Privacy Policy
This Privacy Policy explains how Shloka Events Co., Ltd. ("Shloka Events", "we", "us" or "our")
collects, uses and protects personal data when you visit
www.shlokamice.com, contact us, subscribe to our newsletter or otherwise
interact with our website.
We take the protection of personal data seriously and process personal data in accordance
with applicable data protection law, including, where applicable, Regulation (EU) 2016/679,
the General Data Protection Regulation ("GDPR").
1. Data Controller
The controller responsible for the processing of personal data through this website is:
Shloka Events Co., Ltd.
125/5 Soi Ruam Rudee
Ploenchit Road
Bangkok 10330
Thailand
Privacy Contact: Catherine Pucher
Email:
info@shlokaevents.com
Website:
www.shlokamice.com
2. Personal Data We Process
Depending on how you use our website and services, we may process the following categories
of personal data:
- your name and contact details;
- your email address and telephone number;
- company or organisation information that you voluntarily provide;
- information contained in enquiries or messages sent to us;
- information relating to a planned event or requested service;
- newsletter subscription information;
- technical connection information such as browser and user-agent information;
- requested URLs and referring URLs;
- anonymised IP information used for technical and security logging;
- information relating to website errors and requests for pages that cannot be found; and
- aggregated website usage and traffic information.
We seek to limit the collection of personal data to information that is necessary
for the relevant purpose.
3. Contact Form and Enquiries
Our website provides a contact form which you may use to send us enquiries about our services,
events or other matters. You may also contact us directly by email, telephone or other
communication channels.
When you contact us, we process the information you provide. Depending on the information entered,
this may include:
- your name;
- your email address;
- your telephone number;
- your company or organisation;
- information relating to a planned event or requested service; and
- the content of your message.
We use this information to process and respond to your enquiry and, where appropriate,
to prepare or perform a business relationship with you.
Where the GDPR applies, the legal basis for this processing is Article 6(1)(b) GDPR
where your enquiry concerns a contract or steps taken at your request before entering
into a contract.
For general enquiries, the legal basis is our legitimate interest pursuant to
Article 6(1)(f) GDPR in communicating with prospective clients, existing clients,
business partners and other persons contacting us.
Information submitted through the contact form or by other means is retained only for
as long as necessary to process the enquiry and manage any subsequent business relationship,
subject to applicable legal, contractual, tax or accounting retention requirements.
4. Newsletter
You may subscribe to our newsletter through our website.
If you subscribe, we process your email address and any other information that you
voluntarily provide for the purpose of sending you news, updates, event information
and information about Shloka Events and our services.
Where the GDPR applies, the legal basis for sending our newsletter is your consent
pursuant to Article 6(1)(a) GDPR.
You may withdraw your consent at any time by using the unsubscribe option contained
in our newsletter communications or by contacting us at
info@shlokaevents.com.
Withdrawal of consent does not affect the lawfulness of processing carried out
before consent was withdrawn.
Newsletter subscription information is normally retained until you unsubscribe
or otherwise withdraw your consent.
We may retain limited information where necessary to document that consent was given
or withdrawn, to prevent further communications after an unsubscribe request,
or to comply with applicable legal obligations.
5. Website Hosting and Server Logs
When you visit our website, the server hosting the website necessarily processes certain
technical information in order to deliver the requested pages and maintain the security,
availability and stability of the website.
Depending on the configuration of the hosting infrastructure, this information may include:
- IP address;
- date and time of the request;
- requested URL or file;
- referring page;
- browser and operating system information;
- HTTP status information; and
- user-agent information.
This information may be processed for purposes including:
- delivering the website;
- maintaining technical stability;
- diagnosing website problems;
- detecting misuse;
- detecting automated or malicious requests;
- protecting the website against attacks; and
- maintaining the security of our systems.
Where the GDPR applies, this processing is based on our legitimate interests pursuant to
Article 6(1)(f) GDPR in operating a secure, reliable and technically functional website.
Server log information is retained only for as long as reasonably necessary for security,
technical administration and troubleshooting purposes, unless longer retention is necessary
in connection with a specific security incident, legal claim or legal obligation.
6. Website Analytics with Fathom Analytics
We use Fathom Analytics to understand how our website is used and
to improve its content, performance and usability.
Fathom Analytics is designed as a privacy-focused website analytics service and does not
use conventional analytics cookies to track visitors across websites.
When you visit our website, certain technical information may be temporarily processed
in order to generate privacy-preserving website statistics.
This may include technical information such as your IP address, browser information,
user agent, referring page and requested page.
Fathom processes this information in a manner designed to avoid creating persistent
individual visitor profiles.
For visitors located in the European Union, Fathom provides European processing infrastructure
designed to prevent directly identifying EU visitor data from being transferred outside
the European processing environment before it has been anonymised.
We use Fathom Analytics to obtain information such as:
- the number of visits to our website;
- the pages viewed;
- referring websites or sources;
- general device and browser information; and
- aggregate information about how visitors use the website.
We do not use Fathom Analytics to build advertising profiles of individual visitors
or to track visitors across unrelated websites.
Where the GDPR applies, the legal basis for this processing is our legitimate interest
pursuant to Article 6(1)(f) GDPR in understanding the overall use of our website,
improving our services and maintaining an effective online presence while minimising
the collection of personal information.
Fathom Analytics acts as a processor for relevant personal data processed on our behalf.
Further information about Fathom Analytics and its privacy practices is available at:
https://usefathom.com/privacy
7. Redirect and 404 Error Logging
We use the WordPress plugin Redirection to manage URL redirects and
to identify requests for pages, files or other resources that cannot be found on our
website ("404 errors").
404 monitoring helps us identify:
- broken internal or external links;
- outdated URLs;
- incorrectly indexed website addresses;
- technical problems following changes to the website;
- automated bot activity;
- repeated requests for non-existent resources;
- suspicious requests; and
- patterns that may indicate attempted misuse or attacks against the website.
Depending on the type of request, the Redirection logs may contain information such as:
- the requested URL;
- the destination URL of a redirect;
- date and time of the request;
- referring URL;
- browser or user-agent information;
- HTTP request information; and
- an anonymised version of the requesting IP address.
We have configured Redirection to anonymise IP addresses stored in its logs.
The full IP address is therefore not retained by the Redirection logging system.
Redirection operates locally within our WordPress installation.
The plugin does not require this logging information to be transmitted to the plugin developer
or another external service as part of its normal operation.
The purpose of this processing is to maintain the technical integrity and security
of the website, identify broken links and redirects, diagnose errors, detect suspicious
or automated traffic and protect the website against misuse.
Where the GDPR applies, the legal basis is our legitimate interest pursuant to
Article 6(1)(f) GDPR in maintaining a functional, secure and technically reliable website
and protecting our website and infrastructure against misuse and attacks.
404 and redirect log information is retained for a limited period required for technical,
security and troubleshooting purposes and is subsequently deleted automatically or manually.
8. Optional External Lookup Functions
The Redirection plugin includes optional administrative functions that can obtain additional
information about an IP address, URL or browser user agent through external services.
These functions are not required for the normal operation of the website and are not
automatically performed when you visit the website.
If such a function is deliberately used by a website administrator, the particular item
being looked up, such as an IP address, URL or user-agent string, may be transmitted to
the external service used to perform the lookup.
These administrative lookup functions are separate from the ordinary 404 and redirect
logging described above.
9. Website Security
We process technical information where necessary to protect our website, infrastructure
and visitors against security threats.
This may include analysing server logs, 404 requests and patterns of automated traffic
to identify activities such as:
- attempted unauthorised access;
- malicious automated scanning;
- requests for known vulnerable files or software;
- spam or abusive requests;
- denial-of-service activity;
- attempted exploitation of website vulnerabilities; and
- other behaviour that may threaten the security or availability of the website.
Where the GDPR applies, such processing is based on our legitimate interest pursuant to
Article 6(1)(f) GDPR in ensuring the security, integrity and availability of our website
and information systems.
10. Cookies and Similar Technologies
Our Fathom Analytics implementation does not rely on analytics cookies for conventional
cross-site or behavioural tracking.
The website may nevertheless use technically necessary cookies or similar storage
mechanisms where these are required for essential WordPress functionality, website security,
forms, user preferences or website administration.
Technically necessary technologies may be used where they are required to provide
the website or a feature requested by the visitor.
If we introduce non-essential cookies or comparable technologies in the future for which
consent is required under applicable law, those technologies will only be activated
after the required consent has been obtained.
11. Service Providers and Recipients
We may use selected service providers to operate and maintain our website and business systems.
Where service providers process personal data on our behalf, they are required,
where applicable, to process personal data in accordance with our instructions and
applicable data protection law.
Depending on the circumstances, recipients of personal data may include:
- website hosting and infrastructure providers;
- email and communication providers;
- newsletter and mailing infrastructure providers;
- website maintenance and technical service providers;
- Fathom Analytics for privacy-focused website analytics; and
- other technical providers necessary to operate, maintain or secure the website.
Access to personal data is limited to persons and service providers who require access
for the relevant purpose.
We do not sell personal data.
12. International Processing and Transfers
Shloka Events is established in Thailand and provides services internationally.
As a result, information you provide to us may be processed in Thailand or other countries
outside the European Economic Area ("EEA").
This may occur, for example, where you contact Shloka Events from within the European Union
and your enquiry is received and processed by our team in Thailand.
Where the GDPR applies and personal data is transferred from the EEA to a country that
is not subject to an adequacy decision of the European Commission, we take appropriate
measures where required by applicable data protection law to protect the transferred information.
Depending on the circumstances, safeguards may include contractual protections,
Standard Contractual Clauses approved by the European Commission or another legally
recognised transfer mechanism.
Where service providers process personal data internationally, we take their processing
locations and applicable safeguards into account when selecting and using those providers.
