ກັບຄືນ

ນະໂຍບາຍຄວາມເປັນສ່ວນຕົວ

Privacy Policy

ເວີຊັນ 2.0 ອັບເດດ 24/08/2026 15:08 privacy_policy 7,401 ຕົວອັກສອນ

ພາສາລາວ

ນະໂຍບາຍຄວາມເປັນສ່ວນຕົວ

ຜູ້ຮັບຜິດຊອບຂໍ້ມູນ (Data Controller): ບໍລິສັດ PSL Service ໃນນາມຜູ້ໃຫ້ບໍລິການແພລດຟອມ LAO G-AIR
ສະບັບທີ: 2.0  ·  ມີຜົນບັງຄັບໃຊ້ແຕ່ວັນທີ: 24 ສິງຫາ 2026

ນະໂຍບາຍນີ້ອະທິບາຍວ່າ ພວກເຮົາເກັບກຳຂໍ້ມູນສ່ວນບຸກຄົນຫຍັງແດ່, ເກັບເພື່ອຫຍັງ, ແບ່ງປັນໃຫ້ໃຜ, ຮັກສາໄວ້ດົນປານໃດ ແລະ ທ່ານມີສິດຫຍັງແດ່ເໜືອຂໍ້ມູນຂອງທ່ານ. ລາຍການຂໍ້ມູນທີ່ລະບຸໄວ້ຂ້າງລຸ່ມນີ້ ແມ່ນອີງໃສ່ຂໍ້ມູນທີ່ລະບົບ LAO G-AIR ເກັບໄວ້ໃນຖານຂໍ້ມູນຕົວຈິງ ບໍ່ແມ່ນຂໍ້ຄວາມທົ່ວໄປ.

1. ຂອບເຂດການນຳໃຊ້

ນະໂຍບາຍນີ້ນຳໃຊ້ກັບ:

  • ລູກຄ້າບຸກຄົນ ແລະ ລູກຄ້ານິຕິບຸກຄົນ (ອົງກອນ) ທີ່ຈອງປີ້ຜ່ານລະບົບ;
  • ຕົວແທນຂາຍປີ້ ແລະ ພະນັກງານຂອງຕົວແທນ ທີ່ໃຊ້ລະບົບຕົວແທນ;
  • ຜູ້ໂດຍສານ ທີ່ຂໍ້ມູນຖືກປ້ອນເຂົ້າລະບົບໂດຍລູກຄ້າ ຫຼື ຕົວແທນ;
  • ຜູ້ເຂົ້າຊົມເວັບໄຊ ທີ່ຍັງບໍ່ໄດ້ລົງທະບຽນ.

ຖ້າທ່ານປ້ອນຂໍ້ມູນຂອງບຸກຄົນອື່ນ (ຕົວຢ່າງ: ຜູ້ໂດຍສານຮ່ວມ, ສະມາຊິກໃນຄອບຄົວ, ພະນັກງານຂອງອົງກອນ) ທ່ານຮັບປະກັນວ່າ ທ່ານໄດ້ຮັບອະນຸຍາດຈາກເຈົ້າຂອງຂໍ້ມູນນັ້ນແລ້ວ ແລະ ໄດ້ແຈ້ງນະໂຍບາຍນີ້ໃຫ້ເຂົາເຈົ້າຊາບ.

2. ຂໍ້ມູນທີ່ພວກເຮົາເກັບກຳ

ປະເພດຂໍ້ມູນລາຍການທີ່ເກັບຕົວຈິງ
ບັນຊີຜູ້ໃຊ້ອີເມວ, ເບີໂທລະສັບ, ຊື່-ນາມສະກຸນ (ພາສາລາວ ແລະ ອັງກິດ), ປະເພດຜູ້ໃຊ້, ອົງກອນທີ່ສັງກັດ, ສະຖານະບັນຊີ, ວັນທີຢືນຢັນອີເມວ/ເບີໂທ, ວັນທີເຂົ້າລະບົບຫຼ້າສຸດ ແລະ ລະຫັດຜ່ານທີ່ຖືກເຂົ້າລະຫັດແບບທາງດຽວ (hash) — ພວກເຮົາບໍ່ເກັບລະຫັດຜ່ານເປັນຂໍ້ຄວາມທຳມະດາ
ຜູ້ໂດຍສານຄຳນຳໜ້າຊື່, ຊື່-ນາມສະກຸນ (ລາວ/ອັງກິດ), ວັນເດືອນປີເກີດ, ສັນຊາດ, ເລກໜັງສືຜ່ານແດນ ແລະ ວັນໝົດອາຍຸ, ເບີໂທ, ອີເມວ, ຄວາມຕ້ອງການພິເສດ (ອາຫານ, ການຊ່ວຍເຫຼືອດ້ານສຸຂະພາບ)
ການຈອງ ແລະ ການເດີນທາງລະຫັດການຈອງ, ຖ້ຽວບິນ, ຊັ້ນໂດຍສານ, ວັນທີເດີນທາງ, ແຜນການເດີນທາງ, ຜູ້ເຂົ້າຮ່ວມແຜນເດີນທາງ, ໃບສະເໜີລາຄາ ແລະ ໃບບິນ
ການຊຳລະເງິນວິທີການຊຳລະ, ເລກອ້າງອີງທຸລະກຳ, ຈຳນວນເງິນ, ສະກຸນເງິນ, ອັດຕາແລກປ່ຽນ, ສະຖານະການຊຳລະ, ຂໍ້ຄວາມຕອບກັບຈາກຜູ້ໃຫ້ບໍລິການຊຳລະ ແລະ ຫຼັກຖານການໂອນທີ່ທ່ານອັບໂຫຼດ. ພວກເຮົາບໍ່ເກັບເລກບັດເຄຣດິດ/ເດບິດເຕັມ ແລະ ບໍ່ເກັບລະຫັດ CVV
ຕົວແທນ / ນິຕິບຸກຄົນຊື່ບໍລິສັດ ແລະ ຊື່ຕາມກົດໝາຍ, ເລກທະບຽນວິສາຫະກິດ, ເລກປະຈຳຕົວຜູ້ເສຍອາກອນ, ໃບອະນຸຍາດດຳເນີນທຸລະກິດ, ທີ່ຢູ່ ແລະ ພິກັດທີ່ຕັ້ງ, ຊື່ທະນາຄານ ແລະ ເລກບັນຊີ, ຜູ້ຕິດຕໍ່ປະສານງານ ພ້ອມອີເມວ ແລະ ເບີໂທ
ເອກະສານແນບໄຟລ໌ທີ່ອັບໂຫຼດ (ເອກະສານປະກອບການສະໝັກຕົວແທນ, ເອກະສານການຈອງ, ເອກະສານແຜນເດີນທາງ) ພ້ອມຊື່ໄຟລ໌, ຂະໜາດ, ປະເພດໄຟລ໌ ແລະ ຜູ້ອັບໂຫຼດ
ຂໍ້ມູນທາງເຕັກນິກ ແລະ ຄວາມປອດໄພທີ່ຢູ່ IP, ຂໍ້ມູນເບຣົາເຊີ (user agent), ບັນທຶກການພະຍາຍາມເຂົ້າລະບົບ (ສຳເລັດ/ລົ້ມເຫຼວ ພ້ອມສາເຫດ), ເຊສຊັນການໃຊ້ງານ ແລະ ບັນທຶກການເຄື່ອນໄຫວຂອງຜູ້ໃຊ້ໃນລະບົບ

ໝາຍເຫດ: ຂໍ້ມູນ “ຄວາມຕ້ອງການພິເສດ” ອາດພົວພັນເຖິງສຸຂະພາບ ຫຼື ຄວາມເຊື່ອທາງສາສະໜາ (ຕົວຢ່າງ: ອາຫານພິເສດ, ລົດເຂັນ). ພວກເຮົາໃຊ້ຂໍ້ມູນປະເພດນີ້ສະເພາະເພື່ອຈັດການບໍລິການທີ່ທ່ານຮ້ອງຂໍ ແລະ ສົ່ງໃຫ້ສາຍການບິນເທົ່ານັ້ນ.

