💊

DrugBox Care

Privacy Policy · นโยบายความเป็นส่วนตัว

ปรับปรุงล่าสุด / Last updated: 18 มิถุนายน 2569 (June 18, 2026)

นโยบายความเป็นส่วนตัว (PDPA)

1. ข้อมูลที่เก็บรวบรวม

DrugBox Care เก็บรวบรวมข้อมูลต่อไปนี้เพื่อให้บริการบริหารจัดการกล่องยาในองค์กรของคุณ:

  • ชื่อ–นามสกุล และอีเมลที่ใช้สมัคร
  • รหัสผู้ใช้ (UID) ที่ Firebase Authentication สร้างให้
  • บทบาทในองค์กร (admin / pharmacist / nurse / viewer)
  • ข้อมูลกล่องยา ยา และรายการเบิก–คืน ที่คุณบันทึกในระบบ
  • รูปภาพยาที่คุณหรือองค์กรอัปโหลด (ถ่ายจากกล้องหรือเลือกจากคลังรูปภาพ) เพื่อใช้อ้างอิงประกอบยาในการ์ดติดกล่อง
  • ข้อมูลระบุตัวตนผู้ป่วย (ชื่อ–นามสกุล, HN และเลขบัตรประชาชนที่เข้ารหัส) — เก็บเฉพาะกรณีจ่ายยาเสพติด/วัตถุออกฤทธิ์ ประเภท 2 ที่กฎหมายเฉพาะ บังคับให้สถานพยาบาลบันทึกลงบัญชี บ.ย.ส.๒ (ดูข้อ 5)
  • เวลาเข้าใช้งานล่าสุด (lastActiveAt) สำหรับแสดงสถานะในองค์กร

2. วัตถุประสงค์และฐานทางกฎหมาย

วัตถุประสงค์ในการประมวลผลข้อมูลของคุณ:

  • จัดการบัญชีผู้ใช้และสิทธิ์เข้าถึงภายในองค์กร
  • บันทึกประวัติการเบิก–คืน–ทำลายยา เพื่อการตรวจสอบย้อนหลัง (audit trail)
  • แจ้งเตือนยาใกล้หมดอายุและยาหมดอายุ
  • ออกรายงานสถิติการใช้ยาให้กับ admin ขององค์กรของคุณเท่านั้น

ฐานทางกฎหมาย (PDPA มาตรา 24):

  • ความยินยอม (consent) — สำหรับการเก็บชื่อ อีเมล และข้อมูลโปรไฟล์ ตอนสมัครสมาชิก (ติ๊กในแบบฟอร์มสมัคร)
  • การปฏิบัติตามสัญญา (มาตรา 24(3)) — สำหรับการให้บริการแอพหลัง login
  • หน้าที่ตามกฎหมาย / ประโยชน์อันชอบธรรม (มาตรา 24(5)–(6)) — สำหรับการเก็บประวัติเบิก–คืนยา 5 ปี ตามระเบียบโรงพยาบาล แม้บัญชีจะถูกลบไปแล้ว เพื่อให้สามารถตรวจสอบย้อนหลังได้

3. ผลของการไม่ให้ข้อมูล

การให้ข้อมูล ชื่อ–นามสกุล และ email เป็นเงื่อนไขจำเป็นในการสมัครสมาชิก หากคุณไม่ให้ข้อมูลที่กล่าว คุณจะไม่สามารถสร้างบัญชีหรือใช้งาน DrugBox Care ได้สำหรับข้อมูลอื่นๆ (เช่น avatar, lastActiveAt) เป็นข้อมูลเสริมและคุณสามารถใช้งานได้แม้ไม่กรอก

4. การเปิดเผย แบ่งปัน และส่งข้อมูลข้ามประเทศ

ข้อมูลของคุณจะถูกเปิดเผยเฉพาะกับสมาชิกในองค์กรเดียวกันที่มีสิทธิ์ตามบทบาท (role-based access control) เท่านั้น DrugBox Care ไม่ขายและไม่แบ่งปันข้อมูลให้บุคคลที่สามเพื่อวัตถุประสงค์ทางการตลาด

การส่งข้อมูลไปต่างประเทศ (PDPA มาตรา 28): ข้อมูลถูกจัดเก็บบน Google Cloud Firestore (Firebase) region asia-southeast1 ที่สิงคโปร์ — ซึ่งเป็นการส่งข้อมูลข้ามประเทศ Google มีมาตรฐานความปลอดภัย ISO 27001, SOC 2, ISO 27017, ISO 27018 และ HIPAA-ready และใช้ Standard Contractual Clauses ที่ได้รับการรับรองจากคณะกรรมาธิการยุโรป ซึ่งถือว่าเป็นมาตรฐานคุ้มครองข้อมูลที่เพียงพอตามประกาศของ สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (PDPC) แห่งประเทศไทย

ผู้ประมวลผลข้อมูล (Data Processor): Google LLC (ผ่านบริการ Firebase / Google Cloud Platform) ทำหน้าที่เป็น sub-processor ตามสัญญา Data Processing Addendum (DPA) ของ Google

5. ข้อมูลที่อ่อนไหว / ข้อมูลสุขภาพ (มาตรา 26)

บันทึกการเบิก–จ่าย–ทำลายยาในกล่องยา/ตู้ควบคุมของหน่วยงานคุณ อาจเข้าข่ายข้อมูลสุขภาพ (sensitive personal data) ตาม PDPA มาตรา 26

โดยทั่วไปDrugBox Care ไม่เก็บข้อมูลที่ระบุตัวตนผู้ป่วยรายบุคคล — บันทึกในระบบเป็นเพียงข้อมูล “ยาไหน เบิกเมื่อไร โดยใคร”

ข้อยกเว้น — การจ่ายยาเสพติดให้โทษ/วัตถุออกฤทธิ์ ประเภท 2 (ยส.๒ / ว.จ.๒): กฎหมายเฉพาะ (ประมวลกฎหมายยาเสพติด พ.ศ. 2564 และกฎกระทรวงที่เกี่ยวข้อง) บังคับให้สถานพยาบาลบันทึกตัวตนผู้ป่วยลงบัญชีจำหน่าย (บ.ย.ส.๒/ว.จ.๒) เมื่อมีการจ่ายยากลุ่มนี้ ระบบจึงเก็บ ชื่อผู้ป่วย, HN และเลขบัตรประชาชน เพิ่มเติม โดยมีมาตรการคุ้มครองตามมาตรา 26/37 ดังนี้:

  • ฐานทางกฎหมาย: หน้าที่ตามกฎหมาย (PDPA มาตรา 24(6) / 26(5)) — ไม่ใช้ความยินยอม เพราะกฎหมายเฉพาะบังคับให้ต้องบันทึก
  • เลขบัตรประชาชนถูกเข้ารหัส (encryption) ก่อนจัดเก็บเสมอ — ไม่เก็บเป็น plaintext และถอดรหัสได้เฉพาะผ่านระบบที่ตรวจสอบสิทธิ์ (admin/เภสัชกร) เพื่อจัดทำบัญชี บ.ย.ส.๒ เท่านั้น
  • เข้าถึงได้เฉพาะ admin/เภสัชกร ในองค์กรเดียวกัน (role-based + เข้ารหัส)
  • ไม่ส่งออกสู่หน่วยงานภายนอก:รายงานประจำเดือนที่ส่งสำนักงาน อย. (ร.ย.ส.๒) สรุปเป็น “ผู้ป่วยจำนวน N คน” โดยไม่มีชื่อหรือเลขบัตรผู้ป่วย
  • ระยะเวลาการเก็บเป็นไปตามที่กฎหมายยาเสพติดกำหนด (ดูข้อ 7)

สำหรับยาทั่วไป (ที่ไม่ใช่ ยส.๒/ว.จ.๒) หากองค์กรต้องการเชื่อมโยงข้อมูลกับผู้ป่วย กรุณาทำในระบบ HIS ของโรงพยาบาลแยกต่างหาก

6. สิทธิ์ของเจ้าของข้อมูล

ภายใต้ พ.ร.บ. คุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA) คุณมีสิทธิ์ 8 ประการ:

