PDPA Rights and Duties Notice
§ 01About this notice
With reference to the Personal Data Protection Act B.E. 2562, Ruk-Com Co., Ltd. (“the company”) attaches importance to complying with the law and to providing material information to its customers. We therefore give notice of the following.
This document applies to every type of company service — Web Hosting, WordPress Hosting, VPS Hosting, Platform as a Service (PaaS) and Infrastructure as a Service (IaaS). Read the service-specific terms for the service you use (see the table in clause 1) together with the general terms in this document. Detailed conditions in the relationship between data controller and data processor follow the company’s Data Processing Agreement (DPA).
§ 02Definitions
| Provider | Ruk-Com Co., Ltd. |
|---|---|
| Customer | A user of the company’s services, whether an individual or a legal entity |
| End customer | A user of the customer’s services (the third-party data subject whose personal data the customer stores) |
| Sub-processor | Another processor appointed by the company to process personal data on its behalf in order to deliver the service |
§ 03The provider
1.1 The company provides the service type the customer selects. The nature of each service is as follows:
| Service | Nature of the service |
|---|---|
| Web Hosting / WordPress Hosting | Hosting the customer’s website on the provider’s servers so that it stays online 24 hours a day. Website files, databases, email and similar data are stored on the web server, which serves website pages to visitors through the domain name at all times. |
| VPS Hosting | A virtual private server that the customer administers themselves, so that the customer’s service stays online 24 hours a day. |
| Platform as a Service (PaaS) | A platform for software and application developers where the provider prepares and maintains the infrastructure, operating system and required resources — such as database servers and web applications — so the customer can focus on developing and managing their own applications and data. |
| Infrastructure as a Service (IaaS) | Compute infrastructure delivered as virtual resources — CPU, memory, storage and networking — where the customer installs and manages the operating system, software and applications entirely themselves. |
1.2 The provider has the duties and responsibilities of a “data processor” under the Personal Data Protection Act B.E. 2562. The company maintains security measures by service type as follows:
| Service | Measures provided |
|---|---|
| Web / WordPress / VPS Hosting | A Web Application Firewall (WAF) whose rules are updated regularly, and vulnerability assessment at least once a week. |
| Platform as a Service (PaaS) | Security of the servers, operating system/platform, network and connectivity. |
| Infrastructure as a Service (IaaS) | Security of the physical infrastructure, virtualization layer and core network. The customer is responsible for security from the operating system upwards. |
1.3 The company cannot access, view and/or know what the customer has uploaded, imported and/or stored on its servers, and cannot view the confidential, business or commercial data or any other data of the customer’s own end customers, because that data is under the customer’s control. The company does not use such data for other purposes — in particular advertising or marketing — unless the customer consents or the law requires it.
§ 04The customer
2.1 The customer has the duties and responsibilities of a “data controller” under the Personal Data Protection Act B.E. 2562, because the customer decides about the personal data brought into the company’s services for storage or processing. It is therefore the customer’s own duty to comply with the Personal Data Protection Act B.E. 2562 and/or other applicable regulations and laws.
2.2 The customer must control their own end customers’ data and is responsible for maintaining appropriate security standards for the nature of their own service, including but not limited to data classification, encryption, access rights management, data risk assessment, appointing data custodians, and authentication to maintain security.
2.3 The customer must send the company the types and list of data they have brought into the service, identifying the data type by the numbers defined in clause 3, certified by the customer’s data controller.
2.4 The customer warrants that collecting personal data and instructing the company to process it under the service rests on a lawful legal basis, and is responsible for the lawfulness of the instructions given to the company for processing.
§ 05Categories of personal data
Category 1
- Name, surname, nickname
- National ID number, passport number, social security number, driving licence number, taxpayer identification number, bank account number, credit card number (including images of ID card copies or other card copies showing personal data)
- Address, email, phone number
Category 2
- Device or tool data such as IP address, MAC address, cookie ID
- Biometric data such as facial images, fingerprints, X-ray films, iris scans, voice identity data and genetic data
- Data identifying a person’s assets, such as vehicle registration and land title deeds
- Data that can be linked to the above, such as date of birth, place of birth, ethnicity, nationality, weight, height, location data, medical data, education data, financial data and employment data
- Reference numbers stored on microfilm
- Performance appraisals or an employer’s opinions on an employee’s work
- Records used to track and audit a person’s activity, such as log files
- Data used to search for other personal data on the internet
Category 3
- Ethnicity and race
- Gender
- Groups, affiliations and demographic groups
- Family, relatives and friends
- Physical characteristics
- Knowledge and beliefs
- Data or references and preferences
- Assets and ownership of assets
- Physical and mental health
- Financial status
- Occupation
- Personal behaviour
- Activities and associations
- Sports and recreation
- Personality
- Membership of groups, clubs and activities
Category 4 — sensitive personal data
- Political opinions
- Cult, religious or philosophical beliefs
- Sexual behaviour
- Criminal records
- Health and disability data such as underlying conditions, vaccinations and medical certificates
- Trade union data
Category 5 — data that is not personal data
- Company registration numbers
- Business contact details that do not identify an individual — for example work phone and fax numbers, office addresses, work email and company email such as [email protected]
- Anonymous data, pseudonymous data and data technically rendered no longer able to identify an individual
- Data about deceased persons
- Data about legal entities
§ 06Information security system
Security and legal compliance are a shared responsibility between the company and the customer, divided as follows:
| Security OF the cloud | Security IN the cloud |
|---|---|
| The provider is responsible for operating, managing and controlling the hosting operating system, the network, the control systems for customers, and the physical security of the data centre. | The customer is responsible for managing their own virtual machines and/or containers, including the operating system running on them (updates and security patches), software and applications, firewall and security configuration, connections to their own IT systems, and compliance with applicable law. |
The scope of responsibility at each layer differs by service type, as shown below (R = provider responsibility, C = customer responsibility):
| Layer | Web / WordPress | VPS | PaaS | IaaS |
|---|---|---|---|---|
| Data and content in the system/database² | C | C | C | C |
| Application | C | C | C | C |
| Runtime / Middleware / Database Engine³ | R | C | R | C |
| Operating system (OS) | R | C¹ | R | C |
| Virtualization | R | R | R | R |
| Network | R | R | R | R |
| Physical infrastructure | R | R | R | R |
The security measures the company provides include:
4.1 Web Application Firewall (WAF) — for Web / WordPress / VPS Hosting
A standard system for filtering traffic, monitoring and blocking anomalous HTTP/HTTPS traffic sent to the customer’s web application, and for preventing data leaking out of the application. It works as a reverse proxy so that threatening traffic cannot reach the internal data of the web application server.
4.2 Vulnerability assessment
An initial risk assessment of vulnerabilities found in the operating system, software or network/security devices — identifying which vulnerabilities exist and how severe they are, so they can be fixed and closed.
4.3 Restricting employee access
Access to data is tiered according to each employee’s duties, with confidentiality agreements in place. The personnel involved have a duty of confidentiality that continues after they leave, and receive training so they are aware of their duty to protect personal data.
4.4 The information security team
The company has staff holding the ICDL Personal Data Protection certificate from the International Computer Driving Licence, referenced to European Union standards, namely:
- Data Protection Officer (DPO) — the officer who oversees and protects all personal data in the organisation, both internal and external, with duties from preparing, controlling, auditing, collecting and storing data under the law to coordinating with the Personal Data Protection Committee when issues arise.
- Data Processor — the officer who processes personal data solely under the instructions of, or on behalf of, the data controller.
4.5 Standards and management framework
The company’s technical and organisational measures align with an Information Security Management System (ISMS) and a Privacy Information Management System (PIMS), referencing ISO/IEC 27001 and ISO/IEC 27017 / 27018 / 27701. These cover at least access control and authentication (including multi-factor authentication for privileged access), encryption in transit and at rest as appropriate, segregation of each customer’s data in shared environments, logging and monitoring, vulnerability and patch management, backup and recovery, and business continuity management. The company reviews and improves these measures periodically so they remain appropriate to changing risks.
§ 07Processing on the customer’s instructions
5.1 The company processes the personal data the customer brings into the service only on the customer’s written instructions (including instructions set out in the service contract and the data processing agreement) and only for the purposes of providing the service, unless required by law — in which case the company informs the customer beforehand unless the law prohibits such notice.
5.2 The company does not process personal data for its own purposes and does not use it for marketing or advertising, unless instructed or explicitly consented to by the customer, or required by law.
5.3 If the company considers that an instruction from the customer may conflict with data protection law, it informs the customer without delay and may suspend that instruction until it receives written confirmation or a corrected instruction. Responsibility for the lawfulness of the instruction remains with the customer as data controller.
§ 08Sub-processors
6.1 To deliver the service, the company may appoint sub-processors to process personal data on its behalf. The company contracts with sub-processors in writing, imposing data protection duties equivalent to its own, and remains liable to the customer for the acts or omissions of its sub-processors as if they were its own.
