Multilingual translations are provided for international partners' convenience and reference. In case of any discrepancy or conflict in legal interpretation, the original Vietnamese version shall prevail under Vietnamese law.
1. Legal Basis & Scope of Application
This privacy policy is established in rigorous compliance with:
- Government Decree No. 13/2023/ND-CP on Personal Data Protection dated April 17, 2023.
- Law on Cyber Information Security No. 86/2015/QH13 and regulatory guidance.
- Law on Cybersecurity No. 24/2018/QH14 passed by the National Assembly of Vietnam.
This policy applies to all personal and enterprise contact data collected through CreditBird websites, software apps, ERP systems, IT staffing arrangements, and smart scent diffuser installations.
2. Purposes of Data Processing
CreditBird collects and processes data strictly within the necessary bounds for legitimate business operations:
- Consulting, issuing technical proposals, and preparing quotations for custom software, ERP, IT staffing, and aroma systems.
- Drafting, concluding, and executing commercial contracts between CreditBird and clients.
- Fulfilling hardware warranty commitments (12 - 24 months), regular oil supply, and software SLA maintenance.
- Issuing statutory electronic Value-Added Tax (VAT) invoices compliant with General Department of Taxation regulations.
- Delivering software patch notifications, cybersecurity bulletins, and system operational advisories.
3. Types of Data Collected
3.1. Data Actively Provided by Clients:
- Full names of contact persons and legal corporate representatives.
- Business email addresses and direct telephone numbers.
- Corporate entity names, enterprise tax identification numbers, and headquarters addresses.
- Facility survey sites, hardware installation coordinates, or cloud deployment locations.
3.2. Technical Telemetry Recorded Automatically:
- IP addresses, client device characteristics, browser user-agents, and connection access logs.
- System audit logs utilized for intrusion detection and fraud prevention.
4. Technical Security & Protection Safeguards
CreditBird enforces stringent technical and organizational protocols to prevent unauthorized data access, leakage, or loss:
TLS 1.3 encryption across all public networks; AES-256 cryptographic standards for data at rest.
Least-privilege access restricted exclusively to engineers assigned to active project contracts.
We strictly pledge never to sell, monetize, or lease personal or corporate client data to any external third party for commercial or advertising gain.
5. Data Retention & Geographic Data Sovereign Location
Client data is hosted in domestic sovereign Tier III Data Centers in Vietnam (Viettel IDC, VNPT Data Center, FPT Telecom), ensuring compliance with onshore data residency mandates under the Vietnam Cybersecurity Law.
Records are retained for the duration of the commercial agreement and archived pursuant to Vietnamese tax and accounting statutes before undergoing secure cryptographic deletion.
6. Data Subject Rights & Controls
Under Decree 13/2023/ND-CP, data subjects possess full statutory rights:
- Right to be informed regarding personal data processing operations.
- Right to give consent, withhold consent, or withdraw prior authorization.
- Right to access, review, and request correction of inaccurate records.
- Right to request deletion of personal information once processing objectives conclude.
- Right to lodge formal complaints regarding regulatory data violations.
7. Data Protection Officer (DPO) Contact
To exercise data subject rights or report cybersecurity concerns, please contact our Data Protection Office: