This Personal Data Protection Policy describes how personal data arising in the course of the operations and business activities of Vinpearl Joint Stock Company (hereinafter referred to as the “Company”), having its address at Hon Tre Island, Vinh Nguyen Ward, Nha Trang City, Khanh Hoa Province, Vietnam, and its official website at https://vinpearl.com, is collected, used and processed.
1. GENERAL PROVISIONS
1.1. Personal Data: Means information in the form of symbols, writing, digits, images, sounds or similar forms in the electronic environment that is associated with a specific person or helps identify a specific person. Personal Data includes Basic Personal Data and Sensitive Personal Data.
1.2. Data Subject: Means the individual to whom the Personal Data relates, including all individual customers currently using the Company’s products and services, the Company’s employees, shareholders and/or other individuals having a legal relationship with the Company.
1.3. Processing Personal Data: Means one or more activities performed on Personal Data, such as: collection, recording, analysis, confirmation, storage, modification, disclosure, combination, access, retrieval, recovery, encryption, decryption, copying, sharing, transmission, provision, transfer, deletion, destruction of Personal Data or other related actions.
1.4. When Personal Data of a person related to the Data Subject (including but not limited to information of dependents, related persons as prescribed by law, spouses, children and/or parents and/or guardians, friends, beneficiaries, authorized persons, partners, emergency contacts or other individuals related to the Data Subject) is provided to the Company, the Data Subject and the person related to the Data Subject represent, warrant and assume responsibility that the information has been provided in full and that the Data Subject has lawfully consented/approved to its processing for the purposes specified in this Policy. The Data Subject and the person related to the Data Subject agree that the Company is not responsible for verifying the lawfulness or validity of such consent/approval and that the responsibility for retaining evidence thereof rests with the person related to the Data Subject and the Data Subject. The Company shall be exempt from liability and entitled to claim compensation for related damages and expenses when the Data Subject and/or the person related to the Data Subject fails to comply with the provisions herein.
1.5. By registering for or using the Company’s products and services, entering into a contract and/or allowing the Company to Process Personal Data, the Data Subject accepts in full and without any conditions the policies set out herein and any amendments thereto from time to time.
1.6. This Policy may be updated, amended, supplemented or replaced by the Company from time to time and posted on the Company’s official website. You should regularly access and check our website to stay updated on the latest changes.
1.7. The Company undertakes to comply with the following principles when Processing Personal Data:
(i) The Company processes and protects Personal Data in accordance with the laws of Vietnam; and fully complies with the contracts, agreements and other documents established with the Data Subject;
(ii) The Company collects Personal Data for specific, explicit and lawful purposes, within the scope of the purposes specified in Section 3 of this Policy and in accordance with the laws of Vietnam;
(iii) The Company consistently applies and updates appropriate technical measures in accordance with the laws of Vietnam to ensure the security of Personal Data, including measures to protect it from unauthorized access and/or destruction, loss or damage;
(iv) The Company stores Personal Data appropriately and only to the extent necessary for processing in accordance with the laws of Vietnam;
(v) The Company undertakes to comply with regulations concerning the protection of children’s data.
2. PERSONAL DATA PROCESSED
In order for the Company to Process Personal Data for the purposes specified in Section 3 of this Policy, the Company may process the following types of Personal Data:
2.1. Basic Personal Data includes:
(i) Family name, middle name and given name at birth, and other names (if any);
(ii) Date of birth; date of death or disappearance;
(iii) Gender;
(iv) Place of birth, place of birth registration, permanent residence, temporary residence, current residence, place of origin and contact address;
(v) Nationality;
(vi) Images of the individual; information obtained from security systems, including recordings of images of the Data Subject captured by camera and surveillance systems at the Company’s business/transaction locations;
(vii) Telephone number, identity card number, citizen identity card number, personal identification number, passport number, driver’s license number, vehicle registration plate number, personal tax identification number, social insurance number and health insurance card number;
(viii) Occupation and workplace;
(ix) Marital status;
(x) Information about family relationships (parents and children);
(xi) Information about the individual’s digital accounts; Personal Data reflecting preferences and activity history in cyberspace;
(xii) Other information associated with a specific person or helping to identify a specific person that does not fall within the scope of Sensitive Personal Data specified in Section 2.2 below.
2.2. Sensitive Personal Data includes the following principal data:
(i) Political opinions and religious beliefs;
(ii) Health status and private life recorded in medical records, excluding information about blood type;
(iii) Information relating to racial or ethnic origin;
(iv) Information about an individual’s inherited or acquired genetic characteristics;
(v) Information about an individual’s physical attributes and unique biological characteristics;
(vi) Data on crimes and criminal acts collected and stored by law enforcement authorities;
(vii) Information about the Data Subject’s bank accounts;
(viii) Customer location data determined through location services;
(ix) Other Personal Data specified by law as specific and requiring necessary security measures.
3. PURPOSES OF PROCESSING PERSONAL DATA
Personal Data may be processed for one or more of the following purposes:
3.1. Assessing the ability to provide products or services and/or enter into a contract with the Data Subject, including but not limited to the following purposes:
(i) Identifying and verifying information about the Data Subject;
(ii) Assessing, appraising and approving the provision of products and services based on registration documents, application forms and contracts of the Data Subject and/or the person related to the Data Subject;
(iii) Considering whether to provide or continue providing any of the Company’s products or services to the Data Subject;
3.2. Performing obligations under contracts, agreements, terms, conditions and other documents between the Company and the Data Subject, and providing customer support, including but not limited to the following purposes:
(i) Performing obligations under contracts and agreements and providing products and services to the Data Subject;
(ii) Updating and processing the Data Subject’s information;
(iii) Providing customer care and resolving complaints and legal claims of the Data Subject;
(iv) Using and transferring Personal Data and related information to partners to identify and remedy problems with products and services and to repair products;
(v) Contacting and notifying the Data Subject;
(vi) Conducting promotional programs, gift redemption, prize awarding, gift delivery, marketing and advertising;
(vii) Conducting other customer care and support activities.
3.3. Improving the quality of the Company’s products and services, including but not limited to:
(i) Providing information requested by customers or considered useful to customers by the Company;
(ii) Improving technology and the interfaces of websites, social networks and applications to ensure convenience for customers;
(iii) Managing customer accounts and loyalty programs implemented by Vingroup and its member companies;
(iv) Conducting statistical analysis and data analysis to research, create, develop and improve products and services and enhance the customer experience;
(v) Developing and providing new products and services personalized to customers’ needs and actual circumstances;
(vi) Introducing and providing promotions and incentives for the Company’s products and services and for products and services offered by the Company in cooperation with partners;
(vii) Recommending products and services that customers may be interested in by identifying their preferences.
3.4. Serving the Company’s business and operational activities, including but not limited to fulfilling reporting, financial, accounting and tax obligations; conducting auditing and compliance activities; and carrying out other activities serving the Company’s lawful business in cases deemed necessary by the Company.
3.5. Restructuring and transfer of projects/enterprises:
In the course of its business, the Company may sell or acquire enterprises, restructure an enterprise, or transfer projects or other services in accordance with the law. Accordingly, Personal Data and rights to use information in general are among the assets transferred. In all cases, the transfer and processing of data shall be carried out by the parties in accordance with the law and this Policy.
3.6. Marketing: Developing marketing campaigns and promoting products and services, including developing campaigns based on customer preferences;
3.7. Preventing, combating, investigating and detecting crimes.
3.8. Protecting social order and safety and the lawful rights and interests of the Data Subject, the Company and other related parties.
3.9. Complying with the law and international treaties to which Vietnam is a party, including but not limited to:
(i) Providing information to competent state authorities in accordance with the law;
(ii) Fulfilling obligations under the law and international treaties with which the Company is required to comply (if any).
3.10. Other purposes with the consent of the Data Subject.
4. METHODS OF PROCESSING PERSONAL DATA
4.1. Collection methods
Personal Data is collected as follows:
(i) From the Company’s websites and applications: Personal Data is collected when the Data Subject completes forms made available on the Company’s websites and applications.
(ii) From the provision of products and services and the performance of the Company’s obligations under contracts and agreements: Personal Data is collected when the Data Subject purchases, registers to use or uses any products or services, or enters into a contract with the Company.
(iii) From exchanges and communications with the Data Subject: Personal Data is collected through interactions between the Company and the Data Subject (in person, by mail, by telephone, online, through a call center system, by electronic communication or by any other means), including surveys;
(iv) From social networks: The Company’s social networks and/or social networks on which the Company cooperates with partners;
(v) From audio and video recording devices: Devices installed at stores, business locations or places where part or all of the Company’s business activities are carried out and where the Data Subject meets, appears or interacts with the Company;
(vi) From interactions or automated data collection technologies: The Company may collect information automatically recorded from connections through:
· Cookies, pixel tags and other similar technologies;
· Any technology capable of tracking an individual’s activities on devices or websites;
· Other data information provided by a device.
(vii) Other means
The Company may collect Personal Data from public and official sources of information or by receiving necessary data shared by its parent company, subsidiaries, affiliates or partners during their cooperation with the Company in accordance with the law.
4.2. Storage methods
Personal Data is stored in Vietnam in the Company’s database systems or at any location where we or our branches, subsidiaries, affiliates, partners or service providers have facilities.
The retention period for Personal Data is determined based on the purposes of use specified in this Policy and in accordance with the law.
4.3. Methods of data transfer/sharing
The Company will not sell Personal Data to any party. The Company uses necessary security measures to ensure the secure transfer/sharing of Personal Data. The Company shares Personal Data with (i) its parent company, subsidiaries and affiliates; (ii) individuals/organizations participating in the Processing of Personal Data specified in this Policy; or (iii) competent state authorities or in other cases in accordance with the law.
If the recipient of Personal Data is headquartered outside the territory of Vietnam, when providing/transferring Personal Data abroad (including but not limited to using cyberspace, devices, electronic means or other forms to transfer Personal Data outside the territory of Vietnam), the Company will require the recipient to ensure the safety and confidentiality of the Personal Data provided/transferred. The Company undertakes to fully comply with the regulations and compliance requirements of Vietnamese law to protect the security of Personal Data.
4.4. Analysis methods
Personal Data is analyzed in accordance with the Company’s internal procedures, data confidentiality principles and information security requirements applicable to information technology systems.
4.5. Encryption methods
Where necessary, collected Personal Data is encrypted in accordance with appropriate encryption standards during data storage, transfer and processing to ensure that the data remains protected.
4.6. Data deletion methods
In accordance with the law or upon a valid request from the Data Subject, the Company will delete stored Personal Data, except in the following cases:
(i) The law does not permit data deletion or requires mandatory data retention;
(ii) Personal Data is processed by competent state authorities for the purpose of serving the operations of state authorities in accordance with the law;
(iii) Personal Data has been publicly disclosed in accordance with the law;
(iv) Personal Data is processed to serve legal requirements, scientific research or statistical purposes in accordance with the law;
(v) In the event of an emergency involving national defense, national security, social order and safety, a major disaster or a dangerous epidemic; where there is a threat to national security or defense that does not warrant the declaration of a state of emergency; or for the prevention and combating of riots, terrorism, crime and violations of law;
(vi) Responding to an emergency that threatens the life, health or safety of the Data Subject or another individual.
Throughout the Processing of Personal Data, confidentiality is the Company’s highest priority. The Company implements appropriate technical measures to prevent unauthorized access to and use of Personal Data. We also regularly cooperate with security experts to stay updated on the latest cybersecurity techniques to ensure the security of Personal Data. Data relating to your payment cards issued by financial institutions is protected by the Company on the principle that critical payment card data (card number, cardholder’s name and CVV) is not recorded on our systems. Your payment transactions are conducted through the systems of the relevant banks.
5. PROCESSING CHILDREN’S PERSONAL DATA
5.1. The Company shall Process children’s Personal Data in accordance with the principles of protecting children’s rights and best interests and in accordance with the law.
