Privacy and Personal Data Protection Policy
Is an appendix to and an inseparable part of Terms of Service of HiTechCloud.
PART I - LEGAL BASIS AND SCOPE OF APPLICATION
Article 1. Legal basis
This policy is drawn up and applied in accordance with the following legislation:
- The Personal Data Protection Law 2025 (Luật Bảo vệ dữ liệu cá nhân 2025, Law No. 91/2025/QH15, effective 01/01/2026) — a dedicated statute replacing the previously fragmented approach;
- Decree 356/2025/NĐ-CP detailing and providing measures to implement the Personal Data Protection Law;
- Decree 13/2023/NĐ-CP on personal data protection (applicable to the extent it does not conflict with Law 91/2025);
- Law on Cybersecurity 2025 (Law No. 116/2025/QH15, effective 01/7/2026);
- Data Law 2024 (Law No. 60/2024/QH15) on processing and cross-border transfer of data;
- Law on Electronic Transactions 2023 on protecting information in electronic transactions;
- E-Commerce Law 2025 (Luật số 122/2025/QH15)
- Law on Protection of Consumer Rights 2023;
- Accounting Law 2015 and Tax Administration Law 2025 on document retention;
- Law on Anti-Money Laundering 2022;
- Decree 147/2024/NĐ-CP and related guidance on information security;
- GDPR — applies to personal data of subjects within the scope of the GDPR.
Article 2. Scope and persons covered
2.1. This Policy applies to all personal data (dữ liệu cá nhân) that HiTechCloud collects, processes, stores and shares in the course of providing its services, covering: (a) Customers who are individuals, and the representatives of organizations; (b) the Customer's end users of hosting, cloud and email services; (c) visitors to the hitechcloud.vn and photuesoftware.com websites; and (d) participants in beta testing, surveys or technical support.
2.2. HiTechCloud's role. Under the Personal Data Protection Law 2025, HiTechCloud is The data controller for data collected directly in order to provide the service; and is Data Processor when processing data on the Customer's instructions (for example, hosting the Customer's database). In certain cases, HiTechCloud may be Data Controller and Processor. Each party's specific responsibilities are set out in the data processing contract or agreement.
2.3. The Law on Personal Data Protection 2025 (Luật Bảo vệ dữ liệu cá nhân 2025) also applies extraterritorially to organizations and individuals that are directly involved in, or connected with, the processing of Vietnamese citizens' personal data.
PART II – PERSONAL DATA COLLECTED
Article 3. Basic personal data
3.1. HiTechCloud collects the following basic categories of personal data:
- (a) Identity information: full name, date of birth, gender, nationality, citizen ID card/ID card/passport number; information about a spouse (where the Customer provides it voluntarily, and the mandatory information that customers must provide when using the service);
- (b) Contact information: email address, phone number, residential/registered address;
- (c) Payment information: bank card number (encrypted, not stored in full), cardholder name, issuing bank, transaction history;
- (d) Account information: username, password (hashed), login history and activity logs;
- (e) Device and connection information: IP address, browser type, operating system, time zone and language;
- (f) Service usage data: bandwidth traffic, resource usage and server logs;
- (g) Business information: tax code, company name, line of business and legal representative (for organizations).
Article 4. Sensitive personal data
4.1. In specific cases, and with explicit consent, HiTechCloud may collect sensitive personal data, including: (a) biometric data (facial photograph, fingerprint) in the eKYC process; (b) VNeID electronic identification data; (c) images of identity documents (CCCD citizen ID); (d) full bank account details and transaction history (where required for large service contracts); and (e) corporate legal records.
4.2. Sensitive data is collected only where: (a) there is a clear legal basis; (b) it is protected by advanced technical measures and strong authentication; (c) it is accessible only to authorized personnel holding a specific role.
4.3. Authentication limits. HiTechCloud does not require users to provide images or video showing all or part of an identity document as an account authentication factor, except where the law requires it and with appropriate safeguards in place.
Article 5. Collection methods
5.1. Data is collected through: (a) the data subject directly (registration forms, account records, support requests, surveys); (b) automated technical systems (cookies, pixels, server logs, traffic analytics — subject to the consent mechanism in Article 16); (c) authorized third parties (payment gateways, the VNNIC/ICANN domain registries, eKYC/VNeID verification providers); and (d) social sign-in (Google/Facebook OAuth — permitted basic information only).
PART III - PURPOSES AND LEGAL BASES FOR PROCESSING
Article 6. Purpose and legal basis
HiTechCloud processes Personal Data for the following purposes, each tied to a legal basis under the Personal Data Protection Law 2025 (Luật Bảo vệ dữ liệu cá nhân 2025):
Group 1 – Contract performance:
- Providing and managing the services you have subscribed to; processing payments and issuing invoices; verifying identity and preventing fraud; technical support and complaint resolution.
