Privacy Policy
Your privacy is important to us
Introduction
ORDIS Co., Ltd. ('we', 'us', or 'our') is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This policy was last updated on March 19, 2024.
Data Controller
ORDIS Co., Ltd. is the data controller responsible for your personal data. For all data protection matters, you can contact our Data Protection Officer (DPO) at [email protected] or at our office address.
Information We Collect
We collect and process the following categories of personal data:
- Identity and contact data (name, email, phone number)
- Technical data (IP address, browser type, device information)
- Usage data (how you use our website and services)
- Communication data (your preferences for receiving communications from us)
Legal Basis for Processing
We process your personal data on the following legal grounds:
- Contract performance: Processing necessary for contracts we have with you
- Legal obligation: Processing required to comply with our legal obligations
- Legitimate interests: Processing necessary for our legitimate business interests
- Consent: Processing based on your specific consent
Use of Cookies
Our website uses cookies and similar technologies. These include:
- Essential cookies: Required for the website to function (legal basis: legitimate interest)
- Analytics cookies: Help us understand how visitors use our site (legal basis: consent)
- Preference cookies: Remember your settings and preferences (legal basis: consent)
- Marketing cookies: Track you across websites for marketing (legal basis: consent)
You can manage your cookie preferences through our cookie banner or your browser settings. Refusing non-essential cookies will not affect your ability to use our website.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Contact form data: 2 years after last interaction
- Account information: Duration of your account plus 2 years
- Technical logs: 90 days
- Legal requirements: As required by applicable laws
Your Rights Under GDPR
Under the GDPR, you have the following rights:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ('right to be forgotten')
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
To exercise your rights, contact our DPO at [email protected]. We will respond to your request within one month.
International Data Transfers
We may transfer your data to countries outside the EEA. When we do, we ensure appropriate safeguards are in place through:
- EU Standard Contractual Clauses
- Adequacy decisions by the European Commission
- Binding Corporate Rules where applicable
Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication
- Staff training on data protection
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes through our website or by email.
Contact Information
For any questions about this Privacy Policy or our data practices:
- Data Protection Officer: [email protected]
- Postal Address: Phayathai Plaza, 128/196 Phayathai Road, Ratchathewi, Bangkok 10400, Thailand
- Phone: +66 2 1072512