Sister Safe
ซิสเตอร์เซฟ
Privacy Policy
This Privacy Policy (this “Policy”) explains how Pitch Marketing LLC-FZ (“Company,” “we,” “us”) collects, uses, discloses, and protects information in connection with the Sister Safe mobile application and the sistersafe.io website (collectively, the “Service”). This Policy should be read together with the Terms and Conditions. Capitalized terms not defined in this Policy have the meanings given to them in the Terms and Conditions.
นโยบายความเป็นส่วนตัวฉบับนี้ (“นโยบาย”) อธิบายวิธีที่ Pitch Marketing LLC-FZ (“บริษัท” หรือ “เรา”) เก็บรวบรวม ใช้ เปิดเผย และปกป้องข้อมูลที่เกี่ยวข้องกับแอปพลิเคชันมือถือ Sister Safe และเว็บไซต์ sistersafe.io (เรียกรวมกันว่า “บริการ”) นโยบายฉบับนี้ควรอ่านร่วมกับข้อกำหนดและเงื่อนไข คำที่มีตัวพิมพ์ใหญ่ที่ไม่ได้นิยามไว้ในนโยบายนี้ให้มีความหมายตามที่กำหนดไว้ในข้อกำหนดและเงื่อนไข
1. Data Controller
The data controller responsible for the information described in this Policy is Pitch Marketing LLC-FZ, a limited liability company established in a free zone of Dubai, United Arab Emirates, with its registered office at 6th Floor, Business Center 1, Meydan Hotel, Nad Al Sheba, Dubai, United Arab Emirates. You may contact us regarding this Policy at [email protected].
ผู้ควบคุมข้อมูลที่รับผิดชอบข้อมูลที่อธิบายในนโยบายนี้คือ Pitch Marketing LLC-FZ นิติบุคคลจำกัดความรับผิดที่จัดตั้งขึ้นในเขตปลอดอากรของดูไบ สหรัฐอาหรับเอมิเรตส์ สำนักงานจดทะเบียนตั้งอยู่ที่ 6th Floor, Business Center 1, Meydan Hotel, Nad Al Sheba, Dubai, United Arab Emirates ท่านสามารถติดต่อเราเกี่ยวกับนโยบายนี้ได้ที่ [email protected]
2. Information We Collect
We collect the following categories of information in connection with the Service:
- Account information. A self-selected anonymous username, a hashed password, and the dedicated email address you provide for account verification and notices, as described in Section 3 of the Terms.
- Safety Session and check-in data. Encrypted Date/session details, all-clear code hashes, check-in timestamps, and interval configuration.
- Location data. Approximate or precise device location collected during an active Safety Session where you have enabled location sharing, and associated timestamps.
- Media and audio. Photographs, videos, screenshots, and audio recordings you choose to upload or that are generated through the audio-recording feature described in Section 8 of the Terms.
- Safe Contact information. Encrypted label, username, email, phone number, and name information you provide for the people you designate as Safe Contacts.
- Counterparty and matching data. Social-media handles, contribution records, reviews, and other information you submit about Counterparties, and, if you use the View My Data Service, the matching information you submit about yourself (social profiles, contact identifiers, photographs, or video).
- Health Contact Tracing data. If you opt in, anonymized self-reported health-condition results, anonymized contact-linkage data, and the subscription email/payment identifier needed to route alerts, as described in Section 13 of the Terms and Section 9 of this Policy.
- Payment data. Where you use a paid feature (the View My Data Service or a Health Contact Tracing Service subscription for non-exempt Users), payment details are collected and processed by our third-party payment processor; we do not store full payment-card numbers on our own systems.
- Technical and device data. IP address, device identifiers, push-notification tokens, app version, operating system, and diagnostic/log data.
เราเก็บรวบรวมข้อมูลประเภทต่อไปนี้ที่เกี่ยวข้องกับบริการ:
- ข้อมูลบัญชี ชื่อผู้ใช้แบบไม่ระบุตัวตนที่เลือกเอง รหัสผ่านที่ถูกแฮช และอีเมลเฉพาะที่ท่านให้ไว้เพื่อการยืนยันบัญชีและการแจ้งเตือน
- ข้อมูลเซสชันความปลอดภัยและการเช็คอิน รายละเอียดงาน/เซสชันที่เข้ารหัส แฮชของรหัสยืนยันความปลอดภัย เวลาการเช็คอิน และการตั้งค่าช่วงเวลา
- ข้อมูลตำแหน่ง ตำแหน่งอุปกรณ์โดยประมาณหรือแม่นยำที่เก็บระหว่างเซสชันความปลอดภัยที่ใช้งานอยู่เมื่อท่านเปิดใช้งานการแบ่งปันตำแหน่ง
- สื่อและเสียง รูปภาพ วิดีโอ ภาพหน้าจอ และการบันทึกเสียงที่ท่านเลือกอัปโหลดหรือที่สร้างขึ้นผ่านฟีเจอร์บันทึกเสียง
