Thai-Russian Chamber of Commerce

Become a member

TRCC / Legal & Privacy

Privacy Policy

The Thai-Russian Chamber of Commerce ("TRCC", "we", "our", or "us") explains here how it handles personal data submitted through, or generated by use of, the TRCC website.

Optional measurement

Daily consenting-browser estimate

Allowing sets a random first-party browser identifier for 90 days. TRCC turns it into a different pseudonym for each Bangkok day and excludes confirmed or probable automation. This estimates browsers, not people.

No choice is preselected. The site works either way.

Coverage counts consenting page views, not a percentage of people. Browsers that block or remove the cookie are not linkable, and one person may use several browsers or devices.

At a glance

A clear view of how information is handled.

This policy covers visitors, members, membership applicants, event participants, inquiry senders, and other people who interact with TRCC website services.

Controller identity

The controller for the processing described in this policy is Thai-Russian Chamber of Commerce (TRCC), หอการค้าไทย-รัสเซีย. Its public office address is shown in the contact details below.

Information we may collect

Depending on the service used, TRCC may collect:

  • names, contact details, position, and representative information;
  • company, organization, professional, registration, residence, and business-classification information used in a membership application;
  • event registration choices, attendance information, and related communications;
  • inquiry subjects and messages;
  • supporting documents, including a passport or national ID, representative photo, registration documents, or payment proof where the relevant workflow requests them;
  • independent publication choices for member-directory or representative information;
  • technical and security information such as request time and status, a normalized successful public-page path or safety-screened queryless public 404 path, a bounded public 404 method class, network country, referral domain, robot classification, form-protection events, and short-lived operational server logs. If a visitor explicitly allows optional daily audience measurement, the browser also receives a random first-party identifier and the server derives a different keyed pseudonym for each Bangkok day. A network address and user agent may be processed transiently for country and robot classification of successful requests but are not retained in the site-statistics counters or used to derive the audience pseudonym.

Membership applications

TRCC uses membership application information to receive and review an application, verify applicant and supporter details, communicate about the application, make membership decisions, request or review supporting documents and payment proof where applicable, and create membership records after approval.

Submitting an application does not itself create a public profile. Public directory fields and a representative photo may be shown only after the relevant independent permission, membership conversion, TRCC review, and public eligibility checks.

Event registration

TRCC uses event registration information to administer attendance, capacity and waitlists, communicate registration decisions and event details, manage event operations, and review payment proof where a selected registration option requires it.

Registration data and payment proof are private operational records. They are not public event content unless a separate, clearly identified publication permission and review process applies.

Contact and inquiry forms

TRCC uses information submitted through contact and inquiry forms to review the message, route it to the responsible operator, respond to the sender, protect the form from abuse, and keep an appropriate communication record.

General inquiry forms are not intended for unnecessary identity documents, financial data, or other sensitive information.

Required and optional information

Required fields are identified in the relevant form. If required information, an acknowledgement, or a required supporting file is not supplied, TRCC may be unable to accept, evaluate, or complete the requested application, registration, inquiry, or payment-review step.

Optional fields and separate publication choices may be left blank or unselected. A publication choice does not approve an application or make information public by itself.

Purposes and processing grounds

TRCC processes personal data for the service requested by the person, for administration of membership and events, for communications, for record keeping, for website security and abuse prevention, and to understand aggregate use and reliability of public website pages.

Depending on the interaction and applicable law, processing may be necessary to take requested pre-contractual steps or administer a relationship with TRCC, to meet an applicable obligation, or for legitimate operational and security interests that do not override the person's rights. TRCC relies on consent where the website asks for a separate choice, including an applicable public-directory or representative-publication choice and optional daily audience measurement. The audience choice is not preselected, declining does not limit the site, and consent can be withdrawn for future page views on this Privacy page.

Uploaded and sensitive documents

Passport or national ID files, registration documents, representative photos, and payment proof are used only for the workflow in which they are requested. Access is limited to authorized operators or representatives who need the information for review, verification, payment administration, or the related decision.

These files are not intended for public display. A representative photo may be published only under the separate permission and public-review conditions described above. Users should submit only the document pages and details requested for the relevant workflow.

Recipients and service providers

Personal data may be available to authorized TRCC staff, operators, committee or Chamber representatives, and event personnel where their role requires it for the relevant purpose.

TRCC may also use categories of service providers needed to operate the service, such as website hosting and infrastructure, email delivery, private file storage or backup, security and maintenance, and event or payment administration where applicable. This policy does not name a provider unless its current role has been independently confirmed.

TRCC does not sell personal data.

International processing

Website, communications, event, or infrastructure providers may process data in jurisdictions in which they operate when this is necessary for the relevant service. TRCC does not list specific transfer countries in this policy without confirmed operational evidence.

Where an international transfer occurs, TRCC will address it according to the applicable requirements and the actual service arrangement.

Cookies, embeds, and analytics

The website uses technical functions needed for normal operation, including session and security cookies where a service requires them, form-protection state, and server logs.

TRCC may use its own server-side aggregate counters for eligible public application requests. They distinguish successful public HTML page views from HTTP request counts and do not identify unique people. The counters may include the normalized successful public page, network country, registrable referral domain, confirmed/probable/not-identified robot class, request hour, 404/429/5xx status class, a bounded public 404 method class, and separately validated Trade Statistics filters for direction, country, period, or HS code.

After a separately declared Bangkok-local start date, eligible public 404 responses may be counted in one of two aggregate method classes: `GET/HEAD` or `other`. The activation date is treated as a partial day, so full-day reconciliation begins on the following Bangkok day. The report marks earlier or incomplete coverage as unavailable for this breakdown. This class is an independent counter and is not linked to a retained path, robot class, network country, browser, person, or organization.

For eligible public 404 responses, TRCC may separately retain only a safety-screened path without its query string and an aggregate retention outcome. Private and form namespaces and paths that are malformed or resemble tokens, identifiers, email addresses, or phone numbers are not retained. At most 200 different paths are accepted per Bangkok day; later new paths increment only an aggregate overflow counter, while observations of already accepted paths may continue to be counted. Workspace, accounts, applicant/member portals, forms and receipts, token-bearing links, static files, and media are excluded.

Separately, after an explicit Allow choice, TRCC may set one Secure, HttpOnly, SameSite=Lax first-party cookie containing that choice and a random browser identifier. The identifier lasts for up to 90 days. For each eligible successful public HTML page view, the server derives a keyed daily pseudonym from the identifier and Bangkok date, excludes requests classified as confirmed or probable automation, and retains only the daily pseudonym in a separate short-lived table. The resulting metric is “Unique consenting browsers per day, excluding recognized automation”. It estimates consenting browsers, not people. “Not identified” is not proof that a request came from a person. Daily values are not added together as a unique audience for a longer period.

Every eligible page view has one aggregate audience outcome: valid consented identifier, no valid consented identifier, or recognized automation. At most 50,000 different daily pseudonyms are retained per Bangkok day. After that limit, page views from a new pseudonym increment an aggregate overflow counter without storing the pseudonym, so the daily browser value is displayed as a lower bound. Page-view coverage is consented-identifier page views divided by non-recognized page views; it is not a percentage of people. The estimate may count one person more than once across devices or browsers, count a shared browser once, and change when cookies are deleted or blocked. It cannot reconstruct past audience.

The site statistics do not retain a full URL, query string, full Referer, arbitrary search text, IP address, IP-derived identifier, User-Agent, session/request identifier, or the persistent browser identifier in aggregate counters. The public 404 branch does not read or retain an IP address, User-Agent, or Referer. TRCC does not use Google Analytics, Yandex Metrica, fingerprinting, or IP hashes for this collection. Google and Yandex site-verification meta tags may be present; those text-only tags do not load an analytics tracker.

Some pages may link to or embed third-party content, including privacy-enhanced YouTube content. Loading or activating that content may connect the browser to the external provider, whose own terms and privacy information apply.

Retention

TRCC keeps information only for as long as reasonably needed for the relevant application, membership, event, inquiry, payment, record-keeping, dispute, security, or applicable legal purpose.

Periods differ by record and workflow. The optional random audience identifier cookie lasts for up to 90 days unless the visitor changes the choice earlier. Derived daily audience pseudonyms are retained for no more than 48 hours and are deleted after rollup; they and site-statistics counter data are excluded from database backups. Independent hourly counters are kept for no more than 48 hours. Daily public 404 path and path-disposition aggregates are kept for no more than 90 days; other daily aggregate counters, including the audience result and aggregate outcomes, are kept for no more than 400 days. Necessary Gunicorn/Django operational logs are automatically removed no later than seven days and are not copied into Preview backups. These periods do not extend a shorter workflow-specific period. Other information may be archived, restricted, corrected, or deleted through the applicable operator process.

Security and operational logs

TRCC uses access controls, private storage boundaries, validation, form-abuse protection, backups, and operational logging appropriate to the website workflow. Access to private submissions, documents, payment proof, and internal notes is restricted to authorized roles. The aggregate site-statistics report, including any retained public 404 paths, is available only inside the Secretary Workspace under a separate permission and does not display network addresses.

No website or online transmission can be guaranteed to be completely secure. Users should avoid submitting information not requested by the relevant workflow.

Your data-subject rights

Subject to applicable law, a person may ask about access to personal data, correction, deletion, restriction or objection, portability where applicable, withdrawal of a consent for future processing, or how to raise a concern with the competent authority.

The optional audience consent can be withdrawn on this Privacy page; the personal browser identifier is replaced with a shared declined-preference value and future page views are no longer observed under it. For other requests, send a message to the privacy contact shown below and describe the relevant TRCC interaction and requested action. To protect the person concerned, TRCC may request proportionate information to verify identity before disclosing or changing a private record. A representative may be asked to show authority to act. Do not send passport or national ID material unless TRCC specifically requests it through an appropriate channel.

Updates to this policy

TRCC may update this policy when website functions, forms, providers, or operational practices change. The current version and effective date are displayed on this page.

An update does not rewrite the policy version captured with an earlier form submission.

Contact

For questions about this policy or to make a data-subject request, email the dedicated privacy contact shown below. The contact is a TRCC privacy channel and is not described as a Data Protection Officer. TRCC does not state in this policy that a DPO has been formally appointed.

Need clarification?

Talk to the TRCC team.

Tell us which form, application, event, or page your question relates to so it can be routed correctly.

Phone
+66 2 766 7489
Office
18th Floor, CP Tower, 313 Silom Road, Silom, Bangrak, Bangkok 10500
Email secretary@trcc.or.th