What this notice covers
This notice explains how personal data is used across our websites, enquiries, user accounts, sales and after-sales services, supplier relationships, projects and events, recruitment and internships, employment and internal work systems. It also covers education, assessment and travel activities provided by the responsible company.
Read this notice together with the activity notice that applies to you. The relevant notice identifies the responsible company, required data, purposes, recipients and retention arrangements. Relevant details are provided before or when data is collected. Publishing a notice or continuing to use a website does not constitute consent to every activity.
The company responsible for your data
TECH Infinity International Solution Co., Ltd. (TIIS) and TECH Infinity Education Co., Ltd. are responsible for the activities whose processing they determine. TIIS operates this corporate website and its enquiry form. For other services, the application, quotation, contract or activity notice identifies the responsible legal company.
Domestic and online assessments are the responsibility of TECH Infinity Education through the Teched Assessment Testing Office (TATO). Overseas travel and assessments held overseas are the responsibility of TIIS through the Educational Innovation & Competency Development Office (EICD). These offices are units of their respective companies, not separate legal entities.
TIMS and privacy contact channels may be shared. Access is allocated by company, activity and role. A disclosure to the other company requires a defined purpose and applicable legal basis, with the information required by law provided to you.
Data and its sources
We use information you provide, such as your name, contact details, organisation, role, service requirements, application history, transaction details and relevant documents. Account and system-use information is used where needed for the service and its security. Required fields and the consequences of not supplying them are identified in the relevant process.
Relevant data may come from schools, guardians, employers, coordinators, business partners or business information made publicly available. We assess necessity, the applicable legal basis and the duty to inform you about the source. Public availability does not permit unrestricted reuse.
Health, biometric and other sensitive data is used only for a necessary activity that meets the applicable legal conditions. General enquiry forms do not request this information. We provide specific information and seek explicit consent where the activity relies on consent.
Purposes and legal bases
Responding to requests, preparing proposals, purchasing, supplying products and providing activities or services uses the basis that fits the relationship. This may be steps requested before a contract, performance of a contract, or assessed legitimate interests, particularly when a contact represents a corporate customer.
Accounting, tax, employment and other statutory duties rely on the obligation applicable to the particular record. Security, internal work coordination and review use the basis appropriate to the activity, with your rights considered. We do not apply every legal basis indiscriminately to all data.
Marketing, promotional use, retention for future recruitment opportunities and other consent-based activities have separate choices identifying the company and purpose. Choices are not preselected. Declining an optional activity does not affect a core service that can proceed on another applicable basis.
Recipients and disclosures
Depending on your service, recipients may include authorised staff, IT, hosting, email and storage providers, payment, delivery, installation or repair providers, event organisers, trainers, advisers or authorities acting under law. Only recipients relevant to the actual activity receive the data needed for their role.
A provider acting on instructions has a different role from a recipient that determines its own processing. Agreements reflect the actual role, and recipient categories or activity-specific details are disclosed as required. An affiliation or commercial relationship does not by itself permit access to all data.
Publication of names, images, schools, work or directory profiles has a defined dataset, channel, purpose and duration. This notice does not make detailed individual scores, personnel records or internal business documents public.
International processing
Some systems or providers may store, back up or access data outside Thailand. The responsible company assesses the actual recipients, countries, onward transfers and safeguards, using a condition or mechanism recognised by Thai law. Foreign cloud use does not justify blanket consent covering every service.
For overseas programmes, the relevant notice identifies the destination and recipients before the transfer. You can request details of safeguards through the privacy contact. A signature collected on the travel date does not replace consent that was required before an earlier collection or disclosure.
Retention and end of use
Retention is set by record type and a relevant starting event, such as case closure, recruitment closure, result publication, contract completion or warranty expiry. The examination retention period does not apply to every system. Activity notices below give the relevant period or criteria.
Data that is no longer needed is deleted, destroyed or made non-identifiable. Records retained for a legal obligation or dispute are limited to what is needed, with restricted access and review. Backups follow their defined rotation and recovery purpose; deletion records must be reapplied after restoration.
Children, minors and representatives
Some services are available to minors. We assess age, legal capacity and a representative’s authority for the activity. Consent-based activities follow section 20, including a guardian’s consent where required. A person who has reached 20 is not treated as a minor merely under an age threshold.
Being a teacher, coordinator, telephone contact or OTP recipient does not itself establish guardianship or access to detailed records. We distinguish a coordination contact from an authorised representative.
Security and automated tools
Risk-based measures include role-based access, protection of accounts and data transmission, records of significant access and incident handling. Shared systems must enforce authorisation in the service itself, rather than relying only on hidden interface controls.
AI or automated tools used in assessment, personnel or project work require a defined purpose, identified recipients and appropriate human oversight. Providing data for a service does not authorise model training. Biometric processing and decisions with significant effects require further assessment before activation.
Your rights and how to contact us
Subject to the applicable legal conditions, you may request access or a copy, source information, correction, erasure, restriction, objection or portability, and withdraw consent. Withdrawal affects consent-based activities without invalidating lawful processing before withdrawal. If a request is refused, we explain the reason and complaint route. You may complain to Thailand’s Office of the Personal Data Protection Committee.
Contact our privacy coordinator at privacy@th-tiis.com or 02-681-9799, or write to 25 Alma Link Building, 17th Floor, Room 10, Soi Chit Lom, Phloen Chit Road, Lumphini, Pathum Wan, Bangkok 10330, Thailand. This contact channel coordinates requests for both companies, with responsibility assigned to the relevant company.
You do not need a new account or marketing consent to make a request. Verification is proportionate to the request. Do not attach an identity-card copy or health information at first contact; restricted channels can be arranged if supporting evidence is necessary.
Changes to this notice
The published notice identifies its version, update date and effective date. Changes in purpose or consent-based activities are assessed for additional information and fresh consent where required. Visits to the website or publication of revised text are not recorded as retrospective consent.
Activity notices
Read the details relevant to your service. Each activity notice applies together with the general sections above.
ACTIVITY 01
Customers, sales and after-sales service
- Responsible company
The company named in the proposal, contract or purchase order; TIIS for this website’s enquiry form
- Relevant data
Contact and organisation details, requirements, delivery address, orders, payment references, installation, warranty and necessary service history
- Purposes and legal basis
Handle enquiries, quotations, contracts, delivery, installation, repair and warranty; contract or requested pre-contract steps where applicable, assessed legitimate interests for representative contacts, and specific accounting or tax obligations
- Access and recipients
Sales, service, finance and the delivery or installation provider needed for the job; complete payment records are not shared with marketing
- Retention period or criteria
For a general enquiry, a proposed 12 months after closure. Contract, warranty, accounting, tax and claim records follow the period applicable to that record; retaining an invoice does not require retaining every message
ACTIVITY 02
Suppliers, purchasing and business contacts
- Responsible company
The contracting or purchasing company
- Relevant data
Contact roles, necessary qualification checks, quotations, contracts, payment instructions and delivery evidence
- Purposes and legal basis
Select and manage suppliers, make payments, verify delivery and handle disputes on the basis appropriate to the relationship. Business contact sourcing does not authorise unlimited marketing
- Access and recipients
Purchasing, approvers, finance, necessary providers and relevant lawful authorities
- Retention period or criteria
From qualification review through the relationship, followed by only the contract, transaction and evidence records still needed for duties or claims, with a review date by record type
ACTIVITY 03
Events, training and business matching
- Responsible company
The organiser named in the project registration, not inferred from the brand alone
- Relevant data
Participant and organisation details, role, interests, appointments, attendance, service entitlements and necessary assistance information
- Purposes and legal basis
Register participants, organise schedules and matches, coordinate providers and issue service documents. Promotional images and news about other programmes are separate choices
- Access and recipients
Event staff and providers; matching partners receive only the profile or contact fields explained in advance. Public directory fields require a defined publication scope
- Retention period or criteria
For the event, follow-up and rights periods stated for that round. Transaction records follow separate duties; directories are removed from publication at the announced end date
ACTIVITY 04
Job and internship applications
- Responsible company
The employer named in the vacancy; TIIS for the application form in this website version
- Relevant data
Contact details, education, experience, skills, portfolio and relevant interview information. Health, criminal records and bank details are not default application fields
- Purposes and legal basis
Assess suitability, arrange interviews and process applicable pre-employment requests. References are informed and used only where needed. Submitting an application does not create an employee account
- Access and recipients
HR and authorised interviewers; CVs and interview notes are not public
- Retention period or criteria
A proposed six months after recruitment closes; with a separate future-opportunities choice, up to 12 months after closure or earlier withdrawal. On hiring, only necessary records move to the personnel file
ACTIVITY 05
Employees and interns
- Responsible company
The individual’s employer or contracting company
- Relevant data
Identity, contracts, roles, time, leave, compensation, tax, benefits, payment account and duty-related evidence
- Purposes and legal basis
Manage employment, compensation and statutory duties. Health information for benefits requires the appropriate sensitive-data basis. Blanket consent is not a condition of employment
- Access and recipients
HR, finance, managers and providers within their duties; managers do not automatically see every salary or health record
- Retention period or criteria
During the relationship and afterwards under the labour, accounting, tax, social-security or claims requirements for each record. HR and finance set the category schedule before automated deletion
ACTIVITY 06
TIMS, projects, tasks and development
- Responsible company
The company responsible for the work or activity, as allocated in TIMS
- Relevant data
Tasks, owners, deadlines, evidence, shared notes, approvals, business documents, learning and work-related TECH STAR records
- Purposes and legal basis
Coordinate delivery, review approvals, develop skills and assess work-related performance, with a route to correct errors. Personal surveillance or a score alone must not determine hiring, dismissal or sanctions
- Access and recipients
Assigned staff, authorised members, approvers and technical administrators within their duties. Linking a private note to a project does not make it visible to the team
- Retention period or criteria
For the work and its follow-up or claims needs. Learning evidence follows personnel-development needs; unnecessary copies and detailed activity data are removed. A universal two-year period is not applied
ACTIVITY 07
Domestic and online assessment
- Responsible company
TECH Infinity Education through TATO
- Relevant data
Registration, school source, authorised representatives, answers, scores and certificate-verification records; images or audio only for rounds that disclose their use
- Purposes and legal basis
Register, administer, assess and review the original answers. Score-review requests are open for seven calendar days after results. Detailed scores remain in individual accounts. Closing score appeals does not remove complaint or data rights
- Access and recipients
Exam staff, assessors and individually authorised recipients. Submitting a school roster does not grant access to all detailed scores. Necessary eligibility information may pass to TIIS for an overseas round
- Retention period or criteria
Results and certificate-verification data: a maximum of two years, proposed from result publication. Proctoring recordings support fairness and exam-rule complaints; the duration for complete recordings requires separate assessment before publication, rather than an automatic two years
ACTIVITY 08
Overseas travel and assessment
- Responsible company
TIIS through EICD
- Relevant data
Confirmed participants, travel documents, bookings, emergency contacts, work, assessment results and only the health information needed for care
- Purposes and legal basis
Arrange travel, accommodation, training, assessment and assistance. Provide information and obtain any required consent before collection or disclosure, with signatures from the participant and legally authorised person as applicable
- Access and recipients
Airlines, accommodation, travel providers, trainers, assessors, insurers, care providers or authorities relevant to the round. South Korea is the usual destination; actual recipients, countries and datasets are identified per round
- Retention period or criteria
Proposed: travel-document copies within 30 days after return and document checks, and health data within 90 days after return. Assessment results have the two-year maximum for their round; contracts and accounting records follow their own rules. Proposed periods require approval before use
Reference document
Personal Data Protection Act, B.E. 2562 (2019) ↗
Royal Thai Government Gazette · PDF in Thai

