Oasis Spa Privacy Policy

    1. At Oasis Spa run by Destiny Enterprises Co., Ltd. and its affiliates and its affiliates (individually and collectively, "Oasis Spa", "we", "us" or "our"). We take your privacy seriously. We are committed to complying with all data protection laws as are applicable to us. We recognize the importance of the personal data you have entrusted to us and believe that it is our responsibility to properly manage, protect and process your personal data. That is our objective, and this Privacy Policy (“Policy”) will explain exactly what we mean in further detail below.
    2. By using the Services, registering for an account with us, visiting our Oasis Spa Services, you acknowledge and agree that you accept the practices, requirements, and/or policies outlined in this Privacy Policy, and you hereby consent to us collecting, using, disclosing and/or processing your personal data as described herein. IF YOU DO NOT CONSENT TO THE PROCESSING OF YOUR PERSONAL DATA AS DESCRIBED IN THIS PRIVACY POLICY, PLEASE DO NOT USE OUR SERVICES OR ACCESS OUR WEBSITE. If we change our Privacy Policy, we will post those changes or the amended Privacy Policy on our Platform. We reserve the right to amend this Privacy Policy at any time.
    1. Personal data collected when you sign up for membership
      Membership Registration Data: This is the personal data that is provided by you or collected by us to enable you to sign up for an Oasis Spa Membership. This includes your name, mobile phone, home phone, email address, birth date, gender, postal code, and country and details of your transaction history. Some of the personal data we will ask you to provide is required in order to create your account. You also have the option to provide us with some additional personal data in order to make your account more personalized.
    2. Personal data collected through your purchase eGift Certificate
      eGift Purchase Data: This is the personal data that is provided by you or collected by us to enable you to purchase eGift Certificate. This includes your name, your email, your eGift Massage, your receipt email and your receipt name.
    3. Personal data collected through your Oasis Spa Online Booking
      Oasis Spa Online Booking Data: This is the personal data that is provided by you or collected by us to enable you to do an online booking. This includes your name, your email, your mobile phone, additional request to our reservation staff, If you choose to pay by credit card, we will provide your personal data to our payment processes If you choose to pay by WeChat or Alipay, we will collect transaction date time and payment type.
    1. As with most websites, your device sends information which may include data about you that gets logged by a web server when you browse our website. This typically includes without limitation your device’s Internet Protocol (IP) address, computer/mobile device operating system and browser type, type of mobile device, the characteristics of the mobile device, the unique device identifier (UDID) or mobile equipment identifier (MEID) for your mobile device, the address of a referring web site (if any), the pages you visit on our website and mobile applications and the times of visit, and sometimes a "cookie" (which can be disabled using your browser preferences) to help the site remember your last visit. The information is also included in anonymous statistics to allow us to understand how visitors use our site.
    2. Our Oasis Spa website may collect precise information about the location of your device using technologies such as GPS, Wi-Fi, etc. We collect, use, disclose and/or process this information for one or more Purposes including, without limitation, location-based services that you request or to deliver relevant content to you based on your location or to allow you to share your location to other Users as part of the services under our website. For most mobile devices, you are able to withdraw your permission for us to acquire this information on your location through your device settings. If you have questions about how to disable your mobile device's location services, please contact your mobile device service provider or the device manufacturer.
    Description of why Oasis Spa processes your personal data (‘processing purpose’) Categories of personal data used by Oasis Spa for the processing purpose
    To provide, personalize, and improve your experience with the Oasis Spa Service, for example by providing customized, personalized, or localized content, recommendations.
    • Membership Registration Data
    • eGift Certificate Data
    • Online Booking Data
    To process your payment to prevent or detect fraud including fraudulent payments and fraudulent use of the Oasis Spa.
    • eGift Certificate Data
    • Membership Registration Data
    • Online Booking Data
    To communicate with you:
    marketing, research, promotional purposes,  via emails, notifications, or other messages, consistent with any permissions you may have communicated to us
    • eGift Certificate Data
    • Membership Registration Data
    • Online Booking Data
    If you require further information about the balancing test that Oasis Spa has undertaken to justify its reliance on the legitimate interest legal basis under the GDPR, please see Section 13 ‘How to contact us’ for further details on how to contact us.
    1. We may from time to time implement "cookies" or other features to allow us or third parties to collect or share information that will help us improve our Platform and the Services we offer, or help us offer new services and features. “Cookies” are identifiers we transfer to your computer or mobile device that allow us to recognize your computer or device and tell us how and when the Services or Platform are used or visited, by how many people and to track activity within our Platform. We may link cookie information to personal data. Cookies also link to information regarding what items you have selected for purchase and pages you have viewed. This information is used to keep track of your purchase details, for example. Cookies are also used to deliver content specific to your interest and to monitor usage of the Services.
    2. You may refuse the use of cookies by selecting the appropriate settings on your browser. However, please note that if you do this you may not be able to use the full functionality of our Platform or the Services.

