Privacy Policy for Business Partner Rabbit Care
Rabbit Care (which refers to Rabbit Care Co., Ltd., Rabbit Care Broker Co., Ltd., and Ask Direct Group Co., Ltd.) (the “Company”, “we”, “us”, or “our”) recognizes the importance of the protection of personal data relating to our business partners. This privacy policy for business partner
“Business Partner”, according to this privacy policy, includes, without limitation, business partners, distributors, suppliers, vendors, service providers, construction contractors, investors, analysts, shops, billboard tenants, independent advisors, securities companies, insurance companies, insurance brokers, insurance agents, banks, joint venture partners, and third parties e.g., third parties requesting to enter the area, contractor’s sub-contractors, related persons according to the rules of the securities and exchange commission (e.g., spouse, children under the age of 20), and other business alliances.
The Company collects, uses and/or discloses your personal data because we currently have business relationship with you or may have business relationship with you in the future, or because you work for, represent, or proceed on behalf of our business partners, e.g., companies which supplies or provide services for the company, or which we have business communication with which may involve you.
1. What personal data we collect
“Personal data” means any directly or indirectly identified or identifiable information about you (excluding information concerning the deceased).
“Sensitive data” means personal data which is considered to be sensitive according to the law.
The specific types of personal data collected will depend on the relationship which you have with the company as follows:
- Personal details, such as name – surname, title, age, gender, photo, video, CCTV record, geographic location, date of birth, nationality, marital status, financial status, educational and professional information (e.g. position, division, division code, occupation, information contained in job application, company that you worked for or past employer, certification of employment, salary confirmation letter, professional license, work permit, visa, training information, income and salary, first date of work), identifiable information on
- Contact details, such as phone number, mobile phone number, facsimile number, address, place of business address, email address, postal code, social media account information (e.g., LINE ID, Facebook account and available time) and other similar information;
- Information relating to the interactions between the company and the business partner, such as information that you have given to the company (as appeared in agreement, form or survey), transactional information between you and the company (e.g., lease agreement or purchase and sale agreement, contractor agreement, consultancy agreement, tendering or bidding document), information relating to purchase and sale transaction with related person/third party, product type, budget type, disbursement budget, expense details, traveling expense, date of purchasing product/service, amount of products/services purchased, number of disbursement items, budget, headquarter number, document number, project name, registered company, creditors, branch, area and payment terms, computer data (e.g., IP address or cookies), vendor and service provider status inspection result, including information from the terms of reference or scope of tendering/bidding/procurement, report of interests, incident report, litigation information, details of quotation in procurement project, annual vendor/service provider evaluation report, CCTV record and construction details for each project;
- Information of your related person, such as identified information of your spouse or children, information about employee working for company relating to you;
- Sensitive data, such as health data, Sensitive data from national identification card (e.g., nationality and religion) or Sensitive data which can be used in litigation.
We will collect, use, disclose and/or transfer Sensitive data cross-border only on the basis of your explicit consent or where permitted by law.
2. How we collect your personal data
- Channels for personal data collection
The company may collect your personal data through multiple channels including:
- Directly from you (e.g., when you conduct business with the company or sign an agreement or fill out a form during interactions with the company , including interactions through our online platforms, website or mobile application, communication via email, phone, survey, name card, postal, during meeting and activity or meeting arrangement with you);
- From business partners or service providers that you work for, represent or act as agent;
- Companies under BTS Group;
- From database in the company’s system, central drive/central database or transportation software and/or electronic file;
- From public domain e.g., social media platforms and third-party websites or relevant government agencies; and/or
- From other third parties e.g., other business partners of the company, reference persons, complainants.
