WE DO CARE
YOUR PRIVACY.

BMW Leasing (Thailand) Company Limited (“BMW”, “we”, “us”, or “our”) recognizes the importance of the protection of Personal Data which is any information relating to an identified or identifiable natural person. The high standards you expect from our products and services are our guideline for handling your data which may include the collection, use, disclosure, and/or transfer outside of Thailand. Our aim is to create and maintain the basis for a trusting business relationship with our customers and prospects. The confidentiality and integrity of your personal data is top priority for us.

This privacy policy (“Privacy Policy”) applies to our websites, mobile applications, call center, social networking sites, online communication channels, events and activities, and other locations where we collect your Personal Data. However, please read this Privacy Policy in conjunction with the terms and conditions of particular service that you use, which may set out separately regarding the personal information we collect about you.

We reserve the right to modify this Privacy Policy from time to time, so please review it frequently to see when this Privacy Policy was last revised. Any changes to this Privacy Policy will become effective when we post the revised Privacy Policy on our website or application. We will provide additional notice of significant updates.

1. What Personal Data we collect

We may collect or obtain the following types of information which may include your Personal Data directly or indirectly from you or other sources or through BMW AG, our affiliates, subsidiaries, other companies, or business partners. The specific type of data collected will depend on the context of your interactions with us, and the services or products you need or want from us and within BMW Group.

1) Personal details, such as title, full name, gender, age, blood type, nationality, date of birth, marital status, occupation, job title, position, business type, income, years of work, information on government-issued cards (e.g., national identification number, passport number, tax identification number, driver’s license details or similar identifiers), information on name/surname change certificate, birth certificate, marriage/divorce certificate, foreigner related documents, work permit, residence certificate, house registration, and title deed, socio-cultural data, photograph, CCTV records, conversation records, life insurance information, VISA related documents, information on withholding tax certificate, VAT registration certificate, user profile (e.g., configured news, audio provider), and other legal documents;

2) Contact details, such as postal address, delivery details, billing address, telephone number, fax number, map, location data, email address, LINE ID, Facebook account, Instagram ID, and other ID from social networking sites;

3) Financial details, such as bank account details, bank statement, financed amount, financial contract information (e.g., amount of finance, contract type, contract status, down payment, balloon amount, installment, guarantor name, down payment term, product type, balloon payment behavior), cheque details, NCB record, securities instrument details, details of deposit, tax amount, outstanding balance, arrears amount which relating to the debt collection, financial statement, company affidavit, shareholder lists and other financial related information;

4) Vehicle details, such as Vehicle Identification Number (VIN), license plate number, brand, model, year, color, engine number, chassis number, vehicle type, mileage, battery, voltage, door and hatch status, oil level, brake wear, position and movement data (e.g. time, position, speed), traffic information, environmental information, sensor information (e.g., radar, ultrasonic devices, gestures, voice), details of car insurance, credit life insurance, compulsory insurance and gap insurance, residual value, accessories, bluebook, vehicle price, due date of next service visit, vehicle check-up documents, details of ConnectedDrive and its operation, GPS coordinate and vehicle location, vehicle history report, police summon and letter, and other vehicle related information;

5) Transaction details, such as details about payment to and from you, payment date and/or time, payment amount, details about refund, date and location of purchase, address/date and time for pick up or delivery, service request form, acknowledgement of receipt, recipient signature, receipt, invoices, transaction, transaction history, location, transaction status, purchasing behaviour, and other details of products and services you have purchased, pay in slip, bill payment card, complaints and claims, intended purchasing time, and amount of debt;

6) Technical details, such as Internet Protocol (IP) address and telemetry data;

7) Behaviour details, such as information about your behavior, lifestyle, attitudes and convictions and interaction data;

8) Profile details, such as ConnectedDrive account, myBMW, myMINI account, login name or username, profile details and picture, contact history, compliant history, past orders, purchase history, your interests, preferences, feedback and satisfaction survey responses;

9) Marketing and communication details, such as your preference in receiving marketing from us, our affiliates, subsidiaries, third parties, business partners, and your communication preferences; and/or

10) Sensitive data, such as sensitive data as shown in the identification document, health data (e.g., congenital disease, allergic food), disability, biometric data (e.g. fingerprint, facial recognition), and criminal records.

