Policy Notice of Superrich Green Group Company Limited
Policy Notice of Superrich Green Group Company Limited
No. 03/2022
Privacy Policy
Superrich Green Group Company Limited (“the Company”) is committed to conducting businesses in compliance with business ethics and applicable laws and appreciates the trust you have placed in the Company. The Company is well aware of your transaction security and collection and storage of Personal Data.
The Company values your privacy and thus protects your Personal Data by formulating policies, regulations, and rules for the Company’s business. The full data protection shall ensure you that your Personal Data shall be processed as per your requirements and under the law.
Purpose
This Policy is to inform you, as a data subject, of purposes and details about collection, storage, usage, and/or disclosure of your Personal Data, as well as your legal rights concerning Personal Data.
Personal Data the Company Collects and/or Discloses
1.Personal Data is any information that identifies you, directly or indirectly, i.e.
1.Personal Data you, directly or indirectly, give the Company, or the data available to the Company by your use of services, contact, visit, search via digital platforms, website, call center, assigned persons, or other channels;
2.Personal Data received or accessed by the Company from other sources, not directly from you, e.g., government entities, financial institutions, financial service providers, business partners, the National Credit Bureau, and information service providers, etc. The Company will collect data from other sources only when your consent is given as consistent with laws unless where necessary for the Company as permissible under laws.
Your Personal Data the Company Collects and Discloses are as follows:
- Personal Data, such as name, surname, age, date of birth, marital status, national identification number, and passport number, and contact information, such as home address, workplace, temporary address (other than home address), telephone number, E-mail, and Line account ID;
- Financial information, such as financial statements, source of finance, bank account number, credit card numbers, and debit card numbers;
- Transaction information, such as foreign exchange purchase and sale transactions, including source and distribution of foreign exchange;
- Data related to devices or machines, such as IP address, MAC address, and cookie ID;
- Other information, such as website-visiting data, voice, still picture, moving picture, and other information deemed Personal Data under the Personal Data Protection Laws
2.Sensitive Personal Data is specially categorized by law and will be collected, used, and/or disclosed by the Company only when the Company is given explicit consent or where necessary for the Company as permissible under law. The Company may collect, use, and/or disclose biometric identifiers, e.g., facial recognition, fingerprint recognition, retina recognition, and voice recognition, for the sake of verifying and confirming identify of applicants for services and/or transaction via digital platforms, website, call center or other channels, etc.
Remark : Unless otherwise specified in this Policy, Personal Data and sensitive data about you above will be collectively called “Personal Data”.
3.What are the Company’s purposes of collecting, using, and/or disclosing your Personal Data?
1.For your benefits in using the Company’s products and/or services that meet your own purposes and for other purposes necessary under laws, for example,
1. to allow you to use the Company’s products and/or services that meet your purposes under your contract with the Company or to take steps at your request prior to using the Company’s products and/or services (Contractual Basis), for example,
(1) to approve the using of any products and/or services, such as member subscription and other relevant services;
(2) to take any steps in relation to product and service provision, e.g., processing, contact, notification, outsource, right and/or duty assignment, and notification of services.
2.to comply with the following legal obligations:
(1) to comply with an order from an authority; and/or
(2) to comply with Tax law, Anti-Money Laundering Act, Counter-Terrorism and Proliferation of Weapon of Mass Destruction Financing Act, Computer-Related Crime Act, Bankruptcy Act, and other laws to which the Company is subject both in Thailand and outside the country, including regulations and rules issued pursuant to such law and acts.
3.to take necessary steps for the Company’s legitimate interests or other individual or juristic person which are not overriding your reasonable expectations (Legitimate Interest), for example,
(1) to record voice conversation with call center or images from CCTV, to exchange ID cards before entering buildings;
(2) to maintain relationship with customers, e.g., complaint handling, satisfaction survey, customer service by the Company’s staff, notification or offer on any products and/or services of the same types you are using for your own sake;
(3) to manage risks, monitor, manage within organization including to refer such tasks to the same corporate group under the binding corporate rules;
(4) to anonymize your Personal Data;
(5) to prevent, respond, and minimize potential risks from corruption, cyber threat, or law violation (e.g., money laundering, terrorism and proliferation of weapon of mass destruction financing, offences related to property, life, body, liberty or reputation); including sharing Personal Data to raise work standards of the same corporate group in order to prevent, respond, and minimize such risks;
(6) to collect, use, and/or disclose the Personal Data of directors, representatives, customers’ agents who are juristic person;
(7) to contact and record voice or image during meetings, trainings, seminars or workshops;
(8) to collect, use, and/or disclose the Personal Data of the ward;
(9) to receive-dispatch documents or parcels.
2.to enable you to receive benefits from using products and/or services as per your given consent, for example,
(1) for you to be provided with better and suitable products and/or services as per your requirements;
(2) for you to receive offers, privileges, recommendations and other information including eligibility to attend special activities;
Regardless of being products and/or services, privileges, promotions, information or special activities of the Company, business partner or a third party associated with the Company, depending on your given consent.
4.To Whom may the Company disclose your Personal Data?
The Company may, under your consent and under the applicable law, disclose your personal to other third parties. The persons or entities receiving the data will collect, use, and/or disclose the Personal Data to the extent permissible under your consent or related to this Policy.
The Company may, under your consent and under the applicable law, disclose your personal to other third parties under this Policy, e.g., the Personal Data processor, business partners, external service providers, the Company’s agents, sub-contractors, financial institutions, auditors, external auditors, competent authorities, prospective assignees and/or assignees in any transaction or business merger of the Company, any corporations or individuals under relationship or contract with the Company; including executives, staffs, employees, contractors, agents, the Company’s advisor and of those persons or entities who receive the data, etc.
5.Can the Company send or transfer your Personal Data to other countries?
If need be, the Company may send or transfer your Personal Data to the same corporate group overseas or to other recipients to the extent necessary to perform the Company’s activities, e.g., sending or transferring the Personal Data to be stored on server/cloud in other countries.
In the case of the receiving countries’ adequate standard levels, the Company will ensure that the sending and the transferring are accordance with the law and take reasonable data protection measures as necessary, appropriate, and in consistent with confidentiality measures. Such measures are, for example, entering into confidentiality agreement with recipients overseas, setting out the Personal Data Policy that is audited and certified by competent authorities under the relevant law in case of the corporate group in the same business being the recipients, and controlling the sending and transferring to comply with such policy instead of legal requirements.
6.How long does the Company retain your Personal Data?
The Company will retain your Personal Data for as long as necessary during the period you are a customer or binding on the Company, or for as long as necessary in connection with the purposes set out above, unless law requires or permits longer retention period. For example, retention pursuant to the Anti-money Laundering Act and retention for proving and examining in the event of dispute within legal prescription not exceeding10 years, etc.
The Company may erase, destroy, or anonymize the Personal Data when it is no longer necessary or when the period lapses.
7.How does the Company protect your Personal Data?
The Company will best store your Personal Data according to technical measures and organizational measures to maintain security of personal data processing and prevent a Personal Data breach. The Company has formulated policies, rules, and regulations on Personal Data protection, e.g., security standards of information technology and measures to bar data recipients from using or disclosing the data outside the purposes or without authorization or unlawfully. The Company has developed the policies, rules, and regulations as frequently as necessary and appropriate.
Moreover, the Company’s executives, staffs, employees, contractors, agents, advisers, and data recipients are obligated to keep the Personal Data in confidence pursuant to confidentiality measure provided by the Company.
8.What are your rights related to Personal Data?
Your rights described hereunder are legal rights of which you should be informed. You may exercise any of these rights within legal requirements and policies at the present or as amended in the future as well as regulation set out by the Company. If you are under the age of 20 or your legal contractual capacity is restricted, your parent(s), guardian, or representative may request to exercise the rights on your behalf.
- Withdrawal of Consent : If your consent is given to the Company to collect, use, and/or disclose your Personal Data (whether before or after the effective date of the Personal Data Protection law), you have the right to withdraw such consent at any time throughout the period your Personal Data are held by the Company, unless it is restricted by laws or you are still under beneficial contract. However, your withdrawal of consent may affect your service usage; for instance, you shall neither be provided with privileges, promotions, and offers, nor notified of useful information. For your own benefit, please study and inquire before deciding to withdraw consent.
- Data Access : You have the right to access your Personal Data that is in the Company’s possession; to request the Company to make a copy of such data for you; and to request the Company to reveal as to how to Company obtained your Personal Data.
- Data Portability : You have the right to request for your Personal Data if the Company renders such Personal Data machine-readable or usable via automatic means; to request the Company to send or transfer the Personal Data in such format directly to other data controllers if doable by automatic means; and to request to obtain the Personal Data in such format sent or transferred by the Company directly to other data controller unless technical errors occur.However, your Personal Data above must be under your consent given to the Company to collect, use, and/or disclose; or those the Company deems necessary to collect, use, and/or disclose to allow you to use products and/or services as per your needs under your contract with the Company; or to take steps at your requests before using products and/or services; or as legally required by the authority.
- Objection : You have the right to object to collection, usage, and/or disclosure of your Personal Data at any time if such doing is conducted for legitimate interests of the Company, corporation, or individual which is within your reasonable expectation; or for carrying out public tasks. If you request to object, the Company will continue collecting, using, and/or disclosing your Personal Data only when the Company can establish a legal basis that doing so is more important than your fundamental rights; or to affirm legal rights; to comply with laws; or to defend legal proceedings, depending on a case-by-case basis.In addition, you have the right to object to collection, use, and/or disclosure of your Personal Data carried out for the purposes of scientific, historical, or statistical research.
- Data Erasure or Destruction : You have the right to have the Company erase, destroy, or anonymize your Personal Data if you believe that the collection, use, and/or disclosure of your Personal Data is violating relevant laws; or retention of the data by the Company is no longer necessary under the purposes set out in this Policy; or when you request to withdraw your consent or to object to the processing as earlier described.
- Processing Suspension : You have the right to have the Company suspend processing your Personal Data during the period where the Company examines your rectification or objection request; or when it is no longer necessary and the Company must, under relevant laws, erase or destroy your Personal Data, but you instead request the bank to suspend the processing.
- Data Rectification : You have the right to rectify your Personal Data to be updated, complete, and not misleading.
- Complaint Lodging : You have the right to, under relevant laws, complain to authorities on the condition that you believe that the collection, use, and/or disclosure of your Personal Data is violating or against relevant laws.
- The exercise of the rights above : may be restricted under relevant laws, and it may be necessary for the Company to deny or not be able to respond to your requests, e.g., to comply with laws or court orders, public tasks, your request in breach of rights or freedom of other persons, etc. If the Company denies the request, the Company will inform you of the reason.
This Policy notice shall come into force on 1 January 2021.
Mr. Pokin Susamawathanakun
(Managing Director)
Appendix No. 03/2022
Privacy Policy
You may request to exercise your rights via the following channels:

*from the day you submit your request and the Company receives all documents
Remark : If you wish to make any complaints regarding Personal Data Breach and/or Privacy Violations, you may contact us in person at one of our many locations. (Working Hours)
Superrich Green Group Co., Ltd. Announcement
Issue 04/2022
Subject: CCTV Privacy Notice
Superrich (Thailand) Co., Ltd. (hereinafter referred to as ‘the Company”) are to inform you of the use of closed-circuit television (CCTV) devices to monitor conditions within or around the Company premises to protect life, health, and property. The Company collects Personal Data of all officers, workers, customers, employees, contractors, visitors, or any individuals entering the monitored space within the Company premises (collectively referred to as “you” or “your”) through the use of CCTV devices.
This CCTV Privacy Notice provides information on The Company’s collection, use, or disclosure of individually identifiable information (“Personal Data”) about you.
