Introduction
At Health Passport, we are committed to safeguarding your personal data. This Privacy Policy explains how we collect, use, and protect your personal informationin accordance with the Personal Data Protection Act B.E. 2562 (2019) in Thailand and other applicable laws.
1. Types of Personal Data Collected
We collect various types of personal data that may identify you either directly
or indirectly, including but not limited to:
Identity Data: Full name, surname, date of birth, gender, national ID number, passport number, marital status, email address, phone number.
Financial and Transactional Data: Bank account details, credit/debit card numbers, monthly income, payment history.
Sensitive Data: Health-related information (such as allergies and medical conditions), ethnicity, beliefs, religion, biometric data, and criminal history. In the event that we inadvertently collect any sensitive data, we will not process it and will take immediate steps to delete it.
Technical and Usage Data: IP address, login credentials, browsing data, cookie identifiers, device details, and other technical data from your interaction with our website.
Profile Data: Username, password, purchase history, preferences, survey responses, and other data related to your engagement with us.
Marketing and Communication Data: Your preferences regarding receiving marketing materials and your interaction with us across various platforms.
We may also collect aggregated, anonymized data for statistical and research purposes. This data cannot be used to identify you and is processed in compliance with relevant data protection laws.
2. Purpose of Personal Data Processing
We process your personal data for the following legitimate purposes:
To deliver, improve, and personalize the services and products we offer.
To fulfill our contractual obligations and provide products and services as requested.
To comply with legal obligations and ensure regulatory compliance.
To provide you with relevant marketing communications, promotions, and updates, based on your consent.
For internal assessments, product quality checks, and performance evaluations.
In certain instances, such as processing sensitive data, we will seek your explicit consent before proceeding with data collection and processing.
3. Legal Basis for Processing Personal Data
We process your personal data based on the following legal grounds:
Consent: We collect and process data with your explicit consent, which you may withdraw at any time. Upon withdrawal, we will cease processing your data unless we have another legal basis to continue processing it.
Contractual Necessity: We process your personal data to fulfill contractual obligations, such as providing services you’ve requested or to complete transactions initiated by you.
Legal Obligation: We process personal data to comply with legal obligations, including those required for regulatory and governmental reporting.
Public Task: We process data when necessary to perform tasks that are in the public interest or related to the functions of a government authority.
Vital Interests: We process personal data to protect the life or health of an individual in emergency situations.
Legitimate Interests: We process data where our legitimate business interests outweigh your rights and freedoms, such as improving our services or managing legal claims.
Research: We may process data for research purposes in compliance with applicable laws, including historical, statistical, or scientific research.
In certain instances, such as processing sensitive data, we will seek your explicit consent before proceeding with data collection and processing.
4. Personal Data Disclosure
We may disclose your personal data to third parties, including government agencies and business partners, for the purposes outlined in Section 2 ("Purpose of Personal Data Processing"). This may also include sharing data with regulators or authorities to comply with legal requirements.
5. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes for which it was collected and in accordance with applicable laws and regulations. Once the data is no longer needed, we will securely delete or anonymize it.
6. Data Subject Rights
As a data subject, you have the following rights under the Personal Data Protection Act:
Right to Withdraw Consent: You have the right to withdraw consent at any time, which will halt the processing of your data unless there is another legal basis for its retention.
Right to Access: You have the right to request access to your personal data, including the right to receive a copy of the information we hold about you.
Right to Rectification: You can request that any inaccurate or incomplete data be corrected to ensure it is accurate and up-to-date.
Right to Data Portability: You may request that we send your personal data to another data controller in an easily readable format.
Right to Erasure: You may request the deletion or anonymization of your personal data when it is no longer necessary for the purposes for which it was collected or if it was processed unlawfully.
Right to Restrict Processing: You have the right to restrict the processing of your data under certain circumstances, such as when its accuracy is being verified or when you object to processing for legitimate interests.
Right to Object: You may object to the processing of your personal data, particularly if it is used for direct marketing or research purposes.
Right to Lodge a Complaint: If you believe we have violated your rights, you have the right to lodge a complaint with the relevant supervisory authority.
7. Data Security
We retain your personal data for as long as necessary to fulfill the purposes for which it was collected and we take appropriate measures to safeguard your personal data from unauthorized access, alteration, disclosure, or destruction. This includes implementing technical, organizational, and physical safeguards to protect your information in accordance with applicable laws and regulations. Once the data is no longer needed, we will securely delete or anonymize it.
8. Contact Information
To exercise your rights or for any questions or concerns regarding our privacy practices,
please contact us using the following details: