Data Protection Policy for Customers and Clients
Effective from 1 January 2023 until further notice (supersedes Announcement No. 4/2565). This page is an English translation of the Company's official Thai policy; in the event of any discrepancy, the Thai version prevails.
Open the announced policy (PDF, Thai) ↗
INET Managed Services Company Limited, its parent company, subsidiaries, associated companies and companies in the same group of undertakings (the “Company”) are committed to complying with the Personal Data Protection Act B.E. 2562 (2019), its subordinate legislation, and the announcements, regulations, guidelines and/or orders of the Personal Data Protection Committee. The Company has therefore established the principles and practices governing the collection, use, processing and disclosure of personal data and the protection of Data Subjects' rights, and hereby announces this Data Protection Policy to apply to the Company's customers and clients as follows. Customers and clients are asked to study the details and conditions of this policy carefully.
1. Definitions
“Processing” means any operation performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, rectification, structuring, storage, alteration or adaptation, retrieval, consultation, use, disclosure by transmission, transfer or dissemination, or any other act that makes data available, alignment or combination, restriction, erasure or destruction. “Personal Data” means any information relating to a person that enables that person — the “Data Subject” — to be identified, directly or indirectly, including every category of data that can identify a person, including but not limited to name and surname, address, telephone number, national identification number, passport number, online data, and data on physical, psychological, social, economic or cultural identity, or any other data by which a person can be identified (excluding, specifically, the data of deceased persons). “Sensitive Personal Data” means the special categories of personal data under Section 26 of the Personal Data Protection Act B.E. 2562 (2019), such as personal data concerning race or ethnicity, political opinions, cult, religious or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade-union information, genetic data, biometric data, or any other data of a similar nature as prescribed by the Personal Data Protection Committee. “Group of Undertakings” means undertakings whose operator has controlling management power over another undertaking, or undertakings controlled by an operator with power over them, in the form of a parent company, subsidiary, associated company, or natural or juristic persons related to one another in law or through joint economic activity, determined according to generally accepted accounting standards. “Data Subject” means a natural person who can be identified by the personal data in question, whether directly or indirectly. “Company” means INET Managed Services Company Limited, its parent company, subsidiaries, associated companies and/or companies in the same group of undertakings. “Subsidiary” means a juristic person or company (a) over which INET Managed Services Co., Ltd. or Internet Thailand Public Company Limited has control; (b) over which a juristic person or company under (a) has control; or (c) that is under the control of a company under (b), through successive tiers, beginning with control by a juristic person or company under (b). “Associated Company” means a juristic person or company (a) in which INET Managed Services Co., Ltd., Internet Thailand PCL or a subsidiary holds, directly or indirectly, 20% or more but not more than 50% of all voting shares; or (b) over whose financial and operating policy decisions INET Managed Services Co., Ltd., Internet Thailand PCL or a subsidiary has power to participate, short of control over those policies, and which is not a subsidiary or joint venture. “Parent Company” means a juristic person or company that (a) has control over INET Managed Services Co., Ltd. or Internet Thailand PCL; (b) has control over a juristic person or company under (a); or (c) has control over a company under (b), through successive tiers, beginning with control over a company under (b). “Control” means a relationship in any of the following forms: (a) holding voting shares in a juristic person or company exceeding 50% of its total voting rights; (b) having power to control the majority of votes at a shareholders' meeting, whether directly or indirectly or for any other reason; or (c) having power to control the appointment or removal of at least half of all directors, whether directly or indirectly.
