นโยบายความเป็นส่วนตัว · Privacy ข้อกำหนดการใช้งาน · Terms คู่มือ 2FA

ใช้บังคับกับเว็บไซต์ smart-hr.assystem.co.th, smart-hr-srv01.assystem.co.th และแอปมือถือ "Smart HR" (iOS/Android) ที่พัฒนาโดย บริษัท เอเอส ซิสเต็ม จำกัด ให้องค์กรปกครองส่วนท้องถิ่น (อปท.) ใช้บริหารงานบุคคล ตาม พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA)
หน่วยงาน อปท. ที่ท่านสังกัด เป็นผู้ควบคุมข้อมูลส่วนบุคคล (Data Controller) ของบุคลากรของตน · บริษัท เอเอส ซิสเต็ม จำกัด เป็นผู้ประมวลผลข้อมูล (Data Processor) ตามคำสั่งและสัญญากับหน่วยงาน ไม่นำข้อมูลไปใช้เพื่อวัตถุประสงค์อื่น ไม่ขาย ไม่แบ่งปันเพื่อการโฆษณา
| ประเภท | ตัวอย่าง | ที่มา |
|---|---|---|
| ข้อมูลระบุตัวตน | ชื่อ ตำแหน่ง สังกัด ประเภทบุคลากร รหัสพนักงาน อีเมล/LINE สำหรับแจ้งเตือน · เลขประจำตัวประชาชน (เข้ารหัส) | ระบบ Smart Office ของหน่วยงาน / ทะเบียนประวัติที่งานการเจ้าหน้าที่บันทึก |
| ข้อมูลการปฏิบัติงาน | ใบลา วันลาคงเหลือ เวลาเข้า–ออกงาน การลงเวลานอกสถานที่ (งานที่ไป เหตุผล) ผลการประเมิน การอบรม คำสั่งบรรจุ/แต่งตั้ง | การใช้งานระบบ |
| เอกสารแนบ | ใบรับรองแพทย์ เอกสารประกอบการลา รูปถ่ายเอกสาร — อาจมีข้อมูลสุขภาพ (ข้อมูลอ่อนไหว ม.26) ซึ่งประมวลผลเพื่อปฏิบัติตามระเบียบการลาของทางราชการ | ท่านแนบเองผ่านเว็บ/แอป |
| ลายมือชื่ออิเล็กทรอนิกส์ | ภาพลายเซ็นที่ท่านวาดไว้ ใช้ประกอบใบลาและการอนุมัติ | ท่านบันทึกเองที่หน้า "บัญชีของฉัน" |
| ตำแหน่งที่ตั้ง | พิกัด GPS ความแม่นยำ และระยะห่างจากจุดลงเวลา เฉพาะขณะกดลงเวลา — ไม่ติดตามตำแหน่งเบื้องหลัง | แอปมือถือ/เบราว์เซอร์ (ขออนุญาต "ขณะใช้แอป") |
| ข้อมูลชีวมิติ (เมื่อหน่วยงานเปิดใช้) | แม่แบบใบหน้า (เวกเตอร์ตัวเลข ไม่ใช่รูปภาพ) และรูปยืนยันตัวตนขนาดเล็กขณะลงเวลา | แอป/kiosk หลังได้รับความยินยอมชัดแจ้ง (ข้อ 6) |
| ข้อมูลอุปกรณ์ | รุ่นเครื่อง ระบบปฏิบัติการ เวอร์ชันแอป รหัสเครื่อง (สุ่มโดยแอป) ที่อยู่ IP · เครื่องที่ "จำไว้ 30 วัน" | แอป/เบราว์เซอร์ |
| บันทึกการใช้งาน | เวลาเข้าระบบ การอนุมัติ การแก้ไข การเข้าถึงข้อมูล ตามประมวลแนวทางปฏิบัติของ สกมช. | ระบบ |
แอปนี้ไม่มีการสมัครบัญชีด้วยตนเอง บัญชีถูกสร้างและยกเลิกโดยงานการเจ้าหน้าที่ของหน่วยงานตามสถานะการทำงาน เมื่อพ้นสภาพ บัญชีจะถูกปิดและข้อมูลถูกเก็บหรือทำลายตามระเบียบเอกสารราชการ · ท่านขอลบข้อมูลที่ไม่ใช่เอกสารราชการ (เช่น ลายมือชื่อ แม่แบบใบหน้า เครื่องที่จำไว้) ได้ทันทีในระบบหรือผ่านงานการเจ้าหน้าที่
