This Privacy Notice is designed to provide you with information about how we process your personal data when you use our products/services or website, whether on your own behalf or on behalf of your company. This includes information that you provide to us on our website or when you apply for or use our products/services. We will explain the types of personal data we collect and why we collect them, which includes information that you provide to us and information that we learn about you either directly or indirectly. Additionally, we will provide information on how we process your personal data, the third parties to whom we may disclose your personal data, the retention period for your personal data, and your privacy rights as a data subject under applicable laws.
We currently collect, use and/or disclose the following information:
this includes but not limited to your first name, last name, title, date of birth, personal identification number, passport number, tax identification number, nationality, username or similar identifier.
this includes but not limited to your residential address, government registered address, work address, email address, telephone numbers, work telephone number and social media accounts.
this includes but not limited to your income, your source of income, details about payments to and from you, your bank accounts and payment card details, your correspondence with us and details of products or services you have purchased from us.
this includes online identifiers, IP addresses, operating system type, network information, web browser type and version, cookies, activity logs, unique device identifiers, geo-location data, photographs, videos, and voice recordings.
as you use or navigate through and interact with our or third parties’ channels, applications, websites/sites or social media, as the case may be, we use automatic data collection technologies (i.e. cookies, web beacon, or third party tracking for analytics and advertising purposes) to collect certain information about you and your activities, such as the links you click on, the pages or content you view, the content response times, the download errors and the length of visits.
this includes your login details, purchases or orders made by you, your interests or preferences, feedback or survey responses.
any communications with our officers, such as record of contact, complaints and/or disputes, emails or letters you send to us, record of your feedback, and record of advice that we may have given you.
these include any information that you have provided us about other persons with whom we may or may not have direct legal relationship, such as their identity data and contact data.
“Sensitive Personal Data” means personal data which is specifically determined by law. Company has no intention to collect Sensitive Personal Data from you. In certain cases, however, company may need to collect Sensitive Personal Data from you for providing services or products to you, for example, religion or race (displayed on a copy of identification document), biometric data (such as facial recognition data), data on criminal record.
We collect your information from various sources as follows:
INFORMATION THAT YOU PROVIDE TO US
such as the information filled out in the forms on our website, order forms or application forms provided by us.
INFORMATION THAT WE GENERATE TO YOU
this includes marketing and sales information, such as details of the products and/or services that you receive and your preferences, and audio-visual information, such as recordings from surveillance videos on our premises or recordings of phone or video or chats with our staff.
INFORMATION WE COLLECT FROM OTHER SOURCES
this includes the information received from our business partners and any information that you share publicly via a third-party social network.
If you do not provide the necessary data or consent to the collection, use or disclosure of data, which we indicate to you is mandatory, we may not be able to approve, deliver, procure, or provide the products and/or services that you require, or meet all our obligations we have with you, enter into a contract with you, or it may affect ability to comply with law or the relationship between you and the company.
If you give us personal data of other persons, or you request us to share their personal data with third parties, you have confirmed that such persons understand the information in this Privacy Notice and that you have the rights to share their personal data to us by requesting their consent, if necessary, or based on other legal grounds, to ensure that the Company is able to collect, use, and/or disclose the personal data of these individuals.
We may only collect, use and share (collectively “process”) personal data fairly and lawfully and for specified purposes provided by law (“lawful basis”).
The lawful basis for processing available under the applicable data protection law vary depending on the nature and purpose of the processing activities and the types of data being processed.
Collect ,use, and /or disclose your Sensitive data on which the company cannot comply on the other lawful basis other than obtaining explicit consent include:
We will rely on one or more of the following lawful basis when processing personal data:
In the case of sensitive personal data under the applicable data protection laws, we will process such sensitive personal data only when it has obtained explicit consent from you, or in cases where the company has a lawful basis to do so as permitted by law. Such processing will be carried out only on a case-by-case basis, as and when it is necessary for the company to collect such sensitive personal data from you.
Some processing activities may fall under more than one lawful basis. In such case, we may rely on any of the applicable basis for our processing activities.
The purposes for which we may process personal data, subject to the applicable law, and the legal bases on which we may perform such processing includes:
|Purposes of Personal Data||Lawful Basis|
Provision of Products and/or Services
Fulfilment of Our Legal Obligations
Security and Risk Management
Other relevant processing activities
We may share your personal data or personal data relating to the individuals connected to your business with third parties with your consent or to the extent permitted by law. The individuals or entities receiving such personal data will collect, use, and/or disclose your personal data within the scope of your consent or within the scope relevant to this policy. In certain cases, you may also be subject to the personal data protection policy of the recipients of your personal data.:
We may share your personal data or personal data relating to the individuals connected to your business for these purposes with others, including:
Under some circumstances, the recipients of your personal data listed above may be located outside of Thailand. We will ensure that the cross-border transfers of your personal data comply with related provisions in this Privacy Notice.
There may be instances which we may share your personal or non-personal data to third parties, such as advertising identifiers or one-way coding (cryptographic hash) of a common account identifier (such as a contact number or email address) to enable the conduct of targeted advertising.
We will not use personal data for any other purpose other than for the purposes as described to you. Should we intend to collect or use additional data, which is not described in this Privacy Notice; we will notify you and/or obtain your consent prior to the collection, use or disclosure in order to comply with relevant data protection laws.
Your personal data may be transferred for processing to other countries to companies within the financial business group or service providers of the company, or other data recipients that are part of the company's business operations or required by various laws and regulations of the company. We will take all steps that are reasonably necessary to ensure that your personal data is treated securely and in accordance with this Privacy Notice as well as with the applicable data protection laws.
