Legal & Privacy
About Legal and privacy
SATANG PRIVACY NOTICE
This privacy notice (“Privacy Notice”) aims to give you information on how we process your personal data through your use, either on behalf of yourself or your company, of our products and/or services and/or website. This includes the information provided by you on our website or upon the application or use of our products and/or services. You will be explained on what kind of personal data we collect and why we collect it; this includes what you tell us about yourself and what we learn by having you as a customer, how we process your personal data, who we disclose your personal data to, how long we keep your personal data, and what your privacy rights as a data subject and how the law protects you.
WHAT TYPE OF INFORMATION WE COLLECT
We currently collect and process the following information:
- IDENTITY DATAthis includes but not limited to your first name, last name, title, date of birth, personal identification number, passport number, tax identification number, nationality, username or similar identifier.
- CONTACT DATAthis includes but not limited to your billing address, residential address, email address, telephone numbers and social media accounts.
- TRANSACTION DATAthis includes but not limited to details about payments to and from you, your bank accounts and payment card details, your correspondence with us and details of products or services you have purchased from us.
- DATA FROM DIGITAL DEVICEthis includes online identifiers, IP addresses, operating system type, network information, web browser type and version, cookies, activity logs, unique device identifiers, geo-location data, photographs, videos, and voice recordings.
- WEBSITE/COMMUNICATION USAGE INFORMATIONas you use or navigate through and interact with our or third parties’ channels, applications, websites/sites or social media, as the case may be, we use automatic data collection technologies (i.e. cookies, web beacon, or third party tracking for analytics and advertising purposes) to collect certain information about you and your activities, such as the links you click on, the pages or content you view, the content response times, the download errors and the length of visits.
- PROFILE DATAthis includes your login details, purchases or orders made by you, your interests or preferences, feedback or survey responses.
- OUR CUSTOMER SUPPORT SERVICESany communications with our officers, such as record of contact, complaints and/or disputes, emails or letters you send to us, record of your feedback, and record of advice that we may have given you.
- DETAILS OF OTHERS PROVIDED BY YOUthese include any information that you have provided us about other persons with whom we may or may not have direct legal relationship, such as their identity data and contact data.
- SPECIAL CATEGORIES OF PERSONAL DATA (SENSITIVE PERSONAL DATA)any sensitive data which is necessary for us to providing you products and/or services and to perform our legal obligations as required by law, e.g. information about criminal convictions and offences and biometric data.
WHERE WE COLLECT THE INFORMATION FROM
We collect your information from various sources as follows:
- INFORMATION THAT YOU PROVIDE TO USsuch as the information filled out in the forms on our website, order forms or application forms provided by us.
- INFORMATION THAT WE GENERATE ABOUT YOUthis includes marketing and sales information, such as details of the products and/or services that you receive and your preferences, and audio-visual information, such as recordings from surveillance videos on our premises or recordings of phone or video or chats with our staff.
- INFORMATION WE COLLECT FROM OTHER SOURCES
this includes the information received from our business partners and any information that you share publicly on a third party social network.
If you do not provide the necessary data or consent to the collection, use or disclosure of data, which we indicate to you is mandatory, we may not be able to provide you with the products and/or services you require, or meet all our obligations we have with you, enter into a contract with you, or fulfil legal duties imposed on us by law. In such cases, our service to you may be limited, restricted, suspended, cancelled, prevented or prohibited, as the case may be.
If you give us personal data of other persons, or you request us to share their personal data with third parties, you confirm that such persons understand the information in this Privacy Notice about how we will use their personal data and that you have the rights to share their personal data to us.
WHAT WE DO WITH THE DATA WE HAVE
We may only collect, use and share (collectively “process”) personal data fairly and lawfully and for specified purposes provided by law (“lawful basis”).
The lawful basis for processing available under the applicable data protection law vary depending on the nature and purpose of the processing activities and the types of data being processed.We will rely on one or more of the following lawful basis when processing personal data:
- when it is necessary to fulfil a contract or perform obligations we have with you or to act upon your request before entering into any contractual relationship with you;
- when it is our legal duty;
- when it is in our legitimate interest; and
- when you consent to the processing of your personal data.
In the case of sensitive personal data or special categories of personal data under the applicable data protection laws, in addition to the lawful basis above, we will process such data in accordance with any other additional requirements as prescribed by such data protection laws.
Some processing activities may fall under more than one lawful basis. In such case, we may rely on any of the applicable basis for our processing activities.
The purposes for which we may process personal data, subject to the applicable law, and the legal bases on which we may perform such processing includes:
|Purposes of Personal Data Processing||Lawful Basis|
|Provision of Products and/or Services|
|Fulfilment of Our Legal Obligations|
|Security and Risk Management|
|Other relevant processing activities|
PARTIES WE SHARE THE DATA WITH
We may share your personal data or personal data relating to the individuals connected to your business with third parties where it is lawful to do so, including where we or they:
- need to have access to your personal data in order to provide you with the products and/or services you have requested (e.g. fulfilling a payment request);
- have a public or legal duty to do so (e.g. to assist with detecting and preventing frauds or tax evasion);
- need have access to your personal data for the purpose of regulatory reporting, litigation or to assert or defend their or our legal rights and interests;
- have a legitimate business reason for doing so (e.g. to manage risk, verify identity, enable another company to provide you with services you have requested, or assess your suitability for products and/or services);
- need to prevent harms to your life, body, or health; and/or
- have asked you or the individuals connected to your business for the permission to share the personal data, and you (or they) have agreed.
In case of sensitive personal data or special categories of personal data under the applicable data protection laws, in addition to the lawful basis above, we will share such data in accordance with additional requirements as prescribed by such data protection laws.
Some disclosure activities may fall under more than one lawful basis. In such case, we may rely on any of the listed basis for our disclosure activities.
We may share your personal data or personal data relating to the individuals connected to your business for these purposes with others, including:
- any sub-contractors, agents or service providers who work for us or provide services to us;
- cloud service providers;
- law enforcement, government, courts, dispute resolution bodies, regulators, fraud prevention agencies, tax agencies and auditors; and
- any other person with whom we have been instructed by you to share your personal data.
Under some circumstances, the recipients of your personal data listed above may be located outside of Thailand. We will ensure that the cross-border transfers of your personal data comply with related provisions in this Privacy Notice.
There may be instances which we may share your personal or non-personal data to third parties, such as advertising identifiers or one-way coding (cryptographic hash) of a common account identifier (such as a contact number or email address) to enable the conduct of targeted advertising.
We will not use personal data for any other purpose other than for the purposes as described to you. Should we intend to collect or use additional data, which is not described in this Privacy Notice; we will notify you and/or obtain your consent prior to the collection, use or disclosure in order to comply with relevant data protection laws.
TRANSFERS OF PERSONAL DATA OUTSIDE OF THAILAND
OPTING OUT OF DIRECT MARKETING
You have the right to object to direct marketing activities.
If you do not wish to receive marketing information from us, you may click on the ‘unsubscribe’ link, which can be found in our marketing emails and/or newsletters which are sent to you.
HOW WE STORE YOUR DATA
Your data is securely stored in secured locations. We keep your data for as long as it is necessary to carry out the purposes for which it was collected and/or compliance with applicable laws.
We may keep your data for up to 10 years after you stop being our customer to ensure that contractual disputes can be processed within that time. However, for legal, regulatory or technical reasons, we may keep your data for longer than 10 years. If we do not need to retain personal data any longer, we will destroy, delete or anonymize your personal data.
YOUR DATA SUBJECT RIGHTS
Under the applicable data protection law, you have rights including:
- RIGHT TO WITHDRAW CONSENT
This enables you to withdraw consent that you have already given to us. The withdrawal of your consent will not affect any processing of your personal data carried out prior to your withdrawal being effective.
Where your consent is not mandatory, the withdrawal thereof may partially or completely impede our ability to provide you with full benefits or experience relating to the products and/or services you receive.
Where your consent is mandatory, the withdrawal thereof may render our service limited, restricted, suspended, cancelled, prevented or prohibited, as the case may be.
For either case, we will not be liable to you for any losses incurred, and our legal rights are expressly reserved in respect of such limitation, restriction, suspension, cancellation, prevention or prohibition.
- RIGHT OF ACCESS
This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
- RIGHT TO RECTIFICATION
You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
- RIGHT TO DELETION
This enables you to ask us to delete or remove personal data where there is no good reason for us to continue to process it. You also have the right to ask us to delete or remove your personal data where you have exercised your right to object to the processing of your personal data (see below).
- RIGHT TO OBJECT TO PROCESSING
This enables you to object to the processing of your personal data where we are relying on a legitimate interest (or that of a third party) and your particular circumstances justify your objection to processing on this basis. You also have the right to object where we are processing your personal data for direct marketing purposes.
- RIGHT TO RESTRICTION OF PROCESSING
This enables you to ask us to suspend the processing of personal data about you; for example, you may want us to restrict the use of your personal data which is under our correction process.
- RIGHT TO PORTABILITY
You have the right to ask that we transfer the information you gave us to another organization, or to you, in certain circumstances.
- RIGHT TO COMPLAIN
You may lodge a complaint with the local data protection authority if you believe that we have not complied with the applicable data protection laws.
Please complete the relevant form as provided by us to exercise your rights. Please also note that we will ask you to provide a proof of identity to us before responding to any requests to exercise your rights. We will respond to your request to exercise such rights without delay; we will notify you in advance if we require more time to process your request.
For any processing activities relying on your consent obtained before 1 June 2021, we will maintain and continue processing your personal data based on such consent. If you wish to withdraw your such consent, you may contact us and we will process your request accordingly.
Please note that the above mentioned rights are not absolute, as they should be balanced against legal requirements and our legitimate interest.
SECURITY OF YOUR PERSONAL DATA
We value your privacy; therefore, we place great emphasis on ensuring the security of your personal data. We regularly review and implement reasonable and appropriate physical, technical and organizational security measures when processing your personal data.
Our employees are trained to handle the personal data securely and with respect, failing which they may be subject to disciplinary actions.
CHANGES TO THE PRIVACY NOTICE AND YOUR DUTY TO INFORM US OF CHANGES
This version was last updated on the date written above and historic versions can be obtained by contacting us. We may, from time to time, revise this privacy notice in order to comply with relevant and applicable guidelines and/or laws and/or our services. We will notify you of the revised privacy notice via our communication channels.
Please keep us informed of any changes of your personal data, if any, during your relationship with us to allow us to hold the current and accurate personal data of you.