Last updated: July 2026
WERIN WEALTH INTERTRADE CO., LTD. (the "Company") recognises the importance of protecting personal data and manages personal data in accordance with the personal data protection law and other relevant laws. We therefore provide the following information in compliance with the Personal Data Protection Act B.E. 2562 (2019), with the key content as set out below.
2.1 Personal Data Protection Law means the Personal Data Protection Act B.E. 2562 (2019), including regulations, rules and notifications issued under it by the Personal Data Protection Committee or other competent authorities, as well as any other laws relating to the protection of personal data.
2.2 Personal Data means information about a natural person which enables that person to be identified, whether directly or indirectly, but excluding the data of a deceased person.
2.3 Data Controller means a person or legal entity with the authority to decide on the collection, use or disclosure of personal data.
2.4 Data Processor means a person or legal entity that collects, uses or discloses personal data under the instruction of, or on behalf of, the data controller, and who is not itself the data controller.
2.5 Sensitive Data means personal data concerning race, religion, ethnicity, political opinions, cult/religious or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade-union information, genetic data, biometric data, or any other data which affects the data subject in a similar manner as prescribed by the Personal Data Protection Committee.
2.6 Processing of Personal Data means the collection, use or disclosure of personal data.
2.7 The Company means WERIN WEALTH INTERTRADE CO., LTD.
This policy applies to all processing of personal data carried out by the Company in respect of the personal data of the following persons:
3.1 Individual customers, whether current, past or prospective, including representatives of corporate customers.
3.2 Business partners, contracting parties, business allies and suppliers who are natural persons or representatives of such parties.
3.3 Shareholders who are natural persons, or representatives of legal entities holding shares in the Company.
3.4 Managing directors, authorised signatories of legal entities, and authorised representatives of the Company.
3.5 Employees, officers and personnel who currently work with, previously worked with, or wish to work with the Company in the future, including outsourced staff, those in a probationary period, and interns.
3.6 Persons who participate in activities organised by the Company or jointly with other organisations where personal data processing occurs.
3.7 Any other person who is a data subject jointly with the persons in 3.1–3.6 whose personal data is processed by the Company.
This policy also applies to personal data processing that may occur on the website, applications, mobile devices or any other means by which the Company processes personal data. However, it does not cover personal data you provide through channels not directly controlled by the Company, such as social networks (Facebook, Line, Instagram, Twitter, TikTok, etc.), or where you purchase products or use services from a distributor, person or entity certified by the Company.
The Company collects, uses and discloses your personal data for the following purposes:
4.1 To enable you to register for activities, promotions, campaigns or marketing activities of JANUA.
4.2 To verify identity, check eligibility, and contact participants, including announcing results and awarding prizes.
4.3 To process product orders, delivery, warranty, after-sales service and enquiries.
4.4 To manage members, customers and the Company's customer database.
4.5 To send news, privileges, promotions, campaigns, new product launches or JANUA activities (where consent is obtained).
4.6 To analyse statistical data, study consumer behaviour, and develop products, services and customer experience.
4.7 To improve the efficiency of JANUA's website, applications and online channels.
4.8 To manage customer relationships, receive feedback and improve service quality.
4.9 To comply with the law, orders of government agencies, or the Company's exercise of its legal rights.
4.10 To prevent fraud, unlawful acts, or the improper exercise of rights in activities.
4.11 To disclose data to service providers, partners or business allies involved in operating activities, delivery or services, within the scope permitted by law.
The Company may collect the following personal data:
5.1 Identification data: full name, date of birth (if necessary) and gender (if necessary).
5.2 Contact data: phone number, email, delivery address, Line ID or other contact channels.
5.3 Activity participation data: registration information, proof of participation, eligibility history and order number (where relevant).
5.4 Purchase data: product items, order history and payment method information (excluding full credit-card data).
5.5 Website usage data: IP address, browser, device, cookies and website access logs.
5.6 Marketing data: product interests, website usage behaviour, survey responses, and opinions on products and services.
5.7 Images and video: the Company may record still images, moving images, video or images from participation in JANUA activities for public relations, marketing communications and publishing activities through the Company's various channels.
