2. THE PURPOSE OF COLLECTION, USE OR DISCLOSURE OF YOUR PERSONAL DATA> We may collect, use, disclose and/or cross-border transfer your Personal Data and Sensitive Data for the following purposes.
2.1. Purpose for which consent is required We rely on your consent for the following purposes: Marketing and Communications: To provide marketing communications, sales, special offers, promotions, notices, news, events, and information about products and services from us, NCC Group, our affiliates, subsidiaries, third parties and/or business partners which we cannot rely on other legal bases; Analytic services: To conduct data analytic services on your personal data within NCC Group, our affiliates, subsidiaries, or to third parties; and/or Sensitive Data: We may use your sensitive data for the following purposes: Sensitive data as shown in the identification document (e.g., religion, racial or ethnic origin): for verification and authentication purpose; Religion: for preparation of religion activities; Biometric data (e.g. fingerprints, facial recognition, retinal scans) for accessing premises and security purpose; Health data: for preparation of food and beverage, and/or for coordinating with medical service providers. Criminal records: for security purpose. Where legal basis is consent, you have the right to withdraw your consent at any time. This can be done so, by contacting N.C.C. Management & Development Co., Ltd. The withdrawal of consent will not affect the lawfulness of the collection, use, and disclosure of your Personal Data and Sensitive Data based on your consent before it was withdrawn.
2.2. The purposes we may rely on and other legal grounds for processing your Personal Data We may also rely on (1) contractual basis, for our initiation or fulfilment of a contract with you; (2) legal obligation, for the fulfilment of our legal obligations; (3) legitimate interest, for the purpose of our legitimate interests and the legitimate interests of third parties; (4) vital interest, for preventing or suppressing a danger to a person’s life, body, or health; and/or (5) public interest, for the performance of a task carried out in the public interest or for the exercising of official authorities. We may collect, use, and/or disclose your Personal Data for the following purposes: To provide products and services to you: To enter into a contract and manage our contractual relationship with you; to carry out contract details, financial transaction and services related to the payments including transaction checks, verification, and cancellation; to process on receipt issuance, invoice issuance and proof of purchase; to invite you to participate in events and our services, to organize events, place and other services for you; and to keep evidence records; Marketing and Communications: To provide marketing, communications, special offers, privilege, promotions, notices, news, events, and information about products and services from us, NCC Group, our affiliates, subsidiaries and/or business partners in accordance with preferences you have expressed directly or indirectly; Prize drawing, competitions, and other offers/promotions: To allow you to participate to promotions, special offers, competitions, prize drawing, privilege on such using exclusive spaces, and other offers/promotions; Registration and Authentication: To register, verify, identify, and authenticate you or your identity; To communicate and manage our relationship with you: To communicate with you in relation to the products and services you obtain from us and receive information about the products and services from you; to process and update your information; to facilitate your use of the products and services; to handle customer service-related queries, request, feedback, complains, warranty claims, disputes or indemnity; to deal with technical issues and commercial terms; To process transactions and or payments: such as to process payments or transactions, billing, processing, clearing, refunding, or reconciliation activities. This includes all financial, transaction or payment related record keeping, issuance of bills, tax invoice, payment receipts and delivery of such; Profiling and data analytics: to undertake data analytics for products and services development, market research, surveys, assessments, and behaviour; to perform data analytic to improve our marketing performances and the offerings and sales of our products and services; to evaluate your interest on the solutions; to perform data analytic for system improvement (e.g. develop model classifying customer group for better service provision); to perform data analytic to increase business opportunity; to evaluate, develop, manage, improve, research and develop the services, products, system, and business operations for you and all of our customers; Carrying out business purposes: such as to update your customer data; to maintain data accuracy; to perform data analytic for risk prevention (e.g. develop a model to predict the possibility of non-performing loan, or predict the chances of accident); to perform customer risk assessments; [to perform institutional risk control, auditing and audit record keeping, analyzing credit risk]; to keep business records and otherwise to operate, manage, and maintain our business operations; to maintain our IT operations, management of communication system, operation of IT security and IT security audit; and to maintain internal business management for internal compliance requirements, policies, and procedures; to keep record of the frequency of visits; Compliance with regulatory and compliance obligations: To comply with legal obligations, legal proceedings, or government authorities' orders which can include orders from government authorities outside Thailand, and/or cooperate with court, regulators, government authorities, and law enforcement bodies when we reasonably believe we are legally required to do so, and when disclosing your Personal Data is strictly necessary to comply with the said legal obligations, proceedings, or government orders; to provide and handle tax declaration; to contact with tax authorities, financial service regulators, and other regulatory and governmental bodies, and investigating or preventing crime; Functioning of our sites and platform: such as to administer, operate, track, monitor, and manage our sites and platform to facilitate and ensure that they function properly, efficiently, and securely; to facilitate your experience on our sites and platform; improve the layout and content of our sites and platform; to allow you to access our available systems and provide technical assistance Protection of our interests: To protect the security and integrity of our business; to detect and prevent misconduct within our premises, for example, to detect, prevent, and respond to fraud claims, and to determine fraud risk and identify fraudulent transactions, intellectual property infringement claims, or violations of law; to manage and prevent loss of our assets and property; to perform sanction list checking, risk management, internal audits and records, asset management, system, and other business controls; to follow up on incidents; to prevent and report criminal offences and to protect the security and integrity of our business; for reference and evidence related to claims or litigation; Corporate transaction: in the event of sale, transfer, merger, reorganization, or similar event we may transfer your information to one or more third parties as part of that transaction; Life: To prevent or suppress a danger to a person’s life, body, or health. If you fail to provide your Personal Data when requested, we may not be able to provide our products and services to you.
