loader-a&t

The Architects and Turnkey Public Company Limited ("the Company") recognizes the importance of personal data protection and maintains appropriate security measures in accordance with international standards. This Privacy Policy ("Policy") is published to inform all relevant individuals and is binding upon the Company's executives, employees, and external personnel. The objectives of this Policy are as follows:

  • To ensure that transactions with the Company are secure, reliable, and instill confidence in data subjects.
  • To prevent damage arising from the fraudulent exploitation or unlawful use of personal data.
  • To comply with personal data protection laws; the Company shall not disclose collected personal data to third parties except as required by law.
  1. Scope of Application

    This Privacy Policy applies to personal data that the Company may collect, use, disclose, or transfer abroad for the following groups of individuals:

    • Construction business customers and other types of customers, including individuals and employees/representatives of corporate customers.
    • Contractors and business partners, including individuals and employees/representatives of corporate partners.
    • Shareholders, investors, and prospective investors.
    • Visitors and persons entering Company premises.
    • Stakeholders and persons from whom the Company may collect data for social activities or other purposes.
    • Personnel, employees, and job applicants, including family members or reference persons.

    This Policy also covers all communication channels, whether electronic systems, websites, applications, online channels, various activities, and premises under the Company's responsibility.

  2. Definitions

    Personal Data Protection Law

    The Personal Data Protection Act B.E. 2562 (2019), including any royal decrees, ministerial regulations, notifications, rules, regulations, or guidelines issued thereunder.

    Personal Data

    Information relating to an individual that can identify such person, directly or indirectly, such as name, surname, address, telephone number, national identification number, passport number, bank account number, IP address, Cookie ID, etc. Business contact information that does not identify an individual, anonymized data, or data of deceased persons are not considered personal data.

    Sensitive Personal Data

    Data classified as sensitive under the Personal Data Protection Act, such as religion, health data, disability, biometric data (e.g., facial recognition, voice identity, fingerprints), etc.

    Data Subject

    A natural person who can be identified, directly or indirectly, by personal data. This does not include juristic persons established under the law.

    Personal Data Protection Working Group

    A group of persons appointed by the Company to monitor, audit, and advise on the Company's data processing activities to ensure compliance with applicable laws.

  3. Purposes of Personal Data Processing

    • For communication and relationship management, such as responding to inquiries, sending news and updates, and administering contracts and accounting/finance.
    • For pre-contractual activities and managing contractual parties, such as evaluating the qualifications of job applicants, contractors, or business partners.
    • For compliance with applicable laws, such as disclosure by order of government authorities, labor laws, and tax laws.
    • For recruitment, selection, and human resources management, such as hiring, background checks, employment contracts, performance evaluations, training, payroll, and benefits administration.
    • For analysis, development, and improvement of operational quality, such as analyzing website or system usage behavior.
    • For security of persons and assets, such as CCTV recording, access monitoring, and visitor registration.
    • For risk management, internal audit, and corporate governance, such as accounting audits, and reporting to management or shareholders.
    • For any other purposes of which the data subject has been informed at the time of collection or subsequently on an explicit basis.
  4. Types of Personal Data Collected by the Company

    Data Type Examples
    General personal data Name, surname, nickname, date of birth, gender, age, address, telephone number, email address, etc.
    Government document data National ID number, passport number, social security number, tax ID number, driver's license number, etc.
    Employment data Job title, employment history, training history, performance evaluations, leave records, employment status, etc.
    Financial data Bank account number, payment records, income, tax information, payslips, etc.
    Technical data IP address, Cookie ID, log files, website usage data, etc.
    CCTV data Images or audio recorded when entering Company premises.
    Sensitive data Only when necessary and with explicit consent, such as health data, biometric data, disability, religion, etc.
  5. Roles and Responsibilities of Personnel

    Board of Directors

    Oversees, promotes, and supports the Company's personal data protection practices in compliance with the law.

    Executive Committee

    • Oversees, promotes, and supports operational processes in compliance with the law.
    • Establishes policies and action plans for personal data protection.
    • Appoints and assigns duties to personnel as required by law.

    Personal Data Protection Working Group

    • Advises the Board, management, and employees on compliance with the law.
    • Monitors, audits, and oversees the Company's data processing activities.
    • Serves as the central point of contact for personal data matters and coordinates with government authorities.
    • Develops and maintains relevant personal data protection procedures.

    Employees

    • Comply with the Personal Data Protection Act and the Company's policies and procedures.
    • Immediately report to supervisors and/or the Working Group upon discovering any data breach or violation.
    • Report policy violations through the Company's whistleblowing channels.
  6. Cookies and Cookie Usage

    When visiting the Company's website, cookies may be placed on the visitor's device and data may be collected automatically. Some cookies are necessary for the website to function properly, while others are provided for the visitor's convenience. For more information, please refer to the Company's Cookie Policy.

