PDPA PRIVACY POLICY · v1.0 · CURRENT

🔒 นโยบายความเป็นส่วนตัว PDPA

PDPA Privacy Policy

นโยบายฉบับนี้อธิบายวิธีที่บริษัทฯ เก็บรวบรวม ใช้ เปิดเผย และคุ้มครองข้อมูลส่วนบุคคลของท่าน ตาม พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA) ของราชอาณาจักรไทย · จัดทำสองภาษา ไทย-อังกฤษ · กรณีไม่ตรงกันให้ถือฉบับภาษาไทยเป็นหลัก

🏷️ Doc ID: PDPA-2026-001 📅 3 มิถุนายน 2569 · 3 June 2026 ⚖️ PDPA พ.ศ. 2562 🌐 TH + EN Bilingual
🔒
CURRENT VERSION
Version 1.0 ★ Current
Effective Date: 3 มิถุนายน 2569 · 3 June 2026
🏷️ Doc IDPDPA-2026-001
📋 Sections17 Sections · ครบ 17 ส่วน
🛡️ DPOdpo@constructq.co.th

📋สารบัญ · Table of Contents

นโยบายฉบับนี้แบ่งออกเป็น 17 ส่วน อ้างอิงมาตรา PDPA ที่เกี่ยวข้องในแต่ละส่วน

1
1. บทนำและขอบเขต
1. Introduction and Scope
2
2. คำนิยามตาม PDPA
2. Definitions under PDPA
3
3. ผู้ควบคุมข้อมูลส่วนบุคคล (Data Controller) และเจ้าหน้าที่คุ้มครองข้อมูล (DPO)
3. Data Controller and Data Protection Officer (DPO)
4
4. ข้อมูลส่วนบุคคลที่เก็บรวบรวม
4. Categories of Personal Data Collected
5
5. ฐานทางกฎหมายในการประมวลผลข้อมูล
5. Legal Basis for Processing
6
6. วัตถุประสงค์ในการประมวลผลข้อมูล
6. Purposes of Processing
7
7. ข้อมูลส่วนบุคคลที่อ่อนไหว (Sensitive Personal Data)
7. Sensitive Personal Data
8
8. การเปิดเผยข้อมูลแก่บุคคลที่สาม
8. Disclosure to Third Parties
9
9. การโอนข้อมูลไปยังต่างประเทศ
9. Cross-Border Data Transfer
10
10. ระยะเวลาในการเก็บรักษาข้อมูล
10. Data Retention Period
11
11. มาตรการรักษาความปลอดภัย
11. Security Measures
12
12. สิทธิของเจ้าของข้อมูล (Data Subject Rights)
12. Data Subject Rights
13
13. คุกกี้และเทคโนโลยีติดตาม (Cookies)
13. Cookies and Tracking Technologies
14
14. ข้อมูลของผู้เยาว์
14. Children's Data
15
15. การแจ้งเหตุการละเมิดข้อมูลส่วนบุคคล
15. Data Breach Notification
16
16. การเปลี่ยนแปลงนโยบายความเป็นส่วนตัว
16. Changes to Privacy Policy
17
17. ติดต่อและช่องทางการร้องเรียน
17. Contact and Complaints

🇹🇭1. บทนำและขอบเขต

บริษัทผู้ให้บริการ ConstructQ (ต่อไปนี้เรียกว่า “บริษัทฯ”) ตระหนักถึงความสำคัญของการคุ้มครองข้อมูลส่วนบุคคลของท่าน และจัดทำนโยบายความเป็นส่วนตัวฉบับนี้ขึ้นเพื่อให้ท่านเข้าใจวิธีที่บริษัทฯ เก็บรวบรวม ใช้ เปิดเผย และคุ้มครองข้อมูลส่วนบุคคลของท่าน

นโยบายฉบับนี้เป็นไปตาม พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (Personal Data Protection Act B.E. 2562 หรือ “PDPA”) และกฎหมายที่เกี่ยวข้องของราชอาณาจักรไทย

นโยบายนี้ครอบคลุมการประมวลผลข้อมูลส่วนบุคคลของผู้ใช้บริการแพลตฟอร์ม ConstructQ ทั้งบนเว็บ (Web Application) และบนอุปกรณ์เคลื่อนที่ (Mobile Application) รวมถึงผู้ใช้ที่ลงทะเบียน ผู้เยี่ยมชม ผู้สมัครใช้บริการ และบุคคลที่ปรากฏชื่อในข้อมูลที่ผู้ใช้บริการนำเข้าระบบ

🇬🇧1. Introduction and Scope

The company providing ConstructQ services (hereinafter referred to as the “Company”) recognizes the importance of protecting your personal data and has prepared this Privacy Policy to help you understand how we collect, use, disclose, and protect your personal data.

This policy complies with the Personal Data Protection Act B.E. 2562 (2019) ("PDPA") and other related laws of the Kingdom of Thailand.

This policy covers the processing of personal data of users of the ConstructQ platform on both Web Application and Mobile Application, including registered users, visitors, subscribers, and individuals whose names appear in data uploaded by users.

🇹🇭2. คำนิยามตาม PDPA

“ข้อมูลส่วนบุคคล” หมายถึง ข้อมูลเกี่ยวกับบุคคลซึ่งทำให้สามารถระบุตัวบุคคลนั้นได้ ไม่ว่าทางตรงหรือทางอ้อม แต่ไม่รวมถึงข้อมูลของผู้ถึงแก่กรรมโดยเฉพาะ

“ข้อมูลส่วนบุคคลที่อ่อนไหว” (Sensitive Personal Data) หมายถึง ข้อมูลส่วนบุคคลเกี่ยวกับเชื้อชาติ เผ่าพันธุ์ ความคิดเห็นทางการเมือง ความเชื่อในลัทธิ ศาสนาหรือปรัชญา พฤติกรรมทางเพศ ประวัติอาชญากรรม ข้อมูลสุขภาพ ความพิการ ข้อมูลสหภาพแรงงาน ข้อมูลพันธุกรรม ข้อมูลชีวภาพ ตามมาตรา 26 ของ PDPA

“ผู้ควบคุมข้อมูลส่วนบุคคล” (Data Controller) หมายถึง บริษัทฯ ที่มีอำนาจหน้าที่ตัดสินใจเกี่ยวกับการเก็บรวบรวม ใช้ หรือเปิดเผยข้อมูลส่วนบุคคล

“ผู้ประมวลผลข้อมูลส่วนบุคคล” (Data Processor) หมายถึง บุคคลหรือนิติบุคคลที่ดำเนินการประมวลผลข้อมูลส่วนบุคคลตามคำสั่งของผู้ควบคุมข้อมูล เช่น ผู้ให้บริการ Cloud · Omise · SlipOK · Keycloak

“เจ้าของข้อมูลส่วนบุคคล” (Data Subject) หมายถึง บุคคลที่ข้อมูลส่วนบุคคลนั้นเกี่ยวข้อง

“การประมวลผล” (Processing) หมายถึง การเก็บรวบรวม ใช้ เปิดเผย จัดเก็บ แก้ไข เปลี่ยนแปลง ส่ง โอน ลบ หรือทำลายข้อมูลส่วนบุคคล

🇬🇧2. Definitions under PDPA

“Personal Data” means data about a person that can identify such person, directly or indirectly, but not including data of a deceased person specifically.

“Sensitive Personal Data” means personal data pertaining to racial or ethnic origin, political opinions, cult, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, biometric data, as defined in Section 26 of the PDPA.

“Data Controller” means the Company that has authority to make decisions regarding the collection, use, or disclosure of personal data.

“Data Processor” means a natural or legal person who processes personal data on behalf of the Data Controller, such as cloud providers, Omise, SlipOK, Keycloak.

“Data Subject” means a person to whom the personal data pertains.

“Processing” means the collection, use, disclosure, storage, modification, alteration, transmission, transfer, deletion, or destruction of personal data.

🇹🇭3. ผู้ควบคุมข้อมูลส่วนบุคคล (Data Controller) และเจ้าหน้าที่คุ้มครองข้อมูล (DPO)

ผู้ควบคุมข้อมูลส่วนบุคคล:
บริษัทผู้ให้บริการ ConstructQ
ที่อยู่: [ที่อยู่บริษัทฯ จะถูกระบุเมื่อจดทะเบียนบริษัทเสร็จสิ้น]
อีเมล: info@constructq.co.th
โทรศัพท์: 02-XXX-XXXX

เจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (Data Protection Officer · DPO):
ติดต่อ DPO ได้ที่อีเมล: dpo@constructq.co.th
โทรศัพท์: 02-XXX-XXXX (กด 9)
เวลาทำการ: จันทร์-ศุกร์ 9:00-18:00 น.

ท่านสามารถติดต่อ DPO เพื่อสอบถาม ใช้สิทธิของท่าน หรือร้องเรียนเกี่ยวกับการประมวลผลข้อมูลส่วนบุคคล

🇬🇧3. Data Controller and Data Protection Officer (DPO)

Data Controller:
The company providing ConstructQ services
Address: [Company address to be specified upon company registration completion]
Email: info@constructq.co.th
Phone: 02-XXX-XXXX

Data Protection Officer (DPO):
Contact DPO at: dpo@constructq.co.th
Phone: 02-XXX-XXXX (ext. 9)
Office hours: Monday-Friday, 9:00-18:00

You may contact the DPO to inquire, exercise your rights, or file complaints regarding the processing of personal data.

🇹🇭4. ข้อมูลส่วนบุคคลที่เก็บรวบรวม

บริษัทฯ เก็บรวบรวมข้อมูลส่วนบุคคลของท่านในลักษณะดังต่อไปนี้:

4.1 ข้อมูลที่ท่านให้แก่บริษัทฯ โดยตรง:
(ก) ข้อมูลบัญชี: ชื่อ-นามสกุล อีเมล เบอร์โทรศัพท์ รหัสผ่าน (เข้ารหัส)
(ข) ข้อมูลโปรไฟล์: รูปประจำตัว ตำแหน่ง แผนก
(ค) ข้อมูลบริษัท: ชื่อบริษัท เลขผู้เสียภาษี 13 หลัก ที่อยู่ ผู้ติดต่อ
(ง) ข้อมูลการชำระเงิน: บัตรเครดิต (ผ่าน Omise · ไม่เก็บที่บริษัทฯ) · PromptPay · บัญชีธนาคาร · ใบกำกับภาษี
(จ) ข้อมูลผู้ใช้ในระบบ: ข้อมูลของพนักงาน/ผู้รับเหมาที่ท่านเพิ่มลงในระบบ

4.2 ข้อมูลที่เก็บรวบรวมโดยอัตโนมัติเมื่อท่านใช้บริการ:
(ก) ข้อมูลการเข้าใช้งาน: IP address · User Agent · เวลาเข้าระบบ · เหตุการณ์ในระบบ
(ข) ข้อมูลอุปกรณ์: ประเภทอุปกรณ์ · ระบบปฏิบัติการ · เบราว์เซอร์ · ความละเอียดหน้าจอ
(ค) ข้อมูล GPS (เฉพาะ Mobile App ที่ผู้ใช้ยินยอม): พิกัดที่ติดบนรูปถ่ายการตรวจสอบ
(ง) FCM Token: สำหรับส่ง Push Notification
(จ) Cookies และเทคโนโลยีติดตาม: ตามนโยบาย Cookies

4.3 ข้อมูลที่ผู้ใช้บริการนำเข้าระบบ:
(ก) รูปถ่ายการตรวจสอบ (อาจมีบุคคลปรากฏในภาพ)
(ข) เอกสารการตรวจสอบ · เช็คลิสต์ · NCR
(ค) ลายเซ็นต์ดิจิทัล
(ง) ความเห็น/Comment ในงานตรวจสอบ

4.4 ข้อมูลจากผู้ให้บริการที่สาม:
(ก) SSO/OAuth Login: ชื่อ อีเมล รูปประจำตัว จาก Google · LINE (เฉพาะข้อมูลที่ท่านยินยอม)
(ข) Omise: ข้อมูล token บัตรเครดิต (token เท่านั้น ไม่รวมเลขบัตร)
(ค) SlipOK: ข้อมูลผลการตรวจสลิป

🇬🇧4. Categories of Personal Data Collected

The Company collects personal data as follows:

4.1 Information you provide directly:
(a) Account data: name, email, phone number, password (encrypted)
(b) Profile data: profile picture, position, department
(c) Company data: company name, 13-digit taxpayer ID, address, contact person
(d) Payment data: credit card (via Omise · not stored by us), PromptPay, bank account, tax invoice
(e) User data in the system: information of employees/contractors you add to the system

4.2 Data collected automatically when you use the service:
(a) Access logs: IP address, User Agent, login time, system events
(b) Device data: device type, OS, browser, screen resolution
(c) GPS data (Mobile App only · with consent): coordinates attached to inspection photos
(d) FCM Token: for Push Notifications
(e) Cookies and tracking technologies: per Cookie Policy

4.3 Data uploaded by users:
(a) Inspection photos (may contain persons in the image)
(b) Inspection documents, checklists, NCRs
(c) Digital signatures
(d) Comments on inspection tasks

4.4 Data from third-party providers:
(a) SSO/OAuth Login: name, email, profile picture from Google · LINE (only data you consent to)
(b) Omise: credit card token (token only, not card number)
(c) SlipOK: slip verification results

🇹🇭5. ฐานทางกฎหมายในการประมวลผลข้อมูล

บริษัทฯ ประมวลผลข้อมูลส่วนบุคคลของท่านโดยอาศัยฐานทางกฎหมายตามมาตรา 24 ของ PDPA ดังต่อไปนี้:

5.1 การปฏิบัติตามสัญญา (Contractual Necessity) · มาตรา 24(3)
เพื่อให้บริการแก่ท่านตามที่ระบุในข้อกำหนดและเงื่อนไข เช่น การสร้างบัญชี การประมวลผลคำสั่งสมัครบริการ การส่งใบกำกับภาษี

5.2 การปฏิบัติตามกฎหมาย (Legal Obligation) · มาตรา 24(6)
เพื่อปฏิบัติตามกฎหมายที่เกี่ยวข้อง เช่น ประมวลรัษฎากร (เก็บใบกำกับภาษี 5 ปี) การป้องกันการฟอกเงิน คำสั่งของหน่วยงานที่มีอำนาจ

5.3 ประโยชน์โดยชอบด้วยกฎหมาย (Legitimate Interest) · มาตรา 24(5)
เพื่อประโยชน์ของบริษัทฯ หรือบุคคลภายนอก โดยคำนึงถึงสิทธิและเสรีภาพของท่าน เช่น ป้องกันการฉ้อโกง · รักษาความปลอดภัยของระบบ · พัฒนาบริการ · บันทึก Audit Log

5.4 ความยินยอม (Consent) · มาตรา 24(1)
เมื่อท่านให้ความยินยอมโดยเฉพาะ เช่น การส่งอีเมลการตลาด · การเปิด GPS บน Mobile · การใช้ Cookies ที่ไม่จำเป็น · การเชื่อมต่อกับ SSO Google/LINE

5.5 ประโยชน์สำคัญต่อชีวิต (Vital Interest) · มาตรา 24(2)
กรณีเร่งด่วนที่จำเป็นเพื่อป้องกันอันตรายต่อชีวิต ร่างกาย หรือสุขภาพของบุคคล

5.6 ประโยชน์สาธารณะ (Public Interest) · มาตรา 24(4)
เพื่อดำเนินภารกิจเพื่อประโยชน์สาธารณะ (กรณีที่บริษัทฯ ได้รับมอบหมาย)

🇬🇧5. Legal Basis for Processing

The Company processes your personal data based on the following legal bases under Section 24 of the PDPA:

5.1 Contractual Necessity · Section 24(3)
To provide services to you as specified in the Terms & Conditions, such as account creation, processing subscription orders, sending tax invoices.

5.2 Legal Obligation · Section 24(6)
To comply with applicable laws, such as the Revenue Code (retaining tax invoices for 5 years), anti-money laundering, and orders from competent authorities.

5.3 Legitimate Interest · Section 24(5)
For the legitimate interests of the Company or third parties, taking into account your rights and freedoms, such as fraud prevention, system security, service improvement, and Audit Log recording.

5.4 Consent · Section 24(1)
When you give specific consent, such as for marketing emails, enabling GPS on Mobile, non-essential cookies, and SSO connection with Google/LINE.

5.5 Vital Interest · Section 24(2)
In urgent cases necessary to prevent harm to a person's life, body, or health.

5.6 Public Interest · Section 24(4)
To carry out missions for the public interest (when the Company is so assigned).

🇹🇭6. วัตถุประสงค์ในการประมวลผลข้อมูล

บริษัทฯ ประมวลผลข้อมูลส่วนบุคคลของท่านเพื่อวัตถุประสงค์ต่อไปนี้:

6.1 การให้บริการ: สร้างและจัดการบัญชีผู้ใช้ · พิสูจน์ตัวตน · ให้บริการตามแพ็คเก็จที่ท่านสมัคร · จัดเก็บและประมวลผลข้อมูลการตรวจสอบ

6.2 การชำระเงินและการเรียกเก็บ: ดำเนินการชำระเงินผ่าน Omise/PromptPay · ออกใบกำกับภาษี · ติดตามการชำระเงิน · จัดการ subscription

6.3 การสื่อสารและการสนับสนุน: ส่ง notification เกี่ยวกับบริการ · ตอบคำถาม · แจ้งเตือนกิจกรรมในระบบ · ส่ง email verification

6.4 ความปลอดภัย: ตรวจจับและป้องกันการฉ้อโกง · ป้องกันการเข้าใช้โดยไม่ได้รับอนุญาต · บันทึก Audit Log (immutable) · ตอบสนองต่อเหตุการณ์ด้านความปลอดภัย

6.5 การปฏิบัติตามกฎหมาย: เก็บข้อมูลใบกำกับภาษี 5 ปี ตามประมวลรัษฎากร · ตอบสนองคำสั่งศาล หน่วยงานรัฐ

6.6 การปรับปรุงและพัฒนาบริการ: วิเคราะห์การใช้งานแบบนิรนาม (Anonymized) · ทดสอบ A/B · พัฒนาฟีเจอร์ใหม่

6.7 การตลาด (ต้องได้รับความยินยอมก่อน): ส่ง email โปรโมชั่น · ข่าวสารผลิตภัณฑ์ · ท่านสามารถ unsubscribe ได้ตลอดเวลา

🇬🇧6. Purposes of Processing

The Company processes your personal data for the following purposes:

6.1 Service Provision: Account creation and management, authentication, providing services per your subscribed Package, storing and processing inspection data.

6.2 Payment and Billing: Processing payments via Omise/PromptPay, issuing tax invoices, tracking payments, managing subscriptions.

6.3 Communication and Support: Sending service notifications, answering inquiries, alerting on system activities, sending email verifications.

6.4 Security: Detecting and preventing fraud, preventing unauthorized access, recording Audit Logs (immutable), responding to security incidents.

6.5 Legal Compliance: Retaining tax invoices for 5 years per the Revenue Code, responding to court orders and government agency requests.

6.6 Service Improvement: Analyzing anonymized usage, A/B testing, developing new features.

6.7 Marketing (consent required): Sending promotional emails, product news. You may unsubscribe at any time.

🇹🇭7. ข้อมูลส่วนบุคคลที่อ่อนไหว (Sensitive Personal Data)

บริษัทฯ ไม่เก็บรวบรวมข้อมูลส่วนบุคคลที่อ่อนไหวโดยเจตนา ตามมาตรา 26 ของ PDPA (เช่น เชื้อชาติ ศาสนา ความคิดเห็นทางการเมือง ข้อมูลสุขภาพ ฯลฯ)

อย่างไรก็ตาม หากผู้ใช้บริการนำเข้าข้อมูลส่วนบุคคลที่อ่อนไหวเข้าสู่ระบบ (เช่น รูปถ่ายที่อาจแสดงสภาพร่างกาย) ท่านในฐานะผู้ใช้บริการต้องรับผิดชอบในการขอความยินยอมจากเจ้าของข้อมูลก่อน

ในกรณีที่บริษัทฯ จำเป็นต้องใช้ Biometric Data (เช่น Face ID, Touch ID, ลายนิ้วมือ) สำหรับการล็อกอินใน Mobile App ข้อมูลดังกล่าวจะถูกประมวลผลภายในอุปกรณ์ของท่านเอง (On-device) และไม่ถูกส่งไปยังเซิร์ฟเวอร์ของบริษัทฯ

🇬🇧7. Sensitive Personal Data

The Company does not intentionally collect Sensitive Personal Data under Section 26 of the PDPA (such as race, religion, political opinions, health information, etc.).

However, if a user uploads sensitive personal data to the system (e.g., photos that may show physical conditions), the user is responsible for obtaining consent from the data subject prior to upload.

In cases where the Company must use Biometric Data (such as Face ID, Touch ID, fingerprint) for login in the Mobile App, such data is processed on-device only and is not transmitted to the Company's servers.

🇹🇭8. การเปิดเผยข้อมูลแก่บุคคลที่สาม

บริษัทฯ อาจเปิดเผยข้อมูลส่วนบุคคลของท่านแก่บุคคลที่สามในกรณีต่อไปนี้:

8.1 ผู้ให้บริการที่บริษัทฯ ใช้ (Data Processors):
(ก) Cloud Provider: AWS · GCP · หรือเทียบเท่า (สำหรับเก็บข้อมูลในประเทศไทย)
(ข) Omise: ผู้ให้บริการประมวลผลการชำระเงิน · บริษัทฯ ส่งข้อมูล token เท่านั้น ไม่ส่งเลขบัตรเครดิต
(ค) SlipOK: ผู้ให้บริการตรวจสอบสลิปการโอนเงิน
(ง) Keycloak: ผู้ให้บริการระบบ Identity Management
(จ) MinIO: ผู้ให้บริการ Object Storage
(ฉ) Firebase (Google): ผู้ให้บริการ Push Notification
(ช) SMTP Email Provider: ผู้ให้บริการ Postmark/SES สำหรับส่งอีเมล

8.2 หน่วยงานราชการและกฎหมาย: ในกรณีที่กฎหมายกำหนด คำสั่งศาล หรือคำสั่งของหน่วยงานที่มีอำนาจ เช่น กรมสรรพากร · สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส.) · ศาล

8.3 ที่ปรึกษาวิชาชีพ: ทนายความ · ที่ปรึกษาบัญชี · ผู้สอบบัญชี เมื่อจำเป็นต้องปกป้องสิทธิของบริษัทฯ

8.4 การควบรวมกิจการ: ในกรณีที่บริษัทฯ มีการควบรวม ซื้อกิจการ หรือขายทรัพย์สิน บริษัทฯ จะแจ้งให้ท่านทราบล่วงหน้าก่อนโอนข้อมูล

บริษัทฯ มีสัญญากับ Data Processors ทุกรายเพื่อให้มั่นใจว่าจะมีการคุ้มครองข้อมูลตามมาตรฐาน PDPA

🇬🇧8. Disclosure to Third Parties

The Company may disclose your personal data to third parties in the following cases:

8.1 Service Providers (Data Processors):
(a) Cloud Provider: AWS, GCP, or equivalent (for data storage in Thailand)
(b) Omise: Payment processor · The Company sends tokens only, not credit card numbers
(c) SlipOK: Payment slip verification provider
(d) Keycloak: Identity Management system provider
(e) MinIO: Object Storage provider
(f) Firebase (Google): Push Notification provider
(g) SMTP Email Provider: Postmark/SES for sending emails

8.2 Government Agencies and Legal Authorities: When required by law, court orders, or orders of competent authorities, such as the Revenue Department, the Personal Data Protection Committee (PDPC), the courts.

8.3 Professional Advisors: Lawyers, accountants, auditors, when necessary to protect the Company's rights.

8.4 Mergers and Acquisitions: In case of merger, acquisition, or asset sale, the Company will notify you in advance before transferring data.

The Company has contracts with all Data Processors to ensure data protection meets PDPA standards.

🇹🇭9. การโอนข้อมูลไปยังต่างประเทศ

บริษัทฯ อาจโอนข้อมูลส่วนบุคคลของท่านไปยังต่างประเทศในกรณีที่ใช้บริการผู้ให้บริการระบบ Cloud หรือ SaaS ที่มีเซิร์ฟเวอร์ตั้งอยู่นอกประเทศไทย

การโอนข้อมูลไปยังต่างประเทศจะปฏิบัติตามมาตรา 28-29 ของ PDPA โดย:
(ก) ประเทศปลายทางต้องมีมาตรฐานการคุ้มครองข้อมูลส่วนบุคคลที่เพียงพอ ตามที่คณะกรรมการคุ้มครองข้อมูลส่วนบุคคลประกาศ
(ข) มีมาตรการคุ้มครองที่เหมาะสมและบังคับได้ เช่น Standard Contractual Clauses (SCC) · Binding Corporate Rules (BCR)
(ค) ได้รับความยินยอมจากท่านโดยชัดแจ้ง
(ง) เป็นการจำเป็นเพื่อปฏิบัติตามสัญญา

ปัจจุบัน บริษัทฯ พยายามเก็บข้อมูลในประเทศไทยเป็นหลัก ผ่าน Cloud Provider ที่มี Data Center ในประเทศไทย

🇬🇧9. Cross-Border Data Transfer

The Company may transfer your personal data internationally when using cloud or SaaS providers with servers located outside Thailand.

Cross-border data transfers comply with Sections 28-29 of the PDPA by:
(a) The destination country must have adequate data protection standards as determined by the Personal Data Protection Committee
(b) Adequate safeguards are in place, such as Standard Contractual Clauses (SCC) or Binding Corporate Rules (BCR)
(c) Explicit consent has been obtained from you
(d) Necessary for the performance of the contract

Currently, the Company primarily stores data within Thailand, using Cloud Providers with Data Centers located in Thailand.

🇹🇭10. ระยะเวลาในการเก็บรักษาข้อมูล

บริษัทฯ เก็บข้อมูลส่วนบุคคลของท่านเท่าที่จำเป็นต่อวัตถุประสงค์ในการประมวลผล ดังนี้:

10.1 ข้อมูลบัญชี: ตลอดระยะเวลาที่ท่านใช้บริการ + 30 วัน Grace Period หลังยกเลิกบัญชี ก่อนลบถาวร

10.2 ข้อมูลใบกำกับภาษีและเอกสารทางบัญชี: 5 ปี ตามประมวลรัษฎากร มาตรา 87/3 (แม้ท่านยกเลิกบัญชีแล้ว)

10.3 Audit Logs: 2 ปี สำหรับการตรวจสอบความปลอดภัยและการปฏิบัติตามกฎหมาย

10.4 ข้อมูลการชำระเงิน (token credit card): ตามนโยบายของ Omise · บริษัทฯ ไม่เก็บเลขบัตรจริง

10.5 ข้อมูล Marketing (จากความยินยอม): จนกว่าท่านจะถอนความยินยอม

10.6 ข้อมูลผู้ใช้ในระบบ: ตลอดระยะเวลาที่ผู้ใช้บริการยังคงเก็บข้อมูลในระบบ · ลบอัตโนมัติเมื่อบัญชีถูกลบ

หลังพ้นระยะเวลาเก็บรักษา บริษัทฯ จะลบหรือทำให้ข้อมูลเป็นนิรนาม (Anonymize) อย่างปลอดภัย

🇬🇧10. Data Retention Period

The Company retains your personal data only as long as necessary for the processing purposes, as follows:

10.1 Account Data: Throughout your use of the service + 30-day Grace Period after cancellation, before permanent deletion.

10.2 Tax Invoices and Accounting Documents: 5 years as required by Revenue Code Section 87/3 (even after account cancellation).

10.3 Audit Logs: 2 years for security audits and legal compliance.

10.4 Payment Data (credit card token): Per Omise policy · The Company does not store actual card numbers.

10.5 Marketing Data (from consent): Until you withdraw consent.

10.6 User Data in the System: Throughout the period the user retains the data · automatically deleted when the account is deleted.

After the retention period, the Company will securely delete or anonymize the data.

🇹🇭11. มาตรการรักษาความปลอดภัย

บริษัทฯ ใช้มาตรการรักษาความปลอดภัยตามมาตรฐานอุตสาหกรรม เพื่อปกป้องข้อมูลส่วนบุคคลของท่าน:

11.1 มาตรการทางเทคนิค:
(ก) การเข้ารหัสข้อมูลระหว่างการรับ-ส่ง: TLS 1.3
(ข) การเข้ารหัสข้อมูลที่จัดเก็บ (Data-at-Rest): AES-256
(ค) Role-Based Access Control (RBAC) · จำกัดสิทธิ์การเข้าถึงตามบทบาท
(ง) Two-Factor Authentication (2FA) · TOTP
(จ) Audit Log แบบ Immutable · ใช้ Database Trigger ห้าม UPDATE/DELETE
(ฉ) Rate Limiting · Brute-Force Protection
(ช) Web Application Firewall (WAF)
(ซ) การสำรองข้อมูลรายวัน + Disaster Recovery Plan

11.2 มาตรการเชิงองค์กร:
(ก) นโยบายความปลอดภัยและการคุ้มครองข้อมูลส่วนบุคคล
(ข) การอบรมพนักงานเกี่ยวกับ PDPA และความปลอดภัยข้อมูล
(ค) ข้อตกลงรักษาความลับ (NDA) กับพนักงานและพันธมิตร
(ง) การควบคุมการเข้าถึงข้อมูลตามหลัก Least Privilege
(จ) การตรวจสอบและประเมินความปลอดภัยเป็นระยะ

11.3 มาตรการทางกายภาพ:
(ก) Cloud Provider ที่ผ่านการรับรอง ISO 27001 · SOC 2
(ข) Data Center ที่มีการควบคุมการเข้าออก

อย่างไรก็ตาม ไม่มีระบบใดที่ปลอดภัยอย่างสมบูรณ์ บริษัทฯ จะแจ้งท่านโดยเร็วในกรณีที่มีการละเมิดข้อมูล

🇬🇧11. Security Measures

The Company implements industry-standard security measures to protect your personal data:

11.1 Technical Measures:
(a) Encryption in transit: TLS 1.3
(b) Encryption at rest: AES-256
(c) Role-Based Access Control (RBAC) · access limited by role
(d) Two-Factor Authentication (2FA) · TOTP
(e) Immutable Audit Logs · using database triggers to prevent UPDATE/DELETE
(f) Rate Limiting · Brute-Force Protection
(g) Web Application Firewall (WAF)
(h) Daily backups + Disaster Recovery Plan

11.2 Organizational Measures:
(a) Security and personal data protection policies
(b) PDPA and data security training for employees
(c) Non-Disclosure Agreements (NDAs) with employees and partners
(d) Access control based on the Least Privilege principle
(e) Periodic security audits and assessments

11.3 Physical Measures:
(a) Cloud Providers certified ISO 27001 · SOC 2
(b) Data Centers with access control

However, no system is completely secure. The Company will notify you promptly in case of a data breach.

🇹🇭12. สิทธิของเจ้าของข้อมูล (Data Subject Rights)

ตาม PDPA ท่านมีสิทธิดังต่อไปนี้:

12.1 สิทธิในการเข้าถึงและขอสำเนา (Right of Access) · มาตรา 30
ท่านมีสิทธิขอเข้าถึงและขอสำเนาข้อมูลส่วนบุคคลของท่านที่บริษัทฯ เก็บรักษา

12.2 สิทธิในการแก้ไข (Right to Rectification) · มาตรา 35
ท่านมีสิทธิขอให้บริษัทฯ แก้ไขข้อมูลที่ไม่ถูกต้อง ไม่ครบถ้วน หรือไม่เป็นปัจจุบัน

12.3 สิทธิในการลบ (Right to Erasure / Right to be Forgotten) · มาตรา 33
ท่านมีสิทธิขอให้บริษัทฯ ลบข้อมูลของท่าน เว้นแต่กรณีที่บริษัทฯ ต้องเก็บไว้ตามกฎหมาย (เช่น ใบกำกับภาษี 5 ปี)

12.4 สิทธิในการระงับการใช้ (Right to Restriction) · มาตรา 34
ท่านมีสิทธิขอให้บริษัทฯ ระงับการใช้ข้อมูลของท่านในกรณีที่ระบุไว้ตามกฎหมาย

12.5 สิทธิในการคัดค้าน (Right to Object) · มาตรา 32
ท่านมีสิทธิคัดค้านการเก็บรวบรวม ใช้ หรือเปิดเผยข้อมูลของท่านในบางกรณี เช่น การประมวลผลเพื่อการตลาด

12.6 สิทธิในการเคลื่อนย้ายข้อมูล (Right to Data Portability) · มาตรา 31
ท่านมีสิทธิขอรับสำเนาข้อมูลของท่านในรูปแบบที่อ่านได้โดยอัตโนมัติ และโอนไปยังผู้ควบคุมข้อมูลรายอื่น

12.7 สิทธิในการถอนความยินยอม (Right to Withdraw Consent) · มาตรา 19
ท่านมีสิทธิถอนความยินยอมที่เคยให้แก่บริษัทฯ ได้ตลอดเวลา การถอนความยินยอมจะไม่กระทบต่อการประมวลผลที่เกิดขึ้นก่อน

12.8 สิทธิในการร้องเรียน (Right to Lodge a Complaint) · มาตรา 73
ท่านมีสิทธิร้องเรียนต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส. · PDPC) ในกรณีที่บริษัทฯ ละเมิด PDPA
ที่อยู่ สคส.: เลขที่ 120 หมู่ 3 ชั้น 7 อาคารรัฐประศาสนภักดี ศูนย์ราชการเฉลิมพระเกียรติฯ ถนนแจ้งวัฒนะ แขวงทุ่งสองห้อง เขตหลักสี่ กรุงเทพมหานคร 10210
เว็บไซต์: https://www.pdpc.or.th

วิธีใช้สิทธิ: ติดต่อ DPO ที่ dpo@constructq.co.th หรือผ่านการตั้งค่าในระบบ บริษัทฯ จะดำเนินการภายใน 30 วันนับจากวันที่ได้รับคำขอ

🇬🇧12. Data Subject Rights

Under the PDPA, you have the following rights:

12.1 Right of Access · Section 30
You have the right to access and request copies of your personal data held by the Company.

12.2 Right to Rectification · Section 35
You have the right to request correction of inaccurate, incomplete, or outdated data.

12.3 Right to Erasure (Right to be Forgotten) · Section 33
You have the right to request deletion of your data, except where retention is required by law (e.g., tax invoices for 5 years).

12.4 Right to Restriction · Section 34
You have the right to request the Company to restrict use of your data in legally specified cases.

12.5 Right to Object · Section 32
You have the right to object to the collection, use, or disclosure of your data in certain cases, such as processing for marketing.

12.6 Right to Data Portability · Section 31
You have the right to receive a copy of your data in a machine-readable format and transfer it to another data controller.

12.7 Right to Withdraw Consent · Section 19
You have the right to withdraw any consent given to the Company at any time. Withdrawal does not affect processing that occurred prior to withdrawal.

12.8 Right to Lodge a Complaint · Section 73
You have the right to lodge a complaint with the Personal Data Protection Committee (PDPC) if the Company violates the PDPA.
PDPC Address: 120 Moo 3, 7th Floor, Ratthaprasasanabhakti Building, Government Complex Commemorating His Majesty The King's 80th Birthday Anniversary, 5th December B.E. 2550, Chaeng Watthana Road, Thung Song Hong Sub-district, Lak Si District, Bangkok 10210
Website: https://www.pdpc.or.th

How to exercise your rights: Contact the DPO at dpo@constructq.co.th or via system settings. The Company will respond within 30 days of receiving your request.

🇹🇭13. คุกกี้และเทคโนโลยีติดตาม (Cookies)

บริษัทฯ ใช้ Cookies และเทคโนโลยีที่คล้ายกันเพื่อจดจำการตั้งค่าและปรับปรุงประสบการณ์การใช้งานของท่าน:

13.1 Strictly Necessary Cookies: จำเป็นสำหรับการทำงานของระบบ เช่น Session ID · CSRF Token · Authentication · ไม่ต้องขอความยินยอม

13.2 Functional Cookies: จดจำการตั้งค่า เช่น ภาษา · ธีม · แพ็คเก็จที่เลือก · เป็นไปตามมาตรา 24(5) Legitimate Interest

13.3 Analytics Cookies: ใช้สำหรับวิเคราะห์การใช้งาน (เช่น Google Analytics, ถ้าใช้) · ต้องได้รับความยินยอมก่อน

13.4 Marketing Cookies: ใช้เพื่อแสดงโฆษณาที่เกี่ยวข้อง · ต้องได้รับความยินยอมก่อน

ท่านสามารถจัดการ Cookies ได้ผ่าน Cookie Banner ที่แสดงเมื่อเข้าใช้งานครั้งแรก หรือผ่านการตั้งค่าเบราว์เซอร์ของท่าน

🇬🇧13. Cookies and Tracking Technologies

The Company uses Cookies and similar technologies to remember preferences and enhance your user experience:

13.1 Strictly Necessary Cookies: Required for system functionality, such as Session ID, CSRF Token, Authentication. No consent required.

13.2 Functional Cookies: Remember settings such as language, theme, selected package. Based on Section 24(5) Legitimate Interest.

13.3 Analytics Cookies: Used for usage analysis (e.g., Google Analytics, if used). Consent required.

13.4 Marketing Cookies: Used to display relevant advertisements. Consent required.

You can manage Cookies via the Cookie Banner displayed on first access or through your browser settings.

🇹🇭14. ข้อมูลของผู้เยาว์

บริการ ConstructQ มุ่งสำหรับผู้ใช้บริการที่เป็นนิติบุคคลและผู้ใหญ่ (อายุ ≥ 20 ปี)

บริษัทฯ ไม่เก็บข้อมูลส่วนบุคคลของผู้ที่มีอายุต่ำกว่า 20 ปีโดยเจตนา หากพบว่ามีการเก็บข้อมูลของผู้เยาว์โดยไม่ตั้งใจ บริษัทฯ จะลบข้อมูลดังกล่าวทันที

หากท่านเป็นผู้ปกครองและพบว่าบุตรหลานของท่านได้ให้ข้อมูลแก่บริษัทฯ โปรดติดต่อ DPO ที่ dpo@constructq.co.th

🇬🇧14. Children's Data

ConstructQ services are intended for legal entities and adults (age ≥ 20).

The Company does not knowingly collect personal data of persons under 20 years of age. If we discover such data was collected unintentionally, the Company will delete it immediately.

If you are a parent and discover that your child has provided data to the Company, please contact the DPO at dpo@constructq.co.th.

🇹🇭15. การแจ้งเหตุการละเมิดข้อมูลส่วนบุคคล

ในกรณีที่เกิดเหตุการละเมิดข้อมูลส่วนบุคคล บริษัทฯ จะปฏิบัติตามมาตรา 37(4) ของ PDPA ดังนี้:

15.1 แจ้งสำนักงาน PDPC: ภายใน 72 ชั่วโมง นับจากที่บริษัทฯ ทราบเหตุ ในกรณีที่การละเมิดมีความเสี่ยงต่อสิทธิและเสรีภาพของบุคคล

15.2 แจ้งเจ้าของข้อมูล: โดยไม่ชักช้า ในกรณีที่การละเมิดมีความเสี่ยงสูงต่อสิทธิและเสรีภาพของบุคคล โดยจะแจ้งผ่านอีเมลและ Notification ในระบบ

15.3 ข้อมูลที่จะแจ้ง: ลักษณะของการละเมิด · ประเภทและจำนวนข้อมูลที่ได้รับผลกระทบ · ผลกระทบที่อาจเกิดขึ้น · มาตรการที่บริษัทฯ ดำเนินการเพื่อแก้ไข · ช่องทางติดต่อ DPO

15.4 บันทึก: บริษัทฯ จะบันทึกเหตุการละเมิดทุกครั้งไว้เป็นหลักฐาน

🇬🇧15. Data Breach Notification

In the event of a personal data breach, the Company will comply with Section 37(4) of the PDPA as follows:

15.1 Notification to PDPC: Within 72 hours of becoming aware of the breach, when the breach poses a risk to the rights and freedoms of individuals.

15.2 Notification to Data Subjects: Without delay, when the breach poses a high risk to the rights and freedoms of individuals, via email and in-system notifications.

15.3 Information Provided: Nature of the breach, type and quantity of data affected, possible impacts, measures taken by the Company to remediate, DPO contact channels.

15.4 Records: The Company will record every breach incident as evidence.

🇹🇭16. การเปลี่ยนแปลงนโยบายความเป็นส่วนตัว

บริษัทฯ อาจปรับปรุงนโยบายความเป็นส่วนตัวฉบับนี้เป็นครั้งคราว เพื่อให้สอดคล้องกับการเปลี่ยนแปลงของกฎหมาย แนวทางปฏิบัติ หรือการให้บริการ

บริษัทฯ จะแจ้งการเปลี่ยนแปลงให้ท่านทราบผ่านอีเมลหรือ Notification ในระบบไม่น้อยกว่า 30 วัน ก่อนการเปลี่ยนแปลงมีผลบังคับใช้

ในกรณีที่การเปลี่ยนแปลงส่งผลกระทบต่อสิทธิของท่านอย่างมีนัยสำคัญ บริษัทฯ จะขอความยินยอมจากท่านใหม่

ประวัติการเปลี่ยนแปลงนโยบายฉบับนี้แสดงในส่วน Change Log

🇬🇧16. Changes to Privacy Policy

The Company may update this Privacy Policy from time to time to comply with changes in laws, practices, or services.

The Company will notify you of changes via email or in-system notifications at least 30 days before changes take effect.

If changes significantly affect your rights, the Company will request renewed consent.

The history of policy changes is shown in the Change Log section.

🇹🇭17. ติดต่อและช่องทางการร้องเรียน

ติดต่อทั่วไป:
📧 อีเมล: info@constructq.co.th
☎️ โทรศัพท์: 02-XXX-XXXX (จันทร์-ศุกร์ 9:00-18:00 น.)

ติดต่อเจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (DPO):
📧 อีเมล: dpo@constructq.co.th
☎️ โทรศัพท์: 02-XXX-XXXX (กด 9)

ใช้สิทธิตาม PDPA:
📧 อีเมล: privacy@constructq.co.th
หรือผ่านการตั้งค่าในระบบ (เมนู โปรไฟล์ → ความเป็นส่วนตัว → จัดการสิทธิ)

ร้องเรียนต่อสำนักงาน PDPC (กรณีบริษัทฯ ละเมิด PDPA):
📧 อีเมล: pdpc@mdes.go.th
🌐 เว็บไซต์: https://www.pdpc.or.th
📍 ที่อยู่: เลขที่ 120 หมู่ 3 ชั้น 7 อาคารรัฐประศาสนภักดี ศูนย์ราชการเฉลิมพระเกียรติฯ ถนนแจ้งวัฒนะ แขวงทุ่งสองห้อง เขตหลักสี่ กรุงเทพมหานคร 10210

🇬🇧17. Contact and Complaints

General Contact:
📧 Email: info@constructq.co.th
☎️ Phone: 02-XXX-XXXX (Monday-Friday, 9:00-18:00)

Data Protection Officer (DPO) Contact:
📧 Email: dpo@constructq.co.th
☎️ Phone: 02-XXX-XXXX (ext. 9)

Exercise PDPA Rights:
📧 Email: privacy@constructq.co.th
Or via system settings (Profile menu → Privacy → Manage Rights)

Complaints to PDPC (if the Company violates PDPA):
📧 Email: pdpc@mdes.go.th
🌐 Website: https://www.pdpc.or.th
📍 Address: 120 Moo 3, 7th Floor, Ratthaprasasanabhakti Building, Government Complex, Chaeng Watthana Road, Thung Song Hong Sub-district, Lak Si District, Bangkok 10210

✍️การยอมรับนโยบาย · Acceptance

🇹🇭 การยอมรับนโยบายความเป็นส่วนตัว

เมื่อท่านลงทะเบียนใช้บริการ ติ๊กยอมรับนโยบายนี้ หรือใช้บริการ ConstructQ ในรูปแบบใดก็ตาม ถือว่าท่านได้อ่าน ทำความเข้าใจ และยอมรับนโยบายความเป็นส่วนตัวฉบับนี้ทุกประการ

หากท่านไม่ยอมรับนโยบายนี้ ไม่ว่าทั้งหมดหรือบางส่วน ท่านต้องไม่ใช้บริการของแพลตฟอร์ม

🇬🇧 Acceptance of Privacy Policy

By registering, checking the acceptance checkbox, or using ConstructQ services in any manner, you acknowledge that you have read, understood, and fully agree to this Privacy Policy.

If you do not accept this policy, in whole or in part, you must not use the Services.

🔄Change Log (Version Control)

ประวัติการเปลี่ยนแปลงของนโยบายความเป็นส่วนตัว · History of all Privacy Policy revisions

v1.0 📅 3 มิถุนายน 2569
📝 นโยบาย PDPA และความเป็นส่วนตัวรุ่นแรก Initial version of PDPA Privacy Policy
🇹🇭 ภาษาไทย
  • ✨ สร้างนโยบายความเป็นส่วนตัวฉบับแรกของ ConstructQ ตาม PDPA พ.ศ. 2562
  • ✨ 17 sections ครอบคลุม: นิยาม · ฐานทางกฎหมาย · วัตถุประสงค์ · sensitive data · third-party · cross-border · retention · security · 8 data subject rights · cookies · ผู้เยาว์ · data breach
  • 🇹🇭 จัดทำสองภาษา (ไทย + อังกฤษ) · ภาษาไทยเป็นหลัก
  • ⚖️ อ้างอิงมาตรา PDPA: ม.24 (ฐานทางกฎหมาย) · ม.26 (sensitive) · ม.28-29 (cross-border) · ม.30-35 (rights) · ม.37 (breach notification) · ม.73 (complaint)
  • 🔐 ระบุมาตรการความปลอดภัย: TLS 1.3 · AES-256 · RBAC · 2FA · audit log immutable · WAF
  • 👥 ระบุ Data Processors: AWS/GCP · Omise · SlipOK · Keycloak · MinIO · Firebase · SMTP
  • 📅 ระยะเวลาเก็บข้อมูล: บัญชี 30 วัน grace · ใบกำกับภาษี 5 ปี · audit 2 ปี
  • 📞 ระบุ DPO contact + PDPC contact ครบถ้วน
🇬🇧 English
  • ✨ Initial PDPA Privacy Policy for ConstructQ per PDPA B.E. 2562
  • ✨ 17 sections covering: definitions · legal bases · purposes · sensitive data · third-party · cross-border · retention · security · 8 data subject rights · cookies · children · breach notification
  • 🌐 Bilingual (Thai + English) · Thai prevails
  • ⚖️ References PDPA sections: §24 (legal bases) · §26 (sensitive) · §28-29 (cross-border) · §30-35 (rights) · §37 (breach) · §73 (complaint)
  • 🔐 Security measures specified: TLS 1.3 · AES-256 · RBAC · 2FA · immutable audit log · WAF
  • 👥 Data Processors specified: AWS/GCP · Omise · SlipOK · Keycloak · MinIO · Firebase · SMTP
  • 📅 Retention periods: Account 30-day grace · Tax invoices 5 years · Audit 2 years
  • 📞 Full DPO + PDPC contact details
💡 Version Control: ทุกครั้งที่อัปเดต PDPA Privacy Policy · จะเพิ่ม entry ใหม่ใน Change Log ด้านบน · แจ้งให้ผู้ใช้ทราบล่วงหน้าไม่น้อยกว่า 30 วันก่อนมีผลบังคับใช้ · กรณีกระทบสิทธิอย่างมีนัยสำคัญจะขอความยินยอมใหม่