Privacy Policy
Last updated: July 29, 2026 · Effective: July 29, 2026
This Privacy Policy explains how Servant Leadership Ministry Foundation ("SLM Foundation", "we", "us", or "our") collects, uses, shares, and protects your personal data when you use our website, donate, enroll in our programs, or otherwise interact with us.
We comply with Thailand’s Personal Data Protection Act B.E. 2562 (2019) ("PDPA"), and where applicable, the European Union’s General Data Protection Regulation ("GDPR"), the United Kingdom’s UK GDPR, and similar data protection laws. Where laws conflict, we apply the standard most protective of you.
1. Who we are (Data Controller)
Servant Leadership Ministry Foundation
Pantasanya Building, 1st Floor, Payap University (Mae Khaow Campus)
272 Moo 2, San Phra Net Subdistrict, San Sai District,
Chiang Mai 50210, Thailand
Tel: +66 84 810 2114
Email: sleadershipministry@gmail.com
For PDPA / GDPR matters, contact our Data Protection Officer at sleadershipministry@gmail.com.
2. Personal data we collect
2.1 Information you provide directly
- Account & profile — name (and an optional title/prefix such as Mr., Mrs., Ms., Dr., Rev.), email, phone (international format, optional, stored encrypted at rest), password (stored hashed), date of birth (optional, used to confirm you are at least 18 as required by our Terms of Service), city and country (optional; used to show where our learners come from), and postal address (optional, stored encrypted at rest; used only when you request a paper receipt or physical mail such as a printed certificate).
- Donations — donor name, email, phone (optional, stored encrypted at rest), donation amount, donation message (optional), whether you wish to remain anonymous.
- Course enrollments — selected cohort, member profile, ministry or church affiliation (optional), and your academic / learning status (e.g. in progress, passed, failed, withdrawn) recorded by faculty.
- Newsletter subscription — email address and consent timestamp.
- Contact and support — content of any message you send us.
2.2 Information collected automatically
- Cookies and similar technologies — see our Cookie Policy.
- Server logs — IP address (hashed), browser user-agent, pages visited, timestamps. Used for security and abuse prevention.
- Consent records — your cookie preferences, when given, hashed IP, and user-agent (proof of consent under PDPA Section 19).
2.3 Information from third parties
- Stripe, Inc. — when you donate or enroll, Stripe collects your card or bank details directly. We never see or store full card numbers. Stripe returns to us only: the last 4 digits of your card, card brand, country of issue, and a charge identifier.
2.4 Sensitive data
We do not intentionally collect "sensitive personal data" under PDPA Section 26 (race, religion, political opinion, health, biometric, criminal record, etc.). If you voluntarily share such information in a donation message or correspondence, we will treat it with additional care and only use it for the purpose you provided it.
3. Why we use your data & legal basis
| Purpose | Lawful basis (PDPA & GDPR) |
|---|---|
| Process donations & issue tax-deductible receipts | Performance of a contract / Legal obligation (Thai Revenue Code) |
| Enroll you in a program and deliver course materials | Performance of a contract |
| Send you transactional emails (receipts, confirmations) | Performance of a contract |
| Send newsletters & ministry updates | Consent (you opted in — you can withdraw any time) |
| Comply with tax, accounting & anti-fraud laws | Legal obligation |
| Secure our website and prevent abuse | Legitimate interest |
| Improve our programs and website | Legitimate interest / Consent (analytics cookies) |
| Pastoral follow-up & prayer for donors | Legitimate interest (you may opt out at any time) |
4. Who we share your data with
We share data only with trusted third-party processors who help us operate, under written agreements that meet PDPA / GDPR standards:
- Stripe, Inc. (United States & Ireland) — payment processing. Stripe Privacy Policy.
- Email delivery provider (e.g. Postmark, Resend, Amazon SES, or Mailtrap) — for sending receipts, confirmations, and newsletters.
