Data Privacy Policy
§ 01Introduction
To keep its management aligned with good governance, Ruk-Com Co., Ltd. recognises the importance of data protection and respects the rights attached to personal data. Privacy is a fundamental right protected under the Constitution of the Kingdom of Thailand and the Personal Data Protection Act B.E. 2562. The company therefore publishes this policy as its framework for protecting personal data.
Ruk-Com Co., Ltd. operates the websites https://ruk-com.co.th/, https://hostings.ruk-com.in.th/, https://help.ruk-com.in.th/, https://ruk-com.cloud/ and https://docs.ruk-com.cloud/ (together, “the company’s websites”), as well as the company’s other social media channels. Personal data here means the information collected when you register through the company’s websites, cookies, transaction data and usage experience.
This policy is governed by the Personal Data Protection Act B.E. 2562. The company decides how personal data is collected, used or disclosed, which the law calls the “data controller”. Employees assigned by the company to collect, use or disclose personal data under its instructions or on its behalf are, in legal terms, “data processors”, while you are the “data subject”.
§ 02Scope of application
This notice is the company’s standard of practice. It applies to the board, directors, executives and employees at every level in their dealings with internal personnel and external parties, including partners, service providers and stakeholders. It also applies to every company activity involving personal data — the channels used to collect data, the types and formats of data stored, the purposes for which the company uses personal data, how that data is shared with the company and others, and how the company protects and secures personal data under the Personal Data Protection Act B.E. 2562.
§ 03Collection of personal data
Collecting personal data requires the data subject’s consent as provided by law, except where the law allows collection to the extent necessary. For purposes directly related to the reason for collection, the company informs the data subject before or at the time of collection of the following details required by law:
- 3.1 The purpose of collecting the personal data for use or disclosure.
- 3.2 Compliance with the law or a contract, or entering into a contract — including notifying the data subject of the possible impact of not providing the data.
- 3.3 The personal data to be collected and the retention period.
- 3.4 The categories of people or organisations to whom the collected personal data may be disclosed.
- 3.5 Information about the data controller.
- 3.6 The rights of the data subject.
- 3.7 Any other details required by law.
In addition, the company collects personal data that can identify you directly or indirectly, namely:
- Identifying personal data such as name, surname, taxpayer identification number and a copy of the national ID card. Copies of ID cards are collected, used and/or disclosed only where necessary — for example as supporting documents for .th domain registration, identity verification or job applications.
- Contact details such as residential address, phone number and email.
- Work details such as company name, company address and the company’s taxpayer identification number.
- Transaction data such as payment method, transfer slips and transactions relating to orders and/or use of the company’s products and services.
- Device or tool data such as IP address, MAC address, cookie ID, computer traffic data, browser type and language, location (country), operating system, internet provider, pages visited, visit date/time and the website that referred you to us.
The company collects personal data for the following activities:
| Activity group | Personal data involved | Legal basis |
|---|---|---|
| Recruitment and employment | Name and surname, national ID number, date of birth, education certificates, military service documents, medical certificate, bank account number, employment history, criminal record | Contract / consent |
| Employee finance processes / payroll | Name and surname, national ID number, bank account number, taxpayer identification number | Contract / legitimate interest |
| Employee welfare and protection / insurance and health checks | Name and surname, national ID number, date of birth, address, phone number, company email | Contract / legitimate interest / legal obligation |
| Tax filing | Name and surname, national ID number, taxpayer identification number, address | Contract / legal obligation |
| Social security filing | Name and surname, national ID number, taxpayer identification number, address | Contract / legal obligation |
| Signing up for Ruk-Com services | Name and surname, email, phone number, address, copy of ID card (only in certain cases, such as .th domain registration with THNIC or certain domain types) | Contract / consent |
| Customer support, service monitoring and reporting | Name and surname, email, phone number, address, copy of ID card (only in certain cases, such as identity verification for refunds or for changes you cannot make yourself, issuing withholding tax documents, or affiliate requests) | Contract / consent |
| Contracts with business partners | Name and surname, national ID number, address | Contract |
§ 04Use or disclosure of personal data
Personal data is used or disclosed in line with the purposes notified to the data subject, in line with the consent given, or where necessary for purposes directly related to the collection purposes stated in this policy. Where use or disclosure relies on consent, the company may request that consent beforehand or at the time — except in the following cases, where consent is not required:
- 4.1 To prevent or stop danger to a person’s life, body or health.
- 4.2 Where the data is lawfully public.
- 4.3 Where necessary to establish, comply with, exercise or defend legal claims.
- 4.4 Where required by law or by court order.
- 4.5 In any other case provided by law.
Purposes for collecting, using and/or disclosing personal data
The company collects and may process your personal data for your benefit in using our products and services, to comply with any law that the company and/or you must observe, and for any other purpose stated in this policy, namely:
- To let you use the company’s products and services as intended under your contract with us, or to act on your request before you use them.
- To fix and improve website performance, prepare marketing plans, analyse usage data, evaluate service quality and develop the company’s products and services.
- To comply with applicable law — for example following the orders of authorities, or complying with laws that the company and/or you must observe.
- For operations necessary under the company’s legitimate interest, within what you can reasonably expect — for example call centre voice recording, maintaining customer relationships and handling complaints, anonymising data, and preventing, responding to and reducing risks from fraud and cyber threats.
- To give you the benefits you consented to receive from our products and services — for example better services matched to your needs, offers, special privileges, recommendations and news.
- To process and carry out marketing, improving how offers, special privileges, product and service information, recommendations and company news reach audiences whose interests and/or behaviour are similar to yours.
- For other purposes notified when your personal data was collected, or other purposes related to any of the above.
Who the company may disclose your personal data to
The company may disclose your personal data to others with your consent or under the conditions the law permits, such as:
- Authorised company employees and/or third parties with whom the company has a contract or relationship.
- Parties authorised to act as the company’s agents in selling our products and services, including their subcontractors.
- Other parties, including their agents and subcontractors, involved in the company’s products and services, marketing activities, payment collection, document preparation, technology systems, document delivery and research.
- Government agencies, regulators or any party to whom the company must disclose data under laws, regulations or orders relating to the company, or under an agreement the company has with a government agency.
§ 05Quality of personal data
The company must give importance to the accuracy, completeness and currency of the data it stores, and must allow data subjects to have their personal data corrected and kept up to date. Personal data collected must therefore be accurate, current, complete and not misleading, unless the law provides otherwise.
§ 06Security measures for personal data
The company recognises the importance of personal data security and maintains appropriate measures to prevent loss, unauthorised access, destruction, use, alteration, amendment or unlawful disclosure of personal data, using both technical and organisational measures.
The company has defined policies, rules and criteria for protecting personal data, for example:
- Restricting access rights to personal data both offline and online.
- Securing data to current IT security standards — for example firewalls, virus scanning, encryption in transit via Secure Sockets Layer (SSL), encryption of sensitive data such as passwords, and automatic log-off.
- Putting measures in place so that recipients of data from the company do not use or disclose it beyond the intended purpose, or without authority or lawfully.
- Reviewing those policies, rules and criteria periodically as necessary and appropriate.
In addition, where personal data is sent or transferred abroad — including storing personal data on any other system whose transfer or storage provider is located overseas — the destination country must have personal data protection measures equivalent to or better than those in this policy.
The company is not liable for damage arising from the use or disclosure of personal data to third parties, including neglect or failure to log out of the company’s databases or social media systems, caused by the data subject or by another person acting with the data subject’s consent.
§ 07Rights of the data subject
The rights in this clause are legal rights you should know about. You can exercise them under the law and under the policy in force now or as amended in future, together with the criteria the company sets. If you are under 20 years of age or your legal capacity is restricted, your request can be made by your parents, guardian or authorised representative.
- Right of access: you may request access to the personal data the company holds about you, ask for a copy, and ask the company to disclose how it obtained your personal data.
- Right to rectification: you may ask to have your personal data corrected so that it is accurate, current, complete and not misleading.
- Right to withdraw consent: if you consented to the company collecting, using and/or disclosing your personal data (whether before or after the data protection law took effect), you may withdraw that consent at any time while the company holds your data, unless the right is restricted by law or a contract that benefits you. Withdrawing consent may affect your use of products and services — for example you may no longer receive privileges, promotions or new offers, better services matched to your needs, or useful news. For your own benefit, please check the impact before withdrawing consent.
- Right to data portability: you may request your personal data where the company holds it in a machine-readable format that can be used or disclosed automatically. You may also ask the company to send or transfer that data to another data controller where technically feasible, and to receive personal data the company has sent or transferred directly to another controller, unless technical constraints prevent it.
- Right to object: you may object at any time to the collection, use and/or disclosure of your personal data where it is carried out under the legitimate interest of the company or of another person or legal entity within what you can reasonably expect, or for a public-interest mission. You may also object to collection, use and/or disclosure for marketing purposes or for scientific, historical or statistical research.
- Right to erasure: you may ask for your personal data to be deleted or destroyed, or anonymised, if you believe it was collected, used and/or disclosed unlawfully, if you consider the company no longer needs to keep it for the purposes in this policy, or once you have withdrawn consent or exercised your right to object as described above.
- Right to restriction: you may ask the company to suspend use of your personal data temporarily while it reviews your rectification or objection request, or in any other case where the company no longer needs the data and would have to delete or destroy it under the law but you ask for restriction instead.
- Right to complain: you may complain to the competent authority if you believe your personal data is being collected, used and/or disclosed in breach of applicable law. These rights may be limited by law, and in some cases the company may have to refuse or be unable to act on your request — for example to comply with the law or a court order, for public interest, or because exercising the right would infringe the rights or freedoms of others. If the company refuses a request, it explains the reason for the refusal.
Channels for exercising your rights
| Right | Channel | Processing time* |
|---|---|---|
| Right to withdraw consent | 7 days | |
| Right of access | 30 days | |
| Right to data portability | 30 days | |
| Right to object | 30 days | |
| Right to erasure | 30 days | |
| Right to restriction | 30 days | |
| Right to rectification | Website | Immediate |
§ 08Retention period
The company keeps your personal data for as long as necessary while you are a customer or have a relationship with the company, or for as long as needed to fulfil the purposes in this policy. It may have to be kept after that where the law requires or permits — for example retention under the Computer Crime Act B.E. 2550.
The company deletes or destroys personal data, or renders it unable to identify you, once it is no longer needed or the retention period ends.
§ 09Third-party websites and services
The company may link to other websites and services for your convenience and information, such as payment through external providers. These services and websites may operate independently of the company and may publish and follow their own privacy policies, so we strongly recommend reviewing them before using those services or doing anything on those sites. To the extent the company does not own or control a linked website you visit, we are not responsible for its content, privacy practices or service quality.
§ 10Cookies
The company’s websites, applications, email messages and advertisements use “cookies” and similar technologies such as Google Analytics to help you use the website smoothly and to help the company understand user behaviour better — for example remembering your settings or telling the company which parts of the site people visit. Cookies also add convenience and help measure the effectiveness of advertising and on-site search.
Cookies are text files containing small amounts of information that are stored on your device when you visit the platform. They are sent back to their origin on each visit, or to other websites that recognise them.
You may set your cookie consent at any time on the company’s website, or through the browser you use. You may configure your browser to refuse cookies. However, some services on the company’s website require cookies, so disabling them may prevent some or all functions from working smoothly.
The types of cookies the company may use are:
| Cookie type | Description | Status |
|---|---|---|
| Essential | These cookies are strictly necessary to provide services through the company’s website or platform — for example storing your session ID when you log in, or supporting security operations. | Always on |
| Performance | These cookies improve the performance and functionality of the website or platform but are not essential to use it — for example remembering your username. Without them, some functions may not work. | Configurable |
| Analytics | These cookies collect usage behaviour so the company can understand how our website or platform is used and how marketing campaigns perform, helping us improve the website, platform, products and services for you. | Configurable |
Examples of the cookies the company uses
Entries labelled System describe purpose categories, not literal browser cookie names.
| Cookie / purpose category | Description | Retention | Type |
|---|---|---|---|
| System session | The most widely used cookie on PHP-based websites. It stores a unique session ID per visitor and keeps no personal data in the user’s browser. | Until the browser closes | Essential |
| System affiliate tracking | System sets this cookie when a customer arrives through the affiliate system, storing the referrer ID so credit is given if the customer orders within 90 days. | 1 day | Essential |
| System remember me | Used by System for the “remember me” function in the client area. It is set when the user asks the system to remember their details. | 365 days or until log-out | Essential |
| RUKCOMCOOKIES | A cookie supporting the operation of the company’s website. | 30 days | Essential |
| _ga | A Google Analytics cookie used to count visitors and sessions, record campaign data and track website usage, storing the data anonymously. | 2 years | Analytics |
| _gid | A Google Analytics cookie that records how visitors use the website in order to produce analytics reports. | 1 day | Analytics |
| _gat | A Google Universal Analytics cookie used to throttle the request rate, limiting data collection on high-traffic websites. | 1 minute | Performance |
| __cfduid | A Cloudflare cookie used to identify malicious visitors and reduce the blocking of legitimate users, supporting Cloudflare security features. | 30 days | Essential |
You may set your cookie consent at any time on the company’s website, or through your browser. You may configure your browser to refuse cookies — see the browser developer’s website for instructions:
- Google Chrome
- Safari
- Mozilla Firefox
- Microsoft Edge
§ 11Our role as data processor
Besides acting as the “data controller” for the customer data used to register and manage accounts, the company acts as a “data processor” for the personal data of third parties that customers store or process on our systems. In that role we process data only on the customer’s instructions and for the purposes of providing the service, and we do not use it for other purposes — in particular advertising or marketing — unless the customer consents or the law requires it. Detailed conditions follow the company’s Data Processing Agreement (DPA). Data locations by type and by the company’s role are as follows:
- (1) Account and service usage data that the company holds as “data controller” (such as name, address, email, phone number and payment data) is stored in data centres in Thailand.
