Privacy Policy

Privacy Policy

Privacy Policy

Date of Announcement July 10th, 2024. (Latest Version)

We are well aware of your personal data. The following statement is Privacy Policy of Drivehub Co., Ltd. (“We” or “Company”) in respect of collecting, using, and disclosing your personal data (collectively referred to as “Processing”), which may occur when cars or drivers are reserved or rented by customers through service channels of the Company, such as our website, application, or social media or by agents, representatives, parents, or guardians of such individuals or any other individuals for whom you rent cars or drivers for their benefits (“You”, or “Customer”).

Thus, we have prepared this Privacy Policy to inform you how we use your personal data, your rights in your personal data, and our contact information in order to execute transactions with you in compliance with laws, to update content in our website, and to notify the Company’s partners of your booking request.

1. Personal data to Collect

The Company shall collect your personal data as follows.

1.1 Information for Registering User Account

(1) General personal data and contact information, e.g. name and surname, telephone number, email address;

(2) Information of social media account used for registration (if any), e.g. Facebook or Google account, profile pictures in any social media;

(3) Information regarding user account, e.g. account name, information in user account, username, password, personal email, pictures, updated account information;

(4) Any other information provided by you to the Company (if any)

1.2 Personal data on the Use of Services

(1) Identifiable information of you or any individuals for whom you rent cars or drivers for their benefits, e.g. copy of ID card/passport, copy of driver’s license, copy of proof of travel / stay, copy of work permit, copy of certificate of student status, copy of insurance claim form;

(2) Information of your agents, representative, parents, or guardians, e.g. name-surname, telephone number, or any contact information, signature;

(3) Social media for contact, e.g. Line or WhatsApp ID, Facebook or Instagram account;

(4) Details or records on car rental and drivers, e.g. rental details, cars and accessories information, records on previous rentals, rental time, and car lessors.

1.3 Financial Personal data

Information, evidence, and details on payment of fees or service charges, payment history and proof of payment, as well as information regarding bank account and credit/debit card such as bank account number, card type, credit/debit card number, CCV code, etc.

1.4 Technical Personal data

Information regarding the use and devices used for accessing and using services via the Company’s platform, device identifier, IP address, serial number, device type, connection data, type of browser, log in/out record information, Log, referring website information, geographic location information.

1.5 Claims/Disputes Information

Information on management of claims and disputes, e.g. information regarding the verification and investigation on fraudulence or acts that are in contrary to applicable laws, rules, and the Company’s regulations, agreements between you and the Company; information on judiciary and penalty, litigation, and exercising of rights of the Company; as well as information on reports submitted to relevant regulatory agencies or any agency with legal authority.

1.6 Personal data of Minorsาว์

The Company does not aim to provide services to minors. However, in some cases, the Company may need to process personal data of such individuals from time to time when there are such individuals using services of the Company. In such case, the Company shall comply with the law on personal data protection in respect of Processing the personal data of minors.

1.7 Information Not Required to Be Collected

Generally, the Company does not intend to collect, use, or disclose information: (1) nationality (2) religion, and (3) blood type displayed in your ID card/passport for any specific purpose. If you have provided your copy of ID card/passport to the Company, please conceal such information before submitting it to the Company. Otherwise, if you fail to conceal such information, it shall be deemed that you allow the Company to conceal such information and that documents with concealed information shall be considered fully valid and legally enforceable in all respects.

1.8 Other Personal data

Other personal data:

(1) Contact information, comments/suggestions, and activities with the Company, e.g. information on inquiry via chat platform of the Company, records on participation in the Company’s activities;

(2) Advertisement and public relation materials of the Company in any part in which you or your personal data has appeared (if any).

2. How We Collect Personal data

The Company shall collect your personal data as follows.

2.1 Collecting directly from Customers

You may provide your personal data, either in electronic format or in paper, to the Company directly by signing up and using services of the Company through website, application and other service channels, contacting the Company, asking for information, filling in forms, filing a complaint, participating in events, taking surveys, or giving comments/feedback to the Company.

2.2 Collecting automatically

The Company may collect certain technical information regarding devices you are using, operation system, activities data, accessing format, work area, browsing history, or other technical information which is collected through the use of Cookies or similar technologies. You can learn more details about the Company’s Cookies Policy in the Company’s website.

2.3 Collecting from third parties

In addition, the Company may collect your personal data from other sources or third parties as follows:

(1) Suppliers of cars for rent or rental agencies in the platform of the Company;

(2) Your parents or guardians (in case you are under 20 years of age);

(3) Your social media provider, e.g. Facebook, Google, Line;

(4) Your agent, representative, or any other third parties for whom you rent cars for their benefits.

