Key Definitions
To make the policy practical, we explain terms using examples relevant to our executive workshops and case-study format. Each definition is followed by a short scenario showing how that term applies when a director registers for a cohort or submits a case study for group review.
- Personal data means any information relating to an identified or identifiable person. Example: when a participant registers for a training cohort, their name, business title and email are collected to manage enrollment and to include them in group case discussions.
- Processing covers any operation performed on personal data, such as collection, storage, analysis, or sharing. Practical case: anonymizing a business scenario submitted by an owner before using it in a public workshop.
- User refers to any individual who visits the site, registers for programs, attends workshops or submits materials. Scenario: a CEO who uploads a growth-case study to request feedback from a peer cohort.
- Service means our suite of educational offerings, including live workshops, recorded modules, peer review sessions and downloadable tools. Example: the recorded module on mindful decision-making combined with budget modeling.
- Cookies are small data files stored in a browser to help the site remember preferences and support analytics. Example: a persistent cookie that keeps a logged-in director in the correct cohort portal between sessions.
Data Collection
We collect data necessary to deliver practical, scenario-driven training. The following sections break down what participants provide directly, what is collected automatically, and what may be received from third parties when relevant to case-based activities.
User-Provided Data
Information participants supply when they sign up, join a cohort, submit a case study, or communicate with our team. Each item below includes a brief example of how it is used in training scenarios.
- Contact details: name, business title, company name, email and phone. Example: used to send cohort schedules and speaker notes for a board-level scenario workshop.
- Business data and case materials: business summaries, organizational charts, and workshop case submissions. Example: anonymized case materials are used during peer-review sessions to explore decision pathways.
- Registration information: payment details, billing address and VAT or business ID when required. Example: used to issue receipts for company management departments and to validate corporate participation.
- Preferences and learning goals: submitted during onboarding surveys. Example: tailoring scenario selections to emphasize succession planning or availability management for a specific cohort.
- Communications: messages platform with instructors or support, including feedback on practical exercises. Example: an platform outlining how a director applied a scenario in their board meeting.
- Multimedia submissions: recordings or slides uploaded for group review. Example: a recorded presentation of a transformation case used for structured critique within the training.
Automatically Collected Data
When users interact with the website and platform, certain information is collected automatically to support functionality, analytics and security. Practical notes and examples follow each item.
- Device and browser details: device type, operating system, browser version. Example: to ensure recorded modules play correctly for participants in regional offices.
- Usage data: pages visited, time spent on case materials and module progress. Example: instructors use anonymized analytics to adapt upcoming workshop scenarios to participant engagement patterns.
- IP address and approximate location: used for security and fraud prevention. Example: detecting unusual access attempts to a cohort portal from an unexpected country.
- Cookies and tracking identifiers: to remember login and learning preferences. Example: saving a preference for case-study difficulty level across sessions.
- Error and performance logs: collected to fix technical issues with recorded scenario playback. Example: troubleshooting a failed upload of a CEO's case presentation.
- Interaction timestamps: to reconstruct sequence of actions when participants request help with submission timelines for peer review.
Third-Party Data Sources
In certain cases we receive data from external providers or partners to support payments, training verification or collaborative case studies. We include examples below to illustrate typical flows.
- Payment processors: limited billing information and transaction identifiers to confirm enrollment and issue receipts. Example: confirming a company invoice for a leadership cohort.
- Third-party collaboration platforms: when a cohort uses an external forum or conferencing tool, basic participation records may be shared to coordinate sessions.
- Public sources or professional directories: optional enrichment of public business profiles when participants consent to include their company case in an aggregate study.
Purposes of Processing
We process personal data to operate training services, manage cohorts, improve educational outcomes and meet legal or contractual obligations. Each purpose is described with a practical case or scenario showing how it supports our mission of combining economic practice and spiritual leadership.
- To provide and manage training services: enrolling participants, scheduling workshops, and delivering materials. Case: sending cohort-specific pre-work and post-session reflection prompts.
- To process payments and invoices: handling billing and VAT where applicable. Case: issuing a corporate invoice to a participant's management department using the supplied Business ID.
- To improve programs using analytics: evaluating which case studies drive the best engagement and adjusting content. Case: selecting more scenario-based modules on succession when data shows high engagement.
- To operate platform features: authentication, account management and personalized learning paths. Case: preserving a director's progress through a multi-part scenario module.
- To communicate with participants: sending schedules, updates, and practical feedback on submitted cases. Case: notifying a participant of peer-review outcomes and recommended next steps.
- To ensure security and fraud prevention: monitoring access and contribute anomalous activity. Case: blocking repeated failed login attempts to a cohort portal.
- To comply with legal obligations: record retention for tax and regulatory purposes. Case: retaining payment receipts for the statutory period required by Thai authorities.
- To support legitimate business interests: developing case libraries and research into values-led economic practices, using anonymized and aggregated inputs where consent permits.
Legal Bases for Processing
We rely on appropriate legal bases depending on the processing activity. Below are the primary bases and practical examples relevant to participants from corporate and executive backgrounds.
- Contract performance: processing needed to deliver training and materials once you enroll. Example: storing registration details so we can grant access to cohort resources.
- Legitimate interests: improving program quality, platform security, and preventing fraud, balanced with participant rights. Example: analyzing anonymized engagement metrics to enhance case selections.
- Consent: where participants opt in to optional uses such as public case publication or marketing communications. Example: requesting consent before a director's case study is included in a public seminar.
- Legal compliance: processing required to satisfy tax and reporting obligations in Thailand or other applicable jurisdictions. Example: retaining invoices and transaction records for statutory audits.
GDPR and International Rights
Although becybrixlo operates primarily in Thailand, we recognize international privacy rights. The following items summarize common GDPR-style rights and how participants can use them, illustrated by typical scenarios.
- Right of access: request a copy of personal data we hold. Scenario: a participant requests their registration record and submitted case materials.
- Right to rectification: correct inaccurate or incomplete information. Scenario: a director updates a company title or billing address prior to invoice issuance.
- Right to erasure: request deletion of personal data where there is no overriding legal reason to retain it. Scenario: a former participant asks to remove their contact details from marketing lists.
- Right to restriction: ask that processing be limited in defined circumstances. Scenario: temporarily pausing inclusion of a case study in active cohorts while a board reviews confidentiality concerns.
- Right to data portability: obtain a machine-readable copy of personal data provided directly. Scenario: exporting learning progress and submitted case files when moving to another training provider.
- Right to object: object to processing for direct marketing or other specific purposes. Scenario: opting out of promotional emails while remaining enrolled in an active cohort.
Cookies and Tracking Technologies
We use cookies and similar technologies to enable site features, remember preferences and analyze usage. Below we outline types, categories and how users can manage them with practical notes for executive users.
Common cookies include session cookies for login, persistent cookies for preferences, and analytics cookies for aggregated engagement metrics. Example: a session cookie keeps a participant logged in during a live workshop.
Categories: strictly necessary (site operation), preferences (language, display), analytics (usage patterns) and marketing (where consented). Case: a preference cookie storing preferred module difficulty for repeat cohorts.
Participants can manage cookie settings in their browser or via the cookie consent tool on the site. For cohort-specific functionality we advise allowing necessary cookies; analytics cookies can be disabled without blocking access to core materials.
Cookie Settings and Details
Data Sharing and Disclosure
We share personal data only when necessary for service delivery, legal obligations or with explicit consent. The examples below illustrate typical sharing scenarios tied to our case-based training model.
- With service providers: payment processors, hosting and conferencing platforms to deliver services. Example: sharing billing contact information to issue a corporate invoice.
- With instructors and cohort members: limited case materials shared within a cohort when the participant consents. Example: anonymized business summaries used for group analysis.
- For legal reasons: when required by law, court order, or to comply with regulatory audits. Example: disclosing records in response to a lawful tax authority request.
- With professional advisors: accountants or auditors engaged for compliance, under confidentiality obligations. Example: sharing transaction records with an auditor appointed to review program resources.
- With corporate partners: only when a participant has approved co-branded program participation or public case publication. Example: a company authorizes publication of a transformation case for a joint seminar.
- Aggregated and anonymized data: shared for research or program improvement without identifying individuals. Example: sharing anonymized engagement trends to illustrate program impact to potential corporate clients.
International Transfers
Because we rely on cloud services and international partners, some processing may occur outside Thailand. We take steps to ensure appropriate protections are in place and document transfers in case studies that explain where data is processed and why.
Safeguards include data processing agreements, standard contractual clauses where applicable, and technical measures such as encryption. Practical example: recordings stored in a secure cloud region with contractual obligations to restrict access to authorized personnel only.
Data Retention
We retain personal data only as long as necessary to fulfill the purposes set out or to meet legal and regulatory requirements. Retention times are illustrated with relevant training scenarios below.
Account and profile data: retained while the account is active and for a reasonable period after inactivity to allow reactivation and record keeping for audits. Example: maintaining a director's access to cohort materials for one year after course completion to support follow-up mentoring.
Communications and support records: kept to resolve disputes and improve services, typically for up to three years unless a longer retention is justified by law. Example: preserving an email thread documenting advised adjustments to a submitted case study.
Technical logs: stored for a limited period to support security monitoring and incident response, commonly for 6 to 12 months. Example: log retention used to contribute an access issue during a live peer-review session.
Deletion procedures: when retention periods expire or upon a valid deletion request, we remove or irreversibly anonymize personal data except where legal obligations require continued retention.
Security Measures
We maintain administrative, technical and physical measures to protect personal data against unauthorized access and misuse. Security practices are regularly reviewed and illustrated through incident response case studies to improve resilience.
- Access controls and role-based permissions for staff and instructors. Example: only assigned facilitators can view raw case submissions for a cohort.
- Encryption of data in transit and at rest for sensitive files and recordings. Example: encrypted storage for uploaded business spreadsheets used in peer reviews.
- Regular backups, vulnerability scans and an incident response plan tested with tabletop exercises involving realistic training scenarios.
Your Rights
Participants and visitors have rights regarding their personal data. We describe how to exercise these rights and provide practical examples so executives understand the expected timelines and documentation needed.
- How to exercise rights: submit a request to [email protected] or by postal mail to our office at Thanon Kosi, Pak Nam Pho Sub District, Amphoe Mueang Nakhon Sawan District, Nakhon Sawan Province 60000, Thailand. Include sufficient details to locate your records and a copy of government ID if required for verification.
- Response timeframe and possible exceptions: we aim to respond to access and correction requests within a month and will inform you if more time is required. Some requests may be limited where legal or contractual obligations require retention (for example, invoices for tax purposes).
- Right to request correction of inaccurate personal data we hold about you, including updates to contact information and professional details submitted to becybrixlo.
- Right to request deletion of personal data where processing is no longer necessary or where consent has been withdrawn and no legal basis for retention applies.
- Right to restrict processing of your personal data if you contest accuracy or lawfulness of processing while we verify or resolve the issue.
- Right to data portability for information you provided directly to becybrixlo in a structured, commonly used and machine-readable format when applicable.
- Right to object to processing for direct marketing or profiling where such processing is based on legitimate interests; we will cease such processing unless a compelling lawful basis exists.
- Right to lodge a complaint with a supervisory authority in Thailand if you consider our handling of personal data infringes applicable data protection law.
How to Exercise Your Data Rights
Requests to access, correct, delete or restrict personal data may be submitted to our privacy team by email or postal mail. Include your full name, email address used with becybrixlo, a clear description of the requested action, and any supporting documents to verify your identity. For business accounts, include company name and Business ID 1040394337415 to help us process corporate requests.
We aim to respond to verified requests within a reasonable timeframe. Typical response time is up to 30 calendar days from verification; complex requests may require additional time and we will communicate expected timelines and any lawful reasons for delay.
Marketing Communications
becybrixlo may send targeted emails, event invitations, and updates about training programs, case studies and industry insights relevant to business leaders. Marketing messages are based on preferences you set and interactions such as program attendance, downloads, or expressed interests.
You can opt out of marketing communications at any time by using the unsubscribe link in emails or by contacting [email protected]. Opting out will not affect non-marketing messages related to transactions, account administration, or programs you actively participate in.
Children's Personal Data
Our services are intended for business professionals and directors. becybrixlo does not knowingly collect personal data from individuals under 18. If we discover we have collected data of a minor in error, we will take steps to delete it promptly upon verification.
Links to Third-Party Sites
Our website and communications may include links to third-party sites used for registration, payment processing, analytics, or content hosting. These sites have their own privacy policies. becybrixlo is not responsible for third-party privacy practices and recommends reviewing their policies before providing personal data.
Changes to This Privacy Policy
We may update this privacy policy to reflect legal, operational or service changes. Material updates will be posted at becybrixlo.digital with an updated effective date and, where appropriate, notified to registered users. Continued use of services after changes indicates acceptance of the amended policy.