Privacy Policy
ASH Asia International Co., Ltd.

ASH Asia International Co., Ltd. respects and values the privacy rights and personal data protection of its customers, business partners, affiliates, and stakeholders. ASH Asia International Co., Ltd. is committed to safeguarding customer information, collecting, using, disclosing, transmitting, and/or transferring personal data to third parties while protecting it from misuse and maintaining its security in accordance with international standards. To build trust and confidence among customers in the management of their personal data, this privacy policy has been established as follows:

1. Definitions

In this Privacy Policy, the terms or expressions shall be defined as follows:

“Customer”

Refers to a customer, user, or member of the ASH Club application, including the use of our website, application, or other services, who is a natural person. It also includes business partners, business affiliates, and stakeholders who are natural persons, excluding employees.

“We”

Refers to ASH Asia International Co., Ltd.

“Website”

Refers to the website owned or operated by us, as applicable.

“Application”

Refers to the ASH Club application, platform, and/or applications provided by us. This Privacy Policy applies to the application or platform, including any modifications, updates, upgrades, or additions made by the company, unless such modifications, updates, upgrades, or additions are governed by separate terms and conditions from this Privacy Policy.

“Data Controller”

Refers to the Data Controller as defined under the Personal Data Protection Act B.E. 2562 (2019).

“Data Protection Officer”

Refers to the person appointed by the Data Controller or Data Processor to act as the Data Protection Officer in accordance with the Personal Data Protection Act B.E. 2562 (2019).

“Data Processor” 

Refers to the Data Processor as defined under the Personal Data Protection Act B.E. 2562 (2019).

“Personal Data”

Refers to any information relating to an individual that enables the identification of that person, whether directly or indirectly, in accordance with the Personal Data Protection Act B.E. 2562 (2019).

“Business Partner”

Refers to any partner or entity engaged in business with us or collaborating with us.

“ASH Club application”

Refers to the mobile application used as a communication channel and service platform for members of the ASH Club application, in the form of a Loyalty Program owned by us.    

“Service Provider” 

Refers to the developer, data processor, service provider, and manager of the ASH Club application on our behalf and under our instruction (currently, we have appointed Buzzebees Co., Ltd. “Buzzebees” as the service provider).

2. General Provisions
This Privacy Policy is established to provide details and methods for protecting and managing customers' personal data. We may update or amend this Privacy Policy, including any specific provisions outlined on any part of this website or application, in whole or in part, from time to time to comply with service practices and evolving legal regulations. Therefore, customers are advised to regularly review this Privacy Policy. However, we will publish any changes to the Privacy Policy on this website or application, and if there are significant changes, we will notify customers accordingly.

This Privacy Policy applies to the following:

  1. Our services are provided on the ASH Club application, a mobile application designed to offer a Loyalty Program. This includes point accumulation, point redemption for discounts, rewards, or other benefits, sweepstakes, lotteries, and various marketing activities, as well as communication channels between the ASH Club application and its members. It also includes services provided to application or platform members to redeem rewards for accumulated points from purchases with ASH Asia International Co., Ltd., sponsors, and participating partners. Members can use accumulated points to redeem rewards, discounts, coupons, as well as receive notifications about campaigns, advertisements, badge accumulation programs, or other available services within the application or platform.
  2. The use of services or the purchase of products, access, and use of content, features, technologies, or functions that appear in our application or platform.
  3. Other related services, including any other services we currently provide or will develop or make available in the future.
  4. Registering for the ASH Club application service for the purpose of verifying or identifying customers when accessing the service using a phone number or email for identity verification during membership registration or subsequent access, using a one-time password (OTP) for secure online transactions. When we receive customers' personal information through their registration or usage of the ASH Club application, as well as other information under sections 3.1 to 3.2 of this policy, we will transmit that information through Application Programming Interfaces (API) to Microsoft Azure, where the personal data will be stored in the customer's membership information on our behalf.


3. Collection and Retention of Personal Data
We collect data in several ways, including the use of technologies such as cookies, which are small pieces of data stored on customers' devices that allow the application or website to remember information related to access or usage of the application or website during each session (more information on cookies). The customer-related information we collect includes:

3.1 Information Provided Directly by Customers
We collect personal data that is necessary to provide services to customers, to fulfill contracts, or to comply with legal obligations. The data collected from customers includes their name, surname, email address, and phone number provided during registration. Additionally, information entered during service registration or requests for services, participation in activities, survey responses, user account data, or updates to user account information will also be collected. This includes any data obtained from interactions between customers and us or our team, as well as any information related to other accounts under the customer's control. All types of data displayed on user profile pages and service registration pages will be included, such as:

For personal data requiring customer consent under the law, we will collect only what is necessary and only after receiving customer consent unless an exception provided by law allows us to collect the data without customer consent.

In certain cases, to provide various services or to conduct activities according to the purpose of collecting customer data, we may need to collect, use, or disclose sensitive personal data, such as data related to race, ethnicity, political opinions, religious or philosophical beliefs, sexual behavior, disabilities, union membership, genetic data, biometric data, etc. In such cases, we will inform customers and request their consent to collect, use, or disclose such sensitive personal data for specific purposes. However, where the law permits the collection, use, or disclosure of sensitive personal data without customer consent, we may do so as permitted by law.

3.2 Information Collected from Customer Usage

We collect information related to the services customers use and how they interact with them. This includes data such as images, device information used to access the application, computer traffic data (Log), and usage records, such as device identifiers, device ID, device type, mobile network data, login and logout records for applications or websites, referring websites (websites accessed before and after), application or website usage history, login logs, transaction logs, customer behavior, history of reward redemptions or benefits usage, website visit statistics, access times, search or viewing history, social media usage data, usage of various functions on the website, and information collected through cookies or similar technologies. 

3.3 Retention Period for Personal Data
The aforementioned details are examples of the data we collect. We only collect the necessary personal data and retain it for as long as required, depending on the type of personal data and the purpose of collection:

(a) We will retain the personal data of ASH Club application members, such as name, surname, email, and phone number, for the entire duration of membership in the ASH Club application. Once the membership is canceled, the data will be anonymized or destroyed within 30 days.

(b) For customers who are not members of the ASH Club application but participate in marketing activities organized by us, we will retain data such as name, surname, email, and phone number for the duration of each project, campaign, or marketing activity to verify identity and communicate with customers, or until the customer's consent for data processing expires. The data will be anonymized or destroyed within 30 days thereafter.

In the case of backup data stored on Microsoft Azure, the sub-processor will automatically delete it from the system within 6 months from the date of membership cancellation or termination of consent.

In cases where legal obligations apply, such as exercising legal claims, the data will be deleted after the statute of limitations has expired. Currently, we set the maximum retention period for personal data at 10 years from the date the customer terminates the service, membership, or contract with us. After the retention period expires, we will anonymize or destroy the collected personal data.

3.4 When we receive customer data, including personal data such as telephone numbers and email addresses from registration or the use of the ASH Club application, as well as other data outlined in sections 3.1 to 3.2, the ASH Club application will transmit this data to the service provider through an API. This is done to process the data for user identity verification and to provide various services to the users on the ASH Club application on our behalf.


4. Purpose of Collecting Personal Data for Use or Disclosure

We collect, use, and disclose personal data for the following purposes:

4.1 We use personal data as outlined in Section 3 to provide services to customers, improve our services, and for communication, identity verification, publicity, or to provide information and updates. Additionally, we may conduct customer surveys regarding our business activities. In providing services to customers, we may disclose or transfer personal data to third parties that process personal data for purposes in line with the terms of use for the ASH Club application. We may also engage agents or other contractors to provide services on our behalf or to assist in delivering products and services to customers. This may involve sharing personal data with, but not limited to:

(a) Providers of infrastructure, software, and website developers, as well as IT service providers.

(b) Data storage and cloud service providers.

(c) Providers for data cleansing, data matching, profiling, and data analytics services.

(d) Marketing agencies, advertising, and communication service providers.

(e) Consulting service providers.

This process will be carried out in compliance with relevant laws, regulations, and guidelines, both currently in effect and those that may be amended or introduced in the future, including for legal obligations or to comply with applicable rules and regulations that govern us.

4.2 We use personal data as outlined in Section 3.1 for the purpose of verifying or identifying the customer when accessing various services. This includes using phone numbers or email addresses for identity verification when logging in, registering, or signing up, by utilizing a One-Time Password (OTP) for the security of online transactions. The system sends the OTP via SMS. Additionally, personal data is used to facilitate contracts, fulfill contractual obligations, and provide services to ensure the security and confidentiality of all our services and communications.

4.3 We use personal data as outlined in Sections 3.1 and 3.2 to monitor customer service usage according to system security standards. This includes managing and protecting the information technology infrastructure. Where necessary, we may encrypt customer personal data and/or conduct random checks, penetration tests, and other activities to manage risk, detect, prevent, or eliminate fraud or other activities that may violate the law, relevant usage regulations, or terms and conditions of our application. This also serves to improve and enhance security standards and system stability.

4.4 We use personal data as outlined in Sections 3.1 and 3.2 to improve products, services, and enhance the efficiency of the services provided to customers.

4.5 We use personal data as outlined in Section 3.1 to contact customers via chat, social networks, phone, SMS, email, postal mail, or any other channels, in order to inquire, inform, or verify and confirm customer account information. This also includes conducting surveys or informing customers about service-related information as necessary.

