Accounts and communication
We may collect a name, email address, telephone number, organization, role, account identifiers, login and authentication records, communication preferences, and information you choose to place in an account profile.
Operation Siam · Legal
This policy explains how Dega Central Highlands Organization handles personal information when people use the Operation Siam website, create an account, request support, or make a contribution.
Operation Siam serves audiences that can face serious privacy and safety risks. We seek the minimum information needed for a stated purpose, separate public contact from protected follow-up, and do not require refugee, asylum, immigration, or resettlement records in order to make a contribution.
Operation Siam is a launch-phase humanitarian initiative coordinated by Dega Central Highlands Organization (“DCHO,” “we,” “us,” or “our”). DCHO is responsible for the Operation Siam website and the personal information described in this policy, except where an identified third party processes information under its own privacy policy.
This policy applies to Operation Siam public pages, accounts and portals, contact and support forms, support tickets, contribution checkout, transaction and receipt records, and related security and administrative systems. A partner organization may provide a separate notice when it collects information directly for its own services.
Operation Siam is not part of UNHCR, IOM, the Royal Thai Government, the U.S. Government, or another institution unless a written relationship is specifically identified. Contacting us does not automatically send information to any of those institutions.
We may collect a name, email address, telephone number, organization, role, account identifiers, login and authentication records, communication preferences, and information you choose to place in an account profile.
We collect the enquiry category, message, safe reply method, ticket history, and follow-up correspondence. Attachments are collected only when the feature is used; sensitive records should be shared only after an authorized recipient and protected channel are confirmed.
Operation Siam may record the selected contribution option, amount, currency, billing cycle, invoice or receipt number, transaction status, payment method category, refunds, cancellations, and related account or support history.
Servers and security tools may record IP address, browser and device information, requested pages, referring page, timestamps, session identifiers, errors, login attempts, and events needed to detect abuse or protect the service.
Cookies or browser storage may remember a session, security token, accessibility or theme choice, language, cart contents, and other settings needed to provide the requested experience.
We may receive transaction confirmation from a payment provider, a referral from a partner with an appropriate basis to share it, or public institutional information used for due diligence and communication.
Sensitive refugee information
Refugee and asylum information can expose a person or family to harm. Do not place passports, identity documents, UNHCR or National Screening Mechanism records, immigration history, exact live locations, detention or court files, medical records, children’s records, or detailed protection histories in a public form or first message.
We use transaction information to complete and acknowledge one-time or recurring contributions, issue records, manage cancellations or refunds, and answer account questions.
Card or bank credentials entered in a payment provider’s interface are processed by that provider under its own terms and privacy policy. We generally do not receive or store a full payment-card number or security code, although Operation Siam retains the contribution, invoice, payment status, and processor reference needed to administer the transaction.
Necessary cookies or browser storage support login sessions, request security, fraud prevention, language, theme, and cart continuity. Preference storage can usually be reset through browser controls, although blocking necessary storage may prevent accounts, checkout, or other features from working.
We may send service, security, receipt, contribution-cycle, or support messages. Optional updates or appeals are sent according to the choices available to you and applicable law. We may use aggregated or de-identified information to understand demand and improve public information without publishing identifiable case details.
Depending on the activity and applicable law, we process information to take steps you request or perform an agreement, with consent, to comply with legal obligations, to protect vital interests, or for legitimate interests such as service delivery, security, fraud prevention, accountability, and responsible organizational administration. We consider the rights and risks of affected people when relying on legitimate interests.
We do not sell or rent personal information. We may share the minimum necessary information with hosting, security, email, support, payment, accounting, and other service providers that help operate Operation Siam; with professional advisers who owe duties of confidentiality; or with a receiving organization in a documented organizational transition subject to appropriate safeguards.
We may disclose information when reasonably necessary to comply with applicable law, a valid legal process, or a competent authority; to protect the rights, safety, and security of a person, DCHO, Operation Siam, or the public; or to investigate fraud or abuse. Where permitted and safe, we seek to limit the information disclosed and notify the affected person.
A case referral to a government, UN body, legal provider, humanitarian organization, or other service provider is not automatic. We normally explain the proposed referral and seek appropriate consent before sharing identifiable case information, except where law or an urgent safety circumstance permits or requires otherwise.
We retain information only as long as reasonably necessary for the purpose collected and for operational, safeguarding, accounting, audit, dispute, security, and legal needs. Account records may remain while an account is active; transaction and tax records may be kept for legally required accounting periods; support records may be kept through resolution and a proportionate review period; and security logs are retained according to risk and system needs.
When information is no longer needed, we take reasonable steps to delete, de-identify, or securely archive it. A deletion request may not remove information we must retain for legal, accounting, security, safeguarding, or dispute purposes, and deletion from backups may occur through the normal backup lifecycle.
We use administrative, technical, and organizational safeguards intended to protect information in light of its sensitivity. Measures may include access controls, role separation, authentication, secure connections, backups, updates, logging, and procedures for reviewing incidents. No internet transmission or storage system can be guaranteed completely secure.
If you believe information or an account has been compromised, contact us promptly and avoid sending the affected data in an ordinary email.
DCHO is based in North Carolina, United States, while Operation Siam concerns communities and institutional engagement that may involve Thailand and other countries. Information may therefore be accessed or processed in the United States or another country where an identified service provider or authorized recipient operates.
Privacy protections and government-access rules can differ between countries. We seek to use appropriate contractual, technical, and organizational safeguards where required and practicable, while recognizing that an international transfer may be necessary to provide the requested service.
Depending on applicable law and the circumstances, you may ask to access, correct, delete, restrict, or obtain a copy of personal information, object to certain uses, or withdraw consent for a consent-based activity. You may also change account information, communication choices, browser storage, or a recurring contribution through available account and support tools.
We may need to verify identity and authority before acting on a request. Applicable exceptions can limit a request, including protection of another person, freedom of expression, security, fraud prevention, legal claims, and required records. We will explain a denial when we can. You may also raise a concern with an applicable privacy or consumer-protection authority.
The public account and contribution features are not directed to children under 13, and we do not knowingly invite a child under 13 to open an account or make a contribution independently. A parent, guardian, or appropriately authorized adult should use those features for a child where appropriate.
Humanitarian or safeguarding work may concern a child. In that context, information should be handled through an authorized pathway using heightened necessity, safety, consent or other appropriate authority, and access controls. Never place a child’s identity or case records in a public form.
Changes and questions
We may update this policy as Operation Siam launches, its services change, or legal and security requirements develop. The current version will show its effective date. If a change materially affects how existing personal information is used, we will provide an appropriate notice where reasonably practicable.
Powered by WHMCompleteSolution