iiMS
ประกาศความเป็นส่วนตัว (Privacy Notice)
การคุ้มครองข้อมูลส่วนบุคคลตาม พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA)

ประกาศความเป็นส่วนตัว (Privacy Notice) · ระบบ iiMS Platform · เวอร์ชัน 1.1 · มีผลบังคับใช้ 30 มิถุนายน 2569 / 30 June 2026

ภาษาไทย

1. ผู้ควบคุมข้อมูล / ผู้ประมวลผลข้อมูล

ระบบ iiMS Platform พัฒนาและดูแลโดย บริษัท อินโนเวทีฟ อินฟอร์เมชั่น เทคโนโลยี คอนซัลติง จำกัด (“Innovative Information Technology Consulting Co., Ltd. (IITC)” หรือ “บริษัท”) ซึ่งทำหน้าที่เป็น ผู้ประมวลผลข้อมูลส่วนบุคคล (Data Processor) โดย หน่วยงานคู่สัญญาที่นำระบบไปใช้เป็น ผู้ควบคุมข้อมูลส่วนบุคคล (Data Controller) สำหรับข้อมูลที่ตนนำเข้าระบบ · ติดต่อเจ้าหน้าที่คุ้มครองข้อมูล (DPO) ของบริษัทที่ support@iitc.co.th

2. ข้อมูลส่วนบุคคลที่เก็บรวบรวม

  1. ข้อมูลบัญชีผู้ใช้ — ชื่อ-นามสกุล ชื่อผู้ใช้ อีเมล หน่วยงาน/ตำแหน่ง และบทบาท/สิทธิการใช้งาน
  2. ข้อมูลการเข้าใช้งานและการกระทำ — เวลาเข้าสู่ระบบ การกระทำในระบบ (audit trail/log) และหมายเลข IP
  3. ข้อมูลที่ผู้ใช้นำเข้าสู่ระบบ — ข้อมูลและเอกสารที่ผู้ใช้บันทึก ซึ่งอาจมีข้อมูลส่วนบุคคลของบุคคลอื่น

3. วัตถุประสงค์และฐานทางกฎหมายในการประมวลผล

บริษัทประมวลผลข้อมูลเพื่อ ให้บริการและยืนยันตัวตน · สนับสนุนการใช้งานและบำรุงรักษาระบบ · รักษาความมั่นคงปลอดภัยและตรวจสอบย้อนหลัง · และปฏิบัติตามกฎหมาย โดยอาศัยฐาน การปฏิบัติตามสัญญา ประโยชน์โดยชอบด้วยกฎหมาย การปฏิบัติหน้าที่ตามกฎหมาย และ/หรือ ความยินยอม ตามแต่กรณี

4. การเปิดเผยและผู้ประมวลผลช่วง

บริษัทจะไม่เปิดเผยข้อมูลส่วนบุคคลแก่บุคคลภายนอก เว้นแต่ตามคำสั่งของผู้ควบคุมข้อมูล เพื่อการให้บริการ (เช่น ผู้ให้บริการโครงสร้างพื้นฐาน/คลาวด์ในฐานะผู้ประมวลผลช่วงภายใต้สัญญารักษาความลับ) หรือเมื่อกฎหมายกำหนด

5. การส่งหรือโอนข้อมูลไปต่างประเทศ

โดยหลักข้อมูลจัดเก็บภายในประเทศไทย หากมีการโอนไปต่างประเทศ บริษัทจะดำเนินการให้มีมาตรการคุ้มครองที่เหมาะสมตามที่กฎหมายกำหนด

6. ระยะเวลาการเก็บรักษา

บริษัทเก็บรักษาข้อมูลเท่าที่จำเป็นตามวัตถุประสงค์ ตลอดอายุสัญญาบริการ/ที่ปรึกษา และตามที่กฎหมายกำหนด เมื่อสิ้นความจำเป็นจะลบ ทำลาย หรือทำให้ไม่สามารถระบุตัวบุคคลได้

7. มาตรการรักษาความมั่นคงปลอดภัย

บริษัทจัดให้มีมาตรการที่เหมาะสม เช่น การควบคุมการเข้าถึงตามบทบาท (RBAC) การเข้ารหัสรหัสผ่าน การบันทึกร่องรอยการใช้งาน และการสำรองข้อมูล เพื่อป้องกันการเข้าถึง ใช้ หรือเปิดเผยโดยไม่ได้รับอนุญาต

8. สิทธิของเจ้าของข้อมูลส่วนบุคคล

เจ้าของข้อมูลมีสิทธิตามกฎหมาย ได้แก่ สิทธิเข้าถึงและขอสำเนา · ขอแก้ไขให้ถูกต้อง · ขอลบหรือทำลาย · ขอระงับการใช้ · คัดค้านการประมวลผล · ขอให้โอนย้ายข้อมูล · และเพิกถอนความยินยอม โดยยื่นคำขอผ่านหน่วยงานคู่สัญญา (ผู้ควบคุมข้อมูล) หรือผ่านบริษัทตามช่องทางที่กำหนด

9. คุกกี้

ระบบใช้คุกกี้ที่จำเป็นต่อการทำงาน (เช่น คุกกี้เซสชันเพื่อรักษาสถานะการเข้าสู่ระบบ) เท่านั้น โดยไม่ใช้เพื่อการตลาดหรือติดตามพฤติกรรม

10. การแก้ไขประกาศ

บริษัทอาจปรับปรุงประกาศนี้เป็นคราว ๆ และจะแสดงเวอร์ชันและวันที่มีผลบังคับใช้ทุกครั้ง

11. ช่องทางติดต่อและการร้องเรียน

ติดต่อ DPO ของบริษัทที่ support@iitc.co.th · หากเห็นว่าการประมวลผลไม่ชอบด้วยกฎหมาย เจ้าของข้อมูลมีสิทธิร้องเรียนต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส./PDPC)


English

1. Controller / Processor

The iiMS Platform is developed and operated by Innovative Information Technology Consulting Co., Ltd. (IITC) (บริษัท อินโนเวทีฟ อินฟอร์เมชั่น เทคโนโลยี คอนซัลติง จำกัด, the “Company”), acting as Data Processor. The Contracted Organization deploying the System is the Data Controller for the data it enters. Contact the Company’s Data Protection Officer (DPO) at support@iitc.co.th.

2. Personal Data Collected

  1. Account data — name, username, email, organization/position, and role/permissions.
  2. Access and activity data — login times, in-system actions (audit trail), and IP address.
  3. Data entered by Users — records and documents that Users save, which may contain other individuals’ personal data.

3. Purposes and Legal Bases

The Company processes data to provide the service and authenticate users; support and maintain the System; ensure security and accountability; and comply with law — relying on the bases of contractual performance, legitimate interest, legal obligation and/or consent, as applicable.

4. Disclosure and Sub-processors

The Company does not disclose personal data to third parties except on the Controller’s instruction, for service provision (e.g. infrastructure/cloud providers as sub-processors under confidentiality), or where required by law.

5. International Transfers

Data is primarily stored in Thailand. Where transfer abroad is necessary, the Company will ensure appropriate safeguards as required by law.

6. Retention

Data is retained only as necessary for the purposes, for the term of the service/consulting agreement, and as required by law. When no longer needed, it is deleted, destroyed or anonymized.

7. Security Measures

The Company maintains appropriate measures such as role-based access control (RBAC), password hashing, audit logging and backups to protect against unauthorized access, use or disclosure.

8. Data Subject Rights

Data subjects have statutory rights: access and copy; rectification; erasure or destruction; restriction of use; objection; data portability; and withdrawal of consent — exercisable via the Contracted Organization (Controller) or the Company through designated channels.

9. Cookies

The System uses only cookies strictly necessary for operation (e.g. a session cookie to maintain login state); it does not use cookies for marketing or behavioural tracking.

10. Changes to this Notice

The Company may update this Notice from time to time and will indicate the version and effective date each time.

11. Contact and Complaints

Contact the Company’s DPO at support@iitc.co.th. A data subject who believes processing is unlawful may lodge a complaint with the Office of the Personal Data Protection Committee (PDPC) of Thailand.

ดู ข้อกำหนดการใช้งาน ประกอบ · Innovative Information Technology Consulting Co., Ltd. (IITC) · support@iitc.co.th ← เข้าสู่ระบบ / Log in