Information Security and Data Privacy

Information Security and Data Privacy Policy

Pro Inside Public Company Limited places great emphasis on fostering development by integrating information technology and cyber solutions into daily life, enhancing the efficiency and effectiveness of its products and services, and optimizing internal workflows. This spans from internal and external communication infrastructure to data collection and aggregation across the entire business supply chain, aimed at improving service quality across pre-sales, post-sales, and maintenance stages. To establish informational security within its network systems, the Company has initially implemented a secure system access and authentication framework. Employees are provisioned with user accounts to access the Company’s systems and services, with access rights granted based on authorized levels and the principle of business necessity.

Furthermore, the Company has enacted an Information Technology Security Policy (IT Security Policy) to ensure that executives, full-time employees, contract staff, interns, and business partners are fully aware of secure IT and cyber practices. This policy serves as a guideline for appropriate data utilization, system access, and IT infrastructure maintenance, ensuring strict compliance with applicable laws and security regulations. Additionally, the Company has adopted international IT service quality standards as a foundational framework for its information technology and cyber security management operations.

Document Information Technology Security Policy

  • Personal Data Protection Policy

Pro Inside Public Company Limited respects and prioritizes the privacy rights and personal data protection of all associated individuals and stakeholders. Accordingly, this Personal Data Protection Policy has been established to ensure the Company’s transparency and accountability in the collection, use, or disclosure (collectively referred to as “processing”) of your personal data, in strict accordance with the Personal Data Protection Act B.E. 2562 (2019) (“Personal Data Protection Law”) and other applicable legislations. Furthermore, the Company has implemented appropriate data security measures that meet regulatory standards.

This policy applies to the personal data of individuals who currently have, or may have in the future, a relationship with the Company. This includes the personal data of personnel, employees, customers, suppliers, business partners, and other stakeholders processed by the Company, as well as contractual parties or third parties who process personal data for or on behalf of the Company (“Personal Data Processors”). In addition, the Company has instituted robust data security measures aligned with recognized standards to instill confidence among all stakeholders that the personal data of the Company’s personnel, customers, suppliers, and business partners is highly secure, protected, and fully compliant with the law.

This policy establishes the following core principles and operational scopes:

  1. Policy Framework and Principles: This policy outlines the core principles and essential operational guidelines for the Company’s personal data protection, ensuring that all operations strictly align with the Company’s duties and responsibilities as a Data Controller under the Personal Data Protection Act B.E. 2562 (2019) and other related laws.
  2. Scope of Application: This policy applies to all personal data processing activities conducted within the scope and objectives of the Company. This includes processing carried out by external individuals or juristic persons, as well as via external devices or systems under the aforementioned scope and objectives.
  3. Exclusions: This policy does not cover the personal data processing activities of the Company’s personnel conducted solely for personal benefit or household activities, which are unrelated to the Company’s scope and business objectives.
  4. Implementation and References: Compliance with this policy must be executed in accordance with the detailed guidelines, policies, or consultations to be issued hereafter under this policy, including other corporate announcements or regulations concerning information technology management. Detailed operational guidelines and definitions shall refer to the Thailand Data Protection Guidelines 3.0 (TDPG 3.0) and other supplementary guidelines adopted by the Company.

 

Personal Data Protection Policy Document