Personal Data Protection Policy Tanasin 2560 Company Limited and its Subsidiaries
1.Definitions
“Personal data” means any information that can be used to identify a natural person (“data subject”), whether directly or indirectly, but shall not include, in particular, any information regarding deceased persons.
“Sensitive data” means any information that is intrinsically personal of any individual that is sensitive and may be subject to discrimination. For example, race, political opinions, beliefs, religion, philosophy, information of health or disability or any similar data which may affect the data subject.
“Data controller” means a person or a juristic person who has the power and duty to make decisions regarding the collection, use, or disclosure of personal data.
“Data processor” means a person or a juristic person who is engaged in the collection, use, or disclosure of personal data under the instruction of a data controller. The person or juristic person who is engaged in the above-mentioned activities is not considered a data controller.
2. Collection of Personal Data
3. Purposes of the Collection or use of Personal Data
- In the interest of the operations and the provision of services of the Company;
- For improvement of the service quality and the enhancement of efficiency;
- In order for the Company to be able to perform obligations under agreements;
- In order to update the personal data;
- In order to prevent severe damage to health and life;
- For the legitimate interest of the Company and other persons, provided that such collection of personal data shall not be beyond the scope that the data subject may reasonably foresee, and that the rights of the data subject shall not be prejudiced; and
- In order to comply with the laws or regulations relating to the operations of the Company.
4. Disclosure of Personal Data
5. Protection of Personal Data
6. Control of Third-Party Service Providers
6. Control of Third-Party Service Providers
7. Period for Retention of Personal Data
8. Rights of Data Subjects
- Right to withdraw consent:The data subject has the right to withdraw consent for the processing of personal data that he or she has given to the Company, provided that any withdrawal of consent shall not affect the use, collection, or the disclosure of personal data to which the data subject has given his or her consent.
- Right to access personal data: The data subject has the right to access his or her personal data and to make copies of his or her personal data throughout the period his or her personal data is retained by the Company.
- Right to personal data portability: The data subject has the right to transfer his or her personal data given to the Company to other data controllers when such transfer is made possible by an automatic means or in accordance with the procedures specified by the Company.
- Right to object to the processing of personal data: The data subject has the right to object to the processing of his or her personal data by the Company
- Right to erase, destroy or suspend any use of personal data: The data subject has the right to request the Company to erase, destroy, or suspend any use of his or her personal data retained by the Company, or to request the Company to undertake any act rendering that the data cannot be used to identify the data subject provided that such undertaking is not against the law.
- Right to rectification: The data subject has the right to request the Company to rectify and update his or her personal data retained by the Company.
9. Review and Amendment of the Personal Data Protection Policy
10. Contact Channel
Contact: Data Protection Officer
Name: Ms. Worakanya Chaisittikul
Address: Tanasin 2560 Co., Ltd. 123/4 San Klang, Sankumphaeng, Chiang Mai 50130, Thailand
Email: c.worakanya@www.thantararesort.com