Privacy Policy
1. Principles and Objectives
United Flour Mill Public Company Limited (hereinafter referred to as the "Company") recognizes the importance of personal data and other information related to you (collectively referred to as "Data"). To ensure that you can be confident that the Company is transparent and accountable in the collection, use, or disclosure of your data, the Company acts in accordance with the Personal Data Protection Act B.E. 2562 (2019) ("Personal Data Protection Law") and other relevant laws.
2. Scope of Application
This policy covers the Company's operations relating to your personal data, including board members, executives, employees, business partners, service providers, and stakeholders of the Company and its subsidiaries who interact with the Company through its products and services — such as websites, systems, applications, documents, or other services managed by the Company (collectively referred to as "Services").
3. Definitions

Company means United Flour Mill Public Company Limited.

Personal Data means information that directly or indirectly identifies an individual, such as name, address, national ID number, phone number, etc. This does not include data of deceased persons.

Sensitive Data means personal data as defined under Section 26 of the Personal Data Protection Act B.E. 2562, including data on race, ethnicity, political opinions, beliefs in cults, religion or philosophy, sexual behavior, criminal records, health data, disability, labor union data, genetic data, biometric data, or any other data that similarly impacts the data subject as determined by the Personal Data Protection Committee.

Personal Data Processing means any operation performed on personal data, such as collection, recording, copying, organizing, storing, updating, modifying, using, retrieving, disclosing, forwarding, distributing, transferring, combining, deleting, or destroying data.

Data Subject means the natural person who is the owner of the personal data that the Company collects, uses, or discloses.

Data Controller means the person or legal entity with the authority and responsibility to make decisions regarding the collection, use, or disclosure of personal data.

Data Processor means the person or legal entity that carries out the collection, use, or disclosure of personal data pursuant to the instructions of or on behalf of the Data Controller. Such a person or entity is not considered a Data Controller.

4. Use and Disclosure of Data
The use or disclosure of personal data shall be in accordance with the purposes stated at the time of collection, or as directly necessary for those purposes, and must have the prior or contemporaneous consent of the data subject — unless otherwise permitted by law or regulations.
The use or disclosure of sensitive personal data (Sensitive Data) requires the explicit consent of the data subject, unless otherwise permitted by law or regulations.
5. Sources of Personal Data Collected by the Companys
The Company collects or obtains various types of personal data from the following sources:

1) Directly from the data subject through various service channels, such as application, registration, job application, contract signing, documents, surveys, or use of products/services or other channels managed by the Company; or when the data subject communicates with the Company at its premises or through other contact channels managed by the Company.

2) Through the data subject's use of the Company's website, products, or other services under contract or obligations — for example, tracking website usage behavior through cookies or software on the data subject's device.

3) From third-party sources outside the data subject — if you provide another person's personal data to the Company, you are responsible for notifying that person of this policy or the relevant product/service notice, as applicable, and for obtaining their consent if required before disclosing their data to the Company.
If a data subject refuses to provide personal data that is necessary for the Company's services, the Company may be unable to provide all or part of those services to that data subject.

6. Data Retention Period
The Company will retain your personal data for as long as necessary to fulfill the purposes of collection, use, or disclosure as specified, and/or to comply with applicable laws. The Company may need to retain your data for a longer period to comply with legal obligations, statutes of limitations, applicable regulations, and internal company policies. Where a specific retention period cannot be clearly defined, the Company will retain data for a period consistent with standard collection practices.
7. Security Measures
To maintain the confidentiality, integrity, and security of personal data, the Company has established appropriate technical and organizational measures to prevent loss, unauthorized access, use, modification, alteration, or disclosure of personal data, as follows:
7.1 Access Control for Personal Data

The Company defines levels of access, use, disclosure, and processing of personal data only for those with relevant duties and a genuine need for the data. Appropriate authentication and identity verification measures are also in place.