- Hosting provider — for running this website. Servers are located in Thailand and/or the United States.
- Analytics provider (only if you consent to analytics cookies) — to understand site usage in aggregate.
- Government authorities — if required by Thai law (Revenue Department, court order, etc.).
We do not sell your personal data. We do not allow third-party advertising on this site.
5. International data transfers
Some of our processors (Stripe, hosting, email delivery) may store or process data outside Thailand — including in the United States and the European Union.
When we transfer your data internationally, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, where the recipient is in a non-adequate country;
- Adequacy decisions issued by the EU Commission or by Thailand’s Personal Data Protection Committee, where available;
- Your explicit consent where the transfer is to your benefit (e.g., processing your card via Stripe US).
6. How long we keep your data
| Category | Retention period |
|---|---|
| Donation receipts & payment records | 10 years (Thai Revenue Code § 87/3 retention requirement) |
| Account / profile data | Until you request deletion, then 30-day grace period |
| Course enrollment records | 5 years after course completion |
| Newsletter subscriptions | Until you unsubscribe |
| Cookie consent records | 2 years from consent |
| Server logs | 90 days |
| Anonymized aggregate statistics | Indefinite (no longer personal data) |
After the retention period ends, data is securely deleted or fully anonymized.
7. Your rights
You have the following rights with respect to your personal data, under PDPA §§ 30–36 and GDPR Articles 15–22:
- Right to be informed — this Privacy Policy fulfills that.
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”) — ask us to delete your data, subject to legal retention obligations (e.g., we cannot delete tax receipts before 10 years).
- Right to restrict processing — ask us to pause processing while a complaint is investigated.
- Right to data portability — receive your data in a machine-readable format (JSON).
- Right to object — object to processing based on legitimate interest, including direct marketing.
- Right to withdraw consent — where processing is based on consent (e.g., newsletter, analytics cookies), withdrawal is as easy as giving consent. Withdrawal does not affect prior lawful processing.
- Right to lodge a complaint — with Thailand’s Personal Data Protection Committee (PDPC) or, if you are in the EU, with your local supervisory authority.
Exercise any of these rights through our Data Subject Request form or by emailing sleadershipministry@gmail.com. We respond within 30 days as required by PDPA § 30(3).
8. Cookies
We use cookies and similar technologies. You control them through the cookie banner on your first visit and can change preferences any time via the link in the website footer. Full details are in our Cookie Policy.
9. Security
We protect your data with industry-standard measures:
- HTTPS / TLS encryption for all data in transit.
- Passwords stored using bcrypt one-way hashing (we cannot read them).
- Card and bank details never touch our servers — Stripe Elements collects them directly.
- Sensitive personal fields — including phone numbers and postal addresses — are encrypted at the application layer (AES-256) before they are written to the database. Even an attacker with full database access cannot read these fields without our application encryption key.
- Database backups are encrypted at rest.
- Access to personal data is restricted to authorized SLM Foundation staff on a need-to-know basis.
- Security incidents affecting personal data are notified to the PDPC and to affected users within 72 hours as required by PDPA § 37(4).
10. Children’s data
Our services are intended for adults (18 years and older). We do not knowingly collect personal data from children under 18 without parental consent. If you believe we have inadvertently collected data from a child, please contact our DPO and we will delete it promptly. (PDPA § 20 / GDPR Article 8.)
11. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top will reflect the latest version. For material changes (e.g., a new category of recipient), we will notify registered users by email at least 14 days before the change takes effect.
12. Contact
Servant Leadership Ministry Foundation
Pantasanya Building, 1st Floor, Payap University (Mae Khaow Campus)
272 Moo 2, San Phra Net Subdistrict, San Sai District,
Chiang Mai 50210, Thailand
Email: sleadershipministry@gmail.com
Phone: +66 84 810 2114
Submit a data request: https://slmif.org/data-request
This document is provided for transparency and is not a substitute for legal advice.