Privacy Policy
Thailand E-Commerce Website
Compliant with Personal Data Protection Act B.E. 2562 (PDPA) and Thai E-Commerce Legislation
|
公司 |
生效日期 |
|
CREATE DEVELOPMENT (THAILAND) CO., LTD. |
2026-05-26 |
PART A : PRIVACY POLICY
本隐私政策依据泰国《个人数据保护法》佛历 2562 年(PDPA)及相关法律制定,适用于网站所有用户的个人数据处理行为。
1. Definitions
在本政策中,下列术语含义如下:
• Personal Data: any information that directly or indirectly identifies a natural person.
• Sensitive Personal Data: data pursuant to the PDPA, including health data, race/ethnicity, religious beliefs, and criminal records.
• Data Controller: the Company, which determines the purposes and means of processing Personal Data.
• Data Processor: a person or entity that processes Personal Data on behalf of and under the instructions of the Data Controller.
• Data Subject: the natural person to whom the Personal Data relates.
2. 我们收集的个人数据
2.1 您直接提供的数据
|
Data Type |
|
Examples |
Primary Purpose |
|
Identity Data |
|
Full name, Email, phone |
Account registration |
|
Contact Data |
|
Email, phone, address |
Communication |
|
Payment Data |
|
Account no., card details |
Payment processing |
|
Transaction Data |
|
Order history, items, values |
Contract fulfilment |
|
Account Data |
|
Username, password (hashed), preferences |
Account management |
2.2
Automatically Collected Data
•
Website usage data (Log Data) e.g. IP address, browser type, pages visited, date and time.
•
Cookie and similar tracking technology data, as per the Company's Cookie Policy.
3.
Legal Basis for Processing
|
法律依据 |
对应处理行为 |
|
同意 |
营销邮件、非必要 Cookie |
|
履行合同 |
订单处理、配送、支付 |
|
法定义务 |
会计、税务、监管报送 |
|
合法利益 |
反欺诈、网络安全、数据分析 |
|
重大利益保护 |
紧急情况 |
4.
Purposes of Use
The Company uses your Personal Data for the following purposes:
•
Processing orders, payment, and delivery of goods/services.
•
Creating and managing user accounts.
•
Providing customer service and responding to enquiries or complaints.
•
Sending transactional communications such as order confirmations, receipts, and shipping notifications.
•
Sending marketing content and promotions (only with consent).
•
Improving products, services, and website user experience.
•
Preventing fraud, maintaining security, and monitoring regulatory compliance.
•
Fulfilling legal and regulatory obligations.
5.
Disclosure to Third Parties
The Company may disclose your Personal Data to:
•
Third-party service providers (Data Processors) such as payment processors, logistics providers, cloud providers, who have executed data processing agreements compliant with PDPA).
•
Government authorities and law enforcement agencies when required by law or court order.
•
Group companies and affiliates for internal business purposes.
•
Successors or assigns in the event of a merger, acquisition, or corporate restructuring.
The Company will NOT sell or rent your Personal Data to third parties for marketing purposes without your explicit consent.
6.
International Data Transfers
Where the Company transfers your Personal Data to a foreign country, it shall do so as follows:
• Transfer to countries recognized by the Personal Data Protection Committee as having adequate data protection standards.
•
Implement appropriate safeguards such as Standard Contractual Clauses.
•
Obtain explicit consent from the Data Subject where no other safeguard is available.
7.
Data Retention
|
Data Type |
Retention Period |
|
交易与账户数据 |
5 years after account closure |
|
税务与会计记录 |
5 years |
|
Consent Records |
10-year prescription |
|
Complaint Records |
2 years after resolution |
|
System Log Data |
90 days |
8. 数据主体权利
|
Right |
Description |
|
Right to be Informed |
Informed of collection and use of data |
|
Right of Access |
Access and receive copies of own data |
|
Right to Rectification |
Correct inaccurate or incomplete data |
|
Right to Erasure |
Request deletion or anonymisation |
|
Right to Restriction |
Suspend processing temporarily |
|
Right to Portability |
Receive data in machine-readable format |
|
Right to Object |
Object to processing based on legitimate interests |
|
Right to Withdraw Consent |
Withdraw consent at any time |
You may exercise these rights by contacting the Company's Data Protection Officer (DPO). The Company will respond to requests within 30 days of receipt.
9.
Data Security
The Company implements appropriate technical and organizational security measures including:
•
Encryption using SSL/TLS for data in transit and AES-256 for data at rest.
•
Access control based on the need-to-know principle and Role-Based Access Control (RBAC).
•
Periodic security audits and risk assessments.
•
A personal data breach response and notification plan within 72 hours.
10.
Data Protection Officer (DPO)
|
Contact Info |
Details |
|
Name: Warawut Natpradith |
邮箱: cs@wecre8te.com |
|
Telephone: +66 942916551 |
地址: 曼谷沙吞区亚纳瓦县南沙吞路帝国大厦 3 栋 35 楼 3506 室 |
11.
Right to Lodge a Complaint
If you believe your rights under the PDPA have been violated, you have the right to lodge a complaint with the Office of the Personal Data Protection Committee (PDPC).
Office of the Personal Data Protection Committee (PDPC), Ministry of Digital Economy and Society, Thailand) Website: www.pdpc.or.th
12.
Changes to This Policy
To install this Web App in your iPhone/iPad press
and then Add to Home Screen.