Privacy First

Data Handling and Participant Privacy

We collect only the personal data necessary for course delivery, enrollment administration, and legally required records. Data is processed to manage registrations, certifications, payments, and communications about course logistics. Access to participant data is restricted to authorized staff, instructors, and trusted service providers who support course delivery. Retention periods reflect operational needs and applicable local regulations. Security controls are applied to protect stored and transmitted personal data, and participants have avenues to review, correct, or request deletion of their information within the bounds of legitimate operational requirements.

30-06-2026
vientrepzix · 152, Thanon Vacharaphol, Bang Khen Sub District, Bangkok District, Bangkok 10220, Thailand · Business ID 1943010989687 · +66945373174
152, Thanon Vacharaphol, Bang Khen Sub District, Bangkok District, Bangkok 10220, Thailand

Foundational Principles

Definitions

This section defines key terms used throughout the privacy policy to ensure clarity about the scope of data processing related to IT security and digital literacy courses delivered by vientrepzix.

Personal data means any information relating to an identified or identifiable natural person, such as name, email, phone number, identifiers, or other information that can reasonably be used to identify an individual in the context of our services.
Processing refers to any operation performed on personal data, whether automated or not, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.
User denotes any person who interacts with the vientrepzix website or services, including prospective students, enrolled learners, instructors, and corporate clients participating in IT security and digital literacy programs.
Service refers to the online and offline educational offerings, course materials, assessments, account management, communications, and administrative activities provided by vientrepzix through the website vientrepzix.digital and associated platforms.
Cookies are small data files stored on a user device by a web browser at the request of the website, used to enable site functionality, remember preferences, and support analytics and improvement of service delivery.

Data Collection

We collect data that is necessary to provide, maintain and improve our IT security and digital literacy courses. Collection principles are limited to what supports course delivery, learner administration, communication, accreditation, and legal obligations.

Types of Data Collected

Data Provided Directly by Users

When you register, enroll, or communicate with us we collect the information you provide to enable course access, certification, billing, and support.

  • Identity and contact details: full name, email address, phone number, mailing address for correspondence and certification.
  • Enrollment and academic data: course selections, enrollment dates, progress records, grades, certificates, and professional credentials when applicable.
  • Payment and billing information: payment card voucher, billing address, and invoicing details collected via secure payment providers.
  • Support and communication content: messages, feedback, support requests, and any user-provided materials submitted as part of coursework.
  • Corporate client details: organization name, business contact persons, purchase orders, and contract information for enterprise training agreements.
  • Optional profile information: professional biography, job title, employer, and public collection links supplied voluntarily for networking or visibility within course cohorts.

Automatically Collected Data

When you access our site and services we automatically collect technical data to operate the platform securely, prevent abuse, and improve user experience.

  • Device and technical data: device type, operating system, browser, IP address, and device identifiers necessary for secure access and session management.
  • Usage and interaction data: pages visited, course modules accessed, time spent on lessons, completion events, and clicks used for analytics and product development.
  • Authentication and security logs: login timestamps, failed access attempts, session metadata and security alerts used to detect and respond to suspicious activity.
  • Cookies and similar technologies: cookies and local storage used for preferences, performance monitoring, and functional features of the learning platform.
  • Performance metrics: aggregated course performance and engagement metrics used internally to improve course design and learner outcomes.
  • Location approximations: country and regional information derived from IP addresses to present localized content and comply with regional requirements.

Data from Third Parties

We may receive information about you from trusted third parties to support payment, authentication, hosting and analytics services. We limit third-party data to what is necessary for operational purposes.

  • Payment processors and invoicing platforms that provide transaction confirmations and billing reconciliation.
  • Identity and authentication providers when users choose third-party sign-in options.
  • Analytics and performance vendors supplying aggregated usage data to help optimize course delivery and platform reliability.

How We Use Data

Purposes of Processing

We process personal data only for specific operational purposes necessary to deliver educational services, maintain platform security, administer accounts, and comply with legal and regulatory obligations in Thailand and other applicable jurisdictions.

