Personal Data Protection Policy
Introduction
Phol Dhanya Public Company Limited and its subsidiaries (the "Company") recognize the importance of personal data and have therefore established this Personal Data Protection Policy (the "Policy"), together with personal data protection notices on various matters and related guidelines. The Company governs and manages personal data in accordance with the Personal Data Protection Act B.E. 2562 (2019) and other applicable laws. This Policy is intended to inform data subjects of the purposes and details of the collection, use and/or disclosure of personal data and other related information (collectively, "Data"), as well as their legal rights relating to personal data, so that they are aware of and understand the Company's purposes.
Definitions
"Company" means Phol Dhanya Public Company Limited, including its subsidiaries under its control.
"Company Personnel" means the directors, staff and employees of Phol Dhanya Public Company Limited and its subsidiaries and/or companies under its control.
"Customer" means any individual, organization, company, partnership/juristic person, state enterprise or government agency that purchases products and/or uses services of the Company.
"Business Partner" means any company, partnership/juristic person or individual that buys or sells products or services to or from the Company.
"Visitor" means any external person who contacts, visits or conducts any inspection with the Company for purposes other than the purchase or sale of products and services.
"Personal Data" means any information relating to a person that enables the identification of that person, whether directly or indirectly, but excluding information of deceased persons. Examples of personal data include:
- (1)First name and surname, or nickname
- (2)National ID number, passport number, social security card number, driver's license number, taxpayer identification number, bank account number, credit card number
- (3)Address, email, telephone number
- (4)Device information used for networks or tools, such as IP address, MAC address and Cookie ID
- (5)Biometric data, such as facial images, fingerprints, X-ray films, iris scan data and voice recognition data, as well as genetic data
- (6)Information identifying a person's property, such as vehicle registration and land title deeds
- (7)Information that can be linked to the above information, such as date and place of birth, race, nationality, weight, height, location data, medical data, educational data, financial data and employment data
- (8)Performance appraisal data or an employer's opinions on an employee's work
- (9)Records used to monitor a person's activities, such as log files
- (10)Information that can be used to search for other personal data on the internet
"Data" means anything that conveys the meaning of a matter, fact, information or anything else, whether such meaning is conveyed by the nature of the thing itself or through any means, and whether it is made in the form of a document, file, report, book, diagram, map, photograph, drawing, sound recording, computer recording, electronic means or any other means that enables the recorded matter to be displayed
"Sensitive Personal Data" means a user's personal data relating to race, ethnicity, political opinions, cult, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, genetic data, biometric data, facial image, iris or fingerprint data, trade union data, or any other data designated as sensitive personal data by the Personal Data Protection Committee
"Data Controller" means Phol Dhanya Public Company Limited and its subsidiaries
"Data Processor" means a person who processes data for the benefit of or on behalf of the data controller
"Person" means a natural person who is a data subject under this Policy
"Data Protection Officer (DPO)" means a person assigned to provide advice on and monitor operations, and to coordinate and cooperate with the Office of the Personal Data Protection Committee and other relevant agencies
"Sub-Processor" means a person or juristic person appointed by the data processor to further process data
Policy and Guidelines
1Collection, Use or Disclosure of Personal Data
Collection of personal data refers to access to and use of services in software systems and websites, such as accounting software systems and use of the website with or without registering as a member, which are provided for the purposes of the Company's operations, ordering products and services, making inquiries, filing complaints, submitting suggestions, and other necessary matters for which the data subject must provide personally identifiable data, so that the Company can grant rights or benefits for the use of services under the agreed conditions, as well as improve the quality of products and services, conduct marketing of products or services, organize sales promotions, publicize useful information about products and services, conduct research, analysis and market surveys, and compile statistical data to present new products and services
The Company collects, uses, stores and discloses the personal data of data subjects, placing the utmost importance on the accuracy, completeness and currency of the data by lawful and fair means. The Company stores only the data necessary to provide electronic transaction services and to carry out other operations within the Company's authority and operational objectives, only as required by law. The Company will notify data subjects and request their consent before collecting, using and disclosing such personal data, except where required by law and/or in other cases as specified in this Policy
The Company may collect the personal data of data subjects through various channels, as follows
1.1Collected directly from the data subject, for example
- (1)Collection of personal data through completion of personal data forms in paper and/or online format
- (2)Data that the data subject registers with the Company when making inquiries, creating a user account, ordering products from the website, providing suggestions or feedback on products or services via the website, registering to receive news or participate in activities organized by the Company, including via social media, etc. Examples of registered personal data may include first and last name, gender, age, date of birth, address, email, etc. The Company may use this data to contact the data subject regarding the Company's products and services
1.2. Data from Social Media
