Privacy Policy

Announced on 17 June 2024.

Ignite Education Co., Ltd. ("the Company") is an international tutoring school with the aim of providing comprehensive educational services. Our curriculum includes English, Science, and Mathematics, as well as activities that develop Academic Skills and Life Skills ("Services"). In the course of providing these services, it may be necessary for the Company to collect personal data from individuals ("you"). The Company is responsible for ensuring the security of personal data under its control and is committed to managing this data in a secure, reliable manner.

For such data management, this Privacy Policy ("Policy") explains how the Company handles your personal and sensitive information, including the manner of collection, storage, use, and disclosure. This Policy, which outlines your rights, forms part of the terms and conditions of our services. We recommend that you understand this Policy before using our services. Each time you use our services, it is considered that you have read and acknowledged the details of this Policy.

1. Definitions

"Personal Data"

Refers to information about an individual that enables the identification of that person, whether directly or indirectly. This does not include data of deceased persons; corporate data; business contact information that does not identify an individual, company name, company address, company registration number, work telephone number, work email address, and group email addresses of the company; and anonymous data or pseudonymous data which cannot be used to identify an individual through technical means.

"Sensitive Data"

Refers to information that is sensitive and may carry a risk of unfair discrimination, such as race, ethnicity, political opinions, religious or philosophical beliefs, sexual behavior, criminal records, health information, disabilities, union membership, genetic data, biometric data, or any other information that affects the data subject in a similar manner as defined by the Personal Data Protection Committee.

"Data Subject"

Refers to the individual who owns the personal data. This does not include cases where the individual owns, creates, or collects the data themselves. The data subject refers only to natural persons and does not include legal entities established under the law, such as companies, associations, foundations, or other organizations.

"Processing"

Refers to any operation performed on personal data, whether by automated means or not, such as collection, recording, systemization, storage, alteration, retrieval, consultation, use, disclosure (by transmission, transfer, dissemination, or otherwise making available), organization, compilation, blocking, restriction, deletion, or destruction.

"Data Controller

Refers to a natural or legal person who has the authority to make decisions regarding the collection, use, or disclosure of personal data.

"Data Processor"

Refers to a natural or legal person who processes personal data on behalf of the data controller according to their instructions or on their behalf.

"Cookies"

Refers to small computer files that temporarily store necessary personal data on the data subject's computer to facilitate and speed up communication while using the website.

"Data Protection Officer"

Refers to a person appointed by the company to carry out duties under the Personal Data Protection Act B.E. 2562 (2019).

2. Types of Data Subjects

The Company processes personal data according to the specific Privacy Notice for each type of data subject and activity involved in the processing of personal data as follows:

Customers/Service Recipients

Refers to individuals who purchase products and/or use services from the Company, apply for membership, and includes individuals related to, representing, or authorized to act on behalf of the customer. Please refer to the Privacy Notice for Customers and Service Recipients.

Partners

Refers to natural persons and representatives of legal entities, such as directors, authorized signatories, agents, subcontractors, employees and workers of legal entities who engage or intend to engage in transactions with the Company, and those whose personal data appears in relevant documents. This includes individuals submitting bids to sell products and/or provide services to the Company, such as service providers, consultants, experts, academics, speakers, business project participants, contractors, or others with similar relationships with the Company.
Please refer to the Privacy Notice for Business Partners.

Company Personnel

Refers to employees or individuals who work or perform duties for the Company and receive salaries, wages, benefits, or compensation from the Company, such as executives, managers, staff, personnel, or similar persons. It also includes individuals related to the Company personnel and those whose personal data appears in documents related to the recruitment process, such as family members, parents, spouses, children, emergency contacts, reference persons, and beneficiaries.
Please refer to the Privacy Notice for Employees.

Job Applicants

Refers to individuals who have submitted job/internship applications or other personal details to the Company for the purpose of applying for a job/internship, whether as permanent employees or contract workers. This includes employees under employment from an outsourcing service, freelance workers, interns, scholarship applicants who have not yet been selected by the Company, and individuals related to the applicants whose personal data appears in relevant application documents, such as family members, reference persons, and emergency contacts.
Please refer to the Privacy Notice for Job Applicants.

Individuals recorded by CCTV

Refers to individuals who pass by or enter the Company's premises and those in areas monitored by the Company's CCTV cameras. Please refer to the Privacy Notice for CCTV.

Photographed Individuals

Refers to models, presenters, those hired or compensated for photo shoots, Company personnel, award/scholarship recipients, and individuals consenting to the Company’s recording, whether as still or moving images, during interviews, training, learning sessions, activities, or group photos.
Please refer to the Privacy Notice for Photography and Animation.

Event Participants

Refers to individuals participating in the Company's activities or campaigns, including those organized by the Company, registrants, training and seminar attendees, and other similar persons.
Please refer to the Privacy Notice for Event Participation.

General Public

Refers to individuals who have legal relations or contact with the Company, such as website/application users, those contacting the Call Center, individuals requesting information from the Company, and respondents to surveys about the Company's products and/or services.Please refer to the Privacy Notice for General Public.

Cookies

The Company may use automated technology to collect personal data when you use the website and application through computers and mobile devices, including IP address, browser, operating system, visited web pages, and referral websites. This automated technology may include the use of cookies or similar technologies. Please refer to the Cookie Policy.

3. Privacy Protection

In compliance with the legal requirements for personal data protection, the Company will issue the relevant Privacy Notice detailing the collection of personal data. This notice will inform the data subjects electronically, via short messages, or by other methods determined by the Company. The Company will notify the data subjects before or at the time of personal data collection including at least the following details, unless the data subjects are already aware of such details:

  1. This is some text inside of a div block.
  2. Explain the purposes and methods of personal data collection from the data subjects.
  3. Specify the personal data collected.
  4. State the duration for which the personal data will be retained.
  5. List all the rights of the data subjects.
  6. Explain how the data subjects can exercise their rights and withdraw consent for personal data collection.
  7. Detail all measures taken to protect the personal data of the data subjects.
  8. Provide contact information for the data controller or data protection officer so that data subjects can contact, inquire further, or exercise their rights as data subjects.
  9. Specify the types of individuals or external entities that may use the personal data.

4. Personal Data Collection

The Company implements appropriate measures to ensure the security and confidentiality of your personal data to prevent loss, unauthorized access, destruction, misuse, alteration, modification, or disclosure. The collection of your personal data by the Company or its assigned external parties will adhere to the following conditions:

  1. Data Processing
    The Company will process the personal data you provide with restricted access and in a lawful and fair manner. Data processing will be conducted solely for the purposes specified by the Company. Before such processing, the Company will inform and obtain consent from the data subjects electronically, via short messages, or through methods specified by the Company.
  2. Legal and Necessary Purposes
    The Company will process personal data only to the extent necessary for lawful purposes notified to the data subjects before or at the time of data collection. Explicit consent will be obtained from the data subjects, except in the following cases where the Company can collect personal data without consent:
  3. Sensitive Personal Data
    The Company will obtain explicit consent from the data subjects before or at the time of collecting sensitive personal data, in accordance with the Company's guidelines and legal requirements. Sensitive personal data may be collected for specific services with explicit consent from you, voluntary public disclosure, or as mandated by personal data protection laws, based on at least one lawful basis as defined by the personal data protection law:
    1. With the explicit consent of the data subjects
    2. To prevent or mitigate harm to the life, body, or health of individuals when the data subjects are unable to give consent
    3. For lawful activities of foundations, associations, or non-profit organizations with political, religious, philosophical, or trade union objectives, with appropriate protection measures
    4. Publicly disclosed data with explicit consent from the data subjects
    5. Necessary for establishing legal claims, complying with, or defending legal claims
    6. Necessary to comply with laws for purposes related to preventive or occupational medicine, assessing the working capacity of employees, public health benefits, labor protection, social security, national health insurance, medical welfare, scientific research, historical or statistical research, or significant public interest
  4. If the Company intends to process your personal data in ways or for purposes inconsistent with those specified, the Company will issue additional policies or notices on personal data protection or communicate directly with you to explain the data processing. You should read such additional policies or notices in conjunction with this policy and/or the related communications (as applicable).

