Политика конфиденциальности

PraIn Fintech Company Limited (which refers to PraIn Fintech Company Limited, including the products provided by the Company, such as ModernPay and ChillPay, as well as products to be provided in the future) (hereinafter referred to as “the Company”) recognizes the importance of personal data and other information relating to you, the service user, merchants using the Company’s services, and persons involved in the use of the Company’s services (hereinafter referred to as the “Service User”). In order for Service Users to be confident that the Company operates with transparency and accountability in collecting, using, or disclosing your data in accordance with the Personal Data Protection Act B.E. 2562 (2019) (the “Personal Data Protection Law”) and other applicable laws, the Company has prepared this Privacy Policy (the “Policy”) to inform Service Users of the purposes, scope, and manner in which the Company collects, uses, and discloses personal data, as well as accesses and manages information provided by Service Users to the Company, in compliance with the Personal Data Protection Law.

The Company may amend or revise this Privacy Policy in the future. Service Users are therefore advised to check for updates and review this Privacy Policy on a regular basis. Furthermore, Service Users’ personal data will not be collected, disclosed, made widely available, or used for any purpose other than the purposes already notified to Service Users, unless the Company has obtained the Service User’s consent or is otherwise permitted or required to do so by law.

1. Definitions

“Personal Data”  means any information relating to a natural person which enables the identification of such a person, whether directly or indirectly, but excluding the personal data of a deceased person.

“Sensitive Personal Data”  means personal data pertaining to race, ethnic origin, political opinions, cult, religious or philosophical beliefs, sexual behaviour, criminal record, health data, disability, trade union data, genetic data, biometric data (such as fingerprint or facial scans), or any other data that affects the data subject in a similar manner as announced by the Personal Data Protection Committee.

2. Types of Personal Data Collected by the Company

In order to comply with the Personal Data Protection Law, the Company may be required to obtain your consent to collect, use, or disclose your personal data to the Company and/or a person appointed by the Company as a personal data processor, and/or a government agency and/or private entity, in order to comply with the law. This will depend on the service you use, the context of your relationship with the Company, and other relevant considerations affecting the collection of personal data. The categories of data set out below represent only a general framework for the Company’s collection of personal data. The Company will collect the following data of Service Users (“Personal Data”):

(a)  Personal information, such as first name, last name, date of birth, place of birth, marital status, photographs, video footage, signature, information appearing on a national identification card or passport, a copy of an identification card, and identification card number, among others.

(b)  Contact information, such as address, telephone number, LINE ID, social media contact channels, and place of work, among others.

(c)  Security-related information, such as CCTV footage and information identifying a person’s assets, such as a vehicle and its registration number, in the case of entry onto the Company’s premises, among others.

(d)  Employment and education information, such as job title, the organization for which you work, educational background, employment history, and training courses completed, among others.

(e)  Financial information, such as records of transactions carried out through the ModernPay and ChillPay systems or the Company’s other services, credit card information, bank account information, deposit account information, e-Wallet information, and other information held with banks or financial institutions by the Service User, among others.

(f)  Information relating to access to and use of electronic systems connected with the Company, such as email address, IP address, geolocation, browser type, log files, cookies, and in-application chat history, as well as comments or mentions of the Company or the Company’s business on the internet or other channels, among others.

(g)  Information you provide when contacting, or participating in any activity with, the Company, including video recordings, audio recordings, comments, satisfaction feedback, and suggestions provided in connection with the Company’s operations or your participation in the Company’s activities, among others.

(h)  Information relating to social relationships, such as your political status, holding of political office, or holding a directorship, among others.

(i)  Information relating to your use of the Company’s services, or other information specified in the service agreement with the Company, or information necessary for verification and operational purposes.

(j)  Information relating to the devices used to access the Company’s services, such as computers, mobile phones, and POS (Point of Sale) terminals, including Unique Device Identifiers and IP addresses used to identify devices connected to a network, information regarding the device’s operating system, mobile network operator, location, and cookies.

