01
Key definitions
This section clarifies terms used in the privacy policy with short examples to situate them in typical pensamo scenarios.
Personal data means information that identifies an individual directly or indirectly, such as name, phone number, email, date of birth, health notes shared for care planning, or a guest record created during program registration.
Processing covers any operation performed on personal data — collection, storage, analysis, sharing — for example, scheduling a therapy session or preparing a guest care summary that will be used by our therapists.
User refers to any person interacting with pensamo services or pensamo.click, including prospective guests, family members making enquiries, and referring clinicians submitting intake information.
Service refers to pensamo sanatorium programs, booking tools, wellness activities, therapy sessions, follow-up communications, and content provided via pensamo.click.
Cookies are small data files placed on devices when users visit pensamo.click to enable basic site functionality, remember preferences, and collect aggregated analytics to improve user experience.
02
Data we collect
We collect data required to deliver safe care and to run the website effectively. Below are typical categories with practical examples drawn from real-case scenarios at pensamo.
03
Information you provide
Information you provide directly when using our services, examples include admission forms, consent to treatments, and messages to staff.
- Contact information: full name, phone number (+66902651217), email address, emergency contact details used to coordinate care and appointment reminders.
- Health information relevant to the planned program: medical history summaries, medications, allergies, mobility limitations — provided so therapists and nurses can design appropriate activities.
- Booking and payment details: selected program package, arrival/departure dates, and payment receipts necessary for administrative records and invoicing.
- Preferences and consent: dietary requirements, activity preferences, and consent forms for treatments or data use for research or quality improvement when applicable.
- Feedback and incident reports: comments about the stay, satisfaction surveys, and any safety incident descriptions that help improve services based on concrete cases.
- Communications: messages sent via the website contact form, email correspondence, or notes entered by family members coordinating care.
04
Information collected automatically
Data collected automatically when you interact with pensamo.click or during service delivery, used to maintain security, improve the service, and support operational tasks.
- Device and browser information collected when visiting pensamo.click to help diagnose technical issues and optimize the site.
- Usage data such as pages visited, time spent, and clicks to analyze common user journeys and make the booking process more intuitive.
- Log data recording dates and times of access to maintain audit trails for bookings and to contribute any service-related incidents.
- Aggregated analytics used to evaluate service demand patterns, for example, identifying peak months for rehabilitation bookings to better allocate staff.
- Security-related information such as failed login attempts or unusual access patterns to protect user accounts and facility systems.
- We automatically collect technical and behavioral data when you interact with pensamo services. Typical items include device identifiers, browser and app metadata, IP address and inferred region, cookies and tracking pixels, timestamps, click and navigation paths, crash reports, and aggregated usage metrics. Practical cases: when a resident books a shuttle, approximate location and timestamp help route pickups more efficiently; when a guest syncs an approved fitness tracker (with explicit consent), step totals and activity timestamps are collected to support personalized activity programs; analytics events show which pages or booking flows cause confusion so we can simplify them. Security and fraud-detection systems also rely on automatic logs (login attempts, device fingerprints, anomalous traffic) to protect accounts. Where possible we aggregate and de-identify data before analysis. You can limit automatic collection by adjusting app permissions, disabling location or cookies in your browser, or changing device settings; for health-device integrations we require clear consent and provide an option to stop sharing at any time.
05
Data from third parties
Information received from trusted third parties that supports admissions and care coordination, often provided with consent or through established professional relationships.
- Referrer clinicians or hospitals may provide discharge summaries or therapy recommendations to ensure continuity of care for a named guest.
- Payment processors provide confirmation of transactions and minimal billing details required for accounting and refund processing.
- Publicly available identification information used only to verify basic identity details when needed for safety or fraud prevention.
06
How we use personal data
We use personal data for a limited set of specific, documented purposes that reflect practical cases of service delivery and site operation.
- To provide and coordinate sanatorium services: scheduling therapies, documenting care plans, and communicating with guests and families.
- To manage bookings and payments: processing reservations, issuing receipts, and handling cancellations as in routine examples of guest administration.
- To personalize the guest experience: adapting activity plans to documented mobility limitations and dietary notes shared during admission.
- To comply with legal or regulatory obligations: responding to lawful requests from authorities or maintaining medical records where required by local rules.
- To improve site and service quality: aggregated analytics and feedback drive iterative improvements based on recurring practical scenarios.
- To ensure safety and security: monitoring for incidents, contribute reported events, and preserving logs for routine audits.
- To handle rights requests and communications about data processing from individuals or their authorized representatives.