1.Legal bases for processing your Personal Data
The Company shall process your Personal Data for the following legal purposes:
- to prevent, protect and/or suppress a danger to life, body, and health of a person or those of any relevant third parties;
- to assist in legitimate interest of the Company and that of any relevant third parties, both of which are considered necessary for your fundamental rights to the protection of the Personal Data; and
- to comply with applicable laws regarding safety and environment in the workplace and the Company properties.
2.Purposes of collection of your Personal Data
The Company shall process your Personal Data for the following purposes:
- to protect your health, personal safety, and belongings;
- to protect and prevent premises, facilities, and assets of the Company from damage, disruption, vandalism, or other crime;
- to support law enforcement agencies in the deterrent, prevention, detection, and prosecution of crime;
- to assist in the effective resolution of disputes which arise in the course of disciplinary or grievance proceedings;
- to assist in the investigation or proceedings concerning a whistleblowing complaint; and
- to assist in the establishment or defense of any litigation, including but not limited to employment proceedings.
3.Collected and used Personal Data
The Company installs CCTV devices at clearly visible spots and places appropriate signage at the entrance and the exit, and in other areas the Company considers necessary to be kept under surveillance to alert you that a CCTV installation is in use and your Personal Data is recorded.
- Image
- Video
- Sound
- Images of your belongings, e.g. vehicles, bags, hats, and clothes
Please also note that the Company shall not install CCTV devices in private areas to prevent an invasion of your privacy.
2.Disclosure of your Personal Data
The Company shall keep your Personal Data confidential, and may however, disclose them to any relevant third parties if it is deemed necessary for the following purposes:
- The Company may disclose your Personal Data to law enforcement agencies to comply with legal obligations and assist them in the detection, investigation, and prosecution of crime; and
- The Company may disclose your Personal Data to any relevant third parties to ensure the Company’s protection of your life, body, health, personal safety, and belongings.
2.Your rights as a data subject
Pursuant to the Personal Data Protection Act (PDPA) B.E. 2562 which seeks to empower individuals to take control of their Personal Data, you have the following rights:
- Right of access. You have the right to access and obtain a copy of your Personal Data that the Company collected. The Company may, to the extent permitted by law or a court order, refuse to act on your request where such request could affect the rights and freedom of another person.
- Right to rectification. You have the right to request for rectification of incomplete, inaccurate, misleading, or not up-to-date Personal Data that the Company processes about you.
- Right to restrict processing. You have the right to restrict the processing of your Personal Data in the following circumstances when:
- It is under the pending examination process of checking whether your Personal Data is accurate, up-to-date, and complete or not;
- Your Personal Data is collected, used, or disclosed unlawfully;
- It is no longer necessary to retain your Personal Data for the purpose of which it was collected, used or disclosed, but you still require the data to establish, exercise, or defend a legal claim; and
- The Company is pending verification in order to reject your request for the objection to the collection, use, or disclosure of your Personal Data.
- Right to object. You have the right to object to the collection, use, or disclosure of your Personal Data. However, the Company may refuse to comply with your request if the Company can demonstrate compelling legitimate grounds for such collection, use, or disclosure, which may override your own interest or if such collection, use, or disclosure is for the purposes of establishment, compliance, exercise, or defense of legal claims.
3.Retention period of Personal Data
To achieve the monitoring purposes described in this Notice, the Company may retain your Personal Data for 90 days after your visit to the Company premises or so long as it is necessary to deal with any disputes or legal proceedings that may arise. After that period, your Personal Data will be deleted.
4.Security measures of your Personal Data
The Company uses reasonable technical and administrative security measures to protect your Personal Data from loss or unauthorized access, deletion, destruction, use, modification, alteration, and disclosure of data.
The Company has established the Privacy Policy publicized throughout the Company and security guidelines for the collection, use, and disclosure of Personal Data that cover confidentiality, integrity, and availability. In this regard, the Company will revise the Policy as well as this Notice in due course.
5.Personal Data controllers’ scope of responsibility
The Company allows only authorized controllers to process your Personal Data and has them strictly follow this Notice.
6.Changes to this CCTV Privacy Notice
The Company reserves the right to amend this Notice at any time in its sole discretion and will notify you in appropriate manner of any modification to the terms of this Notice through the QR code at the information counter. It is advisable that you always check the up-to-date Notice before entering the Company premises.
Entering the Company premises is considered acceptance of this Notice. Please do not enter if you do not accept it. Your visit to the Company premises after the Notice has been updated or modified is also considered acceptance of its terms.
7.Contact details
If you have any queries about your Personal Data under this CCTV Privacy Notice, please contact us at:
Data Protection Officer: DPO
Name: Mr. Saksom Singhakul
Address: 45-45/1-2, Rajdamri 1, Rajdamri Road, Lumpini, Pathumwan, Bangkok 10330 Tel. +66(0)2-254-4444 ext. 4713
Email address: Saksom.S@superrichth.com
Announcement
Superrich Green Group Company Limited
No. 1/2021
Anti-Money Laundering Policy
Objective:
The primary aim of Superrich Green Group Company Limited is to ensure compliance with the Anti-Money Laundering Act B.E. 2542, ministerial regulations, criteria, and procedures for customer due diligence B.E. 2555. To achieve this, a customer acceptance policy has been formulated in line with guidelines from the Secretary-General and the Anti-Money Laundering Policy Committee, facilitating accurate customer assessment.
Definitions: Remark
- Company: Superrich Green Group Company Limited
- Office: The Anti-Money Laundering Office
- Board: The Executive Committee of Superrich Green Group Company Limited
- Customer: Any individual utilizing the Company's services
- Transaction: Provision of foreign currency exchange or souvenir selling services
- Customer Acceptance Policy: Principles governing the Company's processes when establishing initial business relationships with customers or conducting transactions with service-using customers on a temporary basis
- Customer Money Laundering Risk Management Policy: Evaluation of customer money laundering risks and financial crime support, considering the risk associated with each product/service and service/transaction channel, along with other customer risk factors, to assess risks for each customer
Policy:
The company bears the responsibility and ethical obligation to establish policies and operational guidelines aimed at preventing money laundering and countering terrorism financing effectively. It is committed to preventing the company from being exploited for money laundering and terrorism financing by strictly adhering to laws, regulations, and guidelines set forth by the relevant authorities. The company must develop supplementary policies and measures to support the aforementioned objectives. These may include customer acceptance policies and risk management measures concerning money laundering. Additionally, guidelines for conducting comprehensive customer due diligence must be implemented, and the company must ensure effective compliance by its personnel.
Roles, Duties, and Responsibilities:
- The board must prioritize the prevention and suppression of money laundering and the combating of terrorism financing by establishing and endorsing policies in these areas. This includes the establishment and endorsement of policies on preventing money laundering and combating terrorism financing, as well as customer acceptance policies and risk management policies regarding customer money laundering. These policies must strictly adhere to the guidelines set by the Anti-Money Laundering Committee's Secretary-General, with the approval of the Anti-Money Laundering Committee.
- The board must prioritize the prevention and suppression of money laundering and the combating of terrorism financing by ensuring that all personnel adhere to policies and procedural regulations concerning these matters. This includes ensuring that all personnel strictly follow policies and operational procedures related to preventing money laundering and combating terrorism financing.
- The company must appoint personnel with the authority to oversee and ensure compliance with laws related to preventing and suppressing money laundering. These personnel will also act as liaisons with the office.
- The company must establish measures to control the risk of money laundering and terrorism financing that may arise from the use of its services.
- The company must support and promote knowledge and understanding of preventing money laundering and suppressing terrorism financing among management, executives, and staff to enable effective compliance with laws related to preventing money laundering and suppressing terrorism financing.
- The company must establish orders/regulations and operation manuals that are consistent with policies and practices related to preventing money laundering and suppressing terrorism financing. These must align with the guidelines set by the Anti-Money Laundering Committee's Secretary-General, with the responsibility of the Anti-Money Laundering Committee. However, in cases where regulations and guidelines issued under this law or other laws are inconsistent with practices, the company must comply with the law more strictly.
- The board and company personnel must adhere strictly to policies and operational regulations concerning preventing money laundering and suppressing terrorism financing.
This announcement shall take effect from January 1, 2021 onwards.
Mr. Apichai Susamawathanakun
Chairman of the Board
Announcement
Superrich Green Group Company Limited
No. 2/2021
Customer Acceptance Policy
Objective:
The primary aim of Superrich Green Group Company Limited is to ensure compliance with the Anti-Money Laundering Act B.E. 2542, ministerial regulations, criteria, and procedures for customer due diligence B.E. 2555. To achieve this, a customer acceptance policy has been formulated in line with guidelines from the Secretary-General and the Anti-Money Laundering Policy Committee, facilitating accurate customer assessment.
Definitions:
- Company: Superrich Green Group Company Limited
- Office: The Anti-Money Laundering Office
- Board: The Executive Committee of Superrich Green Group Company Limited
- Customer: Individuals availing themselves of the company's services
- Transaction: Foreign currency exchange services/souvenir selling services
- Customer Money Laundering Risk Management Policy: Evaluating customer risk in money laundering and terrorism financing; this comprehensive assessment considers product/service usage, transaction channels, and other risk factors to determine individual customer risks.
- Requester to Establish Relationship: Individuals seeking to use services, establish business relationships, or conduct transactions with the company for the first time. Approval is pending completion of the consideration process outlined in the customer acceptance policy.
- Arranging for Customers to Identify Themselves: Obtaining and verifying customer information to ensure authenticity.
- Customer Identification: Comprehensive customer data collection extends beyond basic identification, encompassing details such as income sources, marital status, and business patterns. This information undergoes cross-referencing with the United Nations' terrorist list to evaluate risks associated with money laundering and terrorism financing.
- Customer Risk Management: Utilizing customer identity data and identification information in conjunction with other risk factors for money laundering and terrorist financing, such as high-risk areas or professions, associations with known offenders, and political status. This helps assess the money laundering and terrorist financing risk level of each customer. The assessment is useful for determining whether to file a suspicious activity report with the Anti-Money Laundering Office when a customer's transaction behavior appears abnormal or risky. It also sets the intensity level for future due diligence processes.
- Customer Acceptance Policy
Ensuring that the company's operations align with legal procedures for preventing money laundering and comply with international measures against money laundering and terrorism financing. When a prospective relationship initiator expresses interest in using services, establishing business relationships, or conducting transactions with the company for the first time, the policy dictates following a specific process. Additionally, compliance with the customer money laundering risk management policy is required before approving the relationship establishment.
- Step 1: Customer Identification
When a prospective customer seeks to establish a business relationship or requests a service for the first time, the company must ensure that the prospective customer identifies themselves according to the criteria and methods specified by the regulations set forth by the Ministry of Finance, concerning financial institution transactions and professional practitioners, as outlined in 2011 and the Prime Minister's Office announcement regarding customer identification methods for financial institutions and professional practitioners in accordance with Article 16. Thus, the company must facilitate the prospective customer's identification.
- Step 2: Customer Identity Verification
The company must have additional information about the prospective customer to accurately verify whether the prospective customer seeking to establish a business relationship or request a service is an individual or legal entity, or a person who has entered into a legal agreement, thereby determining the level of risk at which the company can approve or disapprove them as a customer. Sufficient information must be gathered from the prospective customer to accurately assess the level of money laundering risk. In this step, the following information about the prospective customer must be provided for consideration:
- For occasional customers: natural persons
- Information on the income source of funds used in transactions by the requesting person for establishing a relationship (the term “source” encompasses both income-generating activities and the source of income)
- Actual beneficiary details
- For corporate customers:
1.Organizational management structure/ownership (indicating the organization's size and management complexity, shareholding representing managerial power)
2.Executive information (highest level, whether an individual or committee with policy approval authority)
3.Objectives of the organization's operations, legal entity/individual agreements, income sources (main and additional), with real beneficiaries being natural persons determined by:
3.1 Shareholding/interest level
3.2 Information from reliable sources (including financial institutions or companies conducting prior investigations)
3.3 Authority to influence business affairs (not legally authorized but practically influential)
3.4 Authority over organizational policies and operations
4.Additional organizational information from trustworthy sources, economic status, and factors considering money laundering risks for legal entities/individuals with agreements
5.The objective is to establish a relationship with the company and the desired service requested by the person initiating the relationship.
- Step 3: Customer Identity Verification Process
Upon receiving the customer's identity information in Step 1 and identity verification data in Step 2, the Company must verify the accuracy and completeness of the information and evidence of identity.
To verify the accuracy of the information and evidence of identity, the Company may utilize reliable data sources (including trustworthy public databases/commercial databases/verified information from government agencies, financial institutions, etc.).
In cases where no reliable data sources are available, the Company may exercise discretion in verification, considering information consistent with the customer's identity, the type of service requested, or transaction, and the authenticity of documents at a level visible to the naked eye.
The process of verifying customer information against the member database of individuals designated by the United Nations Security Council under a resolution recognized by the Thai government.
In this step, the Company must cross-check the information of the relationship applicant, actual beneficiary, and those involved with the relationship applicant against the member database of individuals designated by the United Nations Security Council under a resolution recognized by the Thai government for certification to ascertain whether the "relationship applicant and involved parties" are not members of individuals designated by the United Nations Security Council under a resolution recognized by the Thai government as perpetrators of wrongdoing.
- Step 4: Customer Anti-Money Laundering Risk Management and Approval or Rejection of Customer Acceptance
Once the company has sufficient information about the relationship applicant to proceed with the anti-money laundering risk management policy and the risk assessment guidelines arising from the customer relationship and risk management measures, it shall consider whether to approve the relationship establishment or service provision to the applicant as a customer. However, if it is found that any relationship applicant poses a high risk of money laundering, the approval of the relationship establishment to accept the relationship applicant as a customer shall be the responsibility of the Board. Nevertheless, the Company must reject the establishment of relationships or transactions with any relationship applicant found to pose such risks as follows;
- The relationship applicant, the actual beneficiary, or individuals significantly involved with the relationship applicant, are members of entities designated as entities engaged in terrorist activities by the government of the Kingdom of Thailand through resolutions or declarations under the authority of the United Nations Security Council.
- No significant identity identification and anti-money laundering risk assessment data are received.
- The relationship applicant uses false names, pseudonyms, or fraudulent information, or if essential evidence is found to be false.
- Accepting each relationship applicant will expose the company to a high risk of money laundering or financing terrorism.
In the event of rejecting a customer or transaction due to reasons outlined in points (1) and (3), or if the Company determines there is a likelihood of money laundering risk or financing terrorism risk from a relationship applicant, the Company should report a "suspicious transaction" to the Office of authority.
This announcement shall take effect from January 1, 2021, onwards.
Mr. Apichai Susamawathanakun
Chairman of the Board
Announcement
Superrich Green Group Company Limited
No. 3/2021
Risk Management Policy Regarding Customer Money Laundering
Objective:
To ensure that the operations of Superrich Green Group Company Limited comply with the Anti-Money Laundering Act B.E. 2542 and the Ministerial Regulations on customer due diligence B.E. 2555. For verifying customer information, a written customer acceptance policy is established according to the guidelines set by the Secretary-General of the Anti-Money Laundering Office, with the approval of the Anti-Money Laundering Board.
Definitions:
- Company: Superrich Green Group Company Limited
- Office: The Anti-Money Laundering Office
- Board: The Executive Committee of Superrich Green Group Company Limited
- Customer: Individuals availing themselves of the company's services
- Transaction: Foreign currency exchange services/souvenir selling services
- Customer Acceptance Policy: The principles outlining the Company’s procedures for establishing initial business relationships or conducting initial transactions with customers.
- Customer Money Laundering Risk Management Policy: The assessment of customers' risks related to money laundering and financing of terrorism. This involves considering the risks associated with the use of products/services and transaction channels, along with other customer risk factors, to evaluate the overall risk for each customer.
- Requester to Establish Relationship: Individuals expressing interest in using the Company’s services, establishing a business relationship, or conducting a transaction for the first time, who have not yet been approved as customers due to pending completion of the Company’s customer acceptance policy procedures.
- Customer Due Diligence: The process of continuously monitoring and reviewing customers' financial activities or transactions. The intensity of this process should align with the customer's assessed risk level based on relevant data and factors. The outcomes of customer due diligence help the Company determine if the customer's relationship or financial activities deviate from the norm or economic status, if the risk level needs adjustment, and if the Company remains secure from money laundering and financing of terrorism in its business relationships with customers.
- Customer Money Laundering Risk Management Policy: After implementing the customer acceptance policy, the Company should follow the money laundering risk management process for customers, recording the risk level before approving a relationship applicant as a customer. If any applicant exhibits high money laundering risk characteristics, the approval decision must be made by an authorized executive, considering various risk factors for each customer group.
Risk Assessment and Management
- Internal risk management involves overseeing money laundering and terrorist financing risks across products/services and transaction channels. This includes evaluating the risks of each product/service and channel along with other customer risk factors to determine the overall risk profile for each customer.


4.Customer Risk Management in managing the risk for company customers, criteria for assessing customer risk at high and low levels are established according to the following principles.
Factors for considering a customer as high-risk:
According to Section 19 of the Ministerial Regulation specifying criteria and methods for verifying facts regarding customers, B.E. 2555, if any customer exhibits any of the following characteristics, the company must classify them as high-risk customers for money laundering: The customer is considered high-risk if:
- The customer is associated with members of entities engaged in acts of terrorism as per the resolutions of the United Nations Security Council. The company may consider the list of members who have engaged in or supported terrorism, money laundering, or other serious offenses against internationally credible organizations or other countries.Note: "Association" in this context refers to close relatives, immediate family members, or those who have the opportunity to assist and support.
