PraIn FinTech Company Limited (meaning PraIn FinTech Company Limited, including products that that the Company provides, such as ModernPay, ChillPay, or any other products that will be available in the future), hereinafter referred to as “Company”, has created Personal Data Protection Policy in order to inform you, the User or the Merchant who are using the Company’s services, hereinafter referred to as “User” or “Users”, the scopes and methods that the Company uses to collect, store, as well as access and manage the information that Users provide to the Company in according to the Personal Data Protection Act, B.E. 2562, herein after referred to as “PDPA”. By agreeing to use the Company’s services, Users shall be deemed to have understood, agreed, accepted, and agreed to comply with the Company’s Privacy Policy and consent to the collection of Personal Data. You may study the Privacy Policy on the Company’s website: https://www.chillpay.co The Company may change or update the Privacy Policy in the future. Therefore, the Company advises the User to often review the updated information and Privacy Policy. User’s Personal Data will not be collected, disclosed, published, or used for any other purposes other than the purposes that the Company has informed the Users, unless the Company receives a consent from the User or otherwise required by law.
To comply with the PDPA, the Company is oblieged to obtain the consent for the Company and/or the Company’s Personal Data Processors and/or government agencies and/or the private sectors to collect, use, or disclose your personal data in compliance with the laws. The Company will collect User’s information or data (collectively referred to as “Personal Data”) as follows:
In the event of obtaining additional information beyond the Company’s fundamental services, or in the case of collecting, using, or disclosing sensitive personal data other than the abovementioned, the Company shall proceed with fundamental procedures required by laws. The Company shall inform the User of such purposes and types of personal data which will be collected, used, or disclosed before or during such actions.
The Company shall collect, use, or disclose User’s personal data according to the law and for the following purposes:
In the event that there is a collection, usage, or disclosure of personal data for any other purposes beyond the above mentioned, the Company shall later inform the Users.
The Company shall collect personal data during the process of registration for services or during the usage of Company’s services.
The Company shall retain such data throughout the service period or until the services are terminated. The Company may retain the data thereafter if it is stipulated by law, such as Anti-Money Laundering Act. Or for the purpose of verifying and examining in the event that any disputes may arise, within the statute of limitation but not exceeding 10 years.
The Company shall not disclose any personal data to the third parties, or allow the third parties to do so, unless:
In order to comply with the regulations prescribed by laws, such as the Anti-Money Laundering Act or the policies of the Bank of Thailand, should the User wish to delete or amend his/her own personal data, and such cause of action is against the regulations prescribed by other laws, the Company will not be able to delete such information. As stipulated by relevant laws, the Company, as a data receiver or a Personal Data Processor, is required to detain the personal data for the period of 10 years.
The Company acknowledges and is aware of the importance of User’s personal data. The Company has therefore improved and developed the security system for your personal data to be in accordance with international standards. The Company shall do its best to comply with this Privacy Policy. The Company shall emphasize its staff, including its Personal Data Processors who are authorized to access User’s personal data or have legal liabilities, to maintain the security of User’s personal data. However, in the event that User’s personal information has been compromised by any means, such as cyber espionage by hacking, stealing, copying, destroying the database, deleting passwords, stealing of documentation, or any other means that do not performed by the Company, or loss of information due to force majeure or any other actions that do not performed by the Company, the Company has the right to deny any responsibilities resulting from such actions.
The translation of this Privacy Policy, whether translated into any languages, is only to facilitate your convenience. The Company has no intentions to change or modify its Personal Information Protection Policy. In the event of a conflict between the Thai edition and any other languages, the Thai edition shall prevail over other editions.
In the event that there is a breach of User’s personal data, the Company, at its best efforts, will inform the Office of the Personal Data Protection Committee immediately within 72 hours after the acknowledgement of such breach. Should the breach be likely to highly affect the rights and freedoms of the Users, the Company shall immediately inform such breach and the remedies to the Users through various channels, such as website, SMS, email, phonecall, or postal letter, etc.
Should the User have any concerns regarding this Privacy Policy, or wish to change or amend any personal data which User has provided to the Company, please contact the Company via email: dpo@chillpay.co, or via phone call: 02-107-7788 during Company’s business hours.