Kiatnakin Phatra Bank Public Company Limited (“KKPB”), Kiatnakin Phatra Securities Public Company Limited (“KKPS”), Kiatnakin Phatra Asset Management Company Limited (“KKPAM”), KKP Dime Securities Company Limited, KKP Capital Public Company Limited and KKP Tower Company Limited (collectively referred to as “Kiatnakin Phatra Financial Group”, “we”, “us” or “our”), including any funds and Trusts under our management or establishment, recognize the importance of your Personal Data and therefore issue this Privacy Notice in order to help you understand our guidelines on protecting your Ppersonal Ddata, to describe our grounds for and means of collection, use, or disclosure your Personal Data and to explain your rights in connection with such Personal Data as well as your options to protect such Personal Data when using our services or products through any channels.
We will collect, use, or disclose your Personal Data merely to the extent necessary to fulfill any of the following purposes as specified in this Privacy Notice or any other purposes as specified in any document or electronic mean in respect of giving consent for the collection, use, or disclosure your Personal Data.
This Privacy Notice applies to how we collect, use, or disclose your Personal Data in relation to the use of our services or products through channels, including our branches, websites, applications or other service channels, or our business partners’ service channels. This Privacy Notice does not apply to the use of other services or products which do not belong to us or are not under our control. This Privacy Notice applies to the Personal Data (as set out in Clause 2 below) of the following data subject(s):
(1) our individual customers including prospective customers (potential customers), current customers and former customers and individual persons related to such individual customers;
(2) employees, personnel, staffs, representatives, shareholders, authorized persons, directors, contact persons, agents and other individual persons related to our corporate customers and individual customers including prospective customers (potential customers), current customers and former customers;
(3) individual persons who are our former, existing or future outsourcing service providers or vendors including individual persons related to our former, existing or future outsourcing service providers or vendors; and
(4) our securities holders or other related holders including any related assignees or assigned proxies
(5) other persons who contact us through any channels or our service recipients whether directly though any of our services, or indirectly through our vendors, or agents.
The Personal Data which we have already processed will be considered as our property.
Natural/individual persons, as “you” or “your”, and the individual customers and the corporate customers, collectively referred to as the “Clients”.
This Privacy Notice is prepared in Thai and English translation. In the event of any inconsistency, the Thai Privacy Notice shall prevail.
“Personal Data” means any identified or identifiable information about you as listed below. We may collect your Personal Data directly from you e.g. through our staffs, call center or other service channels or indirectly from other sources e.g. any company in Kiatnakin Phatra Financial Group, public source, social media where you have set as public, outsourcing service providers, advisors, business partners, agencies, organization, or any person having a contractual relationship with us, such as third-party custodians, sub-custodians and brokers, domestic and international government agencies, your representatives or agents and any authorized person in accordance with the laws, or any person you have given permission or consent for disclosing your Personal Data to us, provided that those data providers have complied with the personal data protection laws. The types of Personal Data we collect depend on the relationship between the Clients or juristic persons and us, as well as services or products the Clients require from us.
"Sensitive Data" means Personal Data classified by law as sensitive data.
In case of individual customers
Personal Data includes:
g) online information, the Clients’ preferences of browsing or using data via electronic channels, data and activities on social media, including financial data, member login, IP Address, intelligent device information, identity verification, browsing, location, website access, spending patterns or searches related to our services or products by using Cookies or connecting with other websites you accessed.
In case of corporate customers or outsourcing service providers or vendors
Personal Data includes:
a) identity Data, such as first name, last name, date of birth, nationality, national identification number, passport number (in case of foreigners), information on personal profile, education, occupational data (e.g. occupation, work place, job title, entitlement or shareholding proportion), signature, photo, house registration, including Sensitive Data as specified below;
b) contact details, such as address, telephone number, email;
c) information generated in connection with the relationship between the Clients and us, such as account opening, administration, operation, payment, settlement, processing and reporting on behalf of the Clients which may include signatures and your correspondences with us;
d) other Personal Data collected, used or disclosed in connection with relationship with us, such as information provided to us in agreements, forms, surveys or questionnaires, or information collected when you participate in our business activities, marketing, seminars or social events, and data from analyzing, researching, and organizing your data for profiling in which we collected data from observing your behavior and/or location by using Cookies or any other technology or electronic means in order to provide and develop our services or products; and
e) images and voices obtained when contacting us (Communication data), such as copies of national identification card, copies of passport, images and/or voices from CCTV, telephone call, or our online channels or any other electronic channels.
