Privacy Notice for Activity Participants
Osotspa Public Company Limited and affiliates

Privacy Notice for Activity Participants
Osotspa Public Company Limited and affiliates

We, Osotspa Public Company Limited, and our affiliates (collectively the “Company”, “we”, “us” or “our”) understand the importance of the privacy and protection of the Personal Data of any participant participated in any of our activities (including CSR, community relations activities, community hearing) (“you” or “your”). Additionally, we also put our mind to the full compliance to the Personal Data Protection Act 2019 regarding the collection, use, and disclosure of your personal data to underline the lawful right of the data subject in accordance to the applicable personal data protection laws. The purpose of this Privacy Notice is to inform the details regarding the Processing of your Personal Data both online and in other channels to comply with the applicable personal data protection law. The Company may, from time to time, amend this Privacy Notice in whole or in part to comply with applicable laws, rules, or guidance for personal data protection.

Personal Data Processing

1. Personal Data that we may collect, use or disclose (the “Process”).

Your personal data, including the data of related persons of the juristic person, which is subject to the Process are:
         (i) Personal Information, e.g., name, address, mobile number, email, photo, copy of ID card, ID card number, copy of passport, passport number, age, career, Facebook account, Line account;
         (ii) Information related to participating with Company, e.g., hobbies, interested activities or information that you have participated in activities with the Company;
         (iii) Information related to your opinion, expectation and satisfaction for the participation in activities with the Company;
         (iv) Information necessary for your convenience, such as travel information, cloth size, food or beverage, etc;
         (v) Sensitive data e.g., race, religion, health information for entering office/operational areas (e.g. body temperature, symptoms for disease screening, including COVID-19) disability information which the Company has received your consent or it is necessary as permitted by law to proceed;
         (vi) Financial information, e.g., bank account number or other related financial information, taxpayer identification number;
         (vii) Technical information, e.g., Log file, IP address, geography information, real-time location data, browser, website history, website usage, log-in Log, transaction log, access time, search history, access history, social media usage, information received from Cookie or other relevance technologies.
         (viii) Record of image, photo, video, and audio recorded by CCTV or any other information that may identify the data subject.

Remark

In the event that we obtain Sensitive Personal Data such as race, religion, health information, disability information and such Sensitive Personal Data is not necessary for the operation of the Company, you may conceal such Sensitive Personal Data before submitting the information to the Company or we reserve our right to conceal such Sensitive Personal Data on the received documents. which will be deemed the Company has not collected such Sensitive Personal Data from you. Please be notified that the company has no policy to store your Sensitive Personal Data without your explicit consent or legal basis.

2. Personal Data Derivation.

We may collect your Personal Data from:
         (i) Any Operating System (OS), Information System, the Company’s website, email, telephone, fax, business card, letter, online, offline, electronics, or other channels which we directly received from you; and
         (ii) Public website, our partner, our contract party, or our affiliates.

Remark

In the event that you visit or access our websites, we may use Cookie to collect your Personal Data in accordance with our Cookie Policy.

3. Personal Data Processing Purpose.

We may Process your Personal Data for the following purposes;
         (i) process your request to participate in our activities; or when you contact us to take any action;
         (ii) take necessary actions in considering and selecting the applicants to participate in the Company's activities including the interview process, assessment process and the management process in relation to the consideration and selection of the participant in any activities of the Company;
         (iii) informing the details of contacting the Company for the participation of the activities, such as a list of participants, date, time, place of contact, etc;
         (iv) preparing of the Company's activities to be appropriate for and facilitating the participant such as analyzing activities, selecting activity’s locations, providing food and beverages, providing accommodation, preparing souvenirs including any facilities related to activities, etc;
         (v) assessing, analyzing and improving any activities of the Company, including applying for management system certification which may use photos of the atmosphere of the activities as evidence for questionnaire completion for the regulatory agency or applying for an award or contests;
         (vi) To handle of information technologies, related to the performance under the agreement or contract;
         (vii) To contact and coordinate both within and outside the organization as necessary for the operation of the Company;
         (viii) to deliver advertisements, publish the Company’s corporate social responsibility activities (CSR) both inside and outside the organization;
         (ix) Managing and administrating your complaint, comments, and suggestions to adjust and improve the quality of our services and products;
         (x) The necessity of establishing, complying, and exercising the legal claim or performing any necessary procedures to comply with the applicable laws;
         (xi) Internal audit and compliance, investigating the complaints or claims to detect and prevent corruption, fraud, and other inappropriate behavior, including wrongful or illegal acts;
         (xii) Security protocols within our buildings, factory, or any places owned by the Company, including video, photo, or audio records from CCTV; and
         (xiii) The necessity to protect your vital interests in case you are not able to give the consent or whatsoever including the necessity to perform a task carried out in the public interest, exercise of official authority vested in us, or comply with a legal obligation.