2. Data the Company collects
2.1 General personal data — the Company needs to collect, use and disclose your personal data, including but not limited to: - Name and surname - Date of birth - Age - User accounts (Account), social-media accounts such as LINE, accounts used to access any of the Company's services, and cookie data (Cookies) - Photographs - Address, house registration and domicile details - National ID card or passport - Telephone number - Mobile telephone number - Email address - Taxpayer identification number - Vehicle registration - Payment data, namely credit- and debit-card data and bank-account data - Occupation and workplace - Data on legal representatives, their income, and contactable persons - Computer traffic data (log files), such as your IP address and the dates and times you used the Company's computer programs, software, hardware, websites, applications, networks and/or other services - Your location (Location) 2.2 Sensitive personal data — the Company collects your sensitive personal data under Section 26 of the Personal Data Protection Act B.E. 2562 (2019), such as data on race or ethnicity, political opinions, cult, religious or philosophical beliefs, sexual behaviour, criminal records, health, disability, trade-union information, genetic data or biometric data, or other data of a similar nature. The Company accesses, collects, uses, processes, discloses and controls such data with care, within the scope prescribed by law, and will notify you of the details of its collection, use, processing and/or disclosure before or at the time of collection, under the conditions and criteria prescribed by law. 2.3 Personal data connected with unlawful acts — you acknowledge that where an offence under civil, criminal or any other law has occurred, the Company is entitled to collect or use data about your unlawful act, and will access, collect, disclose and control such data with care within the scope prescribed by law. 2.4 Personal data collected, processed, used and/or disclosed from third parties — you acknowledge and consent to the Company collecting, processing and using personal data including but not limited to data on your name and surname, national ID number, user accounts and social-media accounts such as LINE (including email linked to a user account), IP address, address, date of birth, gender, age, photographs, email, bank-account number and telephone number, which the Company may receive from financial institutions, agents or the Company's business partners, among others. The Company informs you that, to protect and maintain the safety of the general public and to protect the Company's interests, CCTV cameras are installed for security within Company premises; the Company, or external providers it engages, may collect, use and process still images, moving images and/or sound of you, and data you use and bring into Company premises. The Company may also record telephone conversations in order to improve and develop its services and for public relations.
3. Data the Company processes
The Company processes the personal data it collects from you directly, or collects from third parties as described in Clause 2, for the provision of services, the performance of contracts, compliance with law, the Company's legitimate interests, or the purposes set out in Clause 4. In some cases the Company uses automated decision-making to process your data through computer systems — for example, the Company may evaluate personal data in connection with its services or otherwise. You may ask for further details by contacting the Company's Data Protection Officer as set out in Clause 11.
4. Purposes and legal grounds for collecting, using and disclosing your data
The Company collects, uses and discloses your personal data for the following purposes: - Identifying or verifying your identity - Registering contacts, service applications and/or your use of services - Selling goods and/or providing services to you - Charging and/or collecting payment for goods and/or services, including issuing invoices and receipts, payment reminders, refunds and reclaims - Delivering goods and/or services, including prizes, souvenirs and giveaways - Assessing satisfaction - Developing goods and/or services - Research and statistics - Opening user accounts (Account) for the Company's computer programs, software, hardware, websites, applications, networks and/or other services, including user registration, review of user qualifications, announcement of user lists, preparation of user directories, granting of user benefits and privileges, keeping of usage history and/or benefits received, and/or development of the Company's computer programs, software, hardware, websites, applications, networks and/or other services - Delivering, presenting or publicising information about the Company's services related to services you have expressed interest in, through your contact channels, whether social media, email or telephone - Promoting, developing and improving the business relationship between you and the Company - Considering, processing, testing or analysing your interests in order to promote, develop and improve the Company's services so that they best respond to your interests and needs - Training, supervising or guaranteeing employees and quality in matters connected with coordination or contact with you through various channels - Managing, resolving, inquiring into and analysing problems that may arise from the Company's services, using such data only as necessary - Managing, answering or responding to questions, communications, service complaints or feedback from you - Clarifying, stating or notifying you of changes in format or of information connected with the Company's services - Examining, protecting against or preventing unlawful acts, violations, misconduct or breaches of laws, rules, regulations, agreements and service conditions, and any conditions of the Company - Promoting or publicising participation in advertising campaigns and other sales-promotion activities under the Company's conditions - Marketing purposes, such as sending documents about promotions and news about the Company's goods, services, events and/or sales-promotion activities by post, email and/or telephone and by other means, including direct marketing to increase the benefits you may receive from being a customer of the Company; you may opt out of receiving marketing communications from the Company - Preventing or suppressing danger to a person's life, body or health - Complying with applicable laws, rules, regulations and announcements - Performing the contract between the Company and you, or taking steps in response to your service request before entering into a contract with the Company - Performing duties in carrying out activities in the Company's public interest, or performing duties in the exercise of official authority entrusted to the Company - The legitimate interests of the Company or of other persons - The interests of the Company's business operations - Any other operations closely connected with, or of the same nature as, the purposes set out above Where the Company needs to collect, use and disclose personal data in order to perform a contract with you, or to process your service request before entering into a contract with the Company, and you do not provide that personal data, the Company may be unable to perform the contract or to provide services to you correctly