Privacy Policy

Privacy Policy

Pachara Clinic We recognize the importance of protecting your personal data and are committed to safeguarding the privacy of all our clients. This Privacy Policy outlines the types of information we collect and how your personal data is handled—including its collection, storage, use, disclosure, and your related rights. To ensure transparency regarding our privacy standards, we hereby announce the following Privacy Policy:

General Information

This Personal Data Protection Policy is established to clarify details and guidelines for collecting, storing, using, and disclosing personal data correctly, appropriately, and securely. Its purpose is to protect the rights of data subjects—including customers, service users, employees, or other stakeholders—who provide personal data directly to the Company or through the Company’s information technology systems, and to ensure compliance with the Personal Data Protection Act B.E. 2562 (PDPA).

What Are Cookies?

Cookies are small computer data files (text files) installed or saved onto your computer or electronic device when you visit a website. Cookies remember information regarding your website usage. In this policy, other technologies performing similar functions are also referred to as cookies.

Respect for Privacy Rights

Pachara Clinic Pachara Clinic respects and values individual data privacy rights and recognizes that data subjects desire security when using our services. Personal data received by the Company—such as name, age, address, and phone number, which can identify an individual—will be accurate, complete, up-to-date, and used strictly in accordance with the Company’s operational objectives. We enforce rigorous security measures to prevent unauthorized use of personal data. In the event of a personal data breach, the Company will notify affected data subjects immediately.

Collection of Personal Data

We collect personal data including contact information such as first name, last name, phone number, address, email, and other information provided in forms and supporting documents. We collect this data for our legitimate business operational purposes and to enhance business efficiency, gathering only data that is strictly necessary, including for:

  • Business operations and service provision
  • Research, analysis, and statistical reporting
  • Service development and marketing
  • Operational efficiency improvement
  • Handling complaints and feedback
  • Client communication and coordination
  • Statutory compliance

If there are any changes to the purpose of data collection, the Company will inform data subjects promptly. Personal data collection is conducted only upon receiving explicit consent from data subjects or stakeholders. To ensure smooth business operations or fulfill contractual duties to clients, the Company may disclose personal data to third-party service providers, agents, subsidiaries, or affiliated companies located within or outside Thailand for the stated purposes. Furthermore, the Company may disclose personal data to government authorities or official bodies to comply with applicable laws, regulations, or legal systems. Third parties receiving data are required to maintain strict confidentiality and security, and are prohibited from using the data for purposes other than those specified by the Company. Examples of third parties include:

  • Data entry service providers
  • Expert consultants, advisors, and/or external auditors
  • Third-party service providers (e.g., administrative or operational support such as telecommunications, IT, logistics, shipping, assembly, printing, postal services, or marketing and promotional activities)
  • Relevant government officials or agencies
  • Third parties operating with the Company have the right to use your personal data solely to fulfill obligations defined in contracts made with the Company. These contracts enforce compliance with applicable laws and Company policies, requiring appropriate measures to safeguard your personal data.

Third-Party Disclosure

To ensure safe and appropriate personal data management, the Company implements security measures to prevent unauthorized or unlawful loss, access, use, modification, alteration, or disclosure of personal data. If a data breach occurs that causes direct damage to a data subject, the Company will notify the data subject as soon as possible to mitigate damages, investigate the cause, and determine appropriate remedial measures.

Retention Period

Retention Period

Use or Disclosure of Data

  • Data is used strictly for the Company’s stated purposes.
  • Data will not be sold or distributed without prior authorization.
  • Data may be disclosed pursuant to court orders or legal requirements.

Rights of the Data Subject

  • Request access to, correction of, or deletion of personal data.
  • Object to receiving marketing communications.
  • Request data portability to other organizations.

Data Security

The Company maintains robust data protection measures, including data encryption and access control, and will issue immediate notifications in the event of a data breach.

Policy Updates

The Company may update this policy to align with changes in operations, respond to feedback from data subjects, or comply with legal requirements. Any amendments will be clearly announced prior to implementation or communicated directly to data subjects.

Policy Enforcement

Data subjects agree and acknowledge that this Personal Data Protection Policy applies to all personal data collected by the Company. Data subjects authorize the Company to store, use, or disclose previously collected data (if any), currently collected data, and future data to third parties within the scope specified in this policy.