1.4 The words "we", "us", "our" or any of their derivatives refer to StashAway Thailand and its successors and any novatee, assignee, transferee or purchaser of StashAway Thailand's rights and/or obligations hereunder and any reference to StashAway Thailand includes a reference to such successor, novatee, assignee, transferee or purchaser. The words "you", "your", "yours" or any of their derivatives refer to the person using our Services, operating any account maintained with us, accessing our Platform, website or mobile applications, or otherwise providing information to or communicating with us and shall include, as the context may require, personal representatives (as the case may be).
2.2 The Personal Data that we collect or may collect include:
- (2.2.1) personal contact data including name, telephone number, email address, residential address and correspondence address;
- (2.2.2) specimen signature(s);
- (2.2.3) occupation, education and income levels;
- (2.2.4) identification card or passport number, date of birth, place of birth and other information for the verification of identity;
- (2.2.5) financial and banking information (e.g. information on net assets, income, expenses, credit history, bank account and banking transactions, securities trading account);
- (2.2.6) images and voice recordings of our conversations with you;
- (2.2.7) tax and insurance information;
- (2.2.8) information about your risk profile, investments, investment objectives, knowledge and experience and/or business interests and assets;
- (2.2.9) personal opinions made known to us (e.g. your feedback or responses to any surveys);
- (2.2.10) browsing history, patterns or other unique information;
- (2.2.11) your internet protocol address and information associated with such address;
- (2.2.12) any other Personal Data reasonably required in order for us to provide the services requested by you; and
- (2.2.13) any other Personal Data required to comply with any applicable local or foreign laws, rules, acts, regulations, subsidiary legislation notices, notifications, circulars, licence conditions, directions, requests, requirements, guidelines, directives, codes, information papers, practice notes, demands, guidance and/or decisions of any national, state or local government, any agency, exchange, regulatory or self-regulatory body, law enforcement body, court, central bank or tax revenue authority or any other authority whether in Thailand or elsewhere, whether having the force of law or not (including any intergovernmental agreement between the governments or regulatory authorities of two or more jurisdictions or otherwise), as may be amended from time to time ("Applicable Laws") and our internal control and compliance policies.
Section 2 sets out the type of Personal Data that we collect or may collect from you.
3.1 The Personal Data has/or will be obtained from the following sources, where applicable, or such other sources which we may see fit from time to time:
- (3.1.1) information provided or submitted by you through among others, your dealings and agreements with us, which includes information provided when registering as a user, providing information regarding any account which you may open with us, providing answers to security questions, completing any confirmations, declarations or forms, or through your utilization of any of our Services, accessing or viewing our Platform;
- (3.1.2) as applicable, publicly available or publicly accessible information; and
- (3.1.3) such other written, electronic or verbal communications or documents delivered to us prior to and during the course of our contractual or pre-contractual dealings with you.
Section 3 sets out where we may obtain Personal Data from.
4.1 We may use your Personal Data for our business purposes, including the provision and continuing operation of the Platform and the Services provided to you on the following legal bases and for the following purposes("Purposes"):
- (4.1.1) provision of the Services as requested by you;
- (4.1.2) carrying out any transactions on your behalf contemplated on the Platform and the Services thereto;
- (4.1.3) assessing and processing applications, instructions or requests from you;
- (4.1.4) communicating with you, including providing you with updates on changes to our Services;
- (4.1.5) to verify your identity for the purposes of providing Services to you;
- (4.1.6) conducting due diligence checks, screenings or credit checks as may be required by any Applicable Laws or our internal policies and procedures;
- (4.1.7) to administer any account which you may open with us;
- (4.1.8) to process payments;
- (4.1.9) to respond to queries or feedback;
- (4.1.10) for the specific purpose for which it was volunteered or provided to us;
- (4.1.11) any other reasonable purposes in connection with the provision of our Services;
- (4.1.12) to detect and protect us or any third parties against negligence, fraud, theft and other illegal activities;
- (4.1.13) to understand your needs and preferences;
- (4.1.14) improving the content, appearance and utility of the Platform;
- (4.1.15) to manage and develop infrastructure and business operations;
- (4.1.16) to comply with our internal policies and procedures;
- (4.1.17) to address or investigate any complaints, claims or disputes;
- (4.1.18) as permitted by any Applicable Laws;
- (4.1.19) enforcing obligations owed to us;
- (4.1.20) seeking professional advice, including legal advice;
- (4.1.21) fulfilling any purpose directly related to the above Purposes;
- (4.1.22) any other purposes that are appropriate or authorized by any Applicable Laws;
- (4.1.23) to comply with any Applicable Laws or any request from any relevant governmental or regulatory authority;
- (4.1.24) financial reporting, regulatory reporting, management reporting, risk management, audit and record keeping purposes; or
- (4.1.25) with your consent, providing you with marketing materials in connection with the services we may provide.
