Privacy Notice
Effective on August 2024
Bank of Ayudhya Public Company Limited and its financial group of companies, whose names appear in the attachment to this Privacy Notice, , (collectively, ‘Krungsri Group’ or ‘we’) have recognised the importance of your personal data and have prepared this Privacy Notice (this “Notice”) to inform about Krungsri Group's collection, use, disclosure, or transfer of your personal data including other data relating to you (collectively ‘Data’).
A. To whom does this Notice apply
This Notice applies to third parties that we have relationships with, including the procedures of existing and future transactions with the third parties, whose personal data we collect, use, disclose, or transfer in the course of our normal business or about the products and services we provide (for example, savings account opening service, credit card service, loan service, personal loan service, insurance brokerage service, hire purchase service, leasing service, funds service, securities service) (“Products and Services”), depending on the type of Products and Services that the third parties may apply for or request from Krungsri Group, which includes:
(1) individuals, including business operators who are individuals;
(2) partners and service providers who are individuals;
(3) board of directors, representatives, shareholders, agents, employees, and other persons in a similar capacity (collectively,“Connected Persons”) of:
(a) juristic persons and their affiliates which are customers of Krungsri Group including corporate operators;
(b) business partners of Krungsri Group (such as bond issuers, insurance companies, and representatives of financial institutions);
(c) partners or service providers which are juristic persons including other juristic persons who offer Products and Services to Krungsri Group;
(d) affiliates of Krungsri Group and other juristic person participating or intend to participate in or in relation to any project(s) in which related to investment or business operations including investment partners with affiliates of Krungsri Group;
in this Notice, persons described in (b) (c) and (d) are collectively called “Business Partners”,
(4) users and recipients of the Products and Services;
(5) visitors and users of our websites, including mobile applications, computer devices, and other channels of communication; and
(6) any other persons whose personal data we obtain (such as directors, representatives, shareholders, agents, employees and/or any other persons who have the same position in a company where Krungsri Group invests or makes a transaction, shareholders of companies in Krungsri Group and their proxies, individual guarantors and participants in a public auction and questionnaire respondents).
Persons described in (1) to (6) are collectively called “you”.
B. Changes to this Notice
This Notice, including the name list of Krungsri Group companies in the attachment to this Notice, may be amended or updated from time to time. This is to reflect changes in our practices or policies with respect to the collection, use, disclosure and/or transfer of personal data, or changes in applicable law. Krungsri Group will notify you of such changes to ensure that you have adequate information on the changes. We also encourage you to read this Notice carefully, and to regularly check and review any changes we might make to this Notice.
C. How we collect, use, disclose and/or transfer and protect your Data
The purpose of this Notice is to describe in detail how we collect, use, disclose, and/or transfer your Data. This Notice informs you the rights and options as a data subject with respect to your Data, and our contact details when you have any inquiries.
1. Personal data that we collect
1.1 Categories of personal data
“Personal data” means any identifiable data relating to you. If there is any data which can be combined with your Data, or other data which is used to prepare a profile of an individual, we will deem that such data is personal data.
Krungsri Group may collect or obtain the following categories of data which may include your Personal Data, depending on the context of your relationship with us and the type of data subject you are.
(1) You as an individual
Category of personal data | Description and examples |
---|---|
Name and initials |
Your data you are known of, addressed, or referred to such as title, first name, initial, middle name, last name, previous last name, aliases or previous names, signature |
Personal characteristics |
Your personal characteristics such as age, date of birth, gender, height, weight, marital status, number of children, nationality, country of birth, citizenship and status, military details, leisure and interests, photographs, language skills, travel details, voice recording, data about behaviours and preferences of users |
Contact details |
Your contact details such as home postal address or work address, contact address, home or work telephone and facsimile number, e-mail address, mobile or wireless number, social media profile, household registration, main country of residence, types of residences (e.g., house ownership, welfare housing, house rent and rentals), residences of foreigners in home country, maps showing residences and workplace |
Educational details |
Your educational and professional details such as degrees and schooling, academic records, licenses, professional membership (e.g., member of the Lawyers Council, member of the Engineering Institute of Thailand and member of the Medical Council) |
Employment details |
Your employment details, status, and history such as occupation, title, position, function, employer identification number, job code, corporate held credit/debit card, work visa status/employment authorization details, reference and background checks (excluding criminal records), taxpayer identification number, employee identification number, insurance claims, workers compensation claims, employment records (including salary, attendance, and benefits), recruitment date, work termination, assets in possession of the employee, previous workplace, your workplace or places where you are employed or in which you hold shares, reviews (e.g., potential and performance reviews) including technological evaluation and the use of technology (e.g., internet, email) |
Government-issued identification details |
A number or details given to you by competent authority to identify who you are such as national identification number, driver's license number, operation's license number, vehicle registration number, professional license number, passport number, foreigner registration number, house registration details, social security number and any other identification numbers issued by the government |
Financial and transaction details |
Financial and transaction details such as
|
Credit/ debit card details |
Your credit card details such as number of credit cards you hold, credit card/debit card number, cardholder name, expiration date, CVV, CVC2, CID number, PIN number, sort code, issuance date, issuing banks, types of credit card |
Insurance policy details |
Your data related to pre-existing and current insurance including related terms and conditions such as insurer, policy number, policy type (e.g., life insurance, health insurance, automotive insurance, property insurance, travel insurance, and business insurance), coverages, limits, exposure, claims-related data, data related to insured property (e.g., house and vehicle), driving data, price and quantity, insurance policy number, broker number, conditions (if any), payment and transaction records relating to the client's insurance policy, financial statements, taxes, revenues, income, and default record |
Social relationship details |
Your social relationship details such as political status, relationship with directors, management, and persons with controlling power of Krungsri Group, relationship with other juristic persons (e.g., directorship, management, shareholding), and other relationships |
Segmentation attributes details |
Segmentation attributes details such as household age indicator, designated market area code, estimated income identified, number of persons in the household, number of cars owned, college education, dwelling type and number of audiences |
Products and Services details |
Details about Products and Services which we provide to you such as
relating to transactions of mutual funds, tax deductions of dividends, objectives of mutual fund account opening, and details contained in mutual fund subscription forms including unitholder numbers, subscription date, names of funds, subscription amounts, cheque numbers), membership number (e.g., provident fund membership), types of services (e.g., mutual fund services), number of investment units, details of transfer (e.g., funds for which the transfer is applied and the amount of investments to be transferred), any information on the investment risk profiling questionnaire (including an investment knowledge, risk tolerance, experience in securities investment, investment plans and views);
|
Vehicle or collateral details |
Details about your vehicles or collaterals such as appraised price/estimate evaluation cost, vehicle brand, model, manufactured year, year of registration, license plate number, province of registration, chassis number, engine number, miles record, any attached obligation to vehicles, and/or other details in accordance with the registration document (e.g., engine power/CC), certificate of ownership or land ownership (e.g., land title deed, buy and sale agreement, etc.) |
Online usage details including technical data and data collected via devices |
Details about the use of online and technical data and data collected via devices such as
|
Behaviours, preferences, views, inquiries, and opinions details |
Details relating to behaviours, preferences, views, inquiries, and opinions such as data relating to the use of Products and Services that you are interested in, other information that you choose to send to us (including on or via social media platforms or online surveys), comments, feedback, complaints, recommendations, survey responses, inquiries, and any data you have voluntarily given during marketing or customer service-related communications, including your Data that is disclosed on your social media profiles |
Data in compliance to FATCA (Foreign Account Tax Compliance Act) of the United States of America and and ROYAL DECREE: The Exchange of Information for the Implementations Under the International Agreement on Taxation (Common Reporting Standard: CRS) |
Data in compliance to FATCA such as whether you have the nationality or birthplace that is linked to the United States of America, whether you have legally surrendered American citizenship, you hold an American Permanent Resident Card, you have an obligation to pay tax to the American Revenue Department, you have a current U.S. residence address, U.S. mail address, or U.S. telephone number for contacting you or another person related to the account opened or held with Krungsri Group. |
Provision of Products and Services details including our interaction with you |
Provision of Products and Services details including our interaction with you such as telephone conversation logs between you and Krungsri Group, voice records, call notes (open text fields), co-pay/ financial assistance, terminal ID, data which is subject to litigation holds or eDiscovery, data to be retained for litigation purposes |
Sensitive personal data |
Sensitive personal data such as criminal records, religion data, disabili- ty data, biometric data (such as facial and fingerprint data) |
(2) You as a Connected Person
Category of personal data | Description and examples |
---|---|
Identity data |
Your identity data such as first name, middle name, last name, age, employment information, government-issued ID numbers (e.g., national ID number, driver's license number, ID for professional licenses, passport number, foreigner registration number, tax identification number, social security number), work-related information (e.g., position, function, occupation, job title, company you work for, are employed or hold shares of), nationality, and signature |
Contact data through different channels |
Your contact data through different channels such as phone number, email address, social media account ID, chat ID, address |
If you do not provide your Data, Krungsri Group may not be able to provide you with the Products and Services you request or may not meet our certain obligations to you, or we cannot comply with our legal obligations.
Personal data of third parties
You are responsible for notifying third parties of the details of this Notice, and obtaining any required consent from them (where consent is required) if you give us their personal data. In addition, you must also ensure that we can lawfully collect, use, disclose, or transfer those third parties' personal data as set out in this Notice depending on the companies in Krungsri Group that you have interacted with and gave their Data to. Examples of personal data includes:
• name, family name, age, gender, postal/email address, telephone number, identification number, passport number;
• financial documents, salary, work-related information (e.g., position, function, occupation, job title, company he/she works for, is employed at, or holds shares of);
• relationship with director of, management of and a person having controlling power over Krungsri Group, relationship with other corporate entities (e.g., as a director, management and shareholder), information of persons with the controlling power of funds including the assignees, beneficiaries, information of ultimate beneficiary owners, company's board/ directors/shareholders/representatives of juristic person/chief managers, other persons who can dictate policies or possess executive power in an organization;
• relationship with you and political status such as relatives who hold political status;
• your family members, joint account holders, spouse/former spouse, data relating to your children (such as their titles, name, family name, age, gender, government-issued identification number, address, e-mail address and activities relating to them), next of kin, housing ownership;
• estate administrator/executor’s information, joint account holders’ information, information of witness, information of the assignee of the power of attorney;
• authorized person, information relating to witnesses and assignees under a Power of Attorney, contact person, insurance premium payer, authorized signatory/withdrawer of deposit account, guarantors, reference person, customers of the third parties;
• pledgers/pledgees, mortgagers/mortgagees, lessors/lessees, registrars for property being placed by you as collateral, your debtors, transferee/recipient of the funds, the payee, employer;
• contact person for debt collection, or you ask us to disclose their personal data to other third parties;
• in some cases, we may have inevitably received or accessed personal data about other persons through other sources, such as via Single Form on KSAM's FundConnext platform , in which we do not require such personal data in offering our Products and Services.
Personal data of minors, incompetent persons, and quasi-incompetent persons
If Krungsri Group has acknowledged that we need to obtain consent from data subjects who are minors and cannot lawfully give consent by themselves, we will not collect their Data until the consent of the persons exercising parental power is obtained. In addition, we will not collect any Data from quasi-incompetent persons or incompetent persons until the consent of their legal curators and guardians is obtained (as the case may be).
If Krungsri Group has not acknowledged that the data subjects are minors, quasi-incompetent persons or incompetent persons prior to the collection of their personal data, upon learning that we have collected personal data of minors without the consent of persons exercising parental power (when it is required and the minors cannot lawfully give consent by themselves), or from quasi-incompetent persons and incompetent persons without the consent of their legal curator and guardian, we will delete the personal data at the earliest convenience unless we can rely on other legal bases apart from consent.
Cookies
As part of the security procedure for our services and user experiences in using our Products and Services, cookies and such other systems may be used and may be placed on your device, depending on the company in Krungsri Group that you have interacted with. In general, information gathered using cookies is not linked to any identifiable data (e.g., your name or e-mail). However, if we may need to link your personal data with cookies or other data that is associated with your use of our Products and Services, we will treat cookies and combined data as personal data.
1.2 Collection of your Data
Krungsri Group may collect your Data in various ways (depending on the company in Krungsri Group that you have interacted with), including:
(1) Through the service channels: we may collect your Data directly from you both via online and offline channels (e.g., via branches or offices of Krungsri Group, interviews, post, ATMs, messengers) or via telecommunications such as telephones, e-mails, websites, applications, Krungsri Internet Banking Laos (KIBL), online social network platforms (e.g., Line and Facebook), and other promotional and marketing channels.
(2) From sources other than through the service channels: we may collect your Data from other sources such as when you contact Krungsri Group before carrying out transactions, applying for Products and Services of Krungsri Group, requesting for pitching documents or proposals, participating in transactions or entering into contracts (regardless of the channels through which the contacts are made and personal data is given such as through Krungsri Group branches, electronic platforms, online social networks, Krungsri Group’s official LINE account) or data obtained from the data room relating to transactions.
(3) Other sources: we may collect your Data from other sources such as public sources and/or through our parent company and affiliates (e.g., service providers engaged by us to collect personal data on our behalf), our Business Partners (such as co-branded companies, or companies participating or intend to participate in projects in or in relation to investment or business operations with affiliates of Krungsri Group, or insurance companies for insurance related purposes or FundConnext platform), the entities to which we invest or make a transaction, the entities to which we provide the Services (including their websites, online social networking profiles), government sources, government agencies holding a reliable database of individuals, government authorities (e.g., the Bank of Thailand, the Revenue Department, the Anti-Money Laundering Office, the Office of Insurance Commission, the Legal Execution Department, the Ministry of Commerce, the Office of Securities and Exchange Commission, the Department of Lands,), courts, and from other third parties (e.g., referral persons, your representatives or other parties who are persons who were ultimately given 5ower of attorney from you).
2. Legal bases and why we collect, use, disclose, or transfer your Data
2.1. Legal bases we may rely on
Krungsri Group will determine our legal bases for the collection, use, disclosure, or transfer of your Data, as appropriate, depending on the company in Krungsri Group that you have interacted with. In most cases, the legal bases which we mainly rely on are any of the following:
Legal bases | Description |
---|---|
Contractual basis |
To allow us to perform obligations and/or actions that are necessary for entering into contract with you and/or for providing you with the Products and Services you require under the contracts between you and Krungsri Group (for example, to allow you to make and receive payments using a credit card issued by us, to lend you the amount of money based on your loan contract with us, to assist you with payments relating to insurance policies, etc.), and to perform obligations under contracts. |
Legal obligations |
To allow us to meet our legal obligations (for example, obtaining proof of your identity to meet our obligations under anti-money laundering laws of Krungsri Group and disclosing to the National Credit Bureau (NCB) per our obligations under the credit information laws and the Foreign Account Tax Compliance Act: FATCA). |
Legitimate interests |
To pursue our and others’ legitimate interests (such as to understand how customers use our Services and develop new services, to improve to be new services we currently provide, to run a sales promotion or publicize Products and Services including beneficial privileges that are on your expectation and processing it within each entity of Krungsri Group, to detect and prevent fraud), to administer systems and services for collection and write-off management. |
Vital interest |
To prevent or suppress a danger to your life, body, or health. |
Consent |
To collect, use, disclose, or transfer your Data if your consent is required, such as for promoting sales or publicizing the Products and Services including beneficial privileges. and we cannot rely on another lawful basis. |
If Krungsri Group is required to collect your Data for fulfilling contractual or legal obligations, Krungsri Group may not provide you with the requested services or take the requested steps and you do not provide us with your Data.