  • เข้าถึง — ขอเข้าถึงและรับสำเนาข้อมูลของตนเอง (มาตรา 30)
  • โอนย้าย— ขอรับข้อมูลในรูปแบบที่อ่านได้ด้วยเครื่อง (machine-readable) เพื่อโอนไปยังผู้ควบคุมข้อมูลรายอื่น (มาตรา 31) — ใช้เมนู “Export My Data” (PDF) ใน Settings
  • คัดค้าน — คัดค้านการประมวลผลในบางกรณี (มาตรา 32)
  • ลบ / ทำลาย— ขอลบหรือทำให้ข้อมูลไม่สามารถระบุตัวตนได้ (right to be forgotten — มาตรา 33) — ใช้เมนู “ลบบัญชีของฉัน” ใน Settings
  • ระงับการใช้ — ขอระงับการประมวลผลชั่วคราว (มาตรา 34)
  • แก้ไข — ขอแก้ไขข้อมูลให้ถูกต้องและเป็นปัจจุบัน (มาตรา 35–36)
  • ถอนความยินยอม — ถอนความยินยอมเมื่อใดก็ได้ (มาตรา 19 วรรคห้า)
  • ร้องเรียน — ร้องเรียนต่อคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (PDPC) ที่ www.pdpc.or.th

วิธีใช้สิทธิ์: แจ้งคำขอผ่าน admin ขององค์กรของคุณ (ดูข้อ 12) คำขอจะได้รับการ ดำเนินการภายใน 30 วัน ตามที่ PDPA กำหนด

7. ระยะเวลาการเก็บข้อมูล

ข้อมูลจะถูกเก็บตราบเท่าที่บัญชีของคุณยังใช้งานอยู่ เมื่อถอนความยินยอมหรือลบบัญชี ข้อมูลส่วนบุคคลจะถูกลบภายใน 30 วัน ยกเว้นข้อมูลธุรกรรมที่เกี่ยวกับการเบิก–คืนยา ซึ่งจะเก็บไว้ไม่น้อยกว่า 5 ปี ตามระเบียบการตรวจสอบภายในของโรงพยาบาล (ฐานทางกฎหมาย: หน้าที่ตามกฎหมาย / ประโยชน์อันชอบธรรม) โดยจะถูก anonymize (ลบ userId / ชื่อผู้บันทึก) ก่อน

8. คุกกี้และการจัดเก็บข้อมูลในเครื่อง

DrugBox Care ไม่ใช้คุกกี้เพื่อการโฆษณาหรือติดตาม แต่จำเป็นต้องใช้ IndexedDB/localStorage ของเบราว์เซอร์เพื่อเก็บ session ของ Firebase Authentication (เช่น token เข้าสู่ระบบ) เท่านั้น คุณสามารถลบข้อมูลเหล่านี้ได้โดยล้าง browser data ของแอพ DrugBox Care หรือกดออกจากระบบ

9. การไม่ใช้การตัดสินใจอัตโนมัติ

DrugBox Care ไม่ใช้การตัดสินใจอัตโนมัติ (automated decision-making / profiling) ที่มีผลทางกฎหมายหรือกระทบต่อคุณอย่างมีนัยสำคัญ ตาม PDPA มาตรา 32 (3) การแจ้งเตือนต่างๆ ของระบบ (เช่น ยาใกล้หมดอายุ) เป็นเพียงการคำนวณตาม rule-based เท่านั้น

10. ผู้ใช้ที่อายุต่ำกว่า 20 ปี

DrugBox Care เป็นบริการสำหรับ บุคลากรทางการแพทย์อายุ 20 ปีขึ้นไปเท่านั้น เราไม่เก็บข้อมูลของผู้เยาว์โดยรู้เห็น หากพบว่ามีบัญชีที่อายุต่ำกว่าเกณฑ์ admin จะระงับการใช้งานทันที (PDPA มาตรา 20 ผู้เยาว์ต้องได้รับความยินยอมจากผู้ปกครอง)

