MrKumka.com is now Kumka | Still on the same mission to help you find insurance that's worth it.​

Privacy Policy from Kumka.com

Kumka.com is here to help you find the best deals for your insurance and other financial services

Collection of Personal Data

Kumka Broker Co., Ltd. ("we", "us", or "our") places great importance on the protection of the personal data of our customers, business partners, business contacts, and other related individuals. We are committed to collecting, using, and disclosing personal data in a transparent, fair, and lawful manner, in compliance with applicable personal data protection laws.

This Privacy Policy has been prepared to inform you of the details regarding the collection, use, disclosure and/or processing of your personal data, as well as your rights in relation to such personal data and the measures we employ to ensure its security and protection. We will collect only such personal data as is necessary for the conduct of our business operations, the provision of services, the performance of contractual obligations, compliance with legal requirements, and other legitimate purposes. All personal data will be processed in accordance with the principles and requirements set out in this Privacy Policy.

What We Collect

The personal data we collect from you (the “Data Provider”) depends on the nature of your relationship with us at the time of collection, such as prospective customer and broker, insured person and broker, service provider and service recipient, or business partner, as well as any specific requests made. The information collected, whether in the form of text, documents, images, or videos, may include the following categories of personal data depending on your relationship with us:

  • 1. Personal data collected from prospective service users (“Prospects”) may include:

    • General Personal Data
      • Personal Identification Data: Full name, age, date of birth, gender, marital status
      • Contact Information: Address, phone number, email, Line ID, etc.
      • Insurance Transaction Data: Insurance purchase history, claims history, etc.
      • Electronic Device Data: IP address, MAC address, cookie ID, device serial number
    • Sensitive Personal Data

      Race, religion, disability history, health history, medical history, injury/accident history, medication history

  • 2. Personal data collected from customers and persons related under insurance policies and/or other service agreements, including policyholders, beneficiaries, and/or relevant third parties (“Customers and Related Persons”) may include:

    • General Personal Data
      • Personal identification information: full name, age, date of birth, gender, marital status, national identification number, passport number, driving licence number, nationality, taxpayer identification number, alien registration number, work permit number, job title, civil servant number, signature, photograph, etc.
      • Contact information: residential address, work address, telephone number, email address, Line ID, etc.
      • Financial information: bank account number and account name, credit/debit card number, income, financial history, loan information, investment information, bankruptcy information, foreign tax compliance information, etc.
      • Insurance transaction information: insurance purchase history, claims history, insured property details, history of insurance application refusals, policy number, etc.
      • Electronic device information: IP address, MAC address, cookie identifiers, device serial number.
      • Other information: audio recordings, images, videos, and other information collected and used for insurance underwriting, other insurance-related activities, medical expense receipts, vehicle registration details, chassis number, engine number, location of insured property, land title deeds, vehicle registration copies, application reference numbers, etc.
    • Sensitive Personal Data

      Race, religion, disability history, health records, medical history, injury and accident records, medication history, medical certificates, medical examination results, fingerprints, criminal records, information relating to money laundering or the financing of terrorism and the proliferation of weapons of mass destruction, etc.

  • 3. Personal data collected from business partners, insurance companies, payment service providers, financial service providers, and other service providers under any type of agreement (“Business Partners”) may include:

    • General Personal Data
      • Personal identification information: full name, age, date of birth, gender, marital status, national identification number, passport number, driving licence number, nationality, taxpayer identification number, work permit number, job title, signature, photograph, insurance broker licence, etc.
      • Contact information: address, work address, telephone number, email address, Line ID, etc.
      • Financial information: bank account number and account name, financial history, bankruptcy information, credit score, etc.
      • Other information: other personal data necessary for processing in order to fulfil contractual obligations, such as sales records, training records, etc.
    • Sensitive Personal Data

      Religion, disability history, health records, medical history, injury and accident records, medication history, medical certificates, medical examination results, criminal records, history of money laundering, history relating to the financing of terrorism and the proliferation of weapons of mass destruction, etc.

How We Collect Personal Data

Your personal data may be collected and stored either directly or indirectly when: (a) you access our website; (b) you disclose information to us; (c) any person related to you or appointed by you (including, but not limited to, your spouse, family members, or any other person for the purpose of verifying information provided in an application for products) discloses information to us; and (d) relevant third parties (including, but not limited to, our business partners, regulatory authorities overseeing our business partners, such as the Office of Insurance Commission (OIC), the Revenue Department, the Anti-Money Laundering Office (AMLO), or other reliable sources such as the Thai General Insurance Association) disclose information to us.

In the circumstances described in paragraph (c), where information relating to another individual who is not the Data Provider (the “Data Subject”) is disclosed to us, the Data Provider shall be solely responsible for obtaining any necessary consent from the Data Subject and informing the Data Subject of the disclosure of their personal data, including the terms and conditions of this Privacy Policy.

Reasons for Collecting Data, How We Use It, and Data Security

  1. 1. As a Prospect, we are required to collect, use, and disclose your personal data for the following purposes:

    1. 1.1 To provide services and offer products to you, including the performance of any related contract (Contractual Necessity Basis), as follows:

      • a) To contact you in order to offer insurance products and related services.
    2. 1.2 To pursue the legitimate interests of the Company, an individual, or another legal entity, provided that such interests are balanced against your reasonable expectations and do not override your fundamental rights and freedoms (Legitimate Interests Basis):

      • a) To assess and recommend suitable products or services to prospective customers who may be interested in our services.
      • b) To maintain our relationship with you, including communications and customer satisfaction surveys.
      • c) To offer promotions, privileges, advertisements, and/or cross-selling or up-selling opportunities (where permitted by law), and/or to conduct surveys for the purpose of improving products or services (marketing purposes).
      • d) To collect and analyse information for statistical analysis or research, product and service development, insurance premium calculations aligned with risk profiles, and fraud detection.
      • e) To comply with audit and regulatory compliance requirements.
      • f) To disclose information within our corporate group, to agents, contractors, insurance companies, or external service providers providing administrative, telecommunications, financial, payment, data processing, or other business-related services.
      • g) To prevent, respond to, and mitigate risks arising from fraud, cyber threats, or legal violations.
      • h) To record communications, audio, or visual materials during meetings, seminars, or exhibition booth activities.
      • i) For website administration and business operations.
      • j) To provide services requested by you.
      • k) To carry out any activities related to the purposes set out in this Policy.
  2. 2. As a Customer or Related Person, we are required to collect, use, and disclose your personal data for the following purposes:

    1. 2.1. To provide insurance-related products and services to you, including the performance of any related contract (Contractual Necessity Basis), as follows:

      • a) To communicate with you regarding insurance products or services.
      • b) To fulfil rights and obligations under an insurance contract.
      • c) To undertake legal proceedings in cases involving liability to third parties or the exercise of subrogation rights.
    2. 2.2. To comply with applicable laws and regulations (Legal Obligation Basis), including compliance with the requirements of competent authorities such as the Office of Insurance Commission (OIC), non-life insurance laws and related regulations, the Revenue Department, tax laws, orders of the Anti-Money Laundering Office (AMLO), anti-money laundering legislation, laws concerning counter-terrorism and the proliferation of weapons of mass destruction, financial legislation, the Computer Crime Act, bankruptcy legislation, and any other laws or regulations applicable to the Company's operations, including court orders.

    3. 2.3 To pursue the legitimate interests of the Company, an individual, or another legal entity, provided that such interests are balanced against your reasonable expectations and do not override your fundamental rights and freedoms (Legitimate Interests Basis):

      • a) To assess and recommend suitable products or services to customers who may be interested in our services.
      • b) To maintain our relationship with you, including communications, complaint handling, and customer satisfaction surveys.
      • c) To notify you of policy renewals and/or offer products, services, or promotions related to your existing products for your benefit.
      • d) To offer promotions, privileges, advertisements, and/or cross-selling or up-selling opportunities (where permitted by law), and/or to conduct surveys for product or service development (marketing purposes).
      • e) To collect and analyse information for statistical analysis or research, product and service development, insurance premium calculations aligned with risk profiles, and fraud detection.
      • f) To comply with audit and regulatory compliance requirements.
      • g) To disclose information within our corporate group, to agents, contractors, insurance companies, or external service providers providing administrative, telecommunications, financial, payment, data processing, or other business-related services.
      • h) To prevent, respond to, and mitigate risks arising from fraud, cyber threats, or legal violations.
      • i) To record communications, audio, or visual materials during meetings, seminars, or exhibition booth activities.
      • j) For website administration and business operations.
      • k) To provide services requested by you.
      • l) To carry out any activities related to the purposes set out in this Policy.
    4. 2.4 To carry out activities necessary for reasons of substantial public interest, including:

      • a) Producing statistics relating to insurance premiums based on risk levels and conducting insurance fraud prevention and detection activities.
      • b) Exercising rights or fulfilling obligations under certain insurance contracts involving sensitive personal data, such as health or accident insurance.
      • c) Providing necessary information to the Thai Insurance Brokers Association (TIBA), the Thai General Insurance Association (TGIA), the Non-Life Insurance Fund (RVP), or other relevant organisations or associations.
      • d) Carrying out any activities related to the purposes set out in this Policy.
  3. 3. As a Business Partner of the Company, we are required to collect, use, and disclose your personal data for the following purposes:

    1. 3.1 To fulfil obligations under agreements or contracts between the Company and its business partners.
    2. 3.2 To undertake financial transactions in accordance with agreements between the Company and its business partners.
    3. 3.3 To receive or provide advice or services as agreed between the Company and its business partners.
    4. 3.4 To comply with applicable laws and regulations (Legal Obligation Basis).
    5. 3.5 To verify your identity and authority before entering into contracts.
    6. 3.6 To develop and improve services as agreed by the contracting parties.
    7. 3.7 To comply with audit and regulatory compliance requirements.
    8. 3.8 To conduct legal proceedings.
    9. 3.9 To maintain relationships with business partners, including communications, satisfaction surveys, and recognition or reward programmes.
    10. 3.10 To provide requested services.
    11. 3.11 To carry out any activities related to the purposes set out in this Policy.

Data Security

To ensure the security of your personal data, we implement the following measures: (a) We use encryption and tokenisation technologies to protect sensitive information, such as credit card details, which can only be accessed by authorised persons. (b) Access to your personal data is restricted to employees who have a legitimate business need to access such information. (c) We prevent unauthorised access through regular technology updates and security enhancements. (d) We delete your personal data when it is no longer required for the purposes described above.

Retention Period

We will retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected and used, unless a longer retention period is required or permitted by applicable law. As a general rule, the Company will retain your personal data for a period of ten (10) years from the date on which the legal relationship between you and the Company comes to an end, unless a longer retention period is required by law. Upon expiry of the applicable retention period, the Company will securely delete, destroy, or anonymise your personal data using appropriate security measures.

Third-Party Access

For us to perform our contractual obligations to you, pursue our legitimate business interests, or comply with our legal obligations to regulatory authorities and government agencies, we may disclose and/or transfer your personal data to third parties solely for the relevant purposes described herein. Such third parties may include:

  1. 1. Government authorities and regulatory bodies, such as the Office of Insurance Commission (OIC), the Anti-Money Laundering Office (AMLO), the Revenue Department, and other relevant authorities, where required to comply with applicable laws and regulations.
  2. 2. Insurance industry associations, such as the Thai General Insurance Association and the Thai Insurance Brokers Association.
  3. 3. Business partners and service providers engaged by us in connection with the provision of services, including insurance companies, actuaries, claims assessors, third-party administrators (TPAs), the General Insurance Fund (GIF), hospitals, legal advisers, auditors, postal service providers, banks and other financial institutions, payment service providers, and any other service providers involved in the administration of insurance policies, business operations, or legal proceedings, as necessary. This may also include inspectors, consultants, data survey and analytics providers, and investors.
  4. 4. Our group of companies, including Roojai Service Co., Ltd., Ignite Service Co., Ltd., Roojai Insurance Co., Ltd., Roojai Care Co., Ltd., and Roojai Co., Ltd.
  5. 5. Third parties acting on your behalf in transactions with us, or where your personal data forms part of a transaction with us, such as policyholders under a group insurance policy.
  6. 6. Third parties connected with you and related to the terms, conditions, or benefits of an insurance policy, such as hire purchase providers, lenders, lessors and lessees, beneficiaries, joint insured persons, and other related parties.

