English translation for reference. This is a translation of the Vietnamese original. In the event of any discrepancy or difference in interpretation, the Vietnamese version prevails.
PHO TUE SOFTWARE SOLUTIONS JOINT STOCK COMPANY
SOCIALIST REPUBLIC OF VIETNAM
Independence – Freedom – Happiness
PERSONAL DATA PROTECTION POLICY
Pho Tue SoftWare Solutions Joint Stock Company (“Pho Tue SoftWare Solutions JSC”)
Issued together with Decision No. 882/QD-TTDL dated 10 October 2024 of Pho Tue SoftWare Solutions Joint Stock Company
Pho Tue SoftWare Solutions Joint Stock Company (“Pho Tue SoftWare Solutions JSC”) takes the privacy and protection of our customers' Personal Data seriously. Through this Personal Data Protection Policy (the “Policy”), we aim to give you a transparent account of how we process and protect your Personal Data when you search for, access, purchase, register for and use the products, goods and services of Pho Tue SoftWare Solutions JSC, so that your Personal Data remains private and secure in accordance with the law and with our own security standards.
This Policy constitutes our notice of the processing and protection of Personal Data. It may be amended where necessary, and the most recent version will be published on our official website. We therefore recommend that you review the Policy on our website periodically.
ARTICLE 1. DEFINITIONS
In this Policy, the following terms have the meanings set out below:
- Pho Tue SoftWare Solutions JSC: Pho Tue SoftWare Solutions Joint Stock Company, Enterprise Registration Certificate No. 0318222903, with its registered address at 128 Binh My Street, Binh My Commune, Ho Chi Minh City, Vietnam.
- Customer / you: (i) an individual and/or (ii) an organisation that provides personal data in the course of searching for, accessing, purchasing, registering for or using the products, goods and services of Pho Tue SoftWare Solutions JSC.
- Products, goods and services: any product, good or service supplied by Pho Tue SoftWare Solutions JSC and/or supplied by Pho Tue SoftWare Solutions JSC in cooperation with a partner, which the Customer searches for, accesses, purchases, registers for or uses.
- Personal Data: information in the form of symbols, letters, numerals, images, sound or a similar form in an electronic environment that is associated with a specific Customer or that helps to identify a specific Customer. Personal Data comprises Basic Personal Data and Sensitive Personal Data.
- Basic Personal Data means the following information:
- Surname, middle name and given name as recorded at birth, and any other name used;
- Date of birth; date of death or disappearance;
- Gender;
- Place of birth, place of birth registration, permanent residence, temporary residence, current residence, place of origin and contact address;
- Nationality;
- Personal image;
- Telephone number, identity card number, citizen identification number, personal identification number, passport number, driving licence number, vehicle registration number, personal tax code, social insurance number and health insurance card number;
- Information about family relationships (parents, children);
- Information about the individual's digital accounts; email address;
- Information about the Customer's use of telecommunications services, including: information relating to the use of voice and messaging services (including but not limited to the originating telephone number, the receiving telephone number, call start and end times, call duration, sending and receiving numbers for messages, and message send and receive times); subscribed packages and charging information (usage charges, outstanding charges, prepaid amounts and similar); service fees and charges; mobile data usage history (SMS, value-added services, data and similar) and duration of mobile data use; volume used, history and frequency of use of products, goods and services; IP address; and product, goods or service reviews, complaints, repair requests and fault reports;
- Personal Data reflecting activity and activity history in cyberspace, including but not limited to: data relating to websites, wapsites, social networks or applications; technical data (including device type, operating system, browser type, browser settings, IP address, language settings, date and time of connection to the website, application usage statistics, application settings, date and time of connection to the application, and other technical communication information); account names; passwords; security login details; usage data; cookie data; browsing history; clickstream data; and channel and video-on-demand viewing history;
- Other information associated with a specific Customer, or which helps to identify a specific Customer, as provided by law from time to time, which does not fall within the scope of Sensitive Personal Data under clause 6 of this Article.
- Sensitive Personal Data: Personal Data associated with the Customer's privacy which, if infringed, would directly affect the Customer's lawful rights and interests, including but not limited to:
- Information about the Customer's telecommunications account, including: charge payment history, account top-ups and telecommunications account balance;
- Information relating to the Customer's use of payment intermediary services, including: customer identification information required by law, account information, deposit information, information on deposited assets, transaction information, and information on organisations and individuals acting as guarantors at credit institutions, bank branches and payment intermediary service providers;
- Information relating to ethnic origin, physical attributes and distinctive biological characteristics that you provide to Pho Tue SoftWare Solutions JSC, or that we obtain while you purchase or use products, goods and services;
- Data on the Customer's location determined through location services;
- Other Personal Data which the law designates as specific in nature and requiring necessary security measures.