6.1 The Company may collect personal data through two channels:
6.1.1 Collected directly from the data subject, such as through marketing staff, the website, mobile applications, social network channels operated by the Company, completion of JANUA activity registration forms, purchases through the website, applications, Official Store marketplaces, Google Forms, online forms and JANUA's official social media.
6.1.2 Collected from sources other than the data subject directly, such as searches via the website or social networks, third-party online platforms, or other public sources. In such cases the Company will notify the data subject without delay and no later than thirty days from collection, and will request consent, except where an exemption applies by law.
6.2 The Company will obtain explicit consent before or at the time of collection, except where the law permits collection without consent — for example, to achieve the purpose of historical or archival documents for public benefit, research or statistics; to prevent or suppress danger to a person's life, body or health; to perform a contract; for public interest tasks; for the legitimate interests of the Company; or to comply with the law. As a general rule the Company does not collect sensitive data unless necessary and unavoidable, in which case explicit consent is obtained first.
The Company will retain personal data for the following periods:
7.1 Where a specific retention period is prescribed by law, the Company will retain the data within that period — for example, the Revenue Code, the Accounting Act B.E. 2543 (2000), the Labour Protection Act B.E. 2541 (1998), etc.
7.2 Where no specific retention period is prescribed by law, the Company will set a retention period as reasonably necessary for its operations.
Upon expiry of the retention period above, the Company will delete, destroy or anonymise the personal data so that the data subject can no longer be identified.
8.1 Right to withdraw consent: the data subject may withdraw consent previously given to the Company. Withdrawal does not affect processing for which the Company already obtained consent beforehand.
8.2 Right to access: to access, obtain a copy of, or request disclosure of the source of their personal data held by the Company.
8.3 Right to restriction: to request that the Company suspend the use of their personal data.
8.4 Right to data portability: to obtain or request the transfer of their personal data in a machine-readable, commonly used automated format, where technically feasible.
8.5 Right to object: to object to the processing of their personal data.
8.6 Right to be forgotten: to request deletion, destruction or anonymisation of their personal data.
8.7 Right to rectification: to request that their personal data be corrected to be accurate, up to date, complete and not misleading.
8.8 Right to lodge a complaint: to complain to the Personal Data Protection Committee where there is a breach of the personal data protection law.
The Company has established appropriate guidelines and methods for storing data to prevent damage from data leakage, unauthorised access, deletion, destruction, transfer or disclosure. Only persons authorised by the Company or by law may access the storage of such personal data. Where the Company engages an external organisation or person to process personal data on its behalf, the Company will require that party to keep the data confidential and maintain its security.
Only persons with authority as designated by the Company or by law may access and use the personal data the Company has collected. The Company will define access and use measures for each type of data to prevent damage to, or infringement of, the rights of the data subject. Where personal data was collected before the personal data protection law came into force, the Company may continue to process it for the original purposes.
The Company may disclose personal data only as necessary to external organisations or persons under the data subject's consent, unless done within the scope permitted by law — for example, affiliated companies (if any), website system providers, cloud service providers, delivery service providers, payment system providers, event organisers, marketing and CRM service providers, and government or legally authorised agencies — under data-security measures and for the purposes set out in this policy.
The Company uses appropriate organisational, technical and administrative measures to protect the personal data under its control from destruction, loss, access, use, alteration or disclosure, whether caused intentionally or through negligence. It is generally understood that processing data over the internet cannot be made perfectly secure; the Company will therefore develop its security systems in line with current technology.
If this Personal Data Protection Policy is amended, the Company will notify you by publishing it through the Company's appropriate channels.
Address: 120 Moo 21, Tha Ko Subdistrict, Mae Suai District, Chiang Rai 57180
Phone: 065-541-5650
Email: Werinwealth001@gmail.com