Privacy Policy - SRN Sound Proof Co., Ltd.


1. Introduction and Strategic Importance of Information Security

    SRN Sound Proof Co., Ltd. (SRN), as a leading manufacturer of thermal insulation and sound-absorbing materials in the Automotive Supply Chain, recognizes that information security is the core of building trust with our global partners. We adhere to the Personal Data Protection Act B.E. 2562 (PDPA) and the Computer-Related Crime Act (No. 2) B.E. 2560 as the highest standards in our business operations. These are integrated with international standards such as the JAMA/JAPIA Cybersecurity Guidelines Version 2.2 to protect personal data and intellectual property from cyber threats in all dimensions.

    This policy covers data transmission activities and services through the Company's information systems, including SRN Connect and SRN Data Transfer, to clarify the details of data collection and processing transparently.

2. Data Collection

    The Company collects personal data to the extent necessary for Authentication and Role-Based Access Control (RBAC) via SRN Connect and SRN Data Transfer systems, as follows:

  • Registration and Coordination Data: Full name, company name, department, job title, email, and phone number.
  • Identity Verification Data: Username, password, external authentication via Microsoft 365, and one-time Security-Code.
  • Technical Data (Log Data): Datetime Login/Logout, IP Address, file upload/download history (filename, size, and type), and Cookies.
  • Data Minimization: According to policy ITA 003, the Company does not have a policy to store highly sensitive personal data on our computer systems and servers, such as photos or copies of ID cards, credit card information, and personal financial transaction data.
3. Purposes of Data Collection and Processing

    SRN focuses on data management under the Information Security Audit strategy to protect organizational confidentiality (Confidentiality Management) according to the SI-AD-005 manual, with the following purposes:

  • Authentication and Access Control: To assign Read/Write Permission according to the Folder Access Group structure, preventing unauthorized access to trade secrets and intellectual property.
  • Efficiency and Security in File Transfer: To facilitate the exchange of large technical files with Suppliers and Vendors via the highly secure SRN Data Transfer system.
  • Traceability: To be used as evidence in the Audit process when abnormal events or cybersecurity incidents occur, in accordance with the JAMA/JAPIA standard requirements.
4. Personal Data Security Measures

    The Company employs technical and administrative measures consistent with the 10 Priority Measures of the automotive standard to reduce the Window of Opportunity for system intrusions:

Security Measure Implementation Details
Password Management Mandatory password change every 90 days to mitigate the risk of password leaks, with complexity requirements.
Access Control Implementation of Multi-Factor Authentication (MFA) and one-time Security-Code for downloading critical data.
Information System Protection Installation of Web Filtering and Gateway Security, along with regular Vulnerability Management scans.
Business Continuity Plan (BCP) Compliance with the "Operational Flowchart in Case of Power Outage," with status checks within 15 minutes and clear procedures for server shutdown/data backup to maintain data integrity.
5. Data Subject Rights

    Under the PDPA, Data Subjects have the right to control their own data to ensure transparency, as follows:

  • Right to Access and Obtain a Copy: Check the personal data stored by the Company in the system.
  • Right to Restrict or Object: Suspend data processing when there is no legal or contractual necessity.
  • Right to Rectification: Request correction to ensure data is accurate and up-to-date, such as changing a user account email.
  • Right to Erasure or Destruction: Request deletion of data upon the expiration of the retention period according to the Company's data retention policy.
6. Data Controller Contact Information

    If you wish to exercise your legal rights or have any questions regarding data security measures, you may contact the Data Controller Representative Committee at:

  • Company Name: SRN SOUND PROOF CO., LTD.
  • Address: 700/828 Moo 6, Amata City Industrial Estate, Nong Tamlueng Subdistrict, Phan Thong District, Chonburi 20160 Thailand
  • Telephone: (+66) 038-185-524-8
  • Business Hours: Monday - Friday, 8:00 AM - 5:00 PM (Closed on Saturdays and Sundays)

    The Company is committed to developing and updating our privacy policy to keep pace with changing circumstances and technologies, maintaining the highest level of data security standards in accordance with SRN's ideology.