External Paivacy Policy For Customer

INTRODUCTION

Siam Makro Public Company Limited (the “Company”) provides services and information and sells products through branches and other channels, as well as providing services through all online and digital channels for providing services and information including product ordering for Makro members in which the Company, as the website owner of www.siammakro.co.th, www.makroclick.com, www.makrohorecaacademy.com , www. โชห่วยไทย.com, and/or other websites to be developed by the Company in the future including other applications and online services of the Company (the “Website”). We are aware of the importance of your personal information and we always respect your privacy rights as our service recipient.

In general, you will be able to visit our website and review the contents, without the need to provide your personal information. However, you will need to register for an account if you would like to use our services including disclosing or providing your personal information which will be referred to as “personal information” in order for the Company to process for the purposes of entering into any transactions through our online channels or other channels, such as website, membership registration, ordering products online or other sales promotions for the members as stipulated under this privacy policy, hereinafter referred to as “Privacy Policy”.

SCOPE OF PRIVACY POLICY

This Privacy Policy covers the following topics.

  • Methods of collection and collected personal information
  • Purposes of collection, use or disclosure of personal information
  • Disclosure of personal information
  • Sending or transfer of personal information to overseas
  • Retention period of personal information
  • Your rights
  • Updating your personal information
  • Security measures of your personal information
  • Marketing Information
  • Cookies program and technical information
  • Redirecting to other parties’ websites
  • Changes to the Privacy Policy
  • Contact us

METHODS OF COLLECTION AND COLLECTED PERSONAL INFORMATION

Method of Collection Collected Personal Information

When you register or apply for membership registration in order to receive services from the Company.

  • Identifiable information such as name, surname, birth date, identification number.
  • Contact information such as address for invoices, address for shipping products, email and phone number.

When you log into our website for ordering products through our website or other online channels.

  • Technical information such as username, password, interests, setting preferences, IP address, login information, browser type, browser version, time and date setting, connection setting, operation and platform system and other technology that you have used your devices to sign in into our system.

When you enter into commercial transactions and make payments. This includes the use of membership card.

  • Transaction information such as payment details, bank account, product details and other services that you bought from the Company, including the information of accessing our website and other services.

When you have participated in different events of the Company, such as taking photos when receiving prizes or where you participated in other PR events.

  • Identifiable information such as name, surname, birth date, identification number.
  • Contact information such as address
  • Captured image or footage.

When you subscribe to our advertisement or our marketing news, or participate in any competition, receive discounts or answer surveys.

  • Identifiable information such as name, surname, birth date, identification number.
  • Survey Information.

When you request for document relating to tax, such as tax invoice.

  • Identifiable information such as name, surname, taxpayer identification number (if any)
  • Required information for issuing tax invoice.

Other cases according to security protection system of the Company such as CCTV

  • Captured image or footage

When you contact the Company, our customer service representatives or the customer service representatives which are contracting party of the Company via both online and offline channels.

  • Identifiable information such as name, surname, email and telephone number.
  • Opinion, information and suggestion.
  • Voice record when you have contacted with the Company, representative of customer service department or representative of customer service department which are the contract parties of the Company

When you report any incident to the Company such as in case of lost items, accidents, or illegal acts within the Company’s premises.

  • Identifiable information such as name, surname, birth date. identification number.

The Company will collect your personal information only if you have consented to us. For those who are our existing customers before the Personal Data Protection Act B.E. 2562 (the “PDPA”) enters into force, we will continue collecting and using your personal information which has been collected by the Company for the original purposes which you allowed us to collect your information. If necessary, the Company may collect your sensitive personal information such as health information, religion, blood type, etc. only with your explicit consent or when permitted by laws.

PURPOSES OF COLLECTION, USE OR DISCLOSURE OF PERSONAL INFORMATION

Any collection of your personal information by relevant employees of the Company or other relevant persons or any actions performed on behalf of the Company which is necessary for providing services and management of our website, including the use of personal information for any undertakings may rely on (1) Consent basis (2) Contract (i.e. performance of a contract or taking steps at your request before entering into a contract) (3) Legal obligation basis and (4) Legitimate interest basis by which the purposes of collection, use or disclosure of personal information will be as follows:

  1. To proceed your request for membership registration, to execute your orders or provide services via website and other channels when you enter into commercial transactions and make payments, this includes the use of membership card, such as payment for products, making refund, product delivery, using your membership card for entering into any transaction with the Company, prize delivery. This includes checking and managing the financial transactions initiated by you for the product payment.
  2. To manage and improve the service quality in order to provide an appropriate and satisfiable services such as conduct a customer satisfaction survey with the Company’s products and services to enable the Company to improve and develop products and services, marketing research or other marketing survey.
  3. To conduct a marketing including to inform you about information and offer regarding the Company’s products, services and sale promotions via telephone, SMS, E-mail, post, Makro application, Makro website, Line application, Facebook, Google ads and to assess my purchasing behaviour and service usage as well as my preferences and interests to develop sales and services for the purpose of marketing and sale promotion.
  4. To contact me at the shop for offering the Company’s products, services and any sale promotion.
  5. To conduct business planning, reporting and forecasting.
  6. To perform internal administration, including to verify the Company’s internal IT system.
  7. To proceed the request relating to tax such as issuing tax invoice, tourist tax refund.
  8. To use information for preventing any misconduct or fraud, and for complying with the law, including using information for monitoring and investigating the misconduct, fraud and for security measures,
  9. To monitor security in our buildings or premises including to protect your security via CCTV system, and to undertake in case of any lost belongings, including returning such lost belongings to you.
  10. To investigate and prepare an incident report in the case where there is any incident occurred and proceed with insurance claim according to the insurance policy.
  11. To comply with laws, regulations, orders, legal requirements and obligations of the Company, or to report or disclose information to government authorities as required by laws or upon receiving an order or a writ of attachment from police officers, government authorities, courts, or other competent authorities, to undertake detection and investigation under legal procedures and other regulations including to establish, comply or exercise the rights to legal claims or defend against the rights to legal claims.
  12. To assign rights, obligations and any benefits under a contract between you and the Company, for example, merger or transfer of the contract which has been done legally.

In the case where the personal information collected by the Company as stated above is necessary for the Company’s compliance with applicable laws or performance of contract. If you do not provide us with such necessary personal information, the Company may be subject to legal liabilities; and/or may not be able to provide you with our products and services; and/or may not be able to manage or administer the contract or give any convenience for you.

In the case where the Company needs to collect, use, disclose or perform any processes with your personal information, apart from the purposes mentioned in this Privacy Policy, the Company will inform such change in the website or publish the notice at the Company’s branches which may require an additional consent from you.

DISCLOSURE OF PERSONAL INFORMATION

The Company may disclose your personal information to other relevant parties for the purpose that has been stipulated under this Privacy Policy to:

  1. Subsidiaries, affiliates and any related companies for purposes of undertaking activities as set out in this Privacy Policy;
  2. Agencies, contractors/sub-contractors and/or service providers for their implementation and procedures, for example, carriers, food ordering and delivery service providers, document storage and destruction service providers, printing house, marketing agency, IT development and maintenance service providers, auditors, lawyers, tax and legal advisors, and any consultants;
  3. Government authorities, supervisory authorities or other authorities as stipulated by laws, including competent officials;
  4. Insurance companies;
  5. Our business partners or other third parties as per your consent or relevant contractual requirements or legal requirements, as the case may be.
  6. The assignee of the rights, duties, and any benefits from the Company, including any persons who are assigned by the aforesaid assignee to act on its behalf, for example, in the case of organizational restructuring, merger or acquisition, etc.

When disclosing your personal information to third parties or our affiliated companies within the country, the company will ensure that the company or other organizations that receive your personal information will have an adequate data protection standard in order to prevent any damage that may arises. If any disclosure of personal information requires consent, the Company will proceed with obtaining consent prior to such disclosure.

SENDING OR TRANSFER OF PERSONAL INFORMATION TO OVERSEAS

The Company may transfer your personal information to a country outside Thailand for the purpose that has been stipulated under this Privacy Policy such as sending personal information to the company which processes personal information on behalf of the Company. Where such disclosure or transfer of your personal information to third parties or affiliated companies located overseas, the Company shall comply with the relevant laws regarding sending or transfer of personal data to overseas and ensure that the receiving country has an adequate data protection and security standard at the same level or same standard as provided under the PDPA.

RETENTION PERIOD OF PERSONAL INFORMATION

We retain your personal information for as long as is considered necessary for the purpose for which it was collected, used or disclosed as set out in this Privacy Policy, i.e. as long as you are member of the Company, or for a period as necessary to comply with applicable laws, or to be in accordance with legal prescription, or to establish, comply with or exercise the rights to legal claims or defend against the rights to legal claims, or if you have request us to delete your personal information, or to comply with, for any other cause, our internal policies and regulations.

YOUR RIGHTS

You are entitled to the following rights under the PDPA:

No. Data Subject’s Rights Description

1

Right of access

You have a right to get access and obtain a copy of your personal information that we hold about you, or you may ask us to disclose the sources of where we obtained your information that you haven’t given consent. The Company will send such copy to you within 30 days upon obtaining your request. In certain cases, the Company may request additional information in order to confirm your identity and your rights as part of our security measures.

2

Right to data portability

You have a right to request us to automatically transfer your personal information to other persons, and request to see the personal information that we have transferred to other persons, unless it is impossible due to technical circumstances.

3

Right to object the processing of your information

You have a right to object to collection, use or disclosure of your personal information at any time, for example, if it is under the following circumstances:

  1. It is for the purpose of direct marketing; and/or
  2. It is for the purpose of scientific, historical or statistical research unless it is necessary to performance of a task carried out for reasons of public interest by the data controller.