5.2. The Company shall only Process children’s Personal Data and provide products and services to children if their parents or guardians consent to the children using the Company’s products and services, consent to the Company Processing the children’s Personal Data, agree to this Policy and comply with relevant legal requirements. Where a child aged seven or older uses the Company’s products or services, in addition to the requirements specified herein, the Company shall only Process the child’s Personal Data with the child’s consent. The parent or guardian is responsible for obtaining the child’s consent before providing the child’s Personal Data to the Company.
6. POSSIBLE UNINTENDED CONSEQUENCES AND DAMAGE
6.1. The Company uses various information security technologies, such as firewall systems, access control measures and encryption, to protect Personal Data and prevent its unauthorized access, use or sharing. However, the Company cannot guarantee the absolute security of Personal Data in certain cases, such as:
(i) Hardware or software errors during data processing resulting in the loss of the Data Subject’s data;
(ii) Security vulnerabilities beyond the Company’s control or hacker attacks on the system resulting in the disclosure or leakage of data.
6.2. The Company recommends that the Data Subject keep information relating to account login passwords and OTP codes confidential and not share such information with any other person.
6.3. The Data Subject should be aware that whenever the Data Subject discloses and makes their Personal Data public, such data may be collected and used by others for purposes beyond the control of the Data Subject and the Company.
6.4. The Company recommends that the Data Subject safeguard personal devices (mobile phones, tablets, personal computers, etc.) during use. The Data Subject should log out of their account when it is not in use.
6.5. If a data storage server is attacked, resulting in the loss, disclosure or leakage of Personal Data, the Company shall be responsible for notifying the competent authorities so that the incident may be promptly investigated and handled, and for notifying the Data Subject in accordance with the law.
6.6. Cyberspace is not a secure environment, and the Company cannot guarantee that Personal Data shared through cyberspace will always remain confidential. When transmitting Personal Data through cyberspace, the Data Subject should only use secure systems to access websites, applications or devices. The Data Subject is responsible for keeping their access credentials for each website, application or device secure and confidential.
7. COMMENCEMENT AND TERMINATION OF PERSONAL DATA PROCESSING
7.1. Personal Data is processed from the time the Company lawfully receives the Personal Data and has an appropriate legal basis for processing it in accordance with the law.
7.2. Personal Data shall be processed until the purposes of data processing have been fulfilled.
7.3. The Company may be required to retain Personal Data even after the contract between the parties has terminated in order to fulfill obligations under the law and/or requests of competent state authorities.
8. ORGANIZATIONS AND INDIVIDUALS PARTICIPATING IN THE PROCESSING OF PERSONAL DATA
8.1. Depending on the circumstances, the Company may act as a personal data controller or as both a personal data controller and processor.
8.2. To the extent permitted by law, the Data Subject understands that the Company may share Personal Data for the purposes specified in this Policy with the following organizations and individuals:
(i) The Company’s parent company, subsidiaries and affiliates;
(ii) Organizations and individuals providing services to and/or cooperating with the Company, including but not limited to agents, auditors, lawyers, business cooperation partners, and providers of information technology solutions, software, applications, operational services, management services, troubleshooting services and infrastructure development services;
(iii) Any individual or organization acting as the representative or authorized person of the Data Subject or acting on behalf of the Data Subject;
Data shall be shared in accordance with the procedures, methods and applicable laws. Recipients of Personal Data are obligated to maintain the confidentiality of Personal Data in accordance with this Policy, the Company’s internal regulations and standards on Personal Data protection, and applicable laws.
8.3. The Company may be required to share Personal Data with competent state authorities in accordance with the law.
9. RIGHTS OF THE DATA SUBJECT
9.1. The right to be informed about the Processing of their Personal Data, unless otherwise provided by law.
9.2. The right to consent or refuse to consent to the Processing of their Personal Data, unless otherwise provided by law.
9.3. The right to access and view, modify or request modification of their Personal Data, unless otherwise provided by law.