  • Provision of educational services: enabling access to courses, delivering learning materials, administering assessments and issuing certificates.
  • Account management: creating, maintaining and securing user accounts, authentication, and handling account-related requests.
  • Payment processing and business administration: facilitating payments, invoicing, refunds and related business records.
  • Customer support and communications: responding to inquiries, sending service notices, updates, and administrative messages.
  • Security, fraud prevention and compliance: monitoring for unauthorized access, contribute incidents and complying with legal obligations.
  • Service improvement and analytics: analyzing aggregated usage to improve course content, platform stability and user experience.
  • Research and educational development: conducting internal, non-identifying research to refine curriculum and training approaches.
  • Legal and regulatory obligations: retention and disclosure as required by applicable law, judicial process, or requests by competent authorities.

Legal Basis for Processing

Where applicable, we rely on appropriate legal bases for processing personal data, which may include contractual necessity, compliance with legal obligations, legitimate interests, and consent for specific optional features.

Cookies and Tracking

Cookies and similar technologies are used to provide essential site functionality, preserve preferences, and collect analytics to improve our educational services. You can manage cookie preferences via your browser or provided controls.

We use session cookies for basic functionality, persistent cookies for preferences and login states, and third-party cookies for analytics and performance measurement provided by authorized vendors.

Cookie categories include strictly necessary cookies, performance and analytics cookies, functional cookies for user experience, and marketing cookies used only with explicit consent.

Users may disable or delete cookies via browser settings or consent controls offered on the site; disabling certain cookies may affect the availability of some features, such as saved progress or single sign-on.

For a detailed cookie list and management options, refer to the Cookie Policy available at vientrepzix.digital/cookie-policy.

Data Sharing and Disclosure

We do not sell personal data. We share information only with authorized service providers, partners and authorities as required, under contractual safeguards and for limited, documented purposes.

  • Service providers and vendors engaged to support learning delivery, hosting, content distribution, payment processing, and customer support.
  • Professional advisors such as auditors, legal counsel, and accountants when necessary to manage legal or business obligations.
  • Corporate customers and training partners when data sharing is necessary for enrollment, corporate reporting or to provide contracted training services.
  • Authorized third parties in response to lawful requests by competent authorities, law enforcement or judicial processes.
  • Aggregated or anonymized data shared for research, benchmarking or service improvement purposes where individuals are not identifiable.
  • Successor entities in the event of a merger, acquisition or sale of business assets, with notice provided to users where feasible and as required by law.

Cross-Border Transfers

Because we use global cloud and service providers, personal data may be transferred to, stored and processed in locations outside Thailand. Transfers are managed with appropriate safeguards and contractually required protections.

Safeguards may include data processing agreements, standard contractual clauses, encryption, access controls, and provider assessments to ensure an adequate level of protection in accordance with applicable data protection laws.

Storage and Retention

Retention Policy

We retain personal data only as long as necessary to deliver services, meet legal obligations, resolve disputes and for legitimate business purposes. Retention periods vary by data type and legal requirements.

Account information is retained for the duration of the relationship and for a defined administrative period thereafter to allow for recordkeeping, alumni services and dispute resolution, typically up to several years in line with business and regulatory requirements.

Support communications and correspondence are kept for a limited time to ensure quality of service and to resolve inquiries; retention duration is determined by operational needs and legal obligations.

Security and access logs are retained to support incident response and fraud prevention. Retention balances forensic needs and privacy considerations and is limited to the period required to contribute and mitigate risks.

When data is no longer required, we securely delete or anonymize it in accordance with documented procedures unless retention is required by law. Users may request deletion consistent with applicable rights and legal constraints.

Security Measures

Security of personal data is a priority. We apply administrative, technical and physical measures proportionate to the sensitivity of the data and aligned with accepted security practices for online education platforms.

  • Technical safeguards: encryption of data in transit (TLS) and, where appropriate, encryption at rest, secure authentication mechanisms, and regular vulnerability scanning.
  • Organizational controls: role-based access management, least-privilege principles, employee security training, background checks for personnel with access to personal data, and incident response procedures.
  • Operational processes: logging and monitoring, secure backup and recovery procedures, third-party due diligence, contractual data protection clauses, and periodic security reviews.

Rights of Users

User Rights Overview

Subject to applicable law, users have rights in relation to their personal data. These rights may be exercised by contacting our data protection contact and will be processed in accordance with legal requirements and identity verification procedures.

  • Right of access: request confirmation of processing and access to personal data we hold about you.
  • Right to rectification: request correction of inaccurate or incomplete personal data.
  • Right to erasure (right to be forgotten): request deletion of personal data where legal bases for retention no longer apply, subject to exceptions under law.
  • Right to restriction of processing: request limitation of processing in certain circumstances, such as disputes over accuracy or lawful basis.
  • Right to data portability: request a machine-readable copy of personal data provided by you where processing is based on consent or contract and is carried out by automated means.
  • Right to object: object to processing based on legitimate interests or direct marketing where applicable.
  • Right to withdraw consent: where processing is based on consent, you may withdraw consent at any time without affecting processing carried out prior to withdrawal.
  • Right to lodge a complaint: contact supervisory or regulatory authorities in Thailand or other competent jurisdictions if you believe your rights have been infringed.

How to Exercise Your Rights

To exercise any rights, contact our privacy team at the address or phone number listed on this page. Requests will be handled after identity verification to protect your privacy. Provide a clear description of the request and any supporting details to expedite processing.

[email protected]

We aim to respond to verified rights requests promptly and in accordance with applicable law. Typically, we will acknowledge receipt within 14 calendar days and provide a substantive response within 30 calendar days, subject to complexity and legal timelines.

GDPR and EU Data Subjects

Where European data protection law applies, including the EU General Data Protection Regulation (GDPR), European users have additional rights and protections. This section explains how those rights may be exercised with respect to our processing activities.

  • Lawful basis and transparency: we document processing activities and provide information about lawful bases, retention periods, and the categories of recipients for personal data transferred outside the EU/EEA.
  • EU transfers and safeguards: when data transfers from the EU/EEA occur, we implement appropriate safeguards such as standard contractual clauses, binding corporate rules, or other mechanisms recognized under applicable data protection frameworks.
  • Access: You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data in a commonly used electronic format.
  • Rectification: If your personal data is inaccurate or incomplete, you may request corrections or completion and we will update records accordingly after verification.
  • Erasure: Where applicable under law, you may request deletion of personal data that is no longer necessary for the purposes for which it was collected, subject to legal and contractual retention requirements.
  • Restriction and objection: You may request restriction of processing or object to specific processing activities, including direct marketing and profiling, in line with applicable legal standards.

If you consider our response unsatisfactory or believe processing violates applicable privacy laws, you may lodge a complaint with the competent supervisory authority in your jurisdiction. For residents of Thailand, this can include contacting the Personal Data Protection Committee or other authorized regulators.

Other Purposes and Legal Basis

Marketing Communications

We may send informational and promotional communications about training courses, events, and resources offered by vientrepzix. Marketing messages are based on your consent or our legitimate interests when permitted by law. You will only receive material aligned with the preferences you provide.

To stop receiving marketing messages, follow the unsubscribe link in any email or update your communication preferences in your account settings. Unsubscribe requests are processed promptly and will not affect transactional messages.

Children and Minors

Our courses are designed for adult learners and professionals. We do not intentionally collect personal data from children under the age required by applicable law. If we become aware of inadvertent collection from a minor, we will take measures to remove the data unless retention is required by law.

Third-Party Links and Embedded Content

Our website may include links, plugins, or content from third parties (for example, learning platforms and analytics providers). These third parties operate under their own privacy policies. We recommend reviewing those policies before providing personal data to external providers.

Changes to This Privacy Notice

We periodically review and update our privacy notice to reflect operational or legal changes. Material changes affecting your rights or the processing of your personal data will be communicated via the email address on file or via prominent notice on the site prior to the change taking effect.