Sumitomo Bakelite (Thailand) Co., Ltd. (the “Company”) has established and published this Privacy Notice (the “Privacy Notice”) to explain how we collect, use or disclose Personal Data of any contractual parties, service providers, sellers, entrepreneurs or consultants, including directors, representatives, attorneys, or persons acting on behalf of such persons, which has provided the Personal Data to the Company (the “Vendor”), including how we protect the Personal Data and properly handle such Personal Data according to the Personal Data Protection Act B.E. 2562 (2019).
The Company regularly reviews and, if appropriate, updates this Privacy Notice from time to time to ensure that the Data Subjects’ Personal Data is properly protected. In case of any significant update to this Privacy Notice, the Company will inform the Data Subjects via appropriate channel(s).
1. Definitions
“Data Controller” means a person or a juristic person having the power and duties to make decisions regarding the collection, use or disclosure of the Personal Data.
“Data Processor” means a person or a juristic person who operates in relation to the collection, use or disclosure of the Personal Data pursuant to the instructions given by or on behalf of a Data Controller, whereby such person or juristic person is not the Data Controller.
Data Subject” or “Data Subjects” means natural persons who are data subjects whose Personal Data have been collected, used or disclosed by the Company.
“Personal Data” means any information relating to an individual, which enables the identification of such individual, whether directly or indirectly, but not including the information of the deceased persons in particular.
“Sensitive Personal Data” means any Personal Data stated under Section 26 of the Personal Data Protection Act B.E. 2562 (2019), i.e., race, ethnic origin, political opinion, cult, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, biometric data, or of any data which may affect the Data Subject in the same manner, as prescribed by the Personal Data Protection Committee.
2. Purposes of collection, use or disclosure of Personal Data
2.1 Lawful basis for collection, use or disclosure of Personal Data
The Company processes the Personal Data as it is necessary for the scope set out in this Privacy Notice as follows:
(1) Where the Company obtains consent from the Data Subject as required by law;
(2) To prevent or suppress a danger to a person’s life, body or health;
(3) Where it is necessary for performing contractual obligations between the Data Subject and the Company or taking steps at the Data Subject’s request prior to entering into a contract;
(4) Where it is necessary for legitimate interests of the Company or any other persons or juristic persons, except where such interests are overridden by fundamental rights of the Data Subject’s Personal Data;
(5) To comply with laws to which the Company is subjected.
In some cases, the Company may need to collect the Data Subject’s Sensitive Personal Data. In the case where the Company collects Sensitive Personal Data, the Company shall always obtain explicit consent from the Data Subjects prior to the time of such collection of Sensitive Personal Data, unless the explicit consent is not required by the Personal Data Protection Act B.E. 2562 (2019),
2.2 Purposes of collection for use or disclosure of Personal Data
The Company collects the Data Subjects’ Personal Data for various purposes depending on relationship between the Data Subjects and the Company as follows:
2.2.1. For inspection of the qualifications of the Vendor before entering into a contract or other relevant agreement(s), where the Data Subject is a direct contracting party or where the Data Subject is a director, representative, attorney, or personnel who acts on behalf of such Vendor;
2.2.2. For entering into a contract or other relevant agreement(s) with the Vendor, including procedures of considering the contract and obtaining approval for entering into such contract or agreement(s);
2.2.3. For performance under the scope of the contract or the relevant agreements regarding purchasing of products and services from the Vendor, for example, communication and coordination with the Vendor, planning and controlling the production according to purchase orders, receiving products from Customs house and storing the products in the warehouse, issuing shipping invoices, payment for products or services to the Vendors and other necessary undertakings for payment, both reservation of foreign exchange rates with the bank and withholding taxes, etc. as well as the contract management, products and warehouse management, and the relevant internal administration of the Company;
2.2.4. For management of risks, prevention and undertaking of audits, and undertaking of internal administration as required by laws, internal instructions or regulations of the Company, including considering complaints of fraud or misconduct within the Company, for example, the Company’s internal audit, investigating and preventing fraud or other unlawful acts, etc.;
2.2.5. For maintaining security within the Company’s buildings and premises, including recording image within the Company’s buildings, premises and other places and areas under the responsibility of the Company via the closed-circuit television cameras (CCTV), inspecting and verifying identity for entering and exiting the Company’s buildings and premises;
2.2.6. For undertaking detection and investigation under legal procedures and other regulations, complying with laws, rules, orders, legal requirements and obligations of the Company, and reporting or disclosing information to government authorities as required by laws, for example, Revenue Department, or upon receiving summons or writ of executions from police officers, government authorities, courts, or other competent authorities, including for proceeding with the judicial process, establishment, compliance or exercise of the rights to legal claims or defending against the rights to legal claims.
In the case where the Personal Data collected by the Company as stated above is necessary for the Company’s compliance with applicable laws or performance of contract and if the Data Subjects do not provide the Company with such necessary Personal Data, the Company may be subject to legal liabilities and/or may not be able to manage or administer contract or facilitate the Data Subjects.
3. Collected Personal Data
3.1 Personal Data the Company collects
The Company collects several types of Personal Data from the Data Subjects, including:
3.1.1 Identity data, for example, name, surname, identification number, tax identification number, date of birth, place of birth, gender, age, height, nationality, photo, signature, including other information appeared on copy of identification card, etc.;
3.1.2 Contact data, for example, address, telephone number, e-mail, etc.;
3.1.3 Financial or transaction data, for example, bank account number and bank account information, etc.;
3.1.4 Data regarding education and employment, for example, education history and work experience, training experience, work permit information, professional license information[KPMG3] , place of work, job tittle, department, etc.;
3.1.5 Communication data, for example, image or voice recordings when communicating with the Company, etc.;
In some cases, the Company may collect Sensitive Personal Data, for example, religion and/or blood type as appeared on the copy of the national identification card, upon obtaining explicit consent from the Data Subjects or when permitted by law.
3.2 Sources of Personal Data
The Company may collect the Data Subjects’ Personal Data from various sources as follows
3.2.1 Collect the Personal Data directly from the Data Subjects, for example, when the Data Subjects make inquiries with the Company, including procedures of filling-in, signing or submitting documents to the Company, doing questionnaires or registrations, or procedures for taking steps at the request prior to entering into a contract, attaching supporting documents to the contracts, request for exercising rights to the Company, communication with the Company via various channels (for example, telephone, e-mail, etc.).
3.2.2 Collect the Personal Data from other sources, for example, original affiliation of the Data Subjects, government documents, government authorities, private agencies, or other publicly available sources.
4. Personal Data retention period
The Company retains the Data Subjects’ Personal Data for as long as it is considered necessary for the purpose for which it was collected, used or disclosed as set out in this Privacy Notice. The criteria used to determine the Company’s retention period include: the Company retains the Personal Data for the duration the Company has an ongoing relationship with the Data Subjects; and the Company may retain the Personal Data for a longer period as necessary to comply with applicable laws, or to be in accordance with legal prescription, or to establish, comply with or exercise the rights to legal claims or defend against the rights to legal claims, or to comply with, for any other cause, the Company’s internal policies and regulations.
5. Disclosure of Personal Data
5.1 Categories of persons or entities to whom the Personal Data may be disclosed
The Company may disclose the Data Subjects’ Personal Data in certain circumstances for the purposes set out in this Privacy Notice to:
5.1.1 Subsidiaries, group companies and affiliated companies, both in Thailand and foreign countries, for the purpose of undertaking activities as specified in this Privacy Notice.
5.1.2 Commercial banks for payment of expenses of the Company in the relevant processes, such as payment of services or products, or reserving of foreign exchange rates, etc.;
5.1.3 Government authorities, supervisory authorities, independent authorities or other authorities as stipulated by laws, including competent officials who have power or perform their obligation under the laws, for example, courts, police officers, the Office of the Personal Data Protection Committee, the Revenue Department, the Department of Business Development, the Customs Department, etc.
5.1.4 Agencies, service providers, contractors and/or sub-contractors for conducting any undertakings for the Company such as logistics service providers, document storage and destruction service providers, printing houses, IT development and maintenance service providers, auditors, lawyers, legal and tax advisors, other consultants, etc.
5.1.5 Other third parties as per your consent, or based on contractual provisions, or compliance with legal requirements (as the case may be), including various channels, such as, public medias, online medias, etc.
5.2 Transmission or transfer of Personal Data to foreign countries
In some cases, the Company may transmit or transfer the Personal Data to foreign countries. In such case, the Company shall ensure that the destination country or international organization that receives such Personal Data shall have adequate data protection standard, and the Company shall provide appropriate protection and security measures and comply with the Personal Data Protection Act B.E. 2562 (2019) including obtaining consent from the Data Subjects for the transmission or transfer of Personal Data to foreign countries as required by law.
6. Rights of Data Subjects
The Data Subjects have certain rights according to the Personal Data Protection Act B.E. 2562 (2019) including the following rights:
6.1 Right to withdraw consent
The Data Subjects have the right to withdraw consent given to the Company for collecting, using or disclosing the Data Subjects’ Personal Data at any time, unless there is a restriction of the withdrawal of consent by law or the contract which gives benefits to the Data Subjects.
However, the withdrawal of consent shall not affect the collection, use or disclosure of Personal Data that the Data Subjects have already given consent legally.
6.2 Right of access
The Data Subjects have the right to request access to and obtain copy of the Data Subjects’ Personal Data, which is under the Company’s responsibility, or to request the disclosure of the acquisition of the Personal Data obtained without the Data Subjects’ consent.
6.3 Right to data portability
Where the Company arranges the Data Subjects’ Personal Data to be in the format which is readable or commonly used by ways of automatic tools or equipment, and can be used or disclosed by automated means, the Data Subjects have the right to receive the Data Subjects’ Personal Data from the Company and request the Company to send or transfer the Data Subjects’ Personal Data in such formats to other data controllers as provided by the law.
6.4 Right to object
The Data Subjects have the right to object to the collection, use or disclosure of the Data Subjects’ Personal Data on grounds stipulated by law.
6.5 Right to erasure
The Data Subjects have the right to request the Company to erase, destroy or make the Data Subjects’ Personal Data become unidentifiable data under certain circumstances as provided by law.
6.6 Right to restriction of use
The Data Subjects have the right to request the Company to restrict the use of the Data Subjects’ Personal Data under certain circumstances as provided by law.
6.7 Right to rectification
The Data Subjects have the right to request the Company to modify the Data Subjects’ Personal Data to be accurate, up-to-date, complete, and not misleading.
6.8 Right to complaint
The Data Subjects have the right to file a complaint to an authorized officer appointed by the Personal Data Protection Act B.E. 2562 (2019) when the Company violates or does not comply with such law.
In the case where the Data Subjects request to exercise the rights according to the provisions of the Personal Data Protection Act B.E. 2562 (2019), upon receiving the request, the Company will proceed with such request within the period as stipulated by law. In this regard, the Company reserves the right to refuse or not process the request under certain circumstances as stipulated by law.
7. Security measures for Personal Data
The Company implements appropriate and strict security measures for protecting the security of Personal Data in order to prevent unauthorized or unlawful loss, access to, use, alteration, correction or disclosure of Personal Data.
In the case where the Company assigns third parties to process the Personal Data pursuant to the orders given by or on behalf of the Company, the Company shall appropriately supervise such third parties to ensure that they will maintain the security of the Data Subjects’ Personal Data according to the Personal Data Protection Act B.E. 2562 (2019).
8. Contact information
If the Data Subjects have any questions or inquiries about the Personal Data protection, collection, use or disclosure of the Data Subjects’ Personal Data, or exercise of the Data Subjects’ rights as a data subject, or have any complaints, please contact us