11) Other information that BMW collected, used or disclosed in connection with our relationship, such as, information of our contract (e.g., contract number, contract type, retention period), application form or survey.

If you provide Personal Data of any third party to us, e.g., their name, family name, address details, and telephone number for emergency contact and debt collection, family member income; please provide this Privacy Policy for their acknowledgement and/or obtaining consents where applicable.

We will only collect, use, or disclose sensitive data on the basis of your explicit consent or where permitted by law.

We only collect the information of children, quasi-incompetent persons, and incompetent persons where their parent or guardian has given their consent. We do not knowingly collect information from customers under the age of 20 without their parental consent when it is required, or from quasi-incompetent persons and incompetent persons without their legal guardian’s consent. In the event we learn that we have unintentionally collected personal information from anyone under the age of 20 without parental consent when it is required, or from quasi-incompetent persons and incompetent persons without their legal guardians, we will delete it immediately or process only if we can rely on other legal bases apart from consent.

2. Why we collect, use and/or disclose your Personal Data

2.1. The purpose of which you have given your consent:

1) Marketing and Communications: To provide marketing, re-marketing, re-targeting, segmentation, communications, sales, special offers, promotions, notices, news, information about other products and services from BMW Group, our affiliates, subsidiaries and/or business partners which we cannot rely on other legal bases;

2) Sensitive Data: We may use your sensitive data for the following purposes:

  1. Sensitive data as shown in the identification document: for verification and authentication purpose;
  2. health data: for facilitation and providing benefit to you;
  3. disability: for facilitation and providing benefit to you;
  4. biometric data (e.g. fingerprint, facial recognition): for verification and authentication purpose;
  5. criminal records: for internal check and investigation.

2.2. The purposes we may rely on and other legal grounds for processing your Personal Data

We may also rely on (1) contractual basis, for our initiation or fulfilment of a contract with you; (2) legal obligation, for the fulfilment of our legal obligations; (3) legitimate interest, for the purpose of our legitimate interests and the legitimate interests of third parties; (4) vital interest, for preventing or suppressing a danger to a person’s life, body, or health; and/or (5) public interest, for the performance of a task carried out in the public interest or for the exercising of official authorities.

We may collect, use, and/or disclose your Personal Data for the following purposes:

1) To provide products and services to you: To enter into a contract and manage our contractual relationship with you (including contract activation, implementation, re-agreement, early termination and EOT management); to book a test drive; to provide a car registration and other registration services; to carry out welcome package, contract details, financial transaction and services related to the payments including transaction checks, verification, and cancellation; to send reminding letter and SMS; to consider for a loan offering and credit scoring; to support and perform other activities related to such services or products to process your orders, delivery, collections, returns, refund and exchange of products or services; to provide updates and on the delivery of the products, including maintenance and car repairing reservation; to provide basic ConnectedDrive services (e.g., teleservices, intelligence emergency call); to provide mobility service (roadside assistance); to process on receipt issuance, cash disbursement, account payable, invoice, and proof of purchase; to issue bill payment card; to provide an insurance premium payment, insurance fee conciliation process and other insurance related services; to send reminding letter for insurance policy renewal; to buy or sell used car and offer auction; to provide a car bidding; to inform you about car's recall; to allocate overdue customers for arrears amount collection, propose a refinance or handle on the re-possession of vehicle; to provide aftersales services;

2) Marketing and Communications: To provide marketing, re-marketing, re-targeting, segmentation, communications, sales, special offers, promotions, notices, news, information about other products and services from BMW Group, our affiliates, subsidiaries and/or business partners in accordance with preferences you have expressed directly or indirectly;

3) Participating in contests, prize draws and similar promotion: To allow you to participate to promotions, special offers, privilege, lucky draws, and other offers/promotions (e.g. for sending you reminder emails, transferring your Personal Data to fulfilment partners), technical campaign, activities, events and seminars, re-marketing, re-targeting and all related advertising services; to process and administer your account registration, gift registration, and event registration; to examine your entire user history, both online and offline; to process on your VISA application and facilitate you on overseas events/trips or incentive trips;