4.6 We use personal data as outlined in Sections 3.1 and 3.2 to process and analyze for business-related purposes, such as account configuration and management, personalizing business content or user experiences, preventing fraud, and complying with laws and internal audit requirements.

4.7 We use personal data as outlined in Sections 3.1 and 3.2 to prevent or mitigate harm to the life, body, or health of customers, including customer property, or where it is necessary for us to perform a public service or to exercise a legal mandate entrusted to us or our employees or representatives, or to comply with the law.

4.8 We use personal data as outlined in Sections 3.1 and 3.2 for co-marketing purposes with companies within the ASH Asia International Group and business partners, provided that consent from the data owner has been obtained. The purposes include:

4.8.1 Marketing communication, providing information, or recommending products or services.

4.8.2 Offering promotions, marketing activities, discounts, and benefits from us and/or business partners. This also includes delivering marketing communications, conducting educational activities, research, statistical analysis, surveys, developing products and services, and preparing and sending marketing or advertising information within our group. The aim is to provide content, advertisements, events, promotions, and personalized recommendations tailored to customer interests.

4.8.3 Processing and analyzing data (Data Analytics), customer behavior, and interests (Customer Profiling) to offer personalized or relevant experiences, or those that may interest the customer, through the Loyalty/Reward Program.


5. Disclosure of Personal Data

We may disclose or transfer personal data of users to third parties who process personal data under the purposes stated in the Terms and Conditions of the ASH Club application, including companies within the ASH Asia International Group, business partners, and stores within the shopping centers owned by companies in the ASH Asia International Group, for the purposes outlined in Section 4. We may also engage agents or contractors to provide services on our behalf or to assist in the provision of products and services to customers. This may involve sharing personal data with, but not limited to:

Currently, when we receive customer data, including personal data such as phone numbers and email addresses, obtained from registration or usage of the ASH Club application, we send that data to service providers via API to Microsoft Azure for storage, collection, and processing to verify customer identity and provide various services on the ASH Club application on our behalf.

Beyond the above-mentioned cases, we will not disclose such data to third parties without the customer's consent unless permitted by law to collect, use, or disclose without requiring consent. Nonetheless, to provide services to customers or fulfill the terms and conditions of the ASH Club application, or to support our business operations, we may disclose personal data to companies within the ASH Asia International Group or business partners that collaborate with us, or other parties that need to perform work for us or customers, both within and outside the country.

For cases where a customer believes that their personal data has been used by third parties beyond the agreed-upon scope, they may notify us for further action. However, customers should also verify whether they have used the website, products, or services of our business partners or third parties directly, as they may collect personal data independently from the usage of the website, products, or services. In such cases, we cannot be responsible for the security or privacy of customer data collected by the third parties' websites, products, or services. Customers should exercise caution and review the privacy policies of those third parties.

Additionally, we will disclose personal data as required by law, such as to government authorities, regulatory bodies overseeing the service, or as part of legal processes, such as litigation or law enforcement requests. In the case of corporate restructuring, mergers, or asset sales, we may transfer personal data, either in whole or in part, to related companies.

Customers can view a list of companies within the ASH Asia International Group or business partners working with us, and other parties that work for us or customers, both domestically and internationally, to whom we disclose customer data, on our website. This list will be kept up to date, though the involved entities may change over time.

6. Access and Amendment of Personal Data

6.1 In the event that the customer does not wish to receive information and promotional materials from us, please notify us at ASH Contact Center: +66 2 5088787 or via E-mail: info@ash-asia.com.

6.2 The customer may fill out the "Personal Data Request Form" and submit it to us for consideration in accordance with the customer's request through the contact channels provided in Section 12 in the following cases: 

6.2.1 When the customer believes that we have collected their personal data and wishes to access or inquire about the details of their personal data that we have collected, or requests a copy of such personal data. 

6.2.2 When the customer wishes to amend or correct their personal data to ensure it is accurate, complete, and up to date. Note: If the customer is a member and uses the ASH Club application, they can update their personal data directly through the application by logging in and navigating to the "My Profile" menu to correct information, including deleting or changing their phone number, and manage settings accordingly. 

6.2.3 When the customer wishes to temporarily suspend the use of their personal data. 

6.2.4 When the customer wishes to object to the collection, use, or disclosure of their personal data, including objecting to the processing of their personal data. 

6.2.5 When the customer wishes to request that we delete their personal data from our system or customer database. 

6.2.6 When the customer wishes to withdraw the consent previously given to us for the collection, use, or disclosure of their personal data. 

6.2.7 When the customer wishes to be informed about the existence, nature, and purpose of the use of their personal data by us. 

