Privacy Policy
Cryptomind Media Co., Ltd. (hereinafter collectively referred to as "Cryptomind") recognizes and understands the importance of protecting the Personal Data of customers, representatives of business partners, or other individuals who have a business relationship with Cryptomind ("Data Subject"). To this end, Cryptomind has published this Privacy Policy to inform Data Subjects of the principles regarding the protection of their Personal Data, to explain the reasons and methods for collecting, using, disclosing, and transferring or transferring Personal Data to foreign countries, and to explain the rights of Data Subjects regarding their Personal Data, as well as the channels for exercising these rights to safeguard their Personal Data.
Cryptomind shall collect, use, or disclose Personal Data of Data Subjects only to the extent necessary to achieve the purposes outlined in this Privacy Policy or for other purposes as stated in any documents or electronic methods related to consent for the collection, use, or disclosure of Personal Data of the Data Subject.
"Personal Data" refers to information about the Data Subject that identifies or can identify the Data Subject, as outlined below. Cryptomind collects Personal Data of the Data Subject, both directly from the Data Subject, such as through employees, customer service centers (call centers), or other service channels of Cryptomind, or from other indirect sources, such as companies of the Cryptomind Group, public sources, the Data Subject's publicly available social media, external service providers, consultants, business partners, agencies, organizations, or any individuals who have contracts with Cryptomind, such as government agencies in Thailand and abroad, individuals authorized or appointed by the Data Subject as representatives, and individuals who are legally entitled, authorized, or have consent to disclose the Personal Data of the Data Subject to Cryptomind, provided that such individuals have complied with data protection laws. The type of data that Cryptomind collects depends on the relationship between the Data Subject and Cryptomind, as well as the services and/or products the Data Subject seeks from Cryptomind.
"Sensitive Personal Data" refers to Personal Data that the law classifies as sensitive or confidential.
"Processing of Personal Data" refers to any action taken with Personal Data, such as collection, recording, copying, organizing, storing, updating, altering, using, retrieving, disclosing, transmitting, publishing, transferring, combining, deleting, or destroying, etc.
"Data Controller" refers to the individual or legal entity with the authority to make decisions regarding the collection, use, or disclosure of Personal Data.
"Data Subject" refers to customers, representatives of business partners, or other individuals who have a business relationship with Cryptomind, including those acting on behalf of legal entities.
"Personal Data Processor" refers to an individual or legal entity that processes the collection, use, or disclosure of Personal Data on the instructions or behalf of the Data Controller. However, such individual or legal entity is not the Data Controller.
The Legal & Compliance department, under the guidance of the Data Protection Officer, is responsible for enforcing and updating this Policy as appropriate.
This Policy applies to the Personal Data of individuals who have current or potential future relationships with the company, whose Personal Data is processed by the company, its officers, employees under contract, business units, or other departments operated by the company, including contractors or external parties who process Personal Data on behalf of or in the name of the company ("Personal Data Processors") under various products and services, such as websites, systems, applications, documents, or other services managed by the company (collectively referred to as "Services").
This Personal Data Protection Policy applies to the collection, use, disclosure, as well as the transfer or transmission of Personal Data of Data Subjects to foreign countries, related to the use of the services and/or products of Cryptomind, through various channels such as websites, applications, customer service centers (call centers), activities and exhibitions, online communication channels, other locations, or any other service channels of Cryptomind. This Policy does not apply to the use of services and/or products that are not owned or controlled by Cryptomind.
In accessing and using the services and/or products of Cryptomind, Data Subjects may be required to provide Personal Data that identifies the Data Subject to facilitate transactions related to the services and/or products. This includes information provided in service request forms, identity documents required for service/product registration, and financial information, among others. Cryptomind may process Personal Data in various forms, including documents, images, and/or electronic formats, as well as the sources and types of Personal Data collected, used, and/or disclosed by the company.
This Personal Data Protection Policy applies to the Personal Data of Data Subjects as follows:
(1) Individual customers, including prospective customers (those who may become customers in the future), current customers, and former customers, as well as individuals related to such individual customers.
(2) Employees, personnel, officers, representatives, shareholders, authorized persons, directors, contacts, agents, and other individuals related to the corporate and individual customers mentioned above, including prospective customers (those who may become customers in the future), current customers, and former customers.
(3) Individuals related to those who have been, are, or will be external service providers or business partners of Cryptomind, including other individuals related to those who have been, are, or will be external service providers or business partners of Cryptomind.
(4) Holders of digital assets of Cryptomind or those related, including authorized representatives or proxies of such individuals.
(5) Any other individuals who contact Cryptomind through various channels, whether directly through the service provider or through Cryptomind's partners or agents.
In addition to this Policy, Cryptomind may establish a Privacy Policy statement ("Notice") for its products or services to inform Data Subjects who are users of the services about the Personal Data being processed, the purposes and legal grounds for processing, the retention period for Personal Data, as well as the rights of Data Subjects regarding their Personal Data specific to that product or service.
In the event of any conflict between the content of the privacy notice and this Policy, the provisions of the privacy notice for that service shall prevail.
1. The Personal Data of Data Subjects that Cryptomind will collect, use, disclose, and/or process, including but not limited to the following types of Personal Data:
(a) Identity Data, such as name, surname, date of birth, age, nationality, national ID number, passport number (for foreigners), tax identification number, marital status, education, employment information (e.g., occupation, name of employer, job title, salary), signature, photograph, house registration, as well as Sensitive Personal Data as defined by law and/or this Policy, investment suitability assessment (Suitability test), investment objectives, etc.
(b) Contact Details, such as address on the national ID card, address on the house registration, current address, address for document delivery, work address, telephone number, mobile number, fax number, email address, and identification number for other electronic communication, etc.
(c) Financial Data, such as account numbers and account types, PromptPay information, transaction data, financial history, information from the Enforcement Department database, financial status information (e.g., income, wealth, assets and liabilities, proof of income or expenses, credit information, borrowing history, credit history, and debt repayment information), financial needs and objectives, assets, income and expenses, as well as payment information and service/product application data, etc.
(d) Transaction Data, such as account numbers for products and/or services, account credit limits, remaining balances and collateral, asset and liability values, profit/loss, digital asset trading history, payment and delivery history of digital assets, debt repayment history, deposit and withdrawal history of funds, digital asset deposit and withdrawal history, and transactions related to the Data Subject's assets, etc.
(e) Data related to digital asset wallets and digital tokens reserved for purchase, such as information related to the registration of digital asset wallet services, digital asset wallet details (including wallet address information, transaction history related to the wallet), details of the use of rights in digital tokens for utility redemption, and details of returns from investment in digital tokens for investment purposes, etc.
(f) Image and audio data collected from communication (Communication Data), such as copies of national ID cards, passport copies, images and/or audio from CCTV, telephone conversations, or communications through online channels or any other electronic means.
(g) Other Personal Data collected, used, or disclosed in relation to the relationship between the Data Subject and Cryptomind, such as information provided by the Data Subject to Cryptomind in contracts, forms, surveys, or questionnaires, or information collected when the Data Subject participates in business activities, marketing, seminars, or social events organized by Cryptomind. This also includes data obtained through analysis, research, and the creation of datasets specific to the Data Subject that Cryptomind collects from monitoring behavior and/or location using cookies or other technologies or methods, for the purpose of providing services, developing products, etc.
(h) Technical data, customer preferences for searching or using information through electronic channels, social media data, including financial data, membership login information, IP address, web beacon, logs, device ID, device model and type, network, connection data, access data, single sign-on (SSO) login data, login logs, access times, duration spent on Cryptomind webpages, smart device data, authentication, browsing data, location, website access, and spending patterns or searches related to Cryptomind’s services and/or products obtained through cookies or connections to other websites that the Data Subject interacts with, etc.
2. The purposes for which Cryptomind collects, uses, discloses, and/or processes the Personal Data of
the Data Subject.
Cryptomind will collect, use, disclose, and/or process the Personal Data of the Data Subject to achieve the various purposes as outlined below, relying on (a) the consent of the Data Subject, (b) the necessity for the performance of a contract, (c) Cryptomind's legitimate interests, (d) the necessity to carry out tasks for public interest purposes, or (e) compliance with applicable laws. These purposes may vary depending on the services and/or products or any relationship that the customer, external service provider, business partner, or individuals related to such persons with Cryptomind.
In this regard, Cryptomind may process Personal Data of the Data Subject for the purposes mentioned above using current technologies or those that may be developed in the future, including but not limited to the use of Artificial Intelligence (AI), Cloud Computing, Blockchain, data identity comparison technology, Biometric Comparison, etc.
In some cases, if Cryptomind does not obtain consent from the Data Subject, it may affect the Data Subject's ability to receive services and/or products from Cryptomind, including convenience or fulfillment of the contract. The Data Subject may suffer damage or lost opportunities, and it may impact compliance with any laws that the Data Subject or Cryptomind must adhere to.
In addition, in some cases, Cryptomind may transfer the Personal Data of the Data Subject to foreign countries for the purposes mentioned above. Cryptomind will proceed in accordance with the provisions outlined in Section 7 regarding the transfer of the Data Subject's Personal Data internationally.
3. Who does Cryptomind share the Personal Data of the Data Subject with?
If the Data Subject has given consent, or if it is necessary for the performance of a contract, compliance with the law, the performance of tasks in the public interest or in the exercise of official authority, or for other legitimate legal purposes, Cryptomind may send, transfer, and/or disclose the Personal Data of the Data Subject to the following parties, both in Thailand and abroad. In this regard, Cryptomind will act within the legal framework and ensure that adequate standards for Personal Data protection are in place for such actions.
(a) Cryptomind Group subsidiaries, such as Cryptomind Group Holdings Co., Ltd., Cryptomind Asset Co., Ltd., Cryptomind Advisory Co., Ltd., Cryptomind Media Co., Ltd., Merkel Capital Co., Ltd., and Elkrem Capital Co., Ltd., etc.
(b) Cryptomind’s partners, where Cryptomind may transfer the Personal Data of the Data Subject to individuals acting on behalf of the Data Subject or involved in providing services and/or products of any kind that the Data Subject has received or will receive from Cryptomind, such as life insurance companies, non-life insurance companies, beneficiaries, or contracting parties. However, these recipients must agree to handle the Personal Data of the Data Subject in compliance with Personal Data protection Laws and in accordance with this Privacy Policy.
(c) Cryptomind’s external service providers, such as IT system development companies, marketing activity service providers, research firms, cloud data storage service providers, debt collection agencies, professional consulting firms, law firms, auditors, etc.
(d) Financial institutions or payment system service providers, such as other financial institutions that provide payment systems for the Data Subject's transactions, etc.
(e) Social media, such as Facebook and Line, for sending marketing messages to the Data Subject, collecting data for analysis to develop services and/or products of Cryptomind, etc.
(f) External parties, such as assignees, transferees, or debt purchasers, to whom Cryptomind may assign, transfer, or convert its debts, rights, or obligations, may receive or be transferred Personal Data of the Data Subject, provided that such actions are permitted under the terms and conditions of any agreement entered into between the Data Subject and Cryptomind. Cryptomind may disclose or transfer the Personal Data of the Data Subject to assignees, transferees, or debt purchasers, including parties who may become assignees, transferees, or debt purchasers. However, these recipients must agree to handle the Personal Data of the Data Subject in accordance with applicable data protection laws and in alignment with this Privacy Policy.
(g) Other external parties involved in business transfers: Cryptomind may disclose or transfer Personal Data of the Data Subject to business partners, investors, major shareholders, transferees, potential transferees, or individuals who may receive transfers from Cryptomind, in the event of business recovery, restructuring, mergers, acquisitions, sales, purchases, joint ventures, transfers, dissolution of business, or similar events related to the transfer or sale of business, assets, or shares, in whole or in part, of Cryptomind. If such events occur, the recipients of the data will adhere to this Privacy Policy concerning the Personal Data of the Data Subject.
(h) Regulatory government agencies overseeing Cryptomind or agencies responsible for registration, such as the Securities and Exchange Commission, the Anti-Money Laundering Office, the Courts, the Royal Thai Police, the Department of Business Development, or any other government agency with a subpoena or warrant requiring Cryptomind to send Personal Data of clients or submit assets, such as the Department of Legal Execution or the Revenue Department, etc.
(i) Any agency, organization, or legal entity that has a contract with Cryptomind, or with whom Cryptomind is a contracting party, or has a relationship with Cryptomind, such as a company in which the Data Subject is interested in investing, etc.
(j) Any person or entity necessary to achieve the various purposes outlined in Clause 2.
4. What rights does the Data Subject have regarding their Personal Data?
The Data Subject has the right to take the following actions:
4.1 The right to access and receive a copy of the Data Subject's Personal Data, or the right to request Cryptomind to disclose how such Personal Data was obtained without the Data Subject's consent (Right to Access).
The Data Subject may request to know and receive a copy of their Personal Data under the responsibility of Cryptomind, or request Cryptomind to disclose how the data was obtained without the Data Subject's consent.
4.2 The right to rectify the Data Subject's Personal Data (Right to Rectification).
The Data Subject may have the right to request Cryptomind to rectify the data to ensure it is accurate, up-to-date, and not misleading.
4.3 The right to erase or destroy the Personal Data of the Data Subject (Right to Erasure).
The Data Subject may have the right to request Cryptomind to delete or destroy, or anonymize the Personal Data so that it can no longer identify the Data Subject in the following cases:
(1) The Personal Data is no longer necessary for the purposes for which it was collected, used, or disclosed.
(2) The Data Subject has withdrawn consent, and Cryptomind can no longer rely on any grounds for processing that Personal Data.
(3) The Data Subject has objected to the processing in certain circumstances, and Cryptomind cannot deny such a request.
(4) The Data Subject has objected to the processing for direct marketing purposes.
(5) The Personal Data was collected, used, or disclosed unlawfully.
4.4 Right to Restriction of Processing
The Data Subject may have the right to restrict Cryptomind from processing their Personal Data temporarily in the following circumstances:
(1) The processing is no longer necessary, but the retention of the Personal Data is required for legal claims.
(2) The processing of the Personal Data is unlawful, but the Data Subject wishes to restrict processing instead of requesting erasure of the data.
(3) The Data Subject has requested the verification of the accuracy of their Personal Data.
(4) The Data Subject is in the process of contesting the use of their objection rights.
4.5 Right to Data Portability
The Data Subject may have the right to request Cryptomind to provide or transfer their Personal Data in a structured, commonly used, and machine-readable format that can be used or disclosed by automated means. Additionally:
(a) The Data Subject has the right to request Cryptomind to send or transfer the data in such a format to another data controller when feasible via automated means.
(b) The Data Subject may request Cryptomind to send or transfer the data directly to another data controller, unless this is technically not feasible.
4.6 Right to Object
The Data Subject may have the right to object to the collection, use, or disclosure of their Personal Data in the following circumstances:
(1) When the collection, use, or disclosure of Personal Data is for direct marketing purposes.
(2) When the collection, use, or disclosure of Personal Data is for scientific, historical, or statistical research purposes, unless necessary for Cryptomind to perform its public interest task.
(3) When Personal Data is collected on the basis of necessity for performing a task in the public interest or for legal compliance, unless Cryptomind can demonstrate that there are compelling legitimate grounds for processing that override the interests, rights, and freedoms of the Data Subject or are necessary for the establishment, exercise, or defense of legal claims.
4.7 Right to Withdraw Consent
The Data Subject may have the right to withdraw their consent given to Cryptomind for the collection, use, and disclosure of their Personal Data at any time, except where such withdrawal of consent is restricted by law or contract that benefits the Data Subject, such as when the Data Subject is still using services or products from Cryptomind or when the Data Subject still has an outstanding debt obligation with Cryptomind.
The Data Subject can exercise their right to withdraw consent through the same channels through which they provided their consent initially.
4.8 Right to Lodge a Complaint
The Data Subject may have the right to file a complaint with the relevant authorities if they believe that the collection, use, disclosure, and/or transfer of their Personal Data to foreign countries is unlawful or does not comply with data protection laws.
The Data Subject’s rights mentioned above are subject to the applicability of the law and various other factors. Cryptomind may not be able to comply with the Data Subject's request if Cryptomind has a legitimate reason to retain the Personal Data, such as when the Data Subject is still receiving other services from Cryptomind or when Cryptomind must retain the Personal Data for the period required by law, even if the Data Subject has terminated their relationship with Cryptomind.
If the Data Subject wishes to exercise their rights, they can contact Cryptomind via email at dpo@cryptomind.group or through other channels specified for each transaction. Cryptomind will consider the request and complete it within 30 business days from the date it receives the request from the Data Subject, and Cryptomind may extend the period by an additional 30 business days unless otherwise provided by law.
5. How does Cryptomind protect the Data Subject’s Personal Data?
Cryptomind has implemented technical, physical, and administrative security measures designed to provide appropriate protection for the Personal Data of Data Subjects from loss, misuse, unauthorized access, disclosure, and alteration. These measures include firewalls, data encryption, physical access control when entering Cryptomind's data centers, and access control for data. While Cryptomind secures its systems and services, the Data Subject is responsible for securing their password and account information and ensuring that the Personal Data Cryptomind holds about them is accurate and up-to-date.
Cryptomind has established policies, guidelines, and minimum standards for managing customer Personal Data, such as IT system security standards. Cryptomind also periodically updates these policies, guidelines, and minimum standards according to the criteria set by law.
In addition, employees, contractors, business partners, or external service providers are required to maintain the confidentiality of customers' Personal Data in accordance with the confidentiality agreements signed with Cryptomind Group's affiliated companies.
