Paragon Car Rental Co., Ltd. (hereinafter referred to as the “Company”) recognizes the importance of your personal data and other information relating to you (collectively referred to as “Data”). To ensure your confidence in the Company’s transparency and accountability regarding the collection, use, or disclosure of your Data in accordance with the Personal Data Protection Act B.E. 2562 (2019) (“PDPA”) and other relevant laws, this Privacy Policy (“Policy”) has been established. It outlines the details concerning the collection, use, or disclosure (collectively referred to as “Processing”) of personal data carried out by the Company, including its officers and related persons acting on behalf of or in the name of the Company, as follows:
This Policy applies to the personal data of individuals who currently have, or may have in the future, a relationship with the Company. Such personal data is processed by the Company, its officers, contract employees, business units, or other entities operated by the Company, including contractors or third parties who process personal data on behalf of or in the name of the Company (“Data Processors”) under various products and services such as websites, systems, applications, documents, or other service formats controlled by the Company.
Individuals with a relationship with the Company under the first paragraph include:
Individual customers.
Officers, staff, or employees.
Business partners and service providers who are individuals.
Directors, authorized persons, representatives, agents, shareholders, employees, or other persons with a similar relationship to legal entities that have a relationship with the Company.
Users of the Company’s products or services.
Visitors or users of the websites www.hertzthailand.com, www.thriftythailand.com, and the Hertz Thailand Application, as well as systems, applications, devices, or other communication channels controlled by the Company.
Other persons whose personal data is collected by the Company, such as job applicants, family members of officers, guarantors, beneficiaries under insurance policies, etc.
In addition to this Policy, the Company may establish specific Privacy Notices (“Notices”) for certain products or services to inform the Data Subject of the personal data being processed, the purposes and lawful bases for processing, retention periods, and the rights the Data Subject may have regarding those specific products or services.
In the event of any material conflict between the provisions of a Privacy Notice and this Policy, the provisions of the Privacy Notice for that specific service shall prevail.
The Company means Paragon Car Rental Co., Ltd. and its group companies.
Personal Data means any information relating to an individual which enables the identification of such individual, whether directly or indirectly, but excluding information of deceased persons.
Sensitive Personal Data means personal data as defined under Section 26 of the PDPA, which includes race, ethnic origin, political opinions, cult, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, biometric data, or any other data which may affect the Data Subject in the same manner as prescribed by the Personal Data Protection Committee.
Processing of Personal Data means any operation performed on personal data, such as collection, recording, copying, organizing, storing, updating, altering, using, retrieving, disclosing, sending, disseminating, transferring, merging, erasing, or destroying.
Data Subject means the individual who is the owner of the personal data collected, used, or disclosed by the Company.
Data Controller means a person or legal entity having the power and duties to make decisions regarding the collection, use, or disclosure of personal data.
Data Processor means a person or legal entity who operates in relation to the collection, use, or disclosure of personal data pursuant to the orders of or on behalf of the Data Controller, whereby such person or legal entity is not the Data Controller.
The Company collects and receives your personal data through the following channels:
Personal Data provided directly to the Company: You may provide personal data directly during application processes, registration, job applications, signing contracts, documents, completing surveys, or using products, services, or other service channels controlled by the Company, or when contacting the Company at its office or via other communication channels (written, verbal, telephone, or electronic).
Personal Data collected automatically: The Company may automatically collect certain technical information regarding your devices, activities, browsing patterns, and history using Cookies and similar technologies (for more details, please see our [Cookie Policy]). This also includes still and moving images recorded via Closed-Circuit Television (CCTV) when you enter the Company’s business premises.
Personal Data received from third parties: The Company may occasionally receive your personal data from third parties, such as Online Travel Agencies (OTA), referees, recruitment agencies, government agencies, or various public sources.
Furthermore, if you provide personal data of third parties to the Company, you are responsible for informing such persons of the details of this Policy or the relevant product/service Notice, and obtaining their consent if consent is required for disclosure to the Company.
5.1 The Company collects your personal data by category, whether provided directly, received from third parties, or collected automatically, consisting of the following groups:
Customers: Individuals, website visitors, service recipients, activity participants, seminar participants, and any other persons contacting the Company for information or services, whether obtained directly or indirectly.
Contractual Parties: Individuals who are parties to a contract or involved in any contract with the Company, including business partners, vendors, suppliers, service providers, contractors, consultants, securities professionals, and others in a similar nature.
Company Personnel: Individuals who are employees, staff, or persons working for the Company, directors, managers, executives, experts, and persons receiving salary, wages, benefits, or other compensation directly from the Company, including their family members.
Job Applicants: Individuals who have submitted applications or resumes to the Company, whether in writing or verbally, for the purpose of applying for a job, internship, or scholarship, but who have not yet been selected, including their family members and referees.
5.2 The specific types of personal data collected include:
Identity & Attributes: Full name, date of birth, age, gender, height, weight, photo, passport number and copy, National ID card number and copy, signature, nationality, marital status, military service status, spoken languages, behavioral data, preferences, bankruptcy status, incompetency/quasi-incompetency status, and family member details.