- (2) Data that customers store or process on their own services, where the company acts as “processor”, is stored in the data centre of the region the customer selects — Thailand or Singapore. The customer determines and acknowledges the data location according to the region chosen.
- (3) The services involved in our role as data processor are listed in the table below.
| Ruk-Com service | Personal data involved |
|---|---|
| Web Hosting / WordPress Hosting / Cloud Hosting | Data in websites and databases such as user accounts, contact forms and customer records |
| Cloud VPS / IaaS / PaaS | Web server, mail server, database server, PII in the customer’s databases, and databases (MySQL, PostgreSQL, MongoDB and others) containing PII |
| Business email services | Email content and contact lists |
| Backup systems | Copies of PII from the services above (90 days of backup history) |
| Managed service | Staff may access systems containing PII while delivering the service |
Where data must be transferred to or stored in a data centre abroad, the company puts in place adequate protection measures as required by law and discloses the destination country on request.
§ 12Sub-processors
The company may disclose or pass on your personal data to the following people or organisations, only as necessary for the purposes notified and under appropriate data protection measures:
- External providers acting as data processors on the company’s behalf, such as Microsoft (Microsoft 365) and Google (Google Workspace). These processors process your personal data only on the company’s instructions under their terms of service, and do not use it for their own purposes — in particular marketing or advertising.
- The list of sub-processors is shown in the table below.
| No. | Sub-processor (legal entity) | Service / product | Purpose |
|---|---|---|---|
| 1 | Microsoft Corporation | Microsoft 365 — Exchange Online (email), Teams, SharePoint, OneDrive | Storing and processing email, documents and organisational collaboration data |
| 2 | Google LLC | Google Workspace — Gmail, Drive, Docs, Meet, Calendar | Storing and processing email, documents and organisational collaboration data |
§ 13Customer data ownership
All data and content customers upload to or store on the company’s systems remains the customer’s property. The company claims no ownership of it and accesses it only as necessary to provide the service, maintain the system or comply with the law. At the end of the service, customers may request the return of their data within the defined period, after which the company securely deletes it from our systems.
§ 14Data breach notification
If a personal data breach occurs that poses a risk to the rights and freedoms of data subjects, the company notifies the Office of the Personal Data Protection Committee without delay and, where feasible, within 72 hours of becoming aware of it, and notifies data subjects where the risk is high, in line with section 37(4) of the Personal Data Protection Act B.E. 2562. As a processor, the company notifies the customer (the data controller) without delay once a breach is found, so that the customer can meet its own legal duties in time.
§ 15Contact channels
If you have suggestions, or want to ask about how your personal data is collected, used and/or disclosed — including exercising your rights under this policy — you can contact the Data Protection Officer through the following channels:
| Unit | Data Protection Unit, Ruk-Com Co., Ltd. |
|---|---|
| Address | Vanit Place Ari (Building A), Unit 2703, 27th Floor, 304 Phaholyothin Rd., Samsen Nai, Phaya Thai, Bangkok 10400, Thailand |
| [email protected] |
§ 16Liability and penalties
The company requires employees and units involved with personal data to take responsibility for collecting, using or disclosing personal data strictly in line with this policy and its practice guidelines.
Accordingly, anyone responsible for a given task who neglects or omits to instruct or act, or who instructs or acts in a way that breaches the policies and practices on personal data, and thereby causes an offence under the law and/or damage, is subject to disciplinary penalties under the regulations of their employing organisation.
§ 17Updates to this policy
The company reserves the right to amend all or part of this personal data protection policy so that its content remains appropriate and consistent with the Act and/or subordinate legislation, regulations and newly issued government announcements. If this policy is amended, the company publishes the change on its website as quickly as possible so that it stays current and consistent with the new rules.