Privacy Policy Last Updated Nov 19, 2021 |
AOT Microsite Visitors’ Privacy Policy
Latest updated: 19 พ.ย. 2021
Abstract
AOT Microsite processes personal data of Personnel with the reasonable measures to act in compliance with the Thailand’s Personal Data Protection Act B.E. 2562 (“PDPA”). You can see our full detailed Privacy Policy through the attached QR code, however the summary of our Privacy
policy is shown below.
Topic |
Overview |
What data do we process? |
We process collected personal data including but not limited to Identity Data, Address / Contact, and IT Data. |
How do we use those data? |
We process personal data according to the purpose and scope of Airports of Thailand Public Company Limited, with the legal bases as explained in our Privacy Policy. |
Who do we transfer information to? |
In some circumstances, we may be required to transfer personal data to Third-Party Organizations, which are stated in our vendors/partners list. |
What are your rights as a data subject? |
As a data subject, you are entitled to the data subject rights which include but not limited to right to access, right to rectification and right to erasure. |
Revision of the policy |
Any revision made will be notified to all related parties regarding the changes in The Privacy Policy. |
AOT Microsite Visitors’ Privacy Policy 1.0
1. Purpose and scope
2. What personal data do we process?
3. How do we collect your personal data?
4. How does SKY ICT use your Personal Data?
5. Usage of Personal Data with External Third-party Organization
6. Transferring Personal Data to Foreign Countries
7. Security Measures for Personal Data Protection
8. Time Period of Personal Data Storage
9. Website Visitors’ Personal Data Rights
10. Policy Revision
1. Purpose and scope
This Privacy Policy applies to all AOT Microsite Visitors (“Visitors”). GFIN-SKY Consortium acts as the Data Processor, who has the role and responsibility in processing and ensuring the security and privacy of all personal data in accordance with Personal Data Protection Act (2019), under the scope and purpose determined by Airports of Thailand Public Company Limited as the Data Controller.
Data Controller Contact Information Airports of Thailand Public Company Limited (AOT) Tel.: 1722 or (+66) 2535 1192 |
Data Protection Officer (DPO) Contact Information [*] E-mail: |
This Privacy Policy covers data subjects who are AOT Microsite Visitors, including Airline Passengers, Airport Visitors, Airport Staff.
As used in this Privacy Policy, the following terms shall have the meanings set forth below:
‘Processing’ means anything done with AOT Microsite Visitors’ personal data, including collection, storage, use, disclosure, and deletion.
‘Legal Bases’ means justifiable reasons to process personal data in accordance with Article 24 and Article 26 of PDPA.
This policy may be revised at any given time as notified to Personnel through appropriate channels.
2. What personal data do we process?
AOT Microsite stores the following Visitors’ personal data:
- Address/Contact including but not limited to Address, Phone number and Email
- Identity Data including but not limited to Full name (excluding biometric data)
- Profile Data including but not limited to Sex, Country of Residence, Birth Date
- IT Data including but not limited to the Cookie ID
3. How do we collect your personal data?
In general, AOT Microsite will directly collect Visitors’ personal data through these processes (or channels) including but not limited to:
- Collecting cookie ID from your visit to AOT Microsite (see cookies policy for details)
- Fill in the form on the website.
4. How does AOT Microsite use your Personal Data?
AOT Microsite uses Visitors’ personal data to carry out tasks per Airports of Thailand Public Company Limited’s scope and purpose of providing group of activities, including but not limited to:
Group of Activities |
Group of PIIs |
Legal Bases |
Contact Us |
|
|
Visitor Activity Report |
|
|
Newsletter |
|
|
AOT Microsite will process Visitors’ personal data according to the stated purposes and scope. If there came upon a case where personal data were to be processed for other purposes unclarified above, AOT Microsite would ask for new consent to process Visitors’ personal data on such uses.
5. Usage of Personal Data with External
Third-party Organization
AOT Microsite may be required to pass on personal data to external third-party organizations and process personal data in accordance with the contract or the legal obligation of GFIN-SKY Consortium. These organizations may include:
- Google Analytics
For the case where personal data is being passed on the external third-party organizations, AOT Microsite will ensure that the minimum amount of personal data is being sent and consider anonymization and pseudonymization techniques for greater security. Nevertheless, external third-party organizations who will process Visitors’ personal data for AOT Microsite will be required to have an appropriate privacy policy. AOT Microsite does not permit these external third-party organizations to use the Visitors’ personal data in a way that diverge from the agreed scope and purpose.
6. Transferring Personal Data to Foreign Countries
AOT Microsite may be required to pass on personal data to foreign countries, including, but not limited to
- United States
For these cases, AOT Microsite will pass on Users’ personal data only when these requirements have been met. These include:
- Receiving foreign country has a substantial personal data regulation in place
- Receiving organization has a substantial privacy policy in place and certified by the Personal Data Committee
- Receiving organization is obligated to follow a substantial privacy policy with a sufficient remedial measure in accordance with the procedures identified by the Personal Data Committee (including, but not limited to, standard contract, vendor process agreement)
- A necessary task to exercise legal rights
- Consent has been received from appropriate individuals agreeing to the pass on of Users’ personal data to a foreign country that does not have a substantial privacy policy
- A necessary task to carry out contractual agreements of the Users
- A necessary task to carry out under a contractual agreement between two entities for the benefit of the Users
- To ensure the safety or limit further damage to an individual’s health who cannot give consent at the current time
- A necessary task for the good of the public
7. Security Measures for Personal Data Protection
AOT Microsite has implemented security measures to ensure the security of Visitors’ personal data (More details are available at [link]). External third-party organizations must carry out the processing of personal data in accordance with AOT’s policy and agrees to ensure the security of Visitors’ personal data (More details about GFIN-SKY Consortium’s IT Security Policy are available at https://www.skyict.co.th/privacy-policy)
8. Time Period of Personal Data Storage
AOT Microsite will store Visitors’ personal data throughout for the appropriate period according to AOT Microsite’s scope and purpose including other important matters such as legal requirements, accounting, and auditing purposes. (More details are available at [link])
9. Website Visitors’ Personal Data Rights
Your personal data rights include:
- Right of Access – you have the right to request a copy of all your personal data and assess if the company is processing your personal data in accordance with the law or not
- Right to Data Portability – for the case where a company has an automated platform allowing you to access your personal data automatically:
- You have the right to ask for your personal data to be transferred automatically to other organizations
- You have the right to ask for your personal data to be directly transferred to other organization, with the exceptions of cases where there is a technological limitation
- Right to Object – you have the right to object to any data process activity of your personal data for the legal bases, including:
- Public Task or Legitimate Interest
- Direct Marketing Purposes
- Right to Erasure – you have the right to request data deletion or anonymization, in accord to the following cases:
- Expiration of data processing required terms
- Consent has been withheld
- Objections raised on the data processing activity
- The processing activity is not in accordance with the law
- Right to restrict processing – you have the rights to restrict any data processing activities, in accordance with the following cases:
- During the process of personal data assessment as requested
- For cases related to personal data which has initially asked for deletion and erasure but was followed by an additional request of processing restriction instead
- For cases when the data processing terms have passed, but you have requested for processing restriction due to legal reasons
- During the process of personal data processing objection verification
- Right to Rectification – You have the right to edit your personal data to be correct and concurrent to the present. If any mistake was detected, the company might not edit this themselves.
In the cases where AOT Microsite may not be able to carry out and exercise your rights, including, but not limited to, the cases where a legal process is taking place, you will continue to have the rights to retract your consent by emailing to all related parties. AOT Microsite will be required to terminate all processes as soon as possible. However, the retraction only is carried out to all data processing after the retraction. Any data process activity carried out before the retraction will not be reversed.
Please be informed that AOT Microsite does record all requests to ensure all issues are resolved. For any queries regarding your personal data protection and rights, more details are available at: https://www.law.chula.ac.th/event/9705/
In the case where you have the intention to exercise your personal data protection rights, please contact AOT Call Center 1722 or (+66) 2535 1192. AOT Microsite will process this request in a secure and timely manner. Also, in case that AOT Microsite fails to preserve your rights under PDPA, you can file complaint to Office of the Personal Data Protection Commission (‘PDPC’)
10.Policy Revision
This Privacy Policy applies to all AOT Microsite Visitors and was last updated on 19/11/2021. AOT Microsite holds the rights to review and edit the policy periodically if there is any change in activities or any significant change. Any revision made will be notified to all related parties regarding the changes in data processing activity procedures.