Sangsakao Clinic
Privacy Notice for Applicants and Employees
Sangsakao Clinic (“Clinic”) respects and highly values the privacy rights regarding the personal data of job applicants, internship applicants, current employees, former employees, directors, executives, consultants, and any other persons related to the Clinic's personnel (“You”). In compliance with the Personal Data Protection Act B.E. 2562 (2019) and related subordinate laws or regulations (“Personal Data Protection Law”), the Clinic has issued this Privacy Notice for Personnel to clarify the details, methods for managing and processing personal data received from you, the purposes for collection, use, disclosure, and transfer, the retention period, and your rights as the Data Subject, as follows:
- Clinic:
- Sangsakao Clinic, including the website https://www.laserbankclinic.com/about-us
- Personal Data:
- Data about a person which enables the identification of such person, whether directly or indirectly, but excluding the data of a deceased person specifically.
- Sensitive Personal Data:
- Personal data as stipulated in Section 26 of the Personal Data Protection Act B.E. 2562 (2019), such as racial, ethnic origin, political opinions, cult, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, biometric data, or any other data which affects the data subject in the same manner.
- Data Subject:
- A natural person who can be identified from the Personal Data, such as Clinic personnel, job applicants, family members/references/emergency contacts related to Clinic personnel or applicants, customers, service users, partners, website visitors, custodians authorized to act on behalf of minors, guardians authorized to act on behalf of incompetent persons, curators authorized to act on behalf of quasi-incompetent persons, etc.
- Data Controller:
- A person or legal entity having the authority to make decisions regarding the collection, use, or disclosure of Personal Data.
- Data Processor:
- A person or legal entity that carries out the collection, use, or disclosure of Personal Data on the instructions of or on behalf of the Data Controller.
- Personal Data Processing:
- Any operation performed on Personal Data, such as collection, recording, copying, organization, storage, adaptation, alteration, retrieval, disclosure, transfer, dissemination, transfer, amalgamation, erasure, destruction, etc.
- Personal Data Protection Law:
- The Personal Data Protection Act B.E. 2562 (2019) and related subordinate laws, and shall include any future amendments to such laws.
- Anonymization:
- A process that reduces the risk of identifying the Data Subject to a negligible level (Negligible Risk).
The Clinic collects, uses, or discloses your Personal Data received through various channels as follows:
2.1 Personal Data directly provided by you to the Clinic:
You may provide Personal Data directly to the Clinic when you express the intention to apply for a job or internship with the Clinic, or when you contact for inquiries, or when you send an application with your Personal Data to the Clinic, or when you exchange a card to access the building area.
2.2 Personal Data automatically collected by the Clinic from you:
The Clinic may automatically receive your Personal Data, such as CCTV recordings, technical data, activity and viewing patterns, website browsing history automatically by using cookies and other similar technologies. You can study more details in the Clinic’s “Cookies Policy”.
2.3 Personal Data received by the Clinic from third parties:
The Clinic may occasionally receive your Personal Data from third parties, such as job websites, recruitment agencies, or documents of persons related to you as your family members, emergency contacts, references, beneficiaries, or guarantors of such persons, etc.
Personal Data collected by the Clinic under this Privacy Notice is divided into the following categories of Data Subjects:
3.1 For Job Applicants
3.1.1 Personal Details such as name, surname, address, phone number... education history, work history... 3.1.2 Sensitive Personal Data such as religion, health data... 3.1.3 Other Data...
3.2 For Internship Applicants
3.2.1 Personal Details... 3.2.2 Sensitive Personal Data such as religion... 3.2.3 Other Data such as internship letter from university...
3.3 For Clinic Employees and Personnel
3.3.1 Personal Details... 3.3.2 Sensitive Personal Data... 3.3.3 Employment Data... 3.3.4 Welfare and Benefits Data... 3.3.5 HR Administration Documents... 3.3.6 Other Related Data such as CCTV recordings...
3.4 For Third Parties
The Clinic may receive third-party data related to you, such as spouse data, family data... You must obtain consent and inform these individuals about the processing of personal data under this Privacy Notice...
หมายเหตุ: In cases where the Clinic needs to collect Sensitive Personal Data, the Clinic will provide appropriate security measures and request your consent before collection, unless there is a legal exception...
4.1 For Job Applicants
- 4.1.1 Contractual Basis: To process recruitment applications, verify qualifications, evaluate suitability, and coordinate the hiring process prior to entering into an employment contract.
- 4.1.2 Legitimate Interest: To ensure security within clinic premises (e.g., CCTV), conduct necessary background checks for organizational benefit, and manage preliminary human resources operations.
- 4.1.3 Vital Interest: To prevent or suppress danger to life, body, or health of the applicant or others in emergency situations while on clinic premises.
- 4.1.4 Consent: In cases where the clinic collects Sensitive Data, such as religious information (from ID cards) or health data beyond basic requirements, where other legal bases do not apply.
4.2 For Interns
- 4.2.1 Contractual Basis: To process internship requests, evaluate performance, issue certificates of completion, and coordinate with the respective educational institutions.
- 4.2.2 Legitimate Interest: To maintain clinic discipline, manage access rights to IT systems and restricted areas, and evaluate potential for future employment.
- 4.2.3 Vital Interest: To provide first aid or contact relatives in case of accidents or medical emergencies during the internship period.
- 4.2.4 Consent: To collect photographs or video recordings during the internship for use in internal or external clinic public relations activities.
4.3 For Employees and Personnel
- 4.3.1 Contractual Basis: To fulfill employment contracts, including salary payments, benefits, social security, training, and personnel management throughout the employment term.
- 4.3.2 Legal Obligation: To comply with relevant laws such as labor protection, taxation, social security, and medical facility regulations.
- 4.3.3 Legitimate Interest: To monitor work performance, ensure IT security, prevent fraud, and evaluate performance for merit considerations.
- 4.3.4 Legal Claims: To serve as evidence in legal proceedings, exercise legal rights, or defend against legal claims in the future.
- 4.3.5 Vital Interest: To manage employee health and safety in emergencies or suppress incidents that may jeopardize individual health.
- 4.3.6 Consent: To collect Biometric Data (e.g., fingerprints or facial recognition) for time attendance or deep health insights for additional welfare programs.
For job applicants, please note that the Clinic needs to process your Personal Data for the purpose in 4.1.1. If you do not provide Personal Data under 3.1 to the Clinic, it may affect legal compliance...
The Clinic may disclose your personal data for the specified purposes and in accordance with legal criteria to the following entities and individuals:
5.1 Internal Departments
Human Resources, executives, supervisors, accounting, IT personnel, or relevant departments with a necessary duty to process data based on their roles.
5.2 Affiliates and Group Companies
Your data may be accessed by or disclosed to other legal entities within the group for HR management, internal reporting, and business efficiency.
5.3 Third-Party Service Providers (Data Processors)
Individuals or entities engaged by the Clinic to provide services, including (a) IT, cloud, and software providers, (b) background check agencies or recruitment agents, and (c) legal or accounting consultants.
5.4 Government Authorities and Legal Third Parties
Disclosures required by law to regulatory bodies such as the Revenue Department, Social Security Office, Department of Labor, courts, or other law enforcement agencies.
In the event of cross-border data transfers, the Clinic will ensure that the destination country provides an adequate level of data protection and that data protection agreements are in place as required by law.
- 6.1 Unsuccessful Job Applicants: Data will be retained for 1 year following the conclusion of the recruitment process for future career opportunities.
- 6.2 Employees and Personnel: Data will be retained throughout the term of the employment contract and for an additional 10 years following termination for audit, benefit verification, and legal claim purposes.
- 6.3 Exercise of Data Subject Rights: Records of rights requests will be stored for 1 year after the request has been fully processed.
Upon expiry of these periods, the clinic will proceed to delete, destroy, or anonymize the personal data in accordance with relevant laws and international standards.
- 7.1 The Clinic strictly regulates access, usage, disclosure, and processing of personal data, implementing robust authentication and identity verification systems to prevent unauthorized access.
- 7.2 For cross-border data transfers or cloud storage, the Clinic selects providers with international security standards and enters into Data Processing Agreements (DPAs) to ensure strict confidentiality.
- 7.3 In the event of a security breach resulting in a data leak, the Clinic will notify the Office of the Personal Data Protection Committee (PDPC) within 72 hours and inform the data subjects as soon as possible if the breach poses a high risk to their rights and freedoms.
8.1 Right to Withdraw Consent
You may withdraw your consent at any time, unless restricted by law or an existing contract that benefits you.
8.2 Right of Access
You have the right to access and obtain a copy of your personal data, including requesting disclosure of how your data was acquired without your consent.
8.3 Right to Data Portability
You have the right to receive your data in a machine-readable format and request its transfer to another data controller where technically feasible.
8.4 Right to Object
You have the right to object to the collection, use, or disclosure of your data in certain circumstances, such as for direct marketing or research purposes.
8.5 Right to Erasure
You may request the deletion, destruction, or anonymization of your data when it is no longer necessary or when consent is withdrawn.
8.6 Right to Restrict Processing
You have the right to request a temporary suspension of data usage, such as during the period the clinic is verifying the accuracy of your data.
8.7 Right to Rectification
You have the right to ensure your personal data is accurate, current, complete, and not misleading.
8.8 Right to Lodge a Complaint
You have the right to file a complaint with the Personal Data Protection Committee (PDPC) if you believe the clinic has violated data protection laws.
The clinic will process your request within 30 days of receipt. We reserve the right to decline requests as permitted by law or if they infringe upon the rights and freedoms of others.
If you have any questions or complaints about your Personal Data under this Privacy Notice, please contact the following channels:
9.1 Data Controller
Name: Sangsakao Clinic
Address: 518/3 Ploenchit Road, Lumpini, Pathum Wan, Bangkok 10330
Tel: 090-026-9555
Email: totale2564@gmail.com
9.2 Data Protection Officer (DPO)
Name: HR Department
Address: 518/3 Ploenchit Road, Lumpini, Pathum Wan, Bangkok 10330
Tel: 090-026-9555
Email: totale2564@gmail.com
However, if you wish to exercise any of the rights above under Clause 8, you can contact the Clinic via the contact details above or fill out the “Data Subject Right Request Form”.
The Clinic may amend, review, and update this Privacy Notice from time to time to align with any changes related to the processing of your Personal Data...
© 2026 Sangsakao Clinic. All Rights Reserved.