BSL Clinic Co., Ltd. (“the Company”) respects and values the right to privacy and is committed to protecting the personal data of its customers and service recipients (“patients”). The Company recognizes the importance of the personal data that “patients” have entrusted to the Company.
Therefore, the Company has created this Privacy Notice to assure “patients” that the personal data they provide to the Company will be used according to their needs, in compliance with the law, and kept secure according to international standards for personal data protection.
The company’s policy is to not collect sensitive personal data related to a “patient’s” race, ethnicity, political opinions, cult beliefs, religion or philosophy, sexual behavior, criminal history, health data, disability, genetic data, biometric data, or any other similar data that may affect the “patient,” as per the Personal Data Protection Committee’s announcement.
When the company asks a “patient” to take a photo of their ID card to verify their identity before treatment or a doctor’s visit, it is solely for the purpose of checking the accuracy and verifying the “patient’s” identity with an admin via LINE. The company will immediately delete or destroy the copy of the “patient’s” ID card after verifying the name, last name, and national ID number shown on the card. The company has no intention of collecting, using, or storing sensitive personal data such as race, blood type, or religious information, even if such data appears on the national ID card.
The company collects and receives a “patient’s” personal data through various channels:
In cases where a “patient” is a minor under 18, or an incompetent or quasi-incompetent person who requires consent from a parent, guardian, curator, or custodian (as the case may be), the Company will seek consent directly from that person with parental authority. During the application process, the Company requires these individuals to apply on behalf of the “patient.”
The Company believes in good faith that the data it receives from these individuals is data that the Company has the right to process, and that these individuals have the right to disclose it to the Company. The person with parental authority can choose to apply and receive news and marketing activities on behalf of the “patient.” If they have agreed to receive such information from the Company, they have the right to withdraw that consent at any time. They can do so by changing their consent in the application’s settings or, if they no longer wish to receive emails or other information from the Company, by clicking the “unsubscribe” link in the email correspondence they receive. Furthermore, if they wish to exercise their rights under personal data protection laws, they can do so as detailed in this notice.
The company will process personal data necessary for its operations with the following purposes:
| No. | Purpose | Legal Basis |
|---|---|---|
| 1 | To send information on discounts, treatment course promotions, news, package-related information, and to conduct marketing activities such as sending messages, public relations materials, promotions, and marketing events via email. | Consent |
| 2 | To contact you by phone or other channels you have permitted and to recommend suitable treatment courses that you may be interested in, and to create targeted advertisements based on your behavior. | Consent |
| 3 | To analyze, research, and create statistics on “patients'” behavior from their use of the website, application, or other channels in order to develop and improve the quality of service. | Consent |
| 4 | To verify accuracy and to be used for identifying or verifying the identity of the “patient” before a doctor’s visit, treatment, or service use. | Contractual Performance/Legitimate Interest |
| 5 | To process the service application and create a database of “patients” who use the system. | Contractual Performance |
| 6 | To answer a patient’s questions and clarify various information through the chat system, provide suitable advice, and resolve product and service-related issues and defects. It is also used to indicate the progress of the treatment. | Contractual Performance / Legitimate Interest |
| 7 | To inform you of any other news or information related to the same type of services you have with the company, which may be beneficial to you. | Legitimate Interest |
| 8 | To manage orders, deliver, track, and ship medicines, to change and prepare products and services, to inform patients of their results, and to handle matters related to contract compliance. Failure to do so would affect the company’s ability to provide services fairly and continuously. | Contractual Performance/Legitimate Interest |
| 9 | To successfully complete a transaction and verify the accuracy of the account number, credit or debit card number, and other payment-related transactions, as well as to issue payment vouchers, receipts, and tax invoices in accordance with the Revenue Code and other relevant laws or announcements. | Based on contractual obligations/based on legal obligations. |
| 10 | Receiving complaints and feedback, communicating, conducting surveys and opinion polls about products and services, acting on orders and requests, and managing relationships. This includes providing patient care, assessing post-treatment satisfaction, offering consultation and clarification, and answering questions. | Contractual Performance/Legitimate Interest |
| 11 | The Company processes your data to comply with all applicable laws, rules, and regulations, both domestic and international, that are relevant to its business. This includes following legitimate orders from government agencies, officials, and legal authorities, such as court orders, regulatory bodies, or authorized officers. | Legitimate Interest |
| 12 | For the purpose of establishing, exercising, or defending the company’s legal claims in various legal proceedings, such as official investigations, inquiries by government officials, case preparation, litigation, and/or legal defense in court. | Legitimate Interest |
| 13 | For billing, transactions, and payment processing; managing claims and disputes, including dispute resolution; establishing, exercising, or contesting legal claims; various legal proceedings; and legal enforcement actions. | Based on Contractual Performance/Legitimate Interest |
| 14 | To comply with reasonable business principles, such as creating non-specific usage statistics, conducting audits, reporting, risk control or management, and performing trend analysis and planning or other related or similar activities. | Legitimate Interest |
| 15 | For the purpose of providing service notifications, such as when a contract is about to expire, creating and maintaining user accounts, as well as processing, verifying service usage, and closing user accounts. | Based on Contractual Performance |
| 16 | For use in sales, transfers, mergers, or similar events, where the company may disclose or transfer personal data to one or more third parties involved in those transactions. | Legitimate Interest |
| 17 | The company uses your data for risk management, internal audits, financial and accounting checks, internal organizational management, and to comply with the policy of transferring data to companies within the same corporate group under Binding Corporate Rules (BCR). | Based on Legal Obligations |
| 18 | To prevent security risks, such as monitoring network activity logs, identifying security incidents, conducting data security checks, and other protections against malicious, deceptive, fraudulent, or unlawful acts; to resolve issues, develop, implement, operate, test, and maintain information technology (IT) systems. | Legitimate Interest |
| 19 | For the prevention or cessation of danger to life or body in cases where a “patient” cannot give consent, such as health prevention in an epidemic situation, processing health data for first aid when a “patient” suffers harm while under the care or within the premises of the company, including taking a “patient” to a hospital in an emergency, a necessary situation, or a life-threatening danger. | Basis to prevent or suppress danger to a person’s life, body, or health. |
The company will not condition consent as part of the treatment process. Patients can be assured that the company will use the data solely for the purposes the company has defined or for which the patient has given consent. In cases where the company intends to process a patient’s personal data in a manner and/or for purposes that are not consistent with the purposes defined, the company will implement additional policies or announcements regarding personal data protection and will inform the patient via the website or send an email to explain the processing of the data in such cases.
The company has implemented appropriate measures to protect personal data and to comply with the standards set by personal data protection laws. The company ensures that those individuals maintain personal data with secure and confidential measures and will not use it for purposes outside the scope defined by the company. The company may share the personal data of “patients” with the following individuals or organizations:
Government agencies responsible for legal supervision, or those who request personal data sharing under legal authority, or as authorized by the relevant laws, such as the Revenue Department and its officers, etc.
The company may use third-party programs or applications in the form of software services and platform services to process personal data. However, the company will not allow unauthorized individuals to access personal data and will require these third parties to implement appropriate security measures to protect the data.
“Patients” can connect their accounts with the “Learn Anywhere” platform account for the purposes specified in this notice only.
The company will retain the personal data of “patients” for as long as necessary to achieve the purposes for which the personal data was processed. The retention period will depend on the specific purpose of the processing as follows:
The company respects the privacy rights of “patients” and provides them the opportunity to exercise their rights as defined by personal data protection laws as follows:
Withdrawal of consent may impact the “patient” in terms of service usage, such as not receiving benefits, promotions, new offers, or services that align with the “patient’s” needs, or not receiving valuable information. Therefore, to protect the “patient’s” interests, it is recommended to carefully consider and inquire about the potential consequences before exercising the right to withdraw consent.
If “patients” object, the company may continue to process their personal data only if it can demonstrate legal grounds that override the “patient’s” fundamental rights or for the establishment of legal claims, compliance with the law, or defense in legal proceedings, as applicable.
In cases where the “patient” wishes to correct image-related data, the company will only correct the image data as necessary and in accordance with legal requirements. If fulfilling the correction request incurs costs, the company may charge for these expenses. If the company denies a “patient’s” request, the company will create a record of the denial along with the reasons for refusal.
The company has established appropriate security measures to protect personal data from loss, unauthorized access, use, alteration, modification, or disclosure, in compliance with the law. These measures are in line with the company’s information security policies and personal data protection policies (Privacy Policy).
The company has designated a Data Protection Officer to coordinate matters related to personal data protection. If “patients” believe that the processing of their personal data does not comply with the Personal Data Protection Act B.E. 2562, or if they have suggestions, questions, or wish to inquire about the details of the collection, use, and/or disclosure of personal data, including exercising their rights under this notice, “patients” can contact or file complaints through the following channels:
For matters related to personal data: Contact the Data Protection Officer (DPO).
The company will regularly review the Privacy Notice to ensure it aligns with practices and relevant laws and regulations. If there are any changes to this Privacy Notice, the company will notify “patients” by updating the information on the company’s website as soon as possible. Therefore, the company recommends that “patients” read the Privacy Notice each time they visit or use the services of the company or its website.
Announced on May 31, 2022
Call Center : +66993438666
Whatsapp : +66620136667
Line ID : @bslclinic
bslclinic.com
BSL Clinic (Silom Branch)
30/8 Saladaeng Road, Silom, Bang Rak, Bangkok 10500, Thailand
BSL Clinic (Sukhumvit Branch)
Time Square Building Room 114 (Ground Floor). 246 Sukhumvit Road, Khlong Toei, Bangkok, Thailand 10110
Copyright © 2015 www.bslclinic.com All Rights Reserved.