Privacy & Policy

Personal Data Protection Policy for Patients Receiving Medical Examination and Treatment Services, BDMS Wellness Clinic Company Limited

 

Personal Data Protection Policy for Patients Receiving Medical Examination and Treatment Services, BDMS Wellness Clinic Company Limited

BDMS Wellness Clinic Company Limited (the “Company”) is committed to protecting your personal data as a recipient of medical examination, treatment, and medical services, as well as other services provided by the Company. Your personal data is protected under the Personal Data Protection Act B.E. 2562 (2019). As the data controller, the Company has a legal duty to inform you, through this document, of the reasons and methods by which the Company collects, uses, or discloses your personal data, and to inform you of your rights as a data subject.

Definitions
“Personal Data” means any information relating to a person which enables that person to be identified, whether directly or indirectly, but excluding information of deceased persons in particular.
“Sensitive Personal Data” means personal data relating to race, ethnicity, political opinions, cult, religious or philosophical beliefs, sexual behaviour, criminal records, health data, disability, trade union information, genetic data, biometric data (such as facial recognition data, iris recognition data, fingerprint recognition data), or any other data which affects the data subject in a similar manner as prescribed by the Personal Data Protection Committee.

“Medical Treatment Data” means the following information:

  • Date of receiving treatment
  • History of drug allergies and history of adverse drug reactions
  • History of food allergies
  • Names of diagnosed diseases, names of procedures, and names of surgeries
  • Blood test results, laboratory test results, pathological tissue examination results, radiological images, and radiological reports
  • Medications prescribed by physicians
  • Other information such as symptoms, physicians’ recommendations, and details of diagnoses

“Process” means to collect, use, or disclose.

“Data Controller” means a person or juristic person having the power and duty to make decisions regarding the collection, use, or disclosure of personal data.

“Data Processor” means a person or juristic person who collects, uses, or discloses personal data pursuant to the orders of, or on behalf of, a data controller, whereby such person or juristic person is not a data controller.

“Bangkok Dusit Medical Services Group” means companies within the network of Bangkok Dusit Medical Services Public Company Limited, both existing at present and established in the future, whether registered in Thailand or abroad, which includes BDMS Wellness Clinic Company Limited.

“Network Healthcare Facilities” means healthcare facilities within the group or network of Bangkok Dusit Medical Services Public Company Limited, operating both in Thailand and abroad, which includes BDMS Wellness Clinic Company Limited.

Purposes of Data Processing
We will process your personal data for the following purposes:

  Purpose Data Type Lawful Basis for Processing
1.

For the purpose of medical examination, treatment, and the provision of medical services

1.1. Provision of medical services within the Company’s healthcare facility

The Company’s physicians, nurses, and/or other members of the healthcare team will record your personal data, use your personal data for consultation with physicians or medical personnel, including taking still photographs and video recordings for treatment follow-up, and/or perform any acts in accordance with relevant professional standards throughout the period you receive services. The Company will explain the details to you before proceeding and give you the opportunity to ask questions until you are satisfied.

1.2. Provision of medical services where it is necessary to link data between Network Healthcare Facilities

For the benefit of providing medical services to you, the Company’s physicians, nurses, and/or other relevant personnel may disclose your personal data to Network Healthcare Facilities where it is necessary to share data between Network Healthcare Facilities for certain types of services. The Company has put in place personal data protection measures under mutual agreements among the Network Healthcare Facilities to prevent your personal data from being processed unlawfully or without authority.

1.3 For patient transfer between healthcare facilities (Refer)

Where the Company makes or receives a request to transfer a patient from one healthcare facility to receive further examination and treatment at another healthcare facility, or makes or receives a request to admit a patient from another healthcare facility for treatment at the Company’s healthcare facility under the inter-facility patient referral process (Refer), the Company will follow the patient referral procedures prescribed under the Company’s standards and will use your personal data solely for the purpose of the patient referral and for no other purpose.

- Personal identification data

- Contact data

- Health data

- Financial data

1. It is necessary for the performance of the medical treatment contract to which you are a party with the Company (Section 24 (3)).

2. For sensitive personal data: the legal basis of compliance with laws relating to medical diagnosis and treatment, such as the Sanatorium Act B.E. 2541 (1998) and the Medical Profession Act B.E. 2525 (1982) (Section 26 (5) (a)).

3. For sensitive personal data: to prevent or suppress danger to life, body, or health where the data subject is incapable of giving consent, such as receiving services in emergency cases (Emergency Care) or for patient transfer between hospitals (Refer) (Section 26 (1)).

