Jaspal Public Company Limited (“Company”) recognises the importance of protecting the personal data that you have provided or may provide to the Company. Therefore, the Company has issued this Privacy Notice to inform and help you understand the details concerning the collection, use, and disclosure (collectively referred to as “Processing”) of your personal data in accordance with the Personal Data Protection Act B.E. 2562 (2019), including your legal rights as the data subject. The details are as follows:
This Privacy Notice applies to the personal data of our current suppliers, as well as potential future business partners and suppliers. It applies to both individuals and natural persons acting on behalf of entities that own personal data, including executives, directors, consultants, employees, agents, and anyone related to the company’s personnel. Therefore, the Company recommends that you read this Privacy Notice to be informed of and understand the methods, guidelines, and purposes by which the Company processes your personal data, as well as to be aware of your personal data rights and the Company’s contact channels.
“Supplier” means natural or juristic persons who engage in transactions with the Company and have received approval to enter into legal contract with the Company, including contracting parties, service providers, consultants, lessors, and other current or potential future business partners. This also includes natural persons associated with, or representing, juristic persons who are business partners, such as executives, directors, employees, agents, representatives, or any other related individuals. Additionally, it covers persons whose personal information appears in documents related to transactions between the Company and the juristic person, such as coordinators, shippers, merchandise inspectors, check issuers, and any individuals whose information the juristic person has provided to the Company.
“Personal Data” means any information relating to a person which can be used to identify such person, whether directly or indirectly, excluding data of deceased persons. Types of personal data include:
– General Personal Data: Such as title, name, surname, age, gender, nationality, date of birth, nickname, address, phone number, national ID number, passport number, social security number, taxpayer ID number, driver’s license number, bank account number, email address, vehicle registration number, etc.
– Sensitive Personal Data: Includes personal data related to race, ethnicity, political opinions, doctrines, religious or philosophical beliefs, sexual behaviour, criminal records, health information, disability, labour union information, genetic data, biometric data, or any other information that similarly affects the data subjects as specified by the Personal Data Protection Committee, of which the Company will proceed with special care. The Company will collect, use, and/or disclose Sensitive Personal Data only with your explicit consent or when the Company is legally required to do so.
However, the following information is not considered personal data: business contact information that does not identify a person such as company name, company address, company registration number, office phone number, work email address, email address of a company’s group such as info@company.co.th, anonymous data, or pseudonymous data which has been anonymised such that it cannot be used to identify a person by technical means, and data of deceased persons.
“Data Subject” means an individual who owns the personal data, in this case, “you” as the Supplier.
The Company may collect your personal data as necessary for the purposes of collection, use, or disclosure as specified in Article 5. And in order to inform you and help you understand the details in regard to your personal data that the Company collects, the Company hereby informs you of the details as follows:
Types of Personal Data |
Details of Personal Data |
---|---|
Basic Personal Data | Title, name, surname, age, gender, photograph, date of birth, nationality, national ID number, passport number, address as specified on house registration certificate, signature |
Other Data |
(1) Contact Data: Such as contact address, telephone number, email address (2) Financial Data: Such as bank account number, financial statement (3) Communication Data: Such as recorded audio or images when interacting with the Company (4) Information gathered from procurement before entering into the contract (5) Education and training Data: Such as educational background, educational qualification documents, skills and abilities, and various works (6) Activity Participation Data: Including recording of still images or videos from participation in various activities (7) CCTV Data: Recorded by closed-circuit television (CCTV) (8) Opinions, suggestions, complaints |
Sensitive Personal Data | Health information: Such as weight, height, body measurements |
If you have provided a copy of your national ID card to the Company, please be informed that the Company does not intend to collect and use information related to religions and blood types (if any) appearing on your national ID card. Therefore, we request that you conceal such information (if any), and in the event that you do not conceal such information as informed by the Company, you will be deemed to have given consent and permitted the Company to conceal such information on your behalf, and any documents with such concealed information will be considered legally valid and enforceable in every aspect.
Furthermore, the personal data you provide to the Company must be correct, complete, truthful, and not misleading. You are required to keep your personal data up to date by informing the Company of any changes or updates through the contact channels of the Company as specified in Article 13 of this Privacy Notice.
