PERSONAL DATA PROTECTION POLICY OF NODO MEDIA AND SERVICES JOINT STOCK COMPANY

This Personal Data Protection Policy (also referred to as the Privacy Policy) describes the manner in which personal data arising in the course of the operations and business activities of NODO Media and Services Joint Stock Company (hereinafter referred to as the “Company”) is collected, used and processed. The Company has its address at Audi Building, 8 Pham Hung, Yen Hoa Ward, Hanoi, Vietnam, and its official website is nodo.vn.

1. GENERAL PROVISIONS

1.1 Personal Data: means information in the form of symbols, letters, numerals, images, sounds or similar forms in an electronic environment which is associated with a specific person or which helps to identify a specific person. Personal Data comprises basic Personal Data and sensitive Personal Data. 1.2 Data Subject: means the individual to whom the Personal Data relates, including all individual customers using the Company’s products and services, employees of the Company, shareholders and/or other individuals having a legal relationship with the Company. 1.3 Processing of Personal Data: means one or more activities affecting Personal Data, such as: collecting, recording, analysing, confirming, storing, amending, disclosing, combining, accessing, retrieving, recalling, encrypting, decrypting, copying, sharing, transmitting, providing, transferring, deleting or destroying Personal Data, or other related acts.

1.4 Personal Data Protection Policy, or “this Policy”: means the entire content of this policy drafted and issued by the Company, comprising 11 Sections and 61 sub-sections in full and in their entirety.

1.5 Where the Personal Data of persons related to the Data Subject (including information of dependants, related persons as prescribed by law, spouse, children and/or parents and/or guardians, friends, beneficiaries, authorised persons, partners, emergency contacts or other individuals connected with the Data Subject) is provided to the Company, the Data Subject and the persons related to the Data Subject undertake, warrant and accept responsibility that such information has been provided in full and that the Data Subject has lawfully consented to/approved its processing for the purposes set out in this Policy. The Data Subject and the persons related to the Data Subject agree that the Company shall not be responsible for verifying the legality and validity of such consent/approval, and that the retention of evidence thereof shall be the responsibility of the persons related to the Data Subject and the Data Subject. The Company shall be exempt from liability and shall be entitled to claim compensation for related damages and costs where the Data Subject and/or the persons related to the Data Subject fail to comply with the provisions set out herein.

1.6 By registering for and using the Company’s products and services, entering into contracts and/or permitting the Company to carry out the Processing of Personal Data, the Data Subject accepts in full and without any conditions the policies referred to herein and any changes thereto (if any) from time to time.

1.7 This Policy may be updated, amended, supplemented or replaced by the Company in order to ensure compliance with the provisions of law from time to time, and shall be published by the Company on the Company’s official website. You should visit and check the website regularly in order to keep up to date with the most recent changes.

1.8 The Company undertakes to comply with the following principles when carrying out the Processing of Personal Data: the Company processes and protects Personal Data in accordance with the laws of Vietnam; and fully complies with the contracts, agreements and other documents entered into with the Data Subject;

1. The Company collects Personal Data for specific, clear and lawful purposes, within the scope of the purposes set out in Section 3 of this Policy and in accordance with the laws of Vietnam;

2. The Company shall at all times apply and update technical measures consistent with the laws of Vietnam in order to ensure the security of Personal Data, including measures to protect against unauthorised access and/or the destruction of, loss of or damage to Personal Data;

3. The Company stores Personal Data in an appropriate manner and to the extent necessary for processing in accordance with the laws of Vietnam;

4. The Company undertakes to comply with the provisions relating to the protection of children’s data

2. PERSONAL DATA PROCESSED

In order for the Company to carry out the Processing of Personal Data for the purposes set out in Section 3 of this Policy, the Company may process the following categories of Personal Data:

2.1 Basic Personal Data includes:

1. Surname, middle name and given name as recorded at birth, and any other names (if any);

2. Date of birth; date of death or disappearance;

3. Gender;

4. Place of birth, place of birth registration, place of permanent residence, place of temporary residence, current place of residence, native place, contact address;

5. Nationality;

6. Images of the individual; information obtained from security systems, including recordings of images of the Data Subject captured by cameras and surveillance cameras at the Company’s business and transaction premises;

7. Telephone number, identity card number, citizen identity card number, personal identification number, passport number, driving licence number, vehicle registration number, personal tax code, social insurance number, health insurance card number;

8. Occupation, place of work;

9. Marital status;

10. Information on family relationships (parents, children);

11. Information on the individual’s digital accounts; Personal Data reflecting preferences and activity history in cyberspace;

12. Other information associated with a specific person or which helps to identify a specific person and which does not fall within the scope of sensitive Personal Data as set out in Section 2.2 below.

2.2 Sensitive Personal Data includes the following principal data:

1. Political views and religious views;

2. Health status and private life as recorded in medical records, excluding information on blood type;

3. Information relating to racial origin and ethnic origin;

4. Information on inherited or acquired genetic characteristics of the individual;

5. Information on the individual’s physical attributes and distinct biological characteristics;

6. Data on crimes and criminal acts collected and stored by law enforcement agencies;

7. Information on the Data Subject’s bank accounts;

8. Data on the Customer’s location determined through location services;

9. Other Personal Data prescribed by law as being of a specific nature and requiring the necessary security measures.

3. PURPOSES OF PROCESSING PERSONAL DATA

Personal Data may be processed for one or more of the following purposes: 3.1 Assessing the ability to supply products and services and/or to enter into contracts with the Data Subject, including but not limited to the following purposes:

1. Identifying and verifying information about the Data Subject;

2. Assessing, appraising and approving the supply of products and services pursuant to the registration documents, applications and contracts of the Data Subject and/or the persons related to the Data Subject;

3. Considering the supply or continued supply of any of the Company’s products or services to the Data Subject;

3.2 Performing obligations under contracts, agreements, terms, conditions and other documents between the Company and the Data Subject, and providing customer support, including but not limited to the following purposes:

1. Performing obligations under contracts and agreements and supplying products and services to the Data Subject;

2. Updating and processing the Data Subject’s information;

3. Providing customer care and resolving complaints and claims of the Data Subject;

4. Using and transferring to partners Personal Data and related information in order to identify and remedy defects in products and services, and to repair products;

5. Contacting and notifying the Data Subject;

6. Implementing promotional programmes, gift exchanges, prize awards and the delivery of gifts;

7. Carrying out other customer care and support activities. 3.3 Enhancing the quality of the Company’s products and services, including:

1. Providing information requested by customers or which the Company considers useful to customers;

2. Improving technology and the interfaces of websites, social media pages and applications so as to ensure convenience for customers;

3. Compiling statistics and analysing data in order to research, build, develop and improve products and services, and to enhance the customer experience;

4. Developing and supplying new products and services personalised to the actual needs and circumstances of customers;

5. Introducing and providing promotional programmes and preferential offers for the products and services of the Company and of the Company in cooperation with its partners;

6. Proposing products and services which may be of interest to customers through the identification of customers’ preferences.

3.4 Serving the Company’s business and operational activities, including the performance of reporting, financial, accounting and tax obligations, activities for audit and compliance purposes, and other activities serving the Company’s lawful business in such cases as the Company deems necessary.

3.5 Restructuring and transfer of projects/enterprises:

In the course of its business, the Company may sell or purchase enterprises, restructure the enterprise, or transfer projects or other services in accordance with the provisions of law. Accordingly, Personal Data and the right to use information generally constitute one of the assets to be transferred. In all cases, the transfer and processing of data shall be carried out by the parties in accordance with the provisions of law and this Policy.

3.6 Marketing: Developing marketing campaigns and promoting products and services, including the development of campaigns based on customers’ preferences;

3.7 Preventing, combating, investigating and detecting crime.

3.8 Protecting social order and safety, and protecting the lawful rights and interests of the Data Subject, the Company and other related parties.

3.9 Complying with the provisions of law and international treaties to which Vietnam is a party, including: 1. Providing information to competent State authorities in accordance with the provisions of law. 2. Performing obligations under the provisions of law and international treaties with which the Company must comply (if any).

3.10 Other purposes where the consent of the Data Subject is obtained. The Company shall process Personal Data only for the specific purposes to which the Data Subject has elected to consent.

4. MANNER OF PROCESSING PERSONAL DATA

4.1 Manner of collection Personal Data is collected as follows:

1. From the Company’s websites and applications: Personal Data is collected when the Data Subject completes forms made available on the Company’s websites and applications.

2. From the supply of products and services and the performance of obligations under the Company’s contracts and agreements: Personal Data is collected when the Data Subject purchases, registers to use, or uses any product or service, or enters into a contract with the Company

3. From exchanges and communications with the Data Subject: Personal Data is collected through interactions between the Company and the Data Subject (in person, by post, by telephone, online, through call centre systems, by electronic communication or by any other means), including surveys;

4. From social media: Being the Company’s social media pages and/or social media pages operated by the Company in cooperation with its partners;

5. From audio and video recording devices: installed at stores, business premises or places where part or all of the Company’s business activities are carried out and where the Data Subject meets, appears or interacts with the Company;

6. From interactions or automated data collection technologies: The Company may collect information recorded automatically from the connection:

– Cookies, pixel tags and other similar technologies;

– Any technology capable of tracking individual activity on devices or websites;

– Other data and information provided by a device

7. Other means

The Company may collect Personal Data through public and official sources of information or through the receipt of necessary data shared by parent companies, subsidiaries, affiliates and partners in the course of their cooperation with the Company, in accordance with the provisions of law.

4.2 Manner of storage

Personal Data is stored in Vietnam within the Company’s database systems or at any location where we or our branches, subsidiaries, affiliates, partners or service providers have facilities.

The period for which personal data is stored is determined on the basis of the purposes of use as set out in this Policy and in accordance with the provisions of law.

4.3 Manner of transferring/sharing data

The Company shall not sell Personal Data to any party. The Company applies the necessary security measures to ensure that the transfer/sharing of Personal Data is secure. Personal Data is shared by the Company with (i) the Company’s parent company, subsidiaries and affiliates; (ii) individuals/organisations participating in the Processing of Personal Data as set out in this Policy); or (iii) competent State authorities, or in other cases in accordance with the provisions of law

Where the recipient of Personal Data is headquartered outside the territory of Vietnam, when providing/transferring Personal Data abroad (including the use of cyberspace, devices, electronic means or other forms to transfer Personal Data outside the territory of Vietnam), the Company shall require the recipient to ensure the safety and security of the Personal Data provided/transferred. The Company undertakes to comply fully with the provisions and compliance requirements of the laws of Vietnam in order to safeguard Personal Data.

4.4 Manner of analysis

Personal Data is analysed on the basis of the Company’s internal procedures, data security principles and the assurance of information security for information technology systems. 4.5 Manner of encryption

Where necessary, the Personal Data collected is encrypted in accordance with appropriate encryption standards during storage or during the transfer and processing of data, so as to ensure that the data is protected at all times.

4.6 Manner of data deletion

In accordance with the provisions of law or upon a valid request from the Data Subject, the Company shall delete the Personal Data being stored, save in the following cases:

1. The law does not permit the deletion of the data or mandatorily requires the data to be retained;

2. The Personal Data is processed by a competent State authority for the purpose of serving the activities of the State authority in accordance with the provisions of law;

3. The Personal Data has been disclosed publicly in accordance with the provisions of law;

4. The Personal Data is processed in order to serve legal requirements, scientific research or statistical purposes in accordance with the provisions of law;

5. In the event of a state of emergency relating to national defence, national security, social order and safety, a major disaster or a dangerous epidemic; where there is a threat to security and national defence which has not yet reached the level warranting the declaration of a state of emergency; or for the prevention of and response to riots and terrorism, and the prevention of and combat against crime and violations of law;

6. Responding to an emergency situation threatening the life, health or safety of the Data Subject or another individual.

Throughout the Processing of Personal Data, security is the Company’s highest priority. The Company has appropriate technical measures in place to prevent unauthorised access to and use of Personal Data. We also work regularly with security experts in order to keep abreast of the latest cybersecurity techniques so as to ensure the safety of Personal Data. Data relating to your payment cards issued by financial institutions is protected by the Company on the principle that critical payment card data (card number, cardholder name, CVV number) is not recorded on our systems. Your payment transactions are carried out on the systems of the relevant bank.

5. PROCESSING OF CHILDREN’S PERSONAL DATA

5.1 The Company shall carry out the Processing of children’s Personal Data on the principle of protecting the rights and serving the best interests of children and in accordance with the provisions of law.

5.2 The Company shall carry out the Processing of children’s Personal Data and supply products and services to children only where the father, mother or guardian consents to the child using the Company’s products and services, consents to the Company carrying out the Processing of the child’s Personal Data, agrees to this Policy and complies with the relevant requirements of law. Where a child aged seven years or older uses the Company’s products or services, in addition to the requirements set out herein, the Company shall carry out the Processing of that child’s Personal Data only where the consent of that child has been obtained. The father, mother or guardian shall be responsible for obtaining the child’s consent before providing the child’s Personal Data to the Company.

