Privacy Notice for Voting and Payment Systems
Miss Grand International Public Company Limited recognizes the importance of personal data and respects the rights of data subjects. Therefore, we have prepared this Privacy Notice to explain our policies, processes, and purposes regarding the collection, use, disclosure, and/or international transfer of your personal data in compliance with the Personal Data Protection Act B.E. 2562 (2019) (PDPA) and related laws. This ensures that your personal data will be used strictly in accordance with its intended purposes and the law.
Please read this Privacy Notice carefully to ensure that you acknowledge and understand the purposes for processing your personal data.
1. Sources of Personal Data Collection We collect your personal data from two main sources:
-
(1) Collected directly from you through voting transactions, payments, or communications with the platform.
-
(2) Collected automatically via technological systems when you access the platform (e.g., cookies or technical log systems).
2. Types of Personal Data Collected Personal data means any information relating to a person which enables the identification of such person, whether directly or indirectly (excluding the data of deceased persons). Sensitive personal data refers to personal data classified as sensitive under Section 26 of the PDPA. To support the voting and payment systems, the personal data we collect may include:
-
Transaction and Payment Data: Voting package purchase history, transaction status, reference numbers from payment service providers (Charge ID / Transaction ID), and cryptocurrency Wallet Addresses.
-
Technical and Device Data: IP Address or Hashed IP, Device Data, browser type, and Cookies to prevent fraudulent voting and duplicate transactions.
-
Contact Information (in case of contacting support): First name, last name, email, phone number, or social media account details.
Note: If you refuse to provide the personal data necessary to enter into a contract or use our services, we may not be able to fully perform the contract or provide the services.
3. Purposes and Legal Bases for Processing Personal Data We process your data under the following legal bases:
-
3.1 Contractual Basis: To process your voting package orders, handle payments (both fiat and cryptocurrency), and record votes into the system in accordance with the Terms and Conditions of service.
-
3.2 Legitimate Interest: To maintain the security of the voting system, prevent fraud, automated bot voting, and system attacks, and to use as technical evidence for dispute resolution or chargebacks from banks.
-
3.3 Legal Obligation: To comply with applicable laws, such as tax laws, Anti-Money Laundering (AML) laws, or orders from competent legal authorities.
-
3.4 Consent: To achieve the purposes for which you have explicitly given consent on a case-by-case basis (if any).
4. Rights of the Data Subject Under the PDPA, you have the following rights:
-
4.1 Right to Withdraw Consent: You have the right to withdraw your consent for processing personal data at any time. However, the withdrawal will not affect the processing of personal data that you have already lawfully consented to.
-
4.2 Right to Access: You have the right to request access to and obtain a copy of your personal data, and to request the disclosure of the acquisition of the personal data obtained without your consent.
-
4.3 Right to Rectification: You have the right to request that we correct your personal data to be accurate, up-to-date, complete, and not misleading.
-
4.4 Right to Erasure: You have the right to request that we delete, destroy, or anonymize your personal data if it is no longer necessary, if you withdraw consent, if you object to the processing, or if the processing is unlawful.
-
4.5 Right to Restriction of Processing: You have the right to request that we suspend the use of your personal data while we are verifying your rectification request, when you request suspension instead of deletion, or pending verification of an objection request.
-
4.6 Right to Data Portability: You may request to receive your personal data in a structured, commonly used electronic format and request its transfer to another data controller.
-
4.7 Right to Object: You have the right to object to the processing of your personal data based on legitimate interest, public interest, direct marketing, or scientific, historical, or statistical research purposes.
-
4.8 Right to Lodge a Complaint: You have the right to file a complaint with the relevant competent authority if you believe our collection, use, disclosure, and/or transfer of your personal data violates the PDPA.
Note: We may deny your request based on legal grounds, and we will inform you of the reasons for such denial.
5. Disclosure of Personal Data We may disclose your personal data to the following persons or organizations:
-
Any other organization affiliated with the Company, including directors, executives, employees, staff, contractors, agents, and advisors.
-
Payment Gateways, financial institutions, and Public Blockchain Networks for cryptocurrency transactions.
-
Third-party Service Providers such as cloud computing providers, fraud prevention service providers, agents, or subcontractors acting on behalf of the Company, including data processors.
-
Business partners, agents, or other organizations, such as independent auditors, where disclosure is for specific purposes under legal bases and with appropriate security measures.
-
Government agencies and/or regulatory bodies, such as the Anti-Money Laundering Office (AMLO).
-
Social media service providers (if system integration is utilized).
-
Authorized persons, sub-authorized persons, agents, or legal representatives.
6. Cross-Border Transfer of Personal Data We may need to send or transfer your personal data to overseas service providers or cloud service providers whose data security standards are equivalent to or higher than those in Thailand. If the destination country has lower or inadequate security standards, we will ensure that the transfer complies with the PDPA and that necessary and appropriate security measures are in place.
7. Data Retention Period We will retain your personal data for as long as necessary to fulfill the purposes for which it was collected. However, for data related to financial transactions and voting evidence, we may need to retain it for a longer period if required by law (e.g., accounting and tax laws) or to use as evidence in dispute resolutions and chargebacks. Once this period expires, we will delete, destroy, or anonymize the data so it can no longer identify you.
8. Security of Personal Data We have implemented appropriate security measures to prevent unauthorized or unlawful loss, access, use, alteration, or disclosure of your personal data. If we engage third parties to process your personal data, we will require them to keep the data confidential, implement security measures, and strictly prohibit the use or disclosure of the data for any unauthorized or unlawful purposes.
9. Changes to the Privacy Notice We may amend or update this Privacy Notice from time to time. The updated version will be published on our website and other platforms. However, if such amendments significantly affect you, we will provide adequate notice before any changes take effect.
10. Contact Us If you have any questions regarding this Privacy Notice, please contact us using the details below:
-
Company Name: Miss Grand International Public Company Limited
-
Address: 1751 Soi Lat Phrao 94, Lat Phrao Road, Phlapphla, Wang Thonglang, Bangkok 10310
-
Phone: 02-5309656
-
Email: [email protected] / [email protected]
Effective Date : 15 September 2026