Data Privacy Policy
1. Definitions
“Personal Data” means
name, surname, age, gender, ID card, telephone number, email, LINE ID or any
other data which may specify a person’s identity (whether by the data itself or
by composition with other data).
“Sensitive Data” means
Personal Data containing sensitivity that may affect its data owner, i.e.,
race, ethnicity, religion, faith, sexual orientation, criminal record, health
record, disability, biological data, as ascribed in the Personal Data Protection
Act.
“Personal Data Owner”
means individual person whose Personal Data is to be processed by the Company.
“The Company” means Central
Garden Company Limited
“Personal Data Processing”
means any action to Personal Data and/or Sensitive Data, e.g., collecting,
recording, copying, categorizing, storing, revising, amending, using,
redeeming, disclosing, forwarding, divulging, transferring, combining,
deleting, destroying, etc.
2. Processing of Personal
Data
2.1 You have acknowledged
that, under objectives of service provision, communication, contact, activity
participation, transaction and/or any contracts between you and the Company
(“Activities”), the Company can process your Personal Data.
The Company
needs to obtain your Personal Data accurately, completely and adequately so
that it can procure the Activities, comply with service conditions, rules or
regulations of the Company and/or observe relevant legal requirements. The Company’s inaccurate, incomplete or
inadequate receipt of your Personal Data may result in any Activities between
the Company and you being delay or inconvenient. In the event the Company must needs to
observe certain contractual or legal obligations it may decline to follow any
of our duties towards you, however, the Company does respect all
private rights and shall process your Personal Data only to the necessary
extent and under legitimate objectives.
2.2 Personal Data of a Minor,
an Incompetent Person or and Quasi-Incompetent Person
“Personal Data
Owner who is a Minor” means a person under full 20 years of age and has not
reached its legal age, any consent by whom is subject to consent from its legal
guardian having authority to bind the minor.
“Personal Data
Owner who is an Incompetent Person” means a person decreed by a court order to
be incompetent due to physical or mental disability, or its improvident
roguish behavior, or addiction, or
the likes, to the extent that s/he may not self-manage his/her own affairs or
manage in an adverse manner against one’s or family’s properties. Any consent by the person is
subject to consent from its legal custodian having authority to bind the
person.
“Personal Data
Owner who is a Quasi-Incompetent Person” means a person decreed by a court
order to be quasi-incompetent, any consent by whom is subject to consent from
its legal curator having authority to bind the person.
If the
processing of Personal Data is based on consent and service’s term &
condition, the Company shall collect and process Personal Data of a minor
through consent of legal guardian having authority to bind the minor in all
cases. But if the Company is of no
knowledge that the person is a Minor, an Incompetent Person or a
Quasi-Incompetent Person, and later finds that it has collected Personal Data
without fulfilling such legal condition for consent, the Company shall without
delay delete such Personal Data unless the Company has legitimate ground (other
than consent) to collect, use or disclose the Personal Data.
2.3 Activities the Company
shall proceed, whether by itself or through third-party service provider, and
bases on which your Personal Data is processed, are as follow:
(1) Registration for access to
indoor playgrounds.
(2) Servicing obligation by
the Company in indoor playgrounds.
(3) Procuring paperwork or
utensils for service provision.
(4) Inquiry on indoor
playground services.
(5) Statistics, research or
data analytics regarding indoor playground services.
(6) Making of nametags for
participants in service-related activities.
(7) Collection and record of
Personal Data using service provider of Clouds.
(8) Visual and/or audio record
of Personal Data Owner during services, with consent base.
(9) Reporting to premises
lessor of the indoor playground site.
(10) Informing Personal Data or
Sensitive Data (if any) to hospitals, physicians, or any personnel related to
medical care to Personal Data Owner, in case of incident or accident
threatening harms to Personal Data Owner’s life or body.
(11) Commercials and
advertisement, campaign or marketing activities, with consent base.
(12) Internal and external
audits, including logging expense ledger.
(13) Compliance or observation
of orders of officers, polices, state prosecutors, competent courts or other
authorities.
2.4 The Company affords a security measure to protect your
data with proper and consistent level to keep confidentiality of your Personal
Data, to prevent loss, access, destruction, use, transform, change or
disclosure Personal Data or Sensitive Data without permission
or legal grounds. The measure shall
conform with those details in policy and guideline for data security
protection, and subject to the Company’s periodic suitability reviews.
2.5 If there is any later change or addition to the
objectives of processing Personal Data, the Company shall communicate to you
the new objectives with change/addition through the Company’s website whereby
the Company may seek your consent before proceeding any activities under the
new objectives (if it is legally required).
3. Sources from which the Company
Collects Personal Data
The Company collects or acquires Personal Data of each
type from the following sources:
1) The
Personal Data the Company collects from Personal Data Owner directly via each
service channels, e.g., service application, request, registration, marketing
campaign participation, survey filling, use of products, services or service
channels controlled by the Company; or when the Personal Data Owner contacts
the Company at sites or via other contact channels controlled by the Company,
e.g., online media, LINE, Facebook.
2) The
Personal Data the Company collects from Personal Data Owner’s attendance to
website, product or other service, e.g., tracking user’s trace on the Company’s
website, product or service by Cookies or other software on Personal Data
Owner’s devices.
3) The
Personal Data the Company collects from public sources or sources other than
Personal Data Owner, which has a legitimate ground or Personal Data Owner’s
consent to disclose to the Company, e.g., affiliate companies, peer group
companies, business alliances, schools, customer groups. Necessity to provide service may also
lead to data exchange with relevant individual or corporations.
Also,
in case that you provide us with third party’s Personal Data, you bear a duty
to inform details per this Policy for such person’s acknowledgement, and to
seek his/her consent if your such disclosure to the Company needs the consent.
In
case Personal Data Owner refuses to provide data necessary for the Company’s
service provision or contractual performance or legal compliance, it might
result in the Company being unable to provide service to such Personal Data
Owner in whole or in part.
4. Overseas Transfer of Personal Data
The Company shall not transfer Personal Data
to overseas servicers or any personal outside Thailand.
Nonetheless, at the time of this Policy the
Personal Data Protection Committee has yet to announce a list of destination
with adequate Personal Data protection measures. In case a necessity arises to send or
transfer your Personal Data to any destination, the Company shall procure an
adequate protection measure pursuant to international standard over the Personal
Data to be send or transferred or shall fulfill all conditions required under
the laws to send or transfer such Data.
5. Personal Data Owner as
a Stakeholder
You may inspect an existence, nature,
objectives of use of your Personal Data and/or Sensitive Data, and may:
(1) request for copy or certified copy of your own Personal
Data
(2) request to revise or amend your own Personal Data
(3) dispute or request to suspend any use or disclosure of
your own Personal Data
(4) request to delete or destroy your own Personal Data
(5) request the Company to reveal about an acquisition of
your own Personal Data, regarding data for which you did not consent collection
or storage.
(6) request cancellation of any consent.
(7) request data transfer to other Personal Data controllers.
(8) contact the Company or other relevant institutes in case
of necessity.
(9) file a complaint against the Company, Personal Data
processor, employee or outsourced servicer of the Company or Personal Data
processor, for non-compliance with the Personal Data Protection laws.
In case the Company has any ground to decline your
request, it shall record as evidence the declination of your request/dispute as
well as your reasonings thereof.
6. Duration of Personal Data
Processing
The Company may process your Personal Data, including to
disclose to data processors, outsourced servicers, and relevant authorities
under laws, as the case may be, for a duration of 10 years from the date you
last use the Company’s service or for a duration necessary for the processing.
7. Uses of Cookies
Cookies means microdata sent by a website for storage at
Personal Data Owner visiting the website, to help memorize data of visits by
the Personal Data Owner, e.g., default language, system user, or other
settings; so upon the Personal Data Owner’s revisits,
the website recognizes as a former visitor and procure the settings as the
Personal Data Owner had specified until the Personal Data Owner deletes Cookies
or not allow Cookies’ further usage.
Personal Data Owner may choose to or not to accept Cookies. The non-acceptance or deletion of
Cookies may cause the website to service or effect
results improperly.
8. Communications
The Company:
Central Garden Company Limited
Address: 4199 Yothinpattana 11-5 Praditmanuthum
Klongchan Bangkapi
Bangkok 10240 Thailand
Telephone: 02
966 1533
E-mail:
info@playmondo.com
LINE:
@playmondo