Privacy Notice
Aikchol Hospital Public Company Limited
Aikchol Hospital Public Company Limited (the “Hospital”) places great importance on the protection of your personal data. As the data controller under the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”), the Hospital has prepared this Privacy Notice to inform you of the details regarding the collection, use, and/or disclosure of your personal data, as well as your rights as a data subject, as follows:
1. Definitions
For the purposes of this Notice:
“Personal Data” means any information relating to a natural person which enables the identification of such person, whether directly or indirectly.
“Sensitive Personal Data” means personal data as prescribed by law, including but not limited to health data.
“Data Subject” means a person to whom the personal data relates.
2. Personal Data We Collect
The Hospital collects your personal data only to the extent necessary for the provision of medical services and related purposes, including:
Identification Information: Full name, date of birth, gender, nationality, photograph, national identification number or passport number.
Contact Information: Address, telephone number, email address, emergency contact details.
Health Information (Sensitive Personal Data): Medical history, diagnoses, laboratory results, drug allergy history, genetic data, sexual behavior, religion, ethnicity, and medical photographs.
Financial Information: Payment details, credit card number, healthcare entitlement and/or health insurance information.
Technical Information: Website usage data (cookies), IP address (in case of online services).
Photographs and Video Recordings: CCTV footage or other audio-visual media capable of identifying an individual.
3. Purposes of Data Processing
The Hospital collects, uses, or discloses your personal data based on lawful grounds for the following purposes:
Contractual Basis: For diagnosis, medical treatment, appointment scheduling, and referral to other healthcare facilities.
Legal Obligation: To comply with applicable healthcare laws, communicable disease control laws, and tax regulations.
Legitimate Interest: For security purposes (CCTV), internal administration, and service quality improvement.
Consent: For providing news updates, marketing communications, promotions, or other benefits (you may withdraw your consent at any time).
4. Disclosure of Personal Data
The Hospital will maintain the confidentiality of your personal data. However, we may disclose your data to third parties where necessary, including:
Insurance companies or contractual partners responsible for medical expenses;
Government authorities, such as the Department of Health Service Support, Provincial Public Health Office, and the National Health Security Office (NHSO);
External service providers or data processors engaged by the Hospital;
Business partners or external service providers (Data Processors) supporting the Hospital’s operations.
5. Use and Exchange of Medical Records Within the Hospital Network
For the highest benefit of continuous, quality, and safe medical treatment, the Hospital may use, disclose, or exchange patients’ health information and medical records within the Aikchol Hospital network across all branches for the following purposes:
- To provide diagnosis, treatment, and continuous follow-up care;
- To avoid duplication of examinations and reduce medical risks;
- To enable relevant medical personnel to access necessary information appropriately.
Such use or disclosure will be carried out only to the extent necessary, with access restricted to authorized personnel and subject to appropriate data security measures as required by law.
6. Data Retention Period
The Hospital will retain your personal data for as long as necessary to fulfill the above purposes or as required by law (for example, medical records must be retained for at least five (5) years from the date of the last treatment visit as required by healthcare regulations). Upon expiration of the retention period, the Hospital will delete or destroy such data in accordance with security standards.
7. Rights of the Data Subject
Under the PDPA, you have the following rights:
7.1 The right to access and obtain a copy of your personal data;
7.2 The right to request data portability;
7.3 The right to object to data processing;
7.4 The right to request erasure, destruction, or restriction of use (subject to legal limitations under public health laws);
7.5 The right to request correction of inaccurate or incomplete data;
7.6 The right to withdraw consent (where consent has been given).
8. Data Security Measures
The Hospital has implemented appropriate technical and organizational security measures to prevent loss, unauthorized access, use, alteration, or disclosure of personal data.
9. Cookies
The Hospital may use cookies and similar technologies to enhance website functionality. You may configure your browser settings to manage cookies. However, disabling cookies may affect certain functionalities of the website.
10. Changes to This Notice
The Hospital reserves the right to amend or update this Privacy Notice. Any changes will be announced on the Hospital’s website and shall become effective from the date of publication.
11. Contact Information
If you have any questions regarding this Privacy Notice or wish to exercise your rights as a data subject, please contact:
Data Protection Officer (DPO)
Aikchol Hospital Public Company Limited
68/3 Phrayasatja Road, Ban Suan Subdistrict
Mueang Chonburi District, Chonburi 20000, Thailand
Email: [email protected]
Tel: +66 38 939999
Website: www.aikchol.com