2.

For the purpose of study and analysis to improve the quality of medical treatment without identifying the data subject

The Company may use your personal data for study and analysis to improve the quality of medical treatment, in the form of aggregate reports that do not identify the data subject, and the Company will strictly maintain the confidentiality of such data.

Statistical data

For the legitimate interest of the Company (Legitimate Interest) in analysing statistical data without using identifiable personal data, in order to develop and improve the organisation’s efficiency in medical treatment and the Company’s services (Section 24 (5)).

3.

Disclosure of data to insurance companies with which you or the Company is a contracting party, for the purpose of claiming compensation from the insurance company or exercising the right to reimburse medical expenses

The Company needs to disclose your personal data to insurance companies for the performance of the contract that you or the Company has entered into with the insurance company, for the benefit of claiming compensation or exercising the right to reimburse medical expenses. The Company will not disclose your personal data to any other unrelated persons.

- Personal identification data

- Contact data

- Health data

Upon receiving your explicit consent to disclose personal data that constitutes health data to insurance companies, for the benefit of claiming compensation from the insurance company or exercising the right to reimburse medical expenses (Section 26).

4.

Disclosure of data to the party who referred you for examination or who pays on your behalf, where you have consented to the disclosure of personal data

Where an organisation — whether governmental, private, or a state enterprise — refers you for examination and treatment with the Company or pays for your examination and treatment services, the Company will disclose your examination and treatment data, which constitutes sensitive personal data, to such party only where you have given consent to the disclosure of your personal data to such party. If you have not given such consent, the Company will deliver the examination results to you directly.

- Personal identification data

- Contact data

- Health data

Upon receiving your explicit consent to the disclosure of personal data (Section 26).

5.

For the purpose of linking electronic medical record databases between healthcare facilities via mobile application

Where you give consent, the Company will enter your personal data into a computer system in the form of a mobile application to facilitate your receipt of consultations through the application and to enable you to manage your data through the application. For maximum benefit, the system will link electronic medical record databases among Network Healthcare Facilities so that you can view your personal data held by Network Healthcare Facilities through various electronic devices. The Company has agreements with Network Healthcare Facilities to protect your personal data in accordance with the Personal Data Protection Act B.E. 2562 (2019).

- Personal identification data

- Contact data

- Health data

Upon receiving your explicit consent to the disclosure of health data between healthcare facilities (Section 26).

6.

For the Company’s marketing purposes

The Company may collect, use, and process personal data to analyse your health condition and to contact and communicate with you, send medical news and information, and present promotions, products, and services to you as you have consented.

- Personal identification data

- Contact data

- Newsletter subscription and marketing activity participation data

The Company may carry out these activities after receiving your consent for the Company to use health data for marketing purposes (Section 26).

7.

For the performance of the contract with you in your capacity as a service provider to the Company, or to proceed with your request to enter into a contract with the Company

The Company will process your personal data in your capacity as a service provider to the Company for operations such as:

  • Communicating with you in activities relating to the contract, both before and after entering into the contract
  • Making payments and any remuneration relating to the performance of the contract
  • Verifying the completeness and success of work under the contract
  • Retaining personal data for internal audit purposes (Internal Audit) and audits in accordance with business standards
 

It is necessary for the performance of the contract with you in your capacity as a service provider to the Company, or to proceed with your request to enter into a contract with the Company (Section 24 (3)).

Apart from the purposes stated above, the Company will not use your personal data for any other purposes, except

where permitted by the Personal Data Protection Act B.E. 2562 (2019), such as:

  • Where your consent has been obtained (Section 24), or where your explicit consent has been obtained in the case of the use of sensitive personal data (Section 26)
  • For research or statistical purposes for which suitable protective measures are in place to safeguard the personal data and the rights and freedoms of the data subject (Section 24 (1))
  • To prevent or suppress danger to life, body, or health (Section 24 (2))
  • For the performance of a contract between the Company and you (Section 24 (3))
  • For the performance of a task carried out in the public interest by the Company (Section 24 (4))
  • For the legitimate interests of the Company (Legitimate Interest) or of other persons or juristic persons, except where such interests are overridden by the fundamental rights of the data subject (Section 24 (5))
  • For the Company’s compliance with the law (Section 24 (6))
  • To prevent or suppress danger to life, body, or health where the use of sensitive personal data is involved and the data subject is incapable of giving consent, whatever the case may be (Section 26 (1))
  • For the establishment of legal claims (Section 26 (4))
  • For the benefit of public health or other social protection, for which the Company provides suitable measures to protect the fundamental rights and interests of the data subject (Section 26 (5) (b))
  • Where necessary for compliance with laws on labour protection, medical welfare benefits, and social security (Section 26 (5) (c))

Personal Data the Company Collects from You
Your personal data collected by the Company can be classified into the following categories:

  1. Personal identification data (Personal data), such as name, surname, national ID card number, facial photograph, gender, date of birth, passport, or other identification numbers
  2. Contact data (Contact data), such as address, telephone number, email
  3. Financial data (Financial data), such as billing information, credit or debit card information, receipt information, quotation information
  4. Newsletter subscription and marketing activity participation data (Marketing Data), such as data used to register to receive news and participate in marketing activities
  5. Statistical data (Statistical Data), such as non-identifiable data, patient numbers, and website visit counts
  6. Website usage data (Technical data), such as computer IP address, browser type, Cookies data, time zone settings, operating system, platform and technology of the device used to access the website, and the Online Appointment System
  7. Health data (Health data), such as medical treatment data, reports relating to physical and mental health, patient healthcare records, laboratory test results, diagnoses, names of diagnosed diseases, data relating to medication use and drug allergies, food allergy history, blood test results, laboratory examination results, pathological tissue examination results, radiological images and radiological reports, medications prescribed by physicians, data necessary for the provision of medical services, feedback data, and treatment outcomes

Sources of Personal Data
The Company collects your personal data from the following sources:

  1. Personal data obtained directly from you, namely:
    1. Where you are a recipient of medical examination and treatment services: the Company obtains your personal data from your enquiries with the Company regarding services, or from your registration for medical services and other services from the Company in person at the Company, including registration through electronic media
    2. Where you are a service provider (Vendor) of the Company: the Company obtains your personal data from your enquiries with the Company in order to provide services to the Company, or from the Company’s collection of your personal data in your capacity as a service provider entering into a contract with the Company
  2. Personal data obtained indirectly, namely from:
    1. Persons close to you, such as relatives, spouses, etc.
    2. Persons authorised by you to act on your behalf in contacting the hospital
    3. Network Healthcare Facilities, where you have given consent to the Network Healthcare Facilities to disclose your personal data
    4. Persons, juristic persons, or organisations — whether governmental, private, or state enterprises — that refer you for examination, treatment, or services with the Company, or that pay for services on your behalf

Disclosure or Sharing of Personal Data
The Company will not disclose your personal data to third parties, except where permitted by law as necessary for its operations, in which cases the Company may disclose personal data as follows:

  1. Disclosure of personal data to government agencies, competent authorities, or any persons where required or empowered by law, including compliance with court orders
  2. Disclosure of personal data to persons or juristic persons where the Company is required to perform under a contract or for your benefit as the data subject, whereby the Company requires such persons or juristic persons to maintain confidentiality and protect your personal data in accordance with the standards prescribed by the Personal Data Protection Act B.E. 2562 (2019), including but not limited to the following persons or juristic persons:
    1. Network Healthcare Facilities and the Bangkok Dusit Medical Services Group, to the extent necessary for providing medical examination, treatment, and medical services to you. The Company will disclose only the personal data that is necessary and will maintain the confidentiality of your personal data in accordance with the Company’s duties under relevant laws, such as the Sanatorium Act B.E. 2541 (1998), the National Health Act B.E. 2550 (2007), and the Medical Profession Act B.E. 2525 (1982)
    2. Insurance companies, or claims administration service providers of such insurance companies
    3. Healthcare facilities receiving patient referrals
    4. Parties who refer you for examination, treatment, or services with the healthcare facility, or who pay service fees on your behalf
    5. Data processors necessary for the Company’s operations, such as contractors or service providers for laboratory testing, data preparation, telecommunications, computer systems, payment, or technology services (Technology Outsource)
  3. The Company may store personal data in cloud computing systems (Cloud Computing) using third-party services, whether located in Thailand or abroad, whereby the Company has entered into agreements with such parties with care and with consideration of the data storage security systems that the Cloud Computing service provider offers for the protection of personal data

Personal Data Retention Period

  1. The Company will retain your personal data in the medical records section in the Company’s systems for a period of at least 5 years from the date the Company created or amended the documents containing such data, which is the period reasonably expected to be used for the treatment of illness and follow-up after treatment, or possibly longer where the healthcare facility can still lawfully process such data or for the benefit of your medical treatment or as requested by you, but no longer than 10 years
  2. Upon expiry of the period under Clause 1, the Company will destroy such personal data in accordance with the Company’s data destruction procedures
  3. Where the Company is required to comply with the law or court orders, or to establish legal claims for the purpose of entering into any dispute resolution process, the Company may retain personal data for the period of the legal prescription period, or until such dispute reaches a final conclusion, as the case may be

Measures for the Retention and Processing of Personal Data

  1. The Company will manage the retention of personal data with measures no less stringent than the level required by law and with appropriate systems to prevent and secure personal data, such as using security protocols (Secure Sockets Layer: SSL), protection by firewalls, passwords, and other technical measures for encrypting data transmitted via the internet, and storing personal data in document form in locations with access-control systems limiting the persons who can gain access
  2. The Company limits access to personal data that may be accessed by employees, agents, business partners, or third parties. Access to personal data by third parties may be carried out only as prescribed or as instructed, and such third parties are obliged to maintain confidentiality and protect the personal data
  3. The Company provides technological methods to prevent unauthorised access to its computer systems
  4. The Company has audit systems in place to manage the destruction of personal data that is no longer necessary for the Company’s operations
  5. In the case of sensitive personal data, the Company will provide security measures for both documents and electronic data in terms of access and usage control, with operational and backup systems together with contingency plans for emergencies, and with regular risk assessments of the systems

Transfer of Personal Data Abroad

  1. In some cases, the Company may need to transfer your personal data abroad. The Company may do so after informing you of the purpose of such action and obtaining your consent, whereby the Company will inform you of the potentially inadequate personal data protection standards of the destination country
  2. The Company may transfer your personal data without requesting your consent where the transfer of personal data abroad is for the performance of a contract to which you are a party, or in order to carry out your request prior to entering into that contract, or as otherwise prescribed under the Personal Data Protection Act B.E. 2562 (2019)

Cookie Policy
When you visit the Company’s website, the Company uses cookies to ensure that you receive a good experience from using the Company’s website. Cookies are small files that store data and are recorded onto your computer or communication device through the web browser you choose to use while you visit the website.

The Company uses cookies to store the unique characteristics of your website visits. These unique identifiers enable the Company to more easily recognise your website usage patterns, and this information is used to improve the Company’s website to better suit your needs and to make your use of the website more convenient and faster. In some cases, the Company needs to engage third parties to perform such activities, which may require the use of internet protocol addresses (IP Address) and cookies for analysis, data linkage, and processing for marketing purposes. You can configure cookie settings when you access the Company’s website, and you can choose whether or not to allow cookies to perform analysis, data linkage, and processing for marketing purposes.

Rights of the Data Subject

As a data subject, you have the right to request that the Company take action regarding your personal data within the scope permitted by law, as follows:

  1. Right to withdraw consent (right to withdraw consent): You have the right to withdraw your consent to the processing of personal data for which you have given consent to the Company, at any time during the period your personal data is held by the Company
  2. Right of access (right of access): You have the right to access your personal data and to request that the Company make a copy of such personal data for you, as well as to request that the Company disclose how it obtained personal data that you did not give consent to the Company to collect
  3. Right to rectification (right to rectification): You have the right to request that the Company correct inaccurate data or complete incomplete data
  4. Right to erasure (right to erasure): You have the right to request that the Company delete your data for certain reasons
  5. Right to restriction of processing (right to restriction of processing): You have the right to request that the Company suspend the use of your personal data for certain reasons
  6. Right to data portability (right to data portability): You have the right to transfer your personal data that you have provided to the Company to another data controller, or to yourself, for certain reasons
  7. Right to object (right to object): You have the right to object to the processing of your personal data for certain reasons

You may contact the Data Protection Officer (DPO) to submit a request to exercise the above rights at: Mr. Nawarat (นายนวรัตน์ รัตน์นราทร), BDMS Wellness Clinic Company Limited, 2/4 Wireless Road, Lumpini, Pathumwan, Bangkok 10330, telephone 02-826-9999, email [email protected]

Changes to the Personal Data Protection Policy
The Company may review and amend this Personal Data Protection Policy in the future to further improve the protection of personal data. The Company will notify you every time such policy is changed.


Contact Channels
You may contact the data controller to make enquiries or exercise any rights relating to personal data at: Mr. Nawarat (นายนวรัตน์ รัตน์นราทร), BDMS Wellness Clinic Company Limited, 2/4 Wireless Road, Lumpini, Pathumwan, Bangkok 10330, telephone 02-826-9999, email [email protected]