Where the data subject contacts the Company via social media, the data collected by the Company may include profile data from the social media used by the data subject to which access has been permitted, such as profile pictures, email addresses and friend lists. You are deemed to have permitted the Company to access, collect and use such social media data in accordance with the terms of this Privacy Policy
1.3. Data from the Data Subject's Usage
When you use the Company's website, the Company may collect usage data such as device ID, IP address, location data, browser data, preferred language, date, time and duration of access, purchase data, preferences and other lifestyle-related data, such as hobbies and favorite sports, in order to analyze and understand usage and to present the Company's website and news in line with your needs (unless the data subject opts out of receiving news from the Company). The Company collects this data from all users, whether or not they have a user account or have entered any information on this website
The Company may receive personal data from other sources if the data subject has consented to the disclosure of such data. This includes data from other commercial sources, such as public databases and data-sourcing agents, as well as data from any other person
2Legal Bases and Purposes of Personal Data Processing
Data processing means that the Company will process your personal data through operations such as collection, recording, organization, structuring, storage, alteration or modification, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction
2.1Processing of Personal Data
The Company processes personal data under the following legal bases
Contract Whether or not the data subject registers as a member, and when using other services, it is essential that the data subject provide data to the Company so that the Company can process such personal data to provide services under the agreed service conditions, and use it to communicate, follow up, notify benefits relating to products or services, and answer questions. If the data subject does not provide such personal data, the Company will be unable to provide services, grant rights and benefits under the conditions, communicate, verify the capacity to enter into a contract, or verify the identity of the data subject, in accordance with Section 24(3) of the Personal Data Protection Act B.E. 2562 (2019)
Consent Where necessary, the Company may use the data subject's personal data for processing to design or develop products and/or services, to present products or services, or to organize the Company's marketing activities, or may collect, use or disclose the data subject's personal data for direct marketing purposes. If the data subject does not wish to consent to this, the data subject may withdraw consent through the Company's contact channels.
Legitimate Interest Where necessary, the Company may use the data subject's personal data for processing for the management and preparation of necessary internal reports, system maintenance to uphold or improve service standards, internal risk management, and internal control and audit, which are necessary for the legitimate interests of the data controller and for use by the data processor, in accordance with Section 24(5) of the Personal Data Protection Act B.E. 2562 (2019).
Legal Obligation Where necessary, the Company may use the data subject's data for processing to comply with the law, such as the Accounting Act B.E. 2543 (2000), the Public Limited Companies Act B.E. 2535 (1992), and other laws under which the Company is required to submit personal data, such as the Civil and Commercial Code, which empowers the courts to order parties to submit documents or information in legal proceedings, in accordance with Section 24(6) of the Personal Data Protection Act B.E. 2562 (2019).
2.2Purposes of Personal Data Processing
The Company defines the purposes of personal data processing as follows:
2.2.1Personal Data of Customers, Business Partners or Visitors
The Company collects and retains such data and will use it for the following purposes:
- (1)Presenting information on products and services, organizing prize competitions and sales promotions, and providing news and information that the data subject has requested to receive
- (2)Responding to inquiries and providing consultation
- (3)Analyzing the effectiveness of advertising media, competitions and sales promotions
- (4)Improving and customizing the website to meet requirements, including evaluating website visit statistics, such as time spent visiting the store, whether or not the data subject has visited before, as well as visits to the Company's branches
- (5)Making the website easier to use, including tailoring the website and products to interests and needs
- (6)Improving the quality of the Company's products and services based on market data and survey results
- (7)Providing product support and maintenance
- (8)Issuing service certificates under product warranties
- (9)Providing membership services
- (10)Providing information services and compiling statistical data
- (11)Reviewing for the purpose of developing and improving products and business strategies
- (12)Performance of contracts
2.2.2Personal Data Relating to Personnel of the Company, Business Partners and Third Parties
The Company will use such data for the following purposes:
- (1)Communication and/or business negotiations
- (2)Data management and processing, such as data on income, receipts, disbursements and payments
- (3)Work relating to contracts and assigned tasks
2.2.3Personal Data of Shareholders
The Company will use such data for the following purposes:
- (1)Treatment of shareholders in accordance with applicable laws and regulations
2.2.4Personal Data Relating to the Employment and Resignation of Company Personnel and Job Applicants
- (1)To establish databases and maintain records (including internships)
- (2)To verify identity and check educational and employment history
- (3)To provide employee benefits
- (4)For the purpose of claiming tax allowances
- (5)For communication, evaluation and relationship management
- (6)For the administration and management of related risks
- (7)For compliance with laws and regulations, as well as the guidelines or requirements of the authorities supervising the Company's operations
- (8)For compliance with the Company's internal operating regulations
- (9)For monitoring, auditing and evaluating the Company's services and managing the Company's relationships
3Personal Data to Be Processed and Retention Period
The Company will process personal data in accordance with the Company's policy, such as the data subject's first name, last name, address, contact location, mobile phone number, email and other service usage information.
The Company collects personal data for one or more of the purposes specified in this policy. The Company will retain the data until such purposes have been fulfilled and will not retain the data once the purposes have been achieved, unless the Company is required to do so for legal reasons.
The Company may collect and process the following categories of personal data of the data subject:
Identification data, such as first and last name, national identification number, passport number, date of birth, nationality, gender, photograph and signature
Contact data, such as address, telephone number, email and electronic contact channels
Employment and business data, such as job title, employment history, business partner information, contract information and payment information
Technical and system usage data, such as IP address, log files, system access data and closed-circuit television (CCTV) footage
Sensitive personal data, such as health data, biometric data (facial images, fingerprints) and criminal records. The Company will process such data only where there is a legal basis to do so and will apply a high level of protective measures.
4Categories of Persons or Entities to Whom Personal Data May Be Disclosed
The Company may disclose your personal data to parties such as the Company's auditors, the Company's external inspectors and government agencies as required by law.
5Rights of the Data Subject
The data subject may exercise their legal rights subject to the provisions of the law and the policies currently in effect or as may be amended in the future, as well as the criteria established by the Company. If the data subject is under 20 years of age or is legally restricted in their capacity to perform juristic acts, you may exercise your rights through your father and mother, a person exercising parental authority or an authorized representative, who shall submit the request on your behalf. Your rights are as follows:
5.1Right to Withdraw Consent
The data subject may withdraw consent to the processing of personal data previously given to the Company at any time while the Company holds such personal data.
5.2Right of Access to Personal Data
The data subject may request that the Company provide a copy of such personal data and may request that the Company disclose how it obtained any personal data for which the data subject did not give consent.
5.3Right to Rectification of Personal Data
The data subject may request that the Company correct inaccurate data or complete incomplete data.
5.4Right to Erasure of Personal Data
The data subject may request that the Company erase the data on certain grounds.
5.5Right to Restrict the Use of Personal Data
The data subject has the right to restrict the use of personal data on certain grounds.
5.6Right to Data Portability
The data subject has the right, on certain grounds, to have the personal data provided to the Company transferred to another data controller or to the data subject themselves.
5.7Right to Object to the Processing of Personal Data
The data subject has the right, on certain grounds, to object to the processing of personal data.
5.8Right to Lodge a Complaint with the Competent Authority under Applicable Law
The data subject may exercise this right if the data subject believes that the collection, use and/or disclosure of data has been carried out in a manner that violates or fails to comply with applicable law.
6Procedure for Exercising Data Subject Rights
The data subject may submit a request to exercise their rights in writing or through channels designated by the Company. The Company will verify the requester's identity and consider the request within the period prescribed by law. The procedures, methods and forms shall be in accordance with the Company's “Data Subject Access Request Procedure (DSAR Procedure)”.
The exercise of the data subject rights described above may be limited under applicable law, and in certain cases there may be necessary grounds on which the Company may refuse or be unable to fulfill such requests, for example, where required to comply with the law or a court order, for the public interest, or where the exercise of rights may infringe the rights and freedoms of others. If the Company refuses any such request, the Company will also inform the data subject of the reasons for the refusal.
Any request under the above shall be made by the data subject in writing, and the Company will use its best efforts to act on it within a reasonable period, not exceeding the period prescribed by law. The Company will comply with the legal requirements relating to the rights of the data subject.
Limitations on services: where the data subject requests the Company to delete, destroy, restrict or transfer data, objects to processing, requests anonymization of data, or withdraws consent, this may in some cases limit the Company's ability to conduct transactions with or provide services to the data subject, subject to the terms and conditions of consent for the relevant services and/or as prescribed by law.
7Security Measures
7.1Technological measures are in place to prevent unauthorized access to computer systems.
7.2Personal data is securely destroyed when it is no longer necessary for legal and business purposes. If the data subject has reason to believe that their personal data has been breached by the Company, please contact the Company through the contact channels specified in these terms and conditions.
The data subject's password is important for their service account. Please use a combination of different numbers, letters or symbols, and do not share your password with others. If the password is shared with others, the data subject shall be responsible for all actions taken in their name or through their service account and for the consequences thereof. Failure to maintain control of the password may result in loss of control over personal data or other information submitted to the Company, and the data subject may be bound by any juristic act performed in their name. Therefore, if the password is disclosed or ceases to be confidential for any reason, or there is reason to believe that it has been disclosed or is no longer confidential, the data subject should contact the Company to change the password. In addition, please log off from the service account and close the browser every time a public computer is used.
7.3Personal data in paper form is stored in lockable filing cabinets accessible only to authorized persons.
7.4Personal data stored on computer devices or information systems must be password-protected, with the password known only to the custodian.
7.5Persons accessing personal data may add data but may not arbitrarily delete, modify or remove it without approval from the data controller.
8Data Subject Participation
The Company discloses details of personal data only upon request by the data subject, their successors, heirs, statutory representatives or legal guardians, who may submit requests in accordance with the rights of the data subject. The Company will complete such requests within a reasonable period, not exceeding the period prescribed by law.
Where the data subject, their successors, heirs, statutory representatives or legal guardians object to the collection, accuracy or any action concerning personal data, such as a request to update, correct or delete personal data, the Company will record such objection as evidence.
9Transfer or Disclosure of Personal Data to Other Parties
The Company does not disclose personal data to third parties. However, personal data may be shared, to the extent consented to by the data subject, with trusted third parties, who may be located in Thailand or abroad, as follows:
9.1The Company's advertising, marketing or sales promotion agents, for analyzing the effectiveness of advertising, marketing and sales promotion, including the Company's subsidiaries, branches and business partners in Thailand and abroad.
9.2Third parties responsible for delivering products or providing services, such as delivery of goods or parcels ordered through any online channel.
9.3Third parties to whom the Company has obtained the data subject's consent to disclose data.
9.4Law enforcement authorities or government agencies with the authority to request disclosure of data.
9.5Website analytics providers, such as Google.
10Cross-Border Transfer of Personal Data
The data controller may send or transfer the data subject's data abroad in the following cases:
10.1The destination country or international organization receiving the personal data has adequate personal data protection standards in accordance with the laws, rules and regulations on personal data protection.
10.2. Consent has been obtained from the data subject, who has been informed of and acknowledges the personal data protection standards of the destination country or international organization receiving the data
10.3. It is for compliance with the law
10.4. It is necessary for the performance of a contract to which the data subject is a party, or for taking steps at the request of the data subject prior to entering into such contract
10.5. It is for the performance of a contract between the data controller and another person for the benefit of the data subject
10.6. It is to prevent or suppress a danger to the life, body or health of the data subject or any other person when the data subject is incapable of giving consent at that time
10.7. It is necessary for carrying out a task in the substantial public interest
11Oversight of Data Processors and Sub-Processors
11.1. The Company shall engage personal data processors under a Data Processing Agreement (DPA) that clearly sets out their duties, liabilities and data protection measures.
11.2. The appointment of a Sub-Processor requires the Company's written approval, and the data processor shall be liable for the acts of the Sub-Processor as if they were its own acts.
11.3. Audit or assessment of compliance with data protection measures: the Company has the right to audit or assess the compliance of data processors and Sub-Processors with data protection measures at appropriate intervals.
11.4. The procedures and methods for selecting, overseeing and assessing data processors shall be in accordance with the Company's “Processor & Sub-Processor Management Procedure.”
12Personal Data Breach Management
The Company has established the following principles and governance framework for handling personal data breaches in accordance with the Personal Data Protection Act B.E. 2562 (2019) and the guidelines of the Office of the Personal Data Protection Committee:
12.1. Detection and Assessment of Incidents
Upon any incident or suspicion of unlawful access to, use, disclosure, loss, alteration or destruction of personal data, the Company shall, without delay, investigate the facts and assess the nature of the incident, the scope of the affected data and the level of risk to the rights and freedoms of data subjects.
12.2. Notification to the Office of the Personal Data Protection Committee
Where a personal data breach poses a risk to the rights and freedoms of data subjects, the Company shall notify the Office of the Personal Data Protection Committee (PDPC Office) without delay and within seventy-two (72) hours of becoming aware of the breach, providing at least the following details: (1) the nature of the breach; (2) the categories and volume of the affected data; (3) the potential impact; and (4) the measures taken or to be taken to remedy the breach and prevent recurrence.
12.3. Notification to Data Subjects
Where a personal data breach poses a high risk to the rights and freedoms of data subjects, the Company shall notify the data subjects without delay through appropriate channels that allow direct contact, such as telephone, email, SMS, registered mail, the Company's website or other communication channels the Company normally uses to contact data subjects. The notification shall specify the nature of the breach, the potential risks, measures to prevent or mitigate damage, and the contact details of the Company or the Data Protection Officer (DPO).
12.4. Oversight and Review
The Company shall require executives and relevant units to regularly oversee, monitor and review the personal data breach response plans and measures to ensure consistency with the law and the guidelines of the Office of the Personal Data Protection Committee. The procedures, methods and forms used for receiving reports, investigating, assessing risks, notifying the Office of the Personal Data Protection Committee within 72 hours and notifying data subjects shall be in accordance with the Company's “Incident Response Procedure.”
13Deletion, Destruction and Anonymization of Data
13.1. Deletion or Destruction of Data
The Company shall delete or destroy personal data using appropriate and secure methods to prevent unauthorized access, recovery or reuse of the data.
13.2. Anonymization of Data
Where personal data can no longer identify the data subject, or where the Company needs to retain data for statistical analysis, research or system development, the Company may anonymize the data so that it can no longer be linked back to the data subject.
13.3. Recordkeeping
Any deletion, destruction or anonymization of data shall be recorded as evidence and shall comply with the retention periods specified in the Record of Processing Activities (ROPA) and the Company's “Data Retention and Disposal Procedure.”
14Related Guidelines and Procedures
To ensure that personal data protection is carried out systematically, effectively and verifiably, the Company has prepared guidelines and procedures separate from this Policy that set out detailed steps, methods and operating processes, comprising at least the following documents:
- (1)Procedure for the Exercise of Data Subject Rights (DSAR Procedure)
- (2)Personal Data Breach Response Procedure (Incident Response Procedure)
- (3)Processor & Sub-Processor Management Procedure
- (4)Data Retention and Disposal Procedure
- (5)Cross-Border Personal Data Transfer Procedure
- (6)Data Protection Impact Assessment Procedure (DPIA Procedure)
The above procedures shall be deemed internal documents of the Company and form part of its personal data protection governance framework. Company personnel, data processors and sub-processors must strictly comply with them. In the event of any discrepancy or conflict between this Policy and the procedures, this Policy shall prevail, and the procedures shall be interpreted in accordance with this Policy and the personal data protection laws.
15Amendments to the Policy
The Company reserves the right to amend this Personal Data Protection Policy as necessary and appropriate, or at least once a year, to ensure consistency with applicable guidelines, regulations and other relevant laws. Any amendments will be announced and disclosed on the Company's website or by other appropriate means.
16Personal Data Retention Period
Personal data is retained for the duration of the data subject's status as Company personnel, a business partner, customer, visitor or other relevant third party, member or contracting party, and for no longer than 10 years for those who have provided data to the Company for their own benefit.
17Contact Information
If data subjects have any suggestions or inquiries regarding the collection, use and/or disclosure of personal data, including requests to exercise their rights under this Policy, they may contact the Company through the following channels:
Data Controller and/or Data Protection Officer (DPO) Phol Dhanya Public Company Limited, 1/11 Lam Luk Ka Road, Lat Sawai Subdistrict, Lam Luk Ka District, Pathum Thani 12150 Tel: 02-791-0111 E-mail: dpo@pdgth.com Business hours: 08:00-17:30 (excluding Saturdays, Sundays, government holidays and public holidays)
This Personal Data Protection Policy has been prepared in accordance with the Personal Data Protection Act B.E. 2562 (2019) and was approved by the Board of Directors on 19 September 2026.