Your Sensitive Data which we will collect, use, disclose or cross-border transfer, such as:
a) fingerprint, finger vein, facial recognition, iris recognition, voice recognition, including other Sensitive Data correspondingly for the purposes of proofing and authentication of your identity and carrying out your transactions ;
b) religion and blood type as only appeared on copies of your national identification card as evidence for establishment, compliance, exercise or defense of legal claims;
c) criminal records for public interest in relation to protecting, dealing with and minimizing risks which may occur as a result of any illegal activities, such as money laundering, terrorism or public fraud; and
d) information regarding disability, health or dysfunction in order for us to take care of and render a service to you in compliance with the laws.
We will collect, use or disclose your Sensitive Data merely to the extent necessary to fulfill any of the following purposes as specified Clause 3 and we will procure appropriate measures in order to protect your fundamental rights and benefits.
In case you deny giving the necessary information to us for providing our services, we may not provide you our services in part or in full. In case you give us the Personal Data of other person, you are responsible for notifying such person to acknowledge our Privacy Notice or our services’ term & condition, including having their consent prior disclose other person’s Personal Data to us in some case.
We will collect, use, or disclose your Personal Data to the extent necessary to fulfill any of the purposes set out in the table below. The following Lawful Basis are in accordance with the Persona Data Protection Act B.E. 2562 (2019), The Lawful Basis shall be varies depending on the services or products or relationship you had, have or will have with us.
Purposes of the collection, use, and/or disclosure of your Personal Data | Lawful Basis for doing so |
Operating and rendering services or products provided by any companies under Kiatnakin Phatra Financial Group, or our business partners to you such as account opening, financial planning service, loan application , contacting in relation to the service, emergency contacting and other services or products. |
|
Suggesting services or products provided by any companies under Kiatnakin Phatra Financial Group or our business partners which are similar or related to the services or products you have with us, provided that you did not show any intention to prohibit a telephone contact or we are not prohibited by any other applicable laws, including researching, statistic recording, and analysing your data for the suggestions of such services or products. |
|
Suggesting services or products of each Company in Kiatnakin Phatra Financial Group or our business partners which are not similar or not related to the services or products you have with us , including researching, statistic recording, and analysing your data for the suggestions of such services or products. |
|
Disclosing your Personal Data e.g. first name, last name and contact details to any receiver for marketing purposes. |
|
Processing your request to participate in our activities or projects e.g. promotional activities, trainings, seminars , receiving news and updates |
|
Facilitating you and for benefit of providing you with a service requesting the information you have with all of our companies, including rendering services in connection with our services or products which your have or will have with us. |
|
Conducting Know Your Customer and/or Customer Due Diligence for accuracy, true and up-to-date. |
|
Reporting Personal Data to government agencies supervising our business operation or when receiving a summons or suspension from a government agency or court. |
|
Preventing, detecting, and dealing with unusual transactions to mitigate risks which may arise and lead to illegal activities including sharing Personal Data to upgrade our working standards for such purposes. |
|
Complying with our internal procedures, such as when you open an account or carry out any transaction with us, we have to authenticate and verify if you are an owner of the account, and we may investigate any other facts or circumstances to support your transaction request. |
|
Analyzing risks based on your behavior, such as credit scoring. |
|
Getting insurance for collateral, getting life insurance by appointing KKPB as beneficiary, getting insurance preventing risk of credit customer group, for example, requesting Thai Credit Guarantee Corporation to be a guarantor of the credit debtor group of KKPB, purchasing credit default insurance with KKPB for import and export. the credit debtor group of KKP, purchasing credit default insurance with KKP for import and export. |
|
Building a relationship with the Clients, outsourcing service providers or vendors who have disclosed your Personal Data to us, such as entering into a contract with the individual customers or the corporate customers, our business partners, vendors or outsourcing service providers e.g. verification of information for supporting loan applications of the corporate customers which we may need to review documents that may contain your or third party’s Personal Data or in case we enter into a contract with any juristic person that may contain your or third party’s Personal Data, provided that such juristic person has complied with the personal data protection laws and this Privacy Notice. |
|
Maintaining customer relationships, such as managing complaints, managing your request in accordance with the laws, satisfaction surveys, or offering special benefits |
|
Processing data and analyzing data statistic where those results will not be identifiable as you. |
|
Researching, statistic recording, and analysis your data for providing our services and products and our business partners to suit your demand and preferences, including enhancing your benefits |