6. Notification of Personal Data Breach
In the event of a Personal Data breach where there is a high likelihood of risk affecting the rights and freedoms of individuals, Cryptomind will take actions to prevent, suspend, or rectify the breach to ensure that the Personal Data breach ends or does not cause further impact. Additionally, Cryptomind will notify the Data Subject of the Personal Data breach without undue delay and take other measures according to the Personal Data Protection Commission's Announcement on the Criteria and Procedures for Notification of Personal Data Breach B.E. 2565.
7. Cookies
Cryptomind's websites use cookies technology to enhance the security of the websites and improve the user experience of the website and online services of the Data Subject. Cookies are also used to develop Cryptomind's services and/or products to suit the Data Subject's needs or to expand benefits for the Data Subject. A cookie is a small file stored on the computer's hard drive by the website to store personal information entered by the Data Subject or to store information entered without being recorded for any particular individual. The Data Subject can check the status of cookie usage or reject the use of cookies in their browser settings.
8. Transfer of Personal Data Internationally
Cryptomind may disclose or transfer the Personal Data of the Data Subject to external parties or servers located in foreign countries, where the destination country may or may not have data protection standards similar to those in Thailand. This is for the purposes outlined in this Privacy Policy. Cryptomind has implemented steps and measures to ensure that the Personal Data transfer is conducted securely, and the recipient of the data maintains appropriate standards for data protection. The data transfer is conducted in compliance with the law, utilizing exceptions permitted by law.
9. Personal Data of Minors, Persons with Limited Legal Capacity, and Incapacitated Persons
In general, Cryptomind’s activities are not targeted at minors, persons with limited legal capacity, or incapacitated persons. Cryptomind will not intentionally collect Personal Data from minors without the consent of the person exercising parental authority, or from persons with limited legal capacity or incapacitated persons without the consent of their guardian or custodian under the law. If the Data Subject is a minor, person with limited legal capacity, or incapacitated person who wishes to enter into a contract with Cryptomind, the Data Subject must obtain consent from the person exercising parental authority, guardian, or custodian under the law before contacting Cryptomind or providing their Personal Data to Cryptomind.
10. Personal Data of Third Parties
If the Data Subject provides Personal Data of third parties to Cryptomind, such as guarantors, senior executives, authorized persons, directors, shareholders, employees, contractors, agents, or other individuals related to the Data Subject's relationship with Cryptomind, such as names, addresses, emergency contact details, family members' debt and income information, the Data Subject must inform those third parties about this Privacy Policy and obtain consent if necessary or have another legal basis for disclosing the third party's Personal Data to Cryptomind.
11. How Cryptomind Retains Personal Data and for How Long
Cryptomind will retain the Personal Data of the Data Subject for as long as necessary and reasonable to fulfill the purposes for which the Personal Data was collected, as outlined in this Privacy Policy, and to comply with legal obligations and regulations. However, Cryptomind may retain Personal Data for a longer period if necessary for the establishment of legal claims, compliance with legal obligations, or defense against legal claims. Once the retention period expires and the Personal Data is no longer required for the stated purposes, Cryptomind will delete, destroy, or anonymize the Personal Data in accordance with the standards and methods for data deletion set by the Personal Data Protection Committee or applicable laws or international standards.
In some cases, Cryptomind may retain certain personal data, such as name, surname, address, the dates of commencement and termination of the relationship, in an archive database solely for historical record-keeping purposes, and such data will not be used or disclosed for other purposes.
12. Amendment of This Privacy Policy
Cryptomind may change or update this Privacy Policy from time to time. If there are any changes to Cryptomind's Personal Data protection practices due to various reasons, such as technological advancements, legal changes, etc., Cryptomind recommends that data owners carefully read this Privacy Policy and/or any revised versions, and review any changes that may occur on the Cryptomind Group's website. However, if such changes significantly affect the data owner in their capacity as the owner of personal data, Cryptomind will notify the data owner or seek the data owner's consent in advance, as appropriate, before the changes come into effect.
13. Language of This Privacy Policy
This Privacy Policy has been entered into in English and is provided for reference only. The Parties agree that the Thai version of this Agreement shall prevail in the event of any conflict or inconsistency with the English version.
14. Contact details of Cryptomind
If the Data Subject has any questions regarding Cryptomind's practices and activities related to their personal data, the Data Subject can contact Cryptomind or Cryptomind's Data Protection Officer using the contact details below. Cryptomind is happy to assist the Data Subject by providing information and suggestions.
[Cryptomind Media Co., Ltd.]
Attention: Data Protection Officer
Address: 188/73 G Building, Dragon Town, Charasmuang Road, Wangmai, Pathumwan, Bangkok Thailand 10330
E-mail: dpo@cryptomind.group
[https://cryptomind-group.webflow.io/]