Privacy notice
Data collected
Name, national ID number, phone number, email (if given), address, request details, location and attachments (if any), data a service requires, and your LINE account when you send through LINE, plus usage data needed for security such as time and IP address.
Purposes
To receive, check and carry out requests, ask for more information, report progress and results, let you track the status, prevent duplicate or abusive submissions, and produce statistics that do not identify anyone.
Legal basis
Performance of a task carried out in the public interest or in the exercise of official authority vested in the local government organization (Section 24 (4) of the Personal Data Protection Act B.E. 2562), and compliance with the laws governing each service. Health information entered for certain services (such as booking patient transport) is used only as far as necessary to provide that service, under the exceptions in Section 26 of the same Act.
Who can see your data
Only staff of the organization authorized for the department or service handling the request. Health data is visible only to staff of the responsible department. Viewing a full national ID number requires a reason and is logged. The system does not disclose your data to outside parties unless the law requires it.
Service providers acting for the organization
The system uses outside providers only where necessary: Cloudflare (network delivery, attack protection, bot checks, and storage of attachments in Asia-Pacific data centres), the server hosting provider, and LINE when you use the service through LINE. These providers may use the data only as the organization instructs and must keep it secure. Some data may be processed outside Thailand under the safeguards required by law.
How long data is kept
Requests, their status history and supporting documents are official records. They are kept as evidence and a history of the service and are not deleted automatically, in line with the organization's records management regulations. Temporary usage data, such as tracking sign-ins and verification codes, is deleted automatically within 30 days of expiry, and notification delivery records within 1 year.
Security
National ID numbers are encrypted before storage, attachments are kept in non-public storage, each organization's data is separated in the database, and important staff actions are logged in a way that cannot be changed.
Cookies and browser storage
The system uses only essential cookies, for tracking requests and for staff sign-in. It uses no advertising or behavioural tracking cookies. Your chosen language, display theme and unsent request draft are stored only in your browser (the draft never includes the national ID number or files, and is cleared when you close the tab).
Your rights
You have the right to request access to or a copy of your data, to have it corrected, to object, to have its use restricted, or to have it deleted or masked, under the conditions set by law. The organization may still need to keep data required for its duties or by law, and will tell you why. You also have the right to complain to the Office of the Personal Data Protection Committee.
Changes to this notice
The organization may update this notice when the law or the service changes. The version shown on this page is the one in force.
Contact
For personal data matters, contact System test organization