Personal Data Protection Policy
YHS INTERNATIONAL LIMITED
YHS INTERNATIONAL LIMITED (the “Company”) recognizes and attaches great importance to personal data. In order to comply with the Personal Data Protection Act B.E. 2562 (2019), the Company has prepared this Policy to notify the collection, use, disclosure, and/or transfer of personal data as set out below.
1. Purpose
This Policy is prepared to inform data subjects of:
-
the purposes for which personal data is collected, used, or disclosed,
-
the lawful basis for processing,
-
the types of personal data that will be collected,
-
the retention period of personal data,
-
information about the Company, and
-
the rights of data subjects under Section 23 of the Personal Data Protection Act B.E. 2562 (2019).
Accordingly, the Company has established this Personal Data Protection Policy.
2. Personal Data Collected by the Company, Purpose, Legal Basis, and Retention Period
The Company collects personal data through various channels, both directly and indirectly, in document form and in electronic form. The Company may also collect personal data from sources other than directly from the data subject, which may arise from analysis and compilation of statistics from the use of services or systems. The Company will process personal data only to the extent necessary and in accordance with the purposes specified and notified in this Policy.
2.1 Personal Data Collected
The personal data collected includes, but is not limited to, the following:
-
Personal information such as first name, last name, age, date of birth, etc.
-
Contact information such as address, telephone number, email address, etc.
-
Account information such as user account, usage history, etc.
-
Technical information such as data regarding access to the Company’s website and systems, computer traffic data (log), communications between the data subject and other users, usage records such as device identifiers, computer IP address, device identification number, device type, mobile network information, connection data, geographic location data, browser type, system access logs, information on applications or websites accessed before and after (Referring Website), system usage history, login logs, transaction logs, usage behavior, system usage statistics, and access time.
-
Other information such as photographs, motion images, and any other information that is considered personal data under the personal data protection laws.
-
Service usage information, interests, and all opinions expressed by the data subject through the Company’s systems (if any), information relating to participation in activities through the Company’s systems, survey information, and information obtained from the data subject’s communication with the Company or its staff.
2.2 Storage and Retention Period of Personal Data
2.2.1 We will store your personal data in both document form and electronic form, at locations with restricted access, such as on servers or on cloud systems provided by service providers engaged by the Company.
2.2.2 Personal data will be retained only as necessary for the purposes for which it was collected, used, and disclosed as notified to the data subject, and until the data subject’s relationship with the Company ends. Thereafter, the Company may be required to retain the personal data for an additional period as prescribed by applicable law.
3. Processing of Personal Data
We will collect, use, or disclose your personal data for the following purposes:
-
To create and manage user accounts
-
To deliver products or services
-
To improve products, services, or user experience
-
For internal management and administration of the Company
-
For marketing and sales promotion
-
For after-sales services
-
To collect feedback
-
To process payment for products or services
-
To comply with terms and conditions (Terms and Conditions)
-
To comply with laws and regulations of government authorities
4. Amendments to This Privacy Policy
We may amend or update this Privacy Policy from time to time. The Company will inform you of the new purposes and obtain your consent before processing personal data for such new purposes, unless otherwise permitted by law.
5. Security Measures for Personal Data Protection
The Company has implemented appropriate security measures to protect personal data. The security of personal data refers to maintaining the confidentiality, integrity, and availability of personal data in order to prevent loss, unauthorized access, use, alteration, modification, or disclosure of personal data.
The Company has informed you of its personal data security measures and promotes awareness of the importance of personal data protection.
The Company has implemented security measures which cover:
-
Administrative safeguards
-
Technical safeguards
-
Physical safeguards
in relation to access to, or control over, the use of personal data (access control), including:
-
Controlling access to personal data and to devices used to store and process personal data with due regard to usage and security;
-
Defining permissions or access rights to personal data;
-
Managing user access to control access to personal data only by authorized persons;
-
Defining user responsibilities to prevent unauthorized access, disclosure, acquisition, copying, theft, or loss of devices used to store or process personal data;
-
Implementing methods that allow for audit trails regarding access, alteration, deletion, or transfer of personal data, in accordance with the methods and media used in the collection, use, or disclosure of personal data.
These measures are reviewed as necessary or when technology changes, to ensure effective and appropriate security.
6. Transfer of Personal Data to Foreign Countries
In cases where the Company transfers or sends personal data to foreign countries, such as to cloud computing service providers whose platforms or servers are located overseas, data processors, or platform providers (Platform as a Service: PaaS), for the purposes specified in this Policy, the destination country or international organization receiving the personal data must have adequate personal data protection standards and must enable the data subject to exercise their rights and provide effective legal remedies in accordance with the criteria prescribed by the Personal Data Protection Committee.
7. Rights of Data Subjects
Data subjects have the following rights under the Personal Data Protection Act:
-
Right to withdraw consent:
You are entitled to withdraw your consent at any time while your personal data remains with the Company, unless such right is restricted by law, regardless of whether the consent was given before or after the data protection law came into effect. -
Right of access:
You have the right to access your personal data under our responsibility and to request a copy of such data, as well as to request disclosure of the source from which we obtained your personal data without your consent. -
Right to data portability:
You have the right to receive your personal data in cases where The Company have prepared such data in a format that is readable or commonly used by automated tools or devices and can be used or disclosed by automated means, and you have the right to request that The Company transmit or transfer such personal data to another data controller where technically feasible, and to request that The Company directly receive personal data transferred to another data controller, unless this cannot be done due to technical reasons. -
Right to object:
You have the right to object to the collection, use, or disclosure of your personal data at any time, if such collection, use, or disclosure is carried out on the basis of our legitimate interests or those of another person or juristic person, within a scope that you may reasonably expect, or for the performance of a task carried out in the public interest. -
Right to erasure/destruction:
You have the right to request that your personal data be erased or destroyed, or anonymized so that it can no longer identify you, if you believe that your personal data has been collected, used, or disclosed unlawfully, or when it is no longer necessary for us to retain it for the purposes specified in this Policy, or when you have exercised your right to withdraw consent or your right to object as mentioned above. -
Right to restriction of processing:
You have the right to request that the Company suspend the use of your personal data in the following circumstances:
-
When the Company is in the process of verifying the accuracy or reviewing the data as requested by you.
-
When the personal data is subject to deletion or destruction, you request that its use be suspended instead.
-
When your data is no longer necessary to be retained for the purpose for which it was collected, but you require the Company to retain it for the establishment, exercise, or defense of legal claims.
-
When the Company is in the process of verifying your objection, request to determine whether it has lawful grounds to reject your objection.
-
Right to rectification:
You have the right to request that the Company rectify your personal data so that it is accurate, up-to-date, complete, and does not cause misunderstanding. -
Right to lodge a complaint:
You have the right to lodge a complaint with the competent authority under the relevant laws if you believe that the collection, use, or disclosure of your personal data is in violation of, or inconsistent with, applicable laws.
You may exercise the above rights as a data subject by contacting our Data Protection Officer at the contact details provided at the end of this Policy. The Company will notify you of the result of your request within 30 days from the date of receipt of your request Your rights above may be subject to legal limitations. In some cases, the Company may need to refuse or may be unable to fulfill your request, such as when required by law, court orders, or where your request may affect the rights or freedoms of others.
8. Disclosure of Personal Data
The Company may disclose your personal data to others with your consent or as permitted by law, as follows:
Service providers
The Company may disclose certain personal data to our service providers as necessary for them to carry out activities such as payment processing, marketing, product or service development, etc. Such service providers have their own privacy policies.
Business partners
The Company may disclose certain information to our business partners for coordination in providing products or services and to provide necessary information regarding product or service availability.
The Company confirms that it will not use customers’ or service users’ personal data collected for any purposes other than lawful purposes or for the Company’s business operations.
9. Minors
If the data subject is a minor under Thai law, consent must also be given by their legal guardian. For minors under 10 years old, only the legal guardian can give consent.
If the data subject is an incompetent person or a quasi-incompetent person, consent must be given by their appointed guardian or curator.
If the Company becomes aware that personal data has been collected from any of the individuals mentioned above without valid or lawful consent, the Company has the right to immediately delete such data from its servers and systems.
10. Advertising and Marketing
The Company may send information or newsletters to your email for the purpose of informing you of offers or items that may be of interest to you. If you no longer wish to receive such communications from us via email, you may click “unsubscribe” in the email link or contact us via our email.
11. Tracking Technologies (Cookies)
Cookies are files created by the websites you visit to make your online experience easier by storing your browsing information. Websites use cookies to keep you signed in, remember your preferences, and provide content that is relevant to you.
The Company uses cookies and similar technologies to enhance access to our products or services, deliver appropriate advertisements, and track your usage in order to improve your overall website experience and ensure efficiency.
If you do not wish for your information to be collected through cookies, software, or tracking tools, you can adjust your browser settings to delete or reject cookies, or disable certain tracking technologies before using the Company’s website. Please note that doing so may remove your saved preferences.
12. Notification of Personal Data Breach
In the event of a personal data breach, . The Company will notify the Office of the Personal Data Protection Committee without delay and within 72 hours from the time . The Company become aware of the breach, where feasible. If the breach is likely to result in a high risk to your rights and freedoms The Company will notify you of any data breach without delay through the contact details you have provided.
13. Privacy Policies of Other Websites
This Privacy Policy applies only to the provision of products, services, and website usage for our customers. If you visit other websites, even if accessed via links from our website, the protection of personal data on those websites will be governed by the privacy policies of such websites, which the Company has no involvement and does not assume any rights, obligations, or liabilities in any respect.
14. Contact Details
If you have any questions regarding this Privacy Policy or wish to exercise your rights, you may contact us or our Data Protection Officer at the following contact details:
Legal & Contract Department,
YHS International Limited
2445/27 – 30 Tararom Business Tower, 16th Floor New Petchburi Road, Bangkapi, Huay Kwang, Bangkok Thailand 10310
Tel. 02-3181383, 02-3181385
E-mail: yhsinter@yhsi.com
By accepting this Privacy Policy, you acknowledge that your use of any of the Company’s services constitutes your acceptance of all applicable terms and conditions, and such acceptance is considered valid and binding.
