Home / Privacy Policy
Privacy Policy
How Padauk, the provider of Maha Hub, collects, uses, shares and protects personal data, and the rights you have.
- 1. Who we are
- 2. Our role: controller and processor
- 3. Personal data we collect
- 4. Why we use it and our legal bases
- 5. Who we share it with
- 6. International transfers
- 7. How we protect personal data
- 8. How long we keep it
- 9. Your rights
- 10. Cookies
- 11. Children
- 12. Changes to this policy
- 13. Contact
Last updated: 8 October 2026
1. Who we are
Maha Hub is a product of Padauk Hospitality Technology and Academy ("Padauk"). Registered address: [To be added]. Contact: support@maha-hub.com.
This Privacy Policy explains how Padauk Hospitality Technology and Academy ("Padauk", "we", "us"), the provider of Maha Hub, collects, uses, shares and protects personal data when you visit maha-hub.com, contact us, subscribe to Maha, or use Maha software.
We process personal data in line with applicable data protection laws, including, where they apply, Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA") and the EU and UK General Data Protection Regulation ("GDPR").
2. Our role: controller and processor
Data protection law distinguishes between a controller, which decides why and how personal data is processed, and a processor, which processes it on a controller's instructions.
- Padauk as controller. We are the controller for personal data about website visitors, people who contact us, and the business contacts and users of our customers, which we use to run our business and the Maha service.
- Padauk as processor. When a hotel enters guest, reservation or staff data into Maha, the hotel is the controller of that data and Padauk processes it only on the hotel's behalf and instructions, to provide the service. Guests who have questions about their data should contact the hotel directly.
3. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Enquiry and contact data | Name, business or hotel name, email, phone, country, message | You, through our forms or email |
| Account and user data | Name, username, email, role, shift records, sign-in activity | The customer and its users |
| Billing data | Billing contact, plan, invoices, payment status | The customer and Stripe (card numbers stay with Stripe) |
| Customer business data | Guest, reservation, folio and staff records entered by a hotel | The hotel, as controller |
| Technical data | IP address, browser and device type, pages visited, error logs | Automatically, when you use our website or apps |
We do not ask for, and customers should not enter, sensitive personal data in Maha unless the law requires it for guest registration.
4. Why we use it and our legal bases
| Purpose | Legal basis |
|---|---|
| Providing, operating and supporting Maha for our customers | Performance of a contract |
| Responding to enquiries, demos and quotes | Steps at your request before a contract; legitimate interests |
| Billing, payments and accounting records | Contract; legal obligation |
| Keeping Maha secure and preventing fraud or misuse | Legitimate interests; legal obligation |
| Improving our website and products using usage information | Legitimate interests |
| Sending news about Maha products | Consent, which you may withdraw at any time |
| Meeting legal, tax and regulatory requirements | Legal obligation |
We do not sell personal data, and we do not use customer business data for advertising. We do not make decisions about individuals based solely on automated processing.
5. Who we share it with
We share personal data only where necessary, and only with:
- Service providers acting on our instructions, including Cloudflare (hosting, content delivery and network security), Stripe (payment processing) and cloud database hosting. Each is bound by contractual confidentiality and security obligations.
- The customer whose account you use, for user and activity information within that customer's workspace.
- Authorities or advisers where required by law, to protect rights or safety, or in connection with legal claims.
- A successor business if Maha Hub is reorganised, merged or sold, subject to this policy.
6. International transfers
Our providers may process data in countries other than the one in which it was collected. Where this happens, we rely on appropriate safeguards required by applicable law, such as contractual protections, so that personal data remains protected to the standard described in this policy.
7. How we protect personal data
We apply technical and organisational measures appropriate to the risk, including role-based access controls, individual user accounts, shift-based sign-in, per-hotel and per-product activation, encrypted connections (HTTPS), and the security protections of our infrastructure providers. Read more on our Data security page.
No system is completely secure. If a personal data breach occurs that is likely to affect your rights, we will notify affected customers and, where required, regulators and individuals within the periods the law sets.
8. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not become customers | Up to 24 months after our last contact, unless you ask us to delete them sooner |
| Account and user data | For the life of the subscription, then deleted or anonymised after it ends, unless needed for a dispute |
| Customer business data | For the life of the subscription; returned or deleted on request when it ends, subject to the customer agreement |
| Billing and accounting records | As long as tax and accounting laws require |
| Technical logs | Only as long as needed for security and troubleshooting |
9. Your rights
Subject to applicable law, you have the right to:
- be informed about how your personal data is used;
- access and receive a copy of your personal data;
- correct personal data that is inaccurate or incomplete;
- request deletion, destruction or anonymisation;
- restrict or object to certain processing, including direct marketing;
- request data portability;
- withdraw consent at any time, without affecting earlier processing;
- complain to the relevant data protection authority, such as Thailand's Personal Data Protection Committee.
To exercise a right, email support@maha-hub.com. We may need to verify your identity, and will respond within the time the law requires, normally within 30 days. If your request concerns guest data held by a hotel, we will pass it to that hotel and assist it in responding.
10. Cookies
Our website uses only cookies and similar technologies that are strictly necessary for it to work and to keep it secure. We do not currently use advertising cookies. If we introduce analytics or marketing cookies, we will update this policy and ask for consent where the law requires it.
11. Children
Maha Hub is a business service and is not directed to children. We do not knowingly collect personal data from children for our own purposes. Where a hotel records a child guest, the hotel is responsible for that data as controller.
12. Changes to this policy
We may update this policy to reflect changes in our services or the law. The date at the top shows the latest version. Where changes are significant, we will give notice on our website or directly to customers before they take effect.
13. Contact
For any privacy question or request, contact Padauk at support@maha-hub.com.