3. Purposes of Using Personal Data

The Company collects, uses, discloses personal data (“Data Processing”) for performing executions according to the following purposes (hereinafter referred to as the “Purposes of Using the Information”)

Purposes/Activities

Lawful Basis in Data Processing

1. Management on Providing Services to Customers
Executions according to the process of the Company to provide cars and drivers rental services to you, including user account registration, coordination, contact, car booking, and any other executions in providing services to you as specified in contract or agreement made between you and the Company, including any other contracts or agreements in connection with such service agreements such as Damage Guarantee Agreement etc.
In case you are either parents or guardians of the Customer, the Company shall collect your personal data for purposes of coordination, damage guarantee, or other relevant facilitation

Contractual, Legitimate interest basis

2. Financial Management
Executions according to processes of the Company to manage financial matters, including:
(1) Management on payment of service charges, fees, and rents for cars and drivers, e.g. conducting payment records, receipts issuance;
(2) Management on duty and tax evidence

Contractual, Legitimate interest basis, and Legal obligation basis

3. Corporate Risk Management
Executions to manage and handle risks of the Company, including but not limited to risks on business, products/services, and liquidity

Legitimate interest basis

4. News Release
Releasing information or presenting news to you regarding products, services, advertisements, promotions, events, or other activities of the Company, including invitations to participate in event, activities or other projects of the Company, via channels agreed and permitted by you, such as email address, SMS

Consent
5. Personalized Marketing
Analysing and Processing your personal data to make and present ads, offers, or promotion campaigns to you as personalized marketing, integrating your manners, behaviours, preferences, and thoughts
Consent
6. Development and Improvement of Products and Services
Executions to develop or improve the Company’s products and services, including customer satisfaction survey, research, data analysis, test and experiment, and any other execution for such purpose
Legitimate interest basis
7. Management on Advertisement and Publicity
Management and execution on advertisement and publicity regarding the Company, its products, services, or activities in which you or your personal data are appeared as parts of the advertisement and publicity materials
Consent

8. Settlement of Claims, Disputes, and Lawsuits
Executions to verify and settle claims, disputes, and lawsuits; executions to establish claiming rights or to exercise defence in proceedings and to perform legal executions of the Company

Legitimate interest basis, Needs for Establishment of Claiming Rights or Exercise of Defence for Legal Claims (in case of sensitive data)

9. Security
Executions to assess risks on safety and security of your and the Company’s information system, data, and properties, including:
(1) Inspection, examination, and execution to develop security standards of your and the Company’s information system, data, and properties; management and protection to information technology infrastructure;
(2) Inspection, detection, and execution to prevent unauthorized access to your and the Company’s information system, data, and properties;
(3) Audio and image recordings though CCTV, photographs, recorded voice and images, chat history, record and control of entry to buildings and areas of the Company

Legitimate interest basis
10.Compliance with Laws or Orders of Government Agencies
Executions to comply with laws, rules, procedures, or regulations of governmental or regulatory agencies in connection with business operation, including but not limited to tax law, Computer-Related Crime Act, and Personal Data Protection Act, or orders from government agencies, as well as to comply with judicial process and legal enforcement

Legal obligations basis

11.Danger Prevention
Executions in good faith to collect, use, or disclose your personal data as it is necessary to do so in order to prevent or restrain dangers to your or other’s life, body, and health, in case you are not able to give consent for disclosing the data at that time, and there is not any other way to help prevent or restrain such dangers
Preventing or suppressing danger to a person's life, body or health (Vital Interests)

4. Security of Personal data

We protect your personal data. Any personal data obtained by us shall be protected and processed according to procedures as we deem appropriate to ensure that your personal data shall be only accessed by individuals who have been assigned by us. All employees of the Company shall strictly comply with security guidelines stipulated by the Company. In addition, use of such personal data shall be in accordance with the Purposes of Using the Information.

5. Periods of Retention

The Company stores your personal data. The personal data shall be deleted or destroyed when the periods of retention set out in the table below are terminated or when your personal data becomes unnecessary for execution according the Purposes of Using the Information, unless the Company is required to retain such personal data in order to comply with laws, rules, regulations, or orders of governmental or regulatory agencies, as well as an enforcement of legal rights or contracts as considered appropriate by the Company. The Company shall take appropriate security measures on your personal data in order to prevent any loss, unauthorized access, damage, use, alteration, modification, or disclosure of personal data. The periods of data retention are as follows.
Types of Personal data Periods of Retention

Personal data collected on the legitimate interest basis

10 years after termination of contract

Personal data collected on the contractual basis

5 years after termination of contract

Personal data collected on the legal obligation basis

As required by the law

Personal data collected on the consent basis

As set out in consent forms

6. Disclosure of Personal data

The Company may disclose your personal data to the following third parties under the scope of the Purposes of Using the Information.

