PRIVACY POLICY

Last Updated: dd/mm/yyyy


This Privacy Policy describes how [-Company Name-] (“we,” “us,” or “CashAI”) process Personal Data in relation to your use of the CashAI Application and website (“CashAI App”). Thank you for choosing CashAI as your financial partner. We are committed to helping you achieve financial inclusion and providing you with a product that is a true enabler of financial growth. At our core, we believe that trust is the foundation of any strong relationship. To that end, we are dedicated to being transparent about how we use your information and protecting your right to privacy.

This Privacy Policy (the “Privacy Policy”) for CashAI users is to be read with and used with the Terms and Conditions. All capitalized terms used in this Privacy Policy, unless specifically defined herein or the context requires otherwise, shall have the meanings given to them in the Terms and Conditions. References below to “you” or “customer” shall mean any visitor, user, or customer of CashAI.

CashAI is committed to protecting and respecting your privacy. This Privacy Policy has been formulated to assist you to understand how your Personal Data (defined as below) will be collected, stored, and processed by CashAI when you visit the CashAI App or website. CashAI may amend this Privacy Policy from time to time, with prior notice. Customers visiting or using application or website are advised to check this Privacy Policy on regular basis to keep up to date with any changes made hereto.

1. When this Privacy Policy applies

1.1 This Privacy Policy applies when you use or subscribe to CashAI App to which this Privacy Policy is linked, including personal and financial, video, advertising, internet and other business, products, services, mobile applications, websites, and other places where we collect your Personal Data.

1.2 You must agree to and be willing to accept the terms of this Privacy Policy before you may visit or use any CashAI App.

1.3 This Privacy Policy and any additional terms of use apply to you even if you are not our customer and you interact with us as part of running our business, such as by:

a. CashAI;

b. when using any of our products or services;

c. when entering any promotion;

d. when calling our help desk; or

e. generally enquiring about our services or products.

1.4 Depending on the product or services, you may also receive service-specific and/or terms. You will be legally bound by both this Privacy Policy and the service/region-specific term to the extent that you have accepted them when signing up for any service or product; therefore, you are required to read these terms carefully.

 

2. What information we collect

2.1 CashAI App is designed to make it easy for you to access financial products and services, regardless of your financial background or credit history. “Personal Data” means any information that can be used by itself to uniquely identify, contact, or locate a person, or can be used with information available from other sources to uniquely identify an individual, such as Personal Data that you provide when you make use our services, set up a user account or otherwise interact with us or provide information (the types of Personal Data collected will depend on the context of our interactions with you and the services or products you request from us), which includes but is not limited to:

(1) Personal Details, such as title, name, surname, gender, age, occupation, workplace, job title, type of business, nationality, date of birth, marital status, number of dependents, information on documents issued by government agencies (e.g., national identification cards), audio recordings, images, photographs, video recordings, electronic identity verification (e-KYC) information, information on income and sources of income, including information on financial status, other documents for loan consideration, etc.

(2) Contact Details, such as postal address, delivery details, house registration address, ID card address, workplace, billing details, telephone number, mobile phone number, work phone number, fax number, email, work email, and accounts related to websites and social networks, including contact information, etc.

(3) Account Details, such as loan account number, credit/debit card number, credit/debit card information, bank account number, member code, customer code, member type, customer type, CashAI card number, CashAI account name, customer credit score, product and service applications (e.g. service registration form, loan application form), month of membership/service receipt, payment details, and copies of bank accounts/bank passbooks, etc.

(4) Transaction Details, such as various information in loan applications, loan information and loan contracts, loan usage information, loan withdrawal records, loan repayment information, loan usage history, account card usage information and transaction information, information on responses to advertising campaigns, marketing programs, spending, order history, past orders, purchase history, items purchased, quantity purchased per item, order cancellation or product return, orders via the website, order number, etc.

(5) Technical Details, such as Internet Protocol Address (IP Address), Web Beacon, log information (such as traffic data, location data, weblogs), device type, unique information about the SIM card used by the device, hardware identifiers such as Universal Device Identifier (UDID) or MAC Address, software identifiers such as Advertising Identifier for iOS (IDFA) or Advertising Identifier for Android (AAID), network, connection details, access details, single sign-on (SSO) access to system services, login logs, login timestamps, page length, cookies, login information, search history, search details, browser type and version, location and time zone, browser type, browser plug-in type and version, operating system and platform, Internet service provider, and other technologies on devices used to access the platform, etc.

(6) Relationship Management Details, such as complaint information about products and services and resolution of complaints, etc.

(7) Profile Details, such as username and password, profile, financial records, identification number (PIN), information about interests, preferences, suggestions and survey results, satisfaction survey results, use of social media, details of activity participation, loyalty program, use of discount codes and promotions, details of customer orders, customer service, etc.

(8) Usage Details such as behavioral data on websites, mobile applications, platforms, products and services, and record of questions and answers.

(9) Marketing and Communication Details, such as information about your preferences in receiving marketing media from us, our affiliates and subsidiaries, third parties, our service providers, our business partners, and communication preferences.

(10) Calendar Data: We require the calendar access permission to allow us to remind you of timely payment during the loan repayment period. This facility is to improve the repayment procedure and your experience. With this, we will have access to your calendar data such as meeting data, your location, etc.

(11) Specific information about your installed application on the mobile device. We will upload it encrypted to our server and our external provider to identify and analyze your behavior and risk against multiple loans to assess whether it can be processed the loan or not and help prevent fraud.

(12) Sensitive Personal Data (“Sensitive Data”), such as biometric data (e.g. face scan) for electronic customer identity verification (e-KYC) processes. We will only collect, use and/or disclose Sensitive Data based on your explicit consent or as permitted by law.

CashAI does not have an intention to collect or process your religion and/or blood type which may contain on your national ID card or other documents. Therefore, please conceal, blind or cross out the information about your religion and/or blood type, before providing a copy of your national ID card or other documents to CashAI.

If you did not conceal, blind or cross-out such data, CashAI reserves the right to carry out such actions by ourselves for CashAI’s compliance with our legal obligation under the Personal Data protection laws to only collect Personal Data to the extent that is necessary and relevant for our business operations.

All Personal Data will be uploaded and stored on our server in an encrypted form through the interface.

2.2 We collect Personal Data when a user/borrower registers with us via CashAI App or when user/borrower provides information and data by filling in the forms as part of loan application, or information and data provided in the course of any correspondence with us (for example, by e-mail or chat or helpline).

2.3 We may collect information when you install the CashAI App to avail yourself of CashAI App services. Such service may contain a unique application number or when CashAI App searches for automatic updates, that number, and information about your installation, for example, the type of operating system, may be sent to us.

2.4 We collect information and data you provide when you register to use services via CashAI App, download or register the same, subscribe to any of our services (such as applying for a loan), enter a promotion or survey, and when you report a problem with CashAI App.

2.5 We may also collect your information from outside sources like credit reports and commercially available geographic and demographic information (third-party supplied information).

In addition, we may also collect your Personal Data through social network partner. We allow you to sign in to our CashAI App without filling out forms. If you sign in using a social networking site’s sign-in system, you expressly authorize us to access and store publicly available information in your social network account (e.g., Facebook, Google, Instagram), as well as other information generated during your use of the social network to which you are signed in. We may also communicate your email address to the social network to determine whether you are already a user on that social network and to display relevant advertisements on your social network account, as applicable.

We may collaborate with third parties that allow you to register for their services or participate in their sales promotions. For example, certain companies may permit you to use your loyalty program number or online service account username to access services or register for offerings provided by such third parties. Additionally, your social network account provider may allow you to connect your social media account to your online service account or log in to your online service account through your social media account. When you register for these services, we will disclose your Personal Data to the relevant third parties. If you do not wish to share your Personal Data in this manner, please do not provide your loyalty or reward program numbers or account usernames to third parties, do not use your online service account to register for third-party promotions, and do not link your online service account with third-party service accounts. Please note that data shared in this manner will be governed by the privacy policies of the respective third parties and not by this Privacy Policy.

2.6 CashAI and its authorized third parties may also collect, store and process Personal Data such as, financial information (details of bank account, credit card, debit card, or other payment instrument details), for providing our products, services and for use of our CashAI App.

2.7 Means of obtaining and updating Personal data will be obtained and updated through electronic means.

2.8 When you use our CashAI App, we collect and store your Personal Data which is provided by you from time to time by explicitly seeking permissions from you to get the required information, or when such collection and processing are otherwise permitted by applicable law.

2.9 Where you provide us with Personal Data about any other person (e.g., a reference, family member, friend, beneficiary, business partner), such as their name, surname, telephone number and relationship to them, whether for the purpose of applying for our products or services or for emergency contact, you represent that you are authorized to do so by (a) informing them of this Privacy Policy and (b) obtaining the relevant and necessary consents to allow us to collect, use and disclose such Personal Data in accordance with this Privacy Policy.

2.10 Our products and services are intended for customers whose age are at least 20 years old. In the event that we discover that we have unintentionally collected Personal Data of a person under the age of 20 years old, we will promptly delete such Personal Data, unless otherwise required or permitted by applicable laws.

2.11 You agree that CashAI may collect, store and process all of the Personal Data mentioned above, which we may collect as part of your interaction with CashAI, including third-party supplied information.

 

3. Tracking and Cookies

3.1 Cookies” are small text files transferred by a web server to a user’s hard drive and thereafter stored on your devices.

3.2 We use our own and third-party cookies for different purposes, as detailed below.

(1) Strictly Necessary Cookies: These cookies are essential to enable you to navigate the application and website, and use their features, such as accessing secure areas of CashAI App. CashAI App uses strictly necessary cookies to ensure that CashAI App’s digital services function properly and completely.

(2) Advertising Cookies: These cookies are used to display ads that are more relevant and tailored to your interests. They are also used to limit the number of times you see an ad and to help measure the effectiveness of CashAI’s advertising campaigns. CashAI sometimes discloses non-personally identifiable information about your browsing activities to its advertising partners and creative partners. These partners may use this information to advertise products that may be of interest to you on other platforms or to help develop CashAI’s future advertising campaigns.

(3) Analytic Cookies: We use these purely for internal research on how we can improve the service we provide for all our users. The cookies simply assess how you interact with our application and website – as an anonymous user (the data gathered does not identify you personally).

(4) Third-party Cookies: Please note that third parties may use cookies through CashAI App to display advertisements relevant to your interests based on your browsing activity. These third parties may also collect your browser history or other information to determine how you access CashAI App and which pages you visited before leaving CashAI App. Therefore, CashAI App does not have direct control over the information collected by these cookies. This Privacy Policy covers only Cookies used by us and not any Cookies used by third parties. You may also be subject to the privacy policies or cookie policies of those third parties.

3.3 Customers may have the ability to either accept or decline the use of Cookies on their devices, whether registered with us or not. Typically, you can configure your browser to not accept Cookies. However, declining the use of Cookies may limit your access to certain features of CashAI App. Cookies help us to provide you with a good experience when you use the CashAI App or browse any of the platforms and also allow us to improve the CashAI App and our platforms.

3.4 You can withdraw your consent for further collection of this information at any time through the settings of the platform.

 

4. Use made of Customer Information

4.1 We may collect, use or disclose Personal Data for the following purposes:

Purposes

Categories of Personal Data

Legal Bases

To offer and provide products and services: such as to create and present information on loan products and various financial services; to enable you to use CashAI App; to process your loan applications; to enable you to register for a user account; to enter into contracts and manage our legal relationships; to support and conduct other activities related to loan services; to conduct transactions with our business partners; to conduct financial transactions, including checking, verifying, canceling transactions, and providing customer services, including call center services, etc.

In addition, we may also collect, use or disclose Sensitive Data as shown on the national ID card (i.e. religion and/or blood type) for customer identity verification and biometric data (e.g. face scan) for electronic customer identity verification (e-KYC) processes.