2.2. The purposes for which we collect your Data
Krungsri Group have collected your Data for various purposes, depending on the company in Krungsri Group that you have interacted with or entered into transactions with, Products and Services you have obtained from us, including the nature of relationships between you and our Business Partners and/or any other consideration in each specific context. Kindly note that the purposes listed below only set out the general framework of the use of Data by Krungsri Group on the date that this Notice has been prepared and only purposes relating to you will be applicable.
(1) Pre-enrollment and customer onboarding
Purposes | Description |
---|---|
Identification and verification |
To conduct your identity and signature verification, such as when you apply for the Products and Services of Krungsri Group or our affiliates/ Business Partners or when entering into agreements and transactions with you, to enable you to apply for and obtain the Products and Services, to verify your login credentials, to verify your location for allowing you to access your accounts or to conduct online transactions by using provided channels, to create your electronic signature, to verify your identity when you contact us for requesting to obtain customer-related Products and Services through the provided channels (such as branches of Krungsri Group, telephone, e-mail, LINE account, mobile application and website), and to compile security questions for identity verification processes. |
Quotation and onboarding |
To provide you with insurance premium quotation and process quotation or proposals about Krungsri Group’s Products and Services that you may be interested, apply, or requested for, to process quotation, registration, and applications for customer on-boarding, to assist you in applying for and receiving Products and Services. |
Eligibility assessment, approval, and rejection |
|
Due diligence | • To carry out the processes and steps of customer identification and other security risk checks (including, “know your customer” (KYC), and other risks and security checks, to verify customer's identity and status, to check the data or to conduct background checks in other ways or to identify risks relating to you and/or customers (such as Know Your Customer (KYC), "customer due diligence" (CDD), anti-money laundering, to conduct Related Parties Transaction (RPT) checks, Foreign Account Tax Compliance Act (FACTA), to check your Data which you provided to Krungsri Group against the blacklist data- base, to conduct other due diligence and verification requirements against the public database of law enforcement agencies and/or sanction lists under the law and other relevant lists, including to comply with sanctions, procedures or rules, to verify your relationship with politicians, to carry out financial transactions and payment services, including to carry out transaction checks;
• To check and assure the documents delivered by you, including the eligibility and qualification for obtaining Products and Services, to verify your eligibility for application for obtaining Products and Services of Krungsri Group, such as account opening, loan request, to evaluate your loan information, to inspect the registration manual before a loan can be drawn; • To check the conflict and other necessary onboarding and ongoing customer checks; • To carry out tax reporting and regulatory reporting; • To check customer data for the purpose of improving and managing customer data of Krungsri Group's customer to be up to date; • To carry out verification and cancellation, to check your account opening documents or to provide Products and Services (such as private funds). |
Risk assessment and management | • To assess risks based on your profile and information obtained to determine eligibility for Products and Services, to evaluate your application or eligibility for Services and to conduct an on-going risk assessment;
• To carry out your risk profiling based on determined criteria (such as sanction list, bankruptcy record); • To deal with active intra-group risk management pursuant to which risks in terms of markets, credit, default, processes, liquidity, and image, as well as operational and legal risks must be identified, limited, and monitored; • To carry out risk management of the group companies in compliance with the rules and regulations of The Japanese Financial Service Agency (JFSA) regulated over the parent companies overseas and in compliance with the rules of the Basel Committee on Banking Supervision (BCBS) |
Selection of Business Partners and Partners | To carry out due diligence and verify on you and status of Business Partners and partners, other due diligence (Business Partner Due Diligence / Third Party Due Diligence / Know Your Third Party) and/or background check or to identify risks relating to you and Business Partners and partners (such as Know Your Third Party (KYTP), Third Party Due Diligence, anti-money laundering, to conduct Related Parties Transaction (RPT) checks, Foreign Account Tax Compliance Act (FACTA), to check your Data which you provided to Krungsri Group against the blacklist database, to conduct other due diligence and verification requirements against the public database of law enforcement agencies and/or sanction lists under the law and other relevant lists, including to comply with sanctions, procedures or rules, to verify your relationship with politicians, to carry out financial transactions and payment services, including to carry out transaction checks), to assess eligibility and qualifications of you, Business Partners, partners, and personnel in working for Krungsri Group, requesting for quotations or participating in a bidding process, due diligence on documents received by Krungsri Group (such as company’s affidavit, updated list/ identification card of shareholders and the authorized director of the Company), registration of, negotiation of and entering into contract or transaction with you, partners and/or Business Partners. |
(2) Providing and managing the Products and Services
Purposes | Description |
---|---|
Provision of the Products and Services |
To perform obligations under our agreements such as to perform the following purposes:
|
Processing of transactions and/or payments |
Processing of transactions and/or payments for the following purposes:
|
Debt collection | Proceed with debt collection for the following purposes:
|
Data modification and maintenance | To modify and maintain data for the following purposes:
• to enter your information, to manage customer database and other relevant records for Krungsri Group’s Products and Services, to make customers’ records / data up-to-date, accurate and complete, to make copies of documents relating to sources of income, to keep records of business transactions, and to manage and maintain the business of Krungsri Group; • to take other steps to maintain data including restrict data processing procedures, keep records of contracts and other documents referring to you; |
Customer care services | To perform customer care services for the following purposes:
• to conduct welcome calls, to handle your complaints, to respond to and fulfill your inquiries or requests regarding the Products and Services we provide, to accept any comment/complaint, to investigate the issues you face and provide you with solutions; • to administer accounts, to make plans, take steps and manage relationships (contractual) with you; • to provide customer service in relation to lost, broken, or stolen or non-received cards, to suspend and cancel cards, to replace cards, to consider your fee waiving request; • to send gifts or premiums, and other customer service-related activities. |
Advertising marketing, communication of news, announcements and other data in relation to Products and Services | To advertise marketing, communicate news, announcements and other data in relation to Products and Services for the following purposes:
• to keep you updated on our news, communications, announcements and other forms of information on our existing or new Products and Services and/or those of our affiliates, financial business group, business partners and other entities whom we have relationship with (collectively, "Related Products and Services" for the purpose of this clause), to contact or otherwise inform you about information on the Related Products and Services which we believe may be of interest to you or the entity you work for via appropriate contact channels (such as mails, e-mails, text messages, telephone calls); • to provide you with privileges and special offers for the Related Products and Services, to create and display online advertisements of the Related Products and Services via various channels (including, on social media platforms, instant messaging applications e.g., Facebook. Google, Line and Instagram), to target our customers for our Related Products and Services offers or promotions tailored to our customers' interests; • to conduct market analysis and research, to analyse customers’ behaviours and segmentation, to analyse and target other anonymous individuals who may share similar characteristics (Lookalike), to operate loyalty programs, referral programs, and other similar schemes and campaigns, including marketing and sales schemes and campaigns, to announce award and/or lucky draw prize, to evaluate or improve the effectiveness of our marketing efforts and campaigns, to manage customer relationships and engagement, to carry out promotion planning, organising, conduct meetings and seminars, and visit Krungsri Group |
(3) Services improvement
Purposes | Description |
---|---|
Service Reports |
To prepare and circulate (both internally and externally) reports on the provided Products and Services (including, reports on performance, services performance, sales, customer contact results, settlements for merchants and card network companies, collateral appraisals), to prepare reports required by competent authorities, analytical reports (e.g., for inactive customers for initiating sales campaigns), and other reporting activities for our business purposes |
Improvement of services |
To improve our existing Products and Services, to develop and test our new Products and Services including those from our Business Partners, to develop new ways of offering our Products and Services to best suit your needs and to grow our business, to analyse data for system improvement (e.g., to develop a model of customer segmentation for enhanced efficiency in providing the Products and Services), to conduct customer satisfaction surveys or of other person from which Krungsri Group receive personal data (such as questionnaire respondents), to conduct surveys on our staff's performance, to analyse usage trends, to personalize and optimize your best experiences with our products and Services (e.g., our mobile applications, websites), to recognize you across different browsers and devices you use, to conduct the Products and Service performance monitoring and analysis |
Conduct of data analytics |
|
Krungsri Group's websites and platforms usage |
To maintain, use, follow up, inspect, and manage websites and platforms (including mobile applications) to facilitate and allow appropriate, efficient, and safe use of websites and platforms of Krungsri Group, to improve Krungsri Group’s website and platform layouts and contents to enable you to access systems of Krungsri Group and to provide technical support to you |
(4) Technological system management, fraud prevention, legal compliance, and data protection
Purposes | Description |
---|---|
Detection and prevention of fraud including data protection |
To find, detect and prevent fraud risk, and resolve fraudulent activities, fraudulent transactions, deception, and fraudulent applications, to identify, follow up, investigate, verify, and control logs of network activities, to take other steps to prevent activities aimed to cause damage, fraud, or illegal activities including activities relating to data maintenance, to identify security events, to investigate security issues of data, to protect security for life, health, property, and other rights of persons, to assist with crime prevention |
Technological system management |
|
Compliance with law and dispute resolution |
To comply with applicable laws (including, any subordinate laws, legal or regulatory guidance, codes of conduct, orders, opinions, interpretations, our and our affiliates' internal policies), to sue, defend against, participate in or otherwise respond to civil, criminal, or regulatory lawsuits, subpoenas, legal processes, legal execution processes, regulatory requirements, law enforcement requirements, to exercise our legal rights or defend against legal claims (including, for debt collections and recoveries on overdue accounts), to address complaints and disputes, to comply with regulatory requirements, for investigations and other forms of interaction with government authorities, or to comply with orders of government authorities which may include orders from authorities outside of Thailand and/or to cooperate with courts, regulatory authorities, government officials, and law enforcement agencies when Krungsri Group has reasonable grounds to believe that it has lawful duties to do so, and when it is necessary to disclose your Data to comply with the law, to resolve disputes, to report on credits, to deposit your assets at the Department of Legal Execution instead of performance of obligations |
(5) Managing Krungsri Group's businesses
Purposes | Description |
---|---|
Business management |
To operate our businesses, including without limitations, to strategize and devise plan for our business and for our financial; to add and test systems and processes, to manage internal administration; to follow up and make references (such as when we receive your request), to archive data (e.g. backup and archiving in separate databases), to comply with our IT policies, to ensure business continuity and the availability of systems, to perform our contractual obligations to which we are party(such as contracts with our business partners, service providers or other asset management companies), or under which we are acting as a broker or an agent; to perform risk control, to practice corporate governance, to manage finance, accounting and tax, to audit and administer the business, to comply with the regulation, including internal control requirements and internal audits, to comply with internal policies and procedures in accordance with the internal rules of corporate governance and good governance practices. |
Corporate transactions |
In the event of sales, transfers, mergers, reorganizations, or similar events, Krungsri Group must disclose and transfer your Data to one or more third parties as part of that transaction. |
Supply of Products and Services and communication about business operations(This objective applies when Krungsri Group collects your Data as Connected Persons) |
