Privacy Notice for Business Counterparties
Privacy Notice for Business Counterparties
1. Introduction
This Privacy Notice is issued by Wisesight (Thailand) Co., Ltd. (hereinafter referred to as the "Company" or "Wisesight") to describe the collection, use, and disclosure of the personal data of natural persons connected with the Company's business operations, for persons in contractual and business relationships with the Company.
This is to ensure that data subjects receive the information required under the Personal Data Protection Act B.E. 2562 (2019) (the "PDPA").
This Notice is addressed to natural persons acting as business counterparties of the Company, whether directly in a personal capacity or as representatives/contact persons of juristic persons, namely:
- Prospects / Leads — persons whose data the Company collects for sales and marketing purposes prior to entering into a contractual relationship.
- Contact persons of corporate clients — natural persons acting as representatives, signatories, or contact persons of juristic-person clients.
- Contact persons of Vendors / Suppliers — natural persons acting as representatives of vendors, service providers, consultants, subcontractors, auditors, and certified public accountants providing services to the Company.
- Business Partners (Partners / Channel Partners / Resellers) — natural persons acting as contact persons of the Company's business partners.
- Independent Contractors / Freelancers — natural persons engaged by the Company on a project basis as independent contracting parties, not as employees.
- Shareholders / Directors — natural persons who are shareholders or directors of the Company.
- Business Development Contacts — persons whom the Company contacts for negotiations, partner sourcing, or the exploration of business opportunities.
2. Collection of Personal Data
Collection directly from the data subject (online channels)
- Forms on the Company's website (Contact us, Demo request, Pricing inquiry, Newsletter signup).
- Data entered into the Company's CRM system in the course of sales conversations.
- Correspondence by email and digital communication channels with the Company's Sales, Account Management, Partnership, or Procurement teams.
- Registration for webinars, online meetings, or virtual events organised by the Company.
- Submission of data through social media channels administered by the Company (e.g., Facebook page, LinkedIn page).
Collection directly from the data subject (offline)
- Exchange of business cards at events, meetings, seminars, and exhibitions.
- Registration for seminars, conferences, trade shows, and networking events organised or attended by the Company.
- Telephone contact and face-to-face meetings.
- Exchange of business documents such as company profiles, proposals, and sales materials.
- Execution of contracts, letters of consent, and documents connected with the conduct of business.
Collection from sources other than directly from the data subject
- Data submitted by your juristic person, identifying you as a contact person, signatory, authorised person, or representative of the organisation.
- Commercial business databases (e.g., LinkedIn Sales Navigator, ZoomInfo, DBD Data Warehouse), within the scope of the rights granted to the Company and subject to the terms of service of those providers.
- Referrals from existing clients, business partners, or professional contacts.
- Public sources connected with the conduct of business, such as the website of the organisation to which you belong, information on professional platforms (LinkedIn), business news articles, and information appearing in annual reports.
- Data from government authorities, such as the Department of Business Development (DBD), in respect of executives/directors of juristic-person counterparties.
- Data from business intelligence aggregators, to the extent necessary.
3. Categories of Personal Data Processed
The Company processes your personal data only to the extent necessary and relevant to the purposes of conducting the business relationship, in accordance with the principles of Purpose Limitation and Data Minimisation. The categories of data the Company processes vary according to the nature of your relationship with the Company.
General personal and contact data
- Full name (including title, academic title).
- Nickname, or the name used in business dealings.
- Email address (both personal and organisational email).
- Telephone numbers (mobile, office).
- Contact address (office; address for document delivery).
- Professional social media accounts (LinkedIn profile, X handle used for business).
- The language you use for communication.
Professional and business data
- Job title and role in the organisation.
- Department or line of work.
- The organisation to which you belong, including its name, address, and contact details.
- Level of decision-making authority in the organisation (to the extent relevant to business negotiations).
- Work experience and professional history (to the extent publicly available or disclosed by you in the course of negotiations).
- Professional interests and areas of expertise.
- Membership of professional associations.
Data relating to negotiations and the business relationship
- History of communications and contacts with the Company (emails, telephone calls, meeting minutes).
- Products or services in which you are interested or about which you enquire.
- Business requirements you communicate to the Company.
- Proposals, negotiations, and terms under consideration.
- History of attendance at webinars, seminars, demos, and training.
- Registration for news and marketing communications.
Data in contracts and business documents
- Data in contracts, confirmation letters, memoranda of agreement.
- Signatures (including electronic signatures).
- Consents and authorisations stated in contracts.
- Scope of signing authority.
- Identity documents necessary for signing (e.g., a copy of the national identification card or a power of attorney).
Financial and billing data
- Tax identification number (Tax ID), where a natural person contracts in his or her own name.
- Bank account details (for making or receiving payments).
- Tax invoice address.
- Billing and payment contacts (Accounts Payable / Accounts Receivable contacts).
- Payment history and debt status (for clients/vendors).
Vendor and service provider data
- Vendor qualification and capability assessments (vendor assessment).
- Security and data protection due diligence data.
- Certifications and licences necessary for the provision of services.
Shareholder and director data
- National identification number or passport number.
- Date of birth and age.
- Nationality.
- Registered address and current address.
- Number of shares held and shareholding proportion.
- Role and position on the board of directors.
- Scope of directors' authority.
- Data in shareholders' meetings and board meetings.
- Documents required to be filed with government authorities, such as the Department of Business Development (DBD), the Revenue Department, and others.
- Shareholdings in other companies and directorships in other companies that may give rise to conflicts of interest.
Data relating to access to the Company's premises and systems
- Office entry/exit data (visitor log).
- CCTV images.
- Records of access to the Company's systems, where access rights have been granted.
Sensitive personal data
In general, the Company has no purpose of collecting sensitive personal data under Section 26 of the PDPA from business counterparties, save in the following case, in which the Company will act only to the extent necessary and under an appropriate lawful basis: data in identity documents that may contain sensitive data (e.g., a copy of a national identification card on which religion may appear) — the Company asks that you obscure unnecessary data, or the Company will redact such data.
4. Purposes and Lawful Bases of Processing
- Communications and pre-contractual negotiations, delivery of product information, arranging demos, provision of quotations — performance of a contract / legitimate interest.
- Processing of applications and proposals from vendors/service providers — performance of a contract / legitimate interest.
- Vendor due diligence, including security and data protection assessment — legitimate interest.
- Performance of contracts with clients and vendors, including coordination, service provision, and delivery of goods/services — performance of a contract / legitimate interest.
- Management of payments and billing — performance of a contract / legal obligation.
- Delivery of marketing news and commercial communications (e.g., newsletters, product updates, event invitations) — consent / legitimate interest.
- Organisation of events and webinars and management of event registrations — performance of a contract / consent / legitimate interest.
- Management of client and partner relationships (CRM, account management) — legitimate interest.
- Compliance with applicable law, such as tax law, company law, and the law on the prevention and suppression of money laundering — legal obligation.
- Acts in the capacity of a juristic person, including shareholders' meetings, board meetings, filings with government authorities, and disclosures required by law — legal obligation / legitimate interest.
- Establishment, exercise, or defence of legal claims — legitimate interest.
- Protection and security of the Company's systems and premises — legitimate interest.
5. Data Recipients and External Data Processors
The Company may disclose your personal data to the following persons or categories of persons, to the extent necessary and consistent with the purposes of processing and the lawful bases:
- Employees and contractors of the Company with a need for access on a need-to-know basis.
- Affiliates and partners (Another Dot Co., Ltd., Robolingo Co., Ltd., eTailligence Co., Ltd., TechMatrix Corporation) — for joint service delivery and group management.
- Cloud and infrastructure providers — for the storage and processing of data in the Company's systems.
- CRM and sales tools providers — for the management of client relationships and the sales pipeline (e.g., HubSpot, Salesforce, Pipedrive).
- Marketing automation and communications providers — for the delivery of news and marketing communications (e.g., Mailchimp, HubSpot Marketing).
- Electronic signature providers — for the execution of contracts and business documents (e.g., DocuSign, BoldSign, Creden e-Sign).
- Accounting, tax invoicing, and ERP system providers — for the management of financial transactions.
- Professional advisers (legal advisers, auditors, tax advisers, insurers) — for the performance of professional duties and legal compliance.
- Banks and financial institutions — for making and receiving payments.
- Government authorities and law enforcement agencies — where there is a lawful order, court warrant, or request from a competent authority.
- The Department of Business Development (DBD) and other regulators — in respect of shareholder and director data as required by law.
- Counterparties to corporate transactions (prospective purchasers, investors, advisers) — in the event of a merger, acquisition, asset sale, or corporate restructuring.
- Persons to whom you consent, or whom you request the Company, to disclose data.
6. Cross-Border Transfer of Personal Data
Most processing and storage takes place in the cloud systems of Amazon Web Services and Google located in the Republic of Singapore.
In some cases, data may be transferred to other countries for the provision of services by external data processors, in which case the Company will ensure appropriate protection mechanisms as required by law.
7. Retention of Personal Data
The Company retains your personal data only to the extent necessary, for as long as the data continues to serve a lawful business purpose in relation to the purposes of processing.
When your personal data is no longer used for the above purposes, the Company will delete, destroy, or anonymise your personal data in accordance with its data destruction standards. However, in the event of a dispute, exercise of rights, or legal proceedings concerning your personal data, the Company reserves the right to retain such data until a final order or judgment is received.
8. Data Protection Officer (DPO)
The Company has appointed a Data Protection Officer pursuant to Section 41 of the PDPA to provide advice, monitor compliance with the law, coordinate with the Office of the Personal Data Protection Committee (PDPC), and receive complaints from data subjects.
DPO contact details:
- Email: dpo@wisesight.com
- Address: 123 Suntowers Building B, 33rd Floor, Unit B3301–3304, Vibhavadi Rangsit Road, Chomphon Sub-district, Chatuchak District, Bangkok 10900
- Telephone: 022741299
9. Rights of Data Subjects
Under the PDPA, data subjects have the following rights; the details and procedures for exercising each right appear in the relevant privacy notice:
- Right to be informed. The Company will provide a "Privacy Notice" containing clear details of the purposes of processing, together with a "Cookie Policy" setting out the categories of cookie technologies the Company uses and the purposes of using such cookie technologies; and in the event that the Company processes data other than in accordance with those purposes, or outside the scope of any consent given, the Company will notify and/or seek consent from the data subject before processing personal data outside such purposes.
- Right to withdraw consent. The data subject may withdraw consent previously given to the Company at any time.
- Right of access. The data subject may request access to his or her personal data and a copy of the personal data processing activities, and may request that the Company disclose how such data was obtained.
- Right to rectification. The data subject may request the correction of inaccurate personal data so that such data is accurate, up to date, and not misleading.
- Right to erasure. The data subject may request that the Company delete or destroy personal data, or render personal data anonymous such that the data subject can no longer be identified.
- Right to data portability. Where the Company's data systems support reading or use by generally available automated tools or devices, and the personal data can be used or disclosed by automated means, the data subject may request a copy of his or her personal data, request the automatic transfer of such data to another data controller, and request to receive the personal data so sent or transferred.
- Right to restriction of processing. The data subject has the right to request that the Company restrict the use of personal data.
- Right to object. The data subject may object to the processing of personal data.
Channels for Exercising Rights
Data subjects may exercise the above rights through the following channels:
- Online DSAR form at https://wisesight.com/legal-and-privacy/data-subject-request
- Email: dpo@wisesight.com
- Written correspondence addressed directly to the DPO at the Company's office address.
10. Complaints and Contact Channels
- Internal channel — data subjects may lodge complaints with the Company directly through the DPO via the channels specified.
- Government channel — where a data subject is dissatisfied with the Company's handling of a matter, or wishes to lodge a complaint directly with a government authority, the data subject may contact: Office of the Personal Data Protection Committee (PDPC). Address: 7th Floor, Ratthaprasasanabhakti Building, The Government Complex, 120 Moo 3, Chaengwattana Road, Thung Song Hong Sub-district, Lak Si District, Bangkok 10210. Telephone: 02-142-1033. Email: saraban@pdpc.or.th. Website: https://www.pdpc.or.th
11. Review and Amendment
- Review — The Company will review this Policy at least once a year, or upon a change in law, in PDPC guidance, or a material change in the business.
- Amendment — The Company will announce amendments to employees and affected data subjects through the Company's website and appropriate internal channels.
- Effectiveness — Amendments take effect on the date of announcement or the date specified in the announcement, whichever occurs later.