provided by aeroitlaw related to executive economic training and leadership development.
- Cookies are small text files placed on a device when a user visits our website. They store identifiers and preferences used to enable site functionality, analytics and performance features.
Data We Collect
We collect data directly from users, automatically through site interactions, and from third parties where necessary to deliver services. Below are practical examples tied to case-workflows.
Data You Provide
Examples and scenarios where we collect data directly: enrollment forms for a director-level cohort, consultation booking, or email correspondence about a corporate training case study.
- Contact details: full name, professional title, company name and work email used when registering for programs.
- Communication content: messages and attachments platform with our team when consulting on business scenarios or scheduling sessions.
- Billing and payment details provided to complete invoices for training services and events; we use third-party payment processors to minimize retention of full card data.
- Profile and preference information such as industry sector, team size, strategic priorities and session interests collected to tailor case studies and group exercises.
- Feedback and evaluation responses following workshops and scenario exercises used to refine curricula and document practical outcomes.
- Optional documentation submitted for case reviews, including anonymized business summaries or operational reports used in scenario analysis with participant consent.
Data Collected Automatically
When you interact with aeroitlaw.pro we collect technical data to operate and improve the site and to analyze engagement with our case materials.
- Device and browser information such as operating system, browser type and screen resolution used to ensure training materials display correctly across devices.
- IP address and approximate location used for security monitoring and to localize content and event availability relevant to Thailand-based directors.
- Usage data including pages visited, time spent on case studies and resources, and navigation paths to help optimize learning flows.
- Cookie identifiers and similar tracking vouchers used to remember preferences and to deliver essential site functionality.
- Performance and error logs that capture failures in course materials or registration systems so we can resolve operational issues promptly.
- Analytics signals from third-party platforms that aggregate anonymized engagement metrics to support curriculum development decisions.
Data From Third Parties
We may obtain information from trusted partners to complete transactions, verify identity for paid programs, or enrich participant profiles for tailored case exercises.
- Payment processors and invoicing services providing confirmation of completed transactions and limited billing identifiers necessary to manage registrations.
- Professional networking or verification services that help confirm company affiliation and role when organizing director-level cohorts.
- Analytics and performance providers that offer aggregated insights about site usage to improve training content.
How We Use Your Data
We process personal data for clear, specific purposes tied to program delivery and service improvement. Below are practical use cases accompanied by examples.
- To register and administer participation in training programs and events, including scheduling, providing course materials and issuing certificates.
- To communicate with participants about session logistics, changes to case study materials, and follow-up resources related to workshop scenarios.
- To process payments and manage billing for paid programs, including invoicing and reconciliation with external payment partners.
- To personalize learning content and recommend case studies based on the participant's sector, leadership level, and indicated priorities.
- To analyze program effectiveness using anonymized feedback and usage data so we can refine practical cases and improve outcomes for future cohorts.
- To detect, prevent and respond to fraud, abuse or other unlawful activities that could affect program integrity and participant safety.
- To comply with applicable legal obligations, respond to lawful requests from authorities, and protect legal rights in dispute scenarios.
- To send marketing communications where consent has been obtained, such as announcements about new case-based modules or executive retreats relevant to directors.
Legal Bases for Processing
When we process personal data relating to individuals in the EU or where applicable, we rely on appropriate legal bases. For Thailand-based participants, we follow local requirements and applicable international standards.
- Consent: where you have provided explicit permission for specific activities like marketing communications or use of personal case materials.
- Contractual necessity: processing required to fulfill an agreement to provide training services and manage registrations or payments.
- Legal obligation: processing necessary to comply with statutory requirements such as tax and corporate reporting tied to paid services.
- Legitimate interests: for security, fraud prevention, and operational improvements where such interests are balanced against individual rights and freedoms.
EU Data Protection and Rights
For individuals subject to EU data protection rules, we describe rights and processes to exercise those rights. We also provide examples of how a director or executive might request data related to a specific cohort or case study.
- Right of access: you can request a copy of personal data we hold about you, including enrollment records and submitted feedback.
- Right to rectification: you may ask us to correct inaccurate or incomplete information, for example an incorrect professional title used in cohort materials.
- Right to erasure: in certain circumstances you can request deletion of personal data, subject to retention requirements for legal or accounting records.
- Right to restriction of processing: you may request limits on how we use your data while a dispute about accuracy or purpose is resolved.
- Right to data portability: where applicable, you can request structured, machine-readable copies of data you provided directly to us.
- Right to object: you can object to processing based on legitimate interests or to direct marketing; we will review objections in light of applicable laws and operational needs.
Cookies and Tracking Technologies
We use cookies and similar technologies to deliver core site functions, measure engagement with our case materials, and support personalization. Below we explain types and how to manage them.
Cookies can be session-based (expire when you close the browser) or persistent (remain for a set period). We use first-party cookies for essential features and third-party cookies for analytics and optional services.
Categories include strictly necessary cookies for site operation, performance cookies for analytics, preference cookies to remember settings, and marketing cookies used only with consent.
You can manage cookies via your browser settings to block or delete them. Note that disabling certain cookies may prevent access to parts of the site, such as secure registration pages or course content delivery.
