JANUA X BAMBAM PRESENTS SCENTS OF SOUL COLLECTION
Werin Wealth Intertrade Co., Ltd. (the “Company”) recognises the importance of protecting personal data and governs and manages personal data in accordance with the personal data protection law and other relevant laws. Accordingly, the Company hereby provides the following information in compliance with the Personal Data Protection Act B.E. 2562 (2019), with the key points below.
2.1 “Personal Data Protection Law” means the Personal Data Protection Act B.E. 2562 (2019), including the rules, regulations, and notifications issued under it by the Personal Data Protection Committee or other competent authorities, as well as any other law relating to the protection of personal data, or any other law that must be applied together with the Act or the rules, regulations, or notifications issued under it.
2.2 “Personal Data” means information about a natural person that enables the identification of that person, whether directly or indirectly, but excludes information of a deceased person specifically.
2.3 “Data Controller” means a person or juristic person having the authority to make decisions regarding the collection, use, or disclosure of personal data.
2.4 “Data Processor” means a person or juristic person who processes the collection, use, or disclosure of personal data under the instruction of or on behalf of a data controller, provided that such person or juristic person is not itself the data controller.
2.5 “Sensitive Data” means personal data concerning racial or ethnic origin, religion, political opinions, cult or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade-union information, genetic data, biometric data, or any other data which affects the data subject in a similar manner as prescribed by the Personal Data Protection Committee under the Act.
2.6 “Process Personal Data” means to collect, use, or disclose personal data.
2.7 “the Company” means Werin Wealth Intertrade Co., Ltd.
This policy applies to all processing of personal data carried out by the Company in respect of the personal data of the following persons:
3.1 Customers who are natural persons, whether current, former, or prospective customers, including the representatives of corporate customers.
3.2 Trading partners, contracting parties, business partners, and suppliers who are natural persons or the representatives of such contracting parties.
3.3 Shareholders who are natural persons or the representatives of juristic persons holding shares in the Company.
3.4 Managing directors, authorised representatives of juristic persons, and authorised agents of the Company.
3.5 Employees, officers, and personnel who currently work with the Company, formerly worked with it, or wish to work with it in the future, regardless of whether their contract is permanent or temporary, including outsourced staff, probationers, and interns.
3.6 Persons who participate in activities organised by the Company, or activities the Company holds jointly with other organisations, where processing of personal data occurs.
3.7 Any other person who is a co-owner of personal data with the persons under 3.1 – 3.6 whose personal data is processed by the Company.
In addition, this policy applies to processing of personal data that may occur on websites, applications, mobile devices, or any other means by which the Company processes the personal data of the data subject.
However, this policy does not cover personal data you provide to the Company through other channels that are not directly under the Company’s control, such as social networks (e.g. Facebook, Line, Instagram, Twitter, TikTok, etc.), or where you purchase products or use services from a distributor, person, or entity certified by the Company, as the Company has no authority to control such personal data. In such cases, if the data subject wishes to know the processing details or to exercise their rights under the personal data protection law, they must contact that person or entity directly, unless the Company has appointed such person or organisation as a data processor under a written data-processing agreement, which stipulates that the person must disclose their legal status before or during collection — in which case the processing falls under this policy immediately.
The Company processes data on the following legal bases: Consent, Contract, Legitimate Interest, and Legal Obligation.
The Company collects, uses, and discloses your personal data for the following purposes:
4.1 To enable you to register for JANUA activities, promotions, campaigns, or marketing activities.
4.2 To verify identity, check eligibility, and contact participants, including announcing results and awarding prizes.
4.3 To process orders, delivery, product warranty, after-sales service, and to answer enquiries.
4.4 To manage members, customers, and the Company’s customer database.
4.5 To send news, privileges, promotions, campaigns, new product launches, or JANUA activities (where consent is given).
4.6 To analyse statistical data, study consumer behaviour, and develop products, services, and the customer experience.
4.7 To make JANUA’s website, applications, and online channels more effective.
4.8 To manage customer relationships, gather feedback, and improve service quality.
4.9 To comply with the law, orders of government authorities, or to exercise the Company’s legal rights.
4.10 To prevent fraud, unlawful acts, or the improper exercise of rights in activities.
4.11 To disclose data to service providers, trading partners, or business partners involved in running activities, delivery, or service provision, within the scope permitted by law.
The Company may collect the following personal data:
5.1 Identity data, including full name, date of birth (if necessary), gender (if necessary), national ID number, or Passport ID.
5.2 Contact data, including telephone number, email, delivery address, Line ID, or other contact channels.
5.3 Participation data, including registration details, proof of participation, entitlement history, and order number (if relevant).
5.4 The data subject may exercise their rights via email, stating their full name, telephone number, and request details; the Company will act within the period prescribed by law.
5.5 Purchase data, including product items, order history, and payment method information (excluding full credit-card details).
5.6 Website usage data, including IP address, browser, device, cookies, and website access logs.
5.7 Marketing data, including product interests, website usage behaviour, survey responses, and opinions on products and services.
5.8 Participation in activities may involve recording images, audio, or video of participants, which the Company may use for publicity, publishing via the website, social media, or the Company’s marketing media, without affecting the data subject’s legal rights.
5.9 The Company may use cookies and similar technologies to analyse website usage, improve service efficiency, and present relevant information; users may configure or reject cookies through their browser.
5.10 If a participant is a minor requiring consent from a legal guardian, the Company may seek the guardian’s consent before processing the personal data.
