Super Recruit Success Privacy Policy

Super Resume Company Limited (the “Company”) provides tools for searching and managing the candidate-selection process through the Super Recruit Success platform (the “Platform”) to you, as a company that wishes to hire and recruit employees (the “User”). Recognising the importance of privacy and respecting the personal data rights of its customers, the Company — as data controller — has prepared this Privacy Policy (the “Policy”) setting out the rights, conditions and the Company’s need to collect, process and use your personal data as a customer who contacts the Company and/or uses the Super Recruit Success Platform or the Company’s other services (the “Customer”).

Acceptance of the Policy

This Policy applies only to contact and/or use of the Platform or the Company’s other services directly, and does not apply to processing by third parties the Company does not control, even where connected to the Company’s services; the Customer should review such third parties’ separate privacy policies.

When the Customer contacts the Company (e.g., demo registration via website or platform, or via the Company’s social media) and submits personal data, the Company deems the Customer to have accepted this Policy.

The Company reserves the right to update this Policy from time to time to comply with law and its service methods; it will notify changes by posting the updated Policy on the Platform or its contact channels, and the Customer’s continued account use after such changes is deemed acceptance.

Definitions

Under this Policy, (a) “Personal Data” means data that can identify a natural person, directly or indirectly, excluding data of the deceased; and (b) “Data Subject” means the person who owns the personal data the Company collects, uses or discloses, including but not limited to Customers who are natural persons and authorised signatory representatives or other related persons of a corporate Customer (e.g., authorised directors, authorised representatives, and any employee or agent of the Customer granted rights to use the Company’s Platform).

For the avoidance of doubt, where the Customer submits data of its related third parties to the Company, upon receipt the Company deems the Customer to have warranted its right to transfer and disclose all such third-party data to the Company for processing under this Policy.

Where the User imports or processes an Applicant’s personal data through the Platform — including using the AI recommendation, scoring, or persona/behavioural-signal analysis features — please kindly note that the User is the independent controller of that Applicant personal data, and the Company acts as a data processor on the User’s behalf under a data processing agreement. The User warrants that it has a lawful basis and has given the Applicant any required privacy notice/terms. Processing of Applicant data is also governed by the applicable Job Seeker privacy notice.

Sources of Personal Data Processed

The Company may receive the Customer’s and/or Data Subject’s personal data from 2 sources:
  1. Directly from the Customer, via: (a) inquiries by phone, social media, website or platform; (b) automatic collection when the Customer visits the website/platform; (c) participation in the Company’s promotional activities; or (d) completing/submitting data or forms to use the Company’s support services.
  2. From others, which may include distributors or external service providers the Company engages, or persons who refer to the Customer, of which the Company will notify the Customer.

Personal Data Processed

  1. Contact data of the contact person — name and contact details (phone, email, or social media account).
  2. Technical data (Online Identifier) — location, IP address and/or domain name, referring pages, browser type/version, device OS settings, and cookies (with consent).
  3. Payment and/or tax-invoice data — including credit card, bank account number and other payment evidence (for individual customers).
  4. Personal data of employees who will use the Platform — name, phone, email needed for registration; the Customer or employee is responsible for providing it, and the Customer warrants its accuracy and its right to submit such employee data.
  5. Platform-transaction data — account data, user ID, log-in data, electronic signature, and other transaction data conducted through the Platform (including transaction commands and history for audit).
  6. Other personal data the Customer or Data Subject may disclose during communications — complaints or opinions, support via Help Desk/Customer Support, data for activities/campaigns, and photographs or feedback about the Company’s services.

Purposes and Processing Periods

  1. To perform the contract — including answering questions and complaints, contacting back to present the Platform and close the sale, preparing and coordinating transaction documents for platform use, including accounting documents or contract preparation (if relevant), and exercising the Company’s rights and duties under its published service terms.
  2. To comply with the Company’s legal obligations — e.g., accounting and tax, especially where the Customer requests a tax invoice, for the legally required period.
  3. For the Company’s legitimate interests, without unduly affecting the Customer’s rights — building and improving the business relationship (analysing and resolving service issues, satisfaction surveys, internal monitoring reports, risk analysis, staff training/monitoring), analysis to improve services and product design, Customer grouping for marketing/PR, use of event photos/feedback for PR, and retaining data to protect the Company’s legitimate rights in disputes, including in particular using automated or AI-assisted analysis of the User’s platform-usage and past-selection statistics to provide candidate recommendations, scoring and recruitment analytics to the User; such output is decision-support only, and the User makes its own decisions.
  4. Where the Customer consents — processing for the specific consented purpose, e.g., marketing about the Company’s or affiliates’ other products matching the Customer’s interests.

Retention Period

The Company retains personal data as long as necessary for the purposes in this Policy, based on: (a) throughout the relationship with the Customer, in particular under the platform lease/subscription or while the Customer has an account; (b) as long as necessary to protect rights under the statute of limitations, up to 10 years; (c) as long as the Company has a legal duty to retain; (d) as long as necessary for business operation, without unduly affecting Customer rights; and (e) for consent-based processing, until the Customer withdraws consent.

Disclosure of Personal Data

In principle, the Company does not disclose the Customer’s personal data to third parties, but where necessary may disclose to:
  1. Relevant external service providers — (i) providers supporting the Company in performing its duties/rights toward the Customer; and (ii) providers involved in the Company’s business, including consultants — disclosing only as necessary under a signed data processing agreement. Where data is transferred to providers operating/processing abroad, the Company will ensure the recipient meets accepted, law-compliant data-protection standards.
  2. Government authorities the Company must disclose to by law or order (e.g., the Revenue Department), only as necessary.
  3. Where the Customer consents, to persons the Customer specifies.

Security Measures

The Company ensures appropriate security measures under applicable law to prevent unauthorised or unlawful access, use, alteration or disclosure, and reviews these measures periodically to align with industry standards and legal changes.

Data Subject Rights

The Company respects the Customer’s legal rights as data subject over personal data under the Company’s control, exercisable within the legal framework: (1) withdraw consent; (2) access and obtain a copy; (3) rectification; (4) data portability; (5) object to processing; (6) erasure/anonymisation when no longer necessary; and (7) restriction of use.

The Customer may contact the Company about this Policy or to exercise rights, and the Company will notify the outcome within a reasonable legal timeframe.

Data Protection Officer (DPO)

The Company has appointed a Data Protection Officer (DPO) to oversee compliance. For questions, contact Mr. Pongsak Pongkriangyot, Tel: 089-204-0909, Email: pongsak@topgunthailand.com.