Privacy policy
We, UPD (Thailand) Limited (“we,” “us,” “our,” or the “Company”), value your right in respect to your personal data, and we are committed to the responsible collection, use, disclosure, transfer and otherwise processing (“process,” “processing” or “processed”) of your personal data, and in addition, to comply with our legal obligations under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), we have thus adopted this Privacy Policy (“Privacy Policy”) to provide you with information on how your personal data will be processed and handled by us.
1. Application of this Privacy Policy
This Privacy Policy applies to you if you are (i) a visitor to websites, applications and/or any other platforms (“Visitor”) which are operated by the Company from time to time (collectively, “Platform”); (ii) an individual customer, including individual customer who uses and/or purchases our products and/or services (“Products”) through our Platform, regardless of whether you have signed up for an account on our Platform or not (“Individual Customer”); (iii) a person associated with our non-individual customer (“Corporate Customer” and collectively with Individual Customers be referred to as the “Customer”), including the authorized director(s), authorized representative(s) and/or the contact person(s) of a corporate customer, who purchases or uses our Products (“Associated Person”); and (iv) any person who contacts us via any contact channels including social media platforms.
2. Categories of Personal Data that We Process
In general, we will process the following categories of your personal data.
Category of Personal Data |
Collection of your Personal Data |
Identification and Contact Information |
First name, last name, shipping address, telephone number(s), and email address |
Payment Information |
Credit/debit card information and billing address |
Shopping History |
Information about the Products you viewed, added to your cart, purchased or returned |
Social Media Information |
Information that you post on our social media platforms (e.g. comments, images, posts), your interactions with our posts on social media platforms, your social media profile information, correspondences between you and us through social media platforms, and any other information which you may make available to us on social media platforms |
Information You Submit |
Photos, videos, and other user-generated content that you choose to provide when you send us a message through the “Contact Us” page, any chatbot, or similar features on the Platform; information that we collect when you enter a promotion; and other information that you choose to provide during your interaction(s) with us |
Device and Browser Information |
Your device type, browser type, operating system name and version, device identifier(s), and IP address |
Log and Usage Information |
The date and time you access the Platform, the site you came from and/or the site you visit when you leave the Platform, the frequency with which you access and use the Platform, the pages that you navigate to, the links that you click, and other information about your interactions with the Platform |
Sensitive Personal Data |
We may process your health-related data, e.g. allergies, photos of allergy reactions, medical certificate, medical treatment, etc.
Your Sensitive Personal Data may appear on the copy of your Thai identification card, i.e. your religious belief and/or blood type data. However, we do not have an intention to process such Sensitive Personal Data; therefore, we will require you to blind, cross out or omit the information about religious belief and/or blood type before providing a copy of your identification card to us.
In the case where such Sensitive Personal Data still appears on a copy of identification card, we may, at any time, blind or cross out such Sensitive Personal Data in order to comply with the PDPA (which requires us to only collect personal data to the extent that is necessary and relevant for our business operations). |
In the case where we will collect your personal data other than those prescribed in this Privacy Policy, we will inform you about the collection or the processing of the personal data and may request your consent (if required) in accordance with the requirements prescribed by the PDPA.
3. Methods for the Collection of Your Personal Data
In general, we will collect personal data directly from you; however, in the case where it is necessary for us to collect your personal data from other sources, we will ensure that your Personal Data will be collected and protected in accordance with the PDPA.
In the case where you provide the Personal Data of a third, you warrant that you have informed such person about the processing of his/her Personal Data by us as explained in this Privacy Policy. In addition, if the consent for the processing of the Personal Data is required, you agree to assist us in obtaining the valid and enforceable consent from such person in accordance with the requirements prescribed in the PDPA.
4. Purposes for Processing Your Personal Data
In general, we will process your personal data for the following purposes:
Purposes |
Categories of |
Legal Basis |
To enter into an agreement or establish a legal relationship with you or the legal entity of which you were authorized to represent, and to execute and perform the obligations under such agreement or legal relationship
Your personal data is necessary for the following purposes:
|
Remark: If you do not provide any personal data that is necessary for creation and registration of customer’s account in our systems, payment completion, and order delivery, we may not be able to enter into an agreement with you, nor to execute or perform our obligations as specified under the said agreement or legal relationship (either in whole or in part), nor to proceed with your order and the payment. |
|
To handle your request and/or complaints via online and offline channels
We may process your personal data for the following purposes:
|
Remark: If you do not provide any personal data that is necessary for us to handle your request and/or complaints in respect to allergies, we may not be able to solve your concerns and requests. In addition, we may be unable to comply with the laws which may result us in violation of the law applicable to us.
Moreover, if you do not provide any personal data that is necessary for the handling of Customer’s requests for a product change, return or refund, we may not be able to serve you or to perform our obligations under the agreement between us and the Customer, either in whole or in part. |
|
To record your purchase history
To record and maintain your purchase history for our internal audit purposes.
|
|
Legitimate Interest |
To conduct data analysis, and for sending marketing material/information |
|
Remark: For data analysis, we may rely on either legitimate interest or consent, depending on the purpose of each analysis. |
To comply with applicable laws
We may be required to process your personal data to comply with laws, regulations, orders, notifications, or other rules issued by authorities.
|
The categories of personal data being processed for this purpose would depend on a case-by-case basis, according to the applicable laws, regulations or orders.
Remark: If you do not provide any personal data that is necessary for compliance with the law or order, which is applicable to us, we and/or you may be unable to comply with the laws, and that may affect the necessary processing of your personal data as well as may result in the violation of such applicable law or order.
|
Legal Obligation
|
To establish, exercise, comply or defend legal claims
Your personal data may be processed as part of the establishment, exercising, compliance or defense of legal claims. |
The categories of personal data being processed for this purpose would depend on a case-by-case basis. |
|
Cookies
Your personal data may be processed in order to enhance your experience of visiting and using our Platform, to make the visit of our Platform more attractive, and to enable the use of certain functions, we use so-called “Cookies” on various pages.
For more information of the Cookies we use, please refer to Section 6. Cookies below. |
|
Remark: You can change your preference at any time on the Platform. |
In the case where we will process your personal data for purposes other than those prescribed in this Privacy Policy, we will inform you about such additional processing of personal data and/or arrange to obtain your consent as may be required by applicable laws or regulations.
5. Cookies
Please note that Cookies are small text files that are stored on your device. Below is the information about your choices as well as a detailed list of Cookies we use:
We use cookies to, for example, provide services to you on web browsers, display website content correctly, enable our website to function, allow the exchange of information and communication between your web browser and our web server, and between the website and you, as a website user, and to remember your visits to our website through a web browser.
It is necessary for the Company to use cookies, as described above, in order to provide you with services through our website. These cookies, which are used for the purpose of providing services through website, are used immediately when you access Company’s website through a web browser.
You may block cookies in your browser settings, by declining either all cookies or only some types of cookies. However, please note that if you block all cookies, which include cookies that are necessary for the functioning of our website, you may be unable to access our website, in whole or in part.
Whenever you wish to withdraw your consent to the use of cookies, you may set your browser so that it deletes cookies from each of the web browsers that you use.
Google Analytics and Advertising
We use Google Analytics to better understand how users interact with the Platform. For information on Google Analytics’ information handling practices and how you can control the use of information sent to Google, please visit: www.google.com/policies/privacy/partners/. To disable Google Analytics, please download and install the Google Analytics Opt-out Browser Add-On, which is available here: https://tools.google.com/dlpage/gaoptout/.
We may also utilize certain forms of display advertising and other advanced features through Google Analytics, such as Remarketing with Google Analytics, Google Display Network Impression Reporting, the DoubleClick Campaign Manager Integration, and Google Analytics Demographics and Interest Reporting. These features enable us to use first-party cookies (such as the Google Analytics cookie) and third-party cookies (such as the DoubleClick or Google Dynamic Remarketing advertising cookie) together to inform, optimize, and display advertisements based on your past visits to the Platform. You may control your advertising preferences or opt out of certain Google advertising products by visiting the Google Ads Preferences Manager, currently available at: https://google.com/ads/preferences or by visiting the NAI opt-out tool linked to above.