In cases where the destination country lacks sufficient standards for the protection of personal data, the Company shall ensure that the transfer or transmission of personal data complies with applicable laws and shall implement necessary and appropriate measures for the protection of personal data in accordance with the standards of confidentiality, such as entering into an agreement with the recipient of the data in the relevant country to confirm that your personal data will be protected under standards of personal data protection equivalent to those in Thailand.
Alternatively, in cases where the recipient is another financial services company within the Company's group of businesses, the Company may choose to implement Binding Corporate Rules for personal data protection that have been verified and certified by the relevant authorities, and ensure that the transfer or transmission of personal data to other financial services companies within the Company's group of businesses located abroad is carried out in accordance with such personal data protection policy.
You have the right to object to direct marketing activities.
If you do not wish to receive marketing information from us, you may click on the ‘unsubscribe’ link, which can be found in our marketing emails and/or newsletters which are sent to you.
Your data is securely stored in secured locations. We keep your data for as long as it is necessary to carry out the purposes for which it was collected and/or compliance with applicable laws.
We may keep your data for up to 10 years after the termination of your relationship with the company to ensure that contractual disputes can be processed within that time. However, for legal, regulatory or technical reasons, we may keep your data for longer than 10 years. If we do not need to retain personal data any longer, we will destroy, delete or anonymize your personal data.
Under the applicable data protection law, you have rights including:
RIGHT TO WITHDRAW CONSENT
This enables you to withdraw consent that you have already given to us. The withdrawal of your consent will not affect any processing of your personal data carried out prior to your withdrawal being effective.
Where your consent is not mandatory, the withdrawal thereof may partially or completely impede our ability to provide you with full benefits or experience relating to the products and/or services you receive.
Where your consent is mandatory, the withdrawal thereof may render our service limited, restricted, suspended, cancelled, prevented or prohibited, as the case may be.
For either case, we will not be liable to you for any losses incurred, and our legal rights are expressly reserved in respect of such limitation, restriction, suspension, cancellation, prevention or prohibition.
RIGHT OF ACCESS
This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
RIGHT TO RECTIFICATION
You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
RIGHT TO DELETION
RIGHT TO OBJECT TO PROCESSING
This enables you to object to the processing of your personal data by the company if such processing is conducted for the legitimate interests of the company or other individuals or legal entities, or for the performance of tasks carried out in the public interest, in accordance with the applicable laws and regulations. If you file an objection to the processing of your personal data with the aforementioned reasons, the Company will continue to collect, use, and/or disclose your personal data only where the Company can demonstrate that it is necessary for reasons that are more compelling than your objection, or for the establishment, exercise, or defense of legal claims, or in accordance with applicable laws and regulations, depending on the circumstances of each case. In addition, you also have the right to object to the processing of your personal data by the Company for direct marketing purposes or for purposes of scientific, historical or statistical research.
RIGHT TO RESTRICTION OF PROCESSING
This enables you to ask us to suspend the processing of personal data about you; for example, you may want us to restrict the use of your personal data which is under our correction process.
This enables you to ask us to suspend the processing of your personal data in cases where:
RIGHT TO PORTABILITY
This enables you to request access to your personal information in case the Company has created such personal data in a format that can be read or processed automatically by machines or devices. Furthermore, you have the right to use or disclose such personal information by means of automatic procedures, and to request that the Company send or transfer your personal data to other persons or organizations, provided that it can be done by automatic means. You also have the right to receive your personal information that has been sent or transferred by the Company in the aforementioned format directly from the data controller, unless it is technically impossible to do so.
Whereas, your personal information must be the personal information that you have given consent to the Company for collecting, gathering, using, and/or disclosing, or must be the personal information that the Company is required to collect, gather, use, and/or disclose for you to be able to use the Company's products and/or services in accordance with the agreement between you and the Company, or for the Company to process your request for using the Company's products and/or services, or must be other personal information as prescribed by law.
RIGHT TO COMPLAIN
You may lodge a complaint with the local data protection authority if you believe that we have not complied with the applicable personal data protection laws or other related laws.
Please complete the relevant form as provided by us to exercise your rights. Please also note that we will ask you to provide a proof of identity to us before responding to any requests to exercise your rights. We will respond to your request to exercise such rights without delay; we will notify you in advance if we require more time to process your request.
For any processing activities relying on your consent obtained before 1 June 2021, we will maintain and continue processing your personal data based on such consent. If you wish to withdraw your such consent, you may contact us and we will process your request accordingly.
Please note that the above-mentioned rights may be restricted under relevant laws and there may be certain circumstances where the company may refuse or be unable to comply with your aforementioned request for the exercise of rights. For example, the company must comply with the provisions of the law or court orders for public interest, or the exercise of your rights may infringe on the rights or freedoms of other individuals.
We value your privacy; therefore, we aim to maintain your personal data by focusing on regular inspection and utilizing appropriate security measures, including technical safeguards, administrative safeguards, and physical safeguards, to preserve confidentiality, accuracy, and completeness of personal data and to prevent unauthorized access, collection, alteration, use, and/or disclosure of personal data. This is in accordance with applicable laws and regulations.
Further, our employees are trained to handle the personal data securely and with respect, failing which they may be subject to disciplinary actions.
This version was last updated on the date written above. We may, from time to time, revise this privacy notice in order to comply with relevant and applicable guidelines and/or laws and/or our services. We will notify you of the revised privacy notice via our communication channels.
Please keep us informed of any changes of your personal data, if any, during your relationship with us to allow us to hold the current and accurate personal data of you.