Legal
This Privacy Policy explains how Branch Co., Ltd. ("Branch," "we," "us," or "our") collects, uses, discloses, and protects personal data in accordance with the Personal Data Protection Act B.E. 2562 (2019) ("PDPA") and other applicable laws of the Kingdom of Thailand.
Contents
Branch Co., Ltd. respects your privacy and is committed to protecting the personal data of our customers, website and service users, job applicants, employees, and business contacts. This Privacy Policy sets out the types of personal data we collect, why and how we collect, use, and disclose it, who we share it with, how long we keep it, and the rights available to you as a data subject under the PDPA.
Data Controller: Branch Co., Ltd. (Thai: บริษัท บรานช์ จำกัด), a company registered in Thailand under juristic person registration number 0105553014157, with its registered office at 92/17 Soi Neal-Noi, Ekamai Road, North Klongtan, Wattana, Bangkok 10110, Thailand ("Branch," "Company," "we," "us," or "our").
For the purposes of the PDPA, Branch acts as the data controller for the personal data described in this Policy, except where we act as a data processor on behalf of another controller (for example, when processing data for a business client under a service agreement), in which case that client's privacy policy and our data processing agreement will govern.
This Policy covers the following categories of data subjects (each addressed in more detail in Section 5):
Where we maintain a separate, more detailed notice for a specific category of data subject (for example, an internal Employee Privacy Notice or a Recruitment Privacy Notice), that notice supplements and should be read together with this Policy. In the event of any conflict, the more specific notice will prevail for that category of data subject.
Depending on how you interact with us, we may collect:
In connection with recruitment and employment, we may collect:
Certain employee and applicant data, such as religion (as it may appear on a Thai national ID card), health information (for medical benefits or fitness-to-work assessments), or criminal background check results, may constitute Sensitive Personal Data. See Section 6 below.
For individuals who represent our business counterparties, we may collect business contact details such as name, job title, company name, email address, telephone number, and records of our business dealings and correspondence.
In the course of providing company registration, immigration, work permit, and related corporate/professional services, we collect the following categories of Sensitive Personal Data (or documents that may contain it):
We collect and use this data only for the specific purpose you have engaged us for, and only with your explicit consent obtained before or at the time of collection, unless another exemption under Section 26 of the PDPA applies. You may withdraw consent to the processing of Sensitive Personal Data at any time, subject to Section 15 below.
These documents are stored securely in access-controlled digital storage (Google Drive) and, where you request it, in physical form at our office. We do not share, disclose, or use these documents for any purpose other than performing the service you have instructed, and we do not disclose them to any third party except at your direction or as required by law.
We collect personal data:
We process personal data only where we have a lawful basis to do so under Section 24 (general personal data) and Section 26 (sensitive personal data) of the PDPA. The table below summarizes our main purposes and the corresponding legal bases.
We will not use your personal data for purposes materially different from those described above without notifying you and, where required, obtaining your consent.
Our website uses cookies and similar tracking technologies to operate the site, remember your preferences, and understand how visitors use our services. These include:
Where required by law, we will obtain your consent before placing non-essential cookies, through a cookie consent banner or similar mechanism, and you may withdraw consent or manage your preferences at any time through your browser settings.
We also send marketing emails (such as newsletters, promotions, or updates about our services) to individuals who have given their consent or who have an existing customer relationship with us, as permitted under Section 8. Every marketing email includes an unsubscribe or opt-out option, and you may also opt out at any time by contacting us using the details in Section 20.
We may disclose personal data to the following categories of recipients, only as necessary for the purposes described in Section 8 and subject to appropriate confidentiality and data protection obligations:
We do not sell personal data to third parties. We require all third parties who process personal data on our behalf to implement appropriate security measures and to process personal data only on our documented instructions and for the purposes disclosed in this Policy.
We use service providers that store or process personal data outside Thailand, namely:
When we transfer personal data outside Thailand, we take steps to ensure it receives a level of protection consistent with the PDPA, by one or more of the following means: transferring to a country the PDPC has determined provides adequate standards; entering into standard contractual clauses approved by the PDPC; or obtaining your explicit consent after informing you of the relevant standards. You may contact us for more information about the safeguards applied to a specific cross-border transfer.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. As a general guide:
At the end of the applicable retention period, we securely delete, destroy, or anonymize the personal data, whether held digitally or in physical form.
We implement appropriate technical and organizational security measures to protect personal data against unauthorized or unlawful access, use, alteration, disclosure, loss, or destruction, in accordance with the minimum standards prescribed under the PDPA. Digital records are stored in access-controlled systems accessible only to authorized personnel. Our measures also include staff confidentiality obligations and training, and regular review of our security practices. While we take reasonable steps to protect your personal data, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Subject to the conditions and exceptions under the PDPA, you have the following rights in relation to your personal data:
We may need to verify your identity before responding to a request and may decline where a PDPA exception applies. We will respond within the timeframe required by law.
To exercise any of the rights described in Section 14, or if you have any questions about this Policy or our data handling practices, please contact our Data Protection Officer using the details in Section 20. We will not charge a fee for a reasonable request unless permitted by law, and we aim to respond within the timeframes required under the PDPA.
In the event of a personal data breach, we will assess the risk to the rights and freedoms of affected data subjects. Where the breach is likely to result in a risk to your rights and freedoms, we will notify the PDPC without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Section 37(4) of the PDPA. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
Our products and services are not directed at, or intended for use by, children, and we do not knowingly collect personal data from minors without the consent of a parent or legal guardian, as required under Section 20 of the PDPA. If we become aware that we have collected personal data from a minor without appropriate consent, we will take steps to delete that information, unless we are permitted or required by law to retain it.
We do not currently make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you, without human involvement. If this changes, we will update this Policy and provide information about the logic involved, the significance, and the envisaged consequences of such processing, together with your right to request human review.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated Policy on our website with a revised effective date, and, where required by law, we will notify you of material changes or seek your consent.
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal data, please contact:
Data Protection Officer / Privacy Contact: Scott Haslehurst
Company: Branch Co., Ltd.
Address: 92/17 Soi Neal-Noi, Ekamai Road, North Klongtan, Wattana, Bangkok 10110, Thailand
Email: scott@branch.co.th
Telephone: +66 87 904 5560
You may also lodge a complaint with the Office of the Personal Data Protection Committee (PDPC), Ministry of Digital Economy and Society, if you believe your rights under the PDPA have been violated.