6. POTENTIAL UNDESIRED CONSEQUENCES AND DAMAGE

6.1 The Company employs a variety of information security technologies, such as firewall systems, access control measures and encryption, in order to protect Personal Data and prevent it from being accessed, used or shared without authorisation. However, in certain situations beyond the Company’s control, it is not possible to guarantee absolute security for Personal Data, which may lead to the following consequences:

1. Loss of data due to hardware or software errors in the course of data processing;

2. Data leakage due to security vulnerabilities beyond the Company’s control, or systems being attacked by hackers resulting in the disclosure or leakage of data.

Data which is lost or leaked may be used to commit fraud or deception, or may cause financial loss to the Data Subject. In addition, the disclosure of sensitive information may adversely affect the reputation, personal life or work of the Data Subject. 6.2 The Company recommends that:

1. The Data Subject keep confidential all information relating to the password for logging into their account and OTP codes, and not share such content with any other person.

2. The Data Subject be clearly aware that, at any time when the Data Subject discloses and makes public their own Personal Data, such data may be collected by others and used for purposes beyond the control of the Data Subject and the Company.

3. The Company recommends that the Data Subject safeguard their personal devices (mobile telephones, tablets, personal computers, etc.) during use. The Data Subject should log out of their account when it is not in use.

4. When transmitting Personal Data over cyberspace, the Data Subject should only use secure systems to access websites, applications or devices. The Data Subject is responsible for keeping their access authentication information for each website, application or device secure and confidential.

6.3 The Company’s responsibilities in the event of undesired consequences or damage To the extent permitted by law, the Company undertakes to discharge the following responsibilities in order to minimise risks and protect the interests of the Data Subject:

1. Proactive response and remediation: Immediately upon detecting an incident involving the loss or leakage of Personal Data, the Company shall promptly implement the necessary technical and organisational measures to prevent and remedy the consequences, limit the damage and notify the Data Subject in accordance with the provisions of law.

2. Cooperation with the authorities: The Company shall cooperate closely with the competent authorities in investigating and handling the incident and shall perform its reporting obligations in accordance with the provisions of law.

3. Remedying damage: Where actual damage arises due to the fault of the Company, the Company shall consider discharging its responsibilities towards the Data Subject in accordance with the applicable provisions of law.

4. Review and improvement: Following each incident, the Company shall assess the causes, review its systems and update its security measures in order to prevent similar incidents in the future.

7. COMMENCEMENT AND END OF THE PROCESSING OF PERSONAL DATA

7.1 Personal Data shall be processed from the time at which the Company lawfully receives the Personal Data and the Company has an appropriate legal basis for processing the data in accordance with the provisions of law.

7.2 Personal Data shall be processed until the purposes of the data processing have been fulfilled.

7.3 The Company may be required to retain Personal Data even after the contract between the parties has been terminated, in order to perform obligations under the provisions of law and/or at the request of competent State authorities.

8. ORGANISATIONS AND INDIVIDUALS PARTICIPATING IN THE PROCESSING OF PERSONAL DATA AND THE SCOPE OF USE OF PERSONAL DATA

8.1 Depending on the circumstances, the Company may act as the Data Controller or as the Data Controller and Data Processor of personal data.

8.2 To the extent permitted by law, the Data Subject clearly understands that the Company may share Personal Data for the purposes set out in this Policy with the following organisations and individuals:

1. The Company’s parent company, subsidiaries and affiliates;

2. Organisations and individuals providing services to and/or cooperating with the Company, including: agents, auditors, lawyers, business cooperation partners, and providers of information technology solutions, software, applications, operation and management services, incident handling services and infrastructure development;

3. Any individual or organisation acting as the representative or authorised person of the Data Subject and acting on behalf of the Data Subject;

The sharing of data shall be carried out in accordance with the proper order, manner and applicable provisions of law. The parties receiving Personal Data are obliged to keep the Personal Data confidential in accordance with this Policy, the Company’s internal regulations and standards on the protection of Personal Data, and the applicable provisions of law.

8.3 The Company may be required to share Personal Data with competent State authorities in accordance with the provisions of law.

9. RIGHTS OF THE DATA SUBJECT

9.1 The right to be informed of the Processing of their Personal Data, save where otherwise provided by law.

9.2 The right to consent or to withhold consent to the Processing of their Personal Data, save where otherwise provided by law.

9.3 The right of access to view, amend or request the amendment of their Personal Data, save where otherwise provided by law.