• to purchase Products and Services from Business Partners of Krungsri Group (such as to create and deliver purchase orders to you or to Business Partners), to contact you when you or Business Partners sell Products and Services to Krungsri Group, to take steps about payment, to plan, to perform and to manage contractual relationship with you or Business Partners, to supervise performance of contracts and compliance with policies of Krungsri Group or Business Partners and to comply with internal regulations of Krungsri Group’s affiliates (including to investigate and correct non-compliance with such regulations or policies);
|
(6) Relationships with shareholders of companies in Krungsri Group
Purposes | Description |
---|---|
Management relating to shareholders of companies in Krungsri Group |
To verify identity and signature such as when you contact, carry out transactions, exercise your statutory rights as a shareholder of Krungsri Group companies or when you exercise rights on behalf of shareholders To manage shareholders’ meeting, to attend shareholders’ meetings, to exercise votes, to abstain from voting, to issue/transfer share certificates, to sell shares, shareholders’ register, or other relevant documents. |
2.3. Sensitive Personal Data
Krungsri Group will only collect, use, or disclose sensitive personal data based on your explicit consent, for establishment, defence, compliance with or exercise of legal claims, for satisfying legal obligations in relation to substantial public interests or otherwise as permitted by law. Where consent is required, we will separately ask for your consent using the appropriate means. Categories of sensitive personal data that we may collect from you depend on factors including which Krungsri Group companies that you may contact.
Categories of sensitive personal data | Purposes |
---|---|
Criminal Records | To collect and use your criminal records for detecting, preventing, and prosecuting unlawful acts and fraudulent conduct and for compliance with the requirements of applicable laws and regulations. |
Biometric data | We need to collect and use your biometric data (e.g., your facial and fingerprint data) for customer identity verification, for underwriting processes for credit card issuance and/or personal loan approval, and/or for underwriting and loan approval processes for hire purchase, leasing and loan for authentication, for applying, accessing and/or taking any other steps to use the Products and Services of Krungsri Group (e.g., by accessing or opening an account via our mobile application or at our branch) |
Religion data | In general, we do not require religion data from you in offering our Products and Services. In practice, however, we may inevitably receive religion data from you (e.g., by a scanned copy of your national identification card accompanying agreements, Products and Service applications or for verifying identity of business partners, individuals, directors, shareholders, and authorized directors of a company). In such a case, we will protect your religion data under the applicable laws. |
Disability data | If you have a disability, Krungsri Group may collect, use, or disclose your disability data including your fingerprints for the purposes of entering into contracts between you and Krungsri Group (e.g., if you are disabled and cannot sign your name in a contract with Krungsri Group, then Krungsri Group will request for your fingerprints instead), for the purposes of compliance with a law to achieve the purposes with respect to substantial public interest in order to protect the fundamental rights and interest of the data subject (e.g. in the event that the customer redeems investment units of tax benefit funds before maturity or in violation of the regulatory conditions with respect to tax exemption, it is necessary for the customer to present proof of disability in order to enjoy withholding tax exemption). |
Personal data about vulnerable customers may be sensitive personal data | If Krungsri Group, taking into account your personal circumstances, considers that you are a customer with characteristics of vulnerability according to the relevant notifications of the Bank of Thailand or the Office of Securities and Exchange Commission, including hearing or visual impairment, having health conditions or other characteristics of vulnerability, Krungsri Group will provide you with a level of care that is appropriate for a vulnerable customer when communicating with you or providing you with our services. To ensure the fair treatment of vulnerable customers and to comply with the requirements under the notifications, Krungsri Group is required to collect data on vulnerability, including, health data and disability data, that may be sensitive personal data under the applicable data protection laws, and to analyse the Data of vulnerable customers to identify their customer groups so as to offer products and services that are suitable for their circumstances. |
3. Who we disclose your Data to
Krungsri Group may disclose your Data to the following parties for the purposes described in section 2 above, depending on the context of your relationship with us, Krungsri Group companies that you have interacted with, and the nature of Products and Services you obtain from us:
Categories of recipients of personal data | Descriptions |
---|---|
Affiliates |
Krungsri Group may disclose your Data to other companies within Krungsri Group, our affiliates, as well as other entities in Krungsri Group companies including MUFG Bank, Ltd. and MUFG group companies in Thailand and in other countries, including without limitations, Japan, Singapore, the United States of America, and the United Kingdom. |
Service providers |
Krungsri Group may engage other companies to provide services for us and to support us in our business operation (e.g., outsourcers, representatives of sub-contractors). We may disclose your Data to these service providers, or they may collect your Data on our behalf, for various business purposes, including customer services. |
Professional advisors |
Krungsri Group may disclose your Data to professional advisors relating to audit, legal, accounting, and tax services who assist in our business operations and defending or bringing any legal claims, initiating, and managing auction or taking other legal actions such as depositing properties instead of performing obligations. |
Business Partners |
Krungsri Group may disclose your Data to companies that we have collaborated with to offer or enhance services to our existing or prospective customers (e.g., airlines, hotels, fitness centres, telecommunications service providers, debt management and restructuring company). |
Financial institutions , credit bureau, or insurance companies |
Krungsri Group may also disclose your Data to financial specialists who provide financial service support to Krungsri Group (e.g., other banks, financial institutions, credit bureaus, debt collectors debt management organisations, payment service providers, service providers for exchanging secure financial transaction messages, worldwide payments, and credit transactions, processing electronic transactions worldwide including domestic and international securities transactions, payment transactions and credit reference services), agencies performing the duty of quality assurance, agencies providing anti-fraud services, agencies providing debt collection and attachment services, providers of property tracing services, including custodians, trustees of mutual funds, sub-managers, securities companies providing brokerage securities services, securities asset management companies, registrar services, beneficiaries, counterparties, banks, financial institutions, and credit card companies.
