Under this Personal Data Protection Policy (the “Policy”), SCS may act as a Personal Data Controller, Personal Data Processor, Personal Data Controller and Processor, and/or Third Party involved in the processing of personal data, depending on the context and circumstances in which SCS processes personal data.
Article 1. Definitions
1.1. “SCS” means SCS Cybersecurity Joint Stock Company.
1.2. “SafeGate Family” means a home internet security and management solution developed by SCS Cybersecurity Joint Stock Company. The solution includes a Wi-Fi router and a mobile application installed on users’ mobile devices. The solution helps ensure secure internet access within the home and enables parents to monitor and manage their children’s excessive internet use in a simple and effective manner.
1.3. “Customer” means an individual who searches for, accesses, registers for, or wishes to use the services and products provided by SCS and/or jointly provided by SCS and its partners.
1.4. “Data Subject” means an individual to whom Personal Data relates. Under this Policy, a Data Subject may be a Customer or an individual associated with a Customer.
1.5. “Personal Data” means information in the form of symbols, letters, numbers, images, sounds, or similar forms in an electronic environment that is associated with or capable of identifying a specific individual.
Personal Data includes Basic Personal Data and Sensitive Personal Data.
1.6. “Basic Personal Data” includes:
a) Full name at birth, including surname, middle name, and given name; and any other name, if applicable;
b) Date of birth; date of death or date on which a person is declared missing;
c) Gender;
d) Place of birth; place of birth registration; permanent residence; temporary residence; current residence; hometown; and contact address;
e) Nationality;
f) Images of an individual;
g) Telephone number; identity card number; personal identification number; passport number; driver’s license number; vehicle registration plate number; personal tax identification number; social insurance number; and health insurance card number;
h) Marital status;
i) Information regarding family relationships, including parents and children;
j) Information relating to an individual’s digital accounts; and Personal Data reflecting activities and activity history in cyberspace;
k) Other information associated with or capable of identifying a specific individual that does not constitute Sensitive Personal Data.
1.7. “Sensitive Personal Data” means Personal Data associated with an individual’s privacy which, if infringed upon, may directly affect the lawful rights and interests of that individual, including:
a) Political opinions and religious beliefs;
b) Health status and private information recorded in medical records, excluding information relating to blood type;
c) Information concerning racial origin or ethnic origin;
d) Information concerning an individual’s inherited or acquired genetic characteristics;
e) Information concerning an individual’s unique physical attributes or biological characteristics;
f) Information concerning an individual’s sex life or sexual orientation;
g) Data relating to criminal offenses or criminal conduct collected and stored by law enforcement authorities;
h) Customer information held by credit institutions, branches of foreign banks, payment intermediary service providers, and other authorized organizations, including: Customer identification information as prescribed by law; Account information; Deposit information; Information regarding deposited assets; Transaction information; and Information concerning organizations and individuals providing security to credit institutions, bank branches, or payment intermediary service providers;
i) An individual’s location data determined through location-based services;
j) Other Personal Data designated by law as specific data requiring necessary security measures.
1.8. “Personal Data Protection” means activities aimed at preventing, detecting, stopping, and handling violations related to Personal Data in accordance with applicable laws.
1.9. “Personal Data Processing” means one or more activities performed in relation to Personal Data, including: collecting; recording; analysis; confirmation; storage; modification; disclosure; combination; access; retrieval; recovery; encryption; decryption; copying; sharing; transmission; provision; transfer; erasure; destruction; and other related activities.
1.10. “Personal Data Controller” means an organization or individual that determines the purposes and means of Personal Data Processing.
1.11. “Personal Data Processor” means an organization or individual that processes Personal Data on behalf of a Personal Data Controller under a contract or agreement with the Personal Data Controller.
1.12. “Personal Data Controller and Processor” means an organization or individual that simultaneously determines the purposes and means of Personal Data Processing and directly processes Personal Data.
1.13. “Third Party” means an organization or individual other than the Data Subject, Personal Data Controller, Personal Data Processor, or Personal Data Controller and Processor that is authorized to process Personal Data.
Article 2. Rights and Obligations of Data Subjects
2.1. Data Subjects have the following rights:
a. Right to be informed
Data Subjects have the right to be informed about the processing of their Personal Data, including:
- The types of Personal Data being processed;
- The purposes of processing;
- The parties involved in the processing activities, including individuals and organizations; and
- The rights and obligations of the Data Subject.
b. Right to consent
Data Subjects have the right to give or withhold consent to the processing of their Personal Data.
c. Right of access
Data Subjects have the right to access, review, correct, or request the correction of their Personal Data, except where otherwise provided by law.
d. Right to withdraw consent
Data Subjects have the right to withdraw their consent, except where otherwise provided by law.
e. Right to erasure
Data Subjects have the right to erase or request the erasure of their Personal Data, except where otherwise provided by law.
f. Right to restrict processing
Data Subjects have the right to request the restriction of the processing of their Personal Data, except where otherwise provided by law.
The restriction of Personal Data Processing shall be implemented within 72 hours of receipt of the Data Subject’s request and shall apply to all Personal Data for which the Data Subject has requested processing restrictions, except where otherwise provided by law.
g. Right to obtain Personal Data
Data Subjects have the right to request that the Personal Data Controller or Personal Data Controller and Processor provide them with their Personal Data, except where otherwise provided by law.
h. Right to object to Personal Data Processing
Data Subjects have the right to object to the processing of their Personal Data by a Personal Data Controller or Personal Data Controller and Processor in order to prevent or restrict the disclosure of Personal Data or its use for advertising and marketing purposes, except where otherwise provided by law.
The Personal Data Controller or Personal Data Controller and Processor shall comply with the Data Subject’s request within 72 hours of receiving the request, except where otherwise provided by law.
i. Right to file complaints, denunciations, or legal actions
Data Subjects have the right to file complaints, denunciations, or initiate legal proceedings in accordance with applicable laws.
j. Right to claim compensation for damages
Data Subjects have the right to claim compensation for damages in accordance with applicable laws in the event of a violation of regulations on the protection of their Personal Data, unless otherwise agreed by the parties or otherwise provided by law.
k. Right to self-protection
Data Subjects have the right to protect themselves in accordance with the Civil Code, other relevant laws, and Decree No. 13/2023/ND-CP.
2.2. Data Subjects have the following obligations:
a. To protect their own Personal Data and request relevant organizations and individuals to protect their Personal Data.
b. To respect and protect the Personal Data of others.
c. To provide complete and accurate Personal Data when consenting to the processing of their Personal Data.
d. To participate in communication and awareness-raising activities concerning Personal Data protection skills.
e. To comply with laws on Personal Data Protection and participate in preventing and combating violations of regulations on Personal Data Protection.
Article 3. Customer representations and acknowledgements
3.1. Personal data provided by the Customer to SCS Company and/or otherwise obtained by SCS Company may include the Customer’s Basic personal data and/or Sensitive personal data, as well as the Personal data of individuals related to the Customer.
3.2. Where the Customer provides SCS Company with the Personal Data of individuals related to the Customer, including but not limited to dependants, persons related to the Customer under applicable law, representatives, guardians, friends, references, beneficiaries, authorized persons, business partners, and emergency contacts, the Customer represents that such individuals have been duly notified of this Policy and that the Customer has obtained their consent where required. The Customer shall be responsible for any failure to obtain such consent.
3.3. The Customer acknowledges that they have read, reviewed, understood, and fully grasped their rights and obligations as a Data Subject, the categories of Personal Data processed, the processing purposes, and the organizations and individuals authorized to process the personal data. The information stipulated in this Policy shall constitute notice provided by SCS Company to the Customer before SCS Company initiates personal data processing. For the processing of sensitive personal data, SCS Company will notify the Data Subject via an email/written notice indicating that the data to be processed is sensitive personal data.