- The customer is subject to the restraint of transactions, seizure, or confiscation of assets by court order according to laws concerning the prevention and suppression of money laundering (and other laws related to offenses under the Anti-Money Laundering Act, B.E. 2542).
- The customer is or has been involved in offenses related to money laundering, serious crimes, or offenses related to terrorism and financing of terrorism.
- The customer is politically exposed persons (PEPs), holding positions in political or high-ranking government offices from national to local levels, both domestically and internationally.
- The customer resides in countries or regions where there is no or insufficient implementation of international standards for Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT) measures, considering:
- Countries or regions lacking international standards for AML/CFT.
- Countries or regions subject to sanctions or embargoes by the United Nations or significant international organizations.
- Countries or regions believed to have a high level of corruption or organized crime.
- Countries or regions considered as sources of financial support for terrorism or where terrorist organizations operate.
- The customer derives a significant portion of their income from countries or regions with inadequate implementation of international AML/CFT standards.
- The customer is engaged in professions or businesses with a high risk of money laundering, such as:
- Politically exposed persons (PEPs)
- Business involved in jewelry or precious metals trading
- Gold trading businesses
- Antiques and vintage trading businesses
- Foreign currency exchange businesses
- Outward remittance businesses
- Informal money lending businesses
- Entities listed as terrorist organizations by the Anti-Money Laundering Office (AMLO). Currently, the AMLO has not compiled this information.
- Businesses engaged in the trade of weapons of war
Factors to consider when assessing customers with low risk levels
Factors to consider when assessing customers with low risk levels should be in accordance with the guidelines outlined in the announcements of the Secretary-General of the Anti-Money Laundering Commission.
Here are the key points from the two announcements regarding low-risk customer types:
Announcement No. 1: Types and Characteristics of Low-Risk Customers
This announcement emphasizes that customers who have provided verified identity information and do not meet the criteria for high-risk customers, as defined in Regulation No. 19 of the Ministry of Finance, should be classified as low-risk customers.
Announcement No. 2: Types of Customers for Which Financial Institutions are Not Required to Identify Customers
Customers falling into the following categories are considered low-risk customers with regard to anti-money laundering:
- His Majesty the King, Her Majesty the Queen, His Royal Highness the Crown Prince, or members of the Royal Family.
- The government, central government agencies, regional government agencies, state enterprises, or other state agencies.
- The Crown Property Bureau, specific trusts like the Chai Pattana Foundation, and various royal charities.
- Public companies listed on the stock exchange.
- Mutual funds or provident funds.
- Financial institutions under the supervision of the Bank of Thailand (excluding currency exchange businesses), the Securities and Exchange Commission, and the Office of Insurance Commission, provided that they only establish customer relationships (not as counterparties).
Customers falling into categories (1)-(5) above but located outside countries or areas subject to the following conditions are also considered low-risk customers with regard to anti-money laundering:
- Countries or areas where international anti-money laundering and counter-financing of terrorism (AML/CFT) standards are not adequately enforced.
- Countries or areas subject to sanctions, embargoes, or prohibitions on trade by important international organizations like the United Nations.
- Countries or areas with significantly high rates of corruption or serious crime.
- Countries or areas considered as sources of financial support for criminals and terrorist organizations, based on credible international organizations or developed countries with which the company has business contacts or relationships.
Measures to control the risk associated with money laundering for customers who do not establish or transact business face-to-face.
In cases where the company establishes relationships with customers through "non-face-to-face" interactions or provides "non-face-to-face transactions," there is a risk of money laundering because it's not possible to access the customer's behavior or inquire about the purpose or details of the transaction. Therefore, the company establishes measures to control the risk of money laundering and terrorist financing for such relationship establishment and transaction types. These measures include:
- The establishment of business relationships through "non-face-to-face" interactions or the provision of "non-face-to-face transactions" is only allowed for products or services with low risk.
- Products or services that involve the establishment of business relationships through "non-face-to-face" interactions or the provision of "non-face-to-face transactions."
- There must be limits on transaction amounts and/or frequencies. Additionally, an efficient operational system must be implemented to regularly monitor transactions resulting from the establishment of business relationships through "non-face-to-face" interactions or the provision of "non-face-to-face transactions."
Measures for examining transactions that raise suspicions due to customers not conducting face-to-face transactions
The company must establish a notification system and exercise discretion in suspending transactions promptly when suspicions arise, there are severe abnormalities, or there are behaviors that may be linked to money laundering and terrorist financing resulting from non-face-to-face business relationships or the provision of non-face-to-face transactions.
Practices for examining risks arising from customer relationships and measures to manage those risks
Before approving or rejecting the acceptance of a customer according to the company's customer acceptance policy, conduct an investigation to ascertain the facts about the customer by following these steps:
- Review customer transactions by screening for abnormal and money laundering-prone transactions from the customer's normal business transactions, which may allow the company to determine whether each customer has engaged in abnormal transactions or not.
- Review data and analyze whether the customer has engaged in transactions that pose money laundering risks, predicate offenses, or support for terrorism. Determine whether to report suspicious activity to the anti-money laundering office or not.
- Review and approve the analysis report of customer data review by allowing personnel, including management-level individuals, to review the analysis report of customer data review and have the authority to approve the submission of suspicious transaction reports to the anti-money laundering office or not.
Verification to ascertain the truth about customers
Once transactions with customers are approved according to the company's customer acceptance policy, proceed with regular and continuous verification to ascertain the truth about the customers until the company terminates its relationship with them.
This announcement shall be effective from January 1, 2021, onwards.
