Privacy Policy

Thailand Investor Network Privacy Notice

We, Thailand Investor Network Company Limited ("TIN"), care about the privacy of our customers, and provide this privacy notice to inform you of our policy in relation to the collection, use and disclosure of personal data of an individual ("you") in accordance with the Personal Data Protection Act B.E. 2562 ("PDPA"), relevant laws and regulations. This privacy notice informs you of how we collect, use or disclose your personal data, what and why we collect, use or disclose your personal data, how long we hold it, who we disclose it to, your rights, what steps we will take to make sure your personal data stays private and secure, and how you can contact us.

This privacy notice applies to:

(1) Our customers

Individual customers: Our past and present customers who are individual.

Corporate customers: Directors, shareholders, ultimate beneficial owners, employees, guarantors, security providers, and legal representatives of our past and present corporate customers and other individuals authorised to act on their behalf. Corporate customers shall ensure that they and any authorised persons and any relevant individuals have acknowledged this privacy notice.

(2) Non-customers

These include individuals who have no product or service holding with us, but we may need to collect, use or disclose your personal data, e.g., anyone that visits our website or our software platform applications, offices; guarantors or security providers; beneficiaries under insurance policy; ultimate beneficial owners; directors or legal representatives of a juristic person that uses our services; debtors or tenants of our customers; professional advisors, including our directors, investors, shareholders and their legal representatives, and anyone involved in other transactions with us or our customers.

Please note that some of the links on our platform may lead to third party platforms, if you access such platforms through the TIN website, your personal data will then be processed under that third party's policies. Please make sure that you have read any such third party privacy notices when accessing such platforms.

1. How we collect, use or disclose your personal data

We only collect, use or disclose your personal data where it is necessary or there is a lawful basis for collecting, using or disclosing it. This includes where we collect, use or disclose your personal data based on the legitimate grounds of legal obligation, performance of contract made by you with us, our legitimate interests, performance under your consent and other lawful basis. Reasons for collecting, using or disclosing are provided below:

1.1 Our legal obligation

We are a non-regulated Thai entity, yet abide by multiple laws, rules, regulations, and are bound by orders of any competent governmental, supervisory or regulatory authorities to fulfil our legal requirements, it is therefore necessary to collect, use or disclose your personal data for the following purposes, which include but are not limited to:

a) compliance with the PDPA and any amendment thereof;

b) compliance with laws (e.g. Financial Institution Business Laws, Securities and Exchange Laws, Anti-Money Laundering Laws, Prevention and Suppression of Financial Support to Terrorism and the Proliferation of Weapons of Mass Destruction Laws, Life and Non-life Insurance Laws, and other laws to which we are subject both in Thailand and in other countries), including conducting identity verification, background checks and credit checks, Know Your Customer (KYC) process, Customer Due Diligence (CDD) process, other checks and screenings (including screening against publicly available database of regulatory authorities and/or official sanctions lists), and ongoing monitoring that may be required under any applicable law; and/or

c) compliance with regulatory obligations and/or orders of authorized persons (e.g. orders by any court of competent jurisdiction or of governmental, supervisory or regulatory authorities or authorized officers). In the case that we are an insurance broker, we will disclose your personal data to the Office of Insurance Commission to regulate and promote insurance businesses in accordance with Insurance Commission Act, Life Insurance Act and/or Non-Life Insurance Act.

1.2 Contract made by you with us

We will collect, use or disclose your personal data in accordance with any request and/or agreement made by you with us, for the following purposes, which include but are not limited to:

a) process your request prior to entering into an agreement, consider for approval and provide products and/or services, deliver products and/or services to you, provide informal reverse solicited non-professional advice and deal with all matters relating to products and/or services, including any activities that if we do not proceed, then our operations or our services may be affected or may not be able to provide you with fair and ongoing services;

b) authenticate when entering into, doing or executing any transactions (e.g. sending your proof of identification data to the Department of Provincial Administration for verifying the status of your identification card);

c) carry out your instructions e.g., fulfilling a request for utilization of loan and other credit facilities, making a change to your insurance policy, processing your applications and/or your transactions, fulfilling a request for utilization of products and/or services, responding to your enquiries or feedback, or resolving your complaints, including recorded images, videos and/or voices and/or any similar actions to enable us to efficiently carry out your instructions and/or to keep records as evidence for proceeding with your instructions;

d) provide online real estate support services, mobile applications and other online product platforms;

e) track or record your transactions;

f) produce reports (e.g. transaction reports requested by you or our internal reports);

g) notify you with transaction alerts and notify the due date of products and/or services;

i) carry out account maintenance and operations relating to your user accounts and/or financial accounts, including but not limited to processing your applications or requests for services or products, processing your transactions, generating statements of your user accounts and/or financial accounts, and operating and closing your user accounts and/or financial accounts;

j) carry out or make transactions and/or payments (e.g. processing payments or transactions, fulfilling transactions, billing or processing activities, managing your relationship with us, and administering your account with us);

k) proceed with any acts relating to insurance policies (e.g. proceeding with or monitoring any claim under your insurance policy, claiming against third parties);

l) enforce our legal or contractual rights;

m) provide IT and helpdesk supports, create and maintain user accounts for you, manage your access to any systems to which we have granted you access, and remove inactive accounts; and/or

n) in the event of sale or transfer of claims, assets, debt or business, merger, reorganization, rehabilitation, or similar event, we may disclose and transfer your personal data to one or more third parties who are the transferees of claims, assets, debt, or business, or the parties involved in the merger or reorganizing, or the plan preparers and plan administrators, or those related to such similar event.

1.3 Our legitimate interests

We rely on the basis of legitimate interests by considering our benefits or a third party's benefits with your fundamental rights in personal data which we will collect, use or disclose for the following purposes, which include but not limited to:

a) conduct our business operation (e.g. to conduct compliance audit, to conduct risk management assessments, to conduct finance and accounting management, to conduct financial audits, to conduct internal operation management, to manage the provision of services associated with our products or services, to monitor, prevent, and investigate fraud, money laundering, terrorism, misconduct, or other crimes, including but not limited to carrying out the creditworthiness checks of our corporate customers, which may not be required by any governmental or regulatory authorities, and authenticating your identity to prevent such crimes);

b) conduct our relationship management activities (e.g. to serve customers, to conduct customer surveys, to manage customer segmentation, to handle complaints), including recorded images, video and/or voice and/or any similar actions to enable us to efficiently conduct our relationship management activities and/or to enhance our services;

d) develop and improve our products, services and systems to enhance our services standard, use your personal data for conducting credit modelling, and/or for the greatest benefits in fulfilling your needs, including to conduct research, analyse data and offer products, services and benefits suitable to you by considering the fundamental rights in your personal data. If you do not wish to receive the offering of products, services and benefits from us, you can contact us at [email protected];

e) record images, video and/or voice relating to meetings, training, seminars, recreation or general activities (e.g. marketing activities, corporate social responsibility activities, activities to support customer's business) and use such recorded images, video and/or voice for the purpose of making internal and/or external public relations collaterals relating to such meetings, training, seminars or recreation activities;

f) in the case of our corporate customers, we will collect, use and disclose personal data of directors, authorized persons, attorneys, guarantors, beneficiaries, or any other persons, including personal data of such person as an individual customer, to execute transactions, provide services and/or contact corporate customers;

g) in the case of our individual customers, we may collect, use and disclose personal data of any other person relating to your transaction or use of our services (e.g. spouse, guarantor, beneficiary, insurance premium payer) to execute transactions and/or provide services to you;

h) ensure business continuity;

i) handle claims and disputes, file lawsuits and process the relevant legal proceedings, including the process of enforcement against debtors, guarantors, and security providers, the evaluation of collateral value and the enforcement of collateral through public auction;

j) contact you prior to your entering into a contract with us;