7.2 International Transfer of Personal Data

If the Company transfers personal data to another country or stores it in systems or databases of service providers located abroad, the Company will ensure that the destination country, recipient, or service provider meets adequate data protection standards — at a level equal to or higher than that required by law.

7.3 Personal Data Breach Management

In the event of a personal data breach, or where there are reasonable grounds to believe a breach has occurred that may pose a risk to the rights and freedoms of the data subject, the Company will notify the relevant regulatory authority and/or the data subject in accordance with the criteria and timeframes required by law, and take appropriate measures to prevent, remedy, and mitigate any potential damage.
However, the Company shall not be liable for damage caused by actions of the data subject themselves, or of third parties who received the data subject's consent to disclose or use such data, including cases where the data subject failed to maintain the security of their user account, password, or to log out of the Company's electronic systems.

7.4 Review and Evaluation of Security Measures

The Company will periodically review, audit, and assess the effectiveness of its personal data security measures to ensure alignment with evolving risks, changing technologies, and applicable laws, regulations, or standards.
The Company will retain personal data by identifying an appropriate legal basis for collection, in accordance with the context of each service and as required by law.

8. Rights of Data Subjects under the Personal Data Protection Act B.E. 2562 (2019)
The Personal Data Protection Act B.E. 2562 establishes the following rights for data subjects (effective once the relevant provisions of the law come into force):

1. Right of Access — You have the right to request access to and copies of your personal data, and to request disclosure of its source, unless the Company has lawful grounds or a court order to refuse, or if the exercise of this right may affect the rights and freedoms of others.

2. Right to Rectification — If you find that your personal data is inaccurate, incomplete, or outdated, you have the right to request correction to ensure accuracy, completeness, currency, and non-misleading status.

3. Right to Erasure — You have the right to request the Company to delete or destroy your personal data, or to anonymize it so that it can no longer identify you, subject to the conditions stipulated by law.

4. Right to Restriction of Processing — You have the right to request restriction of use of your personal data in the following cases:
(a) During the period in which the Company is verifying your request to correct personal data;
(b) When your personal data has been unlawfully collected, used, or disclosed;
(c) When the personal data is no longer necessary for the purposes notified at collection, but you wish the Company to retain it for the purpose of establishing, exercising, or defending legal claims;
(d) During the period in which the Company is verifying its lawful basis for collecting your personal data, or examining the necessity of collecting, using, or disclosing your data for public benefit, as a result of your exercise of the right to object.

5. Right to Object — You have the right to object to the collection, use, or disclosure of your personal data, unless the Company has lawful grounds to refuse (e.g., the Company can demonstrate that the collection, use, or disclosure has a stronger legal basis, or is necessary for the establishment, exercise, or defense of legal claims, or for the Company's public benefit purposes).

6. Right to Withdraw Consent — If you have given consent to the Company to collect, use, or disclose your personal data (whether before or after the Personal Data Protection Act B.E. 2562 came into effect), you have the right to withdraw consent at any time during the period your personal data is held by the Company — unless there is a legal restriction requiring the Company to retain the data, or a contract between you and the Company that continues to benefit you.

7. Right to Data Portability — You have the right to receive your personal data from the Company in a format that is generally readable and usable by automated tools or devices, and may request the Company to transmit or transfer such data to another Data Controller, subject to conditions specified by law.

9. Contact Information
If you have any questions or wish to file a complaint regarding personal data, please contact:
Legal Department, United Flour Mill Public Company Limited
177, 205, 9th Floor, Ratchawong Road, Chakrawat Sub-district,
Samphanthawong District, Bangkok 10100
Tel: 02-2266140
10. Language and Governing Law
These Terms of Use shall be construed and enforced in accordance with the Thai language version and shall be governed by the laws of Thailand.
11. Changes or Updates to the Privacy Policy
The Company may amend or update this Privacy Policy at any time. The Company reserves the right to make changes or updates without prior notice to you.