BANGKOK SMARTCARD SYSTEM COMPANY LIMITED
Bangkok Smartcard System Company Limited (the “Company”, “we”, “us”, or “our”) recognizes the importance of the protection of personal data. We follow security procedures when collecting, using, and/ or disclosing your Personal Data (as defined below).
The Company collects, uses and/or discloses your Personal Data because we currently have business relationship with you or may have business relationship with you in the future, or because you work for, represent, or proceed on behalf of our business partners, e.g., companies which supplies or provide services for the Company, or which we have business communication with which may involve you.
- WHAT PERSONAL DATA WE COLLECT
We may directly or indirectly collect your Personal Data from other sources. For example, we may directly collect your Personal Data (such as, when you do business with the Company or sign a contract or fill out a form when you interact with the Company, including having interactions through the Company’s online platform, through the Company’s website or mobile application, communication via email, telephone, questionnaires, business cards, postage, during meetings and events, scheduling meetings with you or from a source in the system, central drive system/central database of the Company or transport software and/or electronic files).
In addition, we may indirectly collect your Personal Data, e.g., from business partner or service provider you work for, act on its behalf, or represent, the BTS Group Companies (as defined in “TO WHOM WE MAY DISCLOSE PERSONAL DATA” section below), public sources (e.g., social media and websites of third parties or relevant government agencies), other third parties (e.g. other business partners of the Company, reference persons and complainants). The specific types of Personal Data collected will depend on the relationship which you have with the Company or the BTS Group Companies. The followings are example of Personal Data that may be collected:
- Personal details, such as name – surname, title, age, gender, photo, video, CCTV record, geographic location, date of birth, nationality, marital status, financial status, educational and professional information (e.g. position, division, division code, occupation, information contained in job application, company that you worked for or past employer, certification of employment, salary confirmation letter, professional license, work permit, visa, training information, income and salary, first date of work), identifiable information on government-issued document (e.g., national identification card number, passport number, taxpayer identification number, driving license number, house registration number), vehicle-related information (e.g., vehicle identification number or vehicle registration number), signature (including electronic signature), business partner’s identification number (including type of business partner, type of business, area of business), business partner’s information (e.g., evaluation score of business partner/service provider, merchant identification number, business partner registration date), bank account and payment information (e.g., bank account name, bank, bank account type and number, beneficiary account name, payment date, payment method, payment currency and payment account, domestic and cross-border transfer details), credit card details (e.g., credit card number, cardholder name, expiration date), including information relating to pricing strategy, discount rate, sales volume, disbursement items, disbursement amount, details relating to lands that you own (e.g., land rights certificate number), number of shares, securities holder registration number, number of securities and dividend amount);
- Contact details, such as phone number, mobile phone number, facsimile number, address, place of business address, email address, postal code, social media account information (e.g., LINE ID, Facebook account and available time) and other similar information;
- Information relating to the interactions between the Company and the business partner, such as information that you have given to the Company (as appeared in agreement, form or survey), transactional information between you and the Company (e.g., lease agreement or purchase and sale agreement, contractor agreement, consultancy agreement, tendering or bidding document), information relating to purchase and sale transaction with related person/third party, product type, budget type, disbursement budget, expense details, traveling expense, date of purchasing product/service, amount of products/services purchased, number of disbursement items, budget, headquarter number, document number, project name, registered company, creditors, branch, area and payment terms, computer data (e.g., IP address or cookies), vendor and service provider status inspection result, including information from the terms of reference or scope of tendering/bidding/procurement, report of interests, incident report, litigation information, details of quotation in procurement project, annual vendor/service provider evaluation report, CCTV record and construction details for each project;
- Information of your related person, such as identified information of your spouse or children, information about employee working for company relating to you;
- Sensitive data, such as health data, Sensitive Data from national identification card (e.g., nationality and religion) or Sensitive Data which can be used in litigation.
We do not intentionally collect your sensitive data (“Sensitive Data”). However, in case that we do, we will only collect, use, and/or disclose Sensitive Data on the basis of your explicit consent or where permitted by law.
