This Policy shall become effective as from 1 June 2022 Onwards.
Rabbit Rewards Company Limited (the “Company”, “we”, “us”, or “our”) recognizes the importance of the protection of personal data. We follow security procedures when collecting, using, and/ or disclosing your Personal Data (as defined below).
This privacy policy for business partner (“Privacy Policy”) explains how we collect, use and/or disclose Personal Data of the business partner’s personnel, authorized persons, authorized signatories, directors, shareholders and other contact persons (collectively referred to as “you”, or “your”) and informs you the rights relating to Personal Data protection.
“Business Partner”, according to this Privacy Policy, includes, without limitation, business partners, distributors, suppliers, vendors, service providers, construction contractors, investors, analysts, shops, billboard tenants, independent advisors, securities companies, insurance companies, insurance brokers, insurance agents, banks, joint venture partners, and third parties e.g., third parties requesting to enter the area, contractor’s sub-contractors, related persons according to the rules of the Securities and Exchange Commission (e.g., spouse, children under the age of 20), and other business partners.
The Company collects, uses and/or discloses your Personal Data because we currently have business relationship with you or may have business relationship with you in the future, or because you work for, represent, or proceed on behalf of our business partners, e.g., companies which supplies or provide services for the Company, or which we have business communication with which may involve you.
From time to time, we may change and/or update this Privacy Policy. We will provide additional notice of significant changes and/or updates. We will post the date on which our Privacy Policy was last updated at the top of the Privacy Policy. We encourage you to read this Privacy Policy carefully and to check Privacy Policy regularly to review any changes and/or updates we might take in accordance with the terms of this Privacy Policy.
For the purposes of this Privacy Policy, “Personal Data” means any identified or identifiable information about you as listed below.
We may directly or indirectly collect your Personal Data from other sources. For example, we may directly collect your Personal Data (such as, when you do business with the Company or sign a contract or fill out a form when you interact with the Company, including having interactions through the Company's online platform, through the Company's website or mobile application, communication via email, telephone, questionnaires, business cards, postage, during meetings and events, scheduling meetings with you or from a source in the system, central drive system/central database of the Company or transport software and/or electronic files).
In addition, we may indirectly collect your Personal Data, e.g., from business partner or service provider you work for, act on its behalf, or represent, the BTS Group Companies (as defined in “TO WHOM WE MAY DISCLOSE PERSONAL DATA” section below), public sources (e.g., social media and websites of third parties or relevant government agencies), other third parties (e.g. other business partners of the Company, reference persons and complainants). The specific types of Personal Data collected will depend on the relationship which you have with the Company or the BTS Group Companies. The followings are example of Personal Data that may be collected:
In addition, your Personal Data may be collected from our business partners in case you purchase a product from one of our business partners whose products are displayed on our websites. Your Personal Data related to the product you have purchased will be sent to us for the purposes of sale tracking and service improvement.
If you provide Personal Data of any third party to us, e.g., their name, family name, telephone number, for the provision of our products and services or for emergency contact, in case you visit any of our platform with your consent, we may access and collect Personal Data of any third party relating to you such as name, photos and/or phone number including their personal data detail and their contact detail of theirs family, friends, emergency contact, instructed person or referral contact that can be accessed through your mobile phone and so on. Please inform them about this Privacy Policy and/or asking for theirs consent.
We do not intentionally collect your sensitive data (“Sensitive Data”). However, in case that we do, we will only collect, use, and/or disclose Sensitive Data on the basis of your explicit consent or where permitted by law.
We only collect the Personal Data of children, quasi-incompetent person and incompetent person where their parent or guardian has given their consent. We do not knowingly collect Personal Data from customers under the age of 20 without their parental consent when it is required, or from quasi-incompetent person and incompetent person without their legal guardian's consent. In the event that we learn that we have unintentionally collected Personal Data from anyone under the age of 20 without parental consent when it is required or from quasi-incompetent person and incompetent person without their legal guardians, we will delete it immediately or process if we can rely on other legal basis apart from consent.
We may collect, use or disclose your Personal Data for the following purposes:
2.1 THE PURPOSES OF WHICH WE RELY ON CONSENT
We rely on consent for the collection, use, and/or disclosure of Personal Data and/or Sensitive Data for the following purposes:
2.2 THE PURPOSE THAT WE MAY RELY ON LEGAL BASES IN PROCESSING YOUR PERSONAL DATA
We may also rely on (1) contractual basis, for our initiation or fulfilment of a contract with you; (2) legal obligation, for the fulfilment of our legal obligations; (3) legitimate interest, for the purpose of our legitimate interests and the legitimate interests of third parties. We will balance the legitimate interest pursued by us and any relevant third party with your interest and fundamental rights and freedoms in relation to the protection of your Personal Data; (4) vital interest, for preventing or suppressing a danger to a person’s life, body or health; or other legal grounds permitted under applicable data protection law (as the case may be). Depending on the context of the interactions with us, we may collect, use and/ or disclose Personal Data for the following purposes:
(1) For business purposes, such as to proceed business transactions with business partners and fulfil our duties and/or requests from business partners, to contact business partners regarding products, services and projects of the Company or the business partners (e.g., to respond to questions or requests);
(2) For selection of business partners, such as to verify you and status of business partners, to check status of business or perform other background checks and screen you and business partners, to assess your and business partners’ suitability and qualifications, to assess your and business partners’ risks (including the verification of public information from law enforcement agencies and/or the Company’s blacklist record), to prepare quotations or bidding offer, to enter into agreements, prepare purchase orders or purchase requests with you or business partners and to evaluate your and business partners’ management;
(3) For relationship management, such as to keep your Personal Data up-to-date, to maintain the accuracy of Personal Data, to keep agreements, relating documents, agreement’s reference documents and evidence of the work of business partners which may mention you, to plan, operate and manage (contractual) relationships and rights with business partners
(e.g., to appoint, withdraw or authorize business partners to engage in transaction and order products or services, process payment, to conduct activities relating to accountancy, audit, invoice issuance, management of product and service delivery), to manage your requests or complaints, to improve, support, monitor, and record;
(4) For business communications, such as communication with business partners about products, services and projects of the Company or business partners (e.g., communication via document, response to questions, requests or operational progress report);
(5) For marketing purposes, such as to inform you about news and public information which may be useful, including activities, new product and service offers, product and service price negotiation and survey, as well as for to evaluate and consider providing financial aid
(e.g., financial loan) to you or business partners;
(6) For internal management and communication within the organization, such as to publish internal activities and to comply with business codes of conduct, including but not limited to, procurement, disbursement, internal management, training, inspection, report, document delivery and management, data processing, risk control or management, trend and statistical analysis and planning, and other similar or relating activities;
(7) For business analysis and improvement, such as to research, analyse data, estimate, survey and evaluate and report on our products and services and your or business partners’ performance, including to develop and improve our marketing strategy, and our products and services;
(8) For registration and authentication, such as for your registration, verification, identification and authentication;
(9) For IT systems and IT support systems, such as to support IT and IT support departments,
to administrate system access in which the Company has granted the right to access to you,
to delete unused accounts, implement business control measures to continue business, and for the Company to identify and solve problems in the IT systems, and to safeguard the security of our systems, to develop, implement, operate and manage the IT systems;
(10) For business partner information management, such as to compile list of business partners, record data in the system and update the list and directory of business partners (which includes your Personal Data), as well as to store and manage agreements and relating documents which may contain your name;
(11) For system monitoring and security, such as to control access, monitor systems, equipment and internet, and safeguard IT security;
(12) For dispute management, such as to resolve dispute, enforce the Company’s agreements, establish, exercise, or raising legal claims, including to grant authorization;
(13) For investigation, complaint and/or crime and fraud prevention;
(14) For compliance with internal policy and relating/applicable laws, rules, regulations, guidelines (such as to apply for business licences as required by law) and to coordinate or communicate with government agencies, courts or relevant agencies (such as the Revenue Department, the Royal Thai Police Headquarter and the State Audit Office) including to investigate, complain and/or prevent crime and fraud;
(15) For danger prevention towards life, body or health of a person, such as to control contagious disease or epidemic;
(16) For organizing corporate social and environmental responsibility
Where the Personal Data we collect from you is needed to meet our legal, regulatory, or contractual obligations or enter into an agreement with you, if you do not provide your Personal Data when requested, we may not be able to achieve the aforementioned purposes.
The Company may disclose or transfer your Personal Data to the following third parties. We will collect, use, and/or disclose Personal Data in accordance with the purposes under this Privacy Policy. These third parties may be located in Thailand and outside Thailand. You can visit their privacy policy to learn more details on how they collect, use and/or disclose Personal Data since you could also be subject to their privacy policies.
3.1 BTS Group Companies
As the Company is part of the BTS Group Companies which all collaborate and/or partially share customer services and systems, e.g., service systems and website-related systems, the Company may need to transfer your Personal Data to, or otherwise allow access to such Personal Data by the BTS Group Companies for the purposes set out in this Privacy Policy. BTS Group Companies may rely on the consent obtained by the Company to use your Personal Data.
List of the BTS Group Companies is (1) BSS Holdings Co., Ltd. (2) Bangkok Smartcard System Co., Ltd. (3) Rabbit Rewards Co., Ltd. (4) Rabbit Internet Co., Ltd. (5) Rabbit Internet Broker Co., Ltd. and (6) ASK Direct Group Co., Ltd.
3.2 The Company’s service providers
The Company may use other companies, agents or contractors to perform services on our behalf or to assist us in our business with you. The Company may share Personal Data to third parties, including but not limited to (1) infrastructure, software and website developers and IT service providers; (2) marketing, advertisement, design, creative advertising and communication service providers; (3) hospitals; (4) data storage and cloud service providers; (5) banks and financial institutions; (6) insurance companies, sub-insurance companies, insurance brokers, insurance agents, lost adjustors and risk surveyors; (7) logistics and transportation service providers; (8) payment and payment system service providers; (9) voting and vote counting service providers; (10) analysts; (11) travel service agencies; (12) garages and auto parts stores; (13) booking system service providers; (14) outsource internal operation service providers; (15) printing houses; and (16) surveying service providers.
In the course of providing such services, the service providers may have access to your Personal Data. However, the Company will only provide the Company’s service providers with the Personal Data that is necessary for them to perform the services, and we will ask them not to use your Personal Data for any other purposes. The Company will ensure that all the service providers we work with will keep your Personal Data secure.
3.3 Our business partners
The Company may transfer your Personal Data to the Company’s business partners, such as business partners, project owners, contract parties, securities companies, stores, construction contractors, joint venture partners, companies that the Company invests in, co-shared partners and third parties that the Company share marketing or promotional campaigns for the business operation and service provision of the Company, provided that the receiving business partner shall agree to treat Personal Data in a manner consistent with this Privacy Policy.
3.4 Third parties permitted by law
In certain circumstances, the Company may be required to disclose or share your Personal Data in order to comply with a legal or regulatory obligation. This includes any government agency, court, government authority, embassy, consulate, or other third party where we believe this is necessary to comply with a legal or regulatory obligation, or otherwise to protect the rights of the Company, third party or individuals’ personal safety; or to detect, prevent, or otherwise address fraud, security or safety issues.
3.5 Professional advisors
The Company may disclose Personal Data to the Company’s expert advisors including, but not limited to, (1) independent advisors; (2) legal advisors who assist the Company in its business operations and provide litigation services such as defending or initiating legal actions; (3) external advisors; (4) project advisors; (5) financial advisors; and (6) auditors who provide accounting services or conduct financial audit for the Company.
3.6 Third parties connected with business transfer
We may disclose or transfer your Personal Data to our business partners, investors, significant shareholders, assignees or transferees in the event of any reorganization, restructuring, merger, acquisition, sale, purchase, joint venture, assignment, or any other similar events involving transfer or other disposition of all or any portion of our business, assets or stock. If any of above events occurs, the receiving party will comply with this Privacy Policy to respect your Personal Data.
We may disclose or transfer Personal Data to third parties or servers located overseas, which the destination countries may or may not have the same data protection standards as Thailand’s. This includes, without limitation, IT service providers, system developers and maintenance service providers, data storage and cloud service providers, bank/financial institutes, securities companies, shareholders, companies that we invest in, business alliances, agents and distributors, advisor companies, in case of international transfer to customers overseas, business partners or alliances overseas, hotels, training agencies, embassies, and/or consulates. We take steps and measures to ensure that Personal Data is securely transferred, that the receiving parties have in place suitable data protection standard and that the transfer is permitted under the law.
The Company will retain your Personal Data for as long as it is reasonably necessary to fulfil purposes for which the Company obtained them and to comply with the Company’s legal and regulatory obligations. However, the Company may have to retain Personal Data for a longer duration, as required by applicable laws.
If you visit our websites, we will gather certain information automatically from you by using tracking tools and cookies (including, but not limited to, Google Tag Manager, Google Analytics, Hotjar, Matomo, Zendesk, Facebook Pixel Analytics, Facebook Ad Manager, and Google Cloud). Cookies are tracking technologies which are used in analyzing trends, administering our websites, tracking users’ movements around the websites, or to remember users’ settings. Some of the cookies are necessary because otherwise the site is unable to function properly. Other cookies are convenient for the visitors and they remember your username in a secure way as well as your language preferences.
Most internet browsers allow you to control whether or not to accept cookies. If you reject cookies, your ability to use some or all of the features or areas of our websites may be limited.
As a way to protect personal privacy of your Personal Data, we maintain appropriate security measures, which include administrative, technical and physical safeguards in relation to access control, to protect the confidentiality, integrity, and availability of Personal Data against any accidental or unlawful or unauthorized loss, alteration, correction, use, disclosure or access, in compliance with the applicable laws.
In particular, we have implemented access control measures which are secured and suitable for our collection, use, and/or disclosure of Personal Data. We restrict access to Personal Data as well as storage and processing equipment by imposing access rights or permission, access management to limit access to Personal Data to only authorized persons, and implement user responsibilities to prevent unauthorized access, disclosure, perception, unlawful duplication of Personal Data or theft of device used to store and process Personal Data; This also includes methods that enabling the re-examination of access, alteration, erasure, or transfer of Personal Data which is suitable for the method and means of collecting, using and/or disclosing of Personal Data.
Subject to applicable laws and exceptions thereof, a data subject may have the following rights to:
1) Access: Data subjects may have the right to access or request a copy of the Personal Data we are collecting, using and/or disclosing. For privacy and security, we may require proof of the data subject's identity before providing the requested Personal Data;
2) Rectification: Data subjects may have the right to have incomplete, inaccurate, misleading, or not up-to-date Personal Data that we collect, use and/or disclose rectified;
3) Data Portability: Data subjects may have the right to obtain Personal Data we hold about that data subject, in a structured, electronic format, and to transmit such data to another data controller, where this is (a) Personal Data which you have provided to us, and (b) if we are collecting, using and/or disclosing that data on the basis of data subject's consent or to perform a contract with the data subject;
4) Objection: Data subjects may have the right to object to certain collection, use and/or disclosure of Personal Data subject to the applicable law;
5) Restriction: Data subjects may have the right to restrict our use of Personal Data where the data subject believes such Personal Data to be inaccurate, that our collection, use and/or disclosure is unlawful, or that we no longer need such Personal Data for a particular purpose;
6) Withdraw Consent: For the purposes the data subjects have consented to our collection, use and/or disclosure of Personal Data, data subjects may have the right to withdraw consent at any time;
7) Deletion: Data subjects may have the right to request that we delete, destroy or anonymize Personal Data that we collect, use, and/or disclose, except we are not obligated to do so if we need to retain such Personal Data in order to comply with a legal obligation or to establish, exercise or defend legal claims; and
8) Lodge a complaint: Data subjects may have the right to lodge a complaint to the competent authority where the data subject believes our collection, use and/or disclosure of Personal Data is unlawful or non-compliance with applicable data protection law.
If you wish to contact us to exercise the rights relating to your Personal Data or if there are any queries about your Personal Data under this Privacy Policy, please contact our Data Protection Officer (DPO) at:
Rabbit Rewards Company Limited
Data Protection Officer