Privacy Policy
At the JUMP Foundation, we believe that every student, teacher, and school partner we work with deserves a safe, meaningful, and trusted experience — both during our programs and when interacting with us online. Protecting personal information is a critical element of our responsibility.
This Privacy Notice explains what information we collect, why we collect it, how we protect it, and the choices you have. We follow the Thailand Personal Data Protection Act (PDPA), the Singapore Personal Data Protection Act (PDPA), and other applicable laws in the places where we operate.
The Information We Collect — and Why
When planning school programs, we only request information needed to deliver a secure, well-organized, and compliant program experience. This may include:
- Identity information: name, date of birth, nationality, passport/ID number
- Health information: allergies, medical needs, dietary requirements — only as necessary to protect wellbeing
- Travel information: visa details, itineraries, insurance information
- Education details: school name, grade level, program specifics
- Parent/guardian contact information: usually provided by the school
We use this information to:
- ensure health, safety, and wellbeing during the program
- arrange travel, accommodation, activities, and support
- fulfil legal and immigration requirements
- communicate important program updates to schools and families
We do not use personal data for any other reason without clear and documented consent.
Our Legal Basis
We process personal data only when one or more legal grounds apply:
- Consent from participants or legal guardians
- Contractual necessity to execute booked program services and delivery
- Legal obligations including safety and immigration requirements
- Legitimate interests that support safe and efficient operations
We are committed to transparency and fairness when handling personal information.
PDPA Compliance
We comply with both the Thailand Personal Data Protection Act (PDPA) and Singapore Personal Data Protection Act (PDPA). That includes:
- Collecting and using data only with appropriate consent or lawful basis
- Allowing individuals or schools to withdraw consent at any time
- Ensuring personal data transferred outside Thailand and Singapore receives a comparable level of protection
- Retaining data only as long as necessary for operations or legal requirements,often only until the completion of a Program
- Supporting access and correction requests for Thailand and Singapore-related data
We also coordinate with participating schools to manage consent and communication according to any local PDPA requirements.
Who We Share Information With
We only share personal data with trusted parties who support the delivery and safety of our programs, such as:
- Airlines, hotels, and transportation providers
- Licensed activity and program partners
- Medical providers in the event of emergencies
- Immigration or public authorities when required by law
These parties are contractually obligated to protect the information and must not use it for any other purposes.
How We Keep Data Safe
We use safeguards and security protocols to keep personal data protected throughout its lifecycle, including:
- Encryption of sensitive personal data in transit and at rest
- Multi-factor authentication for systems containing personal information
- Access controls to ensure only authorized personnel can view data
- Vendor risk management, requiring third-party partners to uphold protective standards
- Secure retention and disposal, deleting information when no longer needed
- Ongoing oversight by our nominated Data Protection Officer (DPO)
We strive to continuously review and improve our protections based on evolving best practices.
Your Rights and Choices
Participants, or their parents/guardians where appropriate, have the right to:
- Request access to personal data we hold
- Request correction of inaccurate or incomplete information
- Request erasure of personal information when permitted by law
- Object to certain processing purposes
- Withdraw consent where applicable, without affecting already completed processing based on earlier consent
Our Data Protection Officer is available to support you with any of these requests.
If Something were to Go Wrong
If an incident occurs where personal information may be at risk, we follow a clear response procedure:
- Immediate reporting to the DPO by any staff or partner who becomes aware of a possible breach
- Rapid investigation and assessment of what happened and who may be affected
- Notification to individuals and authorities when risks are identified
When Singapore PDPA applies, we are committed with the requirement to notify the PDPC and affected individuals within 72 hours after determining a breach is notifiable providing:.
- Clear guidance and support to those affected
- Containment and remediation actions to reduce potential harm
- Documentation and review of all breach incidents to prevent recurrence
We take transparency and timely communication seriously.
Cookies and Website Use
Our website at times uses a limited number of cookies — small files stored on your device — to:
- support website operation
- improve performance and user experience
- help us understand how visitors engage with our content
You may adjust cookie settings in your browser. Some site features may not function fully if certain cookies are disabled.
Updates to This Notice
Privacy requirements change over time, and so may this Notice. Updates will always be posted here, with a revised date, so you remain informed about how your data is protected.
Contact Us
If you have any questions, concerns, or would like to exercise a privacy right, please contact our Data Protection Officer (DPO):
FAO: Data Protection Officer (DPO)
28/3 Inthamara Alley, Samsen Nai,
Phaya Thai, Bangkok
10400, Thailand
We value your trust — and we are committed to keeping your personal information safe, respectful, and protected.