3.4. From the time the Data Subject provides personal data to SCS Company and/or SCS Company otherwise obtains such personal data until the Data Subject no longer has any transactions/obligations with SCS Company, or for such longer period as determined by SCS Company,, whichever is later, SCS Company is permitted to process the Data Subject’s personal data for the following purposes, using methods deemed necessary by SCS Company and permitted under applicable law:
a) Contacting the Customers to verify or update information and providing support Customers when they wish to use SCS Company’s services;
b) Providing Products and services to Customers and performing SCS Company’s rights and obligations under contracts/agreements and legal regulations;
c) Marketing, advertising, and promoting products and services suitable for the Customer's needs or those SCS Company believes may interest the customer;
d) Entering/storing/retaining/managing information collected through SCS Company’s software and technology systems for purposes such as: providing post-consultation support, performing services under contracts, conducting after-sales activities, including but not limited to: periodic and on-demand customer care, addressing inquiries, resolving incidents, analyzing customer information to enhance improve quality, researching and deploying other products and services, and fulfilling requests from competent state authorities during inspections and audits;
e) Organizing training, providing services, evaluating, and issuing certifications, including but not limited to: Information Security Awareness Training, Incident Response Exercise Training, etc., which the Customer has registered for/agreed upon with SCS Company;
f) Assisting the Customer in exercising, and facilitating the exercise of, the Data Subject’s rights in accordance with applicable law;
g) Storing the Data Subject’s personal data on systems operated by third-party hosting or data storage service providers;
h) Inspecting, testing, installing, administering, upgrading, and improving the technical systems and security measures used to safeguard the Data Subject’s Personal Data, including the management of personnel responsible for such systems;
i) Promoting and providing the Data Subject with information regarding about services, promotional programs, research, surveys, news, updates, events, prize contests, reward programs, lucky draws, and event organizations;
k) Receiving, assessing, and processing requests from the Data Subject, including responding to queries or feedback, resolving or investigating any complaints, legal claims, or disputes, or communicating information, providing documents or other materials related to transactions and the use of products, services, features, utilities, and the provision of services as requested by the Data Subject;
i) Improving the quality of Products and services provided by SCS Company;
j) Implementing measures to ensure the safety, security, and protection of the Data Subject’s Data against actual or potential harm; facilitating data storage, management, protection, and information security activities;
m) Resolving disputes, complaints, and reports of violations;
n) Providing and exchanging information with competent state authorities, and other organizations and individuals in accordance with applicable law;
o) Executing advertising activities to promote business and expand SCS Company’s market in each period;
p) Other purposes as determined by SCS Company from time to time, to the extent permitted by applicable law.
3.5. The Customer acknowledges and agrees as follow:
a) They have been informed by SCS Company about personal data processing via this Data Protection Policy and consent to SCS Company processing personal data from the moment the Customer clicks "Agree" when providing data on SCS Company's website/or through products and services provided by SCS Company, until the fulfillment of the processing purposes outlined in Section 3.4. Any actions intended to withdraw the Customer's consent (if any) shall not affect the lawfulness of the personal data processing previously consented to by the Customer. The Customer is fully aware of and responsible for all consequences and damages that may occur/arise from their withdrawal of consent without prior notice from SCS Company. Should the Customer withdraw consent improperly per legal regulations, affecting personal data processing, SCS Company may apply necessary measures to protect its legitimate rights and interests in accordance with the law and/or the Customer's commitments/agreements with SCS Company.
b) In the event the Customer withdraws consent, SCS Company may proactively contact and request the Data Processor/Third Party to cease Processing the Data Subject's personal data at any time SCS Company deems appropriate, subject to the procedures, sequences, and technical infrastructure capabilities of SCS Company and/or the Data Processor and/or the Third Party at that time. If the withdrawal of consent is not executed properly per legal regulations, or due to technical or infrastructure factors preventing SCS Company from ceasing personal data processing within the timeframe requested by the Customer, SCS Company shall be exempt from all obligations and liabilities related to this withdrawal request from the Data Subject.
c) Notify and update SCS Company of any changes related to the Data Subject's personal data and agree that SCS Company holds full rights to update and rectify the Data Subject's personal data based on the change notification provided by the Customer.
d) All personal data of the Data Subject acquired by SCS Company may be managed and retained by SCS Company in a manner and duration it deems appropriate. The Customer shall not arbitrarily propose to view, rectify, or delete such data under any circumstances unless consented to by SCS Company. SCS Company reserves the right to refuse requests to view, rectify, or delete the Customer's Personal Data if such requests are deemed inappropriate.
e) Should SCS Company agree to the Data Subject's requests to rectify personal data, SCS Company reserves the right to proactively execute such requests subject to the procedures and technical infrastructure capabilities of SCS Company. If personal data rectification cannot be performed due to technical factors or infrastructure limitations, SCS Company will notify the Data Subject via email/writing within 72 hours of receiving the rectification request. Furthermore, SCS Company shall be exempt from all obligations and liabilities related to this request to view or rectify personal data from the Data Subject.
f) SCS Company agrees to the request to delete personal data in the following cases:
- The Data Subject finds it is no longer necessary for the originally agreed collection purposes and accepts and bears responsibility for any potential damages that may occur upon requesting data deletion.
- The Data Subject withdraws consent.
- Objects to data processing by SCS Company with legitimate, reasonable grounds, and within SCS Company's capacity to accommodate.
- The Data Subject perceives and proves that their Personal Data is being processed contrarily to the agreed purposes or that the processing violates legal regulations.
In cases where the Data Subject's request to delete personal data is accepted, SCS Company will proceed to delete the requested personal data according to the sequence and technical infrastructure capabilities of SCS Company within 72 hours upon the Data Subject's request, unless otherwise provided by law, ensuring irreversible deletion as much as possible when data is processed for incorrect purposes or the personal data processing purposes consented to by the Data Subject have been fulfilled.
g) Personal data provided by the Customer to SCS Company that is collected and processed in connection with the SafeGate Family software service will primarily be governed by the SafeGate Family Data Protection Policy.
h) Exonerate SCS Company from all obligations and liabilities regarding potential risks during personal data processing, including but not limited to data loss due to system errors or objective causes beyond SCS Company's control.
i) Regarding the use and processing of personal data relating to individuals declared missing/deceased, SCS Company must obtain the consent of the spouse or adult children of that individual. In their absence, consent must be obtained from the parents of the individual declared missing/deceased, except in cases where personal data processing does not require the Data Subject's consent under prevailing legal regulations.
j) Regarding the use and processing of children's personal data, such processing requires the child's consent if the child is 7 years of age or older, and the consent of the parents or legal guardian as prescribed, except in cases where processing does not require the Data Subject's consent under the law. When providing personal data of a child Data Subject, the Customer warrants having obtained consent in strict compliance with the aforementioned regulations and bears responsibility if consent has not been obtained. In addition to statutory personal data protection measures, prior to processing children's personal data, SCS Company will verify the child's age and request the consent of (i) the child aged 7 or older and (ii) the child's parents or legal guardian in accordance with the law.
k) Other related organizations/individuals that may act as Personal Data Processors or third parties provided/shared with the Data Subject's personal data by SCS Company will depend on, including but not limited to, the following processing purposes:
(i) Partners and organizations supplying products and services to provide products and services to Customers upon request;
(ii) Organizations/individuals provided/shared to fulfill other purposes as determined by SCS Company in each period.
l) Agree that to fulfill the purposes of processing the Data Subject's personal data, SCS Company may need to provide/share the Data Subject's personal data with other related organizations/individuals of the Company, and these entities may be located within Vietnam or any other location outside the territory of Vietnam. When transferring personal data abroad, SCS Company will require the receiving party to ensure that the transferred personal data of the Data Subject remains confidential and secure. SCS Company ensures compliance with legal and regulatory obligations concerning the cross-border transfer of the Data Subject's personal data.
Article 4. Types of Personal Data processed by SCS Company
4.1. Basic personal data: Last name, middle name and birth name, other names (if any); date, month, and year of birth; gender; current address, contact address; nationality; personal image; phone number, identity card number, personal identification number, passport number, personal tax identification number; Information regarding persons related to SCS Company Personnel; Other information associated with SCS Company Personnel or helping to identify SCS Company Personnel that does not fall under Sensitive personal data mentioned in Clause 4.2 of this Article (including information on digital accounts; personal data reflecting cyberspace activity history, etc.).
4.2. Sensitive personal data: Depending on SCS Company's service policies in each period.
Article 5. Methods of Personal Data collection
SCS Company proceeds to collect the personal data specified in Article 4 of this Policy from the Customer through methods including, but not limited to, the following activities:
(i) Through verbal and/or written communication and interactions between the Customer and SCS Company;
(ii) From survey documents, social media communications, or third parties providing service activities related to the Customer;
(iii) From other third parties holding a relationship or connection with the Customer;
(iv) Through files generated by SCS Company's website when accessed by the Customer (cookies);
(v) Through service contracts/other agreements signed between SCS Company and the customer;
(vi) Through archived footage from SCS Company’ Closed-Circuit Television (CCTV) cameras.
Article 6. Personal Data Processing Period
6.1. Commencement Period
SCS Company will commence processing the Data Subject's personal data from the moment the personal data is received.
6.2. Termination Period
SCS Company will cease processing the Data Subject's personal data when (whichever occurs later):
- Upon written request from the Data Subject in accordance with the Personal Data Protection Policy; SCS Company will record and archive system logs of the personal data processing to serve the purposes outlined in Section 3.4.
- Conclusion of disputes and complaints via legally binding agreements/judgments/decisions;
- Other times aligning with the Purposes;
- As prescribed by law.
However, SCS Company may still continue to retain personal data to meet its legal obligations, and SCS Company is responsible for maintaining the confidentiality of personal data in accordance with the law.
Article 7. Storage and Security of customer’s Personal Data
7.1. SCS Company is committed to storing and securing the Customer's personal data safely and in compliance with legal regulations. All third parties permitted to access, process, and store the Customer's personal data as stipulated in this Policy are required to adhere to SCS Company's confidentiality obligations.
7.2. SCS Company implements appropriate data processing methods as well as suitable technical and organizational security measures to prevent unauthorized access, reading, use, alteration, destruction, or other processing of personal data.
7.3. SCS Company will record and archive system logs of the personal data processing to serve the purposes outlined in Section 3.4, Article 3 of this Policy, and in accordance with the law.
7.4. The Data Subject understands that SCS Company will/is/has applied appropriate technical, physical, and administrative measures to protect and ensure the confidentiality of the Data Subject's personal data. However, these measures cannot entirely guarantee the absolute prevention of all unauthorized access to the Data Subject's personal data by third parties, such as hackers.
7.5. When the Data Subject's personal data may be shared by SCS Company for the purposes stated in Section 3.4, Article 3 of this Policy, information security risks (the Data Subject's personal information may be stolen, leaked, unlawfully compromised, etc.) can completely occur as the internet is not a completely secure environment. Therefore, the Data Subject acknowledges that SCS Company bears absolutely no responsibility for any risks to the Data Subject's personal data from the moment the third party, with whom SCS Company shares the data, receives the Data Subject's personal data from SCS.
Article 8. Amendment, Supplementation, and Replacement of the Policy
8.1. SCS Company is permitted to amend, supplement the content, or replace this Policy at any time SCS Company deems appropriate, ensuring that such amendments and supplements align with relevant legal regulations.
8.2. SCS Company will notify Customers of amendments, supplements, and replacements through one of the following methods, including: in writing, via email, announcements on mass media, notices on SCS Company's official website, postings at the headquarters and transaction points of SCS Company, and/or other forms SCS Company deems suitable.
8.3. If the Customer continues to maintain a service demand with SCS Company after the time SCS Company issues a notification, it is understood that the Customer accepts all amendments, supplements, and replacements to this Policy by SCS Company.
Article 9. Contact for complaints regarding Personal Data processing
9.1. In the event the Data Subject has any complaints related to this Personal Data Protection Policy or regarding SCS Company's processing of the Data Subject's personal data, the Data Subject may contact SCS Company via the following details:
In-person: SCS Company Headquarters at NIC Building, No. 6, Alley 7, Ton That Thuyet Street, Cau Giay Ward, Hanoi City, Vietnam
Phone: 1900 3250
Email: [email protected]
Website: https://safegate.vn
9.2. To exercise the rights of the Data Subject in accordance with Decree 13/2023/ND-CP, please click on Request.
Article 10. Dispute resolution
Should any dispute arise from or in relation to the processing of personal data, the Data Subject and SCS Company shall first seek to resolve it mutually through negotiation and mediation. If mediation fails, the parties hold the right to bring the dispute before a competent Court in Vietnam for resolution.
Article 11. Implementation provisions
This Personal Data Protection Policy applies to all personal data and all transactions of the Data Subject with SCS Company, demonstrating the Customer's full consent for SCS Company to Process the Data Subject's personal data. This Personal Data Protection Policy shall prevail in the event of any conflicts or inconsistencies with the agreements, terms, and conditions in contracts, agreements, texts, and documents governing the relationship between the Data Subject and SCS Company, regardless of whether such contracts, agreements, texts, and documents were signed before, on, or after the date the Data Subject accepts this Policy. In the event of any objections or the imposition of one/several related conditions regarding the authorization to Process personal data, the Customer shall proactively contact SCS Company for assistance.