3. ຈຸດປະສົງ ແລະ ພື້ນຖານທາງກົດໝາຍ

ຈຸດປະສົງພື້ນຖານທາງກົດໝາຍ
ອອກປີ້, ຢືນຢັນການຈອງ, ອອກໃບບິນ ແລະ ໃຫ້ບໍລິການຫຼັງການຂາຍການປະຕິບັດສັນຍາລະຫວ່າງທ່ານກັບພວກເຮົາ
ສົ່ງຂໍ້ມູນຜູ້ໂດຍສານໃຫ້ສາຍການບິນ ແລະ ອົງການທີ່ກ່ຽວຂ້ອງການປະຕິບັດສັນຍາ ແລະ ພັນທະຕາມກົດໝາຍ
ອອກໃບເກັບເງິນ, ບັນຊີ ແລະ ການເສຍອາກອນພັນທະຕາມກົດໝາຍວ່າດ້ວຍການບັນຊີ ແລະ ກົດໝາຍວ່າດ້ວຍສ່ວຍສາອາກອນ
ພິສູດຢືນຢັນຕົວຕົນ, ປ້ອງກັນການສວມຮອຍ ແລະ ການສໍ້ໂກງ, ບັນທຶກການເຄື່ອນໄຫວໃນລະບົບພັນທະຕາມກົດໝາຍວ່າດ້ວຍການປົກປ້ອງຂໍ້ມູນທາງເອເລັກໂຕຣນິກ ແລະ ຜົນປະໂຫຍດອັນຊອບທຳຂອງຜູ້ໃຫ້ບໍລິການ
ພິຈາລະນາໃບສະໝັກເປັນຕົວແທນ ແລະ ຄິດໄລ່ຄ່ານາຍໜ້າການປະຕິບັດສັນຍາຕົວແທນ
ສົ່ງຂ່າວສານ ຫຼື ໂປຣໂມຊັນຄວາມຍິນຍອມຂອງທ່ານ ເຊິ່ງຖອນຄືນໄດ້ທຸກເວລາ

4. ຄວາມຍິນຍອມ

ເມື່ອທ່ານລົງທະບຽນ ທ່ານຕ້ອງຕິກຍອມຮັບເງື່ອນໄຂການໃຊ້ບໍລິການ ແລະ ນະໂຍບາຍນີ້ ຈຶ່ງຈະສ້າງບັນຊີໄດ້. ທ່ານສາມາດຖອນຄວາມຍິນຍອມສະເພາະສ່ວນທີ່ອີງໃສ່ຄວາມຍິນຍອມ (ເຊັ່ນ: ການຮັບຂ່າວສານ) ໄດ້ທຸກເວລາ ໂດຍບໍ່ກະທົບເຖິງຄວາມຖືກຕ້ອງຂອງການປະມວນຜົນທີ່ໄດ້ດຳເນີນໄປແລ້ວ. ການຖອນຄວາມຍິນຍອມ ບໍ່ລົບລ້າງຂໍ້ມູນທີ່ພວກເຮົາຕ້ອງເກັບໄວ້ຕາມພັນທະທາງກົດໝາຍ.

5. ການເປີດເຜີຍ ແລະ ການແບ່ງປັນຂໍ້ມູນ

ພວກເຮົາບໍ່ຂາຍ ແລະ ບໍ່ໃຫ້ເຊົ່າຂໍ້ມູນສ່ວນບຸກຄົນ. ພວກເຮົາເປີດເຜີຍຂໍ້ມູນສະເພາະເທົ່າທີ່ຈຳເປັນ ໃຫ້ແກ່:

  • ສາຍການບິນ ແລະ ລະບົບສຳຮອງບ່ອນນັ່ງ — ຊື່, ວັນເດືອນປີເກີດ, ສັນຊາດ, ຂໍ້ມູນໜັງສືຜ່ານແດນ ແລະ ຄວາມຕ້ອງການພິເສດ ເພື່ອອອກປີ້;
  • ທະນາຄານ ແລະ ຜູ້ໃຫ້ບໍລິການຊຳລະເງິນ — ເພື່ອຮັບເງິນ, ຄືນເງິນ ແລະ ໂອນຄ່ານາຍໜ້າໃຫ້ຕົວແທນ;
  • ຕົວແທນ ຫຼື ອົງກອນຂອງທ່ານ — ສະເພາະການຈອງທີ່ຕົວແທນ ຫຼື ອົງກອນນັ້ນເປັນຜູ້ດຳເນີນໃຫ້ທ່ານ;
  • ຜູ້ໃຫ້ບໍລິການດ້ານໄອທີ — ຜູ້ໃຫ້ບໍລິການເຊີບເວີ ແລະ ບໍລິການສົ່ງອີເມວ/ແຈ້ງເຕືອນ ພາຍໃຕ້ສັນຍາທີ່ຜູກມັດເລື່ອງຄວາມລັບ;
  • ອົງການຈັດຕັ້ງລັດ — ເຊັ່ນ: ກົມການບິນພົນລະເຮືອນ, ກົມກວດຄົນເຂົ້າ-ອອກເມືອງ, ພາສີ, ສ່ວຍສາອາກອນ ຫຼື ອົງການສືບສວນ-ສອບສວນ ເມື່ອມີການຮ້ອງຂໍຢ່າງຖືກຕ້ອງຕາມກົດໝາຍ.

6. ການສົ່ງຂໍ້ມູນອອກນອກ ສປປ ລາວ

ການເດີນທາງລະຫວ່າງປະເທດ ຮຽກຮ້ອງໃຫ້ສົ່ງຂໍ້ມູນຜູ້ໂດຍສານໄປຍັງສາຍການບິນ ຫຼື ອົງການຄວບຄຸມຊາຍແດນຢູ່ຕ່າງປະເທດ. ຕາມກົດໝາຍວ່າດ້ວຍການປົກປ້ອງຂໍ້ມູນທາງເອເລັກໂຕຣນິກ ເລກທີ 25/ສພຊ ການສົ່ງຂໍ້ມູນອອກນອກປະເທດ ຕ້ອງໄດ້ຮັບຄວາມເຫັນດີ ແລະ ຕ້ອງບໍ່ຂັດກັບຜົນປະໂຫຍດຂອງຊາດ. ພວກເຮົາສົ່ງອອກສະເພາະຂໍ້ມູນທີ່ຈຳເປັນຕໍ່ການເດີນທາງເທົ່ານັ້ນ.

7. ໄລຍະເວລາເກັບຮັກສາ

  • ຂໍ້ມູນບັນຊີ — ຕະຫຼອດເວລາທີ່ບັນຊີຍັງໃຊ້ງານ ແລະ ອີກ 24 ເດືອນ ຫຼັງປິດບັນຊີ;
  • ຂໍ້ມູນການຈອງ ແລະ ຜູ້ໂດຍສານ — ຢ່າງໜ້ອຍ 5 ປີ ນັບແຕ່ວັນເດີນທາງ ເພື່ອຮອງຮັບການຂໍຄືນເງິນ, ການຮ້ອງທຸກ ແລະ ການກວດສອບ;
  • ໃບບິນ, ໃບຮັບເງິນ ແລະ ເອກະສານບັນຊີ — ຕາມກຳນົດເວລາທີ່ກົດໝາຍວ່າດ້ວຍການບັນຊີ ແລະ ກົດໝາຍວ່າດ້ວຍສ່ວຍສາອາກອນກຳນົດ;
  • ບັນທຶກການເຂົ້າລະບົບ ແລະ ບັນທຶກຄວາມປອດໄພ — 12 ເດືອນ;
  • ໃບສະໝັກຕົວແທນທີ່ບໍ່ຜ່ານການອະນຸມັດ — 12 ເດືອນ ນັບແຕ່ວັນແຈ້ງຜົນ.

ເມື່ອໝົດກຳນົດ ຂໍ້ມູນຈະຖືກລຶບ ຫຼື ເຮັດໃຫ້ບໍ່ສາມາດລະບຸຕົວຕົນໄດ້.

8. ມາດຕະການຮັກສາຄວາມປອດໄພ

  • ລະຫັດຜ່ານຖືກເຂົ້າລະຫັດແບບທາງດຽວ (hash) ບໍ່ສາມາດອ່ານກັບຄືນໄດ້;
  • ການເຂົ້າເຖິງຂໍ້ມູນຖືກຄວບຄຸມດ້ວຍລະບົບບົດບາດ ແລະ ສິດອະນຸຍາດ (roles & permissions);
  • ບັນທຶກການພະຍາຍາມເຂົ້າລະບົບ ແລະ ບັນທຶກການເຄື່ອນໄຫວຂອງຜູ້ຄຸ້ມຄອງ ເພື່ອກວດສອບຍ້ອນຫຼັງ;
  • ເຊສຊັນໝົດອາຍຸອັດຕະໂນມັດ (24 ຊົ່ວໂມງ ຫຼື 30 ວັນ ຖ້າເລືອກ “ຈື່ຂ້ອຍໄວ້”);
  • ຮັບສົ່ງຂໍ້ມູນຜ່ານການເຂົ້າລະຫັດ HTTPS.

ເຖິງຢ່າງໃດກໍຕາມ ບໍ່ມີລະບົບໃດປອດໄພ 100%. ຫາກເກີດການຮົ່ວໄຫຼຂອງຂໍ້ມູນທີ່ມີຄວາມສ່ຽງສູງ ພວກເຮົາຈະແຈ້ງໃຫ້ຜູ້ທີ່ຖືກກະທົບ ແລະ ອົງການທີ່ກ່ຽວຂ້ອງຊາບໂດຍໄວ.

9. ສິດຂອງເຈົ້າຂອງຂໍ້ມູນ

  • ຂໍເຂົ້າເຖິງ ແລະ ຂໍສຳເນົາຂໍ້ມູນສ່ວນຕົວຂອງທ່ານ;
  • ຂໍແກ້ໄຂຂໍ້ມູນທີ່ບໍ່ຖືກຕ້ອງ ຫຼື ບໍ່ຄົບຖ້ວນ;
  • ຂໍລຶບຂໍ້ມູນ ຫຼື ປິດບັນຊີ ເທົ່າທີ່ບໍ່ຂັດກັບພັນທະທາງກົດໝາຍ;
  • ຄັດຄ້ານ ຫຼື ຂໍຈຳກັດການປະມວນຜົນບາງປະເພດ;
  • ຖອນຄວາມຍິນຍອມ;
  • ຮ້ອງທຸກຕໍ່ພວກເຮົາ ຫຼື ຕໍ່ອົງການຄຸ້ມຄອງ ຄື ກະຊວງເຕັກໂນໂລຊີ ແລະ ການສື່ສານ.

ພວກເຮົາຈະຕອບຄຳຮ້ອງຂໍພາຍໃນ 30 ວັນ ນັບແຕ່ວັນທີ່ພິສູດຢືນຢັນຕົວຕົນຂອງຜູ້ຮ້ອງຂໍໄດ້.

10. ຂໍ້ມູນຂອງເດັກ

ລະບົບນີ້ບໍ່ໄດ້ອອກແບບໃຫ້ເດັກອາຍຸຕ່ຳກວ່າ 18 ປີ ສ້າງບັນຊີດ້ວຍຕົນເອງ. ຂໍ້ມູນຜູ້ໂດຍສານທີ່ເປັນເດັກ ຫຼື ແອນ້ອຍ ຕ້ອງຖືກປ້ອນໂດຍພໍ່ແມ່, ຜູ້ປົກຄອງ ຫຼື ຕົວແທນທີ່ໄດ້ຮັບມອບໝາຍ.

11. ຄຸກກີ ແລະ ເຊສຊັນ

ພວກເຮົາໃຊ້ຄຸກກີເຊສຊັນ ເພື່ອຮັກສາສະຖານະການເຂົ້າສູ່ລະບົບ ແລະ ຄວາມປອດໄພຂອງແບບຟອມ ເຊິ່ງເປັນຄຸກກີທີ່ຈຳເປັນຕໍ່ການເຮັດວຽກຂອງລະບົບ. ການປິດຄຸກກີດັ່ງກ່າວ ຈະເຮັດໃຫ້ບໍ່ສາມາດເຂົ້າສູ່ລະບົບໄດ້.

12. ການປັບປຸງນະໂຍບາຍ

ນະໂຍບາຍນີ້ອາດຖືກປັບປຸງ. ທຸກຄັ້ງທີ່ປັບປຸງ ເລກສະບັບ ແລະ ວັນທີອັບເດດຢູ່ຫົວເອກະສານຈະປ່ຽນ ແລະ ສະບັບໃໝ່ຈະສະແດງຢູ່ໜ້ານີ້ທັນທີ.