4. Legal Basis for collecting, using, and disclosing Personal Data.

We may Process your Personal Data under the following legal basis;
         (i) Contractual Necessity, or to conduct any process or activity in response to your pre-contractual request;
         (ii) Legitimate Interest pursued by us or by a third party, and such interest shall not exceed your fundamental rights in your Personal Data;
         (iii) Legal Obligation in any applicable laws which the Company has to comply with;
         (iv) Consent which the Company received from you for collection, use, and disclosure of your Personal Data; and
         (v) Any other basis which the Company has under any applicable laws.
In case we collect, use, or disclose any of your Sensitive Personal Data under the following legal basis. We shall ensure that;
         (i) We have received your explicit consent in writing from you to collect, use or disclose such Sensitive Personal Data;
         (ii) It is necessary to prevent or protect your vital interests;
         (iii) It is necessary to establish, comply, or exercise our right or legal claim or to perform any necessary procedures to comply with the applicable laws; and
         (iv) It is necessary to comply with the applicable laws, including Personal Data Protection Act.

5. Personal Data Disclosure.

The disclosure within the Company and the affiliates.

We may share or disclose your Personal Data to pursue our Propose of Processing your Personal Data under the relevant legal basis. Therefore, we may share or disclose your Personal Data within our Company or our affiliates either inside or outside of the territory, which may have different personal data protection measures from Thailand. The Company shall ensure that the disclosure of your Personal Data shall comply with Thailand Personal Data Protection Act.

The disclosure to the third party.

Upon receiving your consent, the contractual necessity, the legal obligation, or the legitimate interest, the Company may deliver, transfer, or disclose your Personal Data to the third party either inside or outside of the territory. We ensure to comply with the applicable laws and provide the necessary Personal Data protection measures to the following:
         a) Person or juristic person which the Company obliged or ordered by the jurisdiction court, state agency, tax authority, regulator, or the law enforcer to disclose such Personal Data; b) Consultant, company’s professional advisor including lawyer, banker, auditor, accountant, insurer, a professional service provider on legal, banking, compliance, accounting, or insurance; c) Financial institution or financial service provider, e.g., a company that provides you an electronic payment service on each transaction; d) External service provider, business partner, social media e.g., IT service provider, marketing company, researching service provider, cloud storage service provider, Facebook or Line etc; and e) External auditor, shall independently perform any assessments and review your data as a part of the Company’s compliance standard.
We may disclose your Personal Data to an external person or juristic person which we may sell or transfer, in whole or in part, our business or asset or Vice Versa, we may acquire or merge other business. Nevertheless, in the circumstance of the Company’s alteration whether about selling, acquiring, or merging (whatsoever) such alteration may require the use or disclosure of your Personal Data similarly to which stated in this privacy notice.

6. Personal Data Security Measures.

The security of your Personal Data privacy is the first priority for the Company. We assure you that we implement and use the appropriate security measures on both technical and administration standards to protect your Personal Data and to prevent any possible damages to your Personal Data (e.g., loss, unpermitted access, disclosure, abuse, misuse, modifying, or destruction.) by using an appropriate technology and security measures. We shall ensure that only the permitted person shall have the right to access your Personal Data and that such person has enough knowledge and experience in the Personal Data protection protocol. Such security measures, from time to time, shall be reconsidered, if it deems necessary or the technology transformation occurs, to ensure that decent and appropriate security measures are applied.

7. Retention Period

We will retain your Personal Data for a necessary period for the purpose we informed you or as described in this privacy notice. In the event that (i) you desire to end your legal relationship or contract with us, (ii) you have no services or transactions with us, or (iii) your Personal Data is no longer necessary for the purpose of Data Processing. Your Personal Data will be retained for the period allowed by the applicable law, prescription, and legal claims. After the retention period ends, we will delete, destroy, or unidentified your Personal Data.

8. Your Rights as a Data Subject

Under the Personal Data Protection Act, your rights as a data subject are the followings:
         (i) Right to withdraw your consent given to us, unless such withdrawal is limited by the applicable law or the contract;
         (ii) Right to access and obtain a copy of your Personal Data under the responsibility of the Company including the right to request the disclosure of the Personal Data acquisition;
         (iii) Right to send or transfer your Personal Data to other Data Controllers;
         (iv) Right to object to the collection, use, or disclosure of your Personal Data;
         (v) Right to delete, destroy, or unidentified your Personal Data;
         (vi) Right to request to restrict the use of your Personal Data;
         (vii) Right to request to edit or modify your Personal Data to be accurate, up-to-date, complete, and not misleading, in the event that your Personal Data retained by us or your Personal Data has been changed; and
         (viii) Right to report or appeal to the authorities if the Company violates or breaches the Personal Data Protection Act.

9. Contact us

For your further questions, queries, or requests, please contact our Data Protection Officer below;

Data Protection Officer

Osotspa Public Company Limited.
348 Ramkhamhaeng Rd., Huamak, Bangkapi, Bangkok 10240 Thailand.
Email: [email protected]