- Processing of Personal Data: one or more operations affecting Personal Data, such as collection, recording, analysis, confirmation, storage, amendment, disclosure, combination, access, retrieval, recall, encryption, decryption, copying, sharing, transmission, provision, transfer, deletion or destruction of Personal Data, or other related actions.
- Personal Data Controller: an organisation or individual that determines the purposes and means of Processing Personal Data.
- Personal Data Processor: an organisation or individual that Processes Personal Data on behalf of a Personal Data Controller, under a contract or arrangement with that Controller.
- Personal Data Controller-cum-Processor: an organisation or individual that both determines the purposes and means of processing and directly Processes Personal Data.
- Transaction channels of Pho Tue SoftWare Solutions JSC: the contact centre channel, electronic transaction channels (applications, websites such as https://photuesoftware.com, and social networks) and physical transaction channels (branches, business locations and similar of Pho Tue SoftWare Solutions JSC), or other transaction channels made available to Customers from time to time by Pho Tue SoftWare Solutions JSC or by parties it authorises.
ARTICLE 2. CATEGORIES OF PERSONAL DATA PROCESSED
- The Personal Data processed comprises the data you provide to us when searching for, accessing, purchasing, registering for and using products, goods and services, together with data arising while you use our products, goods and services, specifically:
- the Basic Personal Data specified in clause 5 of Article 1 of this Policy; and
- the Sensitive Personal Data specified in clause 6 of Article 1 of this Policy.
- Personal Data is processed in a manner appropriate to each corresponding type of product, good or service.
ARTICLE 3. PURPOSES OF PROCESSING
The Personal Data described in Article 2 above may be processed for the following purposes:
- To supply products, goods and services to Customers under contract and to exercise the rights and perform the obligations of Pho Tue SoftWare Solutions JSC as required by law, including but not limited to:
- supporting operational management; operating, exploiting and optimising the quality of the network and of the mobile, television, internet and other services supplied by Pho Tue SoftWare Solutions JSC; resolving network incidents; and providing and improving the quality of our telecommunications, television and information technology services;
- authenticating and carrying out payment transactions; reconciling and settling charges; exchanging information relating to telecommunications service users with other telecommunications enterprises for the purposes of charge calculation, invoicing and preventing evasion of contractual obligations, within the limits permitted by law; and reconciling with our partners for the purpose of supplying products, goods and services to Customers;
- supplying, activating or verifying products, goods and services requested by the Customer under a request form or contract, through our transaction channels, or in response to other Customer requests arising in the course of searching for, accessing, purchasing, registering for and using products, goods and services;
- contacting and notifying Customers;
- giving effect to Customer rights relating to Personal Data under the law and under the agreement between the Customer and Pho Tue SoftWare Solutions JSC;
- performing the Customer's contractual obligations and our obligations towards relevant agencies, organisations and individuals as required by law;
- disclosing Customer Personal Data where required by law;
- discharging our obligations in relation to inspection, examination, statistics, reporting, finance, accounting and taxation;
- carrying out data security operations and ensuring the security of our information systems, such as backup, redundancy, monitoring, resource optimisation and protection of Customer Personal Data;
- detecting and preventing unlawful conduct in cyberspace at the request of competent state authorities and as required by law, including but not limited to spam messages, spam email, nuisance calls, and messages, emails and calls made for fraudulent purposes;
- detecting and preventing fraud, deception, attack, intrusion, unlawful appropriation, criminal conduct and other unlawful acts;
- conducting activities for the purposes of audit, risk management, anti-money laundering, counter-terrorist financing and sanctions compliance;
- responding to a state of emergency concerning national defence, national security, social order and safety, a major disaster or a dangerous epidemic; where there is a threat to security or national defence that has not reached the level of a declared state of emergency; and preventing and combating riot, terrorism, crime and breaches of the law as provided by law;
- supporting the operations of state authorities as required by specialised legislation.
- To support Customers purchasing and using our products, goods and services under contract and as required by law, including:
- updating and processing information when Customers purchase and use products, goods and services;
- customer care, and receiving and resolving Customer queries and complaints regarding our products, goods and services;
- using, and transferring to partners, Personal Data and information on difficulties, incidents and fault reports raised by Customers in order to identify and remedy product, goods or service faults; repairing Customer equipment; and carrying out other customer care and support activities.
- To improve the quality of the products, goods and services we supply to Customers:
- providing information the Customer has requested, or that we consider the Customer may find useful, including information about our products, goods and services as permitted by law;
- improving the technology and interface of our websites, wapsites, social networks and applications for Customer convenience;
- managing Customer accounts and loyalty programmes;
- storing information, market research, analysis, statistics and other internal management activities aimed at improving the Customer experience;
- internal reporting, statistics and data analysis in order to research, build, develop, manage, measure, supply and improve products, goods and services and to run our business;
- developing marketing campaigns for products, goods and services and determining how we may personalise them;
- developing and supplying new products, goods and services personalised to the Customer's needs and actual circumstances, with methods for measuring effectiveness;
- introducing and providing promotional programmes, offers and incentives, whether our own or offered in cooperation with our partners;
- assessing the Customer's capacity to purchase and use our products, goods and services by reference to the Customer's telecommunications rating, in order to support the supply of products, goods and services as effectively as possible.
- To conduct marketing, advertising and product introduction services suited to the Customer's needs, or which we consider to be of interest to the Customer, with the following content, methods, formats and frequency:
- Content: introducing information about products, goods, services and offers supplied by Pho Tue SoftWare Solutions JSC and its partners;
- Method: advertising messages (SMS, USSD, MMS and similar), IVR calls, notices through our transaction channels, or other methods permitted by law;
- Format: sent directly to the Customer through devices or electronic means, or in other forms in cyberspace as permitted by law;
- Frequency: as provided by advertising legislation.
- To conduct market research, opinion polling and brokerage services.
- To organise trade introduction and promotion activities.
ARTICLE 4. METHODS OF PROCESSING
1. Methods of collection
Personal Data is collected directly from you in the following circumstances:
- From our websites: we may collect Personal Data when you visit any Pho Tue SoftWare Solutions JSC website (together, the “Website”) or use any feature or resource available on or through the Website. When you visit the Website, we collect information about your device and browser (such as device type, operating system, browser type, browser settings, IP address, language settings, the date and time of connection to the Website, and other technical communication information).
- From applications: we may collect Personal Data when you download or use a Pho Tue SoftWare Solutions JSC mobile application (together, the “Application”). These Applications may record certain information (including application usage statistics, device type, operating system, application settings, IP address, language settings, the date and time of connection to the Application, and other technical communication information).
- From products, goods and services: we may collect Personal Data when you search for, access, purchase, register for or use any product, good or service by any means (SMS, USSD, IVR, website, wapsite, application and similar), through our transaction channels, in cyberspace, and/or by other means permitted by law.
- From exchanges and communications with Customers: we may collect Personal Data through interactions between us and you (in person, by post, by telephone, online, through the contact centre, by electronic communication or by any other means), including Customer surveys.
- From social networks: our own social network accounts and/or those operated in cooperation with our partners.
- From audio and video recording equipment installed at stores, business points or places where part or all of our business is conducted, where you meet, appear before or interact with us. Such equipment is installed in order to contribute to social order and safety and to protect the lawful rights and interests of Customers and of Pho Tue SoftWare Solutions JSC in accordance with the law.
- From interactions or automatic data collection technologies: we may collect information including IP address, referring URL, operating system, browser and any other information recorded automatically from the connection:
- cookies, flash cookies, plug-ins, pixel tags, web beacons, third-party social network connectors and other tracking technologies;
- any technology capable of tracking individual activity across devices or websites;
- other data provided by a device.
- Other means: we may collect Personal Data when you interact with Pho Tue SoftWare Solutions JSC by any other means.
We may also collect Personal Data indirectly from public and official sources, or through necessary data shared by subsidiaries and partners which they have collected while cooperating with us to supply products, goods and services to you, and which you have permitted to be shared.
2. Methods of storage
Personal Data is stored in Vietnam in the Customer database systems of Pho Tue SoftWare Solutions JSC, or anywhere that we or our branches, subsidiaries, affiliates, partners or service providers maintain facilities, with backup copies created in a data centre in another region.
While you access our websites, applications and social networks, we may also store information temporarily through cookies, clickstream or similar browsing data storage tools, so that the web server within the domain can retrieve it.
3. Methods of transfer and sharing
We will apply the necessary security measures to ensure that the transfer or sharing of your Personal Data to (i) other telecommunications enterprises; (ii) individuals and organisations participating in the Processing of Personal Data as set out in Article 8 of this Policy; or (iii) competent state authorities, is carried out securely and without disclosure or leakage of data, and we require recipients of Personal Data to apply data security measures.
4. Methods of analysis
Personal Data is analysed in accordance with our internal procedures. We maintain strict oversight of each data analysis process, which requires verification that legal requirements on data security and information system security are met before analysis is carried out. We also apply strict rules to ensure that personal information is anonymised or de-identified at the appropriate stage of processing.
5. Methods of encryption
Personal Data collected is encrypted to appropriate encryption standards where necessary during storage or transfer, so that the data is protected, authenticated and complete, and cannot be altered after it has been sent.
6. Methods of deletion
When you cease using our products, goods and services and make a valid request, we will delete all Personal Data you have provided and/or that we have collected while you used those products, goods and services, save where the law provides otherwise and in the following cases where deletion is not possible:
- the law does not permit deletion, or mandatorily requires the data to be retained;
- the Personal Data is processed by a competent state authority for the purpose of that authority's activities as provided by law;
- the Personal Data has been made public in accordance with the law;
- the Personal Data is processed to meet legal requirements, or for scientific research or statistical purposes, as provided by law;
- there is a state of emergency concerning national defence, national security, social order and safety, a major disaster or a dangerous epidemic; a threat to security or national defence that has not reached the level of a declared state of emergency; or activity to prevent and combat riot, terrorism, crime and breaches of the law;
- responding to an emergency threatening the life, health or safety of the Customer or another individual.
ARTICLE 5. OUR DATA SECURITY PRINCIPLES
- Your Personal Data is protected in accordance with this Policy and with the law.
- We are responsible for ensuring network information security in accordance with the law, for safeguarding national defence, national security and state secrets, and for maintaining political stability, social order and safety and promoting socio-economic development.
- Network information security incidents are handled in a manner that safeguards your lawful rights and interests.
- Network information security activities are carried out regularly, continuously, promptly and effectively.
ARTICLE 6. POSSIBLE UNDESIRED CONSEQUENCES AND DAMAGE
- We use a range of information security technologies — including the PCI DSS international standard, SSL, firewalls and encryption — to protect your Personal Data and prevent it from being accessed, used or shared without authorisation. However, no data can be made entirely secure. We therefore cannot guarantee absolute security of your Personal Data in circumstances such as:
- hardware or software faults during data processing that result in loss of Customer data;
- security vulnerabilities beyond our control, or systems compromised by attackers leading to data leakage.
- We recommend that you keep information relating to your account login password and OTP codes confidential, and that you do not share it with anyone else.
- You should be aware that whenever you disclose or make your Personal Data public, that data may be collected and used by others for purposes beyond your control and ours.
- We recommend that you keep your personal devices (mobile phone, tablet, personal computer and similar) secure while in use, and that you sign out of your account when you no longer need it.
- If a server storing data is attacked and Customer Personal Data is lost, disclosed or leaked, Pho Tue SoftWare Solutions JSC will be responsible for notifying the competent authorities so that the matter can be investigated and dealt with promptly, and for notifying you in accordance with the law.
- Cyberspace is not a secure environment and we cannot guarantee absolutely that Personal Data you share over it will always remain secure. When transmitting Personal Data over cyberspace you should use only secure systems to access websites, applications or devices. You are responsible for keeping your access credentials for each website, application or device secure and confidential.
ARTICLE 7. START AND END OF PERSONAL DATA PROCESSING
- Personal Data is processed from the point at which we receive the Personal Data you provide and have an appropriate legal basis for processing it under the law.
- To the extent permitted by law, Personal Data will be processed until the purposes of processing have been fulfilled.
- We may be required to retain your Personal Data even after the contract between you and Pho Tue SoftWare Solutions JSC has ended, in order to discharge our legal obligations and/or to meet the requirements of competent state authorities.
ARTICLE 8. ORGANISATIONS AND INDIVIDUALS INVOLVED IN PROCESSING
- Depending on the circumstances, we may act as the Personal Data Controller or as the Personal Data Controller-cum-Processor.
- To the extent permitted by law, you acknowledge that we may share Personal Data for the purposes set out in Article 3 with the following organisations and individuals:
- member enterprises and affiliates of Pho Tue SoftWare Solutions JSC;
- organisations and individuals supplying services to, and/or cooperating with, Pho Tue SoftWare Solutions JSC, including but not limited to agents, consultants, auditors, lawyers, notaries and business partners providing information technology solutions, software, applications, and operational, management, incident-handling and infrastructure development services;
- any individual or organisation acting as the Customer's representative or authorised party, acting on the Customer's behalf;
- payment service providers, based on the Customer's authorisation or consent.
Data sharing will be carried out in accordance with the order, methods and requirements of applicable law. Recipients of Personal Data are obliged to keep your Personal Data secure in accordance with this Policy, with our personal data protection rules, procedures and standards, and with applicable law.
- We may share your information with competent state authorities when carrying out the Processing purposes set out in Article 3 of this Policy, in accordance with the law.
ARTICLE 9. CUSTOMER RIGHTS
- You have the right to be informed about the Processing of your Personal Data, save where the law provides otherwise.
- You have the right to decide whether to consent to the Processing of your Personal Data, save where the law provides otherwise.
- You have the right to access, view, amend or request amendment of your Personal Data, save where the law provides otherwise. We will amend Personal Data at your request or as required by specialised legislation. Where this is not possible, we will notify you in accordance with our agreement with you and with the law.
- You have the right to delete, or to request the deletion of, your Personal Data in accordance with clause 6 of Article 4 of this Policy.
- You have the right to request restriction of the Processing of your Personal Data as provided by law. We will restrict processing following your request, so far as technically feasible, save where the law provides otherwise or the parties agree otherwise.
- You have the right to request that we provide you with your own Personal Data, save where the law provides otherwise. We will provide your Personal Data following your request, save where the law provides otherwise.
- You have the right to withdraw consent to the processing purposes to which you have consented, save where the law provides otherwise. On receiving such a request, we will inform you of the consequences and potential damage arising from withdrawal of consent. Where withdrawal of your consent affects performance of the contract between us, our legal obligations, or the life, property or lawful rights and interests of you or of other organisations and individuals, or the protection of national security and social order and safety, we may restrict, suspend, terminate or cancel all or part of the contract for the supply of products, goods and services between us.
- You have the right to object to our Processing of your Personal Data in order to prevent or restrict disclosure of Personal Data, or for other reasons provided by law. We will give effect to your objection on receipt, save where the law provides otherwise. Where your objection affects performance of the contract between us, our legal obligations, or the life, property or lawful rights and interests of you or of other organisations and individuals, or the protection of national security and social order and safety, we may restrict, suspend, terminate or cancel all or part of the contract for the supply of products, goods and services between us.
- You have the right to complain, denounce or bring legal proceedings in accordance with the law.
- You have the right to claim compensation for actual damage in accordance with the law if Pho Tue SoftWare Solutions JSC breaches personal data protection requirements, save where the parties agree otherwise or the law provides otherwise.
- You have the right to protect yourself under relevant legislation, including but not limited to the Civil Code, or to request competent agencies and organisations to apply civil remedies such as an order to cease the infringing conduct, an apology, a public correction, or compensation for damage.
- Any other rights under this Policy and under the law.
- You may exercise the rights in clauses 1 to 10 of this Article by visiting https://photuesoftware.com/, calling the hotline on 0865 920 041, emailing supports@photuesoftware.com, or by any other means provided by law and by our rules from time to time. Pho Tue SoftWare Solutions JSC may verify the information necessary to give effect to your request.
ARTICLE 10. CUSTOMER OBLIGATIONS
- Comply with the law and with our rules relating to the Processing of your Personal Data.
- Provide complete, truthful and accurate Personal Data and other information as we require when searching for, accessing, purchasing, registering for and using products, goods and services, and when that information changes. We will protect your Personal Data on the basis of the information you have provided. Accordingly, we accept no responsibility where inaccurate information affects or limits your entitlements. If you fail to notify us of changes and risk or loss arises, you are responsible for errors, misuse or fraud in the use of products, goods and services caused by your fault or by your failure to provide correct, complete, accurate and timely updates, including financial loss and costs arising from incorrect or inconsistent information.
- Cooperate with us, with competent state authorities or with third parties where issues arise affecting the security of your Personal Data.
- Protect your own Personal Data; require other relevant organisations and individuals to protect your Personal Data; take active measures to protect your Personal Data while using our products, goods and services; and notify us promptly on discovering any error or inconsistency in Personal Data, or on suspecting that Personal Data has been compromised.
- Respect and protect the Personal Data of others.
- Take responsibility for the information and data you create and provide in cyberspace, and for cases where Personal Data is leaked or compromised through your own fault.
- Keep up to date with our personal data protection and processing rules and policies as notified to you from time to time through our transaction channels.
- Comply with personal data protection legislation and take part in preventing and combating breaches of personal data protection requirements.
- Any other obligations provided by law.
ARTICLE 11. GENERAL PROVISIONS
- This Policy takes effect from 1 January 2024 and may be amended from time to time, with notice given to you through our transaction channels before it applies. Such changes take effect in accordance with the law.
- This Policy constitutes the notice of Personal Data Processing required by applicable law.
DIRECTOR
(Signed)
NGUYEN THANH AN












































































































































