โดยที่พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 ("กฎหมาย") มีวัตถุประสงค์ในการคุ้มครองสิทธิส่วนบุคคลของเจ้าของข้อมูลส่วนบุคคล การเก็บรวบรวม ใช้ หรือเปิดเผยข้อมูลส่วนบุคคลย่อมต้องเป็นไปตามเงื่อนไขและวิธีการที่กฎหมายกำหนด เพื่อให้การประมวลผลข้อมูลส่วนบุคคลผ่านการดำเนินกิจกรรมของ [รอจดบริษัท — ชื่อนิติบุคคล] ("บริษัทฯ", "เรา") ผู้ให้บริการแพลตฟอร์ม Maibit เป็นไปตามกฎหมาย บริษัทฯ จึงจัดทำนโยบายความเป็นส่วนตัวฉบับนี้ ("นโยบายฯ") เพื่อให้ท่านในฐานะเจ้าของข้อมูลส่วนบุคคลรับทราบและตระหนักถึงความสำคัญในการคุ้มครองข้อมูลส่วนบุคคลของท่าน
"ข้อมูลส่วนบุคคล" หมายถึง ข้อมูลของบุคคลธรรมดาซึ่งทำให้สามารถระบุตัวบุคคลนั้นได้ไม่ว่าทางตรงหรือทางอ้อม เช่น ชื่อ-นามสกุล อายุ เพศ วันเดือนปีเกิด เลขบัตรประจำตัวประชาชน เบอร์โทรศัพท์ อีเมล ภาพถ่าย แต่ไม่รวมถึงข้อมูลของผู้ถึงแก่กรรม
"ข้อมูลส่วนบุคคลที่มีความอ่อนไหว" หมายถึง ข้อมูลส่วนบุคคลเกี่ยวกับเชื้อชาติ เผ่าพันธุ์ ความคิดเห็นทางการเมือง ความเชื่อ ศาสนา พฤติกรรมทางเพศ ประวัติอาชญากรรม ข้อมูลสุขภาพ ความพิการ ข้อมูลพันธุกรรม ข้อมูลชีวภาพ หรือข้อมูลอื่นใดตามที่กฎหมายกำหนด (อาทิ ศาสนาที่อาจปรากฏในสำเนาบัตรประชาชน)
"การประมวลผล" หมายถึง การเก็บรวบรวม ใช้ เปิดเผย หรือการกระทำใด ๆ ต่อข้อมูลส่วนบุคคล รวมถึงการส่งต่อ โอน ทำลาย หรือลบ
"เจ้าของข้อมูลส่วนบุคคล" หรือ "ท่าน" หมายถึง บุคคลธรรมดาที่บริษัทฯ ประมวลผลข้อมูลส่วนบุคคลตามนโยบายฯ นี้
บริษัทฯ จะเก็บรวบรวมข้อมูลส่วนบุคคลของท่านตามวัตถุประสงค์และอำนาจแห่งกฎหมายเท่านั้น โดยอาจเก็บผ่านช่องทางดังนี้:
ในกรณีที่มีการเก็บข้อมูลส่วนบุคคลจากแหล่งอื่น บริษัทฯ จะแจ้งให้ท่านทราบและดำเนินการตามกฎหมายภายใน 30 วันนับแต่วันที่เก็บรวบรวม
บริษัทฯ ประมวลผลข้อมูลส่วนบุคคลของท่านบนฐานทางกฎหมายดังนี้:
ในกรณีที่ไม่เข้าฐานทางกฎหมายอื่น บริษัทฯ จะขอความยินยอมจากท่านก่อนหรือในขณะเก็บรวบรวมข้อมูลส่วนบุคคลเสมอ ท่านสามารถถอนความยินยอมได้ทุกเมื่อ
บริษัทฯ ไม่ประสงค์เก็บข้อมูลของผู้เยาว์โดยไม่ได้รับความยินยอมจากผู้ปกครอง โดย:
หากบริษัทฯ ทราบว่ามีการเก็บข้อมูลของผู้เยาว์โดยไม่ได้รับความยินยอม บริษัทฯ จะดำเนินการลบหรือทำลายข้อมูลโดยทันที
บริษัทฯ อาจประมวลผลข้อมูลส่วนบุคคลเพื่อการโฆษณาและการตลาดผ่านช่องทางต่าง ๆ เช่น Google, Facebook, LINE หรือเครื่องมือวิเคราะห์อื่น ๆ โดยจะดำเนินการเมื่อได้รับความยินยอม
หากท่านไม่ต้องการรับข่าวสารการตลาด ท่านสามารถยกเลิกได้ทุกเมื่อผ่านลิงก์ "ยกเลิกการรับข่าวสาร" ในอีเมล หรือผ่านการตั้งค่าบัญชี การถอนความยินยอมจะไม่กระทบต่อการประมวลผลที่ได้ดำเนินการไปแล้วโดยชอบด้วยกฎหมาย
บริษัทฯ จะเปิดเผยข้อมูลส่วนบุคคลของท่านตามวัตถุประสงค์ที่เก็บรวบรวมหรือตามอำนาจแห่งกฎหมายเท่านั้น โดยอาจเปิดเผยให้แก่:
บริษัทฯ จะกำกับดูแลให้ผู้ประมวลผลข้อมูลส่วนบุคคลภายนอกมีมาตรฐานการคุ้มครองข้อมูลตามกฎหมาย ในกรณีที่มีการส่งข้อมูลไปต่างประเทศ บริษัทฯ จะดำเนินการให้เป็นไปตามมาตรฐานที่กฎหมายกำหนด
บริษัทฯ จะเก็บรักษาข้อมูลส่วนบุคคลของท่านตลอดระยะเวลาที่ท่านใช้บริการ และเท่าที่จำเป็นเพื่อให้บรรลุวัตถุประสงค์ที่กำหนด หรือตามที่กฎหมายกำหนด (เช่น ข้อมูลธุรกรรมทางการเงินที่ต้องเก็บตามกฎหมาย)
เมื่อท่านยกเลิกบัญชี บริษัทฯ จะเก็บข้อมูลเท่าที่จำเป็นตามกฎหมาย และจะลบหรือทำลายข้อมูลส่วนที่ไม่จำเป็นออก
ท่านมีสิทธิตามกฎหมายเกี่ยวกับข้อมูลส่วนบุคคลของท่านดังนี้:
| สิทธิ | รายละเอียด | ระยะเวลาดำเนินการ |
|---|---|---|
| เพิกถอนความยินยอม | ถอนความยินยอมที่ให้ไว้ได้ทุกเมื่อ | 7 วัน |
| เข้าถึงและขอสำเนา | ขอเข้าถึงและรับสำเนาข้อมูลของตน | ทันที / ตามกำหนด |
| ขอให้โอนข้อมูล | ขอให้ส่งหรือโอนข้อมูลไปยังผู้ควบคุมข้อมูลอื่น | 30 วัน |
| ขอแก้ไขข้อมูล | ขอแก้ไขข้อมูลให้ถูกต้องเป็นปัจจุบัน | ทันที / ตามกำหนด |
| คัดค้านการประมวลผล | คัดค้านการประมวลผลในบางกรณี | 30 วัน |
| ขอให้ลบหรือทำลาย | ขอให้ลบหรือทำลายข้อมูลในกรณีที่กฎหมายกำหนด | 30 วัน |
| ระงับการใช้ข้อมูล | ขอให้ระงับการใช้ข้อมูลชั่วคราว | 30 วัน |
| ร้องเรียน | ร้องเรียนการประมวลผลที่ไม่ชอบด้วยกฎหมาย | ทันที |
ระยะเวลาดำเนินการนับแต่วันที่บริษัทฯ ได้รับเอกสารครบถ้วน ท่านสามารถใช้สิทธิได้ผ่านศูนย์ช่วยเหลือ บริษัทฯ มีสิทธิปฏิเสธคำขอได้หากมีอำนาจประมวลผลตามกฎหมาย โดยจะบันทึกเหตุผลไว้
บริษัทฯ จัดให้มีมาตรการรักษาความมั่นคงปลอดภัยที่เหมาะสม ทั้งด้านการบริหารจัดการ ด้านเทคนิค และด้านกายภาพ เพื่อป้องกันการสูญหาย เข้าถึง ใช้ เปลี่ยนแปลง แก้ไข หรือเปิดเผยข้อมูลโดยมิชอบ ครอบคลุมการรักษาความลับ ความถูกต้องครบถ้วน และสภาพพร้อมใช้งานของข้อมูล
เอกสารยืนยันตัวตน (KYC) จะถูกจัดเก็บในพื้นที่จัดเก็บแบบส่วนตัว (private storage) และเข้าถึงได้เฉพาะเจ้าหน้าที่ที่มีสิทธิเท่านั้น
ในกรณีที่มีเหตุละเมิดข้อมูลส่วนบุคคล บริษัทฯ จะแจ้งให้สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคลทราบภายใน 72 ชั่วโมงนับแต่ทราบเหตุเท่าที่สามารถกระทำได้ และหากการละเมิดมีความเสี่ยงสูงต่อสิทธิและเสรีภาพของท่าน บริษัทฯ จะแจ้งให้ท่านทราบพร้อมแนวทางการเยียวยาโดยไม่ชักช้า
บริษัทฯ อาจแก้ไขเปลี่ยนแปลงนโยบายฯ ได้เป็นครั้งคราว โดยจะประกาศผ่านแพลตฟอร์ม การใช้บริการต่อหลังการเปลี่ยนแปลงถือว่าท่านรับทราบนโยบายฉบับใหม่ นโยบายฉบับนี้มีผลใช้บังคับตั้งแต่วันที่ 1 กันยายน 2569
ผู้ควบคุมข้อมูลส่วนบุคคล / เจ้าหน้าที่คุ้มครองข้อมูล (DPO):
ชื่อบริษัทฯ: [รอจดบริษัท — ชื่อนิติบุคคล]
ที่อยู่: [รอจดบริษัท — ที่อยู่จดทะเบียน]
อีเมล: privacy@maibit.com
หรือผ่านศูนย์ช่วยเหลือ
The Personal Data Protection Act B.E. 2562 (the "Law") aims to protect the privacy rights of data subjects. The collection, use, or disclosure of personal data must comply with the conditions and methods prescribed by Law. To ensure that the processing of personal data through the activities of [Pending registration — legal entity name] (the "Company", "we"), operator of the Maibit Platform, complies with the Law, the Company has prepared this Privacy Policy (the "Policy") so that you, as a data subject, are informed of and aware of the importance of protecting your personal data.