5. Collection of Personal Data of Minors, Incompetent Persons, or Quasi-Incompetent Persons

In cases where the Company needs to process the personal data of minors, incompetent persons, or quasi-incompetent persons, the following procedures will be adhered to:

1. Consent Requirement

If the data subject is a minor, an incompetent person, or a quasi-incompetent person, consent must be obtained from the parent, guardian, custodian, or legal representative, as applicable (unless otherwise permitted by law). The Company may process your data to provide you with services for which you have given consent, complying with personal data protection laws and ensuring the highest level of data protection under the following conditions.

1. Minors
Refers to individuals who have not yet reached legal age but can independently perform actions appropriate to their status, such as educational activities, enrolling in extra courses for additional knowledge, or entering employment contracts related to business or activities they can legally undertake. For the purpose of providing consent, minors may be treated as if they have reached legal age, except where specific laws require the consent of a legal guardian. For minors under the age of 10, consent must be obtained directly from the guardian.

2. Quasi-Incompetent Persons
Refers to individuals declared by a court as quasi-incompetent due to physical disability, mental instability, habitual reckless behavior, addiction to intoxicants, or other similar reasons that prevent them from managing their own affairs or protecting their property and family interests. Consent must be obtained from the legal representative before processing personal data, except where specific laws allow certain actions without such consent.

3. Incompetent Persons
Refers to individuals declared by a court as incompetent due to mental illness. Consent must be obtained from the custodian before processing personal data.

2. Direct Consent

In cases where consent from a parent, guardian, custodian, or legal representative is required, the Company will directly seek consent from the authorized individual and only proceed based on that consent. The Company operates under the good faith assumption that the information provided by these authorized individuals is accurate and that they have the right to disclose such information to the Company. The Company will follow the procedures outlined in the Privacy Notice specific to each type of activity.

6. Use and Disclosure of Personal Data

  1. The Company will use personal data only for the purposes communicated to the data subject. In cases where additional personal data is needed or there is a change in the purpose of data collection, use, or disclosure, the Company will inform the data subject before proceeding unless required or permitted by law.
  2. The Company will use personal data appropriately. In cases where the Company utilizes information technology services from external providers, the Company will ensure the security and control of access, use, and disclosure of personal data. The Company will supervise its employees, service providers, or agents to ensure they do not use or disclose your personal data beyond the purposes specified by the Company or disclose it to third parties.
  3. The Company may disclose your personal data, whether currently stored or to be stored in the future, to companies within the Learn Corporation Group (Public Company Limited) listed on the website www.learn.co.th, partners, business associates, individuals, or legal entities within the agreed scope as mutually agreed.

7. Privacy Policy for Personal Data Processing

1. Principle of Personal Data Processing

The company will process personal data both as a data controller and data processor accurately and in compliance with the law, ensuring fairness, transparency, and data accuracy. This includes defining the scope and purposes of processing personal data, as well as the storage duration, to the extent necessary under legal objectives and the company's business guidelines.

2. Data Management Controls

We establish clear processes and controls to manage personal data at every stage, aligning with legal requirements and our company's data protection policies.

3. Records of Processing Activities (ROPA)

We create and maintain Records of Processing Activities (ROPA) to record all processing activities related to personal data, ensuring compliance with the law and updating ROPA as activities change.

4. Privacy Notices and Consent

We provide clear Privacy Notices detailing the purposes of data collection and processing, obtain consent from data subjects in accordance with the law, and implement measures for data protection and consent management.

5. Access Controls

We grant access to personal data only to individuals who need it for their roles or as specified in contracts, ensuring compliance with legal obligations and limiting access based on job responsibilities. In the cases where the Company processes personal data, the processing will only be done by adhering to written contracts and professional responsibilities while lawfully abiding by the protection of personal data pertaining to data processing.

6. Data Transfers

In cases of data transfers to third parties, we establish agreements to define rights and responsibilities, ensuring legal compliance and alignment with our data protection policies.

7. International Data Transfers

For international data transfers, we adhere to legal requirements and standards.

8. Data Retention and Destruction

We securely destroy personal data when it reaches the end of its retention period, following legal requirements and our business practices.

9. Risk Assessment and Mitigation

We assess risks and implement measures to mitigate risks and minimize the impact of data processing activities.

10. Policy Reviews and Updates

We regularly review and update policies, standards, guidelines, procedures, and related documents to ensure compliance with the law and adapt to changing circumstances.

