Pharmanueva Co., Ltd. (hereinafter referred to as the
“Company”) recognizes the importance of personal data and other information relating to the data subject (collectively referred to as
“Data”) and this Privacy Notice is developed to give the data subject confidence that the Company is transparently and responsibly collecting, using and/or disclosing Data in accordance with the Personal Data Protection Act B.E. 2562 (
“PDPA”) and other relevant laws. This Personal Data Protection Policy (
“Policy”) has been developed to describe the details of the collection, use or disclosure (collectively referred to as
“Processing”) of Personal Data by the Company, including its officers and related persons acting on behalf of or in the name of the Company, in accordance with the following terms and conditions:
1. Definitions
- Personal Data means information relating to persons which is able to identify that person either directly or indirectly, including any information which You provide. For example, personally identifiable information, information from identity documents issued by the government, contact information, employment information, educational background, health information, insurance information, financial information, information on specialties and professions, etc.
- Sensitive Personal Data means Personal Data as provided in Section 26 of the Personal Data Protection Act B.E. 2562 which includes the following: race, religion, political opinions, belief in cult, religion or philosophy, sexual behavior, criminal records, health information, disability, labour union information, genetic data, biometric information, or any other information which affects the data subject in a similar manner as specified by the Personal Data Protection Committee.
- Processing of Personal Data means any processing of Personal Data such as collecting, recording, copying, organizing, keeping, improving, changing, using, recovering, disclosing, forwarding, disseminating, transferring, merging, deleting, destroying, etc.
- Data Subject means a person who owns Personal Data that the Company collects, uses or discloses.
- Data Controller means a person or a legal entity who has the authority to make decisions on collection, use or disclosure of Personal Data.
- Data Processor means a person or a legal entity who collects, uses or discloses Personal Data according to the order or on behalf of the Data Controller. However, a person or a legal entity doing so is not the Data Controller.
- Data Protection Committee means a committee appointed under the PDPA having the authority and duty to supervise, issue rules, measures or other practices related to the protection of Personal Data in accordance with the PDPA.
- The Company's Personal Data Protection Committee means a committee appointed by the Company having the authority and duty to supervise, issue rules, measures or other practices related to personal data protection according to the PDPA.
- Individuals who have or may have a relationship with the Company means customers, job applicants, trainees, employees, directors, consultants, shareholders, persons who formerly had a relationship with the Company in such a manner that the Company must collect Personal Data, vendors/suppliers and service providers, attorneys, representatives and/or representatives of the aforementioned persons as well as other persons who are related to the Company in the same way, such as persons who use the Company's products or services and others from whom the Company collects Personal Data, such as job applicants, officers’ family, guarantors, beneficiaries of insurance policies, visitors, participants in activities organized by the Company, residents of the surrounding areas of the Company, hereinafter collectively referred to as “You”.
2. Scope of Application
This Policy applies to
the Personal Data of individuals who have or will have a relationship with the Company which is processed by the Company, its officers, contractors, business units or other entities operated by the Company including contractual parties or third parties who process Personal Data on behalf of or in the name of the Company (
“Data Processor”).
Your personal Data that the Company will keep as well as Personal Data that You have disclosed or provided to the Company whether in digital form or in the form of hard copy documents or other forms of products and services for example, websites, application systems, webinars or other channels supervised by the Company, such as participations in activities or seminars. The Company may collect or acquire your Personal Data from the following sources:
- Personal Data that the Company collects directly from You through various service channels for example, the process of registering, applying for jobs, signing contracts or documents, completing surveys or using products, services or other service channels supervised by the Company or when the data subject communicates with the Company at the office or through other communication channels supervised by the Company, etc.
- Personal Data that the Company collects from sources other than You, provided that such sources have the authority, legitimate grounds or your consent to disclose Data to the Company, for example through an employment service provider, employment-related activities, internships, including the necessity to provide contractual services where Personal Data may be exchanged with contractual parties.
- In addition, it includes cases where You provide Personal Data of third parties to the Company. Therefore, You are responsible for notifying details of this Policy or notices of products or services, as the case may be, to such parties, as well as seeking consent from such parties in case such consent is required to disclose the Data to the Company.
