PDPA Privacy Notice
Personal Data Protection Act B.E. 2562 (2019) Compliance Statement
Last updated: August 21, 2026
1. Purpose and Scope
LUMENTIS (THAILAND) Co., Ltd. ("Lumentis", "we", "our", or "us") issues this Personal Data Protection Notice in compliance with Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA").
This notice informs you, as a data subject, about our policies regarding the collection, use, disclosure, storage, and cross-border transfer of your personal data when interacting with our website and services.
2. Data Controller Information
LUMENTIS (THAILAND) Co., Ltd. acts as the Data Controller responsible for determining the purposes and means of processing your personal data.
3. Categories of Personal Data Collected
We may collect, use, and process the following categories of personal data:
- Identity & Contact Data: Name, surname, company name, business email address, phone number, and project inquiry details.
- Technical & Usage Data: IP address, device identifier, browser type, operating system, geolocation, access logs, and browsing interaction metrics.
- Communication Records: Content of messages, emails, feedback, and inquiries submitted to us.
4. Legal Bases for Processing
Under the PDPA, we process your personal data under the following lawful bases:
- Consent (Section 19): Where you have expressly consented to receiving news, case studies, or marketing materials.
- Contractual Necessity (Section 24(3)): To take steps at your request prior to entering into a commercial project agreement.
- Legitimate Interests (Section 24(5)): For website cybersecurity, preventing fraudulent activities, and enhancing our creative technology services.
- Legal Obligation (Section 24(6)): To comply with applicable statutory laws, tax regulations, and lawful orders from authorities.
6. Data Retention Period
We retain your personal data for the duration necessary to accomplish the purposes outlined in this notice, typically for up to 2 years from our last business interaction, or as required by applicable Thai statute of limitations.
7. Security Measures
We implement industry-standard administrative, physical, and technical safeguards (including TLS/SSL encryption, restricted access control, and network firewalls) to protect personal data against accidental loss, unauthorized access, destruction, or alteration.
8. Data Subject Statutory Rights
Pursuant to Sections 30–36 of the PDPA, you are entitled to exercise the following rights:
- Right to be informed (Section 23)
- Right of access and obtain a copy (Section 30)
- Right to data portability (Section 31)
- Right to object to processing (Section 32)
- Right to erasure / destruction / anonymization (Section 33)
- Right to restriction of processing (Section 34)
- Right to rectification (Section 35)
- Right to withdraw consent (Section 19)
- Right to lodge a complaint with the Personal Data Protection Committee (PDPC) (Section 73)
9. Data Protection Contact
To submit a Data Subject Access Request (DSAR) or inquire about our PDPA compliance, please contact us:
