Apart from the above purposes, we will not use your personal data for other purposes unless permitted by the PDPA, for example:
5. Disclosure or Sharing of Personal Data
We do not disclose your personal data to third parties except where permitted by law and necessary for operations. We may disclose data in the following cases:
5.1) To government agencies, competent authorities, or any person as required or authorized by law, including to comply with court orders.
5.2) To persons or juristic persons where necessary to perform a contract or for your benefit as a data subject. Such parties are required to keep your data confidential and protect it in accordance with the PDPA. These may include:
We require all external recipients to protect your data under PDPA standards and to use it only for the agreed purposes, to prevent unlawful disclosure or use beyond what has been agreed.
5.3) Cloud computing: We may store personal data in third-party cloud systems located in Thailand or overseas. We enter into contracts with such providers with due care and with appropriate security safeguards for personal data.
6. Retention Period
6.1) We retain your personal data for as long as necessary to fulfill the service purposes and for periods required by accounting, legal, and other applicable regulations.
6.2) In determining retention, we consider the volume and nature of the data, purposes of processing, sensitivity, risks of unauthorized use or disclosure, and statutory requirements.
6.3) Where necessary to comply with the law, court orders, or to establish/exercise/defend legal claims, we may retain data for the statutory limitation period or until the relevant dispute is finally resolved.
7. Security Measures
7.1) We apply security measures no less than those required by law, including appropriate systems to protect personal data—e.g., SSL, firewalls, passwords, encryption for data transmitted over the internet, and restricted physical access for paper records.
7.2) We restrict access to personal data to authorized employees, agents, partners, or external parties on a need-to-know basis; such parties must maintain confidentiality and protect the data.
7.3) We deploy technological measures to prevent unauthorized system access.
7.4) We maintain procedures and controls for the destruction of personal data that is no longer necessary.
7.5) For Sensitive Personal Data, we implement enhanced electronic security, access control, backup/continuity plans, emergency procedures, and regular risk assessments.
8. Your Rights as a Data Subject
Subject to the PDPA, you may request that we:
8.1) Withdraw consent for processing your personal data at any time (without affecting processing already carried out lawfully).
8.2) Access your personal data and obtain a copy, including disclosure of the source of data not obtained directly from you.
8.3) Rectify inaccurate or incomplete personal data.
8.4) Erase your personal data in certain circumstances.
8.5) Restrict the processing of your personal data in certain circumstances.
8.6) Data portability—receive your personal data in a structured, commonly used format and transmit it to another controller where applicable.
8.7) Object to certain processing activities.
Data Protection Officer (DPO)
Email: info@innotechlab.co.th
Innotech Laboratory Service Co., Ltd.
No. 697 Srinagarindra Rd., Phatthanakan,
Suan Luang, Bangkok 10250, Thailand
Tel: 0 2320 5132–5
9. Changes to this Policy
We may review and amend this Policy in the future to enhance personal data protection. We will notify you on our website whenever changes are made.
10. Contact
For any questions or to exercise your rights, please contact:
Email: info@innotechlab.co.th
Innotech Laboratory Service Co., Ltd.
No. 697 Srinagarindra Rd., Phatthanakan,
Suan Luang, Bangkok 10250, Thailand
Tel: 0 2320 5132–5