Providing your Personal Data to the Company or registering in any registration form provided by the Company constitutes Your consent that the Company is able to collect, use, disclose and/or manage your Personal Data. You may choose not to provide Personal Data to the Company. However, such selection may prevent the Company from providing You with some information or services.
3. Purposes of Collection and Use of Personal Data
The Company will collect and use your Personal Data for the purpose, within the scope and with lawful and fair methods to the extent necessary to operate and provide services for the Company's purposes only.
3.1 Collection of Personal Data
The Company will collect your Personal Data under the legal basis for collecting your Personal Data as appropriate and in the context of providing the services. The legal basis for collecting personal data that the Company uses consist of the following content:
Lawful basis for data collection
To enable the Company to exercise state powers and carry out tasks for the public interest according to the Company's mission which is stipulated by law.
To enable the Company to comply with laws that govern the Company, for example:
- Collection of computer traffic data under the Computer Crimes Act B.E. 2560
- Tax Law
- Labor Law
- Partnership and Companies Law
- Various Ministerial Regulations relating to the Company's business operations including the execution of Court orders, etc.
For the legitimate interests of the Company and others which are not less important than the fundamental rights of the Personal Data of the datasubject. For example, the security of the Company's premises or processing of Personal Data for the Company's internal affairs, etc.
Prevention or Limitation of Any Harm to Persons’ Lives, Bodies and Health
To prevent or limit danger to the lives, bodies or health of persons, including but not limited to collecting data to monitor epidemics in accordance with government policies.
To enable the Company to perform its duties in accordance with contracts or take any necessary action for entering into a contract to which You are a contractual party with the Company, including but not limited to contracts relating to employment, hire of work, service contracts, sale and purchase agreements, memorandum of understanding or other forms of contracts.
Preparation of Historical Documents, Research or Important Statistics
To enable the Company to prepare or support the preparation of historical documents, research, or statistics as the Company may be assigned or in relation to the Company's operations.
In case the Company requires your consent the Company will inform You of the purpose of collecting, using or disclosing Personal Data. For example, collecting sensitive personal data for a purpose which is not in accordance with the exceptions in Section 24 or 26 of the Personal Data Protection Act B.E. 2562, or promoting products and services of contractual parties or business partners to You, etc.
3.2 Purposes of Use of Personal Data
The Company will use Your Personal Data to provide goods and services for your benefit. The Company will use your Personal Data for the following purposes:
3.2.1 Customers, Product Users
- 3.2.1.1 To provide services to You or to a third party that You have requested service to be provided.
The Company may use your personal data to respond to your queries and to deliver goods and/or provide services to You. Services provided herein will be subject to applicable laws and related regulations.
- 3.2.1.2 To improve products and services including to protect the rights of consumers.
The Company may use your feedback regarding the impact that the Company's products and services have on You to develop and improve the Company's products and services, as well as to take relevant and necessary actions to address security concerns. The Company may ask for your cooperation in answering surveys relating to the Company's products or services. In addition, the Company may use the information You provide to follow-up and report to authorities as required by law, including using your Personal Data in relation to adverse events, complaints on products, patient safety, etc.
- 3.2.1.3 For the performance of the contract
The Company may use the information You, as a contractual party, have provided or use information for processing your request prior to entering into contracts between the Company and You, including entering into other agreements related to various operations under the contracts or performing the contract. In addition, the Company may use your Personal Data for the purpose of auditing counterparties, contract management, contract preparation and related documents, performance of contracts, communications for payments for goods and services, delivery of goods or provision of services under contract as well as inquiries regarding satisfaction with the company's products and services and notification of marketing and sales activities, inspection and evaluation of work according to the contract or other relevant documents, etc.
- 3.2.1.4 For compliance with the laws, for example tax laws, civil and commercial laws, criminal laws, privacy laws, announcements of the Ministry of Public Health, or any other laws related to the Company's operations or services.
- 3.2.1.5 For the legitimate interests of the Company, for example the Company's business management, product and service development, research, fraud detection and prevention or other crimes, safety of the Company's information technology system, access to the Company's personnel area and participation in various activities operated by the Company.
- 3.2.1.6 To prevent or limit dangers to your life, body or health such as the control and prevention of epidemics, resuscitation, first aid, contact those related with You in case of emergency.
- 3.2.1.7 To form the basis of legal claims.
- 3.2.1.8 To use and to manage your data for marketing activities in accordance with the terms and conditions of participation in each event.