ระบบไม่เก็บรูปถ่ายใบหน้าเพื่อการจดจำ แต่แปลงเป็น "แม่แบบ" ตัวเลขที่เข้ารหัสด้วยกุญแจเฉพาะของหน่วยงาน ใช้เทียบเฉพาะกับตัวท่านเอง (1:1) ขณะลงเวลา · การประมวลผลใบหน้าเกิดขึ้นบนเครื่องของท่านเป็นหลัก · ก่อนลงทะเบียนใบหน้า ท่านจะได้อ่านและให้ความยินยอมแยกต่างหาก และถอนความยินยอมได้ทุกเมื่อ โดยยังลงเวลาได้ด้วยวิธีอื่นที่หน่วยงานจัดให้
ข้อมูลของแต่ละหน่วยงานแยกเก็บเป็นอิสระ ไม่เปิดเผยให้หน่วยงานอื่นหรือบุคคลภายนอก · เจ้าหน้าที่ของ AS System เข้าถึงได้เฉพาะเพื่อดูแลระบบและมีบันทึกทุกครั้ง · ผู้ให้บริการที่จำเป็น: Apple/Google (การแจ้งเตือนและการแจกจ่ายแอป) และ LINE/อีเมล (เฉพาะเมื่อท่านเปิดรับแจ้งเตือน) โดยส่งเพียงข้อความแจ้งเตือน ไม่ส่งข้อมูลทะเบียนประวัติ · เซิร์ฟเวอร์ตั้งอยู่ในประเทศไทย ไม่มีการโอนข้อมูลออกนอกประเทศ · อาจเปิดเผยตามคำสั่งของหน่วยงานรัฐที่มีอำนาจตามกฎหมาย
เข้ารหัสการรับส่งข้อมูล (TLS) · เข้ารหัสข้อมูลอ่อนไหวในฐานข้อมูล · เอกสารแนบและลายมือชื่อเก็บนอกพื้นที่เว็บ เปิดได้เฉพาะผู้เกี่ยวข้อง · ยืนยันตัวตนสองชั้น · แยกสิทธิ์ตามบทบาท · บันทึกการเข้าถึงและแก้ไขทุกครั้ง · ทดสอบช่องโหว่สม่ำเสมอ
ขอเข้าถึง ขอสำเนา ขอแก้ไข ขอลบ/ระงับ คัดค้าน โอนย้าย และถอนความยินยอม ได้โดยติดต่องานการเจ้าหน้าที่ของหน่วยงานที่ท่านสังกัด ซึ่งเป็นผู้ควบคุมข้อมูล หน่วยงานจะตอบภายใน 30 วัน · ท่านมีสิทธิร้องเรียนต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล
แอปไม่ใช้เครื่องมือวิเคราะห์พฤติกรรมหรือโฆษณาของบุคคลที่สาม และไม่เชื่อมโยงข้อมูลกับแอปอื่น
ใช้เฉพาะคุกกี้ที่จำเป็นต่อการทำงาน (เซสชันเข้าสู่ระบบ การป้องกัน CSRF และการจำภาษา/เครื่องที่ท่านเลือก) ไม่มีคุกกี้โฆษณาหรือติดตาม
ระบบมีไว้สำหรับบุคลากรของหน่วยงานเท่านั้น ไม่ได้ออกแบบให้ผู้ที่อายุต่ำกว่า 18 ปีใช้งาน
นโยบายอาจปรับปรุงเมื่อระบบเพิ่มความสามารถใหม่ วันที่ปรับปรุงล่าสุดแสดงไว้ด้านบน · ผู้ประมวลผลข้อมูล: บริษัท เอเอส ซิสเต็ม จำกัด · www.assystem.co.th · เรื่องสิทธิของเจ้าของข้อมูล กรุณาติดต่อเจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (DPO) ของหน่วยงานที่ท่านสังกัด

This policy applies to smart-hr.assystem.co.th, smart-hr-srv01.assystem.co.th and the "Smart HR" mobile app (iOS/Android) developed by AS System Co., Ltd. for Thai local government organisations to manage their personnel, under the Personal Data Protection Act B.E. 2562 (2019) (PDPA).
The local government organisation you work for is the Data Controller of its personnel data. AS System Co., Ltd. is the Data Processor acting under the organisation's instructions and contract. We do not use the data for any other purpose, do not sell it and do not share it for advertising.
| Category | Examples | Source |
|---|---|---|
| Identity | Name, position, unit, personnel type, employee ID, e-mail/LINE for notifications, national ID number (encrypted) | Your organisation's Smart Office system / personnel records entered by HR |
| Work records | Leave requests and balances, clock-in/out times, off-site check-ins (task and reason), appraisals, training, appointment orders | Your use of the system |
| Attachments | Medical certificates and supporting documents for leave — may contain health data (sensitive data, s.26), processed to comply with official leave regulations | Uploaded by you via web/app |
| Electronic signature | The signature image you draw, used on leave forms and approvals | Saved by you under "My account" |
| Location | GPS coordinates, accuracy and distance to the check-in point only at the moment you clock in/out — no background tracking | Mobile app / browser ("while using the app" permission) |
| Biometric data (if enabled by your organisation) | A face template (numeric vector, not a photo) and a small verification snapshot at clock-in | App/kiosk, only after explicit consent (section 6) |
| Device data | Device model, OS, app version, an app-generated device ID, IP address, devices you chose to "remember for 30 days" | App / browser |
| Activity logs | Sign-ins, approvals, edits and data access, as required by the National Cyber Security Agency code of practice | System |
The app has no self-registration. Accounts are created and closed by your organisation's HR according to employment status. When employment ends the account is disabled and records are retained or destroyed under official records rules. You can delete non-record data (signature, face template, remembered devices) yourself in the system or through HR at any time.
We do not store face photos for recognition. Faces are converted into a numeric template encrypted with a key unique to your organisation and compared only against you (1:1) at clock-in. Processing happens primarily on your device. Before enrolment you read and give a separate consent, which you can withdraw at any time; you can still clock in by another method your organisation provides.
Each organisation's data is stored separately and is never disclosed to other organisations or third parties. AS System staff access data only for system maintenance and every access is logged. Necessary service providers: Apple/Google (app distribution and notifications) and LINE/e-mail (only if you enable notifications) receive notification text only, never personnel records. Servers are located in Thailand; no cross-border transfer. Data may be disclosed to government authorities where the law requires.
TLS encryption in transit · encryption of sensitive fields at rest · attachments and signatures stored outside the web root and served only to authorised users · two-factor authentication · role-based access · full audit logging · regular vulnerability testing.
You may request access, a copy, correction, deletion/restriction, objection, portability and withdrawal of consent by contacting the HR unit of your organisation (the Data Controller), which responds within 30 days. You may also lodge a complaint with the Personal Data Protection Committee Office.
The app contains no third-party analytics or advertising SDKs and does not link data with other apps.
Only strictly necessary cookies are used (login session, CSRF protection, your language and remembered-device choices). No advertising or tracking cookies.
The service is intended solely for organisation personnel and is not designed for anyone under 18.
This policy may be updated when new features are added; the date above shows the latest revision. Data Processor: AS System Co., Ltd. · www.assystem.co.th. For data-subject requests please contact the Data Protection Officer (DPO) of your organisation.