6.1 The Company may collect personal data through 2 channels:
6.1.1 Collected directly from the data subject, e.g. via marketing staff, the website, mobile applications (such as on a phone or tablet), social networks (e.g. Facebook, Twitter, LinkedIn, or Instagram) operated or used by the Company, JANUA activity registration forms, orders placed through the website, applications, Official Store marketplaces, Google Forms, online forms, and JANUA’s Official social media.
6.1.2 Collected from sources other than the data subject directly, e.g. searching personal data via websites or social networks (Facebook, Twitter, LinkedIn, or Instagram), third-party online platforms, or other public sources, or enquiries from service providers, advisors, business partners, official agencies, or third parties. In such cases the Company will notify the data subject without delay and no later than thirty days from the date of collection from such source, and will seek consent for such collection, except where an exemption from obtaining consent or notice applies by law.
6.2 The Company will obtain express consent from the data subject before or at the time of collecting personal data, except in the following cases where the Company may collect personal data without consent:
6.2.1 To achieve purposes relating to the preparation of historical documents or archives for the public interest, or relating to research or statistics, with appropriate safeguards to protect the rights and freedoms of the data subject.
6.2.2 To prevent or suppress danger to a person’s life, body, or health.
6.2.3 The Company will retain data for as long as necessary for running activities, product warranty, eligibility verification, litigation (if any), or within the period prescribed by law.
6.2.4 Where necessary to perform a task carried out in the public interest, or to exercise official authority vested in the Company.
6.2.5 Where necessary for the legitimate interests of the Company or of another person or juristic person, except where such interests are overridden by the fundamental rights of the data subject in their personal data.
6.2.6 Where necessary for the establishment, compliance, or exercise of legal claims — a basis under the PDPA.
6.2.7 To comply with the law. In general, the Company will not collect sensitive data unless it is necessary or unavoidable to process such sensitive data, and if so, the Company must obtain express consent from the data subject before or at the time of collecting such sensitive personal data, except where an exemption applies under the personal data protection law.
The Company will retain personal data for the following periods:
7.1 Where a specific retention period is prescribed by law, the Company will retain the personal data within that period, e.g. the Revenue Code, the Accounting Act B.E. 2543 (2000), the Labour Protection Act B.E. 2541 (1998), etc.
7.2 Where the law does not prescribe a specific retention period, the Company will set a retention period as reasonably necessary for its operations.
Upon expiry of the above retention period, the Company will delete, destroy, or anonymise the personal data so that the data subject can no longer be identified.
8.1 Right to withdraw consent: The data subject has the right to withdraw the consent given to the Company for processing their personal data. Withdrawing consent may affect actions that may occur after the withdrawal. However, withdrawal does not affect processing for which the Company has already obtained the data subject’s consent prior to the withdrawal.
8.2 Right to access: The data subject has the right to request access to, obtain a copy of, or ask the Company to disclose the acquisition of their personal data held by the Company.
8.3 Right to restriction: The data subject may request the Company to restrict the use of their personal data.
8.4 Right to data portability: The data subject has the right to obtain their personal data from the Company in a format that is readable or commonly usable by automated tools or equipment and can be used or disclosed by automated means. The data subject may also request the Company to transfer or send their personal data in such a format to another data controller by automated means, or request the Company to directly receive or transfer their personal data to another data controller, where technically feasible.
8.5 Right to object: The right of the data subject to object to the processing of their personal data under the Company’s control.
8.6 Right to be forgotten: The data subject has the right to delete or destroy their personal data, or to anonymise it so that it can no longer identify them.
8.7 Right to rectification: The right of the data subject to request the Company to correct their personal data so that it is accurate, up to date, complete, and not misleading.
8.8 Right to lodge a complaint: Where the data subject considers that there has been a breach of the personal data protection law, the data subject has the right to lodge a complaint with the Personal Data Protection Committee immediately.
The Company has established appropriate methods for data storage to prevent harm that may arise from the leakage, access, deletion, destruction, transfer, or disclosure of personal data without authorisation from the data subject or the Company. Only persons authorised by the Company or by law will have the right to access the location where such personal data is stored.
Where the Company engages an external agency or person to process personal data for the Company’s purposes and on its behalf, the Company will require that agency or person to keep the personal data confidential and secure, and to prevent the personal data from being collected, used, or disclosed for any other purpose outside the scope of engagement or contrary to law.
Only persons with the authority and duties assigned by the Company or by law may access and use the personal data the Company has collected. The Company will establish measures for accessing and using data by category, situation, event, or relevant position, to prevent harm to or infringement of the data subject’s rights.
For personal data collected by the Company before the personal data protection law took effect, the Company has the right to continue processing such personal data for the original purpose without obtaining the data subject’s consent.
Under the purpose in clause 4.4, the Company may disclose personal data as necessary to agencies or third parties with the data subject’s consent, except where done within the scope authorised by law. For personal data in the Company’s possession, the Company may disclose your personal data as necessary to: affiliated companies (if any), website-system providers, cloud providers, delivery providers, payment-system providers, event organisers, marketing and customer-relationship-management (CRM) providers, as well as government agencies or authorities empowered by law. The Company will disclose data only as necessary, under data-security measures, and in accordance with the purposes stated in this policy.
The Company uses appropriate organisational, technical, and administrative measures to protect the personal data under its control from destruction, loss, access, use, alteration, or disclosure, whether such damage arises from intent or negligence.
However, it is generally understood that processing personal data over the internet cannot be made perfectly secure. For this reason, the Company will develop its security systems in line with current technology and within the reasonable cost of technological change.
If this privacy policy statement is amended, the Company will notify you by publishing it through the Company’s appropriate channels.
Address: 120 Moo 21, Tha Ko Subdistrict, Mae Suai District, Chiang Rai 57180, Thailand
Telephone: 065-5415-5650
Email: Werinwealth001@gmail.com