9.4 The right to withdraw consent. 9.5 The right to erasure of data.

9.6 The right to restrict the Processing of their Personal Data in accordance with the provisions of law.

9.7 The right to request that their Personal Data be provided to them, save where otherwise provided by law.

9.8 The right to object to the processing of data.

9.9 The right to lodge complaints, denunciations and lawsuits. 9.10 The right to claim compensation for damage. 9.11 The right of self-protection.

The Data Subject may exercise these rights by submitting a request to the Company. The request form must be sent to the Company and must contain the essential particulars, such as the information of the requester, the detailed content of the request [for example, the type of data to be provided or deleted, the name of the document or file (if any)], the reasons for and purposes of the request, and related information depending on the specific nature of the request (for example, whether the requested documents are to be provided in electronic file or hard copy form, the address for receipt of the documents, etc.). All costs (if any) arising from the performance of the requests set out herein, including printing, photocopying, postage and express delivery charges for sending the data, shall be borne by the requester and must be paid no later than upon receipt of the data or within such time limit as is determined by the Company.

The Company shall handle the Data Subject’s requests in accordance with the provisions of law and with due regard to the legitimate interests of the Data Subject. However, where the Data Subject withdraws their consent, requests the deletion of data and/or exercises other related rights in respect of any or all of the Personal Data in a manner which affects the Company’s ability to supply/maintain its products and services to the Data Subject or to maintain the contractual relationship, then, depending on the nature of the Data Subject’s request, the Company may consider and decide to discontinue the supply of the Company’s products and services to the Data Subject or to terminate the contractual relationship between the Company and the Data Subject. Acts carried out by the Data Subject pursuant to this provision shall be deemed a unilateral termination by the Data Subject of any relationship between the Data Subject and the Company, and may well result in a breach of obligations or undertakings under the contract between the Data Subject and the Company, and the Company reserves its lawful rights and remedies in such cases. Accordingly, the Company shall not be liable to the Data Subject for any loss arising, and the Company’s lawful rights shall be fully reserved. Using reasonable endeavours, the Company shall comply with lawful and valid requests from the Data Subject within a period consistent with the provisions of law. However, for security purposes, the Company may require the Data Subject to verify their identity before processing the Data Subject’s request.

The Company is entitled to refuse to comply with the Data Subject’s requests in certain cases, including where: (i) the Data Subject fails to follow the order and procedures instructed by the Company, including where the content of the request lacks information or is invalid; (ii) the Data Subject fails to provide, or provides incomplete, papers and documents for identity verification; or (iii) the Company assesses that there are signs of fraud or of a violation relating to the protection of Personal Data; or (iv) the provisions of law do not permit compliance with the Data Subject’s request.

10. OBLIGATIONS OF THE DATA SUBJECT

10.1 To protect their own Personal Data; and to require other related organisations and individuals to protect their Personal Data. To notify the Company promptly upon detecting any error, mistake or leakage in respect of Personal Data, or upon suspecting that Personal Data is being infringed.

10.2 To respect and protect the personal data of others.

10.3 To provide Personal Data fully and accurately when consenting to the Processing of Personal Data. In the event of any inaccurate information, the Data Subject shall bear the consequences at their own cost where such information affects or restricts the rights and interests of the Data Subject.

10.4 To comply with the provisions of law on the protection of personal data and to participate in preventing and combating acts in breach of the provisions on the protection of personal data.

10.5 Other responsibilities in accordance with the provisions of law.

11. OTHER PROVISIONS

11.1 The Data Subject acknowledges that, by accepting this Policy, the Data Subject has consented to their Personal Data being processed by the Company and by the organisations and individuals participating in the Processing of Personal Data as set out in this Policy, and is clearly aware of the types of data processed, the purposes of the data processing, the organisations and individuals carrying out the Processing of Personal Data, and their own rights and obligations in relation to Personal Data. The Data Subject has been notified by the Company of, is aware of and agrees to all of the matters required to be notified before their Personal Data is processed by the Company and by the organisations and individuals participating in the Processing of Personal Data. The Data Subject agrees that the Company and the organisations and individuals participating in the Processing of Personal Data need not issue any further notification before carrying out the Processing of Personal Data.

11.2 Should you have any questions regarding the Company’s protection of personal data, please contact us and we shall endeavour to answer your questions at the earliest opportunity. You may also

contact us at the email address info@nodo.vn.

Cart
Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare