Privacy Policy
This Personal Data Protection Policy (“Policy”) was announced effective on March 1, 2020 with the following details.
Pentor(Cambodia) PLC. (“Company”) cares about customer privacy. Therefore, this privacy policy has been announced for the company's customers to be informed of the company's policy regarding the collection, use, and disclosure of personal information of natural persons. (“Data owner”) in accordance with the Personal Data Protection Act 2019 (“Personal Data Protection Act”), related laws and regulations. This privacy policy announcement will inform the data owner of how the company collects, uses, or discloses the data owner's personal information, the types of information, and the purposes for doing so. Including details about how long data will be kept. Disclosing personal information to third parties Rights of the data owner Maintaining the confidentiality and security of the data owner's personal information and how the data owner can contact the company
This privacy notice applies to the following persons.
- (1) Purpose of collection, use, or disclosure of personal information The customer acknowledges, agrees and consents to the company and data processor collecting, using or disclosing personal information. For the following purposes only
- In order to use the service smoothly and in accordance with the laws, rules and regulations related to the company's business operations. Including to perform duties according to law and regulations related to or applicable to the company Including but not limited to Personal Data Protection Act B.E. 2019 and/or Payment Systems Act B.E. 2017 and/or Computer Crime Act B.E. 2007, both currently in effect and those that will be There will be corrections or additions in the future.
- For the benefit of confirming or identifying customers when accessing the website and various applications or services of the company.
- To check information on customer service use in order to develop security standards for using the service. Management and protection of information technology infrastructure In this part, the company may use personal information of customers. Only as necessary and may require encryption before use and/or arrange for random checks. Access testing is used to manage risk, detect, prevent, and/or eliminate fraud or other activity that is likely to violate the law. Related usage regulations or terms and conditions of use of websites and applications (“Terms and Conditions of Use”) of the Company
- For any other benefits related to the Company's business operations, such as for the benefit of studying, researching, preparing statistics, developing services, and creating relevant targeted marketing or advertising. including content delivery Advertising and public relations Various activities and promotions, as well as providing appropriate advice to provide services that meet the interests of customers.
- To operate the Website and Application and provide the Services, including to: - initiate payments, make payments or collect payments; Add value to an account or pay a bill.
- To manage the company's business needs, such as auditing, analysis, and service improvement. and the performance and functionality of websites and applications. For example, the Company analyzes user behavior and conducts research on how customers use the Company's services.
- To manage risk and protect our website and applications, products or services from fraud or theft. To help detect and prevent fraud or theft and abuse of the Company's services.
- To market to customers about the Company's products and services as well as the products and services of unrelated businesses The Company may process Customer Personal Data to tailor marketing content and certain services or experiences of the Website and Applications to the Customer's interests on the Website and Applications or the Website and Apps. Other Third Party Apps
- In order to provide personalized services offered by the Company on third-party websites and online applications and services, the Company may use Customer's “Personal Information“ and other information collected in accordance with This “Privacy Policy“ is intended to provide customers with targeted displays, features, products, services, or offerings on third-party websites and applications. The Company may use cookies and other tracking technologies. To provide these websites and applications and online services and/or work with other third parties such as merchants, partners, advertising agencies and/or analytics companies that provide the websites and applications and online services. these
- to give options Functionality or location-specific offers to customers If Customer chooses to disclose Customer's geographic location information through the Services. The Company uses this information to enhance the security of its websites and applications. Products and services and provide location-based services to customers, such as advertising, search results, and other customized content.
- To carry out our duties and to enforce the terms of the website and application. Company products and services including to comply with all applicable laws and regulations.
- To make it easier for customers to find and connect with others The Company may use the Customer information that the Customer discloses to the Service to provide recommendations for connecting the Customer with people the Customer may know. For example, the Company may connect information that the Company knows about the Customer through the Customer's use of the Services or contacts. of the customer and information provided by customers and others to introduce people they may know or may wish to transact with through the Company's services. Social functionality and features designed to make it easier for customers to share the Services with others may vary by Service.
- To respond to customer requests, such as contacting customers regarding questions that customers send to the Call Center or other departments of the company.
- In order to increase efficiency in providing various services to customers.
- to contact customers Via telephone, text message (SMS), email or post or through any channel to inquire or notify customers. or check and confirm information about the customer's account or poll or provide any other information related to the Company's services as necessary.
- However, when the customer communicates with the company or the company's team, it is considered that the customer acknowledges and accepts that Communications with the Company may be audio recorded. Record the conversation or record contact details by any means.
- To achieve the objectives related to the preparation of historical documents or archives for public benefit. or related to research studies or statistics which have provided appropriate protective measures to protect the rights and freedoms of customers as required by law.
- To prevent or stop danger to a person's life, body, or health.
- It is necessary for the performance of the contract to which the customer is a party or for carrying out the request of the customer before entering into that contract.
- It is necessary for the performance of duties in carrying out missions for the public benefit of the company. or performing duties in the exercise of state power granted to the company
- It is necessary for the legitimate interests of the company. of the data processor or of persons or legal entities other than the Company. unless such benefits are less important than the basic rights of customers' personal data.
- (2) Personal information collected, used, and disclosed The customer acknowledges, agrees and consents to the company and data processor collecting, using or disclosing personal information. only as follows
- Name-Surname
- National identification number
- Passport number or identification number in important identification documents
- Date of birth
- Address according to ID card
- Address according to house registration
- Current address
- occupation
- name of work
- Location of work
- Telephone number or mobile phone number
- Signature or electronic signature
- ID card photo
- Personal photo
- Information about transactions
- Communication record
- Sensitive Personal Data (Sensitive Data)
- However, personal information that is not mentioned above. Include the following information as well.
- Information directly provided by customers: The Company collects information that customers send to the Company, such as information that customers enter when registering for services or opening an account. Information used to apply for services and information for participating in various activities on websites and applications Survey or questionnaire information Request information Customer account information (User Account) or information that the customer has edited or updated in the customer account information (User Account) of the customer or information obtained from the customer contacting the company or the company's team. or information obtained from other customer accounts (User Accounts) that the Company has reasonable grounds to believe is under control of the customer. Including but not limited to All types of information displayed on the customer profile page and various service application pages, such as first and last name, address, date/month/year of birth, gender, age, photograph, email, bank account number. Credit card number (if any) National ID card number Tax ID Telephone number This includes all information about the customer's account, interests, and comments that the customer has expressed through the website and application (if any) to be stored with the account.
- Information received from the customer's use of the service: The Company collects information about the service the customer uses and how the customer uses it. This information includes but is not limited to: Information about the devices customers use to access websites and applications. Computer traffic data (Log), contact and communication data between customers and other customers. and information from usage logs, such as device identifiers. Computer identification number (IP Address) Device identification code Device type Mobile network information Connection data, audio data, geo-location data Browser type (Browser) Website and application log data Website and application information that customers access before and after (Referring Website) information recording history of website and application usage Login log data (Login Log), transaction data (Transaction Log), usage behavior (Customer Behavior), website and application access statistics. Time of visiting websites and applications (Access Time), information that customers search for Using various functions in websites and applications and information that the Company collects through cookies or other similar technologies.
- Information received from third parties: government agencies, banks, financial institutions, partners, data providers. Credit Information Center Officials with legal authority, in the case where the law allows or the customer has given consent and/or the information is disclosed to the public.
- (3) Period of data collection The customer acknowledges, agrees, and consents to the company and data processor collecting, using, or disclosing personal data for a total of 10 years from the date of giving consent to collect, use, or disclose personal data in accordance with this policy or counting. From the date of terminating the relationship or closing the account with the company, as the case may be, and after the said period has elapsed or in the event that the company has no rights or is unable to collect, use, or disclose the customer's personal information. The company will destroy or delete that personal information within 14 days from the end of the said period.
- (4) Disclosure of personal information to third parties The customer acknowledges, agrees and consents to the company and data processor collecting, using or disclosing personal data to third parties. data processor Affiliated companies or partners who work with the company This includes but is not limited to other natural persons or juristic persons both domestically and abroad. For the purposes of this policy and/or as required by law. In addition, the Company may need to send the customer's personal information to the bank where the customer has linked their account with the Company's customer account in order to investigate and prevent legal violations.
3. Linking or sharing customer information with providers of third-party websites and applications, products and/or services.
4. Tracking behavior of customers using websites and applications
- To manage safety and control the operation of the system smoothly
- To process information about the use of the Company's websites and applications. This information can help the company understand the needs and trends of traffic to its websites and applications.
- To help customers have continuous access to the website and applications.
5. Customer Account (User Account)
6. Customer rights in personal information
- (1) Right to withdraw consent: Customers have the right to withdraw consent to the collection, use, or disclosure of personal information that the customer has given consent to the Company. Throughout the period that the customer's personal information is with the company.
- (2) Right of access to personal data: Customers have the right to access their personal data and request that the Company make a copy of such personal data for the customer. Including requesting the company to disclose the acquisition of personal information that the customer has not given consent to the company.
- (3) Right to rectification of personal information: Customers have the right to request the company to correct incorrect information or add incomplete information.
- (4) Right to erasure: Customers have the right to request that the Company delete their personal data for certain reasons.
- (5) Right to restriction of processing: Customers have the right to suspend the use of their personal information for certain reasons.
- (6) Right to data portability: The customer has the right to transfer the customer's personal data that the customer has provided to the company to another data controller or the customer himself for reasons. in some respects
- (7) Right to object to the processing of personal data (right to object): Customers have the right to object to the processing of their personal data on certain grounds.
7. Marketing and promotion activities
8. Maintaining security in the storage of personal information
9. Correcting and updating personal information
- Public health benefits such as health protection from dangerous contagious diseases or epidemics that may be transmitted or spread into the Kingdom. or controlling the standards or quality of drugs, medical supplies, or medical devices. which has provided appropriate and specific measures to protect the rights and freedoms of personal data owners, especially maintaining the confidentiality of personal data according to duties or professional ethics.
- Labor protection Social Security National health insurance Welfare regarding medical treatment of persons with legal rights Protection for car accident victims or social protection The collection of personal data is necessary to comply with the rights or duties of the personal data controller or the owner of personal data. We have put in place appropriate measures to protect the basic rights and interests of personal data owners.
- Scientific research studies history, statistics, or other public benefits. However, this must be done to achieve such objectives only to the extent necessary. and appropriate measures have been put in place to protect the basic rights and interests of personal data owners. As announced by the Personal Data Protection Committee
- Important public benefits We have put in place appropriate measures to protect the basic rights and interests of personal data owners.
- In the case of biological data, it includes personal data that is created by using techniques or technology that involve using physical or behavioral characteristics of a person to be able to confirm that person's identity which is different from other people. such as simulated facial image data Iris simulation data or fingerprint simulation data, etc.
- The Company will record the collection, use and/or disclosure of customers' personal information as specified above as important.
10. Collection, use and/or disclosure of personal data in accordance with personal data protection laws.
- (1) To achieve the objectives related to the preparation of historical documents or archives for public benefit. or related to research studies or statistics which have provided appropriate protection measures to protect the rights and freedoms of the owner of personal data.
- (2) To prevent or stop danger to a person's life, body, or health.
- (3) It is necessary for the performance of a contract to which the owner of personal data is a party or for carrying out the request of the owner of personal data before entering into that contract.
- (4) It is necessary for the performance of duties in carrying out missions for the public benefit of the company. or performing duties in the exercise of state power granted to the company
- (5) It is necessary for the legitimate interests of the company or of persons or juristic persons other than the company. unless such benefit is less important than the basic right to personal data of the personal data owner.
- (6) Compliance with the Company's laws
11. Collection, use and/or disclosure of sensitive personal data (Sensitive Data)
- Preventative medicine or
12. Collection, use and/or disclosure of personal information which is under the guardianship, guardianship or conservatorship of the customer.
- (1) Minors who are not yet of legal age under the guardianship of the customer. Except in the case where the minor is over 10 years of age and has visited, used, been a member, or used the services of the website and application which is an action of the following nature:
- Any action that is performed solely for the purpose of obtaining a particular right. or to escape from any duty
- Any action which must be done personally.
- Any action which is commensurate with one's status. and is necessary for living a reasonable life
- (2) An incapacitated person who is under the guardianship of the customer.
- (3) A quasi-incompetent person who is under the protection of the customer.
13. Sending or transferring personal information abroad
- (1) he destination country or international organization receiving personal data has adequate standards of personal data protection as required by laws, rules, announcements, or regulations regarding personal data protection.
- (2) Receive consent from the customer. Where the customer is the owner of personal data and has been informed and aware of the insufficient standards of personal data protection of the destination country or international organization receiving that data.
- (3) Compliance with the law
- (4) It is necessary for the performance of a contract to which the owner of personal data is a party or for use in carrying out the request of the owner of personal data before entering into that contract.
- (5) It is the performance of a contract between the company and another person for the benefit of the customer who owns the personal data.
- (6) To prevent or stop danger to the life, body, or health of the person to whom the owner of personal data is unable to give consent. Whatever the reason
- (7) It is necessary for the performance of duties in carrying out missions for the public benefit of the company. or performing duties in the exercise of state power granted to the company
14. Notification of personal data breach
- (1) In the case of a personal data breach, there is a risk that it will affect the rights and freedoms of individuals. The Company will report the incident of personal data violation to the Office of the Personal Data Protection Commission without delay within 72 hours from becoming aware of the incident, as far as possible.
- (2) n the case of a personal data breach, there is a high risk of affecting the rights and freedoms of individuals. The Company will notify the owner of the personal data of the violation along with remedies without delay within 72 hours from becoming aware of the incident, as far as possible
15. Recording important transactions
- (1) Personal information collected
- (2) The purpose of collecting each type of personal information.
- (3) nformation about the personal data controller
- (4) Personal information retention period
- (5) Rights and methods for accessing personal information Including conditions regarding persons who have rights to access personal information and conditions for accessing that personal information.
- (6) Collection, use, and/or disclosure of personal information that is exempt from the need for consent from the data owner.
- (7) Rejection of requests or objections
- (8) Details regarding security measures for personal information.