1. Principles and objectives
2. Obtainment of Personal Information
Personal Information means information about an individual from which an individual can be identified either directly or indirectly. We collect personal information where necessary and use it only.
Types of Personal Data
|Details and Examples|
|Details and Examples||- Name, Surname
- Date of Birth
- ID Number
|Contact Information||- Mailing Address
- Phone Number (including home phone number or mobile number)
- Social media accounts such as LINE ID, Facebook account, Facebook ID, Google ID.
|Financial Information||- Credit/debit card details such as name-surname on the card, card number, card expiration date Name of the card provider bank
- Bank account
- Issuing tax invoices
|Technical Data||- IP Address
- MAC Address
- Recording of access data or tracking of website usage behavior from Session ID
- Type and version of the web browser
3. Source of personal information
We may collect your personal information through the following channels:
3.1 Collect personal information directly from you
- When you apply for membership by filling in various forms, whether in the form of documents, through the website, social media or via any channel
- When you order products and services
- When you fill out the information via the form
- When you fill out information through the forum thread
- When you communicate, ask for information, give comments or advice on our products and services
- When you choose to receive news or press releases from us
3.2 Collect personal information automatically
- Information obtained from the use of the service and information related to the use of the service, such as information about the devices accession the service (IP Address & MAC Address)
3.3 Collect your personal information from third parties which is lawfully collected from such sources or has already obtained the consent of the personal data subject to disclose information to us, for example by sending your personal information to us for the benefit of the presentation or provide services to you and related business operations.
4. Principles for collecting personal information
Legal Base to Collect Information
|For the performance of the contract||Performance of the contract of sale between the personal data controller ("us") and the personal data subject ("you") in the payment of goods. This includes collecting your shipping address to us in order to deliver the goods|
|Consent of personal data subject||For the collection, use or disclosure of personal information, we require your consent by informing the purpose of the collection, use or disclosure of personal information in advance or when requesting consent, for example collection of sensitive personal data, but does not qualify for legal exemptions, product and service promotion, service facilitation, and others|
5. Purpose of collecting information
|To facilitate the use of the website and the provision of services;||Ease of ordering Shipping Returns and Product Changes|
|To answer questions and provide assistance to customers;||Providing assistance to customers in connection with the provision of services updating customer information and submitting requests to exercise rights or complaints|
|To develop and improve quality and service;||Analysis and development of better products or services and suitable for the needs of customers|
|To provide information about products and services or marketing publicity;||Submission of information about goods and services to provide special privileges, promotions, discounts and special offers about the products and services of the store to customers via email, SMS and post (when we have your express consent).|
|For data analysis||Using customer data to analyze the market and market research to develop better products and services|
|To prevent, detect and detect criminals||Any audits and actions to prevent the commission of an offense under the relevant laws including security breaches that affect personal data subjects|
We may share your personally identifiable information with the public or our partners or for marketing purposes, Website Performance Analysis, and operation promotion or to show trends about the general use of our products and services.
6. Personal information disclosure to outsiders
We may disclose personal data as necessary to entities or third parties with the consent of the personal data subject, unless done within the framework of the law:
1. Transportation service provider
2. Payment service provider
3. Data analytics service providers doing research for marketing
4. Government officials, government agencies with statutory oversight or requesting to disclose personal information by virtue of law or related to legal process or permitted by applicable law
7. Retention period for personal data
We will retain your personal data only to the extent required by law or as necessary for the purposes for which it was collected. When the personal data that we collect is no longer required for the stated purpose, we will destroy or delete it permanently.
8. Security of personal information
We recognize the importance of maintaining the security of your personal information. We, therefore, take reasonable measures to prevent the unlawful loss access, destruction, use, alteration or disclosure of personal data. Electronic security certification based on SSL (Security Socket Layer) standards approved for websites by CA (Certificate Authority) is encrypted to protect information such as personal information, passwords, credit card numbers.
9. Rights of personal data subject
1. Right to withdraw consent
You have the right to withdraw your consent at any time where we relied on your consent to process your personal information.
2. Right of access to personal data
You have the right to request access to your personal data that is under our responsibility and ask us to make a copy of that information for you.
3. Right to rectification of personal data
You have the right to request personal data management to keep it updated and complete. If you are already a member, you can edit your personal information on the member details page.
4. Right to erasure personal data
You have the right to request deletion, destruction, or making your personal information non-personally identifiable, or when that information is no longer needed.
5. Right to restriction of processing
You have the right to temporarily suspend the personal data use when we are in the process of reviewing the request for the right to correct personal data, or the right to object to the collection, use, or disclosure of your personal information.
6. Right to data portability
You have the right to obtain your personal information, in the event that we make the data in a form readable or generally usable with a device or device that works automatically, including the right to request the transmission or transfer of such data to another data controller.
7. Right to object to the processing of personal data
You have the right to object to the collection, use or disclosure of your personal information. If you choose to object to the collection, to delete or destroy the rights previously given, it may affect the services that you will receive and we may not be able to provide some services to you.
You can use your rights as the above personal data subject, by contacting firstname.lastname@example.org and 0981388290, we will consider and notify the results within 30 days from the date we receive your request.
10. Connecting to external websites or services
Our website may contain links to external websites which may collect information about your use of the service and personal information. We are not responsible for your security or privacy collected by external websites. You must review the privacy policies of those external websites, and comply with the privacy policies displayed on the external websites instead.
11. If you object to consent or do not use personal information
We are legally obliged to collect personal information or for entering into a contract between you and us. If you object to consent to our personal data use, you can still use our service. This may make you less convenient when using our service since we do not have consent to use your personal information to the fullest purpose.
13. Contact Details
Email : email@example.com
Phone number : 0981388290
Contact via the form at www.buathongherbandspa.com/contactus
14. Delete a user account
In case the user wants to delete the user account, you can notify us to request deletion of your account at any time, by sending an email to firstname.lastname@example.org for account deletion. After deleting the user account, your personal data on our server will be wiped out and cannot be recovered.