- 3.2.1.9 To provide information, advice, public relations regarding products, services or marketing activities, including the presentation of the Company's products and services.
- 3.2.1.10 With your express consent where consent is required by law. For example for Clinical trials or notification on product information through various channels.
3.2.2 Vendor/Supplier and/or Service Provider and Attorney, Representatives and/or Representatives of the aforementioned persons.
- 3.2.2.1 For the performance of a contract to which You are a party or for processing of your request before entering into a contract between the Company and You. For example, sales and purchase agreements, employment or service contracts including other agreements relating to various operations under the contract as well as for the purpose of auditing counterparties, contract management, contract preparation and related documents, performance of the contract, communications for payment of goods and services, delivery of goods or provision of services under contracts, and the inspection and evaluation of the work according to the contract or other relevant documents, etc.
- 3.2.2.2 For compliance with laws, for example labour laws, tax laws civil and commercial laws, criminal laws, laws on work safety, privacy laws, announcements of the Ministry of Public Health or any other laws related to the Company's operations or services.
- 3.2.2.3 For the Company's legitimate interests for example, fraud detection and prevention or detection and prevention of other crimes, maintenance of information systems, safety of the Company's information technology systems, access to personnel areas of the Company, participation in various activities operated by the Company and notice of the Company's news related to You.
- 3.2.2.4 To prevent or limit danger to your life, body or health, for example to control and prevent epidemics, provide resuscitation, provide first aid or to contact those related to You in case of emergency.
- 3.2.2.5 To form the basis of legal claims.
3.2.3 Job applicants, Company employees, directors, consultants, shareholders, persons who have formerly had relationships with the Company in such a manner and from whom the Company must still collect their Personal Data.
- 3.2.3.1 For the performance of contracts between the Company and You
This includes but is not limited to the use of your Personal Data to achieve the performance of the terms contained in the contract including various actions in the process of preparing documents for entering into a contract and other related agreements, performance under
employment contracts, job assignments or duties, sending employees to work in other departments, management training or activities, performance evaluations, consideration of working position, employee transfers, compensation, various benefits, employee safety, including the implementation of rules and regulations of personnel management of the Company, etc.
- 3.2.3.2 For the legitimate interests of the Company or third parties
The Company may use your Personal Data for analysis and for database creation, recruitment management and selection processes, performance evaluations, news forwarding regarding job vacancies, human resources management, welfare arrangement, financial and budget management, arrangement of facilities and working environment, taking care of employees after retirement, communication with people inside and outside the organization including government agencies, security in various fields such as physical, information technology systems, internal checking, complaint management, whistleblowing, investigations of fraud or disputes, company management, video recording including meeting audio, attendance history, meeting minutes, security, event organizing, or any news or offers sent for the benefit of shareholders or directors. Your Personal Data will also be used for the Company's business administration, product and service development, research, detection and prevention of fraud or other crimes, maintenance of information systems for the safety of the Company's information technology systems, and for participation in various activities operated by the Company.
- 3.2.3.3 For legal proceedings
The Company must comply with applicable laws, rules, regulations or related orders such as laws, announcements, ordinances that are in force, litigation proceedings, arrangement of information according to subpoenas and lawful orders of authorized officials.
- 3.2.3.4 To prevent or limit dangers to life, body or health of persons, including epidemic surveillance.
- 3.2.3.5 To assess and manage risks, to prevent, detect, avoid and inspect fraud, security breaches, prohibited actions, or illegal activities that may cause damage to either You or the Company.
- 3.2.3.6 To contact and propose suitable job vacancies to You. In case Data is obtained from the recruitment and selection process, for example, information from taking a test, information from job interviews or any other information that You have provided to the Company or chose to share with the Company through various channels, if You are not selected as an employee, the Company will keep your personal data for further consideration on a reserved list for a reasonable period. After the expiration of such period, the Company will delete or destroy your Data in accordance with the Company's personal data security standards.
- 3.2.3.7 If an employee is an intern, Personal Data may include but not be limited to parents/guardians names and contacts, bank accounts for internship allowance payment, characteristics of interns, internship information and other related information.
3.2.4 Participants of corporate activities
- 3.2.4.1 For organizing activities, meetings or seminars
In case the Company organizes activities, meetings or seminars, or “activities” that You are interested in participating in, the Company will use your Personal Data to register You for participation in such activities and to carry out any related activities in order to facilitate Your participation in the activities organized by the Company.
The Company may use Data about participation in activities, for example the history of your participation in previous activities, records on attending training sessions, seminars or other activities, as well as photographs or videos regarding your participation for the benefit of managing data analytics operations in accordance with the terms and conditions of participation in each activity.
- 3.2.4.2 to meet the requirements of special projects that the Company organizes
In case of participating in projects, activities, clinical trials (“Special Program”), the Company will ask for your consent for the use of your Personal Data and Sensitive Personal Data before starting the Special Program. It may be necessary to disclose Data to third parties who participate in the Special Program with the Company, if so the Company will notify You and ask for your consent in accordance with the requirements of applicable law. Please review both the Special Program terms and any related third-party policies/requirements each time before joining the Special Program.
- 3.2.4.3 For the purposes of history, research studies and statistics
The Company may use your data for research or statistics purposes, provided that the Company will provide measures to manage and protect your rights and freedoms in accordance with relevant research standards.
In this regard, the Company will proceed with your acknowledgement and consent in accordance with the Company's methods. In case the Company collects your Sensitive Personal Data, the Company will request your explicit consent prior to doing so, unless the collection of Data and Sensitive Personal Data is subject to exemptions as specified in the PDPA.
4. Use of Cookies
The Company collects and uses cookies and other similar technologies on websites under the Company's supervision or on your device depending on the services You use in order to provide security for the Company's services and to provide, You, the user, a rewarding experience when using the Company's services. This Data will be used to improve the Company's website for a better experience.
You can learn more about the use of cookies in the
Company's Cookies Policy, and You can set and delete cookies preferences manually from the settings on Your web browser. However, when cookies settings are personalized this may compromise the functionality of the website and thus our services on the website.
5. Use of CCTV Cameras
The Company uses CCTV cameras for security surveillance within and around its corporate compound and buildings to protect the areas and Your assets. The Company will record and collect your Personal Data by CCTV cameras in areas where the Company deems appropriate.
The Company will place a sign to inform you that CCTV is being used at the entrances and exits including the area which the Company deems necessary and appropriate to be monitored. However, the Company will not install CCTV cameras in areas that may unduly violate your fundamental rights for example, changing rooms that require high privacy, bathrooms and shower rooms, etc. You can learn more about the privacy policy regarding the use of CCTV at
“Privacy Policy regarding Privacy in the Use of CCTV”. Your access to the areas is deemed your awareness of the terms of this Privacy Policy.
6. Disclosure of Personal Data
The Company will not disclose your Personal Data without your consent unless it is necessary for the benefit of operation and for providing services to You. The Company may disclose your Personal Data to the following persons:
6.1 Related companies
6.2 Government agencies or legal authorities, the Company must disclose your Personal Data for the purposes of legal proceedings or for the public interest or for other important purposes or by lawful order of government agencies or legal authorities, for example the Department of Provincial Administration, the Revenue Department, the Police Office, the Courts, the Public Prosecutor's Office, the Disease Control Department, the Ministry of Digital Economy and Society, the Office of the Permanent Secretary, the Office of the Prime Minister, the Department of Consular Affairs, the Student Loan Fund, etc.
6.3 Contractual parties that manage benefits for the Company's workers, for example, the Company procures agencies to administer benefits such as insurance companies, hospitals, banks, personnel management service providers, telephone service providers, etc.
6.4 Persons who work with the Company for the benefit of providing services to You, such as service providers that You contact through the Company's services, marketing service providers, advertising media, financial institutions, platform providers and telecom operators. This includes the case where the Company assigns a third party to be a service provider on its behalf or to support the Company's operations such as storage service providers (e.g. cloud, document warehouses), system developers, software, applications, websites, couriers, payment service providers, internet service providers, telephone operators, Digital ID service providers, social media service providers, risk management service providers, external consultants, transport service providers, etc.
7. Transfer of Personal Data
In the event that the Company may need to send or transfer your Personal Data to foreign countries for the purpose of providing services to You, the Company shall have the Personal Data transmitted or transferred with sufficient personal data protection measures according to international standards or take action according to the conditions in order to be able to legally transmit or transfer that such Data.
8. Period for collecting personal information
The Company will retain your Personal Data for as long as that Data is necessary for collection pursuant to the details specified in the policies, announcements or related laws. After expiration of the period and your Personal Data is no longer needed for the aforementioned purposes the Company will delete and destroy your Personal Data, or make your Personal Data not identifiable in accordance with standards for destruction of Personal Data that the Personal Data Protection Committee or the law specify or in accordance with international standards. In case there is a dispute, exercise of rights or litigation relating to your Personal Data,
the Company reserves the right to continue maintaining such Data until the dispute has been finalized by an order or judgment.
9. Security of Personal Data
The Company has measures to protect Personal Data by limiting the right of access to Personal Data so that it can only be accessed by specific officials or authorized or designated persons who are re quire the use of such Data for the purposes for which the Data Subject has been notified only. The aforementioned persons will strictly comply with the Company's Personal Data protection measures as well as have a duty to maintain the confidentiality of Personal Data that they become aware of from the performance of their duties. The Company has measures to secure both organizational or technical Data that meet international standards and pursuant to stipulations by the Personal Data Protection Committee.
In addition, when the Company sends, transfers or discloses Personal Data to third parties whether for the provision of services in accordance with obligations, contracts, or other forms of agreements, the Company will determine personal data security and confidentiality measures that are appropriate and in accordance with the law to confirm that Personal Data collected by the Company will always be secure. However, the Company does not make any warranty regarding the effectiveness of data protection measures against the possibility of data theft, data loss or of unauthorized use or access.
10. Rights of Data Subjects under the Personal Data Protection Act B.E. 2562
The Personal Data Protection Act B.E. 2562 provides for a number of rights of Data Subjects. These rights will be effective when the section of law on this right is enforced. The details of the rights are as follows:
10.1 Right to request access to Personal Data,
10.2 Right to request correction of Personal Data to be correct, complete and current, 10.3 Right to delete or destroy Personal Data,
10.4 the right to request the suspension of the use of Personal Data,
10.5 Right to object to the processing of Personal Data,
10.6 Right to withdraw consent,
unless there is a limitation of rights by law that the Company is obliged to keep the Data or there is still a contract between You and the Company that benefits You,
10.7 Right to receive, send or transfer Personal Data.
You can exercise such rights according to the law by using the request for exercise of rights as arranged by the Company and send it to
the “Company Contact” specified herein. You have the option to exercise your rights with the Personal Data Protection Committee or a supervisory authority appointed by the Personal Data Protection Committee by law. However, the Company would like You to contact the Personal Data Protection Committee of the Company
by means of “Company Contact” specified herein to let the Company know your concerns so that the Company is able to provide facts on the issues related to your Personal Data.
11. Personal Data of Minors
As for Personal Data of minors, the Company will respect and protect the rights of Data Subjects who are minors and will collect the minors' Personal Data with the consent of a person exercising parental powers to act on behalf of the minors in accordance with the provisions of the relevant law.
12. Company Contact
For any queries or suggestions regarding the collection, use and disclosure of Personal Data by the Company or this Policy, or if You wish to exercise your rights under the PDPA, You can contact the Personal Data Protection Committee of the Company through the following contacts.
Personal Data Protection Committee of the Company
Address: 171/1-2 Soi Chokchai Ruammit, Chomphon Subdistrict, Chatuchak District, Bangkok 10900
Telephone: 02 625 9999
Email:
DPO@siampharmaceutical.com
13. Updates to the Privacy Policy
The Company may consider improving, amending or changing this Policy at its discretion and will provide the amendment date of each version of the Policy. The Company recommends that You check the Policy regularly through the channels determined by the Company before You disclose Personal Data to the Company.
Access to the Company's products or services after the enactment of the updated Policy is deemed to be an acknowledgment of the revised terms and conditions. Please cease accessing if You do not agree with the details in the latest Policy announcement and please contact the Company
by means of “Company Contact” specified herein to let the Company know of your concerns so that the Company is able to contact You and to provide facts on the issues relating to your concerns.
14. Governing language
The English version of this Privacy Notice is a translation of the original Thai version and is for reference only. In case of any conflict between the Thai and English versions of this Privacy Notice the Thai version shall prevail.
Personal Data Protection Committee of the Company
Announced on 1st June 2022