3.2. Our service providers We may use other companies, agents or contractors to perform services on behalf or to assist with the provision of products and services to you. We may share your Personal Data to our service providers or third-party suppliers including, but not limited to (1) computer program developer, software developer, IT service providers and IT support company; (2) marketing, advertising media, designer, creative, and communications agencies; (3) campaign, event, and market organizers, and CRM agency; (4) data storage and cloud service providers; (5) property management service provider; (6) sale agencies; (7) logistic and courier service providers; (8) payment and payment system service providers; (9) research agencies; (10) analytics service providers; (11) survey agencies; (12) call center; (13) telecommunications and communication service providers; (14) outsourced administrative service providers; (15) printing service providers; (16) travel service provider. In the course of providing such services, the service providers may have access to your Personal Data. However, we will only provide our service providers with the information that is necessary for them to perform the services, and we ask them not to use your information for any other purposes. We will ensure that the service providers we work with will keep your Personal Data secure as required under the laws.
3.3. Our business partners We may disclose your personal data to companies that we have partnered with to offer or enhance products and services for our customers or prospective customers, for example, financial institution partner, access solution company, telecommunication company, sponsors, co-branded partners and other third parties that we conduct joint marketing and cross promotion with.
3.4. Third parties required by law In certain circumstances, we may be required to disclose or share your Personal Data in order to comply with a legal or regulatory obligations. This includes any law enforcement agency, court, regulator, government authority or other third party where we believe it is necessary to comply with a legal or regulatory obligation, or otherwise to protect our rights, the rights of any third party or individuals’ personal safety, or to detect, prevent, or otherwise address fraud, security, or safety issues.
4. CROSS-BORDER TRANSFERS OF YOUR PERSONAL DATA We may disclose or transfer your Personal Data to third parties or servers located overseas, which the destination countries may or may not have the same data protection standards. We take steps and measures to ensure that your Personal Data is securely transferred and that the receiving parties have in place suitable data protection standards or other derogations as allowed by laws. We will request your consent where consent to cross-border transfer is required by law.
5. HOW LONG DO WE KEEP YOUR PERSONAL DATA We keep your Personal Data only for so long as we need the Personal Data to fulfil the purposes we collected it for, and to satisfy our business and/or our legal and regulatory obligations. How long we keep your Personal Data depends on the nature of the data. Some information may be retained for longer, where we are required to do so by law.
6. YOUR RIGHTS AS A DATA SUBJECT Subject to applicable laws and exceptions thereof, you may have the following rights to: Access: You may have the right to access or request a copy of the Personal Data we are collecting, using and disclosing about you. For your own privacy and security, we may require you to prove your identity before providing the requested information to you.
Rectification: You may have the right to have incomplete, inaccurate, misleading, or or not up-to-date Personal Data that we collect, use and disclose about you rectified. Data Portability: You may have the right to obtain Personal Data we hold about you, in a structured, electronic format, and to send or transfer such data to another data controller, where this is (a) Personal Data which you have provided to us, and (b) if we are processing such data on the basis of your consent or to perform a contract with you. Objection: You may have the right to object to certain collection, use and disclosure of your Personal Data such as objecting to direct marketing.
Restriction: You may have the right to restrict the use of your Personal Data in certain circumstances. Withdraw Consent: For the purposes you have consented to our collecting, using and disclosing of your Personal Data, you have the right to withdraw your consent at any time. Deletion: You may have the right to request that we delete or de-identity Personal Data that we collect, use and disclose about you, except we are not obligated to do so if we need to retain such data in order to comply with a legal obligation or to establish, exercise, or defend legal claims. Lodge a complaint: You may have the right to lodge a complaint to the competent authority where you believe our collection, use and disclosure of your Personal Data is unlawful or noncompliant with applicable data protection law.