KWI Life Insurance Public Company Limited (‘KWI’ or “We”) cares about your privacy and is fully committed to protect your personal data.
This Privacy Policy covers how we deal with your personal data and gives you detailed information on how, what, when, and why we collect, use, disclose, transfer or process your personal data, what steps we take to ensure your personal data stays private and secure, how long we retain your personal data, how you can contact us, and your rights under the Personal Data Protection Act B.E. 2562 (‘PDPA’).
Please take a moment to read our Privacy Policy to understand more about your rights to the personal data that you have given to or have with us. This Privacy Policy is subject to change at any time; so, you should come back and read this Privacy Policy from time to time. If there is any significant change to our Privacy Policy which may affect the rights to your personal data, we will inform you without delay.
Your personal data means any information relating to you that can identify you, whether directly or indirectly, from that data alone or in a combination with other identifiers we possess or can reasonably access, except information about the deceased. The types of personal data we collect will depend on the scope of services and/or type of products that you are interested in or that we provide to you.
Depending on the type of products or services you select or your relationship with us, we may collect and hold the following personal data:
In addition, we may also collect and hold your sensitive data such as:
If you do not or are unable or decline to provide certain personal data or to consent us to collect, use or disclose certain personal data which is necessary for us to make a relationship with you or provide our services and/or products to you, we may not be able to stay in contact with you, enter into a contract with you or perform our obligations resulting from a contract entered with you. In some cases, where we have legal obligations to collect, use or disclose certain personal data and you do not or are unable or decline to provide certain personal data to us, we may be liable for failure to comply with the legal obligations under the applicable laws.
We only collect, use, disclose or process your personal data by fair and lawful means to the extent necessary for the specific purposes. We have also set out some lawful reasons why we may process your personal data. These depend on what kind of personal data we are processing.
We normally process personal data which is required or allowed by any law that applies (legal compliance), to provide the services/products set out in a contract (contracts), if it is necessary to prevent danger to a person’s life, body and health (vital interests), if it is in our legitimate interests (legitimate interest) or we have your permission (consent).
For more information about this and the reasons we may need to process your personal data, please see below.
We will rely on the purpose of legal compliance in which the processing of your personal data is necessary for compliance with a legal obligation to which we are subject, for example, relevant insurance laws, anti-money laundering laws, tax laws, securities and exchange laws, and personal data protection laws.
Including collect use and/or disclose your personal data and sensitive personal data to the Office of Insurance Commission (‘OIC’) for the benefit of supervision and promotion of insurance business according to the OIC’s privacy policy which can be viewed at the website www.oic.or.th
We will rely on the purpose of contracts in which the processing of your personal data is necessary for the performance of a contract to which you are a party or in order to take steps at your request before entering into a contract.
We will process your personal data in accordance with the agreement between you and us, and for the following reasons:
We will rely on the purpose of vital interests where the processing of your personal data is necessary to prevent or avoid danger to a person’s life, body, or health.
We may rely on the purpose of legitimate interests pursued by us or by a third party which require us to process your personal data. Considering your interests, rights and freedoms, legitimate interests which allow us to process your personal data include:
Apart from the above lawful bases, we may process your personal data with your consent. We will only ask for your consent if there is no other lawful basis to process your personal data, especially, in the case where our processing activities have potential impact on your sensitive personal data. If we need to ask for your consent, we will make it clear what we are asking for and ask you to confirm your choice to give us that consent. If we cannot provide a product and/or service without your consent to process your personal data, we will make this clear when we ask for your consent.
We may request your consent to process your personal data for the following purposes:
As required by law in certain cases, we cannot collect, use, and/or disclose the Personal Data of minors, quasi-incompetent persons, and incompetent persons in absence of their parental or legal guardian consents. If you are under the age of 20, quasi-incompetent persons, or incompetent persons, please ensure that consent from your legal guardians are obtained when it is required. Where we learn that we have unintentionally collected Personal Data from anyone under the age of 20 without parental consent when it is required, or from quasi-incompetent persons and incompetent persons without their legal guardians, we will delete it immediately or process only if we can rely on other legal bases apart from consent.
We will always notify you, before or at the time of collecting your personal data, about our purposes of processing. However, in some circumstances as specified under the PDPA, it is not necessary for us to inform you about our processing of your personal data, such as when:
We collect your personal data in different ways which include in writing, by electronic or hard copy form, by telephone, email, in person, and over the internet such as via our website, cookies, online forms or social media.
We may collect your personal data directly from you. For example, you provide us with your personal data when you fill in an application form, insurance application form or our request form, communicate with us over the telephone, send us a letter or use our website.
We may also collect your personal data indirectly from publicly available sources of information and/or from other parties including:
If you provide personal data about another individual to us, you agree to:
Generally, this Privacy Policy applies to KWI and all KWI Group members, including all business units, departments, personnel, and third parties that handle personal data with a contractual arrangement with KWI and/or with KWI affiliated entities.
Your personal data may be transferred or disclosed to, accessed by or shared on a need to know basis with the following parties and for the following purposes
We deal with many international organizations and use global information systems. As a result, we transfer your personal data to countries outside Thailand for the purposes set out in this Privacy Policy. Not all countries outside Thailand have data protection laws that are similar to those in Thailand. Where data security standards are deemed inadequate, we will provide appropriate safeguards to protect your interest, or the transfer will take place if one of the exceptions defined by the PDPA is met.
These exceptions are:
You have rights to your personal data, and according to the PDPA these rights include:
If you change your mind about how you would like us to have or process your personal data, you can tell us anytime by following the process under “Exercising your rights” section.
In order to exercise your rights stated above, you may refer to our contact’s details under “How to contact us” stated hereinbelow. If you make a request, we will ask you to confirm your identity (if necessary), and to provide information that helps us to understand your request better. We expect to respond to your request within 30 days of the receipt of your request.
We have full rights and sole discretion to either fulfil or decline your request or charge a reasonable fee to fulfil your request in the case where you have made more than 3 consecutive requests within 10 working days, or in the event that the requests are obviously excessive or unfounded. We are entitled to refuse your request on statutory grounds and we will notify you of the refusal and our grounds.
In the case where we reject your request, we will record the rejection with reasons according to the PDPA.
If you have any questions or would like to exercise any rights relating to your personal data, please contact us via the provided details in the ‘How to contact us’ section.
Your Personal Data will be stored for the period necessary to allow us to fulfil, satisfy or achieve the purposes specified in Part 2 above except where a longer retention period is required or permitted by law or as long as you are our customer and for a period of ten years after the end of the customer relationship, or longer if required by law or to satisfy the purposes specified in Part 2 above. In addition, if you would like to purchase our products or use our services, we will retain your Personal Data for [xx] years from the day on which you have provided your contact information to us or longer. However, the retention period for Personal Data will be in accordance with our internal policy and procedure. In case of legal necessity or achieving the purposes as set out in Part 2 above, there may be specific circumstances where it is necessary for us to retain your Personal Data for longer (such as when a dispute arises).
We will delete, destroy, permanently anonymize, or otherwise dispose of all personal data at the end of the retention period, or when we must comply with your request for erasure of your personal data.
If you have any questions, please contact us at the provided details in the ‘How to contact us’ section.
As part of our products and/or service, we may use your personal data to identify a product and/or service that may benefit you. We may contact you occasionally to let you know about new or existing products or services.
We may also disclose your personal data to our related entities or business partners to enable them to tell you about a product or service. The marketing delivery channels may be through electronic means, email, telephone, text and other forms of communication.
For direct marketing, KWI intends:
If you change your mind about how you would like us to contact you or you no longer wish to receive any of the above information, you can tell us anytime by following the process under “Exercising your rights” section.
To keep your personal data safe and secure, we use a range of measures, which include encryption and other forms of security. We require our employees and third parties who carry out work on our behalf to comply with appropriate privacy standards including obligations to protect against the leakage of information and to apply appropriate security measures for the processing of information.
We maintain and update our security procedures and measures to ensure a level of security for the personal data appropriate to the respective risk and the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing, including to prevent loss and unauthorized collection, access, use, modification, correction or disclosure of personal data. Our security measures apply to all types of data processing regardless of whether the personal data is processed electronically or in paper form.
We certify that all personal data collected will be safely and securely stored with strict security standards. If you have reason to believe that your personal data has been breached or if you have any questions regarding this Privacy Policy, please contact us. See the ‘How to contact us’ section for contact details.
KWI’s website may include hyperlinks to third party websites. KWI has no control over the content, accuracy, expressed opinions, and links provided at these third party websites or how these third party websites deal with your personal data. You should visit these third party websites for details of their privacy policies in relation to their handling of your personal data.
KWI may use ‘cookies’ to improve our internet service. A cookie is a small file of letters and numbers that automatically store on your computer's browser and can be viewed by KWI’s website. Cookies also help KWI’s website to recognize you and your list of favorites or most common use when visiting the website, as well as assisting KWI in customizing the website to suit your need.
The data collected by cookies are customization of anonymous data. Therefore, there are no data concerning your name, address or any data that can enable other parties to contact you via telephone, email address and other forms of contact. There are also no personal data of customers stored in cookies. However, you may block the use of cookies by customizing your browser setting, but blocking our cookies may impact your usage on our website or online services, causing difficulty in entering transaction with us via KWI’s website and taking longer to request additional data.
We reserve the right to change, amend or update the Privacy Policy at any time we deem appropriate. We will notify you of any change, amendment or update on our Corporate Website, which you can check at any time.
If you have any comments, suggestions, questions, complaints or want to exercise your rights regarding your personal data, please contact:
KWI Life Insurance Public Company Limited
43 Thai CC Tower, 33rd Floor,
South Sathorn Road, Yan Nawa,
Sathorn, Bangkok 10120
Tel: 02-033-9000
Kwilife-dataprotection@kwiasia.com
By virtue of Royal Decree Prescribing Organizations and Businesses of which Personal Data Controllers are not Subject to Personal Data Protection Act B.E 2563 postponing the PDPA effective date, you may exercise your rights regarding your personal data from 1 June 2022 onwards.