Sensitive Personal Data: Religion, criminal records.
Health Data: Health history, health status, congenital diseases, disability, physical abnormalities, illness history, accident history, and information appearing in medical certificates.
Contact Data: Residential address, home phone number, mobile number, email, social media contact info (Line ID, MS Teams, Skype, etc.), social media usernames, emergency contact details, fax number, and location maps.
Financial Data: Bank account numbers and tax-related information.
Work and Education Data: Employment details, job history, and educational background (e.g., employment type, occupation, rank, position, duties, expertise, status, work permit, referees, Tax ID, salary, start/end dates, performance evaluations, benefits, academic institutions, degrees, graduation dates).
Evidentiary Data for Legal Transactions: Personal data appearing in copies of ID cards, passports, name/surname change certificates, house registrations, military service certificates, bank books, marriage certificates, birth certificates, salary approval forms, beneficiary designation forms, social security registration, employment contracts, guarantee letters, director appointment agreements (e.g., certificates of position/salary), and Powers of Attorney.
Technical Data: Access logs for websites and systems, computer traffic data (Log), communication logs, IP Address, device type, mobile network info, connection info, geographic location, browser type, account usernames, passwords, application/website logs, Transaction Logs, and data collected through Cookies or similar technologies.
Other Data: Voice recordings, still and moving images, and audio recorded via CCTV.
5.3 Regarding personal data collected prior to June 1, 2022, the Company will process such data in accordance with the requirements set forth by the PDPA.
6.1 The Company may disclose your personal data for specified purposes and according to legal criteria to the following persons and entities:
Partners, Business Allies, and Service Providers: Data Processors assigned or hired by the Company to provide services or manage personal data, such as IT service providers, data entry services, payment systems, auditors, HR management, or any other services beneficial to you.
Company Consultants: Such as legal advisors, lawyers, auditors, or other experts.
Government Agencies: Regulators or entities authorized by law to request data, or related to legal processes, such as the Office of Insurance Commission (OIC), Department of Provincial Administration, Department of Business Development (DBD), Personal Data Protection Commission (PDPC), Office of the Trade Competition Commission (OTCC), Royal Thai Police, Department of Special Investigation (DSI), Office of the Attorney General, Courts, and Legal Execution Department.
Customers/Beneficiaries/Agents: Business partners, brokers, or representatives of persons you communicate with or who are related to your duties/position.
Consented Parties: Any other person or entity to whom you have given consent for disclosure.
6.2 Disclosure to third parties will be conducted only under specified purposes or as permitted by law. If consent is legally required, the Company will obtain your consent before disclosure.
6.3 The Company will implement appropriate measures to protect disclosed personal data and comply with PDPA standards. If data is transferred abroad, the Company will ensure the destination country, international organization, or recipient has adequate data protection standards as required by law, unless an exemption applies. In some cases, the Company may request your consent for such international transfers.
The Company will retain your personal data for as long as necessary to achieve the specified purposes. The retention period varies depending on the purpose and the following factors:
Periods required by relevant laws. After such periods, the Company will delete or anonymize the data.
Legal statutes of limitation for potential legal proceedings arising from or related to the processed data. The Company will generally retain your data for a period not exceeding [10] years from the date the legal relationship ends. However, the Company may retain data longer if permitted by law or if necessary for the establishment of legal claims.
As a Data Subject, you have the following rights under the PDPA. To exercise these rights, please contact the Company using the details in Section 11.
Right of Access: To access and request a copy of your personal data.
Right to Data Portability: To receive your data in a machine-readable format and request its transfer to another Data Controller, where technically feasible.
Right to Object: To object to the processing of your personal data.
Right to Erasure: To request the deletion, destruction, or anonymization of your data.
Right to Restriction of Processing: To request the suspension of your data processing.
Right to Rectification: To ensure your data is accurate, up-to-date, complete, and not misleading.
Right to Withdraw Consent: To withdraw consent you have previously given.
Right to Lodge a Complaint: To complain to regulatory authorities if the Company violates the PDPA.
Member Data Management: You may change or cancel membership data by contacting loyalty@hertzthailand.com.
The Company will review your request and may require additional information or documents. The Company reserves the right to consider and process requests as permitted by the PDPA.
The Company has implemented appropriate technical and administrative security measures and data storage systems to prevent unauthorized use, disclosure, destruction, or access, ensuring your data security aligns with PDPA standards and relevant laws.
The Company’s services may link to third-party websites, applications, or services which may have different privacy policies. The Company recommends reviewing those policies before use. The Company is not responsible for the content, policies, damages, or actions of third-party services.
If you have questions regarding this Policy or wish to exercise your rights, please contact the Data Protection Officer (DPO):
Office Address: Paragon Car Rental Co., Ltd., No. 46, Kronos Sathorn Tower, G Floor and 10th Floor, North Sathorn Road, Silom, Bang Rak, Bangkok 10500.
Email: dpo@hertzthailand.com
Telephone: +66-2266-4666 ext. 1622
The Company may update this Policy from time to time to reflect changes in data processing or legal requirements. Significant changes will be notified through appropriate channels along with the updated version. We recommend checking this Policy periodically.