BUSINESS PARTNERS PRIVACY POLICY

MITSUBISHI MOTORS (THAILAND) CO., LTD. AND/OR MMTH ENGINE CO., LTD.

1. OUR PRIVACY STATEMENT

1.1 This business partners privacy policy (“Privacy Policy”) describes how Mitsubishi Motors (Thailand) Co., Ltd. and/or MMTh Engine Co., Ltd. (hereinafter referred to as “MMTh/MEC”, “we”, “our” or “us”) collects, uses, stores, disclose and/or cross-border transfers Personal Data (as defined below) of employees, non-employed workers, personnel, authorized persons, directors, shareholders and other contact persons (“you” or “your”) of our business partners (e.g., our authorized dealers, suppliers, vendors, service providers and outsourcers) (each called a “Business Partner”), along with the information of any third party you have provided to us in order to protect the privacy of your Personal Data.

1.2 This Privacy Policy applies to any online or offline communication channels where we collect your Personal Data, whether face-to-face, showroom, plants, our premises, events, by phone, call center, or online via emails or social media platforms (e.g., webpage, Facebook, Line), and other channels in relation to any of our business operations.

1.3 For the purposes of this Privacy Policy, "Personal Data" means personal data or individually identifiable information as defined by the Applicable Laws, including sensitive data (as defined below).

1.4 MMTh/MEC is committed to ensuring that your privacy is protected and to ensuring that your Personal Data is processed in accordance with applicable laws and regulations (as amended or replaced from time to time) protecting the privacy of Personal Data in the jurisdictions in which we operate and target ("Applicable Laws"). MMTh/MEC will only collect, use, store, disclose and cross-border transfer your Personal Data in accordance to this Privacy Policy.

1.5 Please read the following carefully to understand MMTh/MEC’s views and practices regarding your Personal Data and how we will process it. Certain information about you is necessary or legally required in relation to our existing or potential business relationship. If you do not agree to provide such information, we will not be able to perform our part of obligation to you.

1.6 This Privacy Policy was last updated on August 20, 2020. MMTh/MEC reserves the right, in its sole discretion, to modify, revise, delete and update this Privacy Policy from time to time. MMTh/MEC will use reasonable endeavours to notify you and in appropriate manner of any significant modifications to the terms of this Privacy Policy (e.g. by emailing to you the revised policy with a new effective date [or by publishing the information about such modification on our websites]).

2. PERSONAL DATA THAT WE COLLECT ABOUT YOU

We may collect or obtain the following types of information which may include your Personal Data directly or indirectly from you or other sources or through our parent company, parent company's affiliates, parent company's subsidiaries, affiliates and subsidiaries (“Group”), our authorized dealers, other companies, governmental agencies, or any other publically available source.

The following are example of Personal Data that may be collected:

2.1 Your personal information: This include information about you that you give us by communicating with us, or information we collected from you. Such information may include, but is not limited to:

(a) Identification Information, such as, title, first name, family name, nick name, gender, age, date of birth, nationality, marital status, photograph, work-related information (e.g., position, type of products and services, company you work for, employed at or holds shares of), copies or your national identification card, passport, house registration, work permits or other similar government-issued identifiers, signature, CCTV records, vehicle details (e.g., copy of vehicle registration book, license plate number, brand, and color), financial details (e.g. bank account name and number) and other identifiers.

(b) Contact Information, such as telephone number, fax number, postal address, workplace, e-mail address, Line ID and other similar information.

(c) Sensitive Data, such as your religion contained in national identification card, ethnicity contained in identification documents, biometric data (e.g. fingerprint, facial recognition, and iris recognition data), and criminal records;

(d) Geolocation information, such as geolocation of vehicles and/or communication devices and/or electronic devices (including longitude/latitude data, city and street location);

(e) Driving Behaviour, such as speed using in driving and/or break using behaviour; and

(f) Other Information, collected, used, stored disclosed and/or cross-border transferred in connection with the relationship between us and the Business Partner, such as information you give us in contract, forms, surveys or documents.

2.2 Personal information of other persons, such as your emergency contact, references, representative/agents, beneficiary, other drivers, guarantor, witness or counterparty which includes name, e-mail, address and phone/mobile number of such person, and any other information relating to any individual which you have provided to us in any forms.