- ข้อมูลผู้ติดต่อเพื่อความปลอดภัย ป้ายชื่อ ชื่อผู้ใช้ อีเมล หมายเลขโทรศัพท์ และชื่อที่เข้ารหัสของบุคคลที่ท่านกำหนดเป็นผู้ติดต่อเพื่อความปลอดภัย
- ข้อมูลคู่กรณีและการจับคู่ ชื่อโซเชียลมีเดีย บันทึกการมีส่วนร่วม รีวิว และข้อมูลอื่นที่ท่านส่งเกี่ยวกับคู่กรณี และหากท่านใช้บริการดูข้อมูลของฉัน ข้อมูลจับคู่ที่ท่านส่งเกี่ยวกับตัวท่านเอง
- ข้อมูลบริการติดตามการสัมผัสด้านสุขภาพ หากท่านเลือกใช้บริการ ผลด้านสุขภาพที่รายงานด้วยตนเองแบบไม่ระบุตัวตน ข้อมูลการเชื่อมโยงการสัมผัสแบบไม่ระบุตัวตน และตัวระบุอีเมล/การชำระเงินสำหรับสมาชิกที่จำเป็นต่อการส่งการแจ้งเตือน
- ข้อมูลการชำระเงิน เมื่อท่านใช้ฟีเจอร์แบบมีค่าใช้จ่าย รายละเอียดการชำระเงินจะถูกเก็บและประมวลผลโดยผู้ประมวลผลการชำระเงินบุคคลที่สามของเรา เราไม่จัดเก็บหมายเลขบัตรชำระเงินแบบเต็มในระบบของเราเอง
- ข้อมูลทางเทคนิคและอุปกรณ์ ที่อยู่ไอพี ตัวระบุอุปกรณ์ โทเคนการแจ้งเตือนแบบพุช เวอร์ชันแอป ระบบปฏิบัติการ และข้อมูลการวินิจฉัย/บันทึก
3. The Anonymity Model and Your Re-Identification Risk
The Service is designed around anonymous usernames and does not require government identification for ordinary safety features. However, anonymity within our systems is not the same as anonymity from all possible correlation. If you use an email address, phone number, photograph, or social-media handle for the Service that you also use elsewhere — including on other websites, applications, marketing lists, or accounts — that shared identifier can function as a bridge that allows the data associated with it inside the Service to be soft-matched, correlated, or linked to your identity on those other platforms by anyone who separately obtains or already holds that identifier, including data brokers, advertisers, or, in the event of a data breach affecting us or a third party, malicious actors.
We strongly recommend using an email address created for the sole purpose of using the Service to minimize this risk. We apply industry-standard technical and organizational security measures, described in Section 8, but no security measure is perfect, and we cannot control, and are not responsible for, re-identification risk that arises from your own reuse of identifying information across contexts outside our control.
บริการนี้ออกแบบขึ้นโดยใช้ชื่อผู้ใช้แบบไม่ระบุตัวตนและไม่กำหนดให้ต้องใช้เอกสารประจำตัวที่ออกโดยรัฐสำหรับฟีเจอร์ความปลอดภัยทั่วไป อย่างไรก็ตาม การไม่ระบุตัวตนภายในระบบของเราไม่เหมือนกับการไม่สามารถเชื่อมโยงได้ทั้งหมด หากท่านใช้อีเมล หมายเลขโทรศัพท์ รูปภาพ หรือชื่อโซเชียลมีเดียสำหรับบริการนี้ซึ่งท่านใช้ที่อื่นด้วย รวมถึงเว็บไซต์ แอปพลิเคชัน รายชื่อทางการตลาด หรือบัญชีอื่น ตัวระบุที่ใช้ร่วมกันนั้นสามารถทำหน้าที่เป็นสะพานที่ทำให้ข้อมูลที่เกี่ยวข้องภายในบริการถูกจับคู่แบบผ่อนคลาย เชื่อมโยง หรือโยงกับตัวตนของท่านบนแพลตฟอร์มอื่นโดยผู้ที่ได้รับหรือมีตัวระบุนั้นอยู่แล้วแยกกัน รวมถึงนายหน้าข้อมูล ผู้โฆษณา หรือในกรณีที่เกิดการรั่วไหลของข้อมูลที่กระทบเราหรือบุคคลที่สาม ผู้ไม่หวังดี
เราขอแนะนำอย่างยิ่งให้ใช้อีเมลที่สร้างขึ้นเพื่อวัตถุประสงค์เดียวคือการใช้บริการนี้เพื่อลดความเสี่ยงดังกล่าว เราใช้มาตรการความปลอดภัยทางเทคนิคและองค์กรตามมาตรฐานอุตสาหกรรมตามที่อธิบายในข้อ 8 แต่ไม่มีมาตรการความปลอดภัยใดที่สมบูรณ์แบบ และเราไม่สามารถควบคุมและไม่รับผิดชอบต่อความเสี่ยงในการระบุตัวตนใหม่ที่เกิดจากการใช้ข้อมูลระบุตัวตนซ้ำของท่านเองในบริบทที่อยู่นอกเหนือการควบคุมของเรา
4. How We Use Information
We use the information described in Section 2 to: operate and provide the Service, including Safety Sessions, Safety Alerts, and Safe Contact notifications; verify your Account and secure it against unauthorized access; deliver transactional emails (such as verification codes, safety alerts, and recovery emails) through our email service provider; process payments for the View My Data Service and Health Contact Tracing Service subscriptions; perform the human- and AI-assisted matching described in Section 7 of this Policy; operate the Health Contact Tracing Service described in Section 9 of this Policy; maintain audit, security, and abuse-prevention logs; comply with legal obligations and respond to lawful requests as described in Section 6; and improve, troubleshoot, and secure the Service. We do not use your information for third-party advertising, and we do not build advertising profiles about you.
เราใช้ข้อมูลตามข้อ 2 เพื่อดำเนินการและให้บริการ รวมถึงเซสชันความปลอดภัย การแจ้งเตือนความปลอดภัย และการแจ้งผู้ติดต่อเพื่อความปลอดภัย ยืนยันบัญชีของท่านและปกป้องจากการเข้าถึงโดยไม่ได้รับอนุญาต ส่งอีเมลเชิงธุรกรรม (เช่น รหัสยืนยัน การแจ้งเตือนความปลอดภัย และอีเมลกู้คืน) ผ่านผู้ให้บริการอีเมลของเรา ประมวลผลการชำระเงินสำหรับบริการดูข้อมูลของฉันและการสมัครสมาชิกบริการติดตามการสัมผัสด้านสุขภาพ ดำเนินการจับคู่โดยมนุษย์และเอไอตามข้อ 7 ของนโยบายนี้ ดำเนินการบริการติดตามการสัมผัสด้านสุขภาพตามข้อ 9 ของนโยบายนี้ รักษาบันทึกการตรวจสอบ ความปลอดภัย และการป้องกันการใช้งานในทางที่ผิด ปฏิบัติตามข้อผูกพันทางกฎหมายและตอบสนองต่อคำขอที่ชอบด้วยกฎหมายตามข้อ 6 และปรับปรุง แก้ไขปัญหา และรักษาความปลอดภัยของบริการ เราไม่ใช้ข้อมูลของท่านเพื่อการโฆษณาของบุคคลที่สาม และเราไม่สร้างโปรไฟล์การโฆษณาเกี่ยวกับท่าน
5. Legal Bases for Processing
Where applicable data-protection law (including the Thailand Personal Data Protection Act and comparable regimes) requires a legal basis for processing, we rely on: your consent (for example, when you opt in to location sharing, audio recording, or the Health Contact Tracing Service); performance of our contract with you under the Terms (for example, operating your Account and Safety Sessions); our legitimate interests in operating, securing, and improving the Service, provided those interests are not overridden by your rights; and compliance with a legal obligation (for example, responding to a lawful law-enforcement request under Section 6). Where processing relies on consent, you may withdraw that consent at any time by adjusting your settings or contacting us, without affecting the lawfulness of processing before withdrawal.
ในกรณีที่กฎหมายคุ้มครองข้อมูลที่ใช้บังคับ (รวมถึงพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคลของประเทศไทยและกฎหมายที่เทียบเคียงได้) กำหนดให้ต้องมีฐานทางกฎหมายในการประมวลผล เราอาศัยฐานดังต่อไปนี้ ความยินยอมของท่าน (เช่น เมื่อท่านเลือกเปิดใช้งานการแบ่งปันตำแหน่ง การบันทึกเสียง หรือบริการติดตามการสัมผัสด้านสุขภาพ) การปฏิบัติตามสัญญาของเรากับท่านภายใต้ข้อกำหนด (เช่น การดำเนินการบัญชีและเซสชันความปลอดภัยของท่าน) ประโยชน์โดยชอบด้วยกฎหมายของเราในการดำเนินการ รักษาความปลอดภัย และปรับปรุงบริการ โดยที่ประโยชน์ดังกล่าวไม่ถูกลบล้างด้วยสิทธิ์ของท่าน และการปฏิบัติตามข้อผูกพันทางกฎหมาย (เช่น การตอบสนองต่อคำขอบังคับใช้กฎหมายที่ชอบด้วยกฎหมายตามข้อ 6) ในกรณีที่การประมวลผลอาศัยความยินยอม ท่านสามารถถอนความยินยอมได้ทุกเมื่อโดยปรับการตั้งค่าหรือติดต่อเรา โดยไม่กระทบต่อความชอบด้วยกฎหมายของการประมวลผลก่อนการถอนความยินยอม
6. Disclosure of Information
We do not sell your personal data to third parties. We disclose information only in the following circumstances:
- Service providers. To infrastructure and processing partners who perform services on our behalf, including email delivery, push notification, cloud storage/CDN, mapping, and payment processing, under contractual confidentiality and data-protection obligations.
- Safe Contacts and authorized viewers. Information relevant to a Safety Alert is shared with your designated Safe Contacts and, where a viewer link/code has been authorized, with the authorized incident viewer.
- Law enforcement and government authorities. As described in Section 9 of the Terms, we may disclose information (a) in response to a valid official legal request, subpoena, warrant, or court order, or (b) on an expedited basis, prior to a formal legal process, where explicit in-application consent for faster release has been given by a User, Safe Contact, or authorized viewer — for example, to help locate a User quickly during a genuine emergency or duress alert.
- Legal and safety reasons. Where we form a good-faith belief that disclosure is necessary to prevent death or serious bodily harm, to prevent fraud or abuse of the Service, or to protect the rights, property, or safety of the Company, our Users, or the public.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.
We do not disclose the identity of a User who anonymously submits a Counterparty review or a Health Contact Tracing self-report to any other User under any circumstance.
