LAPlus

Privacy Policy

Last Updated: 01/07/2026

LAPlus

Privacy Policy

Last Updated: 01/07/2026

LAPlus

Privacy Policy

Last Updated: 01/07/2026

This Privacy Policy explains how LawtonAsia Insurance Brokers Ltd. ("we", "us", or "our") collects, uses, discloses, and protects your personal data when you use our mobile application LA Connect (the "App"). This policy complies with Thailand's Personal Data Protection Act B.E. 2562 (2019) ("PDPA") and related subordinate legislation.

 

1. Data Controller Information

LawtonAsia Insurance Brokers Ltd. is the data controller responsible for your personal data.

Company Name: LawtonAsia Insurance Brokers Ltd.

Registration No.: 0105544093538

Address: 548 One City Centre, 20th Floor Unit 6, Phloen Chit Road, Lumphini, Pathum Wan, Bangkok 10330

Email: info@lawtonasia.co.th

Tel: +66 2 654 1150

 

2. Personal Data We Collect

We collect the following categories of personal data:

2.1 Data You Provide Directly

•       Identity data: full name, date of birth, gender, marital status, government-issued identification

•       Contact data: email address, phone number, mailing address

•       Account credentials: username and encrypted password

•       Profile data: profile picture, preferences, settings

•       Insurance-related data: insurance policies, beneficiary information, claims history

•       Health data: Sensitive personal data such as medical treatments and health details, medical records and history

•       Payment data: Details of employment, income, personal and business financial information including credit card information or bank account details

•       Communications: messages, feedback, or support requests you send us

2.2 Data Collected Automatically

•       Device data: device type, operating system, unique device identifiers

•       Location data: approximate location derived from IP address; precise GPS location (only if you grant permission)

•       Log data: IP address, browser type, access times, error logs

•       Cookie and tracking data: see Section 8 (Cookies & Tracking Technologies)


3. Legal Basis for Processing

Under the PDPA, we rely on the following lawful bases to process your personal data:

•       Consent (Section 19 PDPA): for marketing communications, precise location tracking, market research and other optional analytics. You may withdraw consent at any time.

•       Contract (Section 24(3) PDPA): to provide the App's core services.

•       Legitimate interests (Section 24(5) PDPA): for fraud prevention, service security, and improving the App, provided these interests are not overridden by your rights.

•       Legal obligation (Section 24(6) PDPA): to comply with applicable Thai laws and regulatory requirements.

 

4. Purposes of Processing

We use your personal data for the following purposes: 

•       Account registration, authentication, and management

•       To enable us to acquire or renew insurance policies;

•       To assess your ongoing insurance needs 

•       To market our products and services 

•       To manage claims or potential claims notified by or made against or otherwise involving you or your beneficiaries and dependents, relating to insurance policies handled by us

•       To collect claims statistics/history

•       To conduct market analysis and research

•       To deliver and improve the App's features and content

•       To provide customer support and respond to inquiries

•       To send service-related notifications 

•       To send marketing and promotional communications (with your consent)

•       To detect, prevent, and investigate fraud and security incidents

•       To comply with legal obligations and respond to lawful requests from authorities

 

5. Disclosure of Personal Data

We do not sell your personal data. We may share your data with:

5.1 Service Providers

Third-party vendors who host and/or process data on our behalf under written data processing agreements, including app development, cloud hosting, payment processing, analytics, customer support, and push notification providers. 

5.2 Business Partners

With your consent, we may share data with carefully selected partners offering complementary services.

5.3 Legal & Regulatory Authorities

Where required by Thai law (including the PDPA, the Computer Crime Act B.E. 2550, and any regulatory orders), we may disclose your data to courts, law enforcement, or regulators. 

5.4 Corporate Transactions

In the event of a merger, acquisition, or sale of assets, your data may be transferred to a successor entity, which will remain bound by this Privacy Policy.


6. International Data Transfers

If we transfer your personal data outside Thailand, we will ensure adequate safeguards are in place as required by Sections 28-29 of the PDPA, including:

•       Transfers to countries with adequate data protection standards as determined by the Personal Data Protection Committee (PDPC)

•       Standard contractual clauses approved by the PDPC

•       Your explicit consent, where required under the PDPA

 

7. Data Retention

We may retain your personal data for as long as it is necessary to fulfil the purpose for which it was collected. In case of termination of our business relationship, we will keep your personal data as required or permitted by applicable Thai laws. We will cease to retain your personal data, or remove the means by which the data can be associated with you, as soon as it is reasonable to assume that such retention no longer serves the purpose for which the personal data was collected, and is no longer necessary for legal purposes.

 

8. Cookies & Tracking Technologies

We use cookies and similar technologies to operate and improve the App. You can manage cookie preferences through your device settings or the in-app privacy settings. Types used include:

•       Essential cookies: necessary for core functionality (cannot be disabled)

•       Analytics cookies: help us understand how you use the App (opt-out available)

•       Preference cookies: remember your settings and personalisation choices

•       Marketing cookies: used to show you relevant advertising (requires your consent)

 

9. Your Rights Under the PDPA

As a data subject under Thailand's PDPA, you have the following rights: 

•       Right of access (Section 30): to request a copy of your personal data and information about how it is processed

•       Right to rectification (Section 35): to request correction of inaccurate or incomplete data

•       Right to erasure (Section 33): to request deletion of your data in certain circumstances

•       Right to restriction (Section 34): to request that we limit processing in certain circumstances

•       Right to data portability (Section 31): to receive your data in a machine-readable format

•       Right to object (Section 32): to object to processing based on legitimate interests

•       Right to withdraw consent (Section 19): to withdraw consent at any time, without affecting prior processing

•       Right to lodge a complaint: to file a complaint with the Office of the PDPC

 

To exercise any of these rights, please contact us at dpo@lawtonasia.co.th. We will respond within 30 days. We may need to verify your identity before processing your request.

 

10. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or alteration, including:

•       TLS/SSL encryption for data in transit

•       Encryption for sensitive data at rest

•       Role-based access controls and least-privilege principles

•       Regular security audits and penetration testing

•       Incident response procedures in line with PDPA notification requirements

 

In the event of a personal data breach that may harm your rights and freedoms, we will notify the PDPC within 72 hours and affected individuals without undue delay, as required by the PDPA.

 

11. Children's Privacy

The App is not directed at children under 20 years of age (the age of majority in Thailand) or minors under 10 years of age without verified parental consent. We do not knowingly collect personal data from children without appropriate parental or guardian consent as required by Section 20 of the PDPA. If you believe we have collected such data inadvertently, please contact us immediately.

 

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via in-app notification or email at least 30 days before the changes take effect. Your continued use of the App after the effective date constitutes acceptance of the updated policy. Where required by law, we will seek your fresh consent.

 

13. Contact & Complaints

For any privacy-related queries or to exercise your rights, please contact our Data Protection Officer (DPO):


Data Protection Officer 

Email: dpo@lawtonasia.co.th

Tel: +66 2 654 1150


If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Personal Data Protection Committee (PDPC):


Office of the PDPC

Website: www.pdpc.or.th

Hotline: 1207