6.1 The Company’s personnel

The Company may disclose your personal data to directors, executives, and employees of the Company, whose duties are related to personal data management according to the Purposes of Using the Information under this Privacy Policy. The Company shall limit exclusively for individuals who have access and disclose personal data as much as necessary on the need-to-know basis.

6.2 Car lessors and drivers

The Company may disclose your personal data to car lessors and drivers, to the extent necessary in order for them to make an appointment and reservation for you according to the Purposes of Using the Information as they provide services. The Company shall disclose personal data as much as necessary to authorized individuals only.

6.3 Third-party service providers

The Company may use services from third-party service providers necessary for managing and performing tasks of the Company according to the Purposes of Using the Information, e.g. third-party service providers in respect of information management, Cloud service providers for data backup and storage, service providers on claims management, call centre service providers, IT service providers, email service providers, finance and payment service providers, etc. This also includes consultants in various professions, such as legal consultant and law firm, auditors, lawyers, etc.

6.4 Government agencies, regulatory agencies and other agencies as stipulated by laws

The Company may disclose your personal data to government agencies, regulatory agencies, or other agencies as stipulated by laws, including officers of such agencies, to perform obligations under the laws, rules, or regulations of relevant agencies, which is not limited to tax law, Computer-Related Crime Act, and Personal Data Protection Act. Also, the Company may disclose your personal data to comply with orders of government agencies or courts, as well as to comply with judicial process, legal enforcement, and exercise of the Company’s right under the law.

6.5 Other third parties

The Company may disclose your personal data to other third parties, such as your agents, representatives, parents, or guardians (in case you are under 20 years of age or you rent a car/driver on your behalf), or any other individuals for whom you rent a car/driver for their benefits, etc. The disclosure shall be subject to the Company’s protection of personal data.

7. Rights of Data Owner

You have rights to request the Company to execute anything regarding your Personal data as follows.

7.1 Right of Access to personal data

You have rights to request for access, a copy of personal data relating to you which is under responsibility of the Company, as well as to request the Company to disclose how the Company obtains personal data for which you have never given any consent.

7.2 Right to request for the rectification of personal data

You have rights to request the Company to review, alter, modify, or edit your personal data to be accurate, complete, and up-to-date in order to avoid misunderstanding

7.3 Right to object the collection, use or disclosure of personal data

You have rights to object the collection, use, or disclosure of your personal data at any time. The Company shall perform such executions in the following cases.

(1) In case the Company collects personal data for legitimate interest of the Company or other third party, or for public interests in Processing personal data, except for the case the Company can show a more important legal reason, or the Processing of personal data is for establishing a claiming right, compliance with laws, or use of claiming right, or raise of legal defence.

(2) The Company Processes personal data for a purpose of direct marketing.

(3) The Company Processes personal data for a purpose of conducting research on science, history, or statistics, unless it is necessary to perform missions of the Company for public interests.

7.4 Right to Data Portability of personal data

Subject to personal data protection law, you have rights to ask for obtaining your personal data in a readable or generally useable format with automatically operating tools or devices. You also have rights to ask the Company to send or transfer your personal data in such format to other personal data controllers, or to you, unless technically impracticable.

7.5 Right to Withdraw Consent

In case the Company relies on your consent as a legal basis to collect, use, or disclose your personal data, you have rights to withdraw your consent provided to the Company for Processing your personal data at all time throughout the course such data is stored by the Company, unless your right of consent withdrawal is restricted by laws or a contract beneficial to you. Such withdrawal of consent shall not affect the collection, use, or disclosure of your personal data for which consent has been already given.

7.6 Right to Erasure of personal data

You have rights to ask the Company to delete or make your personal data unidentifiable in the following cases.

(1) Your personal data is no longer necessary for any execution according to the Purposes of Using the Information.

(2) You ask for withdrawing a consent as a legal basis for Processing your personal data, and the Company has no legal authority or legal basis in Processing such personal data any longer.

(3) You have objected the Processing as per Clause 7.3.

(4) Your personal data is illegally collected, used, or disclosed.

The cases mentioned above shall not apply to necessary Processing of personal data for a purpose of exercising freedom of expressions; conducting historical or statistical documents; performing duties in carrying out missions for public interests; complying with laws to achieve purposes of preventive medicine or occupational medicine, or public health common interests; for purposes of establishing, complying with, or exercising legal claiming rights, or raising legal defends, or complying with the laws.

7.7 Right to Restriction of Processing of personal data

You have rights to ask for restriction of Processing to your personal data in the following cases.

(1) The Company is in process of verifying personal data as requested by you.

(2) Personal data that must be deleted or made unidentifiable as per Clause 7.6 is requested by you to suspend using it instead.

