ServerToday (Thailand) Co., Ltd.
ServerToday (Thailand) Co., Ltd. ("the Company") places the highest importance on personal data protection and the security of data processing, in compliance with the Personal Data Protection Act B.E. 2562 (PDPA) and the international standard ISO/IEC 27701:2019. This policy outlines the principles, guidelines, and measures for collecting, using, disclosing, and protecting personal data of customers, users, business partners, and all related parties.
The Company adheres to internationally recognized and PDPA-mandated principles for personal data processing:
The Company may collect personal data such as name, contact information, email, phone number, user account data, website or email system usage data, technical data such as IP addresses, and computer traffic data under the Computer Crime Act B.E. 2550. Data is processed only to the extent necessary and consistent with the stated purposes.
The Company will not collect personal data except in the following cases:
The Company's personal data processing is conducted on legal grounds under Sections 24 and 26 of the PDPA:
The Company will request consent where required by law or where no other legal basis applies to process the personal data collected from you.
The Company processes personal data for the following purposes:
The Company implements measures in accordance with Section 37 of the PDPA and ISO/IEC 27701 standards, establishing appropriate technical, physical, and administrative security measures to prevent loss, unauthorized access, use, modification, alteration, or disclosure. These include:
The Company will not disclose personal data to third parties except when:
In the case of cross-border data transfers, the Company will verify that the destination country has adequate data protection standards.
Data subjects may exercise the following rights under the law: request access to and obtain a copy of personal data
You have the right to file a complaint with the competent authority if you believe that the collection, use, and/or disclosure of your personal data has been conducted in a manner that violates or fails to comply with applicable law.
The Company will notify the Personal Data Protection Committee within 72 hours of becoming aware of a breach, and will notify data subjects if there is a high risk to their rights and freedoms. The Company maintains an Incident Response Plan in accordance with ISO/IEC 27701 standards.
If you have questions or wish to exercise your rights, please contact:
ServerToday (Thailand) Co., Ltd.
111/128 Moo 2, Ratchaphruek Rd., Bangraknoi, Mueang Nonthaburi, Nonthaburi 11000
DPO Team
111/128 Moo 2, Ratchaphruek Rd., Bangraknoi, Mueang Nonthaburi, Nonthaburi 11000
This Personal Data Protection Policy is governed by and interpreted in accordance with Thai law. Thai courts shall have jurisdiction over any dispute that may arise.
The Company may update this policy as appropriate. Updated versions will be published on the Company's website.
This policy is effective as of May 6, 2025
Download Document ID: ISMS-1PC-005