Privacy Policy
Special Risk Allowance Workflow System
นโยบายความเป็นส่วนตัวสำหรับระบบจัดทำและติดตามเอกสารการเบิกค่าเงินเสี่ยงภัยพิเศษ
Last Updated: January 20, 2026
1. Data Collection
We collect personal information through Google OAuth authentication to verify your identity and provide access to the system. The information collected includes:
- Full Name — Used for identification and document attribution
- Email Address — Used for account identification and system notifications
- Profile Picture — Used for visual identification within the system interface
Additionally, the system collects data related to your special risk allowance requests, including:
- Request submission details and timestamps
- Document attachments and supporting evidence
- Approval workflow history and status changes
- Risk assessment information as provided by you
2. How We Use Your Data
Your personal information is used exclusively for the following purposes:
- Processing Special Risk Allowance Requests — To facilitate the submission, review, and approval of your risk allowance claims
- Document Status Tracking — To provide real-time updates on the status of your submitted documents throughout the approval workflow
- Expense Report Generation — To compile departmental expense reports and financial summaries for authorized personnel
- Audit and Compliance — To maintain accurate records for internal auditing and regulatory compliance purposes
- System Notifications — To send you updates regarding your document status via email or other configured notification channels
3. Data Retention
To ensure transparency and maintain comprehensive audit trails, our system implements a Soft Delete policy for data management:
- When you request deletion of your data, records are marked as deleted but retained in our system for audit and historical verification purposes
- Soft-deleted data is not visible in regular system operations but remains accessible for authorized audit reviews
- This approach ensures compliance with financial record-keeping requirements and supports organizational transparency
- Complete data purge requests may be submitted to the system administrator for review on a case-by-case basis, subject to regulatory requirements
Note: Data retention periods comply with applicable Thai financial record-keeping regulations and organizational policies.
4. Data Security
We implement robust security measures to protect your personal information:
- Role-Based Access Control (RBAC) — Data visibility is strictly controlled based on user roles:
- Employees — Can view and manage only their own requests
- Supervisors — Can access requests from their team members for approval
- Administrators — Have system-wide access for management and reporting
- Secure Authentication — All access is authenticated through corporate Google OAuth, ensuring verified identities
- Encrypted Transmission — All data transfers are encrypted using industry-standard HTTPS protocols
- Activity Logging — All system activities are logged for security monitoring and audit purposes
5. Contact Us
If you have any questions or concerns about this Privacy Policy or your personal data, please contact the system administrator or your department's data protection officer.