and completely as specified in the contract. The Company may need to collect, use, process and disclose sensitive personal data by relying on legal grounds that entitle it to do so, including but not limited to the following grounds, or with your explicit consent: - To prevent or suppress danger to the life, body or health of a person where the Data Subject cannot give consent, for whatever reason - For legitimate activities, with appropriate safeguards, of a foundation, association or other not-for-profit body with a political, religious, philosophical or trade-union purpose, for its members, former members, or persons in regular contact with it in connection with that purpose, without disclosing the personal data outside that foundation, association or body - Data that has been made public with the explicit consent of the Data Subject - Where necessary for the establishment of legal claims, compliance with or the exercise of legal claims, or the defence of legal claims - Where necessary for compliance with the law to achieve purposes concerning (a) preventive or occupational medicine, assessment of an employee's working capacity, medical diagnosis, health or social care, medical treatment, health-system management, or social-welfare services; (b) public interest in public health; (c) labour protection, social security, national health security, welfare concerning the medical care of persons entitled by law, road-accident victim protection, or social protection; (d) scientific, historical or statistical research or other public interest; or (e) substantial public interest You may ask for further information by contacting the Data Protection Officer where the Company collects, uses, processes and discloses your sensitive personal data on the basis of consent you have given. You may withdraw consent at any time by contacting the Data Protection Officer as set out in Clause 11. If you withdraw consent, the Company may still need to process your personal data to comply with the law or to protect the Company's interests; the Company will explain to you, at the time of withdrawal, which data it remains obliged to collect or process for legal-compliance purposes. In addition, the Company collects, uses and discloses personal data for other purposes consistent with, or in the same course as, the purposes stated above, including all purposes of historical, statistical or scientific research and archiving in the public interest. Where possible, the Company will not use data that can identify you for those purposes, or will take steps to limit the scope of the personal data used in such research or archives, and may use pseudonymous data to avoid using your personal data.
5. Recipients of your personal data
The Company recognises the importance of ensuring adequate protection of personal data. It endeavours to limit access to personal data to those persons who need such access to perform their duties: the employees and personnel of the Company, its parent company, subsidiaries, associated companies, companies in the same group of undertakings and/or the Company's business partners, together with external parties that have contracted with the Company concerning the collection, use and disclosure of personal data, and other counterparties acting in the Company's name, who will receive, collect, use and disclose your personal data. The Company discloses personal data to those companies only to the extent necessary to process personal data for providing services to you and to protect the Company's interests, and they agree to protect your personal data from unauthorised use, access or disclosure. You may contact the Data Protection Officer as set out in Clause 11 to ask about the categories of providers to which the Company discloses your personal data. The Company may disclose your contact information in a staff directory made available to Company employees and the general public; in any event, you have the right to ask for your data to be removed, subject to the criteria, conditions and periods the Company prescribes. The Company may provide your personal data to any other company or agency — for example, government agencies, state bodies, regulators of the Company's services or of the Company, agencies of which the Company is a member, and government authorities with supervisory power over immigration, tax, national security and criminal matters, as required by law — in order to carry out the Company's business, joint activities, travel, jointly organised events and research. You further agree and consent to the Company disclosing or transferring your personal data to its parent company, subsidiaries, associated companies, companies in the same group of undertakings, or the Company's business partners, for the purposes of the Company's operations, compliance with the Company's policies, performance of contracts or provision of services between the Company and you, protection of the Company's legitimate interests, the public interest, or as announced by the Company case by case. The Company informs you that its website links to third-party websites whose privacy policies may differ from the Company's. You should therefore study the privacy policies of those websites to understand the details of their personal-data protection before deciding to disclose personal data to them. The Company accepts no responsibility for any loss or damage arising from the acts of third-party websites in any case.
6. Transfer of personal data abroad
The Company may transfer your personal data abroad for the purposes of its operations, as necessary. You agree and consent to the Company sending your personal data outside Thailand to persons or agencies located in other countries, or under the jurisdiction of other countries, whether or not the personal-data protection law of those countries meets the standard of Thailand's personal-data protection law. The Company will follow appropriate steps to protect and secure your personal data at the same level as Thailand's personal-data protection law.
7. Security and confidentiality of personal data
To build confidence in the Company's management and to protect against risks that personal data might be accessed without authority, leaked, altered or lost, the Company has put in place security measures for personal data that are appropriate to the standards required by law. It adheres to its Information Security Policy, complies with recognised international information-security standards, and manages business continuity. The Company has measures to protect your privacy by restricting access rights to your personal data: only persons who need to use that data in presenting the Company's goods and/or services, for providing the Company's services, and/or for the purposes set out in Clause 4 above — such as Company employees whom the Company authorises to access the data — may do so, and they must strictly adhere to and comply with the Company's data-protection measures, including maintaining the confidentiality of that data. The Company maintains both physical and electronic safeguards in line with the standards of regulatory supervision that apply to the protection of personal data. When the Company enters into contracts or agreements with third parties, it will set out appropriate measures for the security of personal data and the keeping of confidential data, to ensure that the personal data the Company collects remains secure.
