This website is operated by Zenva Management ("Zenva," "we," "us," or "our"), operating as Zenva — Private Onsen & Spa, located at SEENSPACE Thonglor, FL 03-01, 251/1 Thong Lo 13 Alley, Khlong Tan Nuea, Watthana, Bangkok 10110, Thailand. For any privacy question or request, contact us at admin@zenvaspabkk.com or +66 80 262 9191.
| Category | Examples | How it's collected |
|---|---|---|
| Booking & contact data | Name, phone number, LINE/WhatsApp ID, email, booking date/time, party size | When you book by phone, LINE, WhatsApp, or a website form |
| Membership data | Membership tier, credit balance, transaction history | When you join or use the membership program |
| Sensitive personal data (health information) | Contraindication/health-screening answers (e.g., pregnancy, heart conditions, migraines) collected before Contrast Therapy or ice-bath treatments | Via a screening form at the time of booking or check-in, only with your separate, explicit consent — see Section 4 |
| Technical & usage data | IP address, device/browser type, pages visited, referral source | Automatically, via cookies and similar technologies when you use the site (only after consent for non-essential categories — see Section 7) |
| Marketing data | Your interactions with ads or messages, if you've opted in | Via Meta Pixel / LINE Tag, only after marketing consent |
We do not sell personal data to third parties.
Before certain treatments (Contrast Therapy, the ice bath), we ask health-screening questions to check for contraindications such as pregnancy, cardiovascular conditions, or migraines. This is collected only with your separate, explicit, opt-in consent — never bundled with your general booking consent, and never through a pre-ticked box. You may decline to answer, though we may not be able to offer certain treatments without this safety check. We keep this information only as long as needed to safely deliver the treatment on the day of your visit, and do not retain it beyond 90 days unless you are a returning guest who chooses to have it kept on file, which we will confirm with you again at each visit.
We may share limited data with service providers who help us run the business, such as messaging platforms (LINE, WhatsApp/Meta) and analytics providers (Google). At this time, bookings are made directly by phone, LINE, or WhatsApp rather than through a separate booking, POS, or CRM platform; this section will be updated if a dedicated booking or CRM system is adopted in the future. These providers only receive the data needed to perform their function and are not permitted to use it for their own purposes.
Some of the service providers we use — Google (Google Analytics), Meta (Meta Pixel), and LINE — may process data on servers located outside Thailand. Thailand's Personal Data Protection Committee has not, as of the date of this policy, published a list of countries it recognizes as having data protection standards equivalent to Thailand's. Where we transfer data to these providers, we rely on the safeguards each provider maintains — including their own standard contractual clauses and international compliance certifications — as the basis for the transfer, consistent with PDPA Sections 28–29. We will update this section if Thailand's regulator publishes further guidance that changes how this should be documented or safeguarded.
We use three categories of cookies, described in the table below. Non-essential categories only load after you give consent through the cookie banner or the "Cookie Settings" link in the site footer, which you can use to change your choice at any time.
| Category | Purpose | Examples | Requires consent? |
|---|---|---|---|
| Necessary | Core site function, security, remembering your cookie choice | Session/consent cookies | No — always on |
| Analytics | Understand site usage to improve content and navigation | Google Analytics (GA4) | Yes |
| Marketing | Measure and personalize ads/messages | Meta Pixel, LINE Tag | Yes |
Under Thailand's PDPA, you have the right to:
To exercise any of these rights, contact us at admin@zenvaspabkk.com.
Under the 2023 sub-regulation to PDPA Section 41(2), a Data Protection Officer must be appointed only where a business's core activity involves regular, large-scale monitoring or profiling of individuals — in practice, this generally means processing personal data of more than 100,000 people a year, or operating in specific regulated sectors (large-scale behavioral-advertising platforms, insurance, certain telecommunications licensees). Based on Zenva's own current scale — well under 5,000 customers a year, with website analytics and advertising measurement as a supporting function rather than our core business activity — a formally appointed Data Protection Officer is not required at this time. We will revisit this assessment if the scale or nature of our data processing changes materially. For any data protection question, request, or concern, contact us using the details in Section 1.
We may update this policy from time to time. Material changes will be reflected with a new "last updated" date at the top of this page.