Aydia Creation 2015 Company Limited (“Company”, “we” us “our”) respects the importance of the protection of your rights regarding information relating to any identified or identifiable natural person (“Personal Data”) from our products and services. We understand that you would like to receive the required level of protection as required by the Thai applicable data protection laws for how information about you is collected, used, disclosed, and/or transferred outside of Thailand. The information you share with us allows us to provide the products and services that suit your specific needs appropriately, both from the Company, affiliates and subsidiaries. We provide Personal Data protection measures which includes the protection of your Personal Data from being used without your consent beforehand.
DATA WE COLLECT FROM YOU OR ABOUT YOU AND OUR SOURCES OF THAT DATA
Your personal data includes any information that you provide to us, that we collect or that we are provided with by third parties and that identifies you, or from which you are identifiable, whether directly or indirectly. We may collect, use, store and transfer the following personal data about you:
Data you give us
▪ when you place an order on Company Website or otherwise;
▪ when you create an account on Company Website;
▪ when you join Company loyalty program;
▪ by filling in forms on Company Website;
▪ by downloading or registering with Company mobile app;
▪ when you use Company Website;
▪ when you sign up to receive email updates from us;
▪ when you ask us to provide you with marketing communications such as newsletters, updates or information about special events or promotions;
▪ if you ask us to keep in touch with you or provide you with personalized content (such as targeted advertising);
▪ if you contact us or correspond with us (for example, by phone, email or otherwise) for any reason; or when you provide us with comments, opinions and/or feedback about the Company.
DATA WE COLLECT ABOUT YOU WHEN YOU VISIT OR USE COMPANY WEBSITE
▪ Technical information, including the type of device (and its unique device identifier) you use to access the Company Websites, the Internet protocol (IP) address used to connect your device to the Internet, your unique device identifier (UDID) or mobile equipment identifier (MEID) for your mobile device, your device and component serial numbers, your login information, browser type and version, time zone setting, browser plug in types and versions, operating systems, mobile network information and platform and details of any referring website or application; and
▪ Information about your visit to the Company Websites including full Uniform Resource Locators (URL), clickstream to, through and from the Company Websites (including date and time), pages you viewed, page response time, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
▪ Data other Company members collect about you. Any information you provide to member of the Company will be shared between us.
▪ Data we collect from or are provided with by third parties. We may be given information about you from third parties. We may also collect information that is publicly available, for example, when we interact with you through social media.
▪ The provision of certain personal data by you to us (such as your name, email address, contact information, credit card and such other information as may be indicated by the Company) will be compulsory or obligatory in order for the Company to perform the relevant services for the identified purposes. The Company may not be able to perform the relevant services for the identified purposes if you fail to supply the relevant personal data.
As our valued customer, we wish to advise you that the information collected by us in relation to persons under 20 years of age is limited to their name, nationality, date of birth and, where applicable, special requirements, which can only be supplied to us by parent or legal guardian.
We would be grateful if you could ensure that children you are responsible for do not send us any personal data without your consent (particularly via the Internet).
Our websites are not intended for children and we do not intentionally solicit or collect personal information from individuals under the age of 20. If we learn that personal information of minors has been collected without the appropriate notification or consent, we will take the appropriate steps to delete such information and prohibit its further collection.
HOW WE USE YOUR PERSONAL DATA AND THE LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA
The Company uses the personal data for relevant purposes as indicated below where we have a legal basis to use your personal data without consent, this privacy statement fulfils our duty to process personal data fairly and lawfully and in a manner that you would expect given the nature of our relationship with you, by giving you appropriate notice and explanation of the way in which your personal data will
The relevant purposes are:
▪ To conduct research and development in order to improve our goods, and activities to meet your need;
▪ For administrative purposes relating to our customers’ accounts
▪ To communicate the relevant information between Company and you;
▪ To prepare historical documents or archives for the public interest, study, research or statistic;
▪ To perform a duty for the public interest or a duty as authorized by the government;
▪ To obtain a legitimate interest of Company or others;
▪ To comply with a law and a regulation.
Where consent is required for our use of your personal data as described above, we will request your consent. Typically, we would collect your consent by you performing an action such as ticking the appropriate consent box or otherwise communicating your consent to us (for example, by email or by you providing us with non-mandatory information), you consent to our use of that personal data as set out in this privacy statement. For example, we will only process your personal data for marketing purposes if we have your consent to do so. Please see here for further information on this.
Marketing and your choices
We will, if you have given us your consent and in line with your choices, provide you with information by post, telephone, email, SMS and electronic messaging, which may be of interest to you in respect of the Company. Where you have consented to receiving our direct marketing online this means that you could be presented with our advertisements while using the Company Websites or the services of our online partners.
HOW WE SHARE AND DISCLOSE YOUR PERSONAL DATA
We may share or disclose your personal data in connection with the purposes described in this privacy statement. This may include sharing your personal data with the following:
▪ All companies within the Company for marketing, business, administrative and legal purposes (for example, payment, verification or membership awards and points);
▪ Facebook, Twitter or Instagram (if you use your account with them to sign up / in with us), if applicable;
▪ Service providers, business partners, suppliers, subcontractors or agents and whom perform functions
▪Professional advisers acting as processors or joint controllers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services;
▪ Vendors who provide services to us, such as fulfilling orders, providing data processing and other information technology services, managing promotions, carrying out research and analysis, and personalizing individual customer experiences. We do not allow these vendors to use this information or to share it for any purpose other than to provide services on our behalf;
▪ Government or other law enforcement agencies, in connection with the investigation of unlawful activities or for other legal reasons (this may include your location information);
▪ Third parties, who acquire us or substantially all of our assets, in which case your personal data (including any sensitive personal data) will be one of the transferred assets (however, we will let you know before this happens); and
▪ Analytics and search engine providers that assist us in the improvement and optimization of the Company Websites.
WHERE WE STORE YOUR PERSONAL DATA
The personal data that we collect from you may be transferred to, processed and stored, in different countries depending on the circumstances. This includes any country where our external service providers are based or hosting your personal data on our behalf.
Please note that your personal data may be transferred to and stored in countries which do not provide the same level of protection for personal data as under your local law. However, we will ensure that a similar degree of protection is afforded to it by ensuring that one of the following safeguards is implemented:
LINKS TO THIRD PARTY WEBSITE
The Company Websites may contain links to other third-party websites and microsites, whose privacy practices may differ from those of the Company. If you submit personal data to any of those sites, your personal data is not subject to this privacy statement.
RETENTION OF PERSONAL DATA
Your personal data will only be retained for a period while you are under relationship with us. After that, the data may be further retained as long as
(A) It is necessary for the purpose of collection of the relevant personal data or
(B) The data is required for legal action or
(C) The retention is required by law.
If you choose to unsubscribe from our mailing list or should your access to any of your memberships expire, your personal data will still be retained on our database to the extent permitted by law
HOW WE STORE AND SECURE YOUR PERSONAL DATA
We are committed to taking appropriate measures designed to keep your personal data secure. Our technical and organizational procedures are designed to protect your personal data from accidental, unlawful or unauthorized loss, access, disclosure, use, alteration, or destruction. While we make efforts to protect our information systems, no website, mobile application, computer system, or transmission of information over the or any other public network can be guaranteed to be 100% secure. Once we have received your personal data, we will use strict procedures and security features to try to prevent unauthorized access or inadvertent disclosure.
The personal data that we hold about you will be stored either on our servers or using third party data storage, in compliance with applicable data protection laws. We may post a notice on the relevant Company Website, notify you by email or contact you otherwise if a security breach occurs and such breach presents a high risk to your rights and freedoms.
YOUR LEGAL RIGHTS
You have the following rights with regard to your personal data:
▪ Withdraw consent. When our processing of your personal data is based on consent, you have the right to withdraw such consent at any time. The withdrawal of such consent will not in any way affect the process completed before the time of withdrawal. However, in case that the processing is based solely on your consent, we may not be able to perform the relevant services for you any further.
▪ Access. You have the right to access data we hold about you. This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it or how we obtained such data.
▪ Rectification or erasure. You have the right to request that we rectify, delete, or make unidentifiable of any personal data that we hold about you (unless we have the legal right to retain it). This right does not extend to non-personal data. Please note that your rights to request erasure may be limited by applicable law.
▪ Restriction. You also have the right to restrict us from processing your personal data if the data is inaccurate, the processing is unlawful or we no longer need to your personal data for the purposes for which we hold it.
▪ Data portability. You have the right to obtain personal data we hold about you, in a structured, electronic format, and to transmit such data to another data controller if the legal basis for processing such personal data is consent or contract.
▪ Object /change of preferences. You have a right to request that we stop processing your personal data where we are relying on a legitimate interest (or those of a third party), a public task, or data obtained for a direct marketing purpose or a scientific or historical research or statistics. You have the right to object where we are processing your personal data for direct marketing purposes.
We will comply with your request to exercise the above-mentioned rights, to the extent required by applicable law. However, if you ask us to stop processing your personal data in certain ways or erase your personal data, and this type of processing or data is needed to facilitate your use of the Company Website or is required for us to provide you with a service (such as to manage your account), you may not be able to use the Company Website or the service as you did before.
This does not include your right to object to the processing of your personal data for the purposes of direct marketing. You can exercise this right at any time without restrictions. Please allow at least 3 working days for your request to be actioned.
To protect your confidentiality and to comply with applicable data protection laws, we may need to confirm your identity before we can action your request. Protecting your confidentiality and complying with applicable data protection laws is important to us, the Company may therefore refuse to comply with any request unless it is supplied with such information as it may reasonably require to verify your identity. We will respond to your requests within a reasonable time and in accordance with the applicable data protection laws.
A “cookie” is a small text file that is placed onto an Internet user’s web browser or device and is used to remember and/or obtain information about the user and a “web beacon” is a small object or image that is embedded into a web page, application, or email and is used to track activity, which are also sometimes referred to as pixels and tags.
We use the following cookies:
▪ Strictly necessary cookies. These are cookies that are required for the operation of the Company Websites.
▪ Analytical/performance cookies. They allow us to recognize and count the number of visitors and to see how visitors move around the Company Websites when they are using it. They also enable us to see how users use the Company Websites. This helps us to improve the way the Company Websites work.
▪ Functionality cookies. These are used to recognize you when you return to the Company Websites. This enables us to personalize our content for you, greet you by name and remember your preferences.
▪ Targeting cookies. These cookies record your visit to the Company Websites, the pages you have visited and the links you have followed. We will use this information to make the website and the advertising displayed on it more relevant to your interests.
By clicking “agree” on the cookie consent box when you first access the Company Website and by continuing to access and use such Company Website you accept our use of the cookies. You can block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies. However, if you use your browser settings to block all cookies (including essential cookies) you may not be able to access all or parts of the Company Website.
CHANGES TO THE PRIVACY STATEMENT
▪ This privacy statement is in effect as of the date noted at the top of the statement. We may change our privacy statement from time to time. Any changes we may make to our privacy statement in the future will be posted on this page and, where appropriate, notified to you by e-mail.
▪ Please check back frequently to see any updates or changes to our privacy statement. By continuing to use the Company Website or continuing to allow us to retain or process your personal data following any such changes to our privacy statement, you are deemed to have accepted such changes unless you expressly notify us otherwise in writing (except to the extent we are required to make such changes in accordance with applicable law).
This privacy statement is published in the English Language (English Version) and in such other languages. In the event of any inconsistency in the terms of the privacy statement between the English Version and the other relevant versions, the terms of the privacy statement in the English Version shall prevail to the extent of such inconsistency.