TTC Digital
Talk to us
OTA listing management
Listed, ranked and selling on the booking sites
Listing audit + rewrite
One listing checked, rewritten and repriced
Google Business Profile optimization
Found and booked on Google Maps
SEO & GEO
Found by Google and AI assistants
Operator websites with booking engine
Direct bookings on your own site
Hotel showcase websites
A clean site with booking links and WhatsApp contact
Photo packs
Sharper, brighter photos for your listings
Legal

Privacy Policy

Last updated: 23 September 2026 · Version 1.0
How TTC Digital handles personal data of clients, prospects, website visitors and travellers. Questions: contact@ttcdigitalagency.com.

1. Who we are

TTC Digital is a trade name of AppaSP, a sole proprietorship registered in the Netherlands (KVK 89898893), Oldenzaalsestraat 797, 7524 AD Enschede, the Netherlands ("TTC", "we"). ThaiTourConnect is a further trade name of the same business. Privacy contact: contact@ttcdigitalagency.com.

We provide digital marketing and web services to tourism businesses: OTA listing management, listing audits, Google Business Profile optimisation, SEO/GEO, websites with a booking engine, and marketing photos.

2. Who this policy covers

This policy explains how we handle personal data of:

  • Clients and prospects: owners and staff of tour operators, transfer operators, hotels and other businesses we work with or contact.
  • Website visitors: people who visit ttcdigitalagency.com, thaitourconnect.com or our other brand sites.
  • Travellers: customers of our clients whose data we see while working inside our clients' accounts, or who book through a website we built for a client.

3. Our role depends on the data

  • For clients, prospects and website visitors, we are the controller under the EU General Data Protection Regulation (GDPR).
  • For traveller data inside a client's OTA, Google or analytics account, the client is the controller and we act as its processor. We only work inside those accounts on the client's instructions and never take ownership of the account or the data.
  • For bookings made through the booking engine on a client website, the booking engine is operated by AppaSP under the Jai Thai Travel brand as booking and payment agent. AppaSP and the client are each independent controllers, as described in the privacy policy shown on that website.

We are not an online travel agency and we do not sell tours. If you booked a tour through GetYourGuide, Viator, Klook or another platform, that platform and the tour operator are responsible for your data; please contact them first.

4. What we collect and why

4.1 Clients and prospects

DataWhyLegal basis
Name, role, business name, email, phone, WhatsApp or LINE ID, address, business and tax registration numbers, tourism licence detailsOnboarding, delivering the services, invoicing, tax and accounting recordsContract; legal obligation (Dutch tax law, DAC7 where applicable)
Messages and call notes with you (email, WhatsApp, LINE)Running the engagement, keeping track of instructions and approvalsContract; legitimate interest (record of agreed work)
Login invitations you send us to your OTA, Google or hosting accountsDoing the work you asked for inside your accountsContract
Prospect contact details (name, business, phone, LINE or WhatsApp, email) found through public listings, platforms, referrals or your own enquiryContacting you about our services, following up on your interestLegitimate interest (B2B marketing); you can object at any time and we stop
Bank details on your invoices to us, our payment recordsPayments and bookkeepingContract; legal obligation

We do not run automated decision-making or profiling that produces legal effects on you.

4.2 Website visitors

DataWhyLegal basis
Contact form and enquiry details (name, business, email, phone, message)Answering you and following upPre-contractual steps; legitimate interest
Technical data (IP address, browser, device, pages visited, referrer) collected by hosting and analyticsKeeping the site secure and understanding how it is usedLegitimate interest (security); consent for analytics cookies where required
Cookies and similar technologiesSee section 10Consent, except strictly necessary cookies

4.3 Traveller data inside client accounts (as processor)

While managing a client's OTA listings, Google Business Profile or website analytics we may see traveller names, booking details, messages and reviews. We use this data only to perform the service for that client (for example to update a listing, answer a content query or report booking numbers to the client). We do not copy it out of the platform unless the service requires it, we do not use it for our own marketing, and we do not share it with other clients or third parties. Any request from a traveller about this data is handled by the client (the tour operator) and the platform.

4.4 Booking engine on client websites

When you book through a website we built, the booking data (name, email, phone, nationality where required, pick-up details, payment via the payment provider) is processed by AppaSP as booking and payment agent and shared with the tour operator delivering your service. The privacy policy published on that website explains this in full, including the operator's own use of your data and how to opt out of its marketing.

5. Who we share data with

We share personal data only where needed to run our business and deliver the services:

  • Service providers working under our instructions: website hosting (Vercel), email delivery (SendGrid), business email and file storage (Google Workspace), analytics (Google Analytics), messaging apps (WhatsApp, LINE), and AI-assisted tools used for drafting listing text and marketing content.
  • Freelancers and team members who work on your account under confidentiality obligations. They see only what their task requires.
  • Platforms such as GetYourGuide, Viator, Klook, Trip.com, 12Go and Google, where we enter the client's own business information into the client's account. The platform then processes that data under its own privacy policy.
  • Authorities, advisers and insurers where the law requires it, to comply with tax obligations (including DAC7 reporting where it applies), or to establish or defend legal claims.
  • A successor if our business is sold or restructured; we will inform you.

We never sell personal data, and we never share one client's data or prospects with another client.

6. International transfers

We are based in the Netherlands and work with clients mainly in Thailand and elsewhere in Asia. Your business contact data therefore moves between the EU and your country as a necessary part of our contract with you (GDPR Article 49(1)(b)). Where our providers process data outside the EU (for example in the United States), we rely on the EU-US Data Privacy Framework where the provider is certified, or on the European Commission's standard contractual clauses. Traveller data we access inside a client's platform account stays on that platform; we do not move it.

7. How long we keep data

DataRetention
Client contract, invoicing and tax records7 years after the financial year concerned (Dutch fiscal retention duty)
Client correspondence and account access recordsDuration of the engagement plus 3 years, for evidence of instructions and approvals
Prospect contact detailsUntil you object or 2 years after our last contact, whichever comes first
Website enquiries1 year after we last replied
Analytics dataPer the analytics provider's setting, at most 26 months
Traveller data seen inside client accountsNot stored by us; any working copies are deleted at the end of the task or the engagement

8. Security

We use two-factor authentication on our own accounts, work inside client platforms only through named user access, keep client data in access-controlled business tools, and bind freelancers to confidentiality. No method of transmission or storage is completely secure; if a personal data breach affecting you occurs we will inform you and, where required, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) without undue delay.

9. Your rights

Under the GDPR you may ask us to access, correct, delete or restrict your personal data, to receive it in a portable format, and you may object to processing based on legitimate interest, including B2B marketing, at any time. Where processing is based on consent you may withdraw it, without affecting earlier processing. Email us at contact@ttcdigitalagency.com; we reply within one month. You may also complain to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or your local supervisory authority. Clients in Thailand have comparable rights under the Personal Data Protection Act (PDPA), which we honour in the same way.

If you are a traveller and your request concerns a booking with a tour operator, we will forward your request to that operator or platform, since they control that data.

10. Cookies

Our websites use strictly necessary cookies to function and, with your consent, analytics cookies (Google Analytics) to understand how the site is used. You can accept or refuse non-essential cookies in the banner and change your choice at any time via the cookie settings link in the footer. Details are in our Cookie Policy.

11. Changes to this policy

We may update this policy when our services or the law change. The effective date at the top shows the current version. For material changes affecting clients we send an email notice.

12. Contact

TTC Digital (AppaSP), Oldenzaalsestraat 797, 7524 AD Enschede, the Netherlands. KVK 89898893. Email: contact@ttcdigitalagency.com.