11. การเปลี่ยนแปลงนโยบาย

DrugBox Care อาจปรับปรุงนโยบายฉบับนี้เป็นครั้งคราว เมื่อมีการเปลี่ยนแปลง สาระสำคัญ เราจะแจ้งให้คุณทราบผ่าน:

  • การแสดง dialog “นโยบายมีการอัพเดต” ตอน login ครั้งถัดไป
  • การ reset วันที่ Last updated และบังคับยอมรับเวอร์ชันใหม่

วันที่ปรับปรุงล่าสุดแสดงไว้ที่ด้านบนของหน้านี้ คุณควรตรวจสอบเป็นระยะ การใช้งานต่อหลังการอัพเดตถือเป็นการยอมรับนโยบายใหม่

12. ติดต่อผู้ควบคุมข้อมูล (Data Controller) และ DPO

ผู้ควบคุมข้อมูลส่วนบุคคล ของข้อมูลที่คุณกรอกลงระบบ คือ องค์กร/โรงพยาบาลที่คุณสังกัด (ไม่ใช่ผู้พัฒนาแอพ) หากต้องการใช้สิทธิ์ตามข้อ 6 กรุณาติดต่อ ผู้ดูแลระบบ (admin) ขององค์กรของคุณ โดยตรง

เจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (Data Protection Officer / DPO): ตาม PDPA มาตรา 41 องค์กรที่ประมวลผลข้อมูลสุขภาพในปริมาณมาก (เช่น โรงพยาบาล) มีหน้าที่แต่งตั้ง DPO ของตนเอง กรุณาตรวจสอบกับผู้ดูแลระบบขององค์กรคุณ เพื่อทราบช่องทางติดต่อ DPO

เมื่อเข้าสู่ระบบแล้ว คุณสามารถดูข้อมูลผู้ควบคุมข้อมูลของ องค์กรคุณได้ที่เมนู ตั้งค่า → ข้อมูลผู้ควบคุมข้อมูล ในแอพ

หากคุณเป็น admin ขององค์กรของคุณ กรุณากรอกชื่อองค์กร อีเมล เบอร์ติดต่อ ที่อยู่ และข้อมูลติดต่อ DPO ในหน้าดังกล่าวก่อนเชิญสมาชิกเข้ามาใช้งาน เพื่อให้สมาชิกสามารถใช้สิทธิ์ตาม PDPA ได้อย่างถูกต้อง

13. ติดต่อผู้พัฒนา (Data Processor)

ผู้พัฒนาแอพ DrugBox Care (adisak_kob) ทำหน้าที่เป็น ผู้ประมวลผลข้อมูล (Data Processor) ภายใต้คำสั่งของแต่ละองค์กร — ติดต่อ: [email protected]

สำหรับการใช้สิทธิ์ของคุณตาม PDPA กรุณาติดต่อ admin ขององค์กร (ข้อ 12) ก่อน — ผู้พัฒนาไม่สามารถดำเนินการให้ได้โดยตรงเพราะข้อมูลอยู่ภายใต้การควบคุมของแต่ละองค์กร


Privacy Policy (English summary)

1. Data we collect

  • Your name and email address provided at signup
  • The Firebase Authentication UID assigned to your account
  • Your role within the organization (admin / pharmacist / nurse / viewer)
  • Medicine boxes, drug records, and transaction logs you create
  • Drug reference photos you or your organization upload (captured via the camera or chosen from your photo library) to help identify medicines on box cards
  • Your last active timestamp for presence within the organization

2. Purposes & lawful basis (PDPA s.24)

We process your data to operate your organization’s medicine management, generate audit trails, send near-expiry alerts, and produce statistics available only to your organization’s admins.

Lawful basis: consent (signup data); contract performance (in-app services); legal obligation / legitimate interest (5-year drug transaction retention required by hospital audit rules).

3. Consequences of withholding data

Providing your name and email is mandatory to register. If you decline, you cannot create an account or use DrugBox Care. Optional fields (avatar, last-active timestamp) do not block usage.

4. Sharing & cross-border transfer (PDPA s.28)

Data is visible only to authorized members of your organization via role-based access. We do not sell or share data with third parties for marketing.