"Personal Data" means information about an identifiable natural person, whether directly or indirectly, such as name, age, gender, date of birth, national ID number, phone number, email, or photo, but excluding data of deceased persons.
"Sensitive Personal Data" means personal data concerning race, ethnicity, political opinions, beliefs, religion, sexual behavior, criminal records, health data, disability, genetic data, biometric data, or other data prescribed by Law (e.g. religion that may appear on a copy of a national ID card).
"Processing" means the collection, use, disclosure, or any action taken on personal data, including transfer, destruction, or deletion.
"Data Subject" or "you" means the natural person whose personal data the Company processes under this Policy.
The Company collects your personal data only for lawful purposes and within its legal authority, through channels including:
Where personal data is collected from other sources, the Company will notify you and act in accordance with the Law within 30 days of collection.
The Company processes your personal data on the following legal bases:
Where no other legal basis applies, the Company will always seek your consent before or at the time of collection. You may withdraw consent at any time.
The Company does not intend to collect data from minors without guardian consent:
If the Company learns that data from a minor was collected without consent, it will delete or destroy the data immediately.
The Company may process personal data for advertising and marketing through channels such as Google, Facebook, LINE, or other analytics tools, only with your consent.
If you do not wish to receive marketing communications, you may opt out at any time via the "Unsubscribe" link in emails or through account settings. Withdrawal of consent does not affect processing already lawfully carried out.
The Company discloses your personal data only for the purposes collected or within its legal authority, and may disclose to:
The Company ensures third-party processors maintain data protection standards as required by Law. Where data is transferred abroad, the Company will act in accordance with the standards prescribed by Law.
The Company retains your personal data throughout your use of the service and as long as necessary to fulfill the stated purposes or as required by law (e.g. financial transaction data that must be retained by law).
When you close your account, the Company retains only data necessary under the law and deletes or destroys unnecessary data.
You have the following legal rights regarding your personal data:
| Right | Description | Processing time |
|---|---|---|
| Withdraw consent | Withdraw consent given at any time | 7 days |
| Access & copy | Access and obtain a copy of your data | Immediate / as scheduled |
| Data portability | Request transfer of data to another controller | 30 days |
| Rectification | Request correction of data to be accurate and current | Immediate / as scheduled |
| Object | Object to processing in certain cases | 30 days |
| Erasure | Request deletion or destruction where the law permits | 30 days |
| Restrict processing | Request temporary suspension of use | 30 days |
| Complain | Complain about unlawful processing | Immediate |
Processing time is counted from when the Company receives complete documents. You may exercise these rights via the Help Center. The Company may refuse a request where it has lawful authority to continue processing, recording the reason.
The Company maintains appropriate security measures — administrative, technical, and physical — to prevent loss, unauthorized access, use, alteration, modification, or disclosure of data, covering confidentiality, integrity, and availability.
KYC verification documents are stored in private storage and accessible only by authorized staff.
In the event of a personal data breach, the Company will notify the Personal Data Protection Committee Office within 72 hours of becoming aware, where feasible. Where the breach poses a high risk to your rights and freedoms, the Company will notify you without delay, along with remedial guidance.
The Company may amend this Policy from time to time, announced via the Platform. Continued use after changes constitutes acknowledgment of the revised Policy. This Policy takes effect from 1 September 2026.
Data Controller / Data Protection Officer (DPO):
Company: [Pending registration — legal entity name]
Address: [Pending registration — registered address]
Email: privacy@maibit.com
or via the Help Center.