Privacy Policy
PTG Energy Public Company Limited and its subsidiaries or affiliated companies ("Group Companies") value and respect your privacy and are committed to safeguarding personal data, including maintaining the security of personal data in accordance with the law and international standards.
The Company hereby announces this Privacy Policy ("Policy") with the purpose of informing you about the details of personal data protection and management for maintaining the security of your personal data as a current, former, or potential customer, business partner, contract party, employee, staff, personnel, representative, authorized individual acting on behalf of a legal entity, director, contact person, and other natural persons acting on behalf of a legal entity, who are customers or business partners of the Company, shareholders, investors, and individuals associated with the Company. This is to assure you that your personal data collected, disclosed, or transferred to external parties and/or overseas are protected in accordance with the personal data protection laws.
Furthermore, the Company has established privacy settings for cases involving the collection and use of your personal data from accessing the Company's website. The Company will implement measures to ensure the security of your personal data in an appropriate manner.
The terms mentioned in this Policy
"Personal Data" refers to information about you that identifies or can identify you, which the Company collects and gathers as stated in this Policy.
"Sensitive Personal Data" refers to personal data that the Personal Data Protection Act of 2019 ("Personal Data Protection Act") designates as sensitive data. The Company collects, discloses, or transfers sensitive personal data to external parties and/or overseas when the Company has obtained explicit consent from you. Sensitive personal data may include information such as ethnicity, race, political opinions, beliefs, religion, or philosophy, sexual orientation, criminal records, health data, disabilities, labor union data, genetic data, biometric data, or any other data that similarly affects the data subject in a comparable manner.
The personal data that the Company collects and stores
Your personal data that the Company collects, uses, or discloses, including but not limited to the following categories:
  1. Personal information such as name, surname, title, national identification number, passport number, taxpayer identification number, position, nationality, age, including sensitive information that may appear on a copy of your identification card, such as religion, ethnicity, and blood type, for which the Company has obtained clear consent from you or where necessary as permitted by law.
  2. Contact information such as address, phone number, mobile phone number, and email address.
  3. Employment information such as occupation and workplace.
  4. Financial information such as bank account numbers, transaction details, and credit card numbers.
  5. Other personal information such as data related to the use of information systems and the company's website, recorded images from CCTV cameras, recorded audio conversations.
In the case that you are a minor under the age of 10 or a person with limited legal capacity, or a person with no legal capacity, the company requests that your legal guardian, guardian, or custodian, who has the authority, provide consent for the collection, usage, disclosure, and processing of your personal data. This includes any actions related to such cases. Additionally, if the company discovers that it has collected, used, disclosed, and processed your personal data without legal consent from your legal guardian, guardian, or custodian, the company will reject any requests from you and promptly delete your personal data. However, the company may still proceed with collecting, using, disclosing, and processing your personal data if it falls under legally permissible exceptions to the requirement of consent.
In the case that you are a minor over the age of 10 and not covered by the exemptions under Sections 22, 23, or 24 of the Thai Civil and Commercial Code, the company requests that your legal guardian, who has the authority, provide consent for the collection, usage, disclosure, and processing of your personal data. This includes any actions related to such cases. Additionally, if the company discovers that it has collected, used, disclosed, and processed your personal data without legal consent from your legal guardian, the company will reject any requests from you and promptly delete your personal data. However, the company may still proceed with collecting, using, disclosing, and processing your personal data if it falls under legally permissible exceptions to the requirement of consent.
In the case that you are a minor over the age of 10 and fall within the exemptions specified under Sections 22, 23, or 24 of the Thai Civil and Commercial Code, the company requests your consent for the collection, compilation, usage, disclosure, and processing of your personal data, including any related actions. Furthermore, if the company discovers that it has collected, used, disclosed, and processed your personal data without obtaining legal consent from you, the company will decline any requested actions from you and will promptly delete your personal data, unless the collection, usage, disclosure, and processing of such personal data falls within legally permissible exceptions where the company can proceed without requiring your consent.
"General customers" or service users in that context, the Company will collect and use your personal data, including information related to your purchases of goods and/or services. For those of you who are shop owners or business operators, in addition to personal data as service users, the collection and use of your data will also encompass information related to your additional trading activities.
Foreign countries, in which various types of personal data related to your relationship with the Company, including but not limited to sensitive data such as ethnicity, religion, blood type, and biometric data appearing in photographs of national identification cards, are collected, used, disclosed, and processed by the Company only when required by law. The Company complies with relevant laws, including notifications from the Bank of Thailand and the Anti-Money Laundering Act concerning the identification and verification of identity, data verification, due diligence, customer due diligence, and Know Your Customer (KYC) practices. These actions are necessary for service provision or in cases where data is collected, used, disclosed, processed, and/or transferred.
In this regard, for the necessity of providing services or in cases of collection, use, disclosure, processing, and/or transfer to foreign countries of various types of personal data related to your relationship with the Company, including but not limited to sensitive data such as ethnicity, religion, blood type, and biometric data appearing in photographs of national identification cards, the Company collects, uses, discloses, and processes personal data of this sensitive nature only when required by law. The Company complies with relevant laws, including notifications from the Bank of Thailand and the Anti-Money Laundering Act concerning the identification and verification of identity, data verification, due diligence, customer due diligence, and Know Your Customer (KYC) practices. These actions are necessary for service provision or in cases where data is collected, used, disclosed, processed, and/or transferred.
Sources of Personal Data
The company may collect personal data from you when you provide your personal information to the company, whether it's through channels such as purchasing products or services, exchanging business cards, providing your information electronically, or receiving your personal data from other sources. These other sources may include sales representatives, government agencies, companies within the PTG Energy Public Company Limited group, and more.
The purposes of processing personal data:
The company will process your personal data that has been collected by the company for the following purposes:
  1. For the necessary communication regarding purchasing goods or services, fulfilling contractual obligations, or considering and processing your requests before entering into a contract. This includes activities such as contacting you for sales and service, contract formation, conducting operations related to invoicing or payment for goods or services, evaluating procurement options, arranging delivery or receipt of goods or services, processing compensation for position-related duties, reviewing and tracking contractual performance, and more.
  2. For legal interests, such as verifying the accuracy or quality of products or services according to international standards, conducting investigations or affirming facts, preventing, controlling, or investigating fraudulent activities, enhancing security, conducting legal or tax consultations, or accounting purposes.
  3. To comply with laws related to business operations or activities, such as providing information to government agencies as required by law, complying with court orders or orders from legal authorities or officers, conducting activities related to obtaining permits or licenses under the law, making legal fee payments as required by law, establishing or exercising rights according to laws or court orders, organizing meetings and disbursing compensation as legally entitled, among other things.
  4. To analyze the usage of products or services by members, for the purpose of creating promotions or discounts on products or services that cater to their preferences. Additionally, with your consent, for general customers who are service users, the company may collect and use your personal data for processing data for marketing purposes, and to provide you with benefits from receiving informational materials, advertisements, campaign creation, sales and marketing activities, promotions, benefits, discounts, or invitations to participate in activities. This may involve disclosing personal information and any other data of yours to PTG Energy Public Company Limited, Max Card Company Limited, Max Solutions Service Company Limited, as well as affiliated companies, subsidiaries, joint venture partners, associates, and service providers of the aforementioned companies, for the purpose of processing data for marketing purposes, presenting news, sales promotion events, campaign creation, product presentations, and analyzing the usage of products or services by members.