Data is stored on Google Cloud Firestore region asia-southeast1 (Singapore) — this constitutes cross-border transfer. Google maintains ISO 27001, SOC 2, ISO 27017/27018, and HIPAA-ready controls, and applies EU Standard Contractual Clauses, which the Thai PDPC recognizes as adequate safeguards.

Google LLC acts as a sub-processor under its standard Data Processing Addendum.

5. Sensitive / health data (PDPA s.26)

Drug-transaction records may qualify as health data under PDPA s.26. By default, DrugBox Care does not store patient identifiers; records describe only “which drug, when, by whom”.

Exception — dispensing Schedule-2 narcotics / psychotropics (ยส.๒ / ว.จ.๒): Thai law (the Narcotics Code B.E. 2564 and related ministerial regulations) requires healthcare facilities to record patient identity in the statutory dispensing ledger (บ.ย.ส.๒). For these drugs the system additionally stores the patient name, HN, and national ID, with the following safeguards (PDPA s.26/37):

  • Lawful basis: legal obligation (PDPA s.24(6)/26(5)) — not consent, because a specific law mandates the record.
  • The national ID is always encrypted before storage — never stored as plaintext, and decryptable only through an access-controlled service (admin/pharmacist) solely to produce the บ.ย.ส.๒ ledger.
  • Accessible only to admins/pharmacists within the same organization.
  • Not disclosed externally:the monthly report filed with the Thai FDA (ร.ย.ส.๒) is aggregated as “N patients” with no names or national IDs.
  • Retention follows the periods set by narcotics law (see s.7).

For non-controlled drugs, any patient linkage must happen separately in your hospital’s HIS.

6. Your rights (Thailand PDPA)

PDPA grants you 8 rights:

  • Access — receive a copy of your data (s.30)
  • Portability— machine-readable export (s.31) — use “Export My Data” in Settings
  • Object — object to certain processing (s.32)
  • Erase— right to be forgotten (s.33) — use “Delete My Account” in Settings
  • Restrict — temporary suspension of processing (s.34)
  • Rectify — correct inaccurate data (s.35–36)
  • Withdraw consent — at any time (s.19 ¶5)
  • Lodge complaint — with the PDPC at www.pdpc.or.th

Requests are handled within 30 days. Contact your organization’s admin (see s.12 below).

7. Retention

Personal data is retained while your account is active and deleted within 30 days of account closure. Drug transaction records are retained for at least 5 years to satisfy hospital audit requirements (anonymized after personal data deletion).

8. Cookies & local storage

DrugBox Care uses no advertising or tracking cookies. The browser’s IndexedDB / localStorage is used only to persist your Firebase Authentication session. Clear it via browser settings or by signing out.

9. No automated decision-making

DrugBox Care performs no automated decision-making or profiling with legal or significant effects (PDPA s.32(3)). System alerts (e.g. expiry warnings) are deterministic rule-based calculations.

10. Users under 20

DrugBox Care is intended for medical professionals aged 20 or older. We do not knowingly collect data from minors. Detected sub-20 accounts are suspended (PDPA s.20 — minors require parental consent).

11. Policy changes

Material changes will be notified via an “Updated policy” dialog at the next sign-in and a refreshed “Last updated” date at the top of this page. Continued use after the update constitutes acceptance.

12. Contact (Data Controller & DPO)

The data controller for the personal information you enter is the organization / hospital you belong to, not the app developer. Contact your organization’s admin directly to exercise your rights.

Data Protection Officer (PDPA s.41): organizations processing health data at scale (e.g. hospitals) must appoint their own DPO. Ask your admin for DPO contact details.

After signing in, your organization’s data controller contact details are visible in Settings → Data Controller Info inside the app.

If you are an admin, please fill in your organization name, email, phone, address, and DPO contact on that page before inviting members, so members can exercise their PDPA rights properly.

13. Developer contact (Data Processor)

The DrugBox Care app developer (adisak_kob) acts as a data processor on behalf of each organization — contact: [email protected]

For PDPA rights requests, please contact your organization’s admin (s.12) first. The developer cannot act on your behalf because data is under each organization’s control.