(3) The Company is no longer necessary to use your personal data, but you are necessary and request the Company to retain such personal data to use for establishment of claiming rights, compliance, or use of claiming right, or raise of legal defence.

(4) The Company is in process of verifying as per Clause 7.3 (1) or checking as per Clause 7.3 (3) to reject your objection as per Clause 7.3.

7.8 Right to File Complaint

In case the Company, its employees or officers infringe(s) or fail(s) to comply with the personal data protection laws, you are entitled to file a complaint to the Office of the Personal Data Protection Committee.

8. Exercise of Rights and Contact

In case you have any questions or suggestions about our protection of personal data or wish to exercise your rights as per Clause 7, please contact us at:

Company Name Drivehub Co., Ltd.
Address

No. 193-195 Lake Ratchada Building, 3B Floor, Ratchada Road, Khlong Toei Sub-District, Khlong Toei District, Bangkok 10110

Contact information

Telephone: 02-038-5222
Email: [email protected]

Contact information of Personal data Protection Officer

Data Protection Officer: Mr. Pittaya Yansomboon
Address: No. 193-195 Lake Ratchada Building, 3B Floor, Ratchada Road, Khlong Toei Sub-District, Khlong Toei District, Bangkok 10110
Telephone: 02-038-5222
Email: [email protected]

The Company may need to verify your identity before performing any execution according to the request for exercising rights and shall use its best effort based on the capability of the relevant system, to facilitate and proceed with your request without delay within thirty (30) days from the date of receipt of such request, unless it appears that proceeding of such request can cause excessive burdens to the Company, or the case where we are entitled to reject the request, or it is at risk of violating against the protection of personal data of others or in contrary to the laws, or in case that it is practically impossible to proceed as requested.

9. Effects of Failure to Provide Personal data

9.1 Personal data that the Company is Processing on the contract and legal obligations bases under the personal data protection law is necessary for the Company to comply with the relevant contracts and laws according to the Purposes of Using the Information. In event you reject to provide such personal data, it may cause the Company to be unable to execute your personal data according to the Purposes of Using the Information until you provide personal data necessary to the Company completely. For instance, the Company may not be able to make a car reservation for you.

9.2 In case you reject or withdraw your consent for Processing the data, it might cause some limitations to your rights, or might cause the Company to be unable to completely manage or execute according to the Purposes of Using the Information, if such data is necessary for the execution by the Company.

10. Sending or Transferring Personal data Overseas

The Company may send or transfer your personal data to third parties, the Company’s affiliates, or service providers in foreign countries. The recipient countries may or may not have sufficient personal data protection standard as required by the Personal Data Protection Act. However, the Company shall provide procedures and measures to ensure that your personal data is sent or transferred securely. In case it is required by the Personal data Protection Act, the Company shall obtain consent from you for sending or transferring your personal data to foreign countries to be in accordance with such law.

11. Other Privacy Policies

This Privacy Policy is applied only for collecting, using, and disclosing your personal data as customers who book or rent cars and drivers through service channels of the Company, such as the Company’s website, application, social media, agents, representatives, parents, or guardians of such individuals, or any other individuals for whom you rent cars/drivers for their benefits. It does not include any other cases that you need to learn privacy policy in separation from this Privacy Policy entirely.

12. Personal data Protection Policy under the General Data Protection Regulation (GDPR)

This Privacy Policy is made in correspondence with the General Data Protection Regulation (“GDPR”) issued by the European Union (EU) and effective since May 25th, 2018. Enforced among the EU member countries, including transmission of personal data to individuals in the EU countries. As a result, the Company is required to have appropriate and sufficient measures on personal data protection in compliance with GDPR as well. The Company is aware of this matter in order to enhance the management of personal data in its possession, the Company makes this Privacy Policy to be corresponding to GDPR and the Personal Data Protection Act, B.E. 2562 (2019) of Thailand.

13. Governing Law

This Privacy Policy shall be enforced and construed under the law of Thailand. The courts of Thailand shall have exclusive jurisdiction to settle any dispute arising out of or in connection with this Privacy Policy. This includes General Data Protection Regulation (“GDPR”), which is the law issued by the European Union (EU) to be applied among member countries and have been effective since May 25th, 2018.

14. Changes to Privacy Policy

The Company may make any change to this Privacy Policy from time to time to be corresponded to changes in connection with the Processing of your data and changes of the law on personal data protection and other relevant laws. The Company shall notify of any significant change or alteration through appropriate channels. However, if such changes are about imposing additional purposes of using data, the Company may ask for your consent before Processing your data according to such purposes for the case where consent is required by law. However, you acknowledge and undertake that it is under your obligations to track changes of this Privacy Policy every time you visit or use services from website or application of the Company.

contact