Privacy Policy
Published and Effective: October 2024
Scope and Purpose
Aion Automobile Sales (Thailand) Co., Ltd and Aion Automobile Manufacturing (Thailand) Co., Ltd. and affiliates under GAC AION ecosystem/group (hereinafter referred to as "AION" or "We")
This privacy policy is made to protect the legitimate rights and interests of users or personal data subjects (hereinafter referred to as "customer” or "user" or "you") and regulate to comply with the use Personal Data Protection Act B.E. 2562 (PDPA) of your personal information in Thailand, this policy is formulated.
We recognize the importance of the security and privacy of your personal data and we are committed to providing you with the best possible service experience. By accessing and using our services or products, you are deemed to have consented to and agreed with the terms outlined in this policy. If you do not agree with this policy, you have the right to decline the use of our services and products.
We may collect personal data and non-personal data for the purpose of improving our products, resolving issues, and continuously enhancing our services. This will be done strictly in accordance with the provisions of the PDPA and relevant laws to protect your data according to the required standards. The term "personal data" refers to any information relating to a Person, which enables the identification of such Person, whether directly or indirectly, but not including the information of the deceased Person in particular.
This privacy policy will include the details of:
-
1. Types of Personal Data
-
2. How we process children's personal information
-
3. How your personal information is used and collected
-
4. Cross-border Personal Data transferring
-
5. Disclosure of Personal Data
-
6. How long do we keep your Data
-
7. Your rights and The Protection of those Rights
-
8. Advertising and Marketing
-
9. Cookies
-
10. Data Breach Notification
-
11. Updates and changes to this privacy policy
-
12. Contact Information
Types and Purpose of Personal Data Collection
We collect various types of personal data, in general, depending on your relationship with us such as when you register to the “TEST DRIVE” with us or for marketing purposes, we are collecting; Personal Data such as name, surname; Contact Information such as phone number, email; Account Information such as AION user account, usage history; Technical Information such as IP address, Cookie ID, website usage history (Activity Log) and any other data is considered personal information under the Personal Data Protection Act which shall be limited to the extent necessary concerning the lawful purpose of us.
customer care purposes, we may collect your voice audio with our call center, the date and time of the call, customer details, car model and specifications, license plate, and purchase store details. This may also include the detailed content provided by the customer and vehicle information, including the Vehicle Identification Number (VIN), vehicle model name, model code, and engine number.
For sales purposes, we may collect the customer type (private/Commercial), customer name, phone number, sales time, sales consultant information, sales price (with and without tax), email, invoice number, invoice date, insurance purchase date, purchase details, and any relevant details will be included.
For wall charger purposes, we may collect the car owner's details, contact number, Vehicle Identification Number (VIN), address for setting up the device, date, and store of purchase, and vehicle motor number.
For mobile phone application users, we may collect data such as AION account details which may contain the phone number and address. If you use our test drive feature, we may collect the first name, last name, and phone number, but for the test drive evaluation, we may only collect the phone number. Suppose you contact us for after-sales service or service center on the feature on the application. In that case, we may collect the name, phone number, vehicle registration number, Vehicle Identification Number (VIN), and service history. When you leave us feedback, we may collect the phone number and email address. Additionally, for the Internet of Vehicle (IOV), we may collect the Vehicle Identification Number (VIN), motor number, phone number, email address, and vehicle model.
For driver safety purposes, we may collect and process the data of vehicles such as monitor driving speed, battery power, vehicle gear position, driving behavior data such as distance traveled, and power usage. We may also track and collect the operation of the system such as the status of the air conditioning system, seat adjustment, location data stored via GPS and WLAN networks, facial recognition, and driver gesture recognition, as well as movement and vision assessments, are included, operational status of the vehicle, usage statistics such as battery level, location, and collision-related data are collected to enhance system performance.
We also collect personal data necessary to comply with the law, ensure public health and safety, and respond to emergencies, as well as de-identified personal data for academic and statistical research purposes which may be different in each vehicle model, but will not exceed what is stated above. However, we will not collect or use sensitive personal data, such as race, nationality, political opinions, religious or philosophical beliefs, sexual behavior, criminal records, health information, disabilities, union membership, genetic data, or biometric data, unless permitted by law or with your explicit consent.
How we process children’s personal information
Our products, websites, and services are primarily intended for adults. Children should not create their personal information subject account without the consent of a parent or guardian.