|
Third parties as an authorised or permitted person by you | Krungsri Group may disclose your Data based on your consent or your instruction such as to Business Partners of Krungsri Group. |
Third parties as assignees, transferees, or novatees | Krungsri Group may assign, transfer, or novate our rights or obligations to a third party in accordance with an agreement between you and Krungsri Group. We may disclose or transfer your Data to assignees, transferees, or novatees, including prospective assignees, transferees, or novatees. |
Third parties who act on your behalf or provide services to you | Krungsri Group may disclose or transfer your Data to representatives/ your employer, sponsor, and third parties that have roles in delivering services to you or someone acting on your behalf that may provide us with information about you (e.g., hospitals, garages, etc.). |
Third parties connected with corporate transactions | Krungsri Group may disclose or transfer your Data to our Business Partners, investors, significant shareholders, assignees, prospective assignees, transferees, or prospective transferees in the event of any reorganization, merger, acquisition, sale, purchase, joint venture, assignment, dissolution, or any similar event involving the transfer or other disposal of all or any portion of our business, assets, or stock. |
Government authorities and others organisations | Krungsri Group may disclose your Data for legal or necessary purposes to government entities or regulatory bodies (e.g., the Bank of Thailand, The Office of Securities and Exchange Commission, the Revenue Department, the Anti-Money Laundering Office, Thailand Securities Depository Company Limited, the Department of Provincial Administration, police officers, courts, the Legal Execution Department, the Department of Land Transport, the Office of the Consumer Protection Board, agencies performing the duty of registering collaterals, collaterals that are scripless securities, registering share pledges, and registering vehicles (when you purchase compulsory insurance), the Office of Insurance Commission (for the purpose of collecting, using and/or disclosing of your Data to the Office of Insurance Commission, and for the purpose of regulating and promoting insurance business according to Insurance Commission Act, Non-Life Insurance Act, Life Insurance Act, and in accordance with privacy policy of the Office of Insurance Commission by visiting at https://www.oic.or.th).
|
Service providers of insurance company | Krungsri Group may disclose and/or transfer your Data to service providers of insurance companies such as loss surveyors, loss adjustors, hospitals, garages counterparty's insurance companies. |
E-commerce platforms | Krungsri Group may disclose and/or transfer your Data to e-commerce platforms if you apply for their services. |
Other categories of data recipients | Krungsri Group may disclose your Data to other categories of recipients, including members of the National Digital ID (NDID) platform, your insurer, your contact persons and/or family members, your employers, non-profitable organizations or foundations, hospitals, or other organizations in connection with our Products and Services and/or your rewards donations and redemptions. |
4. Transfer of your Data to other countries
We may need to transfer your Data to our affiliates, third parties located overseas (e.g., Japan, Singapore, Taiwan, Philippine, Indonesia, Laos, Cambodia, Myanmar, Vietnam, Israel, India, Australia, the United States of America, the United Kingdom and the European Union Countries ) including Cloud platforms for achieving our business purposes or for your benefit, depending on which Krungsri Group companies that you have interactions with, such as when we use systems and services and transfer your Data to our service providers operating outside Thailand for credit scoring as part of our underwriting process or when we provide you with remittance service. We may need to forward and transfer your Data to representative banks to complete your transactions or to our Business Partners in abroad for introducing of any potential investment project and for any performances in relation to such projects, or when you apply for products or services from our affiliates or business partners. In addition, we may need to transfer your Data overseas via our payment networking provider for approving and settling the transactions you request. We may also transfer your Data to an overseas Master Fund to comply with the regulations of the Master Fund, including applicable laws and regulations. We may also disclose your Data to an overseas Sub-Manager for the purposes of managing investments. In addition, we may store your Data in our server (such as in Singapore) to provide information technology support outside of Thailand. We may also disclose or transfer your Data to our parent company, affiliates, and relevant regulators and government authorities of other countries for which the Personal Data Protection Committee under the Act has not ruled that this country has adequate data protection standards at the time when this Notice is prepared. When we need to transfer your Data to a country with data protection standards that are not equivalent to that of Thailand, we will ensure that there shall be sufficient data protection measures for the transferred Data, or the transfer is otherwise permitted in accordance with the applicable data protection law. For example, prior to transferring your Data to the applicable third parties, we may require such third parties to represent and warrant that the transferred data will be protected by data protection standards which are equivalent to those required in Thailand.