|
Recording everyone entering our office buildings, branches, or spaces through CCTV for security purposes and verifying our transactions. |
|
Recording videos and/or voices through telephone or any other electronic means to verify your requests, orders, or complaints , or for analyzings, improving and developing our products and/or services, including training our employees for such purposes. |
|
Interviewing for use in preparation of any form of media such as publication and electronic media through channels, such as our websites, social media and internal email to our employees for public relations and advertisement. |
|
Recording images, videos, or voices in trainings, seminars, or other activities that we organized or supported such as annual general meetings, in order to make a media in any form, such as, printing or electronic media through any channel such as our websites, social media and internal communication email for the advertising and public relation purposes. |
|
Using your fingerprint, finger vein, facial recognition, iris recognition, voice recording, including other Sensitive Data correspondingly for verifying and authenticating your identity and carrying out your transactions. |
|
Collecting and using of your Sensitive Data such as religion or blood type as only appeared on copies of your national identification card. |
|
Collecting information regarding your disability, health and/or dysfunction to offer special care or for our references to analyze your risks upon receiving services or product by us or through us. |
|
Managing risks, supervising conduct, managing internal management, and transferring of data amongst the companies in Kiatnakin Phatra Financial Group for such purposes under the agreements mutually agreed by the companies in Kiatnakin Phatra Financial Group. The process above will be subject to appropriate safety measures in accordance to the laws. |
|
Collecting debt and enforcing obligations arising from our agreement, liabilities, legal rights, investigation, seizure, and take over assets or property, including bringing into auction or any other activities in a similar way. |
|
Transferring of a group debt sale to third persons such as sale of non-performing loan (NPL) to an asset management company. |
|
Using and disclosing of your Personal Data for the purposes of transfer or disposal of business assets or shares (whether in whole or in part) or the disclosure for conducting due diligence as normal practice of our business. We will have an appropriate safety measure according to the laws |
|
Managing the securities’ issuer in relation to the securities holders or any assignees, appointed proxies, members of the provident fund, fund administrator, securities registrar, Trusts registrar |
|
The disclosure of your Personal Data in accordance with rules and regulations prescribed by organizations or regulators in a foreign country or in accordance with such foreign country’s laws or international convention. |
|
We may process your personal data in accordance with the above-mentioned purposes through our existing technologies or as we may occupied in the near future, including but not limited to the use of Artificial Intelligence (AI), Cloud Computing, Block Chain, and Biometric Comparison.
In the event that we have not obtained your consent, you may not be able to use our services or products, have a convenience or obtain a performance of agreement, and you may be damaged or may lose opportunity, and it may affect a performance pursuant to any law which you or we must comply.
In addition to this, we may transfer your Personal Data outside of Thailand in order to carry out the above-mentioned purposes merely in accordance with Clause 8 Cross-border transfer of your personal data.
If you have given consent, or it is necessary for complying with contracts, substantive public interest, laws or regulations, or it is in our legitimate interests, we may send, transfer and/or disclose any of your Personal Data to the following third parties, whether located in or outside Thailand. We will act in accordance with the laws and will procure sufficient personal data protection standards.
You may exercise the following rights:
5.1 Right to Access
You have the right to access and request a copy of your Personal Data which is under our responsibilities or request us to disclose the sources of your personal data which you have not given consent.
5.2 Right to Rectification
You have the right to request us to rectify your Personal Data in order for data to be accurate, up-to-date and not misleading.
5.3 Right to Erasure
You have the right to request us to delete or destroy or anonymize your Personal Data in case of the following events:
5.4 Right to Restriction of Processing
You have the right to restrict our processing of your Personal Data in case of the following events:
The processing of Personal Data is no longer necessary but the collection remains necessary for exercising legal claims;
It is an unlawful processing of Personal Data but you desire to restrict the processing instead of deleting or destroying the personal data;
During the process of demonstrating the objection of the request.
5.5 Right to Data Portability
You have the right to receive Personal Data concerning you from us in case that we have arranged your Personal Data in the format which is readable or commonly used by ways of automatic tools or equipment, and can be used or disclosed by automated means and (a) have the right to request us to send or transfer your personal data in such formats to other data controllers if it can be done by the automatic means or (b) request to directly obtain your Personal Data in such formats that we send or transfer to other data controllers, unless it is impossible to do so because of the technical circumstances.