6.2.8 When the customer wishes to request that we disclose the source of their personal data in cases where the data was not directly provided by the customer. We will consider and inform the customer of the outcome of their request within 30 days of receipt. However, we reserve the right to deny the customer's request under the conditions prescribed by law. If we cannot fulfill the customer's request, we will record the denial along with the reasons.

6.3 In the event that the customer does not consent to us collecting, using, or disclosing certain types of personal data or requests that we delete their personal data from our system, or withdraws their previously given consent, this may result in our inability to fulfill the customer's request or provide services. This may limit or reduce the effectiveness of the services the customer receives from us.

6.4 We will make every effort, within the capabilities of our relevant systems, to accommodate and act upon the customer's request unless it is found that fulfilling the request would risk violating the privacy policies of other users, contravene the law, or violate system security policies, or if it is otherwise impractical to fulfill the request.

6.5 In the event that the customer believes we have collected, used, and disclosed their personal data, and wishes to exercise their rights or has questions regarding their rights under the Personal Data Protection Act, B.E. 2562 (2019), including: 

6.5.1 Right to be Informed

6.5.2 Right to Withdraw Consent

6.5.3 Right of Access

6.5.4 Right to Rectification

6.5.5 Right to Erasure

6.5.6 Right to Restrict Processing

6.5.7 Right to Data Portability

6.5.8 Right to Object, Please contact or submit your request through the contact channels specified in Section 12.

6.6 In the event that the customer wishes to cancel their membership, they can access the "Cancel Membership" menu via the ASH Club application. Upon successful completion of this process, all personal data will be removed from the system immediately.


7. Security Measures for the Protection of Personal Data

We place great importance on the security of our customers' personal data and have implemented strict security measures. Our system for the collection, use, and disclosure of personal data is designed to be safe and appropriate, preventing the loss, unauthorized use, access, alteration, or disclosure of customer personal data. Access to personal data is restricted to employees, agents, contractors, and external parties who have a legitimate need to access the data, and they are permitted to process customer personal data only under the terms and conditions set forth by us.

Furthermore, we will retain personal data only for the purposes communicated to the customer, the owner of the personal data, and in accordance with applicable laws. In cases where we engage external parties to process customer personal data, we will select external parties with data protection systems that meet appropriate standards and enter into agreements ensuring compliance with our personal data protection policies.

In the event of a personal data breach affecting customer information, we will notify the Office of the Personal Data Protection Commission without undue delay, and no later than 72 hours after becoming aware of the breach, to the extent possible, unless the breach poses no risk to the rights and freedoms of the customer. If the breach presents a high risk to the customer's rights and freedoms, we will inform the customer promptly along with remedial actions to address the breach.


8. Links to External Websites, Applications, Products, and Services

Our application or website may contain links to external websites, products, and services. These external parties may collect certain information regarding the usage of their services by customers. We cannot be held responsible for the security or privacy of any customer data collected by such external websites, products, or services. Customers are advised to exercise caution and review the privacy policies of these external websites, products, and services.

9. Applicability of the Personal Data Protection Policy

This Personal Data Protection Policy applies to all personal data that we collect, use, and disclose. Customers agree to grant us the right to collect and use their personal data that we have already collected (if any), as well as any personal data that we collect currently and in the future, for use or disclosure to third parties within the scope defined in this Personal Data Protection Policy.

10. Policy Review

In the interest of good governance and social responsibility, we and the relevant authorities will review this policy at least once a year.


11. Governing Law and Jurisdiction

This Personal Data Protection Policy shall be governed by and construed in accordance with Thai law, and Thai courts shall have exclusive jurisdiction over any disputes that may arise.

12. Contact Channels

If customers have any questions or inquiries regarding this Personal Data Protection Policy, they may contact Ash Asia International Co., Ltd. through the following channels:

 

We have appointed Mr. Teerin Chanwatana as the Data Protection Officer (DPO), granting her the authority and responsibilities as specified by the Personal Data Protection Act B.E. 2562 (2019) and serving as the coordinator for our data protection efforts.

Contact Information:
Ash Asia International Co., Ltd.
999/9 The Offices at Central World,
19th Floor, Room No. OFML 1901-1903,
Rama I Road, Pathum Wan,
Pathum Wan, Bangkok 10330, Thailand
Contact Channels: +66 2 5088787
Email: info@ash-asia.com

In the event of a complaint regarding our company, employees, or staff violating or failing to comply with the law, data subjects may file a complaint with the supervisory authority as follows:
Office of the Personal Data Protection Commission
Contact Information: 7th Floor, Ratchaprasasanapakdee Building,
Government Complex Commemorating His Majesty the King’s 80th Birthday,
Chaeng Watthana Road,
Thung Song Hong, Lak Si,
Bangkok 10210, Thailand

Data subjects must file their complaints within the timeframe prescribed by law.