The Company collects and gathers your personal data and sensitive personal data through the following methods:
4.1 Personal Data Provided Directly by You:
This includes information provided during the new supplier registration process, procurement procedures before contract signing, filling out forms, completing surveys, or submitting claims or requests for various rights. It also includes information given when registering for an account or profile with the Company for communication purposes, both offline and online.
4.2 Personal Data which is automatically collected
When you use the Company’s services through its systems or visit the Company’s website using electronic devices such as mobile phones, computers, laptops, etc., using technology known as “cookies” or similar technologies.
4.3 Personal Data Received from External Sources or Reliable Public Sources
The Company may obtain your personal data from the Department of Provincial Administration, the Department of Business Development, commercial sources, websites, applications, social media sources, data providers, agencies or companies or associations related to legal transactions and/or business operations of the Supplier, etc.
4.4 Personal Data obtained from your interactions with the Company
The Company may receive the personal data of your employees, staff, representatives, partners, or authorized agents, or any other individuals or entities involved or assigned by the Company through websites, applications, social media, phone calls, emails, meetings, interviews, or any other means. The Company may collect personal data in the form of text, as well as images and audio.
The Company will collect, use, and disclose your personal data for the purposes outlined below, based on the legal basis for data processing and in accordance with the personal data collected as specified in Article 3 of this Privacy Notice. The details are as follows:
Purpose of Processing |
Legal Basis |
---|---|
1. To carry out the processes before entering into a contract with the Company, including: (1) Consideration of the qualifications of the Supplier. (2) New Supplier registration. (3) Preparing information before entering the Company’s procurement process, including preferred vendor procurement, price comparison procurement, and bidding procurement. (4) Invitation to bid, bidding, and obtaining for submission of bidding documents according to the Company’s procurement process. (5) Drafting a Non-Disclosure Agreement (NDA) with you before providing Company data for your review and to assist in preparing details, conditions, specifications, and prices in accordance with the Company’s procurement requirements. |
- Contractual Basis - Legitimate Interest |
2. To execute and sign commercial contracts between the Supplier and the Company after you have been selected. |
- Contractual Basis |
3. To fulfill commercial contracts, such as employment contracts, service contracts, lease agreements, sales contracts, and other commercial agreements, and to verify contract performance and acceptance. |
- Contractual Basis - Legitimate Interest |
4. For the establishment of legal claims, compliance with or exercise of legal claims, or the defence against legal claims, as well as for providing evidence in legal proceedings, conducting litigation, and taking any other actions to enforce legal judgments, including reporting data to government agencies as required by law. |
- Legal Obligation - Legitimate Interest |
5. To develop an information system for data storage, processing, and as a database for selecting partners and/or hiring for future projects. | - Legitimate Interest |
6. For security purposes within the Company premises, including exchanging access cards containing your personal data before accessing office/branch/work areas, leased or service areas, and recording images on the Company’s premises through CCTV. | - Legitimate Interest |
7. To plan, report, and forecast the Company’s business activities. | - Legitimate Interest |
8. To manage health and safety aspects related to your work with the Company. |
- Legal Obligation - Legitimate Interest |
The Company may disclose your personal data to internal and external parties as necessary to fulfil the purposes specified in this Privacy Notice. The Company may send your personal data to the following parties:
6.1 Internal Parties
Your personal data may be disclosed or sent to various departments within the Company, but only to those that are relevant and have a role or responsibility, and only to the extent necessary for the stated purposes, as follows:
6.2 External Parties
Your personal data may be disclosed or sent to the following organisations or third parties:
6.2.1 Government authorities, regulatory bodies, or other entities as required by law, such as the Revenue Department, Office of the Consumer Protection Board, Department of Business Development, Department of International Trade, Thai Customs, Department of Intellectual Property, government, courts, Legal Execution Department, or any other agencies with legal authority.
6.2.2 Organisations, or external parties: The company may disclose your data to external organizations or individuals for purposes such as verifying transactions and providing or arranging products and services that meet your needs.
7.1 If the Company collects, uses, or discloses your personal data based on your consent, you have the right to withdraw your consent at any time. The withdrawal of consent will not affect the collection, use, or disclosure of personal data that you have already consented to.