By providing other person's Personal Data to us, you represent and warrant that you have the authority to do so and to permit us to use such Personal Data in accordance to this Privacy Policy. You are also responsible to provide this Privacy Policy for their acknowledgement and/or obtain consent where applicable or necessary.

Even if certain information under 2. are not Personal Data, however, when combining with other information or the related Personal Data, it could be used to identify you and deemed Personal Data as well. Therefore, we will treat this information with the same standard as the Personal Data. However, when we process anonymized data or in aggregated form which can no longer identify you, this Privacy Policy would not be applicable.

3. WHY WE COLLECT, USE, STORE DISCLOSE AND/OR CROSS-BORDER TRANSFER YOUR PERSONAL DATA AND ON WHAT LEGAL GROUNDS

MMTh/MEC, Group and third party who may be acting on our behalf may collect, use, store, disclose and/or cross-border transfer your Personal Data described above based on (1) your consent; (2) contractual basis, for our initiation or fulfilment of a contract with you; (3) legitimate interest, to be balanced the purpose of our legitimate interests and the legitimate interests of third parties, to be balanced with your own interest and fundamental rights and freedoms in relation to the protection of your Personal Data; (4) our legal obligations to which we are subject; (5) vital interest, preventing or suppressing a danger to a person's life, body or health; and (6) the reason for an establishment and defences of legal claims in the future, for the following purposes:

3.1 The purpose of which your consent would be required: Activities related to Sensitive Data:

To collect, use, store, disclose, and/or cross-border transfer your sensitive data for the purposes where consent is required by law, which is the following:

  • Religion (contained in the national identification card) such as to authenticate and verify identity of a person;
  • Ethnicity (contained in identification documents) such as to authenticate and verify identity of a person;
  • Biometric data (e.g. fingerprint, facial recognition, and iris recognition data) such as to authenticate and verify identity of a person; and
  • Criminal records for security, safety and protection of our interest or interest of third parties.

Where legal basis is consent, you have the right to withdraw consent pursuant to the conditions provided under this Privacy Policy and applicable law. The withdrawal of consent will not affect the lawfulness of the collection, use and/or disclosure of your Personal Data based on your consent before it was withdrawn.

3.2 The purpose that we may rely on other grounds for processing your Personal Data:

(a) Business Partner selection: To evaluate suitability and qualifications of your and the Business Partner; to facilitate bidding process; to issue request for quotation; and to execute contract with you and the Business Partner;

(b) Business purposes: To contact, initiate, or manage the contractual relationship with the Business Partner; to communicate with you and the Business Partner about products and/or services; to proceed with the transaction made by Business Partner (e.g. delivery, exchange and return of products, invoice and receipt issuance); and to perform any obligations and/or request made by Business Partners;

(c) Relationship management: To create a vendor code; to register in lists/directories of Business Partner; to provide support services and keep tracks and records; to grant you building access card and parking card; and to invite the Business Partner to participate in events/activities;

(d) Registration and authentication: To register, verify, identify, and authenticate you or your identity;

(e) Marketing communication: To inform you of information relating to marketing communication, activities, sales, public relation, notices, news, promotions, special offers, product display, procurement and support, special activities, and direct marketing;

(f) Business operation: To comply with our internal record keeping requirements, internal management, auditing, reporting, submissions or filing, data processing, or other related or similar activities;

(g) Security: To ensure security, risk prevention and solving conflicts; to record and handling on disputes; to proceed on crime or fraud prevention; and

(h) Compliance of legal obligation: To process your Personal Data in accordance to legal obligation, right or duty under the applicable laws, including laws outside your country of residence; to assess compliance with applicable laws, rule, regulations, and internal policies and procedures; to comply with investigational purposes, as requested by governmental officials.

4. DISCLOSURE OF YOUR PERSONAL DATA TO THIRD PARTIES

4.1 We may share your Personal Data within the MMTh/MEC network for the purposes described above. We will take steps to ensure that access to Personal Data is restricted to MMTh/MEC employees and/or representatives on a need-to-know basis.

4.2 We may also share your Personal Data outside of MMTh/MEC network with the following parties, for the purposes set out in this Privacy Policy:

(a) Group: Parent companies, subsidiary companies, affiliates. As MMTh/MEC is part of a Group which all collaborate and partially share Business Partner services and systems including website-related services and systems, we may need to transfer your Personal Data to, or otherwise allow access to such Personal Data by other companies within our Group for the purposes set out in this Privacy Policy. This will allow other companies within our Group to rely on consent obtained by MMTh/MEC.

(b) Business Partners: We may transfer your Personal Data to our other Business Partners to conduct business and services, provided that the receiving Business Partner agrees to treat your Personal Data in manner consistent with this Privacy Policy.

(c) Authorized dealers and sale representative agencies. From time to time, MMTh/MEC will share Personal Data to our authorized dealers that you choose, or located near you, to serve you with our services;

(d) Service providers/ Suppliers/ Sub-contractors. We may use other companies, agents or contractors to perform services on our behalf or to assist with the business relationship with you. We may share your Personal Data to our service providers or third-party suppliers including, but not limited to (1) IT system service providers and IT support company; (2) analytics and research service providers; (3) companies who provide statistical analysis services; (4) survey agencies; (5) marketing, advertising media, designer, creative, and communications agencies; (6) campaign, event, and market organizers; (7) outsourced administrative service providers; (8) data storage and cloud service providers; and (9) similar third-party vendors and other outsourced service providers that assist us in carrying out business activities;

(e) External advisors. This includes lawyers, technicians, tax consultants and auditors who assist in running our business, and defending or bringing any legal claims;

(f) Third parties required by law. In certain circumstances, we may be required to disclose or share your Personal Data in order to comply with a legal or regulatory obligations. This includes any law enforcement agency (e.g., Department of Land Transport, Revenue Department, Office of the Consumer Protection Board), court, regulator, government authority or other third party where we believe it is necessary to comply with a legal or regulatory obligation, or otherwise to protect our rights, the rights of any third party or individuals’ personal safety, or to detect, prevent, or otherwise address fraud, security, or safety issues;

(g) Hospitals and emergency rescue. Your Personal Data may be disclosed in case of emergency for the protection of your own interest;

(h) Assignee of rights and/or obligations. Third parties as our assignee, in the event of any reorganization, merger, business transfer, whether in whole or in part, sale, purchase, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock or similar transaction; will comply with this Privacy Policy to respect your Personal Data; and

(i) Other publicly available sources, such as website, advertisement and/or social media platforms.

4.3 To the fullest extent permitted by law, MMTh/MEC excludes all liability arising from the use of your information by third parties. So, please view the privacy notices of these third parties to understand how they will use your Personal Data.

4.4 Except as set out in this Privacy Policy, we will not disclose, sell, distribute, rent or lease your Personal Data to third parties unless we have your permission or to complete a transaction for you.

5. INTERNATIONAL TRANSFER OF PERSONAL DATA

5.1 MMTh/MEC operates a global business and may transfer the Personal Data collected from you to our oversea related entities, Group, and franchisees in order to provide our services for the purposes set out above. It may also be necessary for us to disclose your Personal Data to third parties located overseas in connection with the purposes set out in this Privacy Policy. The countries to where we may transfer your Personal Data include but not limited to US, Japan and Singapore. Such disclosure or transfer may only be done by obtaining your consent, unless there are any other compelling legitimate grounds (e.g. to perform the contract terms between us and other persons for your benefit) or other cross-border mechanism as permitted by applicable laws for us to conduct without obtaining your consent.

5.2 Please be aware that those overseas countries, that from the standpoint of the data protection supervisory authority in Thailand, may not have an ‘adequate standard of protection’ as specified by the data protection supervisory authority in Thailand, although our collection, storage, disclosure and use of your Personal Data will continue to be governed by this Privacy Policy. If your Personal Data is transferred to destination countries where the standard of protection available is not sufficient under the Applicable Laws, we will take steps necessary to protect the Personal Data transferred to other persons internationally to reach the same level of protection as we provide with respect to your Personal Data, and in compliance with the Applicable Laws which is in effect at that time.

6. HOW LONG DO WE KEEP YOUR PERSONAL DATA

MMTh/MEC will only retain your Personal Data for as long as reasonably necessary to fulfil our duties to achieve the purposes prescribed in this Privacy Policy. If a judicial or disciplinary action is initiated, your Personal Data may be stored until the end of such action, including any potential period for appeal, and will then be deleted or archived as permitted by Applicable Laws.

7. SECURITY

MMTh/MEC has in place security measures to store all Personal Data collected and received securely. We use appropriate technical, organizational, administrative and physical security measures to protect your Personal Data contained in our system against the unauthorized or unlawful loss, access to, use, alteration, correction, accidental damage, and deletion of Personal Data. We will also review such measures when it is necessary, or when the technology has changed in order to efficiently maintain the appropriate security and safety. Once MMTh/MEC has received your Personal Data, we will use strict procedure and security features to try to prevent unauthorized access.

8. YOUR RIGHTS AS A DATA SUBJECT

Under some circumstances, we may require you to prove your identity before complying with data subject exercise of rights, for your own privacy and security.

Subject to Applicable Laws and exceptions thereof, you may have the following rights to:

(a) Access: You may have the right to access or request a copy of the Personal Data we are collecting, using and disclosing about you. For your own privacy and security, we may require you to prove your identity before providing the requested information to you.

(b) Rectification: You may have the right to request for rectification of the incomplete, inaccurate, misleading, or not up-to-date Personal Data that we collect, use, store, disclose and/or cross-border transfer.

(c) Data Portability: You may have the right to obtain Personal Data we hold about you, in a structured, electronic format, and to send or transfer such data to another data controller, where this is (a) Personal Data which you have provided to us, and (b) if we are processing such data on the basis of your consent or to perform a contract with you.

(d) Objection: You may have the right to object to certain collection, use and disclosure of your Personal Data.

(e) Restriction: You may have the right to restrict the use of your Personal Data in certain circumstances.

(f) Withdraw Consent: For the purposes, you have consented to our collecting, using and disclosing of your Personal Data, you have the right to withdraw your consent.

(g) Deletion: You may have the right to request that we delete or de-identity Personal Data that we collect, use and disclose about you, except we are not obligated to do so if we need to retain such data in order to comply with a legal obligation or to establish, exercise, or defend legal claims.

(h) Lodge a complaint: You may have the right to lodge a complaint to the competent authority where you believe our collection, use and disclosure of your Personal Data is unlawful or noncompliant with Applicable Laws.

9. Channels and period for exercising rights of data subject

Rights

Channels for data subject to exercise its rights

Period for fulfilling data subject’s right request

Access

Our responsible person with your transaction

30 days

Rectification

Our responsible person with your transaction

7 days

Data Portability

Our responsible person with your transaction

30 days

Objection

Our responsible person with your transaction

30 days

Restriction

Our responsible person with your transaction

30 days

Withdraw Consent

Our responsible person with your transaction

7 days

Deletion

Our responsible person with your transaction

30 days

10. OUR CONTACT DETAILS

If you wish to exercise your rights above, or if you have queries, comments and/or questions about your Personal Data under this Privacy Policy, please contact us at:

10.1 MMTh/MEC responsible person with your transaction

For MMTh/MEC

Address:
  • FYI Center: 2525 FYI Centre, Floor 9, Rama IV, Khlong Toei Sub-District, Khlong Toei District, Bangkok, 10110 Thailand
  • Laem Chabang: 199 Moo 3, Sukhumvit Road, Tungsukhla Sub-District, Sriracha District, Chonburi 20230
Contact Details:

Phone Number

  • FYI Center: 0-2079-9000

(Available every day except National Holiday from 8:30 to 17:00)

  • Laem Chabang: 0-3849-8000

(Available every day except National Holiday from 8:30 to 17:00)

10.2 Data Protection Officer (DPO)

Contact Details:
  • Address: 2525 FYI Centre, Floor 9, Rama IV, Khlong Toei Sub-District, Khlong Toei District, Bangkok, 10110 Thailand
  • Email address: dpo.mmth@th.mitsubishi-motors.com