Privacy Notice
Thai Housing Development Co., Ltd. (“We,” “Us,” “Our”) has a measure to protecting your Personal Data. We shall ensure you that your Personal Data is handled in accordance with the Personal Data Protection Act B.E. 2562 (2019) in Thailand (“Thai PDPA”) and other applicable laws.
1. Definitions
Terms and Definitions used in this Privacy Notice are set out in the details as below:
Personal Data: means as specified in clause 2 “Types of Personal Data Collected”.
Data Controller: : means a natural or legal person who has powers and duties to make decision regarding the collection, storage, usage and disclosure of Personal Data.
Data Processor: : means a natural or legal person who proceeds the collection, storage, usage or disclosure of Personal Data according to the order or on behalf of Data Controller; however, such natural or legal person who proceeds such activities is not Data Controller.
Data Subject: : means any individual person who can be identified, directly or indirectly, via Personal Data.
Person:: means a natural person.
Business Partners: : means a natural or legal person who directly or indirectly controls us, is controlled by us, owns us, is owned by us, manages us, is managed by us; including any legal entities whom we discloses, transfers, or receives Personal Data, for example, consulting and law firms, telemarketing companies, co-brand partners, correspondent banks, recruitment agencies, business alliances, external service providers (suppliers, vendors, outsources) and/or government affairs or regulators in order to comply with applicable laws.
DPO: Data Protection Officer.
2. Types of Personal Data Collected
Personal data refers to information about an individual from which that person can be identified whether by either a direct or an indirect means. However, Personal Data does not include information of deceased person and anonymous data.
Personal data includes:
1. Identity Data : data about individuals which can be used to identify specific individual, whether by a direct or an indirect means such as name, surname, date/ month/ year of birth, gender, ID number, driving license number, passport number and marital status.
2. Contact Data: such as email address and phone number.
3. Sensitive Data: : such as ethnicity, beliefs, religion, health information (including food and general allergies) and biometric data, including criminal history data. In the event that we have unintentionally received it and has no intention to collect such data, and the data is not intended to be used to facilitate your stays at our hotels, We will not process your sensitive data.
4. Financial and Transactional Data: :such as bank account number, credit card number and debit card number, monthly income and payment information.
5. Technical and Usage Data: such as IP Address, login information, website browsing information, cookie ID, device types, platforms, and other technologies used to access the our websites.
6. Profile Data: such as username and password, purchase history, interests, likes and information from survey responses.
7. Marketing and Communication Data: such as your preferences in receiving marketing materials from us, and from third party. These also include contact information you have with us, such as tape record when contact is made via contact center or from other social media channels.
Personal Data excludes:
1. Personal Data which is publicly available at the point of collection.
2. Business contact information such as business phone number and business address.
3. Anonymous data.
4. Deceased Person.
We also collect, storage, use, and disclose aggregated data, such as statistical, and demographic information. The aggregated data may be derived from your Personal Data; however, the data is not considered as Personal Data since it cannot be used to identify a specific individual. For example, we may use some of your information after the process of anonymization in order to create statistical information of people who make a reservation through our website. We are aware that the data used must not be able to revert to identifiable information. If the data is then able to be used to identify a specific individual, we will consider it as Personal Data and processed in accordance with this Privacy Notice.
3. Third-party Links
Our website may lead you to a third-party website when you access the website. Such action may allow other websites to collect, store, use, or disclose your Personal Data. We are not responsible for any processing activities of Personal Data occurred on other websites. Hence, we encourage you to read the privacy notice of every websites you visit, for the interests of your data privacy.
4. Legal Basis
We will process your Personal Data under following legal basis:
• Consent : We process Personal Data based on consensual basis. In the event that you have provided us explicit consent to us, we will process your Personal Data within the scope of the purpose we have informed you.
• Contract: We process Personal Data under the contractual basis. We use this legal basis when the processing of Personal Data is necessary to fulfill the contract for which you are a part of, or to use in fulfilling your request prior to entering into the contract. For example, processing your Personal Data is crucial to our ability to provide products and services as well as internal processes in achieving contractual objectives.
• Legal Obligation: We process personal data in accordance with legal compliance, such as the prevention and detection of irregular transactions which may involve with illegal activities. For example, we have legal obligation to report your personal data to the Revenue Department or other government affairs as required by law.
• Vital Interest: We process personal data under the necessity emergency medical situation to protect your life and death or another natural person.
• Legitimate Interest: We process Personal Data under the necessity to take steps for our legitimate interests or other individual or juristic person which are not overriding your interests or your fundamental rights and freedoms.
However, if you do not provide Personal Data to us, it may affect your inconveniences and may not be in compliance with our contract. Furthermore, it may affect certain legal compliance which can result in penalties.
5. Purpose of Personal Data Processing
As our customers, we collect, storage, use, or disclose your Personal Data, for the following purposes;
PURPOSE
DESCRIPTION OF ACTIVITIES ASSOCIATED WITH PURPOSE
LEGAL BASES
Booking & Guest Registration
There are a number of activities associated with this purpose, such as: facilitating reservations and bookings of hotel accommodations and related services; engaging in pre arrival communications (logistics, changes, preferences, etc.); and processing payments and security deposits.
Performance of contract for the individual with the guest booking the room
Legitimate interests for the individual booking the room, for example, honoring his/her preferences, as well as for any individuals accompanying the primary guest (e.g., spouse, children, friends)
Legal obligations relating to financial transactions, such as the obligation to maintain books and records
On-Site Reception & Stay Services
There are a number of activities associated with this purpose, such as: facilitating check-in and check-out; processing payments; providing consistent and personalized service and advice about the on-site services (based on past usage or expressed preferences); providing concierge, luggage storage and parking services; making arrangements with third party providers on behalf of guests (such as coordinating tours, arranging taxi, shuttle and chauffeur services; and facilitating reservations and bookings at restaurants and events); administering and facilitating access to Wi-Fi, TV and other connectivity services (including access to business center amenities, such as fax and photocopying services) and facilitating in-room dining (including taking into account any dietary, health restrictions or other personal needs expressed by the guest); housekeeping services (including preferences for special pillows, duvets and other amenities expressed by the guest) and dry-cleaning services; handling customer requests, inquiries and complaints; and determining eligibility for age restricted goods and services (such as alcohol or in-room adult entertainment).
Performance of contract, such as processing payments
Legitimate interests, such as honoring the guest’s preferences (e.g., for a room near the elevator or on a top floor)
Consent, such as collecting information regarding dietary preferences that the guest chooses to provide
Legal obligations, such as collecting national ID numbers where legally required
Conferences & Events
There are a number of activities associated with this purpose, such as: communicating with customers about conferences and other event planning (“Events”); facilitating reservation and bookings of Events; engaging in pre Event communications (logistics, accommodations, changes, etc.); preparing for and coordinating Events in accordance with customer instructions, expectations and preferences; facilitating catering; communicating about billing and recovering amounts owed; processing payments and security deposits; performing credit checks; handling customer requests, inquiries and complaints; and communicating with participants during Events.
Performance of contract, such as collecting information regarding a planned Event
Legitimate interests, such as responding to customer complaints or concerns relating to an Event
Legal obligations relating to financial transactions, such as the obligation to maintain books and records
General Business
There are a number of activities associated with this purpose, such as: administering customer-care services to facilitate and address inquiries, comments and complaints about any of our services (such as in person, through phone lines, email, or on social media); handling security and fraud prevention; administering online services (including troubleshooting, data analysis, testing, system maintenance, support, reporting and the hosting of data); monitoring and analyzing usage of services and using data analytics to improve services, marketing, programs, overall customer experience, gathering feedback, carrying out pilot programs for potential new services and both developing new and improving existing services; and facilitating mergers, acquisitions and other reorganizations and restructurings of our business (including prospective transactions).
Performance of contract, such as ensuring that online services are functioning so that individuals can make reservations
Legitimate interests, such as responding to customer complaints and concerns.
Consent, such as for marketing programs
Legal obligations relating to financial transactions, such as the obligation to maintain books and records
Emergency & Incident Response
There are a number of activities associated with this purpose, such as: ensuring the security of on-site services; responding to, handling and documenting on-site accidents and medical and other emergencies (including facilitating in house doctor services); actively monitoring properties to ensure adequate incident prevention, response and documentation (including CCTV); requesting assistance from emergency services; and sending notifications and alerts in the event of incidents or emergencies (such as via SMS, email, call, audio-visual device prompts, etc.).
Performance of contract, such as ensuring the safety of guests and personnel through interactions with on-site security personnel
Legitimate interests, such as monitoring properties through CCTV to ensure the safety of guests and personnel
Legal obligations, such as documenting on site accidents
Individuals’ vital interests, such as contacting medical or emergency services for an ill guest
Legal & Compliance
There are a number of activities associated with this purpose, such as: complying with applicable laws; complying with legal processes; responding to requests from public and government authorities; meeting national security or law enforcement requirements; enforcing our terms and conditions; protecting our operations; protecting the rights, privacy, safety, or property of the Thai Housing Development Co., Ltd., guests, visitors and other relevant individuals; and allowing us to pursue available legal remedies and limiting the damages that we may sustain.
Legal obligations, such as complying with legal processes
Legitimate interests, such as enforcing terms and conditions to protect trademarks
Individuals’ vital interests, such as contacting emergency services in case of disturbances and incidents involving guests
Fitness Services
There are a number of activities associated with this purpose, such as: facilitating reservations and bookings; determining eligibility for services; honoring disability or other health-related restrictions and providing appropriate and safe activities, services and treatments; providing consistent and personalized service based on past usage and preferences expressed by the individual; processing payments; arranging requested professionals for specific treatments and services; and handling customer requests, inquiries and complaints.
Performance of contract, such as processing payments
Consent, such as collecting information about parts of body problems when working out
Legitimate interests, such as providing personalized services (e.g., Offering Yoga class based on previous activities)
Legal obligations relating to financial transactions, such as the obligation to maintain books and records
Individuals’ vital interests (e.g., when an individual becomes ill while using the fitness equipment)
Food & Beverage Services
There are a number of activities associated with this purpose, such as: facilitating reservations; honoring dietary preferences; providing consistent and personalized service based on past usage and preferences expressed by the individual; processing payments; arranging reservations; and handling customer requests, inquiries, and complaints.
Performance of contract, such as processing payments
Consent, such as collecting information about dietary, health restrictions, or personal needs of a guest when ordering food
Legitimate interests, such as providing personalized services (e.g., offering special beverages a guest based on previous requests)
Legal obligations relating to financial transactions, such as the obligation to maintain books and records
Individuals’ vital interests (e.g., when an individual becomes ill in one of the restaurants)
Marketing, Promotions, Contests & Third-Party Products
There are a number of activities associated with this purpose, such as: communicating about products and services that may be of interest to guests; providing personalized advertisements for products and services on selected websites; facilitating participation in sweepstakes, contests, and other promotions (such as best vacation photo contests on social media); and handling customer requests, inquiries and complaints.
Performance of a contract, such as fulfilling obligations associated with a contest
Consent, such as honoring the mode of communication preferences (e.g., email, SMS)
Legitimate interests, such as providing advertisements for similar products and services
Legal obligations, such as handling information consistent with rules relating to sweepstakes
However, the collection, storage, usage, or disclosure of Personal Data will be processed on legal basis. We may process your Personal Data on different legal basis, depending on the purpose of data processing.
