Privacy Policy

STT GDC (Thailand) Co., Ltd. (the “Company,” “we,” “us,” or “our”) commits to safeguard your Personal Data (as defined below). We know you care how information about you is collected, used, disclosed, and/or transferred outside of Thailand. The information you share with us allows us to provide the products and services you need and want appropriately tailored for you, not only from us, but also those within STT GDC (Thailand) Co., Ltd. We appreciate your trust that we will carefully and sensibly handle your Personal Data while giving you the personalized experience and customer services from us. 

 

This Privacy Notice (“Notice”) explains the collection, use, disclosure and transfer of Personal Data 
(as defined below) and the data protection rights of individuals outside our organization with whom we interact and whose Personal Data (as defined below) we handle in the course of our businesses or in connection with the products and services we provide, including: (i) individual customers; (ii) contact persons, employees, personnel, authorized persons, representatives, agents, directors, shareholders or any persons, who have the power to establish business relationship or engage in a transaction on behalf of our) corporate customers and their affiliates; (iii) users and visitors of our websites; (iv) other recipients of our products and services; and (v) any other individuals about whom we obtain Personal Data (as defined below) (together, “you” or “your”). This Privacy Policy also applies to our websites, mobile applications, social networking sites, online communication channels, events and activities, and other locations where we collect your Personal Data. However, please read this Privacy Policy in conjunction with the terms and conditions of particular service that you use, which may set out separately regarding the personal information we collect about you.

 

We may review and amend this Privacy Policy from time to time to reflect changes in applicable laws and the way we handle Personal Data. You are encouraged to revisit our Privacy Policy from time to time to keep yourself updated on these changes. Any changes to this Privacy Policy will become effective when we post the revised Privacy Policy on our website, application or other communication channels. We will provide additional notice of significant updates.

 

1. What Personal Data we collect

 

"Personal Data" means any identified or identifiable information about you as listed below. In order to offer you with our products and services, we may collect Personal Data directly (e.g. through our representatives, officers, relationship manager, salesperson, staff, call center, application) or indirectly from you or other sources (e.g. social media, third party’s online platforms, and other publicly available sources) or through our parent company, affiliates, subsidiaries, business partners, official authorities, or third parties. The specific type of data collected will depend on the context of your interactions with us, and the services or products you need or want from us and within STT GDC (Thailand) Co., Ltd. 


"Sensitive Data" means Personal Data classified by law as sensitive data. We will only collect, use, disclose and/or cross-border transfer Sensitive Data if we have received your explicit consent or as permitted by law.


The following Personal Data is categorized under the nature of businesses of STT GDC (Thailand) 
Co., Ltd., data centre business:

 

1)    Personal details, such as title, full name, job title, position, workplace, information on government-issued cards (e.g., national identification number), photograph; 
2)    Contact details, such as postal address, telephone number, email address;
3)    Financial details, such as salary, bank account details; 
4)    Sensitive data, such as sensitive data as shown in the identification document (e.g., religion, racial or ethnic origin), biometric data (e.g. fingerprints, facial recognition, retinal scans), criminal records and health data where applicable, we may also collect other information, such as cookies, and internet browsing behaviour, login data, search history browsing type, browsing language, IP address, information about how you use and interact with our online services or advertising (including web page viewed, content viewed, links clicked and features used), when and how often you use our online services, the webpage from which you clicked a link to come to our online services (e.g., the referrer URL), and crash reports. If it is possible to combine any information with your personal information, or if other information is used to build a profile of an individual, we will treat such other information and combined information as personal data. Nevertheless, you can reject or delete cookies at any time in your web browser’s privacy setting. You can choose to reject cookies either in whole or in part. By using the website without deleting or rejecting, you agree to our use of cookies and store on your device.

 

If you provide Personal Data of any third party to us, e.g., their name, family name, address details, and telephone number for emergency contact, family member income; please provide this Privacy Policy for their acknowledgement and/or obtaining consents where applicable.  

 

We will only collect, use, or disclose sensitive data on the basis of your explicit consent or where permitted by law.