- To send service-related notices such as appointment reminders or changes to scheduled therapy sessions.
07
Legal bases for processing
Where applicable, we rely on lawful bases for processing personal data. These bases align with common cases encountered in providing care and running an operational website.
- Performance of a contract: processing needed to deliver booked sanatorium services and related administrative tasks.
- Legal obligation: processing required to comply with applicable laws or regulatory record-keeping obligations.
- Legitimate interests: limited, documented interests such as fraud prevention, safety monitoring, and service improvement balanced against individual rights.
- Consent: where explicit consent is required (e.g., optional research participation or marketing communications), we obtain and record it separately.
08
Cookies and similar technologies
pensamo.click uses cookies to enable essential site functionality and to collect anonymized data to improve the user journey. Below are types and management options with practical examples for visitors.
Types include essential cookies (session management), preference cookies (language or display settings), analytics cookies (site usage patterns), and advertising cookies (third-party tracking when consented). For example, analytics cookies help us see that many seniors prefer to view program schedules in a calendar layout, which informed a site update.
We categorize cookies as: essential (cannot be turned off), performance/analytics (help optimize the site), and optional marketing cookies (used only with consent). Essential cookies support login sessions and booking forms used during admissions.
Users can manage cookie preferences through the cookie banner on initial visit or via browser settings to block or delete cookies. Blocking some cookies may limit certain features such as remembering booking form details.
Read our cookie policy for technical details and how to change settings
09
Sharing and disclosure
We share personal data only when necessary for service delivery, legal compliance, or with explicit consent. Sharing is limited and documented with examples of common recipient types.
- Healthcare providers and therapists directly involved in a guest's care receive the minimal clinical information required to plan and deliver services.
- Payment processors and accountants receive transaction-related information necessary to complete billing and tax reporting.
- Authorities or regulators when required by law, such as responding to lawful inspection requests related to health and safety compliance.
- Service providers engaged to support operations, such as secure IT hosting, analytics providers, and document archiving services, with contractual safeguards.
- Researchers only receive de-identified or aggregated data for quality improvement projects and only with appropriate approvals or consent in specific cases.
- Family members or authorized representatives when the guest has provided consent or when the representative is legally authorized to act on behalf of the guest.
10
International data transfers
pensamo may transfer data to service providers located outside Thailand where necessary to operate parts of the website or administrative systems. Transfers are limited to countries with adequate safeguards or under contracts that include standard protections.
When transferring data internationally, we use contractual clauses, data processing agreements, and other appropriate technical and organizational measures to protect data. For instance, analytics or hosting partners are required to meet security standards and restrict access to authorized personnel only.
11
Data retention and deletion
Retention periods are based on service needs and legal requirements. We retain the minimal records necessary for care continuity, administrative purposes, and compliance, then securely delete or anonymize data.
Account and guest records are retained for operational purposes and for a period consistent with applicable law and clinical best practice, typically several years after the last service date depending on local regulatory obligations.
Communications such as emails and support messages are retained to resolve queries and maintain an audit trail related to bookings and care coordination for a reasonable period.
Security and access logs are kept for a defined period to contribute incidents and support service integrity; retention periods are determined by operational and legal needs.
When data is no longer needed, we remove personal identifiers or securely delete records. Individuals can request deletion subject to legal and clinical constraints, such as obligations to retain medical records for a statutory period.
12
Security measures
pensamo implements technical and organizational measures proportionate to the sensitivity of the data processed. Practical steps include role-based access for staff, encrypted backups, periodic access reviews, staff training on handling health-related information, and incident response procedures to contribute and learn from events.
- Access controls and role-based permissions to limit who can view guest records.
- Data encryption at rest and in transit for sensitive records and backups.
- Regular staff training, mock incident drills, and supplier security assessments.
13
Your data subject rights
Depending on applicable law, you may have rights to access, correct, restrict processing, or request erasure of personal data. We provide practical guidance and examples for making such requests.
- Right to access: you can request a copy of personal data we hold. For instance, a guest may request their therapy notes and appointment history; pensamo will provide the information subject to necessary professional redactions and identity verification.
- Right of access — You can request a copy of personal data we hold about you. Example scenario: a family member requests a copy of a service booking record to reconcile care arrangements; we provide the information after verifying identity and relationship.
- Right to rectification — If information about your health preferences or contact details is inaccurate, you can request correction. Case study: a resident updated their emergency contact details after a move; pensamo recorded the change and logged the correction for future audits.
- Right to erasure — You may request deletion of personal data where retention is no longer necessary. Practical case: after a short-term stay ends and statutory retention periods have passed, a former guest requested removal of marketing consents and non-essential profile notes; we evaluated the request against retention needs and acted accordingly.
- Right to restriction of processing — You can ask us to limit how we use your data while a dispute is resolved. Scenario: a user contested billing details; we restricted further billing-related processing until the dispute concluded.
- Right to data portability — When applicable, you can request a machine-readable copy of certain personal data. Example: a resident transferring to a partner facility requested records of dietary preferences and activity logs; we provided a structured export to support continuity of care.
- Right to object — You may object to processing based on legitimate interests or direct marketing. Practical example: a retiree opted out of profiling used for event invitations; we ceased those profiling activities for that profile.
- Right to withdraw consent — If you previously gave consent for a service or newsletter, you can withdraw it at any time. Case: a caretaker withdrew consent for email updates and we stopped sending further marketing materials while preserving transaction records required by law.
14
EU data protection (where applicable)
pensamo respects data protection laws and provides information about rights derived from the EU General Data Protection Regulation (GDPR) where applicable. This section explains relevant GDPR rights and practical steps for exercising them while describing real-life scenarios and case handling that illustrate how requests are processed.
GDPR applies to individuals located in the European Economic Area and to processing that targets EU residents. pensamo is based in Thailand and applies GDPR principles to EU residents’ data when required. Example: when an EU citizen books a stay through pensamo.click, GDPR requirements guide how we handle consent and access requests.
- Access requests: submit a verified request and we will provide a copy of personal data relevant to the request. Typical case: adult child requests activity logs of a parent to coordinate follow-up care; we verify identity and deliver the requested records where appropriate.
- Rectification requests: provide proof of the correct information and we will update records to reflect accurate details. Practical step: present an official ID or medical note to update name or health preference fields.
- Erasure requests: we assess each request against retention obligations and service needs; non-essential data will be deleted when lawful to do so. Case scenario: a temporary guest requests removal of marketing data after departure; we remove marketing consents while keeping transaction records as required.
- Portability requests: where processing is based on consent or contract and carried out by automated means, we can provide a structured, commonly used format for the data. Example: export of a resident’s dietary profiles and activity participation history to transfer to another facility.
If you believe your GDPR rights are not properly addressed, you may lodge a complaint with the relevant supervisory authority in your country of residence. For guidance, pensamo can provide documentation of the request and our response timeline to support an external review. We aim to cooperate with supervisory authorities in good faith.
15
How to make a rights request
To exercise your privacy rights, submit a written request via email to [email protected] or by post to our registered address. Include your full name, date of birth, a description of the request, and any documents needed to verify identity or legal authority. In case studies, verified requests from authorized family members included proof of guardianship.
[email protected]
We aim to acknowledge receipt of rights requests within 5 business days and to respond substantively within 30 calendar days. For complex requests or where additional verification is required, we will notify you and provide an updated timescale and a case reference number.
16
Marketing communications
pensamo uses contact details to send relevant service updates, event notices, and offers tailored for seniors and caregivers. Marketing is based on consent or a legitimate interest assessment. Practical example: invitations to a low-impact exercise class are sent only to residents who have expressed interest or whose profiles indicate suitability.
You can unsubscribe from marketing at any time using the unsubscribe link in emails, by adjusting communication preferences in your account, or by emailing [email protected]. Case: a subscriber used the one-click opt-out link in a newsletter and received confirmation of removal within 24 hours.
17
Information about minors
pensamo’s services and communications are not intended for children under 18. If a parent or guardian manages an account on behalf of a minor, we require appropriate consent and documentation. Scenario: a family member setting up a booking for an adult dependent provided legal paperwork to demonstrate authority.
18
Third-party links
Our website may link to third-party providers for travel, medical equipment, or local transport. These links are provided for convenience and their privacy practices are not controlled by pensamo. Case studies show we vet partners for basic privacy hygiene before featuring them, but users should review partner policies directly.
19
Changes to this policy
We review and update this privacy information periodically. Material changes will be published on pensamo.click with an updated effective date. Example: on 2026-05-21 we updated our data retention schedule to reflect new record-keeping requirements for guest stays.
Contact our privacy team: pensamo, Soi Inthamara 29 Yaek 1, Bangkok District, Bangkok 10400, Thailand. Phone: +66902651217. Business ID: 0999472835599. Email: [email protected]. For requests, include proof of identity and a clear description of the action you seek.