6. Personal Data Disclosure
We may disclose your Personal Data to government agencies and our Business Partners for the purposes stated in clause 5 “Purpose of Personal Data Processing” and government affairs or regulators in order to comply with the law.
7. Cross Boarder Transfer of Personal Data
We will not transfer personal data outside Thailand unless the personal data is protected with the same or higher standard of protection under this Notice. In the event that we have necessity to send or disclose customers’ personal data internationally, we will create personal data protection agreement or contract with the contracting partner in that country.
8. Data Security
We classify your Personal Data as confidential information and apply various security measures to be responsible for maintaining the confidentiality and safety of customer Personal Data in accordance to the agreements.
9. Data Retention
We will retain your personal data for as long as necessary to achieve the purposes for which we have collected it for. If you have ended your business relationship with us, we will retain your personal data in accordance with our Privacy Policy, for a period of 10 years, or as required by law, in order to ensure the provision of products or services to you, and for legal purposes. However, at the end of the said period, we will destroy your personal data.
10. Data Subject Rights
You have rights under the Personal Data Protection law that you should be aware of. You can make a request by using the contact channel provided in the section “11. Contact Us.” We will process your request as soon as possible, which may take up to 30 days or more, depending on the volume and complexity of the request.
• Right to Withdraw Consent: You have the right to withdraw your consent on which the collection, storage, usage, or disclosure is based on at any time. As a result, we will stop the processing of your information as soon as possible and if we do not have other lawful basis which allow us to process your Personal Data, we will then delete your information.
• Right to Access: You have the right to request access and to obtain a copy of your Personal Data related to you under our responsibility or to request disclosure of the acquisition of the Personal Data obtained without your consent. Once we have received the request, will proceed to comply within 30 days or more, depending on the volume and complexity of the request.
• Right to Rectification: You have the right to request correction and rectification on your Personal Data to ensure that the data is correct, up-to-date, and complete.
• Right to Data Portability: You have the right to request us to send or transmit your Personal Data to another Data Controller by the transmission that can be done with automatic means. You also have the right to receive directly your Personal Data in the format that we send or transfer to another Data Controller, except where it is not technically feasible.
• Right to Erasure: You have the right to request us to erase, destroy, or anonymized your Personal Data in the cases stated below:
1. Personal Data is no longer necessary for the purpose in which it is collected for.
2. You withdraw consent in processing Personal Data and we have no legal ground for further retaining or processing activity.
3. You object processing of Personal Data for direct marketing purposes.
4. Processing of Personal Data is unlawful.
• Right to Restriction of Processing: You have the right to restrict the processing of Personal Data if the stated conditions are met:
1. Processing of Personal Data is no longer necessary but we can demonstrate that there is a compelling legitimate ground.
2. Processing of Personal Data is unlawful but you want to restrict the processing activity instead of deletion.
3. Personal Data is under review for completeness and accuracy upon your request.
4. Processing of Personal Data is carried out for the establishment, compliance, or exercise /defense of legal claims.
• Right to Object: You have the right to object the processing of Personal Data if the stated conditions are met:
1. Personal Data is being processed for direct marketing purposes.
2. Personal Data is being processed for research purposes either in the field of science, history, or statistics, unless it is necessary to performance of a task carried out for reasons of public interest.
3. Personal Data is collected for our necessity to carry out public tasks or for other legitimate ground. Unless we are able to demonstrate higher legitimate grounds, or the processing activity is to establish legal claims or compliance.
• Right to Lodge a Complaint: You have the right to submit complaint to the relevant government agencies in the event that our employees, vendors, contractors violate or fail to comply with the personal data protection requirements.
11. Contact Us
If you wish to exercise data subject rights or if you have any question or complaint, you can contact us via:
• Thai Housing Development Co., Ltd.
• 215 Yaowaraj Rd., Sampantawong, Bangkok 10100
• Email : dpo@grandchina.com