For customers who are merchants or business operators, the company may collect and use personal data and any data related to your products or services for the purpose of processing data for marketing purposes and providing you with benefits in purchasing the products and services of the company. This includes sending news, advertisements, campaign promotions, sales promotions, benefits, and inviting you to participate in various activities that you have expressed interest in to the company. Analyzing data related to your product or service transactions in order to create promotions or discounts that align with your preferences and needs. The company may disclose personal data and any data related to the purchase and sale of your products or services to PTG Energy Public Company Limited, Max Card Company Limited, Max Solutions Service Company Limited, including affiliated companies, subsidiaries, joint ventures, partners, allies, and service providers of the aforementioned companies, for the purpose of processing data for marketing purposes, such as presenting news, sales promotion programs, offering benefits and promotions, advertisements, creating various campaigns, presenting and selling products, and analyzing the usage of products or services of members.
In cases where it is necessary to request a copy of your national identification card or official documents used for personal identification, or to verify your identity, the company understands well that it must obtain clear and explicit consent from you in order to process your sensitive personal data. This includes, but is not limited to, sensitive personal data such as ethnicity, religion, blood type, and any other sensitive data as defined by the law.
Once the company has obtained your explicit consent, the company will collect, use, and disclose sensitive personal data, including facial recognition data and fingerprint data, for the purpose of ensuring the safety of individuals and property, as well as for recording work attendance and other purposes.
The disclosure of your personal data.
The company will not disclose your personal data unless you provide consent or unless it is necessary to disclose or report your personal data to other individuals by law, granting the authority to do so without requiring consent or further action as required by law.
Upon obtaining your consent, the company may disclose your personal data and any related information to PTT Group Company Limited, Max Card Company Limited, Max Solutions Service Limited, including affiliated companies, subsidiaries, joint venture companies, partners, associates, and service providers of the aforementioned companies, for the purpose of processing data for marketing purposes, presenting news and information, conducting sales promotions, organizing benefits and promotions, creating various campaigns, presenting product sales, and analyzing the usage of products or services by members.
The Company may share your personal data with its affiliated companies within the group or with external parties for the purpose of conducting activities such as account auditing, seeking legal advice, pursuing legal cases, and undertaking other necessary business-related operations, as specified in this policy.
The Company may transfer personal data across international borders for the purposes specified in this policy. In such cases, the Company will take appropriate measures to ensure that the transfer complies with relevant data protection laws and that the personal data remains adequately protected.
To ensure that various operations related to your personal data adhere to the same data protection standards as mandated by Thai law, the Company will not disclose or transfer your personal data to external parties or destinations that do not provide data protection standards equivalent to those required by Thai law, unless such disclosure is permissible under the law. As an example, the Company may utilize the services of third-party Cloud providers to enhance service delivery and maintain the continuity of its services. Consequently, there may be occasions when your personal data is transferred to Cloud servers located outside of Thailand. Additionally,
The Company may also need to grant access to its information technology service providers, including those located outside the country (if applicable), to access its information technology systems, including certain personal data items of yours. The Company will implement necessary measures to ensure the security of sharing your personal data and to ensure that relevant third parties comply with appropriate standards of data protection and security as required by law. In cases where applicable laws require obtaining your consent for such actions, the Company will seek your consent as required by law.
You acknowledge and agree that the Company may transfer rights, responsibilities, and personal data to third parties and/or other businesses for various purposes, including but not limited to outsourcing certain functions, obtaining services, or complying with legal obligations, without requiring further consent from you.
You acknowledge and agree that the Company may engage in mergers, acquisitions, divestitures, business transfers, establishment of new businesses, or other activities that may result in the transfer of personal data, including the personal data of all or some of the service users, to affiliated companies, subsidiary companies, joint venture partners, or newly established businesses, without requiring further consent from you.
Data Retention, Duration, and Security Measures
The company will retain your personal data only as necessary to achieve the purposes stated in this policy. The company will assess the retention period of your personal data to ensure it is appropriate and in line with the contract duration, legal age, as well as the necessity to retain your personal data going forward, according to the statutory retention period required for establishing legal claims or exercising legal rights. The company will retain your data for a maximum of 10 years after the end of your relationship with the group of companies or from the last contact with the group of companies, whichever comes last.
