Privacy Policy
S 45 Medical Group Co., Ltd. (“the Company”) recognises the importance of the privacy of its customers. The Company has therefore prepared this personal data protection policy for customers (“this Privacy Policy”) to set out clear rules for protecting the personal data of customers who use the Company’s services, and to ensure that customers’ personal data is handled in accordance with the Personal Data Protection Act B.E.2562 (A.D.2019) (and any future amendments).
This Privacy Policy applies to the personal data (as defined in section 1 below) of the Company’s individual customers, and of employees, staff, officers, representatives, shareholders, authorised persons, directors, contact persons, agents and other individuals connected with the Company’s corporate customers, whether they are prospective customers (people who may become customers in the future), current customers or former customers. This Privacy Policy explains how the Company collects, uses, discloses and/or transfers customers’ personal data to third parties or to recipients in other countries.
1. Personal Data the Company Collects
“Personal data” means information about a customer that identifies the customer or can be used to identify the customer, as set out below. This information is important and necessary for the Company to provide services to customers. The Company may collect customers’ information in different ways, such as directly from the customer, or indirectly from other sources (for example, social media, third-party online platforms or other public sources), and through its affiliated companies, service providers, business partners, government authorities or other third parties. The types of information the Company needs to collect depend on the customer’s relationship with the Company and the services or products the customer requires from the Company. The customer personal data that the Company will collect, use, disclose and/or transfer to third parties or to recipients in other countries includes, but is not limited to, the following types of personal data:
1) Personal details, such as title, name, sex, age, height, weight, occupation, job title, income, workplace, position, education, nationality, date of birth, marital status, information on documents issued by government authorities (such as national ID card, house registration, passport and driving licence), signature, voice recordings, recordings of telephone conversations, photographs, CCTV images and video, house registration and other identifying information
2) Contact details, such as address, telephone number, mobile phone number, fax number, email address and account names or identifiers for other electronic communication, and the personal data of relatives or people who can be contacted in an emergency
3) Service information, such as information on doctor appointments, preferences for rooms, food and other additional services, and feedback on treatment results and/or services that the customer gives to the Company
4) Account and financial information, such as credit or debit card details, account numbers and account types, PromptPay details, assets, income and expenses, payment information, and information on applications for services and products
5) Transaction information, such as types of products and/or services, prices and quantities, order numbers, conditions (if any), service history, balances, payment history and the customer’s related transaction history
6) Technical information, such as IP address (internet protocol address), web beacons, logs, device ID, device model and device type, network, connection information, access information, single sign-on (SSO) information, login logs, access times, time spent on the Company’s pages or website, cookies, login information, search history, browsing information, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the device the customer uses to access the Company’s service platforms
7) Usage information, such as information on the customer’s use of the website, platforms, products and services, and
8) Information on subscribing to news and taking part in marketing activities, such as registering to attend a seminar
“Sensitive data” means personal data that is genuinely private to a person but is sensitive and at risk of being used for unfair discrimination, so it must be handled with particular care. The Company will collect, use, disclose and/or transfer sensitive data to third parties or to recipients in other countries (if any) only with the customer’s explicit consent, or where the law allows it.
The customer sensitive data that the Company will collect, use, disclose and/or transfer to third parties or to recipients in other countries includes:
1) Health information, such as medical treatment information, service history, information on medicines used and drug allergies, response to treatment, long-term health conditions and blood group
2) Biometric data, such as face, iris, fingerprints, photographs taken as part of treatment, and photographs taken before and after treatment
3) Other sensitive data shown on identity documents, such as ethnicity and religion
2. Purposes of Collecting and Using Personal Data
To provide services to customers, the Company needs to collect, use, disclose and/or transfer personal data and sensitive data to third parties or to recipients in other countries (if any) for the Company’s business operations, providing medical services to customers, communication, establishing or exercising legal claims, and contacting external organisations, in order to meet the Company’s obligations as a service provider, for the benefit of its business operations, to comply with the law, and/or for the legitimate interests of the Company and/or the customer. The Company will strictly comply with this Privacy Policy.
The Company will only request the customer’s information as far as necessary and as permitted by law. If, for any reason, the Company cannot collect, use, disclose and/or transfer the customer’s personal data to third parties or to recipients in other countries (if any) as set out in this Privacy Policy, the Company may not be able to perform its contract with the customer, and in some cases the Company may no longer be able to provide services to the customer.