6.2 The list of approved sub-processors at present is:
| No. | Sub-processor | Service / product | Data location | Certifications / transfer mechanism |
|---|---|---|---|---|
| 1 | Microsoft Corporation (EEA: Microsoft Ireland Operations Ltd) | Microsoft 365 — email / files / collaboration | Global / region selectable | ISO 27001/27017/27018/27701; SOC 1/2/3; SCCs in the DPA |
| 2 | Google LLC (EEA: Google Ireland Ltd) | Google Workspace — email / files / collaboration | Global / data regions US, EU | ISO 27001/27017/27018/27701; SOC 2/3; SCCs in the DPA |
| 3 | Ruk-Com Co., Ltd. | Cloud Hosting / Email / VPS (as actually used) | Thailand / Singapore | ISO 27001; DPA |
6.3 Where the company wishes to add or change a sub-processor, it notifies the customer at least 30 (thirty) days in advance. The customer may object to the change on reasonable data protection grounds by giving written notice within 14 (fourteen) days of being notified. If the parties cannot reach a resolution, the customer may suspend or terminate the affected part of the service under the conditions of the service contract.
§ 09Assistance with rights and DPIAs
7.1 If a data subject (the customer’s own end customer) submits a rights request directly to the company, the company forwards it to the customer without delay and does not respond to it itself, unless instructed by the customer or required by law.
7.2 The company provides the customer with reasonable assistance through appropriate technical and organisational measures so the customer can meet data subject rights requests (such as access, rectification, erasure, objection and portability) within the time limits set by law.
7.3 The company provides the customer with reasonable assistance in preparing Data Protection Impact Assessments (DPIAs) and in consulting the Office of the Personal Data Protection Committee, taking into account the nature of the processing and the information available to the company.
§ 10Data breach notification
8.1 When the company becomes aware of a personal data breach involving the customer’s data, the company as data processor notifies the customer (the data controller) without delay and no later than 48 (forty-eight) hours after becoming aware, so that the customer can notify the Office of the Personal Data Protection Committee within 72 hours under section 37(4) of the Personal Data Protection Act B.E. 2562.
8.2 The notification includes the necessary information known to the company — for example the nature of the incident, the approximate categories and volume of data and data subjects, the possible impact, and the measures taken or proposed. The company cooperates with the customer in investigating and remediating the incident.
§ 11Cross-border transfers
9.1 Personal data may be stored or processed in data centres in Thailand and abroad (for example Singapore), according to the region the customer chooses to use. The customer determines and acknowledges the location of that data.
9.2 Where data is stored or processed abroad, the company puts in place appropriate protection measures under section 28 of the Personal Data Protection Act B.E. 2562 — for example Standard Contractual Clauses (SCCs) or another legally recognised mechanism — and discloses the destination country on request.
§ 12Audit and demonstrating compliance
10.1 The company provides the information reasonably necessary to demonstrate compliance with its data processor duties — for example standards certifications or assessment reports from independent assessors.
10.2 The customer may audit the company’s compliance no more than once a year, with at least 30 days’ written notice, subject to confidentiality, during business hours, and without affecting the data or systems of the company’s other customers — unless a significant breach occurs or the law provides otherwise.
10.3 The company prepares and maintains records of the personal data processing activities carried out on the customer’s behalf, and makes them accessible to the customer on reasonable request.
§ 13Return and deletion of data
11.1 All data and content the customer uploads to or stores on the company’s systems remains the customer’s property. The company claims no ownership of it and accesses it only as necessary to provide the service, maintain the system or comply with the law.
11.2 At the end of the service, the company returns or deletes and destroys the personal data, including copies, on the customer’s instructions within 30 (thirty) days, unless the law requires continued retention. On request, the company issues written confirmation that the data has been destroyed.
§ 14Penalties
Breaching or failing to comply with the Personal Data Protection Act B.E. 2562 carries criminal, civil and administrative penalties as provided by law. Each party agrees to bear the administrative fines or liability arising from its own actions.
§ 15Contact and submitting your data list
If you have questions or want to ask for more information, contact us by email at [email protected] between 9:00 and 18:00.
You may notify and update the data categories under clauses 2.3 and 3 yourself through the company’s portal at https://portal.ruk-com.cloud/ or by email to [email protected] within 30 days of receiving this document. If you do not do so within that period, the company treats the categories of personal data brought into the service as not yet specified and protects the data under its standard measures as far as it is aware. Responsibility for the accuracy and completeness of the data categories rests with the customer as data controller. This does not affect either party’s duties and responsibilities under the law.