For cases where we collect personal information from children with parental consent, we will only use or publicly disclose this information as permitted by law in compliance with PDPA and other applicable laws, with the explicit consent of the parent or guardian, or as necessary to protect the child.
*How your personal information is used and collected
We use the collected data for various purposes, including creating and managing accounts, providing services, and enhancing the user experience. Additionally, we share and manage data within the organization, carry out marketing and promotional activities, and provide after-sales services. We also collect user feedback and process payments to ensure compliance with our Terms and Conditions, as well as with laws, regulations, and requirements from regulatory authorities.
The personal data we collect and process within Thailand may be stored on the servers of our data service providers or our business partners, both domestically and internationally. We implement security measures as required by law to protect your personal data from unauthorized access, loss, leakage, or misuse.
When transferring data internationally, we ensure that the destination country has personal data protection measures equivalent to or higher than the standards enforced in Thailand or that a data protection agreement is in place with the recipient as required by law. If the destination country lacks sufficient data protection measures, we will seek your consent before transferring the data to ensure compliance with applicable legal regulations.
Cross-border Personal Data transferring
Our services and products utilize resources and servers located around the world. Therefore, upon receiving your explicit authorization and consent, your personal data may be transferred to or accessed from locations outside the country or region where you use our products or services.
However, we will comply with Thailand's PDPA requirements for all data transfers. For example, we will seek your explicit consent for cross-border data transfers or implement additional security measures, such as anonymizing the data before transferring it.
Disclosure of Personal Data
Without your explicit authorization and consent, we will not share or disclose your personal information to any third party except in the case that we may disclose your personal data to the following parties under certain circumstances:
-
Within Our Organization: We may share your personal data internally across different departments, services, and affiliates under GAC AION to provide, improve, and develop our products or services. This helps us offer more relevant and personalized experiences to you and others.
-
Service Providers: We may disclose personal data to third-party service providers who assist us with tasks such as payment processing, marketing, and product development.
-
Business Partners: We may share certain personal data with our business partners to coordinate services and provide essential information related to product availability, ensuring a smooth experience for you.
-
Law Enforcement and Government Authorities: In compliance with legal requirements, we may disclose your personal data to law enforcement or government agencies, such as courts or regulatory authorities, when necessary for national security, public safety, or criminal investigations.
-
Public Interest or Legal Justifications: In cases directly related to national security, public health, or criminal investigations, we may disclose your data without explicit consent. We may also share information if you have publicly disclosed it or if it comes from legal, publicly available sources.
These disclosures are made in accordance with applicable laws, including Thailand's Personal Data Protection Act (PDPA). We comply with legal regulations to ensure that your personal data is fully protected.
How long do we keep your data
We will retain your personal data for as long as you remain a customer or interact with us, or until the data is no longer necessary for the purposes outlined in this privacy policy. We may retain data for a longer period if required or permitted by law. When your data is no longer necessary or when the retention period has expired, we will delete, destroy, or anonymize it.
Fortest drive and marketing purposes, we will retain your information for the duration of our contact with you, and for up to 5 years thereafter.
For customers with mobile app accounts, in-car app accounts, or service-related accounts with us, such as when you contact us for assistance or additional information, we will retain your data for as long as you have an account with us and for up to 10 years after you close the account.
For customer service or after-sales service, we will retain your information for the duration of our relationship, and for up to 10 years afterward, or up to 10 years after your warranty expires, whichever is later.
Your rights as a data subject and the Protection of those Rights
In compliance with the Personal Data Protection Act (PDPA) and relevant laws, you have the following rights to manage your personal data. You can exercise these rights by contacting our Data Protection Officer, and we will respond within 30 working days.
-
Right to Access: You can request access to and obtain a copy of your personal data that we hold.
-
Data Portability: You have the right to receive your data in a machine-readable format and request us to send or transfer it to another Data Controller, if feasible.
-
Right to Object: You may object to the collection, use, or disclosure of your personal data.
-
Data Erasure or Destruction: You can request us to erase or anonymize your personal data if it’s no longer needed or was unlawfully collected.
-
Restriction of Use: You have the right to request a restriction on the use of your personal data in certain circumstances.
-
Rectification: You can request that your personal data remain accurate, up-to-date, complete, and not misleading.
-
Complaint Lodging: You have the right to file a complaint if we or our service providers violate or fail to comply with the PDPA or related regulations.
