(2) An employee, staff, officer, representative, shareholder, director, contact person, agent, and individuals related to Corporate customers which include a targeted customer (prospective customer), current customer, and former customer of the Company and;
(3) Non-customers who have transactions or activities or have relationships with the Company, such as external service providers, business partners, contract parties with the Company, or shareholders of the Company, etc. (hereinafter if not specifically referred to (1) to (3), the persons under (1) to (3) are collectively referred to as “Data Subject”)
The Company has always placed importance and reiterated on Personal Data protection to ensure that your Personal Data will be used in accordance with the following principles.
- Lawfulness, fairness, and transparency: The Company shall process any Personal Data which is limited and necessary based on the lawful basis and explicitly establish methods for collecting and using Personal Data.
- Purpose Limitation Principle: The Company will only process the data for the purposes specified and notified at the time that the Company obtains Personal Data unless the processing is for a related purpose or a performance of an explicit legal obligation.
- Data Minimization Principle: The Company will collect and use Personal Data only to the extent necessary to achieve the purposes of data processing.
- Data Accuracy Principle: The Company will take reasonable steps to ensure that the collected Personal Data is accurate, complete, and up to date with regard to the processing purpose.
- Storage Limitation Principle: The Company will keep the data as needed unless it is necessary for the Company to meet the standards of document retention or by state regulations.
- Integrity and Confidentiality Principle: The Company will provide appropriate technical and administrative measures to ensure an appropriate level of safekeeping of Personal Data that the Company stores.
- Accountability Principle: The Company will take reasonable steps to be able to demonstrate that it has complied with the principles above.
- Consent bases that requires your consent first
- Archives/Statistics/Research bases to achieve objectives related to the preparation of historical documents or archives for the public interest, or in connection with research or statistics which have put appropriate safeguards in place to protect your rights and freedoms.
- Life-threatening suspension bases to prevent or suppress a danger to the life, body or health of a person.
- The contract bases. It is necessary for the performance of a contract to which you are a party or for the performance of your request prior to entering into such contract.
- Public interest bases. It is necessary for the performance of duties to carry out the public interest of the Personal Data Controller, or the performance of the duties to exercise the state power assigned to the Personal Data Controller
- Legitimate Interests Bases. It is necessary for the legitimate interests of the Personal Data Controller or of a person or juristic persons other than the Personal Data Controller unless such benefits are less important than the fundamental rights of the Data Subject.
- Legal Compliance Bases. It is in compliance with the law of the Personal Data Controller.
If it is Sensitive Data, it requires consent in accordance with Section 26 of the Personal Data Protection Act B.E. 2562 (2019), unless permitted by laws.
“Person” means a natural person.
“Personal Data” means any information relating to a person who can be identified, directly or indirectly. The Company may collect, use and/ or disclose Personal Data that is directly obtained from the data subject (Company’s registration platform) or obtained or accessed from other sources (e.g. Department of Business Development, Ministry of Commerce, Department of Provincial Administration, Ministry of Interior, Department of Consular Affairs, Ministry of Foreign Affairs, Credit Information Company, Legal Execution Department, Financial Institutions, Professional Advisors, Social Media, Third-Party Online Platforms or other public sources), or through our affiliates, service providers, business partners, official agency or outsiders.
“Sensitive Data” means any information which is genuinely personal of a Person, but sensitive and likely exposed to unfair discrimination, e.g., racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual orientation, criminal records, data relating to health and disability, labor union data, genetic data, biometric data or any other data which affects the data subject in such manner as prescribed and announced by the Personal Data Protection Committee.
“Data Subject” means a Person who owns Personal Data, except where the Person holds the data ownership or creates or collects such data on his/her own, whereby this Data Subject refers to only a natural person and excludes a “juristic person” established by law, such as company, association, foundation or any other organization.
In this regard, a Data Subject includes any of the following Persons:
1. Data Subject of legal age refers to:
1.1 a Person at the age of 20 or older; or
1.2 anyone who is married at the age of 17 or older; or
1.3 anyone who is married before the age of 17 with the Court’s permission or
1.4 a minor whose legal representative has given consent for the minor to carry on a trade or other business or to enter into an employment contract as an employee, and in relation to the business or employment above, the minor shall have the same capacity as a person of legal age (sui juris).
In this regard, for the purpose of giving any consent, a Data Subject of legal age may give consent of his/her own accord.
2. A minor Data Subject refers to a Person below the age of 20 and not of legal age under Item 1, and as such, for the purpose of giving any consent, the consent of the person with the appointed guardian authorized to act on behalf of the minor shall also be obtained.
3. A quasi-incompetent Data Subject refers to a Person adjudged by the Court to be quasi-incompetent on the ground that he/she is incapable of managing his/her own affairs or manages it to the detriment of his/her own property or family because of physical or mental infirmity, habitual prodigality, habitual intoxication or other similar causes, and as such, for the purpose of giving any consent, the consent of the curator with the power to act on behalf of the quasi-incompetent person must first be obtained.
4. An incompetent Data Subject refers to a Person adjudged by the Court to be incompetent on the ground of unsound mind5, and as such, for the purpose of giving any consent, the consent of the guardian with the power to act on behalf of the incompetent person must first be obtained.
In this regard, such request for a Data Subject’s consent that does not proceed in compliance with the Personal Data protection law shall not be binding upon the Data Subject.
“Data Controller” refers to a Person or a juristic person with the power and duties to make decisions regarding the collection, use or disclosure of Personal Data.
“Data Processor” refers to a Person or a juristic person who proceeds with the collection, use or disclosure of Personal Data under such orders given by or on behalf of a Data Controller, whereby the Person or juristic person who proceeds as such is not a Data Controller.
2.1.1 Personal Data collected from customersType of data- Personal Data
Examples of data that the Company collects, uses and/or discloses- Title, first name, middle name, last name, alias (if any), Identification card number/Passport number, Date of birth, age, Marketing taste, Gender, Emergency contacts, Health details, Vaccination information, Occupation, AIA insurance status, Payment details, Photograph, Signature
Type of data- Sensitive DataExamples of data that the Company collects, uses and/or discloses–
1. Collecting data from the physical test, including - Information about past and present heart disease problems, Chest pain or chest tightness, Medical history for heart disease, blood pressure, or diuretics, Problems related to sickness of bones and joints, Problems with balance and unconsciousness, Other diseases that affect exercise, such as gout.
2. Collecting data from BodiTrax – Impedance, Fat-free mass, Muscle value, Fat value, Bone value, BMR value, age, BMI value, weight, height.
3. Other health record data
4. Religious data
Type of data- Contact Information
Examples of data that the Company collects, uses and/or discloses– Current address, Personal or work telephone, E-mail address.
Type of data- Educational Information
Examples of data that the Company collects, uses and/or discloses– Career, Company Name.
Type of data- Financial Information
Examples of data that the Company collects, uses and/or discloses– Account number, Credit card number, Payment or settlement information, The Company's services and products usage, Trading history and balance, Payment and transaction history.
Type of data- Record images and/or voices interacting with the Company
Examples of data that the Company collects, uses and/or discloses– Records from CCTV, Records of communications through online or other electronic channels of the Company
Type of data- Usage details
Examples of data that the Company collects, uses and/or discloses– Data relating to your usage of websites, platforms, products and services, Cookies, Data relating to your usage and interaction with our platforms and operating system.
2.1.2 Personal data collected from job applicants
Type of data- Personal Data
Examples of data that the Company collects, uses and/or discloses- Title, first name, middle name, last name, Hobbies, Gender, Photograph.
Type of data- Sensitive Data
Examples of data that the Company collects, uses and/or discloses- Other health data, Religious data.
Type of data- Contact Information
Examples of data that the Company collects, uses and/or discloses- Current address, Phone number, mobile number, Email, Line ID.
Type of data- Educational and Professional Information
Examples of data that the Company collects, uses and/or discloses- Educational institutions and training information, Educational qualification, Occupation, Company name, Work history.
Type of data- Record images and/or voices interacting with the Company
Examples of data that the Company collects, uses and/or discloses- Records from CCTV, Records of communications through online or other electronic channels of the Company.
Type of data- Usage details
Examples of data that the Company collects, uses and/or discloses- Data relating to your usage of websites, platforms, products and services, Cookies, Data relating to your usage and interaction with our platforms and operating system.
2.1.3 Personal data collected from employees
Type of data- Personal Data
Examples of data that the Company collects, uses and/or discloses- Date of birth, Proof of name and surname change (if any), Photograph, Height, Weight, EWTH application or Resume/CV, Employee Checklist, Employment Contract, Welfare documents (Confidentiality Agreement / Facebook Usage Agreement / Provident Fund Membership Application / Group Insurance Beneficiary Letter), Job Description according to position, Various Competency Documents, Other Assessment.
Type of data- Sensitive Data
Examples of data that the Company collects, uses and/or discloses- Criminal record, Religion, Ethnicity, COVID vaccination history.
Type of data- Contact Information
Examples of data that the Company collects, uses and/or discloses- Current address, Current address and house registration address, Phone number and mobile number, Email, Line ID, FB account / IG account or other social media platforms (if any).
Type of data- Educational and Professional Information
Examples of data that the Company collects, uses and/or discloses– Occupation, Company name, Educational qualifications and related training, Copy of educational background, Various training contracts, Relevant proficiency test results such as an English test, Driving license according to the nature of work (only required position), Other Certificates.
Type of data- Financial Information
Examples of data that the Company collects, uses and/or discloses– Account number, Income and tax information, Copy of Book Bank, Credit card number, Payment or settlement information, The Company's services and products usage, Trading history and balance, Payment and transaction history.
Type of data- Record images and/or voices interacting with the Company
Examples of data that the Company collects, uses and/or discloses– Records from CCTV, Records of communications through online or other electronic channels of the Company.
Type of data- Usage details
Examples of data that the Company collects, uses and/or discloses– Data relating to your usage of websites, platforms, products and services, Cookies, Data relating to your usage and interaction with our platforms and operating system.
Type of data- Personal Data of any other third party
Examples of data that the Company collects, uses and/or discloses–
1. Emergency contact information: Name, Surname, Phone number
2. Referral Person: Name, Surname, Phone number, Job title, Place of work.
3. Guarantor information: Name, Surname, Photo, Phone number, Job title, Proof of income for guarantee, Copy of ID card / Copy of government official card.
2.1.4 Personal Data collected from partners
Type of data- Personal Data
Examples of data that the Company collects, uses and/or discloses–
1. Information in the copy of the ID card is: Name, surname, ID number, Address, Date of birth, Photo, Height.
2. Information in the copy of the house registration is: Name, surname, ID card number, Address according to the house registration, Nationality.
3. Other information: Signature, Job title.
Type of data- Sensitive Data
Examples of data that the Company collects, uses and/or discloses– Religion
Type of data- Record images and/or voices interacting with the Company
Examples of data that the Company collects, uses and/or discloses– Records from CCTV.
Type of data- Usage details.
Examples of data that the Company collects, uses and/or discloses– Data relating to your usage of websites, platforms, products and services, Cookies, Data relating to your usage and interaction with our platforms and operating system.
2.2 Sensitive Data means any information which is genuinely personal of a Person, but sensitive and likely exposed to unfair discrimination, e.g., racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual orientation, criminal records, data relating to health and disability, labor union data, genetic data, biometric data or any other data which affects the data subject in such manner as prescribed and announced by the Personal Data Protection Committee.
The Company has no policy to collect Sensitive Personal Data from you, however, in certain cases that the Company may need to collect Sensitive Personal Data from you, the Company shall collect the Sensitive Personal Data provided that the Company has been given explicit consent by you or permitted by law.
In the event that the Data Subject does not provide Personal Data or provides inaccurate or out-of-date Personal Data to the Company, the Data Subject may be affected by being unable to transact with the Company or may not be convenient or not receive the performance of the existing contracts with the Company, and may cause damage or loss to the Data Subject, and may prevent the Company or the Data Subject from complying with the contract.
2.3 Personal Data of minors, incompetent or quasi - incompetent persons
The Company has no intention to collect, use and / or disclose Personal Data of minors, the incompetent or quasi - incompetent persons, unless the Company obtains consent from the guardian, the appointed guardian, the appointed curator or any act which minors may give consent by itself pursuant to law (as the case may be) and / or has any lawful basis. If the Company discovers that the collection, use and / or disclosure of Personal Data of minors, the incompetent or quasi - incompetent persons is undertaken without (i) consent from the guardian, the appointed guardian, the appointed curator or minors who may give consent by itself pursuant to law (as the case may be) and (ii) any lawful basis, the Company shall delete or destroy such Personal Data.
2.4 Personal Data of any other third party
If you provide us Personal Data of any other third party who has involvement with you i.e. emergency contact persons and / or any other person per document of your transaction, and reference persons such as , name, surname, address, telephone number, family income and personal information and other contact information to contact in an emergency, fill out an application, or transact with the Company. You certify that such information is lawful. Please inform those persons of the details under this Policy and request their consent.