4

Right to erasure

You have a right to request us to delete, destroy or anonymize your personal information in the following circumstances where:

  1. The personal information is no longer necessary for the purpose of which it was collected, used or disclosed;
  2. You have withdrawn your consent to which the collection, use or disclosure is based on;
  3. You have objected to the collection, use or disclosure of the personal information and the Company has no ground to reject such request; and/or
  4. When the personal information has been unlawfully collected, used or disclosed under the PDPA.

5

Right to restrict the processing of your information

You have a right to request us to restrict the processing of your personal information in the following circumstances when:

  1. It is under the pending examination process of checking whether the personal information is accurate, up-to-date and complete or not;
  2. It is the personal information that should be deleted or destroyed as it does not comply with the law and you request to restrict it instead;
  3. The personal information is no longer necessary to retain for the purpose of which it was collected, used or disclosed, but you still have the necessity to request the retention for the purposes of the establishment, compliance, or exercise of legal claims or the defense of legal claims;
  4. The Company is pending verification in order to reject the objection request of the collection, use or disclosure of personal information.

6

Right to withdraw consent

You may withdraw your consent at any time, unless it is restricted by law, or the contract which gives benefits to you.

However, the withdrawal of consent shall not affect the processing of personal information you have already given consent legally.

7

Right to rectification

You have a right to rectify inaccurate personal information in order to make it accurate, up-to-date, complete and not misleading. If the Company rejects your request, the Company will record such rejection with reasons.

8

Right to lodge a complaint

You will have the right to make a complaint in the case of where the Company, the data processor including the employees and employers of the Company do not comply with the PDPA or other notifications issued under the PDPA.

Under the PDPA, If you have any questions or would like to exercise any rights relating to your personal information, please submit your request via www.siammakro.co.th on exercise your right under the PDPA topics or contact the public relation staff at the branch or call center every Monday to Friday between 08.00-18.00 hours.

UPDATING YOUR PERSONAL INFORMATION

In the event that the personal information you have provided has changed, you must notify the Company of such update or edit the provided personal information so that your personal information is always accurate and up-to-date. If any of your personal information is incorrect, it may affect the service provision of the Company and the Company will not be responsible for any loss or damage that may occur to you or the third party as a result of your failure to correct or update your personal information to be accurate in any way.

SECURITY MEASURES OF YOUR PERSONAL INFORMATION

The Company certifies that all the personal information collected will be stored safely and strictly with adequate security standards. If you have a reason to believe that your personal information has been breached or if you have any questions regarding this Privacy Policy, please contact the DPO of the Company.

MARKETING INFORMATION

The Company will send information about products or marketing information to you from time to time if you have expressed your intention to the subscription to receive the information via our newsletters, telephone, email, or other communication channels. However, you can cancel such subscription by made change via www.siammakro.co.th at Consent Preference

COOKIES PROGRAM AND TEACHNICAL INFORMATION

Cookies program will be sent to your web browser or to your device when you visit the website or check for messages. This program will collect information about website usage behavior and when you ordered other products. In addition, it includes technical information that is username, password, interests, setting preferences, IP address, login information, browser type, browser version, time and date setting, connection setting, operation and platform system and other technology on your devices where you sign in into our system.

Adherence to such information, the program assists the Company to contact and remember your browser or device, which will facilitate the use of the website. If you have no demand to use the cookies program, you can reject installation of such program. However, refusing to use this cookie program may affect the use of our website or online services, or this may make it difficult for you to order products from the Company due to insufficient information, or the Company may require time to request for additional information. (if any)

You can learn more about our cookies program in our Cookies Policy at [https://www.siammakro.co.th/cookies-policy/php]

REDIRECTING TO OTHER PARTY’S WEBSITES

The Company’s website may be redirected to other websites for the purpose of facilitating you when you visit other websites. These websites may collect your personal information where the Company is not involved nor responsible for the collection of your personal information or the disclosure of your personal information to other websites of other parties, as well as the privacy policy of those websites in any way. For this reason, the Company recommends that you carefully review the privacy policy of those websites before you use the service on those websites.

CHANGES TO THE PRIVACY POLICY

The Company reserves the right to change, amend or update the Privacy Policy at any time as it deems appropriate by notifying you of the said changes. The Company will notify the changes, amendments or updates on the Company’s website which you can check at any time.

INCIDENT AND BREACH

In case of incident and breach of personal data occur, the Company determine the channels to report or direct to DPO promptly at

Email: DPO@siammakro.co.th

CONTACT US

If you have any comments, suggestions, questions or want to make a complaint regarding your personal information, please contact us at:

Siam Makro Public Company Limited Makro

Address: 1468 Phatthanakan Road, Phatthanakan, Suan Luang, Bangkok 10250

Data Protection Officer

Address: 1468 Phatthanakan Road, Phatthanakan, Suan Luang, Bangkok 10250
E-mail: [DPO@siammakro.co.th]

line