 

We only collect the information of children, quasi-incompetent persons, and incompetent persons where their parent or guardian has given their consent. We do not knowingly collect information from customers under the age of 20 without their parental consent when it is required, or from quasi-incompetent persons and incompetent persons without their legal guardian's consent. In the event we learn that we have unintentionally collected personal information from anyone under the age of 20 without parental consent when it is required, or from quasi-incompetent persons and incompetent persons without their legal guardians, we will delete it immediately or process only if we can rely on other legal bases apart from consent.  

 

2. The Purpose of collection, use or disclosure of your Personal Data 

 

We may collect, use, disclose and/or cross-border transfer your Personal Data and Sensitive Data for 
the following purposes.

 

2.1. Purpose for which consent is required

 

We require your consent in order to use your Sensitive Data. We may use your sensitive data for 
the following purposes:

 

•    Sensitive data as shown in the identification document (e.g., religion, racial or ethnic origin): for verification and authentication purpose;
•    Biometric data (e.g. fingerprints, facial recognition, retinal scans) for accessing premises and security purpose; 
•    Criminal records: for security purpose. 

 

Where legal basis is consent, you have the right to withdraw your consent at any time. This can be done so, by contacting pdpacenter@sttelemediagdc.co.th.

 

The withdrawal of consent will not affect the lawfulness of the collection, use, and disclosure of your Personal Data and Sensitive Data based on your consent before it was withdrawn.

 

2.2. The purposes we may rely on and other legal grounds for processing your Personal Data

 

We may also rely on (1) contractual basis, for our initiation or fulfilment of a contract with you; 
(2) legal obligation, for the fulfilment of our legal obligations; (3) legitimate interest, for the purpose of our legitimate interests and the legitimate interests of third parties; (4) vital interest, for preventing or suppressing a danger to a person’s life, body, or health; and/or (5) public interest, for the performance of a task carried out in the public interest or for the exercising of official authorities.

 

We may collect, use, and/or disclose your Personal Data in order to provide products and services to you: to enter into a contract and manage our contractual relationship with you; to carry out contract details, financial transaction and services related to the payments including transaction checks, verification, and cancellation; to allow access to Data Centre premise; and for security purposes;

 

3. To whom we may disclose or transfer your Personal Data

 

We may disclose or transfer your Personal Data to the following third parties who collects, uses and discloses Personal Data in accordance with the purpose under this Policy. These third parties may be located in Thailand and areas outside Thailand. You can visit their privacy policy to learn more details on how they collect, use and disclose your Personal Data as you are also subject to their privacy policies.

 

3.1. Data ecosystem of STT GDC (Thailand) Co., Ltd.

 

As STT GDC (Thailand) Co., Ltd. is part of a Frasers Property Technology Group, Frasers Property Industrial Group and ST Telemedia Thailand Group which all collaborate and partially share customer services and systems including website-related services and systems, we may need to transfer your Personal Data to, or otherwise allow access to such Personal Data by other companies within Frasers Property Technology Group, Frasers Property Industrial Group and ST Telemedia Thailand Group for the purposes set out in this Privacy Policy. This will allow other companies within Frasers Property Technology Group, Frasers Property Industrial Group and ST Telemedia Thailand Group to rely on consent obtained by STT GDC (Thailand) Co., Ltd. 

 

3.2. Our service providers

 

We may use other companies, agents or contractors to perform services on behalf or to assist with
 the provision of products and services to you. We may share your Personal Data to our service providers or third-party suppliers including, but not limited to (1) computer program developer, software developer, IT service providers and IT support company; (2) marketing, advertising media, designer, creative, and communications agencies; (3) campaign, event, and market organizers, and CRM agency; (4) data storage and cloud service providers; (5) property management service provider; (6) sale agencies; (7) logistic and courier service providers; (8) payment and payment system service providers; (9) research agencies; (10) analytics service providers; (11) survey agencies; (12) call center; (13) telecommunications and communication service providers; (14) outsourced administrative service providers; (15) printing service providers.

 

In the course of providing such services, the service providers may have access to your Personal Data. However, we will only provide our service providers with the information that is necessary for them to perform the services, and we ask them not to use your information for any other purposes. We will ensure that the service providers we work with will keep your Personal Data secure as required under the laws. 

 

3.3. Our business partners

 

We may disclose your personal data to companies that we have partnered with to offer or enhance products and services for our customers or prospective customers, for example, financial institution partner, access solution company, telecommunication company, sponsors, co-branded partners and other third parties that we conduct joint marketing and cross promotion with.

 

3.4. Third parties required by law 

 

In certain circumstances, we may be required to disclose or share your Personal Data in order to comply with a legal or regulatory obligations. This includes any law enforcement agency, court, regulator, government authority or other third party where we believe it is necessary to comply with a legal or regulatory obligation, or otherwise to protect our rights, the rights of any third party or individuals’ personal safety, or to detect, prevent, or otherwise address fraud, security, or safety issues. 

 

3.5. Professional advisors 

 

This includes lawyers, technicians and auditors who assist in running our business, and defending or bringing any legal claims. 

 

3.6. Assignee of rights and/or obligations 

 

Third parties as our assignee, in the event of any reorganization, merger, business transfer, whether in whole or in part, sale, purchase, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock or similar transaction; will comply with this Privacy Policy to respect your Personal Data. 

 

4. International transfers of your Personal Data

 

We may disclose or transfer your Personal Data to third parties or servers located overseas, which 
the destination countries may or may not have the same data protection standards. We take steps and measures to ensure that your Personal Data is securely transferred and that the receiving parties have in place suitable data protection standards or other derogations as allowed by laws. We will request your consent where consent to cross-border transfer is required by law.

 

5. How long do we keep your Personal Data

 

We keep your Personal Data only for so long as we need the Personal Data to fulfil the purposes we collected it for, and to satisfy our business and/or our legal and regulatory obligations. How long we keep your Personal Data depends on the nature of the data. Some information may be retained for longer, where we are required to do so by law.

 

6. Your rights as a data subject

 

Subject to applicable laws and exceptions thereof, you may have the following rights to:

 

1)    Access: You may have the right to access or request a copy of the Personal Data we are collecting, using and disclosing about you. For your own privacy and security, we may require you to prove your identity before providing the requested information to you. 
2)    Rectification:  You may have the right to have incomplete, inaccurate, misleading, or or not up-to-date Personal Data that we collect, use and disclose about you rectified.
3)    Data Portability: You may have the right to obtain Personal Data we hold about you, in a structured, electronic format, and to send or transfer such data to another data controller, where this is 
(a) Personal Data which you have provided to us, and (b) if we are processing such data on the basis of your consent or to perform a contract with you.  
4)    Objection: You may have the right to object to certain collection, use and disclosure of your Personal Data such as objecting to direct marketing. 
5)    Restriction: You may have the right to restrict the use of your Personal Data in certain circumstances. 
6)    Withdraw Consent: For the purposes you have consented to our collecting, using and disclosing of your Personal Data, you have the right to withdraw your consent at any time. 
7)    Deletion: You may have the right to request that we delete or de-identity Personal Data that we collect, use and disclose about you, except we are not obligated to do so if we need to retain such data in order to comply with a legal obligation or to establish, exercise, or defend legal claims.
8)    Lodge a complaint: You may have the right to lodge a complaint to the competent authority where you believe our collection, use and disclosure of your Personal Data is unlawful or noncompliant with applicable data protection law.

 

8. Our Contact Details

 

If you wish to contact us to exercise the rights relating to your Personal Data or if you have any queries about your Personal Data under this Privacy Policy, please contact us or our Data Protection Officer at:

 

1)    Company Name


•    STT GDC (Thailand) Co., Ltd.
•    No.944 Mitrtown Office Tower, 22nd Floor, Rama 4 Rd., Wangmai, Pathumwan District, Bangkok 10330 Thailand

 

2)    Data Protection Officer

 

•    Address:    No.944 Mitrtown Office Tower, 22nd Floor, Rama 4 Rd., Wangmai,
                          Pathumwan District, Bangkok 10330 Thailand
•    Email:        pdpacenter@sttelemediagdc.co.th