    We keep your personal data only as long as necessary to provide you with the Oasis Spa Service and for legitimate and essential business purposes, such as maintaining the performance of the Oasis Spa Service, making data-driven business decisions about new features and offerings, complying with our legal obligations, and resolving disputes. We keep some of your personal data for as long as you are a user of the Oasis Spa Service. If you request, we will delete your personal data so that it no longer identifies you, unless, we are legally allowed or required to maintain certain personal data, including situations such as the following:

    • If there is an unresolved issue relating to your account, such as an outstanding credit on your account or an unresolved claim or dispute we will retain the necessary personal data until the issue is resolved;
    • Where we are required to retain the personal data for our legal, tax, audit, and accounting obligations, we will retain the necessary personal data for the period required by applicable law; and/or, where necessary for our legitimate business interests such as fraud prevention or to maintain the security of our users.
    1. Our Platform uses Google Analytics, a web analytics service provided by Google, Inc. ("Google"). Google Analytics uses cookies, which are text files placed on your device, to help the Platform analyses how Users use the Website. The information generated by the cookie about your use of the Website (including your IP address) will be transmitted to and stored by Google on servers in the United States. Google will use this information for the purpose of evaluating your use of the Website, compiling reports on website activity for website operators and providing other services relating to website activity and Internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google's behalf. Google will not associate your IP address with any other data held by Google.
    2. We, and third parties, may from time to time make software applications downloads available for your use via the Website or through the Services. These applications may separately access, and allow a third party to view, your identifiable information, such as your name, your user ID, your device’s IP Address or other information such as any cookies that you may previously have installed or that were installed for you by a third party software application or website. Additionally, these applications may ask you to provide additional information directly to third parties. Third party products or services provided through these applications are not owned or controlled by Oasis Spa. You are encouraged to read the terms and other policies published by such third parties on their websites or otherwise.
    1. We implement a variety of security measures to ensure the security of your personal data on our systems. User personal data is contained behind secured networks and is only accessible by a limited number of employees who have special access rights to such systems. We will retain personal data in accordance with the Privacy Laws and/or other applicable laws. That is, we will destroy or anonymize your personal data when we have reasonably determined that (i) the purpose for which that personal data was collected is no longer being served by the retention of such personal data; (ii) retention is no longer necessary for any legal or business purposes; and (iii) no other legitimate interests warrant further ration of such personal data. If you cease using the Website, or your permission to use the Website and/or the Services is terminated, we may continue storing, using and/or disclosing your personal data in accordance with this Privacy Policy and our obligations under the Privacy Laws. Subject to applicable law, we may securely dispose of your personal data without prior notice to you.
    1. In conducting our business, we will/may need to disclose your personal data to our third party service providers, agents and/or our affiliates or related corporations, and/or other third parties, whether sited in Thailand or outside of Thailand, for one or more of the above-stated Purposes. Such third-party service providers, agents and/or affiliates or related corporations and/or other third parties would be processing your personal data either on our behalf or otherwise, for one or more of the above-stated Purposes. Such third parties include, without limitation:
      • our subsidiaries, affiliates and related corporations; contractors, agents, service providers and other third parties we use to support our business. These include but are not limited to those which provide administrative or other services to us such as mailing houses, telecommunication companies, information technology companies and data centers;
      • a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution or other sale or transfer of some or all of Oasis Spa’s assets, whether as a going concern or as part of bankruptcy, liquidation or similar proceeding, in which personal data held by Oasis Spa about our Service Users is among the assets transferred; or to a counterparty in a business asset transaction that Oasis Spa or any of its affiliates or related corporations is involved in; and
      • third parties to whom disclosure by us is for one or more of the Purposes and such third parties would in turn be collecting and processing your personal data for one or more of the Purposes
    1. WE DO NOT GUARANTEE THE SECURITY OF PERSONAL DATA AND/OR OTHER INFORMATION THAT YOU PROVIDE ON THIRD PARTY SITES. We do implement a variety of security measures to maintain the safety of your personal data that is in our possession or under our control. Your personal data is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems and are required to keep the personal data confidential. When you place orders or access your personal data, we offer the use of a secure server. All personal data or sensitive information you supply is encrypted into our databases to be only accessed as stated above.
    2. In an attempt to provide you with increased value, we may choose various third-party websites to link to, and frame within, the Website. We may also participate in co-branding and other relationships to offer e-commerce and other services and features to our visitors. These linked sites have separate and independent privacy policies as well as security arrangements. Even if the third party is affiliated with us, we have no control over these linked sites, each of which has separate privacy and data collection practices independent of us. Data collected by our co-brand partners or third-party web sites (even if offered on or through our Website) may not be received by us.
    3. We therefore have no responsibility or liability for the content, security arrangements (or lack thereof) and activities of these linked sites. These linked sites are only for your convenience and you therefore access them at your own risk. Nonetheless, we seek to protect the integrity of our Website and the links placed upon each of them and therefore welcome any feedback about these linked sites (including, without limitation, if a specific link does not work).

    Your personal data and/or information may be transferred to, stored or processed outside of your country. In most cases, your personal data will be processed in Thailand, where our servers are located, and our central database is operated. Oasis Spa will only transfer your information overseas in accordance with Privacy Laws.

    1. Withdrawing Consent
      1. You may withdraw your consent for the collection, use and/or disclosure of your personal data in our possession or under our control by sending an email to our Personal Data Protection Officer at  cs@oasisspa.net . However, your withdrawal of consent may mean that we will not be able to continue providing the Services to you and we may need to terminate your existing relationship and/or the contract you have with us.
    2. Requesting Access to or Correction of Personal Data
      1. If you have an account with us, you may personally access and/or correct your personal data currently in our possession or control through the Account Settings page on the Website. If you do not have an account with us, you may request to access and/or correct your personal data currently in our possession or control by submitting a written request to us. We will need enough information from you in order to ascertain your identity as well as the nature of your request so as to be able to deal with your request. Hence, please submit your written request by sending an email to our Personal Data Protection Officer at  cs@oasisspa.net
      2. We may charge you a reasonable fee for the handling and processing of your requests to access your personal data. If we so choose to charge, we will provide you with a written estimate of the fee we will be charging. Please note that we are not required to respond to or deal with your access request unless you have agreed to pay the fee.
      3. We reserve the right to refuse to correct your personal data in accordance with the provisions as set out in Privacy Laws, where they require and/or entitle an organization to refuse to correct personal data in stated circumstances.

    If you have any questions or concerns about our privacy practices, we welcome you to contact us by e-mail at cs@oasisspa.net.