5.6 Right to Object
You have the right to object the collection, use or disclosure of your Personal Data in case that
the collection, use or disclosure of your Personal Data is for the purpose of direct marketing;
the collection, use or disclosure of your Personal Data is for the purposes of scientific, historical or statistic research unless it is necessary to performance of a task carried out for reasons of public interest by us;
the collection of your personal data based on an essential reason for carrying out our public interest tasks or legitimate interest unless we can demonstrate that there is a more important legal grounds or it is to establish legal claims, comply with laws or exercise or defence of legal claims.
5.7 Right to Withdraw Consent
You have the right to withdraw consent given to us for collecting, using or disclosing your Personal Data at any time unless there is a restriction on the right to withdraw consent as required by law or pursuant to a contract that benefits you, for example, you still use our services or products or you still have a contractual obligation to render to us.
Your above-mentioned rights are subject to the various relevant factors which in some case we may not be able to process your request due to our legal obligations or liabilities relating to the collection, usage, or disclosure of your Personal Data, you still have a deposit account or a credit account with us or still use other services with us, or we are required to collect your Personal Data for a period specified by laws even if you have ended the contractual relationship with us
If you wish to exercise your rights, please request for the Data Subject Right Request Form at our branches or KKP Contact Center and submit it to our branches, KKP Contact Center or [email protected] or other channels as further specified in each transaction. In addition to this, we will process your request within 30 days upon our receipt of such request and we could extend such period for not more than 30 days, unless otherwise required by laws.
We maintain technical, physical, and administrative security measures designed to provide optimal protection of your Personal data from loss, misuse, unauthorized access, disclosure and modification. Such Security measures are firewall, data encryption, physical access control when accessing our data center and data access control. While we maintain our security systems and services, you are responsible for maintaining the security and privacy of your password and information regarding your account and verifying that your Personal Data we have is accurate and up to date.
We prescribe the policies, manuals and minimum standards for handling the Clients’ Personal Data such as IT security standards and improve such policies, manuals and minimum standards from time to time according to the law.
In addition, our personnel, employees or outsourcing service providers are obliged to keep the Clients’ Personal Data confidential in accordance with the confidentiality agreements signed with the Kiatnakin Phatra Financial Group.
We collect and use cookies technology to secure our websites, to enhance the efficiency and security upon using our websites and online services and to develop our services or products to suit your demands or to expand your benefits. Cookies are very small files that the websites store on your computer's hard drive or electronic device which record your Personal Data or other data that you filled without particularly recording data of any specific person. You can check cookies status or refuse the use of cookies in your browser. For more information about Cookies, please see our Cookies Policy.
For the purposes as mentioned above in this Privacy Notice, we may disclose or transfer your Personal Data to third parties or servers located overseas which the destination countries may or may not have the same data protection standards as Thailand. In addition, we have taken steps and measures to ensure that your Personal Data is securely transferred, that the data recipients have suitable data protection standards in place, and that the transfer is lawful by relying on the derogations as permitted under the law.
Our activities are not generally aimed at minors, quasi-incompetent or incompetent persons and we do not knowingly collect Personal Data from such persons without their parental consent, or from quasi-incompetent persons and incompetent persons without their legal guardian's consent. If you are a minor, quasi-incompetent or incompetent person and wish to engage in a contractual relationship with us, you must obtain the consent from your parent or legal guardian prior to contacting us or providing us with your Personal Data.
We will retain your Personal Data for as long as it is reasonably necessary to fulfill the purposes for which we have obtained your Personal Data as set out in this Privacy Notice, and to comply with legal and regulatory obligations. We may extend to retain your Personal Data if it is necessary for you to exercise any legal defenses, claims, or rights. After such period, and your Personal Data is no longer necessary for the purposes as specified above, we will delete, destroy, or anonymize your Personal Data according to the standards issued by the Personal Data Protection Committee or any laws or international standard.
In some case, your Personal Data e.g. name, surname, address, date of birth, the start and end date of your relationship with us, may be stored as our archive database and will not be used or disclosed to other persons for any purpose.
In order to improve efficiency in operating your Personal Data, we may amend this Privacy Notice as we deem appropriate by publishing its latest version on our websites. We will notify you if such changes materially affect the operation of your Personal Data.