5. How long we will store your personal data
We will store your Data only for as long as it is necessary for the purposes for which it was collected, as explained in this Notice and in accordance with the applicable law. However, we may retain your Data for a longer period to comply with applicable laws and regulations and our internal policy or with regard to our operational requirements, such as proper account information maintenance, facilitating client relationship management, and responding to legal claims or regulatory requests.
6. Your rights
Subject to the provisions of data protection law, you have a number of rights regarding the collection, use, disclosure and/or transfer of your personal data, including the rights
(1) to access: you can access and obtain a copy of information relating to the collection, use, disclosure and/or transfer of your personal data, and a copy of your personal data, or request that we disclose the acquisition of your personal data without your consent;
(2) to rectify: where you consider that your personal data is inaccurate, not up-to-date, or incomplete, you can require that such Personal Data be modified accordingly;
(3) to erase or destroy: you can request the deletion, destruction, or anonymization of your personal data to the extent permitted by law;
(4) to restrict: you can request the restriction of the use of your personal data, for example in the case you found that your personal data is inaccurate, you can request to restrict the use of such data until it is modified;
(5) to object: You have the right to object to the collection, use, or disclosure of your personal data including for direct marketing purposes in any case, which covers profiling related to such direct marketing;
(6) to withdraw your consent: where you have given your consent for the collection, use, or disclosure of personal data, you have the right to withdraw your consent at any time;
(7) to data portability: where legally applicable, you have the right to request us to provide your personal data in a structure, commonly used and machine-readable format using tools or devices which function automatically and by which personal data can be used and disclosed in automatic mode; and transmit or transfer your personal data in such format to another organization; and
(8) to lodge complaints in case you notice that Krungsri Group does not comply with the data protection laws: you are entitled to lodge a complaint with the competent authority regarding the collection, use, and/or disclosure of your personal data by us or on our behalf. Before approaching the competent authority, we would, however, appreciate the chance to deal with your concerns, so please contact us in the first instance.
You may contact Krungsri to exercise your right, by using any of the following channels.
Type of Data subjects |
Customer |
Vendor / Business Partner |
Visitor / CCTV |
||
---|---|---|---|---|---|
Channel |
Call Center 1572 |
Krungsri Branch |
Electronic Channel |
DPO.CentralAdmin@krungsri.com / Security.center@krungsri.com |
|
Right to withdraw consent |
|||||
Other rights |
- |
For individuals residing in Laos, to exercise your rights at the Vientiane Main Branch, please contact the branch directly.
Type of Data subjects |
Customer |
Vendor / Business Partner |
Visitor) / CCTV |
|
---|---|---|---|---|
Channel |
Vientiane Branch |
Vientiane Branch |
Vientiane Branch |
|
Right to withdraw consent |
||||
Other rights |
Your request to exercise any of the above rights as a data subject may be limited by the law. There may be certain cases where we can reasonably and lawfully decline your request, for example, due to legal obligations or court orders.
7. Security measures for protecting Data
Krungsri Group implements the policies and security measures for protecting Data, including management measures, technical protection and physical protection measures regarding the access or control of the use of Data in accordance with this Notice as well as policies provided for personnel of both internal and external corporates who have recognised the importance of Data security strictly. In addition, if Krungsri Group acknowledges that countries of the counterparties which we may transfer Data to has insufficient data-protection standards, we will procure them to have adequate data-protection standards.
8. Links to other third party websites
For website users, our Products and Services may contain links to social networks, platforms, and other websites that are operated by third parties. While we try to link only to websites that share our high standards for privacy, we do not take responsibility for the content or the data protection standards employed by such other websites. Unless this Notice otherwise provides, any personal data you provide to any such third-party website will be collected by that party and not by us and will be subject to that party’s privacy notice/policy (if any), rather than this Notice. In such a situation, we will have no control over, and shall not be responsible for, that party’s use of your personal data.
9. Contact us
If you have any questions, comments, or concerns about our privacy practices, please contact us at the appropriate address below. We will respond to your requests as soon as possible and provide you with additional privacy-related information.
E-mail : dpo.compliance@krungsri.com
Address :
- Bank of Ayudhya Public Company Limited (Head office) 1222 Rama III Road, Bang Phongphang, Yan Nawa, Bangkok 10120 Thailand
Telephone : 0-2296-2000
- Bank of Ayudhya Public Company Limited (Laos Branch) Baan Hassadi, 084/1-2 , Lane Xang Avenue, P.O. Box 5072 Chanthaboury District, Vientiane, Lao. P.D.R.
Telephone : 021 218777
Additional information on how to reach our Data Protection Officers is provided in the attachment to this Notice.
Attachment
Name List of Krungsri Group's Companies
Company’s Name |
Contact Details |
---|---|
|
Email: dpo.compliance@krungsri.com |
|
Email: dpo.ksconsumer@krungsri.com |
|
Email: dpo.ksauto@krungsri.com |
|
Email: dpo-adlc@krungsrileasing.com |
|
Email: dpo.ksam@krungsri.com |
|
Email: dpo.kss@krungsrisecurities.com |
|
Email: dpo.kfin@krungsri.com
|
|
Email: dpc@krungsricapital.com |
Version 1.8