The Company has established measures to ensure the appropriate security of personal data, covering various forms such as documents, electronic systems, computer systems, and tools. These measures adhere to international standards and are designed to instill confidence in the security of your personal data. They encompass prevention of loss, unauthorized access, use, alteration, modification, or unauthorized disclosure of personal data. These measures are implemented in accordance with legal authority and compliance.
The Company has implemented access limitations and utilizes technology to ensure the security of your personal data, with the aim of preventing unauthorized access or attacks on the Company's computer and electronic systems. The Company will take measures accordingly when disclosing your personal data to external parties for the purpose of processing your personal data, including data processors. Therefore, please be assured that the Company will oversee and ensure that these parties act appropriately and in compliance with instructions.
Your Rights as a Data Subject
Under the Personal Data Protection Act, as the data subject, you have the right, as provided by law, to request access to or obtain a copy of your personal data that the Company collects, uses, or discloses. You also have the right to request the transfer of your data in a structured, electronic format, as well as the right to request that your data be transmitted to another person as you desire (subject to the Company's right to impose a reasonable fee for such requests).
You have the right to object to the collection, use, or disclosure of your personal data as prescribed by law. You also have the right to request erasure or destruction of your personal data so that it becomes data that cannot identify an individual by any means. Additionally, you have the right to request the suspension of the use of your personal data, unless there are limitations imposed by law that prevent the Company from complying with your request.
Furthermore, in any instance where you have provided consent to the Company, you are entitled to withdraw that consent at any time. However, please note that the withdrawal of consent may be subject to legal or contractual limitations. Your request to withdraw consent will not affect the processing of your personal data that occurred prior to your withdrawal, as long as such processing was lawful.
The Company will undertake its best efforts to accurately and currently collect your personal data to ensure that it is complete and not misleading. You have the right to request corrections or changes to your personal data if you discover any modifications or inaccuracies in your personal data held by the Company.
Please note that the exercise of your rights as outlined above must be in accordance with the law. In doing so, the Company may reject your request based on limitations on the exercise of your rights as stipulated by the law, considering your capacity as the data subject, as provided by the law.
You have the right to file a complaint to the competent authority under the Personal Data Protection Act if the Company fails to comply with any legal obligations.
To exercise your rights, you can contact the Data Protection Officer (DPO) or the person responsible for overseeing personal data, using the contact details provided in this Policy. The Company will review your request and provide a response within 30 days from the date of receiving your request. In the event that the Company denies your request, the Company will provide reasons for such denial.
Cookies and the Use of Cookies
If you visit the Company's website, the Company may place cookies on your device and automatically collect your data. Some cookies are necessary for the website to function properly, while others are used to enhance the user experience. You can find more information about cookies in the Company's Cookies Policy [Https://www.maxme.co.th/CookiesPolicy.html]
Updating the Privacy Policy
The Company may periodically review, revise, and modify this Privacy Policy occasionally, at least once per year, to align with best practices, regulations, rules, and relevant laws. In the event of any revisions or modifications to this Privacy Policy, the Company will promptly publish the updated version on its website and other relevant channels. This is to allow you to review and acknowledge the changes through electronic means or any other appropriate methods. If you, as a user, have taken the necessary steps to acknowledge and accept these modifications, it will be considered that the amended and additional provisions of this Policy are also part of this Policy.
Supervision and Oversight in the Collection, Use, and Disclosure of Data by Data Processors
As the data controller, the Company may delegate external individuals or entities, including but not limited to, Max Card Limited and Max Solutions Service Limited, as data processors for your personal data. In this regard, the Company will provide oversight to ensure that the processors, including subprocessors (if any), are obliged to abide by this Policy and comply strictly with the Personal Data Protection Act of 2019 and relevant laws.
With respect,
PTG Energy Public Company Limited
15th November 2022
Contact Details
PTG Energy Public Company Limited 90 CW Tower A, 33rd Floor, Ratchadapisek Road, Huay Kwang Sub-District, Huay Kwang District, Bangkok 10310, Thailand
Tel: 0 2168 3377, 0 2168 3388