13. ຕິດຕໍ່ພວກເຮົາ

ຄຳຖາມ ຫຼື ຄຳຮ້ອງຂໍກ່ຽວກັບຂໍ້ມູນສ່ວນຕົວ ສາມາດຕິດຕໍ່:
ອີເມວ: [email protected]
ໂທລະສັບ: +856 20 5555 0000
ທີ່ຢູ່: ຖະໜົນຫຼວງພະບາງ, ເມືອງສີສັດຕະນາກ, ນະຄອນຫຼວງວຽງຈັນ, ສປປ ລາວ

14. ບ່ອນອີງທາງກົດໝາຍ

  1. ກົດໝາຍວ່າດ້ວຍການປົກປ້ອງຂໍ້ມູນທາງເອເລັກໂຕຣນິກ ເລກທີ 25/ສພຊ, ລົງວັນທີ 12 ພຶດສະພາ 2017 (ມີຜົນບັງຄັບໃຊ້ 23 ມິຖຸນາ 2017) — dig.watch
  2. ກົດໝາຍວ່າດ້ວຍທຸລະກຳທາງເອເລັກໂຕຣນິກ ເລກທີ 20/ສພຊ, ລົງວັນທີ 07 ທັນວາ 2012 — ລັດຖະບັນຍັດທາງລັດຖະການ
  3. ກົດໝາຍວ່າດ້ວຍການຕ້ານ ແລະ ສະກັດກັ້ນອາຊະຍາກຳທາງຄອມພິວເຕີ ເລກທີ 61/ສພຊ, ລົງວັນທີ 15 ກໍລະກົດ 2015 — dig.watch
  4. ຄຳແນະນຳວ່າດ້ວຍຄວາມປອດໄພຄອມພິວເຕີ ເລກທີ 3623/ກປທ ແລະ ຂໍ້ຕົກລົງວ່າດ້ວຍການປັບໃໝ ເລກທີ 3624/ກປທ, ລົງວັນທີ 11 ທັນວາ 2017
  5. ກົດໝາຍວ່າດ້ວຍການປົກປ້ອງຜູ້ຊົມໃຊ້ ເລກທີ 02/ສພຊ, ລົງວັນທີ 30 ມິຖຸນາ 2010
  6. ກົດໝາຍວ່າດ້ວຍການບັນຊີ (ສະບັບປັບປຸງ) ເລກທີ 47/ສພຊ, ລົງວັນທີ 26 ທັນວາ 2013
  7. ICAO Annex 9 (Facilitation) ວ່າດ້ວຍຂໍ້ມູນຜູ້ໂດຍສານລ່ວງໜ້າ (API) ສຳລັບການເດີນທາງລະຫວ່າງປະເທດ

ໝາຍເຫດ: ເອກະສານນີ້ຂຽນຂຶ້ນເພື່ອອະທິບາຍການປະຕິບັດຕົວຈິງຂອງລະບົບ LAO G-AIR ບໍ່ແມ່ນຄຳປຶກສາທາງກົດໝາຍ. ກ່ອນປະກາດໃຊ້ຢ່າງເປັນທາງການ ຄວນໃຫ້ທີ່ປຶກສາດ້ານກົດໝາຍກວດຄືນ ແລະ ຢືນຢັນຂໍ້ມູນຕິດຕໍ່ຂອງບໍລິສັດ.

English

Privacy Policy

Data controller: PSL Service Co., operator of the LAO G-AIR platform
Version: 2.0  ·  Effective: 24 August 2026

This policy explains what personal data we collect, why, who we share it with, how long we keep it and what rights you have. The data listed below is what the LAO G-AIR database actually stores, not generic boilerplate.

1. Scope

This policy applies to individual and organisational customers who book through the platform, to ticket agents and their staff, to passengers whose details are entered by a customer or an agent, and to visitors who have not registered. If you enter another person data (a fellow passenger, a family member, an employee), you confirm that you have their permission and have shown them this policy.

2. Data we collect

CategoryFields actually stored
AccountEmail, phone, name in Lao and English, user type, organisation, account status, email/phone verification dates, last login, and a one-way password hash. Plain-text passwords are never stored.
PassengerTitle, given and family name (Lao and English), date of birth, nationality, passport number and expiry, phone, email, special requirements (meals, medical assistance).
Booking and travelBooking reference, flights, cabin class, travel dates, travel plans and participants, quotations and invoices.
PaymentPayment method, transaction reference, amount, currency, exchange rate, status, payment-gateway response and any transfer slip you upload. Full card numbers and CVV are never stored.
Agent / corporateCompany and legal name, enterprise registration number, tax ID, licence number, address and map coordinates, bank name and account, contact person with email and phone.
Uploaded documentsFiles attached to agent applications, bookings and travel plans, with file name, size, MIME type and uploader.
Technical and securityIP address, browser user agent, login attempts (success or failure with reason), sessions and administrative activity logs.