6. Disclosure of Your Personal Data
In processing your personal data for the above purposes, it may be necessary for us to disclose your personal data to any one or more of the following third parties:
(a) to any of the Company’s affiliates or group companies within or outside Thailand;
(b) to third-party vendors, suppliers or service providers who provide services to us such as, payment service providers, logistics service providers, information technology service providers, auditors, accountants, legal counsels, etc.;
(c) to any competent regulatory, prosecuting, tax or governmental agencies, courts or other tribunals in any jurisdiction;
(d) to any other persons or entities to whom we are required to make disclosure by applicable law, or whom we are permitted by you or your organization to disclose your personal data; and/or
(e) to prospect buyers in case of merger or acquisition of our business.
7. The Cross-Border Transfer of Personal Data
In certain circumstances, the Company may have to transfer, disclose, and give access of your personal data to offshore entities such as to our affiliates and group companies located outside Thailand for processing of personal data for the purposes mentioned in this Privacy Policy. The destination countries may have different data protection standards to those prescribed by the data protection authority in Thailand.
Notwithstanding that, we will ensure that it will protect your personal data by implementing adequate personal data protection standards for the transfer of your personal data outside Thailand, as prescribed under the PDPA.
8. Retention of the Personal Data
(a) Individual Customer: We retain your personal data for as long as is required in order to fulfil our contractual obligations under the agreement with you, and generally for a period not exceeding 10 years thereafter.
(b) Associated Person: We generally retain your personal data for a duration of our contractual relationship with the Corporate Customer whom you are associated with, and generally for a period not exceeding 10 years thereafter.
(c) Visitors and any person who uses the Platform: We may retain your personal data relating to your use of and/or access to our Platform for a period of 90 days, unless otherwise required by applicable law, in order to comply with our legal obligations.
Notwithstanding the above, we may retain your personal data longer than the above period as may otherwise be permitted or prescribed by the applicable laws or regulations.
9. Your Rights to Personal Data
Subject to the conditions and limitations imposed by the PDPA, you have the following rights with respect to your personal data:
(a) To withdraw your consent at any time if the processing of your personal data is based on your consent;
(b) To access or to obtain a copy of your personal data which is under the Company’s possession, and to request to disclose the source(s) of your personal data which has been obtained without your consent;
(c) To request the rectification or completion of your personal data;
(d) In certain circumstances, you may request the deletion, destruction or de-identification of your personal data;
(e) In certain circumstances, you may request to object the processing of your personal data such as when your personal data is processed for direct marketing purposes;
(f) In certain circumstances, you may request to receive your personal data from the Company that arranges your personal data to be in the format which is readable or commonly used by ways of automatic tools or equipment, and can be used or disclosed by automated means, and request the Company to send or transfer your personal data in such formats to other data controllers; and
(g) In certain circumstances, you may request suspension of the use of your personal data.
In addition to the rights above, you also have the right to file a complaint in relation to our processing of your personal data with the Office of the Personal Data Protection Committee. However, we kindly request that you reach out to us first in case of any concerns so that we can effectively address your issue in a timely manner.
10. Contact Details
If you have any inquiries in relation to your personal data, or you would like to exercise any of your rights under the PDPA, you may contact us at:
UPD (Thailand) Limited
989 Siampiwat Tower Building. 12A Floor B1-B2, Room 1225 Rama I Rd. Pathum Wan, Pathum Wan, Bangkok 10330
Email Address: support@paulaschoice.th
11. Changes to this Privacy Policy
We may amend, change, or update this Privacy Policy from time to time, whereby we will update the changes on our Platform, or by sending you a notification to your e-mail or communicated through appropriate channels as deemed appropriate. However, we encourage you to regularly review this Privacy Policy to stay informed about any updates.
In the event that the amendment, change, or update will affect the purposes for which your Personal Data has originally been collected, we will notify you about such changes, and obtain your consent (if required by law), prior to such changes becoming effective.
This Privacy Policy shall take effect from 4 December 2024.