Last updated · 13 September 2026

Privacy Policy

Your trust matters to us. This policy explains what personal data Sirina handles, how we use it, and the rights you have under Thai law.

Who we are

Sirina is a hospitality platform operated by Northflow Technologies AS (Norwegian organisation number 936 979 815, registered address Jåttåveien 92, 4020 Stavanger, Norway), with a team present in Pattaya and Bangkok. For data collected through Sirina, the property using Sirina is the data controller, and Northflow Technologies AS acts as the data processor on its behalf.

Data requests (access, correction, deletion, withdrawal of consent) can be sent to platform@northflow.no. We respond within 30 days as required by the PDPA.

Compliance with Thai law (PDPA)

We handle personal data in accordance with Thailand's Personal Data Protection Act (PDPA). We collect only what is needed to provide the service, use it only for the purposes described here, and keep it only as long as necessary.

What we collect

Property information you provide (rooms, rates, photos, contact details). Guest information needed to manage bookings (name, contact, stay details). Where required for legal compliance, passport and travel details for TM30 reporting. Booking and payment records. Messages exchanged through connected channels such as LINE.

How we use it

To operate your booking website and dashboard, process payments, prepare TM30 filings, deliver guest communications, and provide analytics and support. We do not sell personal data, and we do not use guest data for advertising.

Payments

PromptPay payments settle directly into the property's own bank account; Sirina does not hold guest funds. Card payments are handled by regulated payment providers — we do not store full card numbers.

Your rights

Under the PDPA you may request access to, correction of, or deletion of your personal data, and you may withdraw consent where processing is based on consent. To make a request, contact the property directly or email platform@northflow.no and we will assist.

How long we keep data

Booking and financial records: 5 years after the end of the tax year in which the booking took place, as required by the Thai Revenue Code for accounting records.

TM30 and passport data collected for Immigration reporting: 1 year after check-out, then deleted.

Marketing preferences and contact details used for marketing: until you withdraw consent or unsubscribe.

Support tickets and dashboard audit logs: for the life of the property's subscription plus 12 months, so disputes can be resolved.

Sub-processors & international transfers

We rely on the following providers to run Sirina. Each is bound by a data-processing agreement and processes data only on our instructions: Vercel (application hosting, EU region); Neon (PostgreSQL database, Frankfurt, Germany); Vercel Blob (photo and media storage); Resend (transactional email); Stripe (subscription billing for properties — Stripe never receives guest booking data); Google Maps (embedded map on property contact pages, loaded only after the visitor consents).

Because these providers operate in the European Union and the United States, personal data is transferred outside Thailand. Under section 28 of the PDPA such transfers are made to destinations with adequate protection or under appropriate safeguards (standard contractual clauses and data-processing agreements), and only to the extent needed to provide the service.

Cookies

Sirina uses only cookies that are necessary to run the service, plus one consent cookie. NEXT_LOCALE remembers the language you chose (1 year). The Auth.js session and CSRF cookies keep operators signed in to the dashboard and protect forms against cross-site requests (session lifetime). nf_consent stores your choice about optional embedded content such as the Google map (1 year). We do not use advertising or cross-site tracking cookies.

Security

Data is stored on secure, access-controlled infrastructure, encrypted in transit and at rest, and retained only for the periods above or as required by law. We apply appropriate technical and organisational safeguards to protect it, and we will notify the property and the Personal Data Protection Committee of any breach as the PDPA requires.

Questions about this document? Contact us at platform@northflow.no
Privacy Policy · Sirina