  7. Limited Collection of Personal Data

    The Company collects data that you have provided directly or that is generated from your use of services or communications with the Company, whether in document form or computer traffic data. Collection is conducted lawfully, fairly, and appropriately, and only to the extent necessary for operations.

    The Company will inform you of the purposes of collection and the consequences of not providing data, and will obtain your consent prior to collection unless otherwise permitted by law. Where sensitive data must be collected, the Company will always obtain explicit consent beforehand.

    The Company may also collect personal data from sources other than the data subject directly, only when necessary and as permitted by law, such as from relevant service providers or public media.

  8. Personal Data Required for Legal or Contractual Compliance

    The Company may need to collect certain types of personal data that are essential for compliance with the law or for the proper performance of a contract, such as name, surname, national ID number, and bank account information for compensation payments, in order to comply with tax laws, labor laws, and employment or service agreements.

    If you refuse or do not wish to provide such necessary personal data, the Company may be unable to proceed with the relevant processes, such as considering job applications, executing contracts, paying compensation, or providing services under a contract.

  9. Disclosure of Personal Data

    Access to your personal data is restricted to persons who have a need to know in order to carry out the purposes stated in this Policy. However, the Company may disclose or transfer your personal data to:

    • Third parties as required by law: For compliance with legal obligations and government orders, including disclosure under securities and stock exchange laws.
    • Within the corporate group: For internal administration as necessary.
    • Service providers to the Company: Such as contractors, construction subcontractors, internet service providers, web developers, architecture/engineering service providers, auditors, lawyers, and legal advisers.
    • Any other person related to disputes or authorized to manage any interests.
    • Any person: To whom the Company has been instructed by you to disclose data.

    The Company will use or disclose your sensitive personal data only for the purposes for which explicit consent has been obtained or as required by law.

  10. Retention, Duration, and Security Measures

    The Company retains personal data only as long as reasonably necessary to fulfill the stated purposes, taking into account contractual periods, statutory limitation periods, audit requirements, and the establishment or exercise of legal claims. After the retention period expires, the Company will delete, destroy, or anonymize the data.

    The Company maintains personal data with appropriate security measures in accordance with international standards to prevent loss, unauthorized access, use, or disclosure. The Company restricts access and uses security technology, and ensures that third parties processing data on its behalf do so appropriately.

    However, the Company cannot guarantee the security of data you disclose through online channels. The Company therefore reserves the right to disclaim liability for damages arising from unauthorized access.

  11. Data Subject Rights

    Under the Personal Data Protection Act, data subjects have the following rights:

    Right Details
    Right to withdraw consent You may withdraw consent for data processing at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
    Right to access personal data You may request access to your personal data held by the Company and request a copy of such data.
    Right to data portability You may request to receive your data in a machine-readable electronic format and, in certain cases, request that it be transferred to another party or to yourself.
    Right to object to processing You may object to the collection, use, or disclosure of your personal data in cases prescribed by law.
    Right to erasure or destruction You may request that the Company delete, destroy, or anonymize your personal data by any means.
    Right to restriction of processing You may request that the Company restrict the use of your data, except where limited by law.
    Right to rectification You may request correction, amendment, or supplementation of personal data that is inaccurate or incomplete.
    Right to lodge a complaint If you have concerns or questions regarding compliance with the Personal Data Protection Act, you may file a complaint with the competent authority as prescribed by law.
  12. Penalties for Non-Compliance with the Policy

    Failure to comply with the Company's Privacy Policy that results in a legal violation or damage shall be subject to disciplinary action in accordance with the Company's regulations and legal penalties as applicable. If such violation causes damage to the Company or any other person, the Company may consider taking additional legal action.

  13. Updates to the Privacy Policy

    The Company may review, amend, or update this Policy from time to time to ensure compliance with applicable practices, laws, rules, and regulations. Any updates will be published on the Company's website or through other appropriate channels.

  14. Contact Information

    If you have any questions or require further information regarding personal data protection, please contact the Company through the following channels:

    Data Controller

    The Architects and Turnkey Public Company Limited

    47/47 Moo 9, Bang Len, Bang Yai, Nonthaburi 11140, Thailand

    Data Protection Officer (DPO)

    The Architects and Turnkey Public Company Limited

    47/47 Moo 9, Bang Len, Bang Yai, Nonthaburi 11140, Thailand

    This Policy is effective from 1 November 2025 onwards.

Privacy Policy

The Architects and Turnkey Public Company Limited