(k)  Sensitive personal data, such as health data, disability data, biometric data, and data used to assess behaviour, attitude, and aptitude.

With respect to the sensitive personal data described above, the Company will obtain your consent for the collection and processing of such sensitive personal data, unless the Personal Data Protection Law authorizes the collection of sensitive personal data without consent.

Identity Verification: The Company wishes to inform you that where the Company requires a copy of an identity document, such as a national identification card, passport, or other document, which may contain sensitive personal data such as religion or blood type, the Company has no intention of collecting such data. The Company therefore requests that you cross out or otherwise obscure such information. If you fail to do so, the Company shall be deemed to have your permission to conceal such information itself, and the document shall remain fully valid and enforceable in every respect. Where the Company is unable to conceal such information due to certain limitations, the Company confirms that the collection and use of such document is solely for the purpose of identity verification, and the Company has no intention of collecting or using any sensitive personal data appearing in such document.

3. Purposes of Collecting Personal Data

The Company will collect, use, or disclose the personal data of Service Users on the legal bases and for the purposes set out below:

  1. To carry out actions requested by the Service User prior to entering into a contract, including matters necessary for the performance of a contract to which the Service User is a party, such as:

–  Considering registration applications for the use of products provided by the Company, such as ModernPay and ChillPay, including products to be provided in the future;

–  Providing assistance, responding to inquiries, handling requests, providing information, or responding to questions regarding the service;

–  Developing and improving the quality and efficiency of the service, and providing convenience to Service Users;

–  Processing data for the purpose of providing the service, or any other matter necessary to provide the best possible service to Service Users.

  1. To comply with legal duties, regulations, rules, or guidelines issued by government agencies or regulatory authorities, such as the Bank of Thailand and the Anti-Money Laundering Act, among others. The Company may transmit your personal data to internal/external auditors, government agencies, or other relevant persons or juristic persons, in accordance with the Company’s Know Your Customer/Customer Due Diligence (KYC/CDD) policy under the Anti-Money Laundering Act.
  2. For the purpose of providing news or information, marketing and sales promotion, or offers relating to benefits, products, and services; or for the collection and use of data for statistical or research purposes, analysis, or evaluation; or for managing the business needs of the Company, the Company’s business partners, or its affiliated companies; as well as for any other purpose that the Company considers may be of benefit to the Service User. The Service User agrees and consents to the Company carrying out checks and/or exchanging data and/or disclosing data to any person and/or juristic person, including the group of affiliated companies and/or other persons bound by a data protection agreement with the Company, and the Service User shall not claim any compensation from the Company in this regard.
  3. For the prevention of crime and fraud, and to maintain the security of systems and networks in line with international standards.

Where the Company collects, uses, or discloses personal data for any purpose other than those stated above, the Company will notify the Service User accordingly at a later time. The Company will collect, use, and disclose your personal data upon obtaining your consent, unless the Personal Data Protection Law authorizes the Company to do so without consent, for the legitimate interests of the Company or of another person or juristic person.

4. Collection of Personal Data

In collecting personal data directly from the data subject, and in using or disclosing such personal data, the Company will obtain the data subject’s consent before or at the time of collection, where consent is required by law, and will process the personal data only to the extent necessary to achieve the purposes expressly specified by the Company.

The Company may also collect personal data obtained from sources other than the data subject directly, but only where necessary and by means permitted by law, such as from relevant service providers or public media, among others.

5. Data Retention Period

The Company will retain your personal data for as long as is necessary to fulfil the purposes of collecting, using, and disclosing personal data set out in this notice. The criteria used to determine the retention period include the period during which the Company continues to have a relationship with you, and the data may continue to be retained thereafter where required by law, such as under the law on the prevention and suppression of money laundering, or for the purpose of proving or verifying facts in the event of a possible dispute, within the limitation period prescribed by law, for a period not exceeding 10 years.

