Grow to Demand: reserve a crop before it is planted. See how it works

Data Protection Policy

  1. Effective date: 25 July 2026

    This Data Protection Policy describes the principles and internal commitments Varmers follows when processing personal data, including under Thailand’s Personal Data Protection Act B.E. 2562 (2019) where applicable.

    1. Scope and responsibility

    This policy applies to personal data processed by Varmers Growing Tech Co., Ltd. in connection with customers, website users, suppliers, partners, employees and other individuals.

    Management is responsible for establishing appropriate data-protection controls, and personnel who handle personal data must follow this policy.

    2. Data-protection principles

    • Process personal data lawfully, fairly and transparently.
    • Collect personal data for specified, explicit and legitimate purposes.
    • Limit collection to information that is adequate, relevant and necessary.
    • Take reasonable steps to keep personal data accurate and current.
    • Retain personal data no longer than necessary or legally required.
    • Protect personal data against unauthorised access, loss, alteration or disclosure.
    • Be accountable for compliance and maintain appropriate records.

    3. Lawful processing and notices

    Before or at the time personal data is collected, Varmers will provide appropriate information about the purpose of processing, relevant disclosures, retention, rights and contact details unless an exception applies.

    Where consent is required, it will be requested in a clear manner and recorded. Consent can be withdrawn according to applicable law.

    4. Data minimisation and access control

    Personnel should access only the personal data needed for their responsibilities. Accounts, permissions and systems should be configured according to operational need.

    Sensitive or high-risk information should receive additional safeguards appropriate to the risk.

    5. Service providers

    Before engaging a provider that processes personal data, Varmers will take reasonable steps to assess the provider and establish appropriate contractual obligations concerning confidentiality, security, permitted processing, incident reporting and deletion or return of data.

    6. Security and incidents

    Varmers maintains reasonable security measures, which may include access controls, secure connections, backups, system updates, malware protection, staff awareness and incident-response procedures.

    Suspected loss, unauthorised access, disclosure or other personal-data incident must be reported promptly to the responsible manager. Varmers will assess notification obligations and take appropriate remedial action.

    7. Retention and disposal

    Personal data will be retained according to operational and legal requirements and securely deleted, destroyed or anonymised when no longer required.

    8. Individual requests

    Requests concerning personal data may be submitted to info@varmers.com. Varmers will verify identity, record the request and respond within the period required by applicable law, subject to lawful exceptions.

    9. Training and review

    Personnel with access to personal data should receive appropriate guidance. This policy will be reviewed periodically and when significant changes occur.

    10. Contact

    Data-protection enquiries may be sent to info@varmers.com or mailed to 3079 Sukhumvit Road, Bang Chak Subdistrict, Phra Khanong District, Bangkok, Thailand.

     

    Business contact Varmers Growing Tech Co., Ltd.
    3079 Sukhumvit Road, Bang Chak Subdistrict, Phra Khanong District, Bangkok, Thailand
    info@varmers.com
    +66 2 566 0958