เราไม่ขายข้อมูลส่วนบุคคลของท่านให้บุคคลที่สาม เราเปิดเผยข้อมูลเฉพาะในกรณีต่อไปนี้:
- ผู้ให้บริการ แก่พันธมิตรด้านโครงสร้างพื้นฐานและการประมวลผลที่ให้บริการในนามของเรา รวมถึงการส่งอีเมล การแจ้งเตือนแบบพุช การจัดเก็บข้อมูลบนคลาวด์/ซีดีเอ็น แผนที่ และการประมวลผลการชำระเงิน ภายใต้ข้อผูกพันด้านการรักษาความลับและการปกป้องข้อมูลตามสัญญา
- ผู้ติดต่อเพื่อความปลอดภัยและผู้ดูที่ได้รับอนุญาต ข้อมูลที่เกี่ยวข้องกับการแจ้งเตือนความปลอดภัยจะถูกแบ่งปันกับผู้ติดต่อเพื่อความปลอดภัยที่ท่านกำหนด และในกรณีที่มีการอนุญาตลิงก์/รหัสผู้ดู กับผู้ดูเหตุการณ์ที่ได้รับอนุญาต
- หน่วยงานบังคับใช้กฎหมายและหน่วยงานรัฐ ตามที่อธิบายในข้อ 9 ของข้อกำหนด เราอาจเปิดเผยข้อมูล (ก) เพื่อตอบสนองต่อคำขอทางกฎหมายที่ถูกต้อง หมายเรียก หมายค้น หรือคำสั่งศาล หรือ (ข) บนพื้นฐานเร่งด่วนก่อนกระบวนการทางการ ในกรณีที่ผู้ใช้ ผู้ติดต่อเพื่อความปลอดภัย หรือผู้ดูที่ได้รับอนุญาตให้ความยินยอมในแอปอย่างชัดแจ้งสำหรับการเปิดเผยที่รวดเร็วขึ้น เช่น เพื่อช่วยระบุตำแหน่งผู้ใช้อย่างรวดเร็วระหว่างเหตุฉุกเฉินหรือการแจ้งเตือนภาวะคับขันจริง
- เหตุผลทางกฎหมายและความปลอดภัย ในกรณีที่เราเชื่อโดยสุจริตว่าจำเป็นต้องเปิดเผยเพื่อป้องกันการเสียชีวิตหรือการบาดเจ็บสาหัส ป้องกันการฉ้อโกงหรือการใช้งานในทางที่ผิด หรือปกป้องสิทธิ์ ทรัพย์สิน หรือความปลอดภัยของบริษัท ผู้ใช้ของเรา หรือสาธารณะ
- การโอนธุรกิจ ในกรณีการควบรวม การเข้าซื้อ การจัดหาเงินทุน หรือการขายทรัพย์สิน ภายใต้การคุ้มครองความลับที่เหมาะสม
เราไม่เปิดเผยตัวตนของผู้ใช้ที่ส่งรีวิวคู่กรณีหรือรายงานผลด้านสุขภาพด้วยตนเองแบบไม่ระบุตัวตนแก่ผู้ใช้อื่นใดไม่ว่าในกรณีใด
7. View My Data Service: Matching, Payment, and Deletion of Association
Uploaded Counterparty information (images, screenshots, social-media links, contact details, and reviews) is stored without any verified association to a specific identified individual. We do not, at the time of collection, know or record whose personal identity corresponds to that data.
When you submit a request through the View My Data Service, you provide matching information about yourself (which may include social-media handles, contact identifiers, and photographs or a short video) and payment information to cover the applicable fee. A combination of trained human reviewers and automated tools, which may include facial-recognition-assisted image comparison, compares your submitted matching information against the anonymously stored Counterparty data to identify data that reasonably appears to correspond to you, and that data is then released to you.
Because payment necessarily identifies the payer, completing a request temporarily links your payment identity to your search request and its result. To limit the duration and scope of this exposure, we delete the association between (a) your search request and submitted matching information, and (b) the specific report and search criteria used to generate your result, immediately after the result has been delivered to you. Following this deletion, no record in our databases links your payment information to the underlying, still-anonymous Counterparty data, and the underlying data continues to be stored without any verified owner. We retain only the minimum transactional/accounting record required by Applicable Law (such as tax and payment-processor records), which does not include the substantive matching content or search result itself.
ข้อมูลคู่กรณีที่อัปโหลด (รูปภาพ ภาพหน้าจอ ลิงก์โซเชียลมีเดีย ข้อมูลติดต่อ และรีวิว) จะถูกจัดเก็บโดยไม่มีการเชื่อมโยงที่ผ่านการยืนยันกับบุคคลที่ระบุตัวตนเฉพาะเจาะจง เราไม่ทราบหรือบันทึกในขณะเก็บรวบรวมว่าข้อมูลดังกล่าวเป็นของผู้ใด
เมื่อท่านยื่นคำขอผ่านบริการดูข้อมูลของฉัน ท่านให้ข้อมูลจับคู่เกี่ยวกับตัวท่านเอง (ซึ่งอาจรวมถึงชื่อโซเชียลมีเดีย ข้อมูลติดต่อ และรูปภาพหรือวิดีโอสั้น) และข้อมูลการชำระเงินเพื่อครอบคลุมค่าบริการที่ใช้บังคับ การผสมผสานระหว่างเจ้าหน้าที่ที่ผ่านการฝึกอบรมและเครื่องมืออัตโนมัติ ซึ่งอาจรวมถึงการเปรียบเทียบภาพด้วยระบบจดจำใบหน้า จะเปรียบเทียบข้อมูลจับคู่ที่ท่านส่งกับข้อมูลคู่กรณีที่จัดเก็บแบบไม่ระบุตัวตนเพื่อระบุข้อมูลที่ดูเหมือนตรงกับท่านอย่างสมเหตุสมผล และข้อมูลดังกล่าวจะถูกเปิดเผยให้ท่าน
เนื่องจากการชำระเงินจำเป็นต้องระบุตัวผู้ชำระเงิน การดำเนินการตามคำขอให้เสร็จสมบูรณ์จะเชื่อมโยงตัวตนการชำระเงินของท่านกับคำขอค้นหาและผลลัพธ์ของท่านเป็นการชั่วคราว เพื่อจำกัดระยะเวลาและขอบเขตของความเสี่ยงนี้ เราจะลบความเชื่อมโยงระหว่าง (ก) คำขอค้นหาและข้อมูลจับคู่ที่ท่านส่งมา และ (ข) รายงานและเกณฑ์การค้นหาที่ใช้สร้างผลลัพธ์ของท่านทันทีหลังจากส่งผลลัพธ์ให้ท่านแล้ว หลังจากการลบข้อมูลนี้ จะไม่มีบันทึกในฐานข้อมูลของเราที่เชื่อมโยงข้อมูลการชำระเงินของท่านกับข้อมูลคู่กรณีที่เกี่ยวข้องซึ่งยังคงไม่ระบุตัวตน และข้อมูลดังกล่าวจะยังคงจัดเก็บโดยไม่มีเจ้าของที่ยืนยันแล้ว เราเก็บรักษาเพียงบันทึกทางธุรกรรม/บัญชีขั้นต่ำที่กฎหมายที่ใช้บังคับกำหนด (เช่น บันทึกภาษีและผู้ประมวลผลการชำระเงิน) ซึ่งไม่รวมเนื้อหาการจับคู่หรือผลการค้นหาที่เป็นสาระสำคัญ
8. Data Security
We implement industry-standard technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, or destruction, including encryption of sensitive fields at rest, hashed and peppered storage of codes and passwords, access controls, rate limiting, and audit logging. No method of transmission over the internet, and no method of electronic storage, is completely secure, and we cannot guarantee absolute security. In the event of a data breach affecting your information, the risk described in Section 3 (that reused identifiers such as an email address, phone number, or photograph may allow correlation with your identity on other platforms) means that a breach could have consequences beyond the Service itself. We will notify affected Users and relevant authorities where required by Applicable Law.
เราใช้มาตรการทางเทคนิคและองค์กรตามมาตรฐานอุตสาหกรรมที่ออกแบบมาเพื่อปกป้องข้อมูลจากการเข้าถึง การเปลี่ยนแปลง การเปิดเผย หรือการทำลายโดยไม่ได้รับอนุญาต รวมถึงการเข้ารหัสข้อมูลที่ละเอียดอ่อนขณะจัดเก็บ การจัดเก็บรหัสและรหัสผ่านแบบแฮชพร้อมเกลือลับ การควบคุมการเข้าถึง การจำกัดอัตรา และการบันทึกการตรวจสอบ ไม่มีวิธีการส่งข้อมูลผ่านอินเทอร์เน็ตหรือวิธีการจัดเก็บข้อมูลอิเล็กทรอนิกส์ใดที่ปลอดภัยอย่างสมบูรณ์ และเราไม่สามารถรับประกันความปลอดภัยได้อย่างแน่นอน ในกรณีที่เกิดการรั่วไหลของข้อมูลที่กระทบต่อข้อมูลของท่าน ความเสี่ยงตามข้อ 3 (ที่ตัวระบุที่ใช้ซ้ำ เช่น อีเมล หมายเลขโทรศัพท์ หรือรูปภาพ อาจทำให้สามารถเชื่อมโยงกับตัวตนของท่านบนแพลตฟอร์มอื่น) หมายความว่าการรั่วไหลอาจมีผลกระทบเกินกว่าบริการนี้เอง เราจะแจ้งผู้ใช้ที่ได้รับผลกระทบและหน่วยงานที่เกี่ยวข้องตามที่กฎหมายที่ใช้บังคับกำหนด
9. Health Contact Tracing Service Data Handling
If you opt in to the Health Contact Tracing Service, we process the following data specifically for that feature: an anonymized linkage record connecting your subscription to other subscribing Users' anonymized contact-chain data; your self-reported health-condition result, if any, which is stored without any identifying link to your Account username or profile visible to other Users; and the subscription email address and payment/citizenship-exemption status needed to determine whether, and to whom, an alert should be routed.
When a positive result is self-reported for HIV or syphilis, we identify subscribing Users within the reporting User's contact chain during the trailing ninety (90) day window described in Section 13.5 of the Terms and send those subscribers an alert naming the specific condition. For any other supported health condition, alerted subscribers receive only a generic notice (“Health alert received from your contact chain”) without further detail. In no case is any information identifying the reporting User included in an alert, and no other User is ever informed that a specific person made a report.
We retain contact-chain linkage data only as long as necessary to operate the rolling ninety (90) day window and to deliver alerts to active subscribers, and we do not use Health Contact Tracing data for any purpose other than operating this feature and complying with legal obligations. As explained in Section 13.5 of the Terms, alerts are only generated for and delivered to actively subscribed Users at the time of processing; we do not retroactively reconstruct or deliver missed alerts for a period during which your subscription had lapsed.
หากท่านเลือกใช้บริการติดตามการสัมผัสด้านสุขภาพ เราจะประมวลผลข้อมูลต่อไปนี้เฉพาะสำหรับฟีเจอร์นี้ บันทึกการเชื่อมโยงแบบไม่ระบุตัวตนที่เชื่อมการสมัครสมาชิกของท่านกับข้อมูลสายโซ่การสัมผัสแบบไม่ระบุตัวตนของผู้ใช้ที่สมัครสมาชิกรายอื่น ผลด้านสุขภาพที่ท่านรายงานด้วยตนเอง หากมี ซึ่งจัดเก็บโดยไม่มีการเชื่อมโยงที่ระบุตัวตนกับชื่อผู้ใช้หรือโปรไฟล์ของท่านที่ผู้ใช้อื่นมองเห็นได้ และอีเมลสำหรับสมัครสมาชิกและสถานะการชำระเงิน/การยกเว้นด้วยสัญชาติที่จำเป็นต่อการพิจารณาว่าควรส่งการแจ้งเตือนหรือไม่และแก่ผู้ใด
เมื่อมีการรายงานผลบวกด้วยตนเองสำหรับเอชไอวีหรือซิฟิลิส เราจะระบุผู้ใช้ที่สมัครสมาชิกภายในสายโซ่การสัมผัสของผู้ใช้ที่รายงานในช่วง 90 วันก่อนหน้าตามข้อ 13.5 ของข้อกำหนด และส่งการแจ้งเตือนที่ระบุภาวะเฉพาะแก่สมาชิกดังกล่าว สำหรับภาวะสุขภาพอื่นที่รองรับ สมาชิกที่ได้รับการแจ้งเตือนจะได้รับเพียงข้อความทั่วไป (“ได้รับการแจ้งเตือนด้านสุขภาพจากสายโซ่การสัมผัสของท่าน”) โดยไม่มีรายละเอียดเพิ่มเติม ไม่มีกรณีใดที่ข้อมูลระบุตัวผู้ใช้ที่รายงานจะถูกรวมอยู่ในการแจ้งเตือน และไม่มีผู้ใช้อื่นใดที่จะได้รับแจ้งว่าบุคคลใดเป็นผู้รายงาน
เราเก็บรักษาข้อมูลการเชื่อมโยงสายโซ่การสัมผัสเท่าที่จำเป็นต่อการดำเนินการหน้าต่าง 90 วันแบบต่อเนื่องและการส่งการแจ้งเตือนแก่สมาชิกที่ใช้งานอยู่เท่านั้น และเราไม่ใช้ข้อมูลบริการติดตามการสัมผัสด้านสุขภาพเพื่อวัตถุประสงค์อื่นใดนอกจากการดำเนินการฟีเจอร์นี้และการปฏิบัติตามข้อผูกพันทางกฎหมาย ตามที่อธิบายในข้อ 13.5 ของข้อกำหนด การแจ้งเตือนจะถูกสร้างและส่งเฉพาะแก่ผู้ใช้ที่สมัครสมาชิกอยู่ในขณะประมวลผลเท่านั้น เราจะไม่สร้างหรือส่งการแจ้งเตือนที่พลาดไปย้อนหลังสำหรับช่วงเวลาที่การสมัครสมาชิกของท่านขาดช่วง
10. Data Retention
We retain information for as long as necessary to provide the Service, comply with legal, tax, and regulatory obligations, resolve disputes, and enforce our agreements. Specific retention practices include: Safety Session and incident data is retained to support the safety functions of the Service and is eligible for erasure following the periods and conditions described in the Service’s data-lifecycle rules; View My Data Service search associations are deleted immediately upon delivery of a result, as described in Section 7; Health Contact Tracing linkage data is retained only as long as necessary to operate the rolling window described in Section 9; and Account information is retained until you request deletion or your Account is terminated, subject to residual copies retained where required by Applicable Law (for example, financial records) or preserved in connection with a legal hold, dispute, or law-enforcement request.
เราเก็บรักษาข้อมูลเท่าที่จำเป็นต่อการให้บริการ การปฏิบัติตามข้อผูกพันทางกฎหมาย ภาษี และข้อบังคับ การแก้ไขข้อพิพาท และการบังคับใช้ข้อตกลงของเรา แนวปฏิบัติการเก็บรักษาข้อมูลที่เฉพาะเจาะจง ได้แก่ ข้อมูลเซสชันความปลอดภัยและเหตุการณ์จะถูกเก็บรักษาเพื่อสนับสนุนฟังก์ชันความปลอดภัยของบริการและมีสิทธิ์ถูกลบตามระยะเวลาและเงื่อนไขที่กำหนดในกฎวงจรชีวิตข้อมูลของบริการ ความเชื่อมโยงคำขอค้นหาของบริการดูข้อมูลของฉันจะถูกลบทันทีเมื่อส่งผลลัพธ์ตามข้อ 7 ข้อมูลการเชื่อมโยงบริการติดตามการสัมผัสด้านสุขภาพจะถูกเก็บรักษาเท่าที่จำเป็นต่อการดำเนินการหน้าต่างแบบต่อเนื่องตามข้อ 9 และข้อมูลบัญชีจะถูกเก็บรักษาจนกว่าท่านจะขอลบหรือบัญชีของท่านถูกยกเลิก ภายใต้สำเนาที่เหลือที่เก็บรักษาไว้ตามที่กฎหมายที่ใช้บังคับกำหนด (เช่น บันทึกทางการเงิน) หรือที่เก็บรักษาไว้เกี่ยวข้องกับการระงับทางกฎหมาย ข้อพิพาท หรือคำขอบังคับใช้กฎหมาย
11. International Data Transfers
The Company is established in the United Arab Emirates and may use service providers located in other countries, including Thailand and other jurisdictions where our infrastructure or vendors operate. Where information is transferred across borders, we take reasonable steps to ensure it is protected in a manner consistent with this Policy, including through contractual safeguards with service providers.