- Personal Details

- Contact Details

- Account Details

- Transaction Details

- Technical Details

- Profile Details

- Usage Details

- Sensitive Data

- Necessity to proceed with your request prior to entering into a contract(Such as to process your loan applications, enable you to register for a user account)

 

- Performance of contractual obligations (Such as to provide our loan services to you)

 

- Legitimate Interest (For conducting verification and other related activities that cannot rely on the necessity to proceed with your request prior to entering into a contract and performance of contractual obligations)

 

- Legal Obligation (To the extent that the collection, use or disclosure of your Personal Data is required by the applicable law)

 

- Explicit consent (In relation to the verification using your biometric data)

Marketing and Communications: For marketing communications, providing information, special offers, promotional materials, telemarketing, privileges, advertising, newsletters, loyalty and rewards programs, prize draws, competitions, other offers, marketing and other communications, both online and offline, about our products and services. For example, to enable you to participate in marketing promotions, special offers and other offers (e.g. to send you email alerts).

Your Personal Data will also be collected, used or disclosed in order to provide you with information, promotions and offers relating to the products of our affiliates, subsidiaries, service providers and/or business partners.

- Personal Details

- Contact Details

- Account Details

- Transaction Details

- Technical Details

- Profile Details

- Usage Details

- Marketing and Communication Details

 

- Legitimate Interest (For the marketing and communications relating to the products and services you have purchased, obtained or received from us.)

 

- Consent (For other marketing and communication purposes such as providing you with our business partner’s marketing materials)

 

Calendar Data: We require the calendar access permission to allow us to remind you of timely payment during the loan repayment period. This facility is to improve the repayment procedure and your experience.

- Personal Details

- Profile Details

- Calendar Data

 

Consent

To communicate with you on non-marketing matters: Such as providing information, necessary notifications about products and services you purchased, obtained or received from us, sending loan contract documents, sending account statements, payment notifications, contacting officials to provide various services related to your account, or providing general information, notifying debt payments, following up after correspondence (live chat, email, or phone inquiries), etc.

- Personal Details

- Contact Details

- Account Details

- Transaction Details

- Technical Details

- Profile Details

- Usage Details

 

Legitimate Interest

To manage relationships: Such as providing customer service, call center and/or hotline to answer questions, requests, feedback, complaints, claims, disputes or compensation; asking for ratings and reviews of services or products; providing technical assistance and handle technical issues; processing and updating information, and to facilitate the use of products and services, etc.

- Personal Details

- Contact Details

- Account Details

- Transaction Details

- Technical Details

- Profile Details

- Usage Details

- Relationship Management Details

Legitimate Interest

For data verification, distribution and analysis: Such as to learn more about the products and services received from us, our affiliates and subsidiaries, our service providers and our business partners, and other services that you may be interested in receiving; to analyze credit information for use in loan approval, credit review, account renewal, risk management, development of risk score models; to measure service performance or product offerings that are appropriate for you; to verify and match information, distribute information and analyze information;  to study marketing research, survey, evaluate behavior, statistics and market segmentation, trends and consumption patterns; to know and understand our customers better; to identify your preferences; to provide you with a personalized experience and to develop future article content that is in line with your interests, etc.

- Personal Details

- Contact Details

- Account Details

- Transaction Details

- Technical Details

- Profile Details

- Usage Details

- Relationship Management Details

- Marketing and Communication Details

- Legitimate Interest

 

- Consent (For analysis for marketing purposes)

 

 

To improve our business operations, products and services: For example, to evaluate, develop, manage and improve our current services, products, systems and business operations, and to design new services, products, systems and business operations for all our customers; to improve our services, to identify and resolve issues; to prepare aggregated and anonymous reports and measure performance and marketing campaigns; and to manage, operate and maintain our systems. We may listen to conversations and/or record telephone calls to train our staff and improve our services.

- Personal Details

- Contact Details

- Account Details

- Transaction Details

- Technical Details

- Profile Details

- Usage Details

- Relationship Management Details

- Marketing and Communication Details

Legitimate Interest

To improve the performance of our website, mobile applications and platforms: Such as to administer, operate, track, monitor and manage our website, mobile applications and platforms; to facilitate and ensure that our website, mobile applications and platforms function properly, efficiently and securely; to facilitate and enhance the user experience in using our website, mobile applications and platforms; and to improve the layout and content of our website, mobile applications and platforms.

- Contact Details

- Account Details

- Transaction Details

- Technical Details

- Profile Details

- Usage Details

Legitimate Interest

To manage our information technology systems: Such as for the purposes of managing our business, including our information technology operations, managing our communications systems, conducting information technology security and IT security audits, for internal business management in accordance with internal governance requirements, policies and procedures, and keeping our databases up-to-date.

- Personal Details

- Contact Details

- Account Details

- Transaction Details

- Technical Details

- Profile Details

- Usage Details

 

Legitimate Interest

To perform regulatory and supervisory duties: Such as to comply with any law, legal process or order of a government authority, which may include orders from government authorities outside Thailand, and/or to cooperate with courts, regulators, government officials and law enforcement agencies when we have reasonable grounds to believe that we are legally obligated to do so and when disclosure of Personal Data is strictly necessary to comply with such legal obligation, legal process or government order, including issuing tax invoices or tax returns, to perform legal duties related to electronic payment (e-Payment), finance and anti-money laundering businesses, to record and monitor communications, to disclose to tax authorities, financial service regulators, regulatory agencies and other government agencies, and to investigate or prevent crimes.

- Personal Details

- Contact Details

- Account Details

- Transaction Details

- Technical Details

- Profile Details

- Usage Details

- Legal Obligation

 

- Legitimate Interest (For other related activities that cannot rely on the legal obligation, such as preparing information and documentation for submission with supervisory authorities)

 

 

 

To protect our interests: Such as to maintain the safety and integrity of our business operations, to exercise our rights or protect our interests where necessary and lawful, such as to investigate, prevent and respond to claims of fraud, intellectual property infringement or other violations of law, to manage and prevent loss of our assets and property, to ensure compliance with our terms and conditions, to detect and prevent misconduct within our premises, to track incidents, to prevent and report criminal offenses and to maintain the safety and integrity of our business, etc.

- Personal Details

- Contact Details

- Account Details

- Transaction Details

- Technical Details

- Profile Details

- Usage Details

- Relationship Management Details

 

Legitimate Interest

 

To investigate, deter and prevent fraud/illegal acts: Such as to verify and authenticate identity and to verify compliance with laws and other regulations (e.g. anti-money laundering, to comply with customer verification (KYC) or electronic identity verification (e-KYC) processes and to prevent fraud and suspicious transactions), including to conduct checks on sanctions lists, internal audits and internal records, asset management, other business systems and controls, etc.

- Personal Details

- Contact Details

- Account Details

- Transaction Details

- Technical Details

- Profile Details

- Usage Details

- Relationship Management Details

- Calendar Data

- Marketing and Communication Details

- Sensitive Data

- Legal Obligation

 

- Legitimate Interest (For other related activities that cannot rely on the legal obligation, such as internal audits and internal records)

 

To transfer in the event of a merger: For example, in the event of a sale, transfer, merger, restructuring, or similar event, we may transfer Personal Data to another party as part of such transaction.

- Personal Details

- Contact Details

- Account Details

- Transaction Details

- Technical Details

- Profile Details

- Usage Details

- Relationship Management Details

- Calendar Data

- Marketing and Communication Details

- Sensitive Data

- Legal Obligation

 

- Consent (To the extent that Personal Data to be transferred is a Sensitive Data)

 

Risk assessment and management: To carry out risk management, to examine and assess risks, to check credit and review the financial status of customers and/or

- Personal Details

- Account Details

- Transaction Details

- Profile Details

 

Legitimate Interest

Vital Interest: To prevent or suppress danger to the life, body or health of any person.

- Personal Details

- Contact Details

 

Vital interest

Cookies: such as to enhance your experience of visiting and using CashAI App, to make the visit of CashAI App more attractive, and to enable the use of certain functions.

For more information on the Cookies we use, please refer to Clause 3 above

 

- Technical Details

- Usage Details

- Legitimate Interest (for Strictly Necessary Cookies)

- Consent (for Advertising Cookies and Analytic Cookies)

Where we rely on consent as a legal basis for collecting, using and/or disclosing your Personal Data, you have the right to withdraw your consent through settings. The withdrawal of consent will not affect the lawfulness of the collection, use and/or disclosure of your Personal Data based on your consent given prior to such withdrawal. However, to the extent that such Personal Data is necessary for us to provide the services to you, if you do not provide such consent or later withdraw your consent, we may not be able to provide the services to you.

4.2 In the event that your Personal Data is required for the performance of contract or for pre-contractual measures, and you did not provide such Personal Data to us, we may not be able to proceed with your request to enter into a contract with us, or may not be able to perform our obligation under the contract with you, either in whole or in part. For example, we may not be able to process your application, or may not be able to provide you our CashAI App service. In addition, in the event that your Personal Data is required for the performance of legal obligations, failure to provide Personal Data under said circumstance may result in us and/or you being in breach of the applicable law or regulation. We may also suspend or terminate our service, or determine not to enter into a contractual relationship with you to avoid being in violation of such applicable law or regulation.

 

5. Security Practices

5.1 While no organization can guarantee perfect security, we are continuously implementing and updating administrative, technical, and physical security measures to help protect your information against unlawful or unauthorized access, loss, destruction, or alteration. We adopt reasonable security practices and procedures which are consistent with the standards required by the applicable personal data protection laws, including technical, organizational, operational, managerial, and physical security controls in order to protect your Personal Data from unauthorized access, or disclosure while it is under our control. Your Personal Data is contained behind secured networks and is only accessible by a limited number of persons who have special access rights to such systems and are required to keep the information confidential.

5.2 The data and information we collect from you may be transferred to, and stored in Thailand or other countries outside your jurisdiction. The staff members at the destination may be engaged in the fulfillment of your requests. To the extent permitted by applicable law, by submitting your data, you agree to this transfer, storing, or processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy, and that cross-border transfer of your Personal Data will be consistent with the requirements under the applicable personal data laws such as by entering into the standard contractual clauses or relying on other permitted legal grounds.

5.3 Our security practices and procedures limit access to Personal Data on a need-only basis. Further, our employees are bound by a code of conduct and confidentiality policies that obligate them to protect the confidentiality of Personal Data.

5.4 We maintain the security of our CashAI App, however, for reasons outside of our control, security risks may still arise. Any Personal Data transmitted to us or from our online products or services will therefore be at your own risk. However, we will use all reasonable efforts to ensure the security of your information. We observe reasonable security measures to protect your Personal Data against hacking and virus dissemination.

5.5 Where we have given you (or where you have chosen) a password that enables you to access certain parts of our CashAI App, you are responsible for keeping this password confidential. We ask you not to share a password with anyone.

5.6 You agree that CashAI or any of its affiliates, associated or related entities, employees, directors, shareholders, agents, representatives, etc. shall have no liability towards you in case of any unintended security breach which results in unauthorized access to, or disclosure of, your information. You agree to waive, to the fullest extent permitted by law, all of your rights to seek damages or otherwise hold CashAI and its related entities liable for any security breach resulting in disclosure or unauthorized access to your information.

6. Your rights

You can exercise any of the rights described in this section consistent with the conditions and limitations prescribed by the applicable law. We may ask you to verify your identity and request before taking further action on your request.

6.1 You can access and update some of your Personal Data through your account settings. You are responsible for keeping your Personal Data up to date, or if you cannot update your Personal Data by yourself, please contact us to rectify or update your Personal Data. You may also contact us to request access to other Personal Data of yours as well as to obtain copy of your Personal Data from us, and request the disclosure of the source of your Personal Data which we have acquired without your consent.

6.2 We retain your Personal Data for as long as reasonably necessary to fulfil the purposes for which we obtained it and to carry out our legal and regulatory obligations. However, in certain circumstances, we may need to retain your Personal Data for a longer period if permitted by, or in order to comply with applicable law.

