Personal Data Protection Policy
Dear valued IKEA customers and guests,
1. Ikano (Thailand) Limited ("us", "we", "our") is the operator of www.ikea.com/th/en/ and http://www.ikea.com/th/th/ (the "Website").We recognise the importance of the personal data you have entrusted to us and believe that it is our responsibility to properly manage, protect and process your personal data.
3. Unless restricted by law, you agree that we may process your personal data in the manner, and for the purposes set out in the terms described in paragraph 2 above.
What is Personal Data?
4. Personal data means data which relates to an individual who can be directly or indirectly identified from such data but does not include data on deceased persons.
5. Common examples of personal data could include names, identification numbers, contact information, medical records, photographs and video images.
How Personal Data is collected
6. Below are examples of situations where we collect your personal data:
(a) when you register for an account on the Website, apps or kiosks;
(b) when you complete purchase orders, requests or applications for our products or services (by telephone, in person, snail mail or electronically);
(c) when you make a purchase on the Website;
(d) when you communicate with us directly in relation to our products and services (in person via our customer service centre or via our co-workers in our stores, by email, telephone or any other means);
(e) when you use services that are made available on the Website or at our stores; such as Småland, home delivery, assembly/installation services, sewing services, etc.;
(f) when you conduct certain types of transactions such as refunds;
(g) when you enter, and when you interact with us during promotions, competitions, contests, lucky draws or special events;
(h) when you apply for employment with us;
(i) when you subscribe to any of our membership programmes, i.e. IKEA FAMILY and/or IKEA småles; or
(j) when you participate in surveys and other types of research.
When Personal Data Collected and what is Collected
7. You can use and browse the Website without disclosing your personal data. The provision of your personal data is voluntary. But, if you do not provide your personal data to us, we may not be able to provide the products and services that you require of us.
8. We collect personal data through registration, placement of orders, completion of forms, emails, inquiries, requests, and other situations where you have chosen to provide personal data to us.
9. If you are a candidate for employment, we will collect personal data that you provide to us during the recruitment process, including personal data that is contained in your resume and in any application form that we require you to fill up. Such personal data may include your employment history and working eligibility rights.
10. Other examples of the types of personal data which we may collect about you include:
(a) contact information such as names, addresses, telephone numbers, and email addresses;
(b) housing information such as household size, type of home and living situation;
(c) billing information such as billing address and credit card information;
(d) unique information such as ID or passport number, photograph, contact preferences, and date of birth;
(e) details of any membership that you have with us, such as IKEA FAMILY and/or IKEA Småles;
(f) details of your visits to the Website, such as traffic data, location data, and the resources that you access on the Website; and
(g) your transaction history.
Storage of personal data
11. We are required by law to store your trafficking information for a period of 90 days from the date such information was inputted into our system and will ensure that after such period has lapsed, subject to paragraph 32, your trafficking information will be destroyed or anonymized as soon as it is reasonable to do so.[SPI7]
Purposes for Collection, Use, Disclosure and Processing of Personal Data
12. You may, in certain circumstances, provide us with personal data relating to third parties (for example, your next-of-kin or any person who may receive delivery of your purchased item on your behalf or, any person whom you have nominated as your referee if you are a candidate for employment). When this happens, you are deemed to have represented and confirmed to us that you have obtained the consent of such third party to provide his/her personal data to us for processing in the manner set out in paragraph 2 above.