Mr. Apichai Susamawathanakun
Chairman of the Board
Announcement
Superrich Green Group Company Limited
No. 4/2021
Protection of Customer Personal Data in Accordance with the Personal Data Protection Policy of Superrich Green Group Company Limited
- Scope and Objectives
Superrich Green Group Company Limited, hereinafter referred to as the "Company," acknowledges the paramount importance of safeguarding the personal information of individuals utilizing the Company's services, hereinafter referred to as "Customers," in accordance with the Personal Data Protection Act 2019. Consequently, the Board of Directors has duly deliberated and endorsed the Company's Personal Data Protection Policy. In light of this, the Company has formulated the following announcement, applicable to all Customers, with the aim of elucidating the procedures for collecting, utilizing, and disclosing Customers' personal information in relation to any service rendered by the Company.
"Personal information" refers to data pertaining to customers that enables their identification, whether directly or indirectly. This excludes information regarding deceased individuals, juridical entities, or data that has undergone procedures rendering it impossible to identify the respective customer who owns said personal information.
"Sensitive Data" refers to personal information encompassing race, ethnicity, political opinions, beliefs in cults, religions, or philosophies, sexual behavior, and criminal history, which similarly impacts the data subject. As stipulated by the committee, the company will only collect, use, and/or disclose sensitive personal information under two conditions: explicit consent from you or when deemed necessary by law. Additionally, the Company may need to collect, use, and/or disclose personal biometric information such as facial image data, fingerprint simulation data, iris simulation data, and voice identity information for the purpose of verifying and authenticating the user's identity in providing services you request to apply for and/or conduct transactions through various channels.
"Processing of personal data" means any action the Company takes regarding customers' personal information, including the collection, use, disclosure, and deletion of such information.
"Services of the Company" refers to foreign currency exchange services and souvenir sales services.
2.Individuals Who Use Customer Personal Data
Company is the "Personal Data Controller" for all customers and has the duty and responsibility to process and secure customers' personal information. The processing of personal data will be conducted as necessary to provide services or fulfill requests, which may include promotions and marketing, as applicable. This will be done with the objectives, scope, and methods of use as specified by law.
Additionally, the Company may transfer your personal information to agencies or third parties for processing, acting as "Personal Data Processors" on behalf of the Company.
3.Customer Personal Data That May Be Collected by the Company
For accessing and using the Company's financial services, customers must provide personal information necessary for their identification. This is to enable service usage and/or financial transactions related to financial products. Such information includes:
- Personal information required for service usage.
- Identity verification documents as supporting documents for service usage.
- Credit/debit card information.
- Transactional data/service usage information.
Additionally, the Company also processes personal data pertaining to usage through its information technology system. This includes data from CCTV cameras, the building entry-exit system, and computer traffic information, in accordance with the law on computer crimes.
Generally, the company collects almost all personal data directly from customers through the membership application/service usage process. However, the company may also gather additional information from other sources, such as external service providers or government agencies. Nonetheless, information obtained from other sources undergoes verification or certification to ensure its suitability for the purposes outlined in this announcement.
The company may process personal data that can identify customers in the form of documents, and/or images, and/or electronic formats.
4.Why does the company need to use customers' personal data?
The company uses customers' personal data for various operations in accordance with the company's objectives related to financial services. The company processes customers' personal data with reasons (grounds for data processing), which may rely on one reason or multiple reasons, as follows:
4.1 Due to the company's obligation to adhere to contractual agreements: processing in accordance with the contract.
To enable customers to utilize the company's services as per their existing membership or customer agreement with the company, or as per customer requests either prior to or during their membership/service usage with the company.
- Membership registration with the company involves providing and updating personal information/service-related data for customer relations. This data processing is aimed at service development, benefits provision, and invoice issuance.
- Other operations conducted to fulfill the objectives of service/membership provision include handling complaints, conducting satisfaction surveys regarding service delivery, and managing service risk.
4.2 Due to the company's legal obligation to act in accordance with its lawful interests: processing based on legitimate interests.
The company may use customers' personal data for processing purposes, including management, auditing, and internal reporting. This encompasses maintaining systems to uphold service standards, managing the company's risks, and conducting routine internal operations, all in accordance with legal and beneficial interests, such as:
- Voice recording through member service channels, or CCTV camera recording.
- Maintaining customer relations, such as managing complaints, assessing satisfaction with service usage, and offering services similar to those already held by customers with the company, for the benefit of customers.
- Organizational risk management, audits, internal management, as well as forwarding to affiliated companies for the aforementioned operations.
- Controlling, preventing, mitigating, or transferring risks that may arise from fraudulent activities, cyber threats, defaulting on debts, or breaching contracts, as well as violations of various laws (such as preventing and combating money laundering, providing financial support for terrorism, and proliferating weapons of mass destruction, violations related to property, life, body, freedom, or reputation, etc.). This includes sharing personal data to enhance the operational standards of the company within the financial business group for controlling, preventing, mitigating, or transferring the aforementioned risks.
- Collecting, using, and/or disclosing personal data of directors, authorized representatives, or corporate clients' representatives.
- Contacting for image and sound recording from meetings, training sessions, recreational activities, or booth exhibitions.
- Collecting, using, and/or disclosing personal data of individuals subject to court-appointed conservatorship.
4.3 Due to the company's legal obligation to comply with laws: processing based on legal obligation.
The company may process customers' personal data to comply with the laws regulated by supervising agencies overseeing the company's business operations, such as the Bank of Thailand, the Office of the Consumer Protection Board, the Department of Business Development under the Ministry of Commerce, the National Anti-Corruption Commission, and the Office of the Personal Data Protection Committee. Additionally, this includes laws governing transactions in the securities market, such as the Cybersecurity Act B.E. 2562, the Anti-Money Laundering Act B.E. 2542, the Debt Collection Act B.E. 2558, and other laws that the company must adhere to, including requirements to provide data both domestically and internationally, as well as decrees and regulations issued in accordance with the aforementioned laws, such as the Compilation of Procedures for Considering Disputes, which grants courts the authority to order parties to submit documents or information for case consideration, and so forth.
4.4 Due to the company having obtained consent from customers: processing is carried out in accordance with consent.
The Company will seek customer consent to process their personal data for marketing purposes, sales promotion, offering of benefits, any product or service offerings, as well as for statistical analysis, study, research, data evaluation, or any other lawful purposes.
