Privacy Policy

Effective Date: Jan 1st 2025

1. Introduction

Welcome to radach.com & saiyoksprings.com & almaco.co & yaoyai.org (the “Website(s)”), operated by Radach & Family Organics Co., LTD. (“we,” “us,” or “our”). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect,1 use, disclose, and safeguard your personal data when you visit our Website2 radach.com or saiyoksprings.com or almaco.co or yaoyai.org and use our services, in compliance with Thailand’s Personal Data Protection Act B.E. 2562 (2019) (PDPA).

Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Website.3

2. Data Controller

The data controller responsible for your personal data is:

Radach & Family Organics Co., LTD.

29/1 Soi Langsuan, 10330 Bangkok

Email: info@radach.com

Data Protection Officer (DPO) / Privacy Contact:

While the PDPA has specific requirements for the formal appointment of a Data Protection Officer (DPO), for privacy-related inquiries, you can contact:

Alex

Email: info@radach.com

3. What Personal Data We Collect

We may collect various types of personal data from and about you, including but not limited to:

Identity Data: Such as your name, username or similar identifier, title, date of birth, gender.4

Contact Data: Such as your billing address, delivery address, email address, and telephone numbers.
Technical Data: Such as your Internet Protocol (IP) address, browser type and version, time zone setting and location,5 browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this Website.6

Usage Data: Such as information about how you7 use our Website, products, and services.
Marketing and Communications Data: Such as your preferences in receiving marketing from us and our8 third parties and your communication9 preferences.
Cookies and Tracking Data: Information collected through cookies, web beacons, and other tracking technologies. (See Section 11 for more details).
Sensitive Personal Data:

We generally do not collect sensitive personal data (as defined by the PDPA, e.g., race, ethnic origin, political opinions, religious beliefs, sexual orientation, health data, biometric data, criminal records). [If you DO collect sensitive personal data, you MUST explicitly state what types, for what specific purpose, and that you will obtain explicit consent or have another lawful basis under the PDPA for such collection. This section needs careful legal review.]

4. How We Collect Your Personal Data

We collect personal data in the following ways:

Direct Interactions: You may give us your Identity, Contact, and E-mail by filling in forms on our Website, corresponding with us by post, phone, email, or otherwise. This includes personal data you provide when you:
Create an account on our Website.
Subscribe to10 our service or publications.
Request marketing to be sent to you.
Enter a competition, promotion, or survey.
Give us feedback or contact us.11
[Add other direct interaction methods relevant to your website]
Automated Technologies or Interactions: As you interact with our Website, we may automatically collect Technical Data about your equipment, Browse actions, and patterns.12 We collect this personal data by using cookies, server logs, and other similar technologies. (See Section 11 for more details).

Third Parties or Publicly Available Sources: We may receive personal data about you from various third parties and13 public sources as set out below:
Technical Data from analytics providers such as Google Analytics.14
Linkedin, Instagram
5. Legal Basis for Processing Personal Data

We will only collect, use, and disclose your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

Consent: Where you have given us explicit consent to process your personal data for one or more specific purposes.
Contractual Necessity: Where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.
Legal Obligation: Where it is necessary for compliance with a legal obligation to which we are subject.
Legitimate Interests: Where it is necessary for our legitimate interests (or those of a third party) and your interests and15 fundamental rights do not override those interests. We will identify our legitimate interests when applicable.
Vital Interest: Where it is necessary to protect your vital interests or those of another natural person.
Public Task: For the performance of a task carried out in the public interest or in the exercise of official authority vested in16 us.
6. How We Use Your Personal Data (Purposes of Processing)

We use the personal data we collect for various purposes, including:

To provide and maintain our Website and services.
To manage your account and our relationship with you.
To process your transactions
To personalize your experience on our Website.
To communicate with you, including responding to your inquiries and providing customer support.
For marketing17 and promotional purposes, with your consent where required18 (e.g., sending newsletters, special offers).
To improve our Website, products, services, marketing, customer relationships, and experiences.
To ensure the security of our Website and prevent fraud.
To comply with our legal obligations.
For data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns.
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider19 that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis which20 allows us to do so, or seek your consent.