7.2 If you are a minor under the Civil and Commercial Code, please inform the Company of the details of your legal guardian before providing consent so that the Company can obtain consent from the guardian as well.
You may withdraw your consent for the collection, use, or disclosure of all or part of your personal data as specified in this Privacy Notice by notifying the Company.
If you withdraw your consent, the fact that you consented to the Company collecting, using, or disclosing your personal data may result in you losing benefits related to the Company’s services, similar to the situation where you initially consented to the collection, use, or disclosure of your personal data.
8.1 The Company may transfer or disclose your personal data to other parties, both domestically and internationally, when necessary to fulfill a contract you are a party to, or to perform a contract between the Company and other individuals or legal entities for your benefit. This may also include processing data in response to your pre-contractual requests or to prevent or mitigate harm to your or others’ lives, bodies, or health, or to comply with legal obligations or for necessary public interest missions.
8.2 The Company may store your data on computers, servers, or cloud services provided by third parties, and may use third-party software or applications in the form of ready-made software services and platform services to process your personal data. The Company will not permit unauthorized access to personal data and will ensure that these third parties implement appropriate measures to protect the security of personal data.
8.3 In cases where it is necessary to transfer or disclose your personal data to foreign countries, the Company will comply with data protection laws and take appropriate measures to ensure that your personal data is protected and that you can exercise your rights concerning your personal data as provided by law. Additionally, the Company will require recipients of your personal data to implement suitable protection measures and process the data only as necessary, taking steps to prevent unauthorized use or disclosure of your personal data.
9.1 The Company will retain your personal data only for as long as necessary, considering the necessity and purposes for which the Company needs to collect, use, and process the data, including compliance with applicable legal requirements.
The criteria for determining the retention period include the duration of the Company’s relationship with you as a registered partner, contractor, director, representative, authorized person, or employee acting on behalf of an individual or legal entity registered as a partner or business associate of the Company. Data may be retained beyond this period if necessary for legal compliance, statutory limitation periods, establishing, exercising, or defending legal claims, or other reasons according to the Company’s internal policies and requirements.
9.2 The Company may continue to collect, use, and disclose your personal data even if you end your relationship with the Company, as necessary to comply with legal requirements for legitimate interests, or in anonymized or pseudonymized forms that prevent identification of individuals directly or indirectly, such as anonymization or pseudonymization methods that make it technically impossible to identify individuals.
9.3 The Company may retain your personal data for as long as necessary to achieve the purposes of processing your personal data as described in this Privacy Notice. The Company will retain your personal data for no longer than 10 years from the date you end your relationship or the last contact with the Company. The Company may retain your personal data for longer if permitted by law.
9.4 To comply with applicable retention periods and statutory limitation periods, the Company will store your personal data in appropriate forms according to the type of personal data. However, the Company may need to retain your personal data beyond the statutory limitation period for legitimate interests of the data controller, provided such interests are not outweighed by your fundamental rights concerning your personal data.
9.5 The Company will undertake to delete or destroy personal data to ensure it can no longer identify the data subject permanently, or otherwise restrict all personal data when the retention period has expired, or if it is no longer relevant or necessary for the purposes of collection. This includes complying with your request to delete your personal data.
The Company has implemented appropriate security standards to prevent the loss, unauthorised access, use, alteration, or disclosure of personal data without authorisation or improperly, and the Company will review these measures as necessary, or when technology changes, to ensure the effectiveness of the security measures as appropriate.
In the event that the Company collects, uses, or discloses your personal data for the purposes specified in this Privacy Notice, you have the following rights under the Personal Data Protection Act B.E. 2562 (2019):
11.1 Right to Withdraw Consent
If you have given consent to the Company for the collection, use, and/or disclosure of your personal data (whether such consent was given before or after the enforcement of the Personal Data Protection Law), you have the right to withdraw your consent at any time while your personal data is with the Company, unless there are legal restrictions or contractual obligations that benefit you.
The withdrawal of your consent may affect job consideration, various benefits that you may receive from the Company, or the ability to receive beneficial information. Therefore, it is beneficial for you to study and inquire about the potential impacts before withdrawing your consent.