Group 2 – Fulfilling legal obligations:
- Retaining accounting records under the Accounting Law 2015 (Luật Kế toán 2015) and the Law on Tax Administration 2025 (Luật Quản lý thuế 2025); complying with the requirements of competent state authorities; anti-money laundering and counter-terrorist financing (AML/CFT).
Group 3 – Legitimate interests:
- Improving service quality through aggregated, anonymized analysis; securing systems and detecting and blocking cyber attacks; managing risk and preventing fraud.
Group 4 – On the basis of the data subject's consent:
- Sending marketing emails, newsletters and promotions; user research and experience surveys; sharing data with partners for advertising purposes (only with explicit consent).
Consent principle. Consent is legally valid only where it is given voluntarily, clearly and specifically, is verifiable, and the data subject has a genuine choice. HiTechCloud does not share data with third parties by default without the data subject's consent.
PART IV - RIGHTS AND OBLIGATIONS OF DATA SUBJECTS
Article 7. Rights of data subjects
Under the Personal Data Protection Law 2025, data subjects have the following rights:
- Right to be informed — about its own data processing activities, including the purpose, scope, method of processing and the identity of the Controller.
- Right to consent and withdraw consent — at any time, without affecting the lawfulness of processing carried out before the withdrawal.
- Access control — view and request a copy of the personal data being processed.
- Right to rectification — request correction of inaccurate data.
- Right to erasure — when the data is no longer necessary, when consent is withdrawn, or when the data has been Processed unlawfully; except for data that must be retained under the law.
- Right to restrict processing — suspend processing pending review of the accuracy or lawfulness of the data.
- Right to object to processing — particularly for direct marketing.
- The right to request data access or portability — receive the data in a structured, commonly used, machine-readable format.
- The right not to be subject to a solely automated decision — unless necessary for the contract or with explicit consent.
- The right to complain, denounce, sue and claim compensation — in accordance with the law.
Article 8. How to exercise your rights
8.1. Data subjects may exercise their rights by: (a) logging into the account management portal to act directly (access, edit); (b) emailing cskh@photuesoftware.com with the subject line "PDPD Rights Request – [Full name]"; (c) sending a written request to our headquarters at 128 Đường Bình Mỹ, xã Bình Mỹ, TP. Hồ Chí Minh.
8.2. HiTechCloud commits to: acknowledging requests within 3 business days; completing them within 30 days (extendable by a further 30 days for complex cases, with written notice); processing reasonable requests free of charge (up to 2 times per year per data subject), with a reasonable administrative fee possible for repeated or excessive requests.
8.3. Obligations of the data subject. Data subjects are obliged to protect their own Personal Data, to provide complete and accurate information, to respect other people's data and to comply with personal data protection law.
PART V - DATA STORAGE, PROTECTION, AND TRANSFER
Article 9. Retention period
HiTechCloud retains personal data on a data minimization basis:
| Data type | Retention period |
| Active account data | For the duration of use plus 30 days after termination |
| Records, invoices, and financial documents | 10 years (Accounting Law 2015, Tax Administration Law 2025) |
| Access logs | 12 months (Decree 147/2024/NĐ-CP) |
| E-commerce transaction logs | Under the E-commerce Law 2025 (Luật Thương mại điện tử 2025) |
| AML/KYC data | 5 years after the customer relationship ends (Anti-Money Laundering Law 2022) |
| Analytics cookies / technical cookies | 13 months / until browser data is cleared |
Article 10. Technical and organizational safeguards
Encryption:
- Data at rest: AES-256; data in transit: TLS 1.3 with HTTPS enforced; passwords: bcrypt with a salt factor of 12 or higher.
Access control (Access Control):
- The principle of least privilege; mandatory multi-factor authentication (MFA) for staff accessing sensitive data; identity and access management (IAM) with periodic reviews; and logging of every access to personal data.
Infrastructure security:
- A web application firewall (WAF) and intrusion detection and prevention systems (IDS/IPS); vulnerability scanning and penetration testing at least once a year; network segmentation to isolate sensitive data; aligned with ISO/IEC 27001.
HR management:
- Information security training for all staff; non-disclosure agreements with employees and contractors; screening of personnel who handle sensitive data.
Article 11. Transferring data to third parties
11.1. HiTechCloud shares data, only to the extent necessary, with: (a) technical service providers (cloud infrastructure, CDN, email) under binding data processing agreements; (b) payment gateways and banks — limited to the data required to process payment; (c) licensed eKYC/VNeID providers; (d) competent state authorities where required by law; and (e) business partners — only with the data subject's explicit consent.
11.2. Buying and selling data is strictly prohibited. HiTechCloud does not buy, sell, rent or exchange personal data for commercial purposes. Trading in personal data is strictly prohibited and carries severe sanctions under the Law on Personal Data Protection 2025 (Luật Bảo vệ dữ liệu cá nhân 2025).
