Privacy Policy

Your privacy is important to us

Introduction

ORDIS Co., Ltd. ('we', 'us', or 'our') is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This policy was last updated on March 19, 2024.

Data Controller

ORDIS Co., Ltd. is the data controller responsible for your personal data. For all data protection matters, you can contact our Data Protection Officer (DPO) at [email protected] or at our office address.

Information We Collect

We collect and process the following categories of personal data:

  • Identity and contact data (name, email, phone number)
  • Technical data (IP address, browser type, device information)
  • Usage data (how you use our website and services)
  • Communication data (your preferences for receiving communications from us)
Legal Basis for Processing

We process your personal data on the following legal grounds:

  • Contract performance: Processing necessary for contracts we have with you
  • Legal obligation: Processing required to comply with our legal obligations
  • Legitimate interests: Processing necessary for our legitimate business interests
  • Consent: Processing based on your specific consent
Use of Cookies

Our website uses cookies and similar technologies. These include:

  • Essential cookies: Required for the website to function (legal basis: legitimate interest)
  • Analytics cookies: Help us understand how visitors use our site (legal basis: consent)
  • Preference cookies: Remember your settings and preferences (legal basis: consent)
  • Marketing cookies: Track you across websites for marketing (legal basis: consent)

You can manage your cookie preferences through our cookie banner or your browser settings. Refusing non-essential cookies will not affect your ability to use our website.

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Contact form data: 2 years after last interaction
  • Account information: Duration of your account plus 2 years
  • Technical logs: 90 days
  • Legal requirements: As required by applicable laws
Your Rights Under GDPR

Under the GDPR, you have the following rights:

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ('right to be forgotten')
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority

To exercise your rights, contact our DPO at [email protected]. We will respond to your request within one month.

International Data Transfers

We may transfer your data to countries outside the EEA. When we do, we ensure appropriate safeguards are in place through:

  • EU Standard Contractual Clauses
  • Adequacy decisions by the European Commission
  • Binding Corporate Rules where applicable
Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit and at rest
  • Regular security assessments
  • Access controls and authentication
  • Staff training on data protection
Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes through our website or by email.

Contact Information

For any questions about this Privacy Policy or our data practices:

  • Data Protection Officer: [email protected]
  • Postal Address: Phayathai Plaza, 128/196 Phayathai Road, Ratchathewi, Bangkok 10400, Thailand
  • Phone: +66 2 1072512