We will not disclose and/or transfer your personal data to any other person or organisation other than those described above, unless we have obtained your consent or where disclosure is permitted or required by law, including where: (a) disclosure is required under applicable law; (b) disclosure is necessary to prevent an emergency or protect any person from harm; or (c) disclosure is required in the public interest.

Where we disclose or transfer your personal data to third parties, we will inform such parties of the confidential nature of the information and their obligation to limit its use to authorised persons strictly on a need-to-know basis and only for the permitted purposes. We will also require them to handle and protect such personal data appropriately in accordance with this Privacy Policy and the Personal Data Protection Act B.E. 2562 (2019) and any other applicable data protection laws.

International Data Transfers

In order to provide services to you, particularly for the storage of data and documents, your personal data may be stored in countries outside Thailand. The standards of data protection and privacy in such countries may differ from those required under the Personal Data Protection Act of Thailand or our own standards. Nevertheless, we will implement appropriate safeguards and necessary measures to ensure that your personal data is stored securely and handled appropriately.

Your Rights as a Data Subject

Under the Personal Data Protection Act (PDPA), when you use our website, receive services from us, and/or purchase our products, you are entitled to the following rights in relation to your personal data that we hold:

  • Right to Withdraw Consent

    You have the right to withdraw any consent you have previously given to us for the collection, storage, use, or processing of your personal data, including consent for our third-party service providers to process your personal data on our behalf.

  • Right of Access

    You have the right to obtain confirmation as to whether we hold personal data concerning you. Where we do, you have the right to request information regarding the location at which your data is stored, the methods by which it is processed, the purposes for which it is used, and to obtain an electronic copy of your personal data.

  • Right to Object to Processing

    You may object at any time to the collection, use, and/or disclosure of your personal data where such processing is carried out in the public interest, on the basis of legitimate interests that exceed your reasonable expectations, or on any other legal basis permitted by law. We will continue such

    processing only where we can demonstrate compelling legitimate grounds that override your fundamental rights and freedoms, or where processing is necessary for the establishment, exercise, or defence of legal claims, compliance with legal obligations, or the conduct of legal proceedings, as applicable.

  • Right to Rectification

    If you believe that any personal data we hold about you is inaccurate, incomplete, or out of date, you have the right to request that such information be corrected, completed, or updated.

  • Right to Data Portability

    Where your personal data is processed by automated means, you have the right to request that such data be transferred to another data controller.

  • Right to Restriction of Processing or Erasure

    You have the right to request that we suspend, restrict, or limit the use or processing of your personal data, or permanently erase your personal data.

Please note that the withdrawal of consent, restriction, suspension, or deletion of your personal data may affect our ability to provide services and/or products to you in full.

Contacting Us About Your Personal Data

If you have any questions, comments, or suggestions regarding this Privacy Policy, or if you wish to exercise your data protection rights, please complete a Data Subject Request Form and submit it to:

Address: Kumka Broker Co., Ltd. 4/222 Harbor Mall Building, 11th Floor Unit 11A01, Moo 10,Sukhumvit Road, Sriracha, Chonburi 20230

Email: KumkaDPO@Kumka.com

The process may take up to 30 days from the date on which your request is received.

You may click here to download the Data Subject Request Form.

Cookies

  • What Are Cookies?

    Cookies are small data files sent from a website and stored on your device. Cookies enable a website to recognise your device and collect information in order to improve website content and tailor it to your preferences. We use cookies through third-party service providers to enhance your browsing experience.

    What Cookies Do We Use?

    Analytics Cookies

    These cookies monitor your usage behaviour in order to understand how often you use particular features or other functions on our website. The retention period for these cookies is between one and two consecutive years.

    Managing Cookies

    You can manage, block, or delete cookies through your web browser settings. Further information about cookies, including how to manage them, can be found at the Allaboutcookies

  • External Links

    This website may contain links to third-party websites. As we do not control such websites, we cannot guarantee their privacy or security practices. Accordingly, we do not warrant that any third-party website will provide a level of protection for your personal data equivalent to that set out in this Privacy Policy.

  • Changes to This Privacy Policy

    We reserve the right to amend this Privacy Policy from time to time in order to ensure compliance with applicable laws and regulations. We therefore recommend that you review the “Last Updated” date of this Privacy Policy periodically.

*Last Updated: 1st September 2026