Privacy Notice

How Burapha University, by the Faculty of Medicine, collects and uses your personal data for the 26th Thai Medical Education Conference.

This notice explains what personal data the TMEC 2027 registration system collects from you, why we need it, who else sees it, and what you can ask us to do with it. It covers this conference only and forms part of the university-wide Privacy Notice referred to in section 7.

1 Data controller and how to contact us

The data controller is Burapha University, by the Faculty of Medicine. The Faculty is a division of the university under section 9 of the Burapha University Act B.E. 2550, not a separate controller.

Postal address
Burapha University, 169 Long-Had Bangsaen Road, Saensuk Sub-district, Mueang District, Chonburi 20131, Thailand
Conference secretariat
secretariat@tmec2027.com
Data Protection Officer (DPO)
dpo@buu.ac.th

2 Personal data we collect for this conference

We collect only what the conference actually needs. Not every item applies to every participant — the research and shuttle-bus data exist only if you use those services.

Account
E-mail address, password (kept only as a one-way hash — we never see it), title and name.
Registration details
Institution, country, telephone number, participant category, the academic track you are interested in, an invitation code if you were given one, and any dietary requirement you tell us so that meals can be ordered.
Payment and receipt
The image of your bank transfer slip, the bank reference and transfer date, and the name and address you give us for the official receipt.
Attendance
The day and time you check in at the venue, used to admit you and to work out which certificate you are entitled to.
Research submission
The title of your work, co-authors, presenter name, institution, contact e-mail and the manuscript file you upload.
Shuttle bus
Your name, telephone number, e-mail and the hotel you are staying at.

3 Why we use your data, and on what legal basis

We rely on the legal bases set out in the university's central Privacy Notice. We do not ask for your consent for the data above, because the conference cannot be run without it — asking for a consent you could not realistically refuse would be misleading.

Running the conference
Registration, name badge, venue check-in and your certificate of attendance. Basis: public task and performance of a contract.
Fees and accounting
Verifying your transfer, issuing the official receipt and keeping the accounting records the law requires. Basis: performance of a contract and legal obligation.
Contacting you
Confirmation e-mails, payment results, the QR code you present at the venue and conference announcements. Basis: performance of a contract.
Academic programme
Peer review of submitted research, notifying you of the result, and publishing accepted work in the conference proceedings. Basis: public task.
Publicity
Photographs and video recorded during the event may be published on the university's websites and social media, as already stated in the university's central Privacy Notice. Basis: public task.

4 Who else receives your data

We do not sell your data and we do not pass it to anyone for marketing. It is shared only with the parties below, and only with what each of them needs.

Consortium of Thai Medical Schools
Participation figures and academic reporting for the conference.
Catering provider
Meal counts and dietary requirements.
Shuttle bus operator
Pick-up points and passenger numbers per hotel.
Certificate provider
The name to be printed and the days you attended.
E-mail service provider
Delivery of the conference e-mails sent to you.
QR code service (outside Thailand)
Your registration number — for example TMEC2027-00001 — is sent to an external service that turns it into the QR code image in your e-mail. The number on its own does not identify you and no name, e-mail or payment data is sent.

5 How long we keep it

When a retention period ends, the data is deleted or anonymised so that it can no longer identify you.

Financial records
Transfer slips, receipt details and accounting entries — kept for 10 years after the end of the fiscal year in which the conference is held, as required by accounting and tax law and the university's financial regulations.
Account and registration records
Kept while the conference cycle is running and for 5 years after the conference ends, for reference and certificate re-issue.
Attendance records
Kept for 5 years after the conference ends, so that a certificate can be re-issued or verified.
Telephone number and shuttle-bus data
Deleted within 90 days after the conference ends — they are needed only to run the transport on the day.
Research files
Work that is not accepted is destroyed after the conference closes, as stated in the submission guideline. Accepted work is retained as part of the academic record.

6 Your rights

Under the Personal Data Protection Act B.E. 2562 you have the following rights over your own data.

Access
Ask what data we hold about you and obtain a copy of it.
Rectification
Have data that is inaccurate, out of date or incomplete corrected.
Erasure
Ask us to delete or anonymise your data when we no longer have a lawful reason to keep it.
Restriction
Ask us to pause the use of your data while a request or objection is being examined.
Objection
Object to a particular use of your data.
Portability
Receive the data you gave us in a machine-readable form, or have it sent to another controller.
Withdraw consent
Where a specific activity does run on your consent, withdraw it at any time. Withdrawing does not affect what was done lawfully beforehand.

To exercise any of these rights, write to the conference secretariat or to the university Data Protection Officer using the addresses in section 1. We will answer within 30 days. If you are not satisfied, you may complain to the Personal Data Protection Committee.

7 Relationship to the university notice, and version

This notice describes one activity — the 26th Thai Medical Education Conference. Everything it does not cover is governed by the central Privacy Notice of Burapha University and by the university's Personal Data Protection Policy Regulation B.E. 2564, which continue to apply in full.

If we change how we use your data, we will publish a new version of this page. The version number below tells you which wording you acknowledged when you registered.

Version 1.1
Effective date 11 Aug 2026
Questions secretariat@tmec2027.com  ·  dpo@buu.ac.th