You can request that your Personal Data be deleted, destroyed or de-identified. Please note that if you request the deletion of your Personal Data, or if your account is suspended, terminated, or voluntarily closed:

(1) We may retain your Personal Data as necessary for a period of five (5) years for our legitimate business interests, such as the prevention of money laundering, fraud detection and prevention, an enhancing safety. For example, if we suspend an Account for fraud or safety reasons, we may retain information from that Account to prevent that Member from opening a new Account in the future.

(2) We may retain and use your Personal Data to the extent necessary to comply with our legal obligations. For example, we may keep information for tax, legal reporting, and auditing obligations.

(3) Because we take measures to protect data from accidental or malicious loss and destruction, residual copies of your Personal Data may not be removed from our backup systems for a limited time.

6.3 You can request to receive your Personal Data from us in the format which is generally readable or usable by automatic tools or equipment, and which can be used or disclosed by automated means (if any), and to request us to send or transfer your Personal Data in such format to other data controllers as well as to receive Personal Data which we sent or transferred to such other data controllers.

6.4 You can object to the collection, use, or disclosure of your Personal Data at any time, particularly the collection, use, or disclosure of such Personal Data is for the purpose of direct marketing. 

6.5 You can request that CashAI suspends the use of your Personal Data.

6.6 If you believe that we process your Personal Data in violation of the applicable Personal Data protection laws, you may lodge complaint with the competent authority in your jurisdiction.

 

7. Sharing & Disclosure

7.1 We may disclose or transfer Personal Data to the following third parties who collect, use and/or disclose Personal Data for the purposes set out under this Privacy Policy. Please note that these third parties may be located within or outside of Thailand.

(1) CashAI Companies: Members of our group, which means our subsidiaries, our ultimate holding entity, and its subsidiaries.

(2) Our service providers: We may use other companies, agents or contractors to perform services on our behalf or to assist us in providing our products and services to you. Accordingly, we may share Personal Data with the following parties, including but not limited to: (1) infrastructure, software, website and information technology providers and developers; (2) warehousing and transportation providers; (3) data storage and cloud service providers; (4) data monitoring, analysis and analytics providers; (5) marketing, advertising and communications providers; (6) research providers; (7) survey providers; (8) advertising and event organizers; (9) telemarketing providers; (10) call center providers; (11) payment, settlement and authentication providers; (12) administrative services providers; (13) telecommunications and communications providers; and/or (14) authorized credit bureau providers; and (15) debt collection providers.

During the period of providing the services, such service providers may have access to your Personal Data. However, we will only provide such service providers with access to your Personal Data to the extent necessary to provide the Services. We will request that they not use your Personal Data for any other purpose. We will ensure that all service providers we work with keep your Personal Data secure.

(3) Our business partners: We may transfer your Personal Data to our business partners, including but not limited to digital marketing service providers, banking and financial service providers, loyalty and rewards program operators, insurance service providers, telecommunications and communications operators, financial professionals, property management service providers, investment service providers, retailers, e-commerce operators, investors, co-registered program partners, co-branded partners such as banks, referred partners who may partner with us to offer products or services, partners with shared memberships such as food and retail operators and automotive operators, data transmission partners, data resellers and other business partners, providers of lead generation marketing activities, business partners for whom we provide lead generation marketing activities, research agencies, partners who survey the market and their customers, advertising agencies or media agencies to conduct market research, surveys, assessments, behavior, statistics and market segmentation, consumption trends and patterns, reporters for our marketing campaigns, independent financial professionals; reinsurers which assist in managing our business and reducing the risk under the insurance policies taken out by spreading the risk to other institutions; claims investigation agencies to prevent and detect fraud and overclaims; insurance brokers and/or insurance agents in Thailand, where such business partners who receive the data agree to treat the Personal Data in a manner consistent with this Privacy Policy.

(4) Third parties authorized by law: In some cases, we may be required to disclose or share Personal Data in order to comply with legal or regulatory obligations or valid legal request (such as a subpoena or court order), including to local or international law enforcement agencies, courts, regulators, government officials, embassies, consulates or any other person we believe is necessary to comply with legal or regulatory obligations, or to protect our rights, the rights of third parties, or the safety of any person, or to investigate, prevent, or address fraud, security, or safety issues (such as the Anti-Money Laundering Office (AMLO), the Bank of Thailand (BOT), and the Revenue Department).