Article 12. Cross-border data transfers
12.1. When transferring or processing the personal data of Vietnamese citizens outside Vietnam (storage, backup, CDN distribution, or processing by an overseas infrastructure provider), HiTechCloud complies with the Personal Data Protection Law 2025 and the Data Law 2024, including: (a) preparing a cross-border data transfer impact assessment where one is mandatory; (b) applying appropriate safeguards and entering into data protection contractual terms with the recipient; and (c) ensuring there is a lawful basis for the transfer.
12.2. Where the Customer selects an infrastructure region that results in data being stored or processed outside Vietnamese territory, the Customer is responsible for ensuring there is a legal basis for doing so and for cooperating with HiTechCloud in preparing the impact assessment file.
PART VI - IMPACT ASSESSMENT, DATA BREACHES, AND SANCTIONS
Article 13. Data protection impact assessment (DPIA)
13.1. For activities in which HiTechCloud is the Data Controller, HiTechCloud prepares and retains a personal data processing impact assessment dossier (DPIA) and sends one original copy to the authority responsible for personal data protection (the Department of Cybersecurity and High-Tech Crime Prevention – A05, Ministry of Public Security) within 60 days of the first day of processing, in accordance with Article 21 of the Personal Data Protection Law 2025 (Luật Bảo vệ dữ liệu cá nhân 2025).
13.2. For processing activities in which HiTechCloud acts as the Data Processor, DPIA records are prepared and retained as agreed with the Customer (the Controller). Those records are retained and produced on request by the competent authority.
Article 14. Personal data breach notification
14.1. In the event of a personal data breach, HiTechCloud will: (a) notify the specialized authority (A05, Ministry of Public Security (Bộ Công An)) within the statutory deadline; (b) notify the affected data subjects/Customers via their registered email; (c) provide information on the scope of the breach, the type of data affected, and the remedial measures; (d) immediately implement containment and remedial measures.
14.2. The Customer must notify HiTechCloud as soon as possible on discovering an incident or data breach affecting data under the Customer's control on the platform, so that both parties can respond within the statutory deadlines.
Article 15. Sanctions (cross-reference)
Under Article 8 of the Personal Data Protection Law 2025, administrative fines for organizations can reach: 10 times the proceeds obtained from buying or selling personal data; up to 5% of the previous year's revenue for cross-border transfer breaches; and up to VND 3,000,000,000 for other breaches. Individuals committing the same act are fined at half the rate applied to organizations. Criminal prosecution and liability for damages may also apply.
PART VII – COOKIES AND TRACKING TECHNOLOGIES
Article 16. Cookie policy and the “do not track” mechanism
16.1. HiTechCloud uses cookies and similar tracking technologies. Full details are in the Cookie Policy. Summary of cookie categories:
- Technically necessary cookies: cannot be declined — required to operate the website;
- Analytics cookies: can be declined — aggregate traffic analysis with IP anonymization;
- Functional cookies: may be declined — remembers user preferences;
- Marketing/targeting cookies: require active consent — advertising and remarketing.
16.2. HiTechCloud gives users the option to opt out of the collection and sharing of tracking data files, including a “do-not-track” option. Tracking activity is carried out only with the user's consent. Customers can manage cookies through: (a) the cookie banner shown on first visit; (b) the cookie management portal in the website footer; (c) their browser settings.
PART VIII - DATA PROTECTION STAFF, CONTACT, AND COMPLAINTS
Article 17. Data protection officer (DPO)
17.1. HiTechCloud appoints dedicated personnel or a dedicated unit for personal data protection (DPO) in accordance with Decree 356/2025/NĐ-CP. Contact details:
- Email: legal@photuesoftware.com
- Phone: 0865.920041
- Address: 128 Đường Bình Mỹ, xã Bình Mỹ, TP. Hồ Chí Minh
17.2. The DPO is responsible for: monitoring compliance; advising on impact assessments; and acting as the point of contact for the state authority and for data subjects.
Article 18. Privacy complaints
18.1. A data subject who believes their privacy has been infringed may: (a) submit a complaint to HiTechCloud at report@photuesoftware.com; (b) complain to the Department of Cybersecurity and High-Tech Crime Prevention (A05, Ministry of Public Security), the authority responsible for personal data protection; or (c) where the data subject falls within the scope of the GDPR, complain to the Data Protection Authority (DPA) in their EU member state of residence.
PART IX – EFFECTIVE DATE AND UPDATES
Article 19. Effective date
19.1. This policy takes effect on 1 July 2026 and supersedes all previous versions.
19.2. HiTechCloud may update this Policy; notice of an update is published on the website and/or sent to the registered email address before it takes effect. This Policy is drafted in Vietnamese; the Vietnamese version has the highest legal authority.