Customer Privacy Policy 

SleepHappy Co., Ltd. prioritizes the protection of your personal data. This privacy policy explains our practices regarding the collection, use, and disclosure of personal data, as well as the rights of data subjects under data protection laws.

 

Collection of personal data

We will collect personal information directly from you through the following channels:

  • Subscription
  • telephone
  • Email
  • Facebook Login
  • Google Login
  • LINE Login
  • Twitter Login
  • LinkedIn Login

We may collect your personal information that we have access to from other sources, such as search engines, social media, government agencies, other third parties, etc.

 

Types of personal data collected.

Personal information such as name, surname, age, date of birth, nationality, national identification number, passport number, etc.

Contact information such as address, phone number, email, etc.

Account information, such as username, browsing history, etc.

Proof of identity , such as a copy of an identity card or a copy of a passport, etc.

Transaction and financial information, such as purchase history, credit card details, bank accounts, etc.

Technical information such as IP address, Cookie ID, website usage history (Activity Log), etc.

Other information, such as images, videos, and any other data considered personal information under the Personal Data Protection Act.

We will collect, use, or disclose the following sensitive personal information only when we have your explicit consent, unless required by law.

  • ethnicity
  • race
  • political opinions
  • Belief in a cult
  • Religion or philosophy
  • Criminal record
  • Health information
  • Disability
  • Labor union information.
  • Sexual behavior
  • genetic information
  • Biometric data, such as facial recognition data, iris data, and fingerprint data.

Any other information that affects your personal data as specified by the Personal Data Protection Committee.

 

minor

If you are under 20 years of age or have legal limitations, we may collect, use, or disclose your personal information. We may require your parental or guardian's consent or, as permitted by law, do so. If we become aware that personal information has been collected from a minor without parental or guardian consent, we will take steps to delete that information from our servers.

 

Methods for storing personal data.

We will store your personal information in both document and electronic formats.

We store your personal information as follows:

  • Our company's server in Thailand.

 

Processing of personal data

We will collect, use, or disclose your personal information for the following purposes:

  • To create and manage user accounts.
  • To deliver goods or services.
  • To improve products, services, or user experience.
  • For internal company management purposes.
  • For marketing and sales promotion.
  • For after-sales service.
  • To gather feedback.
  • To pay for goods or services.
  • To comply with the Terms and Conditions.
  • To comply with laws and regulations of government agencies.


Disclosure of personal information

We may disclose your personal information to others with your consent or where permitted by law, as follows:

Internal organizational management

We may disclose your personal information within the company only as necessary to improve and develop our products or services. We may collect internal information for various products or services under this policy for your benefit and the benefit of others.

Service provider

We may disclose some of your personal information to our service providers as necessary to carry out various tasks such as payments, marketing, product or service development, etc. Each service provider has their own privacy policy.

Business partners

We may disclose certain information to business partners for the purpose of communication and coordination in providing goods or services, and to provide only necessary information regarding the availability of goods or services.

Business transfer

We may disclose information, including your personal information, for organizational restructuring, mergers or sales, or other asset transfers. The receiving party must treat your information in a manner consistent with this policy and any applicable privacy laws.

Law enforcement

In cases where requested by law or a government agency, we will disclose your personal information only as necessary to that agency, such as courts or other government bodies.

Transferring personal data abroad.

We may disclose or transfer your personal data to individuals, organizations, or servers located abroad. We will take measures to ensure that the transfer of your personal data to the destination country meets adequate data protection standards, or as otherwise required by law.


Personal data retention period.

We will retain your personal data for the period necessary during your time as a customer or in a relationship with us, or for the period necessary to achieve the purposes relating to this policy, which may require further retention if required by law. We will delete, destroy, or anonymize your data when it is no longer needed or when such retention period expires.


Rights of data subjects

Under the Personal Data Protection Act, you have the right to take the following actions:

Right to withdraw consent: If you have given your consent, we will collect, use, or disclose your personal information, whether your consent was given before or after the Personal Data Protection Act came into effect. You have the right to withdraw your consent at any time.

Right to access: You have the right to request access to your personal data that we hold in custody and to ask us to provide you with a copy of such data, as well as to ask us to disclose how we obtained your personal data.

Right to data portability: You have the right to receive your personal data if we have made it available in a format that can be read or used by automated tools or devices, and if the personal data can be used or disclosed automatically. You also have the right to request that we send or transfer your personal data in such a format to another data controller when it is possible to do so automatically, and you have the right to receive the personal data that we send or transfer in such a format directly to another data controller, unless this is not possible due to technical reasons.

Right to object: You have the right to object to the collection, use, or disclosure of your personal data at any time, provided that the collection, use, or disclosure of your personal data is done for the purpose of carrying out operations that are necessary in our legitimate interests or the interests of other individuals or entities, and does not exceed the limits that you can reasonably expect, or to carry out tasks for the public interest.

Right to Erasure/Destruction: You have the right to request the deletion or destruction of your personal data , or to anonymize your personal data, if you believe your personal data was collected, used, or disclosed unlawfully under applicable laws, or if you believe we no longer need to retain it for the purposes outlined in this policy, or if you have exercised your right to withdraw consent or your right to object as stated above.

Right to restriction of data processing: You have the right to request a temporary suspension of the use of your personal data in cases where we are investigating your request to correct your personal data, or your objection, or in any other case where we no longer need and must delete or destroy your personal data according to applicable law, but you request us to suspend its use instead.

Right to rectification: You have the right to request corrections to your personal data to ensure it is accurate, up-to-date, complete, and does not cause misunderstanding.

Right to lodge a complaint: You have the right to lodge a complaint with the relevant legal authority if you believe that the collection, use, or disclosure of your personal data is in violation of or non-compliance with applicable laws.

You can exercise your rights as a data subject as described above by contacting our Data Protection Officer using the details at the end of this policy. We will inform you of the outcome within 30 days of receiving your request to exercise your rights, using the form or method we specify. If we reject your request, we will notify you of the reasons for the rejection through various channels such as SMS, email, telephone, or letter.

 

Advertising and marketing

To better serve your needs, we use your data to analyze and improve our products or services, and to market them through Google, Facebook, pixel tracking codes, and more. We use this data to tailor products or services to you.

Our website may display advertisements from third parties to facilitate our services, such as Google AdSense and BuySellAds. These third parties may access your personal information only to perform these tasks and are obligated not to disclose or use it for any other purpose.

We may send information or newsletters to your email address with the purpose of offering you something of interest. If you no longer wish to receive communications from us via email, you can click "Unsubscribe" in the email link or contact us via email.


Personal tracking technology (COOKIES)

To enhance your user experience and make it more efficient, we use cookies or similar technologies to improve product and service accessibility, relevant advertising, and track your usage. We use cookies to identify and track website users and their access to our site. If you do not want cookies stored on your computer, you can configure your browser to reject cookies before using our website.


Maintaining the security of personal data.

We will maintain the security of your personal data in accordance with the principles of confidentiality, integrity, and availability, to prevent loss, unauthorized access, use, alteration, modification, or disclosure. Furthermore, we will implement security measures encompassing administrative, technical, and physical safeguards regarding access control for your personal data.


Reporting a privacy violation.

In the event of a breach of your personal data, we will notify the Personal Data Protection Commission without delay, within 72 hours of becoming aware of the incident, to the best of our ability. If the breach poses a high risk of impacting your rights and freedoms, we will inform you of the breach and provide remedies without delay through various channels such as our website, SMS, email, telephone, or letter.


Amendments to the privacy policy.

We may revise this policy from time to time. You can find the revised terms and conditions on our website.

This policy was last revised and is in effect from May 25, 2022.


Privacy policies of other websites.

This privacy policy applies only to the offering of products, services, and website usage for our customers. If you visit other websites, even through our website, the protection of your personal data will be in accordance with that website's privacy policy, in which we are not involved.

 

Contact details

If you would like to inquire about this privacy policy, including exercising your rights, you can contact us or our Data Protection Officer as follows:

 

Data controller

Sleep Happy Company Limited
193/141, 35th Floor, Lake Ratchada Office Complex, Ratchadaphisek Road, Khlong Toei Subdistrict, Khlong Toei District, Bangkok.

 

Data Protection Officer

Sleep Happy Company Limited
193/141, 35th Floor, Lake Ratchada Office Complex, Ratchadaphisek Road, Khlong Toei Subdistrict, Khlong Toei District, Bangkok.