logo 1

Privacy Policy

SPI Tech – Privacy Policy

SPI TECH

Privacy Policy

Company Information

Legal Name: TH SP INNOVATION TECHNOLOGY CO., LTD.

Trading As: SPI TECH

Website: spitech.co.th

Address: 1179, Winlong Building 1st Floor, Bang Rak District, Bangkok, Thailand

Phone: +66 9426 50019

Email Support: infospinnvtech@gmail.com

🔒 PDPA Compliant

SPI Tech is fully compliant with Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA). We are committed to protecting your personal data rights and ensuring the highest standards of data privacy and security in accordance with Thai law.

THAILAND PDPA CERTIFIED

Privacy Policy

Effective Date: November 19, 2025

1. Introduction and PDPA Compliance

TH SP Innovation Technology Co., Ltd. (“SPI Tech”, “we”, “us”, or “our”) is committed to protecting your privacy and ensuring the security of your personal information in full compliance with Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”).

This Privacy Policy describes how we collect, use, disclose, and safeguard your personal data when you visit our website spitech.co.th or make a purchase from us. By using our services, you consent to the data practices described in this policy.

As the Data Controller under the PDPA, we are responsible for ensuring your personal data is processed lawfully, fairly, and transparently.

2. Legal Basis for Processing Personal Data (PDPA Compliance)

Under the PDPA, we process your personal data based on the following legal grounds:

  • Consent: You have given explicit consent for processing your personal data for specific purposes (e.g., marketing communications)
  • Contract Performance: Processing is necessary to fulfill our contractual obligations to you (e.g., order processing and delivery)
  • Legal Obligation: We are required by Thai law to process certain data (e.g., tax records, compliance reporting)
  • Legitimate Interests: Processing is necessary for our legitimate business interests (e.g., fraud prevention, website security) while respecting your rights

3. Information We Collect

We collect several types of personal data to provide and improve our services:

  • Personal Identification Information: Name, email address, phone number, shipping address, billing address, date of birth
  • Payment Information: Credit card details, billing information (processed securely through encrypted payment gateways and not stored by SPI Tech)
  • Transaction Information: Purchase history, product preferences, order details, return requests
  • Technical Data: IP address, browser type, device information, cookies, and usage data
  • Communication Data: Your correspondence with our customer service team, feedback, reviews, and support tickets
  • Sensitive Data (with explicit consent): We do not intentionally collect sensitive personal data as defined under the PDPA unless absolutely necessary and with your explicit consent

4. How We Use Your Personal Data

Your personal data is used for the following purposes in compliance with the PDPA:

  • Processing and fulfilling your orders and deliveries
  • Communicating with you about orders, shipments, and customer service inquiries
  • Sending promotional materials, newsletters, and marketing communications (with your explicit consent, which can be withdrawn at any time)
  • Improving our website, products, and services through data analysis
  • Detecting and preventing fraud, security breaches, and illegal activities
  • Complying with legal obligations under Thai law and international regulations
  • Analyzing customer behavior and preferences to enhance user experience
  • Maintaining accurate business records and accounting

5. Information Sharing and Disclosure

We respect your privacy and do not sell, trade, or rent your personal data to third parties. We may share your information with:

  • Service Providers: Trusted third-party companies that assist with payment processing, shipping, logistics, marketing, and customer service (bound by confidentiality agreements)
  • Legal Authorities: When required by Thai law, court orders, or to protect our rights, property, or safety
  • Business Transfers: In the event of a merger, acquisition, or asset sale, your information may be transferred to the acquiring entity (with prior notice to you as required by PDPA)
  • With Your Consent: Any other disclosure will only occur with your explicit consent

All third parties processing your data on our behalf are contractually obligated to comply with PDPA requirements and maintain appropriate security measures.

6. Data Security Measures

We implement industry-standard security measures to protect your personal data in compliance with PDPA requirements:

  • SSL/TLS encryption (256-bit) for all data transmission
  • Secure payment gateways (PCI-DSS compliant) for financial transactions
  • Restricted access to personal data by authorized personnel only
  • Regular security audits and vulnerability assessments
  • Firewall protection and intrusion detection systems
  • Secure data storage with backup and disaster recovery procedures
  • Employee training on data protection and PDPA compliance
  • Data breach response protocols as required by PDPA

However, no method of transmission over the internet is 100% secure. While we strive to protect your information using commercially acceptable means, we cannot guarantee absolute security.

7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your browsing experience. Types of cookies we use:

  • Essential Cookies: Required for website functionality and security
  • Performance Cookies: Help us analyze website traffic and improve performance
  • Functional Cookies: Remember your preferences and settings
  • Marketing Cookies: Used to deliver personalized advertisements (with your consent)

You can control cookies through your browser settings. Disabling cookies may affect certain website features. By continuing to use our website, you consent to our use of cookies as described.

8. Your Rights Under Thailand’s PDPA

As a data subject under Thailand’s PDPA, you have the following rights regarding your personal data:

Right Description
Right to Access Request access to your personal data and receive a copy
Right to Rectification Request correction of inaccurate or incomplete personal data
Right to Erasure Request deletion of your personal data (subject to legal obligations)
Right to Restriction Request restriction of processing under certain circumstances
Right to Data Portability Receive your data in a structured, commonly used format
Right to Object Object to processing based on legitimate interests or for direct marketing
Right to Withdraw Consent Withdraw consent at any time (does not affect prior lawful processing)
Right to Lodge a Complaint File a complaint with the Personal Data Protection Committee of Thailand

To exercise these rights, please contact us at infospinnvtech@gmail.com. We will respond to your request within 30 days as required by PDPA.

9. Data Retention Period

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Transaction Records: Retained for 7 years to comply with Thai tax and accounting laws
  • Marketing Data: Retained until you withdraw consent or request deletion
  • Customer Service Records: Retained for 3 years for quality assurance and dispute resolution
  • Website Analytics: Anonymized after 2 years

After the retention period expires, we will securely delete or anonymize your personal data in accordance with PDPA requirements.

10. International Data Transfers

Your personal data may be transferred to and processed in countries outside of Thailand for purposes such as payment processing, cloud storage, or customer support. When transferring data internationally, we ensure:

  • Transfers are made to countries with adequate data protection standards as recognized by the Personal Data Protection Committee
  • Appropriate safeguards are in place (e.g., Standard Contractual Clauses, Binding Corporate Rules)
  • Recipients are contractually obligated to protect your data in accordance with PDPA standards
  • You have the right to obtain information about safeguards in place for international transfers

11. Children’s Privacy

Our services are not directed to individuals under the age of 20 years (legal age of majority in Thailand). We do not knowingly collect personal data from minors without parental consent. If you believe we have inadvertently collected data from a minor, please contact us immediately, and we will delete it promptly.

12. Data Breach Notification

In compliance with the PDPA, in the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the Personal Data Protection Committee within 72 hours of becoming aware of the breach
  • Notify affected data subjects without undue delay if the breach poses a high risk
  • Provide information about the nature of the breach, potential consequences, and remedial measures taken
  • Document all data breaches, including facts, effects, and remedial actions

13. Automated Decision-Making and Profiling

We may use automated decision-making and profiling for purposes such as:

  • Fraud detection and prevention
  • Personalized product recommendations
  • Targeted marketing campaigns

You have the right to:

  • Be informed about the logic involved in automated decision-making
  • Object to decisions based solely on automated processing
  • Request human intervention in automated decisions

14. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy at any time to reflect changes in our practices or legal requirements. Changes will be posted on this page with an updated effective date. Material changes will be communicated to you via email or prominent notice on our website.

We encourage you to review this policy periodically to stay informed about how we protect your personal data.

15. Data Protection Officer (DPO)

In compliance with the PDPA, SPI Tech has designated a Data Protection Officer responsible for overseeing our data protection strategy and compliance:

Data Protection Officer
TH SP Innovation Technology Co., Ltd.
Email: infospinnvtech@gmail.com
Phone: +66 9426 50019

You may contact our DPO with any questions or concerns regarding your personal data or this Privacy Policy.

Contact Us Regarding Privacy and PDPA Matters

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data rights under the PDPA, please contact us:

Email: infospinnvtech@gmail.com
Phone: +66 9426 50019
Address: 1179, Winlong Building 1st Floor, Bang Rak District, Bangkok, Thailand

Response Time: We will respond to your inquiry within 30 days as required by Thailand’s PDPA.

Lodge a Complaint with Regulatory Authority

If you believe your personal data rights under the PDPA have been violated, you have the right to lodge a complaint with:

Personal Data Protection Committee
Office of the Personal Data Protection Committee
Ministry of Digital Economy and Society
Thailand

Website: www.pdpc.or.th

0
    0
    Your Cart
    Your cart is emptyReturn to Shop