บริษัทจัดตั้งขึ้นในสหรัฐอาหรับเอมิเรตส์และอาจใช้ผู้ให้บริการที่ตั้งอยู่ในประเทศอื่น รวมถึงประเทศไทยและเขตอำนาจศาลอื่นที่โครงสร้างพื้นฐานหรือผู้ให้บริการของเราดำเนินการอยู่ ในกรณีที่มีการโอนข้อมูลข้ามพรมแดน เราจะดำเนินการตามสมควรเพื่อให้แน่ใจว่าข้อมูลได้รับการปกป้องในลักษณะที่สอดคล้องกับนโยบายนี้ รวมถึงผ่านมาตรการป้องกันตามสัญญากับผู้ให้บริการ
12. Your Rights
Subject to Applicable Law and the practical limits inherent in an anonymized system (described further below), you may have rights to: request access to information we hold about your Account; request correction of inaccurate information; request deletion of your Account and associated data, subject to retention obligations described in Section 10; withdraw consent for optional features such as location sharing, audio recording, or the Health Contact Tracing Service; and lodge a complaint with a competent data-protection authority. Because Counterparty data and Health Contact Tracing linkage data are stored without a verified association to any specific identified individual, we may only be able to act on a request relating to such data through the identity-adjacent process described in Section 7 (the View My Data Service) or, for Health Contact Tracing, by ceasing further processing of your own subscription going forward. To exercise any right, contact us at [email protected].
ภายใต้กฎหมายที่ใช้บังคับและข้อจำกัดในทางปฏิบัติที่มีอยู่ในระบบที่ไม่ระบุตัวตน (ดังที่อธิบายเพิ่มเติมด้านล่าง) ท่านอาจมีสิทธิ์ในการขอเข้าถึงข้อมูลที่เรามีเกี่ยวกับบัญชีของท่าน ขอแก้ไขข้อมูลที่ไม่ถูกต้อง ขอลบบัญชีและข้อมูลที่เกี่ยวข้องของท่าน ภายใต้หน้าที่การเก็บรักษาตามข้อ 10 ถอนความยินยอมสำหรับฟีเจอร์เสริม เช่น การแบ่งปันตำแหน่ง การบันทึกเสียง หรือบริการติดตามการสัมผัสด้านสุขภาพ และยื่นเรื่องร้องเรียนต่อหน่วยงานคุ้มครองข้อมูลที่มีอำนาจ เนื่องจากข้อมูลคู่กรณีและข้อมูลการเชื่อมโยงบริการติดตามการสัมผัสด้านสุขภาพถูกจัดเก็บโดยไม่มีการเชื่อมโยงที่ผ่านการยืนยันกับบุคคลที่ระบุตัวตนเฉพาะเจาะจง เราอาจสามารถดำเนินการตามคำขอที่เกี่ยวข้องกับข้อมูลดังกล่าวได้เฉพาะผ่านกระบวนการที่เกี่ยวข้องกับตัวตนตามข้อ 7 (บริการดูข้อมูลของฉัน) หรือสำหรับบริการติดตามการสัมผัสด้านสุขภาพ โดยการหยุดการประมวลผลการสมัครสมาชิกของท่านต่อไปในอนาคต หากต้องการใช้สิทธิ์ใดๆ กรุณาติดต่อเราที่ [email protected]
13. Minors; Parent, Guardian, or Police Contact Requirement
The Service does not verify age and does not identify Users. We recognize that individuals under eighteen (18) years of age may face safety risks that make anonymous safety reporting especially important, and we do not exclude minors from the Service’s core safety features.
As described in Section 2 of the Terms, if you are under eighteen (18), you are required to designate a parent, legal guardian, and/or the police as at least one of your Safe Contacts, so that a responsible adult or the appropriate authority receives any Safety Alert generated on your behalf. We do not independently verify a User’s age or verify that a designated Safe Contact is in fact a parent, legal guardian, or police contact.
Because we do not collect date of birth or other information that would let us determine a User’s age, we do not have actual knowledge of which Accounts belong to minors. Where Applicable Law imposes specific obligations regarding the personal data of children (such as a requirement for parental consent for certain processing), we will comply with those obligations to the extent we become aware that a User is a minor, including, where appropriate, by directing any such request to the parent or legal guardian designated as a Safe Contact under this Section. As noted in Section 2 of the Terms, the fee-based View My Data Service and Health Contact Tracing Service subscription require the involvement of a parent or legal guardian able to lawfully complete payment on behalf of a minor.
บริการนี้ไม่ตรวจสอบอายุและไม่ระบุตัวตนผู้ใช้ เราเข้าใจว่าบุคคลที่มีอายุต่ำกว่าสิบแปด (18) ปีอาจเผชิญความเสี่ยงด้านความปลอดภัยที่ทำให้การรายงานเพื่อความปลอดภัยแบบไม่ระบุตัวตนมีความสำคัญเป็นพิเศษ และเราไม่กีดกันผู้เยาว์จากฟีเจอร์ความปลอดภัยหลักของบริการ
ตามที่ระบุในข้อ 2 ของข้อกำหนด หากท่านมีอายุต่ำกว่าสิบแปด (18) ปี ท่านต้องกำหนดบุพการี ผู้ปกครองตามกฎหมาย และ/หรือตำรวจ เป็นผู้ติดต่อเพื่อความปลอดภัยอย่างน้อยหนึ่งราย เพื่อให้ผู้ใหญ่ที่รับผิดชอบหรือหน่วยงานที่เหมาะสมได้รับการแจ้งเตือนความปลอดภัยที่เกิดขึ้นในนามของท่าน เราไม่ได้ตรวจสอบอายุของผู้ใช้หรือตรวจสอบว่าผู้ติดต่อเพื่อความปลอดภัยที่กำหนดไว้เป็นบุพการี ผู้ปกครองตามกฎหมาย หรือผู้ติดต่อตำรวจจริง
เนื่องจากเราไม่เก็บรวบรวมวันเดือนปีเกิดหรือข้อมูลอื่นที่จะทำให้เราทราบอายุของผู้ใช้ เราจึงไม่มีความรู้ที่แท้จริงว่าบัญชีใดเป็นของผู้เยาว์ ในกรณีที่กฎหมายที่ใช้บังคับกำหนดข้อผูกพันเฉพาะเกี่ยวกับข้อมูลส่วนบุคคลของเด็ก (เช่น ข้อกำหนดให้ต้องได้รับความยินยอมจากผู้ปกครองสำหรับการประมวลผลบางประการ) เราจะปฏิบัติตามข้อผูกพันดังกล่าวเท่าที่เราทราบว่าผู้ใช้เป็นผู้เยาว์ รวมถึงในกรณีที่เหมาะสม โดยการส่งคำขอดังกล่าวไปยังบุพการีหรือผู้ปกครองตามกฎหมายที่กำหนดเป็นผู้ติดต่อเพื่อความปลอดภัยตามข้อนี้ ตามที่ระบุในข้อ 2 ของข้อกำหนด บริการดูข้อมูลของฉันและการสมัครสมาชิกบริการติดตามการสัมผัสด้านสุขภาพแบบมีค่าใช้จ่ายต้องมีบุพการีหรือผู้ปกครองตามกฎหมายที่สามารถชำระเงินได้ตามกฎหมายในนามของผู้เยาว์เข้าร่วมด้วย
14. Cookies and Similar Technologies
The sistersafe.io website uses only strictly necessary cookies and similar local-storage mechanisms required for core functionality, such as maintaining your admin session or language preference. We do not use third-party advertising or cross-site tracking cookies.
เว็บไซต์ sistersafe.io ใช้เฉพาะคุกกี้ที่จำเป็นอย่างเคร่งครัดและกลไกจัดเก็บข้อมูลในเครื่องที่คล้ายกันซึ่งจำเป็นต่อการทำงานหลัก เช่น การรักษาเซสชันผู้ดูแลระบบหรือการตั้งค่าภาษาของท่าน เราไม่ใช้คุกกี้โฆษณาของบุคคลที่สามหรือคุกกี้ติดตามข้ามเว็บไซต์
15. Free Service; No Sale of Data
The core safety features of the Service are provided to Users free of charge, and we do not sell your personal data to third parties for money or other valuable consideration, whether in connection with the free features or the fee-based View My Data Service and Health Contact Tracing Service described above. Fees charged for those optional services compensate us for the operational, human-review, and infrastructure costs of providing them, and are not payment for your data.
ฟีเจอร์ความปลอดภัยหลักของบริการให้บริการแก่ผู้ใช้โดยไม่มีค่าใช้จ่าย และเราไม่ขายข้อมูลส่วนบุคคลของท่านให้บุคคลที่สามเพื่อเงินหรือสิ่งตอบแทนอันมีค่าอื่น ไม่ว่าจะเกี่ยวข้องกับฟีเจอร์ฟรีหรือบริการดูข้อมูลของฉันและบริการติดตามการสัมผัสด้านสุขภาพแบบมีค่าใช้จ่ายที่กล่าวถึงข้างต้น ค่าบริการที่เรียกเก็บสำหรับบริการเสริมดังกล่าวเป็นการชดเชยต้นทุนการดำเนินงาน การตรวจสอบโดยมนุษย์ และโครงสร้างพื้นฐานในการให้บริการ ไม่ใช่การชำระเงินสำหรับข้อมูลของท่าน
16. Changes to This Policy
We may update this Policy from time to time in our sole discretion. Where a change is material, we will use reasonable efforts to provide notice through the Service or by email to your Account address. Your continued use of the Service after a change takes effect constitutes your acceptance of the updated Policy. The then-current version of this Policy will always be available at sistersafe.io/privacy.
เราอาจปรับปรุงนโยบายนี้เป็นครั้งคราวตามดุลพินิจของเราแต่ผู้เดียว ในกรณีที่มีการเปลี่ยนแปลงที่เป็นสาระสำคัญ เราจะใช้ความพยายามตามสมควรในการแจ้งผ่านบริการหรือทางอีเมลไปยังที่อยู่บัญชีของท่าน การใช้บริการต่อไปของท่านหลังจากการเปลี่ยนแปลงมีผลบังคับใช้ถือเป็นการยอมรับนโยบายที่ปรับปรุงแล้วของท่าน นโยบายฉบับล่าสุดจะเผยแพร่อยู่ที่ sistersafe.io/privacy เสมอ
17. Contact Us
If you have questions about this Policy or wish to exercise any of your rights, contact:
Pitch Marketing LLC-FZ
6th Floor, Business Center 1, Meydan Hotel, Nad Al Sheba, Dubai, United Arab Emirates
Email: [email protected]
หากท่านมีคำถามเกี่ยวกับนโยบายนี้หรือต้องการใช้สิทธิ์ใดๆ กรุณาติดต่อ:
Pitch Marketing LLC-FZ
6th Floor, Business Center 1, Meydan Hotel, Nad Al Sheba, Dubai, สหรัฐอาหรับเอมิเรตส์
อีเมล: [email protected]