8. Retention Period for Personal Data

The company will retain personal data of data subjects according to the type of activity and purposes of personal data processing as specified in the Privacy Notice on the company's website. After the specified retention period mentioned above, the company will delete or destroy such personal data from the company's systems and from any third parties providing services to the company (if applicable), anonymize the data to the extent that the data subject cannot be identified, or take any other actions as required by data protection laws to ensure the effective protection of personal data, unless the company is legally allowed to continue retaining such personal data under data protection laws or other relevant laws.

In any cases, the company may retain personal data of data subjects beyond the specified retention period if permitted by law or if such retention is necessary for the establishment of the company's legal rights, compliance with the law, or compliance with orders from authorized employees or government agencies, and for business purposes or as required by law.

9. Rights of Data Subjects

The Company grants rights to data subjects as stipulated by data protection laws as follows:

  1. Right to withdraw consent for the processing of personal data throughout the period when the personal data is with the company
  2. Right to access and request a copy of personal data and right to request disclosure of the means of obtaining personal data
  3. Right to receive personal data in a readable or usable format
  4. Right to object to the processing of personal data at any time
  5. Right to request the company to delete, destroy, or anonymize personal data
  6. Right to request the company to suspend the use of personal data
  7. Right to request the company to ensure that the personal data is accurate, up-to-date, complete, and not misleading
  8. Right to file complaints if the company, employees, or contractors of the company violates or fails to comply with data protection laws regarding personal data processing through the data processing complaint form.

The company respects your rights as a data subject and provides opportunities for you to select the method of control or communication methods used by the company. The company will act according to your requests to promote transparency, data quality, and data accuracy. Any requests to exercise your rights as stipulated by law must be in writing through the electronic system provided on the company's website, or if you wish to withdraw consent, you can access the settings in the application where you are a member or fill out the data subject rights request form.

10. Personal Data Security

The company recognizes the importance of maintaining the security of your personal data. Therefore, appropriate measures are in place to prevent loss, unauthorized access, destruction, use, alteration, modification, or disclosure of personal data unlawfully. This includes setting policies, regulations, practices, and procedures as follows:

  1. Establish clear policies and procedures for the protection of personal data and manage data in compliance with legal requirements securely.
  2. Do not sell or trade your personal data under any circumstances and do not transfer your personal data to any party other than the company’s data processors.
  3. Restrict the rights of the company’s employees to access personal data and set rights for accessing or using personal data of data subjects to maintain confidentiality and data security.
  4. Prevent unauthorized access and use of personal data by implementing necessary encryption, authentication, and virus detection technologies.
  5. Verify the status of the company's partners, requiring them to comply with legal and regulatory standards on personal data protection and set limitations on the use of personal data.
  6. Monitor the company's website through entities specializing in personal data protection and security.
  7. Require company employees to undergo training on personal data protection and data security.
  8. Evaluate practices regarding personal data protection, data management, and technical, physical, and administrative data security measures as appropriate. Review security measures when necessary or when technology changes.
  9. Implement audit systems to delete or destroy personal data when the retention period expires or when the data is irrelevant or exceeds the necessity for the purpose of personal data collection.
  10. Establish a system for reporting personal data breaches to the Office of the Personal Data Protection Commission within 72 hours of becoming aware of the breach, unless the breach poses no risk to the rights and freedoms of individuals.

12. Use of Personal Data for Original Purposes

If the company collected your personal data before the Personal Data Protection Act regarding the collection, use, or disclosure of personal data came into effect, the company will continue to collect and use your personal data for the original purposes. You have the right to withdraw your consent at any time by contacting the company through the consent withdrawal form or managing your consent in the personal data management settings in the company’s application where you are a member.

13. Contact Information

The Company has assigned Learn Corporation Public Company Limited as the coordinator for the Company’s personal data protection. If data subjects have any questions or wish to exercise their rights as outlined in this policy, they can contact:
Data Protection Officer (DPO)

  • Email: DPO@Learn.co.th
  • Address: 444 MBK Tower, 14th Floor, Phayathai Road, Wang Mai, Pathum Wan, Bangkok 10330

14. Review

The Company may occasionally update, modify, or amend this Privacy Policy to comply with legal guidelines. The Company will notify you of any changes through the its website and/or platform.