13. Data Retention
We retain personal data only for as long as necessary for the purpose for which it was
collected and to comply with applicable legal, contractual, accounting, tax or security requirements.
The applicable retention period depends on the nature of the information and the reason
for which it is processed.
For example:
- contact and enquiry information is retained for as long as necessary to respond
to the enquiry and manage any resulting business relationship; - newsletter information is generally retained until consent is withdrawn or
the recipient unsubscribes; - technical and security logs are retained for a limited period necessary for
security, troubleshooting and website administration; and - information required by law may be retained for the applicable statutory period.
When personal data is no longer required, it is deleted, anonymised or otherwise removed
from active use, subject to applicable legal retention requirements.
14. Legal Bases for Processing
Where the GDPR applies, we process personal data only where a lawful basis exists.
Depending on the circumstances, this may include:
- Consent, Article 6(1)(a) GDPR
Where you have voluntarily agreed to a particular processing activity,
such as receiving our newsletter. - Contract and pre-contractual measures, Article 6(1)(b) GDPR
Where processing is necessary to perform a contract with you or to take steps
at your request before entering into a contract. - Legal obligation, Article 6(1)(c) GDPR
Where processing is necessary to comply with a legal requirement applicable to us. - Legitimate interests, Article 6(1)(f) GDPR
Where processing is necessary for our legitimate business, communication,
technical, analytical or security interests and those interests are not overridden
by your fundamental rights and freedoms.
15. Our Legitimate Interests
Where we rely on Article 6(1)(f) GDPR, our legitimate interests may include:
- operating and maintaining our website;
- communicating with clients and prospective clients;
- responding to enquiries;
- understanding how our website is used;
- improving the content and performance of our website;
- identifying technical errors and broken links;
- detecting automated, suspicious or malicious traffic;
- preventing misuse and attempted attacks;
- maintaining the security of our website and IT systems; and
- establishing, exercising or defending legal claims where necessary.
16. Your Data Protection Rights
Where the GDPR applies to the processing of your personal data, you have the rights
provided by applicable data protection law.
Depending on the circumstances, these may include the right to:
- request access to personal data we hold about you;
- request correction of inaccurate or incomplete personal data;
- request deletion of your personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive certain personal data in a structured, commonly used and
machine-readable format; - request transmission of eligible data to another controller where applicable;
- withdraw consent at any time where processing is based on consent; and
- lodge a complaint with a competent data protection supervisory authority.
Not all rights apply in every circumstance, and certain rights may be subject to
statutory conditions or exceptions.
To exercise your rights or ask questions concerning your personal data, please contact:
info@shlokaevents.com.
17. Right to Object
Where we process your personal data on the basis of legitimate interests under
Article 6(1)(f) GDPR, you have the right to object to that processing on grounds
relating to your particular situation.
If we process personal data for direct marketing purposes, you have the right to
object to such processing at any time.
Where you object to direct marketing, your personal data will no longer be processed
for that purpose.
18. Withdrawal of Consent
Where processing is based on your consent, you may withdraw that consent at any time.
Withdrawal of consent does not affect the lawfulness of any processing carried out
on the basis of your consent before it was withdrawn.
You may withdraw consent by using any unsubscribe functionality provided for the relevant
service or by contacting us at
info@shlokaevents.com.
19. Complaints
If you believe that the processing of your personal data infringes applicable data
protection law, you may contact us directly so that we can address your concerns.
Where the GDPR applies, you also have the right to lodge a complaint with a competent
data protection supervisory authority in the European Union, in particular in the
Member State of your habitual residence, your place of work or the place of the alleged infringement.
20. Data Security
We implement appropriate technical and organisational measures designed to protect
personal data against accidental or unlawful destruction, loss, alteration, unauthorised
disclosure or unauthorised access.
Measures may include, where appropriate:
- access controls;
- secure website connections;
- software and system maintenance;
- security monitoring;
- restricted administrative access;
- logging and analysis of suspicious requests;
- backup procedures; and
- other measures appropriate to the risks involved.
Security measures are reviewed and adjusted where appropriate in light of the nature
of the information, the risks involved and developments in technology.
21. Third-Party Websites
Our website may contain links to websites operated by third parties.
We are not responsible for the privacy practices or content of external websites.
When you leave our website, personal data processed by the destination website is
subject to the privacy practices of that website operator.
22. Automated Decision-Making
We do not use personal data collected through this website to make decisions based
solely on automated processing that produce legal effects concerning you or similarly
significantly affect you within the meaning of Article 22 GDPR.
23. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our website,
services, technical systems, data processing activities or applicable legal requirements.
The current version of this Privacy Policy will be published on this website.
24. Contact
If you have questions about this Privacy Policy, wish to exercise your data protection
rights, or have any other questions concerning the processing of your personal data,
please contact:
Shloka Events Co., Ltd.
Attn: Catherine Pucher
125/5 Soi Ruam Rudee
Ploenchit Road
Bangkok 10330
Thailand
Email:
info@shlokaevents.com
Website:
www.shlokamice.com
Last updated: 31 August 2026
