Devasom Resorts, comprising Devasom Global Co., Ltd. as well as its affiliates, subsidiaries and related entities (“Devasom” or “we”) has established and disclose this Privacy approach to explain how we process personal data of our vendors, and other business partners including its corporate entity’s individuals such as its employees, contact persons, and directors (“You”), since the protection of your personal data is of great importance to us. We process your personal data in accordance with the applicable regulation relating to personal data protection, in particular the Personal Data Protection Act B.E. 2562 (“PDPA”).
- Personal Data
Regarding the PDPA, personal data means any information relating to an individual, which enables the identification of such individual, whether directly or indirectly, but not including the information of the deceased persons in particular.
We collect the following personal data for processing to achieve the purposes as herein with the legal basis provided for in the PDPA. In addition, we may process your personal data of a sensitive nature, including your religious beliefs, in accordance with special criteria provided for in the PDPA.
- Personal information: name, surname, signature, gender, date of birth, identity card information, passport information, etc.
- Contact information: address, telephone number, e-mail address
- Payment information: bank account information and other payment and billing information
- Other information: Videos and Images caught on CCTV cameras at our premises
- Information from Third Parties
Sometimes, we receive information about you from third parties. In particular, we may receive information about you from other sources, such as the company which you are a director, a representative, an assignee, an employee, and government organizations.
- Purposes of Personal Data Processing Activities
We collect, use, or disclose your Personal Data for various purposes depending on relationship between you and Devasom as follows:
- To consider entering into an agreement with you or your company or to take steps to enter into an agreement with you or your company
- To perform contractual obligations, to monitor your services in accordance with the agreement between you or your company and the Company, and to comply with our internal procedures, including issuing payment, issuing the purchase order, issuing tax form, and delivering the information or documents between you or your company and the Company.
- To verify your identity during performing services in accordance with the agreement between you or your company and the Company.
- To comply with relevant regulations such as tax laws, to report information to government authorities as required by laws or upon receiving an order or a writ of attachment from the authority for the purpose of investigation or examination under the laws, and to exercise the rights to legal claims or defend against the rights to legal claims.
- To record your information in Devasom’s database
- To control access to the buildings and premises, and to observe, prevent, deter, and (if necessary) investigate unauthorized access to buildings and premises for the purpose of monitoring security of the buildings and premises of Devasom.
- Retention Period
We will retain your personal data for as long as necessary to fulfill the aforementioned purposes for obtaining and processing your personal data. Specific criteria used to determine our retention periods are the duration we have an ongoing relationship with you, the compliance with applicable laws, the compliance with legal prescription to exercise the rights to legal claims or defend against the rights to legal claims and the necessity of retaining the personal data for other legal or business reasons.
Please kindly be ensured that the retention of personal data after the expiry date of retention period will only occur only in the necessary circumstance. When the retention period has ended or the retention of such data is no longer necessary (whichever is applicable), we will destroy or erase such data from our system.
- Legal basis
The legal basis for the processing of your personal data is as follows:
- When required by the law, a consent shall be obtained;
- When the processing activity is necessary for the performance of contractual obligations to perform contractual obligations between you and us;
- When the processing activity is required for the pursuit of legitimate interests of Devasom; or
- When the processing activity is required for the compliance with our legal obligations.
You have the right to withdraw your consent at any time by the method separately designated by us at the timing of obtaining your consent. However, your withdrawal of consent will not affect the legality of processing conducted based on your consent before its withdrawal.
We will notify you separately, if the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as the possible consequences of failure to provide such data.
- Disclosure of Personal Data
We may share your Personal Data with the following third parties for the purposes listed above:
- Devasom Resorts’ (including its subsidiaries and affiliated companies) employees: to comply with our internal procedures;
- Business partners and external service providers who provide us with payment related, data management, banks and credit card issuers, legal services, consultants, and etc.;
- Government authorities, or other authorities as stipulated by laws, including competent officials, e.g., courts, police officers, the Revenue Department
- International Transfers
- Security of Personal Data
Devasom Resorts have implemented the necessary technical and organizational measures, in compliance with legal requirements, with the aim of protecting the Personal Data, ensuring confidentiality in accordance with the principles laid in this policy.
In case where Devasom assigns any third party to process your personal information pursuant to the instructions given by or on behalf of Devasom, Devasom shall appropriately supervise such third party to ensure your personal information protection in accordance with the PDPA.
- Personal Data Rights
Under certain circumstances, you have rights under data protection laws in relation to your Personal Data. To exercise any of the following rights please submit a request to the address indicated below:
- Right of access: You have the right to obtain from us confirmation as to whether or not Personal Data concerning you is processed, and, to request access to the Personal Data. Please note that this is not an absolute right, and the interests of other individuals may restrict your right of access;
- Right to rectification: You have the right to obtain from us the rectification of inaccurate Personal Data about you and where applicable, you have the right to complete such information, including by means of providing a supplementary statement;
- Right to erasure (“right to be forgotten”): Under certain circumstances, you have the right to obtain from us the erasure of Personal Data concerning you, and we may be obligated to erase that Personal Data;
- Right to the restriction of processing: Under certain circumstances, you have the right to obtain from us restriction of processing your Personal Data. In that case, your data will be marked and may only be processed by us for certain limited purposes;
- Right to data portability: Under certain circumstances, you have the right to receive the Personal Data about you, which you have provided to us, in a structured, commonly used and machine-readable format, and you have the right to transmit that data to another entity without hindrance from us;
- Right to be subjected to automated decision-making: Under certain circumstances, you have the right not to be subject to solely data-based, automated decision-making (including profiling) that produces any legal or similar material effect on you;
- Right to object: Under certain circumstances, and at any time, you have the right to object, on grounds relating to your particular situation, to the processing of your Personal Data by us, and we can be required to no longer process your Personal Data; and
- Right to lodge complaints: Where permitted by applicable law, you also have the right to lodge a complaint with a competent data protection supervisory authority.
If you intend to exercise any of the aforementioned rights, please inquire using the contact details at the end of this policy. Such requests will be dealt with as quickly as possible. We will request a copy of a valid identification document to confirm your identity, before making any changes.
- Contact Us