Where appropriate, we may notify you about legal requests unless: (i) providing notice is prohibited by the legal process itself, by court order we receive, or by applicable law, or (ii) we believe that providing notice would be futile, ineffective, create a risk of injury or bodily harm to an individual or group, or create or increase a risk of fraud upon or harm to CashAI, or expose CashAI to a claim of obstruction of justice.

(5) Professional consultants: We may disclose Personal Data to our professional advisors, including but not limited to (1) independent consultants, project consultants, financial advisors, (2) legal advisors who assist in the operation of our business and provide professional litigation services, such as defending or litigating legal proceedings, and/or (3) auditors who provide accounting or financial auditing services to the Company.

(6) Third parties involved in the transfer of business: We may disclose or transfer Personal Data to our business partners, investors, significant shareholders or transferees in the event of a corporate restructuring, change in corporate structure, merger, acquisition, sale, purchase, joint venture, transfer or any similar event involving the transfer or disposal of all or part of our business, assets or stock, or in connection with the contemplation of such transaction (e.g., due diligence). If any of the above events occur, the receiving party will treat Personal Data in accordance with this Privacy Policy.

8. Changes to this Privacy Policy

We reserve the right to modify this Privacy Policy at any time in accordance with applicable law. If we do so, we will post the revised Privacy Policy and update the “Last Updated” date at the top. In case of material changes, we will also provide you with notice and obtain your consent (if required) through a pop-up window in the application and send notifications to your mobile phone before the effective date. If you disagree with the revised Privacy Policy, you can cancel your account. If you do not cancel your account before the date the revised Privacy Policy becomes effective, your continued access to or use of the CashAI App will be subject to the revised Privacy Policy.

9. Contact information and responsible entities

Any disputes regarding this Privacy Policy shall be subject to the Terms and Conditions of CashAI, including but not limited to any provisions related to indemnification, limitation of liability relating to damages, choice of law, and dispute resolution forum. We ask you to first submit any such complaints directly to us at the relevant customer services desk or helpline.

If you wish to contact us to exercise your rights relating to your Personal Data, or if you have any questions about your Personal Data under this Privacy Policy, please contact us at:

Address: [*]

Email: [*]

Call: [*]


Consent Request

I hereby certify that I have thoroughly read, understood, and acknowledged all information in the Privacy Policy for [-Company Name-] (“CashAI”) regarding CashAI’s collection, use, disclosure and/or otherwise processing (“Process”) of my Personal Data (as defined in the Privacy Policy). I therefore agree to the following:

1. I hereby give explicit consent to CashAI to Process my Sensitive Data such as biometric data (e.g. face scan) for electronic customer identity verification (e-KYC) processes.

 Yes    No

2. I hereby give consent to CashAI to Process my Personal Details and Contact Details for marketing communications, such as for providing me an information, special offers, promotions, as well as to enable me to participate in marketing promotions, special offers and other offers, etc.

 Yes    No

3. I hereby give consent to the CashAI to Process my Personal Details, Profile Details, Usage Details and Account Details to analyze and evaluate my behavior, identify my preferences and to provide me with a personalized experience when using CashAI App.

 Yes    No

4. I hereby give consent to the CashAI to access calendar and permission to remind me of timely payment during the loan repayment period, including to Process my Calendar Data for such purposes.

 Yes    No

5. I hereby give consent to the CashAI to access specific information about my installed application on the mobile device, and to send such information, in the encrypted format, to CashAI’s server and CashAI’s external provider to identify and analyze my behavior and risk against multiple loans, to assess whether the loan can be processed, and to prevent fraud.

 Yes    No

6. I hereby give consent to the CashAI to use Advertising Cookies and Analytic Cookies to display ads that are more relevant and tailored to my interests, and for internal research to improve the service CashAI provides for all its users.

 Yes    No