Detailed Cookie Policy
How We Share Data
We limit sharing to parties necessary to deliver training programs and fulfill legal obligations. Below are common sharing scenarios illustrated by examples.
- Service providers such as payment processors and event management platforms that handle registrations and invoicing on our behalf.
- Analytics providers that aggregate anonymized engagement data to evaluate effectiveness of specific case study modules.
- Affiliates or partners when jointly delivering programs, always under contractual restrictions on use and confidentiality.
- Legal and regulatory authorities when required to comply with laws or respond to valid legal processes, such as tax audits relating to paid courses.
- Professional advisors, for example auditors or legal counsel, who require access to limited records for compliance reviews.
- Potential buyers or partners in the event of a business transaction, where data sharing would be scoped to support due diligence and subject to confidentiality safeguards.
International Data Transfers
Because we use global service providers, personal data may be transferred to, and processed in, countries outside your country of residence. Transfers are limited to necessary recipients and handled with appropriate protections.
We implement safeguards such as standard contractual clauses, review of provider security practices, and where appropriate rely on providers in jurisdictions with adequate protections or obtain consent for specific transfers.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described and to meet legal and business requirements. Practical retention examples are listed below.
Account and registration records are retained for the duration of your relationship and typically for up to seven years afterward for accounting and tax compliance related to paid programs.
Communications such as email platform and support tickets are retained for up to three years, unless required longer for dispute resolution or where you request deletion and no legal requirement prevents it.
Technical logs and analytics data are retained in aggregated or anonymized form for up to two years to support product improvements and incident contribute.
When retention periods expire or you request deletion where allowed, we securely remove data from primary systems and schedule deletion from backups in accordance with our data lifecycle procedures.
Security Measures
We apply a combination of technical, administrative and physical safeguards to protect personal data. Measures are chosen to be appropriate to the sensitivity of the information and the nature of our services to business leaders.
- Encryption of data in transit using TLS and encryption at rest for sensitive records where feasible.
- Access controls and role-based permissions limiting internal access to personal data to staff and contractors with a legitimate need.
- Regular security assessments, patch management, and incident response plans to detect and address potential breaches promptly.
Your Privacy Choices and Rights
You can exercise rights to access, correct or limit processing of your personal data. For practical assistance, examples and typical response timelines are provided below.
- Access: request a copy of data we hold about you and an explanation of how it is used in specific case-study contexts.
- Correction: request updates to incorrect information such as a change in job title or company affiliation used in cohort materials.
- Deletion or restriction: request removal or limitation of processing where permissible, noting legal or contractual retention obligations may apply.
- Objection and marketing preferences: opt out of direct marketing communications and object to processing carried out on legitimate interests, which we will evaluate and respond to promptly.
- Restriction of processing: request limitation on specific uses of personal data, for example during a dispute about accuracy.
- Data portability: request receipt of provided personal data in a common, machine-readable format for transfer to another service.
- Right to lodge a complaint: file a complaint with a supervisory authority in Thailand if you consider our response insufficient.
- Right to withdraw consent: when processing is based on consent, you may withdraw that consent for future processing without affecting prior lawful processing.
How to exercise your data rights
To exercise any of the rights listed, please contact our data protection team with a clear description of the request and supporting information to help us verify your identity. Practical cases: 1) If an executive requests data portability to migrate payroll records to a new provider, specify the date range and data types; 2) if a director disputes data accuracy, provide examples and documents that show the discrepancy. Send requests through the contact channels below; include your full name, business affiliation, and Business ID if relevant.
[email protected]
We aim to respond to verifiable requests within 30 calendar days. Complex requests or requests requiring third-party coordination may require up to 60 days; we will notify you if an extension is necessary and explain the reasons.
Marketing communications
We may send marketing information about aeroitlaw training, workshops, and events to contacts who opt in. Marketing uses include announcements about economic training sessions that combine business strategies with spiritual leadership topics tailored for directors and business owners. Examples: invitation to a case-study workshop on fiscal mindfulness for SMEs, or an executive retreat focused on value-based resources allocation. Recipients can manage preferences or opt out at any time.
To stop receiving marketing emails, use the unsubscribe link in any marketing email or contact us. Following an unsubscribe request, we will update the preference for future mailings within a reasonable period. Unsubscribe requests do not remove transactional or administrative communications related to active registrations or purchases.
Children's privacy
aeroitlaw materials and services are directed at professionals and business audiences. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a minor without parental consent, we will take steps to delete that information. Example scenario: if an underage participant registers for an executive training by error, we will verify age and remove the record if no lawful consent is available.
Third-party links
Our site and materials may link to third-party sites for case studies, registration platforms, or partner content. These external sites have their own privacy practices. Practical note: when a director registers for a partner-hosted retreat via a third-party booking platform, personal details entered on the partner site are subject to that platform's policy, not aeroitlaw's.
Changes to this privacy policy
This policy was made effective on 24-04-2026. We may revise the policy to reflect changes in legal requirements or service offerings. When we update the policy, we will post a revised version at aeroitlaw.pro/privacy and indicate the effective date. For significant changes that affect how we use personal data in marketing or sharing with partners, we will provide a prominent notice or direct communication to affected contacts.