Special requirements may reveal health or religious information (for example a special meal or wheelchair assistance). We use such data only to arrange the service you asked for and pass it only to the operating airline.

3. Purposes and legal basis

  • Issuing tickets, confirming bookings, invoicing and after-sales service — performance of our contract with you.
  • Passing passenger details to airlines and authorities — contract performance and legal obligation.
  • Invoicing, bookkeeping and tax — legal obligation under Lao accounting and tax legislation.
  • Identity verification, fraud prevention and audit logging — legal obligation under the Law on Electronic Data Protection and our legitimate interest in a secure service.
  • Assessing agent applications and calculating commission — performance of the agency contract.
  • News and promotional messages — your consent, which you may withdraw at any time.

4. Consent

You must accept the terms of service and this policy to create an account. Consent-based processing (such as marketing) can be withdrawn at any time without affecting processing already carried out, and without deleting records we are legally required to keep.

5. Disclosure and sharing

We do not sell or rent personal data. We disclose only what is necessary to: airlines and reservation systems (to issue tickets); banks and payment providers (to take payment, refund and pay agent commission); your agent or organisation (for bookings they make for you); IT service providers under confidentiality obligations (hosting, email and notification delivery); and government bodies such as civil aviation, immigration, customs, tax or investigating authorities on a lawful request.

6. Transfers outside Lao PDR

International travel requires passenger data to reach airlines or border authorities abroad. Under Law No. 25/NA on Electronic Data Protection, transferring data out of Lao PDR requires consent and must not conflict with national interests. We transfer only what the journey requires.

7. Retention

  • Account data — while the account is active, plus 24 months after closure.
  • Booking and passenger data — at least 5 years from the travel date, to support refunds, disputes and audit.
  • Invoices, receipts and accounting records — for the period required by Lao accounting and tax legislation.
  • Login and security logs — 12 months.
  • Rejected agent applications — 12 months from the decision.

After these periods data is deleted or anonymised.

8. Security measures

  • Passwords stored as one-way hashes.
  • Access governed by roles and permissions.
  • Login-attempt and administrative activity logging for audit.
  • Sessions expire automatically (24 hours, or 30 days with "remember me").
  • Data in transit protected by HTTPS.

No system is completely secure. In the event of a high-risk breach we will notify the affected people and the competent authority without undue delay.

9. Your rights

You may request access to and a copy of your data, correction of inaccurate data, deletion or account closure where no legal obligation requires retention, objection to or restriction of certain processing, and withdrawal of consent. You may also complain to us or to the Ministry of Technology and Communications. We respond within 30 days of verifying your identity.

10. Children

The platform is not intended for people under 18 to register on their own. Data about child or infant passengers must be entered by a parent, guardian or authorised agent.

11. Cookies and sessions

We use strictly necessary session cookies to keep you signed in and to protect forms. Disabling them prevents sign-in.

12. Changes to this policy

When this policy changes, the version number and update date at the top of the document change and the new version appears on this page immediately.

13. Contact

Email [email protected], phone +856 20 5555 0000, or write to Luang Prabang Road, Sisattanak District, Vientiane Capital, Lao PDR.

14. Legal references

  1. Law on Electronic Data Protection No. 25/NA, 12 May 2017 (in force 23 June 2017) — dig.watch
  2. Law on Electronic Transactions No. 20/NA, 7 December 2012 — Lao Official Gazette
  3. Law on Prevention and Combating Cyber Crime No. 61/NA, 15 July 2015 — dig.watch
  4. Guidelines on Computer Security No. 3623/MPT and Decision on cyber-crime penalties No. 3624/MPT, both 11 December 2017
  5. Law on Consumer Protection No. 02/NA, 30 June 2010
  6. Amended Law on Accounting No. 47/NA, 26 December 2013
  7. ICAO Annex 9 (Facilitation) on Advance Passenger Information for international travel

Note: this document describes how the LAO G-AIR system actually operates; it is not legal advice. Have counsel review it and confirm the company contact details before formal publication.

© 2026 LAO G-AIR. ສະຫງວນລິຂະສິດທັງໝົດ.