Processing of customer personal data will strictly adhere to the stated objectives. In some instances, the Company may deem it appropriate to process customer personal data for additional purposes related to, and not inconsistent with, the original purpose. However, should the Company find it necessary to process data for purposes unrelated to the original objective, new consent will be requested.
Should customers wish to withdraw their consent for such processing, they may contact the Company to make their request. However, it is essential to note that withdrawing consent may impact the customer's utilization of membership services or access to other services, such as missing out on benefits, promotions, or receiving tailored services. Therefore, for the customers' benefit, it is advisable to study or inquire about the consequences before revoking consent.
2.Disclosure of Personal Information to Third Parties
The Company may disclose customers' personal information to third parties to the extent necessary for data processing in accordance with contractual obligations, legal requirements, or with the customers' consent. The Company may transmit customers' personal data to external parties as follows:
- Agents, contractors, or service providers who offer services to the Company and its customers, such as business groups, financial institutions, partners, business associates providing joint services, consultants, experts, and service providers in various fields such as information technology and communication.
- Regulatory authorities or government agencies responsible for overseeing business operations, such as the Bank of Thailand, the Office of the Consumer Protection Board, the Department of Business Development under the Ministry of Commerce, the Anti-Money Laundering Office, the Revenue Department, the Department of Special Investigation, the Ministry of Justice, the National Police Office, or any other entity that the Company is obliged to disclose information to as required by law or relevant regulations, or in specific cases such as court orders.
- For the establishment of rights claims under the Company's contract or legal obligations, or for legal proceedings.
- The Company may send or transfer customers' data abroad in compliance with agreements between the Company and individuals or legal entities for the benefit of customers or to comply with legal requirements. The destination country must be assessed by the Personal Data Protection Committee to ensure adequate protection of personal data, or the receiving agency or organization must be audited and certified by the Personal Data Protection Committee to have appropriate data protection measures in place.
3.Automated processing process
In cases where clear consent has been obtained from customers, the company may utilize customers' personal data for automated processing. This could impact customer profiles or serve other purposes such as data aggregation for marketing. Should customers wish to withdraw their consent, they can directly contact the company to request withdrawal of their consent.
4.Rights to Customer Personal Data
Customers have rights to their personal data, and they can request to exercise these rights in accordance with the terms set by the law and regulations currently in place or those that may be amended or added in the future.
- The right to be informed entails receiving notification about the processing of personal data, methods of collection, individuals who will receive the data, reasons for processing, and the duration of data retention.
- The right of access allows individuals to request copies of their personal data held by the company and verify whether the company has processed the data lawfully or not.
- The right to data portability enables customers to request that the company transmit their personal data to another entity in a machine-readable format that is commonly used and processed by automatic means. Customers can request the company to send or transfer their personal data to another entity automatically, or they can request to receive the personal data that the company has sent or transferred to another entity directly, unless it is technically unfeasible.
- The right to object allows customers to object to the processing of their personal data by the company.
- The right to erasure, also known as the right to be forgotten, allows customers to request the deletion or destruction of their personal data, or to make their personal data unidentifiable.
- The right to restrict processing Customers can request a suspension of the processing while the Company verifies or addresses their requests.
- The right of rectification allows customers to request the correction of their personal data to ensure its accuracy, completeness, and currency. If customers find that their data is inaccurate, incomplete, or outdated, they have the right to request corrections.
In addition, customers have the right to submit requests to exercise their rights to the company. In some cases, the company may refuse to grant the customer's rights for reasons that will be communicated to them. If customers disagree with the reasons provided by the company, they can file a complaint with the Office of the Personal Data Protection Committee.
Any request to exercise customer rights as mentioned above must be made in writing, and the company will make its best efforts to process or respond to the request within 30 days or within the time frame specified by law. The company will comply with legal requirements related to customer rights as data subjects. In cases where customers request the company to delete, destroy, remove, temporarily suspend processing of personal data, convert personal data into a form that cannot identify the data subject, or withdraw consent, it may impose limitations on the company's ability to conduct transactions or provide services to customers. In this regard, the company reserves the right to charge any relevant fees necessary for processing personal data in accordance with customer requests.
5.The Data Retention Period
In accordance with the principle of necessity, our company will retain your personal data for the duration necessary to fulfill the purposes of data collection as required by law.
- Customer personal data will be collected and retained for the duration of the customer's membership in financial products, and for an additional period not exceeding 10 years from the date of the termination of the customer's membership.
- In the event of non-approval of membership, the company will retain any personal data of customers who have not been approved for a period not exceeding 1 year from the date of non-approval.
- In the event that the retention period expires, the company will proceed to delete or anonymize personal data to render it unidentifiable.
6.Methods Used by the Company to Protect Customers' Personal Data
The company manages the protection of personal data in accordance with the 'Information Security Management System Standard.'
7.Amendments to the Personal Data Protection Policy
The company may consider reviewing its policy on customer data protection. In the event of any changes, the company will notify through its website and other appropriate channels.
8.Contact Channels
In case customers wish to exercise their rights or withdraw consent for the processing of their personal data, or have any inquiries regarding our company's personal data processing, they can reach us at:
- Superrich Green Group Company Limited: No. 45, Soi Ratchadamri 1, Ratchadamri Road, Lumpini Subdistrict, Pathumwan District, Bangkok 10330 on the day and time specified by the company.
- Call Center : โทร 02-2544444
- ● If customers believe that the processing of their personal data does not comply with the Personal Data Protection Act B.E. 2562, they have the right to lodge a complaint with the Office of the Personal Data Protection Committee.
2.his announcement serves as an advance notice for enforcement, effective from May 27, 2021 onwards.
"In the event of any enforcement impact regarding personal data protection under the Personal Data Protection Act B.E. 2562 being postponed, this announcement will also postpone its enforcement to the same effective date as when the personal data protection laws come into effect, solely for the affected areas."