Privacy Policy
Thailand
E-Commerce Website
Compliant
with Personal Data Protection Act B.E. 2562 (PDPA) and Thai E-Commerce
Legislation
|
Company |
Effective Date |
|
CREATE DEVELOPMENT (THAILAND) CO., LTD. |
2026-05-26 |
PART A : PRIVACY POLICY
This Privacy Policy is established in accordance with the Personal Data Protection Act B.E. 2562 (PDPA) and related laws. It applies to all processing of personal data of all website users.
1. Definitions
In this Policy, the following terms shall have the meanings set forth below:
•
Personal Data:
any information that directly or indirectly identifies a natural person.
•
Sensitive Personal Data:
data pursuant to the PDPA, including health data, race/ethnicity, religious beliefs, and criminal records.
•
Data Controller:
the Company, which determines the purposes and means of processing Personal Data.
•
Data Processor:
a person or entity that processes Personal Data on behalf of and under the instructions of the Data Controller.
•
Data Subject:
the natural person to whom the Personal Data relates.
2.
Personal Data We Collect
2.1 Data You Provide Directly
|
Data Type |
|
Examples |
Primary Purpose |
|
Identity Data |
|
Full name, Email, phone |
Account registration |
|
Contact Data |
|
Email, phone, address |
Communication |
|
Payment Data |
|
Account no., card details |
Payment processing |
|
Transaction Data |
|
Order history, items, values |
Contract fulfilment |
|
Account Data |
|
Username, password (hashed), preferences |
Account management |
2.2
Automatically Collected Data
•
Website usage data (Log Data) e.g. IP address, browser type, pages visited, date and time.
•
Cookie and similar tracking technology data, as per the Company's Cookie Policy.
3.
Legal Basis for Processing
|
Legal Basis |
Relevant Processing |
|
Consent |
Marketing emails, non-essential cookies |
|
Contract Performance |
Order processing, delivery, payment |
|
Legal Obligation |
Accounting, tax, regulatory reporting |
|
Legitimate Interests |
Fraud prevention, network security, analytics |
|
Vital Interests |
Emergency situations |
4.
Purposes of Use
The Company uses your Personal Data for the following purposes:
•
Processing orders, payment, and delivery of goods/services.
•
Creating and managing user accounts.
•
Providing customer service and responding to enquiries or complaints.
•
Sending transactional communications such as order confirmations, receipts, and shipping notifications.
•
Sending marketing content and promotions (only with consent).
•
Improving products, services, and website user experience.
•
Preventing fraud, maintaining security, and monitoring regulatory compliance.
•
Fulfilling legal and regulatory obligations.
5.
Disclosure to Third Parties
The Company may disclose your Personal Data to:
•
Third-party service providers (Data Processors) such as payment processors, logistics providers, cloud providers, who have executed data processing agreements compliant with PDPA).
•
Government authorities and law enforcement agencies when required by law or court order.
•
Group companies and affiliates for internal business purposes.
•
Successors or assigns in the event of a merger, acquisition, or corporate restructuring.
The Company will NOT sell or rent your Personal Data to third parties for marketing purposes without your explicit consent.
6.
International Data Transfers
Where the Company transfers your Personal Data to a foreign country, it shall do so as follows:
• Transfer to countries recognized by the Personal Data Protection Committee as having adequate data protection standards.
•
Implement appropriate safeguards such as Standard Contractual Clauses.
•
Obtain explicit consent from the Data Subject where no other safeguard is available.
7.
Data Retention
|
Data Type |
Retention Period |
|
Transaction & Account Data |
5 years after account closure |
|
Tax & Accounting Records |
5 years |
|
Consent Records |
10-year prescription |
|
Complaint Records |
2 years after resolution |
|
System Log Data |
90 days |
8.
Rights of Data Subjects
|
Right |
Description |
|
Right to be Informed |
Informed of collection and use of data |
|
Right of Access |
Access and receive copies of own data |
|
Right to Rectification |
Correct inaccurate or incomplete data |
|
Right to Erasure |
Request deletion or anonymisation |
|
Right to Restriction |
Suspend processing temporarily |
|
Right to Portability |
Receive data in machine-readable format |
|
Right to Object |
Object to processing based on legitimate interests |
|
Right to Withdraw Consent |
Withdraw consent at any time |
You may exercise these rights by contacting the Company's Data Protection Officer (DPO). The Company will respond to requests within 30 days of receipt.
9.
Data Security
The Company implements appropriate technical and organizational security measures including:
•
Encryption using SSL/TLS for data in transit and AES-256 for data at rest.
•
Access control based on the need-to-know principle and Role-Based Access Control (RBAC).
•
Periodic security audits and risk assessments.
•
A personal data breach response and notification plan within 72 hours.
10.
Data Protection Officer (DPO)
|
Contact Info |
Details |
|
Name: Warawut Natpradith |
Email: cs@wecre8te.com |
|
Telephone: +66 912294261 |
Address: 1 Empire Tower, Building Tower 3, Floor 35 Unit 3506, South Sathon Rd, Yan Nawa, Sathon, Bangkok |
11.
Right to Lodge a Complaint
If you believe your rights under the PDPA have been violated, you have the right to lodge a complaint with the Office of the Personal Data Protection Committee (PDPC).
Office of the Personal Data Protection Committee (PDPC), Ministry of Digital Economy and Society, Thailand) Website: www.pdpc.or.th
12.
Changes to This Policy
To install this Web App in your iPhone/iPad press
and then Add to Home Screen.