11.2 Right to Access
You have the right to access your personal data and request a copy of your personal data that is under the Company’s responsibility. You may also request that the Company disclose the source of your personal data that is in the possession of the Company.
The Company may refuse your request to access and obtain a copy of your personal data if doing so would adversely affect the rights and freedom of other individuals, or if the Company is required by law or a court order to withhold such personal data.
11.3 Data Portability Right
You have the right to obtain your personal data in the event that the Company has prepared such personal data in a readable or usable format by automated tools or devices and where such personal data can be used or disclosed in an automatic manner. You also have the right to request the Company to send or transfer the personal data in the foregoing formats to another data controller where such process can be done by automated means, and you also have the right to request the personal data which the Company sends or transfers in the foregoing formats to another data controller directly unless otherwise technically unfeasible.
However, the foregoing personal data must be the data you provided consent for the Company to collect, use, and/or disclose, or the personal data that the Company is required to collect, use, and/or disclose to provide you with services of the Company as per your agreement with the Company, or other personal data as specified by the legally authorised entity.
11.4 Right to Object
You have the right to object to the collection, use, and/or disclosure of your personal data at any time if the collection, use, and/or disclosure of your personal data is carried out for operations necessary for the legitimate interests of the Company or of another person or juristic persons, within reasonable expectations, or for the performance of a task carried out in the public interest. If you object, the Company will still continue to collect, use, and/or disclose your personal data only where the Company can demonstrate legal grounds that outweigh your fundamental rights, or for the establishment of legal rights, legal compliance, or defence of legal claims in litigations as applicable.
11.5 Right to Erasure
You have the right to request the deletion or destruction of your personal data, or to have your personal data anonymised if you believe that your personal data has been unlawfully collected, used, and/or disclosed, or if you find that it is no longer necessary for the Company to retain your personal data for the purposes stated in this Privacy Notice, or when you have exercised your right to withdraw consent or object as stated above, unless in the cases where the Company must retain the data for legal compliance or to exercise its legal rights in relation to the retention of such personal data.
11.6 Right to Restrict Processing
You have the right to request the temporary suspension of the use of your personal data in cases where the Company is verifying your request for correction of personal data or objection, or in any other case where the Company no longer needs to retain and must delete or destroy your personal data in accordance with applicable laws, but you request the Company to suspend its use instead.
11.7 Right to Rectification
You have the right to request that the Company correct your personal data to be correct, up-to-date, complete, and not misleading.
11.8 Right to Lodge a Complaint
You have the right to file a complaint with the relevant legal authorities if you believe that the collection, use, and/or disclosure of your personal data has been conducted in a manner that violates or does not comply with the applicable laws.
If you have any concerns or questions about the Company’s practices regarding your personal data, please contact the Company using the contact details provided in Article 12 of this Privacy Notice. In the event that there is reasonable evidence to believe that the Company has violated the Personal Data Protection Law, you have the right to file a complaint with the Expert Committee appointed by the Personal Data Protection Committee in accordance with the regulations and procedures specified by the Personal Data Protection Law.
If you wish to exercise the rights stipulated above, you must contact the Company using the contact details provided in Article 13 of this Privacy Notice by submitting a written request. The Company will make its best endeavour to consider and respond to your request without delay, or within the time frame specified by law. However, any request to exercise these rights may be limited subject to the relevant laws, and in some cases, the Company may refuse or is unable to proceed as requested as appropriate and on lawful grounds such as where the law grants the right to deny such requests.
The Company reserves the right to amend this Privacy Notice as necessary and appropriate. Any changes will be announced and displayed on the Company’s website or by other appropriate means.
If you have any questions related to this Privacy Notice, or if you wish to exercise your rights as outlined in Article 11, or if you have any complaints, you can contact the Company at:
Data Controller
Jaspal Public Company Limited – Data Protection Officer (DPO)
Contact Address: 1054 Sukhumvit 66/1, Phrakhanong Tai Sub-district, Phrakhanong District, Bangkok 10260
Phone Number: 02 856 2000
Email: dpo@jaspal.co.th
You hereby acknowledge and agree that this Privacy Notice is governed by and construed in accordance with the laws of Thailand, and that the courts of Thailand have jurisdiction over any disputes that may arise.
Effective Date: 6 September 2024