4.2 We will use your Personal Data only where we have a lawful basis for using it. These lawful basis include where:
- (4.2.1) we need to pursue our legitimate business interests;
- (4.2.2) we need to process the information to perform our contract with you;
- (4.2.3) we need to process the information to comply with a legal obligation;
- (4.2.4) the use of your information as described is in the public interest, such as for the purpose of preventing or detecting crime; and
- (4.2.5) we have your consent.
Section 4 sets out how we may use your Personal Data. This includes using your Personal Data for the provision of our Services / Platform to you, for marketing purposes, and to comply with regulatory requirements. We will use your Personal Data only where we have a lawful basis for using it, which include, pursuing our legitimate business interests; processing the information to perform our contract with you; processing the information to comply with a legal obligation; for the public interest, such as for the purpose of preventing or detecting crime; and having your consent.
We may from time to time disclose and share your Personal Data to our directors, officers, employees, representatives, agents or delegates or any third parties, whether located in Thailand or otherwise, to carry out the Purposes. This includes, disclosing and sharing your Personal Data with the following:
- (5.1) any of our directors, officers, employees, representatives, agents or delegates;
- (5.2) any of our shareholders or related corporations, and any of their successors or assigns, and their directors, officers, employees, representatives, agents or delegates;
- (5.3) our professional advisers, consultants and auditors;
- (5.4) any service providers, agents, contractors, delegates, suppliers or third parties which we may appoint from time to time to provide us with services in connection with the Platform or the Services that we offer to you, and their directors, officers, employees, representatives, agents or delegates;
- (5.5) any sub-contractors which any of our service providers, agents, suppliers, delegates or contractors may appoint from time to time to provide them with services in connection with the Platform or the Services that we offer to you, and their directors, officers, employees, representatives, agents or delegates;
- (5.6) anyone who takes over or may take over all or part of our rights or obligations under any agreement we have with you which any agreement we have with you (or any part thereof) is transferred to or may be transferred to;
- (5.7) any person who we believe in good faith to be your legal advisers or other professionals;
- (5.8) any relevant governmental or regulatory authority, in so far as we need to do so to keep to any Applicable Laws, or which we in good faith believe that we should keep to;
- (5.9) pursuant to a request by any relevant governmental or regulatory authority (regardless of the reason for such request and whether such request is exercised under a court order or otherwise);
- (5.11) any person to whom we are, in our belief in good faith, under an obligation to make disclosure as required by any Applicable Laws, provided that in the case of disclosures under any of the circumstances in (5.1) to (5.4), we shall procure that the recipient is subject to the same duty of confidence.
We may also disclose and share your Personal Data with other persons in connection with the Purposes described in Section 4
6.1 You may, at any time, withdraw your consent to receive marketing information from us. If you wish to do so, please click on the “Unsubscribe” option available on all marketing/newsletter emails that you may receive from us or contact our Data Protection Officer at firstname.lastname@example.org.
6.2 You may also withdraw consent and request us to stop collecting, using and/or disclosing your personal data for any or all of the Purposes described in Section 4 by submitting your request in writing or via email to our Data Protection Officer.
6.3 Upon receipt of your written request to withdraw your consent, we may require reasonable time (depending on the complexity of the request and its impact on our relationship with you) for your request to be processed and for us to notify you of the consequences of us acceding to the same, including any legal consequences which may affect your rights and liabilities to us. In general, we shall seek to process your request within ten (10) business days of receiving it.
6.4 Whilst we respect your decision to withdraw your consent, please note that depending on the nature and scope of your request, we may not be in a position to continue providing our Services to you and we shall, in such circumstances, notify you before completing the processing of your request. Should you decide to cancel your withdrawal of consent, please inform us in writing in the manner described in Section 6.2 above.
6.5 Please note that withdrawing consent does not affect our right to continue to collect, use and disclose personal data where such collection, use and disclose without consent is permitted or required under applicable laws.
You have the right to withdraw any consent provided by you to receive any marketing information from us or to the collection, usage and/or disclosure of your personal data in connection with the Purposes described in Section 4. We will seek to process your withdrawal request within ten (10) business days. However, a withdrawal of your consent to collect, use and/or disclosure your personal data in connection with the Purposes described in Section 4 means that we may not be able to continue to provide you with our Services.
7.1 You may also request access to Personal Data we hold, or request the rectification of any inaccurate data. If you would like to do so, please contact our Data Protection Officer at email@example.com.
7.2 Please note that a reasonable fee may be charged for an access request. If so, we will inform you of the fee before processing your request.
7.3 We will respond to your request as soon as reasonably possible. In general, our response will be within thirty (30) business days. Should we not be able to respond to your request within thirty (30) days after receiving your request, we will inform you in writing within thirty (30) days of the time by which we will be able to respond to your request. If we are unable to provide you with any personal data or to make a correction requested by you, we shall generally inform you of the reasons why we are unable to do so (except where we are not required to do so under the PDPA) and shall keep the record of your request together with the above reasons pursuant to the requirements under the PDPA.
You may contact our Data Protection Officer to access or request changes to your Personal Data.
8.1 To safeguard your Personal Data from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks, we have introduced appropriate administrative, physical and technical measures such as:
- (8.1.1) minimised collection of personal data;
- (8.1.2) authentication and access controls (such as good password practices, need-to-basis for data disclosure, etc.);
- (8.1.3) encryption of data;
- (8.1.4) data anonymization;
- (8.1.5) up-to-date antivirus protection;
- (8.1.6) regular patching of operating system and other software;
- (8.1.7) securely erase storage media in devices before disposal;
- (8.1.8) web security measures against risks;
- (8.1.9) usage of one time password(“OTP”)/ 2 factor authentication (“2FA”)/ multi-factor authentication (“MFA”) to secure access, and
- (8.1.10) security review and testing performed regularly.
8.2 You should be aware, however, that no method of transmission over the Internet or method of electronic storage is completely secure. While security cannot be guaranteed, we strive to protect the security of your information and are constantly reviewing and enhancing our information security measures.
We have introduced administrative, physical and technical measures to ensure the protection of your Personal Data with us.
9.1 The accuracy of your Personal Data depends largely on the information you provide to us, you should inform us as soon as practicable if there are any errors in the Personal Data or if there have been any changes to the Personal Data. We intend to keep the Personal Data accurate and up-to-date, and retain the Personal Data no longer than necessary for the above purposes or as required or permitted by any applicable law.
The accuracy of your Personal Data depends largely on the information you provide to us, you should inform us as soon as practicable if there are any errors in the Personal Data or if there have been any changes to the Personal Data.
To the extent necessary, we may transfer, store, process and/or deal with your Personal Data outside Thailand. In doing so, we will comply with the PDPA and other applicable data protection and privacy laws. If the recipient countries do not maintain adequate standard levels, we will ensure that the transfers are in compliance with legal requirements and will put in place the as necessary and appropriate measures for the purpose of protecting your Personal Data.