-
Withdrawal of Consent: You can withdraw your consent to our collection, use, or disclosure of your personal data at any time unless restricted by law or ongoing contracts.
-
Data Access: Beyond receiving a copy, you can ask how we obtained your data.
-
Suspension: You may request a suspension of data processing during periods of rectification, objection, or while we examine requests for deletion or destruction.
-
Objection: You have the right to object to any automated decision-making that significantly impacts your legal rights, and you can request human intervention if needed.
We aim to ensure your rights are protected. You have the option to manage automated decision-making processes on the application by your setting, or you can contact us directly to review or adjust these decisions. We reserve the right to refuse requests that could endanger others’ rights or that are related to national security, public safety, or legal obligations.
Advertising and Marketing
We may send certain information or a newsletter for the purpose of utilizing your preference via your email, text message, or call. If you no longer want to receive the communications from us, you can click the "unsubscribe" link in the email or contact us directly via email or our customer service center.
Cookies
To enhance your experience, we use cookies and similar technologies to display personalized content, and relevant advertising, and store your preferences on your device. Cookies are small data files; including cookies, Flash cookies, or other local storage provided by your browser or associated applications (collectively referred to as "cookies"), which allow us to identify and track visitors, website usage, and access preferences.
Cookies help us prevent the need for repeated registration details and assist in personalizing your experience. Some of our services may only function when cookies are used. Additionally, the cookies placed by third-party partners, such as advertisers, may collect anonymous information for user behavior analysis, targeted advertising, and evaluating the effectiveness of ads.
Type of cookies |
Categories based on where it’s stored |
Operation and Management |
Duration of Storing |
HERE Map |
Session Cookies |
To assist in finding nearby service centers. |
The data will be deleted when the user exits the website. |
|
Persistent Cookies |
|
The data will remain on the user's device until the cookie expires or is deleted. |
Google Analytics |
Third Party Cookies |
To track user behavior on the website such as visited web pages, clicks, and the time of exit from the website, will be analyzed to improve the website's performance and user experience. |
The data will be stored on the server's cloud for a period of 14 months. |
These third-party cookies are subject to their own privacy policies and terms. We encourage you to read their personal information protection policies and user agreements for details on how they collect and use data.
You can manage or reject cookies through your browser settings. However, please note that disabling cookies may affect your ability to fully access and use our services, and some features may not function properly. You may still see advertisements, but they may be less relevant to you.
We ensure that your personal information is managed in compliance with third-party agreements and applicable laws. If you prefer not to have cookies placed on your device, adjust your browser settings to refuse cookies before using our website. However, this may limit your overall experience on our platform.
Data Breach Notification
In the event of a personal data breach, we will notify the Office of the Personal Data Protection Commission without delay and within 72 hours of becoming aware of the breach, as far as reasonably possible. If the breach poses a high risk to your rights and freedoms, we will inform you of the breach and the remedial actions available without delay, through either our website, SMS, email, phone call, or letter.
Updates and changes to this privacy policy
Our personal information protection policy may change. To provide you with better services, we may revise this policy from time to time. When the terms of this policy change, we encourage you to frequently check on our website. This Privacy Policy was last updated and effective in October 2024.
For Car and Mobile application users, we will display them to you in the form of push notifications through the system when you log in again and when the version of Privacy Policy is updated. Your explicit consent will be sought for any changes that affect the way your personal information is handled
Once you have provided your consent, we will collect, use, and store your personal data only in accordance with the updated policy.
If you have suggestions or questions about the updated content of this privacy policy, you can contact us through the customer service center to give us feedback, and we will respond within 30 working days.
The purpose of this Privacy Policy is to offer products or services and use of our website. Any websites from other domains found on our site are subject to their privacy policy which is not related to us.
Contact Information
If you have any questions about this Privacy Policy or would like to exercise your rights, you can contact us by using the following details:
Data Controller
AION AUTOMOBILE SALES (THAILAND) CO., LTD.
98 (2901-2904) Floor 29th Sathorn Square Tower, Si Lom, Bang Rak, Bangkok, 10500
Email: DPO@aionauto.com
Website: https://www.aionauto.com/th-th/policy/privacy-policy
Tel.: +662 013 9999
Personal Data Protection Officers
98 (2901-2904) Floor 29th Sathorn Square Tower, Si Lom, Bang Rak, Bangkok, 10500
Email:DPO@aionauto.com