Personal data of third party
If you provide personal data of third party to the company e.g., spouse, children, parents, authorized persons or any other persons, please inform such third party of this Privacy Policy for their acknowledgement and request their consent to the company if necessary, unless there is other legal ground(s) permitted for disclosure of personal data of such third party.Personal data of incompetent person
The company only collects the personal data of children, quasi-incompetent person and/or incompetent person where their parent or guardian has given their consent. The company does not knowingly collect personal data from customers under the age of 20 without their parental consent when it is required, or from quasi-incompetent person and incompetent person without their legal guardian’s consent (as the case may be). In the event that the company learns that we have unintentionally collected personal data from anyone under the age of 20 without parental consent when it is required or from quasi-incompetent person and incompetent person without their legal guardians’ consent, the company will delete it immediately or collect, use and/or disclose if we can rely on other legal basis apart from consent or where permitted by law.
3. Why we collect, use and/or disclose personal data
The purposes of which we rely on consent
After having obtained your consent, the company may collect, use, disclose and/or transfer your sensitivedata cross-border, for the following purposes:
- Sensitive data as appeared in identification documents (e.g., religion and nationality): for the purposes of authentication and verification;
- Health data: for food preparation and facilitation.
Where we rely on consent for the collection, use and/or disclosure of personal data, you have the right to withdraw your consent at all time by contacting us (please see contact details in Item 8 of this privacy policy). The withdrawal of consent will not affect the collection, use and/or disclosure of personal data and sensitive data that was previously consented before the withdrawal. The company may request your consent directly from you or through the Companies under BTS Group, business partners and/or other legal entities.The purpose that we may rely on legal bases in processing your personal data
We will collect, use and/or disclose your personal data based on the context of your interactions with us by relying on legitimate interest, contractual basis, legal compliance, consent or other legal bases permitted under the applicable laws concerning personal data protection (as the case may be), for the following purposes:- For business purposes, such as to proceed business transactions with business partners and fulfil our duties and/or requests from business partners, to contact business partners regarding products, services and projects of the company or the business partners (e.g., to respond to questions or requests);
- For selection of business partners, such as to verify you and status of business partners, to check status of business or perform other background checks and screen you and business partners, to assess your and business partners’ suitability and qualifications, to assess your and business partners’ risks (including the verification of public information from law enforcement agencies and/or the company’s blacklist record), to prepare quotations or bidding offer, to enter into agreements, prepare purchase orders or purchase requests with you or business partners and to evaluate your and business partners’ management;
- For relationship management, such as to keep your personal data up-to-date, to maintain the accuracy of personal data, to keep agreements, relating documents, agreement’s reference documents and evidence of the work of business partners which may mention you, to plan, operate and manage (contractual) relationships and rights with business partners (e.g., to appoint, withdraw or authorize business partners to engage in transaction and order products or services, process payment, to conduct activities relating to accountancy, audit, invoice issuance, management of product and service delivery), to manage your requests or complaints, to improve, support, monitor, and record;
- For business communications, such as communication with business partners about products, services and projects of the company or business partners (e.g., communication via document, response to questions, requests or operational progress report);
- For marketing purposes, such as to inform you about news and public information which may be useful, including activities, new product and service offers, product and service price negotiation and survey, as well as for to evaluate and consider providing financial aid (e.g., financial loan) to you or business partners;
- For internal management and communication within the organization, such as to publish internal activities and to comply with business codes of conduct, including but not limited to, procurement, disbursement, internal management, training, inspection, report, document delivery and management, data processing, risk control or management, trend and statistical analysis and planning, and other similar or relating activities;
- For business analysis and improvement, such as to research, analyse data, estimate, survey and evaluate and report on our products and services and your or business partners’ performance, including to develop and improve our marketing strategy, and our products and services;
- For registration and authentication, such as for your registration, verification, identification and authentication;
- For IT systems and IT support systems, such as to support IT and IT support departments, to administrate system access in which the company has granted the right to access to you, to delete unused accounts, implement business control measures to continue business, and for the company to identify and solve problems in the IT systems, and to safeguard the security of the our systems, to develop, implement, operate and manage the IT systems;
- For business partner information management, such as to compile list of business partners, record data in the system and update the list and directory of business partners (which includes your personal data), as well as to store and manage agreements and relating documents which may contain your name;
- For system monitoring and security, such as to control access, monitor systems, equipment and internet, and safeguard IT security;
- For dispute management, such as to resolve dispute, enforce the company’s agreements, establish, exercise, or raising legal claims, including to grant authorization;
- For investigation, complaint and/or crime and fraud prevention;
- For compliance with internal policy and relating/applicable laws, rules, regulations, guidelines (such as to apply for business licenses as required by law) and to coordinate or communicate with government agencies, courts or relevant agencies (such as the Revenue Department, the Royal Thai Police Headquarter and the State Audit Office) including to investigate, complain and/or prevent crime and fraud;
- For danger prevention towards life, body or health of a person, such as to control contagious disease or epidemic;
- For organizing corporate social and environmental responsibility
- For business purposes, such as to proceed business transactions with business partners and fulfil our duties and/or requests from business partners, to contact business partners regarding products, services and projects of the company or the business partners (e.g., to respond to questions or requests);
Refusing to provide the company your personal data may affect you, for example, we may not be able to proceed your request, facilitate you, or fulfil our contractual obligations we have with you, and you may suffer damages or loss of opportunity. Apart from that, refusing to provide your personal data may affect our or your legal compliance which may impose penalty.
4. To whom we may disclose your personal data
The company may disclose or transfer your personal data to the following third parties. We will collect, use, and/or disclose personal data in accordance with the purposes under this privacy policy. These third parties may be located
in Thailand and outside Thailand. You can visit their privacy policy to learn more details on how they collect, use and/or disclose personal data since you could also be subject to their privacy policies.
- Companies under BTS Group
As the company is part of Companies under BTS Group which all collaborate and/or partially share customer services and systems, e.g., service systems andwebsite-related systems, the company may need to transfer your personal data to, or otherwise allow access to such personal data by the Companies under BTS Group for the purposes set out in this privacy policy. Companies under BTS Group may rely on the consent obtained by the company to use your personal data. Please see the list of the Companies under BTS Group - The company’s service providers
The company may use other companies, agents or contractors to perform services on our behalf or to assist us in our business with you. The company may share personal data to third parties, including but not limited to (1) infrastructure, software and website developers and IT service providers; (2) marketing, advertisement, design, creative advertising and communication service providers; (3) hospitals; (4) data storage and cloud service providers; (5) banks and financial institutions; (6) insurance companies,sub-insurance companies, insurance brokers, insurance agents, lost adjustors and risk surveyors; (7) logistics and transportation service providers; (8) payment and payment system service providers; (9) voting and vote counting service providers; (10) analysts; (11) travel service agencies; (12) garages and auto parts stores; (13) booking system service providers; (14) outsource internal operation service providers; (15) printing houses; and (16) surveying service providers.
In the course of providing such services, the service providers may have access to your personal data. However, the company will only provide the company’s service providers with the personal data that is necessary for them to perform the services, and we will ask them not to use your personal data for any other purposes. The company will ensure that all the service providers we work with will keep your personal data secure. - Our business partners
The company may transfer your personal data to the company’s business partners, such as business partners, project owners, contract parties, securities companies, stores, construction contractors, joint venture partners, companies that the company invests in,co-shared partners and third parties that the company share marketing or promotional campaigns for the business operation and service provision of the company , provided that the receiving business partner shall agree to treat personal data in a manner consistent with this privacy policy. - Third parties permitted by law
In certain circumstances, the company may be required to disclose or share your personal data in order to comply with a legal or regulatory obligation. This includes any government agency, court, government authority, embassy, consulate, or other third party where we believe this is necessary to comply with a legal or regulatory obligation, or otherwise to protect the rights of the company , third party or individuals’ personal safety; or to detect, prevent, or otherwise address fraud, security or safety issues. - Professional advisors
The company may disclose personal data to the company’s expert advisors including, but not limited to, (1) independent advisors; (2) legal advisors who assist the company in its business operations and provide litigation services such as defending or initiating legal actions; (3) external advisors; (4) project advisors; (5) financial advisors; and (6) auditors who provide accounting services or conduct financial audit for the company. - Assignees of rights and/or duties
We may disclose or transfer your personal data to our business partners, investors, significant shareholders, assignees or transferees in the event of any reorganization, restructuring, merger, acquisition, sale, purchase, joint venture, assignment, or any other similar events involving transfer or other disposition of all or any portion of our business, assets or stock. If any of above events occurs, the receiving party will comply with this privacy policy to respect your personal data.
5. Cross-border transfers of your personal data
The company may disclose or transfer personal data to third parties located overseas, which the destination countries may have the higher or lower data protection standards than Thailand’s, such as when the company stores your personal data on cloud platforms or servers located outside Thailand or when we engage IT support services
Where it is necessary to transfer your personal data to countries having lower data protection standards than Thailand’s, the company will take steps to ensure that personal data is securely transferred, the receiving parties has in place suitable data protection standard, or the transfer is permitted under the applicable data protection law. For instance, the company may have to obtain a guarantee from third parties who have the rights to access personal data that such personal data will be protected under the same data protection standards as Thailand’s.
If you require more information on how the company protects your personal data when being transferred
6. How long do we keep your personal data
The company will retain your personal data for as long as it is reasonably necessary to fulfil purposes for which the company obtained them and to comply with the company’s legal and regulatory obligations. However, the company may have to retain personal data for a longer duration, as required by applicable laws.
7. Rights as a data subject
Subject to applicable laws and exceptions thereof, a data subject may have the following rights to:
- access or request a copy of the personal data or request the company to disclose how we acquired the personal data without your consent;
- request for revision of your personal data to be accurate, updated, complete and not misleading;
- request for deletion, destruction or anonymization of your personal data;
- obtain personal data relating to you, in a structured, readable or usable electronic format, and to transmit or transfer such personal data to another data controller, where (a) this is personal data which you have provided to the company, and (b) the company is processing such data on the basis of your consent or to fulfill contractual obligation under the agreement we have with you;
- object our collection, use and/or disclosure of your personal data or restrain our further use of your personal data;
- withdraw consent to our collection, use and/or disclosure of your personal data which we have to rely on your consent to at any time.
If you wish to exercise any rights above, please contact us as per the details in “Our Contact Details” section.
There may be cases where the law limits the exercise of any rights above or where the company may appropriately or justifiably decline your request, for example, the company may decline your exercise of right in order to comply with the laws or court’s orders. If we decline your request due to such reason, the company will notify you of the reason.
If you believe that our collection, use and/or disclosure of your personal data by has does not comply with the applicable laws concerning personal data protection, you have the right to submit a complaint to the relevant agencies relating to personal data protection. However, if you have any complaints, please contact the company first before contacting the relevant agencies so that we have an opportunity to resolve your complaints accordingly.
8. Data security
As a way to protect personal privacy, the company maintains appropriate security measures, which includes administrative, technical and physical safeguards in relation to access control, to protect the confidentiality, integrity, and availability of personal data against any accidental or unlawful or unauthorized loss, alteration, correction, use, disclosure or access, in compliance with the applicable laws.
In particular, the company has implemented access control measures which are secured and suitable for the company ’s collection, use and/or disclosure of personal data. The company restricts access to personal data as well as storage and processing equipment by imposing access rights or permission, user, access management to limit access to personal data to only authorized persons, and implement user responsibilities to prevent unauthorized access, disclosure, perception, unlawful duplication of personal data or theft of device used to store and process personal data. This also includes methods enabling the
9. Amendment to this privacy policy
The company may amend this privacy policy from time to time if there is a change in the company’s practice in personal data protection due to reasons, such as changes in technology or the law. Such amendment shall be in effect when the company publishes the
10. Our contact details
If you wish to contact us to exercise the rights relating to your personal data or if there are any queries about your personal data under this Privacy Policy, please contact our Data Protection Officer (DPO) at:
Rabbit Care (which refers to Rabbit Care Co., Ltd., Rabbit Care Broker Co., Ltd., and Ask Direct Group Co., Ltd.)
1 Q. House Lumpini Building, 29th Floor, South Sathorn Road, Thungmahamek, Sathorn, Bangkok 10120
[email protected] or 084-021-9999