k) produce and/or display data relating to your account, account statement and/or transaction reports, in case you transfer money to or receive money from our customers and/or in case you make or receive payment for products or services from our customers;

l) protect against security risks (e.g. monitoring network activity logs, detecting security incidents, conducting data security investigations, and otherwise protecting against malicious, deceptive, fraudulent, or illegal activity);

m) comply with applicable domestic and foreign laws;

n) carry out research, plan and conduct statistical analysis (e.g. data analytics, assessments, surveys and reports on our products and/or services and your behaviour);

o) carry out our projects or marketing events (e.g. promotional campaigns, social activities, events for supporting our business and/or our customer's business), conferences, seminars, and company visits;

p) facilitate financial audits to be performed by auditors;

q) receive advisory services from legal counsels, financial advisors, and/or other advisors appointed by you or us;

r) prepare a summary report for consideration and/or disclose your personal data to one or more third parties who are interested to be the transferees of claims, assets, debt, or business, or are interested in merger or reorganizing, or those related to such similar event before sale, or transfer of claims, assets, debt or business, merger, reorganization, or similar event;

s) maintain and update lists and directories of customers (including your personal data) and maintain/keep contracts and associated documents in which you may be referred to; and/or

t) comply with reasonable business requirements (e.g. management, training, auditing, reporting, control or risk management, statistical and trend analysis and planning or other related or similar activities, implementing business controls to enable our business to operate, and enabling us to identify and resolve issues in our IT systems to keep our systems secured, performing our IT systems development, implementation, operation and maintenance).

1.4 Your consent

In certain cases, we may ask for your consent to collect, use or disclose your personal data to maximise your benefits and/or to enable us to provide services to fulfil your needs for the following purposes, which include but are not limited to:

a) collect, use or disclose your sensitive personal data as necessary (e.g. to use face recognition or your identification card photo (which contains your sensitive personal data, namely religion and/or blood type) for verification of your identity before entering into transactions and for Know Your Customer (KYC) process);

b) collect and use your personal data and any other data for the purpose of offering or providing products, services and benefits suitable to you. To proceed with such activity, we will research, conduct statistical data, analyse or develop such products, services and benefits;

c) contact you to provide financial advice and offer our products or services which may interest you (in case the consent is required under the PDPA);

d) disclose your personal data and any other related parties, group companies and/or subsidiaries and/or our trusted business partners for the purpose of offering or providing products, services and benefits to you. To proceed with such activity, related company's and our trusted business partners will research, conduct statistical data research, analyse or develop products, services and benefits suitable to you;

e) send or transfer your personal data and sensitive personal data overseas, which may have inadequate personal data protection standards (unless the PDPA specifies that we may proceed under other lawful basis or without obtaining consent);

g) other activities which we may require your consent.

1.5 Other lawful basis

Apart from the lawful basis which we mentioned earlier, we may collect, use or disclose your personal data based on the following lawful basis:

a) prepare historical documents or archives for the public interest, or for purposes relating to research or statistics;

b) prevent or suppress a danger to a person's life, body or health; and/or

c) necessary to carry out a public task, or for exercising official authority.

If the personal data we collect from you is required to meet our legal obligations or to enter into an agreement with you, we may not be able to provide (or continue to provide) some or all of our products and services to you if you do not provide such personal data when requested.

2. What personal data we collect, use or disclose

The type of personal data, namely personal data and sensitive personal data, which we collect, use or disclose, varies depending on the scope of products and/or services that you may have used or had an interest in.

3. Sources of your personal data

Normally, we will collect your personal data directly from you, but sometimes we may obtain it from other sources, in such case we will ensure our compliance with the PDPA.

Personal data we collect from other sources may include but not limited to:

a) Data obtained by us from related entities, business partners, and/or any other persons who we have legal relationship with;

b) Data obtained by us from persons related to you (e.g. your family, friends, referees);

c) Data obtained by us from corporate customers as you are director, authorised person, attorney, representative or contact person;

d) Data obtained by us from governmental authorities, regulatory authorities, financial institutions, credit bureau and/or third-party service providers (e.g. data that is publicly available, data that relates to transactions, credit data); and/or

e) Data obtained by us from insurance companies and/or other persons in relation to insurance policies or claims for compensation.

In case you have provided any personal data of any other person to us in executing transactions with us or any purposes, you shall notify such person of the details relating to the collection, use and disclosure of personal data and rights under this privacy notice. In addition, you shall obtain consent from such person (if necessary) or relied on another legal basis to provide personal data to us.

4. Your rights

The PDPA aims to give you more control of your personal data. You can exercise your rights under the PDPA, details as specified below, through the channels prescribed by us:

4.1 Right to access and obtain copy

You have the right to access and obtain copy of your personal data retained by us, unless we are entitled to reject your request under the laws or court orders, or if such request will adversely affect the rights and freedoms of other individuals.

4.2 Right to rectification

You have the right to rectify your inaccurate personal data or to update your incomplete personal data.

4.3 Right to erasure

You have the right to request us to delete, destroy or anonymise your personal data, unless there are certain circumstances where we have the legal grounds to reject your request.

4.4 Right to restrict

You have the right to request us to restrict the use of your personal data under certain circumstances (e.g. when we are processing a record change in accordance with your request to rectify your personal data or to object to the collection, use or disclosure of your personal data, or you request to restrict the use of personal data instead of the deletion or destruction of personal data which is no longer necessary as you have necessity to retain it for the purposes of compliance, exercise or defence of legal claims).

4.5 Right to object

You have the right to object to the collection, use or disclosure of your personal data in the case where we proceed on a legitimate interests basis or for the purpose of direct marketing, or for the purpose of scientific, historical or statistic research, unless we have legitimate grounds to reject your request (e.g. we have compelling legitimate ground to collect, use or disclose your personal data, or the collection, use or disclosure of your personal data is carried out for the establishment, compliance, or exercise legal claims, or for the reason of our public interests).

4.6 Right to data portability

You have the right to receive your personal data in the case where we can arrange such personal data to be provided in a format which is readable or can be read/accessed through commonly used software or automatic tools and can be used or disclosed by automated means. Also, you have the right to request that we send or transfer your personal data to a third party, or to receive your personal data which we have sent or transferred to third party, unless it is impossible to do so because of the technical circumstances, or we are entitled to legally reject your request.

4.7 Right to withdraw consent

You have the right to withdraw your consent that has been given to us at any time pursuant to the methods and means prescribed by us, unless the nature of consent does not allow such withdrawal. The withdrawal of consent will not affect the lawfulness of the collection, use, or disclosure of your personal data based on your consent before it was withdrawn.

You can review and change your consent to use or disclose your personal data for marketing purposes through channels as specified in No. 11 below or other channels prescribed by us in the future.

4.8 Right to lodge a complaint

You have the right to make a complaint with the Personal Data Protection Committee or their office in the event that we do not comply with the PDPA.

5. How we share your personal data

We may disclose your personal data to the following parties under the provisions of the PDPA:

a) related entities, business partners and/or other persons with whom we have a legal relationship, including our directors, executives, employees, staffs, contractors, representatives, advisors and/or such persons' directors, executives, employees, staffs, contractors, representatives, advisors;

b) governmental authorities and/or supervisory or regulatory authorities (e.g. the Bank of Thailand, the Securities and Exchange Commission, Office of Insurance Commission, the Anti-Money Laundering Office, the Ministry of Digital Economy and Society, the Thai Revenue Department, the Department of Provincial Administration);

c) suppliers, agents and other entities (e.g. professional associations to which we are a member organisation, external auditors, depositories, document warehouses, overseas financial institutions) where the disclosure of your personal data has a specific purpose and under lawful basis, as well as appropriate security measures;

d) any relevant persons as a result of activities relating to selling the rights of claims and/or assets, restructuring or acquisition of any of our entities, where we may transfer our rights to; any persons with whom we are required to share data for a proposed sale, reorganisation, business transfer, financial arrangement, asset disposal or other transaction relating to our business and/or assets used in our business operation;

e) other banks, financial institutions and third parties where required by law or trace funds where you are a victim of suspected financial crime, or where suspect funds have entered your account/s as a result of financial crime;

f) debt collection agencies, lawyers, credit bureaus, fraud prevention agencies, courts, authorities or any persons whom we are required or permitted by laws, regulations, or orders to share personal data;

g) third parties providing services to us (e.g. IT service providers, market analysis and benchmarking service providers, cloud computing service providers, agents or subcontractors acting on our behalf etc.);

h) social media service providers (in a secure format) or other third-party advertisers so they can display relevant messages to you and others on our behalf about our products and/or services. Third-party advertisers may also use data relating to your previous online activities to tailor adverts to you;

i) our customers, persons involved in making transactions with us and/or persons in relation to the provision of our products or services;

j) third-party security providers;

k) other persons that provide you with benefits or services associated with our products or services (e.g. insurance company); and/or

l) your attorney, sub-attorney, authorized persons or legal representatives who have lawfully authorized power.

6. International transfer of personal data

The nature of modern finance, real estate and internet powered software platform businesses is global and under certain circumstances it is necessary for us to send or transfer your personal data internationally (e.g. transferring data to related entities or to cloud servers overseas for the purpose of the provision of services). When sending or transferring your personal data, we will always exercise our best effort to have your personal data transferred to our reliable business partners, service providers or other recipients by the safest method in order to maintain and protect the security of your personal data.

If the destination countries do not have adequate data protection standard, we will proceed to transfer personal data as specified by the PDPA and will put in place the protection measures of such personal data as necessary and appropriate.

7. Retention period of personal data

We will maintain and keep your personal data while you are our customer and once you have ended your relationship with us (e.g. after you closed your account with us, or following a transaction with us, or in case of your application to use our services is disapproved, or you terminated the services provided by us), we will only keep your personal data for a period of time that is appropriate and necessary for each type of personal data and for the purposes as specified by the PDPA.

The period we keep your personal data will be linked to the prescription period or the period under the relevant laws and regulations (e.g. Financial Institutions Businesses Laws, Securities and Exchange Laws, Anti-Money Laundering Laws, Counter-Terrorism and Proliferation of Weapon of Mass Destruction Financing Laws, Accounting Laws, Tax Laws, Labour Laws and other laws to which we are subject both in Thailand and in other countries). In addition, we may need to retain records of CCTV surveillance in our office and/or voice records of customer services calls to prevent fraud and to ensure security, including investigating suspicious transactions which you or related persons may inform us of.

8. Use of Cookies

We may collect and use cookies and similar technologies when you use our products and/or services. This includes when you use our websites or software applications.

The collection of such cookies and similar technologies helps us recognise you, remember your preferences and customise how we provide our products and/or services to you. We may use cookies for a number of purposes (e.g. enabling and operating basic functions, helping us understand how you interact with our websites or emails, or enabling us to improve your experiences or our communications with you).

9. Use of personal data for original purposes

We are entitled to continue collecting and using your personal data, which has previously been collected by us before the effectiveness of the PDPA in relation to the collection, use and disclosure of personal data, in accordance with the original purposes. If you do not wish us to continue collecting and using your personal data, you may notify us to withdraw your consent at any time.

10. Security

We endeavour to ensure the security of your personal data through our internal security measures and strict policy enforcement. The measures extend from data encryption to firewalls. We also require our staff and third-party contractors to follow our applicable privacy standards and policies and to exercise due care and measures when using, sending or transferring your personal data.

11. How to contact us

If you have any questions or would like more details about our privacy notice, please contact us through the following channels:

Thailand Investor Network Company Limited

Email: [email protected]

12. Changes to this privacy notice

We may change or update this privacy notice from time to time and we will inform the updated privacy notice at our website www.thailandinvestornetwork.com