Privacy-Policy
Privacy Policy for Website and Application Use
This Privacy Policy, hereinafter referred to as the “Policy”, was first effective on
May 2024 and contains the following details:
Section 1 Definitions
In this Policy
(a) “Website and Application” means the website and application
named Mr. Melon’s: Magic Mansion (Melon phonics) and has the website address at mrmelonmagicmansion.com
(b) “Data Controller” means the service provider or owner of the website and application under this Policy, namely, Carroll Prep Co., Ltd., legal entity registration number 0105563134171, office located at 105/1 Bon Marche, Thetsaban Songkhro Road, Lat Yao, Chatuchak, Bangkok 10240 Contact support@carrollprep.ac.th
(c) “Data Processor” means an external person who processes data for the benefit of or on behalf of the data controller.
(d) “Information” means anything that conveys meaning to a story, fact, information or anything, whether such communication is possible by the nature of the thing itself or through any other means, and whether it is prepared in the form of a document, file, report, book, diagram, map, drawing, photograph, film, video or audio recording, recorded by a computer, by electronic means or any other means that makes the recorded thing visible.
(e) “Personal Data” means any information about a natural person that enables the identification of that person directly or indirectly.
(f) “Sensitive Personal Data” means personal data of the user regarding race, ethnicity, political opinions, religious or philosophical beliefs, sexual behavior, criminal history, health information, disability, genetics, biometric data, facial, iris or fingerprint image data, trade union data. Or any other information that the Personal Data Protection Committee has announced under the Personal Data Protection Act has announced as sensitive personal data.
(c) “User” means you, visitors, users, members of the website and application, who are the owners of personal data under this policy.
Section 2 User consent
In using the website and application, the user agrees and gives consent to the collection and use of personal data, including sending or transferring personal data abroad, as follows:
(a) Purpose of collecting and using personal data, including sending or transferring personal data abroad
The user acknowledges, agrees, and consents to the data controller and data processor to collect and use personal data for the following purposes only:
Public relations and marketing, providing social media services, and billing for services
(b) Personal data collected and used, including sending or transferring personal data abroad. The user acknowledges, agrees and consents to the data controller and data processor to collect and use personal data, including sending or transferring personal data abroad, as follows only:
Name, surname, address, date of birth, telephone number, age, education, work history, ethnicity, and email
(c) Period of data collection
The user acknowledges, agrees and consents to the data controller and data processor to collect and use personal data, including sending or transferring personal data abroad for a total period of 60 (sixty) months from the date of consent to collect and use personal data, including sending or transferring personal data abroad in accordance with this policy.
Section 3 Linking data of website and application users with third-party service providers
The user acknowledges, agrees and consents to the data controller to link the data of website and application users with third-party service providers. In linking or sharing data with third-party service providers each time, the data controller will inform the user which data of the user will be linked or shared with the third-party service provider. However, when the user has clearly expressed his intention to allow such linking or sharing, including but not limited to pressing to accept, allow, link, share or any action Which is clearly stated that the user has consented to link or share information with the third-party service provider.
Section 4 Tracking the user’s website and application usage behavior
The user acknowledges, consents and agrees that the data controller may use the following systems and/or technologies to track the user’s website and application usage behavior:
Cookies technology, use of Pixel Tags and Google Analytics Tag
For the purposes specified herein only:
To develop services and present products that meet the needs of the user.
Section 5 Withdrawal of user consent
The user acknowledges that the user has the right to withdraw any consent that the user has given to the data controller under this policy at any time by taking the following actions:
Notify in writing to email support@carrollprep.ac.th or select “Do not consent” when registering or setting personal data.
The user also acknowledges that when the user withdraws consent, the user will be affected as follows:
The user will be limited to accessing special content, including logging into the study, and will only be able to view the website as a general person.
The user also agrees to accept all consequences of such withdrawal of consent.
Article 6 User Account
In using the website and application, the data controller may provide each user’s user account for the use of the website and application, where the data controller has the sole right to approve the opening of the user account, determine the type of user account, determine the access rights to data for each type of user account, the right to use the website and application, any expenses related to the user account, the duties and responsibilities of the user who owns the user account.
The user agrees to keep the user account name, password, and any information strictly confidential and agrees not to consent to, including using the best effort to prevent other persons from using the user’s user account.
In the event that the user’s user account is used by another person, the user agrees and warrants that such use by such other person is done as the user’s agent and is binding as if the user had done it himself.
Article 7 User’s Rights
By accessing the Website and Applications in accordance with this Policy and by providing any consent under this Policy, the User is fully aware of his/her rights as a data subject under the Personal Data Protection Act, including but not limited to the following rights of the User:
(a) The User may withdraw the consent given under this Policy at any time by notifying the Data Controller in writing in the manner and channels specified in this Policy.
(b) The User has the right to access and request a copy of his/her personal data or that related to him/her that the Data Controller has collected in accordance with this Policy.
(c) The User has the right to obtain disclosure from the Data Controller of the acquisition of his/her personal data or that related to him/her that he/she has not given consent to, if such a case occurs.
(d) The User may allow the Data Controller to send or transfer his/her personal data or that related to him/her to another data controller, including requesting such information sent or transferred directly from the Data Controller who sent or transferred such data.
(e) The User may object to the collection, use or disclosure of his/her personal data or that related to him/her. In the following cases:
(1) The data controller collects, uses or discloses the user’s personal data in a manner necessary for the legitimate interests of the data controller or another person in which the user may prove that he has a better right than the data controller;
(2) The data controller collects, uses or discloses the user’s personal data in order to comply with the data controller’s legal obligations in which the user may prove that he has a better right than the data controller;
(3) The data controller collects, uses or discloses the user’s personal data in a manner necessary for the legitimate interests of the data controller or another person in which the user may prove that he has a better right than the data controller
Use or disclose such personal data for direct marketing purposes
(4) The data controller collects, uses or discloses such personal data for scientific, historical or statistical research purposes where such research is not necessary for the public interest.
(f) The user may request the data controller to erase, destroy or anonymize the data in the following cases:
(1) When the personal data is no longer necessary for the purpose for which it was collected, used or disclosed.
(2) When the user, who is the owner of the personal data, withdraws his or her consent to the collection, use or disclosure of such personal data and the data controller no longer has any other legal authority to collect, use or disclose such personal data.
(3) When the user has lawfully objected to the collection, use or disclosure of such data.
(4) When personal data has been collected, used or disclosed unlawfully under laws, rules, regulations or regulations on the protection of personal data.
(g) The user may request the data controller to suspend the use of such personal data while still retaining it. In the following cases:
(1) The data controller is under investigation by a committee of experts under the Personal Data Protection Act, to which the user has filed a complaint;
(2) Personal data has been collected, used or disclosed unlawfully under the law, rules, regulations or regulations on the protection of personal data;
(3) In the event that the user needs the data controller to keep his/her personal data for the benefit of the user’s own claims, including the establishment of legal claims by the user, the compliance with or exercise of legal claims, or the defense of legal claims. Users may request the data controller to simply suspend the use of the data instead of deleting, destroying or anonymizing the data owner.
(4) The data controller is in the process of verifying or investigating to reject the objection to the collection, use or disclosure of the user’s personal data under the personal data protection law, which the user has lawfully objected to.
(h) When the user finds that the user’s personal data is incorrect, outdated or unclear, the user has the right to request the data controller to correct such personal data to be correct, current, complete and not misleading.
(i) The user may file a complaint with the committee of experts under the personal data protection law in the case of an action that violates or fails to comply with the law, rules, regulations, or regulations on personal data protection of the data controller and/or data processor.
Section 8 Security
In the collection and use of personal data in accordance with this policy The data controller shall provide appropriate security measures to prevent the loss, access, use, alteration, modification or disclosure of data that is not in accordance with the law, through the following measures, standards, technologies and/or systems:
Determining data access rights (Access Right), data encryption (Encryption) and firewalls systems
Including controlling the data processor to maintain the security of personal data no less than that specified in this policy
Section 9 Amendment of personal data
The data controller shall provide the following systems and inspection measures:
(a) Carry out the process of amending personal data to be correct, up-to-date, complete and not misleading
(b) Delete or destroy personal data that exceeds the collection period that the user has consented to, and
(c) Delete or destroy personal data that is not related to the use of such personal data as the user has consented to
Section 10 Collection, use and/or disclosure of personal data in accordance with the Personal Data Protection Law
The user acknowledges and agrees that the data controller may collect, use and/or disclose the user’s data without prior consent from the user, only as necessary and as long as it is in accordance with the purposes and in the following cases:
(a) To achieve the purposes related to the preparation of historical documents or archives for public benefit or in connection with research or statistics for which appropriate safeguards have been put in place to protect the rights and freedoms of the personal data of the user; (b) to prevent or suppress harm to the life, body or health of any person; (c) it is necessary for the performance of a contract to which the user who owns the personal data is a party or to take action at the request of the user who owns the personal data prior to entering into such contract; (d) it is necessary for the performance of duties carried out in the public interest of the data controller or in the exercise of public authority vested in the data controller; (e) it is necessary for the legitimate interests of the data controller or of another person whose interests are more important than the fundamental rights of the user in the personal data; (f) it is necessary for the compliance with the law of the data controller; the data controller shall record the collection, use or disclosure of the personal data of the user in accordance with the preceding paragraph as a matter of importance.
Article 11 Collection, use and/or disclosure of sensitive personal data
The user acknowledges and agrees that in addition to the collection, use and/or disclosure of personal data for which the user has expressly consented to the collection, use and/or disclosure of personal data in the previous paragraph, the data controller may collect, use and/or disclose sensitive personal data of the user without prior consent from the user, only to the extent necessary and in accordance with the purposes and in the following cases:
(a) To prevent or suppress danger to the life, body or health of the user who owns the personal data who is unable to give consent for whatever reason.
(b) It is information that is disclosed to the public with the express consent of the user who owns the personal data.
(c) It is necessary for the establishment, compliance, exercise or defense of legal claims.
(d) It is necessary to comply with the law to achieve the purposes related to:
(1) Preventive or occupational medicine, assessment of employee work ability, medical diagnosis, provision of health or social services, medical treatment, health management or social welfare system and services.
(2) Public benefits in the area of public health, such as health protection from dangerous communicable diseases or epidemics that may be transmitted or spread into the Kingdom. Or control of the standard or quality of drugs, medical supplies or medical devices, which have provided appropriate and specific measures to protect the rights and freedoms of the users who own the personal data, especially the confidentiality of personal data according to the duties or ethics of the profession.
(3) Labor protection, social security, national health insurance, welfare for medical treatment of those who are entitled by law, protection of victims of road accidents or social protection, where the collection of the user’s personal data is necessary to comply with the rights or duties of the data controller or the user who owns the data, by providing appropriate measures to protect the fundamental rights and benefits of the user who owns the personal data.
(4) Scientific, historical or statistical research or other public interests, by collecting, using and/or disclosing only as necessary and providing appropriate measures to protect the fundamental rights and benefits of the user who owns the personal data as determined by the Personal Data Protection Committee.
(5) Significant public interests, by providing appropriate measures to protect the fundamental rights and benefits of the user who owns the personal data.
The data controller shall record the collection, use or disclosure of the user’s personal data according to the previous paragraph as important.
Section 12 Use of websites and applications of persons under the custody, guardianship or supervision of the user
The User certifies that he/she is not and will not allow any person who is a person with disabilities under the law to visit, use or become a member of the Website and Application:
(a) A person with disabilities who is under the care of the User
(b) A person with a quasi-incapacity who is under the protection of the User
In the event that the User allows the above-mentioned person to visit, use or become a member of the Website and Application, the User agrees that the User shall be deemed to have exercised the parental, guardianship or custody power of such person, as the case may be, in agreeing and giving consent to this Policy for and on behalf of such person.
Section 13 Sending or transferring personal data abroad
The data controller may send or transfer the user’s personal data abroad in the following cases:
(a) The destination country or international organization receiving the personal data has adequate personal data protection standards as required by laws, rules, regulations and regulations on personal data protection.
(b) The consent of the owner of the personal data has been obtained. Where the data subject has been informed and made aware of the inadequate personal data protection standards of the destination country or international organization receiving the data; (c) in compliance with the law; (d) necessary for the performance of a contract to which the data subject is a party or for taking action at the request of the data subject prior to entering into such contract; (e) in compliance with a contract between the data controller and another person for the benefit of the data subject; (f) to prevent or suppress a danger to the life, body or health of the data subject or any other person when the data subject is unable to give consent at that time; (g) necessary for the performance of a mission for important public interest; Article 14 Notification of Personal Data Breach Incidents; Where the data controller becomes aware of a personal data breach regardless of who has committed the breach, the data controller shall take the following actions:
(a) In the event of a risk of affecting the rights or freedoms of any person, the data controller shall notify the Personal Data Protection Committee of such personal data breach without delay, as far as is practicable within 72 (seventy-two) hours from becoming aware of the incident;
(b) In the event of a risk of a high level of affecting the rights or freedoms of any person The Data Controller shall notify the Personal Data Protection Commission and the personal data owner of such personal data of any such breach and its remedy as soon as practicable within 72 (seventy-two) hours from becoming aware of the incident.
Article 15 Complaints and Reporting of Personal Data Problems
Users may complain and report problems regarding personal data, including but not limited to requesting the data controller to correct and update the data to be current and/or correct, objecting to the collection of data, or suspending the use of data, through the following channels:
support@carrollprep.ac.th
Article 16 Recording of Important Records
Unless the Personal Data Protection Act stipulates the rights of the data controller otherwise, the data controller shall record important records regarding the collection, use, or disclosure of data in writing or electronic systems for inspection by the data owner or government agencies, including but not limited to the following:
(a) Personal data collected
(b) Purpose of collection of each type of personal data
(c) Information about the data controller
(d) Period of retention of personal data
(e) Rights and methods of access to personal data, including conditions regarding persons with the right to access personal data and conditions for access to such personal data
(f) Collection, use, or disclosure of personal data that is exempt from the consent of the data owner
(g) Rejection of requests and various objections
(h) Details of personal data security measures
Article 17 Policy Amendments
The Data Controller may amend and change the text of this Policy at any time, in whole or in part, and the Data Controller will notify the User of each change so that the User can consider and accept it electronically or otherwise, and if the User has accepted it, the amended Policy shall be deemed to be part of this Policy.
In addition, the User may access the latest amended and changed Privacy Policy from the sources displayed by the Data Controller through the following channels:
https://www.mrmelonmagicmansion.com/privacy-policy/
Article 18 Relationship of the Contracting Parties
Both Contracting Parties understand and are aware that entering into this Policy does not cause the Contracting Parties and their employees to have a relationship as employees under the labor law or as partners under the partnership and company law.
Article 19 Assignment
Unless otherwise expressly provided in this Policy The parties agree not to transfer any rights, duties and/or liabilities under this Policy to any person without the prior written consent of the other party.
Section 20 Waiver
No failure or delay by the Data Controller to exercise or to exercise any right or any part of it shall be deemed a waiver of such right, and no partial exercise or waiver by the Data Controller of any right or any part of it shall be deemed a waiver of any other right or any part thereof.
Section 21 Severability
If any provision of this Policy is held to be invalid, invalid or unenforceable for any reason whatsoever, the parties agree that the other provisions of this Policy shall remain valid and binding on the parties as if such invalid, invalid or unenforceable part were not contained in this Policy.
Section 22 Applicable Law
This Policy shall be governed by the laws of Thailand.
Section 23 Dispute Resolution
In the event of any dispute or controversy arising out of this Policy, if the parties are unable to reach an agreement, the parties agree to sue such dispute in the courts of Thailand.