This policy explains how asian.directory handles personal data. It is the operator policy we work to. It is not legal advice.
Who we are
asian.directory is an AI-driven business directory for Asia (Japan, South Korea, China, Singapore, Thailand, Vietnam, Malaysia, Indonesia, Philippines, India, and Laos). People search by asking. Businesses can be submitted for review before they appear.
The compiled public directory is operated by asian.directory (Laurent Laboise).
Privacy requests: privacy@asian.directory.
What we collect
We collect only what the live site and API actually handle:
- Search and chat queries. When you search, the public site sends your query to our API and then saves the conversation (your query, the listings we returned, and related listing IDs).
- Business listing submissions. The public “Add your business” form asks for business name, category, city, country, phone, street address, description, email, and website. Submissions go to our review queue. A hidden anti-spam field may be present; people should leave it blank.
- Technical request data. The API stores the IP address with saved conversations and with the audit record of a public submission. We also use IP addresses for rate limiting and write basic server logs (time, method, URL path, status code, duration) so we can run and secure the service. An analytics-event endpoint can store an event type, optional event data, a session id, IP address, and user-agent. The public homepage does not currently call that endpoint.
- Staff accounts. Admin login (password or optional Google / Facebook sign-in) stores account details for operators. That is for running the directory, not for public searchers.
We do not require an account to search or to submit a listing.
The public search pages do not set a tracking cookie.
The API can read a session_id cookie if one is present;
the public homepage does not set one.
A short-lived security cookie is used only if a client asks the API for a CSRF token
(admin tools, not ordinary search).
We do not run advertising pixels, and we do not use Google Analytics, Plausible, or similar analytics products on this site.
Why we use this information
- Operate the directory and return listings that match a search.
- Review, publish, correct, or reject submitted listings.
- Improve search quality (for example, seeing which queries found nothing useful).
- Security, abuse prevention, and rate limiting.
- Respond to access, correction, and deletion requests.
We process this data because we need it to run the service you used (search or a listing submission), because we have a legitimate interest in operating a useful and secure directory, and where a law requires us to keep a record. Sending a listing for review is a request that we use those details to consider publication.
Search and AI
Queries are processed so we can match them against listings and return results. We save those conversations on our own systems as described above. We do not sell your chats or search queries.
The public directory and personal data
The compiled public directory — the published list of businesses — is operated by us. A published listing is meant to be public directory information (name, category, location, public contact details, description, website).
That does not remove rights over personal data. If you submitted a listing, or if you are an identifiable person named in a listing (for example a contact name or personal email), you can still ask us to access, correct, or delete that personal data, and you can ask us to take down or change a listing that identifies you. See deletion and rights below.
Your rights (searchers, submitters, listing owners)
Depending on where you are and which law applies, you can ask us to:
- Tell you what personal data we hold about you and give you a copy.
- Correct inaccurate personal data.
- Delete personal data or a submitted / published listing (see the next section).
- Object to, or ask us to restrict, some processing.
- Withdraw consent where we relied on it (this does not undo lawful processing already done).
Listing owners and submitters can request a correction, an update, or removal of a listing on the data deletion page or by emailing privacy@asian.directory with the listing name, city, country, and the contact email used on the listing or submission. There is no public user account.
How to request deletion
Use the dedicated page How to delete your data (form or email). You can also email privacy@asian.directory with the subject line “Deletion request”.
Please include:
- What you want deleted (personal data, a search/chat log, a submitted listing, a published listing, or more than one of these).
- Listing name, city, and country (if the request is about a listing).
- The contact email used on the submission or listing, if you used one.
- For a search-log request: the query text and the approximate date, if you remember them.
How we confirm it is you
We keep this light. Email us from the same address used on the submission or listing when you can. If that is not possible, we will ask only enough to match the record (for example the listing name plus city and the email or phone already on file). We do not ask for extra identity documents unless we cannot match the record and the request is disputed.
What we will delete
- Personal data we hold about you that we no longer need (including submitter email and other personal contact details we stored for that request).
- Search / conversation logs we can reasonably find that relate to you.
- An unpublished submission, or a published listing, when you ask us to remove it and we can match it.
What we may keep
- A short audit note that a deletion request was received and completed (so we can show we handled it).
- Security and abuse logs (including IP-based rate-limit and server logs) for a limited time.
- Information we must keep to comply with law or to handle a legal claim.
- Copies we do not control — for example another website that already cited a listing we published. We will remove it from our directory; we cannot erase every copy elsewhere.
Timeline
We aim to acknowledge your request within 7 days and to finish it within 30 days where the applicable law requires that (or sooner if we can). If we need more time because the request is complex, we will say so and explain why.
How long we keep data
- Published listings stay while they remain on the directory, until we unpublish them or you successfully ask us to remove them.
- Submissions stay until we review them (publish, reject, or delete). Rejected or withdrawn submissions are then removed or reduced to a non-identifying audit note.
- Search / conversation logs. The current system does not auto-delete these after a fixed number of days. We treat 12 months as the normal maximum unless you ask us to delete sooner or we need a specific log longer for security or a legal requirement.
- Server and security logs are kept only as long as needed to operate and secure the service, then discarded in the ordinary course of log rotation.
- Staff account data lasts for as long as the person is an operator, then is removed when the account is closed.
International visitors
This is an Asia-focused directory. Hosting (GitHub Pages and Railway) may process data in the United States and other countries. If you search or submit a listing, your information may cross borders so we can store it and show results. We do not hold ISO, GDPR, or similar certifications, and we do not claim to.
If you are in the EU or UK, GDPR and UK GDPR may give you rights of access, correction, deletion, restriction, and objection, and the right to complain to a supervisory authority. Our legal bases are those set out under Why we use this information. We do not have a separate EU or UK representative; contact us at the address above.
If Singapore PDPA, Thailand PDPA, Japan’s APPI, Korea’s PIPA, or China’s PIPL applies to your request, we will handle access, correction, deletion, and withdrawal requests in line with those laws to the extent they apply to us. Cross-border hosting is part of how the service is run; we do not sell the data.
Children
This directory is for businesses and people looking for businesses. It is not directed at children. We do not knowingly collect personal data from children. If you believe we have, email us and we will delete it.
Changes to this policy
If we change how we handle personal data, we will update this page and the date at the top. The current version is always at https://asian.directory/privacy.html.