4) Recommendations and Personalization: To recommend products and services that might be of interest to you, identify your preferences, and personalize your experience;

5) Registration and Authentication: To register, verify, identify, and authenticate you or your identity;

6) To contact and communicate with you: To provide you with marketing communications, sales, special offers, promotions, notices, news, and information about the products and services; to process and update your information;

7) To manage our relationship with you: To communicate with you in relation to the products and services you obtain from us, within BMW Group, our affiliates, subsidiaries, and from our business partners; to process and update your information as our member; to facilitate your use of the products and services; to handle customer service-related queries, request, feedback, complains, warranty claims, disputes or indemnity; to deal with technical issues, provide technical assistance, car repairing, warranty and goodwill; to conduct customer relationship management activities (e.g., customer satisfaction index survey);

8) Profiling and data analytics: To measure your engagement with the products and services; to undertake data analytics for products and services development, market research, surveys, assessments, behaviour, statistics and segmentation, consumption trends and patterns; to know you better; to improve business performance and better adapt our content to the identified preferences of our customers; to determine the effectiveness of our promotional campaigns; to identify and resolve of issues with existing products and services, and qualitative information development;

9) To improve business operations, products, and services: To evaluate, develop, manage, improve, research and develop the services, products, system, and business operations for you and all of our customers and within BMW Group's, including but not limited to, our business partners; to measure the performance of our physical products, digital properties, and marketing campaigns; to conduct a lead generation and sales funnel management; to assure products and service quality; to conduct a legal consulting; to create aggregated and anonymized reports; to identify and resolve issues; to provide training courses for sales personnel; to improve the request and sales process;

10) To learn more about you: To learn more about the products and services you receive, and other products and services you may be interested in receiving, including profiling based on the processing of your Personal Data, for example, by looking at the types of products and services that you use from us, how you like to be contacted and so on; to learn from the satisfaction survey and customer credit evaluation;

11) Functioning of our sites, mobile application, and platform: To administer, operate, track, monitor, and manage our sites, application and platform to facilitate and ensure that they function properly, efficiently, and securely; to facilitate your experience on our sites and platform; improve layout, and content of our sites and platform;

12) IT Management: For our own business management purpose including for our IT operations, management of communication system, operation of IT security and IT security audit; internal business management for internal compliance requirements, policies, and procedures;

13) Compliance with regulatory and compliance obligations: To comply with legal obligations, legal proceedings, or government authorities' orders which can include orders from government authorities outside Thailand, and/or cooperate with court, regulators, government authorities, and law enforcement bodies when we reasonably believe we are legally required to do so, and when disclosing your Personal Data is strictly necessary to comply with the said legal obligations, proceedings, or government orders; to provide and handle VAT refund service; to issue tax invoices or full tax forms; to record and monitor communications; to handle with traffic fine letter and road tax; to send any transaction to AMLO; to send information to NCB and issue NCB letter to you; to disclose to tax authorities, financial service regulators, and other regulatory and governmental bodies, and investigating or preventing crime;

14) Protection of our interests: To protect the security and integrity of our business; to exercise our rights or protect our interest where it is necessary and lawfully to do so, for example, to detect, prevent, and respond to fraud claims, intellectual property infringement claims, or violations of law; to manage and prevent loss of our assets and property; to secure the compliance of our terms and conditions; to detect and prevent misconduct within our premises which includes our use of CCTV; to follow up on incidents; to prevent and report criminal offences; to protect the security and integrity of our business;

15) Fraud detection: To verify your identity, and to conduct legal and other regulatory compliance checks (for example, to comply with anti-money laundering regulations, and prevent fraud). This includes to perform internal audits and records, asset management, fraud database, system, and other business controls;

16) Corporate transaction: in the event of sale, transfer, merger, reorganization, or similar event we may transfer your information to one or more third parties as part of that transaction;

17) Risks: To perform risk management, audit performance, and risk assessments; and/or

18) Life: To prevent or suppress a danger to a person’s life, body, or health.

If you fail to provide your Personal Data when requested, we may not be able to provide our products and services to you. We may request your consent from time to time, if required.

3. To whom we may disclose or transfer your Personal Data

We may disclose or transfer your Personal Data to the following third parties who collects, uses and discloses Personal Data in accordance with the purpose under this Policy. These third parties may be located in Thailand and areas outside Thailand. You can visit their privacy policy to learn more details on how they collect, use and disclose your Personal Data as you are also subject to their privacy policies.

3.1. BMW Group's data ecosystem

As BMW Leasing (Thailand) Company Limited is part of a BMW Group (which include both companies in Thailand and overseas under BMW AG) which all collaborate and partially share customer services and systems including website-related services and systems, we may need to transfer your Personal Data to, or otherwise allow access to such Personal Data by other companies within BMW Group for the purposes set out in this Privacy Policy. This will allow other companies within BMW Group to rely on consent obtained by BMW Leasing (Thailand) Company Limited.

3.2. Our service providers

We may use other companies, agents or contractors to perform services on behalf or to assist with the provision of products and services to you. We may share your Personal Data to our service providers or third-party suppliers including, but not limited to (1) internet, software, website developer, digital media, IT service providers and IT maintenance & support company; (2) logistic and courier service providers; (3) payment and payment system service providers; (4) research and market surveillance agencies; (5) analytics service providers; (6) survey agencies; (7) auditors; (8) marketing, advertising media, designer, creative, and communications agencies; (9) call center; (10) campaign, event, and market organizers, and CRM agency; (11) telecommunications and communication service providers; (12) outsourced administrative service providers; (13) data storage and cloud service providers; (14) printing service providers; (15) insurance company and broker; and/or (16) auction house service provider.

In the course of providing such services, the service providers may have access to your Personal Data. However, we will only provide our service providers with the information that is necessary for them to perform the services, and we ask them not to use your information for any other purposes. We will ensure that the service providers we work with will keep your Personal Data secure as required under the laws.

3.3. Our business partners

We may transfer your Personal Data to our business partners to conduct business and services related to banking, finance, credit, loan, vehicle, insurance, telecommunications, marketing, retail, wholesale, equipment rental, including platform sellers or providers whom we may jointly offer products or services, or whose products or services may be offered to you.

3.4. Authorized dealer and sale representative agencies

From time to time, BMW Leasing (Thailand) Company Limited will share and receive Personal Data from the authorized dealer, that you choose, or located near you, to serve you with our services. You can choose your assigned authorized dealer by our Online Form https://yourbmwleasingthailand.com or when we offer the specific campaign to you or contacting us by phone at 1397.

3.5. Use of Facebook social plugins on www.bmw.co.th

One of the features of the BMW AG Internet presence on the domain www.bmw.co.th is that it uses what are called social plugins ('plugins') from the social network facebook.com, which are operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA ('Facebook'). These plugins are indicated by a Facebook logo.

When you access the BMW AG Internet presence on the domain www.bmw.co.th , your browser establishes a direct connection with the Facebook servers. The content of the plugin is transferred by Facebook directly to your browser, which then integrates it into the website.

Integration of the plugin causes Facebook to receive the information that you have accessed on the corresponding page of the BMW AG Internet presence. If you are logged in with Facebook, it will be able to assign your visit to your Facebook account. Please note that an exchange of this information already takes place when you visit our Internet presence on the domain www.bmw.co.th, regardless of whether you interact with the plugin or not. If you interact with the plugins, such as by pressing the 'Like' button, the corresponding information is sent directly to Facebook by your browser and saved there. You can find information on the purpose and extent of data acquisition as well as how the data is processed further and used by Facebook, together with your rights and optional settings to protect your private sphere, in the Facebook data protection notes (http://www.facebook.com/policy.php).

If you do not want Facebook to gather data about you via our Internet presence, you must log out of Facebook before visiting the BMW AG Internet presence on the domain www.bmw.co.th

3.6. Third parties required by law

In certain circumstances, we may be required to disclose or share your Personal Data in order to comply with a legal or regulatory obligations. This includes any law enforcement agency, court, regulator, government authority or other third party where we believe it is necessary to comply with a legal or regulatory obligation, or otherwise to protect our rights, the rights of any third party or individuals’ personal safety, or to detect, prevent, or otherwise address fraud, security, or safety issues.

3.7. Professional advisors

This includes lawyers, technicians and auditors who assist in running our business, and defending or bringing any legal claims.

3.8. Associations

We may transfer your Personal Data to Thailand Hire-Purchase Association.

3.9 Assignee of rights and/or obligations

Third parties as our assignee, in the event of any reorganization, merger, business transfer, whether in whole or in part, sale, purchase, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock or similar transaction; will comply with this Privacy Policy to respect your Personal Data.

4. International transfers of your Personal Data

We may disclose or transfer your Personal Data to BMW AG, our affiliates, subsidiaries, third parties or servers located overseas, which the Personal Data Protection Committee under the Thai Personal Data Protection Act B.E. 2562 has not ruled that the destination countries have adequate data protection standard. When we transfer your personal data outside Thailand, we will take steps and measures to ensure that your Personal Data is securely transferred and that the receiving parties have in place suitable data protection standards or other derogations as allowed by laws. We will request your consent where consent to cross-border transfer is required by law.

5. How long do we keep your Personal Data

We retain your Personal Data for as long as is reasonably necessary to fulfil purpose for which we obtained it, and to comply with our legal and regulatory obligations. If data is processed for several purposes, the data is deleted automatically or saved in a form that cannot be traced back to you once the last specified purpose has been met. However, we may have to retain your Personal Data for a longer duration, as required by applicable law.

6. Cookies and pixel and how they are used

If you visit our websites, we will gather certain information automatically from you by using cookies regarding visitor browsing history.

A cookie is a small text file which is copied onto your hard disk by a website. Cookies do not cause any damage to your computer and do not contain any viruses. The cookies from our websites do not gather any Personal Data about you. As a rule, cookies are only used on our websites for the length of your session for the purpose of anonymous, statistical assessments and for improving user-friendliness. Cookies may occasionally serve an additional purpose in certain sections of the website. You will be informed of this if you access one of these sections.

We also set up pixel which is an analytics tool which we use to understand you more based on your actions that you take on our website. This will help us to know more about you.

You can disable cookies and pixel settings by visiting their browser settings and configure privacy settings to restrict any future collection of cookies. (https://www.bmw.co.th/th/footer/footer-section/cookie-policy.html)

7. Your rights as a data subject

Subject to applicable laws and exceptions thereof, you may have the following rights to:

1) Access: You may have the right to access or request a copy of the Personal Data we are collecting, using and disclosing about you. For your own privacy and security, we may require you to prove your identity before providing the requested information to you.

2) Rectification: You may have the right to have incomplete, inaccurate, misleading, or not up-to-date Personal Data that we collect, use and disclose about you rectified.

3) Data Portability: You may have the right to obtain Personal Data we hold about you, in a structured, electronic format, and to send or transfer such data to another data controller, where this is (a) Personal Data which you have provided to us, and (b) if we are processing such data on the basis of your consent or to perform a contract with you.

4) Objection: You may have the right to object to certain collection, use and disclosure of your Personal Data such as objecting to direct marketing.

5) Restriction: You may have the right to restrict the use of your Personal Data in certain circumstances.

6) Withdraw Consent: For the purposes you have consented to our collecting, using and disclosing of your Personal Data, you have the right to withdraw your consent at any time.

7) Deletion: You may have the right to request that we delete or de-identity Personal Data that we collect, use and disclose about you, except we are not obligated to do so if we need to retain such data in order to comply with a legal obligation or to establish, exercise, or defend legal claims.

8) Lodge a complaint: You may have the right to lodge a complaint to the competent authority where you believe our collection, use and disclosure of your Personal Data is unlawful or noncompliant with applicable data protection law.

8. Our Contact Details

If you wish to contact us to exercise the rights relating to your Personal Data or if you have any queries about your Personal Data under this Privacy Policy, please contact us or our Data Protection Officer at:

Company Name:

BMW Leasing (Thailand) Company Limited.

Address:

1875 17th floor, One Bangkok Tower 3, Rama 4 Road, Lumphini Sub-District, Pathumwan District, Bangkok 10330.

For Data Subject Right Request

E-mail:

Contact Number:

1397

Data Privacy Protection Officer

Contact Number:

+662 305 4390