8. Retention period
The Company will collect and retain your personal data as necessary and within the timeframes prescribed by law. You may inquire about the periods for which the Company retains your personal data by contacting the Company's Data Protection Officer as set out in Clause 11.
9. Your rights
Subject to the law, you have the following rights over your personal data at any time: - The right to access your personal data held by the Company, including the right to have inaccurate or incomplete data corrected - The right to obtain a copy of your personal data in electronic form, which you may send to a third party or ask the Company to send directly - The right to object to the processing of your personal data for marketing purposes and any other purposes prescribed by law - The right to have your personal data erased when it is no longer necessary for the purposes for which it was collected, including the right to restrict the scope of processing where erasure cannot be carried out - The right to have the data controller suspend the use of your personal data - The right to ask the Company to ensure that your personal data is accurate, current, complete and not misleading - The right to lodge a complaint with the supervisory authority where you believe your rights have been violated The exercise of these rights is subject to the terms, announcements and regulations the Company prescribes, in line with the criteria of personal-data protection law, the Company's data-protection policy and other criteria the Company sets. To exercise the rights above you must submit a written request to the Company's Data Protection Officer as set out in Clause 11 of this announcement; consideration of such requests is at the Company's sole discretion, and the Company's determination on a request to exercise your rights is final. Where you ask the Company to erase, destroy, restrict the collection, use, processing or disclosure of personal data, temporarily suspend its use, convert it into non-identifiable form, or where you withdraw consent, this may create limitations on the Company in carrying out transactions with you or providing services to you.
10. Withdrawal of consent
If you no longer wish the Company to collect, use, process or disclose your personal data, you may withdraw your consent by submitting a request to the Company's Data Protection Officer. Withdrawal of consent is subject to the conditions, terms, announcements or regulations prescribed under personal-data protection law, the Company's data-protection policy and any other criteria the Company prescribes. Withdrawal of consent may create limitations on the Company in carrying out transactions with you or providing services to you.
11. Data Protection Officer
If you wish to exercise the rights set out in Clause 9, to withdraw consent under Clause 10, or if you have questions about the collection, use or disclosure of personal data, please contact the Data Protection Officer: Data Protection Officer Address: INET Managed Services Co., Ltd., 1768 Thai Summit Tower, 14th Fl., New Petchburi Rd., Bang Kapi, Huai Khwang, Bangkok 10310 Telephone: 0 2257 7000 Email: dpooffice@inetms.co.th Website: https://www.inetms.co.th
12. Customers or clients who are natural persons not yet sui juris
If you are a natural person who is not yet 20 years of age, or who has not otherwise become sui juris under the law, you confirm that you are more than 15 years old and are able, with binding legal effect, to perform by yourself the juristic acts and other acts that must be carried out personally or that befit your station in life — including but not limited to purchasing goods or using any services from the Company, its parent company, subsidiaries, associated companies and companies in the same group of undertakings — and that you acknowledge and agree to comply with this Data Protection Policy. If you are a natural person aged not more than 15 years, you confirm that you have received the consent of your legal representative under the law for purchasing goods or using any services from the Company, its parent company, subsidiaries, associated companies and companies in the same group of undertakings, that both you and your legal representative acknowledge and agree to comply with this Data Protection Policy, and that you will gladly provide the relevant supporting evidence to the Company on request.
13. Amendments
The Company reserves the right to amend this policy for any reason it deems appropriate, including where required for compliance with laws, government policies, rules, announcements, regulations or other relevant instruments. When any change is made, the Company will announce it on the Company's website at https://www.inetms.co.th, and such amendment takes effect immediately upon its announcement on the website. You acknowledge and agree to comply with the data-protection policy as amended in every version, and you should check and read the details of the data-protection policy the Company announces on its website regularly. Announcement No. 4/2565 is hereby repealed, and this announcement takes effect from 1 January 2023 onwards, until otherwise ordered.
Contact the Data Protection Officer
For questions about this policy, or to exercise your rights over your personal data, contact the Data Protection Officer at INET Managed Services Co., Ltd., 1768 Thai Summit Tower, 14th Fl., New Petchburi Rd., Huai Khwang, Bangkok 10310, telephone 0 2257 7000, or email dpooffice@inetms.co.th.