The Company may collect, use, disclose and/or transfer customers’ personal data and sensitive data to third parties or to recipients in other countries for the following purposes:
2.1. Purposes for Which the Company Can Process Customers’ Personal Data on a Legal Basis Without the Customer’s Consent
In the following cases, the Company may collect, use, disclose and/or transfer the customer’s personal data to third parties or to recipients in other countries without asking for the customer’s consent:
1. It is necessary to perform a contract with the customer, or to act on the customer’s request before entering into a contract
2. It is to comply with the Company’s legal obligations
3. It is necessary for the legitimate interests of the Company and of third parties, provided that such necessity is balanced against the customer’s interests and fundamental rights and freedoms relating to the protection of their personal data
4. It is to prevent or suppress a danger to a person’s life, body or health
5. It is necessary to carry out a task in the public interest by the Company, or to exercise official authority given to the Company
However, the Company will rely on the legal bases in (1) to (5) above to collect, use, disclose and/or transfer the customer’s personal data to third parties or to recipients in other countries only for the following purposes:
1. Contacting the customer about using services and/or entering into legal transactions with the Company
2. Providing medical services and other related services under a contract or business agreement between the Company and the customer, such as:
- providing or delivering services, and the customer’s access to services, through any channel
- booking doctor appointments and sending appointment reminders
- offering help from the Company and giving details of the Company’s services
- coordinating with and passing information to other healthcare facilities that need to admit the customer for further treatment
- verifying the customer’s identity to receive the Company’s services
- accounting or financial purposes, such as checking credit card payments, billing and verification, and refunds
- maintaining security while using services or staying for recovery after receiving services
- complying with laws, requirements, regulations, rules or any requests from relevant government authorities, such as complying with a witness summons, a court order or other valid requests in line with the law
- other purposes that support the purposes above
3. Managing the relationship between the customer and the Company, and managing the customer’s accounts with the Company
4. Carrying out the customer’s instructions, responding to the customer’s questions or comments, and resolving the customer’s complaints
5. Identity verification, other checks and screening, and ongoing monitoring that may be required under applicable law
6. Complying with laws, regulations, rules, guidelines, orders, recommendations and requests from government authorities, tax authorities, law enforcement authorities, regulators or other authorities (whether in Thailand or abroad)
7. Managing the Company’s infrastructure, internal controls, audits, business operations and compliance with the Company’s policies and procedures that may be required by applicable laws and regulations, including laws and regulations on risk control, security, auditing, finance and accounting, systems and business continuity
8. Handling or investigating complaints, claims or disputes
9. Enforcing the Company’s legal or contractual rights, including but not limited to collecting any amounts owed to the Company
10. Financial audits carried out by auditors, or receiving legal services from legal advisers
2.2. Purposes for Which the Company Needs the Customer’s Consent Before Processing Personal Data
The Company may process the customer’s personal data for the following purposes with the customer’s consent:
1) Marketing communications, special offers and promotional materials about the products and services of the Company, its affiliated companies and subsidiaries, and third parties, where the Company cannot rely on another legal basis
2) Developing services, presenting new products, and giving customers up-to-date information about the Company’s services and products from time to time
3) Research, planning and statistical analysis for the purpose of developing the Company’s services and products
4) Organising sales promotion projects or activities, meetings, seminars and visits to the Company
The customer has the right to withdraw consent at any time by contacting our Customer Relations team at pdpa@s45clinic.com. Withdrawing consent does not affect the lawfulness of the collection, use and disclosure of the customer’s personal data and sensitive data based on the customer’s consent before the withdrawal, or of any collection, use, disclosure and transfer of sensitive data to third parties or to recipients in other countries (if any) that the Company is entitled to carry out without the customer’s consent.
2.3. Purposes for Using Sensitive Data
The customer has the right to withdraw consent at any time by contacting our Customer Relations team at pdpa@s45clinic.com. Withdrawing consent does not affect the lawfulness of the collection, use and disclosure of the customer’s personal data and sensitive data based on the customer’s consent before the withdrawal, or of any collection, use, disclosure and transfer of sensitive data to third parties or to recipients in other countries (if any) that the Company is entitled to carry out without the customer’s consent.
1) Health information, such as medical treatment information, service history, information on medicines used and drug allergies, response to treatment, long-term health conditions and blood group, to provide medical services to the customer under a contract or business agreement between the Company and the customer
2) Biometric data (namely [facial recognition, fingerprints]) for [registering for services, and verifying and confirming identity]
3) Religion, to make it easier for the customer to use the services
4) Sensitive data shown on identity documents (such as ethnicity and religion), to verify and confirm identity and to provide medical services to the customer under a contract or business agreement between the Company and the customer
3. Third Parties to Whom the Company May Disclose or Transfer Customers’ Personal Data
The Company may disclose and/or transfer the customer’s personal data to the following third parties (including the staff and representatives of those third parties) in Thailand or outside Thailand, who process personal data to provide medical services to the customer or for other purposes under this Privacy Policy. The customer can read the privacy policies of those third parties to learn more about how they process the customer’s personal data.
1) Group companies. The customer’s personal data may be accessed by or disclosed to other legal entities within the group of companies, including directors, executives, employees, staff or any other people connected with those entities, to provide medical services to the customer, analyse data, report the Company’s performance, and manage risk or carry out internal audits of the group.
2) The Company’s service providers. The Company may use individuals, legal entities, agents or contractors to provide services on the Company’s behalf, or to help and support the supply of products and services to customers. The Company may disclose the customer’s personal data to these service providers, including but not limited to (a) information technology service providers, (b) research agents, (c) analysis and/or laboratory service providers, (d) survey agents, (e) marketing, advertising and communication agents, (f) payment service providers and (g) administrative and operational service providers.
To provide the services above, service providers may need to access the customer’s personal data. However, the Company will only give service providers the personal data needed for them to provide those services, and the Company will make sure that every service provider it works with keeps the customer’s personal data secure and does not use it for any purpose other than providing services to the Company.
3) The Company’s business partners. The Company may disclose or transfer the customer’s personal data to its business partners who take part in providing medical services to the customer, or who are involved in supplying any products or services that the customer receives from the Company, such as co-brand partners, market counterparties and co-issuers of products. The Company will make sure that every business partner it works with keeps the customer’s personal data secure and does not use it for any purpose other than providing services to the customer.
4) Third parties as permitted by law. In some cases, the Company may need to disclose or transfer the customer’s personal data to third parties to meet legal or regulatory obligations, including complying with orders from law enforcement authorities, courts, regulators, government authorities or other third parties as required by law.
5) Professional advisers. The Company may disclose or transfer the customer’s personal data to its professional advisers for audit, legal, accounting and tax services, who help with running the business or handling legal claims.
6) Third parties involved in a business transfer. The Company may disclose or transfer the customer’s personal data to business partners, investors, major shareholders, assignees, potential assignees, transferees or potential transferees of the Company in the event of a business rehabilitation, restructuring, merger, acquisition, sale, purchase, joint venture, transfer, dissolution or any similar event involving the transfer or disposal of all or any part of the Company’s business, assets or shares. If any such event happens, the recipient of the data will comply with this Privacy Policy with regard to the customer’s personal data.
4. Requirements for Transferring Customers’ Personal Data to Recipients in Other Countries
The Company may disclose or transfer the customer’s personal data to third parties or to servers located in other countries, where the destination country may or may not have data protection standards similar to those in Thailand. The Company will follow procedures and measures to make sure that the customer’s personal data is transferred securely, that the recipient has appropriate personal data protection standards, and that the transfer is lawful.
5. Links to Third-Party Websites
The Company’s website may contain links to third-party websites. If the customer visits a website through such a link, this Privacy Policy does not cover the use of the customer’s personal data on that third-party website. The processing of the customer’s personal data by the third party that controls such a website is therefore outside the Company’s control, and the Company is not involved in and accepts no liability for the actions of such third parties.
6. Keeping Customers’ Personal Data
The Company will keep the customer’s personal data for as long as is reasonably necessary to achieve the purposes for which the Company received it, as set out in this Privacy Policy, and to meet its legal and regulatory obligations. However, the Company may keep the customer’s personal data for longer if required by applicable law.
After that period, if the customer does not consent to the Company continuing to process the personal data, the Company will destroy it in line with the Company’s data destruction procedures without delay.
The Company will use appropriate technical and management measures to protect and secure the customer’s personal data that it collects, such as using a security protocol (Secure Sockets Layer: SSL) to encrypt data over the internet. The Company will limit access to the customer’s information, whether stored electronically or on paper, to staff who need to process that personal data, and will store it in places with access protection systems that meet appropriate security standards.
7. Personal Data of Minors, Quasi-Incompetent Persons and Incompetent Persons
In general, the Company’s medical services (including its recruitment process for service staff) are not aimed at minors, quasi-incompetent persons or incompetent persons, and the Company does not intend to collect the personal data of minors, quasi-incompetent persons or incompetent persons. If a minor, quasi-incompetent person or incompetent person wants to receive medical services from the Company, that person must get consent from their parent or person exercising parental authority, curator or guardian before contacting the Company or giving their personal data to the Company, unless the Company can rely on another legal basis to process the personal data of customers who are minors, quasi-incompetent persons or incompetent persons without the customer’s consent.
8. Other Important Information About Customers’ Personal Data
1) Cookies and how cookies are used. When the customer visits the Company’s website, the Company will automatically collect some information from the customer by using cookies. Cookies are a type of tracking technology used to analyse trends, manage the website, track activity on the Company’s website, or remember user settings. Most internet browsers let the customer control whether to accept cookies. If the customer refuses tracking by cookies, the customer’s ability to use the website may be limited, in whole or in part.
2) Personal data about third parties. If the customer gives the Company the personal data of any third party (such as the customer’s spouse and children, people who can be contacted in an emergency, or referrals for emergency treatment), the customer must make sure that they have the authority to give that personal data and to allow the Company to use it under this Privacy Policy. The customer is also responsible for telling those third parties about this Privacy Policy and getting consent from the relevant third parties (if needed), unless the customer can rely on another legal basis to disclose the personal data of those third parties without consent.
9. The Customer’s Rights Over Their Personal Data
Subject to the provisions of the law and the relevant legal exceptions, the customer may have the following rights over their personal data:
1) Access: the customer may have the right to request access to, or a copy of, the personal data that the Company processes about them.
2) Data portability: the customer may have the right to receive the personal data that the Company holds about them in a structured, electronically readable format, and to send or transfer that data to another data controller.
3) Objection: in some cases, the customer may have the right to object to how the Company processes their personal data in certain activities set out in this Privacy Policy.
4) Erasure or destruction: the customer may have the right to ask the Company to erase or destroy the personal data that the Company processes about them, or to make it anonymous so that the data owner cannot be identified, for example if the data is no longer needed for the purpose of processing.
5) Restriction: the customer may have the right to restrict the processing of their personal data if they believe the data is inaccurate, the Company’s processing is unlawful, or the Company no longer needs to process the data for a particular purpose.
6) Rectification: the customer may have the right to ask for personal data that is incomplete, inaccurate, misleading or out of date to be corrected.
7) Withdrawal of consent: the customer may have the right to withdraw the consent they gave to the Company to process their personal data, unless there are legal restrictions on the right to withdraw consent or a contract that benefits the customer.
8) Complaints: the customer may have the right to make a complaint to the relevant authority if they believe the Company has processed their personal data unlawfully or not in line with the applicable data protection law.
10. Changes to This Privacy Policy
The Company may change or update this Privacy Policy from time to time. The Company asks customers to read this Privacy Policy carefully and to check regularly for any changes under the terms of this Privacy Policy at www.s45clinic.com. The Company will notify customers or ask for their consent again if there are any significant changes to this Privacy Policy.
11. Contact Details of the Company
If the customer wants to exercise their rights over their personal data, or has any questions or complaints about their personal data under this Privacy Policy, please contact the Company or its Data Protection Officer at:
S 45 Medical Group Co., Ltd.
- 10/3 and 10/4 Soi Sukhumvit 33/2 (Daeng Udom), Khlong Tan Nuea, Watthana, Bangkok 10110
- pdpa@s45clinic.com
Data Protection Officer
- Branch Manager or Acting Branch Manager, and Branch Sales Manager
- 10/3 and 10/4 Soi Sukhumvit 33/2 (Daeng Udom), Khlong Tan Nuea, Watthana, Bangkok 10110
- pdpa@s45clinic.com