9.4. The right to withdraw consent.
9.5. The right to data deletion.
9.6. The right to restrict the Processing of their Personal Data in accordance with the law.
9.7. The right to request the provision of their Personal Data, unless otherwise provided by law.
9.8. The right to object to data processing.
9.9. The right to lodge complaints, make denunciations and initiate legal proceedings.
9.10. The right to claim compensation for damage.
9.11. The right to self-protection.
The Data Subject may exercise these rights by submitting a request to the Company. The request form must be sent to the Company and contain basic information such as information about the requester; detailed contents of the request [for example, the type of data to be provided or deleted, and the name of the document or record (if any)]; the reason and purpose for making the request; and relevant information depending on the specific nature of the request (for example, whether the requested documents should be provided in electronic or paper form, the address for receipt of documents, etc.). All costs (if any) arising from the fulfillment of the requests specified herein, including but not limited to printing, photocopying, postage and express delivery charges for sending the data, shall be borne by the requester and must be paid no later than upon receipt of the data or by a deadline specified by the Company.
The Company shall process the Data Subject’s requests in accordance with the law and with due consideration for the legitimate interests of the Data Subject. However, where the Data Subject withdraws their consent, requests data deletion and/or exercises other related rights with respect to any or all Personal Data in a manner that affects the Company’s ability to provide or maintain products or services for the Data Subject or to maintain the contractual relationship, the Company may, depending on the nature of the Data Subject’s request, consider and decide not to continue providing its products or services to the Data Subject or to terminate the contractual relationship between the Company and the Data Subject. Actions taken by the Data Subject under this provision shall be deemed a unilateral termination by the Data Subject of any relationship between the Data Subject and the Company and may result in a breach of obligations or contractual commitments between the Data Subject and the Company; the Company reserves its lawful rights and remedies in such cases. Accordingly, the Company shall not be liable to the Data Subject for any resulting loss, and the Company’s lawful rights shall be fully reserved. Using reasonable efforts, the Company shall fulfill lawful and valid requests from the Data Subject within the period prescribed by law. However, for security purposes, the Company may require the Data Subject to verify their identity before processing the Data Subject’s request.
The Company has the right to refuse to fulfill requests from the Data Subject in certain cases, including but not limited to where: (i) the Data Subject fails to follow the procedures instructed by the Company, including where the request lacks information or is invalid; (ii) the Data Subject fails to provide, or inadequately provides, documents and materials required for identity verification; (iii) the Company determines that there are indications of fraud or a violation of Personal Data protection; or (iv) the law does not permit the Data Subject’s request to be fulfilled.
10. OBLIGATIONS OF THE DATA SUBJECT
10.1. Protect their own Personal Data; request other relevant organizations and individuals to protect their Personal Data; and promptly notify the Company upon discovering any error, mistake or leakage of Personal Data or suspecting that Personal Data is being compromised.
10.2. Respect and protect the Personal Data of others.
10.3. Provide complete and accurate Personal Data when consenting to the Processing of Personal Data. If any information is inaccurate, the Data Subject shall bear, at their own expense, any consequences where such information affects or limits the Data Subject’s rights and interests.
10.4. Comply with laws on Personal Data protection and participate in preventing and combating violations of Personal Data protection regulations.
10.5.Other responsibilities as prescribed by law.
11. OTHER PROVISIONS
11.1. The Data Subject confirms that, by accepting this Policy, the Data Subject has consented to their Personal Data being processed by the Company and the organizations and individuals participating in the Processing of Personal Data as specified in this Policy; is aware of the types of data processed, the purposes of data processing, the organizations and individuals permitted to Process Personal Data, and their rights and obligations relating to Personal Data. The Data Subject has been notified of, is aware of and agrees to all contents required to be notified before Personal Data is processed by the Company and the organizations and individuals participating in the Processing of Personal Data. The Data Subject agrees that the Company and the organizations and individuals participating in the Processing of Personal Data are not required to provide such notification again before Processing Personal Data.
11.2. If you have any questions about the Company’s protection of Personal Data, please contact us, and we will endeavor to respond to your questions as soon as possible. You may also contact us at the address below:
11.3. This Policy is effective from 05/11/2024