We may transfer your Personal Data outside Thailand. If we do, we will comply with applicable data protection and privacy laws.
Your Personal Data is retained as long as the purpose for which it was collected remains and until it is no longer necessary for any other business purposes or to comply with any Applicable Laws and in accordance with our policy or manual on data retention of StashAway Thailand.
We may retain your Personal Data for as long as it is necessary for the purpose it was collected, for business purposes or to comply with applicable laws.
However, you may also
12.1 request access to and obtain a copy of your Personal Data we hold;
12.2 request the rectification of any inaccurate data;
12.3 request to obtain your Personal Data we hold in the format which is readable or commonly used by ways of automatic tools or equipment which can be used or disclosed by automated means;
12.4 object to the processing of your Personal Data by us;
12.5 request us to delete or anonymise of your Personal Data that we no longer have a legal ground to process;
12.6 request us to restrict the processing of your Personal Data;
12.7 where you have provided us with your consent to process your Personal Data, withdraw your consent at any time; and
12.8 lodge a complaint to relevant authority in case that we process your personal data unlawfully or not in compliance with applicable laws.
You may contact our Data Protection Officer to access or request changes to your Personal Data.
13.2 Please note that we may not be able to provide you with our Services if you do not agree to our collection, use, processing and disclosure of the Personal Data for any of the Purposes.
14.2 A pixel tag, also known as a web beacon, is an invisible tag placed on certain pages of our website but not on your computer. Pixel tags are usually used in conjunction with cookies and are used to monitor the behaviour of users visiting the website.
14.3 You may set up your web browser to block cookies which will in turn disable the pixel tags from monitoring your website visit. You may also remove cookies stored from your computer or mobile device. However, if you do block cookies and pixel tags, you may not be able to use certain features and functions of our websites or the Platform.
14.4 We also use analytics programs such as Google Analytics for web analytics purposes to manage and improve our websites, mobile applications, the Platform and/or our Services. Features of Google Analytics that we may use include Remarketing with Google Analytics, Google Display Network Impression Reporting, and Google Analytics Demographics and Interest Reporting. Accordingly, your information may be collected for reports such as impression reporting, demographic reporting, interest reporting and to assist with tailoring our online advertising to provide you with a better experience. You may refer to https://www.google.com/policies/privacy/partners for more information about how your data is collected through Google Analytics.
14.5 We and our third-party vendors, including Google, use first-party cookies (such as the Google Analytics cookie) or other first-party identifiers, and third-party cookies (such as Google advertising cookies) or other third-party identifiers together, to inform, analyse, optimise, and serve custom ads based on your interests, searches and prior usage patterns when visiting our websites, mobile applications and Platform, and for other market research analysis purposes such as impression reporting and how your interactions with these ads are related to visits to our websites, mobile applications and Platform, amongst others. As a consequence, third party vendors may show our ads on other websites or mobile applications. We neither support or endorse the goals, causes or statements of these websites or mobile applications which display our ads.
14.6 Using the Google Ad Settings (https://www.google.com/settings/u/0/ads/authenticated), you may control the ads you view, block specific advertisers, learn how ads are selected for you, and opt-out of Google Analytics for Display Advertising. To opt out from any collection or use of information by Google Analytics, please download and install the Google Analytics Opt-Out Browser Add-on available at https://tools.google.com/dlpage/gaoptout. By opting out, you will not be subject to online advertising or marketing analysis by Google Analytics and you will no longer receive ads tailored to your browsing patterns and usage preferences.
If you have any questions about any aspects of this policy or your Personal Data, please contact our Data Protection Officer, at 725 S-Metro Building, 18th Floor Sukhumvit Road, Khlong Tan Neua, Wattana, Bangkok 10110, firstname.lastname@example.org or +662 821-6888.