นโยบายความเป็นส่วนตัว
Privacy Policy – ตามพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA)
1. ผู้ควบคุมข้อมูลส่วนบุคคล
บริษัท ฟาร์มโซลูทิค จำกัด (Pharmsolutic Co., Ltd.) ต่อไปนี้เรียกว่า "ฟาร์มโซลูทิค" หรือ "บริษัท" ในฐานะผู้ควบคุมข้อมูลส่วนบุคคล (Data Controller) ตาม พ.ร.บ. คุ้มครอง ข้อมูลส่วนบุคคล พ.ศ. 2562 ขอแจ้งนโยบายความเป็นส่วนตัวเพื่อให้ท่านทราบ
2. ข้อมูลส่วนบุคคลที่เก็บรวบรวม
2.1 ข้อมูลที่ท่านให้โดยตรง
| ประเภทข้อมูล | ตัวอย่าง |
|---|---|
| ข้อมูลระบุตัวตน | ชื่อ-นามสกุล, ชื่อบริษัท/องค์กร |
| ข้อมูลติดต่อ | อีเมล, เบอร์โทรศัพท์ (ถ้าให้) |
| ข้อมูลบัญชี | รหัสผ่าน (เก็บแบบ encrypted/hashed) |
| ข้อมูลทางการเงิน | หลักฐานการชำระเงิน (สลิป) |
| เนื้อหาคำถาม | ข้อความและไฟล์แนบที่ท่านส่งผ่านระบบ |
2.2 ข้อมูลที่ระบบสร้างอัตโนมัติ
- บันทึกการเข้าใช้งาน (login logs) พร้อม IP address และวันเวลา
- ประวัติการซื้อและใช้ Token
- ประวัติการยอมรับ Terms of Service และ NDA พร้อม timestamp
- คุกกี้ที่จำเป็น (essential cookies) เพื่อรักษา session
3. วัตถุประสงค์และฐานทางกฎหมาย
| วัตถุประสงค์ | ฐานทางกฎหมาย |
|---|---|
| ให้บริการที่ปรึกษาตามที่ท่านขอ | การปฏิบัติตามสัญญา (มาตรา 24(3)) |
| ส่งใบเสนอราคาและเมลแจ้งสถานะ | การปฏิบัติตามสัญญา (มาตรา 24(3)) |
| ปรับปรุงคุณภาพบริการ | ประโยชน์โดยชอบด้วยกฎหมาย (มาตรา 24(5)) |
| ปฏิบัติตามกฎหมายภาษีและบัญชี | การปฏิบัติตามกฎหมาย (มาตรา 24(6)) |
| การตลาดอีเมล (newsletter) | ความยินยอม (มาตรา 19) |
4. การเปิดเผยข้อมูลต่อบุคคลที่สาม
4.1 หลักการทั่วไป
บริษัทจะไม่ขาย ให้ หรือเปิดเผยข้อมูลส่วนบุคคลของท่านต่อบุคคลที่สาม ยกเว้น:
- ได้รับความยินยอมโดยชัดแจ้งจากท่าน
- ถูกบังคับโดยคำสั่งศาลหรือกฎหมาย
- เพื่อปกป้องสิทธิ์ของบริษัทในกรณีฟ้องร้อง
4.2 ผู้ประมวลผลข้อมูล (Data Processors)
บริษัทใช้บริการของผู้ให้บริการเทคโนโลยี ซึ่งทำหน้าที่ประมวลผลข้อมูล ภายใต้สัญญา Data Processing Agreement (DPA):
- Supabase Inc. (สหรัฐอเมริกา) — Database hosting และ Authentication
- Resend, Inc. (สหรัฐอเมริกา) — บริการส่งอีเมลธุรกรรม
- Cloudflare Inc. (สหรัฐอเมริกา) — CDN และ DNS
การส่งข้อมูลไปต่างประเทศได้รับการคุ้มครองด้วยมาตรการทางเทคนิค (encryption) และทางกฎหมาย (Standard Contractual Clauses)
5. ระยะเวลาเก็บรักษาข้อมูล
| ประเภทข้อมูล | ระยะเวลาเก็บ |
|---|---|
| ข้อมูลบัญชีสมาชิก | ตลอดอายุการเป็นสมาชิก + 1 ปี หลังยกเลิก |
| ประวัติคำถาม-คำตอบ | ตลอดอายุการเป็นสมาชิก |
| หลักฐานการเงิน (ใบเสร็จ, สลิป) | 5 ปี (ตามกฎหมายภาษี) |
| บันทึกการเข้าใช้งาน (logs) | 90 วัน |
| ข้อมูลที่ใช้เพื่อการตลาด | จนกว่าท่านจะถอนความยินยอม |
6. สิทธิ์ของเจ้าของข้อมูล (Data Subject Rights)
ตาม PDPA ท่านมีสิทธิ์ดังต่อไปนี้:
- สิทธิ์เข้าถึง — ขอดูข้อมูลส่วนบุคคลที่บริษัทเก็บไว้
- สิทธิ์แก้ไข — ขอให้แก้ไขข้อมูลที่ไม่ถูกต้องหรือไม่เป็นปัจจุบัน
- สิทธิ์ลบ — ขอให้ลบข้อมูล (เว้นแต่กฎหมายกำหนดให้เก็บ)
- สิทธิ์ระงับการใช้ — ขอให้ระงับการประมวลผลชั่วคราว
- สิทธิ์โอนย้าย — ขอให้ส่งข้อมูลในรูปแบบที่อ่านได้ด้วยเครื่อง
- สิทธิ์คัดค้าน — คัดค้านการประมวลผลในบางกรณี
- สิทธิ์ถอนความยินยอม — ถอนความยินยอมที่เคยให้ไว้
- สิทธิ์ร้องเรียน — ร้องเรียนต่อสำนักงานคณะกรรมการคุ้มครอง ข้อมูลส่วนบุคคล (สคส.)
การใช้สิทธิ์ดังกล่าวสามารถส่งคำขอมาที่ support@pharmsolutic.com บริษัทจะตอบกลับภายใน 30 วัน
7. ความปลอดภัยของข้อมูล
บริษัทใช้มาตรการรักษาความปลอดภัยตามมาตรฐานสากล:
- การเข้ารหัสระหว่างส่ง — HTTPS/TLS 1.2+ ทุกการสื่อสาร
- การเข้ารหัสระหว่างจัดเก็บ — at-rest encryption (AES-256)
- รหัสผ่าน hashed — ใช้ bcrypt ไม่เก็บ plaintext
- การควบคุมการเข้าถึง — Row Level Security (RLS) บนฐานข้อมูล
- Audit log — บันทึกทุกการเข้าถึงข้อมูลสำคัญ
- การสำรองข้อมูล — backup รายวันเก็บไว้ 30 วัน
8. การละเมิดข้อมูลส่วนบุคคล (Data Breach)
หากเกิดเหตุการณ์ที่ข้อมูลรั่วไหลและอาจส่งผลกระทบต่อสิทธิ์เสรีภาพของท่าน บริษัทจะแจ้ง สคส. ภายใน 72 ชั่วโมง และแจ้งท่านโดยไม่ชักช้า ตามที่กฎหมายกำหนด
9. คุกกี้และเทคโนโลยีติดตาม
เว็บไซต์ใช้คุกกี้เฉพาะที่จำเป็นต่อการทำงาน (essential cookies) เช่น การเก็บ session login ไม่ใช้คุกกี้สำหรับการตลาดหรือการติดตามข้ามเว็บไซต์
10. การติดต่อเจ้าหน้าที่คุ้มครองข้อมูล
หากมีคำถามหรือข้อร้องเรียนเกี่ยวกับการคุ้มครองข้อมูลส่วนบุคคล:
- อีเมล: support@pharmsolutic.com
- ติดต่อ สคส.: www.pdpc.or.th
11. การเปลี่ยนแปลงนโยบาย
บริษัทอาจปรับปรุงนโยบายนี้ได้ โดยจะแจ้งสมาชิกผ่านอีเมลและประกาศบนเว็บไซต์ ก่อนวันที่นโยบายใหม่มีผลบังคับใช้อย่างน้อย 30 วัน
Privacy Policy
Compliant with Thai Personal Data Protection Act (PDPA) 2019
1. Data Controller
Pharmsolutic Co., Ltd. (the "Company") acts as Data Controller under the Thai Personal Data Protection Act, B.E. 2562 (2019), and provides this Privacy Policy for your information.
2. Personal Data Collected
2.1 Data You Provide Directly
| Data Type | Examples |
|---|---|
| Identification | Full name, company/organization |
| Contact | Email, phone (if provided) |
| Account credentials | Password (encrypted/hashed) |
| Financial | Payment evidence (slips) |
| Question content | Messages and attachments submitted |
2.2 Data Generated Automatically
- Login logs with IP address and timestamps
- Token purchase and usage history
- Terms of Service and NDA acceptance records with timestamps
- Essential cookies for session management
3. Purposes and Legal Basis
| Purpose | Legal Basis |
|---|---|
| Provide consultation service | Contract performance (Section 24(3)) |
| Send quotations and status emails | Contract performance (Section 24(3)) |
| Improve service quality | Legitimate interest (Section 24(5)) |
| Tax and accounting compliance | Legal obligation (Section 24(6)) |
| Email marketing | Consent (Section 19) |
4. Disclosure to Third Parties
4.1 General Principle
The Company will not sell, lease, or disclose your personal data to third parties, except:
- With your explicit consent
- Under court order or legal compulsion
- To protect Company's rights in litigation
4.2 Data Processors
The Company engages technology service providers under Data Processing Agreements (DPAs):
- Supabase Inc. (USA) — Database hosting and Authentication
- Resend, Inc. (USA) — Transactional email service
- Cloudflare Inc. (USA) — CDN and DNS
Cross-border data transfers are protected by technical (encryption) and legal (Standard Contractual Clauses) measures.
5. Data Retention
| Data Type | Retention Period |
|---|---|
| Member account data | Membership duration + 1 year after termination |
| Q&A history | Throughout membership |
| Financial records (receipts, slips) | 5 years (tax law requirement) |
| Access logs | 90 days |
| Marketing data | Until consent withdrawal |
6. Data Subject Rights
Under PDPA, you have the following rights:
- Right of Access — request your personal data held by us
- Right of Rectification — correct inaccurate or outdated data
- Right of Erasure — request data deletion (subject to legal obligations)
- Right to Restrict Processing — request temporary processing suspension
- Right to Data Portability — receive data in machine-readable format
- Right to Object — object to processing in certain cases
- Right to Withdraw Consent — withdraw previously given consent
- Right to Complain — file complaints with the Office of the Personal Data Protection Committee (PDPC)
To exercise these rights, contact privacy@pharmsolutic.com. We will respond within 30 days.
7. Data Security
The Company employs international-standard security measures:
- Encryption in transit — HTTPS/TLS 1.2+ for all communications
- Encryption at rest — AES-256 for stored data
- Password hashing — bcrypt; no plaintext storage
- Access control — Row Level Security (RLS) on database
- Audit logging — all sensitive data access logged
- Backup — daily backups retained 30 days
8. Data Breach
In case of a data breach affecting your rights and freedoms, the Company will notify the PDPC within 72 hours and inform you without undue delay, as required by law.
9. Cookies and Tracking
Our website uses only essential cookies necessary for functionality (e.g., login session management). We do not use marketing or cross-site tracking cookies.
10. Contact Data Protection
For privacy questions or complaints:
- Email: privacy@pharmsolutic.com
- PDPC: www.pdpc.or.th
11. Policy Changes
The Company may update this Policy with at least 30 days advance email and website notice before the new policy takes effect.