Customers Privacy Notice
Silicon Craft Technology PLC. (“SIC,” “Company,” or “We) prioritizes the protection of personal data in accordance with the Personal Data Protection Act B.E. 2562 (2019). This Privacy Notice has been established to inform you of the details regarding the collection, use, and disclosure of your personal data as follows:
This Privacy Notice covers natural persons associated with the offering of products or services by SIC. This includes prospective customers, current customers, former customers, and natural persons acting on behalf of legal entities (such as directors, advisors, executives, employees, representatives, coordinators, etc.). It also applies to service users, campaign participants, and legal representatives of customers (such as attorneys-in-fact, persons exercising parental power, etc.). Collectively, these individuals are referred to as “Data Subject,” “Customer,” or “You.”
Section 1. Purposes of the Collection, Use, and Disclosure of Personal Data
We collect, use, and disclose your personal data based on the following legal bases: consent, necessity for contract entry or performance, legitimate interests, legal obligations, legal claims, fulfillment of legal objectives regarding medicine, social protection, and labor, or any other bases permitted under the personal data protection laws. These activities are carried out to achieve the following purposes:
- To take steps at your request prior to entering into a contract, for example, communication, service application, qualification verification, identity verification, etc.
- To perform contractual obligations, for example, payment processing, product or service delivery, service provision, after-sales service, problem-solving, inquiry management, etc.
- For management and administration, for example, customer relationship management (CRM), complaint handling, service development and improvement, service usage monitoring, etc.
- For internal operations, for example, customer data storage, data analysis and reporting related to services, information technology system maintenance, etc.
- For advertising and public relations management, for example, marketing activities, event organization, marketing campaigns, product analysis and development, advertising media management, etc.
- For legitimate interests, for example, business operations, security maintenance, crime prevention, risk management, corporate governance, business planning, exercising legal rights in court, etc.
- To comply with legal obligations, for example, tax laws, anti-money laundering laws, personal data protection laws, criminal laws, etc.
- For other purposes, for example, contacting customers or business partners, preventing danger to life, body, or health, etc.
Note: In cases where we need to collect personal data to enter into or perform a contract, or to comply with the law, if you do not provide such personal data, we may not be able to proceed with your request.
Section 2. Personal Data Collected by the Company
We collect personal data directly from you (e.g., through service applications, contract execution, communications, surveys, and use of the Company’s systems). We also collect personal data from other sources (e.g., the Department of Provincial Administration, the Department of Business Development, commercial data sources, social media, and data service providers). The relevant personal data includes:
- Basic Data: Such as first name, last name, gender, date of birth, photograph, signature, identification card details, house registration details, and passport details.
- Contact Data: Such as current address, email address, telephone number, and Line ID.
- Financial Data: Such as bank account details and financial transaction data.
- Sensitive Data: Such as criminal records, biometric data, and religious beliefs.
- Third-Party Data: Such as coordinators and contact persons.
- Other Data: Such as cookie data, usage behavior details, technological data, and event participation records.
ID Card Copies & Sensitive Data: If we receive a copy of your national identity card for identity verification and/or transaction purposes, which may contain sensitive data such as religion or blood type, we have a policy not to retain such sensitive data, unless permitted by laws. We will manage this in accordance with guidelines and applicable laws.
Third-Party Notice: If you provide personal data of third parties (such as coordinators or contact persons) to the Company, please inform those third parties of this Privacy Notice and obtain their consent if necessary, unless there are other legal exemptions where consent is not required.
Section 3. Disclosure of Your Personal Data
We may disclose your personal data to the following entities:
Government Agencies: Such as the Revenue Department, the Office of the Consumer Protection Board, the Department of Business Development, the Ministry of Commerce, the Legal Execution Department, the Anti-Money Laundering Office, courts, or any other authorities exercising statutory powers.
External Service Providers: Such as software and information technology system providers, transportation service providers, data analysis service providers, marketing providers, organizational management evaluators, external auditors, and various advisors (e.g., legal advisors, business planning advisors).
Other Third Parties: Such as potential buyers of the Company’s business, affiliates, and relevant associations.
Section 4. Cross-Border Transfer of Personal Data
If it is necessary to send or transfer personal data abroad, we will comply with the criteria specified by personal data protection laws and implement appropriate measures to prevent unauthorized or unlawful use or disclosure of personal data by other persons.
Section 5. Retention and Retention Period of Your Personal Data
We will retain your personal data for as long as necessary to achieve the relevant purposes specified in this Privacy Notice. We may be required to retain data beyond that period if stipulated or permitted by laws (for example, retaining data for up to 10 years in accordance with the legal statute of limitations).
Section 6. Security Measures for Personal Data Protection
We securely safeguard your personal data by implementing Technical Measures and Organizational Measures. This ensures appropriate security in protecting personal data and prevents personal data breaches in accordance with the standards required by the personal data protection laws.
Section 7. Rights of the Data Subject
You have the following rights under the personal data protection law:
(1) Right to Withdraw Consent
You have the right to withdraw your consent at any time while your personal data is held by the Company. However, withdrawing consent may affect job considerations, benefits you are entitled to receive from the Company, or your receipt of useful news and updates. For your own benefit, please study and inquire about the potential impacts before withdrawing consent.
(2) Right to Access, Obtain a Copy, and Disclose Source
You have the right to access your personal data, request a copy of such data from the Company, and request disclosure on how we obtained your personal data.
(3) Right to Data Portability
You have the right to obtain your personal data in a format that is readable or usable by automatic tools or devices, and can be automatically used or disclosed. You also have the right to request the Company to directly send or transfer your data in such format to another Data Controller when possible by automated means, and to receive such data directly transferred from another Data Controller.
(4) Right to Object
You have the right to object to the collection, use, or disclosure of your personal data when it is based on legitimate interests, public tasks, direct marketing purposes, or scientific, historical, or statistical research purposes.
(5) Right to Erasure
You have the right to request the deletion or destruction of your personal data, or to anonymize the data so that it can no longer identify you.
(6) Right to Restriction of Processing
You have the right to temporarily restrict the use of your personal data while we are reviewing your request to rectify data or your objection request. This also applies to cases where the Company no longer needs the data and must delete or destroy it by laws, but you request restriction instead.
(7) Right to Rectification
You have the right to request that your personal data be corrected, updated, complete, and not misleading.
(8) Right to Complain
You have the right to lodge a complaint with the expert committee under the personal data protection law if you believe that the collection, use, and/or disclosure of your personal data violates or fails to comply with the law.
Processing Requests:
Once we receive your request to exercise your rights, we will proceed within the period prescribed by laws. Please note that we may refuse or may not be able to comply with your request in certain circumstances, such as when we must comply with the laws or court orders, for public interest, or if exercising your right may infringe upon the rights or freedoms of others. We will provide reasons for any refusal.
Section 8. Changes to the Privacy Notice
If there are any modifications or amendments to this Privacy Notice, we will notify you through appropriate channels.
Section 9. Contact Information
You can inquire about this Privacy Notice and exercise your data subject rights through the following contact details:
Data Protection Officer (DPO)
- Name: Amorn Jiraseree-amornkun
- Address: 40 3rd FL., La Unique Plaza, Thetsabanrangsannua Rd., Ladyao, Chatuchak, Bangkok 10900 Thailand
- Contact channel: Email: privacy@sic.co.th or Tel. 02-589-9991
Section 10. Governing Law
This Privacy Notice is governed by and construed in accordance with Thai law, and the Thai courts shall have exclusive jurisdiction over any disputes that may arise.

