Privacy Policy
A Asset Company Limited — www.aasset.co.th
Version 1.0, effective from [27 august 2026]
1. Who we are
A Asset Company Limited (registration number 0105560164592), together with its affiliates and joint-venture companies ("A Asset" or "we"), is the controller of your personal data. We develop and invest in real estate, both in Thailand and overseas.
We protect your personal data in accordance with the Personal Data Protection Act B.E. 2562 (2019) ("PDPA").
2. What we collect and why
Who you are | Data we collect | What we use it for |
|---|---|---|
Website users and visitors | Name, contact details, website usage data (IP, logs, cookies), CCTV footage | Operating the website, answering enquiries, arranging visits, security |
Customers and prospective customers | Identity data, contact details, financial and loan data, transaction records, property and investment preferences | Assessing purchase applications, contracts, transfer of ownership, after-sales service, and marketing (with consent) |
Suppliers and business counterparties | Identity data, contact details, bank account details, employer information, professional licences | Supplier registration, tendering, contract execution and administration, due diligence |
Job applicants | Application and CV data, education and employment history, referees, interview results | Assessing applications, verifying qualifications, and notifying outcomes |
We collect data mainly from you directly, and may also receive it from other sources such as sales agents, property brokers, financial institutions, your employer, or publicly available sources.
Sensitive data — we do not normally collect data on religion, race or health. If you send us a copy of your national ID card, please redact the religion and blood type first. Where we do need sensitive data, we will obtain your explicit consent case by case.
3. Legal bases we rely on
Purpose | Legal basis |
|---|---|
Performing contracts — reservations, sale and purchase, leases, transfer of ownership, after-sales service | Contractual Basis |
Complying with the law — land and condominium legislation, tax, anti-money laundering, and the Computer Crime Act | Legal Obligation |
Customer relationship management, product and service development, security, fraud prevention, internal audit, and legal claims | Legitimate Interests |
Newsletters and marketing, non-essential cookies, and processing of sensitive data | Consent (withdrawable at any time) |
Preventing or suppressing danger to life, body or health | Vital Interest |
If you do not provide data that is necessary for a contract or for compliance with the law, we may be unable to provide services or enter into a transaction with you.
4. Who we share data with
We do not sell your personal data. We share it only as necessary with:
Companies within the A Asset Group, its affiliates and joint-venture companies
Government agencies and officials exercising statutory powers, such as the Land Department, the Revenue Department, courts, police officers and the Anti-Money Laundering Office
Banks and financial institutions (for loan applications and transfers of ownership)
Condominium and housing estate juristic persons, and property managers
Contractors, after-sales service providers, sales agents and marketing service providers
Professional advisers such as auditors, lawyers and property valuers, and insurance companies
IT and cloud service providers
We put in place a written Data Processing Agreement (DPA) with service providers who access your data.
5. Transfers abroad
A Asset holds investments and business partnerships overseas, including in Japan and Vietnam, and may use cloud services hosted abroad. We transfer data internationally in accordance with Sections 28 and 29 of the PDPA, with appropriate safeguards such as standard contractual clauses.
6. How long we keep data
Type of data | Retention period |
|---|---|
Computer traffic data (logs) | Not less than 90 days (Computer Crime Act) |
CCTV footage | Approximately 30 days |
Prospective customers who do not contract | [2 years] from last contact |
Contractual customer data | Term of contract + not less than 10 years (prescription) |
Accounting and tax records | Not less than 5 years (Revenue Code) |
Unsuccessful job applicants | [1 year] from notification |
After these periods we delete, destroy or anonymise the data, unless retention is required by law or for legal proceedings.
7. Cookies
Cookie category | Consent required? |
|---|---|
Strictly necessary cookies | No — essential to the website's operation |
Analytics / performance cookies | Yes — consent required first |
Functionality cookies | Yes — consent required first |
Targeting / advertising cookies | Yes — consent required first |
Social media cookies | Set by the external platform |
You can set or withdraw your cookie consent at any time through the "Cookie Settings" menu on the website, or through your browser settings. We renew cookie consent at least every 12 months.
8. Your rights
Under the PDPA you have the right to:
Withdraw consent at any time — this does not affect processing already lawfully carried out
Access your data and obtain a copy
Data portability — receive or transfer your data in a machine-readable format
Object to processing, including objecting to direct marketing at any time
Erasure — request deletion or destruction of your data
Restriction — request that use of your data be restricted
Rectification — have your data corrected and kept up to date
Lodge a complaint with the Expert Committee of the Personal Data Protection Committee Office (PDPC)
Submit a request with proof of identity through the channels in Clause 10. We will respond within 30 days, free of charge.
9. Data security
We maintain security measures under Section 37 of the PDPA: organisational (internal policies, need-to-know access control, staff training, confidentiality undertakings), technical (authentication, encryption in transit via HTTPS/TLS, backups, audit logs) and physical (access control to data storage areas, secure document destruction).
If a personal data breach occurs, we will notify the PDPC within 72 hours of becoming aware of it, and will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
Minors — this website is not intended for use by minors. If we find that we have collected a minor's data without the legally required consent of the holder of parental responsibility, we will delete it without undue delay.
10. Contact us
A Asset Company Limited
63 Athenee Tower, Unit 14, 23rd Floor, Wireless Road, Lumphini, Pathumwan, Bangkok 10330, Thailand
Tel. +66 (0) 2126 8140 | Email info@aasset.co.th
11. Changes to this policy
We may amend this policy from time to time. The amended version and its effective date will be published on the website, and where further consent is required we will obtain it from you.