PRIVACY POLICY
For Employees
GoodView Medical Company Limited (the "Company") places importance on privacy and is committed to protecting your personal data ("Personal Data") in accordance with the Personal Data Protection Act B.E. 2562 (2019). The "Company" has prepared this Privacy Notice to inform you of the details regarding the collection, use, and/or disclosure of your personal data.
1. Purposes of Personal Data Processing
The Company collects, uses, and discloses your personal data only on reasonable grounds and/or as required by law, including disclosure to third parties, for the following main purposes:
- To inform about the collection, use, and disclosure of personal data of Company employees.
- For the benefit of suppressing danger to life, body, or health.
- For the processing of your personal data in compliance with laws and legal obligations.
- For the legitimate interests of the Company to process your personal data, while taking into account your fundamental rights, not overriding the Company's interests.
- For specific purposes based on the consent you have given to the Company for processing your personal data.
2. Lawful Basis for Personal Data Processing
In order to achieve the objectives, the Company may process your personal data under relevant laws and legal bases. The Company processes such personal data using the following legal bases:
| Purpose of Collection, Use, and Disclosure | Lawful Basis |
|---|---|
| To display criminal record check results of new employees on start/signing date | Consent |
| To store employee data during employment contract term | Contract, Vital Interest |
| To store employee data for payroll processing | Contract, Legal Obligation, Legitimate Interest |
| To submit data to the Revenue Department | Contract, Legal Obligation, Legitimate Interest |
| To submit data to the Social Security Office / Workmen's Compensation Fund | Contract, Legal Obligation, Legitimate Interest |
| To submit data to the Student Loan Fund | Legal Obligation |
| To submit data to the Legal Execution Department | Legal Obligation |
| To notify the Fund for Empowerment of Persons with Disabilities | Legal Obligation |
| To store training history and submit to Department of Skill Development | Legal Obligation |
| To process fuel allowance welfare with the bank | Contract |
| To process telephone allowance welfare | Contract |
| For other activities outside the employment contract within the Company, such as employee trips, parties, rewards, satisfaction surveys, etc. | Contract, Legal Obligation, Legitimate Interest |
| To evaluate performance for bonus consideration or salary adjustment, and disciplinary actions | Contract |
| To provide data to requesting agencies for employee benefit, e.g., banks for loan applications | Consent |
| To store fingerprints/face data for access control and leave management | Contract, Consent |
3. Collection of Personal Data
The Company collects and uses various types of personal data. The types of personal data that the Company collects, uses, and discloses are detailed as follows:
3.1 Types of collected, used, or disclosed personal data
Types of your "Personal Data" that the Company collects, uses, or discloses (collectively "processes") under this Act and related laws include:
Personal data such as Name-Surname, Date of Birth, Marital Status, Military Status, Education History, Work History (Place, Duration, Position, Job Description, Salary, Reason for Leaving, Comments from previous employer), ID Card Number, Driving License Number, Copy of House Registration, Copy of Educational Certificate, Copy of Transcript, Copy of Name Change Certificate, Training Evidence, Employment Certificate.
- Contact Information such as Phone Number, Email, Address (Registered Address, Current Address).
- Sensitive Personal Data such as Race, Nationality, Religion as appears on ID card, Blood Type, Disability Information (Disability ID, Physical Impairment), Criminal Record, Health Information, Face Recognition Data, or Fingerprint Data.
- Other Information such as Photographs, Still Images, Moving Images, Voice, Asset Images, Cookies.
3.2 Refusal to provide personal data to the Company
In the event that the Company needs to collect your personal data and you do not provide your personal data to the Company, the Company may refuse related actions.
4. Disclosure of Personal Data
The Company may disclose or transfer your personal data to third parties for them to process your personal data as follows:
4.1 Disclosure of personal data to others, including:
- Internal departments to achieve specified objectives.
- External agencies, including Royal Thai Police, Revenue Department, Payroll Company, Social Security Office, Legal Execution Department, Insurance Company, Fund for Empowerment of Persons with Disabilities, Department of Skill Development, Banks, Telecommunication Providers, Partners.
4.2 Cross-border transfer or transmission of personal data
The Company may need to send or transfer your personal data to foreign countries for storage and/or processing in compliance with contracts between you and the Company. The Company will not allow unrelated persons to access such personal data and will establish appropriate security measures.
5. Retention of Personal Data
The Company will retain your personal data for as long as necessary to achieve the objectives of collection and processing. The Company will determine the retention period as appropriate for the Company's operations. Upon the expiration of the retention period, the Company will delete, destroy, or anonymize the personal data. In cases of legal necessity or technical reasons, the Company may retain your personal data for a longer period.
6. Rights of the Data Subject
You have rights regarding your personal data under the Personal Data Protection Law. The Company respects your rights and will proceed according to laws, rules, or regulations related to the processing of your data under certain circumstances in a timely manner.
You have the right to proceed regarding your personal data as follows:
- Right to Withdraw Consent: In case the Company processes your personal data based on your consent, you have the right to withdraw your consent at any time. However, the Company may continue to process your personal data if the Company relies on other lawful bases.
- Right to Access: You have the right to request a copy of your personal data from the Company.
- Right to Rectification: You have the right to request correction of your personal data to be accurate, up-to-date, and complete.
- Right to Erasure: You have the right to request the Company to delete, destroy, or de-identify your personal data in case there is no reasonable ground for the Company to continue processing it.
- Right to Restriction of Processing: You have the right to request the Company to suspend the processing of your personal data temporarily, for example, when you want the Company to correct your data or verify the reason/lawful basis for processing.
- Right to Data Portability: You can request the Company to send or transfer your personal data in a generally readable electronic format to another data controller. This applies only to data you provided based on consent or contract performance.
- Right to Lodge a Complaint: You have the right to lodge a complaint with relevant government agencies, including the Personal Data Protection Committee, if you believe the Company, its employees, or service providers violate the Act.
You may exercise the above rights at any time by contacting the Company through the channels specified in Clause 8 below.
The Company may need to request certain information from you to verify your identity and ensure your right to access personal data, in accordance with security measures to ensure your data is not disclosed to unauthorized persons.
The Company will attempt to respond to all legitimate requests within 30 days. In some cases, it may take longer than 30 days if your request is complex or you submit multiple requests. The Company will inform you and keep you updated on the status.
7. Security of Your Personal Data
The Company places great importance on the security of your personal data. The Company regularly audits and uses appropriate organizational, physical, and technical security measures in storing and processing your personal data to ensure it is not lost, accidentally destroyed, disclosed, or misused/accessed by unauthorized persons.
8. Complaint or Inquiry Handling
You can contact the Company to make a complaint about how the Company collects, uses, processes, and discloses your personal data or make inquiries at the following channels:
Data Protection Officer
GoodView Medical Company Limited
142/8 Rama 5 Road, Suan Chitlada Subdistrict, Dusit District, Bangkok 10300
Email hr@goodviewmedical.com
This announcement is effective from January 1, 2026 onwards.