13. We collect personal data if it is necessary for us to conduct our everyday activities or functions.
14. The personal data which we collect from you may be collected, used, disclosed and/or processed for various purposes, depending on the circumstances for which we may/will need to process your personal data, including:
(a) to communicate with you;
(b) to maintain and improve customer relationship;
(c) to assess, process and provide products, services and/or facilities to you;
(d) to administer and process any payments (including refunds) related to products, services and facilities requested by you;
(e) to establish your identity and background;
(f) to respond to your enquiries or complaints and resolve any issues and disputes which may arise in connection with any dealings with us;
(g) to provide you with services or assistance that you have requested;
(h) to provide you with information and/or updates on our products, services, upcoming promotions offered by us and/or events organised by us and selected third parties which may be of interest to you from time to time;
(i) for direct marketing purposes via SMS, phone call, email, fax, mail, social media and/or any other appropriate communication channels, if you are a member of any of our loyalty programmes e.g. IKEA FAMILY and småles, in accordance with your consent;
(j) to facilitate your participation in, and our administration of, any events including contests, promotions or campaigns;
(k) to award points in a loyalty or rewards programme;
(l) to maintain and update internal record keeping;
(m) for internal administrative purposes;
(n) to send you seasonal greetings messages from time to time;
(o) to send you the invitation to join our events and promotions and product launch events;
(p) to monitor, review and improve our events and promotions, products and/or services;
(q) to conduct credit reference checks and establish your creditworthiness, where necessary, when providing you with products, services and/or facilities;
(r) to administer, process and fulfil your commercial transactions with us (such as a purchase on the Website, a tender award, contract for service or tenancy agreement);
(s) to process any payments related to your commercial transactions with us;
(t) to process and analyse your personal data either individually or collectively with other individuals;
(u) to conduct market research or surveys, internal marketing analysis, customer profiling activities, analysis of customer patterns and choices, planning and statistical and trend analysis in relation to our products and/or services;
(v) to share any of your personal data with the auditor for our internal audit and reporting purposes;
(w) to share any of your personal data pursuant to any agreement or document which you have duly entered with us for purposes of seeking legal and/or financial advice and/or for purposes of commencing legal action;
(x) to share any of your personal data with our business partners to jointly develop products and/or services or launch marketing campaigns;
(y) to share any of your personal data with financial institutions necessary for the purpose of applying and obtaining credit facility(ies), if necessary;
(z) for audit, risk management and security purposes;
(aa) for detecting, investigating and preventing fraudulent, prohibited or illegal activities;
(bb) for enabling us to perform our obligations and enforce our rights under any agreements or documents that we are a party to;
(cc) to transfer or assign our rights, interests and obligations under any agreements entered into with us;
(dd) for meeting any applicable legal or regulatory requirements and making disclosure under the requirements of any applicable law, regulation, direction, court order, by-law, guideline, circular or code applicable to us;
(ee) to enforce or defend our rights and your rights under, and to comply with, our obligations under the applicable laws, legislation and regulations;
(ff) to carry out verification and background checks as part of any recruitment and selection process in connection with your application for employment with us; and/or
(gg) for other purposes required to operate, maintain and better manage our business and your relationship with us; which we notify you of at the time of obtaining your consent.
15. As the purposes for which we may/will collect, use, disclose or process your personal data depend on the circumstances at hand, such purpose may not appear above. However, we will notify you of such other purpose(s) at the time of obtaining your consent, unless we are permitted by law to process your personal data without your consent.
Specific Issues for the Disclosure of Personal Data to Third Parties
16. In order to smoothly conduct our business operations or to fulfil our obligations to you, we may also disclose the personal data that you have provided to us to our third party service providers, agents, affiliates or related corporations, who may be situated inside or outside of Thailand, for one or more of the purposes stated in or notified to you under the Purposes for Collection, Use, Disclosure and Processing of Personal Data section. We will also disclose your personal data to government regulators or authorities in order to comply with any laws, rules, guidelines, regulations or schemes that apply to us.
17. Examples of third parties that we disclose your personal data to include:
(a) data entry service providers;
(b) professional advisors, consultants and/or external auditors;
(c) storage and warehousing facility providers (which may include data storage and processing servers located overseas);
(d) third party service providers who provide administrative or operational services in connection with our business such as telecommunications, information technology, logistics, delivery, assembly, installation, printing and postal services or services relating to marketing and promotional activity;
(e) relevant government regulators or authorities;
(f) Inter IKEA Systems B.V., other IKEA franchisees and our related corporations and affiliates either in Singapore or overseas; and
(g) to third-party credit reporting or employment agencies as part of the recruitment and selection process and/or otherwise in connection with your application for employment with us.
18. The third parties whom we conduct business are only authorized to use your information to perform the service for which they were hired. As part of our agreement with them, they are required to adhere to the law and any policies that we provide, and to take reasonable measures to ensure your personal data is secure.