We only collect the Personal Data of children, quasi-incompetent person and incompetent person where their parent or guardian has given their consent. We do not knowingly collect Personal Data from any person under the age of 20 without their parental consent when it is required, or from quasi-incompetent person and incompetent person without their legal guardian’s consent. In the event that we learn that we have unintentionally collected Personal Data from anyone under the age of 20 without parental consent when it is required or from quasi-incompetent person and incompetent person without their legal guardians’ consent, we will immediately delete such Personal Data or only collect, use and/or disclose if we can rely on other legal basis apart from consent or where permitted by law.
2. WHY WE COLLECT, USE AND/OR DISCLOSE PERSONAL DATA
We collect, use and/or disclose Personal Data for the following purposes:
2.1. THE PURPOSES OF WHICH WE RELY ON CONSENT
We rely on consent for the collection, use, and/or disclosure of Personal Data and/or Sensitive Data for the following purposes:
- Health data: for food preparation and facilitation.
2.2. THE PURPOSE THAT WE MAY RELY ON LEGAL BASES IN PROCESSING YOUR PERSONAL DATA
We may also rely on (1) contractual basis, for our initiation or fulfilment of a contract with you; (2) legal obligation, for the fulfilment of our legal obligations; (3) legitimate interest, for the purpose of our legitimate interests and the legitimate interests of third parties. We will balance the legitimate interest pursued by us and any relevant third party with your interest and fundamental rights and freedoms in relation to the protection of your Personal Data; (4) vital interest, for preventing or suppressing a danger to a person’s life, body or health; or other legal grounds permitted under applicable data protection law (as the case may be). Depending on the context of the interactions with us, we may collect, use and/ or disclose Personal Data for the following purposes:
- ) For business purposes, such as to proceed business transactions with business partners and fulfil our duties and/or requests from business partners, to contact business partners regarding products, services and projects of the Company or the business partners (e.g., to respond to questions or requests);
- ) For selection of business partners, such as to verify you and status of business partners, to check status of business or perform other background checks and screen you and business partners, to assess your and business partners’ suitability and qualifications, to assess your and business partners’ risks (including the verification of public information from law enforcement agencies and/or the Company’s blacklist record), to prepare quotations or bidding offer, to enter into agreements, prepare purchase orders or purchase requests with you or business partners and to evaluate your and business partners’ management;
- ) For relationship management, such as to keep your Personal Data up-to-date, to maintain the accuracy of Personal Data, to keep agreements, relating documents, agreement’s reference documents and evidence of the work of business partners which may mention you, to plan, operate and manage (contractual) relationships and rights with business partners
(e.g., to appoint, withdraw or authorize business partners to engage in transaction and order products or services, process payment, to conduct activities relating to accountancy, audit, invoice issuance, management of product and service delivery), to manage your requests or complaints, to improve, support, monitor, and record;
- ) For business communications, such as communication with business partners about products, services and projects of the Company or business partners (e.g., communication via document, response to questions, requests or operational progress report);
- ) For marketing purposes, such as to inform you about news and public information which may be useful, including activities, new product and service offers, product and service price negotiation and survey, as well as for to evaluate and consider providing financial aid
(e.g., financial loan) to you or business partners;
- ) For internal management and communication within the organization, such as to publish internal activities and to comply with business codes of conduct, including but not limited to, procurement, disbursement, internal management, training, inspection, report, document delivery and management, data processing, risk control or management, trend and statistical analysis and planning, and other similar or relating activities;
- ) For business analysis and improvement, such as to research, analyse data, estimate, survey and evaluate and report on our products and services and your or business partners’ performance, including to develop and improve our marketing strategy, and our products and services;
- ) For registration and authentication, such as for your registration, verification, identification and authentication;
- ) For IT systems and IT support systems, such as to support IT and IT support departments,
to administrate system access in which the Company has granted the right to access to you,