6. Disclosure of Personal Data

The Company may need to disclose personal data in the following circumstances:

–  To comply with legal provisions or a court order, or where the Company has been notified to investigate a transaction suspected of being fraudulent by a person involved in the provision of the service or a customer;

–  Disclosure to employees, staff, directors, and advisors involved in the provision of the service;

–  Where the Company has obtained the consent of the data subject, or the data subject has requested such disclosure;

–  Disclosure to the Company’s auditors, external examiners, government agencies, assignees of claims, and any other person or juristic person to whom the Company is required to provide personal data in order to comply with the law;

–  Disclosure to a juristic person that controls the Company or is controlled by the Company, including companies under common control with the Company, or any other person with whom the Company has a contractual or other legal relationship, including other service providers authorized to carry out any action with respect to the personal data of Service Users, whether within or outside Thailand, such as external service providers, financial institutions, or other business partners of the Company;

–  The transferee of a business or undertaking, in the event that the Company undergoes a merger, or transfers or sells assets and/or the whole or part of its business.

Where personal data must be transferred abroad, the Company will strictly comply with the requirements of the Personal Data Protection Law.

7. Rights as a Data Subject

As a data subject, you have the following rights under the Personal Data Protection Law:

  1. The right to withdraw consent, as provided by law;
  2. The right to request access to your personal data;
  3. The right to request the receipt, sending, or transfer of your personal data;
  4. The right to object to the collection, use, or disclosure of your personal data;
  5. The right to request the deletion or destruction of your personal data;
  6. The right to request the restriction of the use of your personal data;
  7. The right to request the rectification of your personal data to make it accurate, complete, and up to date;
  8. The right to be informed of any amendment to the notice concerning your personal data;
  9. The right to lodge a complaint with the Office of the Personal Data Protection Committee.

Where a data subject submits a request to exercise any of the above rights, the Company will process the request within the period prescribed by law. The Company reserves the right, however, to refuse or decline to act on such a request in circumstances permitted by law, such as under the Anti-Money Laundering Act or the regulations of the Bank of Thailand, where the grounds for the request conflict with the requirements of other applicable laws. In such cases, the Company will not be able to delete the relevant data, because applicable laws require the Company, as the recipient or processor of the data, to retain personal data for a period of 10 years.

8. Use of Cookies

The Company’s website may use cookies and related technologies to help the website function efficiently, to analyze usage, and to improve your user experience. For further details, please refer to the Company’s Cookie Policy.

9. Data Security

The Company acknowledges and recognizes the importance of Service Users’ personal data. The Company has accordingly continuously improved and developed its personal data security systems to keep them aligned with international security standards. The Company will use its best endeavours to comply with this Personal Data Protection Policy, and places strong emphasis on its personnel, including personal data processors engaged by the Company who have access to personal data or duties under the law, maintaining the security of Service Users’ personal data.

10. Language

Any translation of this Personal Data Protection Policy, into whatever language, is provided solely for your convenience and is not intended to alter this Personal Data Protection Policy in any respect. In the event of any inconsistency between the Thai language version and any version in a language other than Thai, the Thai language version shall prevail.

11. Amendment of the Personal Data Protection Policy

The Company may consider amending, revising, or changing this Policy as it deems appropriate, and will notify you via its website (https://www.chillpay.co), with the effective date of each amended version indicated. Nevertheless, the Company recommends that you check regularly so as to be aware of any new version of the Policy before disclosing personal data to the Company.

Continued use of the Company’s products or services after a new Policy takes effect shall be deemed acceptance of the terms of the new Policy. If you do not agree with the contents of this Policy, please discontinue use of the service and contact the Company to clarify the relevant facts.

12. Contact

If you have any questions regarding this Privacy Policy, or wish to exercise your rights as a data subject, you may contact the Company as follows:

PraIn Fintech Company Limited

Email: help@chillpay.co

Telephone: 02-107-7788

Business days and hours: Monday – Friday, 8:00 a.m. – 5:00 p.m.

Website: https://www.chillpay.co

The Company will consider your request to exercise your rights in accordance with the criteria and time period prescribed by law.

Effective date: 1 September 2026

Last updated: 1 September 2026

Scroll to Top