Privacy Policy
We are a B2B Thailand DMC and process personal data under Thailand's Personal Data Protection Act (PDPA). This policy explains what we collect and your rights.
Last updated: 16 July 2026
This Privacy Policy explains how Explera DMC Co., Ltd. (“Explera”, “we”, “us”), a business-to-business (B2B) destination management company based in Bangkok, Thailand, collects, uses, discloses and protects personal data in connection with this website and our trade services. We process personal data in accordance with Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) and other applicable law.
On this page
1. Who we are (data controller)
Explera DMC Co., Ltd., “FOR YOU RESIDENCY” Room #201, 839, Si Lam Road (Soi 17), Silom, Bangrak, Bangkok 10500, Thailand. IATA 96215733 · TAT licence in application. We act as the data controller for the personal data described in this policy. For any privacy matter, contact b2b@explera.co.th.
2. Scope of this policy
Explera is a Thailand DMC for travel agents and works only with travel-trade partners; this website is not intended for consumers. This policy covers data we collect through the website (forms, newsletter, cookies), through direct trade correspondence (email, WhatsApp, the partner portal at b2b.expleradmc.com), and traveller information that partner agencies share with us to operate bookings. Investor enquiries sent to ceo@explera.co.th and payment correspondence with accounts@explera.co.th are also covered.
3. What personal data we collect
- Trade partner registration & enquiries — agency/company name, contact name, work email and phone, country, IATA or national licence number (optional), and the content of your enquiry (group size, dates, destinations, services requested).
- Trade newsletter — your work email address, where you have opted in, together with a record of that consent.
- Correspondence — information you provide when you contact us by email, WhatsApp or website forms, including booking and itinerary details relating to your clients that you share to obtain a quotation.
- Traveller data supplied by agencies — when a partner confirms a booking we may receive traveller names, passport details, contact information, flight details, rooming lists, dietary requirements and, for specific programs such as medical-travel logistics, health-related information necessary to deliver the service (see section 5).
- Investor enquiries — name, contact details, country of residence and the information you choose to share about your investment interests.
- Technical & usage data — collected automatically via cookies and similar technologies: IP address, device and browser type, pages viewed, referrers and interaction data (see our Cookie Policy).
4. Purposes and lawful bases
- Performing our contract with you — responding to enquiries, preparing net-rate quotations and itineraries, operating confirmed bookings, coordinating suppliers, issuing invoices and vouchers.
- Consent — sending the trade newsletter and marketing updates; processing any sensitive traveller data (for example dietary or health information) that a program requires. Consent can be withdrawn at any time.
- Legitimate interests — verifying trade credentials, securing and improving the website, preventing fraud and misuse, and maintaining business records.
- Legal obligations — accounting, tax and tourism-licensing requirements, and lawful requests from Thai authorities (for example immigration formalities connected to a booking).
5. Your clients’ data (travellers)
Partner agencies remain responsible for their own client relationships and for obtaining any consents required before sharing traveller data with us. We use traveller data solely to deliver the booked ground services — hotel check-ins, transfers, guides, permits, insurance where requested — and share it only with the suppliers involved in that itinerary. Health-related information (for example allergies, mobility needs, or details connected to medical-travel logistics) is treated as sensitive data under the PDPA: we process it only to the extent needed for the service, on the basis of the explicit consent your agency confirms it has obtained, and we do not retain it beyond the program.
6. Who we share data with
- Suppliers engaged for your itinerary — hotels, transport operators, licensed guides, activity and marine operators, restaurants, insurers.
- Service providers that run parts of our infrastructure — website hosting (Vercel), analytics (Google Analytics), email and productivity tools — under appropriate safeguards.
- Authorities where required by Thai law, such as immigration or licensing bodies.
- Professional advisers (legal, accounting, insurance) where necessary.
We do not sell personal data, and we do not share it with third parties for their own marketing.
7. International transfers
Our operations are based in Thailand, but some service providers (for example hosting and analytics) process data outside Thailand. Where personal data leaves Thailand we rely on the PDPA’s transfer mechanisms, including transfers necessary for the performance of a contract and providers with recognised safeguards.
8. How long we keep data
- Trade enquiries that do not become bookings — up to 24 months from last contact.
- Booking and invoicing records — as required by Thai accounting and tax law (generally 5–10 years).
- Newsletter data — until you unsubscribe or we delete inactive addresses.
- Sensitive traveller data — deleted after the program ends unless law requires otherwise.
9. How we protect data
We apply administrative, technical and physical safeguards proportionate to the data we handle: encrypted connections (HTTPS) across the site, access controls limiting data to the team members working your file, supplier data-sharing limited to what each service requires, and staff confidentiality obligations. No system is perfectly secure; if a breach affecting your rights occurs we will notify you and the regulator as the PDPA requires.
10. Your rights under the PDPA
Subject to conditions in the law, you may: access and obtain a copy of your data; correct inaccurate data; delete or anonymise data; restrict or object to processing; obtain portability of data you provided; and withdraw consent at any time without affecting prior processing. To exercise any right, email b2b@explera.co.th; we respond within 30 days.
11. Cookies
See our Cookie Policy for the specific cookies and local-storage keys this site uses and how to control them.
12. Children
This website is a trade platform and not directed at children. Traveller data concerning minors is processed only as supplied by the responsible agency for a confirmed booking.
13. Changes to this policy
We update this policy when our practices change; the date at the top reflects the latest revision. Material changes will be flagged to registered partners by email or portal notice.
14. Contact & complaints
Privacy questions and requests: b2b@explera.co.th. If you believe we have processed your data unlawfully you may lodge a complaint with Thailand’s Personal Data Protection Committee (PDPC).