19. We respect the confidentiality of the personal data that you provide to us. We do not sell personal data to any third party.
Request for Access and/or Correction of Personal Data
20. You may request to access and/or correct your personal data that is in our possession or under our control by writing to us at firstname.lastname@example.org
21. For a request to access personal data, we will provide you with the relevant personal data within thirty (30) days from such a request being made.
22. Where a request cannot be complied with within the above time frame, we will inform you of the reasonably soonest time in which we will respond.
23. For a request to correct personal data, we will:
(a) correct your personal data as soon as practicable after the request has been made unless we have reasonable grounds not to do so; and
(b) subject to paragraph 24 below, we will send the corrected personal data to every other organisation to which the personal data was disclosed by us within a year before the date the correction was made unless that other organisation does not need the corrected personal data for any legal or business purpose.
24. We may, if you so consent, send the corrected personal data only to specific organisations to which the personal data was disclosed by us within a year before the date the correction was made.
25. Depending on the scope and nature of the work required to process your access request, we may be required to impose a fee to recover our administrative costs. This will be assessed on a case-by-case basis by our Data Protection Officer. Where such a fee is to be imposed, we will provide you with a written estimate of the fee for your consideration. Please note that we will only process your request once you have agreed to the payment of the fee. In certain cases, we may also require a deposit from you before we process the access request. You will be notified if a deposit is required when we provide you with the written estimate of the fee if any.
26. You understand that we are reliant on you to provide us with accurate and complete personal data and with updates if there are any changes to your personal data. We will not be responsible for relying on or using any inaccurate or incomplete personal data where you have provided with such personal data and/or have failed to update us of any changes in your personal data.
Request to Withdraw Consent
27. You may withdraw your consent for the collection, use and/or disclosure of your personal data that is in our possession or under our control by writing to us at email@example.com
28. We will process your request within a reasonable time from such a request for withdrawal of consent being made, and will thereafter not collect, use and/or disclose your personal data in the manner stated in your request.
29. Your withdrawal of consent may result in certain consequences. For example, it may mean that we will not be able to provide you with certain products or services that you have requested or that we will not be able to continue with your existing relationship with us. We will inform you of such consequences after we receive your request for withdrawal.
30. However, you understand that notwithstanding your withdrawal of consent, we will still be entitled to collect, use or disclose your personal data if we are required or authorised to do so under the law.
Protection and Destruction of Personal Data
31. We will put in place reasonable security arrangements to ensure that your personal data is adequately protected and secured. In particular, reasonable security arrangements will be taken to prevent any unauthorized access, collection, use, disclosure, copying, modification, leakage, loss, damage and/or alteration of your personal data. However, we cannot assume responsibility for any unauthorized use of your personal data by third parties which are wholly attributable to factors beyond our control.
32. We will also put in place measures to ensure that any of your personal data that is in our possession or under our control is destroyed and/or anonymized as soon as it is reasonable to assume that:
(a) the purpose for which that personal data was collected is no longer being served by the retention of such personal data; and
(b) retention is no longer necessary for any other legal or business purposes.
33. If you have any complaint or grievance regarding how we are handling your personal data or about how we are complying with the law, we welcome you to contact us by writing to us at firstname.lastname@example.org
34. We will certainly strive to deal with any complaint or grievance that you may have speedily and fairly.
35. You may contact us (or send us any request or complaint form) either by post or by email at the following address:
Data Protection Officer
Updates on Personal Data Protection Policy
36. As part of our efforts to ensure that we properly manage, protect and process your personal data, we will be reviewing our policies, procedures and processes from time to time.
37. We reserve the right to amend the terms of this Personal Data Protection Policy at our absolute discretion. Any amended Personal Data Protection Policy will be posted on the Website and can be viewed at www.ikea.com/th/en/ and www.ikea.com/th/th/ No individual notice will be sent to you.
38. You are deemed to have acknowledged and agreed to any amended version of this Personal Data Protection Policy if you continue to use the Website after the changes have taken place. As such, you are encouraged to visit the above website from time to time to ensure that you are well informed of our latest policies in relation to personal data protection.
Last Updated on 12 May 2022