Company means United Flour Mill Public Company Limited.
Personal Data means information that directly or indirectly identifies an individual, such as name, address, national ID number, phone number, etc. This does not include data of deceased persons.
Sensitive Data means personal data as defined under Section 26 of the Personal Data Protection Act B.E. 2562, including data on race, ethnicity, political opinions, beliefs in cults, religion or philosophy, sexual behavior, criminal records, health data, disability, labor union data, genetic data, biometric data, or any other data that similarly impacts the data subject as determined by the Personal Data Protection Committee.
Personal Data Processing means any operation performed on personal data, such as collection, recording, copying, organizing, storing, updating, modifying, using, retrieving, disclosing, forwarding, distributing, transferring, combining, deleting, or destroying data.
Data Subject means the natural person who is the owner of the personal data that the Company collects, uses, or discloses.
Data Controller means the person or legal entity with the authority and responsibility to make decisions regarding the collection, use, or disclosure of personal data.
Data Processor means the person or legal entity that carries out the collection, use, or disclosure of personal data pursuant to the instructions of or on behalf of the Data Controller. Such a person or entity is not considered a Data Controller.
The use or disclosure of sensitive personal data (Sensitive Data) requires the explicit consent of the data subject, unless otherwise permitted by law or regulations.
1) Directly from the data subject through various service channels, such as application, registration, job application, contract signing, documents, surveys, or use of products/services or other channels managed by the Company; or when the data subject communicates with the Company at its premises or through other contact channels managed by the Company.
2) Through the data subject's use of the Company's website, products, or other services under contract or obligations — for example, tracking website usage behavior through cookies or software on the data subject's device.
3) From third-party sources outside the data subject — if you provide another person's personal data to the Company, you are responsible for notifying that person of this policy or the relevant product/service notice, as applicable, and for obtaining their consent if required before disclosing their data to the Company.
If a data subject refuses to provide personal data that is necessary for the Company's services, the Company may be unable to provide all or part of those services to that data subject.
The Company defines levels of access, use, disclosure, and processing of personal data only for those with relevant duties and a genuine need for the data. Appropriate authentication and identity verification measures are also in place.
If the Company transfers personal data to another country or stores it in systems or databases of service providers located abroad, the Company will ensure that the destination country, recipient, or service provider meets adequate data protection standards — at a level equal to or higher than that required by law.
In the event of a personal data breach, or where there are reasonable grounds to believe a breach has occurred that may pose a risk to the rights and freedoms of the data subject, the Company will notify the relevant regulatory authority and/or the data subject in accordance with the criteria and timeframes required by law, and take appropriate measures to prevent, remedy, and mitigate any potential damage.
However, the Company shall not be liable for damage caused by actions of the data subject themselves, or of third parties who received the data subject's consent to disclose or use such data, including cases where the data subject failed to maintain the security of their user account, password, or to log out of the Company's electronic systems.
The Company will periodically review, audit, and assess the effectiveness of its personal data security measures to ensure alignment with evolving risks, changing technologies, and applicable laws, regulations, or standards.
The Company will retain personal data by identifying an appropriate legal basis for collection, in accordance with the context of each service and as required by law.
1. Right of Access — You have the right to request access to and copies of your personal data, and to request disclosure of its source, unless the Company has lawful grounds or a court order to refuse, or if the exercise of this right may affect the rights and freedoms of others.
2. Right to Rectification — If you find that your personal data is inaccurate, incomplete, or outdated, you have the right to request correction to ensure accuracy, completeness, currency, and non-misleading status.
3. Right to Erasure — You have the right to request the Company to delete or destroy your personal data, or to anonymize it so that it can no longer identify you, subject to the conditions stipulated by law.
4. Right to Restriction of Processing — You have the right to request restriction of use of your personal data in the following cases:
(a) During the period in which the Company is verifying your request to correct personal data;
(b) When your personal data has been unlawfully collected, used, or disclosed;
(c) When the personal data is no longer necessary for the purposes notified at collection, but you wish the Company to retain it for the purpose of establishing, exercising, or defending legal claims;
(d) During the period in which the Company is verifying its lawful basis for collecting your personal data, or examining the necessity of collecting, using, or disclosing your data for public benefit, as a result of your exercise of the right to object.
5. Right to Object — You have the right to object to the collection, use, or disclosure of your personal data, unless the Company has lawful grounds to refuse (e.g., the Company can demonstrate that the collection, use, or disclosure has a stronger legal basis, or is necessary for the establishment, exercise, or defense of legal claims, or for the Company's public benefit purposes).
6. Right to Withdraw Consent — If you have given consent to the Company to collect, use, or disclose your personal data (whether before or after the Personal Data Protection Act B.E. 2562 came into effect), you have the right to withdraw consent at any time during the period your personal data is held by the Company — unless there is a legal restriction requiring the Company to retain the data, or a contract between you and the Company that continues to benefit you.
7. Right to Data Portability — You have the right to receive your personal data from the Company in a format that is generally readable and usable by automated tools or devices, and may request the Company to transmit or transfer such data to another Data Controller, subject to conditions specified by law.
Legal Department, United Flour Mill Public Company Limited
177, 205, 9th Floor, Ratchawong Road, Chakrawat Sub-district,
Samphanthawong District, Bangkok 10100
Tel: 02-2266140