7. Sharing Your Personal Data (Disclosure to Third Parties)

We may share your personal data with the following categories of third parties for the purposes set out in this Privacy Policy:

Service Providers: Companies that provide services on our behalf, such as payment processing, data analysis, email delivery, hosting21 services, customer service, and marketing assistance. These service providers22 are contractually bound to protect your data and use it only for the purposes for which we disclose it to them.
Professional Advisors: Including lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting23 services.
Legal Authorities: If required by law or in response to valid requests by public authorities (e.g., a court or a government agency),24 including the Personal Data Protection Committee (PDPC).
Business Transfers: In connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all25 or a portion of our business by another company.
International Data Transfers:

Your personal data may be transferred to, stored, and processed in countries other than Thailand. [Specify the countries or regions, if known. If you don’t transfer data internationally, state that.]. If we transfer your personal data outside of Thailand, we will ensure that appropriate safeguards are in place to protect your personal data in accordance with the PDPA. This may include:

Ensuring the recipient country has adequate data protection laws as determined by the PDPC.
Implementing standard contractual clauses approved by the PDPC.
You can request further information about the safeguards we use for international transfers by contacting us.
8. Data Retention

We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying26 any legal, regulatory, tax, accounting, or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

Upon expiry of the retention period, or when the data is no longer necessary for the stated purposes, we will securely delete or anonymize your personal data.

9. Your Rights as a Data Subject

Under the PDPA, you have the following rights regarding your personal data:

Right to be Informed: The right to be informed about the collection, use, and disclosure of your personal data.
Right of Access: The right to request access to copies of your personal data that we hold.
Right to Rectification: The right to request correction of inaccurate or incomplete personal data.
Right to Erasure (Right to be Forgotten): The right to request the deletion27 or destruction of your personal data, or to have it anonymized, under certain conditions.
Right to Restrict Processing: The right to request the restriction of the use of your personal data under certain conditions.
Right to Data Portability: The right to request that we transfer the personal data28 that we have collected about you to another organization, or directly to you, in29 a commonly used and machine-readable format, under certain conditions.
Right to Object: The right to object to the collection, use, or disclosure of your personal data for certain purposes, such as direct marketing.30

Right to Withdraw Consent: If we are relying on your consent to process your personal data, you have the right to withdraw your consent at any31 time. Withdrawing consent will not affect the lawfulness of any processing32 carried out before you withdrew your consent.
Right to Lodge a Complaint: The right to lodge a complaint with the Personal Data Protection Committee (PDPC) if you believe that we are not complying with the PDPA.
To exercise any of these rights, please contact us using the contact details provided in Section 14. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.

We will33 respond to all legitimate requests within34 a week or as soon as reasonably practicable.

10. Data Security

We have implemented appropriate technical and organizational security measures to protect your personal data from accidental35 loss, unauthorized access, use, alteration, or disclosure.

However, please note that no method of transmission over the Internet or method of electronic storage is 100% secure.36 While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.

In the event of a personal data breach, we37 will notify the PDPC and you (if the breach is likely to result in a high risk to your rights and freedoms) in accordance with our obligations under the PDPA.

11. Use of Cookies and Other Tracking Technologies

Our Website uses cookies and similar tracking technologies (such as web beacons and pixels) to enhance your Browse experience, analyze site traffic, understand where our audience is coming from, and for marketing purposes.38


What are Cookies? Cookies are small text files that are placed on your computer or mobile device by websites that you visit.3940

Types of Cookies We Use:
Strictly Necessary Cookies: Essential for the Website to function and cannot be switched off.
Performance/Analytical Cookies: Allow us to recognize and count visitors and see how they move around our Website. This helps us improve the way our Website works. (e.g., Google Analytics)
Functionality Cookies: Used to recognize you when you return to our Website and enable us to personalize content and remember your preferences (e.g., language, region).
Targeting/Advertising Cookies: Record your visit to our Website, the pages you have visited, and the links you have followed. We may use this information to make our Website and the advertising displayed on it more relevant to your interests. We may41 also share this information with third parties for this purpose.
Your Choices Regarding Cookies: When you first visit our Website, you will be presented with a cookie banner requesting your consent for the use of non-essential cookies. You42 can manage your cookie preferences at any time through . Please note that blocking some types of cookies may impact your experience on the site and the services we are able to offer.43
12. Privacy of Minors

Our Website is not intended for individuals under the age of 20 (“Minors”) without the consent of a parent or legal guardian, especially for Minors under the age of 10 where parental consent is typically required for any data processing. We do not knowingly collect personal data from Minors without appropriate consent.

If you are a parent or guardian and you believe that your child has provided us with personal data without your consent, please contact44 us. If we become aware that we have collected personal data from a Minor without verification of parental45 or guardian consent as required by law, we will take steps to remove that information from our servers.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any changes by posting the new Privacy Policy on46 this page and updating the “Effective Date” at the top.

We encourage you to review this Privacy Policy periodically for any changes. Changes47 to this Privacy Policy are effective when they are48 posted on this page.

14. Contact Us

If you have any questions or concerns about this Privacy Policy, our privacy practices, or if you wish to exercise your rights as a data subject, please contact:

Privacy Officer: Alex

Radach & Family Organics Co., LTD.

29/1 Soi Langsuan, 10330 Bangkok

Email: info@radach.com