to delete unused accounts, implement business control measures to continue business, and for the Company to identify and solve problems in the IT systems, and to safeguard the security of our systems, to develop, implement, operate and manage the IT systems;
- ) For business partner information management, such as to compile list of business partners, record data in the system and update the list and directory of business partners (which includes your Personal Data), as well as to store and manage agreements and relating documents which may contain your name;
- ) For system monitoring and security, such as to control access, monitor systems, equipment and internet, and safeguard IT security;
- ) For dispute management, such as to resolve dispute, enforce the Company’s agreements, establish, exercise, or raising legal claims, including to grant authorization;
- ) For investigation, complaint and/or crime and fraud prevention;
- ) For compliance with internal policy and relating/applicable laws, rules, regulations, guidelines (such as to apply for business licences as required by law) and to coordinate or communicate with government agencies, courts or relevant agencies (such as the Revenue Department, the Royal Thai Police Headquarter and the State Audit Office) including to investigate, complain and/or prevent crime and fraud;
- ) For danger prevention towards life, body or health of a person, such as to control contagious disease or epidemic;
- ) For organizing corporate social and environmental responsibility
Where the Personal Data we collect from you is needed to meet our legal, regulatory, or contractual obligations or enter into an agreement with you, if you do not provide your Personal Data when requested, we may not be able to achieve the aforementioned purposes.
3. TO WHOM WE MAY DISCLOSE YOUR PERSONAL DATA
3.1. BTS Group Companies
3.2. The Company’s service providers
The Company may use other companies, agents or contractors to perform services on our behalf or to assist us in our business with you. The Company may share Personal Data to third parties, including but not limited to (1) infrastructure, software and website developers and IT service providers;
(2) marketing, advertisement, design, creative advertising and communication service providers;
(3) hospitals; (4) data storage and cloud service providers; (5) banks and financial institutions;
(6) insurance companies, sub-insurance companies, insurance brokers, insurance agents, lost adjustors and risk surveyors; (7) logistics and transportation service providers; (8) payment and payment system service providers; (9) voting and vote counting service providers; (10) analysts; (11) travel service agencies; (12) garages and auto parts stores; (13) booking system service providers; (14) outsource internal operation service providers; (15) printing houses; and (16) surveying service providers.
In the course of providing such services, the service providers may have access to your Personal Data. However, the Company will only provide the Company’s service providers with the Personal Data that is necessary for them to perform the services, and we will ask them not to use your Personal Data for any other purposes. The Company will ensure that all the service providers we work with will keep your Personal Data secure.
3.3. Our business partners
3.4. Third parties permitted by law
In certain circumstances, the Company may be required to disclose or share your Personal Data in order to comply with a legal or regulatory obligation. This includes any government agency, court, government authority, embassy, consulate, or other third party where we believe this is necessary to comply with a legal or regulatory obligation, or otherwise to protect the rights of the Company, third party or individuals’ personal safety; or to detect, prevent, or otherwise address fraud, security or safety issues.
3.5. Professional advisors
The Company may disclose Personal Data to the Company’s expert advisors including, but not limited to, (1) independent advisors; (2) legal advisors who assist the Company in its business operations and provide litigation services such as defending or initiating legal actions; (3) external advisors; (4) project advisors; (5) financial advisors; and (6) auditors who provide accounting services or conduct financial audit for the Company.
3.6. Third parties connected with business transfer
4. CROSS-BORDER TRANSFERS OF YOUR PERSONAL DATA
We may disclose or transfer Personal Data to third parties or servers located overseas, which the destination countries may or may not have the same data protection standards as Thailand’s. This includes, without limitation, IT service providers, system developers and maintenance service providers, data storage and cloud service providers, bank/financial institutes, securities companies, shareholders, companies that we invest in, business alliances, agents and distributors, advisor companies, in case of international transfer to customers overseas, business partners or alliances overseas, hotels, training agencies, embassies, and/or consulates. We take steps and measures to ensure that Personal Data is securely transferred, that the receiving parties have in place suitable data protection standard and that the transfer is permitted under the law.
5. HOW LONG DO WE KEEP YOUR PERSONAL DATA
The Company will retain your Personal Data for as long as it is reasonably necessary to fulfil purposes for which the Company obtained them and to comply with the Company’s legal and regulatory obligations. However, the Company may have to retain Personal Data for a longer duration, as required by applicable laws.
6. COOKIES AND HOW THEY ARE USED
If you visit our websites, we will gather certain information automatically from you by using tracking tools and cookies (including, but not limited to, Google Tag Manager, Google Analytics, Hotjar, Matomo, Zendesk, Facebook Pixel Analytics, Facebook Ad Manager, and Google Cloud). Cookies are tracking technologies which are used in analyzing trends, administering our websites, tracking users’ movements around the websites, or to remember users’ settings. Some of the cookies are necessary because otherwise the site is unable to function properly. Other cookies are convenient for the visitors and they remember your username in a secure way as well as your language preferences.
Most internet browsers allow you to control whether or not to accept cookies. If you reject cookies, your ability to use some or all of the features or areas of our websites may be limited. Please see our Cookies Policy for more details [*link].
7. DATA SECURITY
As a way to protect personal privacy of your Personal Data, we maintain appropriate security measures, which include administrative, technical and physical safeguards in relation to access control, to protect the confidentiality, integrity, and availability of Personal Data against any accidental or unlawful or unauthorized loss, alteration, correction, use, disclosure or access, in compliance with the applicable laws.
In particular, we have implemented access control measures which are secured and suitable for our collection, use, and/or disclosure of Personal Data. We restrict access to Personal Data as well as storage and processing equipment by imposing access rights or permission, access management to limit access to Personal Data to only authorized persons, and implement user responsibilities to prevent unauthorized access, disclosure, perception, unlawful duplication of Personal Data or theft of device used to store and process Personal Data; This also includes methods that enabling the re-examination of access, alteration, erasure, or transfer of Personal Data which is suitable for the method and means of collecting, using and/or disclosing of Personal Data.
8. RIGHTS AS A DATA SUBJECT
Subject to applicable laws and exceptions thereof, a data subject has the following rights to:
- ) Access: Data subjects have the right to access or request a copy of the Personal Data we are collecting, using and/or disclosing. For privacy and security, we may require proof of the data subject’s identity before providing the requested Personal Data;
- ) Rectification: Data subjects have the right to have incomplete, inaccurate, misleading, or not up-to-date Personal Data that we collect, use and/or disclose rectified;
- ) Data Portability: Data subjects have the right to obtain Personal Data we hold about that data subject, in a structured, electronic format, and to transmit such data to another data controller, where this is (a) Personal Data which you have provided to us, and (b) if we are collecting, using and/or disclosing that data on the basis of data subject’s consent or to perform a contract with the data subject;
- ) Objection: Data subjects have the right to object to certain collection, use and/or disclosure of Personal Data subject to the applicable law;
- ) Restriction: Data subjects have the right to restrict our use of Personal Data where the data subject believes such Personal Data to be inaccurate, that our collection, use and/or disclosure is unlawful, or that we no longer need such Personal Data for a particular purpose;
- ) Withdraw Consent: For the purposes the data subjects have consented to our collection, use and/or disclosure of Personal Data, data subjects have the right to withdraw consent at any time;
- ) Deletion: Data subjects have the right to request that we delete, destroy or anonymize Personal Data that we collect, use, and/or disclose, except we are not obligated to do so if we need to retain such Personal Data in order to comply with a legal obligation or to establish, exercise or defend legal claims; and
- ) Lodge a complaint: Data subjects have the right to lodge a complaint to the competent authority where the data subject believes our collection, use and/or disclosure of Personal Data is unlawful or non-compliance with applicable data protection law.
- ) OUR CONTACT DETAILS
Bangkok Smartcard System Company Limited
21 TST Tower, 19th and 24th Floors, Vibhavadi Rangsit Rd.
Chom Phon, Chatuchak, Bangkok 10900
Email: email@example.com Tel: 0-2617-8338