Privacy Notice for Clients, Vendors, Business Partners, Visitors, and Third Parties

Siam Premier International Law Office Limited (“Company” or “we” or “us”) respects and values the protection of privacy and personal data of our clients, vendors, business partners, visitors and other third parties who have contact with the Company (“you”). We shall collect, use and disclose your personal data only in a manner and to the extent that is required for the fulfilment of the purposes stated in this privacy notice (“Privacy Notice” or “Notice”). Moreover, we shall strictly comply with the applicable regulations and standards for personal data protection as prescribed by law.

  1. Data Subjects

    For the purpose of this Notice, we shall collect and process the personal data of the following individuals:

    Clients: clients and those interested in the Company’s services, who are natural persons, as well as shareholders, directors, employees, personnel, representatives or other related persons of the clients and those interested in the Company’s services, who are legal entities.

    Vendors: the Company’s suppliers, contractors and service providers, who are natural persons, as well as shareholders, directors, employees, personnel, representatives or other related persons of the Company’s suppliers, contractors and service providers, who are legal entities, including subcontractors or sub-service providers of the aforesaid persons.

    Business Partners: the Company’s business partners that the Company collaborates with for the purpose of business referral or promotion, joint bidding, or professional or organizational development, who are natural persons, as well as shareholders, directors, employees, personnel, representatives or other related persons of the business partners, who are legal entities.

    Visitors: those coming to contact the Company on its premises.

    Other Third Parties: other third parties who become involved with the Company or its clients, vendors, or business partners, either directly or indirectly, in specific situation, e.g., the persons whose personal data is provided or disclosed to the Company in the course of service provided by the Company and other persons involved in the fulfillment of the purposes stated in this Notice.

  2. Personal Data that We Collect

    For the purpose of this Notice, we shall collect “personal data,” which is defined as any information that verifies your identification and which includes the following:

    General personal information concerning individuals – including, title, first name, last name, nickname, gender, age, date of birth, identification number, place or country of birth or origin, place or country of residence or domicile, taxpayer identification number, passport number, vehicle license plate, education background, company name, position, department, section, past performance and work history, service assessment, information provided in documents issued by government agencies or professional federations (e.g., identity cards, professional licenses, birth certificate, corporate documentation), physical identity of a natural person (e.g., face, weight, height), voice, photograph, video, CCTV data, and signature.

    Contact data – including, address, workplace, phone number, e-mail address, Line Account, Whatsapp Account, and other information appearing on business cards.

    Bank account and financial data – including, bank account number, bank account name, bank account holder name, payment details, and other information relating to bank transaction.

    Sensitive personal data – including, personal data related to race, ethnicity, political opinion, doctrinal, religious or philosophical faith, sexual behavior, criminal background, health information, disability, labor union information, genetic information, biological information or any other information similarly affects the data subject as stipulated by the Personal Data Protection Committee, which the Company considers necessary for the purposes stated herein .

    Other data – including, records of correspondences or communications between you and the Company in any format or presentation, or stored by any means, including, without limitation, correspondences or communications via email or messaging platforms or applications, voice or video records, agenda or minutes of any meetings, negotiation, discussion or consultation whether conducted in person or online via any available technological platforms or applications, and other information required or necessary for the Company to achieve the purposes stated in this Notice.

    Apart from the aforementioned personal data, we may collect other kinds of personal data, if necessary and permissible by law, and we will strictly comply with the applicable rules, regulations and standards for data protection as prescribed by law.

  3. Sources of Personal Data Collected
    1. Personal Data Collected Directly from You

      In general, we collect your personal data directly from you in the following manners:

      (a)
      when you are in contact with us to obtain quotations, to introduce your products, services or business profiles, or to deal in any way with the legal services provided by the Company or any transactions or cooperations made with the Company, including exchanging business cards, quoting prices, performing contractual obligations, and enforcing the contracts made with the Company;
      (b)
      upon the preparation of sale and purchase agreements, service agreements or other related agreements made with the Company; or
      (c)
      such other manners as you will be notified.
    2. Personal Data Collected Automatically

      Your personal data will be automatically collected, with the aid of technology, in the following manners:

      (a)
      Your personal data will be collected via our surveillance technology or other measures such as CCTV installed on the Company’s premises.
      (b)
      Your personal data will be collected when you use the Company’s information technology system, such as the Internet or website.
      (c)
      Your personal data may be collected in such other manners as you will be notified.
    3. Personal Data Collected from Third Party

      We may receive your personal data from a third party in the following manners:

      (a)
      We may receive your personal data from any one of our subsidiaries/affiliates or any companies in our group.
      (b)
      If you are a person related to our clients or the works assigned to us, we may receive your personal data from your related persons.
      (c)
      We may receive your personal data from your referral.
      (d)
      If you are subcontractors or sub-service providers, we may receive your personal data from the contractors or service providers.
      (e)
      We may receive your personal data in such other manners as you will be notified.

      In addition, it may be necessary for us to collect from you the personal data of other related persons. Before disclosing such personal data to us, you must inform such persons and receive their consents to our collection, use and/or disclosure of their personal data for the purposes stated in this Notice unless consent is exempted by the personal data protection law. The Company shall strictly comply with the rules and regulations of the personal data protection law in regard to the collection and processing of third-party personal data.

      If you are required to provide your personal data for compliance with the law or for contractual relationship or contractual obligations, we shall inform you of the possible effects of not giving such personal data at the time of the collection. In some cases, your failure to provide the personal data may result in you being denied certain right due to lack of personal data that are vital to the fulfilment of the condition for such right.

  4. Purposes of Personal Data Processing

    The purposes of our collection, use and disclosure (if any) of your personal data are explained in the table below. Your personal data will generally be processed under one or several of the following bases:

    (a)
    The processing of your personal data for preventing or suppressing a danger to a person’s life, body or health;
    (b)
    The processing of your personal data necessary for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract;
    (c)
    The processing of your personal data necessary for the performance of a task carried out in the public interest by the Company, or it is necessary for the exercising of official authority vested in the Company;
    (d)
    The processing of your personal data necessary for legitimate interests of the Company or any other persons, except where such interests are overridden by the fundamental rights in your personal data; and
    (e)
    The processing of your personal data necessary for compliance with a law to which the Company is subject.

    If we are unable to process your personal data under any one of the aforesaid bases, we will seek your explicit consent. Specifically, in the case of a minor, an incompetent person or a quasi-incompetent person, we will seek consent of the person exercising the parental power who acts on behalf of the minor, the guardian or the custodian (as the case may be) to the processing of the personal data of such minor or person in accordance with the data protection law. We do not knowingly collect personal data from a minor, an incompetent person or a quasi-incompetent person without consent from the person exercising the parental power, the guardian or the custodian (as the case may be) when it is required by law. In an event we learn that we unintentionally collected personal data from any minor, an incompetent person or a quasi-incompetent person without the relevant consent where it is required by law, we will promptly delete and/or dispose of the personal data in an appropriate manner.

    You can withdraw your consent at any time by contacting the Company via means of communication provided in this Notice.

    For the purpose of this Notice, we explain the purposes and the legal bases for the collection and processing of your personal data, as follows:

  5.   Purposes Legal Basis
    1 Clients
    1.1 For use as information in fee proposal, including conflict check, coordination in the fee proposal preparation process, opening and administering client and matter record, contacting relevant personnel of the clients, maintaining database of clients and contact persons, etc.
    • The processing of your personal data is necessary in order to take steps at the request of the data subject prior to entering into a contract.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    1.2 For use as information in the performance of services requested by clients pursuant to the contracts with the clients including, without limitation, response to clients’ queries, completion and submission of corporate documents, application, registration or notification to relevant authorities or financial institutions, etc.
    • The processing of your personal data is necessary for the performance of a contract to which you are a party.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    1.3 For use as information in the preparation of the documents used in the collection of payments for services, issuing bills, processing invoices, collecting payment, administering clients’ credit information, etc.
    • The processing of your personal data is necessary for the performance of a contract to which you are a party.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    1.4 For use as information in the submission of tax returns, completing audit letter, preparation of reconciliation reports, etc.
    • The processing of your personal data is necessary for compliance with a law to which the Company is subject.
    1.5 For use as information in the preparation of the Company’s financial statements and the group’s consolidated financial statements, financial and performance review, revenue assessment, etc.
    • The processing of your personal data is necessary for compliance with a law to which the Company is subject.
    1.6 For use as information in the communication of the marketing and promotion of the Company’s services as well as its campaign through available channels including event invitation and administration, providing legal update alerts and newsletter, client conferences, seminars or networking events, reference for firm awards submission, etc.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    • Where the processing may not be reasonably expected, the personal data shall be processed once the Company obtains the express consent from the data subject
    2 Vendors
    2.1 For use as information in the consideration of price quotations and the negotiation of business deals, transactions or employment, including coordination in the process pertaining to the above.
    • The processing of your personal data is necessary in order to take steps at the request of the data subject prior to entering into a contract.
    • The processing of your personal data is necessary for legitimate interests of the dCompany or any other persons.
    2.2 For use as information in the preparation of sale and purchase agreements and service agreements, including, without limitation, the ordering of goods and services, the opening and administering vendor record, contacting relevant personnel of the vendors, maintaining database of vendors and contact persons etc.
    • The processing of your personal data is necessary in order to take steps at the request of the data subject prior to entering into a contract.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    2.3 For use as information in the submission of the warranty claim, the collection of payments for goods and services including, without limitation, issuing bills, processing invoices, collecting payment, and the performance of other contractual obligations.
    • The processing of your personal data is necessary for the performance of a contract to which you are a party.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    2.4 For assessing and creating databases of vendors who have ongoing transactions or relationships with the Company after the expiration of their contracts/agreements or vendors who used to submit quotations to the Company, for future reference.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    2.5 For use as information in the submission of documents, application, registration or notification to relevant authorities.
    • The processing of your personal data is necessary for compliance with a law to which the Company is subject.
    2.6 For use as information in the submission of tax returns, completing audit letter, preparation of reconciliation reports, etc
    • The processing of your personal data is necessary for compliance with a law to which the Company is subject.
    2.7 For use as information in the preparation of the Company’s financial statements and the group’s consolidated financial statements.
    • The processing of your personal data is necessary for compliance with a law to which the Company is subject.
    2.8 For use as information in the communication of the marketing and promotion of the Company’s services.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    • Where the processing may not be reasonably expected, the personal data shall be processed once the Company obtains the express consent from the data subject.
    3 Business Partners
    3.1 For use as information in the discussion and negotiation of business deals, transactions or cooperations with the Company.
    • The processing of your personal data is necessary in order to take steps at the request of the data subject prior to entering into a contract.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    3.2 For use as information in the preparation of relevant agreements, including any memorandums or letter of intents.
    • The processing of your personal data is necessary in order to take steps at the request of the data subject prior to entering into a contract.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    3.3 For use as information in the implementation of any agreed cooperations.
    • The processing of your personal data is necessary for the performance of a contract to which you are a party.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    3.4 For use as information in the communication of the marketing and promotion of the Company’s services where the business partners participate in the campaign with the Company.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    • Where the processing may not be reasonably expected, the personal data shall be processed once the Company obtains the express consent from the data subject.
    4 Visitors and Other Third Parties
    4.1 For the safety of, and the protection against damage to, people and property as well as the investigation and prevention of illegal activities.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    5 Other Purposes
    5.1 Unless already exempted from the scope of the personal data protection law, for use as information or evidence in legal proceedings, trial, or hearing or arbitral process, which include, without limitation, the execution of court or arbitration orders, legal execution, the issue of demand letters, and the disclosure of the said information to counsels or third-party counsellors to carry out the same.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    5.2 For the safety of, and the protection against damage to, people and property as well as the investigation and prevention of illegal activities.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    5.3 Unless already exempted from the scope of the personal data protection law, for responding to requests or orders of the government agencies or law enforcement bodies performing their official duties and for cooperating in official investigations or inquiries and prosecutions against offenders.
    • The processing of your personal data is necessary for compliance with a law to which the Company is subject.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    5.4 Managing access right for our system; administering IT systems and security; monitoring how our websites, platforms and online properties are used to detect and prevent fraud, other crimes and unauthorized use of our websites, platforms and online properties to allow them to be safely navigated.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    5.5 For the prevention and suppression of a danger to life, body and health of a person.
    • The processing of your personal data is for preventing or suppressing a danger to a person’s life, body or health.
    5.6 For the disclosure and transfer of information to related persons when divestiture, merger, acquisition or reorganization is concerned or contemplated.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    5.7 For the control, supervision, operation and management of our subsidiaries/affiliates or companies in our group.
    • The processing of your personal data is necessary for legitimate interests of the Company or any other persons.
    5.8 For such other purposes as permitted by law and subject to the rules and regulations set out by law.

    The failure to provide us with the personal data necessary for the purposes above may prevent us from performing processing activities described in this Notice, and in some cases we may not be able to continue our business relationship or transaction with you.

  6. Data Retention Period

    Generally, we will retain your personal data throughout the term of the agreement or contract you made with the Company or throughout your legal relation with the Company, unless any applicable law, statute of limitations, or professional standard requires or permits a longer duration, for a legitimate purpose, in which case we will retain your personal data further, but not longer than necessary for the purpose.

    In the absence of storage limitation imposed by the applicable law, statute of limitations, or professional standard, we will retain your personal data only for a duration necessary and appropriate for the purposes stated in this Notice.

    We will take appropriate technical and organizational measures for the protection of personal data, particularly against unauthorized or unlawful loss, access to, use, alteration, correction or disclosure of your personal data in order to protect the confidentiality, integrity and availability of personal data.

    Once your personal data is no longer necessary or upon the lapse of the retention period, your personal data will be anonymized or permanently removed from the Company’s electronic records, and all physical records will be completely destroyed.

  7. Disclosure of Personal Data

    Generally, your personal data will be disclosed to our personnel only on a need-to-know basis or to those in charge of processing. In addition, your personal data may be disclosed to any of the following third parties:

    (a)
    Our subsidiaries, affiliates and companies in our Group: SPI Legal Consulting Co., Ltd., Siam Premier Service Co., Ltd., and Lao Premier International Law Office Limited including their personnel.
    (b)
    Our suppliers/providers: providers of development and maintenance services for infrastructure, software, websites and IT; cloud computing and storage providers; data analysts; paper-document depositories; legal advisors; financial advisors and auditors; commercial banks and financial institutions; telecommunication mobile service providers; event and seminar organizers and hotels; printing service providers; and other operational service providers.
    (c)
    Our business partners: business partners of the Company (such as associated, sister or partner law firms), including their personnel who need to process your personal data.
    (d)
    Persons or agencies with legal authority: the Revenue Department, the Department of Business Development, the Office of the Attorney-General, police officers, inquiry officials, agencies/authorities supervising the business conduct or operation of the Company or the data subjects, courts, arbitration institutions and other law enforcement officers, regulators or agencies
    (e)
    Those responsible for public health control: medical facilities, hospitals, and other public health agencies.
    (f)
    Aggrieved parties: employees or third parties (including their agents or representatives) who are aggrieved or have suffered as a result of a tortious act or a criminal offence and who have requested for the disclosure in accordance with the procedures set out by the Company.
    (g)
    Those involved in merger, acquisition or reorganization: investors, inspectors, advisors and consultants who are involved in decision-making for the Company’s business management, merger, acquisition or reorganization.

    If your personal data is disclosed to those aforementioned or if they are allowed access to your personal data in our name, we will ensure that those persons process your personal data only for such purposes as you are informed and keep them confidential with adequate data protection measures.

  8. International Data Transfers

    For the purpose of managing our subsidiaries/affiliates and companies in our group, we may transfer your personal data to Lao Premier International Law Office Limited in the Lao PDR. Additionally, we may also transfer your personal data to be stored and processed in servers of our service providers located in another country.

    While the Lao PDR and those countries may not be recognized as having an adequate level of data protection, we shall take all relevant measures to ensure that your personal data will be securely transferred and protected in accordance with the rules and regulations of the applicable laws.

  9. Rights of the Data Subject

    As a data subject, you have the following rights in regard to your personal data subject to the rules, procedures, and conditions set out by the personal data protection law:

    (a)
    Right to withdraw consent: Where your personal data is collected, used or disclosed on the basis of your consent, you have the right to withdraw your consent at any time, unless there is a restriction on the withdrawal of consent by law, or the contract which gives benefits to the data subject. However, the withdrawal of consent shall not affect the collection, use, or disclosure of personal data prior to such withdrawal.
    (b)
    Right to access: You have the right to request access to and obtain a copy of your personal data, which is under the responsibility of the Company, or to request the disclosure of the acquisition of your personal data obtained without your consent. For security purpose, the Company may request a proof of your identity before providing the requested information to you.
    (c)
    Right to data portability: Where your personal data are collected, used or disclosed on the basis of your consent, or where your personal data are collected without your consent due to the necessity for the performance of a contract to which you are a party, or in order to take steps at your request prior to entering into a contract, you have the right to receive your personal data from the Company if such personal data is in the format which is readable or commonly used by ways of automatic tools or equipment, and can be used or disclosed by automated means. You also have the right to request the Company to send or transfer your personal data in such formats to other data controllers if it can be done by automated means.
    (d)
    Right to object: You have the right to object the collection, use, or disclosure of your personal data at any time.
    (e)
    Right to erase: You have the right to request the Company to erase or destroy your personal data, or anonymize your personal data for it to become anonymous data and to be unable to identify the data subject in some circumstances.
    (f)
    Right to suspend: You have the right to request the Company to restrict the use of your personal data in certain circumstances.
    (g)
    Right to rectify: You have the right to request the Company to rectify your personal data so that they remain accurate, up-to-date, complete, and not misleading.

    However, we reserve the right to proceed as necessary to verify your identification before granting your request, and in some cases, we may deny your request when permitted by law.

    If you wish to exercise the aforesaid rights, you can contact the Company via means of communication set forth in this Notice.

    You also have the right to file a complaint with the expert committee in the event that the Company collects, uses, or discloses your personal data in a way that violates or does not comply with the personal data protection law.

  10. Amendment

    This Notice will be reviewed on a regular basis and may be amended from time to time to be alignedwith the practices and personal data protection law. You will be informed of any material change by appropriate means.

  11. Amendment

    If you have any queries with respect to this Notice, or any personal data collected, used or disclosed by us, or wish to exercise your rights under the personal data protection law, you can contact us at:

    Contact Person:
    Thaneeya Kitchawet
    Data Protection Officer (DPO)
    Address:
    Siam Premier International Law Office Limited
    999/9 The Offices at Central World, 26th Floor, Rama I Road,
    Pathumwan